I was visiting my mom in California over the Labor Day weekend when my laptop's hard drive crashed. I use this for my business and needed to get up and running fast. Since I wasn't at home I didn't have access to most of my computer stuff. Finding anything open over the holiday weekend was next to impossible but I managed to find a local computer repair shop with good reviews online. He replaced the hard drive and managed to rescue the latest work I had done and hadn't had a chance to back up. The rest I restored from backups. The problem was I had also just upgraded to Windows 10 so there were some issues with the Nvidia drivers at the time. I ended up doing a clean install over what the computer guy did. But the problems continued and grew worse. I started searching for malware and found one of the programs the computer guy installed had Open Candy. I got rid of that or so I thought. My laptop is slowing down, locking, up, and just being a butt. I just did yet another "clean" install (my fifth I believe? I lost count) yesterday and this morning I couldn't even check my email without locking up. I did a system restore, wiping out the programs but saving my files this morn. But my Firewall is wide open. I love the rule. "Allow any connection from any port to any remote port by any program." So I started digging a little deeper and even though I reformatted and did supposed clean installs, I'm finding everything comes back to the programs the computer guy installed. I'm starting to wonder if he left a back door open or something. Anyway, if y'all need specifics, let me know. I have a bunch of logs because one of my concerns is that there's a bad security certificate now. I have one that's expired but it's still labeled as trusted and there are flags on a few specifics of the certificate code. Having a bad cert means a lot of virus software would fall into the trap and say everything is just fine when it isn't. Okay, enough of that here are the specifics.
My laptop is an Asus ROG G750JX running Windows 10 Pro. The main HD which the computer guy replaced is 750gb but I also have a secondary drive which is a 1TB and it has a mystery partition I haven't been able to figure out. It's a 64bit system and Windows recognizes that on the system info screen but a majority of the software I run will only install and run as 32bit. I do a lot of intensive work in DAZ3D and Photoshop along with Adobe InDesign, so when these programs aren't running in 64bit, I notice it. I just upgraded the ram from 16gb to 32gb, and with the clean installs, this baby should be running lean and mean - she's not. For the 64bit issue I called Microsoft Tech support and they used Log Me In and couldn't figure out the problem. The programming guys are supposed to call me back next week. Yeah, watch me hold my breath on that one. I'd have better odds expecting a call from Bill Gates himself.
Here's the info from FARBAR:
Ran by kathr (administrator) on KATHRYNLAPTOP (02-10-2015 19:18:17)
Running from C:\Users\kathr\Desktop
Loaded Profiles: kathr (Available Profiles: kathr)
Platform: Windows 10 Pro (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Comodo) C:\Program Files (x86)\Comodo\Chromodo\chromodo_updater.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(SecureMix LLC) C:\Program Files (x86)\GlassWire\GWCtlSrv.exe
(SecureMix LLC) C:\Program Files (x86)\GlassWire\GWIdlMon.exe
(SecureMix LLC) C:\Program Files (x86)\GlassWire\GlassWire.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
(Comodo Security Solutions, Inc.) C:\Program Files\COMODO\GeekBuddy\unit_manager.exe
(Comodo Security Solutions, Inc.) C:\Program Files\COMODO\GeekBuddy\unit.exe
(Microsoft Corporation) C:\Windows\HelpPane.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
() C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
() C:\Program Files (x86)\Logitech\LWS\Webcam Software\MotionDetection.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\Adobe Installer.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe
(Joyent, Inc) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieCtrl.exe
==================== Registry (Whitelisted) ===========================
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508104 2015-09-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [tvncontrol] => C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-06-30] (Comodo Security Solutions, Inc.)
HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2292912 2015-09-17] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [1855672 2015-07-03] (Adobe Systems Inc.)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-4055827758-3256202687-3425098328-1001\...\Run: [Google Update] => C:\Users\kathr\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-10-02] (Google Inc.)
HKU\S-1-5-21-4055827758-3256202687-3425098328-1001\...\Run: [GlassWire] => C:\Program Files (x86)\GlassWire\glasswire.exe [10485248 2015-09-29] (SecureMix LLC)
HKU\S-1-5-21-4055827758-3256202687-3425098328-1001\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [787592 2015-09-21] (Sandboxie Holdings, LLC)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-09-11] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-09-11] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-09-11] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk [2015-10-02]
ShortcutTarget: Start GeekBuddy.lnk -> C:\Program Files\COMODO\GeekBuddy\launcher.exe (Comodo Security Solutions, Inc.)
Startup: C:\Users\kathr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Product Registration.lnk [2015-10-02]
ShortcutTarget: Logitech . Product Registration.lnk -> C:\Program Files (x86)\Logitech\Ereg\eReg.exe (Leader Technologies/Logitech)
Tcpip\..\Interfaces\{19d2050b-3eb4-4079-8edf-fcea30acdb4b}: [DhcpNameServer] 192.168.1.1
==================
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2015-07-03] (Adobe Systems Incorporated)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2015-07-03] (Adobe Systems Incorporated)
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2015-07-03] (Adobe Systems Incorporated)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2015-07-03] (Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2015-07-03] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2015-07-03] (Adobe Systems Incorporated)
========
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2015-09-17] (Adobe Systems)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2015-07-03] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2015-09-17] (Adobe Systems)
FF Plugin HKU\S-1-5-21-4055827758-3256202687-3425098328-1001: @tools.google.com/Google Update;version=3 -> C:\Users\kathr\AppData\Local\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-10-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-4055827758-3256202687-3425098328-1001: @tools.google.com/Google Update;version=9 -> C:\Users\kathr\AppData\Local\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-10-02] (Google Inc.)
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat DC - Create PDF - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn [2015-10-02]
=======
CHR Profile: C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Docs) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-10-02]
CHR Extension: (Google Drive) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-02]
CHR Extension: (YouTube) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-02]
CHR Extension: (Google Search) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-02]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-10-02]
CHR Extension: (Gmail) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-10-02]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
=======
OPR Extension: (LastPass) - C:\Users\kathr\AppData\Roaming\Opera Software\Opera Stable\Extensions\hnjalnkldgigidggphhmacmimbdlafdo [2015-10-02]
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2015936 2015-09-29] (Adobe Systems, Incorporated)
R4 ChromodoUpdater; C:\Program Files (x86)\Comodo\Chromodo\chromodo_updater.exe [1998520 2015-08-19] (Comodo)
R2 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70848 2015-08-13] (Comodo Security Solutions, Inc.)
R2 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-06-30] (Comodo Security Solutions, Inc.)
R2 GlassWire; C:\Program Files (x86)\GlassWire\GWCtlSrv.exe [8825344 2015-09-29] (SecureMix LLC)
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [177800 2015-09-21] (Sandboxie Holdings, LLC)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-09] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-09] (Microsoft Corporation)
R1 gwdrv; C:\Windows\system32\DRIVERS\gwdrv.sys [33152 2015-05-28] (SecureMix LLC)
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [193336 2015-10-01] (Intel Corporation)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [191624 2015-09-21] (Sandboxie Holdings, LLC)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-09] ()
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-07-09] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
==================== One Month Created files and folders ========
2015-10-02 19:13 - 2015-10-02 19:13 - 00003972 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-10-02 19:12 - 2015-10-02 19:12 - 00002469 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk
2015-10-02 19:12 - 2015-10-02 19:12 - 00002114 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk
2015-10-02 19:12 - 2015-10-02 19:12 - 00002091 _____ C:\Users\Public\Desktop\Adobe Acrobat DC.lnk
2015-10-02 19:04 - 2015-10-02 19:04 - 00001073 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe InDesign CC 2015.lnk
2015-10-02 18:57 - 2015-10-02 18:57 - 00076330 _____ C:\Users\kathr\Desktop\PFx REFLECTIONS.atn
2015-10-02 18:56 - 2015-10-02 19:06 - 00001472 _____ C:\WINDOWS\Sandboxie.ini
2015-10-02 18:56 - 2015-10-02 18:55 - 00000937 _____ C:\Users\kathr\Desktop\Sandboxed Web Browser.lnk
2015-10-02 18:55 - 2015-10-02 18:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie
2015-10-02 18:55 - 2015-10-02 18:55 - 00000000 ____D C:\Program Files\Sandboxie
2015-10-02 18:54 - 2015-10-02 18:55 - 08518280 _____ (Sandboxie Holdings, LLC) C:\Users\kathr\Downloads\SandboxieInstall.exe
2015-10-02 18:52 - 2015-10-02 19:12 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2015-10-02 18:51 - 2015-10-02 18:51 - 00001085 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2015.lnk
2015-10-02 18:49 - 2015-10-02 19:01 - 00000000 ____D C:\Program Files\Common Files\Adobe
2015-10-02 18:49 - 2015-10-02 19:01 - 00000000 ____D C:\Program Files\Adobe
2015-10-02 18:49 - 2015-10-02 18:49 - 00000000 ____D C:\Users\kathr\AppData\Local\Scrivener
2015-10-02 18:36 - 2015-10-02 18:37 - 00000000 ___RD C:\Users\kathr\Creative Cloud Files
2015-10-02 18:36 - 2015-10-02 18:36 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-10-02 18:35 - 2015-10-02 19:11 - 00000000 ____D C:\ProgramData\Adobe
2015-10-02 18:35 - 2015-10-02 18:35 - 00001302 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2015-10-02 18:35 - 2015-10-02 18:35 - 00001290 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2015-10-02 18:35 - 2015-10-02 18:35 - 00000000 ____D C:\ProgramData\Package Cache
2015-10-02 18:34 - 2015-10-02 19:11 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-10-02 18:32 - 2015-10-02 18:32 - 00001704 _____ C:\Users\Public\Desktop\Scrivener.lnk
2015-10-02 18:32 - 2015-10-02 18:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Scrivener
2015-10-02 18:31 - 2015-10-02 18:32 - 00000000 ____D C:\Program Files (x86)\Scrivener
2015-10-02 18:29 - 2015-10-02 18:29 - 00000000 ____D C:\ProgramData\DAZ 3D
2015-10-02 18:28 - 2015-10-02 18:29 - 00001176 _____ C:\Users\kathr\Desktop\DAZ Studio 4.8 (64-bit).lnk
2015-10-02 18:28 - 2015-10-02 18:28 - 00000000 ____D C:\Program Files\DAZ 3D
2015-10-02 18:00 - 2015-10-02 18:00 - 00000000 ____D C:\Users\kathr\AppData\Local\Logitech® Webcam Software
2015-10-02 17:58 - 2015-10-02 17:58 - 00000000 ____D C:\Users\kathr\AppData\Roaming\Leadertech
2015-10-02 17:58 - 2015-10-02 17:58 - 00000000 ____D C:\ProgramData\LogiShrd
2015-10-02 17:57 - 2015-10-02 17:58 - 00003850 _____ C:\WINDOWS\LDPINST.LOG
2015-10-02 17:57 - 2015-10-02 17:58 - 00000000 ____D C:\Program Files (x86)\Logitech
2015-10-02 17:57 - 2015-10-02 17:57 - 00001713 _____ C:\Users\Public\Desktop\Logitech Webcam Software .lnk
2015-10-02 17:57 - 2015-10-02 17:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2015-10-02 17:55 - 2015-10-02 17:56 - 74520472 _____ (Logitech, Inc.) C:\Users\kathr\Downloads\lws280.exe
2015-10-02 17:49 - 2015-10-02 17:58 - 00007384 _____ C:\WINDOWS\system32\lvcoinst.log
2015-10-02 17:49 - 2015-10-02 17:58 - 00000000 ____D C:\Program Files\Common Files\logishrd
2015-10-02 17:43 - 2015-10-02 17:43 - 00000000 ____D C:\Users\kathr\Desktop\Heart's Ransom cover
2015-10-02 17:42 - 2015-10-02 17:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2015-10-02 17:40 - 2015-10-02 17:40 - 00001226 _____ C:\Users\Public\Desktop\FastPictureViewer Cheat Sheet.lnk
2015-10-02 17:40 - 2015-10-02 17:40 - 00001156 _____ C:\Users\Public\Desktop\Fast Picture Viewer 64.lnk
2015-10-02 17:40 - 2015-10-02 17:40 - 00000000 ____D C:\WINDOWS\WICCodecs
2015-10-02 17:40 - 2015-10-02 17:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FastPictureViewer
2015-10-02 17:40 - 2015-10-02 17:40 - 00000000 ____D C:\ProgramData\FastPictureViewer
2015-10-02 17:40 - 2015-10-02 17:40 - 00000000 ____D C:\Program Files\FastPictureViewer
2015-10-02 17:38 - 2015-10-02 17:39 - 00000000 ____D C:\Users\kathr\Desktop\3d n Art
2015-10-02 17:37 - 2015-10-02 18:32 - 00000000 ____D C:\Users\kathr\Desktop\computer
2015-10-02 17:33 - 2015-10-02 17:33 - 02192384 _____ (Farbar) C:\Users\kathr\Desktop\FRST64.exe
2015-10-02 17:24 - 2015-10-02 17:24 - 01872472 _____ C:\Users\kathr\Desktop\SmitfraudFix.exe
2015-10-02 17:20 - 2015-10-02 17:20 - 00872029 _____ C:\Users\kathr\Desktop\HxDSetupEN.zip
2015-10-02 17:19 - 2015-10-02 17:19 - 02023693 _____ C:\Users\kathr\Desktop\tweaking.com_registry_backup_portable.zip
2015-10-02 17:18 - 2015-10-02 17:18 - 18801736 _____ C:\Users\kathr\Desktop\RogueKiller.exe
2015-10-02 17:16 - 2015-10-02 17:16 - 00680600 _____ (Sysinternals - www.sysinternals.com) C:\Users\kathr\Desktop\autoruns.exe
2015-10-02 17:02 - 2015-10-02 17:02 - 00002148 _____ C:\Users\kathr\Desktop\VirusTotal Uploader 2.2.lnk
2015-10-02 17:02 - 2015-10-02 17:02 - 00000000 ____D C:\Users\kathr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirusTotal Uploader 2.2
2015-10-02 17:02 - 2015-10-02 17:02 - 00000000 ____D C:\Program Files (x86)\VirusTotalUploader2
2015-10-02 16:56 - 2015-10-02 16:56 - 00142744 _____ C:\Users\kathr\Downloads\vtuploader2.2.exe
2015-10-02 16:33 - 2015-10-02 16:33 - 00003740 _____ C:\WINDOWS\System32\Tasks\herdProtectScan
2015-10-02 16:15 - 2015-10-02 16:15 - 00002086 _____ C:\Users\Public\Desktop\GeekBuddy.lnk
2015-10-02 16:15 - 2015-10-02 16:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo Security Solutions Inc
2015-10-02 16:14 - 2015-10-02 16:15 - 225688096 _____ (COMODO) C:\Users\kathr\Documents\cav_installer_3264_29.exe
2015-10-02 16:13 - 2015-10-02 16:15 - 225688096 _____ (COMODO) C:\Users\kathr\Documents\cav_installer_5964_b8.exe
2015-10-02 16:06 - 2015-10-02 16:06 - 00000000 ____D C:\Users\kathr\AppData\Local\PeerDistRepub
2015-10-02 16:04 - 2015-10-02 16:04 - 03861568 _____ (Reason Software Company Inc.) C:\Users\kathr\Documents\reason-core-security-setup.exe
2015-10-02 16:04 - 2015-10-02 16:04 - 03861568 _____ (Reason Software Company Inc.) C:\Users\kathr\Documents\reason-core-security-setup (1).exe
2015-10-02 16:02 - 2015-10-02 16:02 - 02873112 _____ (Reason Company Software Inc.) C:\Users\kathr\Documents\herdProtectScan_Setup.exe
2015-10-02 16:02 - 2015-10-02 16:02 - 00001162 _____ C:\Users\Public\Desktop\herdProtect.lnk
2015-10-02 16:02 - 2015-10-02 16:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\herdProtect
2015-10-02 16:02 - 2015-10-02 16:02 - 00000000 ____D C:\Program Files\Reason
2015-10-02 15:50 - 2015-10-02 15:50 - 21854008 _____ (SecureMix LLC) C:\Users\kathr\Downloads\GlassWireSetup.exe
2015-10-02 15:50 - 2015-10-02 15:50 - 00001974 _____ C:\Users\kathr\Desktop\GlassWire.lnk
2015-10-02 15:50 - 2015-10-02 15:50 - 00000000 ____D C:\Users\kathr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GlassWire
2015-10-02 15:50 - 2015-10-02 15:50 - 00000000 ____D C:\Users\kathr\AppData\Local\GlassWire
2015-10-02 15:50 - 2015-10-02 15:50 - 00000000 ____D C:\ProgramData\GlassWire
2015-10-02 15:50 - 2015-10-02 15:50 - 00000000 ____D C:\Program Files (x86)\GlassWire
2015-10-02 15:50 - 2015-05-28 23:30 - 00008392 _____ C:\WINDOWS\system32\Drivers\gwdrv.cat
2015-10-02 15:50 - 2015-05-28 23:15 - 00033152 _____ (SecureMix LLC) C:\WINDOWS\system32\Drivers\gwdrv.sys
2015-10-02 15:37 - 2015-10-02 15:38 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-10-02 15:37 - 2015-08-26 18:37 - 134753440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-10-02 15:36 - 2015-10-02 15:36 - 10919784 _____ C:\WINDOWS\SysWOW64\LogiDPP.dll
2015-10-02 15:36 - 2015-10-02 15:36 - 10919784 _____ C:\WINDOWS\system32\LogiDPP.dll
2015-10-02 15:36 - 2015-10-02 15:36 - 04758176 _____ (Logitech Inc.) C:\WINDOWS\system32\Drivers\lvuvc64.sys
2015-10-02 15:36 - 2015-10-02 15:36 - 00768288 _____ (Logitech Inc.) C:\WINDOWS\system32\LVUI64.dll
2015-10-02 15:36 - 2015-10-02 15:36 - 00560416 _____ (Logitech Inc.) C:\WINDOWS\system32\LVUIRC64.dll
2015-10-02 15:36 - 2015-10-02 15:36 - 00542568 _____ (Logitech Inc.) C:\WINDOWS\SysWOW64\LVUI2.dll
2015-10-02 15:36 - 2015-10-02 15:36 - 00538472 _____ (Logitech Inc.) C:\WINDOWS\SysWOW64\LVUI2RC.dll
2015-10-02 15:36 - 2015-10-02 15:36 - 00336232 _____ C:\WINDOWS\SysWOW64\DevManagerCore.dll
2015-10-02 15:36 - 2015-10-02 15:36 - 00336232 _____ C:\WINDOWS\system32\DevManagerCore.dll
2015-10-02 15:36 - 2015-10-02 15:36 - 00305000 _____ (Logitech Inc.) C:\WINDOWS\SysWOW64\lvcodec2.dll
2015-10-02 15:36 - 2015-10-02 15:36 - 00266828 _____ C:\WINDOWS\system32\Drivers\LVAFT.cfg
2015-10-02 15:36 - 2015-10-02 15:36 - 00262432 _____ (Logitech Inc.) C:\WINDOWS\system32\lvco1380853.dll
2015-10-02 15:36 - 2015-10-02 15:36 - 00175392 _____ (Logitech Inc.) C:\WINDOWS\system32\lvcod64.dll
2015-10-02 15:36 - 2015-10-02 15:36 - 00103272 _____ C:\WINDOWS\SysWOW64\LogiDPPApp.exe
2015-10-02 15:36 - 2015-10-02 15:36 - 00103272 _____ C:\WINDOWS\system32\LogiDPPApp.exe
2015-10-02 15:36 - 2015-10-02 15:36 - 00029494 _____ C:\WINDOWS\system32\lvcoin64.ini
2015-10-02 15:36 - 2015-10-02 15:36 - 00000000 ____D C:\Program Files\Elantech
2015-10-02 15:29 - 2015-10-02 15:29 - 00000000 ____D C:\WINDOWS\pss
2015-10-02 15:13 - 2015-10-02 15:13 - 00000000 ____D C:\Users\kathr\AppData\Roaming\Macromedia
2015-10-02 15:03 - 2015-10-02 15:03 - 00016148 _____ C:\WINDOWS\system32\KATHRYNLAPTOP_kathr_HistoryPrediction.bin
2015-10-02 15:01 - 2015-10-02 15:02 - 00324544 _____ C:\WINDOWS\Minidump\100215-39906-01.dmp
2015-10-02 15:01 - 2015-10-02 15:01 - 656602759 _____ C:\WINDOWS\MEMORY.DMP
2015-10-02 15:01 - 2015-10-02 15:01 - 00000000 ____D C:\WINDOWS\Minidump
2015-10-02 14:47 - 2015-10-02 14:47 - 00000000 ___HD C:\VTRoot
2015-10-02 13:20 - 2015-10-02 13:20 - 00069632 _____ C:\Users\kathr\Documents\acctchg.evtx
2015-10-02 12:48 - 2015-10-02 12:48 - 00000000 ____D C:\Windows.old
2015-10-02 12:48 - 2015-10-02 10:02 - 00000000 ___DC C:\WINDOWS\Panther
2015-10-02 12:45 - 2015-10-02 12:45 - 00028672 ___SH C:\WINDOWS\system32\config\BCD-Template.LOG
2015-10-02 12:44 - 2015-10-02 12:44 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2015-10-02 12:43 - 2015-10-02 12:43 - 00000000 ____D C:\WINDOWS\Setup
2015-10-02 12:41 - 2015-10-02 12:41 - 00000000 ____D C:\WINDOWS\OCR
2015-10-02 12:40 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm
2015-10-02 12:40 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
2015-10-02 12:40 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
2015-10-02 12:40 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr
2015-10-02 12:40 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2015-10-02 12:40 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\SysWOW64\0409
2015-10-02 12:40 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\system32\winrm
2015-10-02 12:40 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\system32\WCN
2015-10-02 12:40 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\system32\slmgr
2015-10-02 12:40 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2015-10-02 12:40 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\system32\0409
2015-10-02 12:40 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\DigitalLocker
2015-10-02 12:38 - 2015-09-15 11:12 - 00812008 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-10-02 12:38 - 2015-09-15 11:12 - 00178152 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-10-02 12:37 - 2015-10-02 09:57 - 00001189 _____ C:\WINDOWS\DtcInstall.log
2015-10-02 12:36 - 2015-10-02 19:06 - 00000000 ____D C:\WINDOWS\system32\sru
2015-10-02 12:36 - 2015-10-02 18:29 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-10-02 12:36 - 2015-10-02 17:58 - 00000000 ____D C:\WINDOWS\registration
2015-10-02 12:36 - 2015-10-02 12:48 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2015-10-02 12:36 - 2015-10-02 12:43 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-02 12:36 - 2015-10-02 12:43 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-02 12:36 - 2015-10-02 12:43 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
2015-10-02 12:36 - 2015-10-02 12:43 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2015-10-02 12:36 - 2015-10-02 12:43 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2015-10-02 12:36 - 2015-10-02 12:43 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2015-10-02 12:36 - 2015-10-02 12:43 - 00000000 ____D C:\WINDOWS\system32\oobe
2015-10-02 12:36 - 2015-10-02 12:43 - 00000000 ____D C:\WINDOWS\system32\Dism
2015-10-02 12:36 - 2015-10-02 12:43 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-10-02 12:36 - 2015-10-02 12:43 - 00000000 ____D C:\WINDOWS\Provisioning
2015-10-02 12:36 - 2015-10-02 12:43 - 00000000 ____D C:\Program Files\Windows Journal
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ___SD C:\WINDOWS\system32\F12
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ___SD C:\WINDOWS\system32\dsc
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\SysWOW64\setup
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\SysWOW64\Com
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\system32\setup
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\system32\MUI
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\system32\migwiz
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\system32\Com
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\IME
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\Program Files\Windows Defender
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\Program Files\Common Files\System
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2015-10-02 12:36 - 2015-10-02 12:37 - 00000000 __RSD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-10-02 12:36 - 2015-10-02 12:37 - 00000000 __RSD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 __SHD C:\WINDOWS\BitLockerDiscoveryVolumeContents
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 __SHD C:\Program Files\Windows Sidebar
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 __RSD C:\WINDOWS\Media
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 __RHD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___SD C:\WINDOWS\SysWOW64\Nui
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___SD C:\WINDOWS\SysWOW64\Configuration
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___SD C:\WINDOWS\system32\Nui
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___SD C:\WINDOWS\system32\Configuration
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___SD C:\Program Files\WindowsPowerShell
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___SD C:\Program Files (x86)\WindowsPowerShell
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___RD C:\WINDOWS\Offline Web Pages
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___RD C:\WINDOWS\DesktopTileResources
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\Web
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\Vss
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\tracing
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\TAPI
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\zh-HK
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\WindowsPowerShell
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\uk-UA
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\tr-TR
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\th-TH
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\sru
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\sr-Latn-RS
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\sr-Latn-CS
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\sppui
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\spp
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\Speech_OneCore
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\Speech
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\sl-SI
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\sk-SK
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\ro-RO
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\restore
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\Recovery
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\RasToast
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\ras
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\networklist
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\NDF
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\MsDtc
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\MSDRM
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\Licenses
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\Ipmi
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\InputMethod
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\icsxml
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\hr-HR
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\he-IL
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\fr-CA
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\et-EE
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\es-MX
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\en-GB
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\downlevel
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\Bthprops
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\bg-BG
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\ar-SA
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\AppLocker
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SystemResources
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\zh-HK
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\WinMetadata
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\winevt
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\WindowsPowerShell
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\uk-UA
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\tr-TR
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\th-TH
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\sr-Latn-RS
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\sr-Latn-CS
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\sppui
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\spp
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\spool
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\Speech_OneCore
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\Speech
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\sl-SI
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\sk-SK
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\ro-RO
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\RasToast
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\ras
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\ProximityToast
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\PointOfService
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\networklist
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\MsDtc
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\MSDRM
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\Macromed
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\lv-LV
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\lt-LT
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\Licenses
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\Ipmi
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\InputMethod
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\IME
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\icsxml
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\ias
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\hr-HR
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\he-IL
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\fr-CA
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\et-EE
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\es-MX
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\en-GB
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\downlevel
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\config\Journal
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\Bthprops
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\bg-BG
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\ar-SA
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\AppLocker
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system\Speech
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\System
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\Speech_OneCore
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\Speech
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SKB
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\ShellNew
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\security
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\schemas
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SchCache
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\Resources
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\PLA
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\Performance
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\L2Schemas
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\InputMethod
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\Globalization
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\Cursors
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\Branding
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\appcompat
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\addins
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\ProgramData\USOPrivate
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\ProgramData\Comms
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\Program Files\Windows Portable Devices
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\Program Files\Windows NT
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\Program Files\Common Files\Services
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\Program Files (x86)\Windows NT
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2015-10-02 12:36 - 2015-10-02 12:34 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2015-10-02 12:36 - 2015-10-02 12:34 - 00215943 _____ C:\WINDOWS\SysWOW64\dssec.dat
2015-10-02 12:36 - 2015-10-02 12:34 - 00215943 _____ C:\WINDOWS\system32\dssec.dat
2015-10-02 12:36 - 2015-10-02 12:34 - 00208384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2015-10-02 12:36 - 2015-10-02 12:34 - 00017463 _____ C:\WINDOWS\system32\Drivers\etc\services
2015-10-02 12:36 - 2015-10-02 12:34 - 00015462 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2015-10-02 12:36 - 2015-10-02 12:34 - 00008798 _____ C:\WINDOWS\SysWOW64\icrav03.rat
2015-10-02 12:36 - 2015-10-02 12:34 - 00008798 _____ C:\WINDOWS\system32\icrav03.rat
2015-10-02 12:36 - 2015-10-02 12:34 - 00003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam
2015-10-02 12:36 - 2015-10-02 12:34 - 00001988 _____ C:\WINDOWS\SysWOW64\ticrf.rat
2015-10-02 12:36 - 2015-10-02 12:34 - 00001988 _____ C:\WINDOWS\system32\ticrf.rat
2015-10-02 12:36 - 2015-10-02 12:34 - 00001358 _____ C:\WINDOWS\system32\Drivers\etc\protocol
2015-10-02 12:36 - 2015-10-02 12:34 - 00000858 _____ C:\WINDOWS\system32\DefaultQuestions.json
2015-10-02 12:36 - 2015-10-02 12:34 - 00000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT
2015-10-02 12:36 - 2015-10-02 12:34 - 00000741 _____ C:\WINDOWS\system32\NOISE.DAT
2015-10-02 12:36 - 2015-10-02 12:34 - 00000407 _____ C:\WINDOWS\system32\Drivers\etc\networks
2015-10-02 12:36 - 2015-10-02 12:34 - 00000219 _____ C:\WINDOWS\system.ini
2015-10-02 12:36 - 2015-10-02 12:34 - 00000092 _____ C:\WINDOWS\win.ini
2015-10-02 12:36 - 2015-10-02 11:06 - 00000000 ____D C:\WINDOWS\system32\restore
2015-10-02 12:36 - 2015-10-02 10:38 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-10-02 12:36 - 2015-10-02 10:06 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2015-10-02 12:36 - 2015-10-02 10:06 - 00000000 ___RD C:\WINDOWS\PrintDialog
2015-10-02 12:36 - 2015-10-02 10:06 - 00000000 ___RD C:\WINDOWS\MiracastView
2015-10-02 12:36 - 2015-10-02 10:06 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2015-10-02 12:36 - 2015-10-02 10:04 - 00000000 ____D C:\WINDOWS\rescache
2015-10-02 12:36 - 2015-10-02 10:01 - 00000000 __RHD C:\Users\Public\Libraries
2015-10-02 12:36 - 2015-10-02 10:01 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2015-10-02 12:36 - 2015-10-02 10:01 - 00000000 ____D C:\WINDOWS\system32\Recovery
2015-10-02 12:36 - 2015-10-02 09:59 - 00000000 ____D C:\WINDOWS\CSC
2015-10-02 12:36 - 2015-10-02 09:57 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2015-10-02 12:36 - 2015-10-02 09:57 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2015-10-02 12:36 - 2015-10-02 09:54 - 00000000 ____D C:\WINDOWS\Help
2015-10-02 12:28 - 2015-10-02 15:38 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-10-02 12:25 - 2015-10-02 17:42 - 00000000 ____D C:\Program Files (x86)\7-Zip
2015-10-02 12:24 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\servicing
2015-10-02 12:24 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\SMI
2015-10-02 12:24 - 2015-10-02 10:26 - 00131072 ___SH C:\WINDOWS\system32\config\BBI
2015-10-02 12:24 - 2015-10-02 10:02 - 00000000 __RHD C:\Users\Default
2015-10-02 12:24 - 2015-10-02 09:53 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2015-10-02 12:24 - 2015-07-10 04:11 - 00000164 _____ C:\WINDOWS\system32\config\FP
2015-10-02 12:23 - 2015-10-02 12:44 - 00000000 ___HD C:\$Windows.~BT
2015-10-02 12:23 - 2015-10-02 12:23 - 00000000 ___HD C:\$SysReset
2015-10-02 11:32 - 2015-10-02 13:50 - 00000000 ____D C:\Users\kathr\AppData\Roaming\Comodo
2015-10-02 11:27 - 2015-10-02 11:27 - 00000000 ___HD C:\OneDriveTemp
2015-10-02 11:10 - 2015-10-02 11:10 - 11992318 _____ C:\Users\kathr\Desktop\OBS_0_655b.zip
2015-10-02 11:09 - 2015-10-02 11:09 - 00000000 ____D C:\ProgramData\Shared Space
2015-10-02 11:07 - 2015-10-02 19:13 - 00000000 ____D C:\Users\kathr\AppData\Local\Adobe
2015-10-02 11:07 - 2015-10-02 11:07 - 00686768 _____ (Adobe Systems Incorporated) C:\Users\kathr\Downloads\CreativeCloudSet-Up (1).exe
2015-10-02 11:04 - 2015-10-02 17:57 - 00000000 ____D C:\Program Files\COMODO
2015-10-02 11:04 - 2015-10-02 17:57 - 00000000 ____D C:\Program Files (x86)\Comodo
2015-10-02 11:04 - 2015-10-02 16:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
2015-10-02 11:04 - 2015-10-02 11:04 - 00000000 ____D C:\Users\kathr\AppData\Local\Comodo
2015-10-02 11:03 - 2015-10-02 17:57 - 00000000 ____D C:\ProgramData\Comodo Downloader
2015-10-02 11:02 - 2015-10-02 17:58 - 00000000 ____D C:\ProgramData\Comodo
2015-10-02 11:01 - 2015-10-02 11:01 - 01060864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc71.dll
2015-10-02 11:01 - 2015-10-02 11:01 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr71.dll
2015-10-02 11:00 - 2015-10-02 11:00 - 11278928 _____ (COMODO) C:\Users\kathr\Desktop\CPM_SETUP_1.3.2.30_xp_vista_server2003_win7.exe
2015-10-02 10:59 - 2015-10-02 11:02 - 225688136 _____ (COMODO) C:\Users\kathr\Downloads\cispro_30day_installer_1157_1a.exe
2015-10-02 10:59 - 2015-10-02 11:00 - 225688096 _____ (COMODO) C:\Users\kathr\Downloads\cmd_fw_installer_6106_c6.exe
2015-10-02 10:58 - 2015-10-02 17:42 - 01079856 _____ (Igor Pavlov) C:\Users\kathr\Desktop\7z1507.exe
2015-10-02 10:53 - 2015-10-02 10:53 - 00000000 ____D C:\Users\kathr\AppData\Roaming\DAZ 3D
2015-10-02 10:52 - 2015-10-02 18:28 - 00000000 ____D C:\Users\kathr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DAZ 3D
2015-10-02 10:52 - 2015-10-02 10:52 - 30151896 _____ (DAZ 3D) C:\Users\kathr\Downloads\DAZ3DIM_1.1.0.41_Win32 (1).exe
2015-10-02 10:52 - 2015-10-02 10:52 - 00000000 ____D C:\Program Files (x86)\DAZ 3D
2015-10-02 10:48 - 2015-10-02 17:57 - 00000000 ____D C:\Users\kathr\AppData\Roaming\vlc
2015-10-02 10:48 - 2015-10-02 10:48 - 00001143 _____ C:\Users\Public\Desktop\VLC media player.lnk
2015-10-02 10:48 - 2015-10-02 10:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2015-10-02 10:48 - 2015-10-02 10:48 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2015-10-02 10:44 - 2015-10-02 10:45 - 28849904 _____ C:\Users\kathr\Downloads\vlc-2.2.1-win32.exe
2015-10-02 10:38 - 2015-07-05 05:08 - 00300704 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2015-10-02 10:34 - 2015-10-02 18:39 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4055827758-3256202687-3425098328-1001UA.job
2015-10-02 10:34 - 2015-10-02 11:04 - 00001199 _____ C:\Users\kathr\Desktop\Internet (Chromodo).lnk
2015-10-02 10:34 - 2015-10-02 10:39 - 00000884 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4055827758-3256202687-3425098328-1001Core.job
2015-10-02 10:34 - 2015-10-02 10:34 - 00004054 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4055827758-3256202687-3425098328-1001UA
2015-10-02 10:34 - 2015-10-02 10:34 - 00003940 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1443800042
2015-10-02 10:34 - 2015-10-02 10:34 - 00003678 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4055827758-3256202687-3425098328-1001Core
2015-10-02 10:34 - 2015-10-02 10:34 - 00001208 _____ C:\Users\Public\Desktop\Opera.lnk
2015-10-02 10:34 - 2015-10-02 10:34 - 00001208 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2015-10-02 10:34 - 2015-10-02 10:34 - 00000000 ____D C:\Users\kathr\AppData\Roaming\Opera Software
2015-10-02 10:34 - 2015-10-02 10:34 - 00000000 ____D C:\Users\kathr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-10-02 10:34 - 2015-10-02 10:34 - 00000000 ____D C:\Users\kathr\AppData\Local\Opera Software
2015-10-02 10:33 - 2015-10-02 10:34 - 00000000 ____D C:\Users\kathr\AppData\Local\Google
2015-10-02 10:33 - 2015-10-02 10:34 - 00000000 ____D C:\Program Files (x86)\Opera
2015-10-02 10:33 - 2015-10-02 10:33 - 00724456 _____ (Opera Software) C:\Users\kathr\Downloads\Opera_NI_stable.exe
2015-10-02 10:32 - 2015-10-02 10:33 - 00929872 _____ (Google Inc.) C:\Users\kathr\Downloads\ChromeSetup (1).exe
2015-10-02 10:25 - 2015-10-01 00:15 - 02544872 _____ (ELAN Microelectronics Corp.) C:\WINDOWS\ETDUninst.dll
2015-10-02 10:21 - 2015-10-02 10:32 - 00000000 ____D C:\Users\kathr\AppData\Local\MicrosoftEdge
2015-10-02 10:16 - 2015-10-02 10:16 - 00002338 _____ C:\Users\kathr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-10-02 10:08 - 2015-10-02 10:08 - 00014044 _____ C:\Users\kathr\Desktop\Removed Apps.html
2015-10-02 10:08 - 2015-10-02 10:08 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2015-10-02 10:07 - 2015-10-02 10:07 - 00000000 ____D C:\Users\kathr\AppData\Local\Comms
2015-10-02 10:06 - 2015-10-02 19:01 - 00000000 ____D C:\Users\kathr\AppData\Roaming\Adobe
2015-10-02 10:06 - 2015-10-02 10:33 - 00000000 ____D C:\Users\kathr\AppData\Local\Packages
2015-10-02 10:06 - 2015-10-02 10:06 - 00000000 ____D C:\Users\kathr\AppData\Local\VirtualStore
2015-10-02 10:06 - 2015-10-02 10:06 - 00000000 ____D C:\Users\kathr\AppData\Local\TileDataLayer
2015-10-02 10:06 - 2015-10-02 10:06 - 00000000 ____D C:\Users\kathr\AppData\Local\Publishers
2015-10-02 10:05 - 2015-10-02 18:00 - 00830266 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-02 10:05 - 2015-10-02 10:05 - 00000020 ___SH C:\Users\kathr\ntuser.ini
2015-10-02 10:02 - 2015-10-02 10:02 - 00000000 __SHD C:\Recovery
2015-10-02 10:00 - 2015-10-02 18:36 - 00000000 ____D C:\Users\kathr
2015-10-02 10:00 - 2015-10-02 12:37 - 00000000 __RSD C:\Users\kathr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-10-02 10:00 - 2015-10-02 12:36 - 00000000 ___RD C:\Users\kathr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-10-02 10:00 - 2015-10-02 12:36 - 00000000 ___RD C:\Users\kathr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-02 10:00 - 2015-10-02 12:36 - 00000000 ____D C:\Users\kathr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-10-02 10:00 - 2015-10-02 10:06 - 00000000 ___RD C:\Users\kathr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-02 09:54 - 2015-10-02 16:56 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-10-02 09:54 - 2015-10-02 09:54 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-10-02 09:54 - 2015-10-02 09:54 - 00000000 ____D C:\ProgramData\NVIDIA
2015-10-02 09:54 - 2015-07-13 12:37 - 06873744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2015-10-02 09:54 - 2015-07-13 12:37 - 03493008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2015-10-02 09:54 - 2015-07-13 12:37 - 02558792 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2015-10-02 09:54 - 2015-07-13 12:37 - 00937616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2015-10-02 09:54 - 2015-07-13 12:37 - 00385168 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2015-10-02 09:54 - 2015-07-13 12:37 - 00062792 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2015-10-02 09:54 - 2015-07-13 11:28 - 05096627 _____ C:\WINDOWS\system32\nvcoproc.bin
2015-10-02 09:53 - 2015-10-02 09:54 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2015-10-02 09:53 - 2015-10-02 09:53 - 00000000 ____D C:\ProgramData\USOShared
2015-10-02 09:53 - 2015-07-10 00:37 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2015-10-02 09:51 - 2015-10-02 17:58 - 00004446 _____ C:\WINDOWS\setupact.log
2015-10-02 09:51 - 2015-10-02 09:51 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-10-02 09:50 - 2015-10-02 15:02 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-10-02 09:49 - 2015-10-02 09:59 - 00189240 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-10-02 01:41 - 2015-10-02 01:41 - 00000000 ____D C:\Users\kathr\Documents\Bills
2015-10-02 01:34 - 2015-10-02 17:39 - 00000000 ____D C:\Users\kathr\Desktop\unzipped
2015-10-02 00:42 - 2015-09-17 22:57 - 138614960 _____ C:\Users\kathr\Desktop\Contemporary.7z
2015-10-02 00:39 - 2015-09-17 22:58 - 140702508 _____ C:\Users\kathr\Desktop\Barbarian.7z
2015-10-02 00:39 - 2015-09-17 22:52 - 661759905 _____ C:\Users\kathr\Desktop\Box Set Legacy.7z
2015-10-02 00:39 - 2015-07-15 04:45 - 1636930063 _____ C:\Users\kathr\Desktop\Caitlyn and Revian.7z
2015-10-02 00:38 - 2015-09-17 22:56 - 00634518 _____ C:\Users\kathr\Desktop\Star Song.7z
2015-10-02 00:38 - 2015-09-17 22:41 - 111781367 _____ C:\Users\kathr\Desktop\Heart's Ransom.7z
2015-10-02 00:36 - 2015-09-17 23:07 - 2851067503 _____ C:\Users\kathr\Desktop\Heart's Ransom cover.7z
2015-10-02 00:36 - 2015-09-17 22:56 - 00081827 _____ C:\Users\kathr\Desktop\dragoninksketch.7z
2015-10-02 00:36 - 2015-09-17 22:55 - 62534172 _____ C:\Users\kathr\Desktop\Demon Heir.7z
2015-10-02 00:36 - 2015-09-17 22:54 - 02936301 _____ C:\Users\kathr\Desktop\coverformat settings.7z
2015-10-02 00:36 - 2015-09-17 22:46 - 118194152 _____ C:\Users\kathr\Desktop\Demon Seed.7z
2015-10-01 11:56 - 2015-10-01 11:56 - 01592640 _____ (LogMeIn, Inc.) C:\Users\kathr\Downloads\Support-LogMeInRescue.exe
2015-10-01 10:05 - 2015-10-01 13:41 - 00000000 ____D C:\Users\kathr\Documents\DAZ 3D
2015-10-01 09:58 - 2015-10-01 10:40 - 00000000 ____D C:\Users\kathr\Documents\Outlook Files
2015-10-01 02:37 - 2015-10-01 23:35 - 00000000 ____D C:\Users\Public\Documents\My DAZ 3D Library
2015-10-01 02:12 - 2015-10-01 02:12 - 00000000 ____D C:\Users\Public\Documents\DAZ 3D
2015-10-01 02:11 - 2015-10-02 18:25 - 00002114 _____ C:\Users\kathr\Desktop\DAZ Install Manager.lnk
2015-10-01 02:09 - 2015-10-01 02:48 - 02875456 _____ (Microsoft Corporation) C:\Users\kathr\Desktop\Setup.X86.en-US_O365HomePremRetail_fce58278-39ee-4cee-bbf1-e65d341595be_TX_PR_.exe
2015-10-01 02:03 - 2015-10-02 18:51 - 00000000 ____D C:\Users\kathr\Documents\Adobe
2015-10-01 01:58 - 2015-10-01 01:58 - 00000000 _____ C:\d956d726f5b732d32501
2015-10-01 01:58 - 2015-10-01 01:58 - 00000000 _____ C:\c9112f9ef026831bf709
2015-10-01 01:46 - 2015-10-02 18:36 - 00000000 ___RD C:\Users\kathr\Creative Cloud Files (1)
2015-10-01 01:39 - 2015-10-01 01:39 - 00686768 _____ (Adobe Systems Incorporated) C:\Users\kathr\Desktop\CreativeCloudSet-Up.exe
2015-10-01 01:05 - 2015-10-01 01:06 - 16790552 _____ (LastPass) C:\Users\kathr\Desktop\lastpass_x64.exe
2015-10-01 01:05 - 2015-10-01 01:05 - 00929872 _____ (Google Inc.) C:\Users\kathr\Downloads\ChromeSetup.exe
2015-10-01 00:38 - 2015-10-01 00:38 - 00832016 _____ (Webroot) C:\Users\kathr\Downloads\wsainstall.exe
2015-10-01 00:20 - 2015-10-02 15:15 - 00000000 ___RD C:\Users\kathr\OneDrive
2015-10-01 00:17 - 2015-10-01 00:17 - 00193336 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\TeeDriverW8x64.sys
2015-10-01 00:15 - 2015-10-01 00:15 - 00447576 _____ (ELAN Microelectronics Corp.) C:\WINDOWS\system32\Drivers\ETD.sys
2015-09-30 23:26 - 2015-09-30 23:26 - 42730128 _____ C:\WINDOWS\system32\nvcompiler.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 37748880 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 30518928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 22972560 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 18514616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 16159608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 16009800 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 15892904 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 14510584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 13274560 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 12972336 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 11842680 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 11139216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2015-09-30 23:26 - 2015-09-30 23:26 - 03344672 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 02955832 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 02360976 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 02163856 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 01898312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6435354.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 01558848 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 01557832 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvir3dgenco64.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 01557648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6435354.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 01061192 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 01052488 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 00983368 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 00976528 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 00787200 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 00632848 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 00452240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvstusb.sys
2015-09-30 23:26 - 2015-09-30 23:26 - 00408208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 00384464 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 00374416 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 00364176 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 00340624 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 00314936 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 00195912 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2015-09-30 23:26 - 2015-09-30 23:26 - 00031976 _____ C:\WINDOWS\system32\nvinfo.pb
2015-09-30 23:26 - 2015-09-30 23:26 - 00031552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 00019976 _____ (ASUS) C:\WINDOWS\system32\Drivers\AsHIDSwitch64.sys
2015-09-30 23:01 - 2015-09-30 23:01 - 00000000 ___HD C:\$Windows.~WS
2015-09-30 21:54 - 2015-09-30 23:13 - 00000000 ____D C:\ESD
2015-09-30 21:45 - 2015-10-02 19:18 - 00000000 ____D C:\FRST
2015-09-30 21:24 - 2015-09-30 22:08 - 00000000 ____D C:\SUPERDelete
2015-09-17 23:23 - 2015-09-04 05:19 - 809386882 _____ C:\Users\kathr\Desktop\Render Library.7z
2015-09-10 00:08 - 2015-09-10 00:08 - 24594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 22324656 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 21874688 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 20857848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 19324416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 18806272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 16706560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 14241792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 13024768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 12589056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 12503552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 11557888 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 11262464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 09889792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 08613200 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 08019296 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 07569408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 07523328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 07051264 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 06878256 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 06488312 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 06305792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 06101504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 05118024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 05076480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 04791296 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 04760576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 04611584 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 04532304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 04398080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 04350464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 04169728 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 04048808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 03780096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 03687936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 03620736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 03586560 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 03579904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 03527168 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 03443200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 03362816 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 03248640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 03248128 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02880032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02748416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02741760 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02662400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02646528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02606080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02558976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02498808 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02462648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02446336 _____ C:\WINDOWS\system32\InputService.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02416640 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02415104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02350592 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02235904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02226688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02225664 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02207744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02178560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02153472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02151208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02147080 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02125312 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02116448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 02112512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02093056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01985024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01983840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01916928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01888768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01867160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01823232 _____ C:\WINDOWS\SysWOW64\InputService.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01822280 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01820672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01774592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01771592 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01714176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01679360 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01643872 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01612288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01602560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01601536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01593344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01591856 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01562968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01561872 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01533496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01521664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01420288 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01418240 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 01417216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01411072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01396064 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01382912 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 01380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01365072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01356368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01334784 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01294352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2015-09-10 00:08 - 2015-09-10 00:08 - 01294336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcnwiz.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01290752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01274880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01234944 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 01226752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wcnwiz.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01212416 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01203200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01203200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01201664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01200400 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01178112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01169408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01168736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 01162240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01135312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 01123400 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 01112064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01106432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01101792 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01087296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01067520 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01061888 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01043968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01043872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01031680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorDataService.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 01025840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01018568 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2015-09-10 00:08 - 2015-09-10 00:08 - 01008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00996352 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00993104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2015-09-10 00:08 - 2015-09-10 00:08 - 00966424 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00963920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00934752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refsv1.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 00925696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00918320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00902656 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00898560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00896144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00893440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00877016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00872448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00858408 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00856064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00850432 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00845664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00841728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00832512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00823336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00816576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfuimanager.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00808856 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00801632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00799232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpccpl.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00798208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00783872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00783112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00778752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00762896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00754688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfuimanager.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00750592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00713312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00705520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00700256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00695136 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 00680448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00679424 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00677888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00671232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00670208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00658568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00654848 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00644128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00642560 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00632168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00630160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00609592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00608936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00601344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 00599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00594472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00593920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efscore.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00586752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00584544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00583128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00569344 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00565088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 00563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00554744 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00542720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00541248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00527952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00521568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00521216 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00518144 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00516960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-09-10 00:08 - 2015-09-10 00:08 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00507696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00505696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 00505344 _____ C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00501008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00498016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMediaManager.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00487424 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00485888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00473088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00454000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00445240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00442208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00437248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00430592 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcomapi.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00425824 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00420352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00416256 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00413184 _____ C:\WINDOWS\system32\diagtrack_win.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00407616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00407040 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00404480 _____ C:\WINDOWS\system32\diagtrack_wininternal.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00393568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00384000 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00373248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00373072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2015-09-10 00:08 - 2015-09-10 00:08 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00366592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00356352 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00343040 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationGeofences.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00335360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00335248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00333168 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00328704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00325984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenter.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00303616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00293376 _____ C:\WINDOWS\system32\TextInputFramework.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00292856 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00291840 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemcpl.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00290312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00285632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00280576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\systemcpl.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncutil.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00265480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00263168 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActionCenter.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_UserAccount.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00252768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00251392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00247296 _____ C:\WINDOWS\system32\facecredentialprovider.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00243800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00243248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00242176 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00237392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdyboost.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 00235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicesFlowBroker.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\notepad.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\notepad.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00208736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\srumsvc.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\OmaDmAgent.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00200704 _____ C:\WINDOWS\SysWOW64\TextInputFramework.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00200528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModelShim.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00191488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReInfo.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.PicturePassword.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00181088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SignInOptions.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\coredpus.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00179200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srumsvc.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Privacy.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReInfo.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tunnel.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabSvc.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnApi.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPermissions.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkStatus.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWCN.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00116736 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeParserTask.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdWCN.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00102752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WcnApi.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00097128 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcd.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdWCN.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\spbcd.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00082616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcd.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00080720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthRadioMedia.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkInternalPS.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00077400 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\setbcdlocale.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spbcd.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.ProxyStub.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\unenrollhook.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00061280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.OneCore.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msiexec.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\hmkd.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.PAL.Desktop.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmprc.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00052264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wpcfltr.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnNetsh.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00046432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpiowin32.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 00046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmUcsi.sys
2015-09-10 00:08 - 2015-09-10 00:08 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hmkd.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tetheringclient.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\VoiceActivationManager.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VoiceActivationManager.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00032768 _____ C:\WINDOWS\system32\LicenseManagerApi.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\calc.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\calc.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 00008847 _____ C:\WINDOWS\system32\ResPriHMImageList
2015-09-10 00:20 - 2015-07-09 22:36 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorCustomAdbAlgorithm.dll
2015-09-10 00:20 - 2015-07-09 22:34 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PeerDist.dll
2015-09-10 00:20 - 2015-07-09 22:32 - 02533888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InkAnalysis.dll
2015-09-10 00:20 - 2015-07-09 22:31 - 01949696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsCpl.dll
2015-09-10 00:20 - 2015-07-09 22:29 - 00815104 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2015-09-10 00:20 - 2015-07-09 22:29 - 00577536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpprefcl.dll
2015-09-10 00:20 - 2015-07-09 22:29 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrptadm.dll
2015-09-10 00:20 - 2015-07-09 22:29 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SrpUxNativeSnapIn.dll
2015-09-10 00:20 - 2015-07-09 22:29 - 00295936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppIdPolicyEngineApi.dll
2015-09-10 00:20 - 2015-07-09 22:29 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuditNativeSnapIn.dll
2015-09-10 00:20 - 2015-07-09 22:29 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appmgmts.dll
2015-09-10 00:20 - 2015-07-09 22:29 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\auditpolmsg.dll
2015-09-10 00:20 - 2015-07-09 22:29 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuditPolicyGPInterop.dll
2015-09-10 00:20 - 2015-07-09 22:29 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpscript.dll
2015-09-10 00:20 - 2015-07-09 22:29 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpscript.exe
2015-09-10 00:20 - 2015-07-09 22:28 - 03793408 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2015-09-10 00:20 - 2015-07-09 22:27 - 00431104 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDistSh.dll
2015-09-10 00:20 - 2015-07-09 22:27 - 00276992 _____ (Microsoft Corporation) C:\WINDOWS\system32\umrdp.dll
2015-09-10 00:20 - 2015-07-09 22:27 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rfxvmt.dll
2015-09-10 00:20 - 2015-07-09 22:26 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SNTSearch.dll
2015-09-10 00:20 - 2015-07-09 22:25 - 00800256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mblctr.exe
2015-09-10 00:20 - 2015-07-09 22:25 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2015-09-10 00:20 - 2015-07-09 22:25 - 00274224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpendp.dll
2015-09-10 00:20 - 2015-07-09 22:25 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\tscfgwmi.dll
2015-09-10 00:20 - 2015-07-09 22:25 - 00029184 _____ (Microsoft Corporation) C:\WINDOWS\system32\qwinsta.exe
2015-09-10 00:20 - 2015-07-09 22:25 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\msg.exe
2015-09-10 00:20 - 2015-07-09 22:25 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\chgport.exe
2015-09-10 00:20 - 2015-07-09 22:25 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tscon.exe
2015-09-10 00:20 - 2015-07-09 22:25 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\change.exe
2015-09-10 00:20 - 2015-07-09 22:24 - 00183296 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpinput.exe
2015-09-10 00:20 - 2015-07-09 22:24 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2015-09-10 00:20 - 2015-07-09 22:24 - 00038752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\terminpt.sys
2015-09-10 00:20 - 2015-07-09 22:24 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\qprocess.exe
2015-09-10 00:20 - 2015-07-09 22:24 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpbus.sys
2015-09-10 00:20 - 2015-07-09 22:24 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\quser.exe
2015-09-10 00:20 - 2015-07-09 22:24 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\qappsrv.exe
2015-09-10 00:20 - 2015-07-09 22:24 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\tskill.exe
2015-09-10 00:20 - 2015-07-09 22:24 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsdiscon.exe
2015-09-10 00:20 - 2015-07-09 22:24 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\rwinsta.exe
2015-09-10 00:20 - 2015-07-09 22:24 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\logoff.exe
2015-09-10 00:20 - 2015-07-09 22:24 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\chgusr.exe
2015-09-10 00:20 - 2015-07-09 22:24 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\chglogon.exe
2015-09-10 00:20 - 2015-07-09 22:24 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\reset.exe
2015-09-10 00:20 - 2015-07-09 22:24 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\query.exe
2015-09-10 00:20 - 2015-07-09 22:23 - 00682496 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDistCacheProvider.dll
2015-09-10 00:20 - 2015-07-09 22:23 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\StikyNot.exe
2015-09-10 00:20 - 2015-07-09 22:23 - 00216064 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationSettings.exe
2015-09-10 00:20 - 2015-07-09 22:22 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\msTextPrediction.dll
2015-09-10 00:20 - 2015-07-09 22:22 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
2015-09-10 00:20 - 2015-07-09 22:22 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hwrcomp.exe
2015-09-10 00:20 - 2015-07-09 22:21 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\hwrreg.exe
2015-09-10 00:20 - 2015-07-09 22:21 - 00177152 _____ (Microsoft Corporation) C:\WINDOWS\system32\sensrsvc.dll
2015-09-10 00:20 - 2015-07-09 22:21 - 00141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsClassExtension.dll
2015-09-10 00:20 - 2015-07-09 22:20 - 01949696 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsCpl.dll
2015-09-10 00:20 - 2015-07-09 22:20 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorPerformanceEvents.dll
2015-09-10 00:20 - 2015-07-09 22:19 - 00785408 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscui.dll
2015-09-10 00:20 - 2015-07-09 22:19 - 00677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpprefcl.dll
2015-09-10 00:20 - 2015-07-09 22:19 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\AdmTmpl.dll
2015-09-10 00:20 - 2015-07-09 22:19 - 00561152 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrptadm.dll
2015-09-10 00:20 - 2015-07-09 22:19 - 00421376 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppIdPolicyEngineApi.dll
2015-09-10 00:20 - 2015-07-09 22:19 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuditPolicyGPInterop.dll
2015-09-10 00:20 - 2015-07-09 22:18 - 00314368 _____ (Microsoft Corporation) C:\WINDOWS\system32\SrpUxNativeSnapIn.dll
2015-09-10 00:20 - 2015-07-09 22:18 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuditNativeSnapIn.dll
2015-09-10 00:20 - 2015-07-09 22:18 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\appmgmts.dll
2015-09-10 00:20 - 2015-07-09 22:18 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\auditpolmsg.dll
2015-09-10 00:20 - 2015-07-09 22:18 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintBrmUi.exe
2015-09-10 00:20 - 2015-07-09 22:18 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpscript.dll
2015-09-10 00:20 - 2015-07-09 22:18 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpscript.exe
2015-09-10 00:20 - 2015-07-09 22:17 - 00306800 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpendp.dll
2015-09-10 00:20 - 2015-07-09 22:16 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\RotMgr.dll
2015-09-10 00:20 - 2015-07-09 22:15 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdechangepin.exe
2015-09-10 00:20 - 2015-07-09 22:15 - 00272384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddputils.dll
2015-09-10 00:20 - 2015-07-09 22:15 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddpchunk.dll
2015-09-10 00:20 - 2015-07-09 22:15 - 00138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddptrace.dll
2015-09-10 00:20 - 2015-07-09 22:15 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\baaupdate.exe
2015-09-10 00:20 - 2015-07-09 22:15 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerWizardElev.exe
2015-09-10 00:20 - 2015-07-09 22:15 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerWizard.exe
2015-09-10 00:20 - 2015-07-09 22:15 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddp_ps.dll
2015-09-10 00:20 - 2015-07-09 22:15 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\dfdts.dll
2015-09-10 00:20 - 2015-07-09 22:14 - 01359872 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmclient.dll
2015-09-10 00:20 - 2015-07-09 22:14 - 00658432 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmscan.dll
2015-09-10 00:20 - 2015-07-09 22:14 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeSysprep.dll
2015-09-10 00:20 - 2015-07-09 22:13 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\appmgr.dll
2015-09-10 00:20 - 2015-07-09 22:13 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmstormod.dll
2015-09-10 00:20 - 2015-07-09 22:13 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\srm.dll
2015-09-10 00:20 - 2015-07-09 22:13 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmshell.dll
2015-09-10 00:20 - 2015-07-09 22:13 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\adrclient.dll
2015-09-10 00:20 - 2015-07-09 22:13 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmtrace.dll
2015-09-10 00:20 - 2015-07-09 22:13 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\srm_ps.dll
2015-09-10 00:20 - 2015-07-09 22:13 - 00029536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpvideominiport.sys
2015-09-10 00:20 - 2015-07-09 22:06 - 00147439 _____ C:\WINDOWS\SysWOW64\gpedit.msc
2015-09-10 00:20 - 2015-07-09 22:06 - 00043566 _____ C:\WINDOWS\SysWOW64\rsop.msc
2015-09-10 00:20 - 2015-07-09 21:50 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srmlib.dll
2015-09-10 00:20 - 2015-07-09 21:33 - 00147439 _____ C:\WINDOWS\system32\gpedit.msc
2015-09-10 00:20 - 2015-07-09 21:33 - 00043566 _____ C:\WINDOWS\system32\rsop.msc
2015-09-10 00:20 - 2015-07-09 21:30 - 00120458 _____ C:\WINDOWS\system32\secpol.msc
2015-09-10 00:20 - 2015-07-09 21:19 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmlib.dll
2015-09-10 00:19 - 2015-07-09 22:29 - 00453120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AdmTmpl.dll
2015-09-10 00:19 - 2015-07-09 22:27 - 00214528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cscobj.dll
2015-09-10 00:19 - 2015-07-09 22:26 - 00544768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\csc.sys
2015-09-10 00:19 - 2015-07-09 22:24 - 01977856 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDistSvc.dll
2015-09-10 00:19 - 2015-07-09 22:24 - 00957440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srmclient.dll
2015-09-10 00:19 - 2015-07-09 22:24 - 00512512 _____ (Microsoft Corporation) C:\WINDOWS\system32\SnippingTool.exe
2015-09-10 00:19 - 2015-07-09 22:24 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srmscan.dll
2015-09-10 00:19 - 2015-07-09 22:24 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpdr.sys
2015-09-10 00:19 - 2015-07-09 22:23 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appmgr.dll
2015-09-10 00:19 - 2015-07-09 22:23 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDist.dll
2015-09-10 00:19 - 2015-07-09 22:23 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srmstormod.dll
2015-09-10 00:19 - 2015-07-09 22:23 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDistWSDDiscoProv.dll
2015-09-10 00:19 - 2015-07-09 22:23 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDistCleaner.dll
2015-09-10 00:19 - 2015-07-09 22:23 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srmtrace.dll
2015-09-10 00:19 - 2015-07-09 22:23 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDistHttpTrans.dll
2015-09-10 00:19 - 2015-07-09 22:23 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDistAD.dll
2015-09-10 00:19 - 2015-07-09 22:23 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srm_ps.dll
2015-09-10 00:19 - 2015-07-09 22:22 - 03603968 _____ (Microsoft Corporation) C:\WINDOWS\system32\InkAnalysis.dll
2015-09-10 00:19 - 2015-07-09 22:22 - 00279040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srm.dll
2015-09-10 00:19 - 2015-07-09 22:22 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srmshell.dll
2015-09-10 00:19 - 2015-07-09 22:22 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adrclient.dll
2015-09-10 00:19 - 2015-07-09 22:21 - 00833536 _____ (Microsoft Corporation) C:\WINDOWS\system32\pmcsnap.dll
2015-09-10 00:19 - 2015-07-09 22:18 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\ppcsnap.dll
2015-09-10 00:19 - 2015-07-09 22:18 - 00165888 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetpp.dll
2015-09-10 00:19 - 2015-07-09 22:18 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveprompt.exe
2015-09-10 00:19 - 2015-07-09 22:18 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetppui.dll
2015-09-10 00:19 - 2015-07-09 22:18 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnpinst.exe
2015-09-10 00:19 - 2015-07-09 22:17 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\system32\rfxvmt.dll
2015-09-10 00:19 - 2015-07-09 22:16 - 00733184 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscsvc.dll
2015-09-10 00:19 - 2015-07-09 22:16 - 00304128 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscobj.dll
2015-09-10 00:19 - 2015-07-09 22:15 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfg.exe
2015-09-10 00:19 - 2015-07-09 22:15 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfgLib.dll
2015-09-10 00:19 - 2015-07-09 22:15 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\DFDWiz.exe
2015-09-10 00:19 - 2015-07-09 22:15 - 00052576 _____ (Microsoft Corporation) C:\WINDOWS\system32\embeddedapplauncher.exe
2015-09-10 00:19 - 2015-07-09 22:15 - 00041312 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmbeddedAppLauncherConfig.dll
2015-09-10 00:19 - 2015-07-09 22:13 - 00147296 _____ (Microsoft Corporation) C:\WINDOWS\system32\CscMig.dll
2015-09-10 00:19 - 2015-07-09 21:28 - 00146389 _____ C:\WINDOWS\system32\printmanagement.msc
2015-09-10 00:08 - 2015-07-09 22:38 - 04847104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0009.dll
2015-09-10 00:08 - 2015-07-09 22:36 - 02629632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0009.dll
2015-09-10 00:08 - 2015-07-09 22:28 - 06358016 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0009.dll
2015-09-10 00:08 - 2015-07-09 22:25 - 05739520 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0009.dll
2015-09-10 00:08 - 2015-07-09 22:25 - 02629632 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0009.dll
2015-09-10 00:08 - 2015-07-09 22:21 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\jnwmon.dll
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-10-02 09:49
Ran by kathr (2015-10-02 19:18:52)
Running from C:\Users\kathr\Desktop
Windows 10 Pro (X64) (2015-10-02 15:02:37)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
DefaultAccount (S-1-5-21-4055827758-3256202687-3425098328-503 - Limited - Disabled)
Guest (S-1-5-21-4055827758-3256202687-3425098328-501 - Limited - Disabled)
kathr (S-1-5-21-4055827758-3256202687-3425098328-1001 - Administrator - Enabled) => C:\Users\kathr
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
Adobe Acrobat DC (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-0C0F074E4100}) (Version: 15.008.20082 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 3.3.0.151 - Adobe Systems Incorporated)
Adobe InDesign CC 2015 (HKLM-x32\...\{DBFD0312-6E55-1014-8952-E78D43BC0147}) (Version: 11.1.0.122 - Adobe Systems Incorporated)
Adobe Photoshop CC 2015 (HKLM-x32\...\{793C2BF7-A4FE-4608-91C9-9282C5801C21}) (Version: 16.0.1 - Adobe Systems Incorporated)
CameraHelperMsi (x32 Version: 13.51.815.0 - Logitech) Hidden
Chromodo (HKLM-x32\...\Chromodo) (Version: 44.5.7.268 - Comodo)
DAZ Install Manager (HKLM-x32\...\DAZ Install Manager 1.1.0.41) (Version: 1.1.0.41 - DAZ 3D)
ELAN Touchpad 11.5.19.2_X64_WHQL (HKLM\...\Elantech) (Version: 11.5.19.2 - ELAN Microelectronic Corp.)
erLT (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
FastPictureViewer Professional 1.9.348.0 (64-bit) (HKLM\...\{91486A00-EE17-4211-A270-E26113687892}) (Version: 1.9.348.0 - Axel Rietschin Software Developments)
GeekBuddy (HKLM\...\{A09AEC8C-5054-4E92-93DE-EA0B8C73BCF2}) (Version: 4.21.144 - Comodo Security Solutions Inc)
GlassWire 1.1 (remove only) (HKLM-x32\...\GlassWire 1.1) (Version: 1.1.27 - SecureMix LLC)
Google Chrome (HKU\S-1-5-21-4055827758-3256202687-3425098328-1001\...\Google Chrome) (Version: 45.0.2454.101 - Google Inc.)
herdProtect Anti-Malware Scanner (HKLM-x32\...\herdProtectScan) (Version: 1.0 - Reason Company Software Inc.)
Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.80 - Logitech Inc.)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Opera Stable 32.0.1948.44 (HKLM-x32\...\Opera 32.0.1948.44) (Version: 32.0.1948.44 - Opera Software)
Sandboxie 5.04 (64-bit) (HKLM\...\Sandboxie) (Version: 5.04 - Sandboxie Holdings, LLC)
Scrivener (HKLM-x32\...\Scrivener 1860) (Version: 1860 - Literature and Latte)
VirusTotal Uploader 2.2 (HKLM-x32\...\VTUploader) (Version: - )
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
CustomCLSID: HKU\S-1-5-21-4055827758-3256202687-3425098328-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\kathr\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-4055827758-3256202687-3425098328-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
CustomCLSID: HKU\S-1-5-21-4055827758-3256202687-3425098328-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\kathr\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll (Google Inc.)
Task: {345A834E-F2F0-4B7B-980D-EF4BB31E6B62} - System32\Tasks\Opera scheduled Autoupdate 1443800042 => C:\Program Files (x86)\Opera\launcher.exe [2015-09-17] (Opera Software)
Task: {36B12D98-0193-4F4D-B435-CB70C0EB4CD3} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4055827758-3256202687-3425098328-1001Core => C:\Users\kathr\AppData\Local\Google\Update\GoogleUpdate.exe [2015-10-02] (Google Inc.)
Task: {61E9F3CF-110D-4DF2-AB06-FAC5827C5C56} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-06-12] (Adobe Systems Incorporated)
Task: {6564E134-DBC3-4BE8-B474-27A248CB1ECB} - System32\Tasks\Microsoft\Windows\SetupSQMTask => C:\WINDOWS\SYSTEM32\OOBE\SETUPSQM.EXE [2015-07-09] (Microsoft Corporation)
Task: {976014CE-36C5-4BC5-8F3A-25BDA3B26981} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4055827758-3256202687-3425098328-1001UA => C:\Users\kathr\AppData\Local\Google\Update\GoogleUpdate.exe [2015-10-02] (Google Inc.)
Task: {AABF306E-EEBF-45C5-8911-7C12999A9E6C} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-08-26] (Microsoft Corporation)
Task: {BDDD28F9-991E-4BD9-BFDD-A188161677CD} - System32\Tasks\herdProtectScan => C:\Program Files\Reason\herdProtect\Scanner\herdProtectScan.exe [2014-12-18] (Reason Software Company Inc.)
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4055827758-3256202687-3425098328-1001UA.job => C:\Users\kathr\AppData\Local\Google\Update\GoogleUpdate.exe
2015-10-02 09:54 - 2015-07-13 12:37 - 00116552 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00404480 _____ () C:\WINDOWS\System32\diagtrack_wininternal.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02498808 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-08-13 14:34 - 2015-08-13 14:34 - 02875584 _____ () C:\Program Files\COMODO\GeekBuddy\QtCore4.dll
2015-08-13 14:34 - 2015-08-13 14:34 - 01283776 _____ () C:\Program Files\COMODO\GeekBuddy\QtNetwork4.dll
2015-08-13 14:34 - 2015-08-13 14:34 - 10451648 _____ () C:\Program Files\COMODO\GeekBuddy\QtGui4.dll
2015-08-13 14:34 - 2015-08-13 14:34 - 00039104 _____ () C:\Program Files\COMODO\GeekBuddy\imageformats\qgif4.dll
2015-08-13 14:34 - 2015-08-13 14:34 - 01529024 _____ () C:\Program Files\COMODO\GeekBuddy\QtScript4.dll
2012-09-13 00:38 - 2012-09-13 00:38 - 00264040 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
2012-09-13 00:38 - 2012-09-13 00:38 - 00165224 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\MotionDetection.exe
2015-09-10 00:08 - 2015-09-10 00:08 - 02498808 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-09-11 19:02 - 2015-09-11 19:02 - 00803488 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
2015-07-09 22:19 - 2015-07-09 22:19 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 06569472 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2015-07-09 22:13 - 2015-09-10 00:08 - 00471040 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 01808384 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 02274816 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-07-09 22:13 - 2015-09-10 00:08 - 00210432 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.ProxyStub.dll
2015-09-11 19:01 - 2015-09-11 19:01 - 31958688 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
2015-09-29 05:20 - 2015-09-29 05:20 - 00246272 _____ () C:\Program Files (x86)\GlassWire\GeoIP.dll
2012-09-13 00:38 - 2012-09-13 00:38 - 02144104 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtCore4.dll
2012-09-13 00:38 - 2012-09-13 00:38 - 07955304 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtGui4.dll
2012-09-13 00:38 - 2012-09-13 00:38 - 00341352 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtXml4.dll
2012-09-13 00:38 - 2012-09-13 00:38 - 00028008 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QGif4.dll
2012-09-13 00:38 - 2012-09-13 00:38 - 00127336 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QJpeg4.dll
2012-09-13 00:39 - 2012-09-13 00:39 - 00336232 _____ () C:\Program Files (x86)\Common Files\logishrd\LWSPlugins\LWS\Applets\CameraHelper\DevManagerCore.dll
2012-09-13 00:38 - 2012-09-13 00:38 - 00412008 _____ () C:\Program Files (x86)\Common Files\logishrd\LWSPlugins\LWS\Applets\MotionDetection\AVCapture.dll
2012-09-13 00:38 - 2012-09-13 00:38 - 00341864 _____ () C:\Program Files (x86)\Common Files\logishrd\LWSPlugins\LWS\Applets\MotionDetection\AVSrc.dll
2012-09-13 00:38 - 2012-09-13 00:38 - 00699752 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\avformat-52.dll
2012-09-13 00:38 - 2012-09-13 00:38 - 00084328 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\avutil-50.dll
2012-09-13 00:38 - 2012-09-13 00:38 - 01826664 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\avcodec-52.dll
2012-09-13 00:38 - 2012-09-13 00:38 - 00336232 _____ () C:\Program Files (x86)\Common Files\logishrd\LWSPlugins\LWS\Applets\MotionDetection\DevManagerCore.dll
2012-09-13 00:39 - 2012-09-13 00:39 - 00336232 _____ () C:\Program Files (x86)\Common Files\logishrd\LWSPlugins\LWS\Applets\PicturesAndVideos\DevManagerCore.dll
2012-09-13 00:39 - 2012-09-13 00:39 - 02084712 _____ () C:\Program Files (x86)\Common Files\logishrd\LWSPlugins\LWS\Applets\MotionDetection\videoC.dll
2012-09-13 00:38 - 2012-09-13 00:38 - 06712680 _____ () C:\Program Files (x86)\Common Files\logishrd\LWSPlugins\LWS\Applets\MotionDetection\LogiPerformanceRoutines.DLL
2015-09-15 08:08 - 2015-09-15 08:08 - 40523440 _____ () C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\libcef.dll
2015-09-15 08:08 - 2015-09-15 08:08 - 01365680 _____ () C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\libglesv2.dll
2015-09-15 08:08 - 2015-09-15 08:08 - 00219312 _____ () C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\libegl.dll
2015-09-11 16:39 - 2015-09-11 16:39 - 00124416 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\js\node_modules\fs-ext\build\Release\fs-ext.node
2015-09-11 16:39 - 2015-09-11 16:39 - 00121856 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\js\node_modules\node-imslib\node_modules\ref\build\Release\binding.node
2015-09-11 16:39 - 2015-09-11 16:39 - 00122880 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\js\node_modules\node-imslib\node_modules\ffi\build\Release\ffi_bindings.node
2015-09-11 16:39 - 2015-09-11 16:39 - 00188416 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\js\node_modules\node-vulcanjs\build\Release\VulcanJS.node
2015-09-11 16:39 - 2015-09-11 16:39 - 00085504 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\js\node_modules\ws\build\Release\bufferutil.node
2015-09-11 16:39 - 2015-09-11 16:39 - 00086016 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\js\node_modules\ws\build\Release\validation.node
2015-09-11 16:39 - 2015-09-11 16:39 - 00081408 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\js\node_modules\idle-gc\build\Release\idle-gc.node
AlternateDataStreams: C:\d956d726f5b732d32501:Win32App
AlternateDataStreams: C:\Users\kathr\Desktop\OBS_0_655b.zip:$CmdZnID
==================== EXE Association (Whitelisted) ===============
==================== Internet Explorer trusted/restricted ===============
==================== Other Areas ============================
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
MSCONFIG\Services: AxInstSV => 3
MSCONFIG\Services: BthHFSrv => 3
MSCONFIG\Services: bthserv => 3
MSCONFIG\Services: CertPropSvc => 3
MSCONFIG\Services: ChromodoUpdater => 2
MSCONFIG\Services: CLPSLauncher => 2
MSCONFIG\Services: dmwappushservice => 2
MSCONFIG\Services: Fax => 3
MSCONFIG\Services: FontCache => 2
MSCONFIG\Services: GeekBuddyRSP => 2
MSCONFIG\Services: HomeGroupListener => 3
MSCONFIG\Services: HomeGroupProvider => 3
MSCONFIG\Services: nvsvc => 2
MSCONFIG\Services: PrintNotify => 3
MSCONFIG\Services: RasAuto => 3
MSCONFIG\Services: RasMan => 3
MSCONFIG\Services: ScDeviceEnum => 3
MSCONFIG\Services: SessionEnv => 3
MSCONFIG\Services: TermService => 3
MSCONFIG\Services: UmRdpService => 3
MSCONFIG\Services: VaultSvc => 3
MSCONFIG\Services: vmicguestinterface => 3
MSCONFIG\Services: vmicrdv => 3
MSCONFIG\Services: vmicshutdown => 3
MSCONFIG\Services: WalletService => 3
MSCONFIG\Services: WbioSrvc => 3
MSCONFIG\Services: WinRM => 3
MSCONFIG\Services: WSearch => 2
MSCONFIG\Services: XblAuthManager => 3
MSCONFIG\Services: XblGameSave => 3
MSCONFIG\Services: XboxNetApiSvc => 3
HKLM\...\StartupApproved\StartupFolder: => "Start GeekBuddy.lnk"
HKLM\...\StartupApproved\Run32: => "tvncontrol"
HKU\S-1-5-21-4055827758-3256202687-3425098328-1001\...\StartupApproved\Run: => "Google Update"
HKU\S-1-5-21-4055827758-3256202687-3425098328-1001\...\StartupApproved\Run: => "OneDrive"
FirewallRules: [{354AE44B-35D4-4362-8763-5203BA22917F}] => (Allow) C:\Program Files (x86)\GlassWire\GWCtlSrv.exe
FirewallRules: [{BE81FEA5-9DB1-4812-9851-293758698903}] => (Block) c:\program files\comodo\geekbuddy\version_logging.exe
FirewallRules: [{3CB0BCEA-C6AD-456E-8ED6-4BFDC4D3162E}] => (Block) c:\program files\comodo\geekbuddy\version_logging.exe
FirewallRules: [{406B962E-1B34-464B-9E53-835B470FBDD2}] => (Block) c:\program files\comodo\geekbuddy\unit_manager.exe
FirewallRules: [{72B31B23-D910-4F20-8A41-D5A21CE80F0E}] => (Block) c:\program files\comodo\geekbuddy\unit_manager.exe
FirewallRules: [{CAD3E2CA-66DD-4462-A5B4-A8F0E398E010}] => (Block) c:\program files\comodo\geekbuddy\unit.exe
FirewallRules: [{740D67F7-D191-4869-816A-1A3ABDC0D922}] => (Block) c:\program files\comodo\geekbuddy\unit.exe
FirewallRules: [{1AB1727C-0178-4E05-99EF-8812D5958D92}] => (Block) c:\windows\explorer.exe
FirewallRules: [{E3E57F9A-7530-4773-B18D-0323A4AF71C2}] => (Block) c:\windows\explorer.exe
FirewallRules: [{ED0A1FB5-88E7-4CA7-9249-DEDBD84C0CE1}] => (Block) c:\users\kathr\appdata\local\microsoft\onedrive\onedrive.exe
FirewallRules: [{98842238-0EAB-4576-8DAE-B19AA821202F}] => (Block) c:\users\kathr\appdata\local\microsoft\onedrive\onedrive.exe
FirewallRules: [{8266BB68-6F9B-4C75-A4B6-399CC6BA2F89}] => (Block) c:\windows\system32\wermgr.exe
FirewallRules: [{26AA02F8-6727-454C-818F-3543FE437501}] => (Block) c:\windows\system32\wermgr.exe
FirewallRules: [{9E112340-E96D-43E4-B57E-D3EBA796BE28}] => (Block) c:\program files (x86)\common files\comodo\launcher_service.exe
FirewallRules: [{EFC9CB00-0A03-4789-986A-7CA914B819A8}] => (Block) c:\program files (x86)\common files\comodo\launcher_service.exe
FirewallRules: [{EB7DA36E-FB0E-4976-BFE3-FDD51AFD22FD}] => (Block) c:\program files\windows defender\mpcmdrun.exe
FirewallRules: [{7112B84E-4BA5-496E-B780-CE40F77D5946}] => (Block) c:\program files\windows defender\mpcmdrun.exe
FirewallRules: [{FAF484CC-AE7E-46BC-A45A-99E756C1308E}] => (Block) c:\program files (x86)\opera\32.0.1948.44\opera.exe
FirewallRules: [{6ACFAF0E-C54E-4D8F-AD5C-8342F9A26EA9}] => (Block) c:\program files (x86)\opera\32.0.1948.44\opera.exe
FirewallRules: [{5732F854-55C1-4CC8-94A3-71803B3BE0A0}] => (Block) c:\program files (x86)\opera\32.0.1948.44\opera_autoupdate.exe
FirewallRules: [{DD82AC3B-CD8E-4D0A-AA87-4800CCB0B54E}] => (Block) c:\program files (x86)\opera\32.0.1948.44\opera_autoupdate.exe
Description: ELAN Input Device
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: ELAN
Service: i8042prt
Problem: : This device cannot work properly until you restart your computer. (Code14)
Resolution: Restart your computer.
==================== Event log errors: =========================
==================
Error: (10/02/2015 07:06:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ExManBridgeTalkCmd.exe, version: 1.0.0.91, time stamp: 0x55a3f6b5
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x66302e25
Faulting process id: 0x1684
Faulting application start time: 0xExManBridgeTalkCmd.exe0
Faulting application path: ExManBridgeTalkCmd.exe1
Faulting module path: ExManBridgeTalkCmd.exe2
Report Id: ExManBridgeTalkCmd.exe3
Faulting package full name: ExManBridgeTalkCmd.exe4
Faulting package-relative application ID: ExManBridgeTalkCmd.exe5
Description: Faulting application name: herdProtectScan.exe, version: 1.0.3.9, time stamp: 0x549300f9
Faulting module name: LSASRV.dll, version: 10.0.10240.16392, time stamp: 0x55a868f9
Exception code: 0xc0000005
Fault offset: 0x000000000004e20e
Faulting process id: 0x1340
Faulting application start time: 0xherdProtectScan.exe0
Faulting application path: herdProtectScan.exe1
Faulting module path: herdProtectScan.exe2
Report Id: herdProtectScan.exe3
Faulting package full name: herdProtectScan.exe4
Faulting package-relative application ID: herdProtectScan.exe5
Description: Faulting application name: herdProtectScan.exe, version: 1.0.3.9, time stamp: 0x549300f9
Faulting module name: LSASRV.dll, version: 10.0.10240.16392, time stamp: 0x55a868f9
Exception code: 0xc0000005
Fault offset: 0x000000000004e20e
Faulting process id: 0x1340
Faulting application start time: 0xherdProtectScan.exe0
Faulting application path: herdProtectScan.exe1
Faulting module path: herdProtectScan.exe2
Report Id: herdProtectScan.exe3
Faulting package full name: herdProtectScan.exe4
Faulting package-relative application ID: herdProtectScan.exe5
Description: Faulting application name: herdProtectScan.exe, version: 1.0.3.9, time stamp: 0x549300f9
Faulting module name: LSASRV.dll, version: 10.0.10240.16392, time stamp: 0x55a868f9
Exception code: 0xc0000005
Fault offset: 0x000000000004e20e
Faulting process id: 0x1340
Faulting application start time: 0xherdProtectScan.exe0
Faulting application path: herdProtectScan.exe1
Faulting module path: herdProtectScan.exe2
Report Id: herdProtectScan.exe3
Faulting package full name: herdProtectScan.exe4
Faulting package-relative application ID: herdProtectScan.exe5
Description: Product: GeekBuddy -- Error 1704. An installation for COMODO Internet Security Pro is currently suspended. You must undo the changes made by that installation to continue. Do you want to undo those changes?
Description: Faulting application name: herdProtectScan.exe, version: 1.0.3.9, time stamp: 0x549300f9
Faulting module name: LSASRV.dll, version: 10.0.10240.16392, time stamp: 0x55a868f9
Exception code: 0xc0000005
Fault offset: 0x000000000004e20e
Faulting process id: 0x1340
Faulting application start time: 0xherdProtectScan.exe0
Faulting application path: herdProtectScan.exe1
Faulting module path: herdProtectScan.exe2
Report Id: herdProtectScan.exe3
Faulting package full name: herdProtectScan.exe4
Faulting package-relative application ID: herdProtectScan.exe5
Description: Faulting application name: rundll32.exe_shell32.dll, version: 10.0.10240.16384, time stamp: 0x559f39d6
Faulting module name: combase.dll, version: 10.0.10240.16384, time stamp: 0x559f3aac
Exception code: 0xc0000005
Fault offset: 0x00000000000bcf8d
Faulting process id: 0x1124
Faulting application start time: 0xrundll32.exe_shell32.dll0
Faulting application path: rundll32.exe_shell32.dll1
Faulting module path: rundll32.exe_shell32.dll2
Report Id: rundll32.exe_shell32.dll3
Faulting package full name: rundll32.exe_shell32.dll4
Faulting package-relative application ID: rundll32.exe_shell32.dll5
Description: SettingSyncHost (3860) Unable to create a new logfile because the database cannot write to the log drive. The drive may be read-only, out of disk space, misconfigured, or corrupted. Error -1032.
Description: SettingSyncHost (3860) An attempt to create the file "C:\WINDOWS\system32\edbtmp.log" failed with system error 5 (0x00000005): "Access is denied. ". The create file operation will fail with error -1032 (0xfffffbf8).
Description: SettingSyncHost (3860) Unable to create a new logfile because the database cannot write to the log drive. The drive may be read-only, out of disk space, misconfigured, or corrupted. Error -1032.
System errors:
=============
Error: (10/02/2015 03:02:27 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: 0x000000ef (0xffffe0004fafb080, 0x0000000000000000, 0x0000000000000000, 0x0000000000000000)C:\WINDOWS\MEMORY.DMP100215-39906-01
Description: The Print Spooler service failed to start due to the following error:
%%5
Description: The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
Description: The event logging service encountered an error (res=5) while initializing logging resources for channel Microsoft-Windows-NlaSvc/Operational.
Description: The event logging service encountered an error (res=5) while initializing logging resources for channel Setup.
Description: The event logging service encountered an error (res=5) while initializing logging resources for channel Microsoft-Windows-DeviceSetupManager/Admin.
Description: The event logging service encountered an error (res=5) while initializing logging resources for channel Microsoft-Windows-Kernel-PnP/Configuration.
Description: The event logging service encountered an error (res=5) while initializing logging resources for channel Microsoft-Windows-Windows Firewall With Advanced Security/ConnectionSecurity.
Description: The Windows Search service failed to start due to the following error:
%%5
Description: The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
CodeIntegrity:
===================================
Date: 2015-10-02 11:10:30.483
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume7\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe because the set of per-page image hashes could not be found on the system.
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume7\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Percentage of memory in use: 13%
Total physical RAM: 32685.47 MB
Available physical RAM: 28142.53 MB
Total Virtual: 37805.47 MB
Available Virtual: 33540.91 MB
Drive e: (Seagate) (Fixed) (Total:443.11 GB) (Free:423.77 GB) NTFS
Drive g: (Seagate BK) (Fixed) (Total:488.28 GB) (Free:485.19 GB) NTFS
Drive h: (BK) (Fixed) (Total:0.44 GB) (Free:0.41 GB) NTFS
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 00000000)
Disk: 1 (MBR Code: Windows XP) (Size: 698.6 GB) (Disk ID: 748798B0)
Edited by stormrider22, 02 October 2015 - 07:30 PM.