Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:14-08-2015 01 Ran by Robbi (administrator) on ROBBI-HP (15-08-2015 17:20:30) Running from C:\Users\Robbi\Downloads Loaded Profiles: Robbi & (Available Profiles: Robbi & BettyBoop) Platform: Windows 10 Home (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: Edge) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Storage Appliance Corp.) C:\ProgramData\OfficeGuardianV2\UACProxy.exe (CinemaNow, Inc.) C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (Microsoft Corporation) C:\Windows\System32\mqsvc.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Microsoft Corporation) C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe (Clickfree) C:\ProgramData\clickfree\cfagent.exe (SAC) C:\ProgramData\OfficeGuardianV2\reminder\SacReminder.exe (Microsoft Corporation) C:\Users\Robbi\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe (Microsoft Corporation) C:\Windows\System32\browser_broker.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe (TweakBit) C:\Program Files (x86)\TweakBit\PCSpeedUp\PCSpeedUp.exe () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe (Lavasoft Limited) C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe (Lavasoft) C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [IgfxTray] => c:\windows\system32\igfxtray.exe HKLM\...\Run: [HotKeysCmds] => c:\windows\system32\hkcmd.exe HKLM\...\Run: [Persistence] => c:\windows\system32\igfxpers.exe HKLM-x32\...\Run: [] => [X] HKU\S-1-5-19\...\Run: [OneDriveSetup] => C:\Windows\SysWOW64\OneDriveSetup.exe [7805120 2015-07-10] (Microsoft Corporation) HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [OneDriveSetup] => C:\Windows\SysWOW64\OneDriveSetup.exe [7805120 2015-07-10] (Microsoft Corporation) HKU\S-1-5-20\...\Run: [OneDriveSetup] => C:\Windows\SysWOW64\OneDriveSetup.exe [7805120 2015-07-10] (Microsoft Corporation) HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [OneDriveSetup] => C:\Windows\SysWOW64\OneDriveSetup.exe [7805120 2015-07-10] (Microsoft Corporation) HKU\S-1-5-21-2666077076-1512666680-1327373929-1001\...\Run: [ClickfreeMonitor] => C:\ProgramData\clickfree\cfagent.exe [333680 2012-06-28] (Clickfree) HKU\S-1-5-21-2666077076-1512666680-1327373929-1001\...\Run: [SacReminderHDDV2] => C:\ProgramData\OfficeGuardianV2\reminder\SacReminder.exe [464752 2012-06-28] (SAC) HKU\S-1-5-21-2666077076-1512666680-1327373929-1001\...\Run: [OneDrive] => C:\Users\Robbi\AppData\Local\Microsoft\OneDrive\OneDrive.exe [382144 2015-08-14] (Microsoft Corporation) HKU\S-1-5-21-2666077076-1512666680-1327373929-1001\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [1381648 2015-06-08] (Lavasoft) HKU\S-1-5-21-2666077076-1512666680-1327373929-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [ClickfreeMonitor] => C:\ProgramData\clickfree\cfagent.exe [333680 2012-06-28] (Clickfree) HKU\S-1-5-21-2666077076-1512666680-1327373929-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [SacReminderHDDV2] => C:\ProgramData\OfficeGuardianV2\reminder\SacReminder.exe [464752 2012-06-28] (SAC) HKU\S-1-5-21-2666077076-1512666680-1327373929-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [OneDrive] => C:\Users\Robbi\AppData\Local\Microsoft\OneDrive\OneDrive.exe [382144 2015-08-14] (Microsoft Corporation) HKU\S-1-5-21-2666077076-1512666680-1327373929-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [1381648 2015-06-08] (Lavasoft) HKU\S-1-5-21-2666077076-1512666680-1327373929-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [OneDriveSetup] => C:\Windows\SysWOW64\OneDriveSetup.exe [7805120 2015-07-10] (Microsoft Corporation) HKU\S-1-5-21-2666077076-1512666680-1327373929-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [HPAdvisorDock] => C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe [1712184 2010-02-09] () HKU\S-1-5-21-2666077076-1512666680-1327373929-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [517632 2015-07-10] (Microsoft Corporation) CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm HKU\S-1-5-21-2666077076-1512666680-1327373929-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/?pc=COSP&ptag=D081515-A031ED942673F4864B9F&form=CONMHP&conlogo=CT3329380 HKU\S-1-5-21-2666077076-1512666680-1327373929-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPDSK/1 HKU\S-1-5-21-2666077076-1512666680-1327373929-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie HKU\S-1-5-21-2666077076-1512666680-1327373929-1001\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://g.msn.com/1me10IE11ENUS/MCM_WCP HKU\S-1-5-21-2666077076-1512666680-1327373929-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/?pc=COSP&ptag=D081515-A031ED942673F4864B9F&form=CONMHP&conlogo=CT3329380 HKU\S-1-5-21-2666077076-1512666680-1327373929-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPDSK/1 HKU\S-1-5-21-2666077076-1512666680-1327373929-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie HKU\S-1-5-21-2666077076-1512666680-1327373929-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://g.msn.com/1me10IE11ENUS/MCM_WCP HKU\S-1-5-21-2666077076-1512666680-1327373929-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPDSK/1 HKU\S-1-5-21-2666077076-1512666680-1327373929-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPDSK/1 SearchScopes: HKLM -> {DD115956-C77C-4739-9AB1-B8248F116FC7} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox SearchScopes: HKLM-x32 -> {DD115956-C77C-4739-9AB1-B8248F116FC7} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2666077076-1512666680-1327373929-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?pc=COSP&ptag=D081515-A031ED942673F4864B9F&form=CONBDF&conlogo=CT3329380&q={searchTerms} SearchScopes: HKU\S-1-5-21-2666077076-1512666680-1327373929-1001 -> {36121CD2-C7DC-4189-9052-BFE4AC763699} URL = hxxp://www.bing.com/search?FORM=U220DF&PC=U220&q={searchTerms}&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-2666077076-1512666680-1327373929-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?pc=COSP&ptag=D081515-A031ED942673F4864B9F&form=CONBDF&conlogo=CT3329380&q={searchTerms} SearchScopes: HKU\S-1-5-21-2666077076-1512666680-1327373929-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {36121CD2-C7DC-4189-9052-BFE4AC763699} URL = hxxp://www.bing.com/search?FORM=U220DF&PC=U220&q={searchTerms}&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-2666077076-1512666680-1327373929-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {B95B9411-451E-4DFC-BB31-3C13BF524634} URL = SearchScopes: HKU\S-1-5-21-2666077076-1512666680-1327373929-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {DD115956-C77C-4739-9AB1-B8248F116FC7} URL = BHO: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2014-11-15] (LastPass) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-07-19] (Google Inc.) BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard) BHO-x32: Charter Toolbar -> {47B6A4A9-DC94-4738-9F20-7411D9691EA4} -> C:\Program Files (x86)\chartertoolbar\chartertoolbarDx.dll [2011-04-20] () BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2012-09-24] (Sun Microsystems, Inc.) BHO-x32: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar.dll [2014-11-15] (LastPass) BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-07-19] (Google Inc.) BHO-x32: IE Developer Toolbar BHO -> {CC7E636D-39AA-49b6-B511-65413DA137A1} -> C:\Program Files (x86)\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll [2010-04-27] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2012-09-24] (Sun Microsystems, Inc.) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard) Toolbar: HKLM - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2014-11-15] (LastPass) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-07-19] (Google Inc.) Toolbar: HKLM-x32 - Charter Toolbar - {47B6A4A9-DC94-4738-9F20-7411D9691EA4} - C:\Program Files (x86)\chartertoolbar\chartertoolbarDx.dll [2011-04-20] () Toolbar: HKLM-x32 - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll [2014-11-15] (LastPass) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-07-19] (Google Inc.) Toolbar: HKU\S-1-5-21-2666077076-1512666680-1327373929-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Toolbar: HKU\S-1-5-21-2666077076-1512666680-1327373929-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Toolbar: HKU\S-1-5-21-2666077076-1512666680-1327373929-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-07-19] (Google Inc.) DPF: HKLM-x32 {02BCC737-B171-4746-94C9-0D8A0B2C0089} hxxp://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab DPF: HKLM-x32 {1851174C-97BD-4217-A0CC-E908F60D5B7A} hxxps://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Winsock: Catalog9 01 C:\WINDOWS\SysWOW64\LavasoftTcpService.dll [348488 2015-08-15] (Lavasoft Limited) Winsock: Catalog9 02 C:\WINDOWS\SysWOW64\LavasoftTcpService.dll [348488 2015-08-15] (Lavasoft Limited) Winsock: Catalog9 03 C:\WINDOWS\SysWOW64\LavasoftTcpService.dll [348488 2015-08-15] (Lavasoft Limited) Winsock: Catalog9 04 C:\WINDOWS\SysWOW64\LavasoftTcpService.dll [348488 2015-08-15] (Lavasoft Limited) Winsock: Catalog9 16 C:\WINDOWS\SysWOW64\LavasoftTcpService.dll [348488 2015-08-15] (Lavasoft Limited) Winsock: Catalog9-x64 01 C:\WINDOWS\system32\LavasoftTcpService64.dll [428880 2015-08-15] (Lavasoft Limited) Winsock: Catalog9-x64 02 C:\WINDOWS\system32\LavasoftTcpService64.dll [428880 2015-08-15] (Lavasoft Limited) Winsock: Catalog9-x64 03 C:\WINDOWS\system32\LavasoftTcpService64.dll [428880 2015-08-15] (Lavasoft Limited) Winsock: Catalog9-x64 04 C:\WINDOWS\system32\LavasoftTcpService64.dll [428880 2015-08-15] (Lavasoft Limited) Winsock: Catalog9-x64 16 C:\WINDOWS\system32\LavasoftTcpService64.dll [428880 2015-08-15] (Lavasoft Limited) Tcpip\Parameters: [DhcpNameServer] 71.10.216.1 71.10.216.2 Tcpip\..\Interfaces\{11b1679f-7c2c-4500-9d71-efb6ad9eb414}: [DhcpNameServer] 71.10.216.1 71.10.216.2 FireFox: ======== FF Plugin: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2014-11-15] (LastPass) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.10.2 -> C:\Windows\SysWOW64\npDeployJava1.dll [2013-01-01] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll [2012-09-24] (Sun Microsystems, Inc.) FF Plugin-x32: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2014-11-15] (LastPass) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-17] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-17] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.) Chrome: ======= CHR Profile: C:\Users\Robbi\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Robbi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-17] CHR Extension: (Google Drive) - C:\Users\Robbi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-17] CHR Extension: (YouTube) - C:\Users\Robbi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-17] CHR Extension: (Google Search) - C:\Users\Robbi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-17] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Robbi\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-23] CHR Extension: (Chrome Web Store Payments) - C:\Users\Robbi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-17] CHR Extension: (Gmail) - C:\Users\Robbi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-17] CHR HKLM\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - http://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - http://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [326144 2015-07-10] (Microsoft Corporation) S3 CDPSvc; C:\Windows\System32\CDPSvc.dll [134144 2015-07-10] (Microsoft Corporation) R2 CFUACProxy_officeguardianv2; C:\ProgramData\OfficeGuardianV2\UACProxy.exe [83824 2012-06-28] (Storage Appliance Corp.) R2 CoreMessagingRegistrar; C:\Windows\system32\coremessaging.dll [808856 2015-08-15] (Microsoft Corporation) R2 CoreMessagingRegistrar; C:\Windows\SysWOW64\coremessaging.dll [510976 2015-08-15] (Microsoft Corporation) S3 diagnosticshub.standardcollector.service; C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [27136 2015-07-10] (Microsoft Corporation) S3 DmEnrollmentSvc; C:\Windows\system32\Windows.Internal.Management.dll [267776 2015-07-10] (Microsoft Corporation) S3 DmEnrollmentSvc; C:\Windows\SysWOW64\Windows.Internal.Management.dll [193024 2015-07-10] (Microsoft Corporation) S3 embeddedmode; C:\Windows\System32\embeddedmodesvc.dll [87040 2015-07-10] (Microsoft Corporation) S3 EntAppSvc; C:\Windows\system32\EnterpriseAppMgmtSvc.dll [275456 2015-07-10] (Microsoft Corporation) R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed] S3 icssvc; C:\Windows\System32\tetheringservice.dll [148992 2015-08-15] (Microsoft Corporation) R2 LavasoftTcpService; C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe [2751792 2015-06-08] (Lavasoft Limited) R3 lfsvc; C:\Windows\SysWOW64\lfsvc.dll [22528 2015-07-10] (Microsoft Corporation) R3 LicenseManager; C:\Windows\system32\LicenseManagerSvc.dll [21504 2015-07-10] (Microsoft Corporation) R2 LightScribeService; c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2010-01-22] (Hewlett-Packard Company) [File not signed] S2 MapsBroker; C:\Windows\System32\moshost.dll [62464 2015-07-10] (Microsoft Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation) R2 MSMQ; C:\Windows\system32\mqsvc.exe [26112 2015-08-15] (Microsoft Corporation) S2 OneSyncSvc; C:\Windows\System32\APHostService.dll [296960 2015-07-10] (Microsoft Corporation) R2 OneSyncSvc_Session1; C:\WINDOWS\system32\svchost.exe [39856 2015-07-10] (Microsoft Corporation) R2 OneSyncSvc_Session1; C:\WINDOWS\SysWOW64\svchost.exe [35176 2015-07-10] (Microsoft Corporation) S3 PimIndexMaintenanceSvc; C:\Windows\System32\PimIndexMaintenance.dll [289280 2015-07-10] (Microsoft Corporation) S3 PimIndexMaintenanceSvc_Session1; C:\WINDOWS\system32\svchost.exe [39856 2015-07-10] (Microsoft Corporation) S3 PimIndexMaintenanceSvc_Session1; C:\WINDOWS\SysWOW64\svchost.exe [35176 2015-07-10] (Microsoft Corporation) S3 RetailDemo; C:\Windows\system32\RDXService.dll [988672 2015-08-02] (Microsoft Corporation) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [303360 2015-06-24] (Realtek Semiconductor) R2 SearchProtectionService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe [19816 2015-06-08] () S3 SensorDataService; C:\Windows\System32\SensorDataService.exe [1031680 2015-08-15] (Microsoft Corporation) R3 StateRepository; C:\Windows\system32\windows.staterepository.dll [2674176 2015-07-10] (Microsoft Corporation) R3 StateRepository; C:\Windows\SysWOW64\windows.staterepository.dll [2049024 2015-07-10] (Microsoft Corporation) S3 UnistoreSvc; C:\Windows\System32\unistore.dll [1203200 2015-08-15] (Microsoft Corporation) S3 UnistoreSvc; C:\Windows\SysWOW64\unistore.dll [925696 2015-08-15] (Microsoft Corporation) S3 UnistoreSvc_Session1; C:\WINDOWS\System32\svchost.exe [39856 2015-07-10] (Microsoft Corporation) S3 UnistoreSvc_Session1; C:\WINDOWS\SysWOW64\svchost.exe [35176 2015-07-10] (Microsoft Corporation) S3 UserDataSvc; C:\Windows\System32\userdataservice.dll [1420288 2015-07-29] (Microsoft Corporation) S3 UserDataSvc_Session1; C:\WINDOWS\system32\svchost.exe [39856 2015-07-10] (Microsoft Corporation) S3 UserDataSvc_Session1; C:\WINDOWS\SysWOW64\svchost.exe [35176 2015-07-10] (Microsoft Corporation) S3 vmicvmsession; C:\Windows\System32\ICSvc.dll [506880 2015-07-10] (Microsoft Corporation) S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [84480 2015-08-15] (Microsoft Corporation) R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [578560 2015-08-15] (Microsoft Corporation) S3 WalletService; C:\Windows\system32\WalletService.dll [504320 2015-07-10] (Microsoft Corporation) R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation) S3 XblAuthManager; C:\Windows\System32\XblAuthManager.dll [918016 2015-07-10] (Microsoft Corporation) S3 XblGameSave; C:\Windows\System32\XblGameSave.dll [1149440 2015-07-10] (Microsoft Corporation) S3 XboxNetApiSvc; C:\Windows\system32\XboxNetApiSvc.dll [1019392 2015-07-10] (Microsoft Corporation) ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 CompositeBus; C:\Windows\System32\DriverStore\FileRepository\compositebus.inf_amd64_98334ba6e76853ba\CompositeBus.sys [39936 2015-07-10] (Microsoft Corporation) R3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2015-08-14] (Windows (R) Win 7 DDK provider) R3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2015-08-14] (Windows (R) Win 7 DDK provider) S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3436896 2015-07-10] (QLogic Corporation) R1 FileCrypt; C:\Windows\System32\drivers\filecrypt.sys [83968 2015-07-10] (Microsoft Corporation) S3 genericusbfn; C:\Windows\System32\drivers\genericusbfn.sys [20992 2015-07-10] (Microsoft Corporation) R1 GpuEnergyDrv; C:\Windows\System32\drivers\gpuenergydrv.sys [8192 2015-07-10] (Microsoft Corporation) S3 ibbus; C:\Windows\System32\drivers\ibbus.sys [424800 2015-07-10] (Mellanox) S3 IoQos; C:\Windows\System32\drivers\ioqos.sys [26624 2015-07-10] (Microsoft Corporation) S0 LSI_SAS3i; C:\Windows\System32\drivers\lsi_sas3i.sys [99168 2015-07-10] (Avago Technologies) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [113880 2015-08-15] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation) S3 mlx4_bus; C:\Windows\System32\drivers\mlx4_bus.sys [705376 2015-07-10] (Mellanox) R3 MQAC; C:\Windows\System32\drivers\mqac.sys [175104 2015-08-15] (Microsoft Corporation) S3 ndfltr; C:\Windows\System32\drivers\ndfltr.sys [76128 2015-07-10] (Mellanox) R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [587264 2015-07-10] (Realtek ) R2 RtNdPt60; C:\Windows\system32\DRIVERS\RtNdPt60.sys [26624 2010-01-19] (Windows (R) Codename Longhorn DDK provider) R2 storqosflt; C:\Windows\System32\drivers\storqosflt.sys [61952 2015-07-10] (Microsoft Corporation) R3 swenum; C:\Windows\System32\DriverStore\FileRepository\swenum.inf_amd64_2a699e44676b7781\swenum.sys [17760 2015-07-10] (Microsoft Corporation) S3 UcmCx0101; C:\Windows\System32\Drivers\UcmCx.sys [61952 2015-07-10] (Microsoft Corporation) S3 UcmUcsi; C:\Windows\System32\drivers\UcmUcsi.sys [46080 2015-08-15] (Microsoft Corporation) S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] () R0 WindowsTrustedRT; C:\Windows\System32\drivers\WindowsTrustedRT.sys [106520 2015-07-10] (Microsoft Corporation) R0 WindowsTrustedRTProxy; C:\Windows\System32\drivers\WindowsTrustedRTProxy.sys [17944 2015-07-10] (Microsoft Corporation) S3 WinMad; C:\Windows\System32\drivers\winmad.sys [26976 2015-07-10] (Mellanox) S3 WinVerbs; C:\Windows\System32\drivers\winverbs.sys [59232 2015-07-10] (Mellanox) S3 xboxgip; C:\Windows\System32\drivers\xboxgip.sys [222720 2015-07-10] (Microsoft Corporation) S3 xinputhid; C:\Windows\System32\drivers\xinputhid.sys [25600 2015-07-10] (Microsoft Corporation) U3 idsvc; no ImagePath S3 PcdrNdisuio; \SystemRoot\syswow64\drivers\pcdrndisuio.sys [X] R3 PCDSRVC{F36B3A4C-F95654BD-06000000}_0; \??\c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms [X] S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X] U3 wpcsvc; no ImagePath ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) NETSVC: dosvc -> C:\Windows\system32\dosvc.dll (Microsoft Corporation) NETSVC: DcpSvc -> C:\Windows\system32\dcpsvc.dll (Microsoft Corporation) NETSVC: NetSetupSvc -> C:\Windows\System32\NetSetupSvc.dll (Microsoft Corporation) NETSVC: dmwappushservice -> C:\Windows\system32\dmwappushsvc.dll (Microsoft Corporation) NETSVC: XblGameSave -> C:\Windows\System32\XblGameSave.dll (Microsoft Corporation) NETSVC: XboxNetApiSvc -> C:\Windows\system32\XboxNetApiSvc.dll (Microsoft Corporation) NETSVC: UsoSvc -> C:\Windows\system32\usocore.dll (Microsoft Corporation) NETSVC: UserManager -> C:\Windows\System32\usermgr.dll (Microsoft Corporation) NETSVC: DmEnrollmentSvc -> C:\Windows\system32\Windows.Internal.Management.dll (Microsoft Corporation) NETSVC: XblAuthManager -> C:\Windows\System32\XblAuthManager.dll (Microsoft Corporation) NETSVC: RetailDemo -> C:\Windows\system32\RDXService.dll (Microsoft Corporation) NETSVCx32: NetSetupSvc -> C:\Windows\SysWOW64\NetSetupSvc.dll ==> No File NETSVCx32: UserManager -> C:\Windows\SysWOW64\usermgr.dll ==> No File ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-08-15 17:19 - 2015-08-15 17:20 - 02173952 _____ (Farbar) C:\Users\Robbi\Downloads\FRST64.exe 2015-08-15 17:02 - 2015-08-15 17:02 - 00016148 _____ C:\WINDOWS\system32\ROBBI-HP_Robbi_HistoryPrediction.bin 2015-08-15 15:54 - 2015-08-15 15:54 - 00000264 _____ C:\prefs.js 2015-08-15 15:54 - 2015-08-15 15:54 - 00000000 ____D C:\searchplugins 2015-08-15 15:53 - 2015-08-15 15:53 - 00002752 _____ C:\WINDOWS\SysWOW64\LavasoftTcpServiceOff.ini 2015-08-15 15:53 - 2015-08-15 15:53 - 00002752 _____ C:\WINDOWS\system32\LavasoftTcpServiceOff.ini 2015-08-15 15:53 - 2015-08-15 15:53 - 00000000 ____D C:\Users\Robbi\AppData\Local\Lavasoft 2015-08-15 15:53 - 2015-06-08 14:13 - 00428880 _____ (Lavasoft Limited) C:\WINDOWS\system32\LavasoftTcpService64.dll 2015-08-15 15:53 - 2015-06-08 14:13 - 00348488 _____ (Lavasoft Limited) C:\WINDOWS\SysWOW64\LavasoftTcpService.dll 2015-08-15 15:50 - 2015-08-15 15:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft 2015-08-15 15:50 - 2015-08-15 15:50 - 00000000 ____D C:\Program Files (x86)\Lavasoft 2015-08-15 15:48 - 2015-08-15 15:48 - 00000000 ____D C:\Users\Robbi\AppData\Roaming\Lavasoft 2015-08-15 15:48 - 2015-08-15 15:48 - 00000000 ____D C:\ProgramData\Lavasoft 2015-08-15 15:45 - 2015-08-15 15:46 - 00257680 _____ (TweakBit) C:\Users\Robbi\Downloads\pc-speed-up-setup (1).exe 2015-08-15 15:44 - 2015-08-15 15:44 - 00001229 _____ C:\Users\Robbi\Desktop\TweakBit PCSpeedUp.lnk 2015-08-15 15:44 - 2015-08-15 15:44 - 00000000 ____D C:\WINDOWS\System32\Tasks\TweakBit 2015-08-15 15:44 - 2015-08-15 15:44 - 00000000 ____D C:\ProgramData\TweakBit 2015-08-15 15:44 - 2015-08-15 15:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TweakBit 2015-08-15 15:44 - 2015-08-15 15:44 - 00000000 ____D C:\Program Files (x86)\TweakBit 2015-08-15 15:43 - 2015-08-15 15:43 - 00257680 _____ (TweakBit) C:\Users\Robbi\Downloads\pc-speed-up-setup.exe 2015-08-15 11:03 - 2015-08-15 11:05 - 00000000 ____D C:\Users\Robbi\AppData\Local\Comms 2015-08-15 01:36 - 2015-08-14 22:31 - 00000000 ___DC C:\WINDOWS\Panther 2015-08-15 01:31 - 2015-08-15 01:31 - 00000000 ____D C:\Windows.old 2015-08-15 01:29 - 2015-08-15 01:29 - 14241792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 12589056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 07569408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 07523328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 07051264 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 06488312 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 06305792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 06101504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 05118024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 05076480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 04791296 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 04760576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 04611584 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 04532304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 04398080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 04350464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 04169728 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 04047288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 03687936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 03620736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 03579904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 03443200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 03362816 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 03248640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 03248128 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 02878000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 02741760 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 02646528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 02606080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 02558976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 02235904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 02224128 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 02207744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 02112512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 01773056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 01611264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 01602560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 01591856 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 01521664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 01418240 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 01417216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 01411072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 01380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 01365072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 01334784 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 01294352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2015-08-15 01:29 - 2015-08-15 01:29 - 01203200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 01203200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 01201664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 01177600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 01169408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 01168736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys 2015-08-15 01:29 - 2015-08-15 01:29 - 01135312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 01123400 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 01112064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 01101792 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 01085776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 01067520 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 01061888 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 01043968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 01031680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorDataService.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 01018568 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2015-08-15 01:29 - 2015-08-15 01:29 - 00991584 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi 2015-08-15 01:29 - 2015-08-15 01:29 - 00966424 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00934752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refsv1.sys 2015-08-15 01:29 - 2015-08-15 01:29 - 00925696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00916800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00902656 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 00872448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00858408 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 00856064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00850432 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00845664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00841728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00832512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00823336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00808856 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00799232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpccpl.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00798208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00783872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00762896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00754688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00750592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 00695136 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00680448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00679424 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00677888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00670208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00658568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00630160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00607008 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00601344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2015-08-15 01:29 - 2015-08-15 01:29 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efscore.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00584544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00578048 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00569344 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00565088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys 2015-08-15 01:29 - 2015-08-15 01:29 - 00562688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 00542720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00521568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00505344 _____ C:\WINDOWS\system32\EditionUpgradeManagerObj.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00498016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys 2015-08-15 01:29 - 2015-08-15 01:29 - 00485888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00437248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00430592 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcomapi.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00425824 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00420352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 00416256 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00412672 _____ C:\WINDOWS\system32\diagtrack_win.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00403968 _____ C:\WINDOWS\system32\diagtrack_wininternal.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00366592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00356352 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00343040 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 00335248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00328704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00325984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys 2015-08-15 01:29 - 2015-08-15 01:29 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00303616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00291840 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemcpl.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00290312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\systemcpl.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00265480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00263168 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00251392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00242264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 00242176 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicesFlowBroker.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00208736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\srumsvc.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\OmaDmAgent.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00191488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReInfo.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00181088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SignInOptions.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00179200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srumsvc.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Privacy.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReInfo.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabSvc.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 00148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 00116736 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00097128 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcd.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\spbcd.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00082616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcd.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\setbcdlocale.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spbcd.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.ProxyStub.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys 2015-08-15 01:29 - 2015-08-15 01:29 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\unenrollhook.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00061280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys 2015-08-15 01:29 - 2015-08-15 01:29 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.OneCore.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msiexec.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\hmkd.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.PAL.Desktop.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmprc.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 00046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmUcsi.sys 2015-08-15 01:29 - 2015-08-15 01:29 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hmkd.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00032768 _____ C:\WINDOWS\system32\LicenseManagerApi.dll 2015-08-15 01:29 - 2015-08-15 01:29 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\calc.exe 2015-08-15 01:29 - 2015-08-15 01:29 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\calc.exe 2015-08-15 01:24 - 2015-08-15 01:24 - 00008192 _____ C:\WINDOWS\system32\config\userdiff 2015-08-15 01:22 - 2015-08-15 01:22 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices 2015-08-15 01:22 - 2015-08-15 01:22 - 00000000 ____D C:\WINDOWS\system32\msmq 2015-08-15 01:22 - 2015-08-15 01:22 - 00000000 ____D C:\WINDOWS\system32\BestPractices 2015-08-15 01:21 - 2015-08-15 01:21 - 00000000 ____D C:\Program Files\Reference Assemblies 2015-08-15 01:21 - 2015-08-15 01:21 - 00000000 ____D C:\Program Files\MSBuild 2015-08-15 01:21 - 2015-08-15 01:21 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies 2015-08-15 01:21 - 2015-08-15 01:21 - 00000000 ____D C:\Program Files (x86)\MSBuild 2015-08-15 01:21 - 2015-08-15 01:21 - 00000000 ____D C:\inetpub 2015-08-15 01:20 - 2015-06-17 22:10 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll 2015-08-15 01:20 - 2015-06-17 22:10 - 00124112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll 2015-08-15 01:20 - 2015-06-17 22:10 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe 2015-08-15 01:20 - 2015-05-30 01:07 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll 2015-08-15 01:20 - 2015-05-30 01:07 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2015-08-15 01:20 - 2015-05-30 01:07 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe 2015-08-15 00:52 - 2015-08-05 22:36 - 21874176 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2015-08-15 00:52 - 2015-08-05 22:03 - 18805248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2015-08-15 00:52 - 2015-08-05 00:03 - 02416640 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2015-08-15 00:52 - 2015-08-03 23:21 - 16709120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2015-08-15 00:52 - 2015-08-03 23:10 - 13025792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2015-08-15 00:52 - 2015-08-02 22:18 - 08613200 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2015-08-15 00:52 - 2015-08-02 22:13 - 22322624 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2015-08-15 00:52 - 2015-08-02 21:56 - 06878256 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2015-08-15 00:52 - 2015-08-02 21:50 - 20857848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2015-08-15 00:52 - 2015-08-02 21:24 - 24592384 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2015-08-15 00:52 - 2015-08-02 21:18 - 12503552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2015-08-15 00:52 - 2015-08-02 21:18 - 03780096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2015-08-15 00:52 - 2015-08-02 21:12 - 19323392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2015-08-15 00:52 - 2015-08-02 21:01 - 11262464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2015-08-15 00:52 - 2015-07-29 23:49 - 11557888 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2015-08-15 00:52 - 2015-07-29 23:44 - 02662400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2015-08-15 00:52 - 2015-07-29 23:15 - 09889792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2015-08-15 00:51 - 2015-08-12 04:57 - 02178560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2015-08-15 00:51 - 2015-08-12 04:22 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll 2015-08-15 00:51 - 2015-08-08 03:30 - 08020320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2015-08-15 00:51 - 2015-08-08 03:29 - 01822280 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2015-08-15 00:51 - 2015-08-08 03:19 - 00608936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2015-08-15 00:51 - 2015-08-08 03:01 - 01533496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2015-08-15 00:51 - 2015-08-08 02:48 - 00539728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2015-08-15 00:51 - 2015-08-08 02:40 - 00365056 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2015-08-15 00:51 - 2015-08-08 02:24 - 02415104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll 2015-08-15 00:51 - 2015-08-08 02:24 - 01679360 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll 2015-08-15 00:51 - 2015-08-08 02:22 - 01105920 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll 2015-08-15 00:51 - 2015-08-08 02:21 - 00642048 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll 2015-08-15 00:51 - 2015-08-08 02:15 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2015-08-15 00:51 - 2015-08-08 02:00 - 01985024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll 2015-08-15 00:51 - 2015-08-05 23:18 - 00290768 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe 2015-08-15 00:51 - 2015-08-05 23:17 - 00237392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdyboost.sys 2015-08-15 00:51 - 2015-08-05 23:17 - 00200528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys 2015-08-15 00:51 - 2015-08-05 22:22 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys 2015-08-15 00:51 - 2015-08-05 00:49 - 00783112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2015-08-15 00:51 - 2015-08-05 00:29 - 00644128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2015-08-15 00:51 - 2015-08-05 00:00 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenter.dll 2015-08-15 00:51 - 2015-08-04 23:54 - 01274880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll 2015-08-15 00:51 - 2015-08-04 23:47 - 03588096 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2015-08-15 00:51 - 2015-08-04 23:47 - 01383424 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2015-08-15 00:51 - 2015-08-04 23:43 - 01916416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2015-08-15 00:51 - 2015-08-04 23:39 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActionCenter.dll 2015-08-15 00:51 - 2015-08-04 00:08 - 02462648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2015-08-15 00:51 - 2015-08-04 00:07 - 00102752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys 2015-08-15 00:51 - 2015-08-04 00:06 - 00583128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll 2015-08-15 00:51 - 2015-08-04 00:06 - 00243248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll 2015-08-15 00:51 - 2015-08-03 23:50 - 02151208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2015-08-15 00:51 - 2015-08-03 23:23 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll 2015-08-15 00:51 - 2015-08-03 22:59 - 01212416 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll 2015-08-15 00:51 - 2015-08-03 22:47 - 00898560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll 2015-08-15 00:51 - 2015-08-02 22:32 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll 2015-08-15 00:51 - 2015-08-02 22:28 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll 2015-08-15 00:51 - 2015-08-02 22:19 - 00505696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2015-08-15 00:51 - 2015-08-02 22:19 - 00393568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2015-08-15 00:51 - 2015-08-02 22:18 - 01983840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2015-08-15 00:51 - 2015-08-02 22:18 - 00594472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll 2015-08-15 00:51 - 2015-08-02 22:18 - 00046432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpiowin32.sys 2015-08-15 00:51 - 2015-08-02 22:17 - 00516960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS 2015-08-15 00:51 - 2015-08-02 22:17 - 00052264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wpcfltr.sys 2015-08-15 00:51 - 2015-08-02 22:12 - 00801632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe 2015-08-15 00:51 - 2015-08-02 21:49 - 00700256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe 2015-08-15 00:51 - 2015-08-02 21:31 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll 2015-08-15 00:51 - 2015-08-02 21:30 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_UserAccount.dll 2015-08-15 00:51 - 2015-08-02 21:24 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll 2015-08-15 00:51 - 2015-08-02 21:24 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll 2015-08-15 00:51 - 2015-08-02 21:24 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModelShim.dll 2015-08-15 00:51 - 2015-08-02 21:23 - 02446336 _____ C:\WINDOWS\system32\InputService.dll 2015-08-15 00:51 - 2015-08-02 21:23 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll 2015-08-15 00:51 - 2015-08-02 21:22 - 01601536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll 2015-08-15 00:51 - 2015-08-02 21:22 - 01008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll 2015-08-15 00:51 - 2015-08-02 21:22 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll 2015-08-15 00:51 - 2015-08-02 21:22 - 00293376 _____ C:\WINDOWS\system32\TextInputFramework.dll 2015-08-15 00:51 - 2015-08-02 21:21 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\coredpus.dll 2015-08-15 00:51 - 2015-08-02 21:19 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\notepad.exe 2015-08-15 00:51 - 2015-08-02 21:19 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\notepad.exe 2015-08-15 00:51 - 2015-08-02 21:18 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll 2015-08-15 00:51 - 2015-08-02 21:18 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkStatus.dll 2015-08-15 00:51 - 2015-08-02 21:15 - 01290752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll 2015-08-15 00:51 - 2015-08-02 21:15 - 00988672 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll 2015-08-15 00:51 - 2015-08-02 21:15 - 00595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2015-08-15 00:51 - 2015-08-02 21:15 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll 2015-08-15 00:51 - 2015-08-02 21:15 - 00384000 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll 2015-08-15 00:51 - 2015-08-02 21:15 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll 2015-08-15 00:51 - 2015-08-02 21:14 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll 2015-08-15 00:51 - 2015-08-02 21:14 - 00247808 _____ C:\WINDOWS\system32\facecredentialprovider.dll 2015-08-15 00:51 - 2015-08-02 21:12 - 01890304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2015-08-15 00:51 - 2015-08-02 21:12 - 01823232 _____ C:\WINDOWS\SysWOW64\InputService.dll 2015-08-15 00:51 - 2015-08-02 21:12 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll 2015-08-15 00:51 - 2015-08-02 21:12 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll 2015-08-15 00:51 - 2015-08-02 21:11 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfuimanager.dll 2015-08-15 00:51 - 2015-08-02 21:11 - 00200704 _____ C:\WINDOWS\SysWOW64\TextInputFramework.dll 2015-08-15 00:51 - 2015-08-02 21:10 - 01162240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll 2015-08-15 00:51 - 2015-08-02 21:06 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe 2015-08-15 00:51 - 2015-08-02 21:03 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll 2015-08-15 00:51 - 2015-08-02 21:02 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll 2015-08-15 00:51 - 2015-08-02 21:02 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll 2015-08-15 00:51 - 2015-08-02 21:00 - 01593856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2015-08-15 00:51 - 2015-08-02 20:59 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfuimanager.dll 2015-08-15 00:51 - 2015-07-30 02:24 - 01561872 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll 2015-08-15 00:51 - 2015-07-30 02:23 - 00527952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2015-08-15 00:51 - 2015-07-30 02:21 - 00816576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll 2015-08-15 00:51 - 2015-07-30 02:17 - 01200400 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll 2015-08-15 00:51 - 2015-07-30 02:17 - 01025840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll 2015-08-15 00:51 - 2015-07-30 02:16 - 02147080 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll 2015-08-15 00:51 - 2015-07-30 02:15 - 00632168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll 2015-08-15 00:51 - 2015-07-30 02:14 - 00333168 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll 2015-08-15 00:51 - 2015-07-30 02:09 - 01562968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll 2015-08-15 00:51 - 2015-07-30 02:06 - 01043872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2015-08-15 00:51 - 2015-07-30 02:05 - 02498808 _____ C:\WINDOWS\system32\CoreUIComponents.dll 2015-08-15 00:51 - 2015-07-30 02:05 - 00501008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2015-08-15 00:51 - 2015-07-30 02:04 - 01396064 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2015-08-15 00:51 - 2015-07-30 02:03 - 02116448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2015-08-15 00:51 - 2015-07-30 01:24 - 00252768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll 2015-08-15 00:51 - 2015-07-30 00:42 - 01643872 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2015-08-15 00:51 - 2015-07-30 00:29 - 00705520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll 2015-08-15 00:51 - 2015-07-30 00:26 - 01867160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll 2015-08-15 00:51 - 2015-07-30 00:26 - 00877016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2015-08-15 00:51 - 2015-07-30 00:25 - 01356368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll 2015-08-15 00:51 - 2015-07-30 00:25 - 00713312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll 2015-08-15 00:51 - 2015-07-30 00:24 - 01769056 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2015-08-15 00:51 - 2015-07-30 00:24 - 00445240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll 2015-08-15 00:51 - 2015-07-30 00:24 - 00407616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2015-08-15 00:51 - 2015-07-30 00:24 - 00285632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll 2015-08-15 00:51 - 2015-07-30 00:22 - 00896144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll 2015-08-15 00:51 - 2015-07-30 00:22 - 00507696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll 2015-08-15 00:51 - 2015-07-30 00:21 - 00962400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2015-08-15 00:51 - 2015-07-30 00:12 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll 2015-08-15 00:51 - 2015-07-30 00:12 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll 2015-08-15 00:51 - 2015-07-30 00:09 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe 2015-08-15 00:51 - 2015-07-30 00:08 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll 2015-08-15 00:51 - 2015-07-30 00:08 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2015-08-15 00:51 - 2015-07-30 00:08 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe 2015-08-15 00:51 - 2015-07-29 23:59 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll 2015-08-15 00:51 - 2015-07-29 23:52 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll 2015-08-15 00:51 - 2015-07-29 23:52 - 00521216 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll 2015-08-15 00:51 - 2015-07-29 23:52 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll 2015-08-15 00:51 - 2015-07-29 23:49 - 00777728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2015-08-15 00:51 - 2015-07-29 23:49 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2015-08-15 00:51 - 2015-07-29 23:46 - 02125312 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2015-08-15 00:51 - 2015-07-29 23:46 - 00593920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll 2015-08-15 00:51 - 2015-07-29 23:46 - 00487424 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll 2015-08-15 00:51 - 2015-07-29 23:46 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll 2015-08-15 00:51 - 2015-07-29 23:45 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll 2015-08-15 00:51 - 2015-07-29 23:45 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tunnel.sys 2015-08-15 00:51 - 2015-07-29 23:44 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2015-08-15 00:51 - 2015-07-29 23:44 - 00229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll 2015-08-15 00:51 - 2015-07-29 23:44 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll 2015-08-15 00:51 - 2015-07-29 23:44 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys 2015-08-15 00:51 - 2015-07-29 23:44 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\VoiceActivationManager.dll 2015-08-15 00:51 - 2015-07-29 23:42 - 00518144 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll 2015-08-15 00:51 - 2015-07-29 23:41 - 00407040 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll 2015-08-15 00:51 - 2015-07-29 23:41 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll 2015-08-15 00:51 - 2015-07-29 23:40 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2015-08-15 00:51 - 2015-07-29 23:38 - 01420288 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll 2015-08-15 00:51 - 2015-07-29 23:38 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll 2015-08-15 00:51 - 2015-07-29 23:34 - 00599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll 2015-08-15 00:51 - 2015-07-29 23:29 - 00654848 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll 2015-08-15 00:51 - 2015-07-29 23:10 - 00585728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2015-08-15 00:51 - 2015-07-29 23:10 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2015-08-15 00:51 - 2015-07-29 23:07 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll 2015-08-15 00:51 - 2015-07-29 23:06 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll 2015-08-15 00:51 - 2015-07-29 23:06 - 00373248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll 2015-08-15 00:51 - 2015-07-29 23:06 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll 2015-08-15 00:51 - 2015-07-29 23:06 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VoiceActivationManager.dll 2015-08-15 00:51 - 2015-07-29 23:04 - 01714176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2015-08-15 00:51 - 2015-07-29 23:04 - 00335360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll 2015-08-15 00:51 - 2015-07-29 22:59 - 00473088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll 2015-08-15 00:51 - 2015-07-29 22:58 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll 2015-08-14 22:43 - 2015-08-14 22:43 - 00002380 _____ C:\Users\Robbi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2015-08-14 22:43 - 2015-08-14 22:43 - 00000000 ___RD C:\Users\Robbi\OneDrive 2015-08-14 22:42 - 2015-08-14 23:12 - 00000000 ____D C:\Users\Robbi\AppData\Local\MicrosoftEdge 2015-08-14 22:41 - 2015-08-14 22:41 - 00000000 ____D C:\ProgramData\Microsoft OneDrive 2015-08-14 22:39 - 2015-08-14 22:39 - 00000000 ____D C:\Users\Robbi\AppData\Local\Publishers 2015-08-14 22:37 - 2015-08-14 22:37 - 03867040 _____ C:\WINDOWS\system32\PortChanger.exe 2015-08-14 22:37 - 2015-08-14 22:37 - 02398112 _____ (Hewlett Packard) C:\WINDOWS\system32\hppldcoi.dll 2015-08-14 22:37 - 2015-08-14 22:37 - 01304576 _____ (Hewlett-Packard) C:\WINDOWS\system32\hpowiav1.dll 2015-08-14 22:37 - 2015-08-14 22:37 - 00736256 _____ (Hewlett-Packard Co.) C:\WINDOWS\system32\hpotscl1.dll 2015-08-14 22:37 - 2015-08-14 22:37 - 00151968 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\Drivers\Dot4.sys 2015-08-14 22:37 - 2015-08-14 22:37 - 00049056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Dot4usb.sys 2015-08-14 22:37 - 2015-08-14 22:37 - 00027040 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\Drivers\Dot4Prt.sys 2015-08-14 22:32 - 2015-08-15 01:04 - 00000000 ____D C:\Users\Robbi\AppData\Local\Packages 2015-08-14 22:32 - 2015-08-14 22:32 - 00000000 ____D C:\Users\Robbi\AppData\Local\TileDataLayer 2015-08-14 22:31 - 2015-08-14 22:31 - 00000020 ___SH C:\Users\Robbi\ntuser.ini 2015-08-14 22:13 - 2015-08-14 22:13 - 00000000 __SHD C:\Recovery 2015-08-14 22:10 - 2015-08-14 22:10 - 00022744 _____ C:\WINDOWS\system32\emptyregdb.dat 2015-08-14 22:07 - 2015-08-14 22:07 - 00002262 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2015-08-14 21:57 - 2015-08-14 21:57 - 00000000 ____D C:\Users\Default\AppData\Roaming\Mozilla 2015-08-14 21:57 - 2015-08-14 21:57 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia 2015-08-14 21:57 - 2015-08-14 21:57 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Mozilla 2015-08-14 21:57 - 2015-08-14 21:57 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia 2015-08-14 21:56 - 2015-08-14 21:56 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2015-08-14 21:47 - 2015-08-14 21:47 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines 2015-08-14 21:45 - 2015-08-15 14:43 - 00000000 ____D C:\Users\Robbi 2015-08-14 21:45 - 2015-08-14 22:32 - 00000000 ___RD C:\Users\Robbi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-08-14 21:45 - 2015-08-14 22:07 - 00000000 ____D C:\Users\BettyBoop 2015-08-14 21:45 - 2015-08-14 21:46 - 00000000 ___RD C:\Users\BettyBoop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-08-14 21:45 - 2015-07-10 07:04 - 00000000 __RSD C:\Users\Robbi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell 2015-08-14 21:45 - 2015-07-10 07:04 - 00000000 __RSD C:\Users\BettyBoop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell 2015-08-14 21:45 - 2015-07-10 07:04 - 00000000 ___RD C:\Users\Robbi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2015-08-14 21:45 - 2015-07-10 07:04 - 00000000 ___RD C:\Users\Robbi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2015-08-14 21:45 - 2015-07-10 07:04 - 00000000 ___RD C:\Users\BettyBoop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2015-08-14 21:45 - 2015-07-10 07:04 - 00000000 ___RD C:\Users\BettyBoop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2015-08-14 21:45 - 2015-07-10 07:04 - 00000000 ____D C:\Users\Robbi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2015-08-14 21:45 - 2015-07-10 07:04 - 00000000 ____D C:\Users\BettyBoop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2015-08-14 21:43 - 2015-08-15 14:46 - 01006464 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2015-08-14 21:43 - 2015-08-14 21:43 - 00961296 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI 2015-08-14 21:42 - 2015-08-14 21:43 - 00021209 _____ C:\WINDOWS\iis.log 2015-08-14 21:41 - 2015-07-10 06:59 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2015-08-14 21:40 - 2015-08-14 21:40 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM 2015-08-14 21:40 - 2015-08-14 21:40 - 00000000 ____D C:\WINDOWS\system32\SRSLabs 2015-08-14 21:40 - 2015-08-14 21:40 - 00000000 ____D C:\Program Files\Realtek 2015-08-14 21:39 - 2015-08-14 21:39 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf 2015-08-14 21:38 - 2015-08-14 21:39 - 00022889 _____ C:\WINDOWS\system32\NetSetupMig.log 2015-08-14 21:37 - 2015-08-15 14:41 - 00009382 _____ C:\WINDOWS\PFRO.log 2015-08-14 20:51 - 2015-08-14 22:11 - 00006681 _____ C:\WINDOWS\comsetup.log 2015-08-14 20:48 - 2015-08-14 22:12 - 00014259 _____ C:\WINDOWS\diagerr.xml 2015-08-14 20:48 - 2015-08-14 22:12 - 00013338 _____ C:\WINDOWS\diagwrn.xml 2015-08-12 23:51 - 2015-07-16 16:12 - 00968704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.exe 2015-08-12 23:51 - 2015-07-16 15:33 - 01359360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmlmedia.dll 2015-08-12 23:51 - 2015-07-16 15:05 - 01155072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmlmedia.dll 2015-08-12 23:50 - 2015-07-20 14:12 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wu.upgrade.ps.dll 2015-08-08 15:16 - 2015-08-08 15:16 - 00000000 ____D C:\ProgramData\clickfree 2015-08-08 15:08 - 2015-08-08 15:32 - 00000000 ____D C:\ProgramData\OfficeGuardianV2 2015-08-03 21:45 - 2015-08-03 21:45 - 00000000 ____D C:\Users\Robbi\AppData\Local\{239AE15D-E2E8-4E5A-A17D-E6DB4D68FD6E} ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-08-15 17:20 - 2015-05-24 13:37 - 00029622 _____ C:\Users\Robbi\Downloads\FRST.txt 2015-08-15 17:20 - 2015-05-24 13:36 - 00000000 ____D C:\FRST 2015-08-15 17:18 - 2012-03-31 08:03 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2015-08-15 16:44 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\sru 2015-08-15 16:43 - 2015-07-10 08:22 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log 2015-08-15 16:40 - 2013-11-17 11:45 - 00000898 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2015-08-15 15:14 - 2014-12-14 18:54 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2015-08-15 15:04 - 2010-10-16 21:02 - 00000448 _____ C:\WINDOWS\Tasks\PCDRScheduledMaintenance.job 2015-08-15 14:47 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\NDF 2015-08-15 14:47 - 2014-12-02 09:25 - 00003242 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForRobbi 2015-08-15 14:47 - 2014-12-02 09:25 - 00000350 _____ C:\WINDOWS\Tasks\HPCeeScheduleForRobbi.job 2015-08-15 14:43 - 2013-11-17 11:45 - 00000894 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-08-15 14:42 - 2015-07-10 08:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2015-08-15 14:24 - 2015-07-10 08:20 - 00201776 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2015-08-15 14:23 - 2015-07-10 05:05 - 00131072 ___SH C:\WINDOWS\system32\config\BBI 2015-08-15 14:22 - 2015-07-10 07:04 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-08-15 14:22 - 2015-07-10 07:04 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-08-15 14:22 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2015-08-15 14:22 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\oobe 2015-08-15 14:22 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\appraiser 2015-08-15 14:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\Provisioning 2015-08-15 10:46 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase 2015-08-15 03:43 - 2011-09-24 14:45 - 00004154 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{171CFEE2-7B0A-4F3E-9AE8-837B12F3DF08} 2015-08-15 03:01 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\appcompat 2015-08-15 01:55 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\AppReadiness 2015-08-15 01:36 - 2015-07-10 07:04 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template 2015-08-15 01:31 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe 2015-08-15 01:31 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform 2015-08-15 01:31 - 2015-07-10 05:05 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism 2015-08-15 01:31 - 2015-07-10 05:05 - 00000000 ____D C:\WINDOWS\system32\Dism 2015-08-15 01:22 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv 2015-08-15 01:22 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\inetsrv 2015-08-15 01:21 - 2015-07-10 07:01 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll 2015-08-15 01:21 - 2015-07-10 07:01 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqutil.dll 2015-08-15 01:21 - 2015-07-10 07:01 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.dll 2015-08-15 01:21 - 2015-07-10 07:01 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll 2015-08-15 01:21 - 2015-07-10 07:01 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqrt.dll 2015-08-15 01:21 - 2015-07-10 07:01 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.tlb 2015-08-15 01:21 - 2015-07-10 07:01 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa30.tlb 2015-08-15 01:21 - 2015-07-10 07:01 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa20.tlb 2015-08-15 01:21 - 2015-07-10 07:01 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll 2015-08-15 01:21 - 2015-07-10 07:01 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa10.tlb 2015-08-15 01:21 - 2015-07-10 07:01 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll 2015-08-15 01:21 - 2015-07-10 07:01 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe 2015-08-15 01:21 - 2015-07-10 07:01 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll 2015-08-15 01:21 - 2015-07-10 07:01 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll 2015-08-15 01:21 - 2015-07-10 07:01 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll 2015-08-15 01:21 - 2015-07-10 07:01 - 00009096 _____ C:\WINDOWS\SysWOW64\msmqtrc.mof 2015-08-15 01:21 - 2015-07-10 07:00 - 01417728 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqqm.dll 2015-08-15 01:21 - 2015-07-10 07:00 - 00813056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll 2015-08-15 01:21 - 2015-07-10 07:00 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqutil.dll 2015-08-15 01:21 - 2015-07-10 07:00 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.dll 2015-08-15 01:21 - 2015-07-10 07:00 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqrt.dll 2015-08-15 01:21 - 2015-07-10 07:00 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll 2015-08-15 01:21 - 2015-07-10 07:00 - 00175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mqac.sys 2015-08-15 01:21 - 2015-07-10 07:00 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqlogmgr.dll 2015-08-15 01:21 - 2015-07-10 07:00 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.tlb 2015-08-15 01:21 - 2015-07-10 07:00 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa30.tlb 2015-08-15 01:21 - 2015-07-10 07:00 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa20.tlb 2015-08-15 01:21 - 2015-07-10 07:00 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll 2015-08-15 01:21 - 2015-07-10 07:00 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll 2015-08-15 01:21 - 2015-07-10 07:00 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqbkup.exe 2015-08-15 01:21 - 2015-07-10 07:00 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa10.tlb 2015-08-15 01:21 - 2015-07-10 07:00 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe 2015-08-15 01:21 - 2015-07-10 07:00 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcertui.dll 2015-08-15 01:21 - 2015-07-10 07:00 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe 2015-08-15 01:21 - 2015-07-10 07:00 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll 2015-08-15 01:21 - 2015-07-10 07:00 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll 2015-08-15 01:21 - 2015-07-10 07:00 - 00009096 _____ C:\WINDOWS\system32\msmqtrc.mof 2015-08-15 01:08 - 2015-07-10 06:55 - 00000000 ____D C:\WINDOWS\CbsTemp 2015-08-15 00:56 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\restore 2015-08-14 23:44 - 2010-10-19 11:45 - 00000000 ____D C:\WINDOWS\System32\Tasks\Games 2015-08-14 22:38 - 2015-07-10 07:04 - 00000000 ___RD C:\WINDOWS\PurchaseDialog 2015-08-14 22:38 - 2015-07-10 07:04 - 00000000 ___RD C:\WINDOWS\PrintDialog 2015-08-14 22:38 - 2015-07-10 07:04 - 00000000 ___RD C:\WINDOWS\MiracastView 2015-08-14 22:37 - 2015-07-10 07:04 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2015-08-14 22:20 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\rescache 2015-08-14 22:12 - 2015-07-10 08:20 - 00018180 _____ C:\WINDOWS\setupact.log 2015-08-14 22:11 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\Registration 2015-08-14 22:10 - 2015-07-10 07:04 - 00000000 __RSD C:\WINDOWS\Media 2015-08-14 22:10 - 2015-01-20 06:54 - 00003996 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2015-08-14 22:10 - 2014-02-23 13:58 - 00003454 _____ C:\WINDOWS\System32\Tasks\{1E981A1E-5CB1-4E7A-9847-4734F19F984F} 2015-08-14 22:10 - 2013-11-17 11:45 - 00004004 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2015-08-14 22:10 - 2013-11-17 11:45 - 00003752 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2015-08-14 22:10 - 2012-03-31 08:03 - 00003878 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2015-08-14 22:10 - 2010-10-16 21:14 - 00003858 _____ C:\WINDOWS\System32\Tasks\RecoveryCDWin7 2015-08-14 22:10 - 2010-10-16 21:14 - 00003558 _____ C:\WINDOWS\System32\Tasks\ServicePlan 2015-08-14 22:10 - 2010-10-16 21:02 - 00003918 _____ C:\WINDOWS\System32\Tasks\PCDRScheduledMaintenance 2015-08-14 22:10 - 2010-09-14 23:18 - 00003310 _____ C:\WINDOWS\System32\Tasks\CLMLSvc 2015-08-14 22:10 - 2010-09-14 23:07 - 00003274 _____ C:\WINDOWS\System32\Tasks\DVDAgent 2015-08-14 22:09 - 2015-07-10 07:04 - 00000000 __RHD C:\Users\Public\Libraries 2015-08-14 22:09 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\spool 2015-08-14 22:00 - 2015-07-10 07:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2015-08-14 22:00 - 2015-07-10 05:05 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM 2015-08-14 22:00 - 2014-12-14 18:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2015-08-14 22:00 - 2014-11-15 21:21 - 00000000 ____D C:\Users\Robbi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass 2015-08-14 22:00 - 2014-11-15 21:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LastPass 2015-08-14 22:00 - 2014-03-11 19:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support 2015-08-14 22:00 - 2013-11-17 11:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2015-08-14 22:00 - 2013-03-13 03:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2015-08-14 22:00 - 2011-11-20 23:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2015-08-14 22:00 - 2011-11-20 23:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft Connect 2015-08-14 22:00 - 2011-11-20 23:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft Print Creations 2015-08-14 22:00 - 2010-10-22 11:02 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live 2015-08-14 22:00 - 2010-10-22 11:02 - 00000000 ____D C:\WINDOWS\en 2015-08-14 22:00 - 2010-10-16 21:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\User Guides 2015-08-14 22:00 - 2010-09-14 23:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LightScribe Direct Disc Labeling 2015-08-14 22:00 - 2010-09-14 23:25 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Services 2015-08-14 22:00 - 2010-09-14 23:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery Manager 2015-08-14 22:00 - 2010-09-14 22:57 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Help & Tools 2015-08-14 22:00 - 2009-07-14 01:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2015-08-14 21:57 - 2015-07-10 07:05 - 00004362 _____ C:\WINDOWS\DtcInstall.log 2015-08-14 21:57 - 2009-07-13 23:20 - 00000000 ____D C:\Users\Default.migrated 2015-08-14 21:50 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\zh-HK 2015-08-14 21:50 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\tr-TR 2015-08-14 21:50 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz 2015-08-14 21:50 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\IME 2015-08-14 21:50 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\zh-HK 2015-08-14 21:50 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\tr-TR 2015-08-14 21:50 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\IME 2015-08-14 21:50 - 2011-03-07 20:00 - 00000000 ____D C:\WINDOWS\system32\SPReview 2015-08-14 21:50 - 2011-03-07 19:59 - 00000000 ____D C:\WINDOWS\system32\EventProviders 2015-08-14 21:48 - 2015-07-10 07:04 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar 2015-08-14 21:48 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\PolicyDefinitions 2015-08-14 21:48 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\Help 2015-08-14 21:48 - 2010-11-04 10:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (English) 2015-08-14 21:48 - 2010-09-14 23:47 - 00000000 ____D C:\ProgramData\Norton 2015-08-14 21:48 - 2010-09-14 23:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio 2015-08-14 21:48 - 2010-09-14 22:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP 2015-08-14 21:48 - 2009-07-14 03:44 - 00000000 ___RD C:\Users\Public\Recorded TV 2015-08-14 21:47 - 2015-07-10 07:04 - 00000000 __SHD C:\Program Files\Windows Sidebar 2015-08-14 21:47 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\Recovery 2015-08-14 21:47 - 2015-07-10 07:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2015-08-14 21:47 - 2009-07-14 01:32 - 00000000 ____D C:\Program Files\Microsoft Games 2015-08-14 21:47 - 2009-07-14 01:32 - 00000000 ____D C:\Program Files\DVD Maker 2015-08-14 21:47 - 2009-07-13 23:20 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy 2015-08-14 21:46 - 2013-05-25 17:21 - 00000000 ____D C:\Users\Robbi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SanDisk 2015-08-14 21:42 - 2015-07-10 05:05 - 00000000 ____D C:\WINDOWS\system32\Sysprep 2015-08-14 21:37 - 2015-07-10 05:05 - 00000000 __RHD C:\Users\Default 2015-08-14 21:01 - 2010-09-14 22:59 - 01098144 _____ C:\WINDOWS\WindowsUpdate (1).log 2015-08-14 21:01 - 2009-07-14 00:45 - 00018736 ____H C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-08-14 21:01 - 2009-07-14 00:45 - 00018736 ____H C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-08-14 20:48 - 2015-07-10 09:39 - 00000000 ___HD C:\$Windows.~BT 2015-08-14 20:41 - 2010-11-02 12:05 - 00000000 ____D C:\Users\Robbi\AppData\Local\CrashDumps 2015-08-13 04:03 - 2013-03-13 03:01 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2015-08-13 04:03 - 2013-03-13 03:01 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2015-08-13 03:08 - 2013-08-18 12:58 - 00000000 ____D C:\WINDOWS\system32\MRT 2015-08-13 03:07 - 2010-10-18 10:31 - 132483416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2015-08-09 08:25 - 2010-12-21 17:57 - 00000052 _____ C:\WINDOWS\SysWOW64\DOErrors.log 2015-08-08 15:20 - 2010-10-18 16:33 - 00000000 ____D C:\Users\Robbi\AppData\Roaming\SoftGrid Client 2015-08-08 11:38 - 2015-07-10 07:06 - 00794088 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2015-08-08 11:38 - 2015-07-10 07:06 - 00179688 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2015-07-17 12:15 - 2014-11-15 09:40 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk ==================== Files in the root of some directories ======= 2014-11-15 21:21 - 2014-11-15 21:21 - 14147584 _____ () C:\Program Files (x86)\Common Files\lpuninstall.exe 2015-04-13 18:30 - 2015-04-13 20:58 - 0000115 _____ () C:\Users\Robbi\AppData\Roaming\LogFile.txt 2010-11-27 15:30 - 2010-11-27 15:33 - 0000298 _____ () C:\ProgramData\hpzinstall.log Some files in TEMP: ==================== C:\Users\Robbi\AppData\Local\Temp\webcompanioninstaller.exe ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\wininit.exe => File is digitally signed C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\dnsapi.dll => File is digitally signed C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-08-14 23:45 ==================== End of log ============================