Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-03-2020 Ran by Administrator (administrator) on DESKTOP-JITGEPI (LENOVO 2347H91) (26-03-2020 14:21:19) Running from C:\Users\chris\Desktop Loaded Profiles: chris & Administrator (Available Profiles: defaultuser0 & chris & Administrator) Platform: Windows 10 Pro Version 1809 17763.1098 (X64) Language: English (United States) Default browser: Edge Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) () [File not signed] C:\ActConnectLink\nssm-x64.exe (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Broadcom Corporation -> Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe (Carbonite -> Carbonite, Inc. (www.carbonite.com)) C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe (Cisco WebEx LLC -> Cisco WebEx LLC) C:\Windows\SysWOW64\atashost.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe (Flexera Software LLC -> Flexera Software LLC.) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Flexera Software LLC -> Flexera Software LLC.) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Flexera Software LLC -> Flexera Software LLC.) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Gladinet, Inc. -> ) C:\Program Files (x86)\Nuance\Nuance Cloud Connector\WOSVSSSvr.exe (Gladinet, Inc. -> Gladinet, INC) C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GladFileMonSvc.exe (Gladinet, Inc. -> Gladinet, INC) C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GladinetClient.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe (IDSA Production signing key -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe (IDSA Production signing key -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Intel(R) Software Development Products -> ) C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe (Intel(R) Software Development Products -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Lenovo -> Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo -> Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\PluginHost86\Lenovo.Modern.ImController.PluginHost.Device.exe (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\PluginHost86\Lenovo.Modern.ImController.PluginHost.Device.exe (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe (Lenovo -> Lenovo) C:\Windows\SysWOW64\Lenovo\PowerMgr\PowerMgr.exe (Lenovo -> Lenovo.) C:\Windows\System32\ibmpmsvc.exe (LogMeIn, Inc. -> LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe (LogMeIn, Inc. -> LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (McAfee, Inc. -> McAfee LLC.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe (McAfee, Inc. -> McAfee, LLC) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe (McAfee, Inc. -> McAfee, LLC) C:\Windows\System32\mfevtps.exe (McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\browserhost.exe (McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\servicehost.exe (McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\uihost.exe (McAfee, LLC -> McAfee, LLC.) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe (McAfee, LLC. -> McAfee, LLC) C:\Program Files\Common Files\McAfee\VSCore_20_1\mcapexe.exe (McAfee, LLC. -> McAfee, LLC.) C:\Program Files\Common Files\McAfee\CSP\3.4.105.0\McCSPServiceHost.exe (McAfee, LLC. -> McAfee, LLC.) C:\Program Files\Common Files\McAfee\ModuleCore\ProtectedModuleHost.exe (McAfee, LLC. -> McAfee, LLC.) C:\Program Files\Common Files\McAfee\PEF\CORE\PEFService.exe (McAfee, LLC. -> McAfee, LLC.) C:\Program Files\McAfee\MfeAV\MfeAVSvc.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL12.ACT7\MSSQL\Binn\sqlservr.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\LogonUI.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe (Microsoft) [File not signed] C:\Program Files (x86)\ACT\Act for Windows\Act.Server.Host.exe (Mixbyte Inc -> Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Node.js Foundation -> Node.js) C:\Program Files\nodejs\node.exe (Nuance Communications, Inc. -> Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Reimage Ltd. -> Reimage) C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe (Reimage Ltd. -> Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe (Siber Systems -> Siber Systems Inc.) C:\Program Files (x86)\Siber Systems\AI RoboForm\rf-chrome-nm-host.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated -> Synaptics) C:\Program Files\Synaptics\SynTP\SynLenovoHelper.exe (TeamViewer GmbH -> TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TechSmith Corporation -> TechSmith Corporation) C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe (TechSmith Corporation -> TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 13\SnagitEditor.exe 0 C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.56.102.0_x64__kzf8qxf38zg5c\SkypeApp.exe 0 C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.56.102.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe 0 C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_3.38.25003.0_x64__8wekyb3d8bbwe\GameBar.exe 0 C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_3.38.25003.0_x64__8wekyb3d8bbwe\GameBarFT.exe 0 C:\Program Files\WindowsApps\Microsoft.YourPhone_1.20022.82.0_x64__8wekyb3d8bbwe\YourPhone.exe 0 C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.20022.11011.0_x64__8wekyb3d8bbwe\Video.UI.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-25] (Logitech Inc -> Logitech, Inc.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16404224 2015-10-01] (Realtek Semiconductor Corp -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2015-10-01] (Realtek Semiconductor Corp -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2015-10-01] (Realtek Semiconductor Corp -> Realtek Semiconductor) HKLM\...\Run: [Reimage] => C:\Program Files\Reimage\Reimage Protector\ReimageApp.exe [263832 2019-07-07] (Reimage Ltd. -> reimage) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [302904 2019-10-26] (Apple Inc. -> Apple Inc.) HKLM-x32\...\Run: [PDFHook] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe [636192 2010-03-05] (Nuance Communications, Inc. -> Nuance Communications, Inc.) HKLM-x32\...\Run: [PDF5 Registry Controller] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc. -> Nuance Communications, Inc.) HKLM-x32\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\isuspm.exe [2068856 2011-10-12] (Flexera Software LLC -> Flexera Software LLC.) HKLM-x32\...\Run: [PaperPort PTD] => C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe [36168 2013-05-14] (Nuance Communications, Inc. -> Nuance Communications, Inc.) HKLM-x32\...\Run: [IndexSearch] => C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe [18248 2013-05-14] (Nuance Communications, Inc. -> Nuance Communications, Inc.) HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2133728 2017-09-12] (Wondershare Technology Co.,Ltd -> Wondershare) HKLM-x32\...\Run: [PowerPDF Registry Controller] => C:\Program Files (x86)\Nuance\Power PDF 21\RegistryController.exe [274216 2017-05-16] (Nuance Communications, Inc. -> Nuance Communications, Inc.) HKLM-x32\...\Run: [NuanPowerPdf1NPDFLM] => C:\Program Files (x86)\Nuance\Power PDF 21\NPDFLM.exe [3464816 2017-05-16] (Nuance Communications, Inc. -> Nuance Communications, Inc.) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5890504 2019-04-02] (LogMeIn, Inc. -> LogMeIn Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [645456 2019-04-01] (Oracle America, Inc. -> Oracle Corporation) HKLM-x32\...\Run: [Act! Preloader] => C:\Program Files (x86)\ACT\Act for Windows\Act!.exe [272336 2019-10-23] (Swiftpage ACT! LLC -> Swiftpage ACT! LLC) HKLM-x32\...\Run: [ISPA] => C:\Program Files (x86)\ACT\Act for Windows\Integration Services Patch for Act!\ISPA.exe [15635456 2019-07-26] () [File not signed] HKLM-x32\...\Run: [ProductUpdater] => C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe [240512 2019-12-25] (Mixbyte Inc -> ) HKLM-x32\...\Run: [Intel Driver & Support Assistant] => C:\Program Files (x86)\Intel\Driver and Support Assistant\DSATray.exe [237416 2020-03-03] (IDSA Production signing key -> Intel) HKLM-x32\...\RunOnce: [ExpressZipUninstall] => cmd.exe /C rmdir /S /Q "C:\Program Files (x86)\NCH Software\ExpressZip" HKLM-x32\...\RunOnce: [ExpressZipUninstall2] => cmd.exe /C rmdir /Q "C:\Program Files (x86)\NCH Software\ExpressZip" HKLM-x32\...\RunOnce: [ExpressZipUninstall3] => cmd.exe /C rmdir /S /Q "C:\Users\Administrator\AppData\Roaming\NCH Software\Program Files\ExpressZip" HKLM-x32\...\RunOnce: [ExpressZipUninstall4] => cmd.exe /C rmdir /Q "C:\Users\Administrator\AppData\Roaming\NCH Software\Program Files" HKLM-x32\...\RunOnce: [ExpressZipUninstall5] => cmd.exe /C rmdir /Q "C:\Users\Administrator\AppData\Roaming\NCH Software" HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [2068856 2011-10-12] (Flexera Software LLC -> Flexera Software LLC.) HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\Run: [ClipMate7] => C:\Program Files (x86)\ClipMate7\ClipMate.exe [5000320 2013-03-20] (Thornsoft Development, Inc. -> Thornsoft Development, Inc.) HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\Run: [Jing] => C:\Program Files (x86)\TechSmith\Jing\Jing.exe [2911224 2015-09-11] (TechSmith Corporation -> TechSmith Corporation) HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\Run: [QuickenScheduledUpdates] => C:\Program Files (x86)\Quicken\bagent.exe [77296 2020-02-07] (Quicken, Inc. -> Quicken Inc.) HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\Run: [Office Timeline Performance Helper] => C:\Program Files (x86)\Office Timeline\Current\OfficeTimelineStartup.exe [15840 2018-04-19] (Office Timeline, LLC -> OfficeTimeline LLC) HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\Run: [AirBackupHelper] => C:\Program Files (x86)\iMobie\AnyTrans\AirBackupHelper.exe [2445824 2019-04-19] (iMobie Inc. -> iMobie Inc.) HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\Run: [TeamSlideEngine] => C:\Program Files (x86)\Aploris\TeamSlide\TeamSlideEngine.exe [2322176 2018-09-06] (Aploris GmbH -> Aploris GmbH) HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\Run: [Zoner Photo Studio Autoupdate] => C:\PROGRAM FILES\ZONER\PHOTO STUDIO 19\Program32\ZPSTRAY.EXE [603592 2018-07-12] (ZONER software, a.s. -> ZONER software) HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [24552064 2019-10-14] (Piriform Software Ltd -> Piriform Ltd) HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\Run: [RoboForm] => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [145704 2019-12-29] (Siber Systems -> Siber Systems) HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\Run: [com.squirrel.WhatsApp.WhatsApp] => C:\Users\chris\AppData\Local\WhatsApp\Update.exe [2253232 2020-03-18] (WhatsApp, Inc -> ) HKU\S-1-5-21-1547701397-687303812-3400344658-500\...\Run: [RoboForm] => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [145704 2019-12-29] (Siber Systems -> Siber Systems) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\80.0.3987.149\Installer\chrmstp.exe [2020-03-18] (Google LLC -> Google LLC) AppInit_DLLs: C:\WINDOWS\Jaksta\AC\x64\jaudcap.dll => C:\WINDOWS\Jaksta\AC\x64\jaudcap.dll [309680 2018-11-12] (Jaksta Technologies Pty Ltd -> Jaksta Technologies Pty Ltd) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Act! Integration.lnk [2019-11-27] ShortcutTarget: Act! Integration.lnk -> C:\Program Files (x86)\ACT\Act for Windows\Act!.Integration.exe (Swiftpage ACT! LLC) [File not signed] Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Nuance Cloud Connector.lnk [2017-05-01] ShortcutTarget: Nuance Cloud Connector.lnk -> C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GladLauncher.exe (Gladinet, Inc. -> ) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start Btrieve Engine.lnk [2017-03-31] ShortcutTarget: Start Btrieve Engine.lnk -> C:\Windows\Installer\{0A3238D7-BB64-1206-B717-F3E3F18B4A8C}\ico_w3dbsmgr.exe (Acresso Software Inc.) [File not signed] Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TSC_SI_13.lnk [2017-04-20] ShortcutTarget: TSC_SI_13.lnk -> C:\Program Files (x86)\TechSmith\Snagit 13\Snagit32.exe (TechSmith Corporation -> TechSmith Corporation) Startup: C:\Users\chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Bookmark Buddy.lnk [2017-03-31] ShortcutTarget: Bookmark Buddy.lnk -> C:\Program Files (x86)\Bookmark Buddy\BmkBuddy.exe (Edward Leigh) [File not signed] Startup: C:\Users\chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2020-03-24] ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation) ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {03E4B40C-83BB-43CE-92B9-9DD51EACB420} - System32\Tasks\Lenovo\Power Manager\Background monitor => C:\WINDOWS\SysWOW64\Lenovo\PowerMgr\PowerMgr.exe [112824 2019-07-25] (Lenovo -> Lenovo) Task: {08080202-D18B-4D50-A7B0-882CF1842E81} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [24600440 2020-03-05] (Microsoft Corporation -> Microsoft Corporation) Task: {0C7964E4-DC95-45CE-AAA6-85AFF3CF0274} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe [4552120 2020-01-06] (McAfee, LLC -> McAfee, LLC.) Task: {0E64931C-0F7C-419E-8675-0155D95A7107} - System32\Tasks\Lenovo\Lenovo Service Bridge\S-1-5-21-1547701397-687303812-3400344658-1001 => C:\Users\chris\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSBUpdater.exe [122344 2019-04-04] (Lenovo (Beijing) Limited -> Lenovo Group Limited) Task: {0F3288D5-38E5-41CE-B37B-5C2472BB5258} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => "C:\WINDOWS\System32\Wscript.exe" //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs" Task: {1178FAB0-B23A-4506-8DC3-BA76F41CC510} - System32\Tasks\NCH Software\VideoPadCacheDeleteAll => C:\Program Files (x86)\NCH Software\VideoPad\VideoPad.exe [6965304 2019-09-26] (NCH Software, Inc. -> NCH Software) Task: {118B0A2C-3FA1-435E-B18D-C214042979CB} - System32\Tasks\4Team updater => C:\Program Files (x86)\4Team Corporation\4Team-Updater\4Team-Updater.exe Task: {1B1266D4-EA80-4E71-9028-81B9361F2148} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18744 2019-04-15] (Intel(R) Software Development Products -> Intel Corporation) Task: {1E304DB8-82C6-4961-A724-0F41047D8747} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616832 2019-09-04] (Apple Inc. -> Apple Inc.) Task: {217643F0-8C4E-4CEB-8CF3-D13B17FDBFD2} - System32\Tasks\Lenovo\Power Manager\Uninstall task => C:\WINDOWS\SysWOW64\Lenovo\PowerMgr\PowerMgrInst.exe [59576 2019-07-25] (Lenovo -> ) "C:\Windows\System32\Tasks\McAfee\McAfee Idle Detection Task" was unlocked. <==== ATTENTION Task: {2DB8BF0D-4B1E-4170-BB53-B85A8EC16448} - System32\Tasks\McAfee\McAfee Idle Detection Task => {ABCDCA3B-DE6B-5A7C-B132-6D7CBA63E5C5} C:\Program Files\Common Files\McAfee\TaskScheduler\McAMTaskAgent.exe [1072312 2020-02-04] (McAfee, LLC. -> McAfee, LLC.) Task: {2F7050A6-B86A-4833-97C4-BC6DF08D37EC} - System32\Tasks\Lenovo\BatteryGauge\BatteryGaugeMaintenance => "%windir%\system32\WindowsPowerShell\v1.0\PowerShell.exe" "powershell -executionpolicy bypass -file %ProgramData%\Lenovo\ImController\Plugins\LenovoBatteryGaugePackage\data\Maintenance.ps1" Task: {40987EDA-1303-4C0C-8152-38A225B0AA3C} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [608384 2019-10-14] (Piriform Software Ltd -> Piriform Software Ltd) Task: {4741C016-2BC6-4363-B4E1-A087FB00CFE8} - System32\Tasks\Lenovo Power Management Driver PnP Task => C:\WINDOWS\System32\ibmpmsvc.exe [949632 2019-12-11] (Lenovo -> Lenovo.) Task: {47BCE973-C0C8-42FE-B077-145AC971D0AB} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [115032 2020-03-17] (Microsoft Corporation -> Microsoft Corporation) Task: {4DE0676B-01E5-4A17-9633-3BBE1F59ADF3} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-04-25] (Dropbox, Inc -> Dropbox, Inc.) Task: {56A04323-78FD-4374-BEA8-0F6E1F7FDA61} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe [761424 2020-02-05] (McAfee, LLC. -> McAfee, LLC.) Task: {56AF25E2-0728-4C05-8097-69E3489EB17E} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 => C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [17184 2014-09-02] (LENOVO -> Lenovo) Task: {5748FB74-1F4C-4488-9D48-30AC60BECB63} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\57619bab-855c-4446-8786-4c397076ac36 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [80536 2020-02-11] (Lenovo -> Lenovo Group Ltd.) Task: {6D3082B7-E40C-4BFE-8CA3-A654EB80ABD2} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION Task: {7B9EAA29-83E3-4DF6-9B14-9A2046C8D21B} - System32\Tasks\Open URL by RoboForm => C:\WINDOWS\system32\rundll32.exe url.dll,FileProtocolHandler "hxxps://www.roboform.com/test-pass.html?aaa=KICMJJLJOMHMNMKMPMGMCNIMJMMMHMCNLMIMHMMJCNOJMMOJPMCNNJLMKMLMKMNMIMOMMMNMMJOJJNJICMHMCNJMCNKMFMOMOMCNGMOMLMCNOMIMIMJMMMFMPMCNPMCNOMIMIMJMMMCNNMJNPICMOMFMEKMICNJJCKFMOMPMPMIMJNHICMEKMICNJJCKJNBJCMMJHJNIGJMIJNKJCMMJOJDJDJOJBJNMIMO (the data entry has 92 more characters). Task: {7BEB8B3C-DF19-4F35-B5BD-D05D6777B761} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [24600440 2020-03-05] (Microsoft Corporation -> Microsoft Corporation) Task: {7BF09FA8-E729-481A-9A20-A9A9529CBA46} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => "%windir%\system32\sc.exe" START ImControllerService Task: {7EB0C82A-00F3-4E4D-B11D-4F36DA76D808} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent => {ABCECA3B-EA5A-496B-A021-5C6BAB365E5C} C:\Program Files\Common Files\McAfee\TaskScheduler\McAMTaskAgent.exe [1072312 2020-02-04] (McAfee, LLC. -> McAfee, LLC.) Task: {81AD2D78-076F-4719-8727-87BDAB825859} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask => %windir%\System32\reg.exe add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler /v start /t reg_dword /d 1 /f /reg:32 Task: {83CB9BFC-5D50-4E91-B580-A8AACCB960A6} - System32\Tasks\G2MUploadTask-S-1-5-21-1547701397-687303812-3400344658-1001 => C:\Users\chris\AppData\Local\GoToMeeting\17052\g2mupload.exe [32256 2020-03-13] (LogMeIn, Inc. -> LogMeIn, Inc.) Task: {8574FE17-9A0C-48FC-BAF8-CD316C873713} - System32\Tasks\DolbySelectorTask => C:\Program Files\Dolby Digital Plus\ddp.exe Task: {88599FB7-191A-4A95-9234-8BA210A3EB1C} - System32\Tasks\G2MUpdateTask-S-1-5-21-1547701397-687303812-3400344658-1001 => C:\Users\chris\AppData\Local\GoToMeeting\17052\g2mupdate.exe [32256 2020-03-13] (LogMeIn, Inc. -> LogMeIn, Inc.) Task: {8D7E1F39-D9AB-423F-9B03-C04C1BDA847F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18458752 2019-10-14] (Piriform Software Ltd -> Piriform Ltd) Task: {8F53A02B-129C-463D-A796-97B82136AB03} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18744 2019-04-15] (Intel(R) Software Development Products -> Intel Corporation) Task: {904FD4CA-6658-4561-AB00-D8AFB7DF6C24} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-03-13] (Google LLC -> Google LLC) Task: {90B83C18-7E1D-4BCA-BDB2-40979BA4B91A} - System32\Tasks\Lenovo\LSC\Lenovo Solution Center Notifications => C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe [1321240 2018-09-06] (Lenovo -> Lenovo) Task: {94C32AF9-8D43-4B60-9554-D0951055C79D} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\685e78ff-a106-44f3-b6cd-b890a10ebc4d => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [80536 2020-02-11] (Lenovo -> Lenovo Group Ltd.) Task: {98DA132C-70DD-4317-B197-58F49EEE5058} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\Lenovo\Lenovo Solution Center\App\LSC.Services.UpdateStatusService.exe [331544 2018-09-06] (Lenovo -> ) Task: {A0CF7094-68A5-44D6-A382-FBF244959CF7} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Monitor => C:\WINDOWS\system32\ImController.InfInstaller.exe [54424 2020-02-11] (Lenovo -> Lenovo Group Ltd.) Task: {A2468796-AC47-4D3C-8F46-CD4A970A1EF1} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [10920216 2018-09-06] (Lenovo -> Lenovo) Task: {A48EB6CC-2E8F-4DF8-997D-8467F15FAB5C} - System32\Tasks\{5F6010C8-60E5-41f3-BF5B-C3AF5DBE12D4} => Powershell -noexit -command "&{$carbProgramDataPath = $env:ProgramData + '\Carbonite\Carbonite Backup\';$upgradeExe = 'CarboniteUpgrade.exe';$upgradeFullPath = $carbProgramDataPath + $upgradeExe;$logFile = 'CarboniteUpgrade.log';$logFileFullPath = $carbProgramDataPath + $logFile;$psversion = [string]$psversio (the data entry has 1818 more characters). Task: {AF22DAE8-7EE6-433A-8D0A-0B91DCD638E0} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [115032 2020-03-17] (Microsoft Corporation -> Microsoft Corporation) Task: {BB121B46-1EA1-49EC-9D1A-E57881FCAC6D} - System32\Tasks\NCH Software\ExpressZipDowngrade => C:\Program Files (x86)\NCH Software\ExpressZip\expresszip.exe Task: {C6013790-296B-4D6B-BE90-8BB2B5913C06} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\553b7280-8356-460d-94f6-bb191e03adbc => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [80536 2020-02-11] (Lenovo -> Lenovo Group Ltd.) Task: {C7A0FCF7-FDE6-403E-94D0-B4DD20850C2E} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-04-25] (Dropbox, Inc -> Dropbox, Inc.) Task: {D34747EE-7407-493B-BBBE-503FD4F0CE34} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe Task: {D70379B7-048C-4CF2-922D-43D68D9DA727} - System32\Tasks\Duplicate Files Fixer_startup => C:\Program Files (x86)\Duplicate Files Fixer\DuplicateFilesFixer.exe Task: {E19AD098-8783-4A6E-9C5A-DD608F7CF1A4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-03-13] (Google LLC -> Google LLC) Task: {E2C17170-B066-45C9-B935-25E390341C13} - System32\Tasks\Run RoboForm TaskBar Icon => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [145704 2019-12-29] (Siber Systems -> Siber Systems) Task: {EE21E588-CBA2-4787-B502-25932E085BFB} - System32\Tasks\LaunchChromeTask111 => C:\Program Files\FileZilla FTP Client\FileZilla.exe [10441896 2018-10-04] (Tim Kosse -> FileZilla Project) Task: {F1EBC414-3E14-464E-AA61-9D8A17E2F17E} - System32\Tasks\NCH Software\PrismDowngrade => C:\Program Files (x86)\NCH Software\Prism\Prism.exe [2311720 2019-01-09] (NCH Software Pty Ltd -> NCH Software) Task: {F95EA272-3BEC-464F-9236-2FA4A5A2B678} - System32\Tasks\Reimage-Post-Reboot => C:\ReimageUndo\PostReboot\PostRebootExecuter.exe [4071784 2020-03-25] (Reimage Limited -> ) <==== ATTENTION (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-1547701397-687303812-3400344658-1001.job => C:\Users\chris\AppData\Local\GoToMeeting\17052\g2mupdate.exe Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-1547701397-687303812-3400344658-1001.job => C:\Users\chris\AppData\Local\GoToMeeting\17052\g2mupload.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\..\Interfaces\{14373ebc-2f96-4c72-867e-489ec2439929}: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{34095199-8759-453a-8aa6-a3e340187ad9}: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{6dc42b3c-4a18-4426-b117-8154c36c0a00}: [DhcpNameServer] 192.168.2.1 198.235.214.4 Tcpip\..\Interfaces\{9c98313a-3799-42d3-81f3-d2df6b473a17}: [DhcpNameServer] 192.168.0.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-1547701397-687303812-3400344658-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKU\S-1-5-21-1547701397-687303812-3400344658-1001 -> {76DEFAE6-09B2-40B2-8F8A-5A6A5D5CE4EB} URL = hxxps://search.yahoo.com/search/?toggle=1&cop=mss&ei=UTF-8&fr=vmn&type=auslog_yaapp6_adw_ch&p={searchTerms} BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2020-01-10] (Microsoft Corporation -> Microsoft Corporation) BHO: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2019-12-29] (Siber Systems -> Siber Systems Inc.) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_211\bin\ssv.dll [2019-04-16] (Oracle America, Inc. -> Oracle Corporation) BHO: Nuance PDF Conversion Toolbar Helper -> {940361F8-7F16-4498-AB43-2EFFE0235AFA} -> C:\Program Files (x86)\Nuance\Power PDF 21\Bin\SPDFIEFavClient_x64.dll [2017-02-10] (Nuance Communications, Inc. -> Zeon Corporation) BHO: PlusIEEventHelper Class -> {9D137966-2E29-45C5-9B12-29D5427F8F66} -> C:\Program Files (x86)\Nuance\Power PDF 21\Bin\PlusIEContextMenu_x64.dll [2017-02-10] (Nuance Communications, Inc. -> Zeon Corporation) BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-25] (Logitech Inc -> Logitech, Inc.) BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\x64\IEPlugin.dll [2020-03-10] (McAfee, LLC -> McAfee, LLC) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_211\bin\jp2ssv.dll [2019-04-16] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll [2009-02-06] (Zeon Corporation) [File not signed] BHO-x32: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2019-12-29] (Siber Systems -> Siber Systems Inc.) BHO-x32: Nuance PDF Conversion Toolbar Helper -> {940361F8-7F16-4498-AB43-2EFFE0235AFA} -> C:\Program Files (x86)\Nuance\Power PDF 21\Bin\SPDFIEFavClient.dll [2017-02-10] (Nuance Communications, Inc. -> Zeon Corporation) BHO-x32: PlusIEEventHelper Class -> {9D137966-2E29-45C5-9B12-29D5427F8F66} -> C:\Program Files (x86)\Nuance\Power PDF 21\Bin\PlusIEContextMenu.dll [2017-02-10] (Nuance Communications, Inc. -> Zeon Corporation) BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-25] (Logitech Inc -> Logitech, Inc.) BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll [2020-03-10] (McAfee, LLC -> McAfee, LLC) BHO-x32: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile -> {D5233FCD-D258-4903-89B8-FB1568E7413D} -> C:\Program Files (x86)\ACT\Act for Windows\Plugins\Act.UI.InternetExplorer.Plugins.AttachFile.DLL [2019-10-23] (Swiftpage ACT! LLC) [File not signed] Toolbar: HKLM - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2019-12-29] (Siber Systems -> Siber Systems Inc.) Toolbar: HKLM - &ClipMate ClipBar v7.5 - {F60C63CE-52AF-4915-AAC9-F100FCDE270F} - C:\Program Files (x86)\ClipMate7\ClipMateDeskBand.dll [2013-03-20] (Thornsoft Development, Inc. -> Thornsoft Development, Inc) Toolbar: HKLM - Nuance PDF Toolbar - {BED78D9C-A025-4FE9-B3BA-27E6D376A3D5} - C:\Program Files (x86)\Nuance\Power PDF 21\Bin\SPDFIEFavClient_x64.dll [2017-02-10] (Nuance Communications, Inc. -> Zeon Corporation) Toolbar: HKLM-x32 - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2019-12-29] (Siber Systems -> Siber Systems Inc.) Toolbar: HKLM-x32 - Nuance PDF Toolbar - {BED78D9C-A025-4FE9-B3BA-27E6D376A3D5} - C:\Program Files (x86)\Nuance\Power PDF 21\Bin\SPDFIEFavClient.dll [2017-02-10] (Nuance Communications, Inc. -> Zeon Corporation) Toolbar: HKU\S-1-5-21-1547701397-687303812-3400344658-1001 -> &RoboForm Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2019-12-29] (Siber Systems -> Siber Systems Inc.) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-03-09] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-03-09] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-03-09] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-03-09] (Microsoft Corporation -> Microsoft Corporation) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll No File Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files\McAfee\MSC\McSnIePl64.dll [2020-02-05] (McAfee, LLC. -> McAfee, LLC.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2020-02-05] (McAfee, LLC. -> McAfee, LLC.) FireFox: ======== FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi FF Extension: (McAfee® WebAdvisor) - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi [2020-03-10] [UpdateUrl:hxxps://www.siteadvisor.com/waffinstall/update.json] FF HKLM\...\Firefox\Extensions: [sweb2pdfextension.3@nuance.com] - C:\Program Files (x86)\Nuance\Power PDF 21\bin\SFirefoxExtn FF Extension: (Nuance PDF Create) - C:\Program Files (x86)\Nuance\Power PDF 21\bin\SFirefoxExtn [2018-03-05] [Legacy] FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2017-04-11] [Legacy] [not signed] FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi FF HKLM-x32\...\Firefox\Extensions: [sweb2pdfextension.3@nuance.com] - C:\Program Files (x86)\Nuance\Power PDF 21\bin\SFirefoxExtn FF Plugin: @java.com/DTPlugin,version=11.211.2 -> C:\Program Files\Java\jre1.8.0_211\bin\dtplugin\npDeployJava1.dll [2019-04-16] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.211.2 -> C:\Program Files\Java\jre1.8.0_211\bin\plugin2\npjp2.dll [2019-04-16] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @mcafee.com/MSC,version=10 -> C:\Program Files\McAfee\MSC\npMcSnFFPl64.dll [2020-02-05] (McAfee, LLC. -> ) FF Plugin-x32: @mcafee.com/MSC,version=10 -> C:\Program Files (x86)\McAfee\MSC\npMcSnFFPl.dll [2020-02-05] (McAfee, LLC. -> ) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-01-10] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @videolan.org/vlc,version=3.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN) FF Plugin HKU\S-1-5-21-1547701397-687303812-3400344658-1001: @zoom.us/ZoomVideoPlugin -> C:\Users\chris\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2019-11-13] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) Chrome: ======= CHR Profile: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default [2020-03-01] CHR HomePage: Default -> hxxps://ca.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_16_05¶m1=1¶m2=f%3D1%26b%3DChrome%26cc%3Dca%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuzzyEyE0B0FyDyD0A0B0DyEtBtAyDyCtDtN0D0Tzu0StCyEzyyEtN1L2XzutAtFtCyBtFzytFtDtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2SyD0DyCzy0DzztAzytGyE0EzztBtG0A0D0BtBtGtBtDzzyDtGtDzy0AzyyDzz0EyE0DzzyDtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0AzzyEzz0D0F0FyCtG0Ezy0E0DtGyEtA0EyCtG0Bzz0C0FtG0AtCzzyE0C0DyDyE0F0DtDyB2QtN0A0LzutBtN1B2Z1V1T1S1NzutCyDtByD%26cr%3D1641846358%26a%3Dwbf_secureddownload_16_05%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro CHR StartupUrls: Default -> "hxxp://www.msn.com/" CHR DefaultSearchURL: Default -> hxxps://ca.search.yahoo.com/search?fr=mcafee&type=E211CA0G0&p={searchTerms} CHR DefaultSearchKeyword: Default -> mcafee CHR DefaultSuggestURL: Default -> hxxps://ca.search.yahoo.com/sugg/gossip/gossip-ca-partner?output=fxjson&appid=mca&source=yahoo_mcafee_searchassist&command={searchTerms} CHR Extension: (Slides) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-02-25] CHR Extension: (Logitech Unifying for Chrome) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\agpmgihmmmfkbhckmciedmhincdggomo [2020-02-25] CHR Extension: (Docs) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-02-25] CHR Extension: (Google Drive) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-02-25] CHR Extension: (FreeConferenceCall.com Launcher) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkkkecfjcahaciigdkmmbfaoejneoogj [2020-02-25] CHR Extension: (YouTube) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-02-25] CHR Extension: (NoCountryRedirect (NCR)) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ciboebddidackjicoeoiigdnbmchkdll [2020-02-25] CHR Extension: (Logitech Smooth Scrolling) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkpejdfnpdkhifgbancbammdijojoffk [2020-02-25] CHR Extension: (Full Page Screen Capture) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdpohaocaechififmbbbbbknoalclacl [2020-02-25] CHR Extension: (Sheets) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-02-25] CHR Extension: (Web) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgbpjpemfgkbddnaiabmaejehjldmipo [2020-02-25] CHR Extension: (McAfee® WebAdvisor) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2020-02-25] CHR Extension: (Page Analytics (by Google)) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnbdnhhicmebfgdgglcdacdapkcihcoh [2020-02-25] CHR Extension: (GoToMeeting for Google Calendar) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gaonpiemcjiihedemhopdoefaohcjoch [2020-02-25] CHR Extension: (Maps Now) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggggbffdgiaofjlokjhjcpgpnfjclbdm [2020-02-25] CHR Extension: (Google Docs Offline) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-02-25] CHR Extension: (Keywords Everywhere - Keyword Tool) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbapdpeemoojbophdfndmlgdhppljgmp [2020-02-25] CHR Extension: (My Roundcube webmail) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hemjkpdgjdjlibimlhodpokkpaanmmdk [2020-02-25] CHR Extension: (zipBoard) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjggbopcacdchdecegldbeknhpeiheaf [2020-02-25] CHR Extension: (Kudani Snipper) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\honhcoadmdmlnlepogdkgfgedhhcdjbe [2020-02-25] CHR Extension: (Bitly | Unleash the power of the link) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\iabeihobmhlgpkcgjiloemdbofjbdcic [2020-02-25] CHR Extension: (Cisco Webex Extension) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlhmfgmfgeifomenelglieieghnjghma [2020-02-25] CHR Extension: (Google Keep Chrome Extension) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpcaedmchfhocbbapmcbpinfpgnhiddi [2020-03-01] CHR Extension: (Pocket) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk [2020-02-25] CHR Extension: (Save to Pocket) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\niloccemoadcdkdjlinkgdfekeahmflj [2020-02-25] CHR Extension: (Tab Colorizer | Customize your tab's color!) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkdjooaecafkkldnkaokhpaindamlngj [2020-02-25] CHR Extension: (Chrome Web Store Payments) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-02-25] CHR Extension: (Oxford English Dictionary) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nplekinjngkpgapibdafdokfipohijkc [2020-02-25] CHR Extension: (Gmail) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-02-25] CHR Extension: (Chrome Media Router) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-03-01] CHR Extension: (Diigo Web Collector - Capture and Annotate) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnhplgjpclknigjpccbcnmicgcieojbh [2020-02-25] CHR Extension: (RoboForm Password Manager) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnlccmojcmeohlpggmfnbbiapkmbliob [2020-02-25] CHR Extension: (Ad Remover) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pogpkmdlehipcepphjbogapenmkbimpo [2020-02-25] CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] CHR HKLM\...\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2017-03-27] CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] CHR HKLM-x32\...\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2017-03-27] ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S2 Act! Scheduler; C:\Program Files (x86)\ACT\Act for Windows\Act.Scheduler.exe [90112 2019-10-23] (Swiftpage ACT! LLC) [File not signed] R2 ActConnectLink; C:\ActConnectLink\nssm-x64.exe [331264 2014-08-31] () [File not signed] R2 ActService; C:\Program Files (x86)\ACT\Act for Windows\Act.Server.Host.exe [27136 2019-10-23] (Microsoft) [File not signed] R2 ActSmartTaskService; C:\Program Files (x86)\ACT\Act for Windows\Act.Server.Host.exe [27136 2019-10-23] (Microsoft) [File not signed] S2 ActWebApiService; C:\Program Files (x86)\ACT\Act.Web.API\bin\act.web.api.hosting.exe [22016 2019-09-19] () [File not signed] R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [96056 2019-10-07] (Apple Inc. -> Apple Inc.) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11091224 2020-03-05] (Microsoft Corporation -> Microsoft Corporation) S3 ClientAnalyticsService; C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe [1508656 2018-05-31] (McAfee, Inc. -> McAfee, Inc.) S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-04-25] (Dropbox, Inc -> Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-04-25] (Dropbox, Inc -> Dropbox, Inc.) R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [44552 2020-03-19] (Dropbox, Inc -> Dropbox, Inc.) R2 DSAService; C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe [37224 2020-03-03] (IDSA Production signing key -> Intel) R3 DSAUpdateService; C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe [143720 2020-03-03] (IDSA Production signing key -> Intel) R2 ESRV_SVC_QUEENCREEK; C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe [877368 2019-08-16] (Intel(R) Software Development Products -> ) R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [81280 2019-12-25] (Mixbyte Inc -> Freemake) R2 GladFileMonSvc; C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GladFileMonSvc.exe [30032 2013-05-05] (Gladinet, Inc. -> Gladinet, INC) R2 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [3361736 2019-04-02] (LogMeIn, Inc. -> LogMeIn Inc.) R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [319520 2019-12-18] (Intel(R) pGFX -> Intel Corporation) R2 ImControllerService; C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [80536 2020-02-11] (Lenovo -> Lenovo Group Ltd.) S3 InstallService; C:\WINDOWS\system32\InstallService.dll [1671680 2020-03-11] (Microsoft Windows -> Microsoft Corporation) [File not signed] S3 InstallService; C:\WINDOWS\SysWOW64\InstallService.dll [1249280 2020-03-11] (Microsoft Corporation) [File not signed] S3 Intel(R) SUR QC SAM; C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18744 2019-04-15] (Intel(R) Software Development Products -> Intel Corporation) R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [419248 2016-05-27] (LogMeIn, Inc. -> LogMeIn, Inc.) S2 LPlatSvc; C:\WINDOWS\System32\LPlatSvc.exe [892288 2019-12-11] (Lenovo -> Lenovo.) S3 LSC.Services.SystemService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSC.Services.SystemService.exe [337688 2018-09-06] (Lenovo -> Lenovo) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6933272 2020-02-29] (Malwarebytes Inc -> Malwarebytes) R2 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [907224 2020-03-10] (McAfee, LLC -> McAfee, LLC) R2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_20_1\McApExe.exe [758864 2020-02-05] (McAfee, LLC. -> McAfee, LLC) R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\3.4.105.0\\McCSPServiceHost.exe [2687856 2020-01-25] (McAfee, LLC. -> McAfee, LLC.) S3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [639048 2020-01-09] (McAfee, Inc. -> McAfee, LLC) R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [639048 2020-01-09] (McAfee, Inc. -> McAfee, LLC) R3 mfevtp; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [639048 2020-01-09] (McAfee, Inc. -> McAfee, LLC) R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1737992 2020-02-06] (McAfee, LLC -> McAfee, LLC.) R2 MSSQL$ACT7; C:\Program Files\Microsoft SQL Server\MSSQL12.ACT7\MSSQL\Binn\sqlservr.exe [370368 2014-02-21] (Microsoft Corporation -> Microsoft Corporation) R2 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [77640 2013-05-14] (Nuance Communications, Inc. -> Nuance Communications, Inc.) R2 PEFService; C:\Program Files\Common Files\McAfee\PEF\CORE\PEFService.exe [1373912 2020-02-04] (McAfee, LLC. -> McAfee, LLC.) R2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [8944800 2019-05-23] (Reimage Ltd. -> Reimage®) S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-02-28] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5897968 2020-03-11] (Microsoft Windows Publisher -> Microsoft Corporation) S4 SQLAgent$ACT7; C:\Program Files\Microsoft SQL Server\MSSQL12.ACT7\MSSQL\Binn\SQLAGENT.EXE [613056 2014-02-21] (Microsoft Corporation -> Microsoft Corporation) R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [243632 2019-07-03] (Synaptics Incorporated -> Synaptics Incorporated) R2 SystemUsageReportSvc_QUEENCREEK; C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe [204088 2019-08-16] (Intel(R) Software Development Products -> ) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10883824 2017-03-17] (TeamViewer GmbH -> TeamViewer GmbH) R2 TechSmith Uploader Service; C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe [3661096 2015-09-14] (TechSmith Corporation -> TechSmith Corporation) S3 USER_ESRV_SVC_QUEENCREEK; C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe [877368 2019-08-16] (Intel(R) Software Development Products -> ) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\NisSrv.exe [3294680 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MsMpEng.exe [103168 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WsDrvInst; C:\Program Files (x86)\Wondershare\Video Converter Ultimate\Transfer\DriverInstall.exe [111368 2020-03-09] (Wondershare Technology Co.,Ltd -> Wondershare) ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R0 amdkmpfd; C:\WINDOWS\System32\drivers\amdkmpfd.sys [87584 2017-01-17] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) R3 BrSerIb; C:\WINDOWS\system32\DRIVERS\BrSerIb.sys [95344 2014-06-06] (Brother Industries, Ltd. -> Brother Industries Ltd.) R3 BrUsbSIb; C:\WINDOWS\system32\DRIVERS\BrUsbSIb.sys [21872 2014-06-06] (Brother Industries, Ltd. -> Brother Industries Ltd.) S3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [75896 2020-01-15] (McAfee, Inc. -> McAfee, LLC) R3 e1cexpress; C:\WINDOWS\system32\DRIVERS\e1c65x64.sys [472016 2016-03-29] (Intel(R) INTELNPG1 -> Intel Corporation) R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153312 2020-02-29] (Malwarebytes Corporation -> Malwarebytes) R3 ETDSMBus; C:\WINDOWS\System32\drivers\ETDSMBus.sys [32840 2017-02-10] (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronic Corp.) R0 FlashBoot; C:\WINDOWS\System32\drivers\FlashBoot.sys [17616 2014-04-03] (Challenger Backup Solutions, LLC -> Challenger Backup Solutions, LLC) R3 Hamachi; C:\WINDOWS\System32\drivers\Hamdrv.sys [45680 2017-05-22] (Microsoft Windows Hardware Compatibility Publisher -> LogMeIn Inc.) S3 HipShieldK; C:\WINDOWS\System32\drivers\HipShieldK.sys [217912 2019-06-04] (McAfee, LLC -> McAfee, Inc.) R3 jakstaVA; C:\WINDOWS\system32\DRIVERS\jaksta_va.sys [103816 2017-02-23] (Jaksta Technologies Pty Ltd -> e2eSoft) R3 LnvHIDHW; C:\WINDOWS\System32\drivers\LnvHIDHW.sys [42544 2017-07-23] (Lenovo -> Lenovo) R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [214496 2020-02-29] (Malwarebytes Inc -> Malwarebytes) S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2020-02-29] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [226448 2020-03-26] (Malwarebytes Inc -> Malwarebytes) R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [73584 2020-03-26] (Malwarebytes Corporation -> Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248968 2020-03-26] (Malwarebytes Inc -> Malwarebytes) R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [119960 2020-03-26] (Malwarebytes Inc -> Malwarebytes) R3 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [527272 2020-01-15] (McAfee, Inc. -> McAfee, LLC) R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [380840 2020-01-15] (McAfee, Inc. -> McAfee, LLC) S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [85920 2020-01-15] (Microsoft Windows Early Launch Anti-malware Publisher -> McAfee, LLC) R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [521128 2020-01-15] (McAfee, Inc. -> McAfee, LLC) R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [997800 2020-01-15] (McAfee, Inc. -> McAfee, LLC) R3 mfencbdc; C:\WINDOWS\System32\DRIVERS\mfencbdc.sys [594360 2019-12-23] (McAfee, Inc. -> McAfee LLC.) S3 mfencrk; C:\WINDOWS\System32\DRIVERS\mfencrk.sys [107960 2019-12-23] (McAfee, Inc. -> McAfee LLC.) R3 mfeplk; C:\WINDOWS\System32\drivers\mfeplk.sys [116856 2020-01-15] (McAfee, Inc. -> McAfee, LLC) R0 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [252328 2020-01-15] (McAfee, Inc. -> McAfee, LLC) R3 NETwNe64; C:\WINDOWS\System32\drivers\NETwew01.sys [3343872 2018-09-15] (Microsoft Windows -> Intel Corporation) R2 npf; C:\WINDOWS\system32\drivers\npf.sys [36600 2013-02-28] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.) R0 PMDRVS; C:\WINDOWS\System32\drivers\pmdrvs.sys [38160 2019-12-11] (Lenovo -> Lenovo.) R3 RCUVCAVS; C:\WINDOWS\system32\DRIVERS\RCUVCAVS.sys [177920 2013-07-05] (Microsoft Windows Hardware Compatibility Publisher -> Ricoh co.,Ltd.) R3 risdxc; C:\WINDOWS\System32\drivers\risdxc64.sys [106496 2013-09-09] (Microsoft Windows Hardware Compatibility Publisher -> REDC) S4 RsFx0300; C:\WINDOWS\System32\DRIVERS\RsFx0300.sys [247488 2014-02-21] (Microsoft Corporation -> Microsoft Corporation) R3 semav6msr64; C:\WINDOWS\system32\drivers\semav6msr64.sys [41816 2019-08-16] (Intel Corporation -> ) S3 ssmirrdr; C:\WINDOWS\system32\DRIVERS\ssmirrdr.sys [10112 2016-01-07] (support.com, Inc. -> support.com, Inc) S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2017-11-27] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.) S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45960 2020-03-25] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [391392 2020-03-25] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [59104 2020-03-25] (Microsoft Windows -> Microsoft Corporation) R1 ZAM; C:\Windows\System32\drivers\zam64.sys [203680 2017-04-11] (Zemana Ltd. -> Zemana Ltd.) R1 ZAM_Guard; C:\Windows\System32\drivers\zamguard64.sys [203680 2017-04-11] (Zemana Ltd. -> Zemana Ltd.) S3 ldiagio_uefi; \??\C:\Program Files\Lenovo\Lenovo Solution Center\App\ldiag\x64\ldiagio_uefi.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) =================== (If an entry is included in the fixlist, the file/folder will be moved.) 2020-03-26 14:21 - 2020-03-26 14:22 - 000059478 _____ C:\Users\chris\Desktop\FRST.txt 2020-03-26 11:48 - 2020-03-26 11:48 - 000000000 ____D C:\Users\chris\AppData\LocalLow\IGDump 2020-03-26 11:26 - 2020-03-26 11:48 - 000073584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2020-03-26 11:26 - 2020-03-26 11:26 - 000226448 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys 2020-03-26 11:17 - 2020-03-26 11:18 - 002279936 _____ (Farbar) C:\Users\chris\Desktop\FRST64.exe 2020-03-26 09:35 - 2020-03-26 11:26 - 000248968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys 2020-03-26 09:35 - 2020-03-26 09:35 - 000119960 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 2020-03-25 17:29 - 2020-03-25 17:29 - 000001648 _____ C:\Users\chris\Downloads\meeting-686536791.ics 2020-03-24 20:10 - 2020-03-24 20:10 - 000002500 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk 2020-03-24 20:10 - 2020-03-24 20:10 - 000002499 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk 2020-03-24 20:10 - 2020-03-24 20:10 - 000002463 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk 2020-03-24 20:10 - 2020-03-24 20:10 - 000002462 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk 2020-03-24 20:10 - 2020-03-24 20:10 - 000002456 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk 2020-03-24 20:10 - 2020-03-24 20:10 - 000002450 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk 2020-03-24 20:10 - 2020-03-24 20:10 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk 2020-03-24 20:10 - 2020-03-24 20:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools 2020-03-24 13:58 - 2020-03-24 13:58 - 000015844 _____ C:\Users\chris\Downloads\Before_We_Forget_2019...._1585072683262.csv 2020-03-24 13:48 - 2020-03-24 13:48 - 000016580 _____ C:\Users\chris\Downloads\Clicking_for_Clients_1585072099813.csv 2020-03-24 11:59 - 2020-03-24 11:59 - 000013693 _____ C:\Users\chris\Downloads\Ciovid-19 CIG unopened.xlsx 2020-03-24 11:58 - 2020-03-24 11:58 - 000014628 _____ C:\Users\chris\Downloads\Corporate_HR_Has_Key_Role_in_COVID-19_Fight_1585065501050.csv 2020-03-22 13:36 - 2020-03-22 13:36 - 000553951 _____ C:\Users\chris\Downloads\transactions (13).csv 2020-03-22 13:32 - 2020-03-22 13:32 - 000551009 _____ C:\Users\chris\Downloads\transactions (12).csv 2020-03-21 18:12 - 2020-03-21 18:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2020-03-19 18:55 - 2020-03-19 18:55 - 000000000 ____D C:\WINDOWS\Minidump 2020-03-19 14:19 - 2020-03-19 14:19 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys 2020-03-19 14:19 - 2020-03-19 14:19 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys 2020-03-19 14:19 - 2020-03-19 14:19 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys 2020-03-19 14:19 - 2020-03-19 14:19 - 000044552 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe 2020-03-18 17:43 - 2020-03-18 17:43 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\WhatsApp 2020-03-18 17:43 - 2020-03-18 17:43 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WhatsApp 2020-03-17 17:18 - 2020-03-17 17:18 - 000008322 _____ C:\Users\chris\Downloads\audio_import (14).txt 2020-03-17 10:14 - 2020-03-17 10:14 - 000011927 _____ C:\Users\chris\Downloads\audio_import (13).txt 2020-03-16 12:03 - 2020-03-16 12:03 - 000000000 ____D C:\Users\chris\Documents\Audacity 2020-03-16 12:02 - 2020-03-16 16:20 - 000000000 ____D C:\Users\chris\AppData\Roaming\audacity 2020-03-16 12:02 - 2020-03-16 12:02 - 000001095 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk 2020-03-16 12:02 - 2020-03-16 12:02 - 000001083 _____ C:\Users\Public\Desktop\Audacity.lnk 2020-03-16 12:02 - 2020-03-16 12:02 - 000001083 _____ C:\ProgramData\Desktop\Audacity.lnk 2020-03-16 12:02 - 2020-03-16 12:02 - 000000000 ____D C:\Users\chris\AppData\Local\Audacity 2020-03-16 12:01 - 2020-03-16 12:02 - 000000000 ____D C:\Program Files (x86)\Audacity 2020-03-16 11:58 - 2020-03-16 12:00 - 022430048 _____ (Audacity Team ) C:\Users\chris\Downloads\audacity-win-2.3.3.exe 2020-03-15 20:28 - 2020-03-15 20:28 - 000001274 _____ C:\Users\chris\Desktop\Switch Sound File Converter.lnk 2020-03-15 20:28 - 2020-03-15 20:28 - 000001260 _____ C:\Users\chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Switch Sound File Converter.lnk 2020-03-15 20:28 - 2020-03-15 20:28 - 000000000 ____D C:\Users\chris\NCH Software Suite 2020-03-15 19:24 - 2020-03-15 19:24 - 000000000 ____D C:\Users\chris\AppData\Roaming\Replay Converter 6 2020-03-15 19:18 - 2020-03-15 19:18 - 000000000 ____D C:\Users\Administrator\Documents\Applian 2020-03-15 19:18 - 2020-03-15 19:18 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Replay Converter 6 2020-03-15 19:18 - 2020-03-15 19:18 - 000000000 ____D C:\Users\Administrator\AppData\Local\Jaksta_Technologies_Pty_L 2020-03-15 19:17 - 2020-03-15 19:17 - 000001353 _____ C:\Users\Public\Desktop\Replay Converter 6.lnk 2020-03-15 19:17 - 2020-03-15 19:17 - 000001353 _____ C:\ProgramData\Desktop\Replay Converter 6.lnk 2020-03-15 19:12 - 2020-03-15 19:16 - 030422288 _____ (Applian Technologies) C:\Users\chris\Downloads\RCSetup.exe 2020-03-15 19:07 - 2020-03-15 19:12 - 016431088 _____ (Applian Technologies) C:\Users\chris\Downloads\Unconfirmed 628665.crdownload 2020-03-15 15:16 - 2020-03-15 15:16 - 000000000 ____D C:\Users\chris\AppData\Roaming\Wondershare 2020-03-15 15:16 - 2020-03-15 15:16 - 000000000 ____D C:\Users\chris\AppData\Roaming\TransferSupport 2020-03-15 15:07 - 2020-03-15 15:07 - 000000000 ____D C:\Wondershare UniConverter 2020-03-15 15:07 - 2020-03-15 15:07 - 000000000 ____D C:\Program Files (x86)\WondershareUpdate 2020-03-15 15:06 - 2020-03-15 15:06 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Wondershare 2020-03-15 15:06 - 2020-03-15 15:06 - 000000000 ____D C:\Users\Administrator\AppData\Local\Wondershare 2020-03-15 14:55 - 2020-03-15 14:55 - 000000054 _____ C:\Users\chris\Desktop\Bmo.url 2020-03-15 14:53 - 2020-03-15 14:53 - 000001304 _____ C:\Users\Public\Desktop\Wondershare UniConverter.lnk 2020-03-15 14:53 - 2020-03-15 14:53 - 000001304 _____ C:\ProgramData\Desktop\Wondershare UniConverter.lnk 2020-03-15 14:53 - 2020-03-15 14:53 - 000000000 ____D C:\ProgramData\Wondershare MediaServer 2020-03-15 14:53 - 2020-03-15 14:53 - 000000000 ____D C:\ProgramData\GraphicsType 2020-03-15 14:50 - 2020-03-15 14:50 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\TransferSupport 2020-03-15 14:50 - 2020-03-15 14:50 - 000000000 ____D C:\Program Files (x86)\Wondershare 2020-03-15 14:46 - 2020-03-15 14:53 - 000000000 ____D C:\Users\Public\Documents\Wondershare 2020-03-15 14:46 - 2020-03-15 14:53 - 000000000 ____D C:\ProgramData\Documents\Wondershare 2020-03-15 14:46 - 2020-03-15 14:46 - 000990312 _____ C:\Users\chris\Downloads\video-converter-ultimate_setup_full495 (1).exe 2020-03-15 14:45 - 2020-03-15 14:45 - 000990312 _____ C:\Users\chris\Downloads\video-converter-ultimate_setup_full495.exe 2020-03-15 14:42 - 2020-03-15 14:42 - 026746079 _____ C:\Users\chris\Downloads\COVID-19 Share.wmv 2020-03-15 14:30 - 2020-03-15 14:34 - 000000000 _____ C:\Users\chris\AppData\Local\{DE066749-FA0D-4F26-9F5F-55716BC0D7A0} 2020-03-15 14:15 - 2020-03-15 14:15 - 027998866 _____ C:\Users\Administrator\Downloads\mmm-free.exe_2 2020-03-15 14:15 - 2020-03-15 14:15 - 026491551 _____ C:\Users\Administrator\Downloads\mmm-free.exe_3 2020-03-15 14:15 - 2020-03-15 14:15 - 022592159 _____ C:\Users\Administrator\Downloads\mmm-free.exe_1 2020-03-15 14:15 - 2020-03-15 14:15 - 021838538 _____ (MiniTool ) C:\Users\Administrator\Downloads\mmm-free.exe_0 2020-03-15 14:15 - 2020-03-15 14:15 - 010189515 _____ (Microsoft Corporation) C:\Users\Administrator\Downloads\framework.exe_0 2020-03-15 14:14 - 2020-03-15 14:15 - 002099184 _____ (MiniTool) C:\Users\chris\Downloads\mmm-setup.exe 2020-03-13 18:47 - 2020-03-18 14:46 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2020-03-13 18:47 - 2020-03-18 14:46 - 000002267 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2020-03-13 18:47 - 2020-03-18 14:46 - 000002267 _____ C:\ProgramData\Desktop\Google Chrome.lnk 2020-03-13 18:40 - 2020-03-21 19:07 - 000003420 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA 2020-03-13 18:40 - 2020-03-21 19:07 - 000003296 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore 2020-03-13 11:45 - 2020-03-13 11:45 - 000001270 _____ C:\Users\chris\Desktop\WavePad Sound Editor.lnk 2020-03-13 11:45 - 2020-03-13 11:45 - 000001256 _____ C:\Users\chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WavePad Sound Editor.lnk 2020-03-13 11:44 - 2020-03-13 11:44 - 002387504 _____ (NCH Software) C:\Users\chris\Downloads\wpsetup.exe 2020-03-12 15:21 - 2020-03-12 15:21 - 000029221 _____ C:\Users\chris\Downloads\audio_import (12).txt 2020-03-11 14:07 - 2020-03-11 14:07 - 000000000 ____D C:\WINDOWS\Lenovo 2020-03-11 11:34 - 2020-03-11 11:34 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2020-03-11 11:32 - 2020-03-11 11:32 - 011723776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll 2020-03-11 11:32 - 2020-03-11 11:32 - 009941504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll 2020-03-11 11:32 - 2020-03-11 11:32 - 003179008 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d12SDKLayers.dll 2020-03-11 11:32 - 2020-03-11 11:32 - 002476544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d12SDKLayers.dll 2020-03-11 11:32 - 2020-03-11 11:32 - 001366016 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11_3SDKLayers.dll 2020-03-11 11:32 - 2020-03-11 11:32 - 001089024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11_3SDKLayers.dll 2020-03-11 11:32 - 2020-03-11 11:32 - 000555008 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1debug3.dll 2020-03-11 11:32 - 2020-03-11 11:32 - 000424960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1debug3.dll 2020-03-11 11:32 - 2020-03-11 11:32 - 000154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\fcon.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 026807296 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 023463424 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 020816384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 019284480 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 019020288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 015220224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 013013504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 012306432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 008907776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 007923712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 007870976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 006942720 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 006545096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 006445056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 006318840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 006060544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 005915936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 005777408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 005608120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 005575168 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 005436904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 005309080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 005210896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 005086208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 004872704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 004664320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 004628480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 004344832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 004066816 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 004018688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 003952760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 003909632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 003873704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 003860832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpltfm.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 003703808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 003629568 _____ (Microsoft Corporation) C:\WINDOWS\system32\tellib.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 003550624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 003490304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 003429888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 003416576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Controls.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 003096064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 002986560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 002981888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 002917688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2020-03-11 11:31 - 2020-03-11 11:31 - 002893312 _____ (Microsoft Corporation) C:\WINDOWS\system32\themeui.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 002832896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themeui.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 002779272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 002765312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 002751336 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 002701816 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 002698752 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 002627088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2020-03-11 11:31 - 2020-03-11 11:31 - 002469432 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 002349056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 002323688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 002298880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 002279296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 002273296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 002264344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 002182456 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 002150912 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeangle.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 002100056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 002074984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001994768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001962296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys 2020-03-11 11:31 - 2020-03-11 11:31 - 001961984 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001899160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001890816 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfuimanager.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001876960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001862656 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001837136 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001804288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfuimanager.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001761280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dui70.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001759232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001753088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConstraintIndex.Search.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001750528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001729024 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShell.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001720936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001711104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001707208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001702600 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2020-03-11 11:31 - 2020-03-11 11:31 - 001702400 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001693696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001678800 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001675008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001674696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001668752 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001606144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directml.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001605000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001590072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001573480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001568768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001506304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001495480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001485312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001484384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001480192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001473080 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 001465344 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001465264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001458056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001430880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001427592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001395056 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001390888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Taskmgr.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 001388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001382912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001360912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys 2020-03-11 11:31 - 2020-03-11 11:31 - 001346192 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2020-03-11 11:31 - 2020-03-11 11:31 - 001323008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001319936 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001309696 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001296360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001294336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001292800 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 001292288 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001288648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001282944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001278808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Taskmgr.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 001272360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001257472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001255936 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001249280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001247856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 001229824 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloSI.PCShell.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001224704 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001223168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdprt.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001222456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpbase.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001201128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001183504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 001162088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001125392 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001122304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001098128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001076224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001076040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001071616 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 001062400 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001051136 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001036800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001027000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001022976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001022464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 001012224 _____ (Microsoft Corporation) C:\WINDOWS\system32\refsutil.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 001001472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmsys.cpl 2020-03-11 11:31 - 2020-03-11 11:31 - 001000448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000993280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000988672 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000982528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000980320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpal.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000976384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000964984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000964096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000961024 _____ (Microsoft Corporation) C:\WINDOWS\system32\CBDHSvc.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000949760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000947200 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000946688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000934912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Phone.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000926056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000915296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmcodecs.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000914432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000909824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontext.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000909624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000908800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmsys.cpl 2020-03-11 11:31 - 2020-03-11 11:31 - 000879104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000870400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000850432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000846848 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000845824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000833024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000829440 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000828728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000823296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVolSSO.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000821760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSMDesktopProvider.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000818688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MdmDiagnostics.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000808960 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscui.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000808272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000805504 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioIso.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000803328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000801792 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000796160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000791864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000791040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000782848 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000774968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Services.TargetedContent.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000774656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SndVolSSO.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000763032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000745472 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicesFlowBroker.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000741376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000740352 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscsvc.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000736272 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingWinRT.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000732000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ortcengine.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000730112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FlightSettings.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000727040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000718944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000712192 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbc32.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000708096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000703488 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000694784 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsInternal.ComposableShell.ComposerFramework.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000687104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000681472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000676352 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000673280 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000671232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000670208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Devices.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000669184 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationFrame.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000663040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000662528 ____R (Microsoft Corporation) C:\WINDOWS\system32\MixedRealityCapture.Pipeline.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000661304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000661056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000658944 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000655160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys 2020-03-11 11:31 - 2020-03-11 11:31 - 000654848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000651264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000648392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000642560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sud.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000642048 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedRealitySvc.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000641696 _____ (Microsoft Corporation) C:\WINDOWS\system32\sechost.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000637440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.Search.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000628736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000622632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicensingWinRT.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000620032 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcIsoCtnr.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000615936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000606208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mscms.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000604248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.applicationmodel.datatransfer.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000594432 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicExtensions.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppResolver.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000589824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000574864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Perception.Stub.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000557056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationExtensions.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000555440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000553472 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000547840 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuietHours.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000545792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000542536 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000542504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000538624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_User.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000537088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9on12.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000535048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys 2020-03-11 11:31 - 2020-03-11 11:31 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000532992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidprov.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000522104 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000520704 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000517632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtrmgr.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000515448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000506368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.PredictionUnit.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000501760 _____ (Microsoft Corporation) C:\WINDOWS\system32\msutb.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000500224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_PCDisplay.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000499712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Display.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Launcher.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000496872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000496128 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000494080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Activities.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000492216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sechost.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000492032 _____ (Microsoft Corporation) C:\WINDOWS\system32\DictationManager.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000487936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000486400 _____ C:\WINDOWS\system32\AssignedAccessCsp.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000481280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000473832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000468480 _____ (Microsoft Corporation) C:\WINDOWS\system32\provsvc.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000462336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000461488 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcIso.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000460800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UiaManager.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnphost.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000454144 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000453208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppResolver.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000451584 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShellAPI.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000449024 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000444416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\intl.cpl 2020-03-11 11:31 - 2020-03-11 11:31 - 000441344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCenter.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000439976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11on12.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000439808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000434176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000429568 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000429056 _____ (Microsoft Corporation) C:\WINDOWS\system32\MixedReality.Broker.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000428544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000427520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000425984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000420352 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneDataSync.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000419840 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicRuntimes.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000415744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv 2020-03-11 11:31 - 2020-03-11 11:31 - 000414208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000409912 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000408528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Enumeration.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000403968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoMetadataHandler.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceCenter.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000395776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ninput.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000389120 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000385536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\provsvc.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000382976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppLockerCSP.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000378880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000373560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\coml2.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000366728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MMDevAPI.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000364544 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000363520 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpinit.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000363320 _____ (Microsoft Corporation) C:\WINDOWS\system32\input.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DictationManager.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000349184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneOm.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuickActionsDataModel.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000340480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.BlueLightReduction.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000334336 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnphost.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000329216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreShellAPI.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000326144 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagnosticLogCSP.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000325120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MicrosoftAccountWAMExtension.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000322560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ninput.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000322048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000320512 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000312632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000310784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Phoneutil.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WiFiDisplay.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000308224 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000304952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\input.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000304128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Cortana.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000302592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.CredDialogController.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000301568 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFIPP.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000297472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DataExchange.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000296448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnclient.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000296448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys 2020-03-11 11:31 - 2020-03-11 11:31 - 000289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\discan.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000287744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Preview.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\coredpus.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000279416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BCP47Langs.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000277840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\biwinrt.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000276480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppLockerCSP.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000274448 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostBroker.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacEncoder.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000267264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockScreenData.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000264704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ComposerFramework.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000264208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemSettings.DataModel.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000263576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000263168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovs.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\DesktopSwitcherDataModel.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthprops.cpl 2020-03-11 11:31 - 2020-03-11 11:31 - 000259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationManager.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SignInOptions.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000254264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mssecflt.sys 2020-03-11 11:31 - 2020-03-11 11:31 - 000252264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_ManagePhone.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000251392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsDocumentTargetPrint.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ConsoleLogon.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\feclient.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000243216 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataExchangeHost.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000241664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedPCCSP.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngOnline.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000240376 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000239664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExecModelClient.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000238080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.CredDialogController.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncSettings.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloSHExtensions.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloShellRuntime.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.CapturePicker.Desktop.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabSvc.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcredprov.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddpchunk.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerCsp.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netplwiz.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000219656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditionUpgradeManagerObj.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000219136 _____ (Microsoft Corporation) C:\WINDOWS\system32\tscfgwmi.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000218624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Cortana.Persona.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000217600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bthprops.cpl 2020-03-11 11:31 - 2020-03-11 11:31 - 000217088 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE 2020-03-11 11:31 - 2020-03-11 11:31 - 000215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactHarvesterDS.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeopleBand.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000205312 _____ C:\WINDOWS\SysWOW64\HeatCore.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000201216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincredui.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SpatializerApo.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RstrtMgr.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000196608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\feclient.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000192512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsInternal.ComposableShell.DesktopHosting.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000186880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enrollmentapi.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Analog.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\oledlg.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.SharedPC.CredentialProvider.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000180736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE 2020-03-11 11:31 - 2020-03-11 11:31 - 000180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_ContentDeliveryManager.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000176112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000175928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Management.Workplace.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_AnalogShell.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000168488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000168448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.CapturePicker.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000165888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MicrosoftAccountTokenProvider.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\edpcsp.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000164152 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.SettingsExtensibility.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.XamlHost.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\EDPCleanup.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthBroker.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000161280 ____R (Microsoft Corporation) C:\WINDOWS\system32\SecureAssessmentHandlers.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000160256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Devices.Sensors.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000159744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincredui.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000159232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ddisplay.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000157536 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcmnutils.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintWSDAHost.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000156160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.OneCore.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000156160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Sockets.PushEnabledApplication.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twext.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\useractivitybroker.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oledlg.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapistub.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapi32.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000144896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SpatialAudioLicenseSrv.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.PAL.Desktop.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\DesktopView.Internal.Broker.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000143360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BitLockerCsp.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000140304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000139648 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialUIBroker.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceMetadataRetrievalClient.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppc.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000132480 _____ (Microsoft Corporation) C:\WINDOWS\system32\profapi.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredDialogBroker.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000124440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmcmnutils.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000123392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.XamlHost.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintWSDAHost.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000119808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mapistub.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000119808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mapi32.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DSCache.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\globinputhost.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\efslsaext.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000108392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Display.DisplayEnhancementOverride.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000107520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olecli32.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000107008 _____ C:\WINDOWS\SysWOW64\WindowsDefaultHeatProcessor.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000106496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olethk32.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000106376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profapi.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000106048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000105784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsentUX.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000104448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GraphicsCapture.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\MuiUnattend.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000102912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppc.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssecuser.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserAccountControlSettings.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000098816 ____R (Microsoft Corporation) C:\WINDOWS\system32\MixedRealityCapture.Broker.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedsbs.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000094496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PickerHost.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\TelephonyInteractiveUser.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PersonalizationCSP.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserAccountControlSettings.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvHelper.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsCtfMonitor.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterpriseresourcemanager.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeedsbs.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ComputerDefaults.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\desktopimgdownldr.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000074752 ____R (Microsoft Corporation) C:\WINDOWS\system32\mdmpostprocessevaluator.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\coredpussvr.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000072984 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationFrameHost.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000072192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Custom.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerUI.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000071168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncPolicy.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.internal.shellcommon.AccountsControlExperience.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enterpriseresourcemanager.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Background.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ComputerDefaults.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvHelper.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olesvr32.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000055376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmmvrortc.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000054272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerUI.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LocationFrameworkInternalPS.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000039936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Profile.SystemManufacturers.dll 2020-03-11 11:31 - 2020-03-11 11:31 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mpnotify.exe 2020-03-11 11:31 - 2020-03-11 11:31 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msauserext.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 022137120 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 017484800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 009672208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 007888896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 007700480 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 007645392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 007556600 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 006058032 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 005577872 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 005528576 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 005301248 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 004997096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 004898144 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpltfm.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 004853760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Controls.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 004736512 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 004589056 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 004417008 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 004303872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 004050432 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 003636736 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2020-03-11 11:30 - 2020-03-11 11:30 - 003630592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Service.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 003581440 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 003392000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 003361080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2020-03-11 11:30 - 2020-03-11 11:30 - 003334496 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 003334144 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 002848768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 002707456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2020-03-11 11:30 - 2020-03-11 11:30 - 002634752 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 002620928 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 002611136 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 002590944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 002466816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 002437344 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 002433024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 002426680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.AppAgent.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 002418176 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2020-03-11 11:30 - 2020-03-11 11:30 - 002233856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 002200376 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 002197504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 002185216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 002149160 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 002086192 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 002084352 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 002050560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 002031104 _____ C:\WINDOWS\system32\rdpnano.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 002015400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 002004992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001929728 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001893376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001886208 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001844456 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001830712 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001818624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001796400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001794048 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdprt.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001771824 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001768960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001751640 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001743376 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001727496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft.Uev.AppAgent.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001720320 _____ (Microsoft Corporation) C:\WINDOWS\system32\directml.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001715712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001715000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntVirtualization.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001701384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001688064 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001677312 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001674752 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001671680 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001664904 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001644544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001612816 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVIntegration.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001608192 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001551360 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001522488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001519488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001496576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001478968 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpbase.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001474560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dui70.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001466368 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001422336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001399824 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystemController.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001387512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001354080 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpal.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001335296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001333248 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001331536 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001315328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001308672 _____ (Microsoft Corporation) C:\WINDOWS\system32\TaskFlowDataEngine.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001293768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001287584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001287072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001267712 _____ (Microsoft Corporation) C:\WINDOWS\system32\APMon.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001262592 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001260032 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001258296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 001221120 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001205248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001194496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001169920 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001145856 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001114112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001091936 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmcodecs.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001085952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.Schema.Shell.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001081656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Services.TargetedContent.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001054712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 001052160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001051648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 001049600 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001049400 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 001038336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001035264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001032544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ortcengine.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001021952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001005568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 001005056 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000998928 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000988240 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000987736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Perception.Stub.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000985088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000984888 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000974848 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontext.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000955392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000938296 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000932864 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000930816 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthSSO.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000928768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000909824 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000904104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000903368 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000902656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000902464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000902144 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000890400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000890368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000889344 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000882176 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000872960 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSMDesktopProvider.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000871792 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000863528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000862224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2020-03-11 11:30 - 2020-03-11 11:30 - 000848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Signals.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000847872 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000828216 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVOrchestration.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9on12.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000822272 _____ (Microsoft Corporation) C:\WINDOWS\system32\conhost.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000820736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000818640 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.applicationmodel.datatransfer.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000817168 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntStreamingManager.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000788480 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000782848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000780408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000779776 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000777728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000776272 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000776192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000769760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000743224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVReporting.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000741688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000740864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Office2013CustomActions.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000739840 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpksetup.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000736256 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockController.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000723456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.Search.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\WFDSConMgrSvc.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000702976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.immersiveshell.serviceprovider.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000690176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000686080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mscms.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000681984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000681416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000680944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000679424 _____ (Microsoft Corporation) C:\WINDOWS\system32\UiaManager.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000678376 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000667664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys 2020-03-11 11:30 - 2020-03-11 11:30 - 000667152 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVCatalog.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000663552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000652304 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000650552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys 2020-03-11 11:30 - 2020-03-11 11:30 - 000650240 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000649528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPublishing.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidprov.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000622336 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11on12.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000621568 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrSvc.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000616448 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000605576 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000605184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbc32.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000604552 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000603792 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000591872 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000581632 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofmsvc.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000575488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000565760 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtrmgr.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000558592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000556544 _____ (Microsoft Corporation) C:\WINDOWS\system32\BTAGService.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000547840 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000542208 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv 2020-03-11 11:30 - 2020-03-11 11:30 - 000535552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChxAPDS.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000532184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000526336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft.Uev.Office2013CustomActions.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000519168 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000518656 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000516096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000515584 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000510504 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000509440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChxHAPDS.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000508720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Enumeration.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000506408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000505856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000495632 _____ (Microsoft Corporation) C:\WINDOWS\system32\TransportDSA.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000495616 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000495616 _____ (Microsoft Corporation) C:\WINDOWS\system32\DDDS.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000494080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000494080 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.UserService.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\intl.cpl 2020-03-11 11:30 - 2020-03-11 11:30 - 000487424 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoMetadataHandler.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000485376 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000482304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000470016 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000468792 _____ (Microsoft Corporation) C:\WINDOWS\system32\coml2.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000467984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS 2020-03-11 11:30 - 2020-03-11 11:30 - 000465408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChtCangjieDS.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000461840 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000461824 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000460288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountWAMExtension.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000458240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChtBopomofoDS.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChtHkStrokeDS.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000455680 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChsStrokeDS.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000454144 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChtQuickDS.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000451120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000450048 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000446480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000443368 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMDevAPI.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000442880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000440832 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockHostingFramework.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000439096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2020-03-11 11:30 - 2020-03-11 11:30 - 000438784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msutb.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000437248 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneOm.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000435712 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000424960 _____ (Microsoft Corporation) C:\WINDOWS\system32\SDDS.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000421888 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_UserAccount.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000418576 _____ (Microsoft Corporation) C:\WINDOWS\system32\vac.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\eeprov.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000415744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000413184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountExtension.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000410624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000407712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtapi.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000407040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000400384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000399376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DataModel.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000395776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Preview.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000390128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000389120 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingASDS.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000386560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_WorkAccess.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000386360 _____ (Microsoft Corporation) C:\WINDOWS\system32\thumbcache.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000385552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000384000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Phoneutil.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthAvctpSvc.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000378880 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000377344 _____ (Microsoft Corporation) C:\WINDOWS\system32\jpndecoder.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000376784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000376320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChxDecoder.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockScreenData.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000367208 _____ (Microsoft Corporation) C:\WINDOWS\system32\BCP47Langs.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000362496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWfdProvider.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnclient.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\chxinputrouter.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000355328 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsDocumentTargetPrint.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000351744 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthAvrcp.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000349696 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000347784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSrvPolicyManager.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000347648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_AssignedAccess.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000335872 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataExchange.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000329216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpr.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000329216 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsku.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.internal.shellcommon.shareexperience.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MtfDecoder.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000320728 _____ (Microsoft Corporation) C:\WINDOWS\system32\biwinrt.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000314072 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExecModelClient.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000313344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFWSD.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000312704 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000312320 _____ (Microsoft Corporation) C:\WINDOWS\system32\LanguageOverlayServer.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceDirectoryClient.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000304952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000298808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys 2020-03-11 11:30 - 2020-03-11 11:30 - 000293856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000293376 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000290304 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\jpnranker.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcredprov.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000283240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtapi.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000282424 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Cortana.Persona.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000281088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000277504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000276496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MTF.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000276480 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_InputPersonalization.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountCloudAP.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000270336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winsku.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000263680 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiCloudStore.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000262656 _____ C:\WINDOWS\system32\HeatCore.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\netman.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000262336 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatializerApo.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnservice.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000255128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmBroker.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000252944 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000246784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000244224 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpnServiceDS.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000241664 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupManager.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys 2020-03-11 11:30 - 2020-03-11 11:30 - 000239120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Workplace.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000238080 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Devices.Sensors.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\TetheringMgr.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacEncoder.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\VideoHandlers.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountTokenProvider.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wosc.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_CapabilityAccess.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.OneCore.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\RstrtMgr.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000222720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Geolocation.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000222008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinesam.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000217904 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000213816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000211456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddisplay.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndiswan.sys 2020-03-11 11:30 - 2020-03-11 11:30 - 000206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\useractivitybroker.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000202552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MTF.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000200720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SIUF.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000199680 _____ C:\WINDOWS\system32\IHDS.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000193552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000193336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys 2020-03-11 11:30 - 2020-03-11 11:30 - 000190976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000189440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Sockets.PushEnabledApplication.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000186464 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbrand.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\twext.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000178688 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbio.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000177664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngctasks.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\IoTAssignedAccessLockFramework.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000172544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\HoloShellRuntime.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000163448 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingCSP.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MTFFuzzyDS.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_AppExecutionAlias.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000152576 _____ (Microsoft Corporation) C:\WINDOWS\system32\VaultCDS.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_BackgroundApps.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\vfuprov.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Security.Attestation.DeviceAttestation.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000149488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winbrand.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000149240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Display.DisplayEnhancementOverride.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\sensrsvc.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DSCache.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000148480 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000147944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000146944 _____ (Microsoft Corporation) C:\WINDOWS\system32\globinputhost.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSpkg.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AdvancedEmojiDS.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\StaticDictDS.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsExtensibilityHandlers.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000141728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\GraphicsCapture.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000138624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.ShellCommon.Broker.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\provpackageapidll.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000134456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000134144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000133432 _____ (Microsoft Corporation) C:\WINDOWS\system32\DTUHandler.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000130872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys 2020-03-11 11:30 - 2020-03-11 11:30 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Storage.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000126976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000126464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winbio.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000125440 _____ C:\WINDOWS\system32\WindowsDefaultHeatProcessor.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000121536 _____ (Microsoft Corporation) C:\WINDOWS\system32\PickerHost.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSpkg.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\chxranker.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000120560 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000118472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinHvEmulation.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinAUG.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\agilevpn.sys 2020-03-11 11:30 - 2020-03-11 11:30 - 000112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AxInstSv.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\HashtagDS.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinHvPlatform.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000109704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredentialUIBroker.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\sihost.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\MTFSpellcheckDS.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000106296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\DesktopShellExt.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000103952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys 2020-03-11 11:30 - 2020-03-11 11:30 - 000103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MTFAppServiceDS.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000099896 _____ (Microsoft Corporation) C:\WINDOWS\system32\RuntimeBroker.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000099840 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingFilterDS.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpnUserService.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Custom.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\RuleBasedDS.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000095544 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteAppLifetimeManager.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys 2020-03-11 11:30 - 2020-03-11 11:30 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncPolicy.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000090608 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.internal.shellcommon.AccountsControlExperience.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Background.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkInternalPS.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MuiUnattend.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dtdump.exe 2020-03-11 11:30 - 2020-03-11 11:30 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityServicePal.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsCtfMonitor.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000062464 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo-overrides.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000056672 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmmvrortc.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000054272 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAProfileNotificationHandler.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Profile.SystemManufacturers.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msauserext.dll 2020-03-11 11:30 - 2020-03-11 11:30 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin 2020-03-11 11:30 - 2020-03-11 11:30 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin 2020-03-11 11:30 - 2020-03-11 11:30 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin 2020-03-11 11:30 - 2020-03-11 11:30 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin 2020-03-11 11:30 - 2020-03-11 11:30 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin 2020-03-11 11:30 - 2020-03-11 11:30 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin 2020-03-11 11:30 - 2020-03-11 11:30 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin 2020-03-11 11:30 - 2020-03-11 11:30 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin 2020-03-06 11:56 - 2020-03-19 18:55 - 000891982 ____N C:\WINDOWS\Minidump\031920-6687-01.dmp 2020-03-04 16:04 - 2020-03-04 16:06 - 097414801 _____ C:\Users\chris\Downloads\2020-02-27 23.05 Leadership Course.mp4 2020-03-04 11:22 - 2020-03-04 11:22 - 000001517 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Driver & Support Assistant.lnk 2020-03-02 12:48 - 2020-03-02 12:48 - 000027278 _____ C:\Users\chris\Downloads\Data_All_200302.zip 2020-03-02 11:49 - 2020-03-02 11:49 - 000009679 _____ C:\Users\chris\Downloads\invite (3).ics 2020-03-02 11:48 - 2020-03-02 11:48 - 000009679 _____ C:\Users\chris\Downloads\invite (2).ics 2020-03-02 11:47 - 2020-03-02 11:47 - 000009679 _____ C:\Users\chris\Downloads\invite (1).ics 2020-03-02 11:43 - 2020-03-02 11:44 - 000000160 _____ C:\Users\chris\Downloads\2020-02-27 10.01 Leadership Course.mp4 2020-03-02 11:31 - 2020-03-02 11:31 - 000000428 _____ C:\Users\chris\Downloads\Cornerstone GoToMeeting recordings (1).zip 2020-03-02 11:25 - 2020-03-02 11:26 - 000000428 _____ C:\Users\chris\Downloads\Cornerstone GoToMeeting recordings.zip 2020-03-02 11:05 - 2020-03-25 12:03 - 000003984 _____ C:\WINDOWS\system32\Tasks\Reimage-Post-Reboot 2020-03-01 17:09 - 2020-03-01 17:09 - 000000144 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2020-03-01 17:07 - 2020-03-01 17:07 - 000003834 _____ C:\WINDOWS\system32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 2020-03-01 16:31 - 2020-03-01 16:31 - 000000000 ____D C:\Users\Administrator\AppData\LocalLow\IGDump 2020-03-01 16:29 - 2020-03-01 16:29 - 000017336 _____ C:\WINDOWS\system32\results.xml 2020-03-01 16:17 - 2020-03-01 16:17 - 000000000 ____D C:\Users\Administrator\Downloads\Intel Driver and Support Assistant 2020-03-01 16:15 - 2020-03-01 16:15 - 000003762 _____ C:\WINDOWS\system32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 2020-03-01 16:15 - 2020-03-01 16:15 - 000003528 _____ C:\WINDOWS\system32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon 2020-03-01 16:15 - 2020-03-01 16:15 - 000002678 _____ C:\WINDOWS\system32\Tasks\USER_ESRV_SVC_QUEENCREEK 2020-03-01 16:15 - 2019-08-16 15:29 - 000041816 _____ C:\WINDOWS\system32\Drivers\semav6msr64.sys 2020-03-01 16:14 - 2020-03-01 16:16 - 000000000 ____D C:\ProgramData\Intel 2020-03-01 16:13 - 2020-03-01 16:13 - 002495584 _____ (Intel) C:\Users\Administrator\Downloads\Intel-Driver-and-Support-Assistant-Installer.exe 2020-03-01 16:13 - 2020-03-01 16:13 - 002495584 _____ (Intel) C:\Users\Administrator\Downloads\Intel-Driver-and-Support-Assistant-Installer (1).exe 2020-02-29 17:31 - 2020-02-29 17:32 - 003210152 _____ (Lenovo ) C:\Users\chris\Downloads\LSBSetup.exe 2020-02-29 14:18 - 2020-02-29 14:18 - 000214496 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys 2020-02-26 20:45 - 2020-02-26 20:45 - 000000000 ____D C:\Users\Administrator\AppData\Local\DBG 2020-02-26 20:42 - 2020-02-26 20:42 - 000000000 ____D C:\Users\Administrator\AppData\Local\ElevatedDiagnostics 2020-02-26 20:15 - 2020-02-26 20:15 - 001041204 _____ C:\Users\chris\Downloads\PDF_103717844_2020-01-25_193.pdf 2020-02-26 20:15 - 2020-02-26 20:15 - 001041204 _____ C:\Users\chris\Downloads\PDF_103717844_2020-01-25_193 (1).pdf 2020-02-25 20:10 - 2020-02-25 20:10 - 000000000 ____D C:\Users\Administrator\AppData\Local\PeerDistRepub 2020-02-25 19:42 - 2020-02-25 19:42 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Nuance 2020-02-25 19:41 - 2020-02-25 19:41 - 000000000 ____D C:\Users\Administrator\AppData\Local\LogMeIn 2020-02-25 19:03 - 2020-02-25 19:04 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps 2020-02-25 18:52 - 2020-02-25 19:01 - 000000000 ____D C:\Users\Administrator\AppData\Local\RoboForm 2020-02-25 18:52 - 2020-02-25 18:53 - 000003392 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1547701397-687303812-3400344658-500 2020-02-25 18:52 - 2020-02-25 18:53 - 000002440 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2020-02-25 18:49 - 2020-03-01 16:11 - 000000000 ____D C:\Users\Administrator\AppData\Local\gladinet 2020-02-25 18:49 - 2020-03-01 16:04 - 000000000 ____D C:\Users\Administrator\AppData\Local\PlaceholderTileLogoFolder 2020-02-25 18:49 - 2020-02-25 18:50 - 000000000 ____D C:\Users\Administrator\Documents\Snagit 2020-02-25 18:49 - 2020-02-25 18:49 - 000000000 ___HD C:\Users\Administrator\MicrosoftEdgeBackups 2020-02-25 18:49 - 2020-02-25 18:49 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\TechSmith 2020-02-25 18:49 - 2020-02-25 18:49 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\FLEXnet 2020-02-25 18:49 - 2020-02-25 18:49 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\ACT 2020-02-25 18:49 - 2020-02-25 18:49 - 000000000 ____D C:\Users\Administrator\AppData\Local\TechSmith 2020-02-25 18:49 - 2020-02-25 18:49 - 000000000 ____D C:\Users\Administrator\AppData\Local\Integration Services Patch for Act! 2020-02-25 18:48 - 2020-02-25 18:50 - 000000000 ____D C:\Users\Administrator\AppData\Local\MicrosoftEdge 2020-02-25 18:48 - 2020-02-25 18:48 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Logitech 2020-02-25 18:45 - 2020-03-01 17:08 - 000000000 __SHD C:\Users\Administrator\IntelGraphicsProfiles 2020-02-25 18:45 - 2020-02-25 20:07 - 000000000 ____D C:\Users\Administrator\AppData\Local\Google 2020-02-25 18:45 - 2020-02-25 18:45 - 000000000 ___RD C:\Users\Administrator\3D Objects 2020-02-25 18:42 - 2020-02-25 18:42 - 000000000 ____D C:\Users\Administrator\AppData\Local\D3DSCache 2020-02-25 18:39 - 2020-02-25 18:39 - 000000000 ____D C:\Users\Administrator\AppData\Local\mbamtray 2020-02-25 18:38 - 2020-03-01 16:30 - 000000000 ____D C:\Users\Administrator\AppData\Local\LogMeIn Hamachi 2020-02-25 18:38 - 2020-03-01 16:04 - 000000000 ____D C:\Users\Administrator\AppData\Local\Publishers 2020-02-25 18:38 - 2020-03-01 16:04 - 000000000 ____D C:\Users\Administrator\AppData\Local\Packages 2020-02-25 18:38 - 2020-02-25 18:53 - 000000000 ___RD C:\Users\Administrator\OneDrive 2020-02-25 18:38 - 2020-02-25 18:50 - 000000000 ____D C:\Users\Administrator\AppData\Local\Lenovo 2020-02-25 18:38 - 2020-02-25 18:49 - 000000000 ____D C:\Users\Administrator\AppData\Local\Nuance 2020-02-25 18:38 - 2020-02-25 18:49 - 000000000 ____D C:\Users\Administrator 2020-02-25 18:38 - 2020-02-25 18:45 - 000000000 ____D C:\Users\Administrator\AppData\Local\ConnectedDevicesPlatform 2020-02-25 18:38 - 2020-02-25 18:38 - 000000020 ___SH C:\Users\Administrator\ntuser.ini 2020-02-25 18:38 - 2017-12-08 11:40 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Macromedia 2020-02-25 18:38 - 2017-01-11 19:24 - 000000000 ____D C:\Users\Administrator\AppData\Local\Comms 2020-02-25 18:38 - 2017-01-11 15:37 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe 2020-02-25 18:38 - 2017-01-11 15:37 - 000000000 ____D C:\Users\Administrator\AppData\Local\TileDataLayer 2020-02-25 18:38 - 2016-09-02 11:32 - 000000319 _____ C:\Users\Administrator\Desktop\Get Office 365 Personal.url 2020-02-25 18:38 - 2016-09-02 11:31 - 000000194 _____ C:\Users\Administrator\Desktop\Get Office 365 Home.url 2020-02-25 18:38 - 2016-08-31 16:58 - 000000154 _____ C:\Users\Administrator\Desktop\Microsoft Store.url ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2020-03-26 14:22 - 2019-06-07 11:06 - 001810469 _____ C:\WINDOWS\ZAM_Guard.krnl.trace 2020-03-26 14:22 - 2019-06-07 11:06 - 001775112 _____ C:\WINDOWS\ZAM.krnl.trace 2020-03-26 14:22 - 2018-02-23 10:35 - 000000000 ____D C:\FRST 2020-03-26 14:20 - 2017-03-30 19:01 - 000000000 ____D C:\Users\chris\Documents\Outlook Files 2020-03-26 13:26 - 2018-09-15 03:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2020-03-26 12:29 - 2017-04-13 18:48 - 000000000 ____D C:\ProgramData\TEMP 2020-03-26 12:27 - 2018-06-12 10:17 - 000000000 ____D C:\Users\chris\AppData\Local\Packages 2020-03-26 12:03 - 2019-03-29 09:12 - 000011650 _____ C:\Users\chris\Documents\OutlookFailureTest.txt 2020-03-26 11:45 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\AppReadiness 2020-03-26 11:44 - 2018-09-15 03:33 - 000000000 ___HD C:\Program Files\WindowsApps 2020-03-26 11:38 - 2017-03-31 11:02 - 000000000 ____D C:\Users\chris\Documents\Bookmark Lists 2020-03-26 11:32 - 2019-02-10 20:13 - 000844816 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2020-03-26 11:31 - 2018-09-15 03:31 - 000000000 ____D C:\WINDOWS\INF 2020-03-26 11:30 - 2017-05-01 11:03 - 000000000 ____D C:\Users\chris\AppData\Local\gladinet 2020-03-26 11:28 - 2017-06-13 14:51 - 000000000 ____D C:\ActConnectLink 2020-03-26 11:27 - 2018-06-12 10:17 - 000000000 ____D C:\Users\chris\AppData\Local\LogMeIn Hamachi 2020-03-26 11:26 - 2019-02-10 20:13 - 000003700 _____ C:\WINDOWS\system32\Tasks\Lenovo Power Management Driver PnP Task 2020-03-26 11:26 - 2019-02-10 20:13 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2020-03-26 11:26 - 2019-01-07 12:54 - 000000000 ____D C:\ProgramData\Reimage Protector 2020-03-26 11:26 - 2017-03-27 13:34 - 000000000 __SHD C:\Users\chris\IntelGraphicsProfiles 2020-03-26 11:25 - 2018-09-15 02:09 - 001048576 _____ C:\WINDOWS\system32\config\BBI 2020-03-26 09:59 - 2018-03-04 15:13 - 000000167 _____ C:\WINDOWS\Reimage.ini 2020-03-26 09:59 - 2018-03-04 15:13 - 000000000 ____D C:\rei 2020-03-26 09:57 - 2017-01-31 04:47 - 000000000 ____D C:\Users\chris\Documents\@scratchpad 2020-03-25 18:03 - 2019-02-11 16:00 - 000000000 ____D C:\Users\chris\AppData\Local\Deployment 2020-03-25 16:16 - 2019-02-10 20:01 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2020-03-25 15:15 - 2017-04-28 14:29 - 000015864 _____ C:\WINDOWS\BRRBCOM.INI 2020-03-25 13:50 - 2017-05-26 10:59 - 000000000 _____ C:\WINDOWS\system32\reimage.rep 2020-03-25 11:50 - 2019-05-30 10:02 - 000000000 ____D C:\ReimageUndo 2020-03-25 11:50 - 2017-05-26 10:40 - 000012710 _____ C:\WINDOWS\system32\Native.exe 2020-03-25 10:33 - 2018-06-12 10:28 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2020-03-23 09:23 - 2018-09-15 02:09 - 000032768 _____ C:\WINDOWS\system32\config\ELAM 2020-03-22 20:28 - 2019-02-10 20:13 - 000000000 ____D C:\WINDOWS\system32\Tasks\NCH Software 2020-03-22 17:24 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\system32\NDF 2020-03-21 18:12 - 2017-04-25 12:19 - 000000000 ____D C:\Program Files (x86)\Dropbox 2020-03-20 09:48 - 2019-08-14 13:46 - 000000000 ____D C:\Users\chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WhatsApp 2020-03-19 18:55 - 2019-02-10 20:03 - 000000000 ____D C:\Users\chris 2020-03-19 11:30 - 2018-12-12 18:22 - 000000000 ____D C:\Users\chris\Documents\@Chris 2020-03-18 18:22 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase 2020-03-18 18:07 - 2019-08-14 13:46 - 000000000 ____D C:\Users\chris\AppData\Local\WhatsApp 2020-03-18 17:40 - 2019-08-14 13:46 - 000000000 ____D C:\Users\chris\AppData\Roaming\WhatsApp 2020-03-18 09:54 - 2019-05-24 15:09 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update 2020-03-18 09:51 - 2018-04-07 11:00 - 000000000 ____D C:\Users\chris\AppData\Local\SquirrelTemp 2020-03-17 18:17 - 2017-01-11 15:52 - 000000000 ____D C:\Program Files (x86)\Microsoft Office 2020-03-16 10:28 - 2017-10-10 10:29 - 000010240 _____ C:\Users\chris\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2020-03-15 20:28 - 2017-05-24 11:35 - 000000000 ____D C:\Users\chris\AppData\Roaming\NCH Software 2020-03-15 20:28 - 2017-05-24 11:35 - 000000000 ____D C:\ProgramData\NCH Software 2020-03-15 19:29 - 2017-04-10 17:39 - 000000000 ____D C:\Users\chris\AppData\Local\Applian 2020-03-15 19:26 - 2019-02-10 20:01 - 000472032 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2020-03-15 19:24 - 2018-12-19 18:36 - 000000000 ____D C:\Users\chris\Documents\Applian 2020-03-15 19:23 - 2018-12-19 18:34 - 000000000 ____D C:\Users\chris\AppData\Local\Jaksta_Technologies_Pty_L 2020-03-15 19:19 - 2020-01-10 16:03 - 000000000 ____D C:\Users\chris\AppData\Roaming\vlc 2020-03-15 19:17 - 2018-12-19 18:34 - 000000000 ____D C:\Program Files (x86)\Applian Technologies 2020-03-15 19:17 - 2018-12-10 15:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Applian Technologies 2020-03-15 15:16 - 2017-10-06 12:15 - 000000000 ____D C:\Users\chris\AppData\Local\Wondershare 2020-03-15 14:53 - 2017-10-06 12:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare 2020-03-15 14:50 - 2017-10-06 12:16 - 000000000 ____D C:\ProgramData\Wondershare 2020-03-15 07:34 - 2017-07-10 16:41 - 000000000 ____D C:\Users\chris\AppData\Local\GoToMeeting 2020-03-13 18:40 - 2017-03-27 15:35 - 000000000 ____D C:\Program Files (x86)\Google 2020-03-13 17:57 - 2017-04-06 11:01 - 000000666 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-1547701397-687303812-3400344658-1001.job 2020-03-13 17:57 - 2017-04-06 11:01 - 000000570 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-1547701397-687303812-3400344658-1001.job 2020-03-13 10:38 - 2019-02-10 20:13 - 000003834 _____ C:\WINDOWS\system32\Tasks\G2MUploadTask-S-1-5-21-1547701397-687303812-3400344658-1001 2020-03-13 10:38 - 2019-02-10 20:13 - 000003738 _____ C:\WINDOWS\system32\Tasks\G2MUpdateTask-S-1-5-21-1547701397-687303812-3400344658-1001 2020-03-12 10:14 - 2017-04-10 17:34 - 000000000 ____D C:\Users\chris\AppData\Roaming\Replay Video Capture 8 2020-03-11 17:19 - 2018-12-21 19:16 - 000000000 ____D C:\Users\chris\AppData\Local\D3DSCache 2020-03-11 14:08 - 2017-05-22 13:44 - 000000000 ____D C:\Program Files\Lenovo 2020-03-11 14:08 - 2017-05-22 13:44 - 000000000 ____D C:\Program Files (x86)\Lenovo 2020-03-11 11:37 - 2017-11-24 10:05 - 000000000 ___RD C:\Users\chris\3D Objects 2020-03-11 11:37 - 2016-11-20 14:51 - 000000000 __RHD C:\Users\Public\AccountPictures 2020-03-11 11:34 - 2018-09-15 05:11 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection 2020-03-11 11:34 - 2018-09-15 03:33 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs 2020-03-11 11:34 - 2018-09-15 03:33 - 000000000 ___RD C:\WINDOWS\PrintDialog 2020-03-11 11:34 - 2018-09-15 03:33 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2020-03-11 11:34 - 2018-09-15 03:33 - 000000000 ___RD C:\Program Files\Windows Defender 2020-03-11 11:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\SysWOW64\setup 2020-03-11 11:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2020-03-11 11:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2020-03-11 11:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform 2020-03-11 11:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences 2020-03-11 11:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\system32\setup 2020-03-11 11:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation 2020-03-11 11:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\system32\oobe 2020-03-11 11:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\ShellExperiences 2020-03-11 11:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\ShellComponents 2020-03-11 11:34 - 2018-09-15 03:33 - 000000000 ____D C:\WINDOWS\bcastdvr 2020-03-11 11:34 - 2018-09-15 02:09 - 000000000 ____D C:\WINDOWS\system32\Dism 2020-03-11 11:34 - 2018-09-15 02:09 - 000000000 ____D C:\WINDOWS\servicing 2020-03-11 11:34 - 2017-01-31 10:36 - 121542864 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2020-03-11 11:34 - 2017-01-31 10:36 - 000000000 ____D C:\WINDOWS\system32\MRT 2020-03-11 11:33 - 2018-09-15 03:23 - 000000000 ____D C:\WINDOWS\CbsTemp 2020-03-06 12:17 - 2017-04-25 12:22 - 000000000 ___RD C:\Users\chris\Dropbox 2020-03-06 12:01 - 2019-03-19 03:30 - 000000000 ___HD C:\$WINDOWS.~BT 2020-03-06 10:55 - 2019-05-22 14:18 - 000000000 ____D C:\WINDOWS\Panther 2020-03-06 10:47 - 2019-02-10 20:12 - 000015243 _____ C:\WINDOWS\diagwrn.xml 2020-03-06 10:47 - 2019-02-10 20:12 - 000015243 _____ C:\WINDOWS\diagerr.xml 2020-03-04 16:02 - 2018-07-10 09:19 - 000000000 ____D C:\ProgramData\Packages 2020-03-04 16:02 - 2018-01-19 10:45 - 000000000 ____D C:\Users\chris\AppData\Local\PlaceholderTileLogoFolder 2020-03-04 11:22 - 2019-09-11 19:17 - 000000000 ____D C:\Program Files (x86)\Intel 2020-03-04 11:22 - 2017-02-02 16:14 - 000000000 ____D C:\ProgramData\Package Cache 2020-03-01 16:26 - 2017-01-31 10:34 - 000000000 ____D C:\Intel 2020-03-01 16:15 - 2017-05-22 13:45 - 000000000 ____D C:\Program Files\Intel 2020-02-29 17:33 - 2019-02-10 20:13 - 000000000 ____D C:\WINDOWS\system32\Tasks\Lenovo 2020-02-29 17:33 - 2018-07-23 11:24 - 000000000 ____D C:\Users\chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo 2020-02-29 14:52 - 2019-07-19 10:10 - 000002028 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2020-02-29 14:52 - 2019-07-19 10:10 - 000002028 _____ C:\ProgramData\Desktop\Malwarebytes.lnk 2020-02-29 14:51 - 2019-07-19 10:10 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys 2020-02-29 14:51 - 2019-07-19 10:10 - 000020936 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys 2020-02-29 14:13 - 2019-08-29 11:42 - 000000000 ____D C:\Users\chris\AppData\Local\cache 2020-02-25 19:06 - 2018-03-04 15:14 - 000001929 _____ C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk 2020-02-25 19:06 - 2018-03-04 15:14 - 000001929 _____ C:\ProgramData\Desktop\PC Scan & Repair by Reimage.lnk 2020-02-25 19:06 - 2018-03-04 15:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair 2020-02-25 18:52 - 2019-02-10 20:13 - 000003716 _____ C:\WINDOWS\system32\Tasks\Run RoboForm TaskBar Icon 2020-02-25 16:05 - 2019-12-31 16:04 - 000000000 ____D C:\WINDOWS\TempInst 2020-02-25 16:05 - 2018-11-20 16:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\lenovo 2020-02-25 16:04 - 2019-02-10 20:13 - 000000000 ____D C:\WINDOWS\system32\Tasks\TVT 2020-02-25 16:04 - 2018-11-20 16:04 - 000001659 _____ C:\WINDOWS\SysWOW64\InstallUtil.InstallLog 2020-02-25 16:03 - 2017-05-22 13:44 - 000000000 ____D C:\ProgramData\Lenovo 2020-02-25 10:38 - 2017-01-31 10:37 - 000748816 _____ (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ========================