Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19.06.2018
Ran by ptichun (administrator) on SVEZNALICA (19-06-2018 14:06:16)
Running from C:\Users\ptichun\Downloads
Loaded Profiles: ptichun (Available Profiles: ptichun & Administrator)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Adobe Systems, Incorporated) C:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Wireless Service) C:\Program Files\D-Link\DWA-125 revA\ANIWZCSdS.exe
() C:\Program Files\D-Link\DWA-125 revA\ANIWConnService.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(Gold Click Ltd) C:\Program Files\ProxyGate\Cloud.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TecoService.exe
(Gold Click Ltd) C:\Program Files\ProxyGate\PGChk.exe
(Microsoft Corporation) C:\Windows\System32\FXSSVC.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\UI0Detect.exe
(RealNetworks, Inc.) C:\Program Files\Real\realplayer\Update\realsched.exe
(Dropbox, Inc.) C:\Program Files\Dropbox\Client\Dropbox.exe
(DivX, LLC) C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe
(AimerSoft) C:\Program Files\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
(Nico Mak Computing) C:\Program Files\File Association Helper\FAHWindow.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Dropbox, Inc.) C:\Program Files\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files\Dropbox\Client\Dropbox.exe
() C:\Program Files\Hexagon\cans.exe
() C:\Program Files\Hexagon\cans.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(© 2015 Microsoft Corporation) C:\Users\ptichun\AppData\Local\Microsoft\BingSvc\BingSvc.exe
() C:\Program Files\FileHippo.com\FileHippo.AppManager.exe
(Ruiware) C:\Program Files\Ruiware\WinPatrol\WinPatrol.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
() C:\Program Files\postural\mccarren.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agrsmsvc.exe
(TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
(TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Melasys) C:\Users\ptichun\AppData\Local\ImpaqSpeed\qtspeedtest.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\RSelect\RSelSvc.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
() C:\Users\ptichun\AppData\Roaming\AGData\bin\proxycheck.exe
() C:\Users\ptichun\AppData\Roaming\AGData\bin\proxycheck.exe
() C:\Users\ptichun\AppData\Roaming\AGData\bin\proxycheck.exe
() C:\Users\ptichun\AppData\Roaming\AGData\bin\proxycheck.exe
() C:\Users\ptichun\AppData\Roaming\AGData\bin\proxycheck.exe
() C:\Users\ptichun\AppData\Roaming\AGData\bin\proxycheck.exe
(Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
() C:\Users\ptichun\AppData\Roaming\AGData\bin\proxycheck.exe
() C:\Program Files\Groundstrokes\Quayside.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefoxJu.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefoxJu.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefoxJu.exe
() C:\Users\ptichun\AppData\Local\Latham.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefoxJu.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefoxJu.exe
() C:\Users\ptichun\AppData\Roaming\AGData\bin\proxycheck.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefoxJu.exe
() C:\Users\ptichun\AppData\Roaming\AGData\bin\proxycheck.exe
() C:\Users\ptichun\AppData\Roaming\AGData\bin\proxycheck.exe
() C:\Users\ptichun\AppData\Roaming\AGData\bin\proxycheck.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [TkBellExe] => C:\Program Files\Real\realplayer\update\realsched.exe [274608 2010-11-23] (RealNetworks, Inc.)
HKLM\...\Run: [Dropbox] => C:\Program Files\Dropbox\Client\Dropbox.exe [3643712 2018-06-04] (Dropbox, Inc.)
HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [1057240 2017-11-17] (DivX, LLC)
HKLM\...\Run: [FAHConsole] => C:\Program Files\File Association Helper\FAHConsole.exe [616632 2014-01-28] (Nico Mak Computing)
HKLM\...\Run: [Aimersoft Helper Compact.exe] => C:\Program Files\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe [2138272 2016-10-08] (AimerSoft)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [315880 2018-01-05] (Adobe Systems, Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [588704 2018-03-28] (Oracle Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [262456 2018-05-22] (Apple Inc.)
HKLM\...\Run: [Flayed] => C:\Program Files\Dissatisfied\Latham.exe [203264 2018-06-18] ()
HKLM\...\Run: [Lentz] => C:\Program Files\schelling\Quayside.exe [203264 2018-06-18] ()
HKLM\...\Run: [Catastrophic] => C:\Program Files\Groundstrokes\Latham.exe [203264 2018-06-18] ()
HKLM\...\Run: [Lady] => C:\Program Files\Dissatisfied\Latham.exe [203264 2018-06-18] ()
HKLM\...\Run: [Scapegoats] => C:\Program Files\schelling\Quayside.exe [203264 2018-06-18] ()
HKLM\...\Run: [Bellotti] => C:\Program Files\Groundstrokes\Latham.exe [203264 2018-06-18] ()
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-2101005229-1017427555-4036206314-1000\...\Run: [BingSvc] => C:\Users\ptichun\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-12] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-2101005229-1017427555-4036206314-1000\...\Run: [FileHippo.com] => C:\Program Files\FileHippo.com\FileHippo.AppManager.exe [10566352 2015-09-02] ()
HKU\S-1-5-21-2101005229-1017427555-4036206314-1000\...\Run: [Chromium] => c:\users\ptichun\appdata\local\chromium\application\chrome.exe [1053184 2016-03-09] (The Chromium Authors)
HKU\S-1-5-21-2101005229-1017427555-4036206314-1000\...\Run: [WinPatrol] => C:\Program Files\Ruiware\WinPatrol\WinPatrol.exe [1223560 2017-05-07] (Ruiware)
HKU\S-1-5-21-2101005229-1017427555-4036206314-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [27831240 2018-03-13] (Skype Technologies S.A.)
HKU\S-1-5-21-2101005229-1017427555-4036206314-1000\...\Run: [iCloudServices] => C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2018-05-23] (Apple Inc.)
HKU\S-1-5-21-2101005229-1017427555-4036206314-1000\...\Run: [Web Companion] => C:\Program Files\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize
HKU\S-1-5-21-2101005229-1017427555-4036206314-1000\...\Run: [Mclarty] => C:\Program Files\Dissatisfied\Latham.exe [203264 2018-06-18] ()
HKU\S-1-5-21-2101005229-1017427555-4036206314-1000\...\Run: [Cleave] => C:\Program Files\schelling\Quayside.exe [203264 2018-06-18] ()
HKU\S-1-5-21-2101005229-1017427555-4036206314-1000\...\Run: [Momentum] => C:\Program Files\Groundstrokes\Latham.exe [203264 2018-06-18] ()
HKU\S-1-5-21-2101005229-1017427555-4036206314-1000\...\Run: [Featherbedding] => C:\Program Files\Dissatisfied\Latham.exe [203264 2018-06-18] ()
HKU\S-1-5-21-2101005229-1017427555-4036206314-1000\...\Run: [Harmonies] => C:\Program Files\schelling\Quayside.exe [203264 2018-06-18] ()
HKU\S-1-5-21-2101005229-1017427555-4036206314-1000\...\Run: [Shucks] => C:\Program Files\Groundstrokes\Latham.exe [203264 2018-06-18] ()
HKU\S-1-5-21-2101005229-1017427555-4036206314-1000\...\Run: [mccarren] => C:\Program Files\postural\mccarren.exe [44824 2018-06-18] ()
HKU\S-1-5-21-2101005229-1017427555-4036206314-1000\...\Run: [caper] => C:\Program Files\Dissatisfied\Latham.exe [203264 2018-06-18] ()
HKU\S-1-5-21-2101005229-1017427555-4036206314-1000\...\Run: [ImpaqSpeed] => C:\Users\ptichun\AppData\Local\ImpaqSpeed\qtspeedtest.exe [15774312 2018-05-21] (Melasys)
HKU\S-1-5-21-2101005229-1017427555-4036206314-1000\...\MountPoints2: {2a329238-ce02-11e0-a84e-002622ebfd92} - E:\LaunchU3.exe
HKU\S-1-5-18\...\Run: [KSS] => "C:\Program Files\Kaspersky Lab\Kaspersky Security Scan\kss.exe" autorun
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2016-11-10]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\ptichun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\greenville.lnk [2018-06-18]
ShortcutTarget: greenville.lnk -> C:\Program Files\Dissatisfied\Latham.exe ()
Startup: C:\Users\ptichun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\greenvillegreenville.lnk [2018-06-18]
ShortcutTarget: greenvillegreenville.lnk -> C:\Program Files\schelling\Quayside.exe ()
BootExecute: autocheck autochk * PCloudBroom.exe \systemroot\system32\BroomData.bitPCloudBroom.exe \systemroot\system32\BroomData.bitPCloudBroom.exe \systemroot\system32\BroomData.bit
GroupPolicy: Restriction ? <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyEnable: [.DEFAULT] => Proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:50955;https=127.0.0.1:50955
AutoConfigURL: [.DEFAULT] => http=127.0.0.1:50955;https=127.0.0.1:50955
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\Parameters: [NameServer] 8.8.8.8,8.8.8.4
Tcpip\..\Interfaces\{0616128D-6371-4967-B2C1-BFAD6043F725}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{0616128D-6371-4967-B2C1-BFAD6043F725}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{69C0A4BD-10DF-4634-9868-861521F3C6BE}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{89F93CFB-3F38-40F9-B383-E16F12C1D582}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{98BA5D8D-9CCB-4208-A8C4-E1B6BCB132A2}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{DFD29AFC-4966-4800-9940-D36BB08AF495}: [DhcpNameServer] 192.168.1.254
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
www.google.com
HKU\S-1-5-21-2101005229-1017427555-4036206314-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ca.yahoo.com/?fr=fp-yie9
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {26080cad-4adc-49ac-8c63-eda16e595cbd} URL = hxxp://
www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-0375bd32&q={searchTerms}
SearchScopes: HKLM -> {d4fee3d1-1014-4db8-a824-573bf9ab51c7} URL = hxxp://
www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-7a9c68e8&q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2101005229-1017427555-4036206314-1000 -> DefaultScope {6586d803-df30-46d3-a89a-4136c8571d45} URL =
SearchScopes: HKU\S-1-5-21-2101005229-1017427555-4036206314-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://
www.bing.com/search?pc=COSP&ptag=D061318-AD26CBEB7DD&form=CONBDF&conlogo=CT3335811&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2101005229-1017427555-4036206314-1000 -> {26080cad-4adc-49ac-8c63-eda16e595cbd} URL = hxxp://
www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-7a9c68e8&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2101005229-1017427555-4036206314-1000 -> {40F707B0-22D1-442B-9824-BF665554FCC8} URL = hxxps://
www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2101005229-1017427555-4036206314-1000 -> {5e7797ae-5ca1-4b50-95d8-97e746340487} URL = hxxp://
www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-0375bd32&q={searchTerms}
BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20] (Hewlett-Packard Co.)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_172\bin\ssv.dll [2018-04-20] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_172\bin\jp2ssv.dll [2018-04-20] (Oracle Corporation)
BHO: KeepVid Pro 4.10.0 -> {F9B65201-3D7F-48DA-AAB3-57A6FAD648FD} -> C:\Program Files\Keepvid\KeepVid KeepVid Pro\BrowserPlugin\KVBrowserAppMgr.dll [2018-02-02] ()
BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20] (Hewlett-Packard Co.)
DPF: {63F5866B-A7C5-40B4-9A89-0CCA99726C8D} hxxps://secure.logmeinrescue.com/Customer/x86/RescueDownloader.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_55-windows-i586.cab
DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} hxxp://
www.shockwave.com/content/dinerdashfloonthego/sis/ddfotg.1.0.0.33.cab
DPF: {CAFEEFAC-0017-0000-0055-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_55-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_55-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-26] (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2018-03-07] (Skype Technologies)
Handler: WSKVAllmytubechrome - {91AB862D-07B8-4A85 - No File
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF DefaultProfile: auwjiotq.default-1471367127920-1510800610513
FF ProfilePath: C:\Users\ptichun\AppData\Roaming\Mozilla\Firefox\Profiles\f4mvyrgd.default-1498053148872 [2018-06-18]
FF ProfilePath: C:\Users\ptichun\AppData\Roaming\Mozilla\Firefox\Profiles\auwjiotq.default-1471367127920-1510800610513 [2018-06-19]
FF Homepage: Mozilla\Firefox\Profiles\auwjiotq.default-1471367127920-1510800610513 -> about:home
FF NewTab: Mozilla\Firefox\Profiles\auwjiotq.default-1471367127920-1510800610513 -> hxxp://
www.bing.com/?pc=COSP&ptag=D061318-AD26CBEB7DD&form=CONMHP&conlogo=CT3335811
FF Extension: (SaveFrom.net helper) - C:\Users\ptichun\AppData\Roaming\Mozilla\Firefox\Profiles\auwjiotq.default-1471367127920-1510800610513\Extensions\helper-sig@savefrom.net.xpi [2018-06-18]
FF SearchPlugin: C:\Users\ptichun\AppData\Roaming\Mozilla\Firefox\Profiles\auwjiotq.default-1471367127920-1510800610513\searchplugins\bing-lavasoft-ff59.xml [2018-06-13]
FF Extension: (WebCompat Reporter) - C:\Program Files\Mozilla Firefox\browser\features\webcompat-reporter@mozilla.org.xpi [2018-05-09] [Legacy] [not signed]
FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: (HP Smart Web Printing) - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-07-04] [Legacy] [not signed]
FF HKU\S-1-5-21-2101005229-1017427555-4036206314-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF32_30_0_0_113.dll [2018-06-07] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\windows\system32\Adobe\Director\np32dsw_1234204.dll [2018-06-06] (Adobe Systems, Inc.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll [2017-11-21] (DivX, LLC)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin: @java.com/DTPlugin,version=11.172.2 -> C:\Program Files\Java\jre1.8.0_172\bin\dtplugin\npDeployJava1.dll [2018-04-20] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.172.2 -> C:\Program Files\Java\jre1.8.0_172\bin\plugin2\npjp2.dll [2018-04-20] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @pages.tvunetworks.com/WebPlayer -> C:\windows\system32\TVUAx\npTVUAx.dll [2010-04-23] (TVU networks)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.17\npGoogleUpdate3.dll [No File]
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.17\npGoogleUpdate3.dll [No File]
FF Plugin: @veetle.com/veetleCorePlugin,version=0.9.19 -> C:\Program Files\Veetle\plugins\npVeetle.dll [2012-01-13] (Veetle Inc)
FF Plugin: @veetle.com/veetlePlayerPlugin,version=0.9.18 -> C:\Program Files\Veetle\Player\npvlc.dll [2012-01-13] (Veetle Inc)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-05-10] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2101005229-1017427555-4036206314-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\ptichun\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2009-11-30] (Unity Technologies ApS)
Chrome:
=======
CHR HomePage: Default -> hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoG1GcnEQ_XpzuQqeGfpS2baVmUZQpltYr1il4ONFvOEVLqgBgcL4Pd51IpZJzznddpDeVUlq7blSF6QFemqrj-rMQQYj9WvYBYE0FaarNOnhNvfXQvx34KwIzzvuTrxvVHUl4E9ZwYESXpc4SPJAEvFXPOFhXLLGTvAxqCMIFA,,
CHR DefaultSearchURL: Default -> hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoG1GcnEQ_XpzuQqeGfpS2baVmUZQpltYr1il4ONFvOEVLqgBgcL4Pd51IpZJzznddpDeVUlq7blSF6QFdpFkfzNnKpPJ44zANdI60m5hktFaXgRfspziMfcD_lYJ237M_pxFV-_TtqK9cHMupac8pqa-cYrPU1XsK6LW-iQYYA,,&q={searchTerms}
CHR DefaultSearchKeyword: Default -> feed.sonic-search.com
CHR Profile: C:\Users\ptichun\AppData\Local\Google\Chrome\User Data\Default [2018-06-18]
CHR Extension: (Slides) - C:\Users\ptichun\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-24]
CHR Extension: (Docs) - C:\Users\ptichun\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-26]
CHR Extension: (Google Drive) - C:\Users\ptichun\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\ptichun\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-27]
CHR Extension: (Google Search) - C:\Users\ptichun\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28]
CHR Extension: (Tampermonkey) - C:\Users\ptichun\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2018-06-18]
CHR Extension: (Adobe Acrobat) - C:\Users\ptichun\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-09-24]
CHR Extension: (Browser Hunt) - C:\Users\ptichun\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdckocnfhibclnnkifmjbbogcfkbijki [2017-09-11]
CHR Extension: (Sheets) - C:\Users\ptichun\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-24]
CHR Extension: (Google Docs Offline) - C:\Users\ptichun\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-16]
CHR Extension: (Skype) - C:\Users\ptichun\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2018-05-06]
CHR Extension: (Mountain Browse) - C:\Users\ptichun\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhgknfkfipiflalfpihaicjijikenfoj [2017-09-11]
CHR Extension: (Chrome Web Store Payments) - C:\Users\ptichun\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-09-11]
CHR Extension: (Simple Finder Multi Region) - C:\Users\ptichun\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbdpajcdgknpendpmecafmopknefafha [2018-06-18]
CHR Extension: (Gmail) - C:\Users\ptichun\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-09-27]
CHR Extension: (Chrome Media Router) - C:\Users\ptichun\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-05-06]
CHR Extension: (System Table) - C:\Users\ptichun\AppData\Local\Google\Chrome\User Data\Default\SystemTable\1.2_0 [2018-06-18]
CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2101005229-1017427555-4036206314-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo] - hxxp://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [14336 2009-03-27] (LSI Corporation)
R2 AGSService; C:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe [2319848 2018-01-05] (Adobe Systems, Incorporated)
R2 cfWiMAXService; C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [181616 2009-07-17] (TOSHIBA CORPORATION)
R2 ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [46448 2009-03-10] (TOSHIBA CORPORATION)
S2 dbupdate; C:\Program Files\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.)
R2 DbxSvc; C:\windows\system32\DbxSvc.exe [43344 2018-06-04] (Dropbox, Inc.)
R2 D_Link_DWA-125; C:\Program Files\D-Link\DWA-125 revA\ANIWZCSdS.exe [126976 2009-08-21] (Wireless Service) [File not signed]
R2 D_Link_DWA-125_WPS; C:\Program Files\D-Link\DWA-125 revA\ANIWConnService.exe [40960 2009-07-07] () [File not signed]
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [96768 2012-06-27] (Freemake) [File not signed]
R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL [694784 2009-09-20] (Hewlett-Packard Co.) [File not signed]
S3 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [97432 2007-04-13] () [File not signed]
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.717\McCHSvc.exe [322792 2018-03-26] (McAfee, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation)
R2 Net Driver HPZ12; C:\windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-23] (Microsoft Corporation)
S2 pgt_svc; C:\Program Files\ProxyGate\MainService.exe [2285664 2017-02-22] (Gold Click Ltd) <==== ATTENTION
R2 Pml Driver HPZ12; C:\windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
R2 RSELSVC; C:\Program Files\TOSHIBA\RSelect\RSelSvc.exe [62832 2009-07-07] (TOSHIBA Corporation)
S2 saiyitechnology; C:\ProgramData\yahoochrome_D\desktop186.exe [517432 2018-05-21] (PandaViewer)
S3 TMachInfo; C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [51512 2009-08-17] (TOSHIBA Corporation)
R2 TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [181616 2009-08-10] (TOSHIBA Corporation)
S3 TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [111960 2009-08-03] (TOSHIBA Corporation)
S3 TPCHSrv; C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [685424 2009-08-06] (TOSHIBA Corporation)
S3 WsDrvInst; C:\Program Files\Keepvid\KeepVid KeepVid Pro\DriverInstall.exe [109688 2018-02-02] (Wondershare)
S2 gupdate; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files\Google\Update\GoogleUpdate.exe" /medsvc [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 anodlwf; C:\windows\System32\DRIVERS\anodlwf.sys [12800 2009-03-06] ()
R0 LPCFilter; C:\windows\System32\DRIVERS\LPCFilter.sys [36208 2009-07-02] (COMPAL ELECTRONIC INC.)
R0 MpFilter; C:\windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation)
S3 Netaapl; C:\windows\System32\DRIVERS\netaapl.sys [18432 2011-08-02] (Apple Inc.) [File not signed]
R3 netr28u; C:\windows\System32\DRIVERS\Dnetr28u.sys [807936 2009-09-15] (Ralink Technology Corp.)
R3 PGEffect; C:\windows\System32\DRIVERS\pgeffect.sys [24064 2009-06-22] (TOSHIBA Corporation)
S3 s117bus; C:\windows\System32\DRIVERS\s117bus.sys [82984 2007-06-25] (MCCI Corporation)
S3 s117mdfl; C:\windows\System32\DRIVERS\s117mdfl.sys [14888 2007-06-25] (MCCI Corporation)
S3 s117mdm; C:\windows\System32\DRIVERS\s117mdm.sys [108456 2007-06-25] (MCCI Corporation)
S3 s117mgmt; C:\windows\System32\DRIVERS\s117mgmt.sys [100264 2007-06-25] (MCCI Corporation)
S3 s117nd5; C:\windows\System32\DRIVERS\s117nd5.sys [22952 2007-06-25] (MCCI Corporation)
S3 s117obex; C:\windows\System32\DRIVERS\s117obex.sys [98344 2007-06-25] (MCCI Corporation)
S3 s117unic; C:\windows\System32\DRIVERS\s117unic.sys [98856 2007-06-25] (MCCI Corporation)
R2 TVALZFL; C:\windows\System32\DRIVERS\TVALZFL.sys [12920 2009-06-19] (TOSHIBA Corporation)
U0 aswVmm; no ImagePath
S3 dbx; system32\DRIVERS\dbx.sys [X]
S1 netfilter2; system32\drivers\netfilter2.sys [X]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-06-19 14:06 - 2018-06-19 14:20 - 000030051 _____ C:\Users\ptichun\Downloads\FRST.txt
2018-06-19 14:04 - 2018-06-19 14:06 - 000000000 ____D C:\FRST
2018-06-19 14:01 - 2018-06-19 14:02 - 001773568 _____ (Farbar) C:\Users\ptichun\Downloads\FRST.exe
2018-06-19 07:11 - 2018-06-19 07:11 - 000748192 _____ (TechGuy, Inc.) C:\Users\ptichun\Downloads\SysInfo(2).exe
2018-06-19 07:09 - 2018-06-19 07:09 - 000748192 _____ (TechGuy, Inc.) C:\Users\ptichun\Downloads\SysInfo(1).exe
2018-06-19 06:03 - 2018-06-19 06:12 - 002709624 _____ C:\windows\ntbtlog.txt
2018-06-18 18:55 - 2018-06-18 18:55 - 000000000 ____D C:\Users\ptichun\AppData\Local\ImpaqSpeed
2018-06-18 18:44 - 2018-06-19 06:09 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\kjq1vcdpyl0
2018-06-18 18:44 - 2018-06-19 06:09 - 000000000 ____D C:\Program Files\NCWS1MPIV7
2018-06-18 18:27 - 2018-06-18 18:27 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\OneSystemCare
2018-06-18 18:27 - 2018-06-18 18:27 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\FastDataX
2018-06-18 18:25 - 2018-06-18 18:25 - 000145456 _____ C:\windows\Minidump\061818-71791-01.dmp
2018-06-18 09:21 - 2018-06-18 16:55 - 000082432 _____ (ahjqtbs) C:\Users\ptichun\AppData\Roaming\command.dll
2018-06-18 07:36 - 2018-06-18 07:36 - 000000000 ____D C:\Users\Public\Documents\XMUpdate
2018-06-18 07:29 - 2018-06-18 07:46 - 000000000 ____D C:\Program Files\CY7UKLC70G
2018-06-18 06:38 - 2018-06-19 06:09 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\uf3r21up1fz
2018-06-18 06:38 - 2018-06-19 06:09 - 000000000 ____D C:\Program Files\74B1NTFBRT
2018-06-18 06:30 - 2018-06-18 06:30 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\se4whuag0ky
2018-06-18 06:30 - 2018-06-18 06:30 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\f4rbsw5zee1
2018-06-18 06:29 - 2018-06-18 06:30 - 000000000 ____D C:\Program Files\ZL9TZMZ5PE
2018-06-18 06:29 - 2018-06-18 06:30 - 000000000 ____D C:\Program Files\M41QM9F4J5
2018-06-18 06:28 - 2018-06-19 06:09 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\qhtybw0wvmx
2018-06-18 06:28 - 2018-06-19 06:09 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\moztjnjsxyu
2018-06-18 06:28 - 2018-06-19 06:09 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\e32exah2ukl
2018-06-18 06:27 - 2018-06-19 06:09 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\c5koq5i2kl1
2018-06-18 06:23 - 2018-06-18 06:23 - 000000000 ____D C:\Program Files\ZP5JQ90FKY
2018-06-18 06:15 - 2018-06-19 06:09 - 000000000 ____D C:\Program Files\AT31O40NII
2018-06-18 06:14 - 2018-06-19 06:09 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\5k4lcptyol1
2018-06-18 06:14 - 2018-06-19 06:09 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\3z5gjlt5qci
2018-06-18 06:14 - 2018-06-18 06:15 - 000000000 ____D C:\Program Files\4OV5D3E3ZM
2018-06-18 06:14 - 2018-06-18 06:14 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\spog5xmyzlf
2018-06-18 06:09 - 2018-06-18 06:09 - 002948240 _____ (BitTorrent Inc.) C:\Users\ptichun\Incredibles 2 2018 NEW HDCAM X264
2018-06-18 06:07 - 2018-06-18 06:07 - 000000012 _____ C:\windows\b8998883
2018-06-18 06:06 - 2018-06-18 06:07 - 000000000 ____D C:\Program Files\ProxyGate
2018-06-18 06:06 - 2018-06-18 06:06 - 000000000 ___HD C:\Program Files\postural
2018-06-18 06:06 - 2018-06-18 06:06 - 000000000 ___HD C:\Program Files\Groundstrokes
2018-06-18 06:06 - 2018-06-18 06:06 - 000000000 ____D C:\Program Files\obo
2018-06-18 06:05 - 2018-06-18 06:05 - 000000000 ____D C:\Program Files\schelling
2018-06-18 06:05 - 2018-06-18 06:05 - 000000000 ____D C:\Program Files\Hexagon
2018-06-18 06:05 - 2018-06-18 06:05 - 000000000 ____D C:\Program Files\Dissatisfied
2018-06-18 06:04 - 2018-06-18 18:46 - 000000000 ____D C:\ProgramData\yahoochrome_D
2018-06-18 06:04 - 2018-06-18 06:05 - 000000000 ____D C:\Users\ptichun\AppData\Local\Package Cache
2018-06-18 06:03 - 2018-06-18 06:03 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\w3bxmavwtvf
2018-06-18 06:03 - 2018-06-18 06:03 - 000000000 ____D C:\Program Files\L1L39K74D5
2018-06-18 06:02 - 2018-06-19 06:09 - 000000000 ____D C:\Program Files\0756KZBAPD
2018-06-18 06:02 - 2018-06-18 06:43 - 000000000 ____D C:\Program Files\Multitimer
2018-06-18 06:01 - 2018-06-19 06:09 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\acnfk1yolmo
2018-06-18 06:01 - 2018-06-19 06:09 - 000000000 ____D C:\Program Files\AAAZZZ
2018-06-18 06:01 - 2018-06-19 06:09 - 000000000 ____D C:\Program Files\7IYDGNJIHD
2018-06-18 06:00 - 2018-06-19 06:09 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\gpezmwclh54
2018-06-18 06:00 - 2018-06-19 06:09 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\3nwf3zdl1oa
2018-06-18 06:00 - 2018-06-19 06:09 - 000000000 ____D C:\Program Files\HLQVFPEM5V
2018-06-18 06:00 - 2018-06-18 06:00 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\5a55opst0te
2018-06-18 05:59 - 2018-06-19 06:09 - 000000000 ____D C:\Program Files\U33K7RH5VK
2018-06-18 05:58 - 2018-06-19 06:25 - 000000000 ____D C:\Program Files\AnonymizerGadget
2018-06-18 05:58 - 2018-06-19 06:24 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\WidModule
2018-06-18 05:58 - 2018-06-19 06:10 - 000000000 ____D C:\Program Files\ios0vrked4g
2018-06-18 05:58 - 2018-06-19 06:09 - 000000000 ____D C:\Program Files\85ZBGYIRU1
2018-06-18 05:58 - 2018-06-18 06:48 - 000000000 ____D C:\Program Files\cleanComputerNew
2018-06-18 05:58 - 2018-06-18 06:06 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\AGData
2018-06-18 05:57 - 2018-06-18 05:57 - 000001094 _____ C:\Users\ptichun\Desktop\Adult Dating.lnk
2018-06-18 05:57 - 2018-06-18 05:57 - 000001090 _____ C:\Users\ptichun\Desktop\Play Warframe.lnk
2018-06-18 05:57 - 2018-06-18 05:57 - 000001090 _____ C:\Users\ptichun\Desktop\Play Crossout.lnk
2018-06-18 05:57 - 2018-06-18 05:57 - 000001086 _____ C:\Users\ptichun\Desktop\Win iPhone X.lnk
2018-06-18 05:50 - 2018-06-18 05:50 - 000763096 _____ (WinZip Computing, S.L.) C:\Users\ptichun\Downloads\winzip22.exe
2018-06-18 05:28 - 2018-06-18 05:28 - 000732164 _____ C:\Users\ptichun\Downloads\Incredibles_2_2018_NEW_HDCAM_X264.rar
2018-06-18 03:38 - 2018-06-18 03:38 - 000203264 _____ C:\windows\grail.exe
2018-06-18 03:38 - 2018-06-18 03:38 - 000203264 _____ C:\Users\ptichun\AppData\Local\Quayside.exe
2018-06-18 03:38 - 2018-06-18 03:38 - 000203264 _____ C:\Users\ptichun\AppData\Local\Latham.exe
2018-06-13 13:08 - 2018-06-13 13:08 - 000000000 ____D C:\Users\ptichun\Downloads\The.Incredibles.2.DVDrip
2018-06-13 12:55 - 2018-06-13 12:58 - 000000000 ____D C:\Users\ptichun\Downloads\The Incredibles (2004)
2018-06-13 09:58 - 2018-05-29 12:40 - 000348824 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2018-06-13 09:58 - 2018-05-28 19:32 - 004050624 _____ (Microsoft Corporation) C:\windows\system32\ntkrnlpa.exe
2018-06-13 09:58 - 2018-05-28 19:32 - 003962048 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2018-06-13 09:58 - 2018-05-28 19:32 - 000189632 _____ (Microsoft Corporation) C:\windows\system32\halmacpi.dll
2018-06-13 09:58 - 2018-05-28 19:32 - 000189632 _____ (Microsoft Corporation) C:\windows\system32\hal.dll
2018-06-13 09:58 - 2018-05-28 19:32 - 000137920 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2018-06-13 09:58 - 2018-05-28 19:32 - 000136384 _____ (Microsoft Corporation) C:\windows\system32\halacpi.dll
2018-06-13 09:58 - 2018-05-28 19:32 - 000067264 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2018-06-13 09:58 - 2018-05-28 19:25 - 001310480 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2018-06-13 09:58 - 2018-05-28 19:22 - 001063424 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2018-06-13 09:58 - 2018-05-28 19:22 - 000655360 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2018-06-13 09:58 - 2018-05-28 19:22 - 000644096 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2018-06-13 09:58 - 2018-05-28 19:22 - 000554496 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2018-06-13 09:58 - 2018-05-28 19:22 - 000082432 _____ (Microsoft Corporation) C:\windows\system32\bcrypt.dll
2018-06-13 09:58 - 2018-05-28 19:01 - 000107520 _____ (Microsoft Corporation) C:\windows\system32\Drivers\videoprt.sys
2018-06-13 09:58 - 2018-05-28 18:59 - 000124928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2018-06-13 09:58 - 2018-05-28 18:58 - 000069632 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2018-06-13 09:58 - 2018-05-28 17:04 - 000535616 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2018-06-13 09:58 - 2018-05-24 21:34 - 020286976 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2018-06-13 09:58 - 2018-05-24 21:16 - 000499712 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2018-06-13 09:58 - 2018-05-24 21:15 - 000341504 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2018-06-13 09:58 - 2018-05-24 21:12 - 002295296 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2018-06-13 09:58 - 2018-05-24 21:09 - 000047104 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2018-06-13 09:58 - 2018-05-24 21:07 - 000476160 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2018-06-13 09:58 - 2018-05-24 21:06 - 000662016 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2018-06-13 09:58 - 2018-05-24 21:05 - 000620032 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2018-06-13 09:58 - 2018-05-24 21:05 - 000115712 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2018-06-13 09:58 - 2018-05-24 20:59 - 000668160 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2018-06-13 09:58 - 2018-05-24 20:57 - 000416256 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2018-06-13 09:58 - 2018-05-24 20:49 - 000168960 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2018-06-13 09:58 - 2018-05-24 20:48 - 000076288 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2018-06-13 09:58 - 2018-05-24 20:47 - 000279040 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2018-06-13 09:58 - 2018-05-24 20:45 - 000130048 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2018-06-13 09:58 - 2018-05-24 20:42 - 004496896 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2018-06-13 09:58 - 2018-05-24 20:40 - 000230400 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2018-06-13 09:58 - 2018-05-24 20:39 - 000696320 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2018-06-13 09:58 - 2018-05-24 20:38 - 013679616 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2018-06-13 09:58 - 2018-05-24 20:38 - 002060288 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2018-06-13 09:58 - 2018-05-24 20:38 - 000692224 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2018-06-13 09:58 - 2018-05-24 20:37 - 001155072 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2018-06-13 09:58 - 2018-05-24 20:19 - 002767872 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2018-06-13 09:58 - 2018-05-24 20:15 - 001314304 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2018-06-13 09:58 - 2018-05-24 20:14 - 000710144 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2018-06-13 09:58 - 2018-05-14 20:44 - 001214656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2018-06-13 09:58 - 2018-05-14 20:13 - 003207168 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
2018-06-13 09:58 - 2018-05-14 20:13 - 000782848 _____ (Microsoft Corporation) C:\windows\system32\webservices.dll
2018-06-13 09:58 - 2018-05-14 20:13 - 000103424 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2018-06-13 09:58 - 2018-05-14 20:13 - 000002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
2018-06-13 09:58 - 2018-05-14 20:01 - 000023040 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
2018-06-13 09:58 - 2018-05-14 18:09 - 000410080 _____ (Microsoft Corporation) C:\windows\system32\ci.dll
2018-06-13 09:58 - 2018-05-14 18:09 - 000374872 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2018-06-13 09:58 - 2018-05-11 18:56 - 000056320 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidclass.sys
2018-06-13 09:58 - 2018-05-11 18:56 - 000025984 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidparse.sys
2018-06-13 09:58 - 2018-05-11 18:56 - 000024064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidusb.sys
2018-06-13 09:58 - 2018-05-10 17:40 - 000741888 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2018-06-13 09:58 - 2018-05-10 17:39 - 000084992 _____ (Microsoft Corporation) C:\windows\system32\hlink.dll
2018-06-13 09:58 - 2018-04-06 09:38 - 000002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2018-06-13 09:57 - 2018-05-28 19:22 - 000690688 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2018-06-13 09:57 - 2018-05-28 19:22 - 000400896 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2018-06-13 09:57 - 2018-05-28 19:22 - 000261120 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2018-06-13 09:57 - 2018-05-28 19:22 - 000254464 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2018-06-13 09:57 - 2018-05-28 19:22 - 000223232 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2018-06-13 09:57 - 2018-05-28 19:22 - 000172032 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2018-06-13 09:57 - 2018-05-28 19:22 - 000146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2018-06-13 09:57 - 2018-05-28 19:22 - 000141312 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll
2018-06-13 09:57 - 2018-05-28 19:22 - 000099840 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2018-06-13 09:57 - 2018-05-28 19:22 - 000070144 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2018-06-13 09:57 - 2018-05-28 19:22 - 000060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2018-06-13 09:57 - 2018-05-28 19:22 - 000050688 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2018-06-13 09:57 - 2018-05-28 19:22 - 000050176 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2018-06-13 09:57 - 2018-05-28 19:22 - 000043008 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2018-06-13 09:57 - 2018-05-28 19:22 - 000038912 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2018-06-13 09:57 - 2018-05-28 19:22 - 000022016 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2018-06-13 09:57 - 2018-05-28 19:22 - 000017408 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2018-06-13 09:57 - 2018-05-28 19:22 - 000007168 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2018-06-13 09:57 - 2018-05-28 19:03 - 000097792 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2018-06-13 09:57 - 2018-05-28 19:03 - 000050688 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2018-06-13 09:57 - 2018-05-28 19:03 - 000050688 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2018-06-13 09:57 - 2018-05-28 19:03 - 000029696 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2018-06-13 09:57 - 2018-05-28 19:03 - 000016896 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2018-06-13 09:57 - 2018-05-28 19:01 - 000262656 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2018-06-13 09:57 - 2018-05-28 18:59 - 000226304 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2018-06-13 09:57 - 2018-05-28 18:59 - 000098304 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2018-06-13 09:57 - 2018-05-28 18:58 - 000036352 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2018-06-13 09:57 - 2018-05-28 18:58 - 000022016 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2018-06-13 09:57 - 2018-05-28 18:58 - 000015872 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2018-06-13 09:57 - 2018-05-24 21:28 - 002724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2018-06-13 09:57 - 2018-05-24 21:28 - 000004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2018-06-13 09:57 - 2018-05-24 21:16 - 000062464 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2018-06-13 09:57 - 2018-05-24 21:15 - 000047616 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2018-06-13 09:57 - 2018-05-24 21:14 - 000064000 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2018-06-13 09:57 - 2018-05-24 21:08 - 000030720 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2018-06-13 09:57 - 2018-05-24 21:06 - 000104960 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2018-06-13 09:57 - 2018-05-24 20:52 - 000073216 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
2018-06-13 09:57 - 2018-05-24 20:52 - 000060416 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2018-06-13 09:57 - 2018-05-24 20:51 - 000091136 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2018-06-13 09:57 - 2018-05-14 20:01 - 000050176 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
2018-06-13 09:57 - 2018-05-10 17:40 - 000084480 _____ (Microsoft Corporation) C:\windows\system32\INETRES.dll
2018-06-09 18:34 - 2018-06-09 18:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2018-06-07 19:36 - 2018-06-07 19:36 - 067752149 _____ C:\Users\ptichun\Downloads\Forensic Files - Season 9, Ep 10_ Head Games.mp4
2018-06-07 19:11 - 2018-06-07 19:11 - 067428038 _____ C:\Users\ptichun\Downloads\Forensic Files - Season 12, Ep 5_ Quite a Spectacle.mp4
2018-06-07 13:08 - 2018-06-07 13:08 - 054842706 _____ C:\Users\ptichun\Downloads\What Does Not Guilty By Reason Of Insanity Mean.mp4
2018-06-07 12:41 - 2018-06-07 12:44 - 292067548 _____ C:\Users\ptichun\Downloads\CSI_ Reality! Real life Forensic Psychiatrist Tara Straker talks criminals.mp4
2018-06-07 12:34 - 2018-06-07 12:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2018-06-05 19:25 - 2018-06-05 19:26 - 084553979 _____ C:\Users\ptichun\Downloads\Forensic Files - Season 2 Ep 6_ The Blood Trail.mp4
2018-06-05 19:17 - 2018-06-05 19:18 - 081292653 _____ C:\Users\ptichun\Downloads\Forensic Files - Season 2 Ep 4_ Sex, Lies, and DNA.mp4
2018-06-05 16:38 - 2018-06-05 16:39 - 153315200 _____ C:\Users\ptichun\Downloads\Forensic Files in HD - Season 13 Ep 20_ DNA Dragnet.mp4
2018-06-05 16:28 - 2018-06-05 16:28 - 000000000 ____D C:\Program Files\Common Files\Avast Software
2018-06-05 06:13 - 2018-06-05 06:15 - 156298723 _____ C:\Users\ptichun\Downloads\DNA The Secret of Photo 51.mp4
2018-06-04 03:18 - 2018-06-04 03:18 - 000043344 _____ (Dropbox, Inc.) C:\windows\system32\DbxSvc.exe
2018-06-04 03:18 - 2018-06-04 03:18 - 000038968 _____ (Dropbox, Inc.) C:\windows\system32\Drivers\dbx-dev.sys
2018-06-04 03:18 - 2018-06-04 03:18 - 000035432 _____ (Dropbox, Inc.) C:\windows\system32\Drivers\dbx-canary.sys
2018-06-04 03:18 - 2018-06-04 03:18 - 000035408 _____ (Dropbox, Inc.) C:\windows\system32\Drivers\dbx-stable.sys
2018-06-03 18:50 - 2018-06-03 19:12 - 035851785 _____ C:\Users\ptichun\Downloads\Forensic Files Death By Poison Dessert Served Cold 2.mp4
2018-06-03 18:46 - 2018-06-03 19:11 - 042949657 _____ C:\Users\ptichun\Downloads\Forensic Files Death By Poison Dessert Served Cold 1.mp4
2018-06-03 18:26 - 2018-06-03 19:10 - 091985802 _____ C:\Users\ptichun\Downloads\Forensic Files_ Season 1 Ep 11 Outbreak.mp4
2018-06-03 09:07 - 2018-06-03 09:07 - 000001718 _____ C:\Users\Public\Desktop\iTunes.lnk
2018-06-03 09:07 - 2018-06-03 09:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2018-06-03 09:05 - 2018-06-03 09:07 - 000000000 ____D C:\Program Files\iTunes
2018-05-25 07:39 - 2018-05-25 08:03 - 047050226 _____ C:\Users\ptichun\Downloads\Balancing Chemical Equations Practice Problems.mp4
2018-05-25 07:18 - 2018-05-25 07:38 - 053286552 _____ C:\Users\ptichun\Downloads\Introduction to Balancing Chemical Equations.mp4
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-06-19 14:23 - 2010-08-02 00:20 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\Skype
2018-06-19 14:10 - 2014-09-03 10:46 - 000000000 ____D C:\Users\ptichun\Documents\Nogomet
2018-06-19 13:26 - 2015-06-11 13:14 - 000000898 _____ C:\windows\Tasks\DropboxUpdateTaskMachineUA.job
2018-06-19 10:25 - 2015-06-11 13:14 - 000000894 _____ C:\windows\Tasks\DropboxUpdateTaskMachineCore.job
2018-06-19 08:30 - 2009-07-13 21:34 - 000016304 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-06-19 08:30 - 2009-07-13 21:34 - 000016304 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-06-19 07:41 - 2016-09-25 09:03 - 000000000 ____D C:\Users\ptichun\AppData\LocalLow\Mozilla
2018-06-19 07:07 - 2011-05-29 18:00 - 000000000 ____D C:\Program Files\Canon
2018-06-19 07:04 - 2011-05-29 18:10 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\Canon
2018-06-19 07:00 - 2009-07-13 19:37 - 000000000 ____D C:\windows\inf
2018-06-19 06:39 - 2014-11-20 22:07 - 000000000 ____D C:\ProgramData\WinZip
2018-06-19 06:22 - 2017-10-24 19:13 - 000000382 _____ C:\windows\Tasks\FreeFileViewerUpdateChecker.job
2018-06-19 06:17 - 2011-10-06 00:08 - 000000007 _____ C:\windows\system32\ANIWZCSUSERNAME{DFD29AFC-4966-4800-9940-D36BB08AF495}
2018-06-19 06:17 - 2009-07-13 21:53 - 000000006 ____H C:\windows\Tasks\SA.DAT
2018-06-18 18:25 - 2014-11-16 12:16 - 000000000 ____D C:\windows\Minidump
2018-06-18 09:24 - 2016-03-21 09:15 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\Opera Software
2018-06-18 06:34 - 2017-06-10 06:33 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-06-18 06:34 - 2015-08-18 13:44 - 000000000 ____D C:\Program Files\Mozilla Maintenance Service
2018-06-18 06:32 - 2016-11-06 21:29 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\BitTorrent
2018-06-18 06:16 - 2011-12-03 20:04 - 000000000 ____D C:\Users\ptichun\AppData\Roaming\vlc
2018-06-18 06:09 - 2009-12-26 23:02 - 000000000 ____D C:\Users\ptichun
2018-06-18 05:58 - 2009-12-26 12:34 - 000000000 ____D C:\Program Files\Google
2018-06-17 23:24 - 2009-07-13 19:37 - 000000000 ____D C:\windows\rescache
2018-06-17 21:51 - 2009-12-26 12:21 - 000730532 _____ C:\windows\system32\PerfStringBackup.INI
2018-06-14 15:04 - 2016-10-07 11:57 - 000000000 ____D C:\Users\ptichun\Documents\My Scans
2018-06-14 14:38 - 2018-03-30 14:16 - 000000000 ____D C:\Users\ptichun\AppData\LocalLow\BitTorrent
2018-06-14 03:20 - 2013-07-10 10:59 - 000000000 ____D C:\windows\system32\MRT
2018-06-14 03:09 - 2017-10-11 22:52 - 130354992 ____C (Microsoft Corporation) C:\windows\system32\MRT-KB890830.exe
2018-06-14 03:09 - 2009-12-28 02:55 - 130354992 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2018-06-13 12:56 - 2016-11-06 21:31 - 000000887 _____ C:\Users\ptichun\Desktop\BitTorrent.lnk
2018-06-13 12:56 - 2016-11-06 21:31 - 000000867 _____ C:\Users\ptichun\AppData\Roaming\Microsoft\Windows\Start Menu\BitTorrent.lnk
2018-06-13 09:53 - 2015-05-03 11:39 - 000000000 ____D C:\Users\ptichun\Documents\My Filehippo Downloads
2018-06-13 06:47 - 2015-02-15 23:34 - 000846848 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe
2018-06-13 06:47 - 2015-02-15 23:34 - 000175616 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl
2018-06-13 06:47 - 2009-12-26 12:29 - 000000000 ____D C:\windows\system32\Macromed
2018-06-13 06:40 - 2013-02-21 16:56 - 000002141 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-06-13 06:40 - 2013-02-21 16:56 - 000002100 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-06-07 14:28 - 2016-11-06 20:40 - 000000000 ____D C:\Program Files\Common Files\AV
2018-06-07 12:35 - 2015-06-11 13:14 - 000000000 ____D C:\Program Files\Dropbox
2018-06-03 12:38 - 2011-12-03 19:53 - 000000999 _____ C:\Users\Public\Desktop\VLC media player.lnk
2018-06-03 09:07 - 2016-09-14 09:42 - 000000000 ____D C:\Program Files\iPod
==================== Files in the root of some directories =======
2016-11-06 20:26 - 2016-11-06 20:28 - 007299584 _____ () C:\Users\ptichun\AppData\Roaming\agent.dat
2011-10-05 23:44 - 2011-10-05 23:44 - 000000258 _____ () C:\Users\ptichun\AppData\Roaming\ANICONFIG_{BCB7DA77-C4C7-49FD-A240-0ABA917BDB77}.ini
2013-03-25 05:02 - 2015-01-27 19:35 - 000000258 _____ () C:\Users\ptichun\AppData\Roaming\ANICONFIG_{DFD29AFC-4966-4800-9940-D36BB08AF495}.ini
2011-10-06 00:09 - 2015-07-19 19:24 - 000003284 _____ () C:\Users\ptichun\AppData\Roaming\ANIWZCS{DFD29AFC-4966-4800-9940-D36BB08AF495}
2018-06-18 09:21 - 2018-06-18 16:55 - 000082432 _____ (ahjqtbs) C:\Users\ptichun\AppData\Roaming\command.dll
2016-11-06 20:24 - 2016-11-06 20:24 - 000140288 _____ () C:\Users\ptichun\AppData\Roaming\Installer.dat
2016-11-06 20:26 - 2016-11-06 20:28 - 000018432 _____ () C:\Users\ptichun\AppData\Roaming\Main.dat
2014-11-20 23:07 - 2015-02-08 11:08 - 000000194 _____ () C:\Users\ptichun\AppData\Roaming\WB.CFG
2010-05-15 12:16 - 2010-05-15 12:16 - 000000000 _____ () C:\Users\ptichun\AppData\Roaming\wklnhst.dat
2011-04-02 19:17 - 2011-04-02 19:17 - 000001550 ___SH () C:\Users\ptichun\AppData\Local\61am7kh612rw85n14158n8334sb5378m1c5h32
2015-09-27 09:08 - 2015-11-15 20:47 - 000183255 _____ () C:\Users\ptichun\AppData\Local\ars.cache
2015-09-27 09:08 - 2015-11-15 20:47 - 000441317 _____ () C:\Users\ptichun\AppData\Local\census.cache
2012-02-29 23:04 - 2018-04-18 16:03 - 000010240 _____ () C:\Users\ptichun\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-11-22 12:29 - 2014-12-17 01:07 - 000000001 _____ () C:\Users\ptichun\AppData\Local\DSI.DAT
2015-09-26 09:40 - 2015-09-26 09:40 - 000000036 _____ () C:\Users\ptichun\AppData\Local\housecall.guid.cache
2011-01-21 12:27 - 2011-01-21 12:27 - 000004096 ____H () C:\Users\ptichun\AppData\Local\keyfile3.drm
2018-06-18 03:38 - 2018-06-18 03:38 - 000203264 _____ () C:\Users\ptichun\AppData\Local\Latham.exe
2011-09-04 02:02 - 2011-09-04 02:02 - 000000000 _____ () C:\Users\ptichun\AppData\Local\Pnumog.bin
2011-09-04 02:02 - 2011-09-04 02:02 - 000000120 _____ () C:\Users\ptichun\AppData\Local\Pyegoxired.dat
2011-04-02 19:17 - 2011-04-02 19:17 - 000114688 ___SH (Microsoft Corporation) C:\Users\ptichun\AppData\Local\qgp.exe
2018-06-18 03:38 - 2018-06-18 03:38 - 000203264 _____ () C:\Users\ptichun\AppData\Local\Quayside.exe
2015-09-27 09:05 - 2015-11-15 20:43 - 000000010 _____ () C:\Users\ptichun\AppData\Local\sponge.last.runtime.cache
2015-11-05 23:05 - 2015-11-05 23:06 - 000000000 _____ () C:\Users\ptichun\AppData\Local\{3862AE44-B056-4D19-A9AE-2CE1126EBDB3}
2016-07-15 19:27 - 2016-07-15 19:27 - 000000000 _____ () C:\Users\ptichun\AppData\Local\{5AFA009C-BEA2-4175-AE4B-623C88EDD3C3}
2016-07-15 19:27 - 2016-07-15 19:27 - 000000000 _____ () C:\Users\ptichun\AppData\Local\{92397A79-A984-49F7-9392-161E9112C5B5}
Files to move or delete:
====================
C:\Program Files\Google\Chrome\Application\winhttp.dll
Some files in TEMP:
====================
2018-06-18 06:03 - 2018-06-18 06:03 - 001537784 _____ (BANANA SUMMER LIMITED) C:\Users\ptichun\AppData\Local\Temp\1529327006RlVtmpdown.exe
2018-06-18 07:30 - 2018-06-18 07:30 - 001537784 _____ (BANANA SUMMER LIMITED) C:\Users\ptichun\AppData\Local\Temp\1529332116RlVtmpdown.exe
2018-06-18 18:44 - 2018-06-18 18:45 - 001537784 _____ (BANANA SUMMER LIMITED) C:\Users\ptichun\AppData\Local\Temp\1529372696RlVtmpdown.exe
2018-06-18 05:57 - 2018-06-18 05:57 - 000920448 _____ () C:\Users\ptichun\AppData\Local\Temp\AnonymizerGadgetSetup.1.000.1680.exe
2018-06-18 05:57 - 2018-06-18 05:57 - 000450370 _____ (Chi5 ) C:\Users\ptichun\AppData\Local\Temp\global_installer.exe
2018-06-18 05:58 - 2018-06-18 05:58 - 000768253 _____ (qwVbBgK7gezpge4ICzVj ) C:\Users\ptichun\AppData\Local\Temp\installer.exe
2017-04-23 18:47 - 2017-04-23 18:47 - 000739904 _____ (Oracle Corporation) C:\Users\ptichun\AppData\Local\Temp\jre-8u131-windows-au.exe
2017-07-19 14:45 - 2017-07-19 14:45 - 000739904 _____ (Oracle Corporation) C:\Users\ptichun\AppData\Local\Temp\jre-8u141-windows-au.exe
2017-10-20 18:37 - 2017-10-20 18:37 - 001856576 _____ (Oracle Corporation) C:\Users\ptichun\AppData\Local\Temp\jre-8u151-windows-au.exe
2018-01-27 10:53 - 2018-01-27 10:53 - 001864256 _____ (Oracle Corporation) C:\Users\ptichun\AppData\Local\Temp\jre-8u161-windows-au.exe
2018-04-19 16:54 - 2018-04-19 16:54 - 001884616 _____ (Oracle Corporation) C:\Users\ptichun\AppData\Local\Temp\jre-8u171-windows-au.exe
2018-02-26 23:14 - 2018-02-26 23:22 - 081400536 _____ (KeepVid Studio ) C:\Users\ptichun\AppData\Local\Temp\keepvid-pro_full2578.exe
2018-06-19 07:04 - 2007-02-15 08:59 - 000308832 ____H (CANON INC.) C:\Users\ptichun\AppData\Local\Temp\Maint000.exe
2018-06-18 06:02 - 2018-06-18 06:02 - 000375522 _____ ( ) C:\Users\ptichun\AppData\Local\Temp\q2i3mrcvzix.exe
2018-04-10 20:30 - 2018-04-10 20:31 - 058834376 _____ (Skype Technologies S.A.) C:\Users\ptichun\AppData\Local\Temp\SkypeSetup.exe
2018-06-19 07:06 - 2007-05-14 09:01 - 000116328 _____ (CANON INC.) C:\Users\ptichun\AppData\Local\Temp\uninst.exe
2018-06-19 07:03 - 2007-01-05 17:10 - 000239200 ____R () C:\Users\ptichun\AppData\Local\Temp\uninstall.exe
2017-03-16 08:16 - 2017-03-16 08:17 - 014456872 _____ (Microsoft Corporation) C:\Users\ptichun\AppData\Local\Temp\vc_redist.x86.exe
2018-01-25 18:00 - 2018-01-25 18:00 - 000057346 _____ () C:\Users\ptichun\AppData\Local\Temp\{A126DDAB-F8EE-4019-8417-3D0F1A7B0149}-DropboxClient_42.4.114.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\windows\explorer.exe => File is digitally signed
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-06-17 23:15
==================== End of FRST.txt ============================