Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Toshiba laptop won't boot- FRST attached


  • This topic is locked This topic is locked

#1
naomiq

naomiq

    New Member

  • Member
  • Pip
  • 3 posts

Hello, the computer shows the TOSHIBA screen but then it goes black with a blinking cursor.

I ran FRST. It is attached. 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 01-05-2017
Ran by SYSTEM on MININT-VFQT71C (03-05-2017 02:04:59)
Running from f:\
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11
Boot Mode: Recovery
Default: ControlSet001
ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.
 
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [] => [X]
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7982112 2009-07-28] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1815848 2009-07-20] (Synaptics Incorporated)
HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [497504 2009-08-05] (TOSHIBA Corporation)
HKLM\...\Run: [HSON] => C:\Program Files\TOSHIBA\TBS\HSON.exe [52600 2009-03-09] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] => C:\Program Files\Toshiba\SmoothView\SmoothView.exe [508216 2009-07-28] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [909624 2009-08-05] (TOSHIBA Corporation)
HKLM\...\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [711000 2009-08-04] (TOSHIBA Corporation)
HKLM\...\Run: [Teco] => C:\Program Files\TOSHIBA\TECO\Teco.exe [1482080 2009-08-11] (TOSHIBA Corporation)
HKLM\...\Run: [SmartFaceVWatcher] => C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [238080 2009-07-29] (TOSHIBA Corporation)
HKLM\...\Run: [TosSENotify] => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [709976 2009-08-03] (TOSHIBA Corporation)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch                                                                                                                               (the data entry has 65 more characters).
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes)
HKLM-x32\...\Run: [NortonOnlineBackupReminder] => C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TobuActivation.exe [529256 2009-07-16] (Toshiba)
HKLM-x32\...\Run: [TWebCamera] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2446648 2009-08-11] (TOSHIBA CORPORATION.)
HKLM-x32\...\Run: [WD Drive Unlocker] => C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe [1694080 2013-07-10] (Western Digital Technologies, Inc.)
HKLM-x32\...\Run: [WD Quick View] => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5571944 2016-04-19] (Western Digital Technologies, Inc.)
HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [240400 2016-12-06] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [240400 2016-12-06] (AVG Technologies CZ, s.r.o.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...26dfa299cadb\InprocServer32: [Authentication UI Logon UI] authuitu.dll <==== ATTENTION
IFEO\cfaddgadgets.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\cfmain.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\cfprofile.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\ndstray.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\pcdiag.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\smoothview.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\tacsprop.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\teco.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\tfcconf.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\tfcrst.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\tobuactivation.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\todisc.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\toshibaservicestation.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\tosramutil.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\tosssdalert.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\tpchviewer.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\twebcamera.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\wddmstatus.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\wddriveutilities.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\wdsmartware.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [1002552 2017-04-11] (AVG Technologies CZ, s.r.o.)
S2 avgfws; C:\Program Files (x86)\AVG\Av\avgfwsa.exe [1824184 2017-04-11] (AVG Technologies CZ, s.r.o.)
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagenta.exe [5334432 2017-04-11] (AVG Technologies CZ, s.r.o.)
S2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1146128 2016-12-06] (AVG Technologies CZ, s.r.o.)
S2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvca.exe [729048 2017-04-11] (AVG Technologies CZ, s.r.o.)
S2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3737792 2017-03-26] (Microsoft Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes)
S2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [5906704 2017-02-21] (AVG Technologies CZ, s.r.o.)
S2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [56080 2017-02-21] (AVG Technologies CZ, s.r.o.)
S2 UxTuneUp; C:\Windows\SysWOW64\uxtuneup.dll [48912 2017-02-21] (AVG Technologies CZ, s.r.o.)
S4 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1049464 2016-04-19] (Western Digital Technologies, Inc.)
S2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [314744 2016-04-19] (Western Digital Technologies, Inc.)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [163072 2016-05-13] (AVG Technologies CZ, s.r.o.)
S1 Avgfwfd; C:\Windows\System32\DRIVERS\avgfwd6a.sys [73992 2016-10-23] (AVG Technologies CZ, s.r.o.)
S1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [313088 2017-02-20] (AVG Technologies CZ, s.r.o.)
S0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [267008 2016-10-05] (AVG Technologies CZ, s.r.o.)
S1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [298240 2016-11-30] (AVG Technologies CZ, s.r.o.)
S0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [360736 2016-02-16] (AVG Technologies CZ, s.r.o.)
S0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [253184 2017-04-11] (AVG Technologies CZ, s.r.o.)
S0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [52992 2016-06-01] (AVG Technologies CZ, s.r.o.)
S1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [299264 2016-07-27] (AVG Technologies CZ, s.r.o.)
S0 avguniva; C:\Windows\System32\DRIVERS\avguniva.sys [77056 2016-06-20] (AVG Technologies CZ, s.r.o.)
S1 ESProtectionDriver; C:\windows\system32\drivers\mbae64.sys [77440 2017-04-17] ()
S2 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [186304 2017-04-17] (Malwarebytes)
S3 MBAMFarflt; C:\windows\system32\drivers\farflt.sys [111544 2017-04-28] (Malwarebytes)
S3 MBAMProtection; C:\windows\system32\drivers\mbam.sys [43968 2017-04-28] (Malwarebytes)
S3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [251832 2017-04-28] (Malwarebytes)
S3 MBAMWebProtection; C:\windows\system32\drivers\mwac.sys [82720 2017-04-28] (Malwarebytes)
S3 RTL8187Se; C:\Windows\System32\DRIVERS\RTL8187Se.sys [427008 2009-06-10] (Realtek Semiconductor Corporation                           )
S3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [32304 2016-02-15] (AVG Netherlands B.V.)
S3 WDC_SAM; C:\Windows\System32\DRIVERS\wdcsam64_prewin8.sys [23200 2016-04-19] (Western Digital Technologies)
S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [X]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-05-03 01:46 - 2017-05-03 02:04 - 00000000 ____D C:\FRST
2017-04-27 10:23 - 2017-04-27 10:23 - 01201768 _____ (Adobe Systems Incorporated) C:\Users\Jacque\Downloads\flashplayer25_ka_install(1).exe
2017-04-27 10:21 - 2017-04-27 10:21 - 01201768 _____ (Adobe Systems Incorporated) C:\Users\Jacque\Downloads\flashplayer25_ka_install.exe
2017-04-24 10:30 - 2017-04-24 10:30 - 00003144 _____ C:\Windows\System32\Tasks\{52255622-5B0F-4D8F-9A7A-6AC6FB06B9F5}
2017-04-24 10:25 - 2017-04-24 10:24 - 00097856 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2017-04-24 10:24 - 2017-04-24 10:24 - 00000000 ____D C:\Program Files (x86)\Java
2017-04-13 10:31 - 2017-04-13 10:31 - 00514980 _____ C:\Users\Jacque\Documents\Indian-Uses-Short-Form.pdf
2017-04-13 07:54 - 2017-03-27 10:13 - 00394448 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2017-04-13 07:54 - 2017-03-27 09:28 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-04-13 07:54 - 2017-03-25 11:39 - 20284416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-04-13 07:54 - 2017-03-25 10:52 - 02289152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-04-13 07:54 - 2017-03-25 10:51 - 01313280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-04-13 07:54 - 2017-03-25 10:48 - 00499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-04-13 07:54 - 2017-03-25 10:47 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-04-13 07:54 - 2017-03-25 10:46 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-04-13 07:54 - 2017-03-25 10:46 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-04-13 07:54 - 2017-03-25 10:46 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-04-13 07:54 - 2017-03-25 10:46 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-04-13 07:54 - 2017-03-25 10:46 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-04-13 07:54 - 2017-03-25 10:46 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-04-13 07:54 - 2017-03-25 10:45 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-04-13 07:54 - 2017-03-25 10:45 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-04-13 07:54 - 2017-03-25 10:45 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-04-13 07:54 - 2017-03-25 10:45 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-04-13 07:54 - 2017-03-25 10:45 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-04-13 07:54 - 2017-03-25 10:45 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-04-13 07:54 - 2017-03-25 10:44 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-04-13 07:54 - 2017-03-25 10:35 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll
2017-04-13 07:54 - 2017-03-25 10:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll
2017-04-13 07:54 - 2017-03-25 10:02 - 00034304 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2017-04-13 07:54 - 2017-03-25 09:56 - 00114688 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe
2017-04-13 07:54 - 2017-03-25 09:30 - 00077824 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll
2017-04-13 07:54 - 2017-03-25 09:29 - 00107520 _____ (Microsoft Corporation) C:\Windows\System32\inseng.dll
2017-04-13 07:54 - 2017-03-25 09:17 - 00152064 _____ (Microsoft Corporation) C:\Windows\System32\occache.dll
2017-04-13 07:54 - 2017-03-25 09:00 - 00725504 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2017-04-13 07:54 - 2017-03-25 08:10 - 01546240 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2017-04-13 07:54 - 2017-03-22 07:32 - 00098816 _____ (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2017-04-13 07:54 - 2017-03-22 07:24 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2017-04-13 07:54 - 2017-03-22 07:15 - 00709120 _____ (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2017-04-13 07:54 - 2017-03-22 07:15 - 00140288 _____ (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2017-04-13 07:54 - 2017-03-22 07:15 - 00037888 _____ (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2017-04-13 07:54 - 2017-03-22 07:05 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2017-04-13 07:54 - 2017-03-22 07:05 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2017-04-13 07:54 - 2017-03-22 07:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2017-04-13 07:54 - 2016-09-15 06:56 - 00041984 _____ (Microsoft Corporation) C:\Windows\System32\UtcResources.dll
2017-04-13 07:54 - 2016-07-22 06:58 - 00142336 _____ (Microsoft Corporation) C:\Windows\System32\poqexec.exe
2017-04-13 07:54 - 2016-07-22 06:51 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2017-04-13 07:53 - 2017-03-25 11:07 - 04604416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-04-13 07:53 - 2017-03-25 11:06 - 13654016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-04-13 07:53 - 2017-03-25 10:55 - 02767360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-04-13 07:53 - 2017-03-25 10:47 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-04-13 07:53 - 2017-03-25 10:47 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-04-13 07:53 - 2017-03-25 10:46 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-04-13 07:53 - 2017-03-25 10:46 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-04-13 07:53 - 2017-03-25 10:45 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-04-13 07:53 - 2017-03-25 10:44 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-04-13 07:53 - 2017-03-25 10:35 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2017-04-13 07:53 - 2017-03-25 10:16 - 00066560 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2017-04-13 07:53 - 2017-03-25 10:14 - 00417792 _____ (Microsoft Corporation) C:\Windows\System32\html.iec
2017-04-13 07:53 - 2017-03-25 10:13 - 00576512 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2017-04-13 07:53 - 2017-03-25 10:13 - 00088064 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll
2017-04-13 07:53 - 2017-03-25 10:10 - 02898432 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2017-04-13 07:53 - 2017-03-25 10:04 - 00054784 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2017-04-13 07:53 - 2017-03-25 09:57 - 00615936 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2017-04-13 07:53 - 2017-03-25 09:56 - 00817664 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
2017-04-13 07:53 - 2017-03-25 09:56 - 00814080 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll
2017-04-13 07:53 - 2017-03-25 09:56 - 00144384 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2017-04-13 07:53 - 2017-03-25 09:52 - 25746944 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2017-04-13 07:53 - 2017-03-25 09:45 - 00968704 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
2017-04-13 07:53 - 2017-03-25 09:41 - 06045696 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2017-04-13 07:53 - 2017-03-25 09:41 - 00489984 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2017-04-13 07:53 - 2017-03-25 09:24 - 00199680 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll
2017-04-13 07:53 - 2017-03-25 09:23 - 00092160 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2017-04-13 07:53 - 2017-03-25 09:20 - 00315392 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2017-04-13 07:53 - 2017-03-25 09:19 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-04-13 07:53 - 2017-03-25 09:06 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-04-13 07:53 - 2017-03-25 09:04 - 00262144 _____ (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2017-04-13 07:53 - 2017-03-25 08:59 - 00806912 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2017-04-13 07:53 - 2017-03-25 08:57 - 02131456 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2017-04-13 07:53 - 2017-03-25 08:57 - 01359360 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
2017-04-13 07:53 - 2017-03-25 08:28 - 15259136 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2017-04-13 07:53 - 2017-03-25 08:27 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-04-13 07:53 - 2017-03-25 08:24 - 03241472 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2017-04-13 07:53 - 2017-03-25 08:01 - 00800768 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2017-04-13 07:53 - 2017-03-24 14:50 - 00405504 _____ (Microsoft Corporation) C:\Windows\System32\gdi32.dll
2017-04-13 07:53 - 2017-03-24 14:42 - 00313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-04-13 07:53 - 2017-03-22 07:32 - 03165184 _____ (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2017-04-13 07:53 - 2017-03-22 07:32 - 00192512 _____ (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2017-04-13 07:53 - 2017-03-22 07:30 - 00091136 _____ (Microsoft Corporation) C:\Windows\System32\WinSetupUI.dll
2017-04-13 07:53 - 2017-03-22 07:17 - 02651136 _____ (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2017-04-13 07:53 - 2017-03-22 07:15 - 00037888 _____ (Microsoft Corporation) C:\Windows\System32\wups2.dll
2017-04-13 07:53 - 2017-03-22 07:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\System32\wups.dll
2017-04-13 07:53 - 2017-03-22 07:15 - 00012288 _____ (Microsoft Corporation) C:\Windows\System32\wu.upgrade.ps.dll
2017-04-13 07:53 - 2017-03-22 07:05 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2017-04-13 07:53 - 2017-03-14 07:34 - 00986344 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2017-04-13 07:53 - 2017-03-14 07:34 - 00265448 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys
2017-04-13 07:53 - 2017-03-10 08:35 - 00382696 _____ (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
2017-04-13 07:53 - 2017-03-10 08:27 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2017-04-13 07:53 - 2017-03-10 08:00 - 03219968 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys
2017-04-13 07:53 - 2017-03-08 12:20 - 01133568 _____ (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2017-04-13 07:53 - 2017-03-08 12:10 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2017-04-13 07:53 - 2017-03-07 20:37 - 00631176 _____ (Microsoft Corporation) C:\Windows\System32\winresume.efi
2017-04-13 07:53 - 2017-03-07 20:36 - 05548264 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2017-04-13 07:53 - 2017-03-07 20:36 - 00706792 _____ (Microsoft Corporation) C:\Windows\System32\winload.efi
2017-04-13 07:53 - 2017-03-07 20:36 - 00154856 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2017-04-13 07:53 - 2017-03-07 20:36 - 00095464 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2017-04-13 07:53 - 2017-03-07 20:34 - 01732864 _____ (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 02064384 _____ (Microsoft Corporation) C:\Windows\System32\ole32.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 01460736 _____ (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 01212928 _____ (Microsoft Corporation) C:\Windows\System32\rpcrt4.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 01163264 _____ (Microsoft Corporation) C:\Windows\System32\kernel32.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00880640 _____ (Microsoft Corporation) C:\Windows\System32\advapi32.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00730624 _____ (Microsoft Corporation) C:\Windows\System32\kerberos.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00690688 _____ (Microsoft Corporation) C:\Windows\System32\adtschema.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00503808 _____ (Microsoft Corporation) C:\Windows\System32\srcore.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00463872 _____ (Microsoft Corporation) C:\Windows\System32\certcli.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00419840 _____ (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00362496 _____ (Microsoft Corporation) C:\Windows\System32\wow64win.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00345600 _____ (Microsoft Corporation) C:\Windows\System32\schannel.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00316928 _____ (Microsoft Corporation) C:\Windows\System32\msv1_0.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00312320 _____ (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00243712 _____ (Microsoft Corporation) C:\Windows\System32\wow64.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00215552 _____ (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00210432 _____ (Microsoft Corporation) C:\Windows\System32\wdigest.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00190464 _____ (Microsoft Corporation) C:\Windows\System32\rpchttp.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00146432 _____ (Microsoft Corporation) C:\Windows\System32\msaudite.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00135680 _____ (Microsoft Corporation) C:\Windows\System32\sspicli.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00123904 _____ (Microsoft Corporation) C:\Windows\System32\bcrypt.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00086528 _____ (Microsoft Corporation) C:\Windows\System32\TSpkg.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00059904 _____ (Microsoft Corporation) C:\Windows\System32\appidapi.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00050176 _____ (Microsoft Corporation) C:\Windows\System32\srclient.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00044032 _____ (Microsoft Corporation) C:\Windows\System32\csrsrv.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00043520 _____ (Microsoft Corporation) C:\Windows\System32\cryptbase.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00034816 _____ (Microsoft Corporation) C:\Windows\System32\appidsvc.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00028160 _____ (Microsoft Corporation) C:\Windows\System32\secur32.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00022016 _____ (Microsoft Corporation) C:\Windows\System32\credssp.dll
2017-04-13 07:53 - 2017-03-07 20:33 - 00016384 _____ (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll
2017-04-13 07:53 - 2017-03-07 20:26 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-04-13 07:53 - 2017-03-07 20:26 - 03945192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-04-13 07:53 - 2017-03-07 20:24 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-04-13 07:53 - 2017-03-07 20:22 - 01416192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2017-04-13 07:53 - 2017-03-07 20:22 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-04-13 07:53 - 2017-03-07 20:22 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-04-13 07:53 - 2017-03-07 20:22 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-04-13 07:53 - 2017-03-07 20:22 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-04-13 07:53 - 2017-03-07 20:22 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-04-13 07:53 - 2017-03-07 20:22 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-04-13 07:53 - 2017-03-07 20:22 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-04-13 07:53 - 2017-03-07 20:22 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-04-13 07:53 - 2017-03-07 20:22 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-04-13 07:53 - 2017-03-07 20:22 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-04-13 07:53 - 2017-03-07 20:22 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-04-13 07:53 - 2017-03-07 20:22 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-04-13 07:53 - 2017-03-07 20:22 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-04-13 07:53 - 2017-03-07 20:22 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2017-04-13 07:53 - 2017-03-07 20:22 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-04-13 07:53 - 2017-03-07 20:21 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-04-13 07:53 - 2017-03-07 20:21 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-04-13 07:53 - 2017-03-07 20:21 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-04-13 07:53 - 2017-03-07 20:21 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-04-13 07:53 - 2017-03-07 20:03 - 00148480 _____ (Microsoft Corporation) C:\Windows\System32\appidpolicyconverter.exe
2017-04-13 07:53 - 2017-03-07 20:03 - 00064000 _____ (Microsoft Corporation) C:\Windows\System32\auditpol.exe
2017-04-13 07:53 - 2017-03-07 20:03 - 00062464 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\appid.sys
2017-04-13 07:53 - 2017-03-07 20:03 - 00017920 _____ (Microsoft Corporation) C:\Windows\System32\appidcertstorecheck.exe
2017-04-13 07:53 - 2017-03-07 20:00 - 00338432 _____ (Microsoft Corporation) C:\Windows\System32\conhost.exe
2017-04-13 07:53 - 2017-03-07 19:59 - 00296960 _____ (Microsoft Corporation) C:\Windows\System32\rstrui.exe
2017-04-13 07:53 - 2017-03-07 19:57 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-04-13 07:53 - 2017-03-07 19:56 - 00291328 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb10.sys
2017-04-13 07:53 - 2017-03-07 19:56 - 00159744 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb.sys
2017-04-13 07:53 - 2017-03-07 19:56 - 00129536 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb20.sys
2017-04-13 07:53 - 2017-03-07 19:55 - 00112640 _____ (Microsoft Corporation) C:\Windows\System32\smss.exe
2017-04-13 07:53 - 2017-03-07 19:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\System32\lsass.exe
2017-04-13 07:53 - 2017-03-07 19:54 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-04-13 07:53 - 2017-03-07 19:53 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-04-13 07:53 - 2017-03-07 08:30 - 00085504 _____ (Microsoft Corporation) C:\Windows\System32\asycfilt.dll
2017-04-13 07:53 - 2017-03-07 08:17 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2017-04-13 07:53 - 2017-03-03 17:27 - 01574912 _____ (Microsoft Corporation) C:\Windows\System32\quartz.dll
2017-04-13 07:53 - 2017-03-03 17:27 - 00093696 _____ (Microsoft Corporation) C:\Windows\System32\mfmjpegdec.dll
2017-04-13 07:53 - 2017-03-03 17:14 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2017-04-13 07:53 - 2017-03-03 17:14 - 00077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmjpegdec.dll
2017-04-13 07:53 - 2017-02-14 08:33 - 00757248 _____ (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2017-04-13 07:53 - 2017-02-14 08:19 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2017-04-13 07:53 - 2017-02-11 07:58 - 00462848 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\srv.sys
2017-04-13 07:53 - 2017-02-11 07:58 - 00405504 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\srv2.sys
2017-04-13 07:53 - 2017-02-11 07:58 - 00168960 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\srvnet.sys
2017-04-13 07:53 - 2017-02-10 08:32 - 00803328 _____ (Microsoft Corporation) C:\Windows\System32\usp10.dll
2017-04-13 07:53 - 2017-02-10 08:17 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2017-04-13 07:53 - 2017-02-10 06:33 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2017-04-13 07:53 - 2017-02-09 08:32 - 00769536 _____ (Microsoft Corporation) C:\Windows\System32\samsrv.dll
2017-04-13 07:53 - 2017-02-09 08:32 - 00106496 _____ (Microsoft Corporation) C:\Windows\System32\samlib.dll
2017-04-13 07:53 - 2017-02-09 08:32 - 00040960 _____ (Microsoft Corporation) C:\Windows\System32\WcsPlugInService.dll
2017-04-13 07:53 - 2017-02-09 08:31 - 00625664 _____ (Microsoft Corporation) C:\Windows\System32\mscms.dll
2017-04-13 07:53 - 2017-02-09 08:31 - 00250880 _____ (Microsoft Corporation) C:\Windows\System32\icm32.dll
2017-04-13 07:53 - 2017-02-09 08:14 - 00481792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll
2017-04-13 07:53 - 2017-02-09 08:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icm32.dll
2017-04-13 07:53 - 2017-02-09 08:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2017-04-13 07:53 - 2017-02-09 07:51 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcsPlugInService.dll
2017-04-13 07:53 - 2017-02-09 06:06 - 01648128 _____ (Microsoft Corporation) C:\Windows\System32\DWrite.dll
2017-04-13 07:53 - 2017-02-09 06:06 - 01180160 _____ (Microsoft Corporation) C:\Windows\System32\FntCache.dll
2017-04-13 07:53 - 2017-02-06 08:14 - 00733696 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe
2017-04-13 07:53 - 2017-01-18 07:36 - 00994760 _____ (Microsoft Corporation) C:\Windows\System32\ucrtbase.dll
2017-04-13 07:53 - 2017-01-18 07:36 - 00063840 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-private-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:36 - 00020832 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-math-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:36 - 00019808 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-string-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:36 - 00016224 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:36 - 00015712 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-convert-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-time-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-2-0.dll
2017-04-13 07:53 - 2017-01-18 07:36 - 00013664 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-process-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-heap-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-conio-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-utility-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-locale-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-environment-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-2-0.dll
2017-04-13 07:53 - 2017-01-18 07:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-13 07:53 - 2017-01-18 07:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l2-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-timezone-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l2-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:36 - 00011608 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-2-0.dll
2017-04-13 07:53 - 2017-01-18 07:35 - 00922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2017-04-13 07:53 - 2017-01-18 07:35 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:35 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:35 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:35 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:35 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2017-04-13 07:53 - 2017-01-18 07:35 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2017-04-13 07:53 - 2017-01-18 07:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-13 07:53 - 2017-01-18 07:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2017-04-13 07:53 - 2017-01-18 07:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2017-04-13 07:53 - 2017-01-13 10:00 - 00976896 _____ (Microsoft Corporation) C:\Windows\System32\inetcomm.dll
2017-04-13 07:53 - 2017-01-13 09:45 - 00741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2017-04-13 07:53 - 2017-01-11 10:01 - 01887744 _____ (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2017-04-13 07:53 - 2017-01-11 09:43 - 01241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2017-04-13 07:53 - 2016-11-21 10:12 - 00109568 _____ (Microsoft Corporation) C:\Windows\System32\hlink.dll
2017-04-13 07:53 - 2016-11-20 08:19 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hlink.dll
2017-04-13 07:53 - 2016-11-20 06:07 - 00467392 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2017-04-13 07:53 - 2016-11-17 08:41 - 00370920 _____ (Microsoft Corporation) C:\Windows\System32\clfs.sys
2017-04-13 07:53 - 2016-11-10 08:32 - 01009152 _____ (Microsoft Corporation) C:\Windows\System32\user32.dll
2017-04-13 07:53 - 2016-11-10 08:19 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2017-04-13 07:53 - 2016-11-09 08:41 - 00114408 _____ (Microsoft Corporation) C:\Windows\System32\consent.exe
2017-04-13 07:53 - 2016-11-09 08:33 - 03244032 _____ (Microsoft Corporation) C:\Windows\System32\msi.dll
2017-04-13 07:53 - 2016-11-09 08:33 - 01941504 _____ (Microsoft Corporation) C:\Windows\System32\authui.dll
2017-04-13 07:53 - 2016-11-09 08:33 - 00504320 _____ (Microsoft Corporation) C:\Windows\System32\msihnd.dll
2017-04-13 07:53 - 2016-11-09 08:33 - 00070144 _____ (Microsoft Corporation) C:\Windows\System32\appinfo.dll
2017-04-13 07:53 - 2016-11-09 08:17 - 02365440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2017-04-13 07:53 - 2016-11-09 08:17 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2017-04-13 07:53 - 2016-11-09 08:17 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2017-04-13 07:53 - 2016-11-09 08:02 - 00128512 _____ (Microsoft Corporation) C:\Windows\System32\msiexec.exe
2017-04-13 07:53 - 2016-11-09 07:55 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2017-04-13 07:53 - 2016-10-11 07:32 - 00069120 _____ (Microsoft Corporation) C:\Windows\System32\nlsbres.dll
2017-04-13 07:53 - 2016-10-11 07:31 - 01148416 _____ (Microsoft Corporation) C:\Windows\System32\IMJP10.IME
2017-04-13 07:53 - 2016-10-11 07:31 - 01068544 _____ (Microsoft Corporation) C:\Windows\System32\msctf.dll
2017-04-13 07:53 - 2016-10-11 07:31 - 00878080 _____ (Microsoft Corporation) C:\Windows\System32\IMJP10K.DLL
2017-04-13 07:53 - 2016-10-11 07:31 - 00457216 _____ (Microsoft Corporation) C:\Windows\System32\imkr80.ime
2017-04-13 07:53 - 2016-10-11 07:31 - 00246784 _____ (Microsoft Corporation) C:\Windows\System32\input.dll
2017-04-13 07:53 - 2016-10-11 07:31 - 00176128 _____ (Microsoft Corporation) C:\Windows\System32\tintlgnt.ime
2017-04-13 07:53 - 2016-10-11 07:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\System32\quick.ime
2017-04-13 07:53 - 2016-10-11 07:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\System32\qintlgnt.ime
2017-04-13 07:53 - 2016-10-11 07:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\System32\phon.ime
2017-04-13 07:53 - 2016-10-11 07:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\System32\cintlgnt.ime
2017-04-13 07:53 - 2016-10-11 07:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\System32\chajei.ime
2017-04-13 07:53 - 2016-10-11 07:31 - 00132608 _____ (Microsoft Corporation) C:\Windows\System32\pintlgnt.ime
2017-04-13 07:53 - 2016-10-11 07:18 - 01027584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10.IME
2017-04-13 07:53 - 2016-10-11 07:18 - 00829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2017-04-13 07:53 - 2016-10-11 07:18 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
2017-04-13 07:53 - 2016-10-11 07:18 - 00430080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imkr80.ime
2017-04-13 07:53 - 2016-10-11 07:18 - 00202240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\input.dll
2017-04-13 07:53 - 2016-10-11 07:18 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tintlgnt.ime
2017-04-13 07:53 - 2016-10-11 07:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quick.ime
2017-04-13 07:53 - 2016-10-11 07:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qintlgnt.ime
2017-04-13 07:53 - 2016-10-11 07:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\phon.ime
2017-04-13 07:53 - 2016-10-11 07:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cintlgnt.ime
2017-04-13 07:53 - 2016-10-11 07:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\chajei.ime
2017-04-13 07:53 - 2016-10-11 07:18 - 00090112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pintlgnt.ime
2017-04-13 07:53 - 2016-10-11 07:18 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlsbres.dll
2017-04-13 07:53 - 2016-10-11 06:55 - 00346112 _____ (Microsoft Corporation) C:\Windows\System32\bcdedit.exe
2017-04-13 07:53 - 2016-10-11 05:33 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2017-04-13 07:53 - 2016-10-11 05:18 - 00419648 _____ C:\Windows\SysWOW64\locale.nls
2017-04-13 07:53 - 2016-10-11 05:17 - 00419648 _____ C:\Windows\System32\locale.nls
2017-04-13 07:53 - 2016-10-11 05:06 - 00221184 _____ (Microsoft Corporation) C:\Windows\System32\UIAnimation.dll
2017-04-13 07:53 - 2016-10-08 05:06 - 00633296 _____ (Microsoft Corporation) C:\Windows\System32\winload.exe
2017-04-13 07:53 - 2016-10-07 07:32 - 03649536 _____ (Microsoft Corporation) C:\Windows\System32\MSVidCtl.dll
2017-04-13 07:53 - 2016-10-07 07:32 - 00877056 _____ (Microsoft Corporation) C:\Windows\System32\oleaut32.dll
2017-04-13 07:53 - 2016-10-07 07:12 - 02291712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll
2017-04-13 07:53 - 2016-10-07 07:12 - 00581632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2017-04-13 07:53 - 2016-10-05 06:54 - 00090112 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\bowser.sys
2017-04-13 07:53 - 2016-10-04 07:31 - 01483264 _____ (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2017-04-13 07:53 - 2016-10-04 07:31 - 00229376 _____ (Microsoft Corporation) C:\Windows\System32\wintrust.dll
2017-04-13 07:53 - 2016-10-04 07:31 - 00190976 _____ (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2017-04-13 07:53 - 2016-10-04 07:31 - 00141824 _____ (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2017-04-13 07:53 - 2016-10-04 07:13 - 01176064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2017-04-13 07:53 - 2016-10-04 07:13 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2017-04-13 07:53 - 2016-10-04 07:13 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2017-04-13 07:53 - 2016-10-04 07:13 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2017-04-13 07:53 - 2016-09-12 13:08 - 00107520 _____ (Microsoft Corporation) C:\Windows\System32\adsmsext.dll
2017-04-13 07:53 - 2016-09-12 12:49 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adsmsext.dll
2017-04-13 07:53 - 2016-09-08 12:34 - 00263680 _____ (Microsoft Corporation) C:\Windows\System32\WebClnt.dll
2017-04-13 07:53 - 2016-09-08 12:34 - 00208896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2017-04-13 07:53 - 2016-09-08 12:34 - 00108544 _____ (Microsoft Corporation) C:\Windows\System32\davclnt.dll
2017-04-13 07:53 - 2016-09-08 12:34 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2017-04-13 07:53 - 2016-09-08 06:55 - 00142336 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxdav.sys
2017-04-13 07:53 - 2016-09-08 06:55 - 00106496 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\dfsc.sys
2017-04-13 07:53 - 2016-08-22 08:19 - 01386496 _____ (Microsoft Corporation) C:\Windows\System32\diagtrack.dll
2017-04-13 07:53 - 2016-08-12 09:02 - 14632960 _____ (Microsoft Corporation) C:\Windows\System32\wmp.dll
2017-04-13 07:53 - 2016-08-12 09:02 - 12574720 _____ (Microsoft Corporation) C:\Windows\System32\wmploc.DLL
2017-04-13 07:53 - 2016-08-12 08:47 - 12574208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2017-04-13 07:53 - 2016-08-12 08:47 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2017-04-13 07:53 - 2016-08-12 08:26 - 00461312 _____ (Microsoft Corporation) C:\Windows\System32\scavengeui.dll
2017-04-13 07:53 - 2016-08-06 07:31 - 02023424 _____ (Microsoft Corporation) C:\Windows\System32\WsmSvc.dll
2017-04-13 07:53 - 2016-08-06 07:31 - 00347136 _____ (Microsoft Corporation) C:\Windows\System32\WSManMigrationPlugin.dll
2017-04-13 07:53 - 2016-08-06 07:31 - 00310784 _____ (Microsoft Corporation) C:\Windows\System32\WsmWmiPl.dll
2017-04-13 07:53 - 2016-08-06 07:31 - 00182272 _____ (Microsoft Corporation) C:\Windows\System32\WsmAuto.dll
2017-04-13 07:53 - 2016-08-06 07:15 - 01178112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2017-04-13 07:53 - 2016-08-06 07:15 - 00249344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2017-04-13 07:53 - 2016-08-06 07:15 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2017-04-13 07:53 - 2016-08-06 07:15 - 00146944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2017-04-13 07:53 - 2016-08-06 07:01 - 00266752 _____ (Microsoft Corporation) C:\Windows\System32\WSManHTTPConfig.exe
2017-04-13 07:53 - 2016-08-06 06:53 - 00199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2017-04-13 07:53 - 2016-06-14 09:21 - 00094440 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mountmgr.sys
2017-04-13 07:53 - 2016-06-14 09:16 - 04121600 _____ (Microsoft Corporation) C:\Windows\System32\mf.dll
2017-04-13 07:53 - 2016-06-14 09:16 - 01202176 _____ (Microsoft Corporation) C:\Windows\System32\drmv2clt.dll
2017-04-13 07:53 - 2016-06-14 09:16 - 01068544 _____ (Microsoft Corporation) C:\Windows\System32\cryptui.dll
2017-04-13 07:53 - 2016-06-14 09:16 - 00842240 _____ (Microsoft Corporation) C:\Windows\System32\blackbox.dll
2017-04-13 07:53 - 2016-06-14 09:16 - 00782848 _____ (Microsoft Corporation) C:\Windows\System32\wmdrmsdk.dll
2017-04-13 07:53 - 2016-06-14 09:16 - 00680448 _____ (Microsoft Corporation) C:\Windows\System32\audiosrv.dll
2017-04-13 07:53 - 2016-06-14 09:16 - 00641024 _____ (Microsoft Corporation) C:\Windows\System32\msscp.dll
2017-04-13 07:53 - 2016-06-14 09:16 - 00632320 _____ (Microsoft Corporation) C:\Windows\System32\evr.dll
2017-04-13 07:53 - 2016-06-14 09:16 - 00499712 _____ (Microsoft Corporation) C:\Windows\System32\AUDIOKSE.dll
2017-04-13 07:53 - 2016-06-14 09:16 - 00497664 _____ (Microsoft Corporation) C:\Windows\System32\drmmgrtn.dll
2017-04-13 07:53 - 2016-06-14 09:16 - 00440320 _____ (Microsoft Corporation) C:\Windows\System32\AudioEng.dll
2017-04-13 07:53 - 2016-06-14 09:16 - 00433152 _____ (Microsoft Corporation) C:\Windows\System32\mfplat.dll
2017-04-13 07:53 - 2016-06-14 09:16 - 00371712 _____ (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2017-04-13 07:53 - 2016-06-14 09:16 - 00325632 _____ (Microsoft Corporation) C:\Windows\System32\msnetobj.dll
2017-04-13 07:53 - 2016-06-14 09:16 - 00295936 _____ (Microsoft Corporation) C:\Windows\System32\AudioSes.dll
2017-04-13 07:53 - 2016-06-14 09:16 - 00284672 _____ (Microsoft Corporation) C:\Windows\System32\EncDump.dll
2017-04-13 07:53 - 2016-06-14 09:16 - 00206848 _____ (Microsoft Corporation) C:\Windows\System32\mfps.dll
2017-04-13 07:53 - 2016-06-14 09:16 - 00187904 _____ (Microsoft Corporation) C:\Windows\System32\pcasvc.dll
2017-04-13 07:53 - 2016-06-14 09:16 - 00081920 _____ (Microsoft Corporation) C:\Windows\System32\cryptsp.dll
2017-04-13 07:53 - 2016-06-14 09:16 - 00037376 _____ (Microsoft Corporation) C:\Windows\System32\pcadm.dll
2017-04-13 07:53 - 2016-06-14 09:11 - 00663552 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\PEAuth.sys
2017-04-13 07:53 - 2016-06-14 07:21 - 03209216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2017-04-13 07:53 - 2016-06-14 07:21 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2017-04-13 07:53 - 2016-06-14 07:21 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2017-04-13 07:53 - 2016-06-14 07:21 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2017-04-13 07:53 - 2016-06-14 07:21 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2017-04-13 07:53 - 2016-06-14 07:21 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2017-04-13 07:53 - 2016-06-14 07:21 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2017-04-13 07:53 - 2016-06-14 07:21 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2017-04-13 07:53 - 2016-06-14 07:21 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2017-04-13 07:53 - 2016-06-14 07:21 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2017-04-13 07:53 - 2016-06-14 07:21 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2017-04-13 07:53 - 2016-06-14 07:21 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2017-04-13 07:53 - 2016-06-14 07:21 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2017-04-13 07:53 - 2016-06-14 07:21 - 00195072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2017-04-13 07:53 - 2016-06-14 07:21 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2017-04-13 07:53 - 2016-06-14 07:21 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2017-04-13 07:53 - 2016-06-14 07:15 - 00125952 _____ (Microsoft Corporation) C:\Windows\System32\audiodg.exe
2017-04-13 07:52 - 2017-03-14 07:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\System32\cdd.dll
2017-04-13 07:52 - 2017-03-10 08:31 - 00100864 _____ (Microsoft Corporation) C:\Windows\System32\fontsub.dll
2017-04-13 07:52 - 2017-03-10 08:31 - 00046080 _____ (Adobe Systems) C:\Windows\System32\atmlib.dll
2017-04-13 07:52 - 2017-03-10 08:31 - 00041472 _____ (Microsoft Corporation) C:\Windows\System32\lpk.dll
2017-04-13 07:52 - 2017-03-10 08:31 - 00014336 _____ (Microsoft Corporation) C:\Windows\System32\dciman32.dll
2017-04-13 07:52 - 2017-03-10 08:20 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2017-04-13 07:52 - 2017-03-10 08:19 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2017-04-13 07:52 - 2017-03-10 08:19 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2017-04-13 07:52 - 2017-03-10 07:53 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00063488 _____ (Microsoft Corporation) C:\Windows\System32\setbcdlocale.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00060416 _____ (Microsoft Corporation) C:\Windows\System32\msobjs.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00028672 _____ (Microsoft Corporation) C:\Windows\System32\sspisrv.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00013312 _____ (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00006656 _____ (Microsoft Corporation) C:\Windows\System32\apisetschema.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00006144 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00005120 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-04-13 07:52 - 2017-03-07 20:22 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-04-13 07:52 - 2017-03-07 20:22 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 20:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 19:54 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-04-13 07:52 - 2017-03-07 19:54 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-04-13 07:52 - 2017-03-07 19:54 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-04-13 07:52 - 2017-03-07 19:53 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 19:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 19:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-04-13 07:52 - 2017-03-07 19:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-04-13 07:52 - 2017-02-11 08:33 - 00002048 _____ (Microsoft Corporation) C:\Windows\System32\tzres.dll
2017-04-13 07:52 - 2017-02-11 08:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2017-04-13 07:52 - 2017-01-13 10:00 - 00084480 _____ (Microsoft Corporation) C:\Windows\System32\INETRES.dll
2017-04-13 07:52 - 2017-01-13 09:45 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll
2017-04-13 07:52 - 2017-01-11 10:01 - 00002048 _____ (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2017-04-13 07:52 - 2017-01-11 09:43 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2017-04-13 07:52 - 2016-11-09 08:33 - 00025088 _____ (Microsoft Corporation) C:\Windows\System32\msimsg.dll
2017-04-13 07:52 - 2016-11-09 08:17 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2017-04-13 07:52 - 2016-08-12 09:02 - 00009728 _____ (Microsoft Corporation) C:\Windows\System32\spwmp.dll
2017-04-13 07:52 - 2016-08-12 09:02 - 00005120 _____ (Microsoft Corporation) C:\Windows\System32\msdxm.ocx
2017-04-13 07:52 - 2016-08-12 09:02 - 00005120 _____ (Microsoft Corporation) C:\Windows\System32\dxmasf.dll
2017-04-13 07:52 - 2016-08-12 08:31 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2017-04-13 07:52 - 2016-08-12 08:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2017-04-13 07:52 - 2016-08-12 08:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2017-04-13 07:52 - 2016-08-06 07:31 - 00054272 _____ (Microsoft Corporation) C:\Windows\System32\WsmRes.dll
2017-04-13 07:52 - 2016-08-06 07:31 - 00012800 _____ (Microsoft Corporation) C:\Windows\System32\wsmplpxy.dll
2017-04-13 07:52 - 2016-08-06 07:15 - 00054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmRes.dll
2017-04-13 07:52 - 2016-08-06 07:01 - 00013824 _____ (Microsoft Corporation) C:\Windows\System32\wsmprovhost.exe
2017-04-13 07:52 - 2016-08-06 06:53 - 00012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmprovhost.exe
2017-04-13 07:52 - 2016-08-06 06:53 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmplpxy.dll
2017-04-13 07:52 - 2016-06-14 09:16 - 00011264 _____ (Microsoft Corporation) C:\Windows\System32\msmmsp.dll
2017-04-13 07:52 - 2016-06-14 09:16 - 00008704 _____ (Microsoft Corporation) C:\Windows\System32\pcaevts.dll
2017-04-13 07:52 - 2016-06-14 09:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\System32\mferror.dll
2017-04-13 07:52 - 2016-06-14 07:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2017-04-13 07:52 - 2016-06-14 07:15 - 00055808 _____ (Microsoft Corporation) C:\Windows\System32\rrinstaller.exe
2017-04-13 07:52 - 2016-06-14 07:15 - 00024576 _____ (Microsoft Corporation) C:\Windows\System32\mfpmp.exe
2017-04-13 07:52 - 2016-06-14 07:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2017-04-13 07:52 - 2016-06-14 07:05 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2017-04-13 07:52 - 2016-06-14 07:00 - 00011264 _____ (Microsoft Corporation) C:\Windows\System32\pcawrk.exe
2017-04-13 07:52 - 2016-06-14 07:00 - 00009728 _____ (Microsoft Corporation) C:\Windows\System32\pcalua.exe
2017-04-13 07:46 - 2016-08-29 07:31 - 14183424 _____ (Microsoft Corporation) C:\Windows\System32\shell32.dll
2017-04-13 07:46 - 2016-08-29 07:31 - 01867776 _____ (Microsoft Corporation) C:\Windows\System32\ExplorerFrame.dll
2017-04-13 07:46 - 2016-08-29 07:12 - 12880384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2017-04-13 07:46 - 2016-08-29 07:04 - 03229696 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2017-04-13 07:46 - 2016-08-16 12:40 - 00343552 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbhub.sys
2017-04-13 07:46 - 2016-08-16 12:40 - 00327168 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbport.sys
2017-04-13 07:46 - 2016-08-16 12:40 - 00099840 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbccgp.sys
2017-04-13 07:46 - 2016-08-16 12:40 - 00056320 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbehci.sys
2017-04-13 07:46 - 2016-08-16 12:40 - 00030720 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbuhci.sys
2017-04-13 07:46 - 2016-08-16 12:40 - 00025600 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbohci.sys
2017-04-13 07:46 - 2016-08-16 12:40 - 00007808 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbd.sys
2017-04-13 07:46 - 2016-07-07 07:36 - 01896168 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2017-04-13 07:46 - 2016-07-07 07:36 - 00377576 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\netio.sys
2017-04-13 07:46 - 2016-07-07 07:36 - 00287976 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS
2017-04-13 07:46 - 2016-07-07 07:08 - 00046080 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tcpipreg.sys
2017-04-13 07:46 - 2016-05-12 07:18 - 00090624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\olepro32.dll
2017-04-13 07:46 - 2016-05-12 05:05 - 00297984 _____ (Microsoft Corporation) C:\Windows\System32\bcryptprimitives.dll
2017-04-13 07:46 - 2016-05-12 05:04 - 00249352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
2017-04-13 07:45 - 2017-02-22 15:42 - 00084712 _____ (Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
2017-04-13 07:45 - 2017-02-22 15:37 - 01285632 _____ (Microsoft Corporation) C:\Windows\System32\aeinv.dll
2017-04-13 07:45 - 2017-02-18 06:05 - 01609216 _____ (Microsoft Corporation) C:\Windows\System32\appraiser.dll
2017-04-13 07:45 - 2017-02-18 06:05 - 00646656 _____ (Microsoft Corporation) C:\Windows\System32\generaltel.dll
2017-04-13 07:45 - 2016-12-31 07:36 - 00556544 _____ (Microsoft Corporation) C:\Windows\System32\devinv.dll
2017-04-13 07:45 - 2016-12-31 07:36 - 00335360 _____ (Microsoft Corporation) C:\Windows\System32\invagent.dll
2017-04-13 07:45 - 2016-12-31 07:36 - 00293376 _____ (Microsoft Corporation) C:\Windows\System32\centel.dll
2017-04-13 07:45 - 2016-12-31 07:36 - 00233984 _____ (Microsoft Corporation) C:\Windows\System32\aepic.dll
2017-04-13 07:45 - 2016-12-31 07:36 - 00133632 _____ (Microsoft Corporation) C:\Windows\System32\acmigration.dll
2017-04-13 07:45 - 2016-08-29 07:12 - 01499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2017-04-13 07:45 - 2016-08-29 06:55 - 02972672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2017-04-13 05:38 - 2016-06-25 16:27 - 00970240 _____ (Microsoft Corporation) C:\Windows\System32\localspl.dll
2017-04-13 05:38 - 2016-06-25 16:27 - 00344576 _____ (Microsoft Corporation) C:\Windows\System32\ntprint.dll
2017-04-13 05:38 - 2016-06-25 16:27 - 00166400 _____ (Microsoft Corporation) C:\Windows\System32\inetpp.dll
2017-04-13 05:38 - 2016-06-25 16:27 - 00022528 _____ (Microsoft Corporation) C:\Windows\System32\inetppui.dll
2017-04-13 05:38 - 2016-06-25 11:53 - 00297472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.dll
2017-04-13 05:38 - 2016-06-25 11:53 - 00061952 _____ (Microsoft Corporation) C:\Windows\System32\ntprint.exe
2017-04-13 05:38 - 2016-06-25 11:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\wpnpinst.exe
2017-04-13 05:38 - 2016-06-25 11:41 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.exe
2017-04-13 05:37 - 2016-05-12 09:15 - 00105472 _____ (Microsoft Corporation) C:\Windows\System32\winipsec.dll
2017-04-13 05:37 - 2016-05-12 09:14 - 00794624 _____ (Microsoft Corporation) C:\Windows\System32\gpsvc.dll
2017-04-13 05:37 - 2016-05-12 09:14 - 00502272 _____ (Microsoft Corporation) C:\Windows\System32\IPSECSVC.DLL
2017-04-13 05:37 - 2016-05-12 09:14 - 00373760 _____ (Microsoft Corporation) C:\Windows\System32\polstore.dll
2017-04-13 05:37 - 2016-05-12 09:14 - 00096256 _____ (Microsoft Corporation) C:\Windows\System32\gpapi.dll
2017-04-13 05:37 - 2016-05-12 09:14 - 00075776 _____ (Microsoft Corporation) C:\Windows\System32\FwRemoteSvr.dll
2017-04-13 05:37 - 2016-05-12 07:18 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\polstore.dll
2017-04-13 05:37 - 2016-05-12 07:18 - 00079360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpapi.dll
2017-04-13 05:37 - 2016-05-12 07:18 - 00070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winipsec.dll
2017-04-13 05:37 - 2016-05-12 07:18 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FwRemoteSvr.dll
2017-04-13 05:37 - 2016-05-11 09:02 - 00483840 _____ (Microsoft Corporation) C:\Windows\System32\StructuredQuery.dll
2017-04-13 05:37 - 2016-05-11 09:02 - 00444928 _____ (Microsoft Corporation) C:\Windows\System32\winhttp.dll
2017-04-13 05:37 - 2016-05-11 09:02 - 00327168 _____ (Microsoft Corporation) C:\Windows\System32\mswsock.dll
2017-04-13 05:37 - 2016-05-11 09:02 - 00296448 _____ (Microsoft Corporation) C:\Windows\System32\ws2_32.dll
2017-04-13 05:37 - 2016-05-11 07:19 - 00363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2017-04-13 05:37 - 2016-05-11 07:19 - 00351744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2017-04-13 05:37 - 2016-05-11 07:19 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2017-04-13 05:37 - 2016-05-11 07:19 - 00206336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ws2_32.dll
2017-04-13 05:37 - 2016-05-11 07:11 - 00025088 _____ (Microsoft Corporation) C:\Windows\System32\netbtugc.exe
2017-04-13 05:37 - 2016-05-11 07:01 - 00026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netbtugc.exe
2017-04-13 05:37 - 2016-05-11 06:58 - 00262144 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\netbt.sys
2017-04-13 05:37 - 2016-04-14 05:49 - 00603648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2017-04-13 05:37 - 2016-04-14 05:21 - 00647680 _____ (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll
2017-04-13 05:37 - 2016-03-09 11:00 - 00396800 _____ (Microsoft Corporation) C:\Windows\System32\webio.dll
2017-04-13 05:37 - 2016-03-09 10:54 - 00275456 _____ (Microsoft Corporation) C:\Windows\System32\InkEd.dll
2017-04-13 05:37 - 2016-03-09 10:40 - 00316416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2017-04-13 05:37 - 2016-03-09 10:34 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2017-04-13 05:36 - 2016-04-08 20:20 - 01230848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2017-04-13 05:36 - 2016-04-08 19:52 - 01424896 _____ (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2017-04-11 11:42 - 2017-04-11 11:42 - 00253184 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgmfx64.sys
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-05-02 23:58 - 2016-11-10 09:57 - 00000000 ____D C:\ProgramData\MFAData
2017-05-02 23:58 - 2014-03-23 12:09 - 00000000 ____D C:\Users\Jacque\AppData\Roaming\Skype
2017-05-02 23:58 - 2014-03-23 11:49 - 00000000 ____D C:\users\Jacque
2017-05-02 23:58 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\registration
2017-05-02 23:58 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\inf
2017-04-30 19:03 - 2016-11-26 17:33 - 00000000 ____D C:\Users\Jacque\AppData\LocalLow\Mozilla
2017-04-28 13:47 - 2016-09-20 18:11 - 00003600 _____ C:\Windows\System32\Tasks\AVG EUpdate Task
2017-04-28 13:46 - 2009-07-13 20:45 - 00018736 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-04-28 13:46 - 2009-07-13 20:45 - 00018736 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-04-28 08:33 - 2017-03-22 12:39 - 00082720 _____ (Malwarebytes) C:\Windows\System32\Drivers\mwac.sys
2017-04-28 08:31 - 2017-03-22 12:39 - 00111544 _____ (Malwarebytes) C:\Windows\System32\Drivers\farflt.sys
2017-04-28 08:31 - 2017-03-22 12:38 - 00251832 _____ (Malwarebytes) C:\Windows\System32\Drivers\MBAMSwissArmy.sys
2017-04-28 08:31 - 2017-03-22 12:38 - 00043968 _____ (Malwarebytes) C:\Windows\System32\Drivers\mbam.sys
2017-04-28 08:29 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-04-25 06:48 - 2017-02-10 12:44 - 00003704 _____ C:\Windows\System32\Tasks\Java Platform SE Auto Updater
2017-04-24 10:29 - 2017-02-06 11:39 - 00000000 ____D C:\ProgramData\Oracle
2017-04-21 07:28 - 2016-10-28 10:00 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-04-20 07:19 - 2016-11-10 10:00 - 00000907 _____ C:\Users\Public\Desktop\AVG Protection.lnk
2017-04-19 06:27 - 2009-07-13 21:13 - 00782470 _____ C:\Windows\System32\PerfStringBackup.INI
2017-04-17 09:59 - 2016-04-09 12:22 - 00000000 ____D C:\Users\Jacque\Memoirs 2016 reorganized
2017-04-17 09:42 - 2017-03-22 12:38 - 00077440 _____ C:\Windows\System32\Drivers\mbae64.sys
2017-04-17 08:23 - 2017-03-22 12:39 - 00186304 _____ (Malwarebytes) C:\Windows\System32\Drivers\MBAMChameleon.sys
2017-04-17 05:50 - 2016-04-09 06:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2017-04-17 05:50 - 2014-03-23 12:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-04-16 14:08 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2017-04-14 06:48 - 2015-04-03 18:36 - 00000000 ___SD C:\Windows\System32\GWX
2017-04-14 06:47 - 2009-07-13 20:45 - 00467176 _____ C:\Windows\System32\FNTCACHE.DAT
2017-04-14 06:41 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files\DVD Maker
2017-04-14 06:41 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
2017-04-14 06:40 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\Dism
2017-04-14 06:39 - 2014-12-10 22:19 - 00000000 ____D C:\Windows\System32\appraiser
2017-04-14 06:39 - 2014-05-06 20:46 - 00000000 ___SD C:\Windows\System32\CompatTel
2017-04-14 06:36 - 2014-03-31 20:13 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-04-14 06:36 - 2014-03-31 20:13 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-04-14 06:36 - 2009-07-13 21:08 - 00032606 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-04-13 21:37 - 2014-03-23 12:50 - 00000000 ____D C:\Windows\System32\MRT
2017-04-13 21:33 - 2014-03-23 12:50 - 148601744 ____C (Microsoft Corporation) C:\Windows\System32\MRT.exe
2017-04-13 21:25 - 2014-03-24 03:42 - 00775084 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2017-04-13 05:15 - 2017-01-10 20:51 - 00001168 _____ C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2017-04-12 13:15 - 2014-12-26 16:08 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-04-10 09:16 - 2014-03-30 10:38 - 00007744 _____ C:\Users\Jacque\AppData\Roaming\wklnhst.dat
2017-04-10 09:16 - 2009-07-13 21:32 - 00000000 ____D C:\Windows\System32\FxsTmp
2017-04-10 00:11 - 2014-06-04 13:55 - 00000000 ____D C:\Windows\Minidump
2017-04-09 13:11 - 2014-03-23 10:43 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
 
==================== Known DLLs (Whitelisted) =========================
 
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\dnsapi.dll => MD5 is legit
C:\Windows\SysWOW64\dnsapi.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
 
==================== Association (Whitelisted) =============
 
 
==================== Restore Points =========================
 
Restore point date: 2017-04-28 13:52
Restore point date: 2017-04-30 16:36
 
==================== BCD ================================
 
Windows Boot Manager
--------------------
identifier              {bootmgr}
device                  partition=D:
description             Windows Boot Manager
locale                  en-US
inherit                 {globalsettings}
default                 {default}
resumeobject            {2ea62aa8-b2c2-11e3-8332-d37fa77daa6f}
displayorder            {default}
bootsequence            {memdiag}
toolsdisplayorder       {memdiag}
timeout                 30
 
Windows Boot Loader
-------------------
identifier              {default}
device                  partition=C:
path                    \windows\system32\winload.exe
description             Windows 7
locale                  en-US
inherit                 {bootloadersettings}
recoverysequence        {2ea62aaa-b2c2-11e3-8332-d37fa77daa6f}
recoveryenabled         Yes
osdevice                partition=C:
systemroot              \windows
resumeobject            {2ea62aa8-b2c2-11e3-8332-d37fa77daa6f}
nx                      OptIn
 
Windows Boot Loader
-------------------
identifier              {2ea62aaa-b2c2-11e3-8332-d37fa77daa6f}
device                  ramdisk=[D:]\Recovery\WindowsRE\Winre.wim,{2ea62aab-b2c2-11e3-8332-d37fa77daa6f}
path                    \windows\system32\winload.exe
description             Windows Recovery Environment
inherit                 {bootloadersettings}
osdevice                ramdisk=[D:]\Recovery\WindowsRE\Winre.wim,{2ea62aab-b2c2-11e3-8332-d37fa77daa6f}
systemroot              \windows
nx                      OptIn
winpe                   Yes
 
Resume from Hibernate
---------------------
identifier              {2ea62aa8-b2c2-11e3-8332-d37fa77daa6f}
device                  partition=C:
path                    \windows\system32\winresume.exe
description             Windows Resume Application
locale                  en-US
inherit                 {resumeloadersettings}
filedevice              partition=C:
filepath                \hiberfil.sys
debugoptionenabled      No
 
Windows Memory Tester
---------------------
identifier              {memdiag}
device                  partition=D:
path                    \boot\memtest.exe
description             Windows Memory Diagnostic
locale                  en-US
inherit                 {globalsettings}
badmemoryaccess         Yes
 
EMS Settings
------------
identifier              {emssettings}
bootems                 Yes
 
Debugger Settings
-----------------
identifier              {dbgsettings}
debugtype               Serial
debugport               1
baudrate                115200
 
RAM Defects
-----------
identifier              {badmemory}
 
Global Settings
---------------
identifier              {globalsettings}
inherit                 {dbgsettings}
                        {emssettings}
                        {badmemory}
 
Boot Loader Settings
--------------------
identifier              {bootloadersettings}
inherit                 {globalsettings}
                        {hypervisorsettings}
 
Hypervisor Settings
-------------------
identifier              {hypervisorsettings}
hypervisordebugtype     Serial
hypervisordebugport     1
hypervisorbaudrate      115200
 
Resume Loader Settings
----------------------
identifier              {resumeloadersettings}
inherit                 {globalsettings}
 
Device options
--------------
identifier              {2ea62aab-b2c2-11e3-8332-d37fa77daa6f}
description             Ramdisk Options
ramdisksdidevice        partition=D:
ramdisksdipath          \Recovery\WindowsRE\boot.sdi
 
 
==================== Memory info =========================== 
 
Percentage of memory in use: 16%
Total physical RAM: 3963.99 MB
Available physical RAM: 3326.13 MB
Total Virtual: 3962.14 MB
Available Virtual: 3325.45 MB
 
==================== Drives ================================
 
Drive c: (TI102618W0G) (Fixed) (Total:287.57 GB) (Free:226.81 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (System) (Fixed) (Total:1.46 GB) (Free:1.26 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive e: (TI102618W0G) (CDROM) (Total:0.16 GB) (Free:0 GB) CDFS
Drive f: (REPAIR DISK) (Removable) (Total:3.72 GB) (Free:3.72 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298.1 GB) (Disk ID: 3B56DC6B)
Partition 1: (Active) - (Size=1.5 GB) - (Type=27)
Partition 2: (Not Active) - (Size=287.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=9.1 GB) - (Type=17)
 
========================================================
Disk: 1 (Size: 3.7 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
LastRegBack: 2017-04-25 06:39
 
==================== End of FRST.txt ============================

Attached Files

  • Attached File  FRST.txt   81.46KB   44 downloads

  • 0

Advertisements


#2
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,668 posts
Hi! My name is zep516 and Welcome to Geekstogo!
I'll do the best I can to resolve your computer issue
Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, don't continue Stop and ask! Never be afraid to ask questions! :)

Download the attached file Attached File  fixlist.txt   2.21KB   37 downloads save it to the sane location FRST64 is f:\
  • Start FRST64 with Administrator privileges.
  • Press the Fix button.
  • When finished, a log file (Fixlog.txt) will pop up and saved in the same location the tool was ran from, f:\

    Please copy and paste its contents in your next reply.
    Boot in Normal Mode and let me know the outcome.


  • 0

#3
naomiq

naomiq

    New Member

  • Topic Starter
  • Member
  • Pip
  • 3 posts
Thanks for your help. Before I got your fixlist file, I ran some other diagnostics from the recovery disk that seemed to have jump-started the computer but the background was lost and there's a permanent dialog box in the middle of the screen with unclickable buttons.
 
Here are the results of running the fixlist:
 
Fix result of Farbar Recovery Scan Tool (x64) Version: 01-05-2017
Ran by SYSTEM (03-05-2017 22:16:34) Run:1
Running from F:\
Boot Mode: Recovery
==============================================
 
fixlist content:
*****************
HKLM\...\Run: [] => [X]
HKLM\...26dfa299cadb\InprocServer32: [Authentication UI Logon UI] authuitu.dll <==== ATTENTION
IFEO\cfaddgadgets.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\cfmain.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\cfprofile.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\ndstray.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\pcdiag.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\smoothview.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\tacsprop.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\teco.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\tfcconf.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\tfcrst.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\tobuactivation.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\todisc.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\toshibaservicestation.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\tosramutil.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\tosssdalert.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\tpchviewer.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\twebcamera.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\wddmstatus.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\wddriveutilities.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\wdsmartware.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [X]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
 
*****************
 
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
HKLM\Software\Classes\CLSID\{7986d495-ce42-4926-8afc-26dfa299cadb}\InprocServer32\\Default => value restored successfully
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cfaddgadgets.exe => key removed successfully
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cfmain.exe => key removed successfully
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cfprofile.exe => key removed successfully
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\ndstray.exe => key removed successfully
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pcdiag.exe => key removed successfully
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\smoothview.exe => key removed successfully
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\tacsprop.exe => key removed successfully
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\teco.exe => key removed successfully
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\tfcconf.exe => key removed successfully
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\tfcrst.exe => key removed successfully
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\tobuactivation.exe => key removed successfully
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\todisc.exe => key removed successfully
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\toshibaservicestation.exe => key removed successfully
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\tosramutil.exe => key removed successfully
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\tosssdalert.exe => key removed successfully
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\tpchviewer.exe => key removed successfully
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\twebcamera.exe => key removed successfully
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\wddmstatus.exe => key removed successfully
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\wddriveutilities.exe => key removed successfully
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\wdsmartware.exe => key removed successfully
HKLM\System\ControlSet001\Services\RSUSBSTOR => key removed successfully
RSUSBSTOR => service removed successfully
HKLM\System\ControlSet001\Services\RtsUIR => key removed successfully
RtsUIR => service removed successfully
HKLM\System\ControlSet001\Services\USBCCID => key removed successfully
USBCCID => service removed successfully
 
==== End of Fixlog 22:16:34 ====

  • 0

#4
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,668 posts
Hello,

Re-run FRST from normal mode and post the 2 logs created, FRST,txt & Additions.txt
  • 0

#5
naomiq

naomiq

    New Member

  • Topic Starter
  • Member
  • Pip
  • 3 posts

Thank you. Here they are:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 01-05-2017

Ran by Jacque (administrator) on JACQUEENSIGN (04-05-2017 22:58:44)
Running from G:\
Loaded Profiles: Jacque &  (Available Profiles: Jacque)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgfwsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagenta.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvca.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgemca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppVShNotify.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7982112 2009-07-28] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1815848 2009-07-20] (Synaptics Incorporated)
HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [497504 2009-08-05] (TOSHIBA Corporation)
HKLM\...\Run: [HSON] => C:\Program Files\TOSHIBA\TBS\HSON.exe [52600 2009-03-09] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] => C:\Program Files\Toshiba\SmoothView\SmoothView.exe [508216 2009-07-28] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [909624 2009-08-05] (TOSHIBA Corporation)
HKLM\...\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [711000 2009-08-04] (TOSHIBA Corporation)
HKLM\...\Run: [Teco] => C:\Program Files\TOSHIBA\TECO\Teco.exe [1482080 2009-08-11] (TOSHIBA Corporation)
HKLM\...\Run: [SmartFaceVWatcher] => C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [238080 2009-07-29] (TOSHIBA Corporation)
HKLM\...\Run: [TosSENotify] => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [709976 2009-08-03] (TOSHIBA Corporation)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch                                                                                                                               (the data entry has 65 more characters).
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes)
HKLM-x32\...\Run: [NortonOnlineBackupReminder] => C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TobuActivation.exe [529256 2009-07-16] (Toshiba)
HKLM-x32\...\Run: [TWebCamera] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2446648 2009-08-11] (TOSHIBA CORPORATION.)
HKLM-x32\...\Run: [WD Quick View] => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5571944 2016-04-19] (Western Digital Technologies, Inc.)
HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [240400 2016-12-06] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [240400 2016-12-06] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [WD Drive Unlocker] => C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe [1761120 2015-12-07] (Western Digital Technologies, Inc.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05042017225523805\...\RunOnce: [SPReview] => C:\windows\System32\SPReview\SPReview.exe [301568 2014-03-23] (Microsoft Corporation)
HKU\S-1-5-21-1359882058-2057507765-851322289-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27545048 2017-03-14] (Skype Technologies S.A.)
HKU\S-1-5-21-1359882058-2057507765-851322289-1001\...\MountPoints2: E - E:\TL_Bootstrap.exe
HKU\S-1-5-21-1359882058-2057507765-851322289-1001\...\MountPoints2: {28423135-cc4d-11e4-9009-001e33fe384a} - F:\TLBootstrap_WPP.exe
HKU\S-1-5-21-1359882058-2057507765-851322289-1001\...\MountPoints2: {74cc4d49-b2df-11e3-8b28-001e33fe384a} - "E:\WD Drive Unlock.exe" autoplay=true
HKU\S-1-5-21-1359882058-2057507765-851322289-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05042017225524601\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27545048 2017-03-14] (Skype Technologies S.A.)
HKU\S-1-5-21-1359882058-2057507765-851322289-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05042017225524601\...\MountPoints2: E - E:\TL_Bootstrap.exe
HKU\S-1-5-21-1359882058-2057507765-851322289-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05042017225524601\...\MountPoints2: {28423135-cc4d-11e4-9009-001e33fe384a} - F:\TLBootstrap_WPP.exe
HKU\S-1-5-21-1359882058-2057507765-851322289-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05042017225524601\...\MountPoints2: {74cc4d49-b2df-11e3-8b28-001e33fe384a} - "E:\WD Drive Unlock.exe" autoplay=true
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\windows\System32\SPReview\SPReview.exe [301568 2014-03-23] (Microsoft Corporation)
IFEO\AcroRd32.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{250052ED-85C0-46F9-9D16-D1C5D2AF098C}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.toshiba.com/
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://start.toshiba.com/
HKU\S-1-5-21-1359882058-2057507765-851322289-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=SKY2&ocid=SKY2DHP&osmkt=en-us
HKU\S-1-5-21-1359882058-2057507765-851322289-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://start.toshiba.com/
HKU\S-1-5-21-1359882058-2057507765-851322289-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05042017225524601\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=SKY2&ocid=SKY2DHP&osmkt=en-us
HKU\S-1-5-21-1359882058-2057507765-851322289-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05042017225524601\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://start.toshiba.com/
SearchScopes: HKLM -> DefaultScope {8C681919-1BB3-4D78-8810-F0351DC9EF21} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNA
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {8C681919-1BB3-4D78-8810-F0351DC9EF21} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNA
SearchScopes: HKLM-x32 -> DefaultScope {274FC070-43E0-49F0-A4EA-DA19DAB17D5D} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNA
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {274FC070-43E0-49F0-A4EA-DA19DAB17D5D} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNA
SearchScopes: HKU\S-1-5-21-1359882058-2057507765-851322289-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=SKY2DF&PC=SKY2&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1359882058-2057507765-851322289-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=SKY2DF&PC=SKY2&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1359882058-2057507765-851322289-1001 -> {274FC070-43E0-49F0-A4EA-DA19DAB17D5D} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNA_enUS580
SearchScopes: HKU\S-1-5-21-1359882058-2057507765-851322289-1001 -> {8C681919-1BB3-4D78-8810-F0351DC9EF21} URL = 
SearchScopes: HKU\S-1-5-21-1359882058-2057507765-851322289-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05042017225524601 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=SKY2DF&PC=SKY2&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1359882058-2057507765-851322289-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05042017225524601 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=SKY2DF&PC=SKY2&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1359882058-2057507765-851322289-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05042017225524601 -> {274FC070-43E0-49F0-A4EA-DA19DAB17D5D} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNA_enUS580
SearchScopes: HKU\S-1-5-21-1359882058-2057507765-851322289-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05042017225524601 -> {8C681919-1BB3-4D78-8810-F0351DC9EF21} URL = 
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-05-03] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL [2017-05-03] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-05-03] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-04-24] (Oracle Corporation)
BHO-x32: Windows Live Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL [2017-05-03] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-04-24] (Oracle Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-03] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-03] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-03] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-03] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2017-01-01] (Skype Technologies)
 
FireFox:
========
FF ProfilePath: C:\Users\Jacque\AppData\Roaming\Mozilla\Firefox\Profiles\inslk75w.default-1454989179346 [2017-05-04]
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_25_0_0_148.dll [2017-05-03] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_148.dll [2017-05-03] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-04-24] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-04-24] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-03-05] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2009-07-10] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-04] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1359882058-2057507765-851322289-1001: @citrixonline.com/appdetectorplugin -> C:\Users\Jacque\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2015-08-30] (Citrix Online)
FF Plugin HKU\S-1-5-21-1359882058-2057507765-851322289-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05042017225524601: @citrixonline.com/appdetectorplugin -> C:\Users\Jacque\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2015-08-30] (Citrix Online)
 
Chrome: 
=======
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [1002552 2017-04-11] (AVG Technologies CZ, s.r.o.)
R2 avgfws; C:\Program Files (x86)\AVG\Av\avgfwsa.exe [1824184 2017-04-11] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagenta.exe [5334432 2017-04-11] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1146128 2016-12-06] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvca.exe [729048 2017-04-11] (AVG Technologies CZ, s.r.o.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3801280 2017-04-19] (Microsoft Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [5906704 2017-02-21] (AVG Technologies CZ, s.r.o.)
R2 UxTuneUp; C:\windows\System32\uxtuneup.dll [56080 2017-02-21] (AVG Technologies CZ, s.r.o.)
R2 UxTuneUp; C:\windows\SysWOW64\uxtuneup.dll [48912 2017-02-21] (AVG Technologies CZ, s.r.o.)
S4 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1049464 2016-04-19] (Western Digital Technologies, Inc.)
R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [314744 2016-04-19] (Western Digital Technologies, Inc.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 Avgdiska; C:\windows\System32\DRIVERS\avgdiska.sys [163072 2016-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgfwfd; C:\windows\System32\DRIVERS\avgfwd6a.sys [73992 2016-10-23] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\windows\System32\DRIVERS\avgidsdrivera.sys [313088 2017-02-20] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\windows\System32\DRIVERS\avgidsha.sys [267008 2016-10-05] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\windows\System32\DRIVERS\avgldx64.sys [298240 2016-11-30] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\windows\System32\DRIVERS\avgloga.sys [360736 2016-02-16] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\windows\System32\DRIVERS\avgmfx64.sys [253184 2017-04-11] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\windows\System32\DRIVERS\avgrkx64.sys [52992 2016-06-01] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\windows\System32\DRIVERS\avgtdia.sys [299264 2016-07-27] (AVG Technologies CZ, s.r.o.)
R0 avguniva; C:\windows\System32\DRIVERS\avguniva.sys [77056 2016-06-20] (AVG Technologies CZ, s.r.o.)
R1 ESProtectionDriver; C:\windows\system32\drivers\mbae64.sys [77440 2017-04-17] ()
R2 MBAMChameleon; C:\windows\system32\drivers\MBAMChameleon.sys [186304 2017-04-17] (Malwarebytes)
R3 MBAMFarflt; C:\windows\system32\drivers\farflt.sys [111544 2017-05-03] (Malwarebytes)
R3 MBAMProtection; C:\windows\system32\drivers\mbam.sys [43968 2017-05-03] (Malwarebytes)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [251832 2017-05-03] (Malwarebytes)
R3 MBAMWebProtection; C:\windows\system32\drivers\mwac.sys [82720 2017-05-04] (Malwarebytes)
S3 RTL8187Se; C:\windows\System32\DRIVERS\RTL8187Se.sys [427008 2009-06-10] (Realtek Semiconductor Corporation                           )
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [32304 2016-02-15] (AVG Netherlands B.V.)
R3 WDC_SAM; C:\windows\System32\DRIVERS\wdcsam64_prewin8.sys [23200 2016-04-19] (Western Digital Technologies)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-05-04 06:50 - 2017-05-04 06:50 - 00001143 _____ C:\Users\Public\Desktop\WD Security.lnk
2017-05-03 02:46 - 2017-05-04 22:58 - 00000000 ____D C:\FRST
2017-04-24 11:30 - 2017-04-24 11:30 - 00003144 _____ C:\windows\System32\Tasks\{52255622-5B0F-4D8F-9A7A-6AC6FB06B9F5}
2017-04-24 11:25 - 2017-04-24 11:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-04-24 11:25 - 2017-04-24 11:24 - 00097856 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2017-04-24 11:24 - 2017-04-24 11:24 - 00000000 ____D C:\Program Files (x86)\Java
2017-04-13 11:31 - 2017-04-13 11:31 - 00514980 _____ C:\Users\Jacque\Documents\Indian-Uses-Short-Form.pdf
2017-04-13 08:54 - 2017-03-27 11:13 - 00394448 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2017-04-13 08:54 - 2017-03-27 10:28 - 00346320 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2017-04-13 08:54 - 2017-03-25 12:39 - 20284416 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2017-04-13 08:54 - 2017-03-25 11:52 - 02289152 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2017-04-13 08:54 - 2017-03-25 11:51 - 01313280 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2017-04-13 08:54 - 2017-03-25 11:48 - 00499200 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2017-04-13 08:54 - 2017-03-25 11:47 - 02055680 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2017-04-13 08:54 - 2017-03-25 11:46 - 00693248 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2017-04-13 08:54 - 2017-03-25 11:46 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2017-04-13 08:54 - 2017-03-25 11:46 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2017-04-13 08:54 - 2017-03-25 11:46 - 00130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2017-04-13 08:54 - 2017-03-25 11:46 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-04-13 08:54 - 2017-03-25 11:46 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2017-04-13 08:54 - 2017-03-25 11:45 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2017-04-13 08:54 - 2017-03-25 11:45 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2017-04-13 08:54 - 2017-03-25 11:45 - 00091136 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
2017-04-13 08:54 - 2017-03-25 11:45 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2017-04-13 08:54 - 2017-03-25 11:45 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2017-04-13 08:54 - 2017-03-25 11:45 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2017-04-13 08:54 - 2017-03-25 11:44 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2017-04-13 08:54 - 2017-03-25 11:35 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2017-04-13 08:54 - 2017-03-25 11:14 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2017-04-13 08:54 - 2017-03-25 11:02 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2017-04-13 08:54 - 2017-03-25 10:56 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2017-04-13 08:54 - 2017-03-25 10:30 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2017-04-13 08:54 - 2017-03-25 10:29 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2017-04-13 08:54 - 2017-03-25 10:17 - 00152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2017-04-13 08:54 - 2017-03-25 10:00 - 00725504 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2017-04-13 08:54 - 2017-03-25 09:10 - 01546240 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2017-04-13 08:54 - 2017-03-22 08:32 - 00098816 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2017-04-13 08:54 - 2017-03-22 08:24 - 00174080 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2017-04-13 08:54 - 2017-03-22 08:15 - 00709120 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2017-04-13 08:54 - 2017-03-22 08:15 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2017-04-13 08:54 - 2017-03-22 08:15 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2017-04-13 08:54 - 2017-03-22 08:05 - 00573440 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2017-04-13 08:54 - 2017-03-22 08:05 - 00093696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2017-04-13 08:54 - 2017-03-22 08:05 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2017-04-13 08:54 - 2016-09-15 07:56 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\UtcResources.dll
2017-04-13 08:54 - 2016-07-22 07:58 - 00142336 _____ (Microsoft Corporation) C:\windows\system32\poqexec.exe
2017-04-13 08:54 - 2016-07-22 07:51 - 00123904 _____ (Microsoft Corporation) C:\windows\SysWOW64\poqexec.exe
2017-04-13 08:53 - 2017-03-25 12:07 - 04604416 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2017-04-13 08:53 - 2017-03-25 12:06 - 13654016 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2017-04-13 08:53 - 2017-03-25 11:55 - 02767360 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2017-04-13 08:53 - 2017-03-25 11:47 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2017-04-13 08:53 - 2017-03-25 11:47 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2017-04-13 08:53 - 2017-03-25 11:46 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2017-04-13 08:53 - 2017-03-25 11:46 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2017-04-13 08:53 - 2017-03-25 11:45 - 00416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2017-04-13 08:53 - 2017-03-25 11:44 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2017-04-13 08:53 - 2017-03-25 11:35 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2017-04-13 08:53 - 2017-03-25 11:16 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2017-04-13 08:53 - 2017-03-25 11:14 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2017-04-13 08:53 - 2017-03-25 11:13 - 00576512 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2017-04-13 08:53 - 2017-03-25 11:13 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2017-04-13 08:53 - 2017-03-25 11:10 - 02898432 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2017-04-13 08:53 - 2017-03-25 11:04 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2017-04-13 08:53 - 2017-03-25 10:57 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2017-04-13 08:53 - 2017-03-25 10:56 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2017-04-13 08:53 - 2017-03-25 10:56 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2017-04-13 08:53 - 2017-03-25 10:56 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2017-04-13 08:53 - 2017-03-25 10:52 - 25746944 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2017-04-13 08:53 - 2017-03-25 10:45 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2017-04-13 08:53 - 2017-03-25 10:41 - 06045696 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2017-04-13 08:53 - 2017-03-25 10:41 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2017-04-13 08:53 - 2017-03-25 10:24 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2017-04-13 08:53 - 2017-03-25 10:23 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2017-04-13 08:53 - 2017-03-25 10:20 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2017-04-13 08:53 - 2017-03-25 10:19 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2017-04-13 08:53 - 2017-03-25 10:06 - 00476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2017-04-13 08:53 - 2017-03-25 10:04 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2017-04-13 08:53 - 2017-03-25 09:59 - 00806912 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2017-04-13 08:53 - 2017-03-25 09:57 - 02131456 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2017-04-13 08:53 - 2017-03-25 09:57 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2017-04-13 08:53 - 2017-03-25 09:28 - 15259136 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2017-04-13 08:53 - 2017-03-25 09:27 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2017-04-13 08:53 - 2017-03-25 09:24 - 03241472 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2017-04-13 08:53 - 2017-03-25 09:01 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2017-04-13 08:53 - 2017-03-24 15:50 - 00405504 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2017-04-13 08:53 - 2017-03-24 15:42 - 00313344 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2017-04-13 08:53 - 2017-03-22 08:32 - 03165184 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2017-04-13 08:53 - 2017-03-22 08:32 - 00192512 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2017-04-13 08:53 - 2017-03-22 08:30 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2017-04-13 08:53 - 2017-03-22 08:17 - 02651136 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2017-04-13 08:53 - 2017-03-22 08:15 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2017-04-13 08:53 - 2017-03-22 08:15 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2017-04-13 08:53 - 2017-03-22 08:15 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2017-04-13 08:53 - 2017-03-22 08:05 - 00030208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2017-04-13 08:53 - 2017-03-14 08:34 - 00986344 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys
2017-04-13 08:53 - 2017-03-14 08:34 - 00265448 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgmms1.sys
2017-04-13 08:53 - 2017-03-10 09:35 - 00382696 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2017-04-13 08:53 - 2017-03-10 09:27 - 00308456 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2017-04-13 08:53 - 2017-03-10 09:00 - 03219968 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2017-04-13 08:53 - 2017-03-08 13:20 - 01133568 _____ (Microsoft Corporation) C:\windows\system32\cdosys.dll
2017-04-13 08:53 - 2017-03-08 13:10 - 00805376 _____ (Microsoft Corporation) C:\windows\SysWOW64\cdosys.dll
2017-04-13 08:53 - 2017-03-07 21:37 - 00631176 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2017-04-13 08:53 - 2017-03-07 21:36 - 05548264 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2017-04-13 08:53 - 2017-03-07 21:36 - 00706792 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2017-04-13 08:53 - 2017-03-07 21:36 - 00154856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2017-04-13 08:53 - 2017-03-07 21:36 - 00095464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2017-04-13 08:53 - 2017-03-07 21:34 - 01732864 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 02064384 _____ (Microsoft Corporation) C:\windows\system32\ole32.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 01460736 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 01212928 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00880640 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00730624 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00463872 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00419840 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00345600 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00215552 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00190464 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00123904 _____ (Microsoft Corporation) C:\windows\system32\bcrypt.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00059904 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00034816 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2017-04-13 08:53 - 2017-03-07 21:33 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2017-04-13 08:53 - 2017-03-07 21:26 - 04000488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2017-04-13 08:53 - 2017-03-07 21:26 - 03945192 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2017-04-13 08:53 - 2017-03-07 21:24 - 01314112 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2017-04-13 08:53 - 2017-03-07 21:22 - 01416192 _____ (Microsoft Corporation) C:\windows\SysWOW64\ole32.dll
2017-04-13 08:53 - 2017-03-07 21:22 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2017-04-13 08:53 - 2017-03-07 21:22 - 00666112 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2017-04-13 08:53 - 2017-03-07 21:22 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2017-04-13 08:53 - 2017-03-07 21:22 - 00275456 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2017-04-13 08:53 - 2017-03-07 21:22 - 00261120 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2017-04-13 08:53 - 2017-03-07 21:22 - 00254464 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2017-04-13 08:53 - 2017-03-07 21:22 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2017-04-13 08:53 - 2017-03-07 21:22 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2017-04-13 08:53 - 2017-03-07 21:22 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2017-04-13 08:53 - 2017-03-07 21:22 - 00141312 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpchttp.dll
2017-04-13 08:53 - 2017-03-07 21:22 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2017-04-13 08:53 - 2017-03-07 21:22 - 00082944 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcrypt.dll
2017-04-13 08:53 - 2017-03-07 21:22 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2017-04-13 08:53 - 2017-03-07 21:22 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2017-04-13 08:53 - 2017-03-07 21:22 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2017-04-13 08:53 - 2017-03-07 21:21 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2017-04-13 08:53 - 2017-03-07 21:21 - 00644096 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2017-04-13 08:53 - 2017-03-07 21:21 - 00342528 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2017-04-13 08:53 - 2017-03-07 21:21 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
2017-04-13 08:53 - 2017-03-07 21:03 - 00148480 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2017-04-13 08:53 - 2017-03-07 21:03 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2017-04-13 08:53 - 2017-03-07 21:03 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2017-04-13 08:53 - 2017-03-07 21:03 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2017-04-13 08:53 - 2017-03-07 21:00 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2017-04-13 08:53 - 2017-03-07 20:59 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2017-04-13 08:53 - 2017-03-07 20:57 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2017-04-13 08:53 - 2017-03-07 20:56 - 00291328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2017-04-13 08:53 - 2017-03-07 20:56 - 00159744 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2017-04-13 08:53 - 2017-03-07 20:56 - 00129536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2017-04-13 08:53 - 2017-03-07 20:55 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2017-04-13 08:53 - 2017-03-07 20:55 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2017-04-13 08:53 - 2017-03-07 20:54 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2017-04-13 08:53 - 2017-03-07 20:53 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2017-04-13 08:53 - 2017-03-07 09:30 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\asycfilt.dll
2017-04-13 08:53 - 2017-03-07 09:17 - 00067584 _____ (Microsoft Corporation) C:\windows\SysWOW64\asycfilt.dll
2017-04-13 08:53 - 2017-03-03 18:27 - 01574912 _____ (Microsoft Corporation) C:\windows\system32\quartz.dll
2017-04-13 08:53 - 2017-03-03 18:27 - 00093696 _____ (Microsoft Corporation) C:\windows\system32\mfmjpegdec.dll
2017-04-13 08:53 - 2017-03-03 18:14 - 01329664 _____ (Microsoft Corporation) C:\windows\SysWOW64\quartz.dll
2017-04-13 08:53 - 2017-03-03 18:14 - 00077312 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfmjpegdec.dll
2017-04-13 08:53 - 2017-02-14 09:33 - 00757248 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll
2017-04-13 08:53 - 2017-02-14 09:19 - 00497664 _____ (Microsoft Corporation) C:\windows\SysWOW64\win32spl.dll
2017-04-13 08:53 - 2017-02-11 08:58 - 00462848 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv.sys
2017-04-13 08:53 - 2017-02-11 08:58 - 00405504 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv2.sys
2017-04-13 08:53 - 2017-02-11 08:58 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srvnet.sys
2017-04-13 08:53 - 2017-02-10 09:32 - 00803328 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll
2017-04-13 08:53 - 2017-02-10 09:17 - 00628736 _____ (Microsoft Corporation) C:\windows\SysWOW64\usp10.dll
2017-04-13 08:53 - 2017-02-10 07:33 - 01251328 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWrite.dll
2017-04-13 08:53 - 2017-02-09 09:32 - 00769536 _____ (Microsoft Corporation) C:\windows\system32\samsrv.dll
2017-04-13 08:53 - 2017-02-09 09:32 - 00106496 _____ (Microsoft Corporation) C:\windows\system32\samlib.dll
2017-04-13 08:53 - 2017-02-09 09:32 - 00040960 _____ (Microsoft Corporation) C:\windows\system32\WcsPlugInService.dll
2017-04-13 08:53 - 2017-02-09 09:31 - 00625664 _____ (Microsoft Corporation) C:\windows\system32\mscms.dll
2017-04-13 08:53 - 2017-02-09 09:31 - 00250880 _____ (Microsoft Corporation) C:\windows\system32\icm32.dll
2017-04-13 08:53 - 2017-02-09 09:14 - 00481792 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscms.dll
2017-04-13 08:53 - 2017-02-09 09:14 - 00215040 _____ (Microsoft Corporation) C:\windows\SysWOW64\icm32.dll
2017-04-13 08:53 - 2017-02-09 09:14 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\samlib.dll
2017-04-13 08:53 - 2017-02-09 08:51 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\WcsPlugInService.dll
2017-04-13 08:53 - 2017-02-09 07:06 - 01648128 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
2017-04-13 08:53 - 2017-02-09 07:06 - 01180160 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll
2017-04-13 08:53 - 2017-02-06 09:14 - 00733696 _____ (Microsoft Corporation) C:\windows\HelpPane.exe
2017-04-13 08:53 - 2017-01-18 08:36 - 00994760 _____ (Microsoft Corporation) C:\windows\system32\ucrtbase.dll
2017-04-13 08:53 - 2017-01-18 08:36 - 00063840 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-private-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:36 - 00020832 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-math-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:36 - 00019808 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:36 - 00017760 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-string-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:36 - 00017760 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:36 - 00016224 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:36 - 00015712 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:36 - 00014176 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-time-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:36 - 00014176 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-2-0.dll
2017-04-13 08:53 - 2017-01-18 08:36 - 00013664 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:36 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-process-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:36 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:36 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:36 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:36 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:36 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:36 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
2017-04-13 08:53 - 2017-01-18 08:36 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-13 08:53 - 2017-01-18 08:36 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:36 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:36 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l2-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:36 - 00011608 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-2-0.dll
2017-04-13 08:53 - 2017-01-18 08:35 - 00922432 _____ (Microsoft Corporation) C:\windows\SysWOW64\ucrtbase.dll
2017-04-13 08:53 - 2017-01-18 08:35 - 00066400 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:35 - 00022368 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:35 - 00019808 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:35 - 00017760 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:35 - 00017760 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:35 - 00016224 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:35 - 00015712 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:35 - 00014176 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:35 - 00014176 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2017-04-13 08:53 - 2017-01-18 08:35 - 00013664 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:35 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:35 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:35 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:35 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:35 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:35 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:35 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2017-04-13 08:53 - 2017-01-18 08:35 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-13 08:53 - 2017-01-18 08:35 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:35 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:35 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2017-04-13 08:53 - 2017-01-18 08:35 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2017-04-13 08:53 - 2017-01-13 11:00 - 00976896 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2017-04-13 08:53 - 2017-01-13 10:45 - 00741888 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
2017-04-13 08:53 - 2017-01-11 11:01 - 01887744 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2017-04-13 08:53 - 2017-01-11 10:43 - 01241088 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2017-04-13 08:53 - 2016-11-21 11:12 - 00109568 _____ (Microsoft Corporation) C:\windows\system32\hlink.dll
2017-04-13 08:53 - 2016-11-20 09:19 - 00084992 _____ (Microsoft Corporation) C:\windows\SysWOW64\hlink.dll
2017-04-13 08:53 - 2016-11-20 07:07 - 00467392 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2017-04-13 08:53 - 2016-11-17 09:41 - 00370920 _____ (Microsoft Corporation) C:\windows\system32\clfs.sys
2017-04-13 08:53 - 2016-11-10 09:32 - 01009152 _____ (Microsoft Corporation) C:\windows\system32\user32.dll
2017-04-13 08:53 - 2016-11-10 09:19 - 00833024 _____ (Microsoft Corporation) C:\windows\SysWOW64\user32.dll
2017-04-13 08:53 - 2016-11-09 09:41 - 00114408 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2017-04-13 08:53 - 2016-11-09 09:33 - 03244032 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2017-04-13 08:53 - 2016-11-09 09:33 - 01941504 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2017-04-13 08:53 - 2016-11-09 09:33 - 00504320 _____ (Microsoft Corporation) C:\windows\system32\msihnd.dll
2017-04-13 08:53 - 2016-11-09 09:33 - 00070144 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2017-04-13 08:53 - 2016-11-09 09:17 - 02365440 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2017-04-13 08:53 - 2016-11-09 09:17 - 01806848 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2017-04-13 08:53 - 2016-11-09 09:17 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\msihnd.dll
2017-04-13 08:53 - 2016-11-09 09:02 - 00128512 _____ (Microsoft Corporation) C:\windows\system32\msiexec.exe
2017-04-13 08:53 - 2016-11-09 08:55 - 00073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\msiexec.exe
2017-04-13 08:53 - 2016-10-11 08:32 - 00069120 _____ (Microsoft Corporation) C:\windows\system32\nlsbres.dll
2017-04-13 08:53 - 2016-10-11 08:31 - 01148416 _____ (Microsoft Corporation) C:\windows\system32\IMJP10.IME
2017-04-13 08:53 - 2016-10-11 08:31 - 01068544 _____ (Microsoft Corporation) C:\windows\system32\msctf.dll
2017-04-13 08:53 - 2016-10-11 08:31 - 00878080 _____ (Microsoft Corporation) C:\windows\system32\IMJP10K.DLL
2017-04-13 08:53 - 2016-10-11 08:31 - 00457216 _____ (Microsoft Corporation) C:\windows\system32\imkr80.ime
2017-04-13 08:53 - 2016-10-11 08:31 - 00246784 _____ (Microsoft Corporation) C:\windows\system32\input.dll
2017-04-13 08:53 - 2016-10-11 08:31 - 00176128 _____ (Microsoft Corporation) C:\windows\system32\tintlgnt.ime
2017-04-13 08:53 - 2016-10-11 08:31 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\quick.ime
2017-04-13 08:53 - 2016-10-11 08:31 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\qintlgnt.ime
2017-04-13 08:53 - 2016-10-11 08:31 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\phon.ime
2017-04-13 08:53 - 2016-10-11 08:31 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\cintlgnt.ime
2017-04-13 08:53 - 2016-10-11 08:31 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\chajei.ime
2017-04-13 08:53 - 2016-10-11 08:31 - 00132608 _____ (Microsoft Corporation) C:\windows\system32\pintlgnt.ime
2017-04-13 08:53 - 2016-10-11 08:18 - 01027584 _____ (Microsoft Corporation) C:\windows\SysWOW64\IMJP10.IME
2017-04-13 08:53 - 2016-10-11 08:18 - 00829952 _____ (Microsoft Corporation) C:\windows\SysWOW64\msctf.dll
2017-04-13 08:53 - 2016-10-11 08:18 - 00701440 _____ (Microsoft Corporation) C:\windows\SysWOW64\IMJP10K.DLL
2017-04-13 08:53 - 2016-10-11 08:18 - 00430080 _____ (Microsoft Corporation) C:\windows\SysWOW64\imkr80.ime
2017-04-13 08:53 - 2016-10-11 08:18 - 00202240 _____ (Microsoft Corporation) C:\windows\SysWOW64\input.dll
2017-04-13 08:53 - 2016-10-11 08:18 - 00126976 _____ (Microsoft Corporation) C:\windows\SysWOW64\tintlgnt.ime
2017-04-13 08:53 - 2016-10-11 08:18 - 00125952 _____ (Microsoft Corporation) C:\windows\SysWOW64\quick.ime
2017-04-13 08:53 - 2016-10-11 08:18 - 00125952 _____ (Microsoft Corporation) C:\windows\SysWOW64\qintlgnt.ime
2017-04-13 08:53 - 2016-10-11 08:18 - 00125952 _____ (Microsoft Corporation) C:\windows\SysWOW64\phon.ime
2017-04-13 08:53 - 2016-10-11 08:18 - 00125952 _____ (Microsoft Corporation) C:\windows\SysWOW64\cintlgnt.ime
2017-04-13 08:53 - 2016-10-11 08:18 - 00125952 _____ (Microsoft Corporation) C:\windows\SysWOW64\chajei.ime
2017-04-13 08:53 - 2016-10-11 08:18 - 00090112 _____ (Microsoft Corporation) C:\windows\SysWOW64\pintlgnt.ime
2017-04-13 08:53 - 2016-10-11 08:18 - 00069120 _____ (Microsoft Corporation) C:\windows\SysWOW64\nlsbres.dll
2017-04-13 08:53 - 2016-10-11 07:55 - 00346112 _____ (Microsoft Corporation) C:\windows\system32\bcdedit.exe
2017-04-13 08:53 - 2016-10-11 06:33 - 00187392 _____ (Microsoft Corporation) C:\windows\SysWOW64\UIAnimation.dll
2017-04-13 08:53 - 2016-10-11 06:18 - 00419648 _____ C:\windows\SysWOW64\locale.nls
2017-04-13 08:53 - 2016-10-11 06:17 - 00419648 _____ C:\windows\system32\locale.nls
2017-04-13 08:53 - 2016-10-11 06:06 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\UIAnimation.dll
2017-04-13 08:53 - 2016-10-08 06:06 - 00633296 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2017-04-13 08:53 - 2016-10-07 08:32 - 03649536 _____ (Microsoft Corporation) C:\windows\system32\MSVidCtl.dll
2017-04-13 08:53 - 2016-10-07 08:32 - 00877056 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
2017-04-13 08:53 - 2016-10-07 08:12 - 02291712 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSVidCtl.dll
2017-04-13 08:53 - 2016-10-07 08:12 - 00581632 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleaut32.dll
2017-04-13 08:53 - 2016-10-05 07:54 - 00090112 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bowser.sys
2017-04-13 08:53 - 2016-10-04 08:31 - 01483264 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2017-04-13 08:53 - 2016-10-04 08:31 - 00229376 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2017-04-13 08:53 - 2016-10-04 08:31 - 00190976 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2017-04-13 08:53 - 2016-10-04 08:31 - 00141824 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2017-04-13 08:53 - 2016-10-04 08:13 - 01176064 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2017-04-13 08:53 - 2016-10-04 08:13 - 00179200 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2017-04-13 08:53 - 2016-10-04 08:13 - 00145920 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2017-04-13 08:53 - 2016-10-04 08:13 - 00106496 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptnet.dll
2017-04-13 08:53 - 2016-09-12 14:08 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\adsmsext.dll
2017-04-13 08:53 - 2016-09-12 13:49 - 00076800 _____ (Microsoft Corporation) C:\windows\SysWOW64\adsmsext.dll
2017-04-13 08:53 - 2016-09-08 13:34 - 00263680 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll
2017-04-13 08:53 - 2016-09-08 13:34 - 00208896 _____ (Microsoft Corporation) C:\windows\SysWOW64\WebClnt.dll
2017-04-13 08:53 - 2016-09-08 13:34 - 00108544 _____ (Microsoft Corporation) C:\windows\system32\davclnt.dll
2017-04-13 08:53 - 2016-09-08 13:34 - 00087040 _____ (Microsoft Corporation) C:\windows\SysWOW64\davclnt.dll
2017-04-13 08:53 - 2016-09-08 07:55 - 00142336 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxdav.sys
2017-04-13 08:53 - 2016-09-08 07:55 - 00106496 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dfsc.sys
2017-04-13 08:53 - 2016-08-22 09:19 - 01386496 _____ (Microsoft Corporation) C:\windows\system32\diagtrack.dll
2017-04-13 08:53 - 2016-08-12 10:02 - 14632960 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2017-04-13 08:53 - 2016-08-12 10:02 - 12574720 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2017-04-13 08:53 - 2016-08-12 09:47 - 12574208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
2017-04-13 08:53 - 2016-08-12 09:47 - 11410432 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2017-04-13 08:53 - 2016-08-12 09:26 - 00461312 _____ (Microsoft Corporation) C:\windows\system32\scavengeui.dll
2017-04-13 08:53 - 2016-08-06 08:31 - 02023424 _____ (Microsoft Corporation) C:\windows\system32\WsmSvc.dll
2017-04-13 08:53 - 2016-08-06 08:31 - 00347136 _____ (Microsoft Corporation) C:\windows\system32\WSManMigrationPlugin.dll
2017-04-13 08:53 - 2016-08-06 08:31 - 00310784 _____ (Microsoft Corporation) C:\windows\system32\WsmWmiPl.dll
2017-04-13 08:53 - 2016-08-06 08:31 - 00182272 _____ (Microsoft Corporation) C:\windows\system32\WsmAuto.dll
2017-04-13 08:53 - 2016-08-06 08:15 - 01178112 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmSvc.dll
2017-04-13 08:53 - 2016-08-06 08:15 - 00249344 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSManMigrationPlugin.dll
2017-04-13 08:53 - 2016-08-06 08:15 - 00214016 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmWmiPl.dll
2017-04-13 08:53 - 2016-08-06 08:15 - 00146944 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmAuto.dll
2017-04-13 08:53 - 2016-08-06 08:01 - 00266752 _____ (Microsoft Corporation) C:\windows\system32\WSManHTTPConfig.exe
2017-04-13 08:53 - 2016-08-06 07:53 - 00199168 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSManHTTPConfig.exe
2017-04-13 08:53 - 2016-06-14 10:21 - 00094440 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mountmgr.sys
2017-04-13 08:53 - 2016-06-14 10:16 - 04121600 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
2017-04-13 08:53 - 2016-06-14 10:16 - 01202176 _____ (Microsoft Corporation) C:\windows\system32\drmv2clt.dll
2017-04-13 08:53 - 2016-06-14 10:16 - 01068544 _____ (Microsoft Corporation) C:\windows\system32\cryptui.dll
2017-04-13 08:53 - 2016-06-14 10:16 - 00842240 _____ (Microsoft Corporation) C:\windows\system32\blackbox.dll
2017-04-13 08:53 - 2016-06-14 10:16 - 00782848 _____ (Microsoft Corporation) C:\windows\system32\wmdrmsdk.dll
2017-04-13 08:53 - 2016-06-14 10:16 - 00680448 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2017-04-13 08:53 - 2016-06-14 10:16 - 00641024 _____ (Microsoft Corporation) C:\windows\system32\msscp.dll
2017-04-13 08:53 - 2016-06-14 10:16 - 00632320 _____ (Microsoft Corporation) C:\windows\system32\evr.dll
2017-04-13 08:53 - 2016-06-14 10:16 - 00499712 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll
2017-04-13 08:53 - 2016-06-14 10:16 - 00497664 _____ (Microsoft Corporation) C:\windows\system32\drmmgrtn.dll
2017-04-13 08:53 - 2016-06-14 10:16 - 00440320 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll
2017-04-13 08:53 - 2016-06-14 10:16 - 00433152 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll
2017-04-13 08:53 - 2016-06-14 10:16 - 00371712 _____ (Microsoft Corporation) C:\windows\system32\qdvd.dll
2017-04-13 08:53 - 2016-06-14 10:16 - 00325632 _____ (Microsoft Corporation) C:\windows\system32\msnetobj.dll
2017-04-13 08:53 - 2016-06-14 10:16 - 00295936 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
2017-04-13 08:53 - 2016-06-14 10:16 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\EncDump.dll
2017-04-13 08:53 - 2016-06-14 10:16 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2017-04-13 08:53 - 2016-06-14 10:16 - 00187904 _____ (Microsoft Corporation) C:\windows\system32\pcasvc.dll
2017-04-13 08:53 - 2016-06-14 10:16 - 00081920 _____ (Microsoft Corporation) C:\windows\system32\cryptsp.dll
2017-04-13 08:53 - 2016-06-14 10:16 - 00037376 _____ (Microsoft Corporation) C:\windows\system32\pcadm.dll
2017-04-13 08:53 - 2016-06-14 10:11 - 00663552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\PEAuth.sys
2017-04-13 08:53 - 2016-06-14 08:21 - 03209216 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll
2017-04-13 08:53 - 2016-06-14 08:21 - 01005056 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptui.dll
2017-04-13 08:53 - 2016-06-14 08:21 - 00988160 _____ (Microsoft Corporation) C:\windows\SysWOW64\drmv2clt.dll
2017-04-13 08:53 - 2016-06-14 08:21 - 00744960 _____ (Microsoft Corporation) C:\windows\SysWOW64\blackbox.dll
2017-04-13 08:53 - 2016-06-14 08:21 - 00617984 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmdrmsdk.dll
2017-04-13 08:53 - 2016-06-14 08:21 - 00519680 _____ (Microsoft Corporation) C:\windows\SysWOW64\qdvd.dll
2017-04-13 08:53 - 2016-06-14 08:21 - 00504320 _____ (Microsoft Corporation) C:\windows\SysWOW64\msscp.dll
2017-04-13 08:53 - 2016-06-14 08:21 - 00489984 _____ (Microsoft Corporation) C:\windows\SysWOW64\evr.dll
2017-04-13 08:53 - 2016-06-14 08:21 - 00442368 _____ (Microsoft Corporation) C:\windows\SysWOW64\AUDIOKSE.dll
2017-04-13 08:53 - 2016-06-14 08:21 - 00406016 _____ (Microsoft Corporation) C:\windows\SysWOW64\drmmgrtn.dll
2017-04-13 08:53 - 2016-06-14 08:21 - 00374784 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioEng.dll
2017-04-13 08:53 - 2016-06-14 08:21 - 00354816 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfplat.dll
2017-04-13 08:53 - 2016-06-14 08:21 - 00265216 _____ (Microsoft Corporation) C:\windows\SysWOW64\msnetobj.dll
2017-04-13 08:53 - 2016-06-14 08:21 - 00195072 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioSes.dll
2017-04-13 08:53 - 2016-06-14 08:21 - 00103424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfps.dll
2017-04-13 08:53 - 2016-06-14 08:21 - 00080896 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsp.dll
2017-04-13 08:53 - 2016-06-14 08:15 - 00125952 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe
2017-04-13 08:52 - 2017-03-14 08:30 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\cdd.dll
2017-04-13 08:52 - 2017-03-10 09:31 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2017-04-13 08:52 - 2017-03-10 09:31 - 00046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2017-04-13 08:52 - 2017-03-10 09:31 - 00041472 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2017-04-13 08:52 - 2017-03-10 09:31 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2017-04-13 08:52 - 2017-03-10 09:20 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
2017-04-13 08:52 - 2017-03-10 09:19 - 00070656 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2017-04-13 08:52 - 2017-03-10 09:19 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
2017-04-13 08:52 - 2017-03-10 08:53 - 00034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:22 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2017-04-13 08:52 - 2017-03-07 21:22 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2017-04-13 08:52 - 2017-03-07 21:22 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 21:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 20:54 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2017-04-13 08:52 - 2017-03-07 20:54 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2017-04-13 08:52 - 2017-03-07 20:54 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2017-04-13 08:52 - 2017-03-07 20:53 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 20:53 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 20:53 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-04-13 08:52 - 2017-03-07 20:53 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-04-13 08:52 - 2017-02-11 09:33 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2017-04-13 08:52 - 2017-02-11 09:16 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2017-04-13 08:52 - 2017-01-13 11:00 - 00084480 _____ (Microsoft Corporation) C:\windows\system32\INETRES.dll
2017-04-13 08:52 - 2017-01-13 10:45 - 00084480 _____ (Microsoft Corporation) C:\windows\SysWOW64\INETRES.dll
2017-04-13 08:52 - 2017-01-11 11:01 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2017-04-13 08:52 - 2017-01-11 10:43 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2017-04-13 08:52 - 2016-11-09 09:33 - 00025088 _____ (Microsoft Corporation) C:\windows\system32\msimsg.dll
2017-04-13 08:52 - 2016-11-09 09:17 - 00025088 _____ (Microsoft Corporation) C:\windows\SysWOW64\msimsg.dll
2017-04-13 08:52 - 2016-08-12 10:02 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\spwmp.dll
2017-04-13 08:52 - 2016-08-12 10:02 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\msdxm.ocx
2017-04-13 08:52 - 2016-08-12 10:02 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\dxmasf.dll
2017-04-13 08:52 - 2016-08-12 09:31 - 00008192 _____ (Microsoft Corporation) C:\windows\SysWOW64\spwmp.dll
2017-04-13 08:52 - 2016-08-12 09:31 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\msdxm.ocx
2017-04-13 08:52 - 2016-08-12 09:31 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxmasf.dll
2017-04-13 08:52 - 2016-08-06 08:31 - 00054272 _____ (Microsoft Corporation) C:\windows\system32\WsmRes.dll
2017-04-13 08:52 - 2016-08-06 08:31 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\wsmplpxy.dll
2017-04-13 08:52 - 2016-08-06 08:15 - 00054272 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmRes.dll
2017-04-13 08:52 - 2016-08-06 08:01 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\wsmprovhost.exe
2017-04-13 08:52 - 2016-08-06 07:53 - 00012288 _____ (Microsoft Corporation) C:\windows\SysWOW64\wsmprovhost.exe
2017-04-13 08:52 - 2016-08-06 07:53 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\wsmplpxy.dll
2017-04-13 08:52 - 2016-06-14 10:16 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\msmmsp.dll
2017-04-13 08:52 - 2016-06-14 10:16 - 00008704 _____ (Microsoft Corporation) C:\windows\system32\pcaevts.dll
2017-04-13 08:52 - 2016-06-14 10:16 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
2017-04-13 08:52 - 2016-06-14 08:21 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mferror.dll
2017-04-13 08:52 - 2016-06-14 08:15 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
2017-04-13 08:52 - 2016-06-14 08:15 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
2017-04-13 08:52 - 2016-06-14 08:05 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\rrinstaller.exe
2017-04-13 08:52 - 2016-06-14 08:05 - 00023040 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfpmp.exe
2017-04-13 08:52 - 2016-06-14 08:00 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\pcawrk.exe
2017-04-13 08:52 - 2016-06-14 08:00 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\pcalua.exe
2017-04-13 08:46 - 2016-08-29 08:31 - 14183424 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2017-04-13 08:46 - 2016-08-29 08:31 - 01867776 _____ (Microsoft Corporation) C:\windows\system32\ExplorerFrame.dll
2017-04-13 08:46 - 2016-08-29 08:12 - 12880384 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2017-04-13 08:46 - 2016-08-29 08:04 - 03229696 _____ (Microsoft Corporation) C:\windows\explorer.exe
2017-04-13 08:46 - 2016-08-16 13:40 - 00343552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys
2017-04-13 08:46 - 2016-08-16 13:40 - 00327168 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys
2017-04-13 08:46 - 2016-08-16 13:40 - 00099840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys
2017-04-13 08:46 - 2016-08-16 13:40 - 00056320 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys
2017-04-13 08:46 - 2016-08-16 13:40 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys
2017-04-13 08:46 - 2016-08-16 13:40 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbohci.sys
2017-04-13 08:46 - 2016-08-16 13:40 - 00007808 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys
2017-04-13 08:46 - 2016-07-07 08:36 - 01896168 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2017-04-13 08:46 - 2016-07-07 08:36 - 00377576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys
2017-04-13 08:46 - 2016-07-07 08:36 - 00287976 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2017-04-13 08:46 - 2016-07-07 08:08 - 00046080 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpipreg.sys
2017-04-13 08:46 - 2016-05-12 08:18 - 00090624 _____ (Microsoft Corporation) C:\windows\SysWOW64\olepro32.dll
2017-04-13 08:46 - 2016-05-12 06:05 - 00297984 _____ (Microsoft Corporation) C:\windows\system32\bcryptprimitives.dll
2017-04-13 08:46 - 2016-05-12 06:04 - 00249352 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcryptprimitives.dll
2017-04-13 08:45 - 2017-02-22 16:42 - 00084712 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2017-04-13 08:45 - 2017-02-22 16:37 - 01285632 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2017-04-13 08:45 - 2017-02-18 07:05 - 01609216 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2017-04-13 08:45 - 2017-02-18 07:05 - 00646656 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2017-04-13 08:45 - 2016-12-31 08:36 - 00556544 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2017-04-13 08:45 - 2016-12-31 08:36 - 00335360 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2017-04-13 08:45 - 2016-12-31 08:36 - 00293376 _____ (Microsoft Corporation) C:\windows\system32\centel.dll
2017-04-13 08:45 - 2016-12-31 08:36 - 00233984 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2017-04-13 08:45 - 2016-12-31 08:36 - 00133632 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2017-04-13 08:45 - 2016-08-29 08:12 - 01499648 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExplorerFrame.dll
2017-04-13 08:45 - 2016-08-29 07:55 - 02972672 _____ (Microsoft Corporation) C:\windows\SysWOW64\explorer.exe
2017-04-13 06:38 - 2016-06-25 17:27 - 00970240 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll
2017-04-13 06:38 - 2016-06-25 17:27 - 00344576 _____ (Microsoft Corporation) C:\windows\system32\ntprint.dll
2017-04-13 06:38 - 2016-06-25 17:27 - 00166400 _____ (Microsoft Corporation) C:\windows\system32\inetpp.dll
2017-04-13 06:38 - 2016-06-25 17:27 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\inetppui.dll
2017-04-13 06:38 - 2016-06-25 12:53 - 00297472 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntprint.dll
2017-04-13 06:38 - 2016-06-25 12:53 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\ntprint.exe
2017-04-13 06:38 - 2016-06-25 12:53 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\wpnpinst.exe
2017-04-13 06:38 - 2016-06-25 12:41 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntprint.exe
2017-04-13 06:37 - 2016-05-12 10:15 - 00105472 _____ (Microsoft Corporation) C:\windows\system32\winipsec.dll
2017-04-13 06:37 - 2016-05-12 10:14 - 00794624 _____ (Microsoft Corporation) C:\windows\system32\gpsvc.dll
2017-04-13 06:37 - 2016-05-12 10:14 - 00502272 _____ (Microsoft Corporation) C:\windows\system32\IPSECSVC.DLL
2017-04-13 06:37 - 2016-05-12 10:14 - 00373760 _____ (Microsoft Corporation) C:\windows\system32\polstore.dll
2017-04-13 06:37 - 2016-05-12 10:14 - 00096256 _____ (Microsoft Corporation) C:\windows\system32\gpapi.dll
2017-04-13 06:37 - 2016-05-12 10:14 - 00075776 _____ (Microsoft Corporation) C:\windows\system32\FwRemoteSvr.dll
2017-04-13 06:37 - 2016-05-12 08:18 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\polstore.dll
2017-04-13 06:37 - 2016-05-12 08:18 - 00079360 _____ (Microsoft Corporation) C:\windows\SysWOW64\gpapi.dll
2017-04-13 06:37 - 2016-05-12 08:18 - 00070144 _____ (Microsoft Corporation) C:\windows\SysWOW64\winipsec.dll
2017-04-13 06:37 - 2016-05-12 08:18 - 00044032 _____ (Microsoft Corporation) C:\windows\SysWOW64\FwRemoteSvr.dll
2017-04-13 06:37 - 2016-05-11 10:02 - 00483840 _____ (Microsoft Corporation) C:\windows\system32\StructuredQuery.dll
2017-04-13 06:37 - 2016-05-11 10:02 - 00444928 _____ (Microsoft Corporation) C:\windows\system32\winhttp.dll
2017-04-13 06:37 - 2016-05-11 10:02 - 00327168 _____ (Microsoft Corporation) C:\windows\system32\mswsock.dll
2017-04-13 06:37 - 2016-05-11 10:02 - 00296448 _____ (Microsoft Corporation) C:\windows\system32\ws2_32.dll
2017-04-13 06:37 - 2016-05-11 08:19 - 00363520 _____ (Microsoft Corporation) C:\windows\SysWOW64\StructuredQuery.dll
2017-04-13 06:37 - 2016-05-11 08:19 - 00351744 _____ (Microsoft Corporation) C:\windows\SysWOW64\winhttp.dll
2017-04-13 06:37 - 2016-05-11 08:19 - 00231424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mswsock.dll
2017-04-13 06:37 - 2016-05-11 08:19 - 00206336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ws2_32.dll
2017-04-13 06:37 - 2016-05-11 08:11 - 00025088 _____ (Microsoft Corporation) C:\windows\system32\netbtugc.exe
2017-04-13 06:37 - 2016-05-11 08:01 - 00026624 _____ (Microsoft Corporation) C:\windows\SysWOW64\netbtugc.exe
2017-04-13 06:37 - 2016-05-11 07:58 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netbt.sys
2017-04-13 06:37 - 2016-04-14 06:49 - 00603648 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10level9.dll
2017-04-13 06:37 - 2016-04-14 06:21 - 00647680 _____ (Microsoft Corporation) C:\windows\system32\d3d10level9.dll
2017-04-13 06:37 - 2016-03-09 12:00 - 00396800 _____ (Microsoft Corporation) C:\windows\system32\webio.dll
2017-04-13 06:37 - 2016-03-09 11:54 - 00275456 _____ (Microsoft Corporation) C:\windows\system32\InkEd.dll
2017-04-13 06:37 - 2016-03-09 11:40 - 00316416 _____ (Microsoft Corporation) C:\windows\SysWOW64\webio.dll
2017-04-13 06:37 - 2016-03-09 11:34 - 00216064 _____ (Microsoft Corporation) C:\windows\SysWOW64\InkEd.dll
2017-04-13 06:36 - 2016-04-08 21:20 - 01230848 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
2017-04-13 06:36 - 2016-04-08 20:52 - 01424896 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2017-04-11 12:42 - 2017-04-11 12:42 - 00253184 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgmfx64.sys
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-05-04 22:58 - 2016-11-10 10:57 - 00000000 ____D C:\ProgramData\MFAData
2017-05-04 06:51 - 2009-07-13 21:45 - 00018736 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-05-04 06:51 - 2009-07-13 21:45 - 00018736 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-05-04 06:49 - 2014-03-24 04:40 - 00000000 ____D C:\ProgramData\Package Cache
2017-05-04 06:49 - 2009-07-13 22:13 - 00782470 _____ C:\windows\system32\PerfStringBackup.INI
2017-05-04 06:49 - 2009-07-13 20:20 - 00000000 ____D C:\windows\inf
2017-05-04 06:45 - 2017-03-22 13:39 - 00082720 _____ (Malwarebytes) C:\windows\system32\Drivers\mwac.sys
2017-05-03 23:58 - 2016-11-26 18:33 - 00000000 ____D C:\Users\Jacque\AppData\LocalLow\Mozilla
2017-05-03 23:58 - 2014-04-01 15:15 - 00802904 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2017-05-03 23:58 - 2014-04-01 15:15 - 00144472 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-05-03 23:58 - 2014-04-01 15:15 - 00004314 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2017-05-03 23:58 - 2014-04-01 15:15 - 00000000 ____D C:\windows\system32\Macromed
2017-05-03 23:58 - 2014-03-23 13:16 - 00000000 ____D C:\Users\Jacque\AppData\Local\Adobe
2017-05-03 23:57 - 2009-09-03 18:16 - 00000000 ____D C:\windows\SysWOW64\Macromed
2017-05-03 23:54 - 2014-03-23 13:09 - 00000000 ____D C:\Users\Jacque\AppData\Roaming\Skype
2017-05-03 23:50 - 2017-01-10 22:32 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-05-03 23:47 - 2014-12-30 15:11 - 00002992 _____ C:\windows\System32\Tasks\{5B19AC4F-4882-431C-9894-E8EC20AEB0D7}
2017-05-03 23:47 - 2014-12-30 15:11 - 00002992 _____ C:\windows\System32\Tasks\{2DD831B2-B01F-498B-BBBE-365165A684D8}
2017-05-03 23:47 - 2014-05-30 11:24 - 00002992 _____ C:\windows\System32\Tasks\{6875C840-9E81-4C31-A43C-163B7F6C2E88}
2017-05-03 23:47 - 2014-05-30 11:24 - 00002992 _____ C:\windows\System32\Tasks\{2A9E900C-A9D9-45F1-B539-5021FBA02675}
2017-05-03 23:47 - 2014-05-26 20:39 - 00002992 _____ C:\windows\System32\Tasks\{94966F68-E499-43C0-BAE8-43E628BDA581}
2017-05-03 23:46 - 2014-12-26 17:08 - 00004478 _____ C:\windows\System32\Tasks\Adobe Acrobat Update Task
2017-05-03 23:45 - 2014-03-23 11:43 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-05-03 22:46 - 2017-03-22 13:39 - 00111544 _____ (Malwarebytes) C:\windows\system32\Drivers\farflt.sys
2017-05-03 22:46 - 2017-03-22 13:38 - 00251832 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2017-05-03 22:46 - 2017-03-22 13:38 - 00043968 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2017-05-03 22:45 - 2009-07-13 22:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2017-05-03 13:02 - 2014-03-23 12:49 - 00000000 ____D C:\Users\Jacque
2017-05-03 00:58 - 2009-07-14 00:44 - 00000000 ___RD C:\Users\Public\Recorded TV
2017-05-03 00:58 - 2009-07-13 20:20 - 00000000 ____D C:\windows\registration
2017-04-28 14:47 - 2016-09-20 19:11 - 00003600 _____ C:\windows\System32\Tasks\AVG EUpdate Task
2017-04-25 07:48 - 2017-02-10 13:44 - 00003704 _____ C:\windows\System32\Tasks\Java Platform SE Auto Updater
2017-04-24 11:29 - 2017-02-06 12:39 - 00000000 ____D C:\ProgramData\Oracle
2017-04-21 08:28 - 2016-10-28 11:00 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-04-20 08:19 - 2016-11-10 11:00 - 00000907 _____ C:\Users\Public\Desktop\AVG Protection.lnk
2017-04-20 08:19 - 2016-11-10 11:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2017-04-17 10:59 - 2016-04-09 13:22 - 00000000 ____D C:\Users\Jacque\Memoirs 2016 reorganized
2017-04-17 10:42 - 2017-03-22 13:38 - 00077440 _____ C:\windows\system32\Drivers\mbae64.sys
2017-04-17 09:23 - 2017-03-22 13:39 - 00186304 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMChameleon.sys
2017-04-17 06:50 - 2016-04-09 07:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2017-04-17 06:50 - 2014-03-23 13:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-04-16 15:08 - 2009-07-13 20:20 - 00000000 ____D C:\windows\rescache
2017-04-14 07:48 - 2015-04-03 19:36 - 00000000 ___SD C:\windows\system32\GWX
2017-04-14 07:41 - 2009-07-13 22:32 - 00000000 ____D C:\Program Files\DVD Maker
2017-04-14 07:41 - 2009-07-13 20:20 - 00000000 ____D C:\windows\SysWOW64\Dism
2017-04-14 07:40 - 2009-07-13 20:20 - 00000000 ____D C:\windows\system32\Dism
2017-04-14 07:39 - 2014-12-10 23:19 - 00000000 ____D C:\windows\system32\appraiser
2017-04-14 07:39 - 2014-05-06 21:46 - 00000000 ___SD C:\windows\system32\CompatTel
2017-04-14 07:36 - 2014-03-31 21:13 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-04-14 07:36 - 2014-03-31 21:13 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-04-14 07:36 - 2009-07-13 22:08 - 00032606 _____ C:\windows\Tasks\SCHEDLGU.TXT
2017-04-13 22:42 - 2014-03-31 21:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-04-13 22:37 - 2014-03-23 13:50 - 00000000 ____D C:\windows\system32\MRT
2017-04-13 22:33 - 2014-03-23 13:50 - 148601744 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2017-04-13 22:25 - 2014-03-24 04:42 - 00775084 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2017-04-13 06:15 - 2017-01-10 21:51 - 00001168 _____ C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2017-04-13 06:15 - 2016-02-06 19:45 - 00001180 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
2017-04-12 14:13 - 2015-11-02 08:51 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-04-10 10:16 - 2014-03-30 11:38 - 00007744 _____ C:\Users\Jacque\AppData\Roaming\wklnhst.dat
2017-04-10 10:16 - 2009-07-13 22:32 - 00000000 ____D C:\windows\system32\FxsTmp
2017-04-10 01:11 - 2014-06-04 14:55 - 00000000 ____D C:\windows\Minidump
 
==================== Files in the root of some directories =======
 
2014-03-30 11:38 - 2017-04-10 10:16 - 0007744 _____ () C:\Users\Jacque\AppData\Roaming\wklnhst.dat
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\SysWOW64\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
 
==================== BCD ================================
 
Windows Boot Manager
--------------------
identifier              {bootmgr}
device                  partition=\Device\HarddiskVolume1
description             Windows Boot Manager
locale                  en-US
inherit                 {globalsettings}
default                 {current}
resumeobject            {2ea62aa8-b2c2-11e3-8332-d37fa77daa6f}
displayorder            {current}
toolsdisplayorder       {memdiag}
timeout                 30
 
Windows Boot Loader
-------------------
identifier              {current}
device                  partition=C:
path                    \windows\system32\winload.exe
description             Windows 7
locale                  en-US
inherit                 {bootloadersettings}
recoverysequence        {2ea62aaa-b2c2-11e3-8332-d37fa77daa6f}
recoveryenabled         Yes
osdevice                partition=C:
systemroot              \windows
resumeobject            {2ea62aa8-b2c2-11e3-8332-d37fa77daa6f}
nx                      OptIn
 
Windows Boot Loader
-------------------
identifier              {2ea62aaa-b2c2-11e3-8332-d37fa77daa6f}
device                  ramdisk=[\Device\HarddiskVolume1]\Recovery\WindowsRE\Winre.wim,{2ea62aab-b2c2-11e3-8332-d37fa77daa6f}
path                    \windows\system32\winload.exe
description             Windows Recovery Environment
inherit                 {bootloadersettings}
osdevice                ramdisk=[\Device\HarddiskVolume1]\Recovery\WindowsRE\Winre.wim,{2ea62aab-b2c2-11e3-8332-d37fa77daa6f}
systemroot              \windows
nx                      OptIn
winpe                   Yes
 
Resume from Hibernate
---------------------
identifier              {2ea62aa8-b2c2-11e3-8332-d37fa77daa6f}
device                  partition=C:
path                    \windows\system32\winresume.exe
description             Windows Resume Application
locale                  en-US
inherit                 {resumeloadersettings}
filedevice              partition=C:
filepath                \hiberfil.sys
debugoptionenabled      No
 
Windows Memory Tester
---------------------
identifier              {memdiag}
device                  partition=\Device\HarddiskVolume1
path                    \boot\memtest.exe
description             Windows Memory Diagnostic
locale                  en-US
inherit                 {globalsettings}
badmemoryaccess         Yes
 
EMS Settings
------------
identifier              {emssettings}
bootems                 Yes
 
Debugger Settings
-----------------
identifier              {dbgsettings}
debugtype               Serial
debugport               1
baudrate                115200
 
RAM Defects
-----------
identifier              {badmemory}
 
Global Settings
---------------
identifier              {globalsettings}
inherit                 {dbgsettings}
                        {emssettings}
                        {badmemory}
 
Boot Loader Settings
--------------------
identifier              {bootloadersettings}
inherit                 {globalsettings}
                        {hypervisorsettings}
 
Hypervisor Settings
-------------------
identifier              {hypervisorsettings}
hypervisordebugtype     Serial
hypervisordebugport     1
hypervisorbaudrate      115200
 
Resume Loader Settings
----------------------
identifier              {resumeloadersettings}
inherit                 {globalsettings}
 
Device options
--------------
identifier              {2ea62aab-b2c2-11e3-8332-d37fa77daa6f}
description             Ramdisk Options
ramdisksdidevice        partition=\Device\HarddiskVolume1
ramdisksdipath          \Recovery\WindowsRE\boot.sdi
 
 
LastRegBack: 2017-05-03 13:55
 
==================== End of FRST.txt ============================
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-05-2017
Ran by Jacque (04-05-2017 23:00:54)
Running from G:\
Windows 7 Home Premium Service Pack 1 (X64) (2014-03-23 19:49:23)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1359882058-2057507765-851322289-500 - Administrator - Disabled)
Guest (S-1-5-21-1359882058-2057507765-851322289-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1359882058-2057507765-851322289-1002 - Limited - Enabled)
Jacque (S-1-5-21-1359882058-2057507765-851322289-1001 - Administrator - Enabled) => C:\Users\Jacque
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AV: AVG Internet Security (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG Internet Security (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
FW: AVG Internet Security (Enabled) {757AB44A-78C2-7D1A-E37F-CA42A037B368}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated)
Adobe Flash Player 25 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 25.0.0.127 - Adobe Systems Incorporated)
Adobe Flash Player 25 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 25.0.0.148 - Adobe Systems Incorporated)
AVG (Version: 16.151.8013 - AVG Technologies) Hidden
AVG 2016 (Version: 16.0.4776 - AVG Technologies) Hidden
AVG PC TuneUp (HKLM-x32\...\AVG PC TuneUp) (Version: 16.74.2.60831 - AVG Technologies)
AVG PC TuneUp (x32 Version: 16.74.1 - AVG Technologies) Hidden
AVG Protection (HKLM\...\AVG) (Version: 2016.151.8013 - AVG Technologies)
Citrix Online Launcher (HKLM-x32\...\{DB014C85-A264-4BCA-A66F-6DD1FCF8EC36}) (Version: 1.0.335 - Citrix)
Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
FMW 1 (Version: 1.143.3 - AVG Technologies) Hidden
Intel® Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1883 - Intel Corporation)
Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version:  - Intel Corporation)
IrfanView 4.44 (32-bit) (HKLM-x32\...\IrfanView) (Version: 4.44 - Irfan Skiljan)
Java 8 Update 121 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation)
Junk Mail filter update (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden
Malwarebytes version 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.7967.2139 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\...\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Suite Activation Assistant (HKLM-x32\...\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1359882058-2057507765-851322289-1001\...\OneDriveSetup.exe) (Version: 17.3.6390.0509 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1359882058-2057507765-851322289-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05042017225524601\...\OneDriveSetup.exe) (Version: 17.3.6390.0509 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50906.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Works (HKLM-x32\...\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
Mozilla Firefox 53.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 53.0 (x86 en-US)) (Version: 53.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 52.0.1.6312 - Mozilla)
Mozilla Thunderbird 52.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Thunderbird 52.0.1 (x86 en-US)) (Version: 52.0.1 - Mozilla)
Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7967.2139 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.7967.2139 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.7967.2139 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7668.2066 - Microsoft Corporation) Hidden
OpenOffice 4.1.0 (HKLM-x32\...\{C87EF11D-36E9-479D-9898-7541EA1E8A6A}) (Version: 4.10.9764 - Apache Software Foundation)
PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
Realtek Ethernet Controller  Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0008 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5904 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30101 - Realtek Semiconductor Corp.)
Realtek WLAN Driver (HKLM-x32\...\{0FB630AB-7BD8-40AE-B223-60397D57C3C9}) (Version: 2.00.0006 - Realtek)
SAMSUNG Mobile Modem Driver Set (HKLM\...\SAMSUNG Mobile Modem) (Version:  - )
Samsung Mobile phone USB driver Drive Software (HKLM\...\Samsung Mobile phone USB driver Drive) (Version:  - )
SAMSUNG Mobile USB Modem 1.0 Software (HKLM\...\SAMSUNG Mobile USB Modem 1.0) (Version:  - )
SAMSUNG Mobile USB Modem Software (HKLM\...\SAMSUNG Mobile USB Modem) (Version:  - )
Samsung PC Studio 3 USB Driver Installer (HKLM-x32\...\{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}) (Version: 3.2.0.70701 - Samsung Electronics Co., Ltd.)
Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation)
Skype Launcher (HKLM-x32\...\{DA84ECBF-4B79-47F2-B34C-95C38484C058}) (Version: 2.01 - TOSHIBA Corporation)
Skype™ 7.33 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.33.105 - Skype Technologies S.A.)
Spelling Dictionaries Support For Adobe Reader 9 (HKLM-x32\...\{AC76BA86-7AD7-5464-3428-900000000004}) (Version: 9.0.0 - Adobe Systems Incorporated)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 13.2.6.1 - Synaptics Incorporated)
Toshiba Application Installer (HKLM-x32\...\{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}) (Version: 9.0.0.9 - Toshiba)
TOSHIBA Assist (HKLM-x32\...\{1B87C40B-A60B-4EF3-9A68-706CF4B69978}) (Version: 3.00.09 - TOSHIBA)
TOSHIBA ConfigFree (HKLM-x32\...\{F3529665-D75E-4D6D-98F0-745C78C68E9B}) (Version: 8.0.21 - TOSHIBA Corporation)
TOSHIBA Disc Creator (HKLM\...\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: 2.1.0.1 for x64 - TOSHIBA Corporation)
TOSHIBA DVD PLAYER (HKLM-x32\...\{6C5F3BDC-0A1B-4436-A696-5939629D5C31}) (Version: 3.01.0.07-A - TOSHIBA Corporation)
TOSHIBA eco Utility (HKLM-x32\...\InstallShield_{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}) (Version: 1.1.7.64 - TOSHIBA Corporation)
TOSHIBA Extended Tiles for Windows Mobility Center (HKLM-x32\...\InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}) (Version:  - )
TOSHIBA Face Recognition (HKLM-x32\...\InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}) (Version: 3.1.0.64 - TOSHIBA Corporation)
TOSHIBA Hardware Setup (HKLM-x32\...\{D0387727-C89D-4774-B643-B9333EAA09DE}) (Version: 2.00.11 - TOSHIBA Corporation)
TOSHIBA HDD/SSD Alert (HKLM-x32\...\InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}) (Version: 3.1.64.0 - TOSHIBA Corporation)
Toshiba Online Backup (HKLM-x32\...\{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}) (Version: 1.2.0.35 - Toshiba)
TOSHIBA PC Health Monitor (HKLM\...\{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}) (Version: 1.4.1.64 - TOSHIBA Corporation)
Toshiba Quality Application (HKLM-x32\...\{E69992ED-A7F6-406C-9280-1C156417BC49}) (Version: 1.001.0000 - Toshiba)
TOSHIBA Recovery Media Creator (HKLM\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.1.0.2 for x64 - TOSHIBA Corporation)
TOSHIBA Service Station (HKLM-x32\...\{AC6569FA-6919-442A-8552-073BE69E247A}) (Version: 2.2.9 - TOSHIBA)
TOSHIBA Speech System Applications (HKLM-x32\...\{EE033C1F-443E-41EC-A0E2-559B539A4E4D}) (Version: 1.00.2518 - )
TOSHIBA Speech System SR Engine(U.S.) Version1.0 (HKLM-x32\...\{008D69EB-70FF-46AB-9C75-924620DF191A}) (Version:  - )
TOSHIBA Speech System TTS Engine(U.S.) Version1.0 (HKLM-x32\...\{3FBF6F99-8EC6-41B4-8527-0A32241B5496}) (Version:  - )
TOSHIBA Supervisor Password (HKLM-x32\...\{A208044D-A88B-4ACF-AE95-E4F213E6EDC0}) (Version: 2.00.09 - TOSHIBA Corporation)
TOSHIBA Value Added Package (HKLM-x32\...\InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}) (Version: 1.2.25.64 - TOSHIBA Corporation)
TOSHIBA Web Camera Application (HKLM-x32\...\{5E6F6CF3-BACC-4144-868C-E14622C658F3}) (Version: 1.1.1.4 - TOSHIBA Corporation)
ToshibaRegistration (HKLM-x32\...\{5AF550B4-BB67-4E7E-82F1-2C4300279050}) (Version: 1.0.3 - Toshiba)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
WD Drive Utilities (HKLM-x32\...\{7431ED5D-9247-4F17-91C9-702D9B36FAC4}) (Version: 1.0.7.3 - Western Digital Technologies, Inc.)
WD Quick View (HKLM-x32\...\{F4F2EF32-EAFE-4F87-B7DC-E19C9F8E76FC}) (Version: 2.4.16.16 - Western Digital Technologies, Inc.)
WD Security (HKLM-x32\...\{249644e6-451a-4a5c-bd5c-21eeb9eec79d}) (Version: 1.3.1.2 - Western Digital Technologies, Inc.)
WD Security (x32 Version: 1.3.1.2 - Western Digital Technologies, Inc.) Hidden
WD SmartWare (HKLM\...\{515B34CA-1229-4EDA-AE7C-53CBA68B8A7A}) (Version: 2.4.16.16 - Western Digital Technologies, Inc.)
WD SmartWare Installer (HKLM-x32\...\{4555885d-a64c-4234-9aac-72a8a6b5590b}) (Version: 2.4.16.16 - Western Digital Technologies, Inc.)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation)
Windows Live Sign-in Assistant (HKLM-x32\...\{45338B07-A236-4270-9A77-EBB4115517B5}) (Version: 5.000.818.5 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\...\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation)
Windows Live Upload Tool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1359882058-2057507765-851322289-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05042017225524601_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Jacque\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileCoAuthLib64.dll ()
CustomCLSID: HKU\S-1-5-21-1359882058-2057507765-851322289-1001_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Jacque\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileCoAuthLib64.dll ()
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {2EF9B4C4-7AB8-4BF0-84D0-2A7B458DE0EB} - System32\Tasks\{6875C840-9E81-4C31-A43C-163B7F6C2E88} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe 
Task: {544B34F5-D628-4C68-87AB-37B72DF445E6} - System32\Tasks\ConfigFree Startup Programs => C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe [2009-07-13] (TOSHIBA CORPORATION)
Task: {5ACF6F79-FE90-48D8-8EDD-C48E014021A4} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe [2017-02-21] (AVG Technologies CZ, s.r.o.)
Task: {6DA2D441-347A-4F4D-B8BE-0432F6EF4772} - System32\Tasks\{2DD831B2-B01F-498B-BBBE-365165A684D8} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe 
Task: {75930C2B-AE49-4AD1-A00F-2A69DEBC5995} - System32\Tasks\{94966F68-E499-43C0-BAE8-43E628BDA581} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe 
Task: {772E93A7-E0BB-4CB0-BDEE-8C4EEF0AAE9E} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-04-19] (Microsoft Corporation)
Task: {7F5F1218-1590-434A-9722-3B457487B843} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe 
Task: {8489885C-8E97-4DC2-B64D-13C4EEAEA808} - System32\Tasks\{5B19AC4F-4882-431C-9894-E8EC20AEB0D7} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe 
Task: {964C6E13-D16D-40AD-BA14-85E23FB255A3} - System32\Tasks\Western Digital\SmartWare\____Volume_d8d9b8ee_b2b9_11e3_8a76_806e6f6e6963______Volume_74cc4d4b_b2df_11e3_8b28_001e33fe384a__ => C:\Program Files (x86)\Western Digital\WD SmartWare\BackupTask.exe [2016-04-19] (Western Digital Technologies, Inc.)
Task: {9DF42437-CD5A-4430-B1A5-CBDCB7F4B42D} - System32\Tasks\{52255622-5B0F-4D8F-9A7A-6AC6FB06B9F5} => pcalua.exe -a C:\Users\Jacque\Downloads\jxpiinstall.exe -d C:\Users\Jacque\Downloads
Task: {AFD58337-C356-48D8-AE3C-5D52E1EE539F} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-02-02] (Adobe Systems Incorporated)
Task: {B0A4738C-2827-4808-B30F-DC28723B2C7D} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-12-12] (Oracle Corporation)
Task: {BD89921E-E45E-4FA5-AEB4-8EECCE303F38} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-04-19] (Microsoft Corporation)
Task: {C44BF2A1-32BD-4B4C-97A0-440FB2145241} - System32\Tasks\{2A9E900C-A9D9-45F1-B539-5021FBA02675} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe 
Task: {CAB01AF9-3719-4148-ADCE-04FC0CDE29F0} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\AVG\AVG PC TuneUp\OneClick.exe 
Task: {F84C2578-698C-46C3-9E8E-E8CF08428FBC} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-05-03] (Adobe Systems Incorporated)
Task: {F91D9249-6013-4CD4-BCDB-C4C48ED9AD78} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-05-03] (Microsoft Corporation)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2017-01-11 09:42 - 2017-01-11 09:42 - 00959168 _____ () C:\Users\Jacque\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll
2017-01-11 09:15 - 2017-05-03 23:43 - 08931008 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
2017-03-22 13:38 - 2017-04-17 10:42 - 02271520 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll
2017-03-22 13:38 - 2017-04-17 10:42 - 02267600 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2016-12-03 00:40 - 2016-12-03 00:40 - 48920064 _____ () C:\Program Files (x86)\AVG\UiDll\2623\libcef.dll
2017-01-11 09:42 - 2017-01-11 09:42 - 00679624 _____ () C:\Users\Jacque\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\ClientTelemetry.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 19:34 - 2009-06-10 14:00 - 00000824 _____ C:\windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1359882058-2057507765-851322289-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Jacque\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-1359882058-2057507765-851322289-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05042017225524601\Control Panel\Desktop\\Wallpaper -> C:\Users\Jacque\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{BE2EF63A-A88B-4F1A-8D56-431A80F238B3}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\wlcsdk.exe
FirewallRules: [{39785E96-A10C-454F-9B98-C49746A2C64E}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{A7D6A2A0-224D-4029-B29A-E99BEDFB1A68}] => (Allow) svchost.exe
FirewallRules: [{32C7FF4F-10D9-497E-AB14-8A05C9BF04A1}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe
FirewallRules: [{38F364C5-C862-4F3E-ACA2-D1A4B73C9C07}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{B0CFBB59-F505-48D6-BF1A-FD0FF17F87D8}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{A5C0BCED-2932-4664-8D74-89F7CD8E423A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{880C7363-7878-406E-8CC1-1B0FF98083B7}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{DE1B3A98-C401-4F15-AB09-0F8686A85A09}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{C757F4CF-32A0-4BA1-8B35-FA71EE2E8826}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{67B55C6A-6CEE-4965-B67A-734AEDB733BD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{F227D87D-1E4D-4553-84D9-8B75121750BC}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{A4BF92E1-2395-4FD5-9414-6246E1D11B07}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{1B574892-D0F7-4D8D-8616-A86DC0CD75F8}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{86F07138-E2D3-4522-A67E-B444362F3D0E}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{0F5ED709-ED0D-4E13-9A25-F2889644D108}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{EB2545CB-66A1-4BD1-83B7-4103AB6D2F72}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{FE74CE2F-74E4-4AC9-BBC4-4242D9C2E72C}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
 
==================== Restore Points =========================
 
03-05-2017 14:02:46 Scheduled Checkpoint
03-05-2017 23:01:47 Windows Update
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (05/03/2017 02:47:20 PM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: The backup did not complete because of an error writing to the backup location F:\. The error is: The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006).
 
Error: (04/24/2017 07:12:51 AM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: The backup did not complete because of an error writing to the backup location F:\. The error is: The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006).
 
Error: (04/16/2017 07:00:02 PM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: The backup did not complete because of an error writing to the backup location F:\. The error is: The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006).
 
Error: (04/10/2017 10:18:20 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: thunderbird.exe, version: 45.8.0.6273, time stamp: 0x58bc9206
Faulting module name: xul.dll, version: 45.8.0.6273, time stamp: 0x58bc92cb
Exception code: 0xc0000005
Fault offset: 0x00080e5f
Faulting process id: 0x1780
Faulting application start time: 0x01d2b21c5143e085
Faulting application path: C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
Faulting module path: C:\Program Files (x86)\Mozilla Thunderbird\xul.dll
Report Id: b17e9df1-1e11-11e7-b070-001e33fe384a
 
Error: (04/10/2017 12:41:27 AM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: The backup did not complete because of an error writing to the backup location F:\. The error is: The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006).
 
Error: (04/09/2017 02:01:40 PM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: The backup did not complete because of an error writing to the backup location F:\. The error is: The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006).
 
Error: (03/20/2017 05:24:28 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: thunderbird.exe, version: 45.8.0.6273, time stamp: 0x58bc9206
Faulting module name: xul.dll, version: 45.8.0.6273, time stamp: 0x58bc92cb
Exception code: 0xc0000005
Fault offset: 0x00080e5f
Faulting process id: 0x13c8
Faulting application start time: 0x01d2a1d8aeb653b9
Faulting application path: C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
Faulting module path: C:\Program Files (x86)\Mozilla Thunderbird\xul.dll
Report Id: be61b10e-0dcc-11e7-8d83-001e33fe384a
 
Error: (03/20/2017 05:09:39 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: thunderbird.exe, version: 45.8.0.6273, time stamp: 0x58bc9206
Faulting module name: xul.dll, version: 45.8.0.6273, time stamp: 0x58bc92cb
Exception code: 0xc0000005
Fault offset: 0x00080e5f
Faulting process id: 0x167c
Faulting application start time: 0x01d2a1cc38409097
Faulting application path: C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
Faulting module path: C:\Program Files (x86)\Mozilla Thunderbird\xul.dll
Report Id: ac8bb18d-0dca-11e7-8d83-001e33fe384a
 
Error: (03/19/2017 07:09:06 PM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: The backup did not complete because of an error writing to the backup location F:\. The error is: The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006).
 
Error: (03/13/2017 02:01:34 PM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: The backup did not complete because of an error writing to the backup location F:\. The error is: The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006).
 
 
System errors:
=============
Error: (05/04/2017 10:54:59 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Wlansvc service.
 
Error: (05/04/2017 06:45:01 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {995C996E-D918-4A8C-A302-45719A6F4EA7} did not register with DCOM within the required timeout.
 
Error: (05/03/2017 10:45:32 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for FailureActions with the following error: 
Access is denied.
 
Error: (05/03/2017 10:45:26 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for FailureActions with the following error: 
Access is denied.
 
Error: (05/03/2017 10:40:39 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for FailureActions with the following error: 
Access is denied.
 
Error: (05/03/2017 10:26:26 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for FailureActions with the following error: 
Access is denied.
 
Error: (05/03/2017 10:26:22 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for FailureActions with the following error: 
Access is denied.
 
Error: (05/03/2017 10:23:25 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Windows Update service terminated with the following error: 
The class is configured to run as a security id different from the caller
 
Error: (05/03/2017 10:23:23 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Security Center service terminated with the following error: 
The authentication service is unknown.
 
Error: (05/03/2017 10:23:22 PM) (Source: WMPNetworkSvc) (EventID: 14338) (User: )
Description: A new media server was not initialized because CoCreateInstance(CLSID_UPnPRegistrar) encountered error '0x8007045b'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™2 Duo CPU T6500 @ 2.10GHz
Percentage of memory in use: 67%
Total physical RAM: 3963.99 MB
Available physical RAM: 1278.24 MB
Total Virtual: 7926.16 MB
Available Virtual: 5860.93 MB
 
==================== Drives ================================
 
Drive c: (TI102618W0G) (Fixed) (Total:287.57 GB) (Free:228.04 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive e: (WD Unlocker) (CDROM) (Total:0.01 GB) (Free:0 GB) UDF
Drive f: (My Passport) (Fixed) (Total:465.73 GB) (Free:371.51 GB) NTFS
Drive g: (REPAIR DISK) (Removable) (Total:3.72 GB) (Free:3.72 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 3B56DC6B)
Partition 1: (Active) - (Size=1.5 GB) - (Type=27)
Partition 2: (Not Active) - (Size=287.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=9.1 GB) - (Type=17)
 
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 465.7 GB) (Disk ID: 8A4A809B)
Partition 1: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)
 
========================================================
Disk: 2 (Size: 3.7 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
==================== End of Addition.txt ============================

  • 0

#6
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,668 posts
Hello,

A few items to fix
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Open notepad (Start =>All Programs => Accessories => Notepad).
Copy/Paste the contents of the code box below into Notepad.
 
start
CloseProcesses:
CreateRestorePoint:
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-1359882058-2057507765-851322289-1001 -> {8C681919-1BB3-4D78-8810-F0351DC9EF21} URL = 
SearchScopes: HKU\S-1-5-21-1359882058-2057507765-851322289-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05042017225524601 -> {8C681919-1BB3-4D78-8810-F0351DC9EF21} URL = 
Emptytemp:
  • Click Format and ensure Wordwrap is unchecked.
  • Save as Fixlist.txt to G:\ (Must be in this location)
  • Run FRST/FRST64 and press the Fix button just once and wait.
  • If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
  • The tool will make a log in G:\ (Fixlog.txt). Please post it to your reply.
Note: If the tool warns you about the version you're using being an outdated version please download and run the updated version.
  • 0

#7
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,668 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP