Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Computer won't boot. MBAMSwissarmy.sys missing


  • This topic is locked This topic is locked

#1
Rittenhouse4

Rittenhouse4

    New Member

  • Member
  • Pip
  • 3 posts

Hi,

I have been trying for a couple days now to fix my other computer to no avail. It will not start and keeps coming up that MBAMSwissarmy.sys is missing. Don't know how it happened. I just went in to use it and had to restart it and it wouldn't start from the last time I used it. A couple days prior. It is my wife's computer so you can realize how much trouble I'm in at this point. :-)

Any way I have been all over the internet looking for advice and you people seem to know the most about repairing this. In looking around I see that I need the FRST tool which I downloaded and I have attached the pasted the resulting scan..

Any help you can give will be greatly appreciated. The scan is pasted below.

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-05-2017
Ran by SYSTEM on MININT-EV3MBHJ (12-05-2017 14:15:55)
Running from L:\
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11
Boot Mode: Recovery
Default: ControlSet001
ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9037832 2016-10-21] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2634872 2015-08-17] (NVIDIA Corporation)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [MBCfg64] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\MBCfg64.dll,RunDLLEntry MBCfg64
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [558496 2014-02-27] (Adobe Systems Incorporated)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2014-06-26] (Intel Corporation)
HKLM-x32\...\Run: [Sound Blaster Cinema] => C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe [711680 2013-08-16] (Creative Technology Ltd)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3499896 2014-05-08] (Adobe Systems Inc.)
HKLM-x32\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe [2075480 2013-06-24] (Flexera Software LLC.)
HKLM-x32\...\Run: [PaperPort PTD] => C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe [36168 2014-06-26] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [IndexSearch] => C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe [18248 2014-06-26] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [WindowsDefender] => -
Startup: C:\Users\Dianne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - .lnk [2015-05-11]
ShortcutTarget: Monitor Ink Alerts - .lnk -> C:\Program Files\HP\HP Officejet Pro 8610\Bin\HPStatusBL.dll (Hewlett-Packard Development Company, LP)
Startup: C:\Users\Dianne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Officejet Pro 8610.lnk [2017-05-07]
ShortcutTarget: Monitor Ink Alerts - HP Officejet Pro 8610.lnk -> C:\Program Files\HP\HP Officejet Pro 8610\Bin\HPStatusBL.dll (Hewlett-Packard Development Company, LP)
BootExecute: autocheck autochk * bootdelete

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 ExpressVpnService; C:\Program Files (x86)\ExpressVPN\bootstrap\AMD64\nssm.exe [331264 2017-03-10] ()
S2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1155192 2015-08-17] (NVIDIA Corporation)
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887256 2014-05-13] (Intel® Corporation)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [158496 2014-11-10] (Intel Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes)
S2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
S2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872504 2015-08-17] (NVIDIA Corporation)
S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5544568 2015-08-17] (NVIDIA Corporation)
S2 OneTouch 4.0 Monitor; C:\Program Files (x86)\Visioneer\OneTouch 4.0\OtService.exe [229376 2015-06-26] (Visioneer Inc.)
S2 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [77640 2014-06-26] (Nuance Communications, Inc.)
S2 RWAR4DHV_0003_0; C:\Program Files\Visioneer\RWAR4D\RWAR4DHV_0003_0.EXE [437248 2015-06-17] (Visioneer Inc.)
S2 RWAR4DMonitor; C:\Program Files\Visioneer\RWAR4D\RWAR4DMonitor.exe [242688 2017-04-19] (Visioneer Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
S2 locep; C:\ProgramData\\locep\\locep.exe shuz -f "C:\ProgramData\\locep\\locep.dat" -l -a

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AcpiCtlDrv; C:\Windows\System32\DRIVERS\AcpiCtlDrv.sys [25880 2012-07-17] (Intel Corporation)
S0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [65248 2015-04-23] (Advanced Micro Devices, Inc.)
S1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77440 2017-04-23] ()
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [54736 2017-04-22] ()
S3 INETMON; C:\Windows\System32\Drivers\INETMON.sys [25800 2014-05-27] ()
S3 ISCT; C:\Windows\System32\DRIVERS\ISCTD.sys [44744 2014-05-27] ()
S3 JmUsbCcgp; C:\Windows\System32\DRIVERS\jmccgp.sys [17136 2009-07-29] (JMicron Technology Corp.)
S1 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [186304 2017-04-23] (Malwarebytes)
S3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [0 2017-05-11] () <==== ATTENTION (zero byte File/Folder)
S0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [0 2017-05-11] () <==== ATTENTION (zero byte File/Folder)
S3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [82720 2017-05-11] (Malwarebytes)
S3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [178976 2015-07-28] (Intel Corporation)
S0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19576 2015-08-17] (NVIDIA Corporation)
S3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [50472 2015-08-10] (NVIDIA Corporation)
S3 tapexpressvpn; C:\Windows\System32\DRIVERS\tapexpressvpn.sys [35696 2017-03-10] (The OpenVPN Project)
S3 WirelessKeyboardFilter; C:\Windows\System32\DRIVERS\WirelessKeyboardFilter.sys [49896 2016-07-22] (Microsoft Corporation)
S3 XtuAcpiDriver; C:\Windows\System32\DRIVERS\XtuAcpiDriver.sys [54344 2016-11-21] (Intel Corporation)
S1 arfvvobb; \??\C:\Windows\system32\drivers\arfvvobb.sys [X]
S3 MSICDSetup; \??\G:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\G:\NTIOLib_X64.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-05-11 08:46 - 2017-05-11 08:46 - 00000000 _____ C:\Windows\System32\Drivers\56F32CD0.sys
2017-05-11 08:38 - 2017-05-11 08:38 - 00000000 _____ C:\Windows\System32\Drivers\4DCC2696.sys
2017-05-11 07:16 - 2017-05-11 07:16 - 00000000 _____ C:\Windows\System32\Drivers\7A78682F.sys
2017-05-09 10:54 - 2017-05-09 10:54 - 00000000 ____D C:\Users\Dick\AppData\Local\{D4F10703-8FBA-4AC5-83FD-C3D10229B06A}
2017-05-04 11:44 - 2017-05-04 11:44 - 00000000 ____D C:\Users\Dick\AppData\Local\{0D87C64C-7861-44AA-88E1-B34DBE84C3C3}
2017-05-01 09:16 - 2017-05-01 09:17 - 00000000 ____D C:\Windows\rescache
2017-05-01 07:34 - 2017-03-10 08:32 - 00300544 _____ (Microsoft Corporation) C:\Windows\System32\pdh.dll
2017-05-01 07:33 - 2017-03-10 08:32 - 01389056 _____ (Microsoft Corporation) C:\Windows\System32\pla.dll
2017-05-01 07:33 - 2017-03-10 08:31 - 00880640 _____ (Microsoft Corporation) C:\Windows\System32\advapi32.dll
2017-05-01 07:33 - 2017-03-10 08:20 - 01508352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pla.dll
2017-05-01 07:33 - 2017-03-10 08:20 - 00237056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdh.dll
2017-05-01 07:33 - 2017-03-10 08:19 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-05-01 07:33 - 2017-03-10 07:57 - 00009216 _____ (Microsoft Corporation) C:\Windows\System32\plasrv.exe
2017-05-01 07:33 - 2017-03-10 07:55 - 00205312 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\fastfat.sys
2017-05-01 07:33 - 2017-03-10 07:55 - 00195584 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\exfat.sys
2017-05-01 07:33 - 2017-03-09 08:34 - 00002048 _____ (Microsoft Corporation) C:\Windows\System32\tzres.dll
2017-05-01 07:33 - 2017-03-09 08:19 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2017-04-23 10:08 - 2017-05-11 08:46 - 00082720 _____ (Malwarebytes) C:\Windows\System32\Drivers\mwac.sys
2017-04-23 10:08 - 2017-05-11 08:46 - 00000000 _____ C:\Windows\System32\Drivers\mbam.sys
2017-04-23 10:08 - 2017-05-11 08:46 - 00000000 _____ C:\Windows\System32\Drivers\farflt.sys
2017-04-23 10:08 - 2017-04-23 11:10 - 00186304 _____ (Malwarebytes) C:\Windows\System32\Drivers\MBAMChameleon.sys
2017-04-23 10:07 - 2017-05-11 08:46 - 00000000 _____ C:\Windows\System32\Drivers\MBAMSwissArmy.sys
2017-04-23 10:07 - 2017-04-23 11:10 - 00077440 _____ C:\Windows\System32\Drivers\mbae64.sys
2017-04-23 10:07 - 2017-04-23 10:07 - 00001912 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-04-23 10:07 - 2017-04-23 10:07 - 00000000 ____D C:\Program Files\Malwarebytes
2017-04-22 09:20 - 2017-04-22 09:22 - 00002164 _____ C:\Users\Dick\Desktop\Rkill.txt
2017-04-22 09:17 - 2017-04-22 09:17 - 00054736 _____ C:\Windows\System32\Drivers\hitmanpro37.sys
2017-04-22 09:13 - 2017-04-22 09:13 - 00010616 _____ C:\Windows\System32\.crusader
2017-04-21 11:50 - 2017-04-21 11:51 - 317016064 _____ C:\Users\Dick\Downloads\kav_rescue_10.iso
2017-04-21 11:01 - 2017-04-21 11:01 - 00001122 _____ C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2017-04-21 10:30 - 2017-04-21 10:31 - 00043846 _____ C:\Users\Dick\Downloads\Addition.txt
2017-04-21 10:28 - 2017-05-12 14:15 - 00000000 ____D C:\FRST
2017-04-21 10:28 - 2017-04-21 10:31 - 00083536 _____ C:\Users\Dick\Downloads\FRST.txt
2017-04-21 10:27 - 2017-04-21 10:27 - 02424832 _____ (Farbar) C:\Users\Dick\Downloads\FRST64.exe
2017-04-21 08:04 - 2017-05-12 01:18 - 00000000 ____D C:\Kaspersky Rescue Disk 10.0
2017-04-20 22:33 - 2017-04-20 22:33 - 00000000 _____ C:\Windows\System32\config\SOFTWARE9fb4499a
2017-04-20 16:56 - 2017-04-20 16:56 - 109178880 _____ C:\Windows\System32\config\SOFTWARE9c2d2755
2017-04-20 16:03 - 2017-04-22 14:26 - 00000000 ____D C:\Windows\Microsoft Antimalware
2017-04-20 12:36 - 2017-04-20 12:36 - 00892944 _____ (Microsoft Corporation) C:\Users\Dick\Downloads\mssstool64.exe
2017-04-20 11:20 - 2017-04-21 10:31 - 00000000 ____D C:\Program Files\Common Files\e4ranz2g
2017-04-20 10:39 - 2017-04-22 09:13 - 00000000 ____D C:\ProgramData\locep
2017-04-20 10:26 - 2017-04-20 10:26 - 00000000 ____D C:\Windows\ERUNT
2017-04-20 10:04 - 2017-04-20 10:04 - 00000000 ____D C:\Users\Dick\AppData\Roaming\Obsidium
2017-04-20 09:40 - 2017-04-20 09:40 - 00000000 ____D C:\Users\Dick\AppData\Roaming\FLEXnet
2017-04-20 09:05 - 2017-04-21 09:08 - 00000000 ____D C:\Program Files\Common Files\krr4pl3r
2017-04-20 07:50 - 2017-04-22 11:44 - 00000000 ____D C:\Users\Dick\AppData\Local\llssoft
2017-04-20 07:41 - 2017-04-22 04:19 - 00000000 ____D C:\Users\Dick\AppData\Local\sgmmol
2017-04-20 07:41 - 2017-04-20 08:03 - 00000000 ____D C:\Users\Dick\AppData\Local\jolxl
2017-04-20 07:41 - 2017-04-20 07:41 - 00000000 ____D C:\Users\Dick\AppData\Roaming\Mozilla
2017-04-20 07:41 - 2017-04-20 07:41 - 00000000 ____D C:\Users\Dick\AppData\Roaming\c
2017-04-20 07:39 - 2017-04-22 04:17 - 00000000 ____D C:\Program Files\BitTorrent
2017-04-20 07:38 - 2017-04-20 07:38 - 00018432 _____ C:\Users\Dick\AppData\Roaming\Main.dat
2017-04-20 07:37 - 2017-04-20 07:37 - 00140288 _____ C:\Users\Dick\AppData\Roaming\Installer.dat
2017-04-20 07:14 - 2017-04-20 07:14 - 00000000 ____D C:\Users\Dianne\Documents\My OneTouch Archive
2017-04-20 07:14 - 2017-04-20 07:14 - 00000000 ____D C:\Users\Dianne\Documents\Mail Attachments
2017-04-20 07:14 - 2017-04-20 07:14 - 00000000 ____D C:\Users\Dianne\AppData\Roaming\Visioneer
2017-04-20 07:14 - 2017-04-20 07:14 - 00000000 ____D C:\Users\Dianne\AppData\Roaming\Nuance
2017-04-20 07:14 - 2017-04-20 07:14 - 00000000 ____D C:\Users\Dianne\AppData\Roaming\LinkManager 4.0
2017-04-19 11:09 - 2017-04-19 11:09 - 00000000 ____D C:\Users\Dick\Documents\My PaperPort Documents
2017-04-19 10:06 - 2017-04-19 11:14 - 00000000 ____D C:\Users\Dick\AppData\Roaming\.oit
2017-04-19 10:06 - 2017-04-19 10:06 - 00002117 _____ C:\Users\Public\Desktop\PaperPort.lnk
2017-04-19 10:06 - 2017-04-19 10:06 - 00000000 ____D C:\Windows\PIXTRAN
2017-04-19 10:06 - 2017-04-19 10:06 - 00000000 ____D C:\Users\Dick\AppData\Roaming\Zeon
2017-04-19 10:06 - 2017-04-19 10:06 - 00000000 ____D C:\Users\Dick\AppData\Local\Nuance
2017-04-19 10:06 - 2017-04-19 10:06 - 00000000 ____D C:\ProgramData\ScanSoft
2017-04-19 10:05 - 2017-04-19 10:05 - 00000000 ____D C:\Users\Dick\Documents\MyWebPages
2017-04-19 10:05 - 2017-04-19 10:05 - 00000000 ____D C:\ProgramData\Nuance
2017-04-19 10:05 - 2017-04-19 10:05 - 00000000 ____D C:\ProgramData\Macrovision
2017-04-19 10:05 - 2017-04-19 10:05 - 00000000 ____D C:\ProgramData\FLEXnet
2017-04-19 10:05 - 2017-04-19 10:05 - 00000000 ____D C:\Program Files (x86)\Nuance
2017-04-19 10:00 - 2017-04-19 10:06 - 00000000 ____D C:\Users\Dick\AppData\Roaming\Nuance
2017-04-19 10:00 - 2017-04-19 10:00 - 00000000 ____D C:\Users\Dick\Documents\My OneTouch Archive
2017-04-19 10:00 - 2017-04-19 10:00 - 00000000 ____D C:\Users\Dick\Documents\Mail Attachments
2017-04-19 10:00 - 2017-04-19 10:00 - 00000000 ____D C:\Users\Dick\AppData\Roaming\Visioneer
2017-04-19 10:00 - 2017-04-19 10:00 - 00000000 ____D C:\Users\Dick\AppData\Roaming\LinkManager 4.0
2017-04-19 09:57 - 2017-04-19 09:57 - 00000000 ____D C:\temp
2017-04-19 09:56 - 2017-04-19 09:56 - 00000000 ____D C:\Users\Public\Documents\Visioneer
2017-04-19 09:56 - 2017-04-19 09:56 - 00000000 ____D C:\ProgramData\Visioneer
2017-04-19 09:55 - 2014-09-30 06:12 - 10608640 _____ C:\Windows\System32\QtGuiViz4.dll
2017-04-19 09:55 - 2014-09-30 06:12 - 08151040 _____ C:\Windows\SysWOW64\QtGuiViz4.dll
2017-04-19 09:55 - 2014-09-30 06:12 - 02910208 _____ C:\Windows\System32\QtCoreViz4.dll
2017-04-19 09:55 - 2014-09-30 06:12 - 02277888 _____ C:\Windows\SysWOW64\QtCoreViz4.dll
2017-04-19 09:55 - 2014-09-30 06:12 - 00168144 _____ (TWAIN Working Group) C:\Windows\System32\TWAINDSM.dll
2017-04-19 09:55 - 2014-09-30 06:12 - 00150736 _____ (TWAIN Working Group) C:\Windows\SysWOW64\TWAINDSM.dll
2017-04-19 09:53 - 2017-04-19 09:57 - 00000000 ____D C:\Program Files\Common Files\Visioneer
2017-04-19 09:53 - 2017-04-19 09:56 - 00000000 ____D C:\Program Files (x86)\Visioneer
2017-04-19 09:53 - 2017-04-19 09:53 - 00000000 ____D C:\Windows\Twain_64
2017-04-19 09:53 - 2017-04-19 09:53 - 00000000 ____D C:\Program Files\Visioneer
2017-04-19 09:50 - 2017-04-19 09:50 - 00000000 ____D C:\Users\Dick\AppData\Roaming\NVIDIA
2017-04-15 10:16 - 2017-04-15 10:16 - 00000000 ____D C:\Users\Dick\AppData\Local\{345303BC-5D99-4BDF-8FE2-CF0984D4BB06}
2017-04-14 03:28 - 2017-04-14 03:28 - 00000000 ____D C:\Users\Dick\AppData\Local\{DC622CBF-0E0A-49CD-993E-F0BA0F31E433}
2017-04-13 15:27 - 2017-04-13 15:27 - 00000000 ____D C:\Users\Dick\AppData\Local\{652DE49E-CD08-4DDE-8C95-9D0078877E01}
2017-04-12 04:52 - 2017-03-27 10:13 - 00394448 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2017-04-12 04:52 - 2017-03-27 09:28 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-04-12 04:52 - 2017-03-25 11:39 - 20284416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-04-12 04:52 - 2017-03-25 11:07 - 04604416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-04-12 04:52 - 2017-03-25 11:06 - 13654016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-04-12 04:52 - 2017-03-25 10:55 - 02767360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-04-12 04:52 - 2017-03-25 10:52 - 02289152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-04-12 04:52 - 2017-03-25 10:51 - 01313280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-04-12 04:52 - 2017-03-25 10:48 - 00499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-04-12 04:52 - 2017-03-25 10:47 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-04-12 04:52 - 2017-03-25 10:47 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-04-12 04:52 - 2017-03-25 10:47 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-04-12 04:52 - 2017-03-25 10:46 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-04-12 04:52 - 2017-03-25 10:46 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-04-12 04:52 - 2017-03-25 10:46 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-04-12 04:52 - 2017-03-25 10:46 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-04-12 04:52 - 2017-03-25 10:46 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-04-12 04:52 - 2017-03-25 10:46 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-04-12 04:52 - 2017-03-25 10:46 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-04-12 04:52 - 2017-03-25 10:46 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-04-12 04:52 - 2017-03-25 10:45 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-04-12 04:52 - 2017-03-25 10:45 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-04-12 04:52 - 2017-03-25 10:45 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-04-12 04:52 - 2017-03-25 10:45 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-04-12 04:52 - 2017-03-25 10:45 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-04-12 04:52 - 2017-03-25 10:45 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-04-12 04:52 - 2017-03-25 10:45 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-04-12 04:52 - 2017-03-25 10:44 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-04-12 04:52 - 2017-03-25 10:44 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-04-12 04:52 - 2017-03-25 10:35 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2017-04-12 04:52 - 2017-03-25 10:35 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll
2017-04-12 04:52 - 2017-03-25 10:16 - 00066560 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2017-04-12 04:52 - 2017-03-25 10:14 - 00417792 _____ (Microsoft Corporation) C:\Windows\System32\html.iec
2017-04-12 04:52 - 2017-03-25 10:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll
2017-04-12 04:52 - 2017-03-25 10:13 - 00576512 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2017-04-12 04:52 - 2017-03-25 10:13 - 00088064 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll
2017-04-12 04:52 - 2017-03-25 10:10 - 02898432 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2017-04-12 04:52 - 2017-03-25 10:04 - 00054784 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2017-04-12 04:52 - 2017-03-25 10:02 - 00034304 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2017-04-12 04:52 - 2017-03-25 09:57 - 00615936 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2017-04-12 04:52 - 2017-03-25 09:56 - 00817664 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
2017-04-12 04:52 - 2017-03-25 09:56 - 00814080 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll
2017-04-12 04:52 - 2017-03-25 09:56 - 00144384 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2017-04-12 04:52 - 2017-03-25 09:56 - 00114688 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe
2017-04-12 04:52 - 2017-03-25 09:52 - 25746944 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2017-04-12 04:52 - 2017-03-25 09:45 - 00968704 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
2017-04-12 04:52 - 2017-03-25 09:41 - 06045696 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2017-04-12 04:52 - 2017-03-25 09:41 - 00489984 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2017-04-12 04:52 - 2017-03-25 09:30 - 00077824 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll
2017-04-12 04:52 - 2017-03-25 09:29 - 00107520 _____ (Microsoft Corporation) C:\Windows\System32\inseng.dll
2017-04-12 04:52 - 2017-03-25 09:24 - 00199680 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll
2017-04-12 04:52 - 2017-03-25 09:23 - 00092160 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2017-04-12 04:52 - 2017-03-25 09:20 - 00315392 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2017-04-12 04:52 - 2017-03-25 09:19 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-04-12 04:52 - 2017-03-25 09:17 - 00152064 _____ (Microsoft Corporation) C:\Windows\System32\occache.dll
2017-04-12 04:52 - 2017-03-25 09:06 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-04-12 04:52 - 2017-03-25 09:04 - 00262144 _____ (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2017-04-12 04:52 - 2017-03-25 09:00 - 00725504 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2017-04-12 04:52 - 2017-03-25 08:59 - 00806912 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2017-04-12 04:52 - 2017-03-25 08:57 - 02131456 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2017-04-12 04:52 - 2017-03-25 08:57 - 01359360 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
2017-04-12 04:52 - 2017-03-25 08:28 - 15259136 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2017-04-12 04:52 - 2017-03-25 08:27 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-04-12 04:52 - 2017-03-25 08:24 - 03241472 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2017-04-12 04:52 - 2017-03-25 08:10 - 01546240 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2017-04-12 04:52 - 2017-03-25 08:01 - 00800768 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2017-04-12 04:52 - 2017-03-24 14:50 - 00405504 _____ (Microsoft Corporation) C:\Windows\System32\gdi32.dll
2017-04-12 04:52 - 2017-03-24 14:42 - 00313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-04-12 04:52 - 2017-03-22 07:32 - 03165184 _____ (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2017-04-12 04:52 - 2017-03-22 07:32 - 00192512 _____ (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2017-04-12 04:52 - 2017-03-22 07:32 - 00098816 _____ (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2017-04-12 04:52 - 2017-03-22 07:30 - 00091136 _____ (Microsoft Corporation) C:\Windows\System32\WinSetupUI.dll
2017-04-12 04:52 - 2017-03-22 07:24 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2017-04-12 04:52 - 2017-03-22 07:17 - 02651136 _____ (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2017-04-12 04:52 - 2017-03-22 07:15 - 00709120 _____ (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2017-04-12 04:52 - 2017-03-22 07:15 - 00140288 _____ (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2017-04-12 04:52 - 2017-03-22 07:15 - 00037888 _____ (Microsoft Corporation) C:\Windows\System32\wups2.dll
2017-04-12 04:52 - 2017-03-22 07:15 - 00037888 _____ (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2017-04-12 04:52 - 2017-03-22 07:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\System32\wups.dll
2017-04-12 04:52 - 2017-03-22 07:15 - 00012288 _____ (Microsoft Corporation) C:\Windows\System32\wu.upgrade.ps.dll
2017-04-12 04:52 - 2017-03-22 07:05 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2017-04-12 04:52 - 2017-03-22 07:05 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2017-04-12 04:52 - 2017-03-22 07:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2017-04-12 04:52 - 2017-03-22 07:05 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2017-04-12 04:52 - 2017-03-14 07:34 - 00986344 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2017-04-12 04:52 - 2017-03-14 07:34 - 00265448 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys
2017-04-12 04:52 - 2017-03-14 07:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\System32\cdd.dll
2017-04-12 04:52 - 2017-03-10 08:35 - 00382696 _____ (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
2017-04-12 04:52 - 2017-03-10 08:31 - 00100864 _____ (Microsoft Corporation) C:\Windows\System32\fontsub.dll
2017-04-12 04:52 - 2017-03-10 08:31 - 00046080 _____ (Adobe Systems) C:\Windows\System32\atmlib.dll
2017-04-12 04:52 - 2017-03-10 08:31 - 00041472 _____ (Microsoft Corporation) C:\Windows\System32\lpk.dll
2017-04-12 04:52 - 2017-03-10 08:31 - 00014336 _____ (Microsoft Corporation) C:\Windows\System32\dciman32.dll
2017-04-12 04:52 - 2017-03-10 08:27 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2017-04-12 04:52 - 2017-03-10 08:20 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2017-04-12 04:52 - 2017-03-10 08:19 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2017-04-12 04:52 - 2017-03-10 08:19 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2017-04-12 04:52 - 2017-03-10 08:00 - 03219968 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys
2017-04-12 04:52 - 2017-03-10 07:53 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2017-04-12 04:52 - 2017-03-08 12:20 - 01133568 _____ (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2017-04-12 04:52 - 2017-03-08 12:10 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2017-04-12 04:52 - 2017-03-07 20:37 - 00631176 _____ (Microsoft Corporation) C:\Windows\System32\winresume.efi
2017-04-12 04:52 - 2017-03-07 20:36 - 05548264 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2017-04-12 04:52 - 2017-03-07 20:36 - 00706792 _____ (Microsoft Corporation) C:\Windows\System32\winload.efi
2017-04-12 04:52 - 2017-03-07 20:36 - 00154856 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2017-04-12 04:52 - 2017-03-07 20:36 - 00095464 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2017-04-12 04:52 - 2017-03-07 20:34 - 01732864 _____ (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 02064384 _____ (Microsoft Corporation) C:\Windows\System32\ole32.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 01460736 _____ (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 01212928 _____ (Microsoft Corporation) C:\Windows\System32\rpcrt4.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 01163264 _____ (Microsoft Corporation) C:\Windows\System32\kernel32.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00730624 _____ (Microsoft Corporation) C:\Windows\System32\kerberos.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00690688 _____ (Microsoft Corporation) C:\Windows\System32\adtschema.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00503808 _____ (Microsoft Corporation) C:\Windows\System32\srcore.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00463872 _____ (Microsoft Corporation) C:\Windows\System32\certcli.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00419840 _____ (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00362496 _____ (Microsoft Corporation) C:\Windows\System32\wow64win.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00345600 _____ (Microsoft Corporation) C:\Windows\System32\schannel.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00316928 _____ (Microsoft Corporation) C:\Windows\System32\msv1_0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00312320 _____ (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00243712 _____ (Microsoft Corporation) C:\Windows\System32\wow64.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00215552 _____ (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00210432 _____ (Microsoft Corporation) C:\Windows\System32\wdigest.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00190464 _____ (Microsoft Corporation) C:\Windows\System32\rpchttp.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00146432 _____ (Microsoft Corporation) C:\Windows\System32\msaudite.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00135680 _____ (Microsoft Corporation) C:\Windows\System32\sspicli.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00123904 _____ (Microsoft Corporation) C:\Windows\System32\bcrypt.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00086528 _____ (Microsoft Corporation) C:\Windows\System32\TSpkg.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00063488 _____ (Microsoft Corporation) C:\Windows\System32\setbcdlocale.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00060416 _____ (Microsoft Corporation) C:\Windows\System32\msobjs.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00059904 _____ (Microsoft Corporation) C:\Windows\System32\appidapi.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00050176 _____ (Microsoft Corporation) C:\Windows\System32\srclient.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00044032 _____ (Microsoft Corporation) C:\Windows\System32\csrsrv.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00043520 _____ (Microsoft Corporation) C:\Windows\System32\cryptbase.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00034816 _____ (Microsoft Corporation) C:\Windows\System32\appidsvc.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00028672 _____ (Microsoft Corporation) C:\Windows\System32\sspisrv.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00028160 _____ (Microsoft Corporation) C:\Windows\System32\secur32.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00022016 _____ (Microsoft Corporation) C:\Windows\System32\credssp.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00016384 _____ (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00013312 _____ (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00006656 _____ (Microsoft Corporation) C:\Windows\System32\apisetschema.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00006144 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00005120 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:26 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-04-12 04:52 - 2017-03-07 20:26 - 03945192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-04-12 04:52 - 2017-03-07 20:24 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-04-12 04:52 - 2017-03-07 20:22 - 01416192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2017-04-12 04:52 - 2017-03-07 20:22 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-04-12 04:52 - 2017-03-07 20:22 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-04-12 04:52 - 2017-03-07 20:22 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-04-12 04:52 - 2017-03-07 20:22 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-04-12 04:52 - 2017-03-07 20:22 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-04-12 04:52 - 2017-03-07 20:22 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-04-12 04:52 - 2017-03-07 20:22 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-04-12 04:52 - 2017-03-07 20:22 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-04-12 04:52 - 2017-03-07 20:22 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-04-12 04:52 - 2017-03-07 20:22 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-04-12 04:52 - 2017-03-07 20:22 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-04-12 04:52 - 2017-03-07 20:22 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-04-12 04:52 - 2017-03-07 20:22 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-04-12 04:52 - 2017-03-07 20:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-04-12 04:52 - 2017-03-07 20:22 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2017-04-12 04:52 - 2017-03-07 20:22 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-04-12 04:52 - 2017-03-07 20:22 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-04-12 04:52 - 2017-03-07 20:22 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 20:03 - 00148480 _____ (Microsoft Corporation) C:\Windows\System32\appidpolicyconverter.exe
2017-04-12 04:52 - 2017-03-07 20:03 - 00064000 _____ (Microsoft Corporation) C:\Windows\System32\auditpol.exe
2017-04-12 04:52 - 2017-03-07 20:03 - 00062464 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\appid.sys
2017-04-12 04:52 - 2017-03-07 20:03 - 00017920 _____ (Microsoft Corporation) C:\Windows\System32\appidcertstorecheck.exe
2017-04-12 04:52 - 2017-03-07 20:00 - 00338432 _____ (Microsoft Corporation) C:\Windows\System32\conhost.exe
2017-04-12 04:52 - 2017-03-07 19:59 - 00296960 _____ (Microsoft Corporation) C:\Windows\System32\rstrui.exe
2017-04-12 04:52 - 2017-03-07 19:57 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-04-12 04:52 - 2017-03-07 19:56 - 00291328 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb10.sys
2017-04-12 04:52 - 2017-03-07 19:56 - 00159744 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb.sys
2017-04-12 04:52 - 2017-03-07 19:56 - 00129536 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb20.sys
2017-04-12 04:52 - 2017-03-07 19:55 - 00112640 _____ (Microsoft Corporation) C:\Windows\System32\smss.exe
2017-04-12 04:52 - 2017-03-07 19:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\System32\lsass.exe
2017-04-12 04:52 - 2017-03-07 19:54 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-04-12 04:52 - 2017-03-07 19:54 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-04-12 04:52 - 2017-03-07 19:54 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-04-12 04:52 - 2017-03-07 19:54 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-04-12 04:52 - 2017-03-07 19:53 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-04-12 04:52 - 2017-03-07 19:53 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 19:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 19:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 19:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-04-12 04:52 - 2017-03-07 08:30 - 00085504 _____ (Microsoft Corporation) C:\Windows\System32\asycfilt.dll
2017-04-12 04:52 - 2017-03-07 08:17 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2017-04-12 04:52 - 2017-03-07 06:05 - 00243200 _____ (Microsoft Corporation) C:\Windows\System32\rdpudd.dll
2017-04-12 04:52 - 2017-03-03 17:27 - 01574912 _____ (Microsoft Corporation) C:\Windows\System32\quartz.dll
2017-04-12 04:52 - 2017-03-03 17:27 - 00093696 _____ (Microsoft Corporation) C:\Windows\System32\mfmjpegdec.dll
2017-04-12 04:52 - 2017-03-03 17:14 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2017-04-12 04:52 - 2017-03-03 17:14 - 00077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmjpegdec.dll
2017-04-12 04:52 - 2017-02-14 08:33 - 00757248 _____ (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2017-04-12 04:52 - 2017-02-14 08:19 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2017-04-12 04:52 - 2017-02-09 08:32 - 00769536 _____ (Microsoft Corporation) C:\Windows\System32\samsrv.dll
2017-04-12 04:52 - 2017-02-09 08:32 - 00106496 _____ (Microsoft Corporation) C:\Windows\System32\samlib.dll
2017-04-12 04:52 - 2017-02-09 08:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2017-04-12 04:52 - 2017-01-18 07:36 - 00994760 _____ (Microsoft Corporation) C:\Windows\System32\ucrtbase.dll
2017-04-12 04:52 - 2017-01-18 07:36 - 00063840 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-private-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:36 - 00020832 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-math-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:36 - 00019808 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-string-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:36 - 00016224 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:36 - 00015712 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-convert-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-time-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-2-0.dll
2017-04-12 04:52 - 2017-01-18 07:36 - 00013664 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-process-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-heap-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-conio-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-utility-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-locale-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-crt-environment-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-2-0.dll
2017-04-12 04:52 - 2017-01-18 07:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-12 04:52 - 2017-01-18 07:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l2-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-timezone-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l2-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:36 - 00011608 _____ (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-2-0.dll
2017-04-12 04:52 - 2017-01-18 07:35 - 00922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2017-04-12 04:52 - 2017-01-18 07:35 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:35 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:35 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:35 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:35 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2017-04-12 04:52 - 2017-01-18 07:35 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2017-04-12 04:52 - 2017-01-18 07:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-12 04:52 - 2017-01-18 07:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2017-04-12 04:52 - 2017-01-18 07:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2017-04-12 04:52 - 2016-03-23 14:40 - 03181568 _____ (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
2017-04-12 04:52 - 2016-03-23 14:40 - 00016384 _____ (Microsoft Corporation) C:\Windows\System32\RdpGroupPolicyExtension.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-01-12 10:05 - 2015-05-08 15:38 - 00003926 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{435D5BEC-8700-4B19-9E49-33494BD9658C}
2019-05-14 10:54 - 2015-05-06 11:49 - 00003934 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{B7E5D322-E3E9-41A3-9242-66699D88E302}
2017-05-11 08:41 - 2015-05-09 00:58 - 00000000 ____D C:\Windows\System32\Macromed
2017-05-11 00:53 - 2009-07-13 20:45 - 00022464 _____ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-05-11 00:53 - 2009-07-13 20:45 - 00022464 _____ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-05-08 17:42 - 2015-05-06 11:30 - 00000278 _____ C:\Windows\Tasks\RtlNetworkGenieVistaStart.job
2017-05-08 17:42 - 2015-05-06 10:21 - 00000000 ____D C:\ProgramData\NVIDIA
2017-05-08 17:42 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-05-06 11:22 - 2015-05-23 09:49 - 00000000 ____D C:\Users\Dick\AppData\Local\CrashDumps
2017-05-04 11:56 - 2015-05-11 12:43 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-05-04 11:43 - 2015-05-06 15:04 - 00000000 ____D C:\Users\Dianne\Documents\Outlook Files
2017-05-01 07:53 - 2009-07-13 21:13 - 00821478 _____ C:\Windows\System32\PerfStringBackup.INI
2017-05-01 07:53 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\inf
2017-04-27 19:19 - 2015-05-06 11:20 - 00003330 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-04-27 19:19 - 2015-05-06 11:20 - 00003202 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-04-26 10:22 - 2015-09-17 07:06 - 00000000 ____D C:\Windows\System32\Tasks\WiseCleaner
2017-04-26 10:22 - 2015-05-21 07:45 - 00000000 ____D C:\Program Files (x86)\Wise
2017-04-23 10:07 - 2015-05-06 12:16 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-04-23 09:56 - 2015-05-12 09:35 - 00000000 ____D C:\Users\Dick\AppData\Roaming\BitTorrent
2017-04-22 11:43 - 2015-05-08 09:35 - 00000000 ____D C:\users\Dick
2017-04-22 09:13 - 2015-06-01 11:18 - 00000000 ____D C:\ProgramData\HitmanPro
2017-04-21 10:49 - 2015-05-21 10:01 - 00028272 _____ C:\Windows\System32\Drivers\TrueSight.sys
2017-04-21 10:48 - 2015-05-21 10:02 - 00000000 ____D C:\Program Files\RogueKiller
2017-04-20 10:40 - 2015-05-07 14:06 - 00001436 _____ C:\Users\Dianne\Desktop\Internet Explorer.lnk
2017-04-20 08:09 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
2017-04-20 07:44 - 2009-07-13 20:45 - 00420664 _____ C:\Windows\System32\FNTCACHE.DAT
2017-04-20 07:41 - 2015-05-15 12:42 - 00000000 ____D C:\users\DefaultAppPool
2017-04-20 07:32 - 2015-05-08 09:35 - 00114072 _____ C:\Users\Dick\AppData\Local\GDIPFONTCACHEV1.DAT
2017-04-20 07:14 - 2015-05-06 11:33 - 00114072 _____ C:\Users\Dianne\AppData\Local\GDIPFONTCACHEV1.DAT
2017-04-19 09:31 - 2015-09-17 11:10 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-04-19 09:31 - 2015-05-06 14:02 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-04-18 12:14 - 2015-05-06 14:00 - 00000000 ____D C:\Windows\System32\MRT
2017-04-18 12:14 - 2009-07-13 18:34 - 00000577 _____ C:\Windows\win.ini
2017-04-18 12:11 - 2015-05-06 14:00 - 148601744 ____C (Microsoft Corporation) C:\Windows\System32\MRT.exe
2017-04-18 12:09 - 2015-05-06 10:28 - 00798132 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2017-04-14 09:22 - 2015-05-08 15:05 - 00000000 ____D C:\Users\Dick\Documents\Outlook Files
2017-04-14 09:18 - 2016-03-29 07:46 - 00000000 ____D C:\Users\Dick\Documents\TurboTax

Some files in TEMP:
====================
2014-03-25 03:22 - 2014-03-25 03:22 - 0398832 _____ (MSI) C:\Users\Dianne\AppData\Local\Temp\AutoWifi.exe
2015-05-06 10:26 - 2010-12-30 19:07 - 0086880 _____ (Microsoft Corporation) C:\Users\Dianne\AppData\Local\Temp\devcon64.exe
2015-05-31 08:15 - 2015-04-27 11:26 - 1728960 _____ (Microsoft Corporation) C:\Users\Dianne\AppData\Local\Temp\dllnt_dump.dll
2015-05-06 13:59 - 2015-05-06 14:00 - 50067152 _____ (Microsoft Corporation) C:\Users\Dianne\AppData\Local\Temp\MouseKeyboardCenterx64_1033.exe
2010-03-16 06:11 - 2010-03-16 06:11 - 0174440 _____ (Microsoft Corporation) C:\Users\Dianne\AppData\Local\Temp\ose00000.exe
2014-03-25 03:22 - 2014-03-25 03:22 - 0398832 ____R (MSI) C:\Users\Dick\AppData\Local\Temp\AutoWifi.exe
2016-01-18 10:18 - 2016-01-18 10:18 - 0170128 _____ (© 2015 Microsoft Corporation) C:\Users\Dick\AppData\Local\Temp\BSvcUpdater.exe
2015-09-17 10:45 - 2016-11-04 09:23 - 2612600 _____ (Microsoft Corporation) C:\Users\Dick\AppData\Local\Temp\DefaultPack.EXE
2016-03-23 10:25 - 2010-12-30 19:07 - 0086880 ____R (Microsoft Corporation) C:\Users\Dick\AppData\Local\Temp\devcon64.exe
2017-04-20 18:38 - 2017-03-07 20:34 - 1732864 _____ (Microsoft Corporation) C:\Users\Dick\AppData\Local\Temp\dllnt_dump.dll
2017-04-20 07:36 - 2017-04-20 07:36 - 0028672 _____ (Western Visayas College of Science and TechnologyT) C:\Users\Dick\AppData\Local\Temp\fox.exe
2017-04-20 12:19 - 2017-04-20 12:19 - 145371664 _____ (Microsoft Corporation) C:\Users\Dick\AppData\Local\Temp\imagepackage32.exe
2017-04-20 12:46 - 2017-04-20 12:47 - 169149456 _____ (Microsoft Corporation) C:\Users\Dick\AppData\Local\Temp\imagepackage64.exe
2017-04-20 07:42 - 2017-04-20 07:42 - 0016384 _____ (DoxX) C:\Users\Dick\AppData\Local\Temp\kube.exe
2017-04-20 12:18 - 2017-04-20 12:19 - 152304920 _____ (Microsoft Corporation) C:\Users\Dick\AppData\Local\Temp\mpam-fe.exe
2017-04-20 12:46 - 2017-04-20 12:46 - 152925464 _____ (Microsoft Corporation) C:\Users\Dick\AppData\Local\Temp\mpam-fex64.exe
2017-04-20 07:36 - 2017-04-20 07:38 - 2626924 _____ () C:\Users\Dick\AppData\Local\Temp\pi.exe
2017-04-21 11:01 - 2017-04-21 11:01 - 11534624 _____ (VS Revo Group                                               ) C:\Users\Dick\AppData\Local\Temp\VSUSetup.exe

==================== Known DLLs (Whitelisted) =========================

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\dnsapi.dll => MD5 is legit
C:\Windows\SysWOW64\dnsapi.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== Association (Whitelisted) =============

==================== Restore Points =========================

Restore point date: 2017-05-10 01:47

==================== Memory info ===========================

Percentage of memory in use: 10%
Total physical RAM: 8140.94 MB
Available physical RAM: 7288.13 MB
Total Virtual: 8139.09 MB
Available Virtual: 7290.53 MB

==================== Drives ================================

Drive c: (Oper System) (Fixed) (Total:265.19 GB) (Free:14.8 GB) NTFS
Drive d: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.03 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive e: (Dick) (Fixed) (Total:465.76 GB) (Free:405.08 GB) NTFS
Drive f: (Data & Dianne) (Fixed) (Total:200.37 GB) (Free:189.62 GB) NTFS
Drive g: (New Volume) (Fixed) (Total:0.1 GB) (Free:0.08 GB) NTFS
Drive j: (Repair disc Windows 7 64-bit) (CDROM) (Total:0.16 GB) (Free:0 GB) UDF
Drive l: (FRST64) (Removable) (Total:7.45 GB) (Free:7.45 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (Everything Else) (Fixed) (Total:465.76 GB) (Free:48.07 GB) NTFS ==>[system with boot components (obtained from drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 523A4088)
Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 034119E0)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=265.2 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=200.4 GB) - (Type=05)

========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: DB7F47AE)
Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS)

========================================================
Disk: 4 (MBR Code: Windows 7 or 8) (Size: 7.5 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=7.5 GB) - (Type=0B)

LastRegBack: 2017-05-02 20:31

==================== End of FRST.txt ============================

 

 

I hope this helps you.

I thank you in advance

Dickster

 

 


  • 0

Advertisements


#2
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,804 posts
Hi! My name is zep516 and Welcome to Geekstogo!
I'll do the best I can to resolve your computer issue
Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, don't continue Stop and ask! Never be afraid to ask questions! :)


Download the attached file=>Attached File  fixlist.txt   744bytes   71 downloads save it to the sane location FRST64 is==>L:\
  • Start FRST64 with Administrator privileges.
  • Press the Fix button.
  • When finished, a log file (Fixlog.txt) will pop up and saved in the same location the tool was ran from.==>L:\

    Please copy and paste its contents in your next reply.
    Boot in Normal Mode and let me know the outcome.

  • 0

#3
Rittenhouse4

Rittenhouse4

    New Member

  • Topic Starter
  • Member
  • Pip
  • 3 posts

You are the greatest. It is up and running. I have pasted the fixlog text file below. Now did the first file I pasted give you any clue as to how this happened? The only thing I had done was get a new wireless mobile mouse to replace the mouse that was part of my wireless keyboard/mouse set as the mouse had broken. Then a day or two later when I went in to use the computer this problem was there. I will say that I leave the computer on all the time. Any advice as to the cause would be appreciated.

Thanx in advance,

Dickster

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 08-05-2017
Ran by SYSTEM (13-05-2017 11:53:34) Run:1
Running from L:\
Boot Mode: Recovery
==============================================

fixlist content:
*****************
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [WindowsDefender] => -
S1 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [186304 2017-04-23] (Malwarebytes)
S3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [0 2017-05-11] () <==== ATTENTION (zero byte File/Folder)
S0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [0 2017-05-11] () <==== ATTENTION (zero byte File/Folder)
S3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [82720 2017-05-11] (Malwarebytes)
S1 arfvvobb; \??\C:\Windows\system32\drivers\arfvvobb.sys [X]
S3 MSICDSetup; \??\G:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\G:\NTIOLib_X64.sys [X]
S2 locep; C:\ProgramData\\locep\\locep.exe shuz -f "C:\ProgramData\\locep\\locep.dat" -l -a
*****************

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\WindowsDefender => value removed successfully
HKLM\System\ControlSet001\Services\MBAMChameleon => key removed successfully
MBAMChameleon => service removed successfully
HKLM\System\ControlSet001\Services\MBAMProtection => key removed successfully
MBAMProtection => service removed successfully
HKLM\System\ControlSet001\Services\MBAMSwissArmy => key removed successfully
MBAMSwissArmy => service removed successfully
HKLM\System\ControlSet001\Services\MBAMWebProtection => key removed successfully
MBAMWebProtection => service removed successfully
HKLM\System\ControlSet001\Services\arfvvobb => key removed successfully
arfvvobb => service removed successfully
HKLM\System\ControlSet001\Services\MSICDSetup => key removed successfully
MSICDSetup => service removed successfully
HKLM\System\ControlSet001\Services\NTIOLib_1_0_C => key removed successfully
NTIOLib_1_0_C => service removed successfully
HKLM\System\ControlSet001\Services\locep => key removed successfully
locep => service removed successfully

==== End of Fixlog 11:53:35 ====


  • 0

#4
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,804 posts
Hello,

I'm still investigating the exact cause as we are getting a quite a few of these, something to do with a malwarebytes driver.

Are there any further issues present with the computer ?
  • 0

#5
Rittenhouse4

Rittenhouse4

    New Member

  • Topic Starter
  • Member
  • Pip
  • 3 posts

It seems to be working just fine. I haven't tried everything yet, obviously, but nothing has failed to work yet. It even needed a MS Update which I allowed and it went through with 8 good and 1 failed. But 1 failing is nothing new. And the reboot worked just fine. Seems like you have it.

 I think I will make it through my wife's wrath now that she has her computer back. I cannot thank you enough.    :yeah:


  • 0

#6
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,804 posts
Hello,

A happy wife is a happy life :)

Thanks for donating :)
  • 0

#7
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,804 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Thanks
Joe :)
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP