Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Possible Trojan files left, or hiding from antivirus.

Trojan virus hidden

  • Please log in to reply

#1
Nerdkid15

Nerdkid15

    New Member

  • Member
  • Pip
  • 7 posts

Hi!

I'm new here, and I apologize for any things that I did wrong.English Isn't my primary language, so I am sorry for grammar mistakes!

I managed to accidentally infect my laptop with some kind of trojan, and I am afraid that it is hiding from my antivirus, or left some files on my computer.

How do I make sure that it's completely gone???

Any help will be appreciated!

 

I've used these antiviruses to scan my PC:

OTL (Unfamiliar, and I didn't understand what it did)

ADWcleaner

JRT

RogueKiller

Spybot

SuperAntiSpyware

Malwarebytes

Avast

MBAR


  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,015 posts
  • MVP
 
 
  •  
 
  • Get FRST from
  • You need to download the appropriate tool for your PC.  If you don't know if you have a 32 or 64 bit system get them both.  Only one will work and that's the right one.
     
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer. 
  • Check the Addition.txt box
  • Press Scan button. 
  • It will produce a log called FRST.txt in the same directory the tool is run from.  
  • Please copy and paste log back here. 
  • It will generate another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply. 

    • 0

    #3
    Nerdkid15

    Nerdkid15

      New Member

    • Topic Starter
    • Member
    • Pip
    • 7 posts
    Logs are here:
     
    Addition.txt
     
    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-01-2017
    Ran by Unknown (15-01-2017 12:13:56)
    Running from C:\Users\Unknown\Desktop
    Windows 10 Pro Version 1607 (X64) (2017-01-01 12:28:41)
    Boot Mode: Normal
    ==========================================================
     
     
    ==================== Accounts: =============================
     
    Administrator (S-1-5-21-2893885579-1820529848-3781320564-500 - Administrator - Disabled)
    Unknown (S-1-5-21-2893885579-1820529848-3781320564-1001 - Administrator - Enabled) => C:\Users\Unknown
    DefaultAccount (S-1-5-21-2893885579-1820529848-3781320564-503 - Limited - Disabled)
    Guest (S-1-5-21-2893885579-1820529848-3781320564-501 - Limited - Disabled)
     
    ==================== Security Center ========================
     
    (If an entry is included in the fixlist, it will be removed.)
     
    AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AV: Avast Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
    AS: Spybot - Search and Destroy (Enabled - Up to date) {A16C3F68-9280-E053-1818-342707FECF4D}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Avast Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
     
    ==================== Installed Programs ======================
     
    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
     
    µTorrent (HKU\S-1-5-21-2893885579-1820529848-3781320564-1001\...\uTorrent) (Version: 3.4.9.43085 - BitTorrent Inc.)
    7-Zip 16.04 (HKLM-x32\...\7-Zip) (Version: 16.04 - Igor Pavlov)
    Ansel (Version: 376.33 - NVIDIA Corporation) Hidden
    Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 12.3.2280 - AVAST Software)
    BayHubTech Flash Memory Card Windows Driver (HKLM-x32\...\InstallShield_{357682C3-2295-45C5-B7DD-8109E66656EC}) (Version: 3.4.00.30 - BayHub Technology LTD.)
    BayHubTech Flash Memory Card Windows Driver (Version: 3.4.00.30 - BayHub Technology LTD.) Hidden
    BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.70.1080 - AB Team, d.o.o.)
    CCSDK Customer Engagement Service (HKLM-x32\...\{AE75190B-11B4-4F90-8254-DAB275CF2557}_is1) (Version: 1.3.0.3 - Lenovo)
    Connect2 (HKLM-x32\...\Connect2_is1) (Version: 4.1.1.3444 - Lenovo)
    Curse (HKLM-x32\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}) (Version: 6.0.0.0 - Curse)
    Dolby Audio X2 Windows API SDK (HKLM\...\{2A027A37-B09B-44FB-B1C9-2DD6BA0014E8}) (Version: 0.7.2.61 - Dolby Laboratories, Inc.)
    Garry's Mod (HKLM\...\Steam App 4000) (Version:  - Facepunch Studios)
    GlassWire 1.2 (remove only) (HKLM-x32\...\GlassWire 1.2) (Version: 1.2.88 - SecureMix LLC)
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 55.0.2883.87 - Google Inc.)
    Google Drive (HKLM-x32\...\{07A12123-B717-496B-B471-48AF6407B433}) (Version: 1.32.4066.7445 - Google, Inc.)
    Google Update Helper (x32 Version: 1.3.21.169 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
    Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios)
    Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4474 - Intel Corporation)
    Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.8.0.1042 - Intel Corporation)
    Intel® Wireless Bluetooth® (HKLM-x32\...\{3920BCB0-23AA-4D0D-93E5-404692DAF9D2}) (Version: 19.00.1621.3340 - Intel Corporation)
    Intel® PROSet/Wireless Software (HKLM-x32\...\{bc883058-299e-461f-8e52-4f1dbb355f86}) (Version: 19.0.1 - Intel Corporation)
    Intel® RealSense™ Depth Camera Manager Beta (x86): dptf_com (x32 Version: 2.2.0.52404 - Intel Corporation) Hidden
    Intel® RealSense™ Depth Camera Manager F200 (HKLM-x32\...\ARP_for_prd_dcm_runtime_1.4.27.52404) (Version: 1.4.27.52404 - Intel Corporation)
    Intel® RealSense™ Depth Camera Manager F200 Gold (x86): Intel® RealSense™ 3D camera IO module (x32 Version: 1.4.27.52404 - Intel Corporation) Hidden
    Intel® RealSense™ Depth Camera Manager F200 Gold (x86): Intel® RealSense™ Depth Camera Manager Service (x32 Version: 1.4.27.52404 - Intel Corporation) Hidden
    Java 8 Update 111 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180111F0}) (Version: 8.0.1110.14 - Oracle Corporation)
    Lenovo Photo Master (HKLM-x32\...\{BC94C56A-3649-420C-8756-2ADEBE399D33}) (Version: 2.1.5117.01 - CyberLink Corp.)
    Lenovo Service Bridge (HKU\S-1-5-21-2893885579-1820529848-3781320564-1001\...\dda9ca0b023f4c56) (Version: 1.6.5.0 - Lenovo)
    Lenovo System Interface Foundation (HKLM\...\{C2E5CA37-C862-4A69-AC6D-24F450A20C16}) (Version: 1.0.069.02 - Lenovo)
    Lenovo System Update (HKLM-x32\...\{25C64847-B900-48AD-A164-1B4F9B774650}) (Version: 5.07.0042 - Lenovo)
    LenovoUtility (HKLM-x32\...\InstallShield_{6ADA7E88-8D16-4D0D-BC90-2B93AC5E56DA}) (Version: 3.0.0.4 - Lenovo)
    LenovoUtility (x32 Version: 3.0.0.4 - Lenovo) Hidden
    Malwarebytes version 3.0.5.1299 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.5.1299 - Malwarebytes)
    Microsoft OneDrive (HKU\S-1-5-21-2893885579-1820529848-3781320564-1001\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23019 (HKLM-x32\...\{2883cce3-040d-45b1-a27a-07934a6d47ec}) (Version: 14.0.23019.0 - Microsoft Corporation)
    Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23019 (HKLM-x32\...\{5184c1f9-e1f4-47ff-82ee-92712c162393}) (Version: 14.0.23019.0 - Microsoft Corporation)
    Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
    NextUp-ScanSoft Daniel British Voice (HKLM-x32\...\{BE916006-E144-44CF-B467-F733D0F86200}) (Version: 4.0.0 - NextUp.com)
    NVIDIA 3D Vision Driver 376.33 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 376.33 - NVIDIA Corporation)
    NVIDIA GeForce Experience 3.2.0.96 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.2.0.96 - NVIDIA Corporation)
    NVIDIA Graphics Driver 376.33 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.33 - NVIDIA Corporation)
    NVIDIA PhysX System Software 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
    NvNodejs (Version: 3.2.0.96 - NVIDIA Corporation) Hidden
    NvTelemetry (Version: 2.0.0.0 - NVIDIA Corporation) Hidden
    OBS Studio (HKLM-x32\...\OBS Studio) (Version: 17.0.0 - OBS Project)
    Paladins (HKLM\...\Steam App 444090) (Version:  - Hi-Rez Studios)
    Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.9.422.2016 - Realtek)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7898 - Realtek Semiconductor Corp.)
    RogueKiller version 12.9.1.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.9.1.0 - Adlice Software)
    SafeZone Stable 1.51.2220.62 (x32 Version: 1.51.2220.62 - Avast Software) Hidden
    SHIELD Streaming (Version: 7.1.0350 - NVIDIA Corporation) Hidden
    SHIELD Wireless Controller Driver (Version: 3.2.0.96 - NVIDIA Corporation) Hidden
    Skype™ 7.31 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.31.104 - Skype Technologies S.A.)
    Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
    Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
    SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1232 - SUPERAntiSpyware.com)
    Thonny 2.0.7 (HKU\S-1-5-21-2893885579-1820529848-3781320564-1001\...\Thonny_is1) (Version: 2.0.7 - Aivar Annamaa)
    Unturned (HKLM\...\Steam App 304930) (Version:  - Smartly Dressed Games)
    Windows Driver Package - Lenovo (ACPIVPC) System  (09/24/2013 19.29.2.34) (HKLM\...\EE9B1F2037C580F36D92FA431CC02BFF04C31F15) (Version: 09/24/2013 19.29.2.34 - Lenovo)
    Windows Driver Package - Lenovo (WUDFRd) LenovoVhid  (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)
    Windscribe version 1.61 build 9 (HKLM-x32\...\{fa690e90-ddb0-4f0c-b3f1-136c084e5fc7}_is1) (Version: 1.61 build 9 - Windscribe)
    World of Tanks (HKU\S-1-5-21-2893885579-1820529848-3781320564-1001\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812eu}_is1) (Version:  - Wargaming.net)
    Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.)
     
    ==================== Custom CLSID (Whitelisted): ==========================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
     
    ==================== Scheduled Tasks (Whitelisted) =============
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
    Task: {03887DB1-C1CE-4CFB-A950-8F61B6922DAC} - System32\Tasks\SafeZone scheduled Autoupdate 1483214677 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-09-06] (Avast Software)
    Task: {050D6534-0E64-4A53-BB2D-0B9111BDFF47} - System32\Tasks\Lenovo\Lenovo Service Bridge\S-1-5-21-2893885579-1820529848-3781320564-1001 => Rundll32.exe dfshim.dll,ShOpenVerbShortcut C:\Users\Ander Eerits\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo\Lenovo Service Bridge.appref-ms
    Task: {0E969B43-89F0-4BC2-B68A-84756C9D5585} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 => C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2015-07-01] (Lenovo)
    Task: {14D07251-53E8-4D1D-9E04-E727816FEAC6} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask => reg.exe add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler  /v start /t reg_dword /d 1 /f /reg:32
    Task: {1588AB06-C6A3-4403-8CEF-6C4D96D1F6A8} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2016-03-21] (Safer-Networking Ltd.)
    Task: {1A842BC8-8706-4046-BFD8-E9BC2F3B7308} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2016-03-21] (Safer-Networking Ltd.)
    Task: {1D78ADE3-D599-48BB-A0A2-1A34CC7B6CB9} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2016-12-13] (NVIDIA Corporation)
    Task: {365CA361-F8FA-4000-B92E-6383C9C76E81} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2016-12-13] (NVIDIA Corporation)
    Task: {3F5FBF82-A899-41CD-A469-AC60F6FCA9C5} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [2016-12-10] ()
    Task: {49E8FAF0-C510-4DAD-B5CC-3E07FFD566A4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-12-31] (Google Inc.)
    Task: {4C29DDA6-DDAE-4B1A-BCED-EDB3CDC54736} - System32\Tasks\SUPERAntiSpyware Scheduled Task efc55b65-b0ec-4d02-94e9-b91b8d34cbc9 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com)
    Task: {783991EA-E9C9-46D1-8F0C-60F91F1D1701} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-12-31] (Google Inc.)
    Task: {89591549-313A-4312-A144-225AE7020041} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2016-12-13] (NVIDIA Corporation)
    Task: {92639620-E033-4978-8D3F-2879F2CA4365} - System32\Tasks\TVT\TVSUUpdateTask_UserLogOn => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [2016-12-10] ()
    Task: {9634866E-738D-48E6-A043-E20301830BAA} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\921250f6-22f2-4e3d-a3a5-7d83b759bdd2 => powershell.exe -nologo -noninteractive "& {New-Item -Path Registry::HKCU\Software\Lenovo\ImController\ScheduledTasks\921250f6-22f2-4e3d-a3a5-7d83b759bdd2 -type directory -force;$conter=Get-Date;$conter=$conter.ToUniversalTime();Set-ItemProperty -Path Registry::HKCU\Software\Lenovo\ImController\ScheduledTasks\9 (the data entry has 73 more characters).
    Task: {9E57C9BE-3183-4F72-B5A1-3A80BC196CCB} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2016-12-13] (NVIDIA Corporation)
    Task: {AC838EE6-46B9-415D-8D83-6C5466D0E826} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.)
    Task: {B2D0D272-D1F1-4E09-85C7-48B9F3E6AD90} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2016-12-13] (NVIDIA Corporation)
    Task: {B391F67E-06BE-4EC7-9357-E45EE2BAEDA3} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-12-31] (AVAST Software)
    Task: {B8F11FFC-3F4B-4888-89F1-5CF3E5783A51} - System32\Tasks\CyberLink\Photo Master Gadget startup => C:\Program Files (x86)\Lenovo\Lenovo Photo Master\PhotoMasterWorker.exe [2016-03-17] (CyberLink Corp.)
    Task: {BEB5CAD7-C2D9-45E1-9032-09C843C0F1A2} - System32\Tasks\SUPERAntiSpyware Scheduled Task e43691ac-19f2-4bf3-84c2-8da7e08639aa => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com)
    Task: {D425BAA0-A9A8-4430-92C3-B5EEE800181B} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => Sc.exe START ImControllerService
    Task: {E8ADC789-00D7-4B8C-B0F2-4B21520F123E} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2016-12-13] (NVIDIA Corporation)
     
    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
     
    Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
    Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task e43691ac-19f2-4bf3-84c2-8da7e08639aa.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe  C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task efc55b65-b0ec-4d02-94e9-b91b8d34cbc9.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe  C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
     
    ==================== Shortcuts =============================
     
    (The entries could be listed to be restored or removed.)
     
    ==================== Loaded Modules (Whitelisted) ==============
     
    2016-12-31 21:53 - 2016-12-13 01:30 - 04489152 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\Poco.dll
    2016-12-31 21:53 - 2016-12-13 01:30 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
    2017-01-08 21:27 - 2016-12-08 01:15 - 00053352 _____ () C:\Program Files (x86)\Windscribe\WindscribeService.exe
    2017-01-01 23:25 - 2016-12-14 12:55 - 02259232 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll
    2016-07-18 10:39 - 2016-07-18 10:39 - 00154816 _____ () C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe
    2017-01-10 23:14 - 2016-12-10 08:23 - 00023416 _____ () C:\Program Files (x86)\Lenovo\System Update\SUService.exe
    2016-07-16 13:42 - 2016-07-16 13:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
    2017-01-01 16:52 - 2016-12-09 12:29 - 02681200 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
    2017-01-01 14:24 - 2016-12-11 20:47 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
    2017-01-01 16:52 - 2016-12-09 12:29 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll
    2017-01-01 16:52 - 2016-12-09 12:29 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
    2017-01-01 16:51 - 2016-09-07 06:56 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
    2017-01-10 23:35 - 2016-12-21 09:09 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
    2017-01-10 23:35 - 2016-12-21 08:54 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
    2017-01-10 23:35 - 2016-12-21 08:48 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
    2017-01-10 23:35 - 2016-12-21 08:48 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
    2017-01-10 23:35 - 2016-12-21 08:48 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
    2017-01-10 23:35 - 2016-12-21 08:53 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
    2016-12-31 22:04 - 2016-12-31 22:05 - 00072192 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkypeHost.exe
    2016-12-31 22:04 - 2016-12-31 22:05 - 00179712 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
    2016-12-31 22:04 - 2016-12-31 22:05 - 42130432 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkyWrap.dll
    2016-12-31 22:04 - 2016-12-31 22:05 - 02216448 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\roottools.dll
    2017-01-10 23:31 - 2017-01-10 23:30 - 00791848 _____ () C:\Program Files\Lenovo\LenovoUtility\utility.exe
    2017-01-10 23:31 - 2017-01-10 23:30 - 00097048 _____ () C:\Program Files\Lenovo\LenovoUtility\kbdhook.dll
    2017-01-10 17:02 - 2017-01-10 17:02 - 13017280 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.7805.42277.0_x64__8wekyb3d8bbwe\Office.UI.Xaml.Core.dll
    2016-12-31 22:03 - 2016-12-31 22:03 - 00169064 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
    2016-12-31 22:03 - 2016-12-31 22:03 - 00482928 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
    2017-01-14 18:01 - 2017-01-14 18:01 - 04444072 _____ () C:\Program Files\AVAST Software\Avast\defs\17011400\algo.dll
    2017-01-10 01:11 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
    2017-01-10 01:11 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
    2017-01-10 01:11 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
    2017-01-10 01:11 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
    2017-01-10 01:11 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
    2016-12-31 21:53 - 2016-12-13 01:30 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
    2016-12-31 21:53 - 2016-12-13 01:30 - 03774400 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\Poco.dll
    2016-12-31 21:53 - 2016-12-13 01:30 - 00900032 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
    2016-12-31 21:54 - 2016-12-13 01:27 - 64245184 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll
    2017-01-01 01:43 - 2016-12-08 17:13 - 00656160 _____ () C:\Program Files (x86)\Steam\SDL2.dll
    2017-01-01 01:43 - 2016-09-01 03:02 - 04969248 _____ () C:\Program Files (x86)\Steam\v8.dll
    2017-01-01 01:43 - 2016-12-20 04:25 - 02322720 _____ () C:\Program Files (x86)\Steam\video.dll
    2017-01-01 01:43 - 2016-01-27 09:49 - 02549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
    2017-01-01 01:43 - 2016-01-27 09:49 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
    2017-01-01 01:43 - 2016-01-27 09:49 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
    2017-01-01 01:43 - 2016-01-27 09:49 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
    2017-01-01 01:43 - 2016-01-27 09:49 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
    2017-01-01 01:43 - 2016-09-01 03:02 - 01563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll
    2017-01-01 01:43 - 2016-09-01 03:02 - 01195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll
    2017-01-01 01:43 - 2016-12-20 04:25 - 00838944 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
    2017-01-01 01:43 - 2016-07-05 00:17 - 00266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll
    2016-12-31 21:53 - 2016-12-12 16:36 - 00525760 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSpCapsAPINode.node
    2016-12-31 21:53 - 2016-12-12 16:36 - 00254008 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\DriverInstall.node
    2016-12-31 21:53 - 2016-12-12 16:36 - 02808888 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\Downloader.node
    2016-12-31 21:53 - 2016-12-12 16:36 - 00384568 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGameShareAPINode.node
    2016-12-31 21:53 - 2016-12-12 16:36 - 00447424 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGalleryAPINode.node
    2016-12-31 21:53 - 2016-12-12 16:36 - 00336832 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVAccountAPINode.node
    2016-12-31 21:53 - 2016-12-12 16:36 - 01003456 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvCameraAPINode.node
    2016-12-31 21:53 - 2016-12-12 16:36 - 00956472 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSDKAPINode.node
    2017-01-01 01:43 - 2016-12-05 18:21 - 67304736 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll
    2017-01-01 01:43 - 2015-09-25 01:52 - 00119208 _____ () C:\Program Files (x86)\Steam\winh264.dll
    2017-01-15 12:09 - 2017-01-15 12:09 - 00098816 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\win32api.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00110080 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\pywintypes27.dll
    2017-01-15 12:09 - 2017-01-15 12:09 - 00364544 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\pythoncom27.dll
    2017-01-15 12:09 - 2017-01-15 12:09 - 00320512 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\win32com.shell.shell.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00914432 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\_hashlib.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 01176576 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\wx._core_.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00806400 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\wx._gdi_.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00816128 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\wx._windows_.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 01067008 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\wx._controls_.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00733184 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\wx._misc_.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00682496 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\pysqlite2._sqlite.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00088064 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\_ctypes.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00686080 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\unicodedata.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00119808 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\win32file.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00108544 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\win32security.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00007168 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\hashobjs_ext.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00017920 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\thumbnails_ext.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00088064 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\usb_ext.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00012800 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\common.time34.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00018432 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\win32event.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00167936 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\win32gui.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00046080 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\_socket.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 01303552 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\_ssl.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00128512 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\_elementtree.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00127488 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\pyexpat.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00038912 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\win32inet.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00036864 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\_psutil_windows.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00524248 ____R () C:\Users\UnknownAppData\Local\Temp\_MEI116442\windows._lib_cacheinvalidation.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00011264 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\win32crypt.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00123392 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\wx._wizard.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00077312 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\wx._html2.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00027648 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\_multiprocessing.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00020480 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\_yappi.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00035840 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\win32process.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00078848 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\wx._animate.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00024064 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\win32pipe.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00010240 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\select.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00025600 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\win32pdh.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00017408 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\win32profile.pyd
    2017-01-15 12:09 - 2017-01-15 12:09 - 00022528 ____R () C:\Users\Unknown\AppData\Local\Temp\_MEI116442\win32ts.pyd
    2017-01-02 02:18 - 2016-03-17 13:11 - 00884504 _____ () C:\Program Files (x86)\Lenovo\Lenovo Photo Master\subsys\Kernel\Boomerang\UNO.dll
    2017-01-02 02:18 - 2016-03-17 12:56 - 00081920 _____ () C:\Program Files (x86)\Lenovo\Lenovo Photo Master\koan\_ctypes.pyd
    2016-12-31 22:03 - 2016-12-31 22:03 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
    2016-12-31 22:04 - 2016-12-08 09:29 - 01829208 _____ () C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\libglesv2.dll
    2016-12-31 22:04 - 2016-12-08 09:29 - 00085848 _____ () C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\libegl.dll
     
    ==================== Alternate Data Streams (Whitelisted) =========
     
    (If an entry is included in the fixlist, only the ADS will be removed.)
     
     
    ==================== Safe Mode (Whitelisted) ===================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
     
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
     
    ==================== Association (Whitelisted) ===============
     
    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)
     
     
    ==================== Internet Explorer trusted/restricted ===============
     
    (If an entry is included in the fixlist, it will be removed from the registry.)
     
     
    ==================== Hosts content: ===============================
     
    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
     
    2015-07-10 13:04 - 2015-07-10 13:02 - 00000824 ____N C:\WINDOWS\system32\Drivers\etc\hosts
     
     
    ==================== Other Areas ============================
     
    (Currently there is no automatic fix for this section.)
     
    HKU\S-1-5-21-2893885579-1820529848-3781320564-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Ander Eerits\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img0.jpg
    DNS Servers: 192.168.1.254
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.
     
    ==================== MSCONFIG/TASK MANAGER disabled items ==
     
    HKLM\...\StartupApproved\Run: => "ZAM"
    HKLM\...\StartupApproved\Run32: => "SDTray"
    HKU\S-1-5-21-2893885579-1820529848-3781320564-1001\...\StartupApproved\StartupFolder: => "Curse.lnk"
    HKU\S-1-5-21-2893885579-1820529848-3781320564-1001\...\StartupApproved\Run: => "Windscribe"
    HKU\S-1-5-21-2893885579-1820529848-3781320564-1001\...\StartupApproved\Run: => "SUPERAntiSpyware"
    HKU\S-1-5-21-2893885579-1820529848-3781320564-1001\...\StartupApproved\Run: => "SpybotPostWindows10UpgradeReInstall"
     
    ==================== FirewallRules (Whitelisted) ===============
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
    FirewallRules: [vm-monitoring-nb-session] => LPort=139
    FirewallRules: [{8D82A10A-4910-4A53-8DF7-C0312CC0129D}] => C:\games\far cry 2 - fortunes edition\bin\fc2editor.exe
    FirewallRules: [{9705D20D-4013-4351-8881-D84139301196}] => C:\games\far cry 2 - fortunes edition\bin\fc2editor.exe
    FirewallRules: [UDP Query User{050FF320-EBE8-413D-91CB-C0702AB150CB}C:\games\far cry 2 - fortunes edition\bin\fc2editor.exe] => C:\games\far cry 2 - fortunes edition\bin\fc2editor.exe
    FirewallRules: [TCP Query User{0500FB5B-881E-4F0D-9261-4E40DFE8ACE4}C:\games\far cry 2 - fortunes edition\bin\fc2editor.exe] => C:\games\far cry 2 - fortunes edition\bin\fc2editor.exe
    FirewallRules: [{CC557455-F152-4964-8137-6DE3186E6159}] => C:\games\far cry 2 - fortunes edition\bin\farcry2.exe
    FirewallRules: [{7EE6E33B-6B6B-4E81-9DF8-167E03B82BF3}] => C:\games\far cry 2 - fortunes edition\bin\farcry2.exe
    FirewallRules: [UDP Query User{F6CFE152-53FC-4885-B3C8-8D0204BDE83F}C:\games\far cry 2 - fortunes edition\bin\farcry2.exe] => C:\games\far cry 2 - fortunes edition\bin\farcry2.exe
    FirewallRules: [TCP Query User{B0020CD5-6E6D-45E7-AD4A-A4A4D9D32087}C:\games\far cry 2 - fortunes edition\bin\farcry2.exe] => C:\games\far cry 2 - fortunes edition\bin\farcry2.exe
    FirewallRules: [{F36B0182-FB4B-4BE7-AA66-673CFF233A14}] => C:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe
    FirewallRules: [{D7326841-33F0-43AB-ACB8-7CAB4F84CC3E}] => C:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe
    FirewallRules: [{C659A7F1-E354-4D24-9725-95D3BF08E38C}] => C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
    FirewallRules: [{97F706F1-305C-416F-98CD-EA6ACD49C584}] => C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
    FirewallRules: [{EA21EC70-924E-4D5B-BCC3-A3719726E573}] => C:\Program Files (x86)\Steam\Steam.exe
    FirewallRules: [{E7AF569D-0713-40D6-987E-4FBDEC230059}] => C:\Program Files (x86)\Steam\Steam.exe
    FirewallRules: [{9876F2E6-626C-4D4F-B749-30BA43E84322}] => C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
    FirewallRules: [{C0B04969-9A4D-4CEE-9A38-F9C961201602}] => C:\Program Files (x86)\Lenovo\Connect2\Connect2.exe
    FirewallRules: [{5F374D80-A9FA-4E4D-95CE-D57850646FC2}] => C:\Program Files (x86)\Lenovo\Connect2\Connect2.exe
    FirewallRules: [{9A2AB5EB-95E1-462D-8853-55B357B4B739}] => C:\Program Files (x86)\Lenovo\Connect2\Connect2.exe
    FirewallRules: [{4B8732DA-D48C-48AC-AA4A-B42641BC9B97}] => C:\Games\World_of_Tanks\worldoftanks.exe
    FirewallRules: [{BF223FE9-5398-4124-962D-C41C5127F8BA}] => C:\Games\World_of_Tanks\worldoftanks.exe
    FirewallRules: [{57AD8AAE-438B-4DCB-A205-2E3B8C313834}] => C:\Games\World_of_Tanks\WoTLauncher.exe
    FirewallRules: [{353F0B40-D8DA-4666-8A78-CE41414702FF}] => C:\Games\World_of_Tanks\WoTLauncher.exe
    FirewallRules: [{D89D2BA7-B33A-4036-B1B4-3AF584184137}] => C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
    FirewallRules: [{9E929AC7-289F-4810-B7AA-7DE15FDA0176}] => C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
    FirewallRules: [UDP Query User{3862E663-A2C3-4711-9FA1-FAEB248A9C9A}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
    FirewallRules: [TCP Query User{D2E87166-4C2F-4ECB-A5C9-4A22AE04B0C2}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
    FirewallRules: [{6A2A4ECA-789D-44E6-AC30-FD9ECC10C8BC}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    FirewallRules: [{30562496-6048-44DE-B2DA-58F6A4FB3757}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
    FirewallRules: [{6AD49BA1-BDD3-4310-B15F-919788CCC32B}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
    FirewallRules: [{436D7E69-D178-4CBF-ACD6-BCA2545B8ED6}] => C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
    FirewallRules: [{FB4A5F6F-59A7-41DE-813D-E767C741B43C}] => C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe
    FirewallRules: [{64BE5531-5985-4DB0-80E9-6CC0D115C8D2}] => C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe
    FirewallRules: [{BD0CFB4A-DFDA-4777-AB28-63B4956E7A4B}] => C:\Program Files (x86)\GlassWire\GWCtlSrv.exe
    FirewallRules: [{271DFC26-4DC0-4129-9539-6EF20DF19216}] => C:\Program Files (x86)\GlassWire\GWCtlSrv.exe
    FirewallRules: [{3DD2C957-190C-4751-B24B-73C7019B5968}] => C:\Program Files (x86)\Skype\Phone\Skype.exe
    FirewallRules: [TCP Query User{7C1148BF-7696-4CA2-B4EA-D726C6DBBCDE}C:\users\Unknown\downloads\beamng.drive.v0.8.0.1\bin64\beamng.drive.x64.exe] => C:\users\Unknown\downloads\beamng.drive.v0.8.0.1\bin64\beamng.drive.x64.exe
    FirewallRules: [UDP Query User{99F9A1E9-86DB-4BBB-B8A6-E1CA697D5189}C:\users\Unknown\downloads\beamng.drive.v0.8.0.1\bin64\beamng.drive.x64.exe] => C:\users\Unknown\downloads\beamng.drive.v0.8.0.1\bin64\beamng.drive.x64.exe
    FirewallRules: [{D4A98867-61D7-4B62-BFE3-7F36097FDCAF}] => C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned_BE.exe
    FirewallRules: [{68437BA6-F8CA-4BB6-9BA9-65EED6E82E26}] => C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned_BE.exe
    FirewallRules: [{3EE76C00-04CF-4BFB-A5E9-35A20FAFC7C3}] => C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned.exe
    FirewallRules: [{84031C6A-445D-41A4-A05B-9C5206887312}] => C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned.exe
    FirewallRules: [{94268146-4608-4BCB-85CA-AF1C9504BB1D}] => C:\Program Files (x86)\Lenovo\Lenovo Photo Master\PhotoPlus.exe
    FirewallRules: [{24E72D57-586D-4EF0-93EB-AE64F720B29C}] => C:\Program Files (x86)\Lenovo\Lenovo Photo Master\subsys\AdvPhotoEditor\PhotoDirector5.exe
    FirewallRules: [{804E10EB-7224-4D94-8C60-578D55900A58}] => C:\Program Files (x86)\Steam\steamapps\common\Paladins\Binaries\Win32\HirezBridge.exe
    FirewallRules: [{5ABA31DB-72AB-480D-8571-6E665EF1F4E2}] => C:\Program Files (x86)\Steam\steamapps\common\Paladins\Binaries\Win32\HirezBridge.exe
    FirewallRules: [{37E65A80-76BC-4BE5-A892-50ABFB483737}] => C:\WINDOWS\system32\rundll32.exe
    FirewallRules: [{063DC591-CEAB-401B-AB90-6FA1DBA4AE0C}] => C:\Windows\System32\rundll32.exe
    FirewallRules: [{CF55FCF4-4F29-4457-A379-A541F52498C4}] => C:\Windows\System32\rundll32.exe
    FirewallRules: [TCP Query User{AC71DC23-F0D5-43AB-AE55-C964154C34CF}C:\users\Unknown\appdata\roaming\utorrent\utorrent.exe] => C:\users\Unknown\appdata\roaming\utorrent\utorrent.exe
    FirewallRules: [UDP Query User{23C77904-8F6A-4442-9F89-CEDDD7C11FE9}C:\users\Unknown\appdata\roaming\utorrent\utorrent.exe] => C:\users\Unknown\appdata\roaming\utorrent\utorrent.exe
    FirewallRules: [{B8F97583-646A-4DD5-8E6F-D3BB7959D201}] => C:\users\Unknown\appdata\roaming\utorrent\utorrent.exe
    FirewallRules: [{7DCC633B-D352-4610-B0B2-4B30980A9B33}] => C:\users\aUnknown\appdata\roaming\utorrent\utorrent.exe
    FirewallRules: [{C59E7F3D-8057-4741-AD61-E9F7E4509B9F}] => C:\Windows\System32\rundll32.exe
    FirewallRules: [{09D9E15A-A038-4DBF-9A4C-0DEC589DC66D}] => C:\Windows\System32\rundll32.exe
    FirewallRules: [TCP Query User{112918BA-1BB7-4E2D-99F9-DD1C9FFC7E6F}C:\users\Unknown\desktop\beamng.drive.v0.8.0.1\bin64\beamng.drive.x64.exe] => C:\users\Unknown\desktop\beamng.drive.v0.8.0.1\bin64\beamng.drive.x64.exe
    FirewallRules: [UDP Query User{CAA12C2A-DFE6-47ED-9179-1E663905CB3C}C:\users\Unknown\desktop\beamng.drive.v0.8.0.1\bin64\beamng.drive.x64.exe] => C:\users\Unknown\desktop\beamng.drive.v0.8.0.1\bin64\beamng.drive.x64.exe
    FirewallRules: [{17D1E2A4-74D4-4F35-8A75-AAB8FFDD2D5F}] => C:\Program Files (x86)\Lenovo\System Update\uncserver.exe
    FirewallRules: [{5FC21FCE-4BA7-4D76-8185-DB24000A1600}] => C:\Program Files (x86)\Lenovo\System Update\uncserver.exe
    FirewallRules: [TCP Query User{9E9BDED8-62CD-4950-B1A2-14C67A62C793}C:\users\Unknown\documents\curse\minecraft\install\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\Unknown\documents\curse\minecraft\install\runtime\jre-x64\1.8.0_25\bin\javaw.exe
    FirewallRules: [UDP Query User{D1D39A46-E091-4B4C-92C8-A88F633EC939}C:\users\Unknown\documents\curse\minecraft\install\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\Unknown\documents\curse\minecraft\install\runtime\jre-x64\1.8.0_25\bin\javaw.exe
    FirewallRules: [{C9567842-A058-4D1D-828C-3A987FE95AE1}] => C:\Program Files (x86)\Lenovo\Connect2\Connect2.exe
    FirewallRules: [{62F43F95-5147-498A-A7A5-861CFF4A4BBC}] => C:\Program Files (x86)\Lenovo\Connect2\Connect2.exe
    FirewallRules: [{0B858D44-29EF-48FB-8439-9577BF92FF8E}] => C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
    FirewallRules: [TCP Query User{056C97CA-FEDB-47BA-85F1-5585A2DD1B11}C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe] => C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe
    FirewallRules: [UDP Query User{36521BDC-6CD2-48A3-BD26-0E2122887806}C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe] => C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe
    StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
    StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
    StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
    StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service
     
    ==================== Restore Points =========================
     
    10-01-2017 01:51:01 JRT Pre-Junkware Removal
    12-01-2017 14:27:25 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
    12-01-2017 14:27:35 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030
    14-01-2017 12:16:37 ASU_MSI_TRAN
     
    ==================== Faulty Device Manager Devices =============
     
    Name: avast! SecureLine TAP Adapter v3
    Description: avast! SecureLine TAP Adapter v3
    Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
    Manufacturer: TAP-Windows Provider V9
    Service: aswTap
    Problem: : This device is disabled. (Code 22)
    Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
     
     
    ==================== Event log errors: =========================
     
    Application errors:
    ==================
    Error: (01/15/2017 12:09:38 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
    Description: License Activation (slui.exe) failed with the following error code:
    hr=0x803F7001
    Command-line arguments:
    RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=UserLogon;SessionId=6
     
    Error: (01/15/2017 12:09:25 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
    Description: License Activation (slui.exe) failed with the following error code:
    hr=0x8007139F
    Command-line arguments:
    RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=NetworkAvailable
     
    Error: (01/15/2017 12:05:51 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Tõrkuv rakendus: BeamNG.drive.x64.ui.exe, versioon: 1.0.0.0, ajatempel: 0x585ed4de
    Tõrkuva mooduli nimi: libcef.dll, versioon: 3.2454.1328.0, ajatempel 0x56134084
    Erandi kood 0x80000003
    Tõrke nihe 0x00000000001d91dd
    Tõrkuva protsessi ID 0x60
    Tõrkuva rakenduse käivitumisaeg: 0x01d26eb0e0ef3ed2
    Tõrkuva rakenduse tee: C:\games\BeamNG.drive.v0.8.0.1\Bin64\BeamNG.drive.x64.ui.exe
    Tõrkuva mooduli tee: C:\games\BeamNG.drive.v0.8.0.1\Bin64\libcef.dll
    Aruande ID: 6d0fe1f3-a69d-415e-91f4-1c6593167d2c
    Tõrkuva paketi täisnimi: 
    Tõrkuva paketiga seotud rakenduse ID:
     
    Error: (01/14/2017 09:32:12 PM) (Source: DAX2API) (EventID: 0) (User: )
    Description: Service cannot be started. The service process could not connect to the service controller
     
    Error: (01/14/2017 08:47:48 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Tõrkuv rakendus: BeamNG.drive.x64.ui.exe, versioon: 1.0.0.0, ajatempel: 0x585ed4de
    Tõrkuva mooduli nimi: libcef.dll, versioon: 3.2454.1328.0, ajatempel 0x56134084
    Erandi kood 0x80000003
    Tõrke nihe 0x00000000001d91dd
    Tõrkuva protsessi ID 0x1a0c
    Tõrkuva rakenduse käivitumisaeg: 0x01d26e8c3c358361
    Tõrkuva rakenduse tee: C:\games\BeamNG.drive.v0.8.0.1\Bin64\BeamNG.drive.x64.ui.exe
    Tõrkuva mooduli tee: C:\games\BeamNG.drive.v0.8.0.1\Bin64\libcef.dll
    Aruande ID: 9f7c74a9-708e-41e3-a3f8-7d9575d86884
    Tõrkuva paketi täisnimi: 
    Tõrkuva paketiga seotud rakenduse ID:
     
    Error: (01/14/2017 06:00:27 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
    Description: License Activation (slui.exe) failed with the following error code:
    hr=0x803F7001
    Command-line arguments:
    RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=UserLogon;SessionId=5
     
    Error: (01/14/2017 06:00:14 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
    Description: License Activation (slui.exe) failed with the following error code:
    hr=0x8007139F
    Command-line arguments:
    RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=NetworkAvailable
     
    Error: (01/14/2017 12:16:39 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
    Description: Krüptograafiateenusel nurjus süsteemikirjuti objekti OnIdentity() kutsungi töötlemine.
     
    Details:
    AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
     
    System Error:
    Access is denied.
    .
     
    Error: (01/14/2017 12:09:05 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
    Description: License Activation (slui.exe) failed with the following error code:
    hr=0x803F7001
    Command-line arguments:
    RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=UserLogon;SessionId=4
     
    Error: (01/14/2017 12:08:59 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
    Description: License Activation (slui.exe) failed with the following error code:
    hr=0x8007139F
    Command-line arguments:
    RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=NetworkAvailable
     
     
    System errors:
    =============
    Error: (01/15/2017 12:09:31 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
    {8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
     and APPID 
    {F72671A9-012C-4725-9D2F-2A4D32D65169}
     to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
     
    Error: (01/15/2017 12:05:55 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
    {D63B10C5-BB46-4990-A94F-E40B9D520160}
     and APPID 
    {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
     to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
     
    Error: (01/14/2017 09:55:06 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
    {D63B10C5-BB46-4990-A94F-E40B9D520160}
     and APPID 
    {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
     to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
     
    Error: (01/14/2017 06:00:25 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
    {8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
     and APPID 
    {F72671A9-012C-4725-9D2F-2A4D32D65169}
     to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
     
    Error: (01/14/2017 01:44:34 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
    {D63B10C5-BB46-4990-A94F-E40B9D520160}
     and APPID 
    {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
     to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
     
    Error: (01/14/2017 12:08:59 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
    {8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
     and APPID 
    {F72671A9-012C-4725-9D2F-2A4D32D65169}
     to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
     
    Error: (01/13/2017 11:50:54 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
    {D63B10C5-BB46-4990-A94F-E40B9D520160}
     and APPID 
    {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
     to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
     
    Error: (01/13/2017 02:15:45 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
    {D63B10C5-BB46-4990-A94F-E40B9D520160}
     and APPID 
    {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
     to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
     
    Error: (01/13/2017 12:42:49 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
    {D63B10C5-BB46-4990-A94F-E40B9D520160}
     and APPID 
    {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
     to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
     
    Error: (01/13/2017 12:06:25 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
    {D63B10C5-BB46-4990-A94F-E40B9D520160}
     and APPID 
    {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
     to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
     
     
    ==================== Memory info =========================== 
     
    Processor: Intel® Core™ i7-6700HQ CPU @ 2.60GHz
    Percentage of memory in use: 25%
    Total physical RAM: 16211.79 MB
    Available physical RAM: 12077.31 MB
    Total Virtual: 17235.79 MB
    Available Virtual: 12569.71 MB
     
    ==================== Drives ================================
     
    Drive c: () (Fixed) (Total:476.39 GB) (Free:346.95 GB) NTFS
     
    ==================== MBR & Partition Table ==================
     
    ========================================================
    Disk: 0 (Size: 476.9 GB) (Disk ID: D9FA2484)
     
    Partition: GPT.
     
    ==================== End of Addition.txt ============================
     
    and FRST
     

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-01-2017
    Ran by Unknown (administrator) on DESKTOP-unknown (15-01-2017 12:13:28)
    Running from C:\Users\Unknown\Desktop
    Loaded Profiles: Unknown (Available Profiles: Unknown)
    Platform: Windows 10 Pro Version 1607 (X64) Language: unknown (unknown)
    Internet Explorer Version 11 (Default browser: Chrome)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
     
    ==================== Processes (Whitelisted) =================
     
    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
     
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
    (Intel Corporation) C:\Windows\System32\igfxCUIService.exe
    (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    (Microsoft Corporation) C:\Windows\System32\wlanext.exe
    (Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
    (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
    (Intel Corporation) C:\Windows\System32\ibtsiva.exe
    (Lenovo) C:\Program Files (x86)\Lenovo\Connect2\Connect2.Service.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
    () C:\Program Files (x86)\Windscribe\WindscribeService.exe
    (Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
    (Intel® Corporation) C:\Program Files (x86)\Common Files\Intel\RSDCM\bin\win32\RealSenseDCM.exe
    (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    (Lenovo Group Limited) C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
    (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    (SecureMix LLC) C:\Program Files (x86)\GlassWire\GWCtlSrv.exe
    (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
    (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
    () C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe
    (Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
    () C:\Program Files (x86)\Lenovo\System Update\SUService.exe
    (Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    (Intel Corporation) C:\Windows\System32\igfxEM.exe
    (Lenovo Group Limited) C:\Program Files (x86)\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.LenovoCorporation.LenovoSettings_4642shxvsv8s2.exe
    (Intel Corporation) C:\Windows\System32\igfxHK.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkypeHost.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
    (Microsoft Corporation) C:\Windows\System32\smartscreen.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
    () C:\Program Files\Lenovo\LenovoUtility\utility.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe
    (Wargaming.net) C:\games\World_of_Tanks\WargamingGameUpdater.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
    (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
    (Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
    (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
    (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
    (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
    (SecureMix LLC) C:\Program Files (x86)\GlassWire\GlassWire.exe
    (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.7805.42277.0_x64__8wekyb3d8bbwe\HxMail.exe
    (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.7805.42277.0_x64__8wekyb3d8bbwe\HxTsr.exe
    (Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
    (Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
    (CyberLink Corp.) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\PhotoMasterImportAgent.exe
    (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
    (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (SecureMix LLC) C:\Program Files (x86)\GlassWire\GWIdlMon.exe
    (Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
    (Lenovo) C:\Users\Unknown\AppData\Local\Apps\2.0\YJ8VY0Q6.9RN\6B5BAJBT.1HP\lsb...tion_2d7b41b05b24775e_0001.0006_49d2acb6f7b8d10a\LSB.exe
    (Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
    (Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
    (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
     
    ==================== Registry (Whitelisted) ====================
     
    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
     
    HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16686600 2016-12-31] (Realtek Semiconductor)
    HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1460744 2016-12-31] (Realtek Semiconductor)
    HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1460744 2016-12-31] (Realtek Semiconductor)
    HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1460744 2016-12-31] (Realtek Semiconductor)
    HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
    HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [323056 2015-11-04] (Intel Corporation)
    HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2776528 2016-12-14] (Malwarebytes)
    HKLM\...\Run: [LenovoUtility] => C:\Program Files\Lenovo\LenovoUtility\utility.exe [791848 2017-01-10] ()
    HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9080768 2016-12-31] (AVAST Software)
    HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation)
    Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
    HKU\S-1-5-21-2893885579-1820529848-3781320564-1001\...\Run: [World of Tanks] => C:\Games\World_of_Tanks\WargamingGameUpdater.exe [3135752 2016-11-18] (Wargaming.net)
    HKU\S-1-5-21-2893885579-1820529848-3781320564-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2876704 2016-12-20] (Valve Corporation)
    HKU\S-1-5-21-2893885579-1820529848-3781320564-1001\...\Run: [GlassWire] => C:\Program Files (x86)\GlassWire\glasswire.exe [5788112 2016-12-26] (SecureMix LLC)
    HKU\S-1-5-21-2893885579-1820529848-3781320564-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23818360 2016-11-30] (Google)
    HKU\S-1-5-21-2893885579-1820529848-3781320564-1001\...\Run: [PhotoMasterImportAgent] => C:\Program Files (x86)\Lenovo\Lenovo Photo Master\PhotoMasterImportAgent.exe [675608 2016-03-17] (CyberLink Corp.)
    HKU\S-1-5-21-2893885579-1820529848-3781320564-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7943072 2017-01-05] (SUPERAntiSpyware)
    HKU\S-1-5-21-2893885579-1820529848-3781320564-1001\...\Run: [Windscribe] => C:\Program Files (x86)\Windscribe\Windscribe.exe [7948392 2016-12-08] ()
    HKU\S-1-5-21-2893885579-1820529848-3781320564-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
    HKU\S-1-5-21-2893885579-1820529848-3781320564-1001\...\MountPoints2: {45e40658-c0c5-11e6-9bc1-806e6f6e6963} - "D:\setup.exe" 
    ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
    ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
    ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
    ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-12-31] (AVAST Software)
    Startup: C:\Users\Unknown\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Curse.lnk [2017-01-11]
    ShortcutTarget: Curse.lnk -> C:\Users\Unknown\AppData\Roaming\Curse Client\Bin\Curse.exe (Curse, Inc)
    BootExecute: autocheck autochk * sdnclean64.exe
     
    ==================== Internet (Whitelisted) ====================
     
    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
     
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
    Tcpip\..\Interfaces\{077e3ed3-bfea-418c-8c8c-4a4f02ae6047}: [DhcpNameServer] 192.168.1.254
    Tcpip\..\Interfaces\{fb728054-4160-4ffc-8048-a45a0693ba0d}: [NameServer] 77.234.40.79
     
    Internet Explorer:
    ==================
    BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2017-01-11] (Oracle Corporation)
    BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2017-01-11] (Oracle Corporation)
     
    FireFox:
    ========
    FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
    FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2017-01-08]
    FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
    FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2017-01-08]
    FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
    FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
    FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2017-01-11] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2017-01-11] (Oracle Corporation)
    FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-12-11] (NVIDIA Corporation)
    FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-12-11] (NVIDIA Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-31] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-31] (Google Inc.)
     
    Chrome: 
    =======
    CHR HomePage: Default -> hxxps://www.google.ee/?gws_rd=cr,ssl&ei=9viCVOnKCcT1UIMS
    CHR Profile: C:\Users\Unknown\AppData\Local\Google\Chrome\User Data\Default [2017-01-15]
    CHR Extension: (Google'i esitlused) - C:\Users\Unknown\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-12-31]
    CHR Extension: (Google'i dokumendid) - C:\Users\Unknown\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-12-31]
    CHR Extension: (Google Drive) - C:\Users\Unknown\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-12-31]
    CHR Extension: (YouTube) - C:\Users\Unknown\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-31]
    CHR Extension: (Avast SafePrice) - C:\Users\Unknown\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-01-01]
    CHR Extension: (Google'i arvutustabelid) - C:\Users\Unknown\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-12-31]
    CHR Extension: (Võrguühenduseta Google’i dokumendid) - C:\Users\Unknown\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-31]
    CHR Extension: (AdBlock) - C:\Users\Unknown\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-12-31]
    CHR Extension: (Avast Online Security) - C:\Users\Unknown\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-12-31]
    CHR Extension: (Grammarly for Chrome) - C:\Users\Unknown\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2017-01-14]
    CHR Extension: (Chrome'i veebipoe maksed) - C:\Users\Unknown\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-12-31]
    CHR Extension: (Gmail) - C:\Users\Unknown\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-12-31]
    CHR Extension: (Chrome Media Router) - C:\Users\Unknown\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-31]
    CHR HKU\S-1-5-21-2893885579-1820529848-3781320564-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
     
    ==================== Services (Whitelisted) ====================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
    R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com)
    R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-12-31] (AVAST Software)
    S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1447944 2017-01-02] ()
    S4 CCSDK; C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe [666608 2016-03-22] (Lenovo)
    R2 connect2hotspot; C:\Program Files (x86)\Lenovo\Connect2\Connect2.Service.exe [100680 2016-11-29] (Lenovo)
    S3 cplspcon; C:\WINDOWS\system32\IntelCpHDCPSvc.exe [448496 2016-12-31] (Intel Corporation)
    R2 DAX2API; C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe [154816 2016-07-18] ()
    S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [395536 2017-01-02] (EasyAntiCheat Ltd)
    R2 GlassWire; C:\Program Files (x86)\GlassWire\GWCtlSrv.exe [4393936 2016-12-26] (SecureMix LLC)
    U2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2016-12-09] (Hi-Rez Studios) [File not signed]
    R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [19440 2015-11-04] (Intel Corporation)
    R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373744 2016-12-31] (Intel Corporation)
    R2 ImControllerService; C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [62792 2016-12-01] (Lenovo Group Limited)
    R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4317648 2016-12-14] (Malwarebytes)
    S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268704 2016-05-03] ()
    R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-13] (NVIDIA Corporation)
    S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-13] (NVIDIA Corporation)
    R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [459832 2016-12-11] (NVIDIA Corporation)
    R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2016-12-13] (NVIDIA Corporation)
    R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [425408 2016-12-13] (NVIDIA Corporation)
    R2 RealSenseDCM; C:\Program Files (x86)\Common Files\Intel\RSDCM\bin\win32\RealSenseDCM.exe [3663512 2015-10-15] (Intel® Corporation)
    R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
    R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [4088608 2016-09-21] (Safer-Networking Ltd.)
    R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [235984 2016-11-24] (Safer-Networking Ltd.)
    S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-09-15] (Microsoft Corporation)
    R3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [23416 2016-12-10] ()
    R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [255608 2016-12-31] (Synaptics Incorporated)
    S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
    S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
    R2 WindscribeService; C:\Program Files (x86)\Windscribe\WindscribeService.exe [53352 2016-12-08] ()
    R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3732896 2016-05-03] (Intel® Corporation)
    R2 ibtsiva; %SystemRoot%\system32\ibtsiva [X]
    S2 ZAMSvc; "C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe" /service [X]
     
    ===================== Drivers (Whitelisted) ======================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
    S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [37656 2016-12-31] (AVAST Software)
    R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [37144 2016-12-31] (AVAST Software)
    R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [108816 2016-12-31] (AVAST Software)
    R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [103064 2016-12-31] (AVAST Software)
    R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-12-31] (AVAST Software)
    R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [969184 2016-12-31] (AVAST Software)
    R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [513632 2016-12-31] (AVAST Software)
    R2 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [163416 2016-12-31] (AVAST Software)
    S3 aswTap; C:\WINDOWS\System32\drivers\aswTap.sys [44640 2016-12-31] (The OpenVPN Project)
    R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-12-31] (AVAST Software)
    R3 BHTPCRDR; C:\WINDOWS\System32\drivers\bhtpcrdr.sys [173432 2016-08-11] (BayHubTech/O2Micro )
    S3 dot4; C:\WINDOWS\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows ® Win 7 DDK provider)
    S3 Dot4Print; C:\WINDOWS\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows ® Win 7 DDK provider)
    R1 gwdrv; C:\WINDOWS\system32\DRIVERS\gwdrv.sys [33152 2015-05-29] (SecureMix LLC)
    R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [250624 2016-12-31] (Intel Corporation)
    R3 IntelDFUACPI; C:\WINDOWS\System32\drivers\IntelDFUACPI.sys [37888 2016-12-31] (Intel® Corporation)
    R3 IXCamera; C:\WINDOWS\system32\DRIVERS\RealSenseDCM.sys [72704 2015-10-15] (Intel® Corporation)
    R0 MBAMSwissArmy; C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [250816 2017-01-11] (Malwarebytes)
    S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
    R3 Netwtw04; C:\WINDOWS\System32\drivers\Netwtw04.sys [7231248 2016-06-17] (Intel Corporation)
    R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_03205ffa8fdea79d\nvlddmkm.sys [14200880 2016-12-12] (NVIDIA Corporation)
    S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-12-13] (NVIDIA Corporation)
    R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [46016 2016-12-13] (NVIDIA Corporation)
    R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [937728 2016-05-17] (Realtek                                            )
    R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [51320 2016-12-31] (Synaptics Incorporated)
    S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
    S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
    S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
    R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [203680 2017-01-08] (Zemana Ltd.)
    S1 ZAM; \??\C:\WINDOWS\System32\drivers\zam64.sys [X]
     
    ==================== NetSvcs (Whitelisted) ===================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
     
    ==================== One Month Created files and folders ========
     
    (If an entry is included in the fixlist, the file/folder will be moved.)
     
    2017-01-15 12:13 - 2017-01-15 12:13 - 00023993 _____ C:\Users\Unknown\Desktop\FRST.txt
    2017-01-15 12:13 - 2017-01-15 12:13 - 00000000 ____D C:\FRST
    2017-01-15 12:12 - 2017-01-15 12:13 - 02419200 _____ (Farbar) C:\Users\Unknown\Desktop\FRST64.exe
    2017-01-15 12:12 - 2017-01-15 12:12 - 02419200 _____ (Farbar) C:\Users\Unknown\Downloads\FRST64.exe
    2017-01-15 12:09 - 2017-01-15 12:09 - 00000000 ___HD C:\OneDriveTemp
    2017-01-14 21:50 - 2017-01-14 21:50 - 00000560 _____ C:\Users\Unknown\Documents\Geekstogo.com post.txt
    2017-01-14 21:45 - 2017-01-14 21:56 - 00118684 _____ C:\Users\Unknown\Downloads\Extras.Txt
    2017-01-14 21:44 - 2017-01-14 21:56 - 03667634 _____ C:\Users\Unknown\Downloads\OTL.Txt
    2017-01-14 21:36 - 2017-01-14 21:36 - 00602112 _____ (OldTimer Tools) C:\Users\Unknown\Downloads\OTL.exe
    2017-01-13 21:09 - 2017-01-13 21:10 - 160497952 _____ (Advanced Micro Devices, Inc.) C:\Users\Unknown\Downloads\13-9-legacy_vista_win7_64_dd_ccc_whql.exe
    2017-01-13 15:13 - 2017-01-13 15:13 - 47683808 _____ (Microsoft Corporation) C:\Users\Unknown\Downloads\Windows-KB890830-x64-V5.44.exe
    2017-01-13 15:13 - 2017-01-13 15:13 - 47683808 _____ (Microsoft Corporation) C:\Users\Unknown\Desktop\Windows-KB890830-x64-V5.44.exe
    2017-01-12 21:15 - 2017-01-12 21:15 - 00001140 _____ C:\Users\Unknown\Desktop\balabolka.exe otsetee.lnk
    2017-01-12 21:14 - 2017-01-12 21:14 - 00001389 _____ C:\Users\Unknown\Desktop\Slender - The Arrival.exe otsetee.lnk
    2017-01-12 21:12 - 2017-01-13 14:13 - 00000000 ____D C:\Users\Unknown\Desktop\Kula kula
    2017-01-12 21:11 - 2017-01-12 21:12 - 00000000 ___RD C:\Users\Unknown\Desktop\Otseteed
    2017-01-12 21:09 - 2017-01-12 21:12 - 00000000 ____D C:\Users\Unknown\Desktop\In case of emerygency, open!
    2017-01-12 19:38 - 2017-01-12 19:38 - 00000917 _____ C:\Users\Unknown\Documents\Xd.txt
    2017-01-12 18:46 - 2017-01-12 18:51 - 00000535 _____ C:\Users\Unknown\Desktop\Found Viruses.txt
    2017-01-12 17:25 - 2017-01-12 17:31 - 00000000 ____D C:\Users\Unknown\AppData\Roaming\BSplayer
    2017-01-12 17:25 - 2017-01-12 17:25 - 00001205 _____ C:\ProgramData\Microsoft\Windows\Start Menu\BS.Player FREE.lnk
    2017-01-12 17:25 - 2017-01-12 17:25 - 00000000 ____D C:\Users\UnknownAppData\Roaming\BSplayer Pro
    2017-01-12 17:25 - 2017-01-12 17:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BS.Player
    2017-01-12 17:25 - 2017-01-12 17:25 - 00000000 ____D C:\Program Files (x86)\Webteh
    2017-01-12 17:24 - 2017-01-12 17:25 - 10550048 _____ C:\Users\Unknown\Downloads\bsplayer270.setup.exe
    2017-01-12 14:53 - 2017-01-12 14:53 - 00001295 _____ C:\Users\Unknown\Downloads\autohaven.jnlp
    2017-01-12 14:53 - 2017-01-12 14:53 - 00001295 _____ C:\Users\Unknown\Desktop\autohaven.jnlp
    2017-01-12 14:53 - 2017-01-12 14:53 - 00000000 ____D C:\Users\Unknown\AppData\Roaming\Haven and Hearth
    2017-01-12 14:29 - 2017-01-12 14:29 - 00558328 _____ C:\WINDOWS\system32\Drivers\EasyAntiCheat.sys
    2017-01-12 14:27 - 2017-01-12 14:27 - 00000000 ____D C:\Users\Unknown\AppData\Local\HirezLauncherUI
    2017-01-12 14:27 - 2017-01-02 02:34 - 00395536 _____ (EasyAntiCheat Ltd) C:\WINDOWS\SysWOW64\EasyAntiCheat.exe
    2017-01-12 00:02 - 2017-01-12 00:30 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
    2017-01-12 00:01 - 2017-01-12 00:01 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
    2017-01-12 00:00 - 2017-01-12 00:01 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Unknown\Downloads\mbar-1.09.3.1001.exe
    2017-01-11 21:26 - 2017-01-11 21:26 - 00000000 ____D C:\Users\Unknown\Documents\Curse
    2017-01-11 21:21 - 2017-01-11 21:21 - 00001102 _____ C:\Users\Unknown\Desktop\Curse.lnk
    2017-01-11 21:21 - 2017-01-11 21:21 - 00001088 _____ C:\Users\Unknown\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Curse.lnk
    2017-01-11 21:20 - 2017-01-12 17:25 - 00000000 ____D C:\Users\Unknown\AppData\Roaming\Curse Client
    2017-01-11 21:20 - 2017-01-11 21:20 - 00000000 ____D C:\Users\Unknown\AppData\Roaming\Curse
    2017-01-11 21:19 - 2017-01-11 21:20 - 83699400 _____ (Curse) C:\Users\Unknown\Downloads\CurseClientSetup_[plugin-Minecraft].exe
    2017-01-11 21:04 - 2017-01-11 21:04 - 00168721 _____ C:\Users\Unknown\Downloads\Chocapic13 V6 Medium.zip
    2017-01-11 20:59 - 2017-01-11 20:59 - 00196835 _____ C:\Users\Unknown\Downloads\Chocapic13 V6 Extreme.zip
    2017-01-11 20:54 - 2017-01-11 20:54 - 01730602 _____ C:\Users\Unknown\Downloads\OptiFine_1.10_HD_U_B6.jar
    2017-01-11 20:44 - 2017-01-11 20:44 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
    2017-01-11 20:44 - 2017-01-11 20:44 - 00000000 ____D C:\Program Files (x86)\Java
    2017-01-11 20:38 - 2017-01-11 20:39 - 00737344 _____ (Oracle Corporation) C:\Users\Unknown\Downloads\JavaSetup8u111.exe
    2017-01-11 20:36 - 2017-01-11 20:36 - 01982056 _____ C:\Users\Unknown\Downloads\OptiFine_1.11.2_HD_U_B5.jar
    2017-01-11 20:35 - 2017-01-11 20:36 - 37295373 _____ C:\Users\Unknown\Downloads\ChromaHills-128x-1.10-v1.zip
    2017-01-11 20:32 - 2017-01-11 20:32 - 00173752 _____ C:\Users\Unknown\Downloads\SEUS-v11.0.zip
    2017-01-10 23:51 - 2017-01-10 23:51 - 05659315 _____ (Swearware) C:\Users\Unknown\Downloads\ComboFix.exe
    2017-01-10 23:40 - 2016-12-21 07:59 - 00218976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinesam.dll
    2017-01-10 23:40 - 2016-12-21 07:09 - 00263472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
    2017-01-10 23:40 - 2016-12-21 07:02 - 03892864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
    2017-01-10 23:40 - 2016-12-21 07:02 - 01852720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
    2017-01-10 23:40 - 2016-12-21 07:02 - 01360464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
    2017-01-10 23:40 - 2016-12-21 07:02 - 01277344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
    2017-01-10 23:40 - 2016-12-21 07:02 - 01201872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
    2017-01-10 23:40 - 2016-12-21 07:02 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
    2017-01-10 23:40 - 2016-12-21 07:01 - 20969928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
    2017-01-10 23:40 - 2016-12-21 06:46 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
    2017-01-10 23:40 - 2016-12-21 06:43 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll
    2017-01-10 23:40 - 2016-12-21 06:41 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll
    2017-01-10 23:40 - 2016-12-21 06:41 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
    2017-01-10 23:40 - 2016-12-21 06:40 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
    2017-01-10 23:40 - 2016-12-21 06:40 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll
    2017-01-10 23:40 - 2016-12-21 06:40 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncSettings.dll
    2017-01-10 23:40 - 2016-12-21 06:40 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
    2017-01-10 23:40 - 2016-12-21 06:39 - 01300480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll
    2017-01-10 23:40 - 2016-12-21 06:39 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe
    2017-01-10 23:40 - 2016-12-21 06:38 - 00866816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
    2017-01-10 23:40 - 2016-12-21 06:35 - 04612608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
    2017-01-10 23:40 - 2016-12-21 06:35 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll
    2017-01-10 23:40 - 2016-12-21 06:34 - 07626752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
    2017-01-10 23:40 - 2016-12-21 06:33 - 19413504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
    2017-01-10 23:40 - 2016-12-21 06:32 - 19417600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
    2017-01-10 23:40 - 2016-12-21 06:30 - 05398016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aclui.dll
    2017-01-10 23:40 - 2016-12-21 06:30 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
    2017-01-10 23:40 - 2016-12-21 06:27 - 00640000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
    2017-01-10 23:40 - 2016-12-21 06:26 - 01155072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVP9DEC.dll
    2017-01-10 23:40 - 2016-12-21 06:25 - 07469056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
    2017-01-10 23:40 - 2016-12-21 06:25 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
    2017-01-10 23:40 - 2016-12-21 06:24 - 06044160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
    2017-01-10 23:40 - 2016-12-21 06:24 - 05061120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
    2017-01-10 23:40 - 2016-12-21 06:24 - 03733504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
    2017-01-10 23:40 - 2016-12-21 06:24 - 00886272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
    2017-01-10 23:40 - 2016-12-21 06:22 - 01883648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
    2017-01-10 23:40 - 2016-12-21 06:22 - 00860672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
    2017-01-10 23:40 - 2016-12-14 07:26 - 01469792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll
    2017-01-10 23:40 - 2016-12-14 07:21 - 02206496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
    2017-01-10 23:40 - 2016-12-14 07:08 - 00341344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
    2017-01-10 23:40 - 2016-12-14 07:06 - 00509792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
    2017-01-10 23:40 - 2016-12-14 07:01 - 01557808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
    2017-01-10 23:40 - 2016-12-14 07:01 - 00382784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
    2017-01-10 23:40 - 2016-12-14 07:01 - 00076984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
    2017-01-10 23:40 - 2016-12-14 06:46 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
    2017-01-10 23:40 - 2016-12-14 06:45 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
    2017-01-10 23:40 - 2016-12-14 06:42 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinSCard.dll
    2017-01-10 23:40 - 2016-12-14 06:40 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudBackupSettings.dll
    2017-01-10 23:40 - 2016-12-14 06:40 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.UI.Logon.ProxyStub.dll
    2017-01-10 23:40 - 2016-12-14 06:38 - 13869056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
    2017-01-10 23:40 - 2016-12-14 06:38 - 00213504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.CredDialogController.dll
    2017-01-10 23:40 - 2016-12-14 06:36 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
    2017-01-10 23:40 - 2016-12-14 06:35 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
    2017-01-10 23:40 - 2016-12-14 06:35 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
    2017-01-10 23:40 - 2016-12-14 06:35 - 00553984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptui.dll
    2017-01-10 23:40 - 2016-12-14 06:32 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
    2017-01-10 23:40 - 2016-12-14 06:32 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
    2017-01-10 23:40 - 2016-12-14 06:22 - 02998272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
    2017-01-10 23:40 - 2016-12-14 06:22 - 02748416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
    2017-01-10 23:40 - 2016-11-02 14:01 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
    2017-01-10 23:40 - 2016-08-02 06:30 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
    2017-01-10 23:36 - 2016-12-21 09:49 - 00328008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
    2017-01-10 23:35 - 2016-12-21 10:08 - 00245600 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
    2017-01-10 23:35 - 2016-12-21 10:08 - 00136032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll
    2017-01-10 23:35 - 2016-12-21 10:04 - 07816032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
    2017-01-10 23:35 - 2016-12-21 09:46 - 00624048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
    2017-01-10 23:35 - 2016-12-21 09:43 - 04130440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
    2017-01-10 23:35 - 2016-12-21 09:43 - 01454504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
    2017-01-10 23:35 - 2016-12-21 09:43 - 01071736 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
    2017-01-10 23:35 - 2016-12-21 09:43 - 00092512 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
    2017-01-10 23:35 - 2016-12-21 09:42 - 22224480 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
    2017-01-10 23:35 - 2016-12-21 09:42 - 01988560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
    2017-01-10 23:35 - 2016-12-21 09:42 - 01702392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
    2017-01-10 23:35 - 2016-12-21 09:42 - 01300600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
    2017-01-10 23:35 - 2016-12-21 09:42 - 00241504 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
    2017-01-10 23:35 - 2016-12-21 09:41 - 01600632 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
    2017-01-10 23:35 - 2016-12-21 09:15 - 22563840 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
    2017-01-10 23:35 - 2016-12-21 09:14 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
    2017-01-10 23:35 - 2016-12-21 09:13 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
    2017-01-10 23:35 - 2016-12-21 09:12 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
    2017-01-10 23:35 - 2016-12-21 09:10 - 00234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
    2017-01-10 23:35 - 2016-12-21 09:09 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneBackupHandler.dll
    2017-01-10 23:35 - 2016-12-21 09:09 - 00363520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll
    2017-01-10 23:35 - 2016-12-21 09:08 - 01292288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
    2017-01-10 23:35 - 2016-12-21 09:08 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
    2017-01-10 23:35 - 2016-12-21 09:08 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
    2017-01-10 23:35 - 2016-12-21 09:08 - 00349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
    2017-01-10 23:35 - 2016-12-21 09:08 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
    2017-01-10 23:35 - 2016-12-21 09:08 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
    2017-01-10 23:35 - 2016-12-21 09:07 - 00748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
    2017-01-10 23:35 - 2016-12-21 09:06 - 06285312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
    2017-01-10 23:35 - 2016-12-21 09:06 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll
    2017-01-10 23:35 - 2016-12-21 09:06 - 00260608 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
    2017-01-10 23:35 - 2016-12-21 09:06 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
    2017-01-10 23:35 - 2016-12-21 09:05 - 00425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
    2017-01-10 23:35 - 2016-12-21 09:05 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll
    2017-01-10 23:35 - 2016-12-21 09:05 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
    2017-01-10 23:35 - 2016-12-21 09:01 - 09131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
    2017-01-10 23:35 - 2016-12-21 09:00 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcfg.dll
    2017-01-10 23:35 - 2016-12-21 08:59 - 01908224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
    2017-01-10 23:35 - 2016-12-21 08:59 - 00883712 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
    2017-01-10 23:35 - 2016-12-21 08:58 - 23678464 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
    2017-01-10 23:35 - 2016-12-21 08:57 - 00462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsettingsprovider.dll
    2017-01-10 23:35 - 2016-12-21 08:56 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVP9DEC.dll
    2017-01-10 23:35 - 2016-12-21 08:56 - 00936960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
    2017-01-10 23:35 - 2016-12-21 08:55 - 08129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
    2017-01-10 23:35 - 2016-12-21 08:55 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
    2017-01-10 23:35 - 2016-12-21 08:53 - 06664192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
    2017-01-10 23:35 - 2016-12-21 08:53 - 04474368 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
    2017-01-10 23:35 - 2016-12-21 08:51 - 08075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
    2017-01-10 23:35 - 2016-12-21 08:51 - 05611008 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
    2017-01-10 23:35 - 2016-12-21 08:50 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
    2017-01-10 23:35 - 2016-12-21 08:49 - 04149248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
    2017-01-10 23:35 - 2016-12-21 08:49 - 02691072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
    2017-01-10 23:35 - 2016-12-21 08:49 - 01062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
    2017-01-10 23:35 - 2016-12-21 08:47 - 01121280 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
    2017-01-10 23:35 - 2016-12-14 07:34 - 02482280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
    2017-01-10 23:35 - 2016-12-14 07:23 - 00404832 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
    2017-01-10 23:35 - 2016-12-14 07:19 - 00584544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
    2017-01-10 23:35 - 2016-12-14 07:17 - 00319288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
    2017-01-10 23:35 - 2016-12-14 07:14 - 01694712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
    2017-01-10 23:35 - 2016-12-14 06:48 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
    2017-01-10 23:35 - 2016-12-14 06:46 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
    2017-01-10 23:35 - 2016-12-14 06:43 - 00201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ScDeviceEnum.dll
    2017-01-10 23:35 - 2016-12-14 06:42 - 00352768 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
    2017-01-10 23:35 - 2016-12-14 06:42 - 00236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSCard.dll
    2017-01-10 23:35 - 2016-12-14 06:42 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.UI.Logon.ProxyStub.dll
    2017-01-10 23:35 - 2016-12-14 06:41 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
    2017-01-10 23:35 - 2016-12-14 06:40 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
    2017-01-10 23:35 - 2016-12-14 06:40 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
    2017-01-10 23:35 - 2016-12-14 06:40 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\certprop.dll
    2017-01-10 23:35 - 2016-12-14 06:39 - 00837632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
    2017-01-10 23:35 - 2016-12-14 06:39 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
    2017-01-10 23:35 - 2016-12-14 06:39 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.CredDialogController.dll
    2017-01-10 23:35 - 2016-12-14 06:38 - 17188864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
    2017-01-10 23:35 - 2016-12-14 06:37 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
    2017-01-10 23:35 - 2016-12-14 06:36 - 01002496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
    2017-01-10 23:35 - 2016-12-14 06:36 - 00539648 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
    2017-01-10 23:35 - 2016-12-14 06:35 - 00600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll
    2017-01-10 23:35 - 2016-12-14 06:26 - 00932864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
    2017-01-10 23:35 - 2016-12-14 06:26 - 00869888 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
    2017-01-10 23:35 - 2016-12-14 06:25 - 02009600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
    2017-01-10 23:35 - 2016-12-14 06:24 - 01005568 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
    2017-01-10 23:35 - 2016-12-14 06:24 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
    2017-01-10 23:35 - 2016-12-14 06:23 - 03134976 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
    2017-01-10 23:35 - 2016-12-14 06:23 - 01231872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
    2017-01-10 23:35 - 2016-12-14 06:22 - 02317824 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
    2017-01-10 23:35 - 2016-12-14 06:22 - 01513472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
    2017-01-10 23:35 - 2016-12-14 06:22 - 00707584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
    2017-01-10 23:35 - 2016-12-14 06:22 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
    2017-01-10 23:35 - 2016-12-14 06:21 - 03616768 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
    2017-01-10 23:34 - 2016-12-21 09:37 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
    2017-01-10 23:34 - 2016-12-21 08:54 - 05511680 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
    2017-01-10 23:34 - 2016-12-21 08:53 - 01692672 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
    2017-01-10 23:34 - 2016-12-21 08:51 - 02275840 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
    2017-01-10 23:34 - 2016-12-14 07:41 - 01235296 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
    2017-01-10 23:34 - 2016-12-14 07:41 - 00590960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
    2017-01-10 23:34 - 2016-12-14 07:33 - 02169184 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll
    2017-01-10 23:34 - 2016-12-14 07:33 - 01669984 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVIntegration.dll
    2017-01-10 23:34 - 2016-12-14 07:33 - 01400160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystemController.dll
    2017-01-10 23:34 - 2016-12-14 07:33 - 01356864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
    2017-01-10 23:34 - 2016-12-14 07:33 - 01054048 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPolicy.dll
    2017-01-10 23:34 - 2016-12-14 07:33 - 00992096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVManifest.dll
    2017-01-10 23:34 - 2016-12-14 07:33 - 00822624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVClient.exe
    2017-01-10 23:34 - 2016-12-14 07:33 - 00813408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntStreamingManager.dll
    2017-01-10 23:34 - 2016-12-14 07:33 - 00779616 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVReporting.dll
    2017-01-10 23:34 - 2016-12-14 07:33 - 00752992 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVOrchestration.dll
    2017-01-10 23:34 - 2016-12-14 07:33 - 00704352 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntVirtualization.dll
    2017-01-10 23:34 - 2016-12-14 07:33 - 00696160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPublishing.dll
    2017-01-10 23:34 - 2016-12-14 07:33 - 00571744 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVCatalog.dll
    2017-01-10 23:34 - 2016-12-14 07:33 - 00513376 _____ (Microsoft Corporation) C:\WINDOWS\system32\TransportDSA.dll
    2017-01-10 23:34 - 2016-12-14 07:33 - 00406368 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVScripting.dll
    2017-01-10 23:34 - 2016-12-14 07:33 - 00241504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVShNotify.exe
    2017-01-10 23:34 - 2016-12-14 07:33 - 00190816 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVDllSurrogate.exe
    2017-01-10 23:34 - 2016-12-14 07:18 - 00715104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
    2017-01-10 23:34 - 2016-12-14 07:18 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
    2017-01-10 23:34 - 2016-12-14 07:14 - 00418952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
    2017-01-10 23:34 - 2016-12-14 07:14 - 00089416 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
    2017-01-10 23:34 - 2016-12-14 06:38 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll
    2017-01-10 23:34 - 2016-11-02 13:00 - 00534096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
    2017-01-10 23:34 - 2016-11-02 12:28 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
    2017-01-10 23:34 - 2016-11-02 12:22 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
    2017-01-10 23:34 - 2016-11-02 12:21 - 00942080 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
    2017-01-10 23:30 - 2017-01-10 23:30 - 04810592 _____ (Lenovo Group Limited ) C:\Users\Unknown\Downloads\wwlb090e (1).exe
    2017-01-10 23:29 - 2017-01-10 23:29 - 05891080 _____ (Lenovo Group Limited ) C:\Users\Unknown\Downloads\wwfd020e.exe
    2017-01-10 23:27 - 2017-01-10 23:27 - 04810592 _____ (Lenovo Group Limited ) C:\Users\Unknown\Downloads\wwlb090e.exe
    2017-01-10 23:23 - 2017-01-10 23:23 - 09308285 _____ C:\Users\Unknown\Downloads\Lenovo Settings.zip
    2017-01-10 23:23 - 2017-01-10 23:23 - 00000000 ____D C:\Users\Unknown\Downloads\Lenovo Settings
    2017-01-10 23:18 - 2017-01-10 23:18 - 00000000 ____D C:\ProgramData\Dolby
    2017-01-10 23:18 - 2017-01-10 23:18 - 00000000 ____D C:\Program Files\Dolby
    2017-01-10 23:15 - 2017-01-10 23:15 - 00000000 ____D C:\Users\Unknown\AppData\Local\Tvsukernel
    2017-01-10 23:14 - 2017-01-10 23:14 - 00000000 ____D C:\Users\Unknown\AppData\Local\PeerDistRepub
    2017-01-10 23:14 - 2017-01-10 23:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo ThinkVantage Tools
    2017-01-10 23:10 - 2017-01-10 23:14 - 00000000 ____D C:\WINDOWS\System32\Tasks\TVT
    2017-01-10 23:10 - 2017-01-10 23:10 - 00000000 ____D C:\Users\Unknown\AppData\Local\LenovoServiceBridge
    2017-01-10 23:06 - 2017-01-10 23:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hi-Rez Studios
    2017-01-10 18:19 - 2017-01-10 18:19 - 00000000 ____D C:\Users\Unknown\AppData\Local\CrashRpt
    2017-01-10 15:46 - 2017-01-10 15:46 - 00000271 _____ C:\Users\Unknown\Documents\Faze MLG.txt
    2017-01-10 14:39 - 2017-01-10 15:29 - 00000000 ____D C:\Users\Unknown\.thonny
    2017-01-10 01:41 - 2017-01-10 01:41 - 01778776 _____ (Safer-Networking Ltd. ) C:\Users\Ander Eerits\Downloads\spybotsd2-windows-upgrade-installer.exe
    2017-01-10 01:41 - 2017-01-10 01:41 - 00000000 ____D C:\Program Files\Common Files\AV
    2017-01-10 01:11 - 2017-01-10 01:49 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
    2017-01-10 01:11 - 2017-01-10 01:41 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
    2017-01-10 01:11 - 2017-01-10 01:11 - 00001464 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
    2017-01-10 01:11 - 2017-01-10 01:11 - 00000000 ____D C:\WINDOWS\System32\Tasks\Safer-Networking
    2017-01-10 01:11 - 2017-01-10 01:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
    2017-01-10 01:11 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\WINDOWS\system32\sdnclean64.exe
    2017-01-10 01:10 - 2017-01-10 01:11 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Unknown\Downloads\spybot-2.4.exe
    2017-01-10 00:51 - 2017-01-10 00:51 - 06771840 _____ (ESET spol. s r.o.) C:\Users\Unknown\Downloads\esetonlinescanner_enu.exe
    2017-01-10 00:51 - 2017-01-10 00:51 - 00000000 ____D C:\Users\Unknown\AppData\Local\ESET
    2017-01-09 23:34 - 2017-01-09 23:34 - 00000000 ____D C:\Users\Unknown\AppData\Local\Chromium
    2017-01-09 23:33 - 2017-01-09 23:33 - 00000000 ____D C:\WINDOWS\Panther
    2017-01-09 20:59 - 2017-01-09 20:59 - 03138176 _____ (ESET) C:\Users\Unknown\Downloads\eset_nod32_antivirus_live_installer.exe
    2017-01-09 15:18 - 2017-01-09 15:26 - 00000000 ____D C:\Users\Unknown\AppData\Roaming\Balabolka
    2017-01-09 15:18 - 2017-01-09 15:18 - 00000000 ____D C:\WINDOWS\Downloaded Installations
    2017-01-09 15:18 - 2017-01-09 15:18 - 00000000 ____D C:\Users\Unknown\Documents\Balabolka
    2017-01-09 15:18 - 2017-01-09 15:18 - 00000000 ____D C:\Program Files (x86)\NextUp-ScanSoft
    2017-01-09 15:16 - 2017-01-09 15:16 - 94175793 _____ (NextUp.com ) C:\Users\Unknown\Downloads\Daniel 22Khz MLG voice.exe
    2017-01-09 15:16 - 2017-01-09 15:16 - 09827694 _____ C:\Users\Unknown\Downloads\Balabolka.rar
    2017-01-09 13:58 - 2017-01-09 13:58 - 00000015 _____ C:\Users\Unknown\Documents\code.py
    2017-01-09 13:56 - 2017-01-09 13:56 - 00002179 _____ C:\Users\Unknown\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Thonny.lnk
    2017-01-09 13:55 - 2017-01-09 13:56 - 09003432 _____ (Aivar Annamaa ) C:\Users\Unknown\Downloads\thonny-2.0.7.exe
    2017-01-09 00:29 - 2017-01-09 00:29 - 00000000 _____ C:\autoexec.bat
    2017-01-08 21:27 - 2017-01-08 21:27 - 00000000 ____D C:\Users\Unknown\AppData\Local\Windscribe
    2017-01-08 21:27 - 2017-01-08 21:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windscribe
    2017-01-08 21:27 - 2017-01-08 21:27 - 00000000 ____D C:\Program Files (x86)\Windscribe
    2017-01-08 20:00 - 2017-01-15 12:13 - 00817504 _____ C:\WINDOWS\ZAM_Guard.krnl.trace
    2017-01-08 20:00 - 2017-01-10 23:46 - 00085773 _____ C:\WINDOWS\ZAM.krnl.trace
    2017-01-08 19:59 - 2017-01-11 18:36 - 00000000 ____D C:\Program Files (x86)\Zemana AntiMalware
    2017-01-08 19:59 - 2017-01-08 19:59 - 00203680 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zamguard64.sys
    2017-01-08 19:59 - 2017-01-08 19:59 - 00000000 ____D C:\Users\Unknown\AppData\Local\Zemana
    2017-01-08 19:49 - 2017-01-08 20:47 - 00000556 _____ C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task efc55b65-b0ec-4d02-94e9-b91b8d34cbc9.job
    2017-01-08 19:49 - 2017-01-08 20:47 - 00000556 _____ C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task e43691ac-19f2-4bf3-84c2-8da7e08639aa.job
    2017-01-08 19:49 - 2017-01-08 19:49 - 00003810 _____ C:\WINDOWS\System32\Tasks\SUPERAntiSpyware Scheduled Task efc55b65-b0ec-4d02-94e9-b91b8d34cbc9
    2017-01-08 19:49 - 2017-01-08 19:49 - 00003728 _____ C:\WINDOWS\System32\Tasks\SUPERAntiSpyware Scheduled Task e43691ac-19f2-4bf3-84c2-8da7e08639aa
    2017-01-08 19:49 - 2017-01-08 19:49 - 00000000 ____D C:\Users\Unknown\AppData\Roaming\SUPERAntiSpyware.com
    2017-01-08 19:49 - 2017-01-08 19:49 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
    2017-01-08 19:49 - 2017-01-08 19:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
    2017-01-08 19:49 - 2017-01-08 19:49 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
    2017-01-08 19:46 - 2017-01-08 19:46 - 00001807 _____ C:\Users\Unknown\Desktop\Scan Results.txt
    2017-01-08 19:36 - 2017-01-08 19:42 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
    2017-01-08 19:30 - 2016-12-31 22:03 - 00391496 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
    2017-01-08 16:05 - 2017-01-08 19:29 - 00000000 ____D C:\ProgramData\HitmanPro
    2017-01-07 22:13 - 2017-01-08 19:29 - 00000000 ____D C:\Users\Unknown\Documents\American Truck Simulator
    2017-01-06 20:31 - 2017-01-11 20:45 - 00000000 ____D C:\ProgramData\Oracle
    2017-01-06 20:31 - 2017-01-11 20:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
    2017-01-06 20:31 - 2017-01-06 20:31 - 00000000 ____D C:\Users\Unknown\AppData\Roaming\Sun
    2017-01-06 20:31 - 2017-01-06 20:31 - 00000000 ____D C:\Users\Unknown\AppData\LocalLow\Sun
    2017-01-06 20:20 - 2017-01-12 14:29 - 00000000 ____D C:\ProgramData\Hi-Rez Studios
    2017-01-06 20:20 - 2017-01-11 18:36 - 00000000 ____D C:\Program Files (x86)\Hi-Rez Studios
    2017-01-06 17:11 - 2017-01-13 16:19 - 00001301 _____ C:\Users\Unknown\Desktop\BeamNG.drive.exe.lnk
    2017-01-06 16:56 - 2017-01-10 01:50 - 00000000 ____D C:\AdwCleaner
    2017-01-02 23:31 - 2017-01-02 23:31 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
    2017-01-02 23:28 - 2017-01-02 23:29 - 00000000 ____D C:\Users\Unknown\AppData\LocalLow\uTorrent
    2017-01-02 23:23 - 2017-01-02 23:23 - 00002711 _____ C:\Users\Unknown\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
    2017-01-02 23:21 - 2017-01-03 01:44 - 00000000 ____D C:\Users\Unknown\AppData\Roaming\uTorrent
    2017-01-02 20:43 - 2017-01-02 20:51 - 00000000 ____D C:\Users\Unknown\AppData\Roaming\obs-studio
    2017-01-02 20:42 - 2017-01-02 20:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio
    2017-01-02 20:42 - 2017-01-02 20:42 - 00000000 ____D C:\Program Files (x86)\obs-studio
    2017-01-02 19:18 - 2017-01-03 01:02 - 00028272 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
    2017-01-02 19:17 - 2017-01-08 19:29 - 00000000 ____D C:\ProgramData\RogueKiller
    2017-01-02 19:17 - 2017-01-02 19:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
    2017-01-02 19:17 - 2017-01-02 19:17 - 00000000 ____D C:\Program Files\RogueKiller
    2017-01-02 17:06 - 2017-01-11 00:24 - 00000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
    2017-01-02 17:06 - 2017-01-02 17:09 - 00000000 ____D C:\WINDOWS\CSC
    2017-01-02 17:06 - 2017-01-02 17:06 - 00000000 __SHD C:\WINDOWS\BitLockerDiscoveryVolumeContents
    2017-01-02 17:06 - 2017-01-02 17:06 - 00000000 ____D C:\WINDOWS\RemotePackages
    2017-01-02 17:04 - 2016-07-16 13:43 - 00033882 _____ C:\WINDOWS\Professional.xml
    2017-01-02 17:03 - 2017-01-02 17:03 - 00000029 _____ C:\Users\Unknown\Documents\ME keyä'.txt
    2017-01-02 13:45 - 2017-01-02 13:45 - 00000000 ____D C:\Users\Unknown\AppData\Local\NBTExplorer
    2017-01-02 02:58 - 2017-01-15 12:09 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
    2017-01-02 02:55 - 2017-01-02 02:55 - 00001051 _____ C:\Users\Unknown\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Valikulised funktsioonid.lnk
    2017-01-02 02:55 - 2017-01-02 02:55 - 00000000 ____D C:\WINDOWS\OCR
    2017-01-02 02:55 - 2016-07-15 19:29 - 05739008 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0009.dll
    2017-01-02 02:55 - 2016-07-15 19:29 - 02629120 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0009.dll
    2017-01-02 02:55 - 2016-07-15 19:14 - 06354944 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0009.dll
    2017-01-02 02:55 - 2016-07-15 18:45 - 02629120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0009.dll
    2017-01-02 02:55 - 2016-07-15 18:29 - 05489664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0009.dll
    2017-01-02 02:34 - 2017-01-02 02:34 - 00000222 _____ C:\Users\Unknown\Desktop\Paladins.url
    2017-01-02 02:26 - 2017-01-02 02:26 - 00000000 ____D C:\Users\Unknown\AppData\LocalLow\Smartly Dressed Games
    2017-01-02 02:18 - 2017-01-10 23:14 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo
    2017-01-02 02:18 - 2017-01-02 02:18 - 00000000 ____D C:\WINDOWS\System32\Tasks\CyberLink
    2017-01-02 02:18 - 2017-01-02 02:18 - 00000000 ____D C:\Users\Unknown\AppData\Roaming\CyberLink
    2017-01-02 02:18 - 2017-01-02 02:18 - 00000000 ____D C:\Users\Unknown\AppData\Local\CyberLink
    2017-01-02 02:18 - 2017-01-02 02:18 - 00000000 ____D C:\ProgramData\CyberLink
    2017-01-02 02:18 - 2017-01-02 02:18 - 00000000 ____D C:\Program Files (x86)\NSIS Uninstall Information
    2017-01-02 02:18 - 2017-01-02 02:18 - 00000000 ____D C:\Program Files (x86)\CyberLink
    2017-01-02 02:17 - 2017-01-02 02:18 - 00000000 ____D C:\ProgramData\SUPPORTDIR
    2017-01-02 02:17 - 2017-01-02 02:17 - 00000000 ____D C:\ProgramData\Temp
    2017-01-02 01:56 - 2017-01-02 01:56 - 00000222 _____ C:\Users\Unknown\Desktop\Unturned.url
    2017-01-01 23:44 - 2017-01-14 23:55 - 00000000 ____D C:\Users\Unknown\Documents\BeamNG.drive
    2017-01-01 23:40 - 2017-01-01 23:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
    2017-01-01 23:40 - 2017-01-01 23:40 - 00000000 ____D C:\Program Files (x86)\7-Zip
    2017-01-01 23:26 - 2017-01-01 23:26 - 00102856 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
    2017-01-01 23:25 - 2017-01-12 00:02 - 00000000 ____D C:\ProgramData\Malwarebytes
    2017-01-01 23:25 - 2017-01-11 18:36 - 00250816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
    2017-01-01 23:25 - 2017-01-08 21:10 - 00001912 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
    2017-01-01 23:25 - 2017-01-08 21:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
    2017-01-01 23:25 - 2017-01-01 23:25 - 00000000 ____D C:\Program Files\Malwarebytes
    2017-01-01 23:25 - 2016-12-14 12:55 - 00077416 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
    2017-01-01 20:53 - 2017-01-01 20:53 - 00000000 ____D C:\ProgramData\Hewlett-Packard
    2017-01-01 20:08 - 2017-01-14 12:16 - 00000000 ____D C:\ProgramData\Skype
    2017-01-01 20:08 - 2017-01-01 20:08 - 00000000 ___RD C:\Program Files (x86)\Skype
    2017-01-01 20:08 - 2017-01-01 20:08 - 00000000 ____D C:\Users\Unknown\Tracing
    2017-01-01 20:08 - 2017-01-01 20:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
    2017-01-01 19:51 - 2017-01-15 12:10 - 00000000 ___RD C:\Users\Unknown\Google Drive
    2017-01-01 19:51 - 2017-01-01 19:51 - 00001767 _____ C:\Users\Unknown\Desktop\Google Drive.lnk
    2017-01-01 19:50 - 2017-01-01 19:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
    2017-01-01 16:52 - 2016-12-09 12:29 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll
    2017-01-01 16:52 - 2016-12-09 12:19 - 01293152 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
    2017-01-01 16:52 - 2016-12-09 12:18 - 01100128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
    2017-01-01 16:52 - 2016-12-09 12:18 - 00989024 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
    2017-01-01 16:52 - 2016-12-09 12:18 - 00947552 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi
    2017-01-01 16:52 - 2016-12-09 12:18 - 00811872 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe
    2017-01-01 16:52 - 2016-12-09 12:15 - 08168000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
    2017-01-01 16:52 - 2016-12-09 12:14 - 01274712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
    2017-01-01 16:52 - 2016-12-09 12:01 - 02323728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
    2017-01-01 16:52 - 2016-12-09 12:01 - 01503544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
    2017-01-01 16:52 - 2016-12-09 11:52 - 01435896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
    2017-01-01 16:52 - 2016-12-09 11:51 - 00117240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll
    2017-01-01 16:52 - 2016-12-09 11:45 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
    2017-01-01 16:52 - 2016-12-09 11:41 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll
    2017-01-01 16:52 - 2016-12-09 11:37 - 00411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
    2017-01-01 16:52 - 2016-12-09 11:36 - 03059200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
    2017-01-01 16:52 - 2016-12-09 11:36 - 00410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
    2017-01-01 16:52 - 2016-12-09 11:33 - 03777536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
    2017-01-01 16:52 - 2016-12-09 11:33 - 01589760 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
    2017-01-01 16:52 - 2016-12-09 11:31 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
    2017-01-01 16:52 - 2016-12-09 11:28 - 03306496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
    2017-01-01 16:52 - 2016-12-09 11:27 - 13084160 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
    2017-01-01 16:52 - 2016-12-09 11:27 - 05114368 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
    2017-01-01 16:52 - 2016-12-09 11:27 - 00981504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
    2017-01-01 16:52 - 2016-12-09 11:23 - 12177920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
    2017-01-01 16:52 - 2016-12-09 11:22 - 02820096 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
    2017-01-01 16:52 - 2016-12-09 11:19 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
    2017-01-01 16:52 - 2016-12-09 11:19 - 00261120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
    2017-01-01 16:52 - 2016-12-09 11:19 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
    2017-01-01 16:52 - 2016-12-09 11:19 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
    2017-01-01 16:52 - 2016-12-09 11:18 - 02138112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
    2017-01-01 16:52 - 2016-12-09 11:16 - 00353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
    2017-01-01 16:52 - 2016-12-09 11:15 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
    2017-01-01 16:52 - 2016-12-09 11:15 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
    2017-01-01 16:52 - 2016-12-09 11:15 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll
    2017-01-01 16:52 - 2016-11-11 12:15 - 00101216 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceReactivation.dll
    2017-01-01 16:52 - 2016-11-11 12:14 - 00603488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
    2017-01-01 16:52 - 2016-11-11 12:13 - 00352096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
    2017-01-01 16:52 - 2016-11-11 12:02 - 00360040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
    2017-01-01 16:52 - 2016-11-11 12:01 - 01859264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
    2017-01-01 16:52 - 2016-11-11 12:00 - 00219488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
    2017-01-01 16:52 - 2016-11-11 11:57 - 01473048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
    2017-01-01 16:52 - 2016-11-11 11:56 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
    2017-01-01 16:52 - 2016-11-11 11:56 - 00187520 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudStorageWizard.exe
    2017-01-01 16:52 - 2016-11-11 11:56 - 00126568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfaudiocnv.dll
    2017-01-01 16:52 - 2016-11-11 11:55 - 00882680 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
    2017-01-01 16:52 - 2016-11-11 11:55 - 00743224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
    2017-01-01 16:52 - 2016-11-11 11:51 - 00454592 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
    2017-01-01 16:52 - 2016-11-11 11:28 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CbtBackgroundManagerPolicy.dll
    2017-01-01 16:52 - 2016-11-11 11:27 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpremove.exe
    2017-01-01 16:52 - 2016-11-11 11:26 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\modem.sys
    2017-01-01 16:52 - 2016-11-11 11:25 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
    2017-01-01 16:52 - 2016-11-11 11:25 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
    2017-01-01 16:52 - 2016-11-11 11:24 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
    2017-01-01 16:52 - 2016-11-11 11:24 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
    2017-01-01 16:52 - 2016-11-11 11:24 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
    2017-01-01 16:52 - 2016-11-11 11:24 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
    2017-01-01 16:52 - 2016-11-11 11:23 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
    2017-01-01 16:52 - 2016-11-11 11:20 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
    2017-01-01 16:52 - 2016-11-11 11:19 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
    2017-01-01 16:52 - 2016-11-11 11:19 - 00388096 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
    2017-01-01 16:52 - 2016-11-11 11:19 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
    2017-01-01 16:52 - 2016-11-11 11:17 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll
    2017-01-01 16:52 - 2016-11-11 11:16 - 01477632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
    2017-01-01 16:52 - 2016-11-11 11:16 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
    2017-01-01 16:52 - 2016-11-11 11:16 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll
    2017-01-01 16:52 - 2016-11-11 11:16 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\RjvMDMConfig.dll
    2017-01-01 16:52 - 2016-11-11 11:14 - 07654400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
    2017-01-01 16:52 - 2016-11-11 11:14 - 02104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
    2017-01-01 16:52 - 2016-11-11 11:14 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
    2017-01-01 16:52 - 2016-11-11 11:13 - 07812096 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
    2017-01-01 16:52 - 2016-11-11 11:13 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
    2017-01-01 16:52 - 2016-11-11 11:12 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcprx.dll
    2017-01-01 16:52 - 2016-11-11 11:11 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
    2017-01-01 16:52 - 2016-11-11 11:08 - 00539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
    2017-01-01 16:52 - 2016-11-11 11:07 - 00991232 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
    2017-01-01 16:52 - 2016-11-11 11:06 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
    2017-01-01 16:52 - 2016-11-11 11:05 - 04136448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
    2017-01-01 16:52 - 2016-11-11 11:05 - 02852864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
    2017-01-01 16:52 - 2016-11-11 11:04 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
    2017-01-01 16:52 - 2016-11-11 11:02 - 03542016 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
    2017-01-01 16:52 - 2016-11-11 11:02 - 01726976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
    2017-01-01 16:52 - 2016-11-11 10:01 - 00167848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll
    2017-01-01 16:52 - 2016-11-11 09:54 - 00122208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\migisol.dll
    2017-01-01 16:52 - 2016-11-11 09:48 - 02277248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
    2017-01-01 16:52 - 2016-11-11 09:47 - 05722832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
    2017-01-01 16:52 - 2016-11-11 09:47 - 00527880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
    2017-01-01 16:52 - 2016-11-11 09:42 - 01123912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
    2017-01-01 16:52 - 2016-11-11 09:42 - 00952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
    2017-01-01 16:52 - 2016-11-11 09:42 - 00091936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfaudiocnv.dll
    2017-01-01 16:52 - 2016-11-11 09:41 - 04311736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
    2017-01-01 16:52 - 2016-11-11 09:41 - 00157536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudStorageWizard.exe
    2017-01-01 16:52 - 2016-11-11 09:38 - 01263856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
    2017-01-01 16:52 - 2016-11-11 09:25 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
    2017-01-01 16:52 - 2016-11-11 09:25 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
    2017-01-01 16:52 - 2016-11-11 09:24 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BcastDVRHelper.dll
    2017-01-01 16:52 - 2016-11-11 09:24 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
    2017-01-01 16:52 - 2016-11-11 09:24 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll
    2017-01-01 16:52 - 2016-11-11 09:23 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
    2017-01-01 16:52 - 2016-11-11 09:23 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll
    2017-01-01 16:52 - 2016-11-11 09:22 - 00505856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
    2017-01-01 16:52 - 2016-11-11 09:22 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll
    2017-01-01 16:52 - 2016-11-11 09:21 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
    2017-01-01 16:52 - 2016-11-11 09:19 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll
    2017-01-01 16:52 - 2016-11-11 09:19 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupugc.exe
    2017-01-01 16:52 - 2016-11-11 09:18 - 02333184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
    2017-01-01 16:52 - 2016-11-11 09:18 - 01196544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl
    2017-01-01 16:52 - 2016-11-11 09:18 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
    2017-01-01 16:52 - 2016-11-11 09:18 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscinterop.dll
    2017-01-01 16:52 - 2016-11-11 09:17 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
    2017-01-01 16:52 - 2016-11-11 09:17 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe
    2017-01-01 16:52 - 2016-11-11 09:15 - 01357824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
    2017-01-01 16:52 - 2016-11-11 09:15 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
    2017-01-01 16:52 - 2016-11-11 09:15 - 00348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
    2017-01-01 16:52 - 2016-11-11 09:10 - 06109184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
    2017-01-01 16:52 - 2016-11-11 09:10 - 00746496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcprx.dll
    2017-01-01 16:52 - 2016-11-11 09:09 - 05380608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
    2017-01-01 16:52 - 2016-11-11 09:09 - 00545280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
    2017-01-01 16:52 - 2016-11-11 09:08 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xolehlp.dll
    2017-01-01 16:52 - 2016-11-11 09:06 - 02362880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll
    2017-01-01 16:52 - 2016-11-11 09:06 - 02109952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll
    2017-01-01 16:52 - 2016-11-11 09:06 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxclu.dll
    2017-01-01 16:52 - 2016-11-11 09:05 - 04423680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
    2017-01-01 16:52 - 2016-11-11 09:05 - 03370496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
    2017-01-01 16:52 - 2016-11-11 09:04 - 02682880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll
    2017-01-01 16:52 - 2016-11-11 09:04 - 01992704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
    2017-01-01 16:52 - 2016-11-11 09:04 - 00912896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
    2017-01-01 16:52 - 2016-11-11 09:04 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
    2017-01-01 16:52 - 2016-11-11 09:04 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll
    2017-01-01 16:52 - 2016-11-11 09:03 - 02484736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll
    2017-01-01 16:52 - 2016-11-11 09:03 - 01556480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
    2017-01-01 16:52 - 2016-11-11 09:03 - 00760832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
    2017-01-01 16:52 - 2016-11-11 09:02 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
    2017-01-01 16:52 - 2016-11-02 14:01 - 00315744 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
    2017-01-01 16:52 - 2016-11-02 13:22 - 00601712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
    2017-01-01 16:52 - 2016-11-02 13:09 - 02257104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
    2017-01-01 16:52 - 2016-11-02 13:01 - 00545936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
    2017-01-01 16:52 - 2016-11-02 12:49 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
    2017-01-01 16:52 - 2016-11-02 12:45 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsensorgroup.dll
    2017-01-01 16:52 - 2016-11-02 12:44 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthExt.dll
    2017-01-01 16:52 - 2016-11-02 12:43 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FSClient.dll
    2017-01-01 16:52 - 2016-11-02 12:42 - 00632832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sud.dll
    2017-01-01 16:52 - 2016-11-02 12:40 - 00896512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontext.dll
    2017-01-01 16:52 - 2016-11-02 12:39 - 00236544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAnimation.dll
    2017-01-01 16:52 - 2016-11-02 12:38 - 00760832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appwiz.cpl
    2017-01-01 16:52 - 2016-11-02 12:37 - 00299008 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpinit.exe
    2017-01-01 16:52 - 2016-11-02 12:36 - 00415744 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpshell.exe
    2017-01-01 16:52 - 2016-11-02 12:33 - 12349952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
    2017-01-01 16:52 - 2016-11-02 12:32 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\efsext.dll
    2017-01-01 16:52 - 2016-11-02 12:31 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
    2017-01-01 16:52 - 2016-11-02 12:28 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ListSvc.dll
    2017-01-01 16:52 - 2016-11-02 12:28 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
    2017-01-01 16:52 - 2016-11-02 12:27 - 02458112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themecpl.dll
    2017-01-01 16:52 - 2016-11-02 12:27 - 00631296 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMediaManager.dll
    2017-01-01 16:52 - 2016-11-02 12:27 - 00580608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hgcpl.dll
    2017-01-01 16:52 - 2016-11-02 12:27 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\system32\timedate.cpl
    2017-01-01 16:52 - 2016-11-02 12:27 - 00422400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll
    2017-01-01 16:52 - 2016-11-02 12:25 - 00956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
    2017-01-01 16:52 - 2016-11-02 12:23 - 02356736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVidCtl.dll
    2017-01-01 16:52 - 2016-11-02 12:22 - 13441024 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
    2017-01-01 16:52 - 2016-11-02 12:22 - 00369664 _____ (Microsoft Corporation) C:\WINDOWS\system32\msinfo32.exe
    2017-01-01 16:52 - 2016-11-02 12:19 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll
    2017-01-01 16:52 - 2016-11-02 12:19 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
    2017-01-01 16:52 - 2016-11-02 12:16 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
    2017-01-01 16:52 - 2016-11-02 12:15 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
    2017-01-01 16:52 - 2016-11-02 12:13 - 03299840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
    2017-01-01 16:52 - 2016-11-02 10:20 - 00446896 _____ C:\WINDOWS\system32\ApnDatabase.xml
    2017-01-01 16:52 - 2016-10-15 06:41 - 05622088 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
    2017-01-01 16:52 - 2016-10-15 06:37 - 00063328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
    2017-01-01 16:52 - 2016-10-15 06:33 - 00455040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll
    2017-01-01 16:52 - 2016-10-15 06:26 - 00811416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
    2017-01-01 16:52 - 2016-10-15 06:26 - 00691080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
    2017-01-01 16:52 - 2016-10-15 06:21 - 00292872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpeffects.dll
    2017-01-01 16:52 - 2016-10-15 06:15 - 00687936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
    2017-01-01 16:52 - 2016-10-15 06:10 - 00254656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpeffects.dll
    2017-01-01 16:52 - 2016-10-15 06:05 - 07216640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
    2017-01-01 16:52 - 2016-10-15 06:00 - 00323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
    2017-01-01 16:52 - 2016-10-15 06:00 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stdole2.tlb
    2017-01-01 16:52 - 2016-10-15 05:59 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfksproxy.dll
    2017-01-01 16:52 - 2016-10-15 05:59 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\stdole2.tlb
    2017-01-01 16:52 - 2016-10-15 05:57 - 00217600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpdxm.dll
    2017-01-01 16:52 - 2016-10-15 05:57 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
    2017-01-01 16:52 - 2016-10-15 05:57 - 00175104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpdxm.dll
    2017-01-01 16:52 - 2016-10-15 05:57 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dtdump.exe
    2017-01-01 16:52 - 2016-10-15 05:56 - 00327680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
    2017-01-01 16:52 - 2016-10-15 05:56 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esentutl.exe
    2017-01-01 16:52 - 2016-10-15 05:55 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys
    2017-01-01 16:52 - 2016-10-15 05:55 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpshell.dll
    2017-01-01 16:52 - 2016-10-15 05:54 - 00410112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SndVolSSO.dll
    2017-01-01 16:52 - 2016-10-15 05:54 - 00152064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autoplay.dll
    2017-01-01 16:52 - 2016-10-15 05:54 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpshell.dll
    2017-01-01 16:52 - 2016-10-15 05:52 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\systemcpl.dll
    2017-01-01 16:52 - 2016-10-15 05:49 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
    2017-01-01 16:52 - 2016-10-15 05:48 - 01323008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
    2017-01-01 16:52 - 2016-10-15 05:47 - 01113600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
    2017-01-01 16:52 - 2016-10-15 05:47 - 00720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll
    2017-01-01 16:52 - 2016-10-15 05:46 - 00718848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
    2017-01-01 16:52 - 2016-10-15 05:45 - 00702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll
    2017-01-01 16:52 - 2016-10-15 05:44 - 00747008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
    2017-01-01 16:52 - 2016-10-15 05:44 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\powercfg.exe
    2017-01-01 16:52 - 2016-10-15 05:43 - 02748928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
    2017-01-01 16:52 - 2016-10-15 05:39 - 00631296 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
    2017-01-01 16:52 - 2016-10-15 05:37 - 01980416 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
    2017-01-01 16:52 - 2016-10-15 05:37 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
    2017-01-01 16:52 - 2016-10-15 05:36 - 00338944 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcpl.dll
    2017-01-01 16:52 - 2016-10-15 05:35 - 02708992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
    2017-01-01 16:52 - 2016-10-15 05:35 - 02005504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
    2017-01-01 16:52 - 2016-10-05 12:35 - 00279904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
    2017-01-01 16:52 - 2016-10-05 12:16 - 00187232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
    2017-01-01 16:52 - 2016-10-05 12:12 - 01112928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
    2017-01-01 16:52 - 2016-10-05 11:50 - 00116576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll
    2017-01-01 16:52 - 2016-10-05 11:49 - 01980768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
    2017-01-01 16:52 - 2016-10-05 11:48 - 01022304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
    2017-01-01 16:52 - 2016-10-05 11:36 - 00113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll
    2017-01-01 16:52 - 2016-10-05 11:35 - 00196096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.dll
    2017-01-01 16:52 - 2016-10-05 11:35 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.Ngc.dll
    2017-01-01 16:52 - 2016-10-05 11:33 - 00651264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
    2017-01-01 16:52 - 2016-10-05 11:32 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll
    2017-01-01 16:52 - 2016-10-05 11:31 - 00480768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
    2017-01-01 16:52 - 2016-10-05 11:31 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ConfigureExpandedStorage.dll
    2017-01-01 16:52 - 2016-10-05 11:27 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
    2017-01-01 16:52 - 2016-10-05 11:26 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
    2017-01-01 16:52 - 2016-10-05 11:24 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.AllJoyn.dll
    2017-01-01 16:52 - 2016-10-05 11:24 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\adsmsext.dll
    2017-01-01 16:52 - 2016-10-05 11:23 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Wallet.dll
    2017-01-01 16:52 - 2016-10-05 11:23 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialclient.dll
    2017-01-01 16:52 - 2016-10-05 11:19 - 02390016 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
    2017-01-01 16:52 - 2016-10-05 11:16 - 00765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
    2017-01-01 16:52 - 2016-10-05 11:07 - 02646016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
    2017-01-01 16:52 - 2016-09-15 19:37 - 00496872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
    2017-01-01 16:52 - 2016-09-15 19:33 - 00083120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devenum.dll
    2017-01-01 16:52 - 2016-09-15 19:29 - 00169056 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
    2017-01-01 16:52 - 2016-09-15 19:29 - 00127328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\AppVStrm.sys
    2017-01-01 16:52 - 2016-09-15 19:29 - 00081760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
    2017-01-01 16:52 - 2016-09-15 19:29 - 00023392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cmimcext.sys
    2017-01-01 16:52 - 2016-09-15 19:27 - 00434528 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
    2017-01-01 16:52 - 2016-09-15 19:23 - 00170960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
    2017-01-01 16:52 - 2016-09-15 19:22 - 00975744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
    2017-01-01 16:52 - 2016-09-15 19:18 - 00856872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
    2017-01-01 16:52 - 2016-09-15 19:15 - 00130912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys
    2017-01-01 16:52 - 2016-09-15 19:13 - 00113504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll
    2017-01-01 16:52 - 2016-09-15 19:11 - 00862064 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
    2017-01-01 16:52 - 2016-09-15 19:11 - 00725664 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
    2017-01-01 16:52 - 2016-09-15 19:06 - 00387872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
    2017-01-01 16:52 - 2016-09-15 19:03 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TempSignedLicenseExchangeTask.dll
    2017-01-01 16:52 - 2016-09-15 19:01 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\findnetprinters.dll
    2017-01-01 16:52 - 2016-09-15 18:58 - 00291840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
    2017-01-01 16:52 - 2016-09-15 18:58 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.SerialCommunication.dll
    2017-01-01 16:52 - 2016-09-15 18:56 - 00670208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.PointOfService.dll
    2017-01-01 16:52 - 2016-09-15 18:56 - 00265728 _____ C:\WINDOWS\SysWOW64\Windows.Perception.Stub.dll
    2017-01-01 16:52 - 2016-09-15 18:56 - 00262656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pdh.dll
    2017-01-01 16:52 - 2016-09-15 18:56 - 00257536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DataExchange.dll
    2017-01-01 16:52 - 2016-09-15 18:56 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManagerApi.dll
    2017-01-01 16:52 - 2016-09-15 18:55 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
    2017-01-01 16:52 - 2016-09-15 18:55 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WwaApi.dll
    2017-01-01 16:52 - 2016-09-15 18:55 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll
    2017-01-01 16:52 - 2016-09-15 18:55 - 00152064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\biwinrt.dll
    2017-01-01 16:52 - 2016-09-15 18:54 - 00431104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprdim.dll
    2017-01-01 16:52 - 2016-09-15 18:54 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Picker.dll
    2017-01-01 16:52 - 2016-09-15 18:53 - 00314368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll
    2017-01-01 16:52 - 2016-09-15 18:53 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.dll
    2017-01-01 16:52 - 2016-09-15 18:52 - 00525824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintDialogs.dll
    2017-01-01 16:52 - 2016-09-15 18:52 - 00500224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.dll
    2017-01-01 16:52 - 2016-09-15 18:52 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
    2017-01-01 16:52 - 2016-09-15 18:51 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CryptoWinRT.dll
    2017-01-01 16:52 - 2016-09-15 18:49 - 00901120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
    2017-01-01 16:52 - 2016-09-15 18:49 - 00653312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
    2017-01-01 16:52 - 2016-09-15 18:47 - 01077760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll
    2017-01-01 16:52 - 2016-09-15 18:47 - 00355328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTMediaFrame.dll
    2017-01-01 16:52 - 2016-09-15 18:47 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Energy.dll
    2017-01-01 16:52 - 2016-09-15 18:46 - 00795648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MiracastReceiver.dll
    2017-01-01 16:52 - 2016-09-15 18:46 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
    2017-01-01 16:52 - 2016-09-15 18:45 - 02642944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
    2017-01-01 16:52 - 2016-09-15 18:44 - 02153984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi.dll
    2017-01-01 16:52 - 2016-09-15 18:44 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAC3ENC.DLL
    2017-01-01 16:52 - 2016-09-15 18:43 - 03520512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
    2017-01-01 16:52 - 2016-09-15 18:43 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imapi2.dll
    2017-01-01 16:52 - 2016-09-15 18:43 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToReceiver.dll
    2017-01-01 16:52 - 2016-09-15 18:43 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdhid.sys
    2017-01-01 16:52 - 2016-09-15 18:43 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmintegrator.dll
    2017-01-01 16:52 - 2016-09-15 18:42 - 01220608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
    2017-01-01 16:52 - 2016-09-15 18:42 - 00719872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_sr.dll
    2017-01-01 16:52 - 2016-09-15 18:42 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
    2017-01-01 16:52 - 2016-09-15 18:41 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\unimdm.tsp
    2017-01-01 16:52 - 2016-09-15 18:41 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Printers.dll
    2017-01-01 16:52 - 2016-09-15 18:40 - 01988096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
    2017-01-01 16:52 - 2016-09-15 18:40 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.XboxLive.Storage.dll
    2017-01-01 16:52 - 2016-09-15 18:40 - 00082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.UserDeviceAssociation.dll
    2017-01-01 16:52 - 2016-09-15 18:39 - 02740224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
    2017-01-01 16:52 - 2016-09-15 18:39 - 00827904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
    2017-01-01 16:52 - 2016-09-15 18:39 - 00418304 _____ C:\WINDOWS\system32\Windows.Perception.Stub.dll
    2017-01-01 16:52 - 2016-09-15 18:39 - 00295936 _____ (Microsoft Corporation) C:\WINDOWS\system32\pdh.dll
    2017-01-01 16:52 - 2016-09-15 18:38 - 00773120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
    2017-01-01 16:52 - 2016-09-15 18:38 - 00730112 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
    2017-01-01 16:52 - 2016-09-15 18:38 - 00620544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
    2017-01-01 16:52 - 2016-09-15 18:38 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
    2017-01-01 16:52 - 2016-09-15 18:38 - 00205824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
    2017-01-01 16:52 - 2016-09-15 18:38 - 00132096 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintWSDAHost.dll
    2017-01-01 16:52 - 2016-09-15 18:37 - 01507840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.FaceAnalysis.dll
    2017-01-01 16:52 - 2016-09-15 18:37 - 00680448 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
    2017-01-01 16:52 - 2016-09-15 18:37 - 00568320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.LowLevel.dll
    2017-01-01 16:52 - 2016-09-15 18:37 - 00390144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
    2017-01-01 16:52 - 2016-09-15 18:37 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll
    2017-01-01 16:52 - 2016-09-15 18:36 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.dll
    2017-01-01 16:52 - 2016-09-15 18:36 - 00349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
    2017-01-01 16:52 - 2016-09-15 18:36 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovslegacy.dll
    2017-01-01 16:52 - 2016-09-15 18:35 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
    2017-01-01 16:52 - 2016-09-15 18:35 - 00538112 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
    2017-01-01 16:52 - 2016-09-15 18:35 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
    2017-01-01 16:52 - 2016-09-15 18:35 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataExchange.dll
    2017-01-01 16:52 - 2016-09-15 18:35 - 00252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
    2017-01-01 16:52 - 2016-09-15 18:34 - 00671744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mbsmsapi.dll
    2017-01-01 16:52 - 2016-09-15 18:34 - 00642048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.InkControls.dll
    2017-01-01 16:52 - 2016-09-15 18:34 - 00441856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AccountsRt.dll
    2017-01-01 16:52 - 2016-09-15 18:33 - 00896512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
    2017-01-01 16:52 - 2016-09-15 18:32 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
    2017-01-01 16:52 - 2016-09-15 18:30 - 01639424 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
    2017-01-01 16:52 - 2016-09-15 18:30 - 01403392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll
    2017-01-01 16:52 - 2016-09-15 18:30 - 01227264 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll
    2017-01-01 16:52 - 2016-09-15 18:30 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTMediaFrame.dll
    2017-01-01 16:52 - 2016-09-15 18:30 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
    2017-01-01 16:52 - 2016-09-15 18:30 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Energy.dll
    2017-01-01 16:52 - 2016-09-15 18:28 - 00442368 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
    2017-01-01 16:52 - 2016-09-15 18:27 - 01078784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
    2017-01-01 16:52 - 2016-09-15 18:27 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceControl.dll
    2017-01-01 16:52 - 2016-09-15 18:27 - 00279040 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
    2017-01-01 16:52 - 2016-09-15 18:27 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\manage-bde.exe
    2017-01-01 16:52 - 2016-09-15 18:27 - 00171008 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvenotify.exe
    2017-01-01 16:52 - 2016-09-15 18:26 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToReceiver.dll
    2017-01-01 16:52 - 2016-09-15 18:26 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
    2017-01-01 16:52 - 2016-09-15 18:26 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdeui.dll
    2017-01-01 16:52 - 2016-09-15 18:25 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
    2017-01-01 16:52 - 2016-09-15 18:25 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\BackgroundMediaPolicy.dll
    2017-01-01 16:52 - 2016-09-15 18:24 - 04596224 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
    2017-01-01 16:52 - 2016-09-15 18:24 - 01080320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Ocr.dll
    2017-01-01 16:52 - 2016-09-15 18:23 - 03405824 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
    2017-01-01 16:52 - 2016-09-15 18:23 - 01040896 _____ (Microsoft Corporation) C:\WINDOWS\system32\NaturalLanguage6.dll
    2017-01-01 16:52 - 2016-09-15 18:21 - 02538496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
    2017-01-01 16:52 - 2016-09-15 18:21 - 02208768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll
    2017-01-01 16:52 - 2016-09-15 18:21 - 00971264 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
    2017-01-01 16:52 - 2016-09-15 18:20 - 02424320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Perception.dll
    2017-01-01 16:52 - 2016-09-15 18:20 - 01535488 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll
    2017-01-01 16:52 - 2016-09-15 18:20 - 00845824 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
    2017-01-01 16:52 - 2016-09-15 18:19 - 01424896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll
    2017-01-01 16:52 - 2016-09-15 18:19 - 00903680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
    2017-01-01 16:52 - 2016-09-15 18:18 - 01369088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
    2017-01-01 16:52 - 2016-09-07 07:29 - 00523712 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMRServer.dll
    2017-01-01 16:52 - 2016-09-07 07:29 - 00118112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\EhStorTcgDrv.sys
    2017-01-01 16:52 - 2016-09-07 07:17 - 00782176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
    2017-01-01 16:52 - 2016-09-07 07:00 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosTrace.dll
    2017-01-01 16:52 - 2016-09-07 07:00 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosHost.dll
    2017-01-01 16:52 - 2016-09-07 06:59 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosResource.dll
    2017-01-01 16:52 - 2016-09-07 06:59 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MapControls.dll
    2017-01-01 16:52 - 2016-09-07 06:59 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
    2017-01-01 16:52 - 2016-09-07 06:59 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlStringsRes.dll
    2017-01-01 16:52 - 2016-09-07 06:58 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll
    2017-01-01 16:52 - 2016-09-07 06:58 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6r.dll
    2017-01-01 16:52 - 2016-09-07 06:56 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\system32\XamlTileRender.dll
    2017-01-01 16:52 - 2016-09-07 06:55 - 06574592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
    2017-01-01 16:52 - 2016-09-07 06:54 - 00468992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
    2017-01-01 16:52 - 2016-09-07 06:54 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
    2017-01-01 16:52 - 2016-09-07 06:54 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappprxy.dll
    2017-01-01 16:52 - 2016-09-07 06:53 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappgnui.dll
    2017-01-01 16:52 - 2016-09-07 06:52 - 00536576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll
    2017-01-01 16:52 - 2016-09-07 06:52 - 00289280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NmaDirect.dll
    2017-01-01 16:52 - 2016-09-07 06:52 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapp3hst.dll
    2017-01-01 16:52 - 2016-09-07 06:50 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapphost.dll
    2017-01-01 16:52 - 2016-09-07 06:47 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappcfg.dll
    2017-01-01 16:52 - 2016-09-07 06:46 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll
    2017-01-01 16:52 - 2016-09-07 06:45 - 00248320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
    2017-01-01 16:52 - 2016-09-07 06:43 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
    2017-01-01 16:52 - 2016-09-07 06:39 - 03116544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAJApi.dll
    2017-01-01 16:52 - 2016-09-07 06:39 - 00895488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
    2017-01-01 16:52 - 2016-09-07 06:37 - 00540160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
    2017-01-01 16:52 - 2016-09-07 06:36 - 02423296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAJApi.dll
    2017-01-01 16:52 - 2016-09-07 06:34 - 04557824 _____ (Microsoft) C:\WINDOWS\SysWOW64\dbgeng.dll
    2017-01-01 16:52 - 2016-09-07 06:34 - 00444416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
    2017-01-01 16:52 - 2016-09-07 06:31 - 00461312 _____ (Microsoft) C:\WINDOWS\SysWOW64\DbgModel.dll
    2017-01-01 16:52 - 2016-08-27 07:12 - 00244816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
    2017-01-01 16:52 - 2016-08-27 06:58 - 00121368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
    2017-01-01 16:52 - 2016-08-27 06:43 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\encapi.dll
    2017-01-01 16:52 - 2016-08-20 07:34 - 00136032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostUser.dll
    2017-01-01 16:52 - 2016-08-20 07:17 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerSvc.dll
    2017-01-01 16:52 - 2016-08-20 07:12 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
    2017-01-01 16:52 - 2016-08-20 07:07 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
    2017-01-01 16:52 - 2016-08-20 07:04 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
    2017-01-01 16:52 - 2016-08-20 06:58 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi_passthru.dll
    2017-01-01 16:52 - 2016-08-20 06:56 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\delegatorprovider.dll
    2017-01-01 16:52 - 2016-08-06 06:17 - 00790760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
    2017-01-01 16:52 - 2016-08-06 06:16 - 00073568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
    2017-01-01 16:52 - 2016-08-06 06:16 - 00020320 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
    2017-01-01 16:52 - 2016-08-06 06:13 - 01847048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
    2017-01-01 16:52 - 2016-08-06 06:03 - 01343928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
    2017-01-01 16:52 - 2016-08-06 05:48 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwmp.dll
    2017-01-01 16:52 - 2016-08-06 05:48 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spwmp.dll
    2017-01-01 16:52 - 2016-08-06 05:48 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdxm.ocx
    2017-01-01 16:52 - 2016-08-06 05:48 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxmasf.dll
    2017-01-01 16:52 - 2016-08-06 05:47 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidusb.sys
    2017-01-01 16:52 - 2016-08-06 05:47 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdxm.ocx
    2017-01-01 16:52 - 2016-08-06 05:47 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxmasf.dll
    2017-01-01 16:52 - 2016-08-06 05:46 - 09260032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmploc.DLL
    2017-01-01 16:52 - 2016-08-06 05:46 - 09260032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmploc.DLL
    2017-01-01 16:52 - 2016-08-06 05:46 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys
    2017-01-01 16:52 - 2016-08-06 05:45 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
    2017-01-01 16:52 - 2016-08-06 05:43 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_WorkAccess.dll
    2017-01-01 16:52 - 2016-08-06 05:41 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncPolicy.dll
    2017-01-01 16:52 - 2016-08-06 05:40 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncPolicy.dll
    2017-01-01 16:52 - 2016-08-06 05:33 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smphost.dll
    2017-01-01 16:52 - 2016-08-05 11:14 - 01066328 _____ (Microsoft Corporation) C:\WINDOWS\system32\pidgenx.dll
    2017-01-01 16:52 - 2016-08-05 11:10 - 00939872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pidgenx.dll
    2017-01-01 16:52 - 2016-08-05 11:05 - 00665768 _____ (Microsoft Corporation) C:\WINDOWS\system32\GenValObj.exe
    2017-01-01 16:52 - 2016-08-05 10:28 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\slcext.dll
    2017-01-01 16:52 - 2016-08-05 10:22 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppc.dll
    2017-01-01 16:52 - 2016-08-05 10:08 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\slc.dll
    2017-01-01 16:52 - 2016-08-02 10:15 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
    2017-01-01 16:52 - 2016-07-22 03:18 - 00297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtapi.dll
    2017-01-01 16:51 - 2016-12-09 12:42 - 01637728 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
    2017-01-01 16:51 - 2016-12-09 12:42 - 00137568 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
    2017-01-01 16:51 - 2016-12-09 12:34 - 01051112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
    2017-01-01 16:51 - 2016-12-09 12:34 - 00894096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
    2017-01-01 16:51 - 2016-12-09 12:33 - 01354320 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
    2017-01-01 16:51 - 2016-12-09 12:33 - 01173496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
    2017-01-01 16:51 - 2016-12-09 12:30 - 00377184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
    2017-01-01 16:51 - 2016-12-09 12:28 - 00764392 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
    2017-01-01 16:51 - 2016-12-09 12:27 - 00172528 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
    2017-01-01 16:51 - 2016-12-09 12:20 - 02677544 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
    2017-01-01 16:51 - 2016-12-09 12:20 - 02189664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
    2017-01-01 16:51 - 2016-12-09 12:20 - 01738560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
    2017-01-01 16:51 - 2016-12-09 12:20 - 00658784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
    2017-01-01 16:51 - 2016-12-09 12:20 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
    2017-01-01 16:51 - 2016-12-09 12:19 - 00168424 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll
    2017-01-01 16:51 - 2016-12-09 12:18 - 02913144 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
    2017-01-01 16:51 - 2016-12-09 12:18 - 01267512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
    2017-01-01 16:51 - 2016-12-09 12:11 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
    2017-01-01 16:51 - 2016-12-09 12:10 - 01572768 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
    2017-01-01 16:51 - 2016-12-09 12:10 - 01461200 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
    2017-01-01 16:51 - 2016-12-09 12:01 - 00861024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
    2017-01-01 16:51 - 2016-12-09 12:00 - 00106896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll
    2017-01-01 16:51 - 2016-12-09 11:59 - 02166752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
    2017-01-01 16:51 - 2016-12-09 11:59 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
    2017-01-01 16:51 - 2016-12-09 11:57 - 06668040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
    2017-01-01 16:51 - 2016-12-09 11:56 - 00959112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
    2017-01-01 16:51 - 2016-12-09 11:52 - 01415752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
    2017-01-01 16:51 - 2016-12-09 11:42 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
    2017-01-01 16:51 - 2016-12-09 11:41 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
    2017-01-01 16:51 - 2016-12-09 11:34 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
    2017-01-01 16:51 - 2016-12-09 11:31 - 03689984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
    2017-01-01 16:51 - 2016-12-09 11:28 - 01004544 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
    2017-01-01 16:51 - 2016-12-09 11:21 - 04746752 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
    2017-01-01 16:51 - 2016-12-09 11:21 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
    2017-01-01 16:51 - 2016-12-09 11:20 - 03198464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
    2017-01-01 16:51 - 2016-12-09 11:20 - 00730624 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
    2017-01-01 16:51 - 2016-12-09 11:20 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
    2017-01-01 16:51 - 2016-12-09 11:20 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
    2017-01-01 16:51 - 2016-12-09 11:18 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
    2017-01-01 16:51 - 2016-12-09 11:18 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
    2017-01-01 16:51 - 2016-12-09 11:17 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
    2017-01-01 16:51 - 2016-12-09 10:54 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
    2017-01-01 16:51 - 2016-11-11 12:14 - 02186896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
    2017-01-01 16:51 - 2016-11-11 12:13 - 02213760 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
    2017-01-01 16:51 - 2016-11-11 12:13 - 01886344 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
    2017-01-01 16:51 - 2016-11-11 12:12 - 00128352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
    2017-01-01 16:51 - 2016-11-11 12:08 - 00142176 _____ (Microsoft Corporation) C:\WINDOWS\system32\migisol.dll
    2017-01-01 16:51 - 2016-11-11 12:03 - 01069720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
    2017-01-01 16:51 - 2016-11-11 12:03 - 00266544 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
    2017-01-01 16:51 - 2016-11-11 12:02 - 02828376 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
    2017-01-01 16:51 - 2016-11-11 12:01 - 07219672 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
    2017-01-01 16:51 - 2016-11-11 12:01 - 00637400 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
    2017-01-01 16:51 - 2016-11-11 12:00 - 00223584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
    2017-01-01 16:51 - 2016-11-11 11:59 - 00433504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
    2017-01-01 16:51 - 2016-11-11 11:56 - 04673304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
    2017-01-01 16:51 - 2016-11-11 11:56 - 00424616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
    2017-01-01 16:51 - 2016-11-11 11:54 - 01418312 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
    2017-01-01 16:51 - 2016-11-11 11:31 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
    2017-01-01 16:51 - 2016-11-11 11:26 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
    2017-01-01 16:51 - 2016-11-11 11:26 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
    2017-01-01 16:51 - 2016-11-11 11:26 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReportingCSP.dll
    2017-01-01 16:51 - 2016-11-11 11:26 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgentc.exe
    2017-01-01 16:51 - 2016-11-11 11:25 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\BcastDVRHelper.dll
    2017-01-01 16:51 - 2016-11-11 11:25 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
    2017-01-01 16:51 - 2016-11-11 11:25 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
    2017-01-01 16:51 - 2016-11-11 11:25 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
    2017-01-01 16:51 - 2016-11-11 11:25 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
    2017-01-01 16:51 - 2016-11-11 11:24 - 00170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
    2017-01-01 16:51 - 2016-11-11 11:24 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
    2017-01-01 16:51 - 2016-11-11 11:24 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll
    2017-01-01 16:51 - 2016-11-11 11:23 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
    2017-01-01 16:51 - 2016-11-11 11:23 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll
    2017-01-01 16:51 - 2016-11-11 11:23 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\EAMProgressHandler.dll
    2017-01-01 16:51 - 2016-11-11 11:22 - 00489472 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
    2017-01-01 16:51 - 2016-11-11 11:22 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\EDPCleanup.exe
    2017-01-01 16:51 - 2016-11-11 11:22 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
    2017-01-01 16:51 - 2016-11-11 11:21 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
    2017-01-01 16:51 - 2016-11-11 11:21 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
    2017-01-01 16:51 - 2016-11-11 11:21 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
    2017-01-01 16:51 - 2016-11-11 11:20 - 00657920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
    2017-01-01 16:51 - 2016-11-11 11:20 - 00641024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
    2017-01-01 16:51 - 2016-11-11 11:20 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
    2017-01-01 16:51 - 2016-11-11 11:20 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
    2017-01-01 16:51 - 2016-11-11 11:20 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
    2017-01-01 16:51 - 2016-11-11 11:20 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
    2017-01-01 16:51 - 2016-11-11 11:20 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
    2017-01-01 16:51 - 2016-11-11 11:20 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
    2017-01-01 16:51 - 2016-11-11 11:20 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll
    2017-01-01 16:51 - 2016-11-11 11:19 - 00620544 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
    2017-01-01 16:51 - 2016-11-11 11:19 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
    2017-01-01 16:51 - 2016-11-11 11:19 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
    2017-01-01 16:51 - 2016-11-11 11:19 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
    2017-01-01 16:51 - 2016-11-11 11:19 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll
    2017-01-01 16:51 - 2016-11-11 11:19 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
    2017-01-01 16:51 - 2016-11-11 11:18 - 02084352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll
    2017-01-01 16:51 - 2016-11-11 11:18 - 00967168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
    2017-01-01 16:51 - 2016-11-11 11:16 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
    2017-01-01 16:51 - 2016-11-11 11:16 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
    2017-01-01 16:51 - 2016-11-11 11:15 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe
    2017-01-01 16:51 - 2016-11-11 11:14 - 00615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
    2017-01-01 16:51 - 2016-11-11 11:14 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppnp.dll
    2017-01-01 16:51 - 2016-11-11 11:13 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcuiu.dll
    2017-01-01 16:51 - 2016-11-11 11:09 - 01366016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
    2017-01-01 16:51 - 2016-11-11 11:09 - 00164352 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll
    2017-01-01 16:51 - 2016-11-11 11:07 - 03441152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
    2017-01-01 16:51 - 2016-11-11 11:07 - 02953216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
    2017-01-01 16:51 - 2016-11-11 11:07 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
    2017-01-01 16:51 - 2016-11-11 11:07 - 01691136 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
    2017-01-01 16:51 - 2016-11-11 11:07 - 01060864 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
    2017-01-01 16:51 - 2016-11-11 11:07 - 00779776 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscui.dll
    2017-01-01 16:51 - 2016-11-11 11:07 - 00347648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
    2017-01-01 16:51 - 2016-11-11 11:06 - 03400192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll
    2017-01-01 16:51 - 2016-11-11 11:06 - 00960000 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
    2017-01-01 16:51 - 2016-11-11 11:05 - 01779712 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
    2017-01-01 16:51 - 2016-11-11 11:05 - 01031680 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
    2017-01-01 16:51 - 2016-11-11 11:04 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll
    2017-01-01 16:51 - 2016-11-11 11:04 - 02611200 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll
    2017-01-01 16:51 - 2016-11-11 11:04 - 01709056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
    2017-01-01 16:51 - 2016-11-11 11:04 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll
    2017-01-01 16:51 - 2016-11-11 11:04 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
    2017-01-01 16:51 - 2016-11-11 11:04 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
    2017-01-01 16:51 - 2016-11-11 11:03 - 04708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
    2017-01-01 16:51 - 2016-11-11 11:03 - 02669056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
    2017-01-01 16:51 - 2016-11-11 11:03 - 02287616 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
    2017-01-01 16:51 - 2016-11-11 11:03 - 00905216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
    2017-01-01 16:51 - 2016-11-11 11:03 - 00632320 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
    2017-01-01 16:51 - 2016-11-11 11:03 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll
    2017-01-01 16:51 - 2016-11-11 11:02 - 00936448 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
    2017-01-01 16:51 - 2016-11-11 10:01 - 01969912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll
    2017-01-01 16:51 - 2016-11-11 10:00 - 01706488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
    2017-01-01 16:51 - 2016-11-11 09:59 - 01572768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
    2017-01-01 16:51 - 2016-11-11 09:49 - 00869848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
    2017-01-01 16:51 - 2016-11-11 09:49 - 00248480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
    2017-01-01 16:51 - 2016-11-11 09:47 - 01430720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
    2017-01-01 16:51 - 2016-11-11 09:42 - 00152416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTWorkQ.dll
    2017-01-01 16:51 - 2016-11-11 09:26 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgentc.exe
    2017-01-01 16:51 - 2016-11-11 09:24 - 00519168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll
    2017-01-01 16:51 - 2016-11-11 09:19 - 01755136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll
    2017-01-01 16:51 - 2016-11-11 09:19 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
    2017-01-01 16:51 - 2016-11-11 09:18 - 01336320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
    2017-01-01 16:51 - 2016-11-11 09:18 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
    2017-01-01 16:51 - 2016-11-11 09:16 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
    2017-01-01 16:51 - 2016-11-11 09:15 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
    2017-01-01 16:51 - 2016-11-11 09:14 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
    2017-01-01 16:51 - 2016-11-11 09:12 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcuiu.dll
    2017-01-01 16:51 - 2016-11-11 09:06 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll
    2017-01-01 16:51 - 2016-11-11 09:06 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
    2017-01-01 16:51 - 2016-11-11 09:04 - 01595392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
    2017-01-01 16:51 - 2016-11-11 09:03 - 02256384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
    2017-01-01 16:51 - 2016-11-11 09:03 - 01576448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
    2017-01-01 16:51 - 2016-11-11 09:03 - 00565248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
    2017-01-01 16:51 - 2016-11-02 13:20 - 00378720 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
    2017-01-01 16:51 - 2016-11-02 13:13 - 00773720 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
    2017-01-01 16:51 - 2016-11-02 13:13 - 00423776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
    2017-01-01 16:51 - 2016-11-02 13:12 - 02255712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
    2017-01-01 16:51 - 2016-11-02 13:08 - 00602464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
    2017-01-01 16:51 - 2016-11-02 13:08 - 00576408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
    2017-01-01 16:51 - 2016-11-02 13:08 - 00186424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll
    2017-01-01 16:51 - 2016-11-02 13:08 - 00111968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
    2017-01-01 16:51 - 2016-11-02 13:04 - 00596832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
    2017-01-01 16:51 - 2016-11-02 13:03 - 02750936 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
    2017-01-01 16:51 - 2016-11-02 13:02 - 00848736 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
    2017-01-01 16:51 - 2016-11-02 13:02 - 00682816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
    2017-01-01 16:51 - 2016-11-02 13:01 - 01425000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
    2017-01-01 16:51 - 2016-11-02 12:56 - 01609920 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
    2017-01-01 16:51 - 2016-11-02 12:56 - 00628552 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
    2017-01-01 16:51 - 2016-11-02 12:56 - 00322912 _____ (Microsoft Corporation) C:\WINDOWS\system32\input.dll
    2017-01-01 16:51 - 2016-11-02 12:55 - 00048992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\iorate.sys
    2017-01-01 16:51 - 2016-11-02 12:48 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efsext.dll
    2017-01-01 16:51 - 2016-11-02 12:46 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
    2017-01-01 16:51 - 2016-11-02 12:43 - 00731136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d8.dll
    2017-01-01 16:51 - 2016-11-02 12:42 - 00549376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActionCenterCPL.dll
    2017-01-01 16:51 - 2016-11-02 12:42 - 00202752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll
    2017-01-01 16:51 - 2016-11-02 12:40 - 00548352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ddraw.dll
    2017-01-01 16:51 - 2016-11-02 12:39 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
    2017-01-01 16:51 - 2016-11-02 12:36 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ErrorDetailsUpdate.dll
    2017-01-01 16:51 - 2016-11-02 12:35 - 00336896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msinfo32.exe
    2017-01-01 16:51 - 2016-11-02 12:34 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
    2017-01-01 16:51 - 2016-11-02 12:32 - 00045056 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
    2017-01-01 16:51 - 2016-11-02 12:31 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcTok.exe
    2017-01-01 16:51 - 2016-11-02 12:31 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
    2017-01-01 16:51 - 2016-11-02 12:30 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll
    2017-01-01 16:51 - 2016-11-02 12:30 - 00321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
    2017-01-01 16:51 - 2016-11-02 12:30 - 00134144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ErrorDetails.dll
    2017-01-01 16:51 - 2016-11-02 12:30 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\dab.dll
    2017-01-01 16:51 - 2016-11-02 12:29 - 01247232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
    2017-01-01 16:51 - 2016-11-02 12:29 - 00884224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
    2017-01-01 16:51 - 2016-11-02 12:29 - 00336896 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll
    2017-01-01 16:51 - 2016-11-02 12:29 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
    2017-01-01 16:51 - 2016-11-02 12:29 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll
    2017-01-01 16:51 - 2016-11-02 12:29 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll
    2017-01-01 16:51 - 2016-11-02 12:28 - 00807424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll
    2017-01-01 16:51 - 2016-11-02 12:28 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenterCPL.dll
    2017-01-01 16:51 - 2016-11-02 12:28 - 00432128 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
    2017-01-01 16:51 - 2016-11-02 12:28 - 00411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCenter.dll
    2017-01-01 16:51 - 2016-11-02 12:28 - 00321024 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkUXBroker.dll
    2017-01-01 16:51 - 2016-11-02 12:28 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.HumanInterfaceDevice.dll
    2017-01-01 16:51 - 2016-11-02 12:28 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
    2017-01-01 16:51 - 2016-11-02 12:28 - 00240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkDesktopSettings.dll
    2017-01-01 16:51 - 2016-11-02 12:28 - 00109568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\chartv.dll
    2017-01-01 16:51 - 2016-11-02 12:27 - 01388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
    2017-01-01 16:51 - 2016-11-02 12:26 - 01509376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
    2017-01-01 16:51 - 2016-11-02 12:26 - 00798208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
    2017-01-01 16:51 - 2016-11-02 12:26 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddraw.dll
    2017-01-01 16:51 - 2016-11-02 12:26 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAnimation.dll
    2017-01-01 16:51 - 2016-11-02 12:25 - 00655872 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll
    2017-01-01 16:51 - 2016-11-02 12:25 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll
    2017-01-01 16:51 - 2016-11-02 12:24 - 00940032 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontext.dll
    2017-01-01 16:51 - 2016-11-02 12:23 - 03106304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
    2017-01-01 16:51 - 2016-11-02 12:23 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GlobCollationHost.dll
    2017-01-01 16:51 - 2016-11-02 12:23 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bowser.sys
    2017-01-01 16:51 - 2016-11-02 12:23 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ErrorDetailsUpdate.dll
    2017-01-01 16:51 - 2016-11-02 12:20 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ErrorDetails.dll
    2017-01-01 16:51 - 2016-11-02 12:19 - 01586176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
    2017-01-01 16:51 - 2016-11-02 12:19 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
    2017-01-01 16:51 - 2016-11-02 12:19 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\chartv.dll
    2017-01-01 16:51 - 2016-11-02 12:18 - 00836608 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcRefreshTask.dll
    2017-01-01 16:51 - 2016-11-02 12:17 - 01282048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
    2017-01-01 16:51 - 2016-11-02 12:17 - 00982528 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
    2017-01-01 16:51 - 2016-11-02 12:17 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
    2017-01-01 16:51 - 2016-11-02 12:16 - 02512384 _____ (Microsoft Corporation) C:\WINDOWS\system32\themecpl.dll
    2017-01-01 16:51 - 2016-11-02 12:16 - 00770560 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
    2017-01-01 16:51 - 2016-11-02 12:16 - 00629248 _____ (Microsoft Corporation) C:\WINDOWS\system32\hgcpl.dll
    2017-01-01 16:51 - 2016-11-02 12:16 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
    2017-01-01 16:51 - 2016-11-02 12:16 - 00308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenter.dll
    2017-01-01 16:51 - 2016-11-02 12:16 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
    2017-01-01 16:51 - 2016-11-02 12:15 - 01348608 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
    2017-01-01 16:51 - 2016-11-02 12:13 - 03496960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll
    2017-01-01 16:51 - 2016-11-02 12:13 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\GlobCollationHost.dll
    2017-01-01 16:51 - 2016-11-02 11:11 - 00788624 _____ C:\WINDOWS\SysWOW64\locale.nls
    2017-01-01 16:51 - 2016-11-02 11:11 - 00788624 _____ C:\WINDOWS\system32\locale.nls
    2017-01-01 16:51 - 2016-10-15 06:51 - 00595296 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
    2017-01-01 16:51 - 2016-10-15 06:51 - 00584032 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
    2017-01-01 16:51 - 2016-10-15 06:51 - 00322912 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
    2017-01-01 16:51 - 2016-10-15 06:51 - 00283488 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
    2017-01-01 16:51 - 2016-10-15 06:51 - 00232800 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
    2017-01-01 16:51 - 2016-10-15 06:51 - 00078688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
    2017-01-01 16:51 - 2016-10-15 06:48 - 00498952 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
    2017-01-01 16:51 - 2016-10-15 06:38 - 00500064 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
    2017-01-01 16:51 - 2016-10-15 06:38 - 00409952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
    2017-01-01 16:51 - 2016-10-15 06:30 - 01851696 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
    2017-01-01 16:51 - 2016-10-15 06:30 - 00557408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
    2017-01-01 16:51 - 2016-10-15 06:30 - 00509280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
    2017-01-01 16:51 - 2016-10-15 06:30 - 00341936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
    2017-01-01 16:51 - 2016-10-15 06:29 - 00908640 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvstore.dll
    2017-01-01 16:51 - 2016-10-15 06:29 - 00079200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\crashdmp.sys
    2017-01-01 16:51 - 2016-10-15 06:26 - 00160096 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostBroker.dll
    2017-01-01 16:51 - 2016-10-15 06:21 - 02537824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
    2017-01-01 16:51 - 2016-10-15 06:21 - 01100128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
    2017-01-01 16:51 - 2016-10-15 06:21 - 00584032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
    2017-01-01 16:51 - 2016-10-15 06:19 - 00272720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
    2017-01-01 16:51 - 2016-10-15 06:18 - 01556712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
    2017-01-01 16:51 - 2016-10-15 06:18 - 00749920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\drvstore.dll
    2017-01-01 16:51 - 2016-10-15 06:06 - 05685760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
    2017-01-01 16:51 - 2016-10-15 05:59 - 00272384 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfksproxy.dll
    2017-01-01 16:51 - 2016-10-15 05:59 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
    2017-01-01 16:51 - 2016-10-15 05:56 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSrvPolicyManager.dll
    2017-01-01 16:51 - 2016-10-15 05:56 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFi.dll
    2017-01-01 16:51 - 2016-10-15 05:56 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll
    2017-01-01 16:51 - 2016-10-15 05:56 - 00098816 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthRadioMedia.dll
    2017-01-01 16:51 - 2016-10-15 05:56 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BluetoothApis.dll
    2017-01-01 16:51 - 2016-10-15 05:55 - 00329216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
    2017-01-01 16:51 - 2016-10-15 05:55 - 00236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Flights.dll
    2017-01-01 16:51 - 2016-10-15 05:55 - 00142336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.WiFi.dll
    2017-01-01 16:51 - 2016-10-15 05:54 - 00717312 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskbarcpl.dll
    2017-01-01 16:51 - 2016-10-15 05:54 - 00463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
    2017-01-01 16:51 - 2016-10-15 05:54 - 00241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
    2017-01-01 16:51 - 2016-10-15 05:54 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairingFolder.dll
    2017-01-01 16:51 - 2016-10-15 05:54 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
    2017-01-01 16:51 - 2016-10-15 05:52 - 00523776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
    2017-01-01 16:51 - 2016-10-15 05:52 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\autoplay.dll
    2017-01-01 16:51 - 2016-10-15 05:51 - 00429568 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVolSSO.dll
    2017-01-01 16:51 - 2016-10-15 05:51 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore6.dll
    2017-01-01 16:51 - 2016-10-15 05:50 - 00509440 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll
    2017-01-01 16:51 - 2016-10-15 05:50 - 00438784 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDec.dll
    2017-01-01 16:51 - 2016-10-15 05:49 - 01913344 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
    2017-01-01 16:51 - 2016-10-15 05:48 - 01554944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
    2017-01-01 16:51 - 2016-10-15 05:48 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
    2017-01-01 16:51 - 2016-10-15 05:46 - 03287552 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
    2017-01-01 16:51 - 2016-10-15 05:46 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll
    2017-01-01 16:51 - 2016-10-15 05:45 - 01790464 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
    2017-01-01 16:51 - 2016-10-15 05:44 - 00636928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
    2017-01-01 16:51 - 2016-10-15 05:44 - 00470016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll
    2017-01-01 16:51 - 2016-10-15 05:43 - 00574976 _____ (Microsoft Corporation) C:\WINDOWS\system32\energy.dll
    2017-01-01 16:51 - 2016-10-15 05:42 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.MediaPlayer.dll
    2017-01-01 16:51 - 2016-10-15 05:42 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\powercfg.exe
    2017-01-01 16:51 - 2016-10-15 05:41 - 00945664 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
    2017-01-01 16:51 - 2016-10-15 05:41 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iscsiwmi.dll
    2017-01-01 16:51 - 2016-10-15 05:39 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
    2017-01-01 16:51 - 2016-10-15 05:39 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Geolocation.dll
    2017-01-01 16:51 - 2016-10-15 05:38 - 00913920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
    2017-01-01 16:51 - 2016-10-15 05:38 - 00675840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
    2017-01-01 16:51 - 2016-10-15 05:37 - 01643008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
    2017-01-01 16:51 - 2016-10-15 05:36 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
    2017-01-01 16:51 - 2016-10-15 05:36 - 00983040 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
    2017-01-01 16:51 - 2016-10-15 05:36 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
    2017-01-01 16:51 - 2016-10-15 05:36 - 00542208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
    2017-01-01 16:51 - 2016-10-15 05:36 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
    2017-01-01 16:51 - 2016-10-15 05:36 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmifw.dll
    2017-01-01 16:51 - 2016-10-15 05:35 - 03054080 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
    2017-01-01 16:51 - 2016-10-15 05:35 - 00701952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
    2017-01-01 16:51 - 2016-10-15 05:34 - 02476544 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
    2017-01-01 16:51 - 2016-10-15 05:34 - 01840640 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
    2017-01-01 16:51 - 2016-10-15 05:32 - 00886784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
    2017-01-01 16:51 - 2016-10-15 05:31 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
    2017-01-01 16:51 - 2016-10-05 12:33 - 00128864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
    2017-01-01 16:51 - 2016-10-05 12:22 - 01181536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
    2017-01-01 16:51 - 2016-10-05 12:17 - 01322848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
    2017-01-01 16:51 - 2016-10-05 12:13 - 00146784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
    2017-01-01 16:51 - 2016-10-05 12:12 - 02446696 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
    2017-01-01 16:51 - 2016-10-05 11:34 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
    2017-01-01 16:51 - 2016-10-05 11:33 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll
    2017-01-01 16:51 - 2016-10-05 11:31 - 00748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
    2017-01-01 16:51 - 2016-10-05 11:30 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
    2017-01-01 16:51 - 2016-10-05 11:29 - 01145856 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
    2017-01-01 16:51 - 2016-10-05 11:29 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
    2017-01-01 16:51 - 2016-10-05 11:28 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
    2017-01-01 16:51 - 2016-10-05 11:28 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDeviceRegistration.dll
    2017-01-01 16:51 - 2016-10-05 11:27 - 00945664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
    2017-01-01 16:51 - 2016-10-05 11:26 - 00590848 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
    2017-01-01 16:51 - 2016-10-05 11:26 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovs.dll
    2017-01-01 16:51 - 2016-10-05 11:26 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDeviceRegistration.Ngc.dll
    2017-01-01 16:51 - 2016-10-05 11:25 - 00404992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsreg.dll
    2017-01-01 16:51 - 2016-10-05 11:25 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
    2017-01-01 16:51 - 2016-10-05 11:25 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthBroker.dll
    2017-01-01 16:51 - 2016-10-05 11:21 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
    2017-01-01 16:51 - 2016-10-05 11:20 - 00661504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
    2017-01-01 16:51 - 2016-10-05 11:18 - 01656832 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
    2017-01-01 16:51 - 2016-10-05 11:18 - 00983040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
    2017-01-01 16:51 - 2016-10-05 11:18 - 00858112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
    2017-01-01 16:51 - 2016-10-05 11:18 - 00759296 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
    2017-01-01 16:51 - 2016-10-05 11:17 - 02914304 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
    2017-01-01 16:51 - 2016-10-05 11:17 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adsmsext.dll
    2017-01-01 16:51 - 2016-10-05 11:16 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
    2017-01-01 16:51 - 2016-10-05 11:16 - 00508416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
    2017-01-01 16:51 - 2016-10-05 11:15 - 00833024 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
    2017-01-01 16:51 - 2016-10-05 11:15 - 00774656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
    2017-01-01 16:51 - 2016-10-05 11:15 - 00141312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dialclient.dll
    2017-01-01 16:51 - 2016-10-05 11:14 - 01456640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
    2017-01-01 16:51 - 2016-10-05 11:14 - 01013760 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
    2017-01-01 16:51 - 2016-10-05 11:13 - 01328128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
    2017-01-01 16:51 - 2016-10-05 11:12 - 00998912 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
    2017-01-01 16:51 - 2016-10-05 11:12 - 00924672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
    2017-01-01 16:51 - 2016-10-05 11:09 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
    2017-01-01 16:51 - 2016-10-05 11:09 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
    2017-01-01 16:51 - 2016-10-05 11:07 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
    2017-01-01 16:51 - 2016-10-05 11:06 - 00850944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
    2017-01-01 16:51 - 2016-10-05 11:05 - 00751104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
    2017-01-01 16:51 - 2016-09-15 19:40 - 00965472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
    2017-01-01 16:51 - 2016-09-15 19:37 - 00402352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ws2_32.dll
    2017-01-01 16:51 - 2016-09-15 19:30 - 00646136 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
    2017-01-01 16:51 - 2016-09-15 19:29 - 01117024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
    2017-01-01 16:51 - 2016-09-15 19:29 - 00512416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
    2017-01-01 16:51 - 2016-09-15 19:29 - 00424640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ws2_32.dll
    2017-01-01 16:51 - 2016-09-15 19:29 - 00218008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
    2017-01-01 16:51 - 2016-09-15 19:29 - 00074080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vpci.sys
    2017-01-01 16:51 - 2016-09-15 19:26 - 00090400 _____ (Microsoft Corporation) C:\WINDOWS\system32\devenum.dll
    2017-01-01 16:51 - 2016-09-15 19:22 - 00433832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
    2017-01-01 16:51 - 2016-09-15 19:21 - 01000288 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
    2017-01-01 16:51 - 2016-09-15 19:20 - 00634944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
    2017-01-01 16:51 - 2016-09-15 19:16 - 01157000 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
    2017-01-01 16:51 - 2016-09-15 19:16 - 00527808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
    2017-01-01 16:51 - 2016-09-15 19:15 - 00649568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
    2017-01-01 16:51 - 2016-09-15 19:14 - 00119648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
    2017-01-01 16:51 - 2016-09-15 19:07 - 00128864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
    2017-01-01 16:51 - 2016-09-15 19:06 - 00372440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll
    2017-01-01 16:51 - 2016-09-15 19:03 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
    2017-01-01 16:51 - 2016-09-15 19:03 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
    2017-01-01 16:51 - 2016-09-15 19:01 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Radios.dll
    2017-01-01 16:51 - 2016-09-15 19:00 - 00554496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
    2017-01-01 16:51 - 2016-09-15 18:59 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unimdm.tsp
    2017-01-01 16:51 - 2016-09-15 18:59 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovslegacy.dll
    2017-01-01 16:51 - 2016-09-15 18:59 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinRtTracing.dll
    2017-01-01 16:51 - 2016-09-15 18:58 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
    2017-01-01 16:51 - 2016-09-15 18:58 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.UserDeviceAssociation.dll
    2017-01-01 16:51 - 2016-09-15 18:57 - 00392192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Input.dll
    2017-01-01 16:51 - 2016-09-15 18:57 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.LowLevel.dll
    2017-01-01 16:51 - 2016-09-15 18:57 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.XboxLive.Storage.dll
    2017-01-01 16:51 - 2016-09-15 18:57 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ClipboardServer.dll
    2017-01-01 16:51 - 2016-09-15 18:56 - 00609280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll
    2017-01-01 16:51 - 2016-09-15 18:56 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Core.dll
    2017-01-01 16:51 - 2016-09-15 18:55 - 01243136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.FaceAnalysis.dll
    2017-01-01 16:51 - 2016-09-15 18:55 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
    2017-01-01 16:51 - 2016-09-15 18:55 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.SmartCards.dll
    2017-01-01 16:51 - 2016-09-15 18:55 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetworkCollectionAgent.dll
    2017-01-01 16:51 - 2016-09-15 18:55 - 00386048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.WiFiDirect.dll
    2017-01-01 16:51 - 2016-09-15 18:55 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll
    2017-01-01 16:51 - 2016-09-15 18:54 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll
    2017-01-01 16:51 - 2016-09-15 18:54 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
    2017-01-01 16:51 - 2016-09-15 18:53 - 00819200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll
    2017-01-01 16:51 - 2016-09-15 18:53 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll
    2017-01-01 16:51 - 2016-09-15 18:53 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
    2017-01-01 16:51 - 2016-09-15 18:52 - 00445952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprapi.dll
    2017-01-01 16:51 - 2016-09-15 18:52 - 00238080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
    2017-01-01 16:51 - 2016-09-15 18:51 - 00762368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprddm.dll
    2017-01-01 16:51 - 2016-09-15 18:50 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pwrshplugin.dll
    2017-01-01 16:51 - 2016-09-15 18:49 - 00468992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.InkControls.dll
    2017-01-01 16:51 - 2016-09-15 18:46 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
    2017-01-01 16:51 - 2016-09-15 18:46 - 00343040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
    2017-01-01 16:51 - 2016-09-15 18:46 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ffbroker.dll
    2017-01-01 16:51 - 2016-09-15 18:45 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dlnashext.dll
    2017-01-01 16:51 - 2016-09-15 18:44 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
    2017-01-01 16:51 - 2016-09-15 18:42 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
    2017-01-01 16:51 - 2016-09-15 18:42 - 00492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
    2017-01-01 16:51 - 2016-09-15 18:42 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winhvr.sys
    2017-01-01 16:51 - 2016-09-15 18:42 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BackgroundMediaPolicy.dll
    2017-01-01 16:51 - 2016-09-15 18:41 - 00259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.SyncEngine.dll
    2017-01-01 16:51 - 2016-09-15 18:41 - 00156160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.Client.dll
    2017-01-01 16:51 - 2016-09-15 18:41 - 00108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.Authentication.dll
    2017-01-01 16:51 - 2016-09-15 18:41 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\NfcRadioMedia.dll
    2017-01-01 16:51 - 2016-09-15 18:40 - 02026496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
    2017-01-01 16:51 - 2016-09-15 18:40 - 01656320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Perception.dll
    2017-01-01 16:51 - 2016-09-15 18:40 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll
    2017-01-01 16:51 - 2016-09-15 18:40 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMapi.dll
    2017-01-01 16:51 - 2016-09-15 18:39 - 01232384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Maps.dll
    2017-01-01 16:51 - 2016-09-15 18:39 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Phone.dll
    2017-01-01 16:51 - 2016-09-15 18:39 - 01004544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
    2017-01-01 16:51 - 2016-09-15 18:39 - 00547840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Input.dll
    2017-01-01 16:51 - 2016-09-15 18:39 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Radios.dll
    2017-01-01 16:51 - 2016-09-15 18:38 - 00691200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
    2017-01-01 16:51 - 2016-09-15 18:38 - 00671232 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkCollectionAgent.dll
    2017-01-01 16:51 - 2016-09-15 18:38 - 00573952 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrGidsHandler.dll
    2017-01-01 16:51 - 2016-09-15 18:38 - 00505856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
    2017-01-01 16:51 - 2016-09-15 18:38 - 00427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmrdvcore.dll
    2017-01-01 16:51 - 2016-09-15 18:38 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvcext.dll
    2017-01-01 16:51 - 2016-09-15 18:38 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
    2017-01-01 16:51 - 2016-09-15 18:38 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
    2017-01-01 16:51 - 2016-09-15 18:38 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SerialCommunication.dll
    2017-01-01 16:51 - 2016-09-15 18:38 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
    2017-01-01 16:51 - 2016-09-15 18:37 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.dll
    2017-01-01 16:51 - 2016-09-15 18:37 - 00296448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlancfg.dll
    2017-01-01 16:51 - 2016-09-15 18:37 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\biwinrt.dll
    2017-01-01 16:51 - 2016-09-15 18:36 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll
    2017-01-01 16:51 - 2016-09-15 18:36 - 00719360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
    2017-01-01 16:51 - 2016-09-15 18:36 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsregcmd.exe
    2017-01-01 16:51 - 2016-09-15 18:36 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
    2017-01-01 16:51 - 2016-09-15 18:36 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\usbmon.dll
    2017-01-01 16:51 - 2016-09-15 18:36 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
    2017-01-01 16:51 - 2016-09-15 18:35 - 01060352 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll
    2017-01-01 16:51 - 2016-09-15 18:35 - 01013248 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
    2017-01-01 16:51 - 2016-09-15 18:35 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
    2017-01-01 16:51 - 2016-09-15 18:35 - 00645120 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
    2017-01-01 16:51 - 2016-09-15 18:35 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprdim.dll
    2017-01-01 16:51 - 2016-09-15 18:35 - 00472064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
    2017-01-01 16:51 - 2016-09-15 18:35 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
    2017-01-01 16:51 - 2016-09-15 18:35 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
    2017-01-01 16:51 - 2016-09-15 18:35 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Picker.dll
    2017-01-01 16:51 - 2016-09-15 18:35 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SessEnv.dll
    2017-01-01 16:51 - 2016-09-15 18:35 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
    2017-01-01 16:51 - 2016-09-15 18:35 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvc.dll
    2017-01-01 16:51 - 2016-09-15 18:35 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
    2017-01-01 16:51 - 2016-09-15 18:34 - 00560640 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll
    2017-01-01 16:51 - 2016-09-15 18:34 - 00284160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
    2017-01-01 16:51 - 2016-09-15 18:33 - 03753984 _____ (Microsoft Corporation) C:\WINDOWS\system32\bootux.dll
    2017-01-01 16:51 - 2016-09-15 18:33 - 00966144 _____ (Microsoft Corporation) C:\WINDOWS\system32\sbe.dll
    2017-01-01 16:51 - 2016-09-15 18:33 - 00512000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprapi.dll
    2017-01-01 16:51 - 2016-09-15 18:32 - 01037312 _____ (Microsoft Corporation) C:\WINDOWS\system32\nettrace.dll
    2017-01-01 16:51 - 2016-09-15 18:31 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\pwrshplugin.dll
    2017-01-01 16:51 - 2016-09-15 18:30 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\baaupdate.exe
    2017-01-01 16:51 - 2016-09-15 18:30 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CastLaunch.dll
    2017-01-01 16:51 - 2016-09-15 18:29 - 01105408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MiracastReceiver.dll
    2017-01-01 16:51 - 2016-09-15 18:29 - 01082368 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
    2017-01-01 16:51 - 2016-09-15 18:29 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
    2017-01-01 16:51 - 2016-09-15 18:29 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
    2017-01-01 16:51 - 2016-09-15 18:29 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\RelPost.exe
    2017-01-01 16:51 - 2016-09-15 18:28 - 00864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
    2017-01-01 16:51 - 2016-09-15 18:28 - 00798720 _____ (Microsoft Corporation) C:\WINDOWS\system32\pwcreator.exe
    2017-01-01 16:51 - 2016-09-15 18:28 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveprompt.exe
    2017-01-01 16:51 - 2016-09-15 18:27 - 02860032 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll
    2017-01-01 16:51 - 2016-09-15 18:27 - 00796672 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
    2017-01-01 16:51 - 2016-09-15 18:27 - 00582656 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
    2017-01-01 16:51 - 2016-09-15 18:27 - 00250368 _____ (Microsoft Corporation) C:\WINDOWS\system32\discan.dll
    2017-01-01 16:51 - 2016-09-15 18:27 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAC3ENC.DLL
    2017-01-01 16:51 - 2016-09-15 18:27 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Sens.dll
    2017-01-01 16:51 - 2016-09-15 18:26 - 00501248 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi2.dll
    2017-01-01 16:51 - 2016-09-15 18:26 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
    2017-01-01 16:51 - 2016-09-15 18:26 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdechangepin.exe
    2017-01-01 16:51 - 2016-09-15 18:25 - 00947200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_sr.dll
    2017-01-01 16:51 - 2016-09-15 18:25 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
    2017-01-01 16:51 - 2016-09-15 18:25 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
    2017-01-01 16:51 - 2016-09-15 18:25 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceAgent.exe
    2017-01-01 16:51 - 2016-09-15 18:24 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
    2017-01-01 16:51 - 2016-09-15 18:23 - 01361408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
    2017-01-01 16:51 - 2016-09-15 18:23 - 00611328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.dll
    2017-01-01 16:51 - 2016-09-15 18:22 - 01709056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
    2017-01-01 16:51 - 2016-09-15 18:22 - 00857600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprddm.dll
    2017-01-01 16:51 - 2016-09-15 18:21 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
    2017-01-01 16:51 - 2016-09-15 18:20 - 02095616 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
    2017-01-01 16:51 - 2016-09-15 18:20 - 01275392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
    2017-01-01 16:51 - 2016-09-15 18:20 - 01266176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
    2017-01-01 16:51 - 2016-09-15 18:20 - 00875520 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
    2017-01-01 16:51 - 2016-09-15 18:19 - 03202048 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
    2017-01-01 16:51 - 2016-09-15 18:19 - 01130496 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
    2017-01-01 16:51 - 2016-09-15 18:17 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\FontProvider.dll
    2017-01-01 16:51 - 2016-09-15 18:16 - 01817088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
    2017-01-01 16:51 - 2016-09-15 18:16 - 00387072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SessEnv.dll
    2017-01-01 16:51 - 2016-09-15 18:16 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\tspubwmi.dll
    2017-01-01 16:51 - 2016-09-15 18:16 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\spaceman.exe
    2017-01-01 16:51 - 2016-09-10 15:21 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\capimg.sys
    2017-01-01 16:51 - 2016-09-07 07:48 - 00379744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
    2017-01-01 16:51 - 2016-09-07 07:44 - 02049480 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
    2017-01-01 16:51 - 2016-09-07 07:34 - 00857440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
    2017-01-01 16:51 - 2016-09-07 07:34 - 00178528 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostUser.dll
    2017-01-01 16:51 - 2016-09-07 07:33 - 00681304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys
    2017-01-01 16:51 - 2016-09-07 07:33 - 00450392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
    2017-01-01 16:51 - 2016-09-07 07:29 - 00755656 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
    2017-01-01 16:51 - 2016-09-07 07:29 - 00595488 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
    2017-01-01 16:51 - 2016-09-07 07:29 - 00382272 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
    2017-01-01 16:51 - 2016-09-07 07:27 - 01362504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpmde.dll
    2017-01-01 16:51 - 2016-09-07 07:13 - 00529928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
    2017-01-01 16:51 - 2016-09-07 07:12 - 00321792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
    2017-01-01 16:51 - 2016-09-07 07:04 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
    2017-01-01 16:51 - 2016-09-07 07:03 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosResource.dll
    2017-01-01 16:51 - 2016-09-07 07:03 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
    2017-01-01 16:51 - 2016-09-07 07:03 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
    2017-01-01 16:51 - 2016-09-07 07:03 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
    2017-01-01 16:51 - 2016-09-07 07:03 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccessRes.dll
    2017-01-01 16:51 - 2016-09-07 07:02 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
    2017-01-01 16:51 - 2016-09-07 07:02 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTypeHelperUtil.dll
    2017-01-01 16:51 - 2016-09-07 07:02 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataLanguageUtil.dll
    2017-01-01 16:51 - 2016-09-07 07:02 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll
    2017-01-01 16:51 - 2016-09-07 07:02 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExtrasXmlParser.dll
    2017-01-01 16:51 - 2016-09-07 07:02 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll
    2017-01-01 16:51 - 2016-09-07 07:02 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
    2017-01-01 16:51 - 2016-09-07 07:02 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneutilRes.dll
    2017-01-01 16:51 - 2016-09-07 07:02 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneServiceRes.dll
    2017-01-01 16:51 - 2016-09-07 07:02 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlStringsRes.dll
    2017-01-01 16:51 - 2016-09-07 07:01 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
    2017-01-01 16:51 - 2016-09-07 07:01 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AddressParser.dll
    2017-01-01 16:51 - 2016-09-07 07:01 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\POSyncServices.dll
    2017-01-01 16:51 - 2016-09-07 07:00 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll
    2017-01-01 16:51 - 2016-09-07 06:59 - 00263680 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExSMime.dll
    2017-01-01 16:51 - 2016-09-07 06:59 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataPlatformHelperUtil.dll
    2017-01-01 16:51 - 2016-09-07 06:59 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactActivation.dll
    2017-01-01 16:51 - 2016-09-07 06:59 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
    2017-01-01 16:51 - 2016-09-07 06:59 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExtrasXmlParser.dll
    2017-01-01 16:51 - 2016-09-07 06:58 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll
    2017-01-01 16:51 - 2016-09-07 06:58 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\MediaFoundation.DefaultPerceptionProvider.dll
    2017-01-01 16:51 - 2016-09-07 06:58 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\POSyncServices.dll
    2017-01-01 16:51 - 2016-09-07 06:58 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AddressParser.dll
    2017-01-01 16:51 - 2016-09-07 06:58 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTypeHelperUtil.dll
    2017-01-01 16:51 - 2016-09-07 06:58 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataLanguageUtil.dll
    2017-01-01 16:51 - 2016-09-07 06:58 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccessRes.dll
    2017-01-01 16:51 - 2016-09-07 06:58 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneutilRes.dll
    2017-01-01 16:51 - 2016-09-07 06:57 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll
    2017-01-01 16:51 - 2016-09-07 06:57 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
    2017-01-01 16:51 - 2016-09-07 06:56 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll
    2017-01-01 16:51 - 2016-09-07 06:56 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactActivation.dll
    2017-01-01 16:51 - 2016-09-07 06:55 - 00820736 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll
    2017-01-01 16:51 - 2016-09-07 06:55 - 00781824 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
    2017-01-01 16:51 - 2016-09-07 06:55 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VCardParser.dll
    2017-01-01 16:51 - 2016-09-07 06:54 - 00678912 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
    2017-01-01 16:51 - 2016-09-07 06:54 - 00366592 _____ (Microsoft Corporation) C:\WINDOWS\system32\NmaDirect.dll
    2017-01-01 16:51 - 2016-09-07 06:54 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Phoneutil.dll
    2017-01-01 16:51 - 2016-09-07 06:54 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataPlatformHelperUtil.dll
    2017-01-01 16:51 - 2016-09-07 06:53 - 00526848 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
    2017-01-01 16:51 - 2016-09-07 06:53 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll
    2017-01-01 16:51 - 2016-09-07 06:50 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
    2017-01-01 16:51 - 2016-09-07 06:49 - 00260096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Phoneutil.dll
    2017-01-01 16:51 - 2016-09-07 06:46 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll
    2017-01-01 16:51 - 2016-09-07 06:41 - 01891328 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
    2017-01-01 16:51 - 2016-09-07 06:40 - 01312768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorDataService.exe
    2017-01-01 16:51 - 2016-09-07 06:39 - 05384192 _____ (Microsoft) C:\WINDOWS\system32\dbgeng.dll
    2017-01-01 16:51 - 2016-09-07 06:37 - 02370048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
    2017-01-01 16:51 - 2016-09-07 06:33 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\csrsrv.dll
    2017-01-01 16:51 - 2016-08-27 06:44 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\encapi.dll
    2017-01-01 16:51 - 2016-08-20 07:20 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
    2017-01-01 16:51 - 2016-08-20 07:15 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
    2017-01-01 16:51 - 2016-08-20 07:14 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_G18030.DLL
    2017-01-01 16:51 - 2016-08-20 07:14 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_IS2022.DLL
    2017-01-01 16:51 - 2016-08-20 07:14 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\c_GSM7.DLL
    2017-01-01 16:51 - 2016-08-20 07:08 - 00204288 _____ (Windows ® Win 7 DDK provider) C:\WINDOWS\system32\DscCoreConfProv.dll
    2017-01-01 16:51 - 2016-08-20 07:06 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
    2017-01-01 16:51 - 2016-08-20 07:00 - 00141824 _____ (Windows ® Win 7 DDK provider) C:\WINDOWS\SysWOW64\DscCoreConfProv.dll
    2017-01-01 16:51 - 2016-08-06 06:26 - 01176664 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
    2017-01-01 16:51 - 2016-08-06 06:23 - 00168800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
    2017-01-01 16:51 - 2016-08-06 06:18 - 00396168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
    2017-01-01 16:51 - 2016-08-06 06:15 - 00408600 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll
    2017-01-01 16:51 - 2016-08-06 05:48 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
    2017-01-01 16:51 - 2016-08-06 05:47 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
    2017-01-01 16:51 - 2016-08-06 05:47 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
    2017-01-01 16:51 - 2016-08-06 05:46 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\dasHost.exe
    2017-01-01 16:51 - 2016-08-06 05:46 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
    2017-01-01 16:51 - 2016-08-06 05:45 - 00327680 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
    2017-01-01 16:51 - 2016-08-06 05:45 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
    2017-01-01 16:51 - 2016-08-06 05:45 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\netiougc.exe
    2017-01-01 16:51 - 2016-08-06 05:45 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
    2017-01-01 16:51 - 2016-08-06 05:44 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbvideo.sys
    2017-01-01 16:51 - 2016-08-06 05:44 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
    2017-01-01 16:51 - 2016-08-06 05:44 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceassociation.dll
    2017-01-01 16:51 - 2016-08-06 05:43 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipboardServer.dll
    2017-01-01 16:51 - 2016-08-06 05:43 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
    2017-01-01 16:51 - 2016-08-06 05:41 - 00462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
    2017-01-01 16:51 - 2016-08-06 05:41 - 00412160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
    2017-01-01 16:51 - 2016-08-06 05:41 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
    2017-01-01 16:51 - 2016-08-06 05:40 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafpos.dll
    2017-01-01 16:51 - 2016-08-06 05:40 - 00234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcpipcfg.dll
    2017-01-01 16:51 - 2016-08-06 05:39 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifiprofilessettinghandler.dll
    2017-01-01 16:51 - 2016-08-06 05:36 - 00447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\das.dll
    2017-01-01 16:51 - 2016-08-06 05:35 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll
    2017-01-01 16:51 - 2016-08-06 05:31 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
    2017-01-01 16:51 - 2016-08-06 05:29 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
    2017-01-01 16:51 - 2016-08-06 05:29 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
    2017-01-01 16:51 - 2016-08-06 05:28 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
    2017-01-01 16:51 - 2016-08-06 05:23 - 00520192 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32time.dll
    2017-01-01 16:51 - 2016-08-06 05:21 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll
    2017-01-01 16:51 - 2016-08-06 05:19 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
    2017-01-01 16:51 - 2016-08-05 10:29 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.UXRes.dll
    2017-01-01 16:51 - 2016-08-05 10:29 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slcext.dll
    2017-01-01 16:51 - 2016-08-05 10:23 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppc.dll
    2017-01-01 16:51 - 2016-08-05 10:18 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slc.dll
    2017-01-01 16:51 - 2016-08-02 10:44 - 00114192 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
    2017-01-01 16:51 - 2016-08-02 06:47 - 00079536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
    2017-01-01 16:51 - 2016-07-22 03:25 - 00389000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtapi.dll
    2017-01-01 16:50 - 2016-12-09 11:32 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
    2017-01-01 16:50 - 2016-12-09 11:25 - 00376832 _____ (Microsoft Corporation) C:\WINDOWS\system32\CryptoWinRT.dll
    2017-01-01 16:50 - 2016-11-11 12:15 - 00198856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
    2017-01-01 16:50 - 2016-11-11 11:56 - 00163752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTWorkQ.dll
    2017-01-01 16:50 - 2016-11-11 11:27 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
    2017-01-01 16:50 - 2016-11-11 11:24 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
    2017-01-01 16:50 - 2016-11-11 11:21 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
    2017-01-01 16:50 - 2016-11-11 11:20 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupugc.exe
    2017-01-01 16:50 - 2016-11-11 11:18 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll
    2017-01-01 16:50 - 2016-11-11 11:17 - 01220096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl
    2017-01-01 16:50 - 2016-11-11 11:15 - 00282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
    2017-01-01 16:50 - 2016-11-11 11:15 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscinterop.dll
    2017-01-01 16:50 - 2016-11-11 11:11 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpoext.dll
    2017-01-01 16:50 - 2016-11-11 11:04 - 01359360 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
    2017-01-01 16:50 - 2016-11-11 11:03 - 00842240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
    2017-01-01 16:50 - 2016-11-11 09:42 - 00374448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
    2017-01-01 16:50 - 2016-11-11 09:27 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetCfgNotifyObjectHost.exe
    2017-01-01 16:50 - 2016-11-11 09:21 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
    2017-01-01 16:50 - 2016-11-11 09:20 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
    2017-01-01 16:50 - 2016-11-11 09:19 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
    2017-01-01 16:50 - 2016-11-11 09:19 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll
    2017-01-01 16:50 - 2016-11-11 09:19 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll
    2017-01-01 16:50 - 2016-11-11 09:03 - 00772608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
    2017-01-01 16:50 - 2016-11-02 13:02 - 00238056 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll
    2017-01-01 16:50 - 2016-11-02 13:02 - 00148832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
    2017-01-01 16:50 - 2016-11-02 13:01 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\input.dll
    2017-01-01 16:50 - 2016-11-02 12:48 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSpkg.dll
    2017-01-01 16:50 - 2016-11-02 12:48 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
    2017-01-01 16:50 - 2016-11-02 12:43 - 00270336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
    2017-01-01 16:50 - 2016-11-02 12:43 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
    2017-01-01 16:50 - 2016-11-02 12:31 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSpkg.dll
    2017-01-01 16:50 - 2016-11-02 12:29 - 00276992 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
    2017-01-01 16:50 - 2016-11-02 12:29 - 00139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
    2017-01-01 16:50 - 2016-11-02 12:28 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
    2017-01-01 16:50 - 2016-11-02 12:25 - 00541696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
    2017-01-01 16:50 - 2016-11-02 12:18 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\shdocvw.dll
    2017-01-01 16:50 - 2016-11-02 12:16 - 01637888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
    2017-01-01 16:50 - 2016-10-15 06:00 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
    2017-01-01 16:50 - 2016-10-15 05:56 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\esentutl.exe
    2017-01-01 16:50 - 2016-10-15 05:56 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll
    2017-01-01 16:50 - 2016-10-15 05:55 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore6.dll
    2017-01-01 16:50 - 2016-10-15 05:43 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsiwmi.dll
    2017-01-01 16:50 - 2016-10-15 05:42 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Geolocation.dll
    2017-01-01 16:50 - 2016-10-15 05:37 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmifw.dll
    2017-01-01 16:50 - 2016-10-05 11:38 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
    2017-01-01 16:50 - 2016-10-05 11:38 - 00237568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Diagnostics.dll
    2017-01-01 16:50 - 2016-10-05 11:33 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
    2017-01-01 16:50 - 2016-10-05 11:32 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.HostName.dll
    2017-01-01 16:50 - 2016-10-05 11:31 - 00561664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll
    2017-01-01 16:50 - 2016-10-05 11:31 - 00425472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
    2017-01-01 16:50 - 2016-10-05 11:28 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
    2017-01-01 16:50 - 2016-10-05 11:28 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.HostName.dll
    2017-01-01 16:50 - 2016-10-05 11:22 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
    2017-01-01 16:50 - 2016-10-05 11:20 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
    2017-01-01 16:50 - 2016-10-05 11:13 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
    2017-01-01 16:50 - 2016-10-05 11:08 - 00598528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
    2017-01-01 16:50 - 2016-10-05 11:06 - 01013248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
    2017-01-01 16:50 - 2016-09-15 19:30 - 00354264 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
    2017-01-01 16:50 - 2016-09-15 19:25 - 00280472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdeunlock.exe
    2017-01-01 16:50 - 2016-09-15 19:19 - 00361104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll
    2017-01-01 16:50 - 2016-09-15 19:16 - 00206096 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
    2017-01-01 16:50 - 2016-09-15 18:58 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlancfg.dll
    2017-01-01 16:50 - 2016-09-15 18:58 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll
    2017-01-01 16:50 - 2016-09-15 18:55 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll
    2017-01-01 16:50 - 2016-09-15 18:54 - 00747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Ocr.dll
    2017-01-01 16:50 - 2016-09-15 18:54 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mbsmsapi.dll
    2017-01-01 16:50 - 2016-09-15 18:52 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NaturalLanguage6.dll
    2017-01-01 16:50 - 2016-09-15 18:50 - 01534464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.3D.dll
    2017-01-01 16:50 - 2016-09-15 18:48 - 01320448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
    2017-01-01 16:50 - 2016-09-15 18:43 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
    2017-01-01 16:50 - 2016-09-15 18:40 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Background.SystemEventsBroker.dll
    2017-01-01 16:50 - 2016-09-15 18:38 - 00654336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
    2017-01-01 16:50 - 2016-09-15 18:38 - 00343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.Phone.dll
    2017-01-01 16:50 - 2016-09-15 18:36 - 00456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
    2017-01-01 16:50 - 2016-09-15 18:36 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
    2017-01-01 16:50 - 2016-09-15 18:35 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\rshx32.dll
    2017-01-01 16:50 - 2016-09-15 18:34 - 00437248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll
    2017-01-01 16:50 - 2016-09-15 18:33 - 00963584 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebcamUi.dll
    2017-01-01 16:50 - 2016-09-15 18:32 - 00634368 _____ (Microsoft Corporation) C:\WINDOWS\system32\StructuredQuery.dll
    2017-01-01 16:50 - 2016-09-15 18:24 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll
    2017-01-01 16:50 - 2016-09-15 18:23 - 01020928 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
    2017-01-01 16:50 - 2016-09-15 18:23 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll
    2017-01-01 16:50 - 2016-09-15 18:16 - 00531456 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
    2017-01-01 16:50 - 2016-09-07 07:54 - 00133472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
    2017-01-01 16:50 - 2016-09-07 07:24 - 00057400 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsass.exe
    2017-01-01 16:50 - 2016-09-07 07:13 - 00640976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
    2017-01-01 16:50 - 2016-09-07 07:02 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6r.dll
    2017-01-01 16:50 - 2016-09-07 07:00 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
    2017-01-01 16:50 - 2016-09-07 06:59 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappprxy.dll
    2017-01-01 16:50 - 2016-09-07 06:57 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
    2017-01-01 16:50 - 2016-09-07 06:56 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll
    2017-01-01 16:50 - 2016-09-07 06:56 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll
    2017-01-01 16:50 - 2016-09-07 06:55 - 00243200 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll
    2017-01-01 16:50 - 2016-09-07 06:54 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
    2017-01-01 16:50 - 2016-09-07 06:53 - 00302592 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll
    2017-01-01 16:50 - 2016-09-07 06:49 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
    2017-01-01 16:50 - 2016-09-07 06:46 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebcamUi.dll
    2017-01-01 16:50 - 2016-09-07 06:38 - 01555456 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
    2017-01-01 16:50 - 2016-09-07 06:35 - 00650240 _____ (Microsoft) C:\WINDOWS\system32\DbgModel.dll
    2017-01-01 16:50 - 2016-09-07 06:31 - 01293312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
    2017-01-01 16:50 - 2016-08-20 08:06 - 00108384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
    2017-01-01 16:50 - 2016-08-20 07:22 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
    2017-01-01 16:50 - 2016-08-20 07:21 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_G18030.DLL
    2017-01-01 16:50 - 2016-08-20 07:21 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
    2017-01-01 16:50 - 2016-08-20 07:21 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\c_GSM7.DLL
    2017-01-01 16:50 - 2016-08-20 07:20 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
    2017-01-01 16:50 - 2016-08-20 07:20 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
    2017-01-01 16:50 - 2016-08-20 07:20 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_IS2022.DLL
    2017-01-01 16:50 - 2016-08-20 07:19 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
    2017-01-01 16:50 - 2016-08-20 07:18 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
    2017-01-01 16:50 - 2016-08-20 07:18 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
    2017-01-01 16:50 - 2016-08-20 07:15 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
    2017-01-01 16:50 - 2016-08-20 07:14 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
    2017-01-01 16:50 - 2016-08-20 07:06 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi_passthru.dll
    2017-01-01 16:50 - 2016-08-20 07:04 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\delegatorprovider.dll
    2017-01-01 16:50 - 2016-08-19 03:33 - 00162850 _____ C:\WINDOWS\system32\C_932.NLS
    2017-01-01 16:50 - 2016-08-06 06:31 - 00041824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe
    2017-01-01 16:50 - 2016-08-06 06:29 - 00199008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
    2017-01-01 16:50 - 2016-08-06 06:16 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
    2017-01-01 16:50 - 2016-08-06 06:13 - 00044472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
    2017-01-01 16:50 - 2016-08-06 06:08 - 00313560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
    2017-01-01 16:50 - 2016-08-06 06:03 - 00036168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
    2017-01-01 16:50 - 2016-08-06 05:50 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
    2017-01-01 16:50 - 2016-08-06 05:48 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
    2017-01-01 16:50 - 2016-08-06 05:48 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
    2017-01-01 16:50 - 2016-08-06 05:48 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanhlp.dll
    2017-01-01 16:50 - 2016-08-06 05:48 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.exe
    2017-01-01 16:50 - 2016-08-06 05:46 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModelOOBE.exe
    2017-01-01 16:50 - 2016-08-06 05:45 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll
    2017-01-01 16:50 - 2016-08-06 05:45 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll
    2017-01-01 16:50 - 2016-08-06 05:45 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netiougc.exe
    2017-01-01 16:50 - 2016-08-06 05:44 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceassociation.dll
    2017-01-01 16:50 - 2016-08-06 05:39 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tcpipcfg.dll
    2017-01-01 16:50 - 2016-08-06 05:34 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\smphost.dll
    2017-01-01 16:50 - 2016-08-05 10:29 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.UXRes.dll
    2017-01-01 16:50 - 2016-08-02 10:21 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
    2017-01-01 16:50 - 2016-08-02 10:13 - 01081856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
    2017-01-01 16:50 - 2016-08-02 06:37 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
    2017-01-01 16:45 - 2017-01-01 16:45 - 00001974 _____ C:\Users\Public\Desktop\GlassWire.lnk
    2017-01-01 16:45 - 2017-01-01 16:45 - 00000000 ____D C:\Users\Unknown\AppData\Local\GlassWire
    2017-01-01 16:45 - 2017-01-01 16:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GlassWire
    2017-01-01 16:45 - 2017-01-01 16:45 - 00000000 ____D C:\ProgramData\GlassWire
    2017-01-01 16:45 - 2017-01-01 16:45 - 00000000 ____D C:\Program Files (x86)\GlassWire
    2017-01-01 16:45 - 2015-05-29 06:30 - 00008392 _____ C:\WINDOWS\system32\Drivers\gwdrv.cat
    2017-01-01 16:45 - 2015-05-29 06:15 - 00033152 _____ (SecureMix LLC) C:\WINDOWS\system32\Drivers\gwdrv.sys
    2017-01-01 14:33 - 2017-01-13 12:17 - 02047676 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2017-01-01 14:30 - 2017-01-01 14:30 - 00000000 ____D C:\ProgramData\USOShared
    2017-01-01 14:30 - 2017-01-01 14:30 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
    2017-01-01 14:28 - 2017-01-01 14:28 - 00000020 ___SH C:\Users\Unknown\ntuser.ini
    2017-01-01 14:27 - 2017-01-13 20:57 - 00002772 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
    2017-01-01 14:27 - 2017-01-11 18:36 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2017-01-01 14:27 - 2017-01-10 23:10 - 00000000 ____D C:\WINDOWS\System32\Tasks\Lenovo
    2017-01-01 14:27 - 2017-01-09 22:38 - 00001908 _____ C:\WINDOWS\diagwrn.xml
    2017-01-01 14:27 - 2017-01-09 22:38 - 00001908 _____ C:\WINDOWS\diagerr.xml
    2017-01-01 14:27 - 2017-01-08 19:52 - 00004020 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1483214677
    2017-01-01 14:27 - 2017-01-08 19:30 - 00004004 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
    2017-01-01 14:27 - 2017-01-01 14:27 - 00003394 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
    2017-01-01 14:27 - 2017-01-01 14:27 - 00003170 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
    2017-01-01 14:27 - 2017-01-01 14:27 - 00003142 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
    2017-01-01 14:27 - 2017-01-01 14:27 - 00003114 _____ C:\WINDOWS\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
    2017-01-01 14:27 - 2017-01-01 14:27 - 00003016 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
    2017-01-01 14:27 - 2017-01-01 14:27 - 00002996 _____ C:\WINDOWS\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
    2017-01-01 14:27 - 2017-01-01 14:27 - 00002944 _____ C:\WINDOWS\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
    2017-01-01 14:27 - 2017-01-01 14:27 - 00002902 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
    2017-01-01 14:25 - 2017-01-15 00:06 - 00000000 ____D C:\Users\Unknown
    2017-01-01 14:25 - 2017-01-01 14:26 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
    2017-01-01 14:25 - 2017-01-01 14:25 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
    2017-01-01 14:25 - 2017-01-01 14:25 - 00000000 ____D C:\Users\Default\AppData\Roaming\Intel Corporation
    2017-01-01 14:25 - 2017-01-01 14:25 - 00000000 ____D C:\Users\Default\AppData\Roaming\Intel
    2017-01-01 14:25 - 2017-01-01 14:25 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Intel Corporation
    2017-01-01 14:25 - 2017-01-01 14:25 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Intel
    2017-01-01 14:24 - 2017-01-01 14:25 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
    2017-01-01 14:24 - 2017-01-01 14:25 - 00000000 ____D C:\Program Files\NVIDIA Corporation
    2017-01-01 14:24 - 2017-01-01 14:24 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf
    2017-01-01 14:24 - 2016-12-11 20:47 - 06384576 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
    2017-01-01 14:24 - 2016-12-11 20:47 - 02475968 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
    2017-01-01 14:24 - 2016-12-11 20:47 - 01764408 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
    2017-01-01 14:24 - 2016-12-11 20:47 - 00548408 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
    2017-01-01 14:24 - 2016-12-11 20:47 - 00392128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
    2017-01-01 14:24 - 2016-12-11 20:47 - 00145344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\oemdspif.dll
    2017-01-01 14:24 - 2016-12-11 20:47 - 00081856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
    2017-01-01 14:24 - 2016-12-11 20:47 - 00071224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
    2017-01-01 14:24 - 2016-12-09 10:52 - 07639617 _____ C:\WINDOWS\system32\nvcoproc.bin
    2017-01-01 14:23 - 2017-01-10 23:18 - 00153349 _____ C:\WINDOWS\system32\Drivers\rtkhdasetting.zip
    2017-01-01 14:23 - 2017-01-10 23:18 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
    2017-01-01 14:23 - 2017-01-10 23:18 - 00000000 ____D C:\WINDOWS\system32\DAX2
    2017-01-01 14:23 - 2017-01-10 23:06 - 00000000 ____D C:\ProgramData\Package Cache
    2017-01-01 14:23 - 2017-01-02 17:04 - 00027136 _____ (Khronos Group) C:\WINDOWS\SysWOW64\opencl.dll
    2017-01-01 14:23 - 2017-01-01 14:25 - 00000000 ____D C:\ProgramData\Intel
    2017-01-01 14:23 - 2017-01-01 14:25 - 00000000 ____D C:\Program Files\Intel
    2017-01-01 14:23 - 2017-01-01 14:25 - 00000000 ____D C:\Program Files\Common Files\Intel
    2017-01-01 14:23 - 2017-01-01 14:25 - 00000000 ____D C:\Program Files (x86)\Realtek
    2017-01-01 14:23 - 2017-01-01 14:23 - 00000568 _____ C:\WINDOWS\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
    2017-01-01 14:23 - 2017-01-01 14:23 - 00000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
    2017-01-01 14:23 - 2017-01-01 14:23 - 00000102 _____ C:\ProgramData\Microsoft.SqlServer.Compact.400.64.bc
    2017-01-01 14:23 - 2017-01-01 14:23 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
    2017-01-01 14:23 - 2017-01-01 14:23 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
    2017-01-01 14:23 - 2017-01-01 14:23 - 00000000 ____H C:\ProgramData\DP45977C.lfl
    2017-01-01 14:23 - 2017-01-01 14:23 - 00000000 ____D C:\Program Files\Synaptics
    2017-01-01 14:23 - 2017-01-01 14:23 - 00000000 ____D C:\Program Files\Realtek
    2017-01-01 14:23 - 2017-01-01 14:23 - 00000000 _____ C:\WINDOWS\system32\GfxValDisplayLog.bin
    2017-01-01 14:23 - 2016-12-31 20:00 - 00099864 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
    2017-01-01 14:23 - 2016-07-16 13:41 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
    2017-01-01 14:22 - 2017-01-14 13:38 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
    2017-01-01 14:22 - 2017-01-11 18:36 - 00194192 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2017-01-01 14:21 - 2017-01-05 18:39 - 00000000 ____D C:\Windows.old
    2017-01-01 14:20 - 2017-01-01 14:22 - 00000000 ____D C:\WINDOWS\ServiceProfiles
    2017-01-01 14:20 - 2017-01-01 14:20 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
    2017-01-01 14:19 - 2017-01-01 14:19 - 00000000 ____D C:\WINDOWS\SysWOW64\SDA
    2017-01-01 14:19 - 2017-01-01 14:19 - 00000000 ____D C:\WINDOWS\system32\SDA
    2017-01-01 14:19 - 2017-01-01 14:19 - 00000000 ____D C:\Program Files\Reference Assemblies
    2017-01-01 14:19 - 2017-01-01 14:19 - 00000000 ____D C:\Program Files\MSBuild
    2017-01-01 14:19 - 2017-01-01 14:19 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
    2017-01-01 14:19 - 2017-01-01 14:19 - 00000000 ____D C:\Program Files (x86)\MSBuild
    2017-01-01 14:19 - 2016-05-25 14:31 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
    2017-01-01 14:19 - 2016-05-25 14:31 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
    2017-01-01 14:19 - 2016-05-25 14:31 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
    2017-01-01 14:19 - 2016-05-25 11:03 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
    2017-01-01 14:19 - 2016-05-25 11:03 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
    2017-01-01 14:19 - 2016-05-25 11:03 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
    2017-01-01 04:58 - 2017-01-02 20:01 - 00000000 ____D C:\ESD
    2017-01-01 04:26 - 2017-01-01 04:26 - 00001455 _____ C:\Users\Unknown\Desktop\Far cry 2 map editor.lnk
    2017-01-01 04:26 - 2017-01-01 04:26 - 00001435 _____ C:\Users\Unknown\Desktop\Far cry 2.lnk
    2017-01-01 01:56 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_40.dll
    2017-01-01 01:56 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_40.dll
    2017-01-01 01:56 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_40.dll
    2017-01-01 01:56 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_40.dll
    2017-01-01 01:56 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_40.dll
    2017-01-01 01:56 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_40.dll
    2017-01-01 01:49 - 2017-01-12 14:29 - 00000000 ____D C:\Users\Unknown\Documents\My Games
    2017-01-01 01:46 - 2017-01-02 02:34 - 00000000 ____D C:\Users\Unknown\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
    2017-01-01 01:46 - 2017-01-01 01:46 - 00000220 _____ C:\Users\Unknown\Desktop\Garry's Mod.url
    2017-01-01 01:44 - 2017-01-01 01:44 - 00000000 ____D C:\Users\Unknown\AppData\Local\Steam
    2017-01-01 01:43 - 2017-01-15 12:09 - 00000000 ____D C:\Program Files (x86)\Steam
    2017-01-01 01:43 - 2017-01-01 14:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
    2017-01-01 01:43 - 2017-01-01 01:43 - 00001036 _____ C:\Users\Public\Desktop\Steam.lnk
    2017-01-01 01:40 - 2017-01-01 01:40 - 00000000 ____D C:\Users\Unknown\AppData\Roaming\Intel Corporation
    2017-01-01 01:34 - 2017-01-01 14:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Realtek
    2017-01-01 01:33 - 2017-01-10 23:18 - 00000000 ___HD C:\Program Files (x86)\Temp
    2017-01-01 01:33 - 2017-01-08 19:29 - 00000000 ___HD C:\WINDOWS\system32\WLANProfiles
    2017-01-01 01:33 - 2017-01-01 01:33 - 00000000 ____D C:\Users\Unknown\AppData\Roaming\Intel
    2017-01-01 01:33 - 2016-04-11 13:38 - 02838232 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\RtlExUpd.dll
    2017-01-01 01:32 - 2017-01-15 00:05 - 00000000 ____D C:\Users\Unknown\AppData\Local\CrashDumps
    2017-01-01 01:32 - 2016-05-17 11:00 - 00937728 _____ (Realtek ) C:\WINDOWS\system32\Drivers\rt640x64.sys
    2017-01-01 01:32 - 2016-05-17 11:00 - 00091272 _____ (Realtek Semiconductor Corporation) C:\WINDOWS\system32\RtNicProp64.dll
    2017-01-01 01:31 - 2017-01-01 14:26 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
    2017-01-01 01:31 - 2017-01-01 14:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Connect2
    2017-01-01 01:31 - 2017-01-01 01:31 - 00982290 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
    2017-01-01 01:31 - 2017-01-01 01:31 - 00000000 ____D C:\Program Files (x86)\BayHubTech
    2017-01-01 01:30 - 2017-01-01 01:30 - 00000000 ____D C:\Users\Unknown\AppData\Roaming\Wargaming.net
    2017-01-01 01:15 - 2017-01-01 01:15 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_ldiagio_uefi_01009.Wdf
    2017-01-01 01:13 - 2017-01-01 01:13 - 00000000 ____D C:\Users\Unknown\AppData\Local\NetworkTiles
    2016-12-31 23:10 - 2016-12-31 23:10 - 00000000 ____D C:\Users\Unknown\AppData\LocalLow\Lenovo
    2016-12-31 23:09 - 2017-01-02 01:54 - 00000000 ____D C:\Users\Unknown\AppData\Local\Lenovo
    2016-12-31 22:51 - 2017-01-12 14:27 - 00028116 _____ C:\WINDOWS\DirectX.log
    2016-12-31 22:51 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_7.dll
    2016-12-31 22:51 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll
    2016-12-31 22:51 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_7.dll
    2016-12-31 22:51 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_7.dll
    2016-12-31 22:51 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll
    2016-12-31 22:51 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_5.dll
    2016-12-31 22:51 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll
    2016-12-31 22:51 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_43.dll
    2016-12-31 22:51 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_43.dll
    2016-12-31 22:51 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_43.dll
    2016-12-31 22:51 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_6.dll
    2016-12-31 22:51 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_6.dll
    2016-12-31 22:51 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_6.dll
    2016-12-31 22:51 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_6.dll
    2016-12-31 22:51 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_4.dll
    2016-12-31 22:51 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_4.dll
    2016-12-31 22:51 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_7.dll
    2016-12-31 22:51 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_7.dll
    2016-12-31 22:51 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_5.dll
    2016-12-31 22:51 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_5.dll
    2016-12-31 22:51 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_5.dll
    2016-12-31 22:51 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_5.dll
    2016-12-31 22:51 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_3.dll
    2016-12-31 22:51 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_3.dll
    2016-12-31 22:51 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_42.dll
    2016-12-31 22:51 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_42.dll
    2016-12-31 22:51 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_42.dll
    2016-12-31 22:51 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_42.dll
    2016-12-31 22:51 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_42.dll
    2016-12-31 22:51 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_42.dll
    2016-12-31 22:51 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll
    2016-12-31 22:51 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_42.dll
    2016-12-31 22:51 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_42.dll
    2016-12-31 22:51 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_42.dll
    2016-12-31 22:51 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_4.dll
    2016-12-31 22:51 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_4.dll
    2016-12-31 22:51 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_4.dll
    2016-12-31 22:51 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_4.dll
    2016-12-31 22:51 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_6.dll
    2016-12-31 22:51 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_6.dll
    2016-12-31 22:51 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_41.dll
    2016-12-31 22:51 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_41.dll
    2016-12-31 22:51 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_41.dll
    2016-12-31 22:51 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_41.dll
    2016-12-31 22:51 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_41.dll
    2016-12-31 22:51 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_41.dll
    2016-12-31 22:51 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_3.dll
    2016-12-31 22:51 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_3.dll
    2016-12-31 22:51 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_3.dll
    2016-12-31 22:51 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_3.dll
    2016-12-31 22:51 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_2.dll
    2016-12-31 22:51 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_2.dll
    2016-12-31 22:51 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_5.dll
    2016-12-31 22:51 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_5.dll
    2016-12-31 22:51 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_2.dll
    2016-12-31 22:51 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_2.dll
    2016-12-31 22:51 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_1.dll
    2016-12-31 22:51 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_1.dll
    2016-12-31 22:51 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_2.dll
    2016-12-31 22:51 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_2.dll
    2016-12-31 22:51 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll
    2016-12-31 22:51 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_39.dll
    2016-12-31 22:51 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll
    2016-12-31 22:51 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_39.dll
    2016-12-31 22:51 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll
    2016-12-31 22:51 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_39.dll
    2016-12-31 22:51 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_1.dll
    2016-12-31 22:51 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_1.dll
    2016-12-31 22:51 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_1.dll
    2016-12-31 22:51 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_1.dll
    2016-12-31 22:51 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_0.dll
    2016-12-31 22:51 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_0.dll
    2016-12-31 22:51 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_4.dll
    2016-12-31 22:51 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_4.dll
    2016-12-31 22:51 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_38.dll
    2016-12-31 22:51 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_38.dll
    2016-12-31 22:51 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_38.dll
    2016-12-31 22:51 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_38.dll
    2016-12-31 22:51 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_38.dll
    2016-12-31 22:51 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_38.dll
    2016-12-31 22:51 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_0.dll
    2016-12-31 22:51 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_0.dll
    2016-12-31 22:51 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_0.dll
    2016-12-31 22:51 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_0.dll
    2016-12-31 22:51 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_3.dll
    2016-12-31 22:51 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_3.dll
    2016-12-31 22:51 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_37.dll
    2016-12-31 22:51 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_37.dll
    2016-12-31 22:51 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_37.dll
    2016-12-31 22:51 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_37.dll
    2016-12-31 22:51 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_37.dll
    2016-12-31 22:51 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_37.dll
    2016-12-31 22:51 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_10.dll
    2016-12-31 22:51 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_10.dll
    2016-12-31 22:51 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_2.dll
    2016-12-31 22:51 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_2.dll
    2016-12-31 22:51 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_36.dll
    2016-12-31 22:51 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_36.dll
    2016-12-31 22:51 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_36.dll
    2016-12-31 22:51 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_36.dll
    2016-12-31 22:51 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_36.dll
    2016-12-31 22:51 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_36.dll
    2016-12-31 22:51 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_9.dll
    2016-12-31 22:51 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_9.dll
    2016-12-31 22:51 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_35.dll
    2016-12-31 22:51 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_35.dll
    2016-12-31 22:51 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_35.dll
    2016-12-31 22:51 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_35.dll
    2016-12-31 22:51 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_35.dll
    2016-12-31 22:51 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_35.dll
    2016-12-31 22:51 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_8.dll
    2016-12-31 22:51 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_8.dll
    2016-12-31 22:51 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_34.dll
    2016-12-31 22:51 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_34.dll
    2016-12-31 22:51 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_34.dll
    2016-12-31 22:51 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_34.dll
    2016-12-31 22:51 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_34.dll
    2016-12-31 22:51 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_34.dll
    2016-12-31 22:51 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_7.dll
    2016-12-31 22:51 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_7.dll
    2016-12-31 22:51 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_3.dll
    2016-12-31 22:51 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_3.dll
    2016-12-31 22:51 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_33.dll
    2016-12-31 22:51 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_33.dll
    2016-12-31 22:51 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_33.dll
    2016-12-31 22:51 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_33.dll
    2016-12-31 22:51 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_33.dll
    2016-12-31 22:51 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_33.dll
    2016-12-31 22:51 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_1.dll
    2016-12-31 22:51 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_1.dll
    2016-12-31 22:51 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_6.dll
    2016-12-31 22:51 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_6.dll
    2016-12-31 22:51 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_5.dll
    2016-12-31 22:51 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_5.dll
    2016-12-31 22:51 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_32.dll
    2016-12-31 22:51 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_32.dll
    2016-12-31 22:51 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10.dll
    2016-12-31 22:51 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10.dll
    2016-12-31 22:51 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_31.dll
    2016-12-31 22:51 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_31.dll
    2016-12-31 22:51 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_4.dll
    2016-12-31 22:51 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_4.dll
    2016-12-31 22:51 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_2.dll
    2016-12-31 22:51 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_3.dll
    2016-12-31 22:51 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_3.dll
    2016-12-31 22:51 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_2.dll
    2016-12-31 22:51 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_2.dll
    2016-12-31 22:51 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_2.dll
    2016-12-31 22:51 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_30.dll
    2016-12-31 22:51 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_30.dll
    2016-12-31 22:51 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_1.dll
    2016-12-31 22:51 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_1.dll
    2016-12-31 22:51 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_1.dll
    2016-12-31 22:51 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_1.dll
    2016-12-31 22:51 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_29.dll
    2016-12-31 22:51 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_29.dll
    2016-12-31 22:51 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_0.dll
    2016-12-31 22:51 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_0.dll
    2016-12-31 22:51 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_0.dll
    2016-12-31 22:51 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_0.dll
    2016-12-31 22:51 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_28.dll
    2016-12-31 22:51 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_28.dll
    2016-12-31 22:51 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_27.dll
    2016-12-31 22:51 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_27.dll
    2016-12-31 22:51 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_26.dll
    2016-12-31 22:51 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_26.dll
    2016-12-31 22:51 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_25.dll
    2016-12-31 22:51 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_25.dll
    2016-12-31 22:51 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_24.dll
    2016-12-31 22:51 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_24.dll
    2016-12-31 22:50 - 2017-01-01 14:26 - 00000000 ____D C:\Users\Unknown\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\World of Tanks
    2016-12-31 22:50 - 2016-12-31 22:51 - 00000000 ___HD C:\WINDOWS\msdownld.tmp
    2016-12-31 22:50 - 2016-12-31 22:50 - 00000810 _____ C:\Users\Unknown\Desktop\World of Tanks.lnk
    2016-12-31 22:36 - 2016-12-31 22:36 - 00001804 _____ C:\Users\Unknown\Desktop\Euro truck simulator 2.lnk
    2016-12-31 22:23 - 2017-01-12 17:42 - 00000000 ____D C:\Users\Unknown\Documents\Euro Truck Simulator 2
    2016-12-31 22:18 - 2017-01-12 21:14 - 00000000 ____D C:\games
    2016-12-31 22:10 - 2016-12-31 22:10 - 00000441 _____ C:\WINDOWS\SysWOW64\swhealthex.log
    2016-12-31 22:05 - 2016-12-31 22:05 - 00000000 ____D C:\Program Files (x86)\VulkanRT
    2016-12-31 22:05 - 2016-12-11 20:23 - 00134712 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
    2016-12-31 22:05 - 2016-09-09 20:25 - 00269600 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
    2016-12-31 22:05 - 2016-09-09 20:25 - 00261920 _____ C:\WINDOWS\system32\vulkan-1.dll
    2016-12-31 22:05 - 2016-09-09 20:25 - 00110880 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
    2016-12-31 22:05 - 2016-09-09 20:24 - 00125216 _____ C:\WINDOWS\system32\vulkaninfo.exe
    2016-12-31 22:04 - 2017-01-08 19:52 - 00001088 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
    2016-12-31 22:04 - 2017-01-01 19:50 - 00000000 ____D C:\Users\Unknown\AppData\Local\Google
    2016-12-31 22:04 - 2017-01-01 19:50 - 00000000 ____D C:\Program Files (x86)\Google
    2016-12-31 22:04 - 2016-12-31 22:04 - 00037144 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
    2016-12-31 22:04 - 2016-12-31 22:04 - 00002264 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
    2016-12-31 22:04 - 2016-12-31 22:04 - 00002252 _____ C:\Users\Public\Desktop\Google Chrome.lnk
    2016-12-31 22:03 - 2017-01-08 19:31 - 00001979 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
    2016-12-31 22:03 - 2017-01-08 19:31 - 00001967 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
    2016-12-31 22:03 - 2016-12-31 22:03 - 00969184 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
    2016-12-31 22:03 - 2016-12-31 22:03 - 00513632 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
    2016-12-31 22:03 - 2016-12-31 22:03 - 00293352 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
    2016-12-31 22:03 - 2016-12-31 22:03 - 00163416 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
    2016-12-31 22:03 - 2016-12-31 22:03 - 00108816 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
    2016-12-31 22:03 - 2016-12-31 22:03 - 00103064 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
    2016-12-31 22:03 - 2016-12-31 22:03 - 00074544 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
    2016-12-31 22:03 - 2016-12-31 22:03 - 00053208 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
    2016-12-31 22:03 - 2016-12-31 22:03 - 00037656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
    2016-12-31 22:03 - 2016-12-31 22:03 - 00000000 ____D C:\Users\Unknown\AppData\Roaming\AVAST Software
    2016-12-31 22:03 - 2016-12-12 05:03 - 40125496 _____ C:\WINDOWS\system32\nvcompiler.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 35222976 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 34710584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 28201408 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 10912744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 10803880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 10353960 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 09158616 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 08913328 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 08761560 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 03934504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 03474392 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 02950200 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 02587704 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 01953336 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6437633.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 01586744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6437633.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 01038392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 00974784 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 00942528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 00894400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 00802768 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 00683640 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 00643928 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 00572888 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 00438208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 00394888 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 00388544 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 00327408 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
    2016-12-31 22:03 - 2016-12-12 05:03 - 00042286 _____ C:\WINDOWS\system32\nvinfo.pb
    2016-12-31 22:03 - 2016-12-12 05:03 - 00000669 _____ C:\WINDOWS\SysWOW64\nv-vk32.json
    2016-12-31 22:03 - 2016-12-12 05:03 - 00000669 _____ C:\WINDOWS\system32\nv-vk64.json
    2016-12-31 22:02 - 2016-12-31 22:04 - 00000000 ____D C:\Program Files\AVAST Software
    2016-12-31 22:02 - 2016-12-31 22:02 - 00044640 _____ (The OpenVPN Project) C:\WINDOWS\system32\Drivers\aswTap.sys
    2016-12-31 22:01 - 2016-12-31 22:04 - 00000000 ____D C:\ProgramData\AVAST Software
    2016-12-31 21:54 - 2017-01-15 12:09 - 00013767 _____ C:\ProgramData\NvTelemetryContainer.log
    2016-12-31 21:54 - 2017-01-12 22:06 - 00000000 ____D C:\Users\Unknown\AppData\Local\NVIDIA Corporation
    2016-12-31 21:54 - 2017-01-11 00:24 - 00005943 _____ C:\ProgramData\NvTelemetryContainer.log_backup1
    2016-12-31 21:54 - 2017-01-01 14:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
    2016-12-31 21:54 - 2016-12-31 21:54 - 00000000 ____D C:\Users\Unknown\AppData\Local\CEF
    2016-12-31 21:54 - 2016-12-13 01:30 - 01853376 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
    2016-12-31 21:54 - 2016-12-13 01:30 - 01755072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
    2016-12-31 21:54 - 2016-12-13 01:30 - 01452480 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
    2016-12-31 21:54 - 2016-12-13 01:30 - 01317312 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
    2016-12-31 21:54 - 2016-12-13 01:30 - 00120256 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll
    2016-12-31 21:54 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_43.dll
    2016-12-31 21:54 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_43.dll
    2016-12-31 21:54 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_43.dll
    2016-12-31 21:54 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_43.dll
    2016-12-31 21:54 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll
    2016-12-31 21:54 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_43.dll
    2016-12-31 21:53 - 2016-12-13 01:30 - 00156096 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
    2016-12-31 21:53 - 2016-12-13 01:30 - 00123840 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
    2016-12-31 21:53 - 2016-12-13 01:30 - 00046016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
    2016-12-31 21:53 - 2016-12-12 16:36 - 00001951 _____ C:\WINDOWS\NvTelemetryContainerRecovery.bat
    2016-12-31 21:53 - 2016-12-11 20:47 - 00001951 _____ C:\WINDOWS\NvContainerRecovery.bat
    2016-12-31 21:32 - 2016-12-31 21:32 - 00000000 ____D C:\Users\Unknown\AppData\Local\Comms
    2016-12-31 21:31 - 2016-12-31 22:18 - 00000000 ____D C:\Users\Unknown\AppData\Local\ConnectedDevicesPlatform
    2016-12-31 21:30 - 2017-01-11 18:36 - 00014372 _____ C:\WINDOWS\PFRO.log
    2016-12-31 21:30 - 2017-01-01 14:27 - 00022840 _____ C:\WINDOWS\system32\emptyregdb.dat
    2016-12-31 21:27 - 2017-01-15 12:09 - 00000000 ____D C:\ProgramData\NVIDIA
    2016-12-31 21:23 - 2016-12-31 21:23 - 00064352 ____N (Avago Technologies) C:\WINDOWS\system32\Drivers\MegaSas2i.sys
    2016-12-31 21:13 - 2017-01-14 18:05 - 00045565 _____ C:\WINDOWS\system32\InstallUtil.InstallLog
    2016-12-31 21:10 - 2016-12-31 21:10 - 00000000 ____D C:\Users\Unknown\AppData\Roaming\NVIDIA
    2016-12-31 21:08 - 2017-01-11 21:09 - 00000000 ____D C:\Users\Unknown\AppData\Roaming\.minecraft
    2016-12-31 21:08 - 2017-01-02 13:39 - 00000000 ____D C:\Program Files (x86)\Minecraft
    2016-12-31 21:08 - 2017-01-01 14:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft
    2016-12-31 21:08 - 2016-12-31 21:08 - 00001030 _____ C:\Users\Public\Desktop\Minecraft.lnk
    2016-12-31 21:08 - 2016-12-31 21:08 - 00000000 ____D C:\Users\Unknown\AppData\Roaming\java
    2016-12-31 21:06 - 2017-01-10 23:30 - 00000000 ____D C:\ProgramData\Lenovo
    2016-12-31 21:04 - 2017-01-10 23:31 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
    2016-12-31 21:04 - 2017-01-10 23:31 - 00000000 ____D C:\Program Files\Lenovo
    2016-12-31 21:04 - 2016-12-31 21:04 - 00000000 ____D C:\Users\Unknown\AppData\Local\Downloaded Installations
    2016-12-31 20:59 - 2017-01-10 23:31 - 00000000 ____D C:\Program Files (x86)\Lenovo
    2016-12-31 20:58 - 2017-01-09 13:56 - 00000000 ____D C:\Users\Unknown\AppData\Local\Programs
    2016-12-31 20:55 - 2017-01-01 14:26 - 00000000 ____D C:\Users\Unknown\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
    2016-12-31 20:54 - 2017-01-13 12:17 - 00648950 _____ C:\WINDOWS\system32\perfh025.dat
    2016-12-31 20:54 - 2017-01-13 12:17 - 00191320 _____ C:\WINDOWS\system32\perfc025.dat
    2016-12-31 20:54 - 2016-12-31 20:54 - 00000000 ____D C:\Users\Unknown\AppData\Local\Apps\2.0
    2016-12-31 20:54 - 2016-12-31 20:54 - 00000000 ____D C:\Users\Unknown\AppData\Local\Apps
    2016-12-31 20:52 - 2016-12-31 20:52 - 00387840 _____ (Intel Corporation) C:\WINDOWS\system32\ibtproppage.dll
    2016-12-31 20:52 - 2016-12-31 20:52 - 00250624 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\ibtusb.sys
    2016-12-31 20:52 - 2016-12-31 20:52 - 00190216 _____ (Intel Corporation) C:\WINDOWS\system32\ibtsiva.exe
    2016-12-31 20:33 - 2017-01-08 19:29 - 00000000 ____D C:\Users\Unknown\AppData\Roaming\Skype
    2016-12-31 20:33 - 2016-12-31 21:58 - 00000000 ____D C:\Users\Unknown\AppData\Local\NVIDIA
    2016-12-31 20:22 - 2016-12-31 20:23 - 00000035 _____ C:\WINDOWS\progress.ini
    2016-12-31 20:22 - 2016-12-31 20:22 - 00000000 ___HD C:\$GetCurrent
    2016-12-31 20:08 - 2016-10-28 03:22 - 00485032 _____ (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
    2016-12-31 20:07 - 2017-01-13 15:13 - 135657872 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
    2016-12-31 20:07 - 2017-01-11 00:04 - 00000000 ____D C:\WINDOWS\system32\MRT
    2016-12-31 20:02 - 2016-12-31 20:02 - 72520720 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoRes64.dat
    2016-12-31 20:02 - 2016-12-31 20:02 - 14057256 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioRealtek64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 13122584 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVoiceAPO3064.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 12988352 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVoiceAPO4064.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 10534704 _____ (Intel Corporation) C:\WINDOWS\system32\IntelSSTAPO.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 07172920 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEP64A.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 07096192 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64A.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 06764662 _____ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT
    2016-12-31 20:02 - 2016-12-31 20:02 - 06358552 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICV3apo.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 06264640 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64AF3.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 05804772 _____ C:\WINDOWS\system32\Drivers\rtvienna.dat
    2016-12-31 20:02 - 2016-12-31 20:02 - 05793528 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICV2apo.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 05593616 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICAPOlfx.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 05341352 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv211.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 05251592 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys
    2016-12-31 20:02 - 2016-12-31 20:02 - 03299824 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE2.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 03283248 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 03282544 _____ (Fortemedia Corporation) C:\WINDOWS\system32\FMAPO64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 03203592 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 03133152 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 02895104 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl
    2016-12-31 20:02 - 2016-12-31 20:02 - 02825104 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO7064.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 02775200 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RltkAPO.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 02706864 _____ (DTS, Inc.) C:\WINDOWS\system32\sltech64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 02439048 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv201.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 02203752 _____ (DTS, Inc.) C:\WINDOWS\system32\slcnt64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 02190992 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 02110592 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\WavesGUILib64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 02073096 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 02050176 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioEQ64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 01965816 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64A.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 01959608 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64AF3.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 01920820 _____ C:\WINDOWS\system32\Drivers\rtkSSTsetting.dat
    2016-12-31 20:02 - 2016-12-31 20:02 - 01780624 _____ (DTS) C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 01608128 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CX64APO.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 01591064 _____ (DTS) C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 01529144 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CX64Proxy.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 01508936 _____ (DTS) C:\WINDOWS\system32\DTSBoostDLL64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 01435144 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRRPTR64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 01422928 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO6064.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 01382240 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tosade.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 01360528 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 01337640 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tossaeapo64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 01334384 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxSpeechAPO64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 01213664 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO5064.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 01186840 _____ (Intel Corporation) C:\WINDOWS\system32\IntelSstCApoPropPage.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 01166160 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO4064.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 01115144 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOProp.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 01041744 _____ (DTS, Inc.) C:\WINDOWS\system32\sl3apo64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 01003864 _____ (Nahimic Inc) C:\WINDOWS\system32\NahimicAPONSControl.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 01001800 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDHF64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00999856 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVoiceAPO2064.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00965032 _____ (Sony Corporation) C:\WINDOWS\system32\SFSS_APO.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00962136 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tosasfapo64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00931624 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPOShell64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00923744 _____ (Sony Corporation) C:\WINDOWS\system32\MISS_APO.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00873472 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo264.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00864352 _____ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SEHDHF32.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00858208 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDRA64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00854040 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SECOMN64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00743968 _____ (DTS) C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00727440 _____ (DTS) C:\WINDOWS\system32\DTSSymmetryDLL64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00725944 _____ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SECOMN32.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00708312 _____ (DTS) C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00689888 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00678184 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO30.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00677680 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVolumeSDAPO.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00618184 _____ (Knowles Acoustics ) C:\WINDOWS\system32\KAAPORT64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00601152 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tossaemaxapo64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00574760 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAC64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00532384 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSX64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00514528 _____ (DTS) C:\WINDOWS\system32\DTSU2PLFX64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00504312 _____ (DTS) C:\WINDOWS\system32\DTSNeoPCDLL64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00500560 _____ (DTS) C:\WINDOWS\system32\DTSU2PGFX64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00498648 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEAPO64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00472312 _____ (ICEpower a/s) C:\WINDOWS\system32\ICEsoundAPO64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00467160 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRAPO64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00447728 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EED64A.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00447184 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\toseaeapo64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00445400 _____ (DTS) C:\WINDOWS\system32\DTSLimiterDLL64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00441272 _____ (DTS) C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00428232 _____ (DTS) C:\WINDOWS\system32\DTSU2PREC64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00416512 _____ (Harman) C:\WINDOWS\system32\HMUI.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00387312 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEP64A.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00381416 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00372744 _____ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2API.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00366128 _____ (Windows ® Win 7 DDK provider) C:\WINDOWS\system32\HMAPO.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00362056 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64AF3.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00360352 _____ (Harman) C:\WINDOWS\system32\HMClariFi.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00343712 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00341152 _____ (Synopsys, Inc.) C:\WINDOWS\SysWOW64\SRCOM.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00341152 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00330568 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO20.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00327456 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64A.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00321720 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DHT64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00321720 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DAA64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00310424 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64F3.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00272720 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00258864 _____ (TODO: <Company name>) C:\WINDOWS\system32\slprp64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00253904 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPO64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00253864 _____ (DTS) C:\WINDOWS\system32\DTSLFXAPO64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00252880 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPONS64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00231920 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFNHK64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00221968 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSH64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00214840 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEED64A.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00209544 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSHP64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00203848 _____ (Harman) C:\WINDOWS\system32\HMHVS.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00192992 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00190944 _____ (Harman) C:\WINDOWS\system32\HMEQ_Voice.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00190944 _____ (Harman) C:\WINDOWS\system32\HMEQ.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00179600 _____ (Harman) C:\WINDOWS\system32\HMLimiter.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00166208 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSWOW64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00158696 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00154368 _____ (Harman) C:\WINDOWS\system32\HarmanAudioInterface.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00151792 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEL64A.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00134208 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEA64A.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00122328 _____ (Real Sound Lab SIA) C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00118600 _____ C:\WINDOWS\system32\AcpiServiceVnA64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00118600 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAR64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00110992 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEL64A.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00105312 _____ C:\WINDOWS\system32\audioLibVc.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00090920 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFCOM64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00088352 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEG64A.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00088328 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFAPO64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00084616 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEG64A.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00083632 _____ (Virage Logic Corporation / Sonic Focus) C:\WINDOWS\SysWOW64\SFCOM.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00075544 _____ (TOSHIBA CORPORATION.) C:\WINDOWS\system32\tepeqapo64.dll
    2016-12-31 20:02 - 2016-12-31 20:02 - 00023696 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll
    2016-12-31 20:00 - 2017-01-15 12:09 - 00000000 __SHD C:\Users\Unknown\IntelGraphicsProfiles
    2016-12-31 20:00 - 2017-01-01 14:23 - 00000000 ____D C:\Intel
    2016-12-31 20:00 - 2017-01-01 01:33 - 00000000 ____D C:\Program Files (x86)\Intel
    2016-12-31 20:00 - 2016-12-31 20:00 - 39862352 _____ (Intel Corporation) C:\WINDOWS\system32\igdumdim64.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 38901776 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdumdim32.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 34821328 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd11dxva32.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 33476816 _____ (Intel Corporation) C:\WINDOWS\system32\igd11dxva64.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 15487912 _____ (Intel Corporation) C:\WINDOWS\system32\igc64.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 14614440 _____ (Intel Corporation) C:\WINDOWS\system32\igd10iumd64.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 13482600 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igc32.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 11921032 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd10iumd32.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 07945712 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\igdkmd64.sys
    2016-12-31 20:00 - 2016-12-31 20:00 - 06695208 _____ (Intel Corporation) C:\WINDOWS\system32\igdusc64.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 05799386 _____ C:\WINDOWS\system32\igdclbif.bin
    2016-12-31 20:00 - 2016-12-31 20:00 - 05688856 _____ (Intel Corporation) C:\WINDOWS\system32\igdmcl64.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 05138952 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdusc32.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 04936728 _____ (Intel Corporation) C:\WINDOWS\system32\igdrcl64.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 04365840 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdrcl32.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 04246568 _____ (Intel Corporation) C:\WINDOWS\system32\igd12umd64.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 04214056 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd12umd32.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 03971608 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdmcl32.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 02813952 _____ C:\WINDOWS\system32\iglhxa64.cpa
    2016-12-31 20:00 - 2016-12-31 20:00 - 02062872 _____ (Intel Corporation) C:\WINDOWS\system32\igfxLHM.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 01956408 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436909.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 01896472 _____ (Intel Corporation) C:\WINDOWS\system32\igdmd64.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 01816736 _____ (Intel Corporation) C:\WINDOWS\system32\iglhsip64.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 01814072 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\iglhsip32.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 01604152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436909.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 01590808 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcmjit64.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 01469920 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdmd32.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 01178648 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxcmjit32.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00757272 _____ (Intel Corporation) C:\WINDOWS\system32\igfxDH.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00644080 _____ (Intel Corporation) C:\WINDOWS\system32\igfxSDK.exe
    2016-12-31 20:00 - 2016-12-31 20:00 - 00632848 _____ (Intel Corporation) C:\WINDOWS\system32\MetroIntelGenericUIFramework.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00536560 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiUMS64.exe
    2016-12-31 20:00 - 2016-12-31 20:00 - 00448496 _____ (Intel Corporation) C:\WINDOWS\system32\IntelCpHDCPSvc.exe
    2016-12-31 20:00 - 2016-12-31 20:00 - 00439320 _____ (Intel Corporation) C:\WINDOWS\system32\igdbcl64.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00416280 _____ (Intel Corporation) C:\WINDOWS\system32\IntelOpenCL64.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00403671 _____ C:\WINDOWS\system32\ImageStabilization.wmv
    2016-12-31 20:00 - 2016-12-31 20:00 - 00401904 _____ C:\WINDOWS\system32\igfxTray.exe
    2016-12-31 20:00 - 2016-12-31 20:00 - 00396824 _____ (Intel Corporation) C:\WINDOWS\system32\igfxDI.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00390168 _____ (Intel Corporation) C:\WINDOWS\system32\igfxOSP.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00388632 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdbcl32.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00373744 _____ (Intel Corporation) C:\WINDOWS\system32\igfxCUIService.exe
    2016-12-31 20:00 - 2016-12-31 20:00 - 00354800 _____ (Intel Corporation) C:\WINDOWS\system32\igfxEM.exe
    2016-12-31 20:00 - 2016-12-31 20:00 - 00350200 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiMCComp64.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00318488 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\IntelOpenCL32.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00312320 _____ (Intel Corporation) C:\WINDOWS\system32\igd10idpp64.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00301552 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\IntelCpHeciSvc.exe
    2016-12-31 20:00 - 2016-12-31 20:00 - 00297184 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd10idpp32.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00273432 _____ C:\WINDOWS\system32\igfxCPL.cpl
    2016-12-31 20:00 - 2016-12-31 20:00 - 00268776 _____ (Intel Corporation) C:\WINDOWS\system32\igfxHK.exe
    2016-12-31 20:00 - 2016-12-31 20:00 - 00266256 _____ (Intel Corporation) C:\WINDOWS\system32\igdfcl64.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00255000 _____ (Intel Corporation) C:\WINDOWS\system32\igfxDTCM.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00242176 _____ (Intel Corporation) C:\WINDOWS\system32\iglhcp64.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00237040 _____ (Intel Corporation) C:\WINDOWS\system32\igfxext.exe
    2016-12-31 20:00 - 2016-12-31 20:00 - 00225304 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdfcl32.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00223264 _____ (Intel Corporation) C:\WINDOWS\system32\igdde64.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00209432 _____ (Intel Corporation) C:\WINDOWS\system32\igfxCoIn_v4474.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00205368 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\iglhcp32.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00193048 _____ (Intel Corporation) C:\WINDOWS\system32\igdail64.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00184000 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcmrt64.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00182976 _____ (Intel Corporation) C:\WINDOWS\system32\igfx11cmrt64.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00181856 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdde32.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00173576 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdail32.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00160288 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxcmrt32.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00160280 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfx11cmrt32.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00111640 _____ ( ) C:\WINDOWS\system32\igfxSDKLibv2_0.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00103960 _____ (Khronos Group) C:\WINDOWS\SysWOW64\Intel_OpenCL_ICD32.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00103448 _____ C:\WINDOWS\system32\igfxCUIServicePS.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00100888 _____ ( ) C:\WINDOWS\system32\igfxSDKLib.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00099864 _____ (Khronos Group) C:\WINDOWS\system32\Intel_OpenCL_ICD64.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00095256 _____ ( ) C:\WINDOWS\system32\igfxDHLibv2_0.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00084504 _____ ( ) C:\WINDOWS\system32\igfxDHLib.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00055264 _____ (Intel Corporation) C:\WINDOWS\system32\igfxexps.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00052760 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxexps32.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00041296 _____ C:\WINDOWS\system32\iglhxc64_dev.vp
    2016-12-31 20:00 - 2016-12-31 20:00 - 00040931 _____ C:\WINDOWS\system32\iglhxo64_dev.vp
    2016-12-31 20:00 - 2016-12-31 20:00 - 00040343 _____ C:\WINDOWS\system32\iglhxo64.vp
    2016-12-31 20:00 - 2016-12-31 20:00 - 00040316 _____ C:\WINDOWS\system32\iglhxc64.vp
    2016-12-31 20:00 - 2016-12-31 20:00 - 00039798 _____ C:\WINDOWS\system32\iglhxg64_dev.vp
    2016-12-31 20:00 - 2016-12-31 20:00 - 00039658 _____ C:\WINDOWS\system32\iglhxg64.vp
    2016-12-31 20:00 - 2016-12-31 20:00 - 00029208 _____ ( ) C:\WINDOWS\system32\igfxDILibv2_0.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00029208 _____ ( ) C:\WINDOWS\system32\igfxDILib.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00027672 _____ ( ) C:\WINDOWS\system32\igfxEMLibv2_0.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00027672 _____ ( ) C:\WINDOWS\system32\igfxEMLib.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00022552 _____ ( ) C:\WINDOWS\system32\igfxLHMLibv2_0.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00022552 _____ ( ) C:\WINDOWS\system32\igfxLHMLib.dll
    2016-12-31 20:00 - 2016-12-31 20:00 - 00004842 _____ C:\WINDOWS\system32\iglhxs64.vp
    2016-12-31 20:00 - 2016-12-31 20:00 - 00001125 _____ C:\WINDOWS\system32\iglhxa64.vp
    2016-12-31 19:59 - 2016-12-31 20:00 - 13619224 _____ (Intel Corporation) C:\WINDOWS\system32\ig9icd64.dll
    2016-12-31 19:59 - 2016-12-31 19:59 - 29101592 _____ (Intel Corporation) C:\WINDOWS\system32\common_clang64.dll
    2016-12-31 19:59 - 2016-12-31 19:59 - 19861520 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\common_clang32.dll
    2016-12-31 19:59 - 2016-12-31 19:59 - 10316296 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\ig9icd32.dll
    2016-12-31 19:59 - 2016-12-31 19:59 - 05233688 _____ (Intel Corporation) C:\WINDOWS\system32\GfxResources.dll
    2016-12-31 19:59 - 2016-12-31 19:59 - 00966640 _____ (Intel Corporation) C:\WINDOWS\system32\Gfxv4_0.exe
    2016-12-31 19:59 - 2016-12-31 19:59 - 00963048 _____ (Intel Corporation) C:\WINDOWS\system32\Gfxv2_0.exe
    2016-12-31 19:59 - 2016-12-31 19:59 - 00818898 _____ C:\WINDOWS\system32\DisplayAudiox64.cab
    2016-12-31 19:59 - 2016-12-31 19:59 - 00641530 _____ C:\WINDOWS\system32\FilmModeDetection.wmv
    2016-12-31 19:59 - 2016-12-31 19:59 - 00511260 _____ C:\WINDOWS\system32\cp_resources.bin
    2016-12-31 19:59 - 2016-12-31 19:59 - 00466928 _____ (Intel Corporation) C:\WINDOWS\system32\GfxUIEx.exe
    2016-12-31 19:59 - 2016-12-31 19:59 - 00375173 _____ C:\WINDOWS\system32\ColorImageEnhancement.wmv
    2016-12-31 19:59 - 2016-12-31 19:59 - 00232432 _____ (Intel Corporation) C:\WINDOWS\system32\DPTopologyApp.exe
    2016-12-31 19:59 - 2016-12-31 19:59 - 00231920 _____ (Intel Corporation) C:\WINDOWS\system32\DPTopologyAppv2_0.exe
    2016-12-31 19:59 - 2016-12-31 19:59 - 00175088 _____ (Intel Corporation) C:\WINDOWS\system32\difx64.exe
    2016-12-31 19:59 - 2016-12-31 19:59 - 00000935 _____ C:\WINDOWS\system32\Gfxv4_0.exe.config
    2016-12-31 19:59 - 2016-12-31 19:59 - 00000935 _____ C:\WINDOWS\system32\DPTopologyApp.exe.config
    2016-12-31 19:59 - 2016-12-31 19:59 - 00000895 _____ C:\WINDOWS\system32\Gfxv2_0.exe.config
    2016-12-31 19:59 - 2016-12-31 19:59 - 00000895 _____ C:\WINDOWS\system32\DPTopologyAppv2_0.exe.config
    2016-12-31 19:57 - 2016-12-31 19:57 - 02517496 _____ (Intel Corporation) C:\WINDOWS\system32\RealSenseF200Coinstaller_227975.dll
    2016-12-31 19:57 - 2016-12-31 19:57 - 00042328 _____ (Lenovo Corporation) C:\WINDOWS\system32\Drivers\AcpiVpc.sys
    2016-12-31 19:57 - 2016-12-31 19:57 - 00037888 _____ (Intel® Corporation) C:\WINDOWS\system32\Drivers\IntelDFUACPI.sys
    2016-12-31 19:56 - 2016-12-31 19:56 - 01804696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WdfCoInstaller01011.dll
    2016-12-31 19:56 - 2016-12-31 19:56 - 00778360 _____ (Synaptics Incorporated) C:\WINDOWS\system32\SynCOM.dll
    2016-12-31 19:56 - 2016-12-31 19:56 - 00642168 _____ (Synaptics Incorporated) C:\WINDOWS\system32\Drivers\SynTP.sys
    2016-12-31 19:56 - 2016-12-31 19:56 - 00428664 _____ (Synaptics Incorporated) C:\WINDOWS\SysWOW64\SynCom.dll
    2016-12-31 19:56 - 2016-12-31 19:56 - 00293496 _____ (Synaptics Incorporated) C:\WINDOWS\system32\SynTPCo34-10.dll
    2016-12-31 19:56 - 2016-12-31 19:56 - 00285304 _____ (Synaptics Incorporated) C:\WINDOWS\system32\SynTPAPI.dll
    2016-12-31 19:56 - 2016-12-31 19:56 - 00202848 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\TeeDriverW8x64.sys
    2016-12-31 19:56 - 2016-12-31 19:56 - 00098936 _____ (Synaptics Incorporated) C:\WINDOWS\system32\Drivers\SynHidI2C_Aux.sys
    2016-12-31 19:56 - 2016-12-31 19:56 - 00051320 _____ (Synaptics Incorporated) C:\WINDOWS\system32\Drivers\Smb_driver_Intel_Aux.sys
    2016-12-31 19:56 - 2016-12-31 19:56 - 00051320 _____ (Synaptics Incorporated) C:\WINDOWS\system32\Drivers\Smb_driver_Intel.sys
    2016-12-31 19:56 - 2016-12-31 19:56 - 00050808 _____ (Synaptics Incorporated) C:\WINDOWS\system32\Drivers\Smb_driver_AMDASF_Aux.sys
    2016-12-31 19:56 - 2016-09-30 05:28 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqrt.dll
    2016-12-31 19:54 - 2016-12-31 22:06 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
    2016-12-31 19:53 - 2016-12-31 19:53 - 01898128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6435362.dll
    2016-12-31 19:53 - 2016-12-31 19:53 - 01557648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6435362.dll
    2016-12-31 19:50 - 2016-12-31 19:50 - 00000000 ____D C:\Users\Unknown\AppData\Roaming\Macromedia
    2016-12-31 19:50 - 2016-12-31 19:50 - 00000000 ____D C:\Users\Unknown\AppData\Local\MicrosoftEdge
    2016-12-31 19:44 - 2017-01-15 12:09 - 00000000 ___RD C:\Users\Unknown\OneDrive
    2016-12-31 19:44 - 2017-01-13 20:57 - 00002446 _____ C:\Users\Unknown\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
    2016-12-31 19:44 - 2017-01-02 23:28 - 00000000 ___SD C:\Users\Unknown\AppData\LocalLow\Microsoft
    2016-12-31 19:42 - 2017-01-15 12:13 - 00000000 ___RD C:\Users\Unknown\Desktop
    2016-12-31 19:42 - 2017-01-15 12:12 - 00000000 ___RD C:\Users\Unknown\Downloads
    2016-12-31 19:42 - 2017-01-15 12:09 - 00000000 ___RD C:\Users\Unknown\Videos
    2016-12-31 19:42 - 2017-01-14 21:50 - 00000000 ___RD C:\Users\Unknown\Documents
    2016-12-31 19:42 - 2017-01-13 19:51 - 00000000 ___RD C:\Users\Unknown\Pictures
    2016-12-31 19:42 - 2017-01-11 21:21 - 00000000 ___RD C:\Users\Unknown\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
    2016-12-31 19:42 - 2017-01-11 20:45 - 00000000 ____D C:\Users\Unknown\AppData\LocalLow
    2016-12-31 19:42 - 2017-01-11 18:37 - 00000488 ___SH C:\Users\Unknown\Desktop\desktop.ini
    2016-12-31 19:42 - 2017-01-11 18:37 - 00000402 ___SH C:\Users\Unknown\Documents\desktop.ini
    2016-12-31 19:42 - 2017-01-11 18:37 - 00000174 ___SH C:\Users\Unknown\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
    2016-12-31 19:42 - 2017-01-11 18:37 - 00000000 __RHD C:\Users\Public\AccountPictures
    2016-12-31 19:42 - 2017-01-11 18:37 - 00000000 ___RD C:\Users\Unknown\Searches
    2016-12-31 19:42 - 2017-01-11 18:37 - 00000000 ___RD C:\Users\Unknown\Saved Games
    2016-12-31 19:42 - 2017-01-11 18:37 - 00000000 ___RD C:\Users\Unknown\Music
    2016-12-31 19:42 - 2017-01-11 18:37 - 00000000 ___RD C:\Users\Unknown\Links
    2016-12-31 19:42 - 2017-01-11 18:37 - 00000000 ___RD C:\Users\Unknown\Favorites
    2016-12-31 19:42 - 2017-01-11 18:37 - 00000000 ___RD C:\Users\Unknown\Contacts
    2016-12-31 19:42 - 2017-01-11 18:37 - 00000000 ___RD C:\Users\Unknown\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    2016-12-31 19:42 - 2017-01-02 17:07 - 00000000 ____D C:\Users\Unknown\AppData\Local\Packages
    2016-12-31 19:42 - 2016-12-31 19:42 - 00016148 _____ C:\WINDOWS\system32\DESKTOP-CF8B5HV_defaultuser0_HistoryPrediction.bin
    2016-12-31 19:42 - 2016-12-31 19:42 - 00000000 ____D C:\Users\Unknown\AppData\Roaming\Adobe
    2016-12-31 19:42 - 2016-12-31 19:42 - 00000000 ____D C:\Users\Unknown\AppData\Local\VirtualStore
    2016-12-31 19:42 - 2016-12-31 19:42 - 00000000 ____D C:\Users\Unknown\AppData\Local\TileDataLayer
    2016-12-31 19:42 - 2016-12-31 19:42 - 00000000 ____D C:\Users\Unknown\AppData\Local\Publishers
     
    ==================== One Month Modified files and folders ========
     
    (If an entry is included in the fixlist, the file/folder will be moved.)
     
    2017-01-15 12:12 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
    2017-01-14 23:36 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\AppReadiness
    2017-01-13 18:10 - 2016-07-16 13:47 - 00000000 ___HD C:\Program Files\WindowsApps
    2017-01-13 14:53 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\rescache
    2017-01-11 19:02 - 2016-07-16 13:45 - 00000000 ____D C:\WINDOWS\INF
    2017-01-11 00:24 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
    2017-01-11 00:24 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
    2017-01-11 00:24 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\oobe
    2017-01-11 00:24 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
    2017-01-11 00:24 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Provisioning
    2017-01-11 00:24 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
    2017-01-11 00:24 - 2016-07-16 08:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
    2017-01-11 00:20 - 2016-07-16 13:36 - 00000000 ____D C:\WINDOWS\CbsTemp
    2017-01-10 23:23 - 2014-05-09 14:04 - 02356592 _____ (Microsoft Corporation) C:\WINDOWS\system32\WudfUpdate_01011.dll
    2017-01-10 23:07 - 2016-07-16 08:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
    2017-01-09 22:38 - 2016-07-16 13:47 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
    2017-01-09 00:08 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
    2017-01-08 19:29 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\registration
    2017-01-08 19:29 - 2016-07-16 08:04 - 00000000 ____D C:\WINDOWS\system32\Sysprep
    2017-01-02 19:34 - 2015-07-10 13:04 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
    2017-01-02 17:06 - 2016-07-17 00:53 - 00000000 ____D C:\WINDOWS\system32\Drivers\et-EE
    2017-01-02 17:06 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\et-EE
    2017-01-02 17:06 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SystemApps
    2017-01-02 17:06 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\et-EE
    2017-01-02 17:06 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\security
    2017-01-02 17:04 - 2016-07-16 13:44 - 00565760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpprefcl.dll
    2017-01-02 17:04 - 2016-07-16 13:44 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PeerDistSh.dll
    2017-01-02 17:04 - 2016-07-16 13:44 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PeerDist.dll
    2017-01-02 17:04 - 2016-07-16 13:44 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appmgmts.dll
    2017-01-02 17:04 - 2016-07-16 13:44 - 00132608 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfg.exe
    2017-01-02 17:04 - 2016-07-16 13:44 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfgLib.dll
    2017-01-02 17:04 - 2016-07-16 13:44 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpscript.dll
    2017-01-02 17:04 - 2016-07-16 13:44 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpscript.exe
    2017-01-02 17:04 - 2016-07-16 13:44 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeSysprep.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 02414432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.AppAgent.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 02232832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ModernAppAgent.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 01949696 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDistSvc.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 01651552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft.Uev.AppAgent.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 01344512 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmclient.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 01227264 _____ (Microsoft Corporation) C:\WINDOWS\system32\AgentService.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 01222144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.CommonBridge.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 01165824 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplySettingsTemplateCatalog.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00935936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srmclient.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\system32\pmcsnap.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00768512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.PrinterCustomActions.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00744960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Office2013CustomActions.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00735744 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscsvc.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00724992 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDistCacheProvider.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00679936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvgogl32.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00674816 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpprefcl.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00654336 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmscan.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\AdmTmpl.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00552448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\csc.sys
    2017-01-02 17:04 - 2016-07-16 13:43 - 00550912 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrptadm.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00512000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft.Uev.Office2013CustomActions.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00477184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrptadm.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00471040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srmscan.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00454144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AdmTmpl.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00453632 _____ (Microsoft Corporation) C:\WINDOWS\system32\appmgr.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00423424 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDistSh.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00419328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.CscUnpinTool.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00410624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppIdPolicyEngineApi.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appmgr.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00313344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SrpUxNativeSnapIn.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SrpUxNativeSnapIn.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ConfigWrapper.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscobj.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ManagedEventLogging.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppIdPolicyEngineApi.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmstormod.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\srm.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00279040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srm.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddputils.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00264192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ppcsnap.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddpchunk.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuditNativeSnapIn.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuditNativeSnapIn.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\tscfgwmi.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00220160 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDistCleaner.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00220160 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDist.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\system32\appvetwsharedperformance.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppvClientEventLog.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationSettings.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00212992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.CmUtil.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cscobj.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\appmgmts.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00194048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srmstormod.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00190304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mavinject.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvgocl32.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDistWSDDiscoProv.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\tssrvlic.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00179040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mssecflt.sys
    2017-01-02 17:04 - 2016-07-16 13:43 - 00173568 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmshell.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00158208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvgu1132.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00153952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mavinject.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00147439 _____ C:\WINDOWS\SysWOW64\gpedit.msc
    2017-01-02 17:04 - 2016-07-16 13:43 - 00147439 _____ C:\WINDOWS\system32\gpedit.msc
    2017-01-02 17:04 - 2016-07-16 13:43 - 00146389 _____ C:\WINDOWS\system32\printmanagement.msc
    2017-01-02 17:04 - 2016-07-16 13:43 - 00145760 _____ (Microsoft Corporation) C:\WINDOWS\system32\CscMig.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.SecureAssessment.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddptrace.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\adrclient.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srmshell.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00126976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppManagementConfiguration.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00120458 _____ C:\WINDOWS\system32\secpol.msc
    2017-01-02 17:04 - 2016-07-16 13:43 - 00119808 ____R (Microsoft Corporation) C:\WINDOWS\system32\SecureAssessmentHandlers.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppManagementConfiguration.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00108544 _____ C:\WINDOWS\system32\RDVGHelper.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00101376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adrclient.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00099840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvgumd32.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AssignedAccessCsp.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00096768 ____R (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.SecureAssessment.CfgProvider.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\auditpolmsg.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\auditpolmsg.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srmlib.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmlib.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\IoTAssignedAccessLockFramework.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageInspector.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmtrace.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.SyncController.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dggpext.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssecuser.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuditPolicyGPInterop.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintBrmUi.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpgradeSubscription.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Common.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srmtrace.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00062464 _____ (Microsoft Corporation) C:\WINDOWS\system32\LSCSHostPolicy.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuditPolicyGPInterop.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ModernAppCore.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UevAppMonitor.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDistHttpTrans.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddp_ps.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00054272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.CabUtil.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00051040 _____ (Microsoft Corporation) C:\WINDOWS\system32\embeddedapplauncher.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpscript.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.EventLogMessages.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Office2010CustomActions.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpscript.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00043566 _____ C:\WINDOWS\SysWOW64\rsop.msc
    2017-01-02 17:04 - 2016-07-16 13:43 - 00043566 _____ C:\WINDOWS\system32\rsop.msc
    2017-01-02 17:04 - 2016-07-16 13:43 - 00042848 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmbeddedAppLauncherConfig.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDistAD.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\UevAgentPolicyGenerator.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00040800 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmbeddedAppLauncherConfig.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00040288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UevAgentDriver.sys
    2017-01-02 17:04 - 2016-07-16 13:43 - 00039776 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVClientPS.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\system32\CIWmi.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft.Uev.Office2010CustomActions.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\srm_ps.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00029184 _____ (Microsoft Corporation) C:\WINDOWS\system32\qwinsta.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\qprocess.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00026976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVClientPS.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\msg.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\lstelemetry.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32_DeviceGuard.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\quser.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\chgport.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\qappsrv.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\tskill.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsdiscon.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tscon.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Management.WmiAccess.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\logoff.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\rwinsta.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\chglogon.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\chgusr.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Management.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ModernAppData.WinRT.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00020320 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVTerminator.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.SyncCommon.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Common.WinRT.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00018272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVTerminator.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.LocalSyncProvider.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\reset.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\change.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srm_ps.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\query.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00015200 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVSentinel.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ModernSync.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\UevTemplateBaselineGenerator.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.AgentDriverEvents.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00013664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVSentinel.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\UevTemplateConfigItemGenerator.exe
    2017-01-02 17:04 - 2016-07-16 13:43 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.SmbSyncProvider.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.MonitorSyncProvider.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.SyncConditions.dll
    2017-01-02 17:04 - 2016-07-16 13:43 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.SecureAssessment.Diagnostics.dll
    2017-01-02 17:04 - 2016-07-16 13:41 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tsusbhub.sys
    2017-01-02 13:07 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\appcompat
    2017-01-01 17:39 - 2016-07-16 13:47 - 00015425 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
    2017-01-01 17:39 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
    2017-01-01 17:39 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\system32\F12
    2017-01-01 17:39 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\system32\dsc
    2017-01-01 17:39 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
    2017-01-01 17:39 - 2016-07-16 13:47 - 00000000 ___RD C:\Program Files\Windows Defender
    2017-01-01 17:39 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\setup
    2017-01-01 17:39 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
    2017-01-01 17:39 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\setup
    2017-01-01 17:39 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\migwiz
    2017-01-01 17:39 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\lv-LV
    2017-01-01 17:39 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\lt-LT
    2017-01-01 17:39 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\es-MX
    2017-01-01 17:39 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\en-GB
    2017-01-01 17:39 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
    2017-01-01 17:39 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\bcastdvr
    2017-01-01 17:39 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files\Windows Photo Viewer
    2017-01-01 17:39 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
    2017-01-01 17:39 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files (x86)\Windows Defender
    2017-01-01 17:39 - 2016-07-16 08:04 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
    2017-01-01 17:39 - 2016-07-16 08:04 - 00000000 ____D C:\WINDOWS\system32\Dism
    2017-01-01 17:39 - 2016-07-16 08:04 - 00000000 ____D C:\WINDOWS\servicing
    2017-01-01 16:41 - 2016-07-16 13:44 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerWizardElev.exe
    2017-01-01 16:41 - 2016-07-16 13:44 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerWizard.exe
    2017-01-01 16:41 - 2016-07-16 13:43 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSErrRedir.dll
    2017-01-01 16:40 - 2016-07-16 13:43 - 00291680 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVStreamingUX.exe
    2017-01-01 16:40 - 2016-07-16 13:43 - 00268128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVFileSystemMetadata.dll
    2017-01-01 16:40 - 2016-07-16 13:43 - 00236384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVStreamMap.dll
    2017-01-01 16:40 - 2016-07-16 13:43 - 00202592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVStreamingUX.dll
    2017-01-01 16:40 - 2016-07-16 13:43 - 00178528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVNice.exe
    2017-01-01 16:40 - 2016-07-16 13:43 - 00157024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\AppvVemgr.sys
    2017-01-01 16:40 - 2016-07-16 13:43 - 00141152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\AppvVfs.sys
    2017-01-01 16:40 - 2016-07-16 13:43 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\system32\appvetwclientres.dll
    2017-01-01 16:40 - 2016-07-16 13:43 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpsign.exe
    2017-01-01 16:40 - 2016-07-16 13:43 - 00075104 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncAppvPublishingServer.exe
    2017-01-01 16:40 - 2016-07-16 13:43 - 00021856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ScriptRunner.exe
    2017-01-01 16:40 - 2016-07-16 13:43 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\appvetwstreamingux.dll
    2017-01-01 14:30 - 2016-07-16 13:47 - 00000000 ____D C:\ProgramData\USOPrivate
    2017-01-01 14:27 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated
    2017-01-01 14:26 - 2016-07-16 13:47 - 00000000 __RSD C:\WINDOWS\Media
    2017-01-01 14:26 - 2016-07-16 13:47 - 00000000 __RHD C:\Users\Public\Libraries
    2017-01-01 14:25 - 2016-07-17 00:53 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
    2017-01-01 14:25 - 2016-07-17 00:53 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
    2017-01-01 14:25 - 2016-07-17 00:53 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr
    2017-01-01 14:25 - 2016-07-17 00:53 - 00000000 ____D C:\WINDOWS\system32\WCN
    2017-01-01 14:25 - 2016-07-17 00:53 - 00000000 ____D C:\WINDOWS\system32\slmgr
    2017-01-01 14:25 - 2016-07-16 13:47 - 00000000 __SHD C:\Program Files\Windows Sidebar
    2017-01-01 14:25 - 2016-07-16 13:47 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
    2017-01-01 14:25 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
    2017-01-01 14:25 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\Configuration
    2017-01-01 14:25 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\system32\Configuration
    2017-01-01 14:25 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI
    2017-01-01 14:25 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
    2017-01-01 14:25 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\spool
    2017-01-01 14:25 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\MUI
    2017-01-01 14:25 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\InputMethod
    2017-01-01 14:25 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\IME
    2017-01-01 14:25 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Help
    2017-01-01 14:25 - 2016-07-16 08:04 - 00000000 ____D C:\Users\Default.migrated
    2017-01-01 14:24 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\PrintDialog
    2017-01-01 14:24 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\MiracastView
    2017-01-01 14:22 - 2016-07-16 13:47 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
    2016-12-31 19:51 - 2015-07-10 13:01 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll
    2016-12-31 19:51 - 2015-07-10 13:01 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll
    2016-12-23 01:13 - 2016-07-16 13:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
    2016-12-23 01:13 - 2016-07-16 13:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
     
    ==================== Files in the root of some directories =======
     
    2017-01-01 14:23 - 2017-01-01 14:23 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
    2017-01-01 14:23 - 2017-01-01 14:23 - 0000102 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.64.bc
    2016-12-31 21:54 - 2017-01-15 12:09 - 0013767 _____ () C:\ProgramData\NvTelemetryContainer.log
    2016-12-31 21:54 - 2017-01-11 00:24 - 0005943 _____ () C:\ProgramData\NvTelemetryContainer.log_backup1
     
    ==================== Bamital & volsnap ======================
     
    (There is no automatic fix for files that do not pass verification.)
     
    C:\WINDOWS\system32\winlogon.exe => File is digitally signed
    C:\WINDOWS\system32\wininit.exe => File is digitally signed
    C:\WINDOWS\explorer.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
    C:\WINDOWS\system32\svchost.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
    C:\WINDOWS\system32\services.exe => File is digitally signed
    C:\WINDOWS\system32\User32.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
    C:\WINDOWS\system32\userinit.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
    C:\WINDOWS\system32\rpcss.dll => File is digitally signed
    C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
    C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
     
    LastRegBack: 2017-01-12 00:17
     
    ==================== End of FRST.txt ============================
    • 0

    #4
    RKinner

    RKinner

      Malware Expert

    • Expert
    • 20,015 posts
    • MVP

    No sign of malware but Windows is not happy with your licensing.  

    Error: (01/14/2017 12:09:05 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
    Description: License Activation (slui.exe) failed with the following error code:
    hr=0x803F7001
    Command-line arguments:
    RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=UserLogon;SessionId=4

     

     

     

    Does this apply?  (The second DNS shown in the log is located in Prague and you are supposed to be in Estonia  so that's a bit odd.)

     

    https://support.micr...en-us/kb/921471

     

     

     

    .  Have you run an Avast boot-time scan yet?

     

     

     
    Open Avast, Scan, Scan for Viruses, Change the Quick Scan (in the box in the center of the page) to Boot-time Scan.  Then at the bottom of the page click on Scan Settings.
    Set Areas to Scan: to All Harddisks
    Make sure both boxes are checked and click on the gray box to the right of the orange ones.  It should turn orange.  Change where it says "Fix Automatically" to "Move to
    Chest."  OK.  Now click on Start and then close Avast.  Mute your speakers so it doesn't wake you up when Windows boots.
     
    When you reboot you will see the scan start.  It will tell you where it saves its log.  Usually it's C:\ProgramData\AVAST Software\Avast\report\aswBoot.txt but it might change so verify the location.   This is a hidden location so you will need to tell Windows to let you see it:
     
     
    Copy and paste the text from the log to a Reply when done.

    • 0

    #5
    Nerdkid15

    Nerdkid15

      New Member

    • Topic Starter
    • Member
    • Pip
    • 7 posts

    I am located in Estonia, and I do not have activated windows, but I am in process of obtaining the key.

    A 15-year-old just can't buy the 120€ key that easily.

     

    For some reason, it did not create the log...


    • 0

    #6
    RKinner

    RKinner

      Malware Expert

    • Expert
    • 20,015 posts
    • MVP

    When you rebooted did you see it start running?


    • 0

    #7
    Nerdkid15

    Nerdkid15

      New Member

    • Topic Starter
    • Member
    • Pip
    • 7 posts

    You mean avast?

    If so, I did not.


    • 0

    #8
    RKinner

    RKinner

      Malware Expert

    • Expert
    • 20,015 posts
    • MVP

    Perhaps you did not schedule the scan.  Try it again. If you do it right it will ask you if you want to reboot to start the scan.   When you reboot it should bring up a black screen with white letters which slowly scans every file on your PC.  It can take up to 6 hours to finish.

     

    avast.JPG

     

    avast2.JPG


    • 0

    #9
    Nerdkid15

    Nerdkid15

      New Member

    • Topic Starter
    • Member
    • Pip
    • 7 posts

    It did the scan, it showed 0 threats or infected files (On a screen what looks like a DOS :P)

    The scan didn't take long, maybe because of an i7core processor and an SSD.

    It just didn't create the .txt file.


    • 0

    #10
    RKinner

    RKinner

      Malware Expert

    • Expert
    • 20,015 posts
    • MVP

    OK.  I would say your system is clean.

     

    Time to clean up:

     

     

    Delete any programs we ran and their logs.
     
     
    Also make sure you have the latest versions of any adobe.com products you use like Shockwave, Flash or Acrobat.  Flash is now the most malware targeted program so it must be kept up to date.  Be careful with Adobe.  They are fond of offering optional downloads like yahoo or Ask toolbars or that worthless McAfee Security Scan.  Go slow and uncheck the optional stuff.
     
    Whether you use adobe reader, acrobat or fox-it to read pdf files you need to disable Javascript in the program.  There is an exploit out there now that can use it to get on your PC.  For Adobe Reader:  Start, All Programs, Adobe Reader, Edit, Preferences, Click on Javascript in the left column and uncheck Enable Acrobat Javascript.  OK Close program.  It's the same for Foxit reader except you uncheck Enable Javascript Actions. 
     
     
    If you use Chrome/Firefox/IE then get the AdBlock Plus Add-on.  Go to adblockplus.org with each browser and get the add-on.  (It's actually a program for IE)
     
    If Chrome/Firefox is slow loading make sure it only has the current Java add-on.  Then download and run Speedy Fox.
    http://www.crystalidea.com/speedyfox.  Close Chrome/Firefox/Skpe. Hit Optimize.   You can run it any time that Chrome/Firefox seems slow starting..
     
    Be warned:  If you use Limewire, utorrent or any of the other P2P programs you will probably be coming back to the Malware Removal forum.  If you must use P2P then submit any files you get to http://virustotal.combeforeyou open them.
     
    Due to a recent rise in the number of Crytolocker infections I am now recommending you install:
     
    CryptoPrevent
     
     
    The free version does not update on its own so you should check for updated versions once in a while. When you install it the default is NONE which is kind of worthless so change it to Standard or default. If you have problems after installing CryptoPrevent you can just uninstall it.
     
    If you have a router, log on to it today and change the default password!  If using a Wireless router you really should be using encryption on the link.  Use the strongest (newest) encryption method that your router and PC wireless adapter support especially if you own a business.  See http://www.king5.com...0637284.htmlandhttp://www.seattlepi...ted-1344185.php for why encryption is important.  If you don't know how, visit the router maker's website.  They all have detailed step by step instructions or a wizard you can download.
     
    Special note on Java.  Old Java versions should be removed after first clearing the Java Cache by following the instructions in:
    Then remove the old versions by going to Control Panel, Programs and Features and Uninstall all Java programs which are not Java Version 7 update 25 or better.  These may call themselves: Java Runtime, Runtime Environment, Runtime, JRE, Java Virtual Machine, Virtual Machine, Java VM, JVM, VM, J2RE, J2SE.  Get the latest version from Java.com.  They will usually attempt to foist some garbage like the Ask toolbar, Yahoo toolbar or McAfee Security Scan on you as part of the download.  Just uncheck the garbage before the download (or install) starts.  If you use a 64-bit browser and want the 64-bit version of Java you need to use it to visit java.com.
    Due to multiple security problems with Java we are now recommending that it not be installed unless you absolutely know you need it.  IF that is the case then go to Control Panel, Java, Security and slide it up to the highest level.  OK.

    • 0

    #11
    Nerdkid15

    Nerdkid15

      New Member

    • Topic Starter
    • Member
    • Pip
    • 7 posts

    Do you mean the Router password or wifi password?


    • 0

    #12
    RKinner

    RKinner

      Malware Expert

    • Expert
    • 20,015 posts
    • MVP

    The router.  We have seen cases where malware would log on to the router using the default password so I recommend that the default password be changed.  The password doesn't have to be fancy - you can uses your last name or your girlfirends name - just don't use password or admin.  (Write the new password on a piece of paper and tape it to the bottom of the router.)  


    • 0

    #13
    Nerdkid15

    Nerdkid15

      New Member

    • Topic Starter
    • Member
    • Pip
    • 7 posts
    Thank you!
    I appreciate you taking your time and making sure that my computer is free from viruses!
    I thought that my post would get drowned under the new posts, but it didn't.
    Thanks for the help!

    Nerdkid15
    • 0

    #14
    RKinner

    RKinner

      Malware Expert

    • Expert
    • 20,015 posts
    • MVP

    Glad I could help.

     

    Actually things have been rather slow recently.  If you click on the Unreplied Posts button in the top right of the page you will see our backlog.  One of them has some illegal software and the other three don't really show a problem but I will probably answer them if I get bored.  


    • 0






    Similar Topics


    Also tagged with one or more of these keywords: Trojan, virus, hidden

    0 user(s) are reading this topic

    0 members, 0 guests, 0 anonymous users

    As Featured On:

    Microsoft Yahoo BBC MSN PC Magazine Washington Post HP