User Tag List

very, very slow

This is a discussion on very, very slow within the Resolved HJT Threads forums, part of the Tech Support Forum category. The su«ystem has fgon extremely slow. I trued to download dds from your link but I get nothing on the


 
 
Thread Tools Search this Thread
Old 03-17-2018, 08:35 AM   #1
Registered Member
 
Join Date: Dec 2006
Posts: 259
OS: Windows 10



The su«ystem has fgon extremely slow. I trued to download dds from your link but I get nothing on the new page...

Wk«hat should I do?

Thank you

qim
qimqim is offline  
Sponsored Links
Advertisement
 
Old 03-18-2018, 06:02 PM   #2
Security Team
Moderator, Analyst
Rangemaster, TSF Academy
 
chemist's Avatar

Microsoft Most Valuable Professional
 
Join Date: Oct 2007
Location: Georgia
Posts: 29,790
OS: XP/Win7/Win10



Hello and Welcome to TSF.

If you haven't already, please Subscribe to this Thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant notification by email, then click Add Subscription.

Please note that the forum is very busy and if I don't hear from you within three days this thread will be closed.

------------------------------------------------------

Please download AdwCleaner from here and save it to your desktop.
  • Run AdwCleaner and select Scan
  • Once the Scan is done, select Clean
  • Once done it will ask to reboot, please allow the reboot.
  • On reboot, a log will be produced. It can also be found at C:\AdwCleaner\AdwCleaner[C#].txt
  • Please copy/paste the contents of the log in your next reply.
------------------------------------------------------

Please download Farbar Recovery Scan Tool and save it to your desktop.
  • Double-click FRST64 to run it. When the tool opens click Yes to the disclaimer.
  • Make sure the Addition.txt button is ticked.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • It also makes another log (Addition.txt). Please attach it to your reply.
------------------------------------------------------
__________________
Our services are free, but you may contribute to the author of ComboFix via PayPal

Proud member of UNITE

Microsoft MVP - Consumer Security 2014, 2015
chemist is offline  
Old 03-19-2018, 06:17 AM   #3
Registered Member
 
Join Date: Dec 2006
Posts: 259
OS: Windows 10



Hi and thanks

I'm pastimng the AdwCleaner.

The other, First64.3exe. when I check the exe.file with VirusTotal it returns two scanners that say it has a suspicious engine. It is from trendMicro-HouseCall. Should I install it?

# AdwCleaner 7.0.8.0 - Logfile created on Mon Mar 19 1351 2018
# Updated on 2018/08/02 by Malwarebytes
# Running on Windows 10 Home (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services deleted.

***** [ Folders ] *****

No malicious folders deleted.

***** [ Files ] *****

No malicious files deleted.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks deleted.

***** [ Registry ] *****

No malicious registry entries deleted.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries deleted.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries deleted.

*************************

::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0



*************************

C:/AdwCleaner/AdwCleaner[S0].txt - [945 B] - [2018/3/19 13:0:42]


########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########
qimqim is offline  
Sponsored Links
Advertisement
 
Old 03-20-2018, 03:43 PM   #4
Security Team
Moderator, Analyst
Rangemaster, TSF Academy
 
chemist's Avatar

Microsoft Most Valuable Professional
 
Join Date: Oct 2007
Location: Georgia
Posts: 29,790
OS: XP/Win7/Win10



FRST64.exe is safe. Why would you question a tool I advised you to run?
__________________
Our services are free, but you may contribute to the author of ComboFix via PayPal

Proud member of UNITE

Microsoft MVP - Consumer Security 2014, 2015
chemist is offline  
Old 03-21-2018, 12:50 AM   #5
Registered Member
 
Join Date: Dec 2006
Posts: 259
OS: Windows 10



Thanks, here we are

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14.03.2018
Ran by Camilo (administrator) on CAMILO-PC (21-03-2018 07:43:12)
Running from C:\Users\Camilo\Desktop
Loaded Profiles: Camilo (Available Profiles: Camilo & UpdatusUser)
Platform: Windows 10 Home Version 1709 16299.309 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.3.1.1\WsAppService.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(HP Inc.) C:\Program Files\HP\HP Touchpoint Analytics Client\TouchpointAnalyticsClientService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Esumsoft) C:\Program Files (x86)\POP Peeper\POPPeeper.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\internet explorer\iexplore.exe
() C:\Program Files\WindowsApps\Microsoft.BingWeather_4.22.3254.0_x64__8wekyb3d8bbwe\Microsoft.Msn.Weather.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.9029.22105.0_x64__8wekyb3d8bbwe\HxCalendarAppImm.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.9029.22105.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1809.217.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18021.12420.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Corporation)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242200 2016-11-11] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [14030080 2015-08-05] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe [1971856 2016-10-24] ()
HKLM-x32\...\Run: [PSUAMain] => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe [144520 2017-07-19] (Panda Security, S.L.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-12-19] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2665017104-2237686660-164763984-1000\...\Run: [POP Peeper] => C:\Program Files (x86)\POP Peeper\POPPeeper.exe [2773168 2017-12-01] (Esumsoft)
HKU\S-1-5-21-2665017104-2237686660-164763984-1000\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1589592 2018-03-13] (Google Inc.)
HKU\S-1-5-21-2665017104-2237686660-164763984-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\Bubbles.scr [805888 2017-09-29] (Microsoft Corporation)
AppInit_DLLs: C:\WINDOWS\system32\DriverStore\FileRepository\nvsmwu.inf_amd64_40e2f893a8ddfad8\nvinitx.dll => C:\WINDOWS\system32\DriverStore\FileRepository\nvsmwu.inf_amd64_40e2f893a8ddfad8\nvinitx.dll [183144 2017-01-17] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\WINDOWS\system32\DriverStore\FileRepository\nvsmwu.inf_amd64_40e2f893a8ddfad8\nvinit.dll => C:\WINDOWS\System32\DriverStore\FileRepository\nvsmwu.inf_amd64_40e2f893a8ddfad8\nvinit.dll [161016 2017-01-17] (NVIDIA Corporation)
GroupPolicyScripts-x32: Restriction <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{11679750-d21a-44d1-8891-44048bbd542c}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{8808ba8a-d705-48d3-a16e-dff1c958c936}: [DhcpNameServer] 192.168.1.254

Internet Explorer:
==================
HKU\S-1-5-21-2665017104-2237686660-164763984-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.co.uk/?gws_rd=ssl
BHO-x32: AcroIEHlprObj Class -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files (x86)\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx [2001-04-16] ()
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\ssv.dll [2018-03-01] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\jp2ssv.dll [2018-03-01] (Oracle Corporation)
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab

Edge:
======
Edge HomeButtonPage: HKU\S-1-5-21-2665017104-2237686660-164763984-1000 -> hxxp://google.co.uk/

FireFox:
========
FF DefaultProfile: 1jggpe4f.default
FF ProfilePath: C:\Users\Camilo\AppData\Roaming\Mozilla\Firefox\Profiles\1jggpe4f.default [2018-03-19]
FF Homepage: Mozilla\Firefox\Profiles\1jggpe4f.default -> hxxps://www.google.co.uk/?gws_rd=ssl
FF Extension: (ADB Helper) - C:\Users\Camilo\AppData\Roaming\Mozilla\Firefox\Profiles\1jggpe4f.default\Extensions\[email protected] [2018-02-24] [Legacy]
FF Extension: (Firebug) - C:\Users\Camilo\AppData\Roaming\Mozilla\Firefox\Profiles\1jggpe4f.default\Extensions\[email protected] [2017-03-08] [Legacy]
FF Extension: (Valence) - C:\Users\Camilo\AppData\Roaming\Mozilla\Firefox\Profiles\1jggpe4f.default\Extensions\[email protected] [2017-08-07] [Legacy]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\ProgramData\Wondershare\Video Converter Ultimate\[email protected]_xpi
FF Extension: (Wondershare Video Converter Ultimate) - C:\ProgramData\Wondershare\Video Converter Ultimate\[email protected]_xpi [2016-11-18] [Legacy]
FF Plugin-x32: @Java.com/DTPlugin,version=11.161.2 -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\dtplugin\npDeployJava1.dll [2018-03-01] (Oracle Corporation)
FF Plugin-x32: @Java.com/JavaPlugin,version=11.161.2 -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\plugin2\npjp2.dll [2018-03-01] (Oracle Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-21] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-21] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-02-11] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2665017104-2237686660-164763984-1000: SkypePlugin -> C:\Users\Camilo\AppData\Local\SkypePlugin\7.32.6.278\npGatewayNpapi.dll [2017-04-18] (Skype Technologies S.A.)
FF Plugin HKU\S-1-5-21-2665017104-2237686660-164763984-1000: SkypePlugin64 -> C:\Users\Camilo\AppData\Local\SkypePlugin\7.32.6.278\npGatewayNpapi-x64.dll [2017-04-18] (Skype Technologies S.A.)

Chrome:
=======
CHR Profile: C:\Users\Camilo\AppData\Local\Google\Chrome\User Data\Default [2018-03-21]
CHR Extension: (Google Drive) - C:\Users\Camilo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-02-25]
CHR Extension: (YouTube) - C:\Users\Camilo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-02-25]
CHR Extension: (Transfer data • mozillaZine Forums) - C:\Users\Camilo\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmfgeiaighlaenofogaceniecknhlakn [2018-03-03]
CHR Extension: (Adobe Acrobat) - C:\Users\Camilo\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-05]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Camilo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22]
CHR Extension: (Gmail) - C:\Users\Camilo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-02-25]
CHR Extension: (Chrome Media Router) - C:\Users\Camilo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-03-14]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ETDService; C:\Program Files\Elantech\ETDService.exe [129752 2016-11-11] (ELAN Microelectronics Corp.)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [332144 2017-11-21] (HP Inc.)
R2 HPTouchpointAnalyticsService; C:\Program Files\HP\HP Touchpoint Analytics Client\TouchpointAnalyticsClientService.exe [332216 2017-11-26] (HP Inc.)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-21] (Malwarebytes)
R2 NanoServiceMain; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe [109024 2017-07-19] (Panda Security, S.L.)
R2 PandaAgent; C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe [86104 2016-07-19] (Panda Security, S.L.)
R2 PSUAService; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe [48784 2017-07-19] (Panda Security, S.L.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [355304 2017-09-29] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [105944 2017-09-29] (Microsoft Corporation)
R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.3.1.1\WsAppService.exe [437392 2016-10-10] (Wondershare)
R2 NvContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -a -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000
S3 NvContainerNetworkService; "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerNetworkService -f "C:\ProgramData\NVIDIA\NvContainerNetworkService.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\NetworkService" -r -p 30000
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [130688 2016-07-22] (Samsung Electronics Co., Ltd.)
R3 ETDSMBus; C:\WINDOWS\system32\DRIVERS\ETDSMBus.sys [32328 2015-09-21] (ELAN Microelectronic Corp.)
S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [252232 2018-03-14] (Malwarebytes)
R1 NNSALPC; C:\WINDOWS\system32\DRIVERS\NNSALPC.sys [106976 2017-04-07] (Panda Security, S.L.)
R1 NNSHTTP; C:\WINDOWS\system32\DRIVERS\NNSHTTP.sys [211936 2017-04-07] (Panda Security, S.L.)
R1 NNSHTTPS; C:\WINDOWS\system32\DRIVERS\NNSHTTPS.sys [121312 2017-04-07] (Panda Security, S.L.)
R1 NNSIDS; C:\WINDOWS\system32\DRIVERS\NNSIDS.sys [125920 2017-04-07] (Panda Security, S.L.)
R1 NNSNAHSL; C:\WINDOWS\system32\DRIVERS\NNSNAHSL.sys [89960 2017-03-17] (Panda Security, S.L.)
R1 NNSPICC; C:\WINDOWS\system32\DRIVERS\NNSPICC.sys [118240 2017-04-07] (Panda Security, S.L.)
R1 NNSPIHSW; C:\WINDOWS\system32\DRIVERS\NNSPIHSW.sys [91104 2017-04-07] (Panda Security, S.L.)
R1 NNSPOP3; C:\WINDOWS\system32\DRIVERS\NNSPOP3.sys [135648 2017-04-07] (Panda Security, S.L.)
R1 NNSPROT; C:\WINDOWS\system32\DRIVERS\NNSPROT.sys [336352 2017-04-07] (Panda Security, S.L.)
R1 NNSPRV; C:\WINDOWS\system32\DRIVERS\NNSPRV.sys [226272 2017-04-07] (Panda Security, S.L.)
R1 NNSSMTP; C:\WINDOWS\system32\DRIVERS\NNSSMTP.sys [123360 2017-04-07] (Panda Security, S.L.)
R1 NNSSTRM; C:\WINDOWS\system32\DRIVERS\NNSSTRM.sys [280032 2017-04-07] (Panda Security, S.L.)
R1 NNSTLSC; C:\WINDOWS\system32\DRIVERS\NNSTLSC.sys [125408 2017-04-07] (Panda Security, S.L.)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvsmwu.inf_amd64_40e2f893a8ddfad8\nvlddmkm.sys [14190520 2017-01-17] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2017-02-23] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [46016 2017-02-23] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [57792 2017-02-23] (NVIDIA Corporation)
R2 PSINAflt; C:\WINDOWS\system32\DRIVERS\PSINAflt.sys [179168 2017-07-19] (Panda Security, S.L.)
R2 PSINFile; C:\WINDOWS\System32\DRIVERS\PSINFile.sys [140256 2017-07-19] (Panda Security, S.L.)
R1 PSINKNC; C:\WINDOWS\system32\DRIVERS\PSINKNC.sys [207328 2017-07-19] (Panda Security, S.L.)
R2 PSINProc; C:\WINDOWS\System32\DRIVERS\PSINProc.sys [133600 2017-07-19] (Panda Security, S.L.)
R2 PSINProt; C:\WINDOWS\system32\DRIVERS\PSINProt.sys [146912 2017-07-19] (Panda Security, S.L.)
R2 PSINReg; C:\WINDOWS\system32\DRIVERS\PSINReg.sys [117216 2017-07-19] (Panda Security, S.L.)
U3 PSKMAD; C:\WINDOWS\System32\DRIVERS\PSKMAD.sys [72648 2017-05-22] (Panda Security, S.L.)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [604160 2017-09-29] (Realtek )
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44608 2017-09-29] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [309144 2017-09-29] (Microsoft Corporation)
S3 wdm_usb; C:\WINDOWS\system32\DRIVERS\usb2ser.sys [159936 2016-08-16] (MBB)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [119192 2017-09-29] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-03-21 07:43 - 2018-03-21 07:44 - 000017671 _____ C:\Users\Camilo\Desktop\FRST.txt
2018-03-21 07:42 - 2018-03-21 07:43 - 000000000 ____D C:\FRST
2018-03-19 15:18 - 2018-03-19 15:18 - 000000000 ___HD C:\OneDriveTemp
2018-03-19 13:13 - 2018-03-19 13:12 - 002403328 _____ (Farbar) C:\Users\Camilo\Desktop\FRST64.exe
2018-03-19 13:12 - 2018-03-19 13:12 - 002403328 _____ (Farbar) C:\Users\Camilo\Downloads\FRST64.exe
2018-03-19 13:10 - 2018-03-19 13:10 - 000001130 _____ C:\Users\Camilo\Desktop\AdwCleaner[C0].txt
2018-03-19 12:58 - 2018-03-19 13:06 - 000000000 ____D C:\AdwCleaner
2018-03-19 12:57 - 2018-03-19 12:51 - 008222496 _____ (Malwarebytes) C:\Users\Camilo\Desktop\AdwCleaner.exe
2018-03-19 12:50 - 2018-03-19 12:51 - 008222496 _____ (Malwarebytes) C:\Users\Camilo\Downloads\AdwCleaner.exe
2018-03-19 09:27 - 2018-03-19 09:27 - 000000233 _____ C:\Users\Camilo\Desktop\VED Rates 2018 DVLA Vehicle Tax Bands Table.url
2018-03-17 20:19 - 2018-03-17 20:19 - 006968952 _____ (ESET spol. s r.o.) C:\Users\Camilo\Downloads\esetonlinescanner_enu.exe
2018-03-17 15:32 - 2018-03-17 15:32 - 000688992 _____ (Swearware) C:\Users\Camilo\Downloads\dds (1).scr
2018-03-17 15:30 - 2018-03-17 15:30 - 000688992 _____ (Swearware) C:\Users\Camilo\Downloads\dds.scr
2018-03-17 12:20 - 2018-03-17 12:20 - 000793098 _____ C:\Users\Camilo\Desktop\Regulamento de Autoridade Portuária da APL.pdf
2018-03-15 15:38 - 2018-03-15 15:38 - 000000213 _____ C:\Users\Camilo\Desktop\BACHATA - BASIC (Beginning Level) - YouTube.url
2018-03-14 11:21 - 2018-03-01 07:31 - 008602520 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-03-14 11:21 - 2018-03-01 07:29 - 000733592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2018-03-14 11:21 - 2018-03-01 07:23 - 000749976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2018-03-14 11:21 - 2018-03-01 07:17 - 002710736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2018-03-14 11:21 - 2018-03-01 07:17 - 000408984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2018-03-14 11:21 - 2018-03-01 07:14 - 007384576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-03-14 11:21 - 2018-03-01 07:14 - 000147872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
2018-03-14 11:21 - 2018-03-01 07:11 - 000093600 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2018-03-14 11:21 - 2018-03-01 07:10 - 000075168 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2018-03-14 11:21 - 2018-03-01 06:48 - 001930736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2018-03-14 11:21 - 2018-03-01 06:30 - 005615968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2018-03-14 11:21 - 2018-03-01 06:28 - 006480616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-03-14 11:21 - 2018-03-01 06:28 - 002193168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2018-03-14 11:21 - 2018-03-01 06:26 - 001524776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2018-03-14 11:21 - 2018-03-01 06:26 - 001057816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2018-03-14 11:21 - 2018-03-01 06:21 - 001558856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2018-03-14 11:21 - 2018-03-01 06:03 - 002902528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-03-14 11:21 - 2018-03-01 06:03 - 000471552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcSpecfc.dll
2018-03-14 11:21 - 2018-03-01 06:03 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2018-03-14 11:21 - 2018-03-01 06:03 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2018-03-14 11:21 - 2018-03-01 06:03 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2018-03-14 11:21 - 2018-03-01 06:01 - 019354624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-03-14 11:21 - 2018-03-01 06:01 - 006575616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2018-03-14 11:21 - 2018-03-01 06:01 - 000155648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2018-03-14 11:21 - 2018-03-01 05:58 - 004839424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2018-03-14 11:21 - 2018-03-01 05:58 - 000459776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2018-03-14 11:21 - 2018-03-01 05:57 - 000369152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2018-03-14 11:21 - 2018-03-01 05:56 - 018922496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2018-03-14 11:21 - 2018-03-01 05:56 - 000559104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2018-03-14 11:21 - 2018-03-01 05:54 - 003664384 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-03-14 11:21 - 2018-03-01 05:54 - 000665088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2018-03-14 11:21 - 2018-03-01 05:54 - 000463360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2018-03-14 11:21 - 2018-03-01 05:53 - 000536576 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2018-03-14 11:21 - 2018-03-01 05:52 - 011923968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2018-03-14 11:21 - 2018-03-01 05:52 - 006030336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2018-03-14 11:21 - 2018-03-01 05:51 - 000034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
2018-03-14 11:21 - 2018-03-01 05:50 - 003677184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-03-14 11:21 - 2018-03-01 05:50 - 002869760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2018-03-14 11:21 - 2018-03-01 05:45 - 000708096 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2018-03-14 11:21 - 2018-03-01 05:45 - 000594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2018-03-14 11:21 - 2018-03-01 05:43 - 012830208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2018-03-14 11:21 - 2018-03-01 05:42 - 002084352 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2018-03-14 11:21 - 2018-03-01 05:41 - 008103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2018-03-14 11:21 - 2018-03-01 05:41 - 004745728 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-03-14 11:21 - 2018-03-01 05:41 - 001548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-03-14 11:21 - 2018-03-01 05:41 - 000812032 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2018-03-14 11:21 - 2018-03-01 05:40 - 005833216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2018-03-14 11:21 - 2018-03-01 05:39 - 002035712 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2018-03-14 11:21 - 2018-03-01 05:39 - 000899584 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2018-03-14 11:21 - 2018-03-01 05:39 - 000666624 _____ (Microsoft Corporation) C:\WINDOWS\system32\DbgModel.dll
2018-03-14 11:21 - 2018-03-01 05:38 - 000963072 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2018-03-14 11:21 - 2018-03-01 05:38 - 000726016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2018-03-14 11:21 - 2018-02-22 02:13 - 000279456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys
2018-03-14 11:21 - 2018-02-22 02:13 - 000077216 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2018-03-14 11:21 - 2018-02-22 02:11 - 000109984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbus.sys
2018-03-14 11:21 - 2018-02-22 02:10 - 000285080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2018-03-14 11:21 - 2018-02-22 02:08 - 001055648 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2018-03-14 11:21 - 2018-02-22 02:08 - 000571288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2018-03-14 11:21 - 2018-02-22 02:03 - 000082848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
2018-03-14 11:21 - 2018-02-22 02:02 - 000149400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys
2018-03-14 11:21 - 2018-02-22 02:00 - 000187296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2018-03-14 11:21 - 2018-02-22 01:54 - 000437144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2018-03-14 11:21 - 2018-02-22 01:52 - 000103328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2018-03-14 11:21 - 2018-02-22 01:51 - 000555424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2018-03-14 11:21 - 2018-02-22 01:51 - 000045472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storufs.sys
2018-03-14 11:21 - 2018-02-22 01:50 - 000362904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2018-03-14 11:21 - 2018-02-22 00:31 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmUcsi.sys
2018-03-14 11:21 - 2018-02-22 00:30 - 000192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netvsc.sys
2018-03-14 11:21 - 2018-02-22 00:30 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys
2018-03-14 11:20 - 2018-03-02 03:36 - 017085440 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2018-03-14 11:20 - 2018-03-02 03:00 - 000329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Feedback.Analog.dll
2018-03-14 11:20 - 2018-03-02 03:00 - 000248320 _____ (Microsoft Corporation) C:\WINDOWS\system32\svf.dll
2018-03-14 11:20 - 2018-03-02 03:00 - 000230912 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloShellRuntime.dll
2018-03-14 11:20 - 2018-03-02 02:59 - 000956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe
2018-03-14 11:20 - 2018-03-01 07:50 - 000270744 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2018-03-14 11:20 - 2018-03-01 07:49 - 000389536 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2018-03-14 11:20 - 2018-03-01 07:48 - 000664472 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2018-03-14 11:20 - 2018-03-01 07:47 - 000749464 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2018-03-14 11:20 - 2018-03-01 07:47 - 000035224 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2018-03-14 11:20 - 2018-03-01 07:46 - 002003352 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2018-03-14 11:20 - 2018-03-01 07:46 - 001568664 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2018-03-14 11:20 - 2018-03-01 07:46 - 000609176 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2018-03-14 11:20 - 2018-03-01 07:46 - 000138144 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2018-03-14 11:20 - 2018-03-01 07:45 - 000070040 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2018-03-14 11:20 - 2018-03-01 07:40 - 002514936 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2018-03-14 11:20 - 2018-03-01 07:40 - 000461720 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2018-03-14 11:20 - 2018-03-01 07:40 - 000273304 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2018-03-14 11:20 - 2018-03-01 07:37 - 007831760 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2018-03-14 11:20 - 2018-03-01 07:30 - 000540064 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2018-03-14 11:20 - 2018-03-01 07:30 - 000264040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2018-03-14 11:20 - 2018-03-01 07:27 - 001173576 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2018-03-14 11:20 - 2018-03-01 07:26 - 000170912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2018-03-14 11:20 - 2018-03-01 07:25 - 000377752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msrpc.sys
2018-03-14 11:20 - 2018-03-01 07:19 - 000710768 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2018-03-14 11:20 - 2018-03-01 07:17 - 000519152 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2018-03-14 11:20 - 2018-03-01 07:15 - 002574232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2018-03-14 11:20 - 2018-03-01 07:14 - 007675784 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-03-14 11:20 - 2018-03-01 07:14 - 005105664 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthFWSnapin.dll
2018-03-14 11:20 - 2018-03-01 07:14 - 001694224 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2018-03-14 11:20 - 2018-03-01 07:14 - 000356952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2018-03-14 11:20 - 2018-03-01 07:14 - 000128928 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2018-03-14 11:20 - 2018-03-01 07:12 - 000677272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2018-03-14 11:20 - 2018-03-01 07:12 - 000250264 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
2018-03-14 11:20 - 2018-03-01 07:12 - 000189344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll
2018-03-14 11:20 - 2018-03-01 07:10 - 001779936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2018-03-14 11:20 - 2018-03-01 07:10 - 000022936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\isapnp.sys
2018-03-14 11:20 - 2018-03-01 07:09 - 001054272 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2018-03-14 11:20 - 2018-03-01 06:51 - 000777904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2018-03-14 11:20 - 2018-03-01 06:39 - 000213400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2018-03-14 11:20 - 2018-03-01 06:29 - 006092152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2018-03-14 11:20 - 2018-03-01 06:29 - 000574960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVideoDSP.dll
2018-03-14 11:20 - 2018-03-01 06:28 - 000115096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll
2018-03-14 11:20 - 2018-03-01 06:27 - 000284112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2018-03-14 11:20 - 2018-03-01 06:27 - 000221592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinesam.dll
2018-03-14 11:20 - 2018-03-01 06:23 - 005105664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthFWSnapin.dll
2018-03-14 11:20 - 2018-03-01 06:09 - 025251840 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-03-14 11:20 - 2018-03-01 06:00 - 000098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSpkg.dll
2018-03-14 11:20 - 2018-03-01 05:59 - 000220672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MicrosoftAccountWAMExtension.dll
2018-03-14 11:20 - 2018-03-01 05:58 - 000405504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Payments.dll
2018-03-14 11:20 - 2018-03-01 05:58 - 000368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2018-03-14 11:20 - 2018-03-01 05:55 - 000346112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
2018-03-14 11:20 - 2018-03-01 05:54 - 003181568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2018-03-14 11:20 - 2018-03-01 05:54 - 001296896 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2018-03-14 11:20 - 2018-03-01 05:54 - 000496128 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2018-03-14 11:20 - 2018-03-01 05:53 - 000863232 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2018-03-14 11:20 - 2018-03-01 05:53 - 000399872 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2018-03-14 11:20 - 2018-03-01 05:53 - 000246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2018-03-14 11:20 - 2018-03-01 05:53 - 000107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2018-03-14 11:20 - 2018-03-01 05:53 - 000097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatecsp.dll
2018-03-14 11:20 - 2018-03-01 05:53 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll
2018-03-14 11:20 - 2018-03-01 05:53 - 000056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcSpecfc.dll
2018-03-14 11:20 - 2018-03-01 05:51 - 002329088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVidCtl.dll
2018-03-14 11:20 - 2018-03-01 05:51 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2018-03-14 11:20 - 2018-03-01 05:50 - 000526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2018-03-14 11:20 - 2018-03-01 05:50 - 000118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSpkg.dll
2018-03-14 11:20 - 2018-03-01 05:50 - 000075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcnfs.sys
2018-03-14 11:20 - 2018-03-01 05:49 - 000675328 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2018-03-14 11:20 - 2018-03-01 05:49 - 000529408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2018-03-14 11:20 - 2018-03-01 05:49 - 000301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountWAMExtension.dll
2018-03-14 11:20 - 2018-03-01 05:49 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2018-03-14 11:20 - 2018-03-01 05:48 - 000543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicExtensions.dll
2018-03-14 11:20 - 2018-03-01 05:48 - 000431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2018-03-14 11:20 - 2018-03-01 05:47 - 023674368 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-03-14 11:20 - 2018-03-01 05:47 - 000579584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Payments.dll
2018-03-14 11:20 - 2018-03-01 05:47 - 000484352 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2018-03-14 11:20 - 2018-03-01 05:46 - 004051968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2018-03-14 11:20 - 2018-03-01 05:46 - 000770048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2018-03-14 11:20 - 2018-03-01 05:45 - 000386560 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2018-03-14 11:20 - 2018-03-01 05:44 - 008030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2018-03-14 11:20 - 2018-03-01 05:44 - 005195776 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2018-03-14 11:20 - 2018-03-01 05:42 - 003505664 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll
2018-03-14 11:20 - 2018-03-01 05:41 - 003334144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-03-14 11:20 - 2018-03-01 05:39 - 002222592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2018-03-14 11:20 - 2018-03-01 05:36 - 004050432 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2018-03-14 11:20 - 2018-03-01 05:35 - 000568320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msra.exe
2018-03-14 11:20 - 2018-03-01 05:35 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe
2018-03-14 11:20 - 2018-02-22 02:23 - 001092016 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-03-14 11:20 - 2018-02-22 02:23 - 000924648 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-03-14 11:20 - 2018-02-22 02:08 - 001206688 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2018-03-14 11:20 - 2018-02-22 02:07 - 001415296 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-03-14 11:20 - 2018-02-22 02:07 - 001209248 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-03-14 11:20 - 2018-02-22 02:07 - 000194456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ataport.sys
2018-03-14 11:20 - 2018-02-22 02:03 - 000712600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2018-03-14 11:20 - 2018-02-22 01:59 - 021351624 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2018-03-14 11:20 - 2018-02-22 01:51 - 000097176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdstor.sys
2018-03-14 11:20 - 2018-02-22 01:50 - 000229272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2018-03-14 11:20 - 2018-02-22 00:41 - 020286120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2018-03-14 11:20 - 2018-02-22 00:30 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\RfxVmt.sys
2018-03-14 11:20 - 2018-02-22 00:27 - 001282048 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2018-03-14 11:20 - 2018-02-22 00:26 - 001015296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2018-03-14 11:20 - 2018-02-22 00:26 - 000441344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\HdAudio.sys
2018-03-14 11:20 - 2018-02-22 00:25 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll
2018-03-14 11:20 - 2018-02-22 00:16 - 001286144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll
2018-03-14 11:20 - 2018-02-22 00:12 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cldapi.dll
2018-03-14 11:19 - 2018-03-02 03:02 - 000037888 _____ C:\WINDOWS\system32\SpectrumSyncClient.dll
2018-03-14 11:19 - 2018-03-02 03:01 - 000640000 _____ (Microsoft Corporation) C:\WINDOWS\system32\HeadTrackerStorage.dll
2018-03-14 11:19 - 2018-03-01 20:28 - 000181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\HoloShellRuntime.dll
2018-03-14 11:19 - 2018-03-01 06:01 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credssp.dll
2018-03-14 11:19 - 2018-03-01 05:53 - 000206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2018-03-14 11:19 - 2018-03-01 05:53 - 000039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\UsoClient.exe
2018-03-14 11:19 - 2018-03-01 05:51 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\credssp.dll
2018-03-14 11:19 - 2018-03-01 05:46 - 000026624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msisip.dll
2018-03-14 11:19 - 2018-03-01 05:36 - 000030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\msisip.dll
2018-03-14 11:19 - 2018-03-01 05:35 - 000128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\racpldlg.dll
2018-03-14 09:21 - 2018-03-14 09:21 - 000000266 _____ C:\Users\Camilo\Desktop\A agenda dançante de Lisboa.url
2018-03-12 18:16 - 2018-03-12 18:17 - 011384381 _____ C:\Users\Camilo\Downloads\4012382.mp4
2018-03-12 14:17 - 2018-03-12 14:17 - 000000000 ____D C:\Users\Camilo\Desktop\Reguengos
2018-03-12 14:00 - 2018-03-14 19:22 - 000252232 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2018-03-11 17:59 - 2018-03-11 17:59 - 000000213 _____ C:\Users\Camilo\Desktop\How to Do Beginner Footwork Bachata Dance - YouTube.url
2018-03-11 17:42 - 2018-03-11 17:42 - 000000426 _____ C:\Users\Camilo\Desktop\salsa steps - Google Search.url
2018-03-11 10:29 - 2018-03-11 11:29 - 000027136 ____H C:\Users\Camilo\Documents\~WRL0001.tmp
2018-03-11 10:29 - 2018-03-11 11:28 - 000027136 ____H C:\Users\Camilo\Documents\~WRL1222.tmp
2018-03-11 10:29 - 2018-03-11 11:27 - 000027136 ____H C:\Users\Camilo\Documents\~WRL3143.tmp
2018-03-11 10:29 - 2018-03-11 11:23 - 000027136 ____H C:\Users\Camilo\Documents\~WRL2058.tmp
2018-03-11 10:29 - 2018-03-11 11:21 - 000027136 ____H C:\Users\Camilo\Documents\~WRL0923.tmp
2018-03-11 10:29 - 2018-03-11 11:21 - 000027136 ____H C:\Users\Camilo\Documents\~WRL0296.tmp
2018-03-11 10:29 - 2018-03-11 11:13 - 000026624 ____H C:\Users\Camilo\Documents\~WRL2123.tmp
2018-03-11 10:29 - 2018-03-11 11:08 - 000026112 ____H C:\Users\Camilo\Documents\~WRL1639.tmp
2018-03-11 10:29 - 2018-03-11 11:07 - 000025088 ____H C:\Users\Camilo\Documents\~WRL3844.tmp
2018-03-11 10:29 - 2018-03-11 10:51 - 000025088 ____H C:\Users\Camilo\Documents\~WRL2624.tmp
2018-03-11 10:29 - 2018-03-11 10:51 - 000025088 ____H C:\Users\Camilo\Documents\~WRL2504.tmp
2018-03-11 10:29 - 2018-03-11 10:50 - 000025088 ____H C:\Users\Camilo\Documents\~WRL0948.tmp
2018-03-11 10:29 - 2018-03-11 10:48 - 000025088 ____H C:\Users\Camilo\Documents\~WRL2207.tmp
2018-03-11 10:29 - 2018-03-11 10:29 - 000024576 ____H C:\Users\Camilo\Documents\~WRL0358.tmp
2018-03-04 12:35 - 2018-03-14 15:22 - 000000000 ____D C:\Users\Camilo\Desktop\DVLA
2018-03-03 12:39 - 2018-03-03 12:39 - 000003843 _____ C:\Users\Camilo\AppData\Local\recently-used.xbel
2018-03-03 10:06 - 2018-03-10 10:06 - 000000000 ____D C:\WINDOWS\System32\Tasks\NCH Software
2018-03-03 09:19 - 2018-03-03 09:19 - 000000000 ____D C:\Users\Camilo\AppData\Roaming\Google
2018-03-02 19:24 - 2018-03-02 19:24 - 000045104 _____ C:\Users\Camilo\Desktop\Globalização, Diplomacia e Segurança — Universidade Nova de Lisboa.html
2018-03-02 19:24 - 2018-03-02 19:24 - 000000000 ____D C:\Users\Camilo\Desktop\Globalização, Diplomacia e Segurança — Universidade Nova de Lisboa_files
2018-03-02 18:16 - 2018-03-02 18:16 - 000003584 _____ C:\Users\Camilo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2018-03-02 11:15 - 2018-03-02 11:15 - 000000206 _____ C:\Users\Camilo\Desktop\Eyebag Removal Guide Pros Cons, Side Effects, Scars and After Care.url
2018-03-01 21:04 - 2018-03-01 21:04 - 000000000 ____D C:\Users\Camilo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\POP Peeper
2018-03-01 21:04 - 2018-03-01 21:04 - 000000000 ____D C:\ProgramData\POP Peeper
2018-03-01 21:02 - 2018-03-01 21:02 - 004886368 _____ C:\Users\Camilo\Downloads\POPPeeperPro-Install (4).exe
2018-03-01 19:39 - 2018-03-01 19:39 - 000103584 _____ C:\Users\Camilo\Downloads\POPPeeper_WebInstall-Plugins.exe
2018-02-28 09:42 - 2018-02-28 09:42 - 000471874 _____ C:\Users\Camilo\Desktop\email account blocked - Google Product Forums.html
2018-02-28 09:42 - 2018-02-28 09:42 - 000000000 ____D C:\Users\Camilo\Desktop\email account blocked - Google Product Forums_files
2018-02-27 16:49 - 2018-02-27 16:49 - 000035958 _____ C:\Users\Camilo\Desktop\Pintura exterior vivenda _ Fórum da Casa.html
2018-02-27 16:49 - 2018-02-27 16:49 - 000000000 ____D C:\Users\Camilo\Desktop\Pintura exterior vivenda _ Fórum da Casa_files
2018-02-27 12:11 - 2018-02-27 12:11 - 000000285 _____ C:\Users\Camilo\Desktop\Expresso Não se pode confundir uma cirurgia plástica com uma ida ao cabeleireiro.url
2018-02-27 11:18 - 2018-02-27 11:20 - 000000000 ____D C:\Users\Camilo\Desktop\OBRAS
2018-02-27 10:33 - 2018-02-27 10:34 - 000000000 ____D C:\Users\Camilo\Desktop\IRS - MAE
2018-02-27 07:22 - 2018-02-27 07:23 - 000000000 ____D C:\Users\Camilo\Desktop\IMT
2018-02-26 17:22 - 2018-02-26 17:22 - 000420664 _____ C:\Users\Camilo\Documents\CCI26022018_2.pdf
2018-02-24 14:24 - 2018-02-24 14:26 - 000000000 ____D C:\Users\Camilo\Desktop\Photos
2018-02-24 14:18 - 2018-02-24 14:19 - 000000000 ____D C:\Users\Camilo\Documents\Parqueamento
2018-02-22 09:51 - 2018-02-22 09:51 - 000041263 _____ C:\Users\Camilo\Downloads\NOTA_LANCAMENTO_2018-2-9_592.pdf
2018-02-22 09:49 - 2018-02-22 09:49 - 000100792 _____ C:\Users\Camilo\Downloads\Comprovativo (18).pdf
2018-02-19 15:43 - 2018-02-19 15:43 - 000138028 _____ C:\Users\Camilo\Desktop\SADORENT » Reservar.html
2018-02-19 15:43 - 2018-02-19 15:43 - 000000000 ____D C:\Users\Camilo\Desktop\SADORENT » Reservar_files

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-03-21 07:36 - 2017-09-29 13:46 - 000000000 ____D C:\WINDOWS\DeliveryOptimization
2018-03-21 07:35 - 2017-09-29 13:46 - 000000000 ___HD C:\Program Files\WindowsApps
2018-03-21 07:35 - 2017-09-29 13:46 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-03-21 07:34 - 2017-11-23 06:34 - 000004156 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{8CA0EB1A-2769-4A1E-A7D9-792AE159DF1B}
2018-03-21 07:34 - 2015-08-15 09:51 - 000000000 ____D C:\Users\Camilo\AppData\Roaming\Skype
2018-03-21 07:31 - 2017-11-23 06:00 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-03-20 22:18 - 2017-02-25 12:51 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-03-20 18:57 - 2017-08-07 05:23 - 000000000 ____D C:\Users\Camilo\AppData\LocalLow\Mozilla
2018-03-20 14:04 - 2015-11-17 16:50 - 000000000 ____D C:\ProgramData\NVIDIA
2018-03-19 15:23 - 2015-08-08 13:30 - 000001357 _____ C:\backup.bat
2018-03-19 15:18 - 2015-08-05 00:03 - 000000000 ___RD C:\Users\Camilo\OneDrive
2018-03-19 15:14 - 2015-08-05 16:10 - 000000000 ____D C:\Users\Camilo\AppData\Roaming\POP Peeper
2018-03-19 13:09 - 2017-11-26 23:02 - 000000356 _____ C:\WINDOWS\Tasks\HPCeeScheduleForCamilo.job
2018-03-19 13:09 - 2017-11-23 06:34 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-03-19 13:08 - 2017-09-29 08:45 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2018-03-19 10:16 - 2015-09-22 14:27 - 000000000 ___RD C:\Users\Camilo\Documents\Scanned Documents
2018-03-18 19:49 - 2017-11-26 23:02 - 000003252 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForCamilo
2018-03-17 21:14 - 2017-09-29 13:46 - 000000000 ____D C:\WINDOWS\rescache
2018-03-17 15:07 - 2017-09-29 13:46 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2018-03-15 11:32 - 2015-08-05 17:26 - 000000000 ____D C:\Users\Camilo\AppData\Local\CrashDumps
2018-03-14 19:24 - 2017-09-29 13:44 - 000000000 ____D C:\WINDOWS\INF
2018-03-14 19:23 - 2017-11-23 06:32 - 002304154 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-03-14 19:23 - 2017-11-22 22:14 - 000986018 _____ C:\WINDOWS\system32\prfh0816.dat
2018-03-14 19:23 - 2017-11-22 22:14 - 000212036 _____ C:\WINDOWS\system32\prfc0816.dat
2018-03-14 19:18 - 2017-11-23 06:39 - 000000000 ___RD C:\Users\Camilo\3D Objects
2018-03-14 19:18 - 2015-08-05 00:00 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-03-14 19:17 - 2017-11-23 06:00 - 000328176 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-03-14 19:14 - 2017-09-29 13:46 - 000000000 ____D C:\WINDOWS\TextInput
2018-03-14 19:14 - 2017-09-29 13:46 - 000000000 ____D C:\WINDOWS\system32\en-GB
2018-03-14 19:14 - 2017-09-29 13:46 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-03-14 19:14 - 2017-09-29 13:46 - 000000000 ____D C:\WINDOWS\ShellExperiences
2018-03-14 19:12 - 2017-11-23 06:10 - 000000000 ____D C:\Users\Camilo
2018-03-14 11:39 - 2017-09-29 13:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-03-14 11:28 - 2017-09-29 13:41 - 000140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2018-03-14 11:28 - 2017-09-29 13:41 - 000106496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2018-03-14 11:18 - 2015-08-12 15:02 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-03-14 11:14 - 2017-10-11 13:07 - 130364688 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2018-03-14 11:13 - 2015-08-13 08:53 - 130364688 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-03-12 14:47 - 2017-11-23 06:34 - 000003958 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1444456389
2018-03-12 14:47 - 2017-06-29 19:13 - 000001120 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera Browser.lnk
2018-03-12 14:47 - 2015-08-23 11:52 - 000000000 ____D C:\Program Files (x86)\Opera
2018-03-11 12:37 - 2018-01-06 16:33 - 000000000 ____D C:\Users\Camilo\Desktop\Rua do Sado
2018-03-07 17:57 - 2017-11-23 06:34 - 000003366 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2665017104-2237686660-164763984-1000
2018-03-07 17:57 - 2015-08-05 00:03 - 000002366 _____ C:\Users\Camilo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-03-03 12:39 - 2015-08-06 03:58 - 000000000 ____D C:\Users\Camilo\.gimp-2.8
2018-03-02 21:09 - 2017-09-29 13:49 - 000834552 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2018-03-02 21:09 - 2017-09-29 13:49 - 000179704 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2018-03-02 12:28 - 2015-08-07 08:31 - 000000000 ____D C:\Users\Camilo\AppData\Local\gtk-2.0
2018-03-01 21:04 - 2015-08-05 16:10 - 000000000 ____D C:\Program Files (x86)\POP Peeper
2018-03-01 09:54 - 2016-03-31 13:39 - 000000000 ____D C:\ProgramData\Oracle
2018-03-01 08:25 - 2016-03-31 13:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2018-03-01 08:25 - 2016-03-31 13:39 - 000000000 ____D C:\Program Files (x86)\Java
2018-03-01 08:24 - 2016-03-31 13:39 - 000097344 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2018-02-28 07:08 - 2017-11-23 06:34 - 000004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2018-02-27 11:08 - 2017-10-16 17:22 - 000000000 ____D C:\Users\Camilo\Desktop\TR More
2018-02-27 07:59 - 2016-04-21 08:10 - 000000000 ____D C:\Users\Camilo\Desktop\Tiushky
2018-02-27 07:20 - 2017-06-23 07:05 - 000000000 ____D C:\Users\Camilo\Desktop\rally
2018-02-26 17:23 - 2018-02-16 12:33 - 000000000 ____D C:\Users\Camilo\Desktop\WORTEN
2018-02-26 11:22 - 2017-06-15 13:24 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2018-02-26 11:22 - 2015-08-06 17:44 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-02-24 14:27 - 2017-06-13 14:22 - 000000000 ____D C:\Users\Camilo\Desktop\Website
2018-02-24 13:32 - 2017-12-25 13:48 - 000000000 ____D C:\Users\Camilo\Desktop\estorl
2018-02-24 12:17 - 2015-11-18 07:53 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-02-23 17:13 - 2015-08-23 11:33 - 000001216 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2018-02-22 10:38 - 2017-03-23 14:53 - 000002358 _____ C:\Users\Camilo\Desktop\SSkkyy99.lnk
2018-02-20 15:17 - 2017-09-29 13:46 - 000000000 ____D C:\WINDOWS\system32\NDF

==================== Files in the root of some directories =======

2018-03-02 18:16 - 2018-03-02 18:16 - 000003584 _____ () C:\Users\Camilo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2018-03-03 12:39 - 2018-03-03 12:39 - 000003843 _____ () C:\Users\Camilo\AppData\Local\recently-used.xbel

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-03-20 11:27

==================== End of FRST.txt ============================
Attached Files
File Type: txt Addition.txt (47.0 KB, 9 views)
qimqim is offline  
Old 03-21-2018, 12:52 AM   #6
Registered Member
 
Join Date: Dec 2006
Posts: 259
OS: Windows 10



DELETED
qimqim is offline  
Old 03-22-2018, 03:45 AM   #7
Security Team
Moderator, Analyst
Rangemaster, TSF Academy
 
chemist's Avatar

Microsoft Most Valuable Professional
 
Join Date: Oct 2007
Location: Georgia
Posts: 29,790
OS: XP/Win7/Win10



Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure the Internet Services option remains checked.
  • Check all the other boxes.
  • Click Scan.
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log in your next reply.
------------------------------------------------------
__________________
Our services are free, but you may contribute to the author of ComboFix via PayPal

Proud member of UNITE

Microsoft MVP - Consumer Security 2014, 2015
chemist is offline  
Old 03-22-2018, 05:41 AM   #8
Registered Member
 
Join Date: Dec 2006
Posts: 259
OS: Windows 10



Farbar Service Scanner Version: 27-01-2016
Ran by Camilo (administrator) on 22-03-2018 at 12:34:59
Running from "C:\Users\Camilo\Desktop"
Microsoft Windows 10 Home (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Policy:
========================


Security Center:
============


Windows Update:
============
wuauserv Service is not running. Checking service configuration:
The start type of wuauserv service is set to Demand. The default start type is Auto.
The ImagePath of wuauserv service is OK.
The ServiceDll of wuauserv service is OK.


Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\System32\mpssvc.dll => File is digitally signed
C:\Windows\System32\bfe.dll => File is digitally signed
C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
C:\Windows\System32\SDRSVC.dll => File is digitally signed
C:\Windows\System32\vssvc.exe => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Windows\System32\ipnathlp.dll => File is digitally signed
C:\Windows\System32\iphlpsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed


**** End of log ****
qimqim is offline  
Old 03-22-2018, 07:39 PM   #9
Security Team
Moderator, Analyst
Rangemaster, TSF Academy
 
chemist's Avatar

Microsoft Most Valuable Professional
 
Join Date: Oct 2007
Location: Georgia
Posts: 29,790
OS: XP/Win7/Win10



Hello again, qim.

------------------------------------------------------

Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate.

Please stay with me until given the 'all clear' even if symptoms seemingly abate.

Kindly follow my instructions and please do no fixing on your own or running of scanners unless requested by a helper.

------------------------------------------------------

If there are any personal files, pics, etc. on your computer you cannot live without, back them up now just as a precaution.

https://windows.microsoft.com/en-us/w...-up-your-files

------------------------------------------------------
  • Open Notepad (Start > All Programs > Accessories > Notepad).
  • Please copy all the text in the codebox below. (To do this highlight the contents of the box, right-click on it and select Copy. Right-click in the open Notepad and select Paste).
  • Save it as fixlist.txt next to FRST64.exe
  • If asked to change 'Encoding:' to 'Unicode:', please agree and save it.

    NOTE: Both FRST64.exe and the fixlist.txt must be in the same location or the fix will not work.


    Code:
    start
    createrestorepoint:
    HKU\S-1-5-21-2665017104-2237686660-164763984-1000\...\ChromeHTML: ->  <==== ATTENTION
    Task: {0080BABB-27C3-4381-B41C-7BAED378110E} - no filepath
    Task: {1D5F9B4D-34A0-4852-B41A-1359773FD3E5} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
    AlternateDataStreams: C:\Users\Camilo\Desktop\Image (210).jpg:3or4kl4x13tuuug3Byamue2s4b [93]
    AlternateDataStreams: C:\Users\Camilo\Desktop\Image (210).jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
    AlternateDataStreams: C:\Users\Camilo\Documents\DPD.jpeg:3or4kl4x13tuuug3Byamue2s4b [93]
    AlternateDataStreams: C:\Users\Camilo\Documents\DPD.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
    AlternateDataStreams: C:\Users\Camilo\Documents\Passport.jpeg:3or4kl4x13tuuug3Byamue2s4b [93]
    AlternateDataStreams: C:\Users\Camilo\Documents\Passport.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
    AlternateDataStreams: C:\Users\Camilo\Documents\Residence Certficate.jpeg:3or4kl4x13tuuug3Byamue2s4b [93]
    AlternateDataStreams: C:\Users\Camilo\Documents\Residence Certficate.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
    GroupPolicyScripts-x32: Restriction <==== ATTENTION
    EmptyTemp:
    end
  • Double-click FRST64 to run the tool. If the tool warns you the version is outdated, please download and run the updated version.
  • Click the Fix button just once, and wait.
  • If you receive a message that a reboot is required, please make sure you allow it to restart normally.
  • The tool will complete its run after the restart.
  • When finished, the tool will make a log (Fixlog.txt) in the same location from where it was run. Please post the Fixlog.txt log in your reply.

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

------------------------------------------------------
__________________
Our services are free, but you may contribute to the author of ComboFix via PayPal

Proud member of UNITE

Microsoft MVP - Consumer Security 2014, 2015
chemist is offline  
Old 03-23-2018, 01:00 AM   #10
Registered Member
 
Join Date: Dec 2006
Posts: 259
OS: Windows 10



Fix result of Farbar Recovery Scan Tool (x64) Version: 14.03.2018
Ran by Camilo (23-03-2018 07:34:23) Run:1
Running from C:\Users\Camilo\Desktop
Loaded Profiles: Camilo (Available Profiles: Camilo & UpdatusUser)
Boot Mode: Normal
==============================================

fixlist content:
*****************
start
createrestorepoint:
HKU\S-1-5-21-2665017104-2237686660-164763984-1000\...\ChromeHTML: -> <==== ATTENTION
Task: {0080BABB-27C3-4381-B41C-7BAED378110E} - no filepath
Task: {1D5F9B4D-34A0-4852-B41A-1359773FD3E5} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
AlternateDataStreams: C:\Users\Camilo\Desktop\Image (210).jpg:3or4kl4x13tuuug3Byamue2s4b [93]
AlternateDataStreams: C:\Users\Camilo\Desktop\Image (210).jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\Camilo\Documents\DPD.jpeg:3or4kl4x13tuuug3Byamue2s4b [93]
AlternateDataStreams: C:\Users\Camilo\Documents\DPD.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\Camilo\Documents\Passport.jpeg:3or4kl4x13tuuug3Byamue2s4b [93]
AlternateDataStreams: C:\Users\Camilo\Documents\Passport.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\Camilo\Documents\Residence Certficate.jpeg:3or4kl4x13tuuug3Byamue2s4b [93]
AlternateDataStreams: C:\Users\Camilo\Documents\Residence Certficate.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
GroupPolicyScripts-x32: Restriction <==== ATTENTION
EmptyTemp:
end
*****************

Restore point was successfully created.
"HKU\S-1-5-21-2665017104-2237686660-164763984-1000_Classes\ChromeHTML" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0080BABB-27C3-4381-B41C-7BAED378110E}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0080BABB-27C3-4381-B41C-7BAED378110E}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1D5F9B4D-34A0-4852-B41A-1359773FD3E5}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1D5F9B4D-34A0-4852-B41A-1359773FD3E5}" => removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager => could not remove. Access Denied.
C:\Users\Camilo\Desktop\Image (210).jpg => ":3or4kl4x13tuuug3Byamue2s4b" ADS removed successfully
C:\Users\Camilo\Desktop\Image (210).jpg => ":{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}" ADS removed successfully
C:\Users\Camilo\Documents\DPD.jpeg => ":3or4kl4x13tuuug3Byamue2s4b" ADS removed successfully
C:\Users\Camilo\Documents\DPD.jpeg => ":{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}" ADS removed successfully
C:\Users\Camilo\Documents\Passport.jpeg => ":3or4kl4x13tuuug3Byamue2s4b" ADS removed successfully
C:\Users\Camilo\Documents\Passport.jpeg => ":{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}" ADS removed successfully
C:\Users\Camilo\Documents\Residence Certficate.jpeg => ":3or4kl4x13tuuug3Byamue2s4b" ADS removed successfully
C:\Users\Camilo\Documents\Residence Certficate.jpeg => ":{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}" ADS removed successfully
C:\WINDOWS\SysWOW64\GroupPolicy\Machine => moved successfully
C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => moved successfully

=========== EmptyTemp: ==========

BITS transfer queue => 10510336 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 196029768 B
Java, Flash, Steam htmlcache => 1981 B
Windows/system/drivers => 15536232 B
Edge => 1258295 B
Chrome => 117443017 B
Firefox => 258515217 B
Opera => 48593711 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 16402 B
NetworkService => 49152 B
Camilo => 335368828 B
UpdatusUser => 0 B

RecycleBin => 193631800 B
EmptyTemp: => 1.1 GB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 23-03-2018 07:46:17)


Result of scheduled keys to remove after reboot:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager => could not remove. Access Denied.

==== End of Fixlog 07:46:17 ====
qimqim is offline  
Old 03-23-2018, 03:47 AM   #11
Security Team
Moderator, Analyst
Rangemaster, TSF Academy
 
chemist's Avatar

Microsoft Most Valuable Professional
 
Join Date: Oct 2007
Location: Georgia
Posts: 29,790
OS: XP/Win7/Win10



Hello again, qim. How is the machine behaving? Any improvement?

Go here and click 'SCAN NOW' under 'ESET Online Scanner' to check for remnants.
  • You will be prompted to download and install esetonlinescanner_enu.exe. Click on the link and save the file to a convenient location.
  • Double-click on esetonlinescanner_enu.exe to install and a new window will open. Follow the prompts.
  • Turn off the real-time scanner of any existing antivirus program before performing the online scan. Here's how
  • At the bottom of the Terms of use window, tick the option Download latest version of ESET Online Scanner then click Accept
  • When/if prompted by UAC, 'Do you want to allow this app to make changes to your PC?', please choose Yes
  • Tick the option Enable detection of potentially unwanted applications
  • Click on Advanced settings
  • Make sure that the option Clean threats automatically is unticked.
  • Ensure these options are ticked:
    • Enable detection of potentially unsafe applications
    • Enable detection of suspicious applications
    • Scan archives
    • Enable Anti-Stealth technology
  • Click Scan
  • Wait for the scan to finish.
  • When the scan is done, if it shows a screen that says Threats found, click Save to text file... then name it and save it to your desktop.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Please copy/paste the contents of the log in your next reply.
  • To close ESET Online Scanner, select Do not clean then Finish
------------------------------------------------------
__________________
Our services are free, but you may contribute to the author of ComboFix via PayPal

Proud member of UNITE

Microsoft MVP - Consumer Security 2014, 2015
chemist is offline  
Old 03-23-2018, 06:52 AM   #12
Registered Member
 
Join Date: Dec 2006
Posts: 259
OS: Windows 10



It finished without errors bu without the option to "Sve to text file"
Attached Thumbnails
Click image for larger version

Name:	Capture.JPG
Views:	44
Size:	46.0 KB
ID:	319298  
qimqim is offline  
Old 03-24-2018, 08:45 PM   #13
Security Team
Moderator, Analyst
Rangemaster, TSF Academy
 
chemist's Avatar

Microsoft Most Valuable Professional
 
Join Date: Oct 2007
Location: Georgia
Posts: 29,790
OS: XP/Win7/Win10



How is the machine behaving? Any improvement?
__________________
Our services are free, but you may contribute to the author of ComboFix via PayPal

Proud member of UNITE

Microsoft MVP - Consumer Security 2014, 2015
chemist is offline  
Old 03-25-2018, 12:42 AM   #14
Registered Member
 
Join Date: Dec 2006
Posts: 259
OS: Windows 10



Yes, it seems back to normal. Did you find some virus?

Thank you
qimqim is offline  
Old 03-25-2018, 06:33 PM   #15
Security Team
Moderator, Analyst
Rangemaster, TSF Academy
 
chemist's Avatar

Microsoft Most Valuable Professional
 
Join Date: Oct 2007
Location: Georgia
Posts: 29,790
OS: XP/Win7/Win10



You're welcome. No, I did not find anything malicious.

------------------------------------------------------

Congratulations. Well done! Your logs appear clean. You should be good to go.

------------------------------------------------------
  • Press the Windows "logo" key and "R" key then type cleanmgr into the Run box and click OK.
  • If prompted, select your hard drive(usually C:\) then click 'OK'.
  • You should see the scanning screenshot for a few seconds.
  • Click 'Clean up system files'
  • If prompted by UAC, then click 'Yes'.
  • If prompted, select your hard drive(usually C:\) then click 'OK'.
  • You should see the scanning screenshot again, for a few seconds up to a few minutes.
  • Click on the 'More Options' tab, and click on the 'Clean up' button under the 'System Restore and Shadow Copies' section.
  • Click/tap on the 'Delete' button in the confirm deletion window, then press 'OK'.
  • Click/tap on the 'Delete files' button in the confirm deletion window.
This will remove all but the most recent System Restore Point.

------------------------------------------------------

Please re-enable your antivirus program and any other antispyware programs disabled earlier if you haven't already.

Run AdwCleaner and go File > Uninstall > Yes

------------------------------------------------------

Press the Windows "logo" key and "R" key then copy/paste the following single-line command into the Run box and click OK:

cmd /c rd /s /q "C:\FRST"

A DOS window will open and close again, this is normal.

------------------------------------------------------

You can safely delete any tools downloaded or any logs, files, and any shortcuts on your desktop that were created during this fix.

Keep MBAM, update and run a Scan('Threat Scan' by default, or 'Scan Now' under the Dashboard tab) weekly.

Empty your Recycle Bin if it does not do so automatically.

------------------------------------------------------

SPYWARE PREVENTION
In light of your recent problem, I'm sure you'd like to avoid any future infections. Please read this well written article: To help protect your computer in the future I recommend that you get the following free programs if you do not already have them:
  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware, or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an add-on available for IE, Firefox, and Chrome.
  • MVPS HOSTS FILE replaces your current HOSTS file with one that will restrict known ad sites from serving you unsolicited advertisements. It basically prevents your computer from connecting to those sites by redirecting them to 0.0.0.0, which is the IP of your local computer. See guide for Windows 8/Windows 10 here
Keep your antivirus program and antispyware programs updated and scan with them on a regular basis.

Please respond to this thread one more time so we can mark this thread as resolved.
__________________
Our services are free, but you may contribute to the author of ComboFix via PayPal

Proud member of UNITE

Microsoft MVP - Consumer Security 2014, 2015
chemist is offline  
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
Mysterious slow downloads
I've had this problem for a few months now. Some, but not all, of my downloads are intolerably slow. It's not a general internet speed issue; speed tests clock in at the expected rate (1.5-2 MB/s), and surfing webpages feels normal. The downloads in question are through websites like Keep2share,...
MedFive File and Application Sharing 1 03-01-2015 02:51 PM
My system running slow
:dance: Hi There!! I shall be very thankful if anybody guide/help me to resolve my computer's slow running issue. My system configuration is as follows: Windows edition: Windows 7 professional - Service pack 1 System:
Binyamin911 Windows 7 , Windows Vista Support 2 07-25-2014 02:23 PM
Win7: Suddenly SLOW, but normal mem usage
(Typing from Safe Mode) My machine: Asus G73Jh laptop Windows 7 64-bit Home Premium SP1 ATI Mobility Radeon™ HD 5800 Intel Core i7 Q720 1.60GHz 8 GB RAM 1TB hard drive, pre-partitioned into 3 segments, 2 of those with about 30% free and one nearly full (not the one with the Windows, etc....
bjj8383 Windows 7 , Windows Vista Support 2 03-29-2011 05:34 AM

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is on
Smilies are on
[IMG] code is on
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Post a Question


» Site Navigation
 > FAQ
  > 10.0.0.2
Powered by vBadvanced CMPS v3.2.3


All times are GMT -7. The time now is 03:21 PM.


Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2020, vBulletin Solutions, Inc.
vBulletin Security provided by vBSecurity v2.2.2 (Pro) - vBulletin Mods & Addons Copyright © 2020 DragonByte Technologies Ltd.
User Alert System provided by Advanced User Tagging v3.1.0 (Pro) - vBulletin Mods & Addons Copyright © 2020 DragonByte Technologies Ltd.
Copyright 2001 - 2018, Tech Support Forum

Windows 10 - Windows 7 - Windows XP - Windows Vista - Trojan Removal - Spyware Removal - Virus Removal - Networking - Security - Top Web Hosts