Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Nero Backitup Agent - virus? Can't open my Seagate hard drive.

Nero Backitup Seagate not opening

  • Please log in to reply

#31
IndyBlue

IndyBlue

    Member

  • Topic Starter
  • Member
  • PipPip
  • 95 posts

Thanks so much! I did everything you told me to do, and the computer restarted. Here are the usual logs:

(1) FRST log:
 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 10-07-2019
Ran by indre (administrator) on DESKTOP-EL88UDV (Dell Inc. OptiPlex 7440 AIO) (13-07-2019 00:37:13)
Running from C:\Users\indre\Desktop
Loaded Profiles: indre (Available Profiles: indre)
Platform: Windows 10 Pro Version 1803 17134.885 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
() [File not signed] C:\Program Files (x86)\DELL\DELLOSD\DellOSDService.exe
() [File not signed] C:\Program Files (x86)\DELL\DELLOSD\MediaButtons.exe
() [File not signed] C:\Program Files (x86)\Intel\Intel® Security Assist\isaHelperService.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19031.11411.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(CyberLink Corp. -> CyberLink) C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvc_P2G8.exe
(CyberLink Corp. -> CyberLink) C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Dell Inc -> CREDANT Technologies, Inc.) C:\Program Files\Dell\Dell Data Protection\Client Security Framework\Dell.SecurityFramework.Agent.exe
(Dell Inc -> CREDANT Technologies, Inc.) C:\Program Files\Dell\Dell Data Protection\Client Security Framework\Dell.SecurityFramework.UserProcess.exe
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\Dell Data Protection\Client Security Framework\DCF.Loader.exe
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe
(Dell Inc -> Dell, Inc.) C:\Program Files\Dell\Dell Data Protection\Client Security Framework\Dell.SecurityFramework.LocalServer.exe
(Dell Inc. -> Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(Dell Inc. -> Dell Products, LP.) C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
(FabulaTech -> ) C:\Program Files (x86)\VMware\ScannerRedirection\ftscanmgr.exe
(FabulaTech -> ) C:\Program Files\Common Files\VMware\DeviceRedirectionCommon\ftnlsv.exe
(FabulaTech -> VMware) C:\Program Files (x86)\Common Files\VMware\SerialPortRedirection\Client\vmwsprrdpwks.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler64.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PrivacyIconClient.exe
(Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel® Intel Network Drivers -> Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Intel® Intel Network Drivers -> Intel® Corporation) C:\Program Files\Intel\NCS2\WMIProv\ncs2prov.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127171.inf_amd64_368f8c7337214025\igfxCUIService.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127171.inf_amd64_368f8c7337214025\igfxEM.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127171.inf_amd64_368f8c7337214025\IntelCpHDCPSvc.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127171.inf_amd64_368f8c7337214025\IntelCpHeciSvc.exe
(Intel® Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel® Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Intel® Wireless Display -> Intel) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksde.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksdeui.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\avp.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\avpui.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\indre\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c\SkypeApp.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(PC-Doctor, Inc. -> PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7033.2285\DSAPI.exe
(PC-Doctor, Inc. -> PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7033.2285\pcdrwi.exe
(Plex, Inc -> ) C:\Program Files (x86)\Plex\Plex Media Server\Plex Tuner Service.exe
(Plex, Inc -> Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex DLNA Server.exe
(Plex, Inc -> Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe
(Plex, Inc -> Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe
(Plex, Inc -> Python Software Foundation) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
(Plex, Inc -> Python Software Foundation) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(TEFINCOM S.A. -> ) C:\Program Files (x86)\NordVPN\nordvpn-service.exe
(TEFINCOM S.A. -> NordVPN) C:\Program Files (x86)\NordVPN\NordVPN.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\VMware\VMware Horizon View Client\bin\vmware-view-usbd.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\VMware\VMware Horizon View Client\wsnm\wsnm.exe
(Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe
(Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe
(Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD App Manager\Plugins\WD Backup\App\WDBackupService.exe
(Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD App Manager\WDAppManager.exe
(Western Digital Techologies -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8853248 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_MAXX6] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1419008 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [VMware Netlink 3 HV Install Utility] => C:\Program Files\Common Files\VMware\DeviceRedirectionCommon\ftnliu.exe [70080 2015-11-04] (FabulaTech -> )
HKLM\...\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [718256 2015-12-22] (Waves Inc -> Waves Audio Ltd.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942864 2016-10-13] (Logitech -> Logitech, Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [302904 2019-05-07] (Apple Inc. -> Apple Inc.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [322120 2019-03-15] (Intel® Rapid Storage Technology -> Intel Corporation)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PrivacyIconClient.exe [1176208 2017-11-09] (Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation)
HKLM-x32\...\Run: [WDDiscovery] => C:\Program Files (x86)\Western Digital\Discovery\Current\WD Discovery.exe [81376496 2019-07-12] (Western Digital Technologies, Inc. -> Western Digital Corporation)
HKLM-x32\...\Run: [WDAppManager] => C:\Program Files (x86)\Western Digital\WD App Manager\AppManagerLauncher.exe [21888 2019-01-02] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\Run: [Uploader] => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\Run: [GarminExpressTrayApp] => "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe"
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\Run: [Plex Media Server] => C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe [23081448 2019-04-04] (Plex, Inc -> Plex, Inc.)
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\Run: [NordVPN] => C:\Program Files (x86)\NordVPN\NordVPN.exe [2186704 2019-05-22] (TEFINCOM S.A. -> NordVPN)
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\Run: [kpm.exe] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe [584128 2019-02-08] (Kaspersky Lab -> AO Kaspersky Lab)
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1555952 2019-06-17] (Google LLC -> Google LLC)
HKU\S-1-5-18\...\Run: [GarminExpress] => C:\Program Files (x86)\Garmin\Express\express.exe [30796352 2018-10-24] (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries)
HKLM\...\Drivers32-x32: [vidc.pDAD] => prodad-codec.dll
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.100\Installer\chrmstp.exe [2019-06-20] (Google LLC -> Google LLC)
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {03DFFC2C-FC22-4010-99E9-4F38D03C4728} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [113200 2019-07-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {06D92E0E-08B8-441B-94A2-7B231EE6DCE1} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26804232 2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {08E2F16C-4C59-4C34-A03C-C83EEEDEBBDE} - System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec-Logon => C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-17] (Intel® Software Asset Manager -> Intel Corporation)
Task: {0C0614F0-18B6-495C-99F1-B61633EE7B2A} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel® Update Manager\bin\iumsvc.exe
Task: {0EBA0793-94A7-49CE-AB2C-1FEF6BA70765} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26804232 2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {0FE0644F-58F4-43E8-A63F-AA62CD169246} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {1D566C7D-1CD5-4E77-826C-E0DF557F6BFA} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_223_Plugin.exe [1457208 2019-07-10] (Adobe Inc. -> Adobe)
Task: {1E20F289-46AA-4529-B808-962BFEF268A3} - System32\Tasks\RtHDVBg_PushButton => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1419008 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {1E4AE78B-2D84-403D-9CD3-0703770FF0B5} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [113200 2019-07-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {267B2E60-3693-45B1-B32D-E5AA4FA083F4} - System32\Tasks\WD Discovery Service Task indre => C:\Program Files (x86)\Western Digital\Discovery\Current\Service\WDDiscoveryService.exe [71408 2019-07-12] (Western Digital Technologies, Inc. -> )
Task: {27CEA27E-1BF2-4A16-B5AE-DCA79020DF0D} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [816960 2017-10-11] (Intel® Trust Services -> Intel® Corporation)
Task: {2BE02930-09E5-4DB5-86B2-C883307D310D} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_223_pepper.exe [1453112 2019-07-10] (Adobe Inc. -> Adobe)
Task: {39820E81-9B7D-411F-A870-C6BEBCB2BF30} - System32\Tasks\Intel\Intel Telemetry 2 => C:\Program Files\Intel\Telemetry 2.0\lrio.exe [1698000 2015-06-05] (Intel® Software -> Intel Corporation)
Task: {4DF09A94-B680-4D73-A2BA-B28905CCA70D} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [39920 2018-10-24] (Garmin International, Inc. -> )
Task: {52187049-A19C-4B23-AFFC-5089227DB2E9} - System32\Tasks\Seagate_Install_Launch => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Dashboard.exe
Task: {5EF9065E-7942-4205-9A7E-625FDF39B32F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [136056 2019-01-02] (HP Inc. -> HP Inc.)
Task: {6D0AA64B-75B4-49CF-9C53-3BF5D9356A9D} - System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec => C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-17] (Intel® Software Asset Manager -> Intel Corporation)
Task: {82F39D33-C846-4F84-8898-8F68198ADD97} - System32\Tasks\CLVDLauncher => C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLVDLauncher.exe [340440 2015-01-28] (CyberLink Corp. -> CyberLink Corp.)
Task: {8B3F29DA-404A-4CB9-8309-9D94ECAA8D3F} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvc_P2G8.exe [110008 2016-04-27] (CyberLink Corp. -> CyberLink)
Task: {8D960D58-2C65-4690-A008-63A3B9664FD6} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [654712 2019-06-05] (HP Inc. -> HP Inc.)
Task: {A5585A2F-2224-44F3-B48A-C02AA6E9CD5D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-09-11] (Google Inc -> Google Inc.)
Task: {BE8068C1-2DB9-4BBE-9031-9E917FD77777} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1448296 2019-07-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {BEEC0D34-AA7B-4933-B79B-EE5F2DA284E3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-07-10] (Adobe Inc. -> Adobe)
Task: {C9DAB848-B95A-4118-8DAB-0AA8CAE862C4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1195544 2018-12-16] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Task: {DCF36F4E-53FF-403E-B92A-CAFE9380489C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616320 2018-01-08] (Apple Inc. -> Apple Inc.)
Task: {DD6E66AE-D0AA-4C99-8D5F-5BA39CA6FC45} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1448296 2019-07-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {ECD51CA1-564E-49C6-A83B-0A4B7EC42B15} - System32\Tasks\WD Device Agent Task indre => C:\Users\indre\AppData\Roaming\WD Discovery\plugins\com.wdc.plugin.catalog\current\library\WD Device Agent.exe [724008 2019-06-18] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
Task: {F219FE43-71D7-4843-8134-11FF7BD69ACF} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistInstaller.exe [1512920 2019-05-24] (Dell Inc. -> Dell Inc.)
Task: {F266FDCC-EAB9-4691-867D-FA95BDE06352} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [791232 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
Task: {F932D694-A1C8-4A80-9BEA-DAAFEF0B6FE1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-09-11] (Google Inc -> Google Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{6fbafdae-3f34-452d-bbc1-3182c4eed1fc}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{df5feca7-b365-4e54-a128-6afee4fc4200}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{eb569711-9ed4-49b4-a209-84f1068bb002}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell17win10.msn.com/?pc=DCTE
SearchScopes: HKU\S-1-5-21-1593158232-969496310-2340663774-1001 -> DefaultScope {97FF47F7-FF6D-4CCE-B19F-284086150FBF} URL = 
SearchScopes: HKU\S-1-5-21-1593158232-969496310-2340663774-1001 -> {97FF47F7-FF6D-4CCE-B19F-284086150FBF} URL = 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2019-06-25] (Microsoft Corporation -> Microsoft Corporation)
BHO: No Name -> {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2}' -> No File
BHO: Kaspersky Protection -> {EC1E29BB-F56A-45D8-B023-D3EF710FA0E0} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
BHO: Kaspersky Password Manager -> {F710F7E5-A520-471D-989C-F653AC328FB2} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\x64\ie_engine.dll [2019-05-08] (Kaspersky Lab -> AO Kaspersky Lab)
BHO-x32: No Name -> {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2}' -> No File
BHO-x32: CutePDF Form Filler Helper -> {D41289F2-69C6-417B-897E-C653D677CBAF} -> C:\Program Files (x86)\Acro Software\CutePDF Filler Evaluation\CPFillerCoE.dll [2014-03-27] (Acro Software Inc. -> Acro Software Inc.)
BHO-x32: Kaspersky Protection -> {EC1E29BB-F56A-45D8-B023-D3EF710FA0E0} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
BHO-x32: Kaspersky Password Manager -> {F710F7E5-A520-471D-989C-F653AC328FB2} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\ie_engine.dll [2019-05-08] (Kaspersky Lab -> AO Kaspersky Lab)
Toolbar: HKLM - Kaspersky Protection Toolbar - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
Toolbar: HKLM-x32 - Kaspersky Protection Toolbar - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
Toolbar: HKU\S-1-5-21-1593158232-969496310-2340663774-1001 -> Kaspersky Protection Toolbar - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} hxxps://meetny.webex.com/client/WBXclient-T30L10NSP6EP6-20000/webex/ieatgpc1.cab
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-06-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-06-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-06-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-06-02] (Microsoft Corporation -> Microsoft Corporation)
 
FireFox:
========
FF DefaultProfile: 1cu7vqt4.default-1534000050440
FF ProfilePath: C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440 [2019-07-11]
FF Homepage: Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440 -> hxxps://www.google.com/
FF Extension: (ETP Search Volume Study) - C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440\Extensions\[email protected] [2019-06-26]
FF Extension: (Notifier for Gmail™) - C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440\Extensions\[email protected] [2019-03-31]
FF Extension: (Honey) - C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440\Extensions\[email protected] [2019-05-18]
FF Extension: (Kaspersky Password Manager) - C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440\Extensions\[email protected] [2019-05-08] [UpdateUrl:hxxps://special.s.kaspersky-labs.com/firefox_extensions/kpm_win_add_on/update.json]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Extension: (Kaspersky Protection) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\FFExt\light_plugin_firefox\addon.xpi [2019-07-06]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_223.dll [2019-07-10] (Adobe Inc. -> )
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_223.dll [2019-07-10] (Adobe Inc. -> )
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2019-04-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-14] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-14] (Google Inc -> Google LLC)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-05-02] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1593158232-969496310-2340663774-1001: @zoom.us/ZoomVideoPlugin -> C:\Users\indre\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2018-04-06] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\kl_prefs_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.js [2019-07-07] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\kl_config_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.cfg [2019-07-07] <==== ATTENTION
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default [2019-07-13]
CHR Extension: (Slides) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-12]
CHR Extension: (Kaspersky Protection) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\amkpcclbbgegoafihnpgomddadjhcadd [2019-07-06]
CHR Extension: (Docs) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12]
CHR Extension: (Google Drive) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-09-11]
CHR Extension: (YouTube) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-09-11]
CHR Extension: (Honey) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2019-07-11]
CHR Extension: (Notifier for Gmail™) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcjichoefijpinlfnjghokpkojhlhkgl [2019-03-25]
CHR Extension: (Kaspersky Password Manager) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhnkblpjbkfklfloegejegedcafpliaa [2019-07-12]
CHR Extension: (Adobe Acrobat) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2019-06-11]
CHR Extension: (Sheets) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-12]
CHR Extension: (Google Docs Offline) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-22]
CHR Extension: (Avast Online Security) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2019-07-01]
CHR Extension: (F.B.(FluffBusting)Purity) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmkinhboiljjkhaknpaeaicmdjhagpep [2019-07-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-07]
CHR Extension: (Gmail) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-03-26]
CHR Extension: (Chrome Media Router) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-06-20]
CHR Profile: C:\Users\indre\AppData\Local\Google\Chrome\User Data\Guest Profile [2019-07-08]
CHR Profile: C:\Users\indre\AppData\Local\Google\Chrome\User Data\System Profile [2019-07-08]
CHR HKLM\...\Chrome\Extension: [amkpcclbbgegoafihnpgomddadjhcadd] - hxxps://chrome.google.com/webstore/detail/amkpcclbbgegoafihnpgomddadjhcadd
CHR HKU\S-1-5-21-1593158232-969496310-2340663774-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhnkblpjbkfklfloegejegedcafpliaa] - hxxps://chrome.google.com/webstore/detail/dhnkblpjbkfklfloegejegedcafpliaa
CHR HKLM-x32\...\Chrome\Extension: [amkpcclbbgegoafihnpgomddadjhcadd] - hxxps://chrome.google.com/webstore/detail/amkpcclbbgegoafihnpgomddadjhcadd
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [96056 2019-04-29] (Apple Inc. -> Apple Inc.)
R2 AVP19.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\avp.exe [619640 2018-02-28] (Kaspersky Lab -> AO Kaspersky Lab)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11413600 2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
S4 dcu-oobe; C:\Program Files (x86)\Dell\CommandUpdate\OobeService.exe [84408 2016-06-07] (Dell Inc. -> Dell Inc.)
R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [209392 2019-02-28] (Dell Inc -> Dell Inc.)
R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3363824 2019-02-28] (Dell Inc -> Dell Inc.)
R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [218096 2019-02-28] (Dell Inc -> Dell Inc.)
R2 Dell Hardware Support; C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7033.2285\DSAPI.exe [1050952 2019-06-02] (PC-Doctor, Inc. -> PC-Doctor, Inc.)
R2 Dell WMI Service; C:\Program Files (x86)\DELL\DELLOSD\DellOSDService.exe [151552 2015-06-29] () [File not signed]
R2 DellMgmtAgent; C:\Program Files\Dell\Dell Data Protection\Client Security Framework\Dell.SecurityFramework.Agent.exe [22280 2016-07-13] (Dell Inc -> CREDANT Technologies, Inc.)
R2 DellMgmtLoader; C:\Program Files\Dell\Dell Data Protection\Client Security Framework\DCF.Loader.exe [35080 2016-07-13] (Dell Inc -> Dell Inc.)
R3 DellMgmtServer; C:\Program Files\Dell\Dell Data Protection\Client Security Framework\Dell.SecurityFramework.LocalServer.exe [52488 2016-07-13] (Dell Inc -> Dell, Inc.)
R2 ftnlsv3hv; C:\Program Files\Common Files\VMware\DeviceRedirectionCommon\ftnlsv.exe [233920 2015-11-04] (FabulaTech -> )
R2 ftscanmgr; C:\Program Files (x86)\VMware\ScannerRedirection\ftscanmgr.exe [6363792 2015-07-31] (FabulaTech -> )
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [356728 2019-06-12] (HP Inc. -> HP Inc.)
S3 iaStorAfsService; C:\WINDOWS\IAStorAfsService\iaStorAfsService.exe [2413752 2017-08-18] (Intel® Rapid Storage Technology -> Intel Corporation)
R2 ibtsiva; C:\WINDOWS\system32\ibtsiva.exe [190208 2016-10-15] (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation)
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [742704 2017-10-11] (Intel® Trust Services -> Intel® Corporation)
S3 Intel® Security Assist; C:\Program Files (x86)\Intel\Intel® Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed]
S2 Intel® TPM Provisioning Service; C:\Program Files\Intel\iCLS Client\TPMProvisioningService.exe [668472 2017-10-11] (Intel® Trust Services -> Intel® Corporation)
S3 Intel® WiDi SAM; C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-17] (Intel® Software Asset Manager -> Intel Corporation)
R2 IntelUSBoverIP; C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe [396992 2015-07-06] (Intel® Wireless Display -> Intel)
R2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel® Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [213648 2017-11-09] (Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation)
S3 klvssbridge64_19.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\vssbridge64.exe [414352 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R2 kpm_launch_service; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe [354008 2019-02-08] (Kaspersky Lab -> AO Kaspersky Lab)
R2 KSDE3.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksde.exe [617016 2018-02-28] (Kaspersky Lab -> AO Kaspersky Lab)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [310880 2019-01-23] (Intel Corporation -> )
R2 nordvpn-service; C:\Program Files (x86)\NordVPN\nordvpn-service.exe [217040 2019-05-22] (TEFINCOM S.A. -> )
R2 PlexUpdateService; C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe [1140200 2019-04-04] (Plex, Inc -> Plex, Inc.)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [253776 2015-09-02] (CyberLink Corp. -> CyberLink)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [310016 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5073792 2019-07-04] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [39896 2019-05-24] (Dell Inc. -> Dell Inc.)
S2 tcsd_win32.exe; C:\Program Files\Dell\Dell Data Protection\Drivers\TSS\bin\tcsd_win32.exe [1636352 2012-12-10] (Security Innovation, Inc.) [File not signed]
R2 vmware-view-usbd; C:\Program Files (x86)\VMware\VMware Horizon View Client\bin\vmware-view-usbd.exe [1158984 2016-02-23] (VMware, Inc. -> VMware, Inc.)
R2 vmwsprrdpwks; C:\Program Files (x86)\Common Files\VMware\SerialPortRedirection\Client\vmwsprrdpwks.exe [261776 2015-05-08] (FabulaTech -> VMware)
R2 WavesSysSvc; C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe [613296 2015-12-22] (Waves Inc -> Waves Audio Ltd.)
S3 WD Backup Drive Helper; C:\WINDOWS\SysWOW64\dllhost.exe /Processid:{4AB831D3-8315-414C-8A7A-303105288D0B} [19360 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
S3 WD Backup Drive Helper; C:\WINDOWS\SysWOW64\dllhost.exe /Processid:{4AB831D3-8315-414C-8A7A-303105288D0B} [19360 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
S3 WD Backup Snapshot; C:\WINDOWS\SysWOW64\dllhost.exe /Processid:{302480DF-3AC5-4400-BE7B-DD77AF93B6DD} [19360 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
S3 WD Backup Snapshot; C:\WINDOWS\SysWOW64\dllhost.exe /Processid:{302480DF-3AC5-4400-BE7B-DD77AF93B6DD} [19360 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [524632 2018-03-26] (Western Digital Techologies -> Western Digital Technologies, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [4413440 2019-03-14] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [107160 2019-02-16] (Microsoft Corporation -> Microsoft Corporation)
R2 wsnm; C:\Program Files (x86)\VMware\VMware Horizon View Client\wsnm\wsnm.exe [541400 2016-03-25] (VMware, Inc. -> VMware, Inc.)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [4107360 2019-01-23] (Intel Corporation -> Intel® Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R0 cm_km; C:\WINDOWS\System32\DRIVERS\cm_km.sys [243400 2018-01-27] (Kaspersky Lab -> AO Kaspersky Lab)
R3 DDDriver; C:\WINDOWS\system32\drivers\DDDriver64Dcsa.sys [40824 2019-02-27] (Microsoft Windows Hardware Compatibility Publisher -> Dell Inc.)
S3 DellProf; C:\WINDOWS\system32\drivers\DellProf.sys [41208 2018-05-08] (Techporch Incorporated -> Dell Computer Corporation)
S3 iaStorAfs; C:\WINDOWS\System32\drivers\iaStorAfs.sys [70664 2017-08-18] (Intel® Rapid Storage Technology -> Intel Corporation)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [732416 2016-10-15] (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation)
R3 IntcAzAudAddService; C:\WINDOWS\system32\drivers\RTDVHD64.sys [2677504 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.)
R0 klbackupdisk; C:\WINDOWS\System32\DRIVERS\klbackupdisk.sys [75600 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klbackupflt; C:\WINDOWS\System32\DRIVERS\klbackupflt.sys [125568 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [91472 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
S0 klelam; C:\WINDOWS\System32\DRIVERS\klelam.sys [29208 2017-03-30] (Microsoft Windows Early Launch Anti-malware Publisher -> AO Kaspersky Lab)
R3 klflt; C:\WINDOWS\system32\DRIVERS\klflt.sys [236672 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 KLHK; C:\WINDOWS\System32\drivers\klhk.sys [1093248 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klids; C:\ProgramData\Kaspersky Lab\AVP19.0.0\Bases\klids.sys [197464 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [1168000 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klim6; C:\WINDOWS\system32\DRIVERS\klim6.sys [58704 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klkbdflt; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [60536 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klmouflt; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [60784 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klpd; C:\WINDOWS\System32\DRIVERS\klpd.sys [50304 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
S3 klpnpflt; C:\WINDOWS\system32\DRIVERS\klpnpflt.sys [46416 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 kltap; C:\WINDOWS\System32\drivers\kltap.sys [48080 2018-02-12] (AnchorFree Inc -> The OpenVPN Project)
R0 klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [245272 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klupd_klif_kimul; C:\WINDOWS\System32\Drivers\klupd_klif_kimul.sys [99152 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [302368 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R0 klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [116104 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [198768 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [104576 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klwtp; C:\WINDOWS\system32\DRIVERS\klwtp.sys [184960 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [218240 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
S3 Netwtw04; C:\WINDOWS\System32\drivers\Netwtw04.sys [7689728 2018-04-11] (Microsoft Windows -> Intel Corporation)
R3 Netwtw06; C:\WINDOWS\system32\DRIVERS\Netwtw06.sys [8833952 2019-01-28] (Intel® Wireless Connectivity Solutions -> Intel Corporation)
R3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [779232 2016-08-04] (Realtek Semiconductor Corp. -> Realsil Semiconductor Corporation)
R0 SEDFilter; C:\WINDOWS\System32\DRIVERS\SEDFilter.sys [197808 2016-07-13] (Dell Inc -> Dell Inc.)
S3 SWDUMon; C:\WINDOWS\system32\DRIVERS\SWDUMon.sys [13920 2016-09-11] (SlimWare Utilities Inc. -> )
R3 tapnordvpn; C:\WINDOWS\System32\drivers\tapnordvpn.sys [44896 2018-07-24] (TEFINCOM S.A. -> The OpenVPN Project)
R3 usb3Hub; C:\WINDOWS\System32\drivers\usb3Hub.sys [212056 2015-07-06] (Intel® Wireless Display -> Windows ® Win 7 DDK provider)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44616 2018-04-11] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [331680 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
R1 wdfsconnect2017; C:\WINDOWS\system32\drivers\wdfsconnect2017.sys [468112 2017-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies, Inc.)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [44032 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
R3 wdvpnpbus; C:\WINDOWS\System32\drivers\wdvpnpbus.sys [20624 2017-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies, Inc.)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-07-13 00:29 - 2019-07-13 00:29 - 000000000 ___HD C:\OneDriveTemp
2019-07-13 00:25 - 2019-07-13 00:25 - 014543816 ____C (Intel Corporation) C:\Users\indre\Desktop\SetupRST.exe
2019-07-13 00:25 - 2019-07-13 00:25 - 014543816 _____ (Intel Corporation) C:\Users\indre\Downloads\SetupRST (2).exe
2019-07-13 00:21 - 2019-07-13 00:21 - 014543816 _____ (Intel Corporation) C:\Users\indre\Downloads\SetupRST (1).exe
2019-07-12 21:35 - 2019-07-12 21:35 - 000000000 ____D C:\Users\indre\Intel
2019-07-12 21:31 - 2019-07-12 21:31 - 021816776 _____ (Intel Corporation) C:\Users\indre\Downloads\SetupRST.exe
2019-07-12 19:03 - 2019-07-12 19:03 - 000042006 ____C C:\Users\indre\Desktop\Addition 3.txt
2019-07-12 19:00 - 2019-07-12 19:00 - 000117354 ____C C:\Users\indre\Desktop\FRST 3.txt
2019-07-12 18:50 - 2019-07-12 18:50 - 000004156 ____C C:\Users\indre\Desktop\Fixlog.txt
2019-07-12 18:49 - 2019-07-12 18:49 - 000062468 _____ C:\ProgramData\agent.uninstall.1562971733.bdinstall.v2.bin
2019-07-12 18:49 - 2019-07-12 18:49 - 000002522 _____ C:\Users\indre\Downloads\fixlist.txt
2019-07-12 13:55 - 2019-07-12 13:56 - 000169646 ____C C:\Users\indre\Desktop\DESKTOP-EL88UDV 2.txt
2019-07-12 13:50 - 2019-07-12 13:50 - 000117516 ____C C:\Users\indre\Desktop\FRST 2.txt
2019-07-12 13:50 - 2019-07-12 13:50 - 000043949 ____C C:\Users\indre\Desktop\Addition 2.txt
2019-07-12 13:32 - 2019-07-13 00:35 - 000042975 ____C C:\Users\indre\Desktop\Addition.txt
2019-07-12 13:29 - 2019-07-12 13:28 - 002095104 ____C (Farbar) C:\Users\indre\Desktop\FRST64.exe
2019-07-12 13:28 - 2019-07-12 13:28 - 002095104 _____ (Farbar) C:\Users\indre\Downloads\FRST64 (3).exe
2019-07-12 13:27 - 2019-07-12 13:27 - 002095104 _____ (Farbar) C:\Users\indre\Downloads\FRST64 (2).exe
2019-07-12 12:53 - 2019-07-12 12:53 - 000003240 _____ C:\WINDOWS\System32\Tasks\WD Device Agent Task indre
2019-07-12 12:51 - 2019-07-12 12:53 - 000003236 _____ C:\WINDOWS\System32\Tasks\WD Discovery Service Task indre
2019-07-12 12:51 - 2019-07-12 12:51 - 000001301 _____ C:\Users\Public\Desktop\WD Discovery.lnk
2019-07-12 12:51 - 2019-07-12 12:51 - 000000000 ___DC C:\Users\indre\AppData\Roaming\WDDesktop
2019-07-12 12:50 - 2019-07-13 00:29 - 000000000 ___DC C:\Users\indre\AppData\Roaming\WD Discovery
2019-07-12 12:50 - 2019-07-12 18:52 - 000000000 ____D C:\Users\indre\.wdc
2019-07-12 12:50 - 2019-07-12 12:54 - 000000000 ____D C:\Program Files\WD Desktop App
2019-07-12 12:50 - 2017-11-21 12:03 - 000468112 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\Drivers\wdfsconnect2017.sys
2019-07-12 12:50 - 2017-11-21 12:03 - 000020624 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\Drivers\wdvpnpbus.sys
2019-07-12 12:50 - 2017-11-10 12:51 - 000223744 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\SysWOW64\wdfsconnectNetRdr2017.dll
2019-07-12 12:50 - 2017-11-10 12:51 - 000180224 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll
2019-07-12 12:50 - 2017-11-10 12:51 - 000154112 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\SysWOW64\wdfsconnectMntNtf2017.dll
2019-07-12 12:50 - 2017-11-10 12:51 - 000118272 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\wdfsconnectNetRdr2017.dll
2019-07-12 12:50 - 2017-11-10 12:51 - 000002560 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\wdfsconnectevtmsg.dll
2019-07-12 12:16 - 2019-07-12 12:16 - 000001192 _____ C:\Users\Public\Desktop\WD Drive Utilities.lnk
2019-07-12 12:14 - 2019-07-12 13:23 - 000002228 _____ C:\Users\Public\Desktop\WD Backup.lnk
2019-07-12 12:14 - 2019-07-12 13:23 - 000000000 ____D C:\Program Files (x86)\Western Digital
2019-07-12 12:14 - 2019-07-12 12:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WD Discovery
2019-07-12 12:14 - 2019-07-12 12:14 - 000000000 ___DC C:\Users\indre\AppData\Roaming\Western Digital
2019-07-12 12:14 - 2019-07-12 12:14 - 000000000 ____D C:\ProgramData\Western Digital
2019-07-12 11:29 - 2019-07-12 11:29 - 005278464 _____ (Paramount Software UK Ltd) C:\Users\indre\Downloads\ReflectDLHF (1).exe
2019-07-12 11:25 - 2019-07-12 11:31 - 000000000 ____D C:\ProgramData\Macrium
2019-07-12 11:25 - 2019-07-12 11:25 - 000000000 ____D C:\Users\indre\Downloads\Macrium
2019-07-12 11:24 - 2019-07-12 11:25 - 005278464 _____ (Paramount Software UK Ltd) C:\Users\indre\Downloads\ReflectDLHF.exe
2019-07-11 12:12 - 2019-07-11 12:12 - 000000000 ___DC C:\Users\indre\Documents\Kaspersky Password Manager
2019-07-10 22:50 - 2019-07-10 22:50 - 000000000 ___DC C:\Users\indre\AppData\Local\Garmin
2019-07-10 07:50 - 2019-07-04 05:40 - 021390504 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2019-07-10 07:50 - 2019-07-04 05:40 - 001616840 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2019-07-10 07:50 - 2019-07-04 05:21 - 008627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2019-07-10 07:50 - 2019-07-04 05:18 - 003614208 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2019-07-10 07:50 - 2019-07-04 04:51 - 020384128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2019-07-10 07:50 - 2019-07-04 04:37 - 002882048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2019-07-10 07:50 - 2019-07-04 01:00 - 001035040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2019-07-10 07:50 - 2019-07-04 00:58 - 001219896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2019-07-10 07:50 - 2019-07-04 00:57 - 003292152 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2019-07-10 07:50 - 2019-07-04 00:57 - 001027384 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2019-07-10 07:50 - 2019-07-04 00:56 - 009084216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2019-07-10 07:50 - 2019-07-04 00:56 - 007519896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2019-07-10 07:50 - 2019-07-04 00:56 - 007436536 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2019-07-10 07:50 - 2019-07-04 00:56 - 002810680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2019-07-10 07:50 - 2019-07-04 00:56 - 002571640 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2019-07-10 07:50 - 2019-07-04 00:42 - 006570368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-07-10 07:50 - 2019-07-04 00:42 - 006044008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2019-07-10 07:50 - 2019-07-04 00:42 - 002479176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2019-07-10 07:50 - 2019-07-04 00:42 - 001980984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2019-07-10 07:50 - 2019-07-04 00:37 - 025857536 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2019-07-10 07:50 - 2019-07-04 00:33 - 022017536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2019-07-10 07:50 - 2019-07-04 00:29 - 022717440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2019-07-10 07:50 - 2019-07-04 00:26 - 004385280 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2019-07-10 07:50 - 2019-07-04 00:25 - 019372544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2019-07-10 07:50 - 2019-07-04 00:25 - 007589888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2019-07-10 07:50 - 2019-07-04 00:25 - 004861440 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2019-07-10 07:50 - 2019-07-04 00:25 - 003401216 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2019-07-10 07:50 - 2019-07-04 00:23 - 001765888 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2019-07-10 07:50 - 2019-07-04 00:22 - 003707904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2019-07-10 07:50 - 2019-07-04 00:21 - 005784064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2019-07-10 07:50 - 2019-07-04 00:21 - 003202560 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2019-07-10 07:50 - 2019-07-04 00:21 - 002166784 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2019-07-10 07:50 - 2019-07-04 00:20 - 001156608 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2019-07-10 07:50 - 2019-06-13 08:12 - 002871848 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2019-07-10 07:50 - 2019-06-13 08:05 - 000810296 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2019-07-10 07:50 - 2019-06-13 08:04 - 001721144 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2019-07-10 07:50 - 2019-06-13 08:00 - 000464696 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2019-07-10 07:50 - 2019-06-13 07:59 - 000740664 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2019-07-10 07:50 - 2019-06-13 07:58 - 000637752 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2019-07-10 07:50 - 2019-06-13 07:58 - 000071480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2019-07-10 07:50 - 2019-06-13 07:56 - 000164152 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2019-07-10 07:50 - 2019-06-13 07:43 - 001427984 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystemController.dll
2019-07-10 07:50 - 2019-06-13 07:42 - 004038688 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2019-07-10 07:50 - 2019-06-13 07:42 - 002266936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll
2019-07-10 07:50 - 2019-06-13 07:18 - 006586880 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2019-07-10 07:50 - 2019-06-13 07:18 - 004847104 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2019-07-10 07:50 - 2019-06-13 07:17 - 012756992 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2019-07-10 07:50 - 2019-06-13 07:16 - 000767488 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcommdlg.dll
2019-07-10 07:50 - 2019-06-13 07:15 - 004718080 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2019-07-10 07:50 - 2019-06-13 07:14 - 000900096 _____ (Microsoft Corporation) C:\WINDOWS\system32\slui.exe
2019-07-10 07:50 - 2019-06-13 07:13 - 002920448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2019-07-10 07:50 - 2019-06-13 07:13 - 000951808 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2019-07-10 07:50 - 2019-06-13 06:11 - 001539896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll
2019-07-10 07:50 - 2019-06-13 06:05 - 003700160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2019-07-10 07:50 - 2019-06-13 05:55 - 005657088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2019-07-10 07:50 - 2019-06-13 05:54 - 011942912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2019-07-10 07:50 - 2019-06-13 05:50 - 000896512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll
2019-07-10 07:50 - 2019-06-13 03:01 - 000513336 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2019-07-10 07:50 - 2019-06-13 03:01 - 000511288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2019-07-10 07:50 - 2019-06-13 02:47 - 005625160 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2019-07-10 07:50 - 2019-06-13 02:45 - 002421560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2019-07-10 07:50 - 2019-06-13 02:44 - 002769688 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2019-07-10 07:50 - 2019-06-13 02:44 - 000607112 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2019-07-10 07:50 - 2019-06-13 02:14 - 003318784 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2019-07-10 07:50 - 2019-06-13 02:13 - 004771840 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2019-07-10 07:50 - 2019-06-13 02:13 - 002370048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2019-07-10 07:50 - 2019-06-13 02:10 - 002912256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2019-07-10 07:50 - 2019-06-13 02:10 - 001400832 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2019-07-10 07:50 - 2019-06-13 02:10 - 001215488 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2019-07-10 07:50 - 2019-06-13 02:09 - 001854976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2019-07-10 07:50 - 2019-06-13 01:14 - 000415544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2019-07-10 07:50 - 2019-06-13 01:06 - 002256768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2019-07-10 07:50 - 2019-06-13 00:47 - 002899456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2019-07-10 07:49 - 2019-07-04 05:45 - 001786680 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntVirtualization.dll
2019-07-10 07:49 - 2019-07-04 05:43 - 000094008 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2019-07-10 07:49 - 2019-07-04 05:41 - 000304144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mssecflt.sys
2019-07-10 07:49 - 2019-07-04 05:40 - 001631808 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2019-07-10 07:49 - 2019-07-04 05:40 - 000790416 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2019-07-10 07:49 - 2019-07-04 05:22 - 000131072 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2019-07-10 07:49 - 2019-07-04 05:22 - 000128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2019-07-10 07:49 - 2019-07-04 05:20 - 001609216 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2019-07-10 07:49 - 2019-07-04 05:19 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2019-07-10 07:49 - 2019-07-04 05:18 - 001663488 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2019-07-10 07:49 - 2019-07-04 04:56 - 001453416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2019-07-10 07:49 - 2019-07-04 04:54 - 000662352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2019-07-10 07:49 - 2019-07-04 04:41 - 007990784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2019-07-10 07:49 - 2019-07-04 04:36 - 001471488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2019-07-10 07:49 - 2019-07-04 00:58 - 001328440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2019-07-10 07:49 - 2019-07-04 00:58 - 000416312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2019-07-10 07:49 - 2019-07-04 00:58 - 000192824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2019-07-10 07:49 - 2019-07-04 00:57 - 000986128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2019-07-10 07:49 - 2019-07-04 00:57 - 000776784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2019-07-10 07:49 - 2019-07-04 00:57 - 000723728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2019-07-10 07:49 - 2019-07-04 00:57 - 000708696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2019-07-10 07:49 - 2019-07-04 00:57 - 000568104 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2019-07-10 07:49 - 2019-07-04 00:57 - 000362264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2019-07-10 07:49 - 2019-07-04 00:57 - 000209424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2019-07-10 07:49 - 2019-07-04 00:57 - 000194360 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2019-07-10 07:49 - 2019-07-04 00:57 - 000137656 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll
2019-07-10 07:49 - 2019-07-04 00:57 - 000134968 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2019-07-10 07:49 - 2019-07-04 00:57 - 000091776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpfve.sys
2019-07-10 07:49 - 2019-07-04 00:56 - 001566520 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2019-07-10 07:49 - 2019-07-04 00:56 - 001459120 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2019-07-10 07:49 - 2019-07-04 00:56 - 001260776 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2019-07-10 07:49 - 2019-07-04 00:56 - 001141496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2019-07-10 07:49 - 2019-07-04 00:56 - 000983936 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2019-07-10 07:49 - 2019-07-04 00:56 - 000767536 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2019-07-10 07:49 - 2019-07-04 00:56 - 000734952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2019-07-10 07:49 - 2019-07-04 00:56 - 000713272 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2019-07-10 07:49 - 2019-07-04 00:56 - 000604984 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2019-07-10 07:49 - 2019-07-04 00:56 - 000493752 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2019-07-10 07:49 - 2019-07-04 00:56 - 000115512 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdnet.dll
2019-07-10 07:49 - 2019-07-04 00:43 - 000832016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2019-07-10 07:49 - 2019-07-04 00:43 - 000665440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2019-07-10 07:49 - 2019-07-04 00:43 - 000328696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2019-07-10 07:49 - 2019-07-04 00:43 - 000287376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2019-07-10 07:49 - 2019-07-04 00:43 - 000191800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2019-07-10 07:49 - 2019-07-04 00:42 - 001427768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2019-07-10 07:49 - 2019-07-04 00:42 - 000573808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2019-07-10 07:49 - 2019-07-04 00:42 - 000356312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2019-07-10 07:49 - 2019-07-04 00:42 - 000097272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll
2019-07-10 07:49 - 2019-07-04 00:41 - 000559328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2019-07-10 07:49 - 2019-07-04 00:26 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2019-07-10 07:49 - 2019-07-04 00:26 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2019-07-10 07:49 - 2019-07-04 00:25 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll
2019-07-10 07:49 - 2019-07-04 00:25 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2019-07-10 07:49 - 2019-07-04 00:24 - 000726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\PEAuth.sys
2019-07-10 07:49 - 2019-07-04 00:24 - 000567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2019-07-10 07:49 - 2019-07-04 00:24 - 000462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2019-07-10 07:49 - 2019-07-04 00:24 - 000153600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2019-07-10 07:49 - 2019-07-04 00:23 - 001217536 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2019-07-10 07:49 - 2019-07-04 00:23 - 000786432 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2019-07-10 07:49 - 2019-07-04 00:22 - 002587648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2019-07-10 07:49 - 2019-07-04 00:22 - 002176000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2019-07-10 07:49 - 2019-07-04 00:22 - 001561088 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2019-07-10 07:49 - 2019-07-04 00:22 - 001549824 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2019-07-10 07:49 - 2019-07-04 00:22 - 001175552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2019-07-10 07:49 - 2019-07-04 00:22 - 000300544 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2019-07-10 07:49 - 2019-07-04 00:22 - 000110592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll
2019-07-10 07:49 - 2019-07-04 00:22 - 000032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2019-07-10 07:49 - 2019-07-04 00:21 - 005307392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2019-07-10 07:49 - 2019-07-04 00:21 - 001920000 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2019-07-10 07:49 - 2019-07-04 00:21 - 001220608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2019-07-10 07:49 - 2019-07-04 00:21 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2019-07-10 07:49 - 2019-07-04 00:21 - 000124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll
2019-07-10 07:49 - 2019-07-04 00:21 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2019-07-10 07:49 - 2019-07-04 00:20 - 000544256 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2019-07-10 07:49 - 2019-07-04 00:20 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2019-07-10 07:49 - 2019-07-04 00:20 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2019-07-10 07:49 - 2019-07-04 00:19 - 000886272 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2019-07-10 07:49 - 2019-07-04 00:19 - 000230912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2019-07-10 07:49 - 2019-07-04 00:18 - 002602496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2019-07-10 07:49 - 2019-07-04 00:18 - 001076224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
2019-07-10 07:49 - 2019-07-04 00:18 - 000965632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2019-07-10 07:49 - 2019-07-04 00:18 - 000953344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2019-07-10 07:49 - 2019-07-04 00:18 - 000275968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2019-07-10 07:49 - 2019-07-04 00:17 - 000531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2019-07-10 07:49 - 2019-07-03 23:01 - 000001312 _____ C:\WINDOWS\system32\tcbres.wim
2019-07-10 07:49 - 2019-06-21 04:50 - 000280584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys
2019-07-10 07:49 - 2019-06-13 08:15 - 000324408 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2019-07-10 07:49 - 2019-06-13 07:43 - 001048480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2019-07-10 07:49 - 2019-06-13 07:42 - 000652088 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPublishing.dll
2019-07-10 07:49 - 2019-06-13 07:42 - 000566536 _____ (Microsoft Corporation) C:\WINDOWS\system32\phoneactivate.exe
2019-07-10 07:49 - 2019-06-13 07:41 - 001626936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVIntegration.dll
2019-07-10 07:49 - 2019-06-13 07:41 - 000830264 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVOrchestration.dll
2019-07-10 07:49 - 2019-06-13 07:41 - 000825144 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntStreamingManager.dll
2019-07-10 07:49 - 2019-06-13 07:41 - 000670008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVCatalog.dll
2019-07-10 07:49 - 2019-06-13 07:40 - 000749880 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVReporting.dll
2019-07-10 07:49 - 2019-06-13 07:40 - 000540984 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2019-07-10 07:49 - 2019-06-13 07:40 - 000495416 _____ (Microsoft Corporation) C:\WINDOWS\system32\TransportDSA.dll
2019-07-10 07:49 - 2019-06-13 07:38 - 000766264 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingWinRT.dll
2019-07-10 07:49 - 2019-06-13 07:37 - 000101192 _____ (Microsoft Corporation) C:\WINDOWS\system32\changepk.exe
2019-07-10 07:49 - 2019-06-13 07:36 - 000251000 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2019-07-10 07:49 - 2019-06-13 07:36 - 000236520 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2019-07-10 07:49 - 2019-06-13 07:35 - 001376688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2019-07-10 07:49 - 2019-06-13 07:34 - 000146888 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingUI.exe
2019-07-10 07:49 - 2019-06-13 07:17 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmvdsitf.dll
2019-07-10 07:49 - 2019-06-13 07:17 - 000115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\RjvMDMConfig.dll
2019-07-10 07:49 - 2019-06-13 07:17 - 000109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe
2019-07-10 07:49 - 2019-06-13 07:17 - 000093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe
2019-07-10 07:49 - 2019-06-13 07:15 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpgradeResultsUI.exe
2019-07-10 07:49 - 2019-06-13 07:14 - 001127936 _____ (Microsoft Corporation) C:\WINDOWS\system32\nettrace.dll
2019-07-10 07:49 - 2019-06-13 07:14 - 000346624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2019-07-10 07:49 - 2019-06-13 07:14 - 000246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\DesktopSwitcherDataModel.dll
2019-07-10 07:49 - 2019-06-13 07:13 - 001339392 _____ (Microsoft Corporation) C:\WINDOWS\system32\TaskFlowDataEngine.dll
2019-07-10 07:49 - 2019-06-13 07:13 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2019-07-10 07:49 - 2019-06-13 07:13 - 000181248 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll
2019-07-10 07:49 - 2019-06-13 07:12 - 000394240 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll
2019-07-10 07:49 - 2019-06-13 07:10 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\vdsbas.dll
2019-07-10 07:49 - 2019-06-13 06:07 - 001027008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2019-07-10 07:49 - 2019-06-13 06:07 - 000660496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicensingWinRT.dll
2019-07-10 07:49 - 2019-06-13 06:07 - 000221232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditionUpgradeManagerObj.dll
2019-07-10 07:49 - 2019-06-13 05:54 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmvdsitf.dll
2019-07-10 07:49 - 2019-06-13 05:53 - 000089600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2019-07-10 07:49 - 2019-06-13 05:51 - 000622080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2019-07-10 07:49 - 2019-06-13 05:49 - 002406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2019-07-10 07:49 - 2019-06-13 05:49 - 000371200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll
2019-07-10 07:49 - 2019-06-13 03:48 - 000677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\HeadTrackerStorage.dll
2019-07-10 07:49 - 2019-06-13 03:46 - 000713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedRealitySvc.dll
2019-07-10 07:49 - 2019-06-13 03:01 - 000036152 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2019-07-10 07:49 - 2019-06-13 02:59 - 000785264 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll
2019-07-10 07:49 - 2019-06-13 02:47 - 001063224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2019-07-10 07:49 - 2019-06-13 02:46 - 001076536 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2019-07-10 07:49 - 2019-06-13 02:46 - 000510296 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2019-07-10 07:49 - 2019-06-13 02:46 - 000093984 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2019-07-10 07:49 - 2019-06-13 02:44 - 002546704 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2019-07-10 07:49 - 2019-06-13 02:44 - 001098272 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2019-07-10 07:49 - 2019-06-13 02:44 - 001033696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2019-07-10 07:49 - 2019-06-13 02:44 - 000545808 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2019-07-10 07:49 - 2019-06-13 02:44 - 000130624 _____ (Microsoft Corporation) C:\WINDOWS\system32\rmclient.dll
2019-07-10 07:49 - 2019-06-13 02:17 - 000106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2019-07-10 07:49 - 2019-06-13 02:16 - 001626112 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2019-07-10 07:49 - 2019-06-13 02:16 - 000140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2019-07-10 07:49 - 2019-06-13 02:15 - 000514560 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2019-07-10 07:49 - 2019-06-13 02:15 - 000433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2019-07-10 07:49 - 2019-06-13 02:15 - 000204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2019-07-10 07:49 - 2019-06-13 02:15 - 000137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2019-07-10 07:49 - 2019-06-13 02:15 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\KdsCli.dll
2019-07-10 07:49 - 2019-06-13 02:14 - 000409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2019-07-10 07:49 - 2019-06-13 02:14 - 000361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2019-07-10 07:49 - 2019-06-13 02:14 - 000302080 _____ (Microsoft Corporation) C:\WINDOWS\system32\CXHProvisioningServer.dll
2019-07-10 07:49 - 2019-06-13 02:13 - 000761344 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2019-07-10 07:49 - 2019-06-13 02:13 - 000322560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2019-07-10 07:49 - 2019-06-13 02:13 - 000110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll
2019-07-10 07:49 - 2019-06-13 02:12 - 000916480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2019-07-10 07:49 - 2019-06-13 02:12 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2019-07-10 07:49 - 2019-06-13 02:12 - 000808448 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2019-07-10 07:49 - 2019-06-13 02:12 - 000624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2019-07-10 07:49 - 2019-06-13 02:12 - 000532992 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuietHours.dll
2019-07-10 07:49 - 2019-06-13 02:12 - 000501248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2019-07-10 07:49 - 2019-06-13 02:11 - 000508416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2019-07-10 07:49 - 2019-06-13 02:11 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll
2019-07-10 07:49 - 2019-06-13 02:11 - 000048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerUI.dll
2019-07-10 07:49 - 2019-06-13 02:10 - 000871424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll
2019-07-10 07:49 - 2019-06-13 02:10 - 000869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
2019-07-10 07:49 - 2019-06-13 02:10 - 000849408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll
2019-07-10 07:49 - 2019-06-13 02:10 - 000523776 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2019-07-10 07:49 - 2019-06-13 02:09 - 000922112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2019-07-10 07:49 - 2019-06-13 02:09 - 000755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2019-07-10 07:49 - 2019-06-13 02:08 - 000506368 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2019-07-10 07:49 - 2019-06-13 01:08 - 000443632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2019-07-10 07:49 - 2019-06-13 01:07 - 000101192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rmclient.dll
2019-07-10 07:49 - 2019-06-13 01:07 - 000080744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll
2019-07-10 07:49 - 2019-06-13 01:06 - 001130776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2019-07-10 07:49 - 2019-06-13 01:06 - 000581600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVideoDSP.dll
2019-07-10 07:49 - 2019-06-13 00:49 - 000172544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enrollmentapi.dll
2019-07-10 07:49 - 2019-06-13 00:47 - 003554304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2019-07-10 07:49 - 2019-06-13 00:47 - 000450048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2019-07-10 07:49 - 2019-06-13 00:46 - 000608768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2019-07-10 07:49 - 2019-06-13 00:46 - 000331776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2019-07-10 07:49 - 2019-06-13 00:46 - 000038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerUI.dll
2019-07-10 07:49 - 2019-06-13 00:45 - 000602112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
2019-07-10 07:49 - 2019-06-13 00:45 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2019-07-10 07:49 - 2019-06-13 00:44 - 001003008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2019-07-10 07:49 - 2019-06-13 00:44 - 000648192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll
2019-07-10 07:49 - 2019-06-13 00:44 - 000630784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.MediaPlayer.dll
2019-07-10 07:49 - 2019-06-13 00:44 - 000582144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2019-07-10 07:49 - 2019-06-13 00:44 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2019-07-10 07:49 - 2019-06-13 00:43 - 000681472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2019-07-10 07:49 - 2019-06-13 00:43 - 000646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll
2019-07-10 07:49 - 2019-06-13 00:43 - 000445952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2019-07-09 13:11 - 2019-07-09 13:11 - 004730179 _____ C:\Users\indre\Downloads\Master Folder For Cleared Checks INDY (2).xlsx
2019-07-09 13:09 - 2019-07-09 13:09 - 008141856 _____ C:\Users\indre\Downloads\MASTER ALL CHECKS (4).xlsx
2019-07-08 13:49 - 2019-07-08 13:49 - 000000000 ___DC C:\Users\indre\Documents\ED stuff
2019-07-08 11:03 - 2019-07-08 11:04 - 000188559 ____C C:\Users\indre\Desktop\DESKTOP-EL88UDV.txt
2019-07-08 11:01 - 2019-07-08 11:01 - 000000839 _____ C:\Users\Public\Desktop\Speccy.lnk
2019-07-08 11:01 - 2019-07-08 11:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2019-07-08 11:01 - 2019-07-08 11:01 - 000000000 ____D C:\Program Files\Speccy
2019-07-08 10:59 - 2019-07-08 10:59 - 006889184 _____ (Piriform Ltd) C:\Users\indre\Downloads\spsetup132.exe
2019-07-08 10:59 - 2019-07-08 10:59 - 001309592 _____ (BraveSoftware Inc.) C:\Users\indre\Downloads\BraveBrowserSetup-TPF550.exe
2019-07-08 10:58 - 2019-07-08 10:58 - 000019118 ____C C:\Users\indre\Desktop\Tasklist 070819.txt
2019-07-08 10:56 - 2019-07-08 10:56 - 000019118 _____ C:\junk.txt
2019-07-08 10:54 - 2019-07-08 10:54 - 000026673 ____C C:\Users\indre\Desktop\Registry 070819.txt
2019-07-08 10:50 - 2019-07-08 10:50 - 002826520 _____ (Sysinternals - www.sysinternals.com) C:\Users\indre\Downloads\procexp (1).exe
2019-07-08 10:50 - 2019-07-08 10:50 - 000043192 _____ (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP152.SYS
2019-07-08 10:49 - 2019-07-08 10:49 - 002826520 _____ (Sysinternals - www.sysinternals.com) C:\Users\indre\Downloads\procexp.exe
2019-07-08 10:47 - 2019-07-08 10:47 - 000023010 ____C C:\Users\indre\Desktop\VEW Application 070819.txt
2019-07-08 10:44 - 2019-07-08 10:44 - 000007664 ____C C:\Users\indre\Desktop\VEW Events 070819.txt
2019-07-08 10:43 - 2019-07-08 10:46 - 000023010 _____ C:\VEW.txt
2019-07-08 10:40 - 2019-07-08 10:40 - 000061440 _____ ( ) C:\Users\indre\Downloads\VEW.exe
2019-07-06 13:06 - 2019-07-06 13:06 - 000302368 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klark.sys
2019-07-06 13:04 - 2019-07-06 13:04 - 000001371 _____ C:\Users\Public\Desktop\Kaspersky Password Manager.lnk
2019-07-06 13:04 - 2019-07-06 13:04 - 000000000 ___DC C:\Users\indre\AppData\Local\Kaspersky Lab
2019-07-06 13:04 - 2019-07-06 13:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Password Manager
2019-07-06 13:00 - 2019-07-06 13:00 - 000245272 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_arkmon.sys
2019-07-06 13:00 - 2019-07-06 13:00 - 000198768 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_mark.sys
2019-07-06 13:00 - 2019-07-06 13:00 - 000116104 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klbg.sys
2019-07-06 13:00 - 2019-07-06 13:00 - 000099152 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_kimul.sys
2019-07-06 13:00 - 2019-07-06 13:00 - 000003392 _____ C:\WINDOWS\System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901}
2019-07-06 13:00 - 2019-07-06 13:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Secure Connection
2019-07-06 12:59 - 2019-07-13 00:29 - 000000000 ____D C:\ProgramData\Kaspersky Lab
2019-07-06 12:59 - 2019-07-06 13:17 - 000236672 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klflt.sys
2019-07-06 12:59 - 2019-07-06 13:16 - 001168000 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klif.sys
2019-07-06 12:59 - 2019-07-06 13:16 - 001093248 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klhk.sys
2019-07-06 12:59 - 2019-07-06 13:16 - 000152288 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\klhkum.dll
2019-07-06 12:59 - 2019-07-06 13:04 - 000000000 ____D C:\Program Files (x86)\Kaspersky Lab
2019-07-06 12:59 - 2019-07-06 12:59 - 000002210 _____ C:\Users\Public\Desktop\Safe Money.lnk
2019-07-06 12:59 - 2019-07-06 12:59 - 000002182 _____ C:\Users\Public\Desktop\Kaspersky Total Security.lnk
2019-07-06 12:59 - 2019-07-06 12:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Total Security
2019-07-06 12:59 - 2013-05-06 08:13 - 000110176 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\klfphc.dll
2019-07-06 12:57 - 2019-07-06 12:56 - 000592616 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2019-07-06 12:54 - 2019-07-06 12:55 - 000000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2019-07-06 12:54 - 2019-07-06 12:54 - 002660224 _____ (Kaspersky Lab) C:\Users\indre\Downloads\startup_14445.exe
2019-07-06 10:01 - 2019-07-06 10:01 - 002420224 _____ (Farbar) C:\Users\indre\Downloads\FRST64 (1).exe
2019-07-06 10:00 - 2019-07-13 00:37 - 000047310 ____C C:\Users\indre\Desktop\FRST.txt
2019-07-06 09:58 - 2019-07-06 10:00 - 000039445 _____ C:\Users\indre\Downloads\Addition.txt
2019-07-06 09:55 - 2019-07-06 09:59 - 000079818 _____ C:\Users\indre\Downloads\FRST.txt
2019-07-06 09:54 - 2019-07-13 00:37 - 000000000 ____D C:\FRST
2019-07-06 09:53 - 2019-07-06 09:53 - 002420224 _____ (Farbar) C:\Users\indre\Downloads\FRST64.exe
2019-07-01 19:18 - 2019-07-01 19:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2019-06-29 23:56 - 2019-06-29 23:56 - 011069444 _____ C:\Users\indre\Downloads\thecourtshipofeddiesfather-1st (1).mpg
2019-06-29 23:55 - 2019-06-29 23:55 - 011069444 _____ C:\Users\indre\Downloads\thecourtshipofeddiesfather-1st.mpg
2019-06-29 11:29 - 2019-06-29 11:29 - 000074636 _____ C:\ProgramData\agent.update.1561822169.bdinstall.v2.bin
2019-06-27 20:31 - 2019-06-27 20:31 - 022709477 _____ C:\Users\indre\Downloads\20190627_202829_19399014677980 (1).mp4
2019-06-27 20:30 - 2019-06-27 20:30 - 022709477 _____ C:\Users\indre\Downloads\20190627_202829_19399014677980.mp4
2019-06-27 19:53 - 2019-06-27 19:53 - 000000054 ____C C:\Users\indre\Desktop\cryptic stacey 062719.txt
2019-06-24 00:13 - 2019-07-07 22:03 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2019-06-23 23:58 - 2019-06-23 23:58 - 000068279 _____ C:\Users\indre\Downloads\Iulo_Susan_References_2019.pdf
2019-06-23 14:04 - 2019-06-23 14:04 - 000128245 _____ C:\Users\indre\Downloads\Iulo_Susan_-_Resume_2019.pdf
2019-06-21 20:51 - 2019-06-21 20:51 - 000128344 _____ C:\Users\indre\Downloads\Iulo_Susan_-_resume_June_2019_FIRST DRAFT (2).pdf
2019-06-21 20:28 - 2019-06-21 20:28 - 000128344 _____ C:\Users\indre\Downloads\Iulo_Susan_-_resume_June_2019_FIRST DRAFT (1).pdf
2019-06-21 20:25 - 2019-06-21 20:25 - 000128344 _____ C:\Users\indre\Downloads\Iulo_Susan_-_resume_June_2019_FIRST DRAFT.pdf
2019-06-20 12:13 - 2019-06-20 12:13 - 000004919 _____ C:\Users\indre\Downloads\imp8A93.pdf
2019-06-20 12:13 - 2019-06-20 12:13 - 000004919 _____ C:\Users\indre\Downloads\imp8A93 (1).pdf
2019-06-18 21:05 - 2019-06-18 21:05 - 000039557 _____ C:\Users\indre\Downloads\Letters_2019_06_14_12_42_30_156.pdf
2019-06-18 02:30 - 2019-06-18 02:30 - 000363078 _____ C:\Users\indre\Downloads\Preprinted UPS label for Treasury to Farmingdale 010918.pdf
2019-06-17 14:37 - 2019-06-17 14:37 - 000350164 _____ C:\Users\indre\Downloads\Statement_062019_8810.pdf
2019-06-13 20:33 - 2019-06-13 20:33 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless
2019-06-13 20:32 - 2019-06-13 20:32 - 000000000 ____D C:\Program Files\Common Files\Intel
2019-06-13 18:57 - 2019-06-13 18:57 - 000042697 _____ C:\Users\indre\Downloads\Vet papers on baby panthers.pdf
2019-06-13 18:56 - 2019-06-13 18:56 - 000115738 _____ C:\Users\indre\Downloads\Indre adoption contract.pdf
 
==================== One month (modified) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-07-13 00:37 - 2018-04-11 19:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-07-13 00:31 - 2018-05-23 14:43 - 000840376 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-07-13 00:31 - 2018-04-11 19:36 - 000000000 ____D C:\WINDOWS\INF
2019-07-13 00:29 - 2016-09-11 19:32 - 000000000 ___RD C:\Users\indre\OneDrive
2019-07-13 00:29 - 2016-09-11 19:30 - 000000000 __SHD C:\Users\indre\IntelGraphicsProfiles
2019-07-13 00:27 - 2018-05-23 14:44 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-07-13 00:27 - 2018-04-11 17:04 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2019-07-13 00:24 - 2017-05-21 14:10 - 000000000 ____D C:\Program Files\Intel
2019-07-13 00:24 - 2016-08-09 19:33 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2019-07-13 00:17 - 2018-05-23 14:37 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-07-12 21:38 - 2018-05-23 14:44 - 000004166 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{71AF15CB-04B4-4B18-8047-5E35B9C7421E}
2019-07-12 21:35 - 2018-05-23 14:38 - 000000000 ____D C:\Users\indre
2019-07-12 21:35 - 2017-05-21 14:10 - 000000000 ____D C:\Program Files (x86)\Intel
2019-07-12 19:21 - 2016-09-17 01:09 - 000000000 ___DC C:\Users\indre\Documents\Letters
2019-07-12 19:00 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\Registration
2019-07-12 18:51 - 2018-06-09 20:55 - 000409520 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-07-12 18:43 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-07-12 13:38 - 2018-04-11 19:38 - 000000000 ___HD C:\Program Files\WindowsApps
2019-07-12 13:23 - 2016-08-09 19:33 - 000000000 ____D C:\ProgramData\Package Cache
2019-07-12 12:10 - 2016-10-12 00:52 - 000000000 ___DC C:\Users\indre\AppData\Roaming\Seagate
2019-07-12 11:43 - 2018-04-11 19:38 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2019-07-12 11:43 - 2016-09-16 22:45 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-07-11 11:11 - 2017-11-15 23:45 - 000000000 ___RD C:\Users\indre\3D Objects
2019-07-11 11:11 - 2016-08-09 19:48 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-07-11 04:09 - 2018-04-12 05:20 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2019-07-11 04:09 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\TextInput
2019-07-11 04:09 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2019-07-11 04:09 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2019-07-11 04:09 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\oobe
2019-07-11 04:09 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\appraiser
2019-07-11 04:09 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\ShellComponents
2019-07-11 04:09 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\Provisioning
2019-07-11 04:09 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\bcastdvr
2019-07-11 04:09 - 2018-04-11 17:04 - 000000000 ____D C:\WINDOWS\system32\Dism
2019-07-11 04:01 - 2016-11-18 22:39 - 000000000 ___DC C:\Users\indre\AppData\LocalLow\Mozilla
2019-07-10 08:13 - 2018-04-11 19:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-07-10 07:49 - 2016-09-12 20:21 - 000000000 ____D C:\WINDOWS\system32\MRT
2019-07-10 07:36 - 2016-09-12 20:20 - 136618864 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2019-07-10 02:37 - 2018-05-23 14:44 - 000004600 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2019-07-10 02:37 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2019-07-10 02:37 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\Macromed
2019-07-10 01:37 - 2018-05-23 14:44 - 000004588 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier
2019-07-10 01:37 - 2018-05-23 14:44 - 000004386 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2019-07-09 13:12 - 2017-11-15 23:37 - 000000000 ___DC C:\Users\indre\AppData\Local\Packages
2019-07-08 14:37 - 2016-09-18 09:35 - 000000000 ___DC C:\Users\indre\AppData\Local\CrashDumps
2019-07-08 13:50 - 2016-09-17 01:49 - 000000000 ___DC C:\Users\indre\Documents\Funny stuff
2019-07-08 13:43 - 2018-12-02 19:00 - 000000000 ___DC C:\Users\indre\Documents\Editing for Josh
2019-07-06 13:17 - 2019-02-13 14:10 - 000184960 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klwtp.sys
2019-07-06 13:17 - 2019-02-13 14:10 - 000125568 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klbackupflt.sys
2019-07-06 13:17 - 2019-02-13 14:10 - 000091472 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\kldisk.sys
2019-07-06 13:17 - 2018-02-24 05:17 - 000218240 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\kneps.sys
2019-07-06 13:17 - 2018-02-17 02:50 - 000104576 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klwfp.sys
2019-07-06 13:17 - 2018-01-15 05:13 - 000060536 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klkbdflt.sys
2019-07-06 13:16 - 2019-02-13 14:10 - 000075600 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klbackupdisk.sys
2019-07-06 13:16 - 2019-02-13 14:10 - 000046416 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klpnpflt.sys
2019-07-06 13:16 - 2018-02-12 04:17 - 000058704 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klim6.sys
2019-07-06 13:16 - 2017-12-11 11:49 - 000060784 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klmouflt.sys
2019-07-06 13:16 - 2017-05-30 18:51 - 000050304 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klpd.sys
2019-07-06 13:00 - 2017-02-04 10:05 - 000000000 ____D C:\Program Files\Common Files\AV
2019-07-06 12:59 - 2018-04-11 17:04 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2019-07-06 01:15 - 2018-06-20 22:44 - 000002365 ____C C:\Users\indre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-07-06 01:15 - 2018-05-23 14:44 - 000003378 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1593158232-969496310-2340663774-1001
2019-07-04 12:01 - 2018-05-23 14:44 - 000003482 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2019-07-04 12:01 - 2018-05-23 14:44 - 000003346 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2019-07-04 12:01 - 2018-05-23 14:44 - 000003298 _____ C:\WINDOWS\System32\Tasks\Dell SupportAssistAgent AutoUpdate
2019-07-04 12:01 - 2018-05-23 14:44 - 000003122 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2019-07-04 12:01 - 2018-05-23 14:44 - 000003118 _____ C:\WINDOWS\System32\Tasks\Intel PTT EK Recertification
2019-07-04 12:01 - 2018-05-23 14:44 - 000003042 _____ C:\WINDOWS\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473
2019-07-04 12:01 - 2018-05-23 14:44 - 000003040 _____ C:\WINDOWS\System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec
2019-07-04 12:01 - 2018-05-23 14:44 - 000002806 _____ C:\WINDOWS\System32\Tasks\Seagate_Install_Launch
2019-07-04 12:01 - 2018-05-23 14:44 - 000002702 _____ C:\WINDOWS\System32\Tasks\GarminUpdaterTask
2019-07-04 12:01 - 2018-05-23 14:44 - 000002674 _____ C:\WINDOWS\System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec-Logon
2019-07-04 12:01 - 2018-05-23 14:44 - 000002528 _____ C:\WINDOWS\System32\Tasks\CLVDLauncher
2019-07-04 12:01 - 2018-05-23 14:44 - 000002528 _____ C:\WINDOWS\System32\Tasks\CLMLSvc_P2G8
2019-07-04 12:01 - 2018-05-23 14:44 - 000002304 _____ C:\WINDOWS\System32\Tasks\RtHDVBg_PushButton
2019-07-01 19:18 - 2019-05-14 13:15 - 000002495 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2019-07-01 19:18 - 2019-05-14 13:15 - 000002494 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2019-07-01 19:18 - 2019-05-14 13:15 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2019-07-01 19:18 - 2019-05-14 13:15 - 000002451 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2019-07-01 19:18 - 2019-05-14 13:15 - 000002437 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2019-07-01 19:18 - 2016-08-09 19:40 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2019-06-29 23:58 - 2017-10-14 21:56 - 000000000 ___DC C:\Users\indre\AppData\Roaming\vlc
2019-06-29 23:56 - 2017-10-14 21:56 - 000001141 _____ C:\Users\Public\Desktop\VLC media player.lnk
2019-06-28 08:30 - 2016-09-16 13:57 - 000000000 ___DC C:\Users\indre\AppData\Roaming\VMware
2019-06-27 18:32 - 2016-09-11 19:59 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2019-06-27 00:47 - 2017-07-15 20:02 - 000014706 ____C C:\Users\indre\Documents\Indy's Finances.xlsx
2019-06-26 22:10 - 2016-09-11 19:59 - 000001007 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2019-06-21 21:34 - 2016-09-17 01:09 - 000000000 ___DC C:\Users\indre\Documents\Resumes etc
2019-06-21 16:50 - 2016-09-17 01:09 - 000000000 ___DC C:\Users\indre\Documents\Recipes
2019-06-20 20:08 - 2016-09-11 19:57 - 000002303 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-06-20 20:08 - 2016-09-11 19:57 - 000002262 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2019-06-20 20:03 - 2018-11-16 12:19 - 000000000 ____D C:\Program Files\rempl
2019-06-20 08:58 - 2017-05-09 21:49 - 000000000 ____D C:\Program Files\UNP
2019-06-18 05:52 - 2016-09-17 01:38 - 000000000 ___DC C:\Users\indre\Documents\Akiko stuff
2019-06-13 20:33 - 2016-08-09 19:33 - 000000000 ____D C:\ProgramData\Intel
2019-06-13 20:33 - 2015-10-30 02:28 - 000000000 ____D C:\Users\Default.migrated
2019-06-13 20:31 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\Drivers\DriverData
2019-06-13 18:45 - 2016-09-16 22:23 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2019-06-13 18:22 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\ShellExperiences
2019-06-13 18:22 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
 
==================== Files in the root of some directories ================
 
2018-11-19 21:23 - 2018-11-19 21:23 - 000000017 ____C () C:\Users\indre\AppData\Local\resmon.resmoncfg
 
==================== SigCheck ===============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ============================
 
(2) Addition log:
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-07-2019
Ran by indre (13-07-2019 00:38:14)
Running from C:\Users\indre\Desktop
Windows 10 Pro Version 1803 17134.885 (X64) (2018-05-23 18:44:41)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1593158232-969496310-2340663774-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1593158232-969496310-2340663774-503 - Limited - Disabled)
Guest (S-1-5-21-1593158232-969496310-2340663774-501 - Limited - Disabled)
indre (S-1-5-21-1593158232-969496310-2340663774-1001 - Administrator - Enabled) => C:\Users\indre
WDAGUtilityAccount (S-1-5-21-1593158232-969496310-2340663774-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Kaspersky Total Security (Enabled - Up to date) {0AB30972-4BAC-7BEE-CBCA-B8F9E68797D8}
AS: Kaspersky Total Security (Enabled - Up to date) {B1D2E896-6D96-7460-F17A-838B9D00DD65}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Total Security (Enabled) {32888857-01C3-7AB6-E095-11CC1854D0A3}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Across Lite (HKLM-x32\...\{5F5C7350-9731-420F-97CC-8CAFEE7DA7A3}) (Version: 2.4.2451.1 - Literate Software)
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 19.012.20035 - Adobe Systems Incorporated)
Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.223 - Adobe)
Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.223 - Adobe)
Angry Birds (HKLM-x32\...\{2F7D5734-056F-4A0A-A1C7-CA1AAE5BB1EB}) (Version: 1.6.3.1 - Rovio)
ANT Drivers Installer x64 (HKLM\...\{D559687A-60C5-4786-9429-C21EC195789D}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Application Support (32-bit) (HKLM-x32\...\{C1BCFECF-6EC2-4750-9072-5E2489423F8F}) (Version: 7.5 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{B202C7F5-7DE3-4FBF-B259-E70E625F56FC}) (Version: 7.5 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B5A46811-3612-4DA5-8A5A-E6DED5D7C523}) (Version: 12.2.1.12 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{A30EA700-5515-48F0-88B0-9E99DC356B88}) (Version: 2.6.0.1 - Apple Inc.)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Cisco WebEx Meetings (HKLM-x32\...\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
CmgMasterPrerequisites (HKLM\...\{EE34FA4E-715A-46FA-9CAF-06E26AE4217D}) (Version: 1.10.0.34 - Dell, Inc.) Hidden
CutePDF Form Filler 3.6 (Evaluation) (HKLM-x32\...\CutePDF Form Filler (Evaluation)_is1) (Version:  - Acro Software Inc.)
CyberLink Media Suite Essentials (HKLM-x32\...\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 12 - CyberLink Corp.)
Dell Command | Update (HKLM-x32\...\{EC542D5D-B608-4145-A8F7-749C02BE6D94}) (Version: 2.2.0 - Dell Inc.)
Dell Data Protection | Client Security Framework (HKLM\...\{FAE38E46-ECB2-44EA-A52B-6955AA6B1B3A}) (Version: 8.10.0.39 - Dell, Inc.)
Dell Data Protection | Security Tools (HKLM-x32\...\{812AA6D3-5BEB-4577-88B1-00998B91AB41}) (Version: 1.10.0.34 - Dell, Inc.) Hidden
Dell Data Protection | Security Tools (HKLM-x32\...\InstallShield_{812AA6D3-5BEB-4577-88B1-00998B91AB41}) (Version: 1.10.0.34 - Dell, Inc.)
Dell Digital Delivery (HKLM-x32\...\{AB7F2792-2ED1-4C5C-9F28-680E5110BF72}) (Version: 3.1.1018.0 - Dell Products, LP)
Dell SupportAssist (HKLM\...\{806422F1-FC4E-4D7C-8855-05748AEFC031}) (Version: 3.2.2.119 - Dell Inc.)
DELLOSD (HKLM-x32\...\{BED3193A-897B-47F6-AEDC-45D147122957}) (Version: 1.0.0.0 - DELL)
Elevated Installer (HKLM-x32\...\{0BF90608-2F95-4C7C-9A85-E90E0CAF4FE9}) (Version: 6.9.1.0 - Garmin Ltd or its subsidiaries) Hidden
FileZilla Client 3.25.1 (HKLM-x32\...\FileZilla Client) (Version: 3.25.1 - Tim Kosse)
Garmin Express (HKLM-x32\...\{95D0EADA-5123-41C0-931A-F37946BC0E8E}) (Version: 6.9.1.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express (HKLM-x32\...\{eab4691c-4022-41cd-8d39-c3097ba62d4b}) (Version: 6.9.1.0 - Garmin Ltd or its subsidiaries)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 75.0.3770.100 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.11 - Google LLC) Hidden
HP Support Solutions Framework (HKLM-x32\...\{2B5A1E68-6617-406D-B797-5DAB5B4630B8}) (Version: 12.11.24.11 - HP Inc.)
Intel® Chipset Device Software (HKLM-x32\...\{fb610cea-ba50-4d4b-a717-cf025419035c}) (Version: 10.1.1.13 - Intel® Corporation) Hidden
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1054 - Intel Corporation)
Intel® Network Connections 20.3.300.1 (HKLM\...\PROSetDX) (Version: 20.3.300.1 - Intel)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 23.20.16.4973 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.8.16.1063 - Intel Corporation)
Intel® Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.47.866.0 - Intel Corporation) Hidden
Intel® Trusted Connect Services Client (HKLM-x32\...\{246c6cc0-9810-4728-9a29-28474de2eec5}) (Version: 1.47.866.0 - Intel Corporation) Hidden
Intel® WiDi (HKLM\...\{C7CD6D54-26AF-4D93-B06F-D81ACE8624CB}) (Version: 6.0.40.0 - Intel Corporation)
Intel® WiDi Software Asset Manager (HKLM-x32\...\{5B5CD20C-29F0-4857-A4FA-A4F4C716B019}) (Version: 1.1.347 - Intel Corporation) Hidden
Intel® Wireless Bluetooth® (HKLM-x32\...\{5068B0F8-CE24-4B61-9C2F-301B411FFB9C}) (Version: 18.1.1611.3223 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{f430aa46-62c4-47a0-8a03-42e7fff664b7}) (Version: 20.120.0 - Intel Corporation)
Intel® Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation)
iTunes (HKLM\...\{A8AF3EF8-5010-4A92-BCCA-90F62A7D62B8}) (Version: 12.9.5.7 - Apple Inc.)
Kaspersky Password Manager (HKLM-x32\...\{B2F7333E-6C8D-4994-AAC4-FEC8EBBF9611}) (Version: 9.0.2.767 - Kaspersky Lab) Hidden
Kaspersky Password Manager (HKLM-x32\...\InstallWIX_{B2F7333E-6C8D-4994-AAC4-FEC8EBBF9611}) (Version: 9.0.2.767 - Kaspersky Lab)
Kaspersky Secure Connection (HKLM-x32\...\{F10AA188-7166-430E-8810-FEAB2AD73DE3}) (Version: 19.0.0.1088 - Kaspersky Lab) Hidden
Kaspersky Secure Connection (HKLM-x32\...\InstallWIX_{F10AA188-7166-430E-8810-FEAB2AD73DE3}) (Version: 19.0.0.1088 - Kaspersky Lab)
Kaspersky Total Security (HKLM-x32\...\{718613F4-492D-4272-ACC3-D04A8EF0F883}) (Version: 19.0.0.1088 - Kaspersky Lab) Hidden
Kaspersky Total Security (HKLM-x32\...\InstallWIX_{718613F4-492D-4272-ACC3-D04A8EF0F883}) (Version: 19.0.0.1088 - Kaspersky Lab)
LaserJet 1020 series (HKLM-x32\...\HP-LaserJet 1020 series) (Version:  - )
Maxx Audio Installer (x64) (HKLM\...\{307032B2-6AF2-46D7-B933-62438DEB2B9A}) (Version: 2.6.8006.3 - Waves Audio Ltd.) Hidden
Microsoft Office Famille et Petite Entreprise 2016 - fr-fr (HKLM\...\HomeBusinessRetail - fr-fr) (Version: 16.0.11727.20230 - Microsoft Corporation)
Microsoft Office Hogar y Empresas 2016 - es-es (HKLM\...\HomeBusinessRetail - es-es) (Version: 16.0.11727.20230 - Microsoft Corporation)
Microsoft Office Home and Business 2016 - en-us (HKLM\...\HomeBusinessRetail - en-us) (Version: 16.0.11727.20230 - Microsoft Corporation)
Microsoft OneDrive (HKU\.DEFAULT\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\OneDriveSetup.exe) (Version: 19.103.0527.0003 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (HKLM-x32\...\{6e8f74e0-43bd-4dce-8477-6ff6828acc07}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 (HKLM-x32\...\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24210 (HKLM-x32\...\{23658c02-145e-483d-ba6b-1eb82c580529}) (Version: 14.0.24210.0 - Microsoft Corporation)
Mozilla Firefox 67.0.4 (x64 en-US) (HKLM\...\Mozilla Firefox 67.0.4 (x64 en-US)) (Version: 67.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 66.0.3 - Mozilla)
NewBlue Video Essentials for Windows (HKLM-x32\...\NewBlue Video Essentials for Windows) (Version: 3.0 - NewBlue)
NordVPN (HKLM-x32\...\{F4325B30-A8A0-4D09-B0DE-7CBB485A52D8}) (Version: 6.22.6 - NordVPN) Hidden
NordVPN (HKLM-x32\...\NordVPN 6.22.6) (Version: 6.22.6 - NordVPN)
NordVPN network TAP (HKLM-x32\...\{97DEC5D6-2BE9-45BB-BFC5-274B851B486B}) (Version: 1.0.1 - NordVPN)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.11727.20230 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.11727.20230 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.11727.20230 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.11727.20230 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-040C-0000-0000000FF1CE}) (Version: 16.0.11727.20230 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0C0A-0000-0000000FF1CE}) (Version: 16.0.11727.20230 - Microsoft Corporation) Hidden
Plex Media Server (HKLM-x32\...\{72238E55-A877-4785-A5E9-0C35EAFB0746}) (Version: 1.15.876 - Plex, Inc.) Hidden
Plex Media Server (HKLM-x32\...\{9203fc01-57c0-4cc8-858d-92911b5142de}) (Version: 1.15.3.876 - Plex, Inc.)
Pretty Good Solitaire version 12.4.0 (HKLM-x32\...\Pretty Good Solitaire_is1) (Version: 12.4.0 - Goodsol Development Inc.)
proDAD Adorage 3.0 (HKLM-x32\...\proDAD-Adorage-3.0) (Version: 3.0.114.1 - proDAD GmbH)
Realtek Audio COM Components (HKLM-x32\...\{2355B503-9B11-4449-861D-1C1748B26320}) (Version: 1.0.2 - Realtek Semiconductor Corp.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.14393.21292 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6105 - Realtek Semiconductor Corp.)
Security Innovation TSS (HKLM\...\{0C11FE22-53F2-4C9B-9E79-824B10D0976E}) (Version: 2.1.42 - Security Innovation) Hidden
Speccy (HKLM\...\Speccy) (Version: 1.32 - Piriform)
Spotify (HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\Spotify) (Version: 1.0.96.181.gf6bc1b6b - Spotify AB)
Stopping Plex (HKLM-x32\...\{3C6D43CB-1211-4C3F-8F3C-2B4F90C5BB95}) (Version: 1.15.876 - Plex, Inc.) Hidden
TextPad 8 (HKLM\...\{861AB1C1-1967-4C4A-BF86-C255E2D2B8FD}) (Version: 8.0.2 - Helios)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{F14FB68A-9188-4036-AD0D-D054BC9C9291}) (Version: 2.59.0.0 - Microsoft Corporation)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.7.1 - VideoLAN)
VMware Horizon Client (HKLM\...\{93CEC220-0D24-41C0-8647-BA1C62A3EE89}) (Version: 4.0.1.781 - VMware, Inc.)
Vulkan Run Time Libraries 1.0.33.0 (HKLM\...\VulkanRT1.0.33.0) (Version: 1.0.33.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.33.0 (HKLM\...\VulkanRT1.0.33.0-2) (Version: 1.0.33.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1) (Version: 1.0.54.1 - Intel Corporation Inc.)
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-2) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
WD Backup (HKLM-x32\...\{50C6CAE8-562E-440D-8616-E0514D41CC10}) (Version: 1.9.6941.25593 - Western Digital Technologies, Inc) Hidden
WD Backup (HKLM-x32\...\{6531bf4b-4bad-46a5-9562-766d0a858003}) (Version: 1.9.6941.25593 - Western Digital Technologies, Inc.)
WD Desktop App 2.1.0.245 (HKLM-x32\...\{d303f1fe-6729-4693-b2e1-51d13b450de5}) (Version: 2.1.0.245 - Western Digital Corporation) Hidden
WD Desktop App 2.1.0.245 (x64) (HKLM\...\{CA7F7232-526E-41BD-971A-47BE28C18516}) (Version: 2.1.0.245 - Western Digital Corporation) Hidden
WD Discovery (HKLM-x32\...\WDDiscovery) (Version: 3.3.34 - Western Digital Technologies, Inc.)
WD Drive Utilities (HKLM-x32\...\{5ea95ccc-fc68-4182-88a9-e563ba3900ed}) (Version: 2.0.0.26 - Western Digital Technologies, Inc.)
WD Drive Utilities (HKLM-x32\...\{893C7059-0464-47FB-85A4-5E1ADDA56141}) (Version: 2.0.0.26 - Western Digital Technologies, Inc.) Hidden
WD SES Driver Setup (HKLM-x32\...\{924A274D-38B6-4930-8859-F3F51CFA8DDD}) (Version: 1.1.0.25 - Western Digital) Hidden
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Intel Corporation (iaStorA) HDC  (08/10/2017 15.7.5.1025) (HKLM\...\FF1B55CEF8D39B696D1F5DF141ACFA7A5D1F2743) (Version: 08/10/2017 15.7.5.1025 - Intel Corporation)
Windows Driver Package - Intel Corporation (iaStorA) SCSIAdapter  (08/10/2017 15.7.5.1025) (HKLM\...\6D773A6E21B2A480569157737F58E8FF7DC6608A) (Version: 08/10/2017 15.7.5.1025 - Intel Corporation)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Zoom (HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\ZoomUMX) (Version: 4.1 - Zoom Video Communications, Inc.)
 
Packages:
=========
CyberLink Media Suite Essentials -> C:\Program Files\WindowsApps\DB6EA5DB.CyberLinkMediaSuiteEssentials_1.0.10.0_x86__mcezb6ze687jp [2018-03-13] (CYBERLINK CORPORATION.)
Dell SupportAssist for PCs -> C:\Program Files\WindowsApps\DellInc.DellSupportAssistforPCs_3.2.5.0_x64__htrsf667h5kn2 [2019-05-29] (Dell Inc)
Mail and Calendar -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe [2019-07-10] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1808.3.0_x64__8wekyb3d8bbwe [2018-09-22] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-12] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-12] (Microsoft Corporation) [MS Ad]
Microsoft Jigsaw -> C:\Program Files\WindowsApps\Microsoft.MicrosoftJigsaw_1.8.1812.301_x86__8wekyb3d8bbwe [2019-03-14] (Microsoft Studios) [MS Ad]
Microsoft Mahjong -> C:\Program Files\WindowsApps\Microsoft.MicrosoftMahjong_3.9.4100.0_x64__8wekyb3d8bbwe [2019-04-18] (Microsoft Studios) [MS Ad]
Microsoft Minesweeper -> C:\Program Files\WindowsApps\Microsoft.MicrosoftMinesweeper_2.7.4300.0_x86__8wekyb3d8bbwe [2019-02-18] (Microsoft Studios) [MS Ad]
Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.31.11723.0_x64__8wekyb3d8bbwe [2019-06-26] (Microsoft Corporation) [MS Ad]
Microsoft Phone -> C:\Program Files\WindowsApps\Microsoft.CommsPhone_3.43.20002.1000_x64__8wekyb3d8bbwe [2018-09-08] (Microsoft Corporation)
Microsoft Phone Companion -> C:\Program Files\WindowsApps\Microsoft.WindowsPhone_10.1802.311.0_x64__8wekyb3d8bbwe [2018-02-12] (Microsoft Corporation)
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.4.6132.0_x64__8wekyb3d8bbwe [2019-06-17] (Microsoft Studios) [MS Ad]
MSN Money -> C:\Program Files\WindowsApps\Microsoft.BingFinance_4.29.10701.0_x64__8wekyb3d8bbwe [2019-03-22] (Microsoft Corporation) [MS Ad]
MSN Sports -> C:\Program Files\WindowsApps\Microsoft.BingSports_4.28.3242.0_x64__8wekyb3d8bbwe [2018-12-15] (Microsoft Corporation) [MS Ad]
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.28.10351.0_x64__8wekyb3d8bbwe [2019-02-12] (Microsoft Corporation) [MS Ad]
PAC-MAN Battle -> C:\Program Files\WindowsApps\50867PocketKingGames.PAC-MANBattle_1.1.0.0_x64__m8bdd0rdw5vr0 [2018-12-15] (Pocket King Games) [MS Ad]
The Backgammon -> C:\Program Files\WindowsApps\6918E89D.TheBackgammon_1.2.0.0_x64__66n08swfvvka0 [2018-12-15] (UNBALANCE corp.) [MS Ad]
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.Twitter_6.1.4.1000_neutral__wgeqdkkx372wm [2018-09-08] (Twitter Inc.)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1593158232-969496310-2340663774-1001_Classes\CLSID\{5A9E21A2-851A-4BEB-B16F-DBBE7D648AF9}\InprocServer32 -> C:\Program Files\TextPad 8\System\ShellExt64.dll (Helios Software Solutions Ltd -> )
SSODL: WDFSMountNotificator-wdfsconnect2017 - {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2} - C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll (Western Digital Technologies, Inc.) [File not signed]
SSODL-x32: WDFSMountNotificator-wdfsconnect2017 - {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2} - C:\WINDOWS\SysWOW64\wdfsconnectMntNtf2017.dll (Western Digital Technologies, Inc.) [File not signed]
ShellServiceObjects: Virtual Storage Mount Notification -> {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2} => C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll [2017-11-10] (Western Digital Technologies, Inc.) [File not signed]
ShellServiceObjects-x32: Virtual Storage Mount Notification -> {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2} => C:\WINDOWS\SysWOW64\wdfsconnectMntNtf2017.dll [2017-11-10] (Western Digital Technologies, Inc.) [File not signed]
ShellIconOverlayIdentifiers: [  WDDesktopIconOverlay01] -> {4F8A325E-9DAF-44B8-A825-1A14DFA0FA78} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [  WDDesktopIconOverlay02] -> {0176BDDE-B59A-4A1E-808B-CAD461415CCA} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [  WDDesktopIconOverlay03] -> {B65909D1-57AF-41F5-AB94-BEB733F62B35} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [  WDDesktopIconOverlay04] -> {C6C2397D-8238-4332-8935-86C39C7C165F} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [  WDDesktopIconOverlay05] -> {E7B3BCF9-0386-4B5F-AE6A-91B9F1423973} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [  WDDesktopIconOverlay06] -> {564EA121-D9DA-485D-82C2-C2ED7BFCCEAD} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2016-04-27] (CyberLink Corp. -> Cyberlink)
ContextMenuHandlers1: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\ShellEx.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers1: [WDDesktopContextMenu] -> {4961b028-350a-3bb9-9d6c-079dc724e5f0} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2016-04-27] (CyberLink Corp. -> Cyberlink)
ContextMenuHandlers2: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\ShellEx.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers4: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\ShellEx.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers4: [WDDesktopContextMenu] -> {4961b028-350a-3bb9-9d6c-079dc724e5f0} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\ki127171.inf_amd64_368f8c7337214025\igfxDTCM.dll [2018-03-22] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\ShellEx.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers1_S-1-5-21-1593158232-969496310-2340663774-1001: [TextPad8] -> {5A9E21A2-851A-4BEB-B16F-DBBE7D648AF9} => C:\Program Files\TextPad 8\System\ShellExt64.dll [2016-02-28] (Helios Software Solutions Ltd -> )
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2016-08-09 19:32 - 2015-06-29 20:13 - 000151552 _____ () [File not signed] C:\Program Files (x86)\DELL\DELLOSD\DellOSDService.exe
2016-08-09 19:32 - 2015-06-29 20:09 - 000548864 _____ () [File not signed] C:\Program Files (x86)\DELL\DELLOSD\MediaButtons.exe
2015-05-19 12:11 - 2015-05-19 12:11 - 000007680 _____ () [File not signed] C:\Program Files (x86)\Intel\Intel® Security Assist\isaHelperService.exe
2019-01-21 07:55 - 2019-01-21 07:55 - 000251392 _____ () [File not signed] C:\Program Files (x86)\NordVPN\x86\Liberation.Native.Firewall.dll
2016-03-25 23:50 - 2016-03-25 23:50 - 001491968 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\VMware\VMware Horizon View Client\bin\LIBEAY32.dll
2016-03-25 23:50 - 2016-03-25 23:50 - 000298496 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\VMware\VMware Horizon View Client\bin\SSLEAY32.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\.DEFAULT\...\localhost -> localhost
IE trusted site: HKU\.DEFAULT\...\webcompanion.com -> hxxp://webcompanion.com
IE trusted site: HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\webcompanion.com -> hxxp://webcompanion.com
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2015-10-30 03:24 - 2019-01-10 23:55 - 000002507 _____ C:\WINDOWS\system32\drivers\etc\hosts
 
0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
0.0.0.0 media.opencandy.com
0.0.0.0 cdn.opencandy.com
0.0.0.0 tracking.opencandy.com
0.0.0.0 api.opencandy.com
0.0.0.0 api.recommendedsw.com
0.0.0.0 rp.yefeneri2.com
0.0.0.0 os.yefeneri2.com
0.0.0.0 os2.yefeneri2.com
0.0.0.0 installer.betterinstaller.com
0.0.0.0 installer.filebulldog.com
0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
0.0.0.0 inno.bisrv.com
0.0.0.0 nsis.bisrv.com
0.0.0.0 cdn.file2desktop.com
0.0.0.0 cdn.goateastcach.us
0.0.0.0 cdn.guttastatdk.us
0.0.0.0 cdn.inskinmedia.com
0.0.0.0 cdn.insta.oibundles2.com
0.0.0.0 cdn.insta.playbryte.com
0.0.0.0 cdn.llogetfastcach.us
0.0.0.0 cdn.montiera.com
0.0.0.0 cdn.msdwnld.com
0.0.0.0 cdn.mypcbackup.com
0.0.0.0 cdn.ppdownload.com
0.0.0.0 cdn.riceateastcach.us
0.0.0.0 cdn.shyapotato.us
0.0.0.0 cdn.solimba.com
0.0.0.0 cdn.tuto4pc.com
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Data Protection\Drivers\TSS\bin\;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL;C:\Program Files\Intel\Intel® Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT;C:\Program Files\Intel\Intel® Management Engine Components\IPT;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\indre\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Warn)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
If an entry is included in the fixlist, it will be removed.
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{F26FF42A-FABC-4237-AF27-9A74BAD6E0C7}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [UDP Query User{B71B19F6-E012-4D87-BC64-170CDB9AE748}C:\program files\itunes\itunes.exe] => (Allow) C:\program files\itunes\itunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [TCP Query User{FF6FAF1B-3C9B-4453-9D51-82A62172D810}C:\program files\itunes\itunes.exe] => (Allow) C:\program files\itunes\itunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{6A551C3A-B926-43D8-9A75-06A3CEEB5AAF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{AD297B5D-2C9A-4E26-9193-5DEFE2B8D5DD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{6CC73312-41C6-4002-A0B0-4F73A84DBE2F}] => (Allow) LPort=8888
FirewallRules: [{277A97E1-8E11-4C68-985D-B7CC9AFC4A42}] => (Allow) LPort=8888
FirewallRules: [{B768845C-68FA-4F5D-8CB0-8915F5518FBE}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe (Intel® Wireless Display -> Intel)
FirewallRules: [TCP Query User{3696DD75-4C0C-490B-A914-59C0D82CE209}C:\program files (x86)\vmware\vmware horizon view client\vmware-remotemks.exe] => (Allow) C:\program files (x86)\vmware\vmware horizon view client\vmware-remotemks.exe (VMware, Inc. -> VMware, Inc.)
FirewallRules: [UDP Query User{881A5D70-E076-4553-AFB1-5DCEB88E106E}C:\program files (x86)\vmware\vmware horizon view client\vmware-remotemks.exe] => (Allow) C:\program files (x86)\vmware\vmware horizon view client\vmware-remotemks.exe (VMware, Inc. -> VMware, Inc.)
FirewallRules: [TCP Query User{56C4283E-A791-4CBC-9F68-AC60C8E0C7B4}C:\users\indre\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\indre\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{1DC4DC8A-7F42-44CE-9FE4-78B806402CE0}C:\users\indre\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\indre\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{3E499D19-4DBA-4DEF-8CF8-19DA405CDB89}] => (Block) C:\users\indre\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{69A76876-400F-4C97-9AC9-188D74D4DEA6}] => (Block) C:\users\indre\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{FE7FEA92-FE61-4E07-AB28-B07698433507}] => (Allow) LPort=8889
FirewallRules: [TCP Query User{5BEC10D3-14A2-4D91-86E2-3FF9AC49678E}C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe] => (Allow) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe No File
FirewallRules: [UDP Query User{DC37BDA6-DFD4-4AE9-A106-AF2D1149CAC6}C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe] => (Allow) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe No File
FirewallRules: [{2F7C3E13-8189-49BC-AD54-293606BAB75F}] => (Block) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe No File
FirewallRules: [{2A5D3459-4437-4C54-AAC4-9E96FEE61614}] => (Block) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe No File
FirewallRules: [{DED84BE3-3BD6-4E0D-A420-B30E49FC626F}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{56381F91-7873-4CEA-8ABE-E10213107A2E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{835008C9-6A51-4365-AFEC-F24E67C44C2E}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe (Plex, Inc -> Plex, Inc.)
FirewallRules: [{B9F683A9-6869-4425-ACDF-4BBE734023A1}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe (Plex, Inc -> Python Software Foundation)
FirewallRules: [{73C29C77-9A88-433D-8F93-2CEF6E260A57}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex DLNA Server.exe (Plex, Inc -> Plex, Inc.)
FirewallRules: [{FCB7161E-863C-4365-A934-94FC0E83A38E}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex Tuner Service.exe (Plex, Inc -> )
FirewallRules: [{F52C8ACB-334D-404D-AC77-F60981439024}] => (Allow) C:\Program Files\iTunes\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{35F1740E-5C7F-48A0-9424-553F25A67238}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{4D93D1F7-7788-460E-AB49-CA919F927793}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe (Intel Corporation -> )
FirewallRules: [{F29C6F66-709F-4614-A9A3-B60FCED2E26A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
 
==================== Restore Points =========================
 
20-06-2019 20:03:03 Windows Update
29-06-2019 20:49:28 Scheduled Checkpoint
10-07-2019 07:35:27 Windows Update
12-07-2019 11:29:53 Installed Macrium Reflect Free Edition
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (07/12/2019 06:54:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IAStorDataMgrSvc.exe, version: 14.8.9.1053, time stamp: 0x5718affa
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x04e1efcd
Faulting process id: 0x40fc
Faulting application start time: 0x01d53904b6f86c23
Faulting application path: C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
Faulting module path: unknown
Report Id: 0d1e7d93-ab79-4603-8b5f-cff08156946e
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (07/12/2019 06:54:11 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: IAStorDataMgrSvc.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.NullReferenceException
   at IAStorUtil.SystemDataModelListener.ProcessSystemDataModelChanges()
   at IAStorUtil.SystemDataModelListener.LoadSavedSystemState()
   at IAStorDataMgr.EventRelay.<Start>b__0(System.Object)
   at System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
   at System.Threading.ThreadPoolWorkQueue.Dispatch()
   at System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()
 
 
System errors:
=============
Error: (07/13/2019 12:30:32 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/13/2019 12:29:31 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
Windows.SecurityCenter.WscBrokerManager
 and APPID 
Unavailable
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/13/2019 12:29:28 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-EL88UDV)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user DESKTOP-EL88UDV\indre SID (S-1-5-21-1593158232-969496310-2340663774-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/13/2019 12:29:13 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/13/2019 12:17:18 AM) (Source: Netwtw06) (EventID: 5005) (User: )
Description: Intel® Dual Band Wireless-AC 8260 : Has encountered an internal error and has failed.
5005 - Driver internal error
 
Error: (07/13/2019 12:17:18 AM) (Source: Netwtw06) (EventID: 5035) (User: )
Description: 5035 - Driver OSC Pending OID watchdog
 
Error: (07/12/2019 09:35:56 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/12/2019 09:35:44 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-EL88UDV)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user DESKTOP-EL88UDV\indre SID (S-1-5-21-1593158232-969496310-2340663774-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
 
CodeIntegrity:
===================================
 
Date: 2019-07-13 00:26:54.793
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\Installer\MSIEC59.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2019-07-13 00:24:49.728
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\Installer\MSI37B.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
==================== Memory info =========================== 
 
BIOS: Dell Inc. 1.8.6 12/12/2017
Motherboard: Dell Inc. 0X2MKR
Processor: Intel® Core™ i7-6700 CPU @ 3.40GHz
Percentage of memory in use: 62%
Total physical RAM: 8048.94 MB
Available physical RAM: 3041.44 MB
Total Virtual: 9840.94 MB
Available Virtual: 3738.34 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:224.73 GB) (Free:98.5 GB) NTFS
Drive e: (My Passport) (Fixed) (Total:1862.98 GB) (Free:1819.02 GB) NTFS
 
\\?\Volume{a8007518-d8a3-4a74-92ee-2363fddb05a7}\ (WINRETOOLS) (Fixed) (Total:0.44 GB) (Free:0.06 GB) NTFS
\\?\Volume{616afac5-ee60-493d-8f6b-5152f9f29468}\ (Image) (Fixed) (Total:12.69 GB) (Free:0.63 GB) NTFS
\\?\Volume{dbd7410f-196c-49b5-bb90-bbf877a175c2}\ (ESP) (Fixed) (Total:0.48 GB) (Free:0.44 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: 4FCEFFCB)
 
Partition: GPT.
 
========================================================
Disk: 1 (Size: 1863 GB) (Disk ID: 16F2A91F)
 
Partition: GPT.
 
==================== End of Addition.txt ============================
 
************************************************************************************************************

It's late--no need to respond tonight! Thanks, as always, for all your help!

  • 0

Advertisements


#32
RKinner

RKinner

    Malware Expert

  • Expert
  • 21,737 posts
  • MVP

No new errors from iastor so that worked.  You do have a new error from your WIFI:

 

Error: (07/13/2019 12:17:18 AM) (Source: Netwtw06) (EventID: 5005) (User: )
Description: Intel® Dual Band Wireless-AC 8260 : Has encountered an internal error and has failed.
5005 - Driver internal error
 
Error: (07/13/2019 12:17:18 AM) (Source: Netwtw06) (EventID: 5035) (User: )
Description: 5035 - Driver OSC Pending OID watchdog

 

 

Don't think you are currently using wifi so it may not matter but it might help to update it too. 

https://downloadcent.../download/28876

Click on the link below where it says:

 

Windows 10, 64-bit*

Language: Multi language

Size: 20.81 MB

MD5: c9e642f834a2283fd44216e0d19ae194

 

 

then Accept and save.  Right click on the saved file and Run As Admin.

 

You can also try intel's "Automatically update your drivers" program which is at the top of that same page.  Not sure how well it works tho.  All of my PCs are AMD.

 

I see you do not have an adblocker installed.  Suggest you install Ublock Origin

 

https://chrome.googl...hjbkeiagm?hl=en

 

Go to:

 

chrome://settings/

 

Scroll to the bottom and click on Advanced.

 

Now scroll to where it says System and turn off

 

Continue running background apps when Google Chrome is closed
 

Under

Privacy and security

 

turn off:

 

Preload pages for faster browsing and searching

 

That should cut down the number of Chrome.exe programs running.  Restart Chrome so that the changes take effect.

 

Let's shutdown some of Win 10's spyware/adware:

 

Download OOSU10.exe:

https://www.oo-softw...com/en/shutup10

Download and Save it (You will get a popup while it's downloading.  You can X out of it)
then Right click and Run As Admin.
Allow it to make a System Restore Point.
Click on Actions then on Apply Recommended Settings.

Close the program and reboot.

After each major update it's wise to rerun the program and Revert the changes.

 

 

How is it running now?


  • 0

#33
IndyBlue

IndyBlue

    Member

  • Topic Starter
  • Member
  • PipPip
  • 95 posts

Thank you for all these clear directions! Before I begin, I have a few questions, if you don't mind:

(1) I use Nord VPN--is this having any sort of impact? Is it possibly causing any of the errors? Is there anything I should be aware of when I'm using it?

(2) FIOS was recently made available in my building (I'm in Manhattan), and a Verizon technician came over a few months ago and did the installation for my apartment. I have a special router that is using wireless but it's FIOS (I don't really understand how I connect to the Internet--is it FIOS or wireless?). Whatever the case, I use the wireless for my mobile devices. I will run the WIFI update as you suggested. Is there anything I should be aware of with FIOS?

 

(3) UBlock Origin sounds great, and I will download that. is it easy to turn on and off? Sometimes I don't want an ad blocker on (believe it or not).

 

(4) What does "Preload pages for faster browsing and searching"? Isn't this a good thing? If you think I should turn this off, I will do it, but I was just curious as to exactly what this meant and how it affects the computer's performance.

 

(5) Finally, I didn't understand these instructions: "After each major update it's wise to rerun the program and Revert the changes." What does this mean? (I told you, I'm a newb, lol).

I apologize for all these questions, but I appreciate all your generosity and kindness in helping me out. I'm learning a lot here, thanks to you! 

IndyBlue


 


  • 0

#34
RKinner

RKinner

    Malware Expert

  • Expert
  • 21,737 posts
  • MVP

1.  Don't think it's hurting anything.

2.  FIOS is Fiber Optic System.  Very fast connection.  Speccy says you are connected to the FIOS modem with an Ethernet cable so WiFi on your PC is not important unless you take it elsewhere.  Your other devices are not impacted by whatever you do on the PC.

3. Ublock puts a shield up on the top right of your browser.  If you want to turn it off you just click on the shield then on ON/Off icon.

4.  Preload means it will look at the links on a page and connect to them in the background so that when you click on the link it will be there right away.  Sounds good but I don't like my browser clicking on links I don't choose.  Wastes CPU time running multiple instances of Chrome.  I also feel it wastes bandwidth tho that may not be a problem with a FIOS connection.  Up to you if you want to leave it on.

5.  When you get a major upgrade in Windows 10 (like from version 1806 to 1903) Windows often turns some of the adware/spyware back on.  By Running OOSU10.exe again and clicking on the Revert option it will turn off any changes that the upgrade may have made.


  • 0

#35
IndyBlue

IndyBlue

    Member

  • Topic Starter
  • Member
  • PipPip
  • 95 posts

Thank you so much for the informative answers--I really appreciate it!

I will go ahead and follow all of your instructions now. I'll send you the usual FRST and Addition scans when done. 

THANK YOU SO MUCH!!


  • 0

#36
IndyBlue

IndyBlue

    Member

  • Topic Starter
  • Member
  • PipPip
  • 95 posts

So, I followed all your instructions to the letter. The following things happened:

 

(1) When I went to do the FARBAR scans, Kaspersky wouldn't let me do it. FARBAR would open; it would give me a prompt that it was updated; and then I would immediately get another prompt that it was already in use. And then Kaspersky would immediately isolate it and recommend disinfecting and restarting the computer. So I did that once, went back to Geeks to Go and downloaded FARBAR again, and the same thing happened all over again. Please see the attached Kaspersky image. I don't know why this is happening because I've been using FARBAR with Kaspersky running for the past few days; perhaps this possibly happening now because of the changes I just made (?)

(2) Before all that happened, I got a Windows prompt--see attached image. I just cancelled it because I didn't know what to do.

Could you please advise?

Thanks!

 

Attached Thumbnails

  • kaspersky prompt.JPG
  • windows prompt.JPG

  • 0

#37
IndyBlue

IndyBlue

    Member

  • Topic Starter
  • Member
  • PipPip
  • 95 posts

Now I'm having weird problems with my computer. Kaspersky seems to have gotten 'stricter.' I have to keep disinfecting and restarting. Before the last disinfect-and-restart, it wouldn't even let me go to Geeks to Go.

Now it's doing a full scan to get rid of those FARBAR downloads (which I already deleted). So not sure what's going on now.

How do I use FARBAR without Kaspersky going nuts? And how do I deal with that Microsoft Windows Troubleshooting prompt?


  • 0

#38
RKinner

RKinner

    Malware Expert

  • Expert
  • 21,737 posts
  • MVP

Either FRST or Kaspersky got a new upgrade and you are getting a false positive on FRST.   I'm too cheap to have a copy of Kaspersky but there must be a way to tell it to ignore FRST.  See soluton 2:

 

https://support.logm...-i-do-000075025

 

If you want to report it you can:

 

https://support.kaspersky.com/1870

 

I would let Windows fix the things it wants to fix.  We don't really want autorun turned on.  Perhaps OOSU10 made a mistake?


  • 0

#39
IndyBlue

IndyBlue

    Member

  • Topic Starter
  • Member
  • PipPip
  • 95 posts

As always, your advice was spot-on. I made FARBAR a trusted application, and was able to do the scans, which I've pasted in below.

The weird thing is that now I don't get that Microsoft Windows Troubleshooting prompt. Should I be worried about that? Should I open something and allow it to correct those things it checked off? If so, where do I find that prompt?

(1) FRST scan:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 13-07-2019
Ran by indre (administrator) on DESKTOP-EL88UDV (Dell Inc. OptiPlex 7440 AIO) (13-07-2019 21:44:04)
Running from C:\Users\indre\Desktop
Loaded Profiles: indre (Available Profiles: indre)
Platform: Windows 10 Pro Version 1803 17134.885 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
() [File not signed] C:\Program Files (x86)\DELL\DELLOSD\DellOSDService.exe
() [File not signed] C:\Program Files (x86)\DELL\DELLOSD\MediaButtons.exe
() [File not signed] C:\Program Files (x86)\Intel\Intel® Security Assist\isaHelperService.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.19051.16210.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1905.28.0_x64__8wekyb3d8bbwe\Calculator.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19031.11411.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(CyberLink Corp. -> CyberLink) C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvc_P2G8.exe
(CyberLink Corp. -> CyberLink) C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Dell Inc -> CREDANT Technologies, Inc.) C:\Program Files\Dell\Dell Data Protection\Client Security Framework\Dell.SecurityFramework.Agent.exe
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\Dell Data Protection\Client Security Framework\DCF.Loader.exe
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe
(Dell Inc -> Dell, Inc.) C:\Program Files\Dell\Dell Data Protection\Client Security Framework\Dell.SecurityFramework.LocalServer.exe
(Dell Inc. -> Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(Dell Inc. -> Dell Products, LP.) C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
(FabulaTech -> ) C:\Program Files (x86)\VMware\ScannerRedirection\ftscanmgr.exe
(FabulaTech -> ) C:\Program Files\Common Files\VMware\DeviceRedirectionCommon\ftnlsv.exe
(FabulaTech -> VMware) C:\Program Files (x86)\Common Files\VMware\SerialPortRedirection\Client\vmwsprrdpwks.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler64.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PrivacyIconClient.exe
(Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel® Intel Network Drivers -> Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127171.inf_amd64_368f8c7337214025\igfxCUIService.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127171.inf_amd64_368f8c7337214025\igfxEM.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127171.inf_amd64_368f8c7337214025\IntelCpHDCPSvc.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127171.inf_amd64_368f8c7337214025\IntelCpHeciSvc.exe
(Intel® Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel® Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Intel® Wireless Display -> Intel) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksde.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksdeui.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\avp.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\avpui.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\indre\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c\SkypeApp.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.WindowsStore_11905.1001.4.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(PC-Doctor, Inc. -> PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7033.2285\DSAPI.exe
(PC-Doctor, Inc. -> PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7033.2285\pcdrwi.exe
(Plex, Inc -> ) C:\Program Files (x86)\Plex\Plex Media Server\Plex Tuner Service.exe
(Plex, Inc -> Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex DLNA Server.exe
(Plex, Inc -> Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe
(Plex, Inc -> Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe
(Plex, Inc -> Python Software Foundation) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
(Plex, Inc -> Python Software Foundation) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(TEFINCOM S.A. -> ) C:\Program Files (x86)\NordVPN\nordvpn-service.exe
(TEFINCOM S.A. -> NordVPN) C:\Program Files (x86)\NordVPN\NordVPN.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\VMware\VMware Horizon View Client\bin\vmware-view-usbd.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\VMware\VMware Horizon View Client\wsnm\wsnm.exe
(Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe
(Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe
(Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD App Manager\Plugins\WD Backup\App\WDBackupService.exe
(Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD App Manager\WDAppManager.exe
(Western Digital Techologies -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8853248 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_MAXX6] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1419008 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [VMware Netlink 3 HV Install Utility] => C:\Program Files\Common Files\VMware\DeviceRedirectionCommon\ftnliu.exe [70080 2015-11-04] (FabulaTech -> )
HKLM\...\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [718256 2015-12-22] (Waves Inc -> Waves Audio Ltd.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942864 2016-10-13] (Logitech -> Logitech, Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [302904 2019-05-07] (Apple Inc. -> Apple Inc.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [322120 2019-03-15] (Intel® Rapid Storage Technology -> Intel Corporation)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PrivacyIconClient.exe [1176208 2017-11-09] (Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation)
HKLM-x32\...\Run: [WDDiscovery] => C:\Program Files (x86)\Western Digital\Discovery\Current\WD Discovery.exe [81376496 2019-07-12] (Western Digital Technologies, Inc. -> Western Digital Corporation)
HKLM-x32\...\Run: [WDAppManager] => C:\Program Files (x86)\Western Digital\WD App Manager\AppManagerLauncher.exe [21888 2019-01-02] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\Run: [Plex Media Server] => C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe [23081448 2019-04-04] (Plex, Inc -> Plex, Inc.)
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\Run: [NordVPN] => C:\Program Files (x86)\NordVPN\NordVPN.exe [2186704 2019-05-22] (TEFINCOM S.A. -> NordVPN)
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\Run: [kpm.exe] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe [584128 2019-02-08] (Kaspersky Lab -> AO Kaspersky Lab)
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1555952 2019-06-17] (Google LLC -> Google LLC)
HKU\S-1-5-18\...\Run: [GarminExpress] => C:\Program Files (x86)\Garmin\Express\express.exe [30796352 2018-10-24] (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries)
HKLM\...\Drivers32-x32: [vidc.pDAD] => prodad-codec.dll
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.100\Installer\chrmstp.exe [2019-06-20] (Google LLC -> Google LLC)
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {03DFFC2C-FC22-4010-99E9-4F38D03C4728} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [113200 2019-07-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {06D92E0E-08B8-441B-94A2-7B231EE6DCE1} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26804232 2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {08E2F16C-4C59-4C34-A03C-C83EEEDEBBDE} - System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec-Logon => C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-17] (Intel® Software Asset Manager -> Intel Corporation)
Task: {0C0614F0-18B6-495C-99F1-B61633EE7B2A} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel® Update Manager\bin\iumsvc.exe
Task: {0EBA0793-94A7-49CE-AB2C-1FEF6BA70765} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26804232 2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {0FE0644F-58F4-43E8-A63F-AA62CD169246} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {1D566C7D-1CD5-4E77-826C-E0DF557F6BFA} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_223_Plugin.exe [1457208 2019-07-10] (Adobe Inc. -> Adobe)
Task: {1E20F289-46AA-4529-B808-962BFEF268A3} - System32\Tasks\RtHDVBg_PushButton => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1419008 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {1E4AE78B-2D84-403D-9CD3-0703770FF0B5} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [113200 2019-07-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {267B2E60-3693-45B1-B32D-E5AA4FA083F4} - System32\Tasks\WD Discovery Service Task indre => C:\Program Files (x86)\Western Digital\Discovery\Current\Service\WDDiscoveryService.exe [71408 2019-07-12] (Western Digital Technologies, Inc. -> )
Task: {27CEA27E-1BF2-4A16-B5AE-DCA79020DF0D} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [816960 2017-10-11] (Intel® Trust Services -> Intel® Corporation)
Task: {2BE02930-09E5-4DB5-86B2-C883307D310D} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_223_pepper.exe [1453112 2019-07-10] (Adobe Inc. -> Adobe)
Task: {39820E81-9B7D-411F-A870-C6BEBCB2BF30} - System32\Tasks\Intel\Intel Telemetry 2 => C:\Program Files\Intel\Telemetry 2.0\lrio.exe [1698000 2015-06-05] (Intel® Software -> Intel Corporation)
Task: {4DF09A94-B680-4D73-A2BA-B28905CCA70D} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [39920 2018-10-24] (Garmin International, Inc. -> )
Task: {52187049-A19C-4B23-AFFC-5089227DB2E9} - System32\Tasks\Seagate_Install_Launch => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Dashboard.exe
Task: {5EF9065E-7942-4205-9A7E-625FDF39B32F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [136056 2019-01-02] (HP Inc. -> HP Inc.)
Task: {6D0AA64B-75B4-49CF-9C53-3BF5D9356A9D} - System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec => C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-17] (Intel® Software Asset Manager -> Intel Corporation)
Task: {82F39D33-C846-4F84-8898-8F68198ADD97} - System32\Tasks\CLVDLauncher => C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLVDLauncher.exe [340440 2015-01-28] (CyberLink Corp. -> CyberLink Corp.)
Task: {8B3F29DA-404A-4CB9-8309-9D94ECAA8D3F} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvc_P2G8.exe [110008 2016-04-27] (CyberLink Corp. -> CyberLink)
Task: {8D960D58-2C65-4690-A008-63A3B9664FD6} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [654712 2019-06-05] (HP Inc. -> HP Inc.)
Task: {A5585A2F-2224-44F3-B48A-C02AA6E9CD5D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-09-11] (Google Inc -> Google Inc.)
Task: {BE8068C1-2DB9-4BBE-9031-9E917FD77777} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1448296 2019-07-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {BEEC0D34-AA7B-4933-B79B-EE5F2DA284E3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-07-10] (Adobe Inc. -> Adobe)
Task: {C9DAB848-B95A-4118-8DAB-0AA8CAE862C4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1195544 2018-12-16] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Task: {DCF36F4E-53FF-403E-B92A-CAFE9380489C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616320 2018-01-08] (Apple Inc. -> Apple Inc.)
Task: {DD6E66AE-D0AA-4C99-8D5F-5BA39CA6FC45} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1448296 2019-07-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {ECD51CA1-564E-49C6-A83B-0A4B7EC42B15} - System32\Tasks\WD Device Agent Task indre => C:\Users\indre\AppData\Roaming\WD Discovery\plugins\com.wdc.plugin.catalog\current\library\WD Device Agent.exe [724008 2019-06-18] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
Task: {F219FE43-71D7-4843-8134-11FF7BD69ACF} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistInstaller.exe [1512920 2019-05-24] (Dell Inc. -> Dell Inc.)
Task: {F266FDCC-EAB9-4691-867D-FA95BDE06352} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [791232 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
Task: {F932D694-A1C8-4A80-9BEA-DAAFEF0B6FE1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-09-11] (Google Inc -> Google Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{28110dcb-4039-465c-840d-a703c58d8f0f}: [DhcpNameServer] 103.86.96.100 103.86.99.100
Tcpip\..\Interfaces\{6fbafdae-3f34-452d-bbc1-3182c4eed1fc}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{df5feca7-b365-4e54-a128-6afee4fc4200}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{eb569711-9ed4-49b4-a209-84f1068bb002}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell17win10.msn.com/?pc=DCTE
SearchScopes: HKU\S-1-5-21-1593158232-969496310-2340663774-1001 -> DefaultScope {97FF47F7-FF6D-4CCE-B19F-284086150FBF} URL = 
SearchScopes: HKU\S-1-5-21-1593158232-969496310-2340663774-1001 -> {97FF47F7-FF6D-4CCE-B19F-284086150FBF} URL = 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2019-06-25] (Microsoft Corporation -> Microsoft Corporation)
BHO: No Name -> {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2}' -> No File
BHO: Kaspersky Protection -> {EC1E29BB-F56A-45D8-B023-D3EF710FA0E0} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
BHO: Kaspersky Password Manager -> {F710F7E5-A520-471D-989C-F653AC328FB2} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\x64\ie_engine.dll [2019-05-08] (Kaspersky Lab -> AO Kaspersky Lab)
BHO-x32: No Name -> {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2}' -> No File
BHO-x32: CutePDF Form Filler Helper -> {D41289F2-69C6-417B-897E-C653D677CBAF} -> C:\Program Files (x86)\Acro Software\CutePDF Filler Evaluation\CPFillerCoE.dll [2014-03-27] (Acro Software Inc. -> Acro Software Inc.)
BHO-x32: Kaspersky Protection -> {EC1E29BB-F56A-45D8-B023-D3EF710FA0E0} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
BHO-x32: Kaspersky Password Manager -> {F710F7E5-A520-471D-989C-F653AC328FB2} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\ie_engine.dll [2019-05-08] (Kaspersky Lab -> AO Kaspersky Lab)
Toolbar: HKLM - Kaspersky Protection Toolbar - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
Toolbar: HKLM-x32 - Kaspersky Protection Toolbar - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
Toolbar: HKU\S-1-5-21-1593158232-969496310-2340663774-1001 -> Kaspersky Protection Toolbar - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} hxxps://meetny.webex.com/client/WBXclient-T30L10NSP6EP6-20000/webex/ieatgpc1.cab
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-06-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-06-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-06-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-06-02] (Microsoft Corporation -> Microsoft Corporation)
 
FireFox:
========
FF DefaultProfile: 1cu7vqt4.default-1534000050440
FF ProfilePath: C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440 [2019-07-11]
FF Homepage: Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440 -> hxxps://www.google.com/
FF Extension: (ETP Search Volume Study) - C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440\Extensions\[email protected] [2019-06-26]
FF Extension: (Notifier for Gmail™) - C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440\Extensions\jid0-GjwrPchS3[email protected] [2019-03-31]
FF Extension: (Honey) - C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440\Extensions\[email protected] [2019-05-18]
FF Extension: (Kaspersky Password Manager) - C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440\Extensions\[email protected] [2019-05-08] [UpdateUrl:hxxps://special.s.kaspersky-labs.com/firefox_extensions/kpm_win_add_on/update.json]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Extension: (Kaspersky Protection) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\FFExt\light_plugin_firefox\addon.xpi [2019-07-06]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_223.dll [2019-07-10] (Adobe Inc. -> )
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_223.dll [2019-07-10] (Adobe Inc. -> )
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2019-04-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-14] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-14] (Google Inc -> Google LLC)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-05-02] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1593158232-969496310-2340663774-1001: @zoom.us/ZoomVideoPlugin -> C:\Users\indre\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2018-04-06] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\kl_prefs_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.js [2019-07-07] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\kl_config_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.cfg [2019-07-07] <==== ATTENTION
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default [2019-07-13]
CHR Extension: (Slides) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-12]
CHR Extension: (Kaspersky Protection) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\amkpcclbbgegoafihnpgomddadjhcadd [2019-07-06]
CHR Extension: (Docs) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12]
CHR Extension: (Google Drive) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-09-11]
CHR Extension: (YouTube) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-09-11]
CHR Extension: (Honey) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2019-07-11]
CHR Extension: (uBlock Origin) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2019-07-13]
CHR Extension: (Notifier for Gmail™) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcjichoefijpinlfnjghokpkojhlhkgl [2019-03-25]
CHR Extension: (Kaspersky Password Manager) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhnkblpjbkfklfloegejegedcafpliaa [2019-07-12]
CHR Extension: (Adobe Acrobat) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2019-06-11]
CHR Extension: (Sheets) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-12]
CHR Extension: (Google Docs Offline) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-22]
CHR Extension: (Avast Online Security) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2019-07-01]
CHR Extension: (F.B.(FluffBusting)Purity) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmkinhboiljjkhaknpaeaicmdjhagpep [2019-07-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-07]
CHR Extension: (Gmail) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-03-26]
CHR Extension: (Chrome Media Router) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-06-20]
CHR Profile: C:\Users\indre\AppData\Local\Google\Chrome\User Data\Guest Profile [2019-07-08]
CHR Profile: C:\Users\indre\AppData\Local\Google\Chrome\User Data\System Profile [2019-07-08]
CHR HKLM\...\Chrome\Extension: [amkpcclbbgegoafihnpgomddadjhcadd] - hxxps://chrome.google.com/webstore/detail/amkpcclbbgegoafihnpgomddadjhcadd
CHR HKU\S-1-5-21-1593158232-969496310-2340663774-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhnkblpjbkfklfloegejegedcafpliaa] - hxxps://chrome.google.com/webstore/detail/dhnkblpjbkfklfloegejegedcafpliaa
CHR HKLM-x32\...\Chrome\Extension: [amkpcclbbgegoafihnpgomddadjhcadd] - hxxps://chrome.google.com/webstore/detail/amkpcclbbgegoafihnpgomddadjhcadd
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [96056 2019-04-29] (Apple Inc. -> Apple Inc.)
R2 AVP19.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\avp.exe [619640 2018-02-28] (Kaspersky Lab -> AO Kaspersky Lab)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11413600 2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
S4 dcu-oobe; C:\Program Files (x86)\Dell\CommandUpdate\OobeService.exe [84408 2016-06-07] (Dell Inc. -> Dell Inc.)
R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [209392 2019-02-28] (Dell Inc -> Dell Inc.)
R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3363824 2019-02-28] (Dell Inc -> Dell Inc.)
R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [218096 2019-02-28] (Dell Inc -> Dell Inc.)
R2 Dell Hardware Support; C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7033.2285\DSAPI.exe [1050952 2019-06-02] (PC-Doctor, Inc. -> PC-Doctor, Inc.)
R2 Dell WMI Service; C:\Program Files (x86)\DELL\DELLOSD\DellOSDService.exe [151552 2015-06-29] () [File not signed]
R2 DellMgmtAgent; C:\Program Files\Dell\Dell Data Protection\Client Security Framework\Dell.SecurityFramework.Agent.exe [22280 2016-07-13] (Dell Inc -> CREDANT Technologies, Inc.)
R2 DellMgmtLoader; C:\Program Files\Dell\Dell Data Protection\Client Security Framework\DCF.Loader.exe [35080 2016-07-13] (Dell Inc -> Dell Inc.)
R3 DellMgmtServer; C:\Program Files\Dell\Dell Data Protection\Client Security Framework\Dell.SecurityFramework.LocalServer.exe [52488 2016-07-13] (Dell Inc -> Dell, Inc.)
R2 ftnlsv3hv; C:\Program Files\Common Files\VMware\DeviceRedirectionCommon\ftnlsv.exe [233920 2015-11-04] (FabulaTech -> )
R2 ftscanmgr; C:\Program Files (x86)\VMware\ScannerRedirection\ftscanmgr.exe [6363792 2015-07-31] (FabulaTech -> )
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [356728 2019-06-12] (HP Inc. -> HP Inc.)
S3 iaStorAfsService; C:\WINDOWS\IAStorAfsService\iaStorAfsService.exe [2413752 2017-08-18] (Intel® Rapid Storage Technology -> Intel Corporation)
R2 ibtsiva; C:\WINDOWS\system32\ibtsiva.exe [190208 2016-10-15] (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation)
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [742704 2017-10-11] (Intel® Trust Services -> Intel® Corporation)
S3 Intel® Security Assist; C:\Program Files (x86)\Intel\Intel® Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed]
S2 Intel® TPM Provisioning Service; C:\Program Files\Intel\iCLS Client\TPMProvisioningService.exe [668472 2017-10-11] (Intel® Trust Services -> Intel® Corporation)
S3 Intel® WiDi SAM; C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-17] (Intel® Software Asset Manager -> Intel Corporation)
R2 IntelUSBoverIP; C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe [396992 2015-07-06] (Intel® Wireless Display -> Intel)
R2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel® Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [213648 2017-11-09] (Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation)
S3 klvssbridge64_19.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\vssbridge64.exe [414352 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R2 kpm_launch_service; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe [354008 2019-02-08] (Kaspersky Lab -> AO Kaspersky Lab)
R2 KSDE3.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksde.exe [617016 2018-02-28] (Kaspersky Lab -> AO Kaspersky Lab)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [310880 2019-01-23] (Intel Corporation -> )
R2 nordvpn-service; C:\Program Files (x86)\NordVPN\nordvpn-service.exe [217040 2019-05-22] (TEFINCOM S.A. -> )
R2 PlexUpdateService; C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe [1140200 2019-04-04] (Plex, Inc -> Plex, Inc.)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [253776 2015-09-02] (CyberLink Corp. -> CyberLink)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [310016 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5073792 2019-07-04] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [39896 2019-05-24] (Dell Inc. -> Dell Inc.)
S2 tcsd_win32.exe; C:\Program Files\Dell\Dell Data Protection\Drivers\TSS\bin\tcsd_win32.exe [1636352 2012-12-10] (Security Innovation, Inc.) [File not signed]
R2 vmware-view-usbd; C:\Program Files (x86)\VMware\VMware Horizon View Client\bin\vmware-view-usbd.exe [1158984 2016-02-23] (VMware, Inc. -> VMware, Inc.)
R2 vmwsprrdpwks; C:\Program Files (x86)\Common Files\VMware\SerialPortRedirection\Client\vmwsprrdpwks.exe [261776 2015-05-08] (FabulaTech -> VMware)
R2 WavesSysSvc; C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe [613296 2015-12-22] (Waves Inc -> Waves Audio Ltd.)
S3 WD Backup Drive Helper; C:\WINDOWS\SysWOW64\dllhost.exe /Processid:{4AB831D3-8315-414C-8A7A-303105288D0B} [19360 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
S3 WD Backup Drive Helper; C:\WINDOWS\SysWOW64\dllhost.exe /Processid:{4AB831D3-8315-414C-8A7A-303105288D0B} [19360 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
S3 WD Backup Snapshot; C:\WINDOWS\SysWOW64\dllhost.exe /Processid:{302480DF-3AC5-4400-BE7B-DD77AF93B6DD} [19360 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
S3 WD Backup Snapshot; C:\WINDOWS\SysWOW64\dllhost.exe /Processid:{302480DF-3AC5-4400-BE7B-DD77AF93B6DD} [19360 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [524632 2018-03-26] (Western Digital Techologies -> Western Digital Technologies, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [4413440 2019-03-14] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [107160 2019-02-16] (Microsoft Corporation -> Microsoft Corporation)
R2 wsnm; C:\Program Files (x86)\VMware\VMware Horizon View Client\wsnm\wsnm.exe [541400 2016-03-25] (VMware, Inc. -> VMware, Inc.)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [4107360 2019-01-23] (Intel Corporation -> Intel® Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R0 cm_km; C:\WINDOWS\System32\DRIVERS\cm_km.sys [243400 2018-01-27] (Kaspersky Lab -> AO Kaspersky Lab)
R3 DDDriver; C:\WINDOWS\system32\drivers\DDDriver64Dcsa.sys [40824 2019-02-27] (Microsoft Windows Hardware Compatibility Publisher -> Dell Inc.)
S3 DellProf; C:\WINDOWS\system32\drivers\DellProf.sys [41208 2018-05-08] (Techporch Incorporated -> Dell Computer Corporation)
S3 iaStorAfs; C:\WINDOWS\System32\drivers\iaStorAfs.sys [70664 2017-08-18] (Intel® Rapid Storage Technology -> Intel Corporation)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [732416 2016-10-15] (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation)
R3 IntcAzAudAddService; C:\WINDOWS\system32\drivers\RTDVHD64.sys [2677504 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.)
R0 klbackupdisk; C:\WINDOWS\System32\DRIVERS\klbackupdisk.sys [75600 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klbackupflt; C:\WINDOWS\System32\DRIVERS\klbackupflt.sys [125568 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [91472 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
S0 klelam; C:\WINDOWS\System32\DRIVERS\klelam.sys [29208 2017-03-30] (Microsoft Windows Early Launch Anti-malware Publisher -> AO Kaspersky Lab)
R3 klflt; C:\WINDOWS\system32\DRIVERS\klflt.sys [236672 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 KLHK; C:\WINDOWS\System32\drivers\klhk.sys [1093248 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klids; C:\ProgramData\Kaspersky Lab\AVP19.0.0\Bases\klids.sys [197464 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [1168000 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klim6; C:\WINDOWS\system32\DRIVERS\klim6.sys [58704 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klkbdflt; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [60536 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klmouflt; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [60784 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klpd; C:\WINDOWS\System32\DRIVERS\klpd.sys [50304 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
S3 klpnpflt; C:\WINDOWS\system32\DRIVERS\klpnpflt.sys [46416 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 kltap; C:\WINDOWS\System32\drivers\kltap.sys [48080 2018-02-12] (AnchorFree Inc -> The OpenVPN Project)
R0 klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [245272 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klupd_klif_kimul; C:\WINDOWS\System32\Drivers\klupd_klif_kimul.sys [99152 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
S3 klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [302368 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R0 klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [116104 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [198768 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [104576 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klwtp; C:\WINDOWS\system32\DRIVERS\klwtp.sys [184960 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [218240 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
S3 Netwtw04; C:\WINDOWS\System32\drivers\Netwtw04.sys [7689728 2018-04-11] (Microsoft Windows -> Intel Corporation)
R3 Netwtw06; C:\WINDOWS\system32\DRIVERS\Netwtw06.sys [8832800 2019-05-17] (Intel® Wireless Connectivity Solutions -> Intel Corporation)
R3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [779232 2016-08-04] (Realtek Semiconductor Corp. -> Realsil Semiconductor Corporation)
R0 SEDFilter; C:\WINDOWS\System32\DRIVERS\SEDFilter.sys [197808 2016-07-13] (Dell Inc -> Dell Inc.)
S3 SWDUMon; C:\WINDOWS\system32\DRIVERS\SWDUMon.sys [13920 2016-09-11] (SlimWare Utilities Inc. -> )
R3 tapnordvpn; C:\WINDOWS\System32\drivers\tapnordvpn.sys [44896 2018-07-24] (TEFINCOM S.A. -> The OpenVPN Project)
R3 usb3Hub; C:\WINDOWS\System32\drivers\usb3Hub.sys [212056 2015-07-06] (Intel® Wireless Display -> Windows ® Win 7 DDK provider)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44616 2018-04-11] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [331680 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
R1 wdfsconnect2017; C:\WINDOWS\system32\drivers\wdfsconnect2017.sys [468112 2017-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies, Inc.)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [44032 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
R3 wdvpnpbus; C:\WINDOWS\System32\drivers\wdvpnpbus.sys [20624 2017-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies, Inc.)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-07-13 21:35 - 2019-07-13 21:35 - 000000000 ___HD C:\OneDriveTemp
2019-07-13 21:30 - 2019-07-13 21:31 - 000044247 ____C C:\Users\indre\Desktop\Addition.txt
2019-07-13 21:29 - 2019-07-13 21:44 - 000046192 ____C C:\Users\indre\Desktop\FRST.txt
2019-07-13 21:28 - 2019-07-13 21:28 - 002095104 ____C (Farbar) C:\Users\indre\Desktop\FRST64.exe
2019-07-13 21:28 - 2019-07-13 21:28 - 002095104 _____ (Farbar) C:\Users\indre\Downloads\FRST64 (4).exe
2019-07-13 13:07 - 2019-07-13 13:08 - 000002858 ____C C:\Users\indre\Desktop\OOSU10.ini
2019-07-13 13:06 - 2019-07-13 13:06 - 001068584 ____C (O&O Software GmbH) C:\Users\indre\Desktop\OOSU10.exe
2019-07-13 13:06 - 2019-07-13 13:06 - 001068584 _____ (O&O Software GmbH) C:\Users\indre\Downloads\OOSU10.exe
2019-07-13 11:53 - 2019-07-13 11:53 - 021820224 ____C (Intel® Corporation) C:\Users\indre\Desktop\WiFi_21.20.0_Driver64_Win10.exe
2019-07-13 11:53 - 2019-07-13 11:53 - 021820224 _____ (Intel® Corporation) C:\Users\indre\Downloads\WiFi_21.20.0_Driver64_Win10.exe
2019-07-13 01:16 - 2019-07-13 01:16 - 000042265 ____C C:\Users\indre\Desktop\Addition 4.txt
2019-07-13 00:42 - 2019-07-13 00:42 - 000100258 ____C C:\Users\indre\Desktop\FRST 4.txt
2019-07-13 00:25 - 2019-07-13 00:25 - 014543816 ____C (Intel Corporation) C:\Users\indre\Desktop\SetupRST.exe
2019-07-13 00:25 - 2019-07-13 00:25 - 014543816 _____ (Intel Corporation) C:\Users\indre\Downloads\SetupRST (2).exe
2019-07-13 00:21 - 2019-07-13 00:21 - 014543816 _____ (Intel Corporation) C:\Users\indre\Downloads\SetupRST (1).exe
2019-07-12 21:35 - 2019-07-12 21:35 - 000000000 ____D C:\Users\indre\Intel
2019-07-12 21:31 - 2019-07-12 21:31 - 021816776 _____ (Intel Corporation) C:\Users\indre\Downloads\SetupRST.exe
2019-07-12 19:03 - 2019-07-12 19:03 - 000042006 ____C C:\Users\indre\Desktop\Addition 3.txt
2019-07-12 19:00 - 2019-07-12 19:00 - 000117354 ____C C:\Users\indre\Desktop\FRST 3.txt
2019-07-12 18:50 - 2019-07-12 18:50 - 000004156 ____C C:\Users\indre\Desktop\Fixlog.txt
2019-07-12 18:49 - 2019-07-12 18:49 - 000062468 _____ C:\ProgramData\agent.uninstall.1562971733.bdinstall.v2.bin
2019-07-12 18:49 - 2019-07-12 18:49 - 000002522 _____ C:\Users\indre\Downloads\fixlist.txt
2019-07-12 13:55 - 2019-07-12 13:56 - 000169646 ____C C:\Users\indre\Desktop\DESKTOP-EL88UDV 2.txt
2019-07-12 13:50 - 2019-07-12 13:50 - 000117516 ____C C:\Users\indre\Desktop\FRST 2.txt
2019-07-12 13:50 - 2019-07-12 13:50 - 000043949 ____C C:\Users\indre\Desktop\Addition 2.txt
2019-07-12 13:32 - 2019-07-13 00:38 - 000042262 ____C C:\Users\indre\Desktop\Addition 1.txt
2019-07-12 13:28 - 2019-07-12 13:28 - 002095104 _____ (Farbar) C:\Users\indre\Downloads\FRST64 (3).exe
2019-07-12 13:27 - 2019-07-12 13:27 - 002095104 _____ (Farbar) C:\Users\indre\Downloads\FRST64 (2).exe
2019-07-12 12:53 - 2019-07-12 12:53 - 000003240 _____ C:\WINDOWS\System32\Tasks\WD Device Agent Task indre
2019-07-12 12:51 - 2019-07-12 12:53 - 000003236 _____ C:\WINDOWS\System32\Tasks\WD Discovery Service Task indre
2019-07-12 12:51 - 2019-07-12 12:51 - 000001301 _____ C:\Users\Public\Desktop\WD Discovery.lnk
2019-07-12 12:51 - 2019-07-12 12:51 - 000000000 ___DC C:\Users\indre\AppData\Roaming\WDDesktop
2019-07-12 12:50 - 2019-07-13 21:35 - 000000000 ___DC C:\Users\indre\AppData\Roaming\WD Discovery
2019-07-12 12:50 - 2019-07-13 21:35 - 000000000 ____D C:\Users\indre\.wdc
2019-07-12 12:50 - 2019-07-12 12:54 - 000000000 ____D C:\Program Files\WD Desktop App
2019-07-12 12:50 - 2017-11-21 12:03 - 000468112 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\Drivers\wdfsconnect2017.sys
2019-07-12 12:50 - 2017-11-21 12:03 - 000020624 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\Drivers\wdvpnpbus.sys
2019-07-12 12:50 - 2017-11-10 12:51 - 000223744 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\SysWOW64\wdfsconnectNetRdr2017.dll
2019-07-12 12:50 - 2017-11-10 12:51 - 000180224 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll
2019-07-12 12:50 - 2017-11-10 12:51 - 000154112 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\SysWOW64\wdfsconnectMntNtf2017.dll
2019-07-12 12:50 - 2017-11-10 12:51 - 000118272 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\wdfsconnectNetRdr2017.dll
2019-07-12 12:50 - 2017-11-10 12:51 - 000002560 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\wdfsconnectevtmsg.dll
2019-07-12 12:16 - 2019-07-12 12:16 - 000001192 _____ C:\Users\Public\Desktop\WD Drive Utilities.lnk
2019-07-12 12:14 - 2019-07-12 13:23 - 000002228 _____ C:\Users\Public\Desktop\WD Backup.lnk
2019-07-12 12:14 - 2019-07-12 13:23 - 000000000 ____D C:\Program Files (x86)\Western Digital
2019-07-12 12:14 - 2019-07-12 12:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WD Discovery
2019-07-12 12:14 - 2019-07-12 12:14 - 000000000 ___DC C:\Users\indre\AppData\Roaming\Western Digital
2019-07-12 12:14 - 2019-07-12 12:14 - 000000000 ____D C:\ProgramData\Western Digital
2019-07-12 11:29 - 2019-07-12 11:29 - 005278464 _____ (Paramount Software UK Ltd) C:\Users\indre\Downloads\ReflectDLHF (1).exe
2019-07-12 11:25 - 2019-07-12 11:31 - 000000000 ____D C:\ProgramData\Macrium
2019-07-12 11:25 - 2019-07-12 11:25 - 000000000 ____D C:\Users\indre\Downloads\Macrium
2019-07-12 11:24 - 2019-07-12 11:25 - 005278464 _____ (Paramount Software UK Ltd) C:\Users\indre\Downloads\ReflectDLHF.exe
2019-07-11 12:12 - 2019-07-11 12:12 - 000000000 ___DC C:\Users\indre\Documents\Kaspersky Password Manager
2019-07-10 22:50 - 2019-07-10 22:50 - 000000000 ___DC C:\Users\indre\AppData\Local\Garmin
2019-07-10 07:50 - 2019-07-04 05:40 - 021390504 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2019-07-10 07:50 - 2019-07-04 05:40 - 001616840 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2019-07-10 07:50 - 2019-07-04 05:21 - 008627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2019-07-10 07:50 - 2019-07-04 05:18 - 003614208 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2019-07-10 07:50 - 2019-07-04 04:51 - 020384128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2019-07-10 07:50 - 2019-07-04 04:37 - 002882048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2019-07-10 07:50 - 2019-07-04 01:00 - 001035040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2019-07-10 07:50 - 2019-07-04 00:58 - 001219896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2019-07-10 07:50 - 2019-07-04 00:57 - 003292152 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2019-07-10 07:50 - 2019-07-04 00:57 - 001027384 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2019-07-10 07:50 - 2019-07-04 00:56 - 009084216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2019-07-10 07:50 - 2019-07-04 00:56 - 007519896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2019-07-10 07:50 - 2019-07-04 00:56 - 007436536 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2019-07-10 07:50 - 2019-07-04 00:56 - 002810680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2019-07-10 07:50 - 2019-07-04 00:56 - 002571640 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2019-07-10 07:50 - 2019-07-04 00:42 - 006570368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-07-10 07:50 - 2019-07-04 00:42 - 006044008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2019-07-10 07:50 - 2019-07-04 00:42 - 002479176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2019-07-10 07:50 - 2019-07-04 00:42 - 001980984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2019-07-10 07:50 - 2019-07-04 00:37 - 025857536 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2019-07-10 07:50 - 2019-07-04 00:33 - 022017536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2019-07-10 07:50 - 2019-07-04 00:29 - 022717440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2019-07-10 07:50 - 2019-07-04 00:26 - 004385280 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2019-07-10 07:50 - 2019-07-04 00:25 - 019372544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2019-07-10 07:50 - 2019-07-04 00:25 - 007589888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2019-07-10 07:50 - 2019-07-04 00:25 - 004861440 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2019-07-10 07:50 - 2019-07-04 00:25 - 003401216 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2019-07-10 07:50 - 2019-07-04 00:23 - 001765888 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2019-07-10 07:50 - 2019-07-04 00:22 - 003707904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2019-07-10 07:50 - 2019-07-04 00:21 - 005784064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2019-07-10 07:50 - 2019-07-04 00:21 - 003202560 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2019-07-10 07:50 - 2019-07-04 00:21 - 002166784 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2019-07-10 07:50 - 2019-07-04 00:20 - 001156608 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2019-07-10 07:50 - 2019-06-13 08:12 - 002871848 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2019-07-10 07:50 - 2019-06-13 08:05 - 000810296 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2019-07-10 07:50 - 2019-06-13 08:04 - 001721144 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2019-07-10 07:50 - 2019-06-13 08:00 - 000464696 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2019-07-10 07:50 - 2019-06-13 07:59 - 000740664 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2019-07-10 07:50 - 2019-06-13 07:58 - 000637752 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2019-07-10 07:50 - 2019-06-13 07:58 - 000071480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2019-07-10 07:50 - 2019-06-13 07:56 - 000164152 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2019-07-10 07:50 - 2019-06-13 07:43 - 001427984 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystemController.dll
2019-07-10 07:50 - 2019-06-13 07:42 - 004038688 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2019-07-10 07:50 - 2019-06-13 07:42 - 002266936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll
2019-07-10 07:50 - 2019-06-13 07:18 - 006586880 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2019-07-10 07:50 - 2019-06-13 07:18 - 004847104 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2019-07-10 07:50 - 2019-06-13 07:17 - 012756992 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2019-07-10 07:50 - 2019-06-13 07:16 - 000767488 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcommdlg.dll
2019-07-10 07:50 - 2019-06-13 07:15 - 004718080 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2019-07-10 07:50 - 2019-06-13 07:14 - 000900096 _____ (Microsoft Corporation) C:\WINDOWS\system32\slui.exe
2019-07-10 07:50 - 2019-06-13 07:13 - 002920448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2019-07-10 07:50 - 2019-06-13 07:13 - 000951808 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2019-07-10 07:50 - 2019-06-13 06:11 - 001539896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll
2019-07-10 07:50 - 2019-06-13 06:05 - 003700160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2019-07-10 07:50 - 2019-06-13 05:55 - 005657088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2019-07-10 07:50 - 2019-06-13 05:54 - 011942912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2019-07-10 07:50 - 2019-06-13 05:50 - 000896512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll
2019-07-10 07:50 - 2019-06-13 03:01 - 000513336 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2019-07-10 07:50 - 2019-06-13 03:01 - 000511288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2019-07-10 07:50 - 2019-06-13 02:47 - 005625160 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2019-07-10 07:50 - 2019-06-13 02:45 - 002421560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2019-07-10 07:50 - 2019-06-13 02:44 - 002769688 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2019-07-10 07:50 - 2019-06-13 02:44 - 000607112 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2019-07-10 07:50 - 2019-06-13 02:14 - 003318784 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2019-07-10 07:50 - 2019-06-13 02:13 - 004771840 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2019-07-10 07:50 - 2019-06-13 02:13 - 002370048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2019-07-10 07:50 - 2019-06-13 02:10 - 002912256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2019-07-10 07:50 - 2019-06-13 02:10 - 001400832 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2019-07-10 07:50 - 2019-06-13 02:10 - 001215488 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2019-07-10 07:50 - 2019-06-13 02:09 - 001854976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2019-07-10 07:50 - 2019-06-13 01:14 - 000415544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2019-07-10 07:50 - 2019-06-13 01:06 - 002256768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2019-07-10 07:50 - 2019-06-13 00:47 - 002899456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2019-07-10 07:49 - 2019-07-04 05:45 - 001786680 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntVirtualization.dll
2019-07-10 07:49 - 2019-07-04 05:43 - 000094008 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2019-07-10 07:49 - 2019-07-04 05:41 - 000304144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mssecflt.sys
2019-07-10 07:49 - 2019-07-04 05:40 - 001631808 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2019-07-10 07:49 - 2019-07-04 05:40 - 000790416 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2019-07-10 07:49 - 2019-07-04 05:22 - 000131072 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2019-07-10 07:49 - 2019-07-04 05:22 - 000128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2019-07-10 07:49 - 2019-07-04 05:20 - 001609216 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2019-07-10 07:49 - 2019-07-04 05:19 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2019-07-10 07:49 - 2019-07-04 05:18 - 001663488 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2019-07-10 07:49 - 2019-07-04 04:56 - 001453416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2019-07-10 07:49 - 2019-07-04 04:54 - 000662352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2019-07-10 07:49 - 2019-07-04 04:41 - 007990784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2019-07-10 07:49 - 2019-07-04 04:36 - 001471488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2019-07-10 07:49 - 2019-07-04 00:58 - 001328440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2019-07-10 07:49 - 2019-07-04 00:58 - 000416312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2019-07-10 07:49 - 2019-07-04 00:58 - 000192824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2019-07-10 07:49 - 2019-07-04 00:57 - 000986128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2019-07-10 07:49 - 2019-07-04 00:57 - 000776784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2019-07-10 07:49 - 2019-07-04 00:57 - 000723728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2019-07-10 07:49 - 2019-07-04 00:57 - 000708696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2019-07-10 07:49 - 2019-07-04 00:57 - 000568104 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2019-07-10 07:49 - 2019-07-04 00:57 - 000362264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2019-07-10 07:49 - 2019-07-04 00:57 - 000209424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2019-07-10 07:49 - 2019-07-04 00:57 - 000194360 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2019-07-10 07:49 - 2019-07-04 00:57 - 000137656 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll
2019-07-10 07:49 - 2019-07-04 00:57 - 000134968 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2019-07-10 07:49 - 2019-07-04 00:57 - 000091776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpfve.sys
2019-07-10 07:49 - 2019-07-04 00:56 - 001566520 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2019-07-10 07:49 - 2019-07-04 00:56 - 001459120 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2019-07-10 07:49 - 2019-07-04 00:56 - 001260776 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2019-07-10 07:49 - 2019-07-04 00:56 - 001141496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2019-07-10 07:49 - 2019-07-04 00:56 - 000983936 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2019-07-10 07:49 - 2019-07-04 00:56 - 000767536 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2019-07-10 07:49 - 2019-07-04 00:56 - 000734952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2019-07-10 07:49 - 2019-07-04 00:56 - 000713272 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2019-07-10 07:49 - 2019-07-04 00:56 - 000604984 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2019-07-10 07:49 - 2019-07-04 00:56 - 000493752 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2019-07-10 07:49 - 2019-07-04 00:56 - 000115512 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdnet.dll
2019-07-10 07:49 - 2019-07-04 00:43 - 000832016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2019-07-10 07:49 - 2019-07-04 00:43 - 000665440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2019-07-10 07:49 - 2019-07-04 00:43 - 000328696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2019-07-10 07:49 - 2019-07-04 00:43 - 000287376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2019-07-10 07:49 - 2019-07-04 00:43 - 000191800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2019-07-10 07:49 - 2019-07-04 00:42 - 001427768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2019-07-10 07:49 - 2019-07-04 00:42 - 000573808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2019-07-10 07:49 - 2019-07-04 00:42 - 000356312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2019-07-10 07:49 - 2019-07-04 00:42 - 000097272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll
2019-07-10 07:49 - 2019-07-04 00:41 - 000559328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2019-07-10 07:49 - 2019-07-04 00:26 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2019-07-10 07:49 - 2019-07-04 00:26 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2019-07-10 07:49 - 2019-07-04 00:25 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll
2019-07-10 07:49 - 2019-07-04 00:25 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2019-07-10 07:49 - 2019-07-04 00:24 - 000726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\PEAuth.sys
2019-07-10 07:49 - 2019-07-04 00:24 - 000567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2019-07-10 07:49 - 2019-07-04 00:24 - 000462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2019-07-10 07:49 - 2019-07-04 00:24 - 000153600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2019-07-10 07:49 - 2019-07-04 00:23 - 001217536 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2019-07-10 07:49 - 2019-07-04 00:23 - 000786432 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2019-07-10 07:49 - 2019-07-04 00:22 - 002587648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2019-07-10 07:49 - 2019-07-04 00:22 - 002176000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2019-07-10 07:49 - 2019-07-04 00:22 - 001561088 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2019-07-10 07:49 - 2019-07-04 00:22 - 001549824 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2019-07-10 07:49 - 2019-07-04 00:22 - 001175552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2019-07-10 07:49 - 2019-07-04 00:22 - 000300544 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2019-07-10 07:49 - 2019-07-04 00:22 - 000110592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll
2019-07-10 07:49 - 2019-07-04 00:22 - 000032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2019-07-10 07:49 - 2019-07-04 00:21 - 005307392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2019-07-10 07:49 - 2019-07-04 00:21 - 001920000 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2019-07-10 07:49 - 2019-07-04 00:21 - 001220608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2019-07-10 07:49 - 2019-07-04 00:21 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2019-07-10 07:49 - 2019-07-04 00:21 - 000124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll
2019-07-10 07:49 - 2019-07-04 00:21 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2019-07-10 07:49 - 2019-07-04 00:20 - 000544256 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2019-07-10 07:49 - 2019-07-04 00:20 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2019-07-10 07:49 - 2019-07-04 00:20 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2019-07-10 07:49 - 2019-07-04 00:19 - 000886272 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2019-07-10 07:49 - 2019-07-04 00:19 - 000230912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2019-07-10 07:49 - 2019-07-04 00:18 - 002602496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2019-07-10 07:49 - 2019-07-04 00:18 - 001076224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
2019-07-10 07:49 - 2019-07-04 00:18 - 000965632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2019-07-10 07:49 - 2019-07-04 00:18 - 000953344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2019-07-10 07:49 - 2019-07-04 00:18 - 000275968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2019-07-10 07:49 - 2019-07-04 00:17 - 000531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2019-07-10 07:49 - 2019-07-03 23:01 - 000001312 _____ C:\WINDOWS\system32\tcbres.wim
2019-07-10 07:49 - 2019-06-21 04:50 - 000280584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys
2019-07-10 07:49 - 2019-06-13 08:15 - 000324408 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2019-07-10 07:49 - 2019-06-13 07:43 - 001048480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2019-07-10 07:49 - 2019-06-13 07:42 - 000652088 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPublishing.dll
2019-07-10 07:49 - 2019-06-13 07:42 - 000566536 _____ (Microsoft Corporation) C:\WINDOWS\system32\phoneactivate.exe
2019-07-10 07:49 - 2019-06-13 07:41 - 001626936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVIntegration.dll
2019-07-10 07:49 - 2019-06-13 07:41 - 000830264 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVOrchestration.dll
2019-07-10 07:49 - 2019-06-13 07:41 - 000825144 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntStreamingManager.dll
2019-07-10 07:49 - 2019-06-13 07:41 - 000670008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVCatalog.dll
2019-07-10 07:49 - 2019-06-13 07:40 - 000749880 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVReporting.dll
2019-07-10 07:49 - 2019-06-13 07:40 - 000540984 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2019-07-10 07:49 - 2019-06-13 07:40 - 000495416 _____ (Microsoft Corporation) C:\WINDOWS\system32\TransportDSA.dll
2019-07-10 07:49 - 2019-06-13 07:38 - 000766264 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingWinRT.dll
2019-07-10 07:49 - 2019-06-13 07:37 - 000101192 _____ (Microsoft Corporation) C:\WINDOWS\system32\changepk.exe
2019-07-10 07:49 - 2019-06-13 07:36 - 000251000 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2019-07-10 07:49 - 2019-06-13 07:36 - 000236520 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2019-07-10 07:49 - 2019-06-13 07:35 - 001376688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2019-07-10 07:49 - 2019-06-13 07:34 - 000146888 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingUI.exe
2019-07-10 07:49 - 2019-06-13 07:17 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmvdsitf.dll
2019-07-10 07:49 - 2019-06-13 07:17 - 000115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\RjvMDMConfig.dll
2019-07-10 07:49 - 2019-06-13 07:17 - 000109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe
2019-07-10 07:49 - 2019-06-13 07:17 - 000093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe
2019-07-10 07:49 - 2019-06-13 07:15 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpgradeResultsUI.exe
2019-07-10 07:49 - 2019-06-13 07:14 - 001127936 _____ (Microsoft Corporation) C:\WINDOWS\system32\nettrace.dll
2019-07-10 07:49 - 2019-06-13 07:14 - 000346624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2019-07-10 07:49 - 2019-06-13 07:14 - 000246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\DesktopSwitcherDataModel.dll
2019-07-10 07:49 - 2019-06-13 07:13 - 001339392 _____ (Microsoft Corporation) C:\WINDOWS\system32\TaskFlowDataEngine.dll
2019-07-10 07:49 - 2019-06-13 07:13 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2019-07-10 07:49 - 2019-06-13 07:13 - 000181248 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll
2019-07-10 07:49 - 2019-06-13 07:12 - 000394240 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll
2019-07-10 07:49 - 2019-06-13 07:10 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\vdsbas.dll
2019-07-10 07:49 - 2019-06-13 06:07 - 001027008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2019-07-10 07:49 - 2019-06-13 06:07 - 000660496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicensingWinRT.dll
2019-07-10 07:49 - 2019-06-13 06:07 - 000221232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditionUpgradeManagerObj.dll
2019-07-10 07:49 - 2019-06-13 05:54 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmvdsitf.dll
2019-07-10 07:49 - 2019-06-13 05:53 - 000089600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2019-07-10 07:49 - 2019-06-13 05:51 - 000622080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2019-07-10 07:49 - 2019-06-13 05:49 - 002406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2019-07-10 07:49 - 2019-06-13 05:49 - 000371200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll
2019-07-10 07:49 - 2019-06-13 03:48 - 000677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\HeadTrackerStorage.dll
2019-07-10 07:49 - 2019-06-13 03:46 - 000713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedRealitySvc.dll
2019-07-10 07:49 - 2019-06-13 03:01 - 000036152 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2019-07-10 07:49 - 2019-06-13 02:59 - 000785264 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll
2019-07-10 07:49 - 2019-06-13 02:47 - 001063224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2019-07-10 07:49 - 2019-06-13 02:46 - 001076536 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2019-07-10 07:49 - 2019-06-13 02:46 - 000510296 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2019-07-10 07:49 - 2019-06-13 02:46 - 000093984 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2019-07-10 07:49 - 2019-06-13 02:44 - 002546704 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2019-07-10 07:49 - 2019-06-13 02:44 - 001098272 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2019-07-10 07:49 - 2019-06-13 02:44 - 001033696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2019-07-10 07:49 - 2019-06-13 02:44 - 000545808 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2019-07-10 07:49 - 2019-06-13 02:44 - 000130624 _____ (Microsoft Corporation) C:\WINDOWS\system32\rmclient.dll
2019-07-10 07:49 - 2019-06-13 02:17 - 000106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2019-07-10 07:49 - 2019-06-13 02:16 - 001626112 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2019-07-10 07:49 - 2019-06-13 02:16 - 000140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2019-07-10 07:49 - 2019-06-13 02:15 - 000514560 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2019-07-10 07:49 - 2019-06-13 02:15 - 000433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2019-07-10 07:49 - 2019-06-13 02:15 - 000204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2019-07-10 07:49 - 2019-06-13 02:15 - 000137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2019-07-10 07:49 - 2019-06-13 02:15 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\KdsCli.dll
2019-07-10 07:49 - 2019-06-13 02:14 - 000409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2019-07-10 07:49 - 2019-06-13 02:14 - 000361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2019-07-10 07:49 - 2019-06-13 02:14 - 000302080 _____ (Microsoft Corporation) C:\WINDOWS\system32\CXHProvisioningServer.dll
2019-07-10 07:49 - 2019-06-13 02:13 - 000761344 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2019-07-10 07:49 - 2019-06-13 02:13 - 000322560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2019-07-10 07:49 - 2019-06-13 02:13 - 000110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll
2019-07-10 07:49 - 2019-06-13 02:12 - 000916480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2019-07-10 07:49 - 2019-06-13 02:12 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2019-07-10 07:49 - 2019-06-13 02:12 - 000808448 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2019-07-10 07:49 - 2019-06-13 02:12 - 000624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2019-07-10 07:49 - 2019-06-13 02:12 - 000532992 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuietHours.dll
2019-07-10 07:49 - 2019-06-13 02:12 - 000501248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2019-07-10 07:49 - 2019-06-13 02:11 - 000508416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2019-07-10 07:49 - 2019-06-13 02:11 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll
2019-07-10 07:49 - 2019-06-13 02:11 - 000048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerUI.dll
2019-07-10 07:49 - 2019-06-13 02:10 - 000871424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll
2019-07-10 07:49 - 2019-06-13 02:10 - 000869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
2019-07-10 07:49 - 2019-06-13 02:10 - 000849408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll
2019-07-10 07:49 - 2019-06-13 02:10 - 000523776 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2019-07-10 07:49 - 2019-06-13 02:09 - 000922112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2019-07-10 07:49 - 2019-06-13 02:09 - 000755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2019-07-10 07:49 - 2019-06-13 02:08 - 000506368 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2019-07-10 07:49 - 2019-06-13 01:08 - 000443632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2019-07-10 07:49 - 2019-06-13 01:07 - 000101192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rmclient.dll
2019-07-10 07:49 - 2019-06-13 01:07 - 000080744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll
2019-07-10 07:49 - 2019-06-13 01:06 - 001130776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2019-07-10 07:49 - 2019-06-13 01:06 - 000581600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVideoDSP.dll
2019-07-10 07:49 - 2019-06-13 00:49 - 000172544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enrollmentapi.dll
2019-07-10 07:49 - 2019-06-13 00:47 - 003554304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2019-07-10 07:49 - 2019-06-13 00:47 - 000450048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2019-07-10 07:49 - 2019-06-13 00:46 - 000608768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2019-07-10 07:49 - 2019-06-13 00:46 - 000331776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2019-07-10 07:49 - 2019-06-13 00:46 - 000038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerUI.dll
2019-07-10 07:49 - 2019-06-13 00:45 - 000602112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
2019-07-10 07:49 - 2019-06-13 00:45 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2019-07-10 07:49 - 2019-06-13 00:44 - 001003008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2019-07-10 07:49 - 2019-06-13 00:44 - 000648192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll
2019-07-10 07:49 - 2019-06-13 00:44 - 000630784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.MediaPlayer.dll
2019-07-10 07:49 - 2019-06-13 00:44 - 000582144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2019-07-10 07:49 - 2019-06-13 00:44 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2019-07-10 07:49 - 2019-06-13 00:43 - 000681472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2019-07-10 07:49 - 2019-06-13 00:43 - 000646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll
2019-07-10 07:49 - 2019-06-13 00:43 - 000445952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2019-07-09 13:11 - 2019-07-09 13:11 - 004730179 _____ C:\Users\indre\Downloads\Master Folder For Cleared Checks INDY (2).xlsx
2019-07-09 13:09 - 2019-07-09 13:09 - 008141856 _____ C:\Users\indre\Downloads\MASTER ALL CHECKS (4).xlsx
2019-07-08 13:49 - 2019-07-08 13:49 - 000000000 ___DC C:\Users\indre\Documents\ED stuff
2019-07-08 11:03 - 2019-07-08 11:04 - 000188559 ____C C:\Users\indre\Desktop\DESKTOP-EL88UDV.txt
2019-07-08 11:01 - 2019-07-08 11:01 - 000000839 _____ C:\Users\Public\Desktop\Speccy.lnk
2019-07-08 11:01 - 2019-07-08 11:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2019-07-08 11:01 - 2019-07-08 11:01 - 000000000 ____D C:\Program Files\Speccy
2019-07-08 10:59 - 2019-07-08 10:59 - 006889184 _____ (Piriform Ltd) C:\Users\indre\Downloads\spsetup132.exe
2019-07-08 10:59 - 2019-07-08 10:59 - 001309592 _____ (BraveSoftware Inc.) C:\Users\indre\Downloads\BraveBrowserSetup-TPF550.exe
2019-07-08 10:58 - 2019-07-08 10:58 - 000019118 ____C C:\Users\indre\Desktop\Tasklist 070819.txt
2019-07-08 10:56 - 2019-07-08 10:56 - 000019118 _____ C:\junk.txt
2019-07-08 10:54 - 2019-07-08 10:54 - 000026673 ____C C:\Users\indre\Desktop\Registry 070819.txt
2019-07-08 10:50 - 2019-07-08 10:50 - 002826520 _____ (Sysinternals - www.sysinternals.com) C:\Users\indre\Downloads\procexp (1).exe
2019-07-08 10:50 - 2019-07-08 10:50 - 000043192 _____ (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP152.SYS
2019-07-08 10:49 - 2019-07-08 10:49 - 002826520 _____ (Sysinternals - www.sysinternals.com) C:\Users\indre\Downloads\procexp.exe
2019-07-08 10:47 - 2019-07-08 10:47 - 000023010 ____C C:\Users\indre\Desktop\VEW Application 070819.txt
2019-07-08 10:44 - 2019-07-08 10:44 - 000007664 ____C C:\Users\indre\Desktop\VEW Events 070819.txt
2019-07-08 10:43 - 2019-07-08 10:46 - 000023010 _____ C:\VEW.txt
2019-07-08 10:40 - 2019-07-08 10:40 - 000061440 _____ ( ) C:\Users\indre\Downloads\VEW.exe
2019-07-06 13:06 - 2019-07-06 13:06 - 000302368 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klark.sys
2019-07-06 13:04 - 2019-07-06 13:04 - 000001371 _____ C:\Users\Public\Desktop\Kaspersky Password Manager.lnk
2019-07-06 13:04 - 2019-07-06 13:04 - 000000000 ___DC C:\Users\indre\AppData\Local\Kaspersky Lab
2019-07-06 13:04 - 2019-07-06 13:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Password Manager
2019-07-06 13:00 - 2019-07-06 13:00 - 000245272 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_arkmon.sys
2019-07-06 13:00 - 2019-07-06 13:00 - 000198768 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_mark.sys
2019-07-06 13:00 - 2019-07-06 13:00 - 000116104 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klbg.sys
2019-07-06 13:00 - 2019-07-06 13:00 - 000099152 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_kimul.sys
2019-07-06 13:00 - 2019-07-06 13:00 - 000003392 _____ C:\WINDOWS\System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901}
2019-07-06 13:00 - 2019-07-06 13:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Secure Connection
2019-07-06 12:59 - 2019-07-13 21:37 - 000000000 ____D C:\ProgramData\Kaspersky Lab
2019-07-06 12:59 - 2019-07-06 13:17 - 000236672 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klflt.sys
2019-07-06 12:59 - 2019-07-06 13:16 - 001168000 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klif.sys
2019-07-06 12:59 - 2019-07-06 13:16 - 001093248 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klhk.sys
2019-07-06 12:59 - 2019-07-06 13:16 - 000152288 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\klhkum.dll
2019-07-06 12:59 - 2019-07-06 13:04 - 000000000 ____D C:\Program Files (x86)\Kaspersky Lab
2019-07-06 12:59 - 2019-07-06 12:59 - 000002210 _____ C:\Users\Public\Desktop\Safe Money.lnk
2019-07-06 12:59 - 2019-07-06 12:59 - 000002182 _____ C:\Users\Public\Desktop\Kaspersky Total Security.lnk
2019-07-06 12:59 - 2019-07-06 12:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Total Security
2019-07-06 12:59 - 2013-05-06 08:13 - 000110176 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\klfphc.dll
2019-07-06 12:57 - 2019-07-06 12:56 - 000592616 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2019-07-06 12:54 - 2019-07-06 12:55 - 000000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2019-07-06 12:54 - 2019-07-06 12:54 - 002660224 _____ (Kaspersky Lab) C:\Users\indre\Downloads\startup_14445.exe
2019-07-06 10:01 - 2019-07-06 10:01 - 002420224 _____ (Farbar) C:\Users\indre\Downloads\FRST64 (1).exe
2019-07-06 10:00 - 2019-07-13 00:38 - 000100255 ____C C:\Users\indre\Desktop\FRST 1.txt
2019-07-06 09:58 - 2019-07-06 10:00 - 000039445 _____ C:\Users\indre\Downloads\Addition.txt
2019-07-06 09:55 - 2019-07-06 09:59 - 000079818 _____ C:\Users\indre\Downloads\FRST.txt
2019-07-06 09:54 - 2019-07-13 21:44 - 000000000 ____D C:\FRST
2019-07-06 09:53 - 2019-07-06 09:53 - 002420224 _____ (Farbar) C:\Users\indre\Downloads\FRST64.exe
2019-07-01 19:18 - 2019-07-01 19:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2019-06-29 23:56 - 2019-06-29 23:56 - 011069444 _____ C:\Users\indre\Downloads\thecourtshipofeddiesfather-1st (1).mpg
2019-06-29 23:55 - 2019-06-29 23:55 - 011069444 _____ C:\Users\indre\Downloads\thecourtshipofeddiesfather-1st.mpg
2019-06-29 11:29 - 2019-06-29 11:29 - 000074636 _____ C:\ProgramData\agent.update.1561822169.bdinstall.v2.bin
2019-06-27 20:31 - 2019-06-27 20:31 - 022709477 _____ C:\Users\indre\Downloads\20190627_202829_19399014677980 (1).mp4
2019-06-27 20:30 - 2019-06-27 20:30 - 022709477 _____ C:\Users\indre\Downloads\20190627_202829_19399014677980.mp4
2019-06-27 19:53 - 2019-06-27 19:53 - 000000054 ____C C:\Users\indre\Desktop\cryptic stacey 062719.txt
2019-06-24 00:13 - 2019-07-07 22:03 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2019-06-23 23:58 - 2019-06-23 23:58 - 000068279 _____ C:\Users\indre\Downloads\Iulo_Susan_References_2019.pdf
2019-06-23 14:04 - 2019-06-23 14:04 - 000128245 _____ C:\Users\indre\Downloads\Iulo_Susan_-_Resume_2019.pdf
2019-06-21 20:51 - 2019-06-21 20:51 - 000128344 _____ C:\Users\indre\Downloads\Iulo_Susan_-_resume_June_2019_FIRST DRAFT (2).pdf
2019-06-21 20:28 - 2019-06-21 20:28 - 000128344 _____ C:\Users\indre\Downloads\Iulo_Susan_-_resume_June_2019_FIRST DRAFT (1).pdf
2019-06-21 20:25 - 2019-06-21 20:25 - 000128344 _____ C:\Users\indre\Downloads\Iulo_Susan_-_resume_June_2019_FIRST DRAFT.pdf
2019-06-20 12:13 - 2019-06-20 12:13 - 000004919 _____ C:\Users\indre\Downloads\imp8A93.pdf
2019-06-20 12:13 - 2019-06-20 12:13 - 000004919 _____ C:\Users\indre\Downloads\imp8A93 (1).pdf
2019-06-18 21:05 - 2019-06-18 21:05 - 000039557 _____ C:\Users\indre\Downloads\Letters_2019_06_14_12_42_30_156.pdf
2019-06-18 02:30 - 2019-06-18 02:30 - 000363078 _____ C:\Users\indre\Downloads\Preprinted UPS label for Treasury to Farmingdale 010918.pdf
2019-06-17 14:37 - 2019-06-17 14:37 - 000350164 _____ C:\Users\indre\Downloads\Statement_062019_8810.pdf
2019-06-13 20:33 - 2019-06-13 20:33 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless
2019-06-13 20:32 - 2019-06-13 20:32 - 000000000 ____D C:\Program Files\Common Files\Intel
2019-06-13 18:57 - 2019-06-13 18:57 - 000042697 _____ C:\Users\indre\Downloads\Vet papers on baby panthers.pdf
2019-06-13 18:56 - 2019-06-13 18:56 - 000115738 _____ C:\Users\indre\Downloads\Indre adoption contract.pdf
 
==================== One month (modified) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-07-13 21:39 - 2018-05-23 14:43 - 000840376 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-07-13 21:39 - 2018-04-11 19:38 - 000000000 ___HD C:\Program Files\WindowsApps
2019-07-13 21:39 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-07-13 21:39 - 2018-04-11 19:36 - 000000000 ____D C:\WINDOWS\INF
2019-07-13 21:35 - 2016-09-11 19:32 - 000000000 ___RD C:\Users\indre\OneDrive
2019-07-13 21:34 - 2018-05-23 14:44 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-07-13 21:34 - 2018-04-11 19:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-07-13 21:34 - 2018-04-11 17:04 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2019-07-13 21:34 - 2016-09-11 19:30 - 000000000 __SHD C:\Users\indre\IntelGraphicsProfiles
2019-07-13 20:57 - 2018-05-23 14:37 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-07-13 15:40 - 2018-05-23 14:44 - 000004166 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{71AF15CB-04B4-4B18-8047-5E35B9C7421E}
2019-07-13 14:01 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\Registration
2019-07-13 13:14 - 2018-04-11 17:04 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2019-07-13 00:24 - 2017-05-21 14:10 - 000000000 ____D C:\Program Files\Intel
2019-07-13 00:24 - 2016-08-09 19:33 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2019-07-12 21:35 - 2018-05-23 14:38 - 000000000 ____D C:\Users\indre
2019-07-12 21:35 - 2017-05-21 14:10 - 000000000 ____D C:\Program Files (x86)\Intel
2019-07-12 19:21 - 2016-09-17 01:09 - 000000000 ___DC C:\Users\indre\Documents\Letters
2019-07-12 18:51 - 2018-06-09 20:55 - 000409520 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-07-12 13:23 - 2016-08-09 19:33 - 000000000 ____D C:\ProgramData\Package Cache
2019-07-12 12:10 - 2016-10-12 00:52 - 000000000 ___DC C:\Users\indre\AppData\Roaming\Seagate
2019-07-12 11:43 - 2018-04-11 19:38 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2019-07-12 11:43 - 2016-09-16 22:45 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-07-11 11:11 - 2017-11-15 23:45 - 000000000 ___RD C:\Users\indre\3D Objects
2019-07-11 11:11 - 2016-08-09 19:48 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-07-11 04:09 - 2018-04-12 05:20 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2019-07-11 04:09 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\TextInput
2019-07-11 04:09 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2019-07-11 04:09 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2019-07-11 04:09 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\oobe
2019-07-11 04:09 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\appraiser
2019-07-11 04:09 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\ShellComponents
2019-07-11 04:09 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\Provisioning
2019-07-11 04:09 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\bcastdvr
2019-07-11 04:09 - 2018-04-11 17:04 - 000000000 ____D C:\WINDOWS\system32\Dism
2019-07-11 04:01 - 2016-11-18 22:39 - 000000000 ___DC C:\Users\indre\AppData\LocalLow\Mozilla
2019-07-10 08:13 - 2018-04-11 19:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-07-10 07:49 - 2016-09-12 20:21 - 000000000 ____D C:\WINDOWS\system32\MRT
2019-07-10 07:36 - 2016-09-12 20:20 - 136618864 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2019-07-10 02:37 - 2018-05-23 14:44 - 000004600 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2019-07-10 02:37 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2019-07-10 02:37 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\Macromed
2019-07-10 01:37 - 2018-05-23 14:44 - 000004588 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier
2019-07-10 01:37 - 2018-05-23 14:44 - 000004386 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2019-07-09 13:12 - 2017-11-15 23:37 - 000000000 ___DC C:\Users\indre\AppData\Local\Packages
2019-07-08 14:37 - 2016-09-18 09:35 - 000000000 ___DC C:\Users\indre\AppData\Local\CrashDumps
2019-07-08 13:50 - 2016-09-17 01:49 - 000000000 ___DC C:\Users\indre\Documents\Funny stuff
2019-07-08 13:43 - 2018-12-02 19:00 - 000000000 ___DC C:\Users\indre\Documents\Editing for Josh
2019-07-06 13:17 - 2019-02-13 14:10 - 000184960 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klwtp.sys
2019-07-06 13:17 - 2019-02-13 14:10 - 000125568 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klbackupflt.sys
2019-07-06 13:17 - 2019-02-13 14:10 - 000091472 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\kldisk.sys
2019-07-06 13:17 - 2018-02-24 05:17 - 000218240 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\kneps.sys
2019-07-06 13:17 - 2018-02-17 02:50 - 000104576 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klwfp.sys
2019-07-06 13:17 - 2018-01-15 05:13 - 000060536 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klkbdflt.sys
2019-07-06 13:16 - 2019-02-13 14:10 - 000075600 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klbackupdisk.sys
2019-07-06 13:16 - 2019-02-13 14:10 - 000046416 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klpnpflt.sys
2019-07-06 13:16 - 2018-02-12 04:17 - 000058704 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klim6.sys
2019-07-06 13:16 - 2017-12-11 11:49 - 000060784 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klmouflt.sys
2019-07-06 13:16 - 2017-05-30 18:51 - 000050304 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klpd.sys
2019-07-06 13:00 - 2017-02-04 10:05 - 000000000 ____D C:\Program Files\Common Files\AV
2019-07-06 01:15 - 2018-06-20 22:44 - 000002365 ____C C:\Users\indre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-07-06 01:15 - 2018-05-23 14:44 - 000003378 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1593158232-969496310-2340663774-1001
2019-07-04 12:01 - 2018-05-23 14:44 - 000003482 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2019-07-04 12:01 - 2018-05-23 14:44 - 000003346 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2019-07-04 12:01 - 2018-05-23 14:44 - 000003298 _____ C:\WINDOWS\System32\Tasks\Dell SupportAssistAgent AutoUpdate
2019-07-04 12:01 - 2018-05-23 14:44 - 000003122 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2019-07-04 12:01 - 2018-05-23 14:44 - 000003118 _____ C:\WINDOWS\System32\Tasks\Intel PTT EK Recertification
2019-07-04 12:01 - 2018-05-23 14:44 - 000003042 _____ C:\WINDOWS\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473
2019-07-04 12:01 - 2018-05-23 14:44 - 000003040 _____ C:\WINDOWS\System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec
2019-07-04 12:01 - 2018-05-23 14:44 - 000002806 _____ C:\WINDOWS\System32\Tasks\Seagate_Install_Launch
2019-07-04 12:01 - 2018-05-23 14:44 - 000002702 _____ C:\WINDOWS\System32\Tasks\GarminUpdaterTask
2019-07-04 12:01 - 2018-05-23 14:44 - 000002674 _____ C:\WINDOWS\System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec-Logon
2019-07-04 12:01 - 2018-05-23 14:44 - 000002528 _____ C:\WINDOWS\System32\Tasks\CLVDLauncher
2019-07-04 12:01 - 2018-05-23 14:44 - 000002528 _____ C:\WINDOWS\System32\Tasks\CLMLSvc_P2G8
2019-07-04 12:01 - 2018-05-23 14:44 - 000002304 _____ C:\WINDOWS\System32\Tasks\RtHDVBg_PushButton
2019-07-01 19:18 - 2019-05-14 13:15 - 000002495 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2019-07-01 19:18 - 2019-05-14 13:15 - 000002494 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2019-07-01 19:18 - 2019-05-14 13:15 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2019-07-01 19:18 - 2019-05-14 13:15 - 000002451 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2019-07-01 19:18 - 2019-05-14 13:15 - 000002437 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2019-07-01 19:18 - 2016-08-09 19:40 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2019-06-29 23:58 - 2017-10-14 21:56 - 000000000 ___DC C:\Users\indre\AppData\Roaming\vlc
2019-06-29 23:56 - 2017-10-14 21:56 - 000001141 _____ C:\Users\Public\Desktop\VLC media player.lnk
2019-06-28 08:30 - 2016-09-16 13:57 - 000000000 ___DC C:\Users\indre\AppData\Roaming\VMware
2019-06-27 18:32 - 2016-09-11 19:59 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2019-06-27 00:47 - 2017-07-15 20:02 - 000014706 ____C C:\Users\indre\Documents\Indy's Finances.xlsx
2019-06-26 22:10 - 2016-09-11 19:59 - 000001007 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2019-06-21 21:34 - 2016-09-17 01:09 - 000000000 ___DC C:\Users\indre\Documents\Resumes etc
2019-06-21 16:50 - 2016-09-17 01:09 - 000000000 ___DC C:\Users\indre\Documents\Recipes
2019-06-20 20:08 - 2016-09-11 19:57 - 000002303 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-06-20 20:08 - 2016-09-11 19:57 - 000002262 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2019-06-20 20:03 - 2018-11-16 12:19 - 000000000 ____D C:\Program Files\rempl
2019-06-20 08:58 - 2017-05-09 21:49 - 000000000 ____D C:\Program Files\UNP
2019-06-18 05:52 - 2016-09-17 01:38 - 000000000 ___DC C:\Users\indre\Documents\Akiko stuff
2019-06-13 20:33 - 2016-08-09 19:33 - 000000000 ____D C:\ProgramData\Intel
2019-06-13 20:33 - 2015-10-30 02:28 - 000000000 ____D C:\Users\Default.migrated
2019-06-13 20:31 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\Drivers\DriverData
2019-06-13 18:45 - 2016-09-16 22:23 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2019-06-13 18:22 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\ShellExperiences
2019-06-13 18:22 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
 
==================== Files in the root of some directories ================
 
2018-11-19 21:23 - 2018-11-19 21:23 - 000000017 ____C () C:\Users\indre\AppData\Local\resmon.resmoncfg
 
==================== SigCheck ===============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ============================
 
(2) Addition scan:
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-07-2019
Ran by indre (13-07-2019 21:44:58)
Running from C:\Users\indre\Desktop
Windows 10 Pro Version 1803 17134.885 (X64) (2018-05-23 18:44:41)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1593158232-969496310-2340663774-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1593158232-969496310-2340663774-503 - Limited - Disabled)
Guest (S-1-5-21-1593158232-969496310-2340663774-501 - Limited - Disabled)
indre (S-1-5-21-1593158232-969496310-2340663774-1001 - Administrator - Enabled) => C:\Users\indre
WDAGUtilityAccount (S-1-5-21-1593158232-969496310-2340663774-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Kaspersky Total Security (Enabled - Up to date) {0AB30972-4BAC-7BEE-CBCA-B8F9E68797D8}
AS: Kaspersky Total Security (Enabled - Up to date) {B1D2E896-6D96-7460-F17A-838B9D00DD65}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Total Security (Enabled) {32888857-01C3-7AB6-E095-11CC1854D0A3}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Across Lite (HKLM-x32\...\{5F5C7350-9731-420F-97CC-8CAFEE7DA7A3}) (Version: 2.4.2451.1 - Literate Software)
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 19.012.20035 - Adobe Systems Incorporated)
Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.223 - Adobe)
Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.223 - Adobe)
Angry Birds (HKLM-x32\...\{2F7D5734-056F-4A0A-A1C7-CA1AAE5BB1EB}) (Version: 1.6.3.1 - Rovio)
ANT Drivers Installer x64 (HKLM\...\{D559687A-60C5-4786-9429-C21EC195789D}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Application Support (32-bit) (HKLM-x32\...\{C1BCFECF-6EC2-4750-9072-5E2489423F8F}) (Version: 7.5 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{B202C7F5-7DE3-4FBF-B259-E70E625F56FC}) (Version: 7.5 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B5A46811-3612-4DA5-8A5A-E6DED5D7C523}) (Version: 12.2.1.12 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{A30EA700-5515-48F0-88B0-9E99DC356B88}) (Version: 2.6.0.1 - Apple Inc.)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Cisco WebEx Meetings (HKLM-x32\...\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
CmgMasterPrerequisites (HKLM\...\{EE34FA4E-715A-46FA-9CAF-06E26AE4217D}) (Version: 1.10.0.34 - Dell, Inc.) Hidden
CutePDF Form Filler 3.6 (Evaluation) (HKLM-x32\...\CutePDF Form Filler (Evaluation)_is1) (Version:  - Acro Software Inc.)
CyberLink Media Suite Essentials (HKLM-x32\...\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 12 - CyberLink Corp.)
Dell Command | Update (HKLM-x32\...\{EC542D5D-B608-4145-A8F7-749C02BE6D94}) (Version: 2.2.0 - Dell Inc.)
Dell Data Protection | Client Security Framework (HKLM\...\{FAE38E46-ECB2-44EA-A52B-6955AA6B1B3A}) (Version: 8.10.0.39 - Dell, Inc.)
Dell Data Protection | Security Tools (HKLM-x32\...\{812AA6D3-5BEB-4577-88B1-00998B91AB41}) (Version: 1.10.0.34 - Dell, Inc.) Hidden
Dell Data Protection | Security Tools (HKLM-x32\...\InstallShield_{812AA6D3-5BEB-4577-88B1-00998B91AB41}) (Version: 1.10.0.34 - Dell, Inc.)
Dell Digital Delivery (HKLM-x32\...\{AB7F2792-2ED1-4C5C-9F28-680E5110BF72}) (Version: 3.1.1018.0 - Dell Products, LP)
Dell SupportAssist (HKLM\...\{806422F1-FC4E-4D7C-8855-05748AEFC031}) (Version: 3.2.2.119 - Dell Inc.)
DELLOSD (HKLM-x32\...\{BED3193A-897B-47F6-AEDC-45D147122957}) (Version: 1.0.0.0 - DELL)
Elevated Installer (HKLM-x32\...\{0BF90608-2F95-4C7C-9A85-E90E0CAF4FE9}) (Version: 6.9.1.0 - Garmin Ltd or its subsidiaries) Hidden
FileZilla Client 3.25.1 (HKLM-x32\...\FileZilla Client) (Version: 3.25.1 - Tim Kosse)
Garmin Express (HKLM-x32\...\{95D0EADA-5123-41C0-931A-F37946BC0E8E}) (Version: 6.9.1.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express (HKLM-x32\...\{eab4691c-4022-41cd-8d39-c3097ba62d4b}) (Version: 6.9.1.0 - Garmin Ltd or its subsidiaries)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 75.0.3770.100 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.11 - Google LLC) Hidden
HP Support Solutions Framework (HKLM-x32\...\{2B5A1E68-6617-406D-B797-5DAB5B4630B8}) (Version: 12.11.24.11 - HP Inc.)
Intel® Chipset Device Software (HKLM-x32\...\{fb610cea-ba50-4d4b-a717-cf025419035c}) (Version: 10.1.1.13 - Intel® Corporation) Hidden
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1054 - Intel Corporation)
Intel® Network Connections 20.3.300.1 (HKLM\...\PROSetDX) (Version: 20.3.300.1 - Intel)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 23.20.16.4973 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.8.16.1063 - Intel Corporation)
Intel® Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.47.866.0 - Intel Corporation) Hidden
Intel® Trusted Connect Services Client (HKLM-x32\...\{246c6cc0-9810-4728-9a29-28474de2eec5}) (Version: 1.47.866.0 - Intel Corporation) Hidden
Intel® WiDi (HKLM\...\{C7CD6D54-26AF-4D93-B06F-D81ACE8624CB}) (Version: 6.0.40.0 - Intel Corporation)
Intel® WiDi Software Asset Manager (HKLM-x32\...\{5B5CD20C-29F0-4857-A4FA-A4F4C716B019}) (Version: 1.1.347 - Intel Corporation) Hidden
Intel® Wireless Bluetooth® (HKLM-x32\...\{5068B0F8-CE24-4B61-9C2F-301B411FFB9C}) (Version: 18.1.1611.3223 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{f430aa46-62c4-47a0-8a03-42e7fff664b7}) (Version: 20.120.0 - Intel Corporation)
Intel® Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation)
iTunes (HKLM\...\{A8AF3EF8-5010-4A92-BCCA-90F62A7D62B8}) (Version: 12.9.5.7 - Apple Inc.)
Kaspersky Password Manager (HKLM-x32\...\{B2F7333E-6C8D-4994-AAC4-FEC8EBBF9611}) (Version: 9.0.2.767 - Kaspersky Lab) Hidden
Kaspersky Password Manager (HKLM-x32\...\InstallWIX_{B2F7333E-6C8D-4994-AAC4-FEC8EBBF9611}) (Version: 9.0.2.767 - Kaspersky Lab)
Kaspersky Secure Connection (HKLM-x32\...\{F10AA188-7166-430E-8810-FEAB2AD73DE3}) (Version: 19.0.0.1088 - Kaspersky Lab) Hidden
Kaspersky Secure Connection (HKLM-x32\...\InstallWIX_{F10AA188-7166-430E-8810-FEAB2AD73DE3}) (Version: 19.0.0.1088 - Kaspersky Lab)
Kaspersky Total Security (HKLM-x32\...\{718613F4-492D-4272-ACC3-D04A8EF0F883}) (Version: 19.0.0.1088 - Kaspersky Lab) Hidden
Kaspersky Total Security (HKLM-x32\...\InstallWIX_{718613F4-492D-4272-ACC3-D04A8EF0F883}) (Version: 19.0.0.1088 - Kaspersky Lab)
LaserJet 1020 series (HKLM-x32\...\HP-LaserJet 1020 series) (Version:  - )
Maxx Audio Installer (x64) (HKLM\...\{307032B2-6AF2-46D7-B933-62438DEB2B9A}) (Version: 2.6.8006.3 - Waves Audio Ltd.) Hidden
Microsoft Office Famille et Petite Entreprise 2016 - fr-fr (HKLM\...\HomeBusinessRetail - fr-fr) (Version: 16.0.11727.20230 - Microsoft Corporation)
Microsoft Office Hogar y Empresas 2016 - es-es (HKLM\...\HomeBusinessRetail - es-es) (Version: 16.0.11727.20230 - Microsoft Corporation)
Microsoft Office Home and Business 2016 - en-us (HKLM\...\HomeBusinessRetail - en-us) (Version: 16.0.11727.20230 - Microsoft Corporation)
Microsoft OneDrive (HKU\.DEFAULT\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\OneDriveSetup.exe) (Version: 19.103.0527.0003 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (HKLM-x32\...\{6e8f74e0-43bd-4dce-8477-6ff6828acc07}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 (HKLM-x32\...\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24210 (HKLM-x32\...\{23658c02-145e-483d-ba6b-1eb82c580529}) (Version: 14.0.24210.0 - Microsoft Corporation)
Mozilla Firefox 67.0.4 (x64 en-US) (HKLM\...\Mozilla Firefox 67.0.4 (x64 en-US)) (Version: 67.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 66.0.3 - Mozilla)
NewBlue Video Essentials for Windows (HKLM-x32\...\NewBlue Video Essentials for Windows) (Version: 3.0 - NewBlue)
NordVPN (HKLM-x32\...\{F4325B30-A8A0-4D09-B0DE-7CBB485A52D8}) (Version: 6.22.6 - NordVPN) Hidden
NordVPN (HKLM-x32\...\NordVPN 6.22.6) (Version: 6.22.6 - NordVPN)
NordVPN network TAP (HKLM-x32\...\{97DEC5D6-2BE9-45BB-BFC5-274B851B486B}) (Version: 1.0.1 - NordVPN)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.11727.20230 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.11727.20230 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.11727.20230 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.11727.20230 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-040C-0000-0000000FF1CE}) (Version: 16.0.11727.20230 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0C0A-0000-0000000FF1CE}) (Version: 16.0.11727.20230 - Microsoft Corporation) Hidden
Plex Media Server (HKLM-x32\...\{72238E55-A877-4785-A5E9-0C35EAFB0746}) (Version: 1.15.876 - Plex, Inc.) Hidden
Plex Media Server (HKLM-x32\...\{9203fc01-57c0-4cc8-858d-92911b5142de}) (Version: 1.15.3.876 - Plex, Inc.)
Pretty Good Solitaire version 12.4.0 (HKLM-x32\...\Pretty Good Solitaire_is1) (Version: 12.4.0 - Goodsol Development Inc.)
proDAD Adorage 3.0 (HKLM-x32\...\proDAD-Adorage-3.0) (Version: 3.0.114.1 - proDAD GmbH)
Realtek Audio COM Components (HKLM-x32\...\{2355B503-9B11-4449-861D-1C1748B26320}) (Version: 1.0.2 - Realtek Semiconductor Corp.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.14393.21292 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6105 - Realtek Semiconductor Corp.)
Security Innovation TSS (HKLM\...\{0C11FE22-53F2-4C9B-9E79-824B10D0976E}) (Version: 2.1.42 - Security Innovation) Hidden
Speccy (HKLM\...\Speccy) (Version: 1.32 - Piriform)
Spotify (HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\Spotify) (Version: 1.0.96.181.gf6bc1b6b - Spotify AB)
Stopping Plex (HKLM-x32\...\{3C6D43CB-1211-4C3F-8F3C-2B4F90C5BB95}) (Version: 1.15.876 - Plex, Inc.) Hidden
TextPad 8 (HKLM\...\{861AB1C1-1967-4C4A-BF86-C255E2D2B8FD}) (Version: 8.0.2 - Helios)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{F14FB68A-9188-4036-AD0D-D054BC9C9291}) (Version: 2.59.0.0 - Microsoft Corporation)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.7.1 - VideoLAN)
VMware Horizon Client (HKLM\...\{93CEC220-0D24-41C0-8647-BA1C62A3EE89}) (Version: 4.0.1.781 - VMware, Inc.)
Vulkan Run Time Libraries 1.0.33.0 (HKLM\...\VulkanRT1.0.33.0) (Version: 1.0.33.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.33.0 (HKLM\...\VulkanRT1.0.33.0-2) (Version: 1.0.33.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1) (Version: 1.0.54.1 - Intel Corporation Inc.)
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-2) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
WD Backup (HKLM-x32\...\{50C6CAE8-562E-440D-8616-E0514D41CC10}) (Version: 1.9.6941.25593 - Western Digital Technologies, Inc) Hidden
WD Backup (HKLM-x32\...\{6531bf4b-4bad-46a5-9562-766d0a858003}) (Version: 1.9.6941.25593 - Western Digital Technologies, Inc.)
WD Desktop App 2.1.0.245 (HKLM-x32\...\{d303f1fe-6729-4693-b2e1-51d13b450de5}) (Version: 2.1.0.245 - Western Digital Corporation) Hidden
WD Desktop App 2.1.0.245 (x64) (HKLM\...\{CA7F7232-526E-41BD-971A-47BE28C18516}) (Version: 2.1.0.245 - Western Digital Corporation) Hidden
WD Discovery (HKLM-x32\...\WDDiscovery) (Version: 3.3.34 - Western Digital Technologies, Inc.)
WD Drive Utilities (HKLM-x32\...\{5ea95ccc-fc68-4182-88a9-e563ba3900ed}) (Version: 2.0.0.26 - Western Digital Technologies, Inc.)
WD Drive Utilities (HKLM-x32\...\{893C7059-0464-47FB-85A4-5E1ADDA56141}) (Version: 2.0.0.26 - Western Digital Technologies, Inc.) Hidden
WD SES Driver Setup (HKLM-x32\...\{924A274D-38B6-4930-8859-F3F51CFA8DDD}) (Version: 1.1.0.25 - Western Digital) Hidden
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Intel Corporation (iaStorA) HDC  (08/10/2017 15.7.5.1025) (HKLM\...\FF1B55CEF8D39B696D1F5DF141ACFA7A5D1F2743) (Version: 08/10/2017 15.7.5.1025 - Intel Corporation)
Windows Driver Package - Intel Corporation (iaStorA) SCSIAdapter  (08/10/2017 15.7.5.1025) (HKLM\...\6D773A6E21B2A480569157737F58E8FF7DC6608A) (Version: 08/10/2017 15.7.5.1025 - Intel Corporation)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Zoom (HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\ZoomUMX) (Version: 4.1 - Zoom Video Communications, Inc.)
 
Packages:
=========
CyberLink Media Suite Essentials -> C:\Program Files\WindowsApps\DB6EA5DB.CyberLinkMediaSuiteEssentials_1.0.10.0_x86__mcezb6ze687jp [2018-03-13] (CYBERLINK CORPORATION.)
Dell SupportAssist for PCs -> C:\Program Files\WindowsApps\DellInc.DellSupportAssistforPCs_3.2.5.0_x64__htrsf667h5kn2 [2019-05-29] (Dell Inc)
Mail and Calendar -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe [2019-07-10] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1808.3.0_x64__8wekyb3d8bbwe [2018-09-22] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-12] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-12] (Microsoft Corporation) [MS Ad]
Microsoft Jigsaw -> C:\Program Files\WindowsApps\Microsoft.MicrosoftJigsaw_1.8.1812.301_x86__8wekyb3d8bbwe [2019-03-14] (Microsoft Studios) [MS Ad]
Microsoft Mahjong -> C:\Program Files\WindowsApps\Microsoft.MicrosoftMahjong_3.9.4100.0_x64__8wekyb3d8bbwe [2019-04-18] (Microsoft Studios) [MS Ad]
Microsoft Minesweeper -> C:\Program Files\WindowsApps\Microsoft.MicrosoftMinesweeper_2.7.4300.0_x86__8wekyb3d8bbwe [2019-02-18] (Microsoft Studios) [MS Ad]
Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.31.11723.0_x64__8wekyb3d8bbwe [2019-06-26] (Microsoft Corporation) [MS Ad]
Microsoft Phone -> C:\Program Files\WindowsApps\Microsoft.CommsPhone_3.43.20002.1000_x64__8wekyb3d8bbwe [2018-09-08] (Microsoft Corporation)
Microsoft Phone Companion -> C:\Program Files\WindowsApps\Microsoft.WindowsPhone_10.1802.311.0_x64__8wekyb3d8bbwe [2018-02-12] (Microsoft Corporation)
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.4.6132.0_x64__8wekyb3d8bbwe [2019-06-17] (Microsoft Studios) [MS Ad]
MSN Money -> C:\Program Files\WindowsApps\Microsoft.BingFinance_4.29.10701.0_x64__8wekyb3d8bbwe [2019-03-22] (Microsoft Corporation) [MS Ad]
MSN Sports -> C:\Program Files\WindowsApps\Microsoft.BingSports_4.28.3242.0_x64__8wekyb3d8bbwe [2018-12-15] (Microsoft Corporation) [MS Ad]
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.28.10351.0_x64__8wekyb3d8bbwe [2019-02-12] (Microsoft Corporation) [MS Ad]
PAC-MAN Battle -> C:\Program Files\WindowsApps\50867PocketKingGames.PAC-MANBattle_1.1.0.0_x64__m8bdd0rdw5vr0 [2018-12-15] (Pocket King Games) [MS Ad]
The Backgammon -> C:\Program Files\WindowsApps\6918E89D.TheBackgammon_1.2.0.0_x64__66n08swfvvka0 [2018-12-15] (UNBALANCE corp.) [MS Ad]
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.Twitter_6.1.4.1000_neutral__wgeqdkkx372wm [2018-09-08] (Twitter Inc.)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1593158232-969496310-2340663774-1001_Classes\CLSID\{5A9E21A2-851A-4BEB-B16F-DBBE7D648AF9}\InprocServer32 -> C:\Program Files\TextPad 8\System\ShellExt64.dll (Helios Software Solutions Ltd -> )
SSODL: WDFSMountNotificator-wdfsconnect2017 - {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2} - C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll (Western Digital Technologies, Inc.) [File not signed]
SSODL-x32: WDFSMountNotificator-wdfsconnect2017 - {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2} - C:\WINDOWS\SysWOW64\wdfsconnectMntNtf2017.dll (Western Digital Technologies, Inc.) [File not signed]
ShellServiceObjects: Virtual Storage Mount Notification -> {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2} => C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll [2017-11-10] (Western Digital Technologies, Inc.) [File not signed]
ShellServiceObjects-x32: Virtual Storage Mount Notification -> {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2} => C:\WINDOWS\SysWOW64\wdfsconnectMntNtf2017.dll [2017-11-10] (Western Digital Technologies, Inc.) [File not signed]
ShellIconOverlayIdentifiers: [  WDDesktopIconOverlay01] -> {4F8A325E-9DAF-44B8-A825-1A14DFA0FA78} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [  WDDesktopIconOverlay02] -> {0176BDDE-B59A-4A1E-808B-CAD461415CCA} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [  WDDesktopIconOverlay03] -> {B65909D1-57AF-41F5-AB94-BEB733F62B35} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [  WDDesktopIconOverlay04] -> {C6C2397D-8238-4332-8935-86C39C7C165F} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [  WDDesktopIconOverlay05] -> {E7B3BCF9-0386-4B5F-AE6A-91B9F1423973} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [  WDDesktopIconOverlay06] -> {564EA121-D9DA-485D-82C2-C2ED7BFCCEAD} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2016-04-27] (CyberLink Corp. -> Cyberlink)
ContextMenuHandlers1: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\ShellEx.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers1: [WDDesktopContextMenu] -> {4961b028-350a-3bb9-9d6c-079dc724e5f0} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2016-04-27] (CyberLink Corp. -> Cyberlink)
ContextMenuHandlers2: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\ShellEx.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers4: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\ShellEx.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers4: [WDDesktopContextMenu] -> {4961b028-350a-3bb9-9d6c-079dc724e5f0} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\ki127171.inf_amd64_368f8c7337214025\igfxDTCM.dll [2018-03-22] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\ShellEx.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers1_S-1-5-21-1593158232-969496310-2340663774-1001: [TextPad8] -> {5A9E21A2-851A-4BEB-B16F-DBBE7D648AF9} => C:\Program Files\TextPad 8\System\ShellExt64.dll [2016-02-28] (Helios Software Solutions Ltd -> )
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2016-08-09 19:32 - 2015-06-29 20:13 - 000151552 _____ () [File not signed] C:\Program Files (x86)\DELL\DELLOSD\DellOSDService.exe
2016-08-09 19:32 - 2015-06-29 20:09 - 000548864 _____ () [File not signed] C:\Program Files (x86)\DELL\DELLOSD\MediaButtons.exe
2015-05-19 12:11 - 2015-05-19 12:11 - 000007680 _____ () [File not signed] C:\Program Files (x86)\Intel\Intel® Security Assist\isaHelperService.exe
2019-01-21 07:55 - 2019-01-21 07:55 - 000251392 _____ () [File not signed] C:\Program Files (x86)\NordVPN\x86\Liberation.Native.Firewall.dll
2016-03-25 23:50 - 2016-03-25 23:50 - 001491968 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\VMware\VMware Horizon View Client\bin\LIBEAY32.dll
2016-03-25 23:50 - 2016-03-25 23:50 - 000298496 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\VMware\VMware Horizon View Client\bin\SSLEAY32.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\.DEFAULT\...\localhost -> localhost
IE trusted site: HKU\.DEFAULT\...\webcompanion.com -> hxxp://webcompanion.com
IE trusted site: HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\webcompanion.com -> hxxp://webcompanion.com
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2015-10-30 03:24 - 2019-01-10 23:55 - 000002507 _____ C:\WINDOWS\system32\drivers\etc\hosts
 
0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
0.0.0.0 media.opencandy.com
0.0.0.0 cdn.opencandy.com
0.0.0.0 tracking.opencandy.com
0.0.0.0 api.opencandy.com
0.0.0.0 api.recommendedsw.com
0.0.0.0 rp.yefeneri2.com
0.0.0.0 os.yefeneri2.com
0.0.0.0 os2.yefeneri2.com
0.0.0.0 installer.betterinstaller.com
0.0.0.0 installer.filebulldog.com
0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
0.0.0.0 inno.bisrv.com
0.0.0.0 nsis.bisrv.com
0.0.0.0 cdn.file2desktop.com
0.0.0.0 cdn.goateastcach.us
0.0.0.0 cdn.guttastatdk.us
0.0.0.0 cdn.inskinmedia.com
0.0.0.0 cdn.insta.oibundles2.com
0.0.0.0 cdn.insta.playbryte.com
0.0.0.0 cdn.llogetfastcach.us
0.0.0.0 cdn.montiera.com
0.0.0.0 cdn.msdwnld.com
0.0.0.0 cdn.mypcbackup.com
0.0.0.0 cdn.ppdownload.com
0.0.0.0 cdn.riceateastcach.us
0.0.0.0 cdn.shyapotato.us
0.0.0.0 cdn.solimba.com
0.0.0.0 cdn.tuto4pc.com
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Data Protection\Drivers\TSS\bin\;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL;C:\Program Files\Intel\Intel® Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT;C:\Program Files\Intel\Intel® Management Engine Components\IPT;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\indre\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Warn)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
If an entry is included in the fixlist, it will be removed.
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{F26FF42A-FABC-4237-AF27-9A74BAD6E0C7}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [UDP Query User{B71B19F6-E012-4D87-BC64-170CDB9AE748}C:\program files\itunes\itunes.exe] => (Allow) C:\program files\itunes\itunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [TCP Query User{FF6FAF1B-3C9B-4453-9D51-82A62172D810}C:\program files\itunes\itunes.exe] => (Allow) C:\program files\itunes\itunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{6A551C3A-B926-43D8-9A75-06A3CEEB5AAF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{AD297B5D-2C9A-4E26-9193-5DEFE2B8D5DD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{6CC73312-41C6-4002-A0B0-4F73A84DBE2F}] => (Allow) LPort=8888
FirewallRules: [{277A97E1-8E11-4C68-985D-B7CC9AFC4A42}] => (Allow) LPort=8888
FirewallRules: [{B768845C-68FA-4F5D-8CB0-8915F5518FBE}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe (Intel® Wireless Display -> Intel)
FirewallRules: [TCP Query User{3696DD75-4C0C-490B-A914-59C0D82CE209}C:\program files (x86)\vmware\vmware horizon view client\vmware-remotemks.exe] => (Allow) C:\program files (x86)\vmware\vmware horizon view client\vmware-remotemks.exe (VMware, Inc. -> VMware, Inc.)
FirewallRules: [UDP Query User{881A5D70-E076-4553-AFB1-5DCEB88E106E}C:\program files (x86)\vmware\vmware horizon view client\vmware-remotemks.exe] => (Allow) C:\program files (x86)\vmware\vmware horizon view client\vmware-remotemks.exe (VMware, Inc. -> VMware, Inc.)
FirewallRules: [TCP Query User{56C4283E-A791-4CBC-9F68-AC60C8E0C7B4}C:\users\indre\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\indre\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{1DC4DC8A-7F42-44CE-9FE4-78B806402CE0}C:\users\indre\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\indre\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{3E499D19-4DBA-4DEF-8CF8-19DA405CDB89}] => (Block) C:\users\indre\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{69A76876-400F-4C97-9AC9-188D74D4DEA6}] => (Block) C:\users\indre\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{FE7FEA92-FE61-4E07-AB28-B07698433507}] => (Allow) LPort=8889
FirewallRules: [TCP Query User{5BEC10D3-14A2-4D91-86E2-3FF9AC49678E}C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe] => (Allow) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe No File
FirewallRules: [UDP Query User{DC37BDA6-DFD4-4AE9-A106-AF2D1149CAC6}C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe] => (Allow) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe No File
FirewallRules: [{2F7C3E13-8189-49BC-AD54-293606BAB75F}] => (Block) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe No File
FirewallRules: [{2A5D3459-4437-4C54-AAC4-9E96FEE61614}] => (Block) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe No File
FirewallRules: [{DED84BE3-3BD6-4E0D-A420-B30E49FC626F}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{56381F91-7873-4CEA-8ABE-E10213107A2E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{835008C9-6A51-4365-AFEC-F24E67C44C2E}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe (Plex, Inc -> Plex, Inc.)
FirewallRules: [{B9F683A9-6869-4425-ACDF-4BBE734023A1}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe (Plex, Inc -> Python Software Foundation)
FirewallRules: [{73C29C77-9A88-433D-8F93-2CEF6E260A57}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex DLNA Server.exe (Plex, Inc -> Plex, Inc.)
FirewallRules: [{FCB7161E-863C-4365-A934-94FC0E83A38E}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex Tuner Service.exe (Plex, Inc -> )
FirewallRules: [{F52C8ACB-334D-404D-AC77-F60981439024}] => (Allow) C:\Program Files\iTunes\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{35F1740E-5C7F-48A0-9424-553F25A67238}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{4D93D1F7-7788-460E-AB49-CA919F927793}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe (Intel Corporation -> )
FirewallRules: [{F29C6F66-709F-4614-A9A3-B60FCED2E26A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
 
==================== Restore Points =========================
 
20-06-2019 20:03:03 Windows Update
29-06-2019 20:49:28 Scheduled Checkpoint
10-07-2019 07:35:27 Windows Update
12-07-2019 11:29:53 Installed Macrium Reflect Free Edition
13-07-2019 13:08:02 O&O ShutUp10
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (07/13/2019 01:14:10 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
Description: Failed to schedule Software Protection service for re-start at 2119-06-19T17:14:10Z. Error Code: 0x80070005.
 
Error: (07/13/2019 01:13:40 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
Description: Failed to schedule Software Protection service for re-start at 2119-06-19T17:13:40Z. Error Code: 0x80070005.
 
Error: (07/13/2019 01:12:49 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
Description: Failed to schedule Software Protection service for re-start at 2119-06-19T17:12:49Z. Error Code: 0x80070005.
 
Error: (07/13/2019 01:12:19 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
Description: Failed to schedule Software Protection service for re-start at 2119-06-19T17:12:19Z. Error Code: 0x80070005.
 
Error: (07/12/2019 06:54:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IAStorDataMgrSvc.exe, version: 14.8.9.1053, time stamp: 0x5718affa
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x04e1efcd
Faulting process id: 0x40fc
Faulting application start time: 0x01d53904b6f86c23
Faulting application path: C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
Faulting module path: unknown
Report Id: 0d1e7d93-ab79-4603-8b5f-cff08156946e
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (07/12/2019 06:54:11 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: IAStorDataMgrSvc.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.NullReferenceException
   at IAStorUtil.SystemDataModelListener.ProcessSystemDataModelChanges()
   at IAStorUtil.SystemDataModelListener.LoadSavedSystemState()
   at IAStorDataMgr.EventRelay.<Start>b__0(System.Object)
   at System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
   at System.Threading.ThreadPoolWorkQueue.Dispatch()
   at System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()
 
 
System errors:
=============
Error: (07/13/2019 09:36:40 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
Windows.SecurityCenter.WscBrokerManager
 and APPID 
Unavailable
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/13/2019 09:35:06 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-EL88UDV)
Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
Windows.SecurityCenter.WscCloudBackupProvider
 and APPID 
Unavailable
 to the user DESKTOP-EL88UDV\indre SID (S-1-5-21-1593158232-969496310-2340663774-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/13/2019 09:35:05 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-EL88UDV)
Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
Windows.SecurityCenter.WscCloudBackupProvider
 and APPID 
Unavailable
 to the user DESKTOP-EL88UDV\indre SID (S-1-5-21-1593158232-969496310-2340663774-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/13/2019 09:35:05 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-EL88UDV)
Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
Windows.SecurityCenter.WscCloudBackupProvider
 and APPID 
Unavailable
 to the user DESKTOP-EL88UDV\indre SID (S-1-5-21-1593158232-969496310-2340663774-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/13/2019 09:35:05 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-EL88UDV)
Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
Windows.SecurityCenter.WscCloudBackupProvider
 and APPID 
Unavailable
 to the user DESKTOP-EL88UDV\indre SID (S-1-5-21-1593158232-969496310-2340663774-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/13/2019 09:34:39 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-EL88UDV)
Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{7022A3B3-D004-4F52-AF11-E9E987FEE25F}
 and APPID 
{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}
 to the user DESKTOP-EL88UDV\indre SID (S-1-5-21-1593158232-969496310-2340663774-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/13/2019 09:34:38 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/13/2019 09:34:38 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
 
CodeIntegrity:
===================================
 
Date: 2019-07-13 00:26:54.793
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\Installer\MSIEC59.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2019-07-13 00:24:49.728
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\Installer\MSI37B.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
==================== Memory info =========================== 
 
BIOS: Dell Inc. 1.8.6 12/12/2017
Motherboard: Dell Inc. 0X2MKR
Processor: Intel® Core™ i7-6700 CPU @ 3.40GHz
Percentage of memory in use: 51%
Total physical RAM: 8048.94 MB
Available physical RAM: 3908.12 MB
Total Virtual: 9840.94 MB
Available Virtual: 4861.68 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:224.73 GB) (Free:96.53 GB) NTFS
Drive e: (My Passport) (Fixed) (Total:1862.98 GB) (Free:1815.01 GB) NTFS
 
\\?\Volume{a8007518-d8a3-4a74-92ee-2363fddb05a7}\ (WINRETOOLS) (Fixed) (Total:0.44 GB) (Free:0.06 GB) NTFS
\\?\Volume{616afac5-ee60-493d-8f6b-5152f9f29468}\ (Image) (Fixed) (Total:12.69 GB) (Free:0.63 GB) NTFS
\\?\Volume{dbd7410f-196c-49b5-bb90-bbf877a175c2}\ (ESP) (Fixed) (Total:0.48 GB) (Free:0.44 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: 4FCEFFCB)
 
Partition: GPT.
 
========================================================
Disk: 1 (Size: 1863 GB) (Disk ID: 16F2A91F)
 
Partition: GPT.
 
==================== End of Addition.txt ============================
 
************************************************************************************************************
 
Thank you, as always!

 

  • 0

#40
RKinner

RKinner

    Malware Expert

  • Expert
  • 21,737 posts
  • MVP

You can turn off the autoplay:

 

https://www.techrepu...-in-windows-10/

 

It looks like you may be a bit behind in your updates.  My Win 10 is version 1903 while yours is 1803 or so FRST claims.  There was a version 1806 between 1803 and 1903 so you may not be able to get an automatic update but check in your PC Settings, Update and Security, Windows Updates -Check For Updates  see if they offer you an upgrade.  (Sometimes it helps to remove your USB drive - there was some bug that lost the letters of attached USB drives earlier this year - don't know if they have fixed it or not but because of the bug they stopped offering the update if there was a USB drive connected.)  If you are too many versions behind they may not offer the update.  I had one that was 1511 and I had to download the update manually.


  • 0

Advertisements


#41
IndyBlue

IndyBlue

    Member

  • Topic Starter
  • Member
  • PipPip
  • 95 posts

OK, I did everything you told me to do (it took awhile because of the Windows Update. Here's what I did:

 

(1) I updated to Win 10 version 1903.

 

(2) I then ran the OOSU10.exe but, like an idiot, I didn't reread your instructions. I didn't run it as an admin; I stupidly forgot to make a restoration point; and I accepted all recommended changes. Hopefully, I didn't screw up anything.

(3) I then followed the instructions to turn off the autoplay settings.

(4) Finally, I rebooted the system again.

Fingers crossed that all is well! Below are the FARBAR scans.

(1) FRST scan: 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 13-07-2019
Ran by indre (administrator) on DESKTOP-EL88UDV (Dell Inc. OptiPlex 7440 AIO) (14-07-2019 01:42:48)
Running from C:\Users\indre\Desktop
Loaded Profiles: indre (Available Profiles: indre)
Platform: Windows 10 Pro Version 1903 18362.239 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
() [File not signed] C:\Program Files (x86)\DELL\DELLOSD\DellOSDService.exe
() [File not signed] C:\Program Files (x86)\DELL\DELLOSD\MediaButtons.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(CyberLink Corp. -> CyberLink) C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvc_P2G8.exe
(CyberLink Corp. -> CyberLink) C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Dell Inc -> CREDANT Technologies, Inc.) C:\Program Files\Dell\Dell Data Protection\Client Security Framework\Dell.SecurityFramework.Agent.exe
(Dell Inc -> CREDANT Technologies, Inc.) C:\Program Files\Dell\Dell Data Protection\Client Security Framework\Dell.SecurityFramework.UserProcess.exe
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\Dell Data Protection\Client Security Framework\DCF.Loader.exe
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe
(Dell Inc -> Dell, Inc.) C:\Program Files\Dell\Dell Data Protection\Client Security Framework\Dell.SecurityFramework.LocalServer.exe
(Dell Inc. -> Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(Dell Inc. -> Dell Products, LP.) C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
(FabulaTech -> ) C:\Program Files (x86)\VMware\ScannerRedirection\ftscanmgr.exe
(FabulaTech -> ) C:\Program Files\Common Files\VMware\DeviceRedirectionCommon\ftnlsv.exe
(FabulaTech -> VMware) C:\Program Files (x86)\Common Files\VMware\SerialPortRedirection\Client\vmwsprrdpwks.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler64.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel® Security Assist\isa.exe
(Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PrivacyIconClient.exe
(Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel® Intel Network Drivers -> Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127171.inf_amd64_368f8c7337214025\igfxCUIService.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127171.inf_amd64_368f8c7337214025\igfxEM.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127171.inf_amd64_368f8c7337214025\IntelCpHDCPSvc.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127171.inf_amd64_368f8c7337214025\IntelCpHeciSvc.exe
(Intel® Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Intel® Wireless Display -> Intel) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksde.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksdeui.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\avp.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\avpui.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\indre\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c\SkypeApp.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.WindowsStore_11905.1001.4.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.18362.235_none_5f42305c58dc2c51\TiWorker.exe
(PC-Doctor, Inc. -> PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7033.2285\DSAPI.exe
(PC-Doctor, Inc. -> PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7033.2285\pcdrwi.exe
(Plex, Inc -> ) C:\Program Files (x86)\Plex\Plex Media Server\Plex Tuner Service.exe
(Plex, Inc -> Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex DLNA Server.exe
(Plex, Inc -> Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe
(Plex, Inc -> Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe
(Plex, Inc -> Python Software Foundation) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
(Plex, Inc -> Python Software Foundation) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(TEFINCOM S.A. -> ) C:\Program Files (x86)\NordVPN\nordvpn-service.exe
(TEFINCOM S.A. -> NordVPN) C:\Program Files (x86)\NordVPN\NordVPN.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\VMware\VMware Horizon View Client\bin\vmware-view-usbd.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\VMware\VMware Horizon View Client\wsnm\wsnm.exe
(Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe
(Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe
(Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD App Manager\Plugins\WD Backup\App\WDBackupService.exe
(Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD App Manager\WDAppManager.exe
(Western Digital Techologies -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8853248 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_MAXX6] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1419008 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [VMware Netlink 3 HV Install Utility] => C:\Program Files\Common Files\VMware\DeviceRedirectionCommon\ftnliu.exe [70080 2015-11-04] (FabulaTech -> )
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [302904 2019-05-07] (Apple Inc. -> Apple Inc.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [322120 2019-03-15] (Intel® Rapid Storage Technology -> Intel Corporation)
HKLM\...\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [718256 2015-12-22] (Waves Inc -> Waves Audio Ltd.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942864 2016-10-13] (Logitech -> Logitech, Inc.)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PrivacyIconClient.exe [1176208 2017-11-09] (Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation)
HKLM-x32\...\Run: [WDDiscovery] => C:\Program Files (x86)\Western Digital\Discovery\Current\WD Discovery.exe [81376496 2019-07-12] (Western Digital Technologies, Inc. -> Western Digital Corporation)
HKLM-x32\...\Run: [WDAppManager] => C:\Program Files (x86)\Western Digital\WD App Manager\AppManagerLauncher.exe [21888 2019-01-02] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\Run: [Plex Media Server] => C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe [23081448 2019-04-04] (Plex, Inc -> Plex, Inc.)
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\Run: [NordVPN] => C:\Program Files (x86)\NordVPN\NordVPN.exe [2186704 2019-05-22] (TEFINCOM S.A. -> NordVPN)
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\Run: [kpm.exe] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe [584128 2019-02-08] (Kaspersky Lab -> AO Kaspersky Lab)
HKLM\...\Drivers32-x32: [vidc.pDAD] => prodad-codec.dll
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.100\Installer\chrmstp.exe [2019-06-20] (Google LLC -> Google LLC)
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {03DFFC2C-FC22-4010-99E9-4F38D03C4728} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [113200 2019-07-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {06D92E0E-08B8-441B-94A2-7B231EE6DCE1} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26804232 2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {08E2F16C-4C59-4C34-A03C-C83EEEDEBBDE} - System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec-Logon => C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-17] (Intel® Software Asset Manager -> Intel Corporation)
Task: {0C0614F0-18B6-495C-99F1-B61633EE7B2A} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel® Update Manager\bin\iumsvc.exe
Task: {0EBA0793-94A7-49CE-AB2C-1FEF6BA70765} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26804232 2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {0FE0644F-58F4-43E8-A63F-AA62CD169246} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {1D566C7D-1CD5-4E77-826C-E0DF557F6BFA} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_223_Plugin.exe [1457208 2019-07-10] (Adobe Inc. -> Adobe)
Task: {1E20F289-46AA-4529-B808-962BFEF268A3} - System32\Tasks\RtHDVBg_PushButton => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1419008 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {1E4AE78B-2D84-403D-9CD3-0703770FF0B5} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [113200 2019-07-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {267B2E60-3693-45B1-B32D-E5AA4FA083F4} - System32\Tasks\WD Discovery Service Task indre => C:\Program Files (x86)\Western Digital\Discovery\Current\Service\WDDiscoveryService.exe [71408 2019-07-12] (Western Digital Technologies, Inc. -> )
Task: {27CEA27E-1BF2-4A16-B5AE-DCA79020DF0D} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [816960 2017-10-11] (Intel® Trust Services -> Intel® Corporation)
Task: {2BE02930-09E5-4DB5-86B2-C883307D310D} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_223_pepper.exe [1453112 2019-07-10] (Adobe Inc. -> Adobe)
Task: {39820E81-9B7D-411F-A870-C6BEBCB2BF30} - System32\Tasks\Intel\Intel Telemetry 2 => C:\Program Files\Intel\Telemetry 2.0\lrio.exe [1698000 2015-06-05] (Intel® Software -> Intel Corporation)
Task: {4DF09A94-B680-4D73-A2BA-B28905CCA70D} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [39920 2018-10-24] (Garmin International, Inc. -> )
Task: {52187049-A19C-4B23-AFFC-5089227DB2E9} - System32\Tasks\Seagate_Install_Launch => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Dashboard.exe
Task: {5EF9065E-7942-4205-9A7E-625FDF39B32F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [136056 2019-01-02] (HP Inc. -> HP Inc.)
Task: {6D0AA64B-75B4-49CF-9C53-3BF5D9356A9D} - System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec => C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-17] (Intel® Software Asset Manager -> Intel Corporation)
Task: {82F39D33-C846-4F84-8898-8F68198ADD97} - System32\Tasks\CLVDLauncher => C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLVDLauncher.exe [340440 2015-01-28] (CyberLink Corp. -> CyberLink Corp.)
Task: {8B3F29DA-404A-4CB9-8309-9D94ECAA8D3F} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvc_P2G8.exe [110008 2016-04-27] (CyberLink Corp. -> CyberLink)
Task: {8D960D58-2C65-4690-A008-63A3B9664FD6} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [654712 2019-06-05] (HP Inc. -> HP Inc.)
Task: {A5585A2F-2224-44F3-B48A-C02AA6E9CD5D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-09-11] (Google Inc -> Google Inc.)
Task: {BE8068C1-2DB9-4BBE-9031-9E917FD77777} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1448296 2019-07-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {BEEC0D34-AA7B-4933-B79B-EE5F2DA284E3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-07-10] (Adobe Inc. -> Adobe)
Task: {C9DAB848-B95A-4118-8DAB-0AA8CAE862C4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1195544 2018-12-16] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Task: {DCF36F4E-53FF-403E-B92A-CAFE9380489C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616320 2018-01-08] (Apple Inc. -> Apple Inc.)
Task: {DD6E66AE-D0AA-4C99-8D5F-5BA39CA6FC45} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1448296 2019-07-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {ECD51CA1-564E-49C6-A83B-0A4B7EC42B15} - System32\Tasks\WD Device Agent Task indre => C:\Users\indre\AppData\Roaming\WD Discovery\plugins\com.wdc.plugin.catalog\current\library\WD Device Agent.exe [724008 2019-06-18] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
Task: {F219FE43-71D7-4843-8134-11FF7BD69ACF} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistInstaller.exe [1512920 2019-05-24] (Dell Inc. -> Dell Inc.)
Task: {F266FDCC-EAB9-4691-867D-FA95BDE06352} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [791232 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
Task: {F932D694-A1C8-4A80-9BEA-DAAFEF0B6FE1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-09-11] (Google Inc -> Google Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{28110dcb-4039-465c-840d-a703c58d8f0f}: [DhcpNameServer] 103.86.96.100 103.86.99.100
Tcpip\..\Interfaces\{6fbafdae-3f34-452d-bbc1-3182c4eed1fc}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{df5feca7-b365-4e54-a128-6afee4fc4200}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{eb569711-9ed4-49b4-a209-84f1068bb002}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell17win10.msn.com/?pc=DCTE
SearchScopes: HKU\S-1-5-21-1593158232-969496310-2340663774-1001 -> DefaultScope {97FF47F7-FF6D-4CCE-B19F-284086150FBF} URL = 
SearchScopes: HKU\S-1-5-21-1593158232-969496310-2340663774-1001 -> {97FF47F7-FF6D-4CCE-B19F-284086150FBF} URL = 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2019-06-25] (Microsoft Corporation -> Microsoft Corporation)
BHO: No Name -> {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2}' -> No File
BHO: Kaspersky Protection -> {EC1E29BB-F56A-45D8-B023-D3EF710FA0E0} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
BHO: Kaspersky Password Manager -> {F710F7E5-A520-471D-989C-F653AC328FB2} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\x64\ie_engine.dll [2019-05-08] (Kaspersky Lab -> AO Kaspersky Lab)
BHO-x32: No Name -> {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2}' -> No File
BHO-x32: CutePDF Form Filler Helper -> {D41289F2-69C6-417B-897E-C653D677CBAF} -> C:\Program Files (x86)\Acro Software\CutePDF Filler Evaluation\CPFillerCoE.dll [2014-03-27] (Acro Software Inc. -> Acro Software Inc.)
BHO-x32: Kaspersky Protection -> {EC1E29BB-F56A-45D8-B023-D3EF710FA0E0} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
BHO-x32: Kaspersky Password Manager -> {F710F7E5-A520-471D-989C-F653AC328FB2} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\ie_engine.dll [2019-05-08] (Kaspersky Lab -> AO Kaspersky Lab)
Toolbar: HKLM - Kaspersky Protection Toolbar - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
Toolbar: HKLM-x32 - Kaspersky Protection Toolbar - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
Toolbar: HKU\S-1-5-21-1593158232-969496310-2340663774-1001 -> Kaspersky Protection Toolbar - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} hxxps://meetny.webex.com/client/WBXclient-T30L10NSP6EP6-20000/webex/ieatgpc1.cab
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-06-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-06-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-06-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-06-02] (Microsoft Corporation -> Microsoft Corporation)
 
FireFox:
========
FF DefaultProfile: 1cu7vqt4.default-1534000050440
FF ProfilePath: C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440 [2019-07-11]
FF Homepage: Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440 -> hxxps://www.google.com/
FF Extension: (ETP Search Volume Study) - C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440\Extensions\[email protected] [2019-06-26]
FF Extension: (Notifier for Gmail™) - C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440\Extensions\[email protected] [2019-03-31]
FF Extension: (Honey) - C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440\Extensions\[email protected] [2019-05-18]
FF Extension: (Kaspersky Password Manager) - C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440\Extensions\[email protected] [2019-05-08] [UpdateUrl:hxxps://special.s.kaspersky-labs.com/firefox_extensions/kpm_win_add_on/update.json]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Extension: (Kaspersky Protection) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\FFExt\light_plugin_firefox\addon.xpi [2019-07-06]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_223.dll [2019-07-10] (Adobe Inc. -> )
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_223.dll [2019-07-10] (Adobe Inc. -> )
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2019-04-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-14] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-14] (Google Inc -> Google LLC)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-05-02] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1593158232-969496310-2340663774-1001: @zoom.us/ZoomVideoPlugin -> C:\Users\indre\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2018-04-06] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\kl_prefs_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.js [2019-07-07] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\kl_config_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.cfg [2019-07-07] <==== ATTENTION
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default [2019-07-14]
CHR Extension: (Slides) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-12]
CHR Extension: (Kaspersky Protection) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\amkpcclbbgegoafihnpgomddadjhcadd [2019-07-06]
CHR Extension: (Docs) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12]
CHR Extension: (Google Drive) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-09-11]
CHR Extension: (YouTube) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-09-11]
CHR Extension: (Honey) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2019-07-11]
CHR Extension: (uBlock Origin) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2019-07-13]
CHR Extension: (Notifier for Gmail™) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcjichoefijpinlfnjghokpkojhlhkgl [2019-03-25]
CHR Extension: (Kaspersky Password Manager) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhnkblpjbkfklfloegejegedcafpliaa [2019-07-12]
CHR Extension: (Adobe Acrobat) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2019-06-11]
CHR Extension: (Sheets) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-12]
CHR Extension: (Google Docs Offline) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-22]
CHR Extension: (Avast Online Security) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2019-07-01]
CHR Extension: (F.B.(FluffBusting)Purity) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmkinhboiljjkhaknpaeaicmdjhagpep [2019-07-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-07]
CHR Extension: (Gmail) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-03-26]
CHR Extension: (Chrome Media Router) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-06-20]
CHR Profile: C:\Users\indre\AppData\Local\Google\Chrome\User Data\Guest Profile [2019-07-08]
CHR Profile: C:\Users\indre\AppData\Local\Google\Chrome\User Data\System Profile [2019-07-08]
CHR HKLM\...\Chrome\Extension: [amkpcclbbgegoafihnpgomddadjhcadd] - hxxps://chrome.google.com/webstore/detail/amkpcclbbgegoafihnpgomddadjhcadd
CHR HKU\S-1-5-21-1593158232-969496310-2340663774-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhnkblpjbkfklfloegejegedcafpliaa] - hxxps://chrome.google.com/webstore/detail/dhnkblpjbkfklfloegejegedcafpliaa
CHR HKLM-x32\...\Chrome\Extension: [amkpcclbbgegoafihnpgomddadjhcadd] - hxxps://chrome.google.com/webstore/detail/amkpcclbbgegoafihnpgomddadjhcadd
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [96056 2019-04-29] (Apple Inc. -> Apple Inc.)
R2 AVP19.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\avp.exe [619640 2018-02-28] (Kaspersky Lab -> AO Kaspersky Lab)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11413600 2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
S4 dcu-oobe; C:\Program Files (x86)\Dell\CommandUpdate\OobeService.exe [84408 2016-06-07] (Dell Inc. -> Dell Inc.)
R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [209392 2019-02-28] (Dell Inc -> Dell Inc.)
R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3363824 2019-02-28] (Dell Inc -> Dell Inc.)
R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [218096 2019-02-28] (Dell Inc -> Dell Inc.)
R2 Dell Hardware Support; C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7033.2285\DSAPI.exe [1050952 2019-06-02] (PC-Doctor, Inc. -> PC-Doctor, Inc.)
R2 Dell WMI Service; C:\Program Files (x86)\DELL\DELLOSD\DellOSDService.exe [151552 2015-06-29] () [File not signed]
R2 DellMgmtAgent; C:\Program Files\Dell\Dell Data Protection\Client Security Framework\Dell.SecurityFramework.Agent.exe [22280 2016-07-13] (Dell Inc -> CREDANT Technologies, Inc.)
R2 DellMgmtLoader; C:\Program Files\Dell\Dell Data Protection\Client Security Framework\DCF.Loader.exe [35080 2016-07-13] (Dell Inc -> Dell Inc.)
R3 DellMgmtServer; C:\Program Files\Dell\Dell Data Protection\Client Security Framework\Dell.SecurityFramework.LocalServer.exe [52488 2016-07-13] (Dell Inc -> Dell, Inc.)
R2 ftnlsv3hv; C:\Program Files\Common Files\VMware\DeviceRedirectionCommon\ftnlsv.exe [233920 2015-11-04] (FabulaTech -> )
R2 ftscanmgr; C:\Program Files (x86)\VMware\ScannerRedirection\ftscanmgr.exe [6363792 2015-07-31] (FabulaTech -> )
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [356728 2019-06-12] (HP Inc. -> HP Inc.)
S2 iaStorAfsService; C:\WINDOWS\IAStorAfsService\iaStorAfsService.exe [2413752 2017-08-18] (Intel® Rapid Storage Technology -> Intel Corporation)
R2 ibtsiva; C:\WINDOWS\system32\ibtsiva.exe [190208 2016-10-15] (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation)
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [742704 2017-10-11] (Intel® Trust Services -> Intel® Corporation)
R3 Intel® Security Assist; C:\Program Files (x86)\Intel\Intel® Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed]
S2 Intel® TPM Provisioning Service; C:\Program Files\Intel\iCLS Client\TPMProvisioningService.exe [668472 2017-10-11] (Intel® Trust Services -> Intel® Corporation)
S3 Intel® WiDi SAM; C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-17] (Intel® Software Asset Manager -> Intel Corporation)
R2 IntelUSBoverIP; C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe [396992 2015-07-06] (Intel® Wireless Display -> Intel)
S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel® Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [213648 2017-11-09] (Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation)
S3 klvssbridge64_19.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\vssbridge64.exe [414352 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R2 kpm_launch_service; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe [354008 2019-02-08] (Kaspersky Lab -> AO Kaspersky Lab)
R2 KSDE3.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksde.exe [617016 2018-02-28] (Kaspersky Lab -> AO Kaspersky Lab)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [310880 2019-01-23] (Intel Corporation -> )
R2 nordvpn-service; C:\Program Files (x86)\NordVPN\nordvpn-service.exe [217040 2019-05-22] (TEFINCOM S.A. -> )
R2 PlexUpdateService; C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe [1140200 2019-04-04] (Plex, Inc -> Plex, Inc.)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [253776 2015-09-02] (CyberLink Corp. -> CyberLink)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [310016 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5773384 2019-07-14] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [39896 2019-05-24] (Dell Inc. -> Dell Inc.)
S2 tcsd_win32.exe; C:\Program Files\Dell\Dell Data Protection\Drivers\TSS\bin\tcsd_win32.exe [1636352 2012-12-10] (Security Innovation, Inc.) [File not signed]
R2 vmware-view-usbd; C:\Program Files (x86)\VMware\VMware Horizon View Client\bin\vmware-view-usbd.exe [1158984 2016-02-23] (VMware, Inc. -> VMware, Inc.)
R2 vmwsprrdpwks; C:\Program Files (x86)\Common Files\VMware\SerialPortRedirection\Client\vmwsprrdpwks.exe [261776 2015-05-08] (FabulaTech -> VMware)
R2 WavesSysSvc; C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe [613296 2015-12-22] (Waves Inc -> Waves Audio Ltd.)
S3 WD Backup Drive Helper; C:\WINDOWS\SysWOW64\dllhost.exe /Processid:{4AB831D3-8315-414C-8A7A-303105288D0B} [19256 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
S3 WD Backup Drive Helper; C:\WINDOWS\SysWOW64\dllhost.exe /Processid:{4AB831D3-8315-414C-8A7A-303105288D0B} [19256 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
S3 WD Backup Snapshot; C:\WINDOWS\SysWOW64\dllhost.exe /Processid:{302480DF-3AC5-4400-BE7B-DD77AF93B6DD} [19256 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
S3 WD Backup Snapshot; C:\WINDOWS\SysWOW64\dllhost.exe /Processid:{302480DF-3AC5-4400-BE7B-DD77AF93B6DD} [19256 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [524632 2018-03-26] (Western Digital Techologies -> Western Digital Technologies, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [4098056 2019-03-19] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [113992 2019-03-19] (Microsoft Corporation -> Microsoft Corporation)
R2 wsnm; C:\Program Files (x86)\VMware\VMware Horizon View Client\wsnm\wsnm.exe [541400 2016-03-25] (VMware, Inc. -> VMware, Inc.)
S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [4107360 2019-01-23] (Intel Corporation -> Intel® Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R0 cm_km; C:\WINDOWS\System32\DRIVERS\cm_km.sys [243400 2018-01-27] (Kaspersky Lab -> AO Kaspersky Lab)
R3 DDDriver; C:\WINDOWS\System32\drivers\dddriver64Dcsa.sys [40824 2019-02-27] (Microsoft Windows Hardware Compatibility Publisher -> Dell Inc.)
S3 DellProf; C:\WINDOWS\system32\drivers\DellProf.sys [41208 2018-05-08] (Techporch Incorporated -> Dell Computer Corporation)
R0 iaStorAfs; C:\WINDOWS\System32\drivers\iaStorAfs.sys [70664 2017-08-18] (Intel® Rapid Storage Technology -> Intel Corporation)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [732416 2016-10-15] (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation)
R3 IntcAzAudAddService; C:\WINDOWS\system32\drivers\RTDVHD64.sys [2677504 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.)
R0 klbackupdisk; C:\WINDOWS\System32\DRIVERS\klbackupdisk.sys [75600 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klbackupflt; C:\WINDOWS\System32\DRIVERS\klbackupflt.sys [125568 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [91472 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
S0 klelam; C:\WINDOWS\System32\DRIVERS\klelam.sys [29208 2017-03-30] (Microsoft Windows Early Launch Anti-malware Publisher -> AO Kaspersky Lab)
R3 klflt; C:\WINDOWS\system32\DRIVERS\klflt.sys [236672 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klhk; C:\WINDOWS\System32\drivers\klhk.sys [1093248 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klids; C:\ProgramData\Kaspersky Lab\AVP19.0.0\Bases\klids.sys [197464 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [1168000 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klim6; C:\WINDOWS\system32\DRIVERS\klim6.sys [58704 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klkbdflt; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [60536 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klmouflt; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [60784 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klpd; C:\WINDOWS\System32\DRIVERS\klpd.sys [50304 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klpnpflt; C:\WINDOWS\system32\DRIVERS\klpnpflt.sys [46416 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 kltap; C:\WINDOWS\System32\drivers\kltap.sys [48080 2018-02-12] (AnchorFree Inc -> The OpenVPN Project)
R0 klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [245272 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klupd_klif_kimul; C:\WINDOWS\System32\Drivers\klupd_klif_kimul.sys [99152 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [302368 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R0 klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [116104 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [198768 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [104576 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klwtp; C:\WINDOWS\system32\DRIVERS\klwtp.sys [184960 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [218240 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 Netwtw06; C:\WINDOWS\System32\drivers\Netwtw06.sys [8832800 2019-05-17] (Intel® Wireless Connectivity Solutions -> Intel Corporation)
R3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [779232 2016-08-04] (Realtek Semiconductor Corp. -> Realsil Semiconductor Corporation)
R0 SEDFilter; C:\WINDOWS\System32\DRIVERS\SEDFilter.sys [197808 2016-07-13] (Dell Inc -> Dell Inc.)
S3 SWDUMon; C:\WINDOWS\system32\DRIVERS\SWDUMon.sys [13920 2016-09-11] (SlimWare Utilities Inc. -> )
R3 tapnordvpn; C:\WINDOWS\System32\drivers\tapnordvpn.sys [44896 2018-07-24] (TEFINCOM S.A. -> The OpenVPN Project)
R3 usb3Hub; C:\WINDOWS\System32\drivers\usb3Hub.sys [212056 2015-07-06] (Intel® Wireless Display -> Windows ® Win 7 DDK provider)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46472 2019-03-19] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [333784 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
R1 wdfsconnect2017; C:\WINDOWS\system32\drivers\wdfsconnect2017.sys [468112 2017-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies, Inc.)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [62432 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
R3 wdvpnpbus; C:\WINDOWS\System32\drivers\wdvpnpbus.sys [20624 2017-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies, Inc.)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-07-14 05:05 - 2019-07-14 01:14 - 000000000 ____D C:\Windows.old
2019-07-14 04:54 - 2019-07-14 05:05 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2019-07-14 04:53 - 2019-07-14 04:54 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2019-07-14 04:53 - 2019-07-14 04:53 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2019-07-14 04:51 - 2019-07-14 04:51 - 025902080 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 025444864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 022625280 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 019849216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 019811328 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 018017792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 008011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 007802224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 007758336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 007175168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 007008768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 006218752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 005919744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 005745504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 005500416 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 005083352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 005014016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 004863488 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 004578816 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 004481536 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 004348408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 004306432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 004129416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 003837440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 003635200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 003525592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 003487232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 003365376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 003243080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 002956984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2019-07-14 04:51 - 2019-07-14 04:51 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2019-07-14 04:51 - 2019-07-14 04:51 - 002494232 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 002398208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 002314440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 002235936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 002216448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 002190648 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 002072152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001866064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001847808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsservices.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001715000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntVirtualization.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001611576 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVIntegration.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001608192 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001555688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001539584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001510960 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001501496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001493944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001391416 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 001383736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystemController.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001319936 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001283384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2019-07-14 04:51 - 2019-07-14 04:51 - 001282560 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001273344 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001273176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001248256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOE.DLL
2019-07-14 04:51 - 2019-07-14 04:51 - 001244728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001192096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 001151816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001124864 _____ (Microsoft Corporation) C:\WINDOWS\system32\CBDHSvc.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001105776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001098712 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001080832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001071928 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 001060352 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001043768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPolicy.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001039872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOE.DLL
2019-07-14 04:51 - 2019-07-14 04:51 - 001012792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001007104 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001000960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000986112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000957240 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVManifest.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000912896 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000875008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000843776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000833536 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000829544 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioIso.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000827192 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVOrchestration.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000816440 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntStreamingManager.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000813568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000806400 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000801592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2019-07-14 04:51 - 2019-07-14 04:51 - 000782120 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000774152 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000769336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000744248 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOE.DLL
2019-07-14 04:51 - 2019-07-14 04:51 - 000743424 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000741176 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVReporting.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000737552 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOD.DLL
2019-07-14 04:51 - 2019-07-14 04:51 - 000705536 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000700928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapi.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000682744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOE.DLL
2019-07-14 04:51 - 2019-07-14 04:51 - 000669496 _____ (Microsoft Corporation) C:\WINDOWS\system32\computecore.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000666280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOD.DLL
2019-07-14 04:51 - 2019-07-14 04:51 - 000665912 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVCatalog.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000649016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPublishing.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000612352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000568336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000551824 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000537608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000529408 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000516752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000510768 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000500224 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2019-07-14 04:51 - 2019-07-14 04:51 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpshell.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000496128 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000494904 _____ (Microsoft Corporation) C:\WINDOWS\system32\TransportDSA.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000472576 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedRealitySvc.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000463272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000460288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcSpecfc.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000450048 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000429568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000422912 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000422008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2019-07-14 04:51 - 2019-07-14 04:51 - 000420360 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000400896 _____ (Microsoft Corporation) C:\WINDOWS\system32\DispBroker.Desktop.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000394040 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVScripting.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\provplatformdesktop.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000382976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcLayers.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000376320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspbde40.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000366184 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000363008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000357376 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000333824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapibase.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000321024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.FileExplorer.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000317952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000316216 _____ (Microsoft Corporation) C:\WINDOWS\system32\computestorage.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000307200 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000300184 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscobj.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000294400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_AnalogShell.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000267528 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000261016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityUxHost.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000257848 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVFileSystemMetadata.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000257536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\provplatformdesktop.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\RdpRelayTransport.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msltus40.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000231432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVShNotify.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000228664 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVStreamMap.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
2019-07-14 04:51 - 2019-07-14 04:51 - 000210440 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000202752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cscobj.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000202552 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVStreamingUX.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000186880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
2019-07-14 04:51 - 2019-07-14 04:51 - 000183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngOnline.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000181560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVDllSurrogate.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000177664 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetpp.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000172856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVNice.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000136720 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-kernel-processor-power-events.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\appvetwclientres.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000129088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000099712 _____ (Microsoft Corporation) C:\WINDOWS\system32\FsIso.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000093496 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000093312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpfve.sys
2019-07-14 04:51 - 2019-07-14 04:51 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompMgmtLauncher.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmlib.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000088064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000084280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winhvr.sys
2019-07-14 04:51 - 2019-07-14 04:51 - 000084280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2019-07-14 04:51 - 2019-07-14 04:51 - 000078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000058825 _____ C:\WINDOWS\system32\srms.dat
2019-07-14 04:51 - 2019-07-14 04:51 - 000053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeUISrv.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000042296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000037904 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncAppvPublishingServer.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimsg.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000022024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ScriptRunner.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000021304 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\appvetwstreamingux.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 017786368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 014816256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 009917752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 007887440 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 007831368 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 007636616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 007275008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 007242312 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 006534712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 006381568 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 006224296 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 006068840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 006036480 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 005939712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 005071360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 005040640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 004562920 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 004552336 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 004537344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 004470784 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 004034048 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 004012032 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 004008960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Service.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003947520 _____ (Microsoft Corporation) C:\WINDOWS\system32\tellib.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003914480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 003771392 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003748864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003734456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003725312 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 003698176 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003654656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003590968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 003550720 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003372952 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003327256 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003263488 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003261440 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003106304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003084800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002990608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 002876416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002871824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 002870784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002798592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 002771008 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002763552 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002725376 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 002698552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 002697728 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002656768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002587328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002576384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002561536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002550584 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002490712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002449456 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002443264 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002321408 _____ (The ICU Project) C:\WINDOWS\system32\icu.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002306048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002281984 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002258336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002178048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmgaclient.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002117160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002081976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001999440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001979392 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001954960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001945600 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001940952 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001918976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001893888 _____ (The ICU Project) C:\WINDOWS\SysWOW64\icu.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001884672 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001856000 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001856000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConstraintIndex.Search.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001841152 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001830416 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001815040 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001784832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001781248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001761792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001754232 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2019-07-14 04:50 - 2019-07-14 04:50 - 001745920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001743672 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001721344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001721144 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001717560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001697792 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001697280 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001690624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001687552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001657856 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001651848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001647280 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001635328 _____ (Microsoft Corporation) C:\WINDOWS\system32\TaskFlowDataEngine.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001633648 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001608704 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001587712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001562640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001553408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmgaserver.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 001535288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001515008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmgaclient.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001509936 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 001505808 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpbase.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001480704 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpsharercom.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001473488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001458176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001437184 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 001422848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 001413704 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001413632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001395600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001393960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001375232 _____ (Microsoft Corporation) C:\WINDOWS\system32\APMon.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001366528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001366128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2019-07-14 04:50 - 2019-07-14 04:50 - 001362432 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001356800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001345024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001337656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001333248 _____ (Microsoft Corporation) C:\WINDOWS\system32\MiracastReceiver.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001321472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001313792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001304888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001282048 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsf3gip.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001262864 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001261568 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001260032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpsharercom.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001250432 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 001213456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpbase.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001182232 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 001159680 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001149928 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 001146880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001101312 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001092096 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001068856 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001067008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001065984 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001063944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001062912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmgaserver.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 001062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\BTAGService.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001042944 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2019-07-14 04:50 - 2019-07-14 04:50 - 001040896 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcRefreshTask.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001010176 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001007160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001006592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000984376 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000947200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000939504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000928776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000919040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000916480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000913408 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000911360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MiracastReceiver.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000910272 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000900608 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000892696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000889656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000888056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000879792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000878080 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2019-07-14 04:50 - 2019-07-14 04:50 - 000876856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000864768 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000862720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Service.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000861696 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000858112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000858112 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000830976 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000824832 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000822072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000821696 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000818656 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000817152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\PEAuth.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000811192 _____ C:\WINDOWS\SysWOW64\locale.nls
2019-07-14 04:50 - 2019-07-14 04:50 - 000811192 _____ C:\WINDOWS\system32\locale.nls
2019-07-14 04:50 - 2019-07-14 04:50 - 000810512 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000804880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000797112 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000773168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000772656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000771584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000751256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000740664 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000739328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000727040 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000726328 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000722072 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000706544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mscms.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntime.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000701952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000696320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsreg.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000680760 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000680448 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000679368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000678400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000675328 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntimewindows.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000674816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000674072 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000673152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000673080 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000668160 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000667272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000663552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000645632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000644096 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000642008 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000637968 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000628616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000621568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000613904 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000611328 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000602432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mscms.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_9.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000592896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000589592 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000588464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000586552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000574976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_9.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000562176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2019-07-14 04:50 - 2019-07-14 04:50 - 000537088 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000537088 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000532992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.UserService.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000531976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2019-07-14 04:50 - 2019-07-14 04:50 - 000531464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000523912 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000516608 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000515896 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000513336 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000511288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000509440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000505856 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000481592 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000480768 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskcomp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000477496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2019-07-14 04:50 - 2019-07-14 04:50 - 000474112 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinDataModelServer.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000472064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000467456 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2019-07-14 04:50 - 2019-07-14 04:50 - 000466624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000464696 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000462848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000462352 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000461824 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000457016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.ConversationalAgent.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000455680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000451896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000441144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000435200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000435000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000425264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000423936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000420152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmicmiplugin.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000415800 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000415544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2019-07-14 04:50 - 2019-07-14 04:50 - 000406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000404392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000401416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000390456 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000388608 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000386016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000381240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000379192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000375808 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskcomp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000363624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000358944 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsta.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\MbbCx.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000353960 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000350208 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManager.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000344064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.BlueLightReduction.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000339520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbt.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000336928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000336752 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSrvPolicyManager.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000327680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000324624 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcommdlg.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000312320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL
2019-07-14 04:50 - 2019-07-14 04:50 - 000309760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000307712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000301568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000296976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000296448 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000284536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000283152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mssecflt.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000283136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000280576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000279624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winsta.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000278528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000274128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcTok.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000270336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\DesktopSwitcherDataModel.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3svc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000268216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000257536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbaudio2.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000248088 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000246784 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerCsp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000242688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_CapabilityAccess.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpnServiceDS.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000233984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\schtasks.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManagerClient.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000223248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelppm.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000220680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdigest.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000214032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ifsutil.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000211968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\hidclass.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000208184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\processr.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000205112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winquic.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000202040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000201256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdppm.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000199688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdk8.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000199184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000199176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000194176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winquic.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000193848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000193800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000187920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ifsutil.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000187392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schtasks.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\AarSvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000182072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpioclx.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000180536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000180024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ulib.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000179512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000178192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000164152 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000161848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000159232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BitLockerCsp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmgaproxystub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000149512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ulib.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000146920 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000146744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleprn.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\GraphicsCapture.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000142544 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingUI.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000142136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbus.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\luafv.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000139472 _____ (Microsoft Corporation) C:\WINDOWS\system32\userenv.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000134760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000132096 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000129848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mup.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000129024 _____ (Microsoft Corporation) C:\WINDOWS\system32\GameChatTranscription.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssitlb.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000127296 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000123912 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdnet.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinAUG.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000120352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapistub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapi32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000117048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000116184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\userenv.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000115200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleprn.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000115120 _____ (Microsoft Corporation) C:\WINDOWS\system32\phoneactivate.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\agilevpn.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Taskbar.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssitlb.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpoext.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GraphicsCapture.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3msm.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000102216 _____ (Microsoft Corporation) C:\WINDOWS\system32\changepk.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mapistub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mapi32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000098816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GameChatTranscription.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000098816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2019-07-14 04:50 - 2019-07-14 04:50 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3api.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000089544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000088560 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3api.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3msm.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApiSetHost.AppExecutionAlias.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\efsext.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000071720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwm.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\monitor.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\UsoClient.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000066360 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptdll.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000065064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsManagementServiceWinRt.ProxyStub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcadm.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ApiSetHost.AppExecutionAlias.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmgaproxystub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssprxy.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\audioresourceregistrar.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000056008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptdll.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000055608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storufs.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efsext.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000047000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\hidparse.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\hidusb.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidusb.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiredNetworkCSP.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpgradeResultsUI.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000037888 _____ C:\WINDOWS\system32\usocoreps.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthMini.SYS
2019-07-14 04:50 - 2019-07-14 04:50 - 000036152 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mskssrv.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxssrv.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\FaxPrinterInstaller.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\KNetPwrDepBroker.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000028936 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmbuspipe.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilotdiag.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wci.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\fixmapi.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\bindflt.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fixmapi.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDJPN.DLL
2019-07-14 04:50 - 2019-07-14 04:50 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaevts.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\pacjsworker.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimg32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimg32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCertResources.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCertResources.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6r.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3r.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tier2punctuations.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6r.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3r.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 004470272 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2019-07-14 04:48 - 2019-07-14 04:48 - 001166488 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 000903168 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsFilt.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 000778912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 000568320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsFilt.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 000124568 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 000103072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\XPSSHHDR.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 000081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XPSSHHDR.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 000076060 _____ C:\WINDOWS\SysWOW64\xpsrchvw.xml
2019-07-14 04:48 - 2019-07-14 04:48 - 000076060 _____ C:\WINDOWS\system32\xpsrchvw.xml
2019-07-14 04:48 - 2019-07-14 04:48 - 000035592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2019-07-14 04:48 - 2019-07-14 04:48 - 000035592 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2019-07-14 04:48 - 2019-07-14 04:48 - 000000000 ____D C:\Program Files\Reference Assemblies
2019-07-14 04:48 - 2019-07-14 04:48 - 000000000 ____D C:\Program Files\MSBuild
2019-07-14 04:48 - 2019-07-14 04:48 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2019-07-14 04:48 - 2019-07-14 04:48 - 000000000 ____D C:\Program Files (x86)\MSBuild
2019-07-14 01:42 - 2019-07-14 01:43 - 000046735 ____C C:\Users\indre\Desktop\FRST.txt
2019-07-14 01:36 - 2019-07-14 01:36 - 000000000 ___HD C:\OneDriveTemp
2019-07-14 01:16 - 2019-07-14 01:16 - 000842664 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-07-14 01:15 - 2019-07-14 01:15 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2019-07-14 01:14 - 2019-07-14 01:14 - 000000020 ___SH C:\Users\indre\ntuser.ini
2019-07-14 01:13 - 2019-07-14 01:35 - 000004166 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{71AF15CB-04B4-4B18-8047-5E35B9C7421E}
2019-07-14 01:13 - 2019-07-14 01:13 - 000007623 _____ C:\WINDOWS\diagwrn.xml
2019-07-14 01:13 - 2019-07-14 01:13 - 000007623 _____ C:\WINDOWS\diagerr.xml
2019-07-14 01:13 - 2019-07-14 01:13 - 000003762 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2019-07-14 01:13 - 2019-07-14 01:13 - 000003750 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier
2019-07-14 01:13 - 2019-07-14 01:13 - 000003482 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2019-07-14 01:13 - 2019-07-14 01:13 - 000003346 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2019-07-14 01:13 - 2019-07-14 01:13 - 000003298 _____ C:\WINDOWS\System32\Tasks\Dell SupportAssistAgent AutoUpdate
2019-07-14 01:13 - 2019-07-14 01:13 - 000003278 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2019-07-14 01:13 - 2019-07-14 01:13 - 000003122 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2019-07-14 01:13 - 2019-07-14 01:13 - 000003118 _____ C:\WINDOWS\System32\Tasks\Intel PTT EK Recertification
2019-07-14 01:13 - 2019-07-14 01:13 - 000003042 _____ C:\WINDOWS\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473
2019-07-14 01:13 - 2019-07-14 01:13 - 000003040 _____ C:\WINDOWS\System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec
2019-07-14 01:13 - 2019-07-14 01:13 - 000002858 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1593158232-969496310-2340663774-1001
2019-07-14 01:13 - 2019-07-14 01:13 - 000002806 _____ C:\WINDOWS\System32\Tasks\Seagate_Install_Launch
2019-07-14 01:13 - 2019-07-14 01:13 - 000002702 _____ C:\WINDOWS\System32\Tasks\GarminUpdaterTask
2019-07-14 01:13 - 2019-07-14 01:13 - 000002674 _____ C:\WINDOWS\System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec-Logon
2019-07-14 01:13 - 2019-07-14 01:13 - 000002638 _____ C:\WINDOWS\System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901}
2019-07-14 01:13 - 2019-07-14 01:13 - 000002528 _____ C:\WINDOWS\System32\Tasks\CLVDLauncher
2019-07-14 01:13 - 2019-07-14 01:13 - 000002528 _____ C:\WINDOWS\System32\Tasks\CLMLSvc_P2G8
2019-07-14 01:13 - 2019-07-14 01:13 - 000002422 _____ C:\WINDOWS\System32\Tasks\WD Device Agent Task indre
2019-07-14 01:13 - 2019-07-14 01:13 - 000002418 _____ C:\WINDOWS\System32\Tasks\WD Discovery Service Task indre
2019-07-14 01:13 - 2019-07-14 01:13 - 000002304 _____ C:\WINDOWS\System32\Tasks\RtHDVBg_PushButton
2019-07-14 01:13 - 2019-07-14 01:13 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-07-14 01:13 - 2019-07-14 01:13 - 000000000 ____D C:\WINDOWS\System32\Tasks\Intel
2019-07-14 01:13 - 2019-07-14 01:13 - 000000000 ____D C:\WINDOWS\System32\Tasks\Hewlett-Packard
2019-07-14 01:13 - 2019-07-14 01:13 - 000000000 ____D C:\WINDOWS\System32\Tasks\Dell
2019-07-14 01:13 - 2019-07-14 01:13 - 000000000 ____D C:\WINDOWS\System32\Tasks\Apple
2019-07-14 01:12 - 2019-07-14 01:12 - 000000000 ____D C:\ProgramData\USOShared
2019-07-14 01:08 - 2019-07-14 04:50 - 002874368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2019-07-14 01:08 - 2019-07-14 01:14 - 000000000 ____D C:\Users\indre
2019-07-14 01:08 - 2019-03-19 00:46 - 000001105 _____ C:\Users\indre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-07-14 01:07 - 2019-07-14 01:07 - 000000000 ____D C:\Program Files\Waves
2019-07-14 01:07 - 2018-03-22 02:24 - 000144832 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2019-07-14 01:05 - 2019-07-14 01:09 - 000444408 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-07-14 01:05 - 2019-07-14 01:06 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-07-14 00:01 - 2019-07-14 01:14 - 000000000 ___DC C:\WINDOWS\Panther
2019-07-13 22:13 - 2019-07-13 22:13 - 000100185 ____C C:\Users\indre\Desktop\FRST 5.txt
2019-07-13 22:13 - 2019-07-13 22:13 - 000044036 ____C C:\Users\indre\Desktop\Addition 5.txt
2019-07-13 21:28 - 2019-07-13 21:28 - 002095104 ____C (Farbar) C:\Users\indre\Desktop\FRST64.exe
2019-07-13 21:28 - 2019-07-13 21:28 - 002095104 _____ (Farbar) C:\Users\indre\Downloads\FRST64 (4).exe
2019-07-13 13:07 - 2019-07-14 01:29 - 000002865 ____C C:\Users\indre\Desktop\OOSU10.ini
2019-07-13 13:06 - 2019-07-13 13:06 - 001068584 ____C (O&O Software GmbH) C:\Users\indre\Desktop\OOSU10.exe
2019-07-13 13:06 - 2019-07-13 13:06 - 001068584 _____ (O&O Software GmbH) C:\Users\indre\Downloads\OOSU10.exe
2019-07-13 11:53 - 2019-07-13 11:53 - 021820224 ____C (Intel® Corporation) C:\Users\indre\Desktop\WiFi_21.20.0_Driver64_Win10.exe
2019-07-13 11:53 - 2019-07-13 11:53 - 021820224 _____ (Intel® Corporation) C:\Users\indre\Downloads\WiFi_21.20.0_Driver64_Win10.exe
2019-07-13 01:16 - 2019-07-13 01:16 - 000042265 ____C C:\Users\indre\Desktop\Addition 4.txt
2019-07-13 00:42 - 2019-07-13 00:42 - 000100258 ____C C:\Users\indre\Desktop\FRST 4.txt
2019-07-13 00:25 - 2019-07-13 00:25 - 014543816 ____C (Intel Corporation) C:\Users\indre\Desktop\SetupRST.exe
2019-07-13 00:25 - 2019-07-13 00:25 - 014543816 _____ (Intel Corporation) C:\Users\indre\Downloads\SetupRST (2).exe
2019-07-13 00:21 - 2019-07-13 00:21 - 014543816 _____ (Intel Corporation) C:\Users\indre\Downloads\SetupRST (1).exe
2019-07-12 21:35 - 2019-07-12 21:35 - 000000000 ____D C:\Users\indre\Intel
2019-07-12 21:31 - 2019-07-12 21:31 - 021816776 _____ (Intel Corporation) C:\Users\indre\Downloads\SetupRST.exe
2019-07-12 19:03 - 2019-07-12 19:03 - 000042006 ____C C:\Users\indre\Desktop\Addition 3.txt
2019-07-12 19:00 - 2019-07-12 19:00 - 000117354 ____C C:\Users\indre\Desktop\FRST 3.txt
2019-07-12 18:50 - 2019-07-12 18:50 - 000004156 ____C C:\Users\indre\Desktop\Fixlog.txt
2019-07-12 18:49 - 2019-07-12 18:49 - 000062468 _____ C:\ProgramData\agent.uninstall.1562971733.bdinstall.v2.bin
2019-07-12 18:49 - 2019-07-12 18:49 - 000002522 _____ C:\Users\indre\Downloads\fixlist.txt
2019-07-12 13:55 - 2019-07-12 13:56 - 000169646 ____C C:\Users\indre\Desktop\DESKTOP-EL88UDV 2.txt
2019-07-12 13:50 - 2019-07-12 13:50 - 000117516 ____C C:\Users\indre\Desktop\FRST 2.txt
2019-07-12 13:50 - 2019-07-12 13:50 - 000043949 ____C C:\Users\indre\Desktop\Addition 2.txt
2019-07-12 13:32 - 2019-07-13 00:38 - 000042262 ____C C:\Users\indre\Desktop\Addition 1.txt
2019-07-12 13:28 - 2019-07-12 13:28 - 002095104 _____ (Farbar) C:\Users\indre\Downloads\FRST64 (3).exe
2019-07-12 13:27 - 2019-07-12 13:27 - 002095104 _____ (Farbar) C:\Users\indre\Downloads\FRST64 (2).exe
2019-07-12 12:51 - 2019-07-12 12:51 - 000001301 _____ C:\Users\Public\Desktop\WD Discovery.lnk
2019-07-12 12:51 - 2019-07-12 12:51 - 000000000 ___DC C:\Users\indre\AppData\Roaming\WDDesktop
2019-07-12 12:50 - 2019-07-14 01:36 - 000000000 ___DC C:\Users\indre\AppData\Roaming\WD Discovery
2019-07-12 12:50 - 2019-07-14 01:36 - 000000000 ____D C:\Users\indre\.wdc
2019-07-12 12:50 - 2019-07-12 12:54 - 000000000 ____D C:\Program Files\WD Desktop App
2019-07-12 12:50 - 2017-11-21 12:03 - 000468112 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\Drivers\wdfsconnect2017.sys
2019-07-12 12:50 - 2017-11-21 12:03 - 000020624 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\Drivers\wdvpnpbus.sys
2019-07-12 12:50 - 2017-11-10 12:51 - 000223744 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\SysWOW64\wdfsconnectNetRdr2017.dll
2019-07-12 12:50 - 2017-11-10 12:51 - 000180224 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll
2019-07-12 12:50 - 2017-11-10 12:51 - 000154112 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\SysWOW64\wdfsconnectMntNtf2017.dll
2019-07-12 12:50 - 2017-11-10 12:51 - 000118272 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\wdfsconnectNetRdr2017.dll
2019-07-12 12:50 - 2017-11-10 12:51 - 000002560 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\wdfsconnectevtmsg.dll
2019-07-12 12:16 - 2019-07-12 12:16 - 000001192 _____ C:\Users\Public\Desktop\WD Drive Utilities.lnk
2019-07-12 12:14 - 2019-07-14 05:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WD Discovery
2019-07-12 12:14 - 2019-07-12 13:23 - 000002228 _____ C:\Users\Public\Desktop\WD Backup.lnk
2019-07-12 12:14 - 2019-07-12 13:23 - 000000000 ____D C:\Program Files (x86)\Western Digital
2019-07-12 12:14 - 2019-07-12 12:14 - 000000000 ___DC C:\Users\indre\AppData\Roaming\Western Digital
2019-07-12 12:14 - 2019-07-12 12:14 - 000000000 ____D C:\ProgramData\Western Digital
2019-07-12 11:29 - 2019-07-12 11:29 - 005278464 _____ (Paramount Software UK Ltd) C:\Users\indre\Downloads\ReflectDLHF (1).exe
2019-07-12 11:25 - 2019-07-12 11:31 - 000000000 ____D C:\ProgramData\Macrium
2019-07-12 11:25 - 2019-07-12 11:25 - 000000000 ____D C:\Users\indre\Downloads\Macrium
2019-07-12 11:24 - 2019-07-12 11:25 - 005278464 _____ (Paramount Software UK Ltd) C:\Users\indre\Downloads\ReflectDLHF.exe
2019-07-11 12:12 - 2019-07-11 12:12 - 000000000 ___DC C:\Users\indre\Documents\Kaspersky Password Manager
2019-07-10 22:50 - 2019-07-10 22:50 - 000000000 ___DC C:\Users\indre\AppData\Local\Garmin
2019-07-09 13:11 - 2019-07-09 13:11 - 004730179 _____ C:\Users\indre\Downloads\Master Folder For Cleared Checks INDY (2).xlsx
2019-07-09 13:09 - 2019-07-09 13:09 - 008141856 _____ C:\Users\indre\Downloads\MASTER ALL CHECKS (4).xlsx
2019-07-08 13:49 - 2019-07-08 13:49 - 000000000 ___DC C:\Users\indre\Documents\ED stuff
2019-07-08 11:03 - 2019-07-08 11:04 - 000188559 ____C C:\Users\indre\Desktop\DESKTOP-EL88UDV.txt
2019-07-08 11:01 - 2019-07-14 05:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2019-07-08 11:01 - 2019-07-08 11:01 - 000000839 _____ C:\Users\Public\Desktop\Speccy.lnk
2019-07-08 11:01 - 2019-07-08 11:01 - 000000000 ____D C:\Program Files\Speccy
2019-07-08 10:59 - 2019-07-08 10:59 - 006889184 _____ (Piriform Ltd) C:\Users\indre\Downloads\spsetup132.exe
2019-07-08 10:59 - 2019-07-08 10:59 - 001309592 _____ (BraveSoftware Inc.) C:\Users\indre\Downloads\BraveBrowserSetup-TPF550.exe
2019-07-08 10:58 - 2019-07-08 10:58 - 000019118 ____C C:\Users\indre\Desktop\Tasklist 070819.txt
2019-07-08 10:56 - 2019-07-08 10:56 - 000019118 _____ C:\junk.txt
2019-07-08 10:54 - 2019-07-08 10:54 - 000026673 ____C C:\Users\indre\Desktop\Registry 070819.txt
2019-07-08 10:50 - 2019-07-08 10:50 - 002826520 _____ (Sysinternals - www.sysinternals.com) C:\Users\indre\Downloads\procexp (1).exe
2019-07-08 10:50 - 2019-07-08 10:50 - 000043192 _____ (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP152.SYS
2019-07-08 10:49 - 2019-07-08 10:49 - 002826520 _____ (Sysinternals - www.sysinternals.com) C:\Users\indre\Downloads\procexp.exe
2019-07-08 10:47 - 2019-07-08 10:47 - 000023010 ____C C:\Users\indre\Desktop\VEW Application 070819.txt
2019-07-08 10:44 - 2019-07-08 10:44 - 000007664 ____C C:\Users\indre\Desktop\VEW Events 070819.txt
2019-07-08 10:43 - 2019-07-08 10:46 - 000023010 _____ C:\VEW.txt
2019-07-08 10:40 - 2019-07-08 10:40 - 000061440 _____ ( ) C:\Users\indre\Downloads\VEW.exe
2019-07-06 13:06 - 2019-07-06 13:06 - 000302368 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klark.sys
2019-07-06 13:04 - 2019-07-14 05:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Password Manager
2019-07-06 13:04 - 2019-07-06 13:04 - 000001371 _____ C:\Users\Public\Desktop\Kaspersky Password Manager.lnk
2019-07-06 13:04 - 2019-07-06 13:04 - 000000000 ___DC C:\Users\indre\AppData\Local\Kaspersky Lab
2019-07-06 13:00 - 2019-07-14 05:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Secure Connection
2019-07-06 13:00 - 2019-07-06 13:00 - 000245272 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_arkmon.sys
2019-07-06 13:00 - 2019-07-06 13:00 - 000198768 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_mark.sys
2019-07-06 13:00 - 2019-07-06 13:00 - 000116104 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klbg.sys
2019-07-06 13:00 - 2019-07-06 13:00 - 000099152 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_kimul.sys
2019-07-06 12:59 - 2019-07-14 05:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Total Security
2019-07-06 12:59 - 2019-07-14 01:36 - 000000000 ____D C:\ProgramData\Kaspersky Lab
2019-07-06 12:59 - 2019-07-06 13:17 - 000236672 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klflt.sys
2019-07-06 12:59 - 2019-07-06 13:16 - 001168000 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klif.sys
2019-07-06 12:59 - 2019-07-06 13:04 - 000000000 ____D C:\Program Files (x86)\Kaspersky Lab
2019-07-06 12:59 - 2019-07-06 12:59 - 000002210 _____ C:\Users\Public\Desktop\Safe Money.lnk
2019-07-06 12:59 - 2019-07-06 12:59 - 000002182 _____ C:\Users\Public\Desktop\Kaspersky Total Security.lnk
2019-07-06 12:59 - 2013-05-06 08:13 - 000110176 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\klfphc.dll
2019-07-06 12:57 - 2019-07-06 12:56 - 000592616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2019-07-06 12:54 - 2019-07-06 12:55 - 000000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2019-07-06 12:54 - 2019-07-06 12:54 - 002660224 _____ (Kaspersky Lab) C:\Users\indre\Downloads\startup_14445.exe
2019-07-06 10:01 - 2019-07-06 10:01 - 002420224 _____ (Farbar) C:\Users\indre\Downloads\FRST64 (1).exe
2019-07-06 10:00 - 2019-07-13 00:38 - 000100255 ____C C:\Users\indre\Desktop\FRST 1.txt
2019-07-06 09:58 - 2019-07-06 10:00 - 000039445 _____ C:\Users\indre\Downloads\Addition.txt
2019-07-06 09:55 - 2019-07-06 09:59 - 000079818 _____ C:\Users\indre\Downloads\FRST.txt
2019-07-06 09:54 - 2019-07-14 01:42 - 000000000 ____D C:\FRST
2019-07-06 09:53 - 2019-07-06 09:53 - 002420224 _____ (Farbar) C:\Users\indre\Downloads\FRST64.exe
2019-07-01 19:18 - 2019-07-14 05:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2019-06-29 23:56 - 2019-06-29 23:56 - 011069444 _____ C:\Users\indre\Downloads\thecourtshipofeddiesfather-1st (1).mpg
2019-06-29 23:55 - 2019-06-29 23:55 - 011069444 _____ C:\Users\indre\Downloads\thecourtshipofeddiesfather-1st.mpg
2019-06-29 11:29 - 2019-06-29 11:29 - 000074636 _____ C:\ProgramData\agent.update.1561822169.bdinstall.v2.bin
2019-06-27 20:31 - 2019-06-27 20:31 - 022709477 _____ C:\Users\indre\Downloads\20190627_202829_19399014677980 (1).mp4
2019-06-27 20:30 - 2019-06-27 20:30 - 022709477 _____ C:\Users\indre\Downloads\20190627_202829_19399014677980.mp4
2019-06-27 19:53 - 2019-06-27 19:53 - 000000054 ____C C:\Users\indre\Desktop\cryptic stacey 062719.txt
2019-06-24 00:13 - 2019-07-07 22:03 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2019-06-23 23:58 - 2019-06-23 23:58 - 000068279 _____ C:\Users\indre\Downloads\Iulo_Susan_References_2019.pdf
2019-06-23 14:04 - 2019-06-23 14:04 - 000128245 _____ C:\Users\indre\Downloads\Iulo_Susan_-_Resume_2019.pdf
2019-06-21 20:51 - 2019-06-21 20:51 - 000128344 _____ C:\Users\indre\Downloads\Iulo_Susan_-_resume_June_2019_FIRST DRAFT (2).pdf
2019-06-21 20:28 - 2019-06-21 20:28 - 000128344 _____ C:\Users\indre\Downloads\Iulo_Susan_-_resume_June_2019_FIRST DRAFT (1).pdf
2019-06-21 20:25 - 2019-06-21 20:25 - 000128344 _____ C:\Users\indre\Downloads\Iulo_Susan_-_resume_June_2019_FIRST DRAFT.pdf
2019-06-20 12:13 - 2019-06-20 12:13 - 000004919 _____ C:\Users\indre\Downloads\imp8A93.pdf
2019-06-20 12:13 - 2019-06-20 12:13 - 000004919 _____ C:\Users\indre\Downloads\imp8A93 (1).pdf
2019-06-18 21:05 - 2019-06-18 21:05 - 000039557 _____ C:\Users\indre\Downloads\Letters_2019_06_14_12_42_30_156.pdf
2019-06-18 02:30 - 2019-06-18 02:30 - 000363078 _____ C:\Users\indre\Downloads\Preprinted UPS label for Treasury to Farmingdale 010918.pdf
2019-06-17 14:37 - 2019-06-17 14:37 - 000350164 _____ C:\Users\indre\Downloads\Statement_062019_8810.pdf
 
==================== One month (modified) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-07-14 05:05 - 2019-06-13 20:33 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless
2019-07-14 05:05 - 2019-05-28 22:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2019-07-14 05:05 - 2019-05-24 22:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NordVPN
2019-07-14 05:05 - 2019-04-21 20:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Plex Media Server
2019-07-14 05:05 - 2019-03-19 00:56 - 000000000 ____D C:\WINDOWS\Setup
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 __RHD C:\Users\Public\Libraries
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\spool
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\NDF
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\Macromed
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\Drivers\DriverData
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2019-07-14 05:05 - 2019-03-19 00:49 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2019-07-14 05:05 - 2018-10-28 02:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
2019-07-14 05:05 - 2018-07-25 13:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CutePDF
2019-07-14 05:05 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2019-07-14 05:05 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2019-07-14 05:05 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\InfusedApps
2019-07-14 05:05 - 2017-10-14 21:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2019-07-14 05:05 - 2017-05-21 14:10 - 000000000 ____D C:\Program Files\Intel
2019-07-14 05:05 - 2017-05-09 21:49 - 000000000 ____D C:\Program Files\UNP
2019-07-14 05:05 - 2016-09-16 23:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TextPad 8
2019-07-14 05:05 - 2016-09-16 23:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2019-07-14 05:05 - 2016-09-16 22:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pretty Good Solitaire
2019-07-14 05:05 - 2016-09-16 13:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware
2019-07-14 05:05 - 2016-09-13 22:50 - 000000000 ____D C:\WINDOWS\system32\appmgmt
2019-07-14 05:05 - 2016-08-09 19:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
2019-07-14 05:05 - 2016-08-09 19:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Media Suite
2019-07-14 05:05 - 2016-08-09 19:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
2019-07-14 05:05 - 2016-08-09 19:34 - 000000000 ___HD C:\WINDOWS\system32\WLANProfiles
2019-07-14 05:05 - 2016-08-09 19:33 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2019-07-14 05:04 - 2019-03-19 00:37 - 000008192 _____ C:\WINDOWS\system32\config\ELAM
2019-07-14 04:54 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\oobe
2019-07-14 04:54 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\Resources
2019-07-14 04:54 - 2017-05-21 14:10 - 000000000 ____D C:\Program Files\Realtek
2019-07-14 04:54 - 2016-09-17 01:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rovio
2019-07-14 04:54 - 2016-09-16 20:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2019-07-14 04:54 - 2016-08-09 19:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewBlue
2019-07-14 04:52 - 2019-03-19 02:23 - 000000000 ___SD C:\WINDOWS\system32\AppV
2019-07-14 04:52 - 2019-03-19 02:23 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2019-07-14 04:52 - 2019-03-19 00:52 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2019-07-14 04:52 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\SystemResources
2019-07-14 04:52 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\migwiz
2019-07-14 04:52 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\appraiser
2019-07-14 04:52 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\ShellExperiences
2019-07-14 04:52 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\ShellComponents
2019-07-14 04:52 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\bcastdvr
2019-07-14 04:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2019-07-14 04:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2019-07-14 04:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2019-07-14 04:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2019-07-14 04:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2019-07-14 04:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2019-07-14 04:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\et-EE
2019-07-14 04:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\es-MX
2019-07-14 01:42 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-07-14 01:36 - 2016-09-11 19:32 - 000000000 ___RD C:\Users\indre\OneDrive
2019-07-14 01:35 - 2016-09-11 19:30 - 000000000 __SHD C:\Users\indre\IntelGraphicsProfiles
2019-07-14 01:32 - 2017-11-15 23:37 - 000000000 ___DC C:\Users\indre\AppData\Local\Packages
2019-07-14 01:31 - 2019-03-19 00:52 - 000000000 ___HD C:\Program Files\WindowsApps
2019-07-14 01:31 - 2018-12-15 03:16 - 000000000 ___DC C:\Users\indre\AppData\Local\PlaceholderTileLogoFolder
2019-07-14 01:30 - 2019-03-19 00:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-07-14 01:30 - 2018-07-04 13:52 - 000000000 ____D C:\ProgramData\Packages
2019-07-14 01:14 - 2019-03-19 00:50 - 000000000 ____D C:\WINDOWS\INF
2019-07-14 01:14 - 2017-11-15 23:45 - 000000000 ___RD C:\Users\indre\3D Objects
2019-07-14 01:14 - 2016-09-30 22:13 - 000000000 ___DC C:\Users\indre\AppData\Local\ConnectedDevicesPlatform
2019-07-14 01:14 - 2016-08-09 19:48 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-07-14 01:13 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\Registration
2019-07-14 01:13 - 2016-08-09 19:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Audio
2019-07-14 01:12 - 2019-03-19 00:52 - 000000000 ____D C:\ProgramData\USOPrivate
2019-07-14 01:12 - 2016-09-11 19:57 - 000002303 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-07-14 01:12 - 2016-09-11 19:57 - 000002262 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2019-07-14 01:10 - 2016-09-30 22:09 - 000027452 _____ C:\WINDOWS\system32\emptyregdb.dat
2019-07-14 01:09 - 2019-03-19 00:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-07-14 01:08 - 2019-03-19 00:37 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2019-07-14 01:08 - 2018-04-06 21:09 - 000000000 ___DC C:\Users\indre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom
2019-07-14 01:07 - 2019-03-19 00:52 - 000000000 ___RD C:\WINDOWS\PrintDialog
2019-07-14 01:07 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\appcompat
2019-07-14 01:07 - 2017-05-21 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\sda
2019-07-14 01:07 - 2017-05-21 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2019-07-14 01:07 - 2017-05-21 14:10 - 000000000 ____D C:\WINDOWS\system32\RTCOM
2019-07-14 01:06 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\ServiceState
2019-07-14 01:06 - 2018-05-23 18:30 - 000000000 ____D C:\WINDOWS\IAStorAfsService
2019-07-12 21:35 - 2017-05-21 14:10 - 000000000 ____D C:\Program Files (x86)\Intel
2019-07-12 19:21 - 2016-09-17 01:09 - 000000000 ___DC C:\Users\indre\Documents\Letters
2019-07-12 13:23 - 2016-08-09 19:33 - 000000000 ____D C:\ProgramData\Package Cache
2019-07-12 12:10 - 2016-10-12 00:52 - 000000000 ___DC C:\Users\indre\AppData\Roaming\Seagate
2019-07-12 11:43 - 2016-09-16 22:45 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-07-11 04:01 - 2016-11-18 22:39 - 000000000 ___DC C:\Users\indre\AppData\LocalLow\Mozilla
2019-07-10 07:49 - 2016-09-12 20:21 - 000000000 ____D C:\WINDOWS\system32\MRT
2019-07-10 07:36 - 2016-09-12 20:20 - 136618864 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2019-07-08 14:37 - 2016-09-18 09:35 - 000000000 ___DC C:\Users\indre\AppData\Local\CrashDumps
2019-07-08 13:50 - 2016-09-17 01:49 - 000000000 ___DC C:\Users\indre\Documents\Funny stuff
2019-07-08 13:43 - 2018-12-02 19:00 - 000000000 ___DC C:\Users\indre\Documents\Editing for Josh
2019-07-06 13:17 - 2019-02-13 14:10 - 000184960 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klwtp.sys
2019-07-06 13:17 - 2019-02-13 14:10 - 000125568 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klbackupflt.sys
2019-07-06 13:17 - 2019-02-13 14:10 - 000091472 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\kldisk.sys
2019-07-06 13:17 - 2018-02-24 05:17 - 000218240 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\kneps.sys
2019-07-06 13:17 - 2018-02-17 02:50 - 000104576 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klwfp.sys
2019-07-06 13:17 - 2018-01-15 05:13 - 000060536 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klkbdflt.sys
2019-07-06 13:16 - 2019-02-13 14:10 - 001093248 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klhk.sys
2019-07-06 13:16 - 2019-02-13 14:10 - 000152288 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\klhkum.dll
2019-07-06 13:16 - 2019-02-13 14:10 - 000075600 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klbackupdisk.sys
2019-07-06 13:16 - 2019-02-13 14:10 - 000046416 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klpnpflt.sys
2019-07-06 13:16 - 2018-02-12 04:17 - 000058704 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klim6.sys
2019-07-06 13:16 - 2017-12-11 11:49 - 000060784 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klmouflt.sys
2019-07-06 13:16 - 2017-05-30 18:51 - 000050304 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klpd.sys
2019-07-06 13:00 - 2017-02-04 10:05 - 000000000 ____D C:\Program Files\Common Files\AV
2019-07-06 01:15 - 2018-06-20 22:44 - 000002365 ____C C:\Users\indre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive (1).lnk
2019-07-01 19:18 - 2019-05-14 13:15 - 000002495 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2019-07-01 19:18 - 2019-05-14 13:15 - 000002494 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2019-07-01 19:18 - 2019-05-14 13:15 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2019-07-01 19:18 - 2019-05-14 13:15 - 000002451 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2019-07-01 19:18 - 2019-05-14 13:15 - 000002437 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2019-07-01 19:18 - 2016-08-09 19:40 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2019-06-29 23:58 - 2017-10-14 21:56 - 000000000 ___DC C:\Users\indre\AppData\Roaming\vlc
2019-06-29 23:56 - 2017-10-14 21:56 - 000001141 _____ C:\Users\Public\Desktop\VLC media player.lnk
2019-06-28 08:30 - 2016-09-16 13:57 - 000000000 ___DC C:\Users\indre\AppData\Roaming\VMware
2019-06-27 18:32 - 2016-09-11 19:59 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2019-06-27 00:47 - 2017-07-15 20:02 - 000014706 ____C C:\Users\indre\Documents\Indy's Finances.xlsx
2019-06-26 22:10 - 2016-09-11 19:59 - 000001007 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2019-06-21 21:34 - 2016-09-17 01:09 - 000000000 ___DC C:\Users\indre\Documents\Resumes etc
2019-06-21 16:50 - 2016-09-17 01:09 - 000000000 ___DC C:\Users\indre\Documents\Recipes
2019-06-20 20:03 - 2018-11-16 12:19 - 000000000 ____D C:\Program Files\rempl
2019-06-18 05:52 - 2016-09-17 01:38 - 000000000 ___DC C:\Users\indre\Documents\Akiko stuff
 
==================== Files in the root of some directories ================
 
2018-11-19 21:23 - 2018-11-19 21:23 - 000000017 ____C () C:\Users\indre\AppData\Local\resmon.resmoncfg
 
==================== SigCheck ===============================
 
(There is no automatic fix for files that do not pass verification.)
 

==================== End of FRST.txt ============================

 

(2) Addition scan:

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-07-2019

Ran by indre (14-07-2019 01:44:39)
Running from C:\Users\indre\Desktop
Windows 10 Pro Version 1903 18362.239 (X64) (2019-07-14 05:14:02)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1593158232-969496310-2340663774-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1593158232-969496310-2340663774-503 - Limited - Disabled)
Guest (S-1-5-21-1593158232-969496310-2340663774-501 - Limited - Disabled)
indre (S-1-5-21-1593158232-969496310-2340663774-1001 - Administrator - Enabled) => C:\Users\indre
WDAGUtilityAccount (S-1-5-21-1593158232-969496310-2340663774-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Kaspersky Total Security (Enabled - Up to date) {0AB30972-4BAC-7BEE-CBCA-B8F9E68797D8}
AS: Kaspersky Total Security (Enabled - Up to date) {B1D2E896-6D96-7460-F17A-838B9D00DD65}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Total Security (Enabled) {32888857-01C3-7AB6-E095-11CC1854D0A3}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Across Lite (HKLM-x32\...\{5F5C7350-9731-420F-97CC-8CAFEE7DA7A3}) (Version: 2.4.2451.1 - Literate Software)
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 19.012.20035 - Adobe Systems Incorporated)
Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.223 - Adobe)
Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.223 - Adobe)
Angry Birds (HKLM-x32\...\{2F7D5734-056F-4A0A-A1C7-CA1AAE5BB1EB}) (Version: 1.6.3.1 - Rovio)
ANT Drivers Installer x64 (HKLM\...\{D559687A-60C5-4786-9429-C21EC195789D}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Application Support (32-bit) (HKLM-x32\...\{C1BCFECF-6EC2-4750-9072-5E2489423F8F}) (Version: 7.5 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{B202C7F5-7DE3-4FBF-B259-E70E625F56FC}) (Version: 7.5 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B5A46811-3612-4DA5-8A5A-E6DED5D7C523}) (Version: 12.2.1.12 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{A30EA700-5515-48F0-88B0-9E99DC356B88}) (Version: 2.6.0.1 - Apple Inc.)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Cisco WebEx Meetings (HKLM-x32\...\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
CmgMasterPrerequisites (HKLM\...\{EE34FA4E-715A-46FA-9CAF-06E26AE4217D}) (Version: 1.10.0.34 - Dell, Inc.) Hidden
CutePDF Form Filler 3.6 (Evaluation) (HKLM-x32\...\CutePDF Form Filler (Evaluation)_is1) (Version:  - Acro Software Inc.)
CyberLink Media Suite Essentials (HKLM-x32\...\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 12 - CyberLink Corp.)
Dell Command | Update (HKLM-x32\...\{EC542D5D-B608-4145-A8F7-749C02BE6D94}) (Version: 2.2.0 - Dell Inc.)
Dell Data Protection | Client Security Framework (HKLM\...\{FAE38E46-ECB2-44EA-A52B-6955AA6B1B3A}) (Version: 8.10.0.39 - Dell, Inc.)
Dell Data Protection | Security Tools (HKLM-x32\...\{812AA6D3-5BEB-4577-88B1-00998B91AB41}) (Version: 1.10.0.34 - Dell, Inc.) Hidden
Dell Data Protection | Security Tools (HKLM-x32\...\InstallShield_{812AA6D3-5BEB-4577-88B1-00998B91AB41}) (Version: 1.10.0.34 - Dell, Inc.)
Dell Digital Delivery (HKLM-x32\...\{AB7F2792-2ED1-4C5C-9F28-680E5110BF72}) (Version: 3.1.1018.0 - Dell Products, LP)
Dell SupportAssist (HKLM\...\{806422F1-FC4E-4D7C-8855-05748AEFC031}) (Version: 3.2.2.119 - Dell Inc.)
DELLOSD (HKLM-x32\...\{BED3193A-897B-47F6-AEDC-45D147122957}) (Version: 1.0.0.0 - DELL)
Elevated Installer (HKLM-x32\...\{0BF90608-2F95-4C7C-9A85-E90E0CAF4FE9}) (Version: 6.9.1.0 - Garmin Ltd or its subsidiaries) Hidden
FileZilla Client 3.25.1 (HKLM-x32\...\FileZilla Client) (Version: 3.25.1 - Tim Kosse)
Garmin Express (HKLM-x32\...\{95D0EADA-5123-41C0-931A-F37946BC0E8E}) (Version: 6.9.1.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express (HKLM-x32\...\{eab4691c-4022-41cd-8d39-c3097ba62d4b}) (Version: 6.9.1.0 - Garmin Ltd or its subsidiaries)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 75.0.3770.100 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.11 - Google LLC) Hidden
HP Support Solutions Framework (HKLM-x32\...\{2B5A1E68-6617-406D-B797-5DAB5B4630B8}) (Version: 12.11.24.11 - HP Inc.)
Intel® Chipset Device Software (HKLM-x32\...\{fb610cea-ba50-4d4b-a717-cf025419035c}) (Version: 10.1.1.13 - Intel® Corporation) Hidden
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1054 - Intel Corporation)
Intel® Network Connections 20.3.300.1 (HKLM\...\PROSetDX) (Version: 20.3.300.1 - Intel)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 23.20.16.4973 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.8.16.1063 - Intel Corporation)
Intel® Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.47.866.0 - Intel Corporation) Hidden
Intel® Trusted Connect Services Client (HKLM-x32\...\{246c6cc0-9810-4728-9a29-28474de2eec5}) (Version: 1.47.866.0 - Intel Corporation) Hidden
Intel® WiDi (HKLM\...\{C7CD6D54-26AF-4D93-B06F-D81ACE8624CB}) (Version: 6.0.40.0 - Intel Corporation)
Intel® WiDi Software Asset Manager (HKLM-x32\...\{5B5CD20C-29F0-4857-A4FA-A4F4C716B019}) (Version: 1.1.347 - Intel Corporation) Hidden
Intel® Wireless Bluetooth® (HKLM-x32\...\{5068B0F8-CE24-4B61-9C2F-301B411FFB9C}) (Version: 18.1.1611.3223 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{f430aa46-62c4-47a0-8a03-42e7fff664b7}) (Version: 20.120.0 - Intel Corporation)
Intel® Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation)
iTunes (HKLM\...\{A8AF3EF8-5010-4A92-BCCA-90F62A7D62B8}) (Version: 12.9.5.7 - Apple Inc.)
Kaspersky Password Manager (HKLM-x32\...\{B2F7333E-6C8D-4994-AAC4-FEC8EBBF9611}) (Version: 9.0.2.767 - Kaspersky Lab) Hidden
Kaspersky Password Manager (HKLM-x32\...\InstallWIX_{B2F7333E-6C8D-4994-AAC4-FEC8EBBF9611}) (Version: 9.0.2.767 - Kaspersky Lab)
Kaspersky Secure Connection (HKLM-x32\...\{F10AA188-7166-430E-8810-FEAB2AD73DE3}) (Version: 19.0.0.1088 - Kaspersky Lab) Hidden
Kaspersky Secure Connection (HKLM-x32\...\InstallWIX_{F10AA188-7166-430E-8810-FEAB2AD73DE3}) (Version: 19.0.0.1088 - Kaspersky Lab)
Kaspersky Total Security (HKLM-x32\...\{718613F4-492D-4272-ACC3-D04A8EF0F883}) (Version: 19.0.0.1088 - Kaspersky Lab) Hidden
Kaspersky Total Security (HKLM-x32\...\InstallWIX_{718613F4-492D-4272-ACC3-D04A8EF0F883}) (Version: 19.0.0.1088 - Kaspersky Lab)
LaserJet 1020 series (HKLM-x32\...\HP-LaserJet 1020 series) (Version:  - )
Maxx Audio Installer (x64) (HKLM\...\{307032B2-6AF2-46D7-B933-62438DEB2B9A}) (Version: 2.6.8006.3 - Waves Audio Ltd.) Hidden
Microsoft Office Famille et Petite Entreprise 2016 - fr-fr (HKLM\...\HomeBusinessRetail - fr-fr) (Version: 16.0.11727.20230 - Microsoft Corporation)
Microsoft Office Hogar y Empresas 2016 - es-es (HKLM\...\HomeBusinessRetail - es-es) (Version: 16.0.11727.20230 - Microsoft Corporation)
Microsoft Office Home and Business 2016 - en-us (HKLM\...\HomeBusinessRetail - en-us) (Version: 16.0.11727.20230 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\OneDriveSetup.exe) (Version: 19.103.0527.0003 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (HKLM-x32\...\{6e8f74e0-43bd-4dce-8477-6ff6828acc07}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 (HKLM-x32\...\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24210 (HKLM-x32\...\{23658c02-145e-483d-ba6b-1eb82c580529}) (Version: 14.0.24210.0 - Microsoft Corporation)
Mozilla Firefox 67.0.4 (x64 en-US) (HKLM\...\Mozilla Firefox 67.0.4 (x64 en-US)) (Version: 67.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 66.0.3 - Mozilla)
NewBlue Video Essentials for Windows (HKLM-x32\...\NewBlue Video Essentials for Windows) (Version: 3.0 - NewBlue)
NordVPN (HKLM-x32\...\{F4325B30-A8A0-4D09-B0DE-7CBB485A52D8}) (Version: 6.22.6 - NordVPN) Hidden
NordVPN (HKLM-x32\...\NordVPN 6.22.6) (Version: 6.22.6 - NordVPN)
NordVPN network TAP (HKLM-x32\...\{97DEC5D6-2BE9-45BB-BFC5-274B851B486B}) (Version: 1.0.1 - NordVPN)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.11727.20230 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.11727.20230 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.11727.20230 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.11727.20230 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-040C-0000-0000000FF1CE}) (Version: 16.0.11727.20230 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0C0A-0000-0000000FF1CE}) (Version: 16.0.11727.20230 - Microsoft Corporation) Hidden
Plex Media Server (HKLM-x32\...\{72238E55-A877-4785-A5E9-0C35EAFB0746}) (Version: 1.15.876 - Plex, Inc.) Hidden
Plex Media Server (HKLM-x32\...\{9203fc01-57c0-4cc8-858d-92911b5142de}) (Version: 1.15.3.876 - Plex, Inc.)
Pretty Good Solitaire version 12.4.0 (HKLM-x32\...\Pretty Good Solitaire_is1) (Version: 12.4.0 - Goodsol Development Inc.)
proDAD Adorage 3.0 (HKLM-x32\...\proDAD-Adorage-3.0) (Version: 3.0.114.1 - proDAD GmbH)
Realtek Audio COM Components (HKLM-x32\...\{2355B503-9B11-4449-861D-1C1748B26320}) (Version: 1.0.2 - Realtek Semiconductor Corp.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.14393.21292 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6105 - Realtek Semiconductor Corp.)
Security Innovation TSS (HKLM\...\{0C11FE22-53F2-4C9B-9E79-824B10D0976E}) (Version: 2.1.42 - Security Innovation) Hidden
Speccy (HKLM\...\Speccy) (Version: 1.32 - Piriform)
Spotify (HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\Spotify) (Version: 1.0.96.181.gf6bc1b6b - Spotify AB)
Stopping Plex (HKLM-x32\...\{3C6D43CB-1211-4C3F-8F3C-2B4F90C5BB95}) (Version: 1.15.876 - Plex, Inc.) Hidden
TextPad 8 (HKLM\...\{861AB1C1-1967-4C4A-BF86-C255E2D2B8FD}) (Version: 8.0.2 - Helios)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{F14FB68A-9188-4036-AD0D-D054BC9C9291}) (Version: 2.59.0.0 - Microsoft Corporation)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.7.1 - VideoLAN)
VMware Horizon Client (HKLM\...\{93CEC220-0D24-41C0-8647-BA1C62A3EE89}) (Version: 4.0.1.781 - VMware, Inc.)
Vulkan Run Time Libraries 1.0.33.0 (HKLM\...\VulkanRT1.0.33.0) (Version: 1.0.33.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.33.0 (HKLM\...\VulkanRT1.0.33.0-2) (Version: 1.0.33.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1) (Version: 1.0.54.1 - Intel Corporation Inc.)
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-2) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-3) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
WD Backup (HKLM-x32\...\{50C6CAE8-562E-440D-8616-E0514D41CC10}) (Version: 1.9.6941.25593 - Western Digital Technologies, Inc) Hidden
WD Backup (HKLM-x32\...\{6531bf4b-4bad-46a5-9562-766d0a858003}) (Version: 1.9.6941.25593 - Western Digital Technologies, Inc.)
WD Desktop App 2.1.0.245 (HKLM-x32\...\{d303f1fe-6729-4693-b2e1-51d13b450de5}) (Version: 2.1.0.245 - Western Digital Corporation) Hidden
WD Desktop App 2.1.0.245 (x64) (HKLM\...\{CA7F7232-526E-41BD-971A-47BE28C18516}) (Version: 2.1.0.245 - Western Digital Corporation) Hidden
WD Discovery (HKLM-x32\...\WDDiscovery) (Version: 3.3.34 - Western Digital Technologies, Inc.)
WD Drive Utilities (HKLM-x32\...\{5ea95ccc-fc68-4182-88a9-e563ba3900ed}) (Version: 2.0.0.26 - Western Digital Technologies, Inc.)
WD Drive Utilities (HKLM-x32\...\{893C7059-0464-47FB-85A4-5E1ADDA56141}) (Version: 2.0.0.26 - Western Digital Technologies, Inc.) Hidden
WD SES Driver Setup (HKLM-x32\...\{924A274D-38B6-4930-8859-F3F51CFA8DDD}) (Version: 1.1.0.25 - Western Digital) Hidden
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Intel Corporation (iaStorA) HDC  (08/10/2017 15.7.5.1025) (HKLM\...\FF1B55CEF8D39B696D1F5DF141ACFA7A5D1F2743) (Version: 08/10/2017 15.7.5.1025 - Intel Corporation)
Windows Driver Package - Intel Corporation (iaStorA) SCSIAdapter  (08/10/2017 15.7.5.1025) (HKLM\...\6D773A6E21B2A480569157737F58E8FF7DC6608A) (Version: 08/10/2017 15.7.5.1025 - Intel Corporation)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Zoom (HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\ZoomUMX) (Version: 4.1 - Zoom Video Communications, Inc.)
 
Packages:
=========
CyberLink Media Suite Essentials -> C:\Program Files\WindowsApps\DB6EA5DB.CyberLinkMediaSuiteEssentials_1.0.10.0_x86__mcezb6ze687jp [2018-03-13] (CYBERLINK CORPORATION.)
Dell SupportAssist for PCs -> C:\Program Files\WindowsApps\DellInc.DellSupportAssistforPCs_3.2.5.0_x64__htrsf667h5kn2 [2019-05-29] (Dell Inc)
Facebook -> C:\Program Files\WindowsApps\Facebook.Facebook_186.2191.46880.0_x86__8xx8rvfyw5nnt [2019-07-14] (Facebook Inc)
Mail and Calendar -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe [2019-07-10] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1808.3.0_x64__8wekyb3d8bbwe [2019-07-14] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-12] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-12] (Microsoft Corporation) [MS Ad]
Microsoft Jigsaw -> C:\Program Files\WindowsApps\Microsoft.MicrosoftJigsaw_1.8.1812.301_x86__8wekyb3d8bbwe [2019-03-14] (Microsoft Studios) [MS Ad]
Microsoft Mahjong -> C:\Program Files\WindowsApps\Microsoft.MicrosoftMahjong_3.9.4100.0_x64__8wekyb3d8bbwe [2019-04-18] (Microsoft Studios) [MS Ad]
Microsoft Minesweeper -> C:\Program Files\WindowsApps\Microsoft.MicrosoftMinesweeper_2.7.4300.0_x86__8wekyb3d8bbwe [2019-02-18] (Microsoft Studios) [MS Ad]
Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.31.11723.0_x64__8wekyb3d8bbwe [2019-06-26] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.4.6132.0_x64__8wekyb3d8bbwe [2019-06-17] (Microsoft Studios) [MS Ad]
MSN Money -> C:\Program Files\WindowsApps\Microsoft.BingFinance_4.29.10701.0_x64__8wekyb3d8bbwe [2019-03-22] (Microsoft Corporation) [MS Ad]
MSN Sports -> C:\Program Files\WindowsApps\Microsoft.BingSports_4.28.3242.0_x64__8wekyb3d8bbwe [2018-12-15] (Microsoft Corporation) [MS Ad]
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.28.10351.0_x64__8wekyb3d8bbwe [2019-02-12] (Microsoft Corporation) [MS Ad]
PAC-MAN Battle -> C:\Program Files\WindowsApps\50867PocketKingGames.PAC-MANBattle_1.1.0.0_x64__m8bdd0rdw5vr0 [2018-12-15] (Pocket King Games) [MS Ad]
The Backgammon -> C:\Program Files\WindowsApps\6918E89D.TheBackgammon_1.2.0.0_x64__66n08swfvvka0 [2018-12-15] (UNBALANCE corp.) [MS Ad]
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.Twitter_6.1.4.1000_neutral__wgeqdkkx372wm [2018-09-08] (Twitter Inc.)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1593158232-969496310-2340663774-1001_Classes\CLSID\{5A9E21A2-851A-4BEB-B16F-DBBE7D648AF9}\InprocServer32 -> C:\Program Files\TextPad 8\System\ShellExt64.dll (Helios Software Solutions Ltd -> )
SSODL: WDFSMountNotificator-wdfsconnect2017 - {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2} - C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll (Western Digital Technologies, Inc.) [File not signed]
SSODL-x32: WDFSMountNotificator-wdfsconnect2017 - {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2} - C:\WINDOWS\SysWOW64\wdfsconnectMntNtf2017.dll (Western Digital Technologies, Inc.) [File not signed]
ShellServiceObjects: Virtual Storage Mount Notification -> {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2} => C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll [2017-11-10] (Western Digital Technologies, Inc.) [File not signed]
ShellServiceObjects-x32: Virtual Storage Mount Notification -> {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2} => C:\WINDOWS\SysWOW64\wdfsconnectMntNtf2017.dll [2017-11-10] (Western Digital Technologies, Inc.) [File not signed]
ShellIconOverlayIdentifiers: [  WDDesktopIconOverlay01] -> {4F8A325E-9DAF-44B8-A825-1A14DFA0FA78} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [  WDDesktopIconOverlay02] -> {0176BDDE-B59A-4A1E-808B-CAD461415CCA} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [  WDDesktopIconOverlay03] -> {B65909D1-57AF-41F5-AB94-BEB733F62B35} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [  WDDesktopIconOverlay04] -> {C6C2397D-8238-4332-8935-86C39C7C165F} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [  WDDesktopIconOverlay05] -> {E7B3BCF9-0386-4B5F-AE6A-91B9F1423973} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [  WDDesktopIconOverlay06] -> {564EA121-D9DA-485D-82C2-C2ED7BFCCEAD} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2016-04-27] (CyberLink Corp. -> Cyberlink)
ContextMenuHandlers1: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\ShellEx.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers1: [WDDesktopContextMenu] -> {4961b028-350a-3bb9-9d6c-079dc724e5f0} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2016-04-27] (CyberLink Corp. -> Cyberlink)
ContextMenuHandlers2: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\ShellEx.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers4: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\ShellEx.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers4: [WDDesktopContextMenu] -> {4961b028-350a-3bb9-9d6c-079dc724e5f0} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\ki127171.inf_amd64_368f8c7337214025\igfxDTCM.dll [2018-03-22] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\ShellEx.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers1_S-1-5-21-1593158232-969496310-2340663774-1001: [TextPad8] -> {5A9E21A2-851A-4BEB-B16F-DBBE7D648AF9} => C:\Program Files\TextPad 8\System\ShellExt64.dll [2016-02-28] (Helios Software Solutions Ltd -> )
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2016-08-09 19:32 - 2015-06-29 20:13 - 000151552 _____ () [File not signed] C:\Program Files (x86)\DELL\DELLOSD\DellOSDService.exe
2016-08-09 19:32 - 2015-06-29 20:09 - 000548864 _____ () [File not signed] C:\Program Files (x86)\DELL\DELLOSD\MediaButtons.exe
2019-01-21 07:55 - 2019-01-21 07:55 - 000251392 _____ () [File not signed] C:\Program Files (x86)\NordVPN\x86\Liberation.Native.Firewall.dll
2015-05-19 12:11 - 2015-05-19 12:11 - 000335872 _____ (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel® Security Assist\isa.exe
2016-03-25 23:50 - 2016-03-25 23:50 - 001491968 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\VMware\VMware Horizon View Client\bin\LIBEAY32.dll
2016-03-25 23:50 - 2016-03-25 23:50 - 000298496 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\VMware\VMware Horizon View Client\bin\SSLEAY32.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\webcompanion.com -> hxxp://webcompanion.com
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2015-10-30 03:24 - 2019-01-10 23:55 - 000002507 _____ C:\WINDOWS\system32\drivers\etc\hosts
 
0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
0.0.0.0 media.opencandy.com
0.0.0.0 cdn.opencandy.com
0.0.0.0 tracking.opencandy.com
0.0.0.0 api.opencandy.com
0.0.0.0 api.recommendedsw.com
0.0.0.0 rp.yefeneri2.com
0.0.0.0 os.yefeneri2.com
0.0.0.0 os2.yefeneri2.com
0.0.0.0 installer.betterinstaller.com
0.0.0.0 installer.filebulldog.com
0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
0.0.0.0 inno.bisrv.com
0.0.0.0 nsis.bisrv.com
0.0.0.0 cdn.file2desktop.com
0.0.0.0 cdn.goateastcach.us
0.0.0.0 cdn.guttastatdk.us
0.0.0.0 cdn.inskinmedia.com
0.0.0.0 cdn.insta.oibundles2.com
0.0.0.0 cdn.insta.playbryte.com
0.0.0.0 cdn.llogetfastcach.us
0.0.0.0 cdn.montiera.com
0.0.0.0 cdn.msdwnld.com
0.0.0.0 cdn.mypcbackup.com
0.0.0.0 cdn.ppdownload.com
0.0.0.0 cdn.riceateastcach.us
0.0.0.0 cdn.shyapotato.us
0.0.0.0 cdn.solimba.com
0.0.0.0 cdn.tuto4pc.com
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Data Protection\Drivers\TSS\bin\;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL;C:\Program Files\Intel\Intel® Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT;C:\Program Files\Intel\Intel® Management Engine Components\IPT;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\indre\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Warn)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
If an entry is included in the fixlist, it will be removed.
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{F29C6F66-709F-4614-A9A3-B60FCED2E26A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{4D93D1F7-7788-460E-AB49-CA919F927793}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe (Intel Corporation -> )
FirewallRules: [{35F1740E-5C7F-48A0-9424-553F25A67238}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{F52C8ACB-334D-404D-AC77-F60981439024}] => (Allow) C:\Program Files\iTunes\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{FCB7161E-863C-4365-A934-94FC0E83A38E}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex Tuner Service.exe (Plex, Inc -> )
FirewallRules: [{73C29C77-9A88-433D-8F93-2CEF6E260A57}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex DLNA Server.exe (Plex, Inc -> Plex, Inc.)
FirewallRules: [{B9F683A9-6869-4425-ACDF-4BBE734023A1}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe (Plex, Inc -> Python Software Foundation)
FirewallRules: [{835008C9-6A51-4365-AFEC-F24E67C44C2E}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe (Plex, Inc -> Plex, Inc.)
FirewallRules: [{56381F91-7873-4CEA-8ABE-E10213107A2E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{DED84BE3-3BD6-4E0D-A420-B30E49FC626F}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{2A5D3459-4437-4C54-AAC4-9E96FEE61614}] => (Block) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe No File
FirewallRules: [{2F7C3E13-8189-49BC-AD54-293606BAB75F}] => (Block) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe No File
FirewallRules: [UDP Query User{DC37BDA6-DFD4-4AE9-A106-AF2D1149CAC6}C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe] => (Allow) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe No File
FirewallRules: [TCP Query User{5BEC10D3-14A2-4D91-86E2-3FF9AC49678E}C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe] => (Allow) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe No File
FirewallRules: [{FE7FEA92-FE61-4E07-AB28-B07698433507}] => (Allow) LPort=8889
FirewallRules: [{69A76876-400F-4C97-9AC9-188D74D4DEA6}] => (Block) C:\users\indre\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{3E499D19-4DBA-4DEF-8CF8-19DA405CDB89}] => (Block) C:\users\indre\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{1DC4DC8A-7F42-44CE-9FE4-78B806402CE0}C:\users\indre\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\indre\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [TCP Query User{56C4283E-A791-4CBC-9F68-AC60C8E0C7B4}C:\users\indre\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\indre\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{881A5D70-E076-4553-AFB1-5DCEB88E106E}C:\program files (x86)\vmware\vmware horizon view client\vmware-remotemks.exe] => (Allow) C:\program files (x86)\vmware\vmware horizon view client\vmware-remotemks.exe (VMware, Inc. -> VMware, Inc.)
FirewallRules: [TCP Query User{3696DD75-4C0C-490B-A914-59C0D82CE209}C:\program files (x86)\vmware\vmware horizon view client\vmware-remotemks.exe] => (Allow) C:\program files (x86)\vmware\vmware horizon view client\vmware-remotemks.exe (VMware, Inc. -> VMware, Inc.)
FirewallRules: [{B768845C-68FA-4F5D-8CB0-8915F5518FBE}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe (Intel® Wireless Display -> Intel)
FirewallRules: [{277A97E1-8E11-4C68-985D-B7CC9AFC4A42}] => (Allow) LPort=8888
FirewallRules: [{6CC73312-41C6-4002-A0B0-4F73A84DBE2F}] => (Allow) LPort=8888
FirewallRules: [{AD297B5D-2C9A-4E26-9193-5DEFE2B8D5DD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{6A551C3A-B926-43D8-9A75-06A3CEEB5AAF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{FF6FAF1B-3C9B-4453-9D51-82A62172D810}C:\program files\itunes\itunes.exe] => (Allow) C:\program files\itunes\itunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [UDP Query User{B71B19F6-E012-4D87-BC64-170CDB9AE748}C:\program files\itunes\itunes.exe] => (Allow) C:\program files\itunes\itunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{F26FF42A-FABC-4237-AF27-9A74BAD6E0C7}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc. -> Apple Inc.)
 
==================== Restore Points =========================
 
ATTENTION: System Restore is disabled (Total:224.66 GB) (Free:98.88 GB) (44%)
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (07/14/2019 01:36:27 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: MicrosoftEdgeSH.exe, version: 11.0.18362.1, time stamp: 0x3538007c
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000409
Fault offset: 0x000000000000008c
Faulting process id: 0x1668
Faulting application start time: 0x01d53a0615293264
Faulting application path: C:\WINDOWS\system32\MicrosoftEdgeSH.exe
Faulting module path: unknown
Report Id: e1774e06-fbb2-41c2-8365-34e66fe574ab
Faulting package full name: Microsoft.MicrosoftEdge_44.18362.1.0_neutral__8wekyb3d8bbwe
Faulting package-relative application ID: MicrosoftEdge
 
Error: (07/14/2019 01:18:32 AM) (Source: Microsoft-Windows-Perflib) (EventID: 1020) (User: NT AUTHORITY)
Description: The required buffer size is greater than the buffer size passed to the Collect function of the "C:\Windows\System32\perfts.dll" Extensible Counter DLL for the "LSM" service. The given buffer size was 10240 and the required size was 41688.
 
Error: (07/14/2019 01:14:42 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: MicrosoftEdgeSH.exe, version: 11.0.18362.1, time stamp: 0x3538007c
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000409
Fault offset: 0x000000000000008c
Faulting process id: 0x3928
Faulting application start time: 0x01d53a030ae2e4df
Faulting application path: C:\WINDOWS\system32\MicrosoftEdgeSH.exe
Faulting module path: unknown
Report Id: 3b35d173-c37e-46ed-82af-23e0eba381cb
Faulting package full name: Microsoft.MicrosoftEdge_44.18362.1.0_neutral__8wekyb3d8bbwe
Faulting package-relative application ID: MicrosoftEdge
 
Error: (07/14/2019 01:12:32 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IAStorDataMgrSvc.exe, version: 14.8.16.1063, time stamp: 0x58eb8338
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x05e216ed
Faulting process id: 0x1380
Faulting application start time: 0x01d53a02bb2bee8e
Faulting application path: C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
Faulting module path: unknown
Report Id: 5b0720f3-504c-47ea-a480-4868c085d2f3
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (07/14/2019 01:12:31 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: IAStorDataMgrSvc.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.NullReferenceException
   at IAStorUtil.SystemDataModelListener.ProcessSystemDataModelChanges()
   at IAStorUtil.SystemDataModelListener.LoadSavedSystemState()
   at IAStorDataMgr.EventRelay.<Start>b__0(System.Object)
   at System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
   at System.Threading.ThreadPoolWorkQueue.Dispatch()
   at System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()
 
Error: (07/14/2019 01:12:14 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
.
 
 
Operation:
   Instantiating VSS server
 
Error: (07/14/2019 01:12:14 AM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name IVssCoordinatorEx2 cannot be started. [0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
]
 
 
Operation:
   Instantiating VSS server
 
Error: (07/14/2019 01:10:36 AM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: Event provider IntelWLANEventProvider attempted to register query "select * from CIntelQosEvent" whose target class "CIntelQosEvent" in //./ROOT/default namespace does not exist. The query will be ignored.
 
 
System errors:
=============
Error: (07/14/2019 01:12:33 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel® Rapid Storage Technology service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (07/14/2019 01:11:24 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: The Printer Extensions and Notifications service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.
 
Error: (07/14/2019 01:10:09 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The iaStorAfsService service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (07/14/2019 01:10:09 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (45000 milliseconds) while waiting for the iaStorAfsService service to connect.
 
Error: (07/14/2019 01:09:25 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The ZeroConfigService service terminated with the following error: 
%%2147770990
 
Error: (07/14/2019 01:08:35 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: The VMware Horizon Client service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.
 
Error: (07/14/2019 01:06:57 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Network List Service service terminated with the following error: 
The device is not ready.
 
Error: (07/14/2019 01:06:40 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The iphlpsvc service terminated with the following error: 
The device is not ready.
 
 
CodeIntegrity:
===================================
 
Date: 2019-07-14 01:31:42.174
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.
 
Date: 2019-07-14 01:31:42.168
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.
 
Date: 2019-07-14 01:31:42.158
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.
 
Date: 2019-07-14 01:13:53.279
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.
 
Date: 2019-07-14 01:13:53.265
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.
 
Date: 2019-07-14 01:13:53.073
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.
 
Date: 2019-07-14 01:13:53.065
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.
 
Date: 2019-07-14 01:13:53.058
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.
 
==================== Memory info =========================== 
 
BIOS: Dell Inc. 1.8.6 12/12/2017
Motherboard: Dell Inc. 0X2MKR
Processor: Intel® Core™ i7-6700 CPU @ 3.40GHz
Percentage of memory in use: 67%
Total physical RAM: 8048.94 MB
Available physical RAM: 2643.04 MB
Total Virtual: 9968.94 MB
Available Virtual: 3597.61 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:224.66 GB) (Free:98.88 GB) NTFS
Drive e: (My Passport) (Fixed) (Total:1862.98 GB) (Free:1813.35 GB) NTFS
 
\\?\Volume{9418ee22-8e7f-4668-b204-a94b09d00e55}\ () (Fixed) (Total:0.51 GB) (Free:0.08 GB) NTFS
\\?\Volume{616afac5-ee60-493d-8f6b-5152f9f29468}\ (Image) (Fixed) (Total:12.69 GB) (Free:0.63 GB) NTFS
\\?\Volume{dbd7410f-196c-49b5-bb90-bbf877a175c2}\ (ESP) (Fixed) (Total:0.48 GB) (Free:0.44 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: 4FCEFFCB)
 
Partition: GPT.
 
========================================================
Disk: 1 (Size: 1863 GB) (Disk ID: 16F2A91F)
 
Partition: GPT.
 
==================== End of Addition.txt ============================
 
*******************************************************************************************************

Have a good night, and thanks, as always! I look forward to your next comments! :)

 

 


  • 0

#42
RKinner

RKinner

    Malware Expert

  • Expert
  • 21,737 posts
  • MVP

Please verify that you have the latest version of Kaspersky.

 

Are you using Microsoft Office?  (You have to pay for it)

 

Let's run dism again to make sure the new version of windows is properly installed.

 

Open an elevated command prompt:

http://www.howtogeek...-in-windows-10/
(If you open an elevated Command Prompt properly it will say Administrator: Command Prompt in the margin at the top of the window)


Once you have an elevated command prompt:

Type:
 

 DISM  /Online  /Cleanup-Image  /RestoreHealth

 (I use two spaces so you can be sure to see where one space goes.)
Hit Enter.  This will take a while (10-20 minutes) to complete.  Once the prompt returns:

Reboot.  Open an elevated Command Prompt again and type (with an Enter after the line):

sfc  /scannow


This will also take a few minutes.  

When it finishes it will say one of the following:

Windows did not find any integrity violations (a good thing)
Windows Resource Protection found corrupt files and repaired them (a good thing)
Windows Resource Protection found corrupt files but was unable to fix some (or all) of them (not a good thing)

If you get the last result then type:

findstr  /c:"[SR]"  \windows\logs\cbs\cbs.log  >  %UserProfile%\desktop\junk.txt



Hit Enter.  Then type::

 

notepad %UserProfile%\desktop\junk.txt


Hit Enter.

 Copy the text from notepad and paste it into a reply.

 

Then let's cleanup some seagate leftovers:

 

Download the attached fixlist.txt to the same location as FRST

Attached File  fixlist.txt   2.6KB   11 downloads

Run FRST and press Fix
A fix log will be generated please post that

Reboot if the fix doesn't reboot it for you

Run FRST again as before.  Make sure Addition.txt is checked and hit Scan.  Post both logs.



 


  • 0

#43
IndyBlue

IndyBlue

    Member

  • Topic Starter
  • Member
  • PipPip
  • 95 posts
Hi again!
 
(1) I installed Kaspersky Total Security this past week (and I paid for 3 years in advance) and I should have the latest version. I checked my settings, and Kaspersky will update automatically. So, I think I'm good there.
 
(2) Yes, I am using Microsoft Office. I bought the software package along with this computer in fall 2016.
 
(3) Looks like all is well here; this is the response I got after doing the scannow command:
 
C:\WINDOWS\system32>sfc /scannow
 
Beginning system scan.  This process will take some time.
 
Beginning verification phase of system scan.
Verification 100% complete.
 
Windows Resource Protection found corrupt files and successfully repaired them.
For online repairs, details are included in the CBS log file located at
windir\Logs\CBS\CBS.log. For example C:\Windows\Logs\CBS\CBS.log. For offline
repairs, details are included in the log file provided by the /OFFLOGFILE flag.
 
(4) Ran the fixlist, and here is the log that was generated (the system automatically prompted me to reboot when it was done, and I did):

Fix result of Farbar Recovery Scan Tool (x64) Version: 13-07-2019
Ran by indre (14-07-2019 13:17:46) Run:2
Running from C:\Users\indre\Desktop
Loaded Profiles: indre (Available Profiles: indre)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Task: {0FE0644F-58F4-43E8-A63F-AA62CD169246} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {52187049-A19C-4B23-AFFC-5089227DB2E9} - System32\Tasks\Seagate_Install_Launch => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Dashboard.exe
2019-07-14 01:13 - 2019-07-14 01:13 - 000002806 _____ C:\WINDOWS\System32\Tasks\Seagate_Install_Launch
2019-07-12 12:10 - 2016-10-12 00:52 - 000000000 ___DC C:\Users\indre\AppData\Roaming\Seagate
FirewallRules: [{2A5D3459-4437-4C54-AAC4-9E96FEE61614}] => (Block) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe No File
FirewallRules: [{2F7C3E13-8189-49BC-AD54-293606BAB75F}] => (Block) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe No File
FirewallRules: [UDP Query User{DC37BDA6-DFD4-4AE9-A106-AF2D1149CAC6}C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe] => (Allow) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe No File
FirewallRules: [TCP Query User{5BEC10D3-14A2-4D91-86E2-3FF9AC49678E}C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe] => (Allow) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe No File
C:\program files (x86)\seagate
CMD: FOR /F "usebackq delims==" %i IN (`wevtutil el`) DO wevtutil cl "%i"
Reboot:
 
 
 
 
 
 
*****************
 
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0FE0644F-58F4-43E8-A63F-AA62CD169246}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0FE0644F-58F4-43E8-A63F-AA62CD169246}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{52187049-A19C-4B23-AFFC-5089227DB2E9}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{52187049-A19C-4B23-AFFC-5089227DB2E9}" => removed successfully
C:\WINDOWS\System32\Tasks\Seagate_Install_Launch => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Seagate_Install_Launch" => removed successfully
"C:\WINDOWS\System32\Tasks\Seagate_Install_Launch" => not found
C:\Users\indre\AppData\Roaming\Seagate => moved successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2A5D3459-4437-4C54-AAC4-9E96FEE61614}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2F7C3E13-8189-49BC-AD54-293606BAB75F}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{DC37BDA6-DFD4-4AE9-A106-AF2D1149CAC6}C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{5BEC10D3-14A2-4D91-86E2-3FF9AC49678E}C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe" => removed successfully
"C:\program files (x86)\seagate" => not found
 
========= FOR /F "usebackq delims==" %i IN (`wevtutil el`) DO wevtutil cl "%i" =========
 
Failed to clear log Intel-SST-CFD-HDA/IntelSST.
The instance name passed was not recognized as valid by a WMI data provider.
Failed to clear log Microsoft-Windows-LiveId/Analytic.
Access is denied.
Failed to clear log Microsoft-Windows-LiveId/Operational.
Access is denied.
Failed to clear log Microsoft-Windows-USBVideo/Analytic.
The instance name passed was not recognized as valid by a WMI data provider.
 
========= End of CMD: =========
 
 
 
The system needed a reboot.
 
==== End of Fixlog 13:18:14 ====
 
(5) The FARBAR scans are pasted in below.

FRST scan:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 13-07-2019
Ran by indre (administrator) on DESKTOP-EL88UDV (Dell Inc. OptiPlex 7440 AIO) (14-07-2019 13:24:27)
Running from C:\Users\indre\Desktop
Loaded Profiles: indre (Available Profiles: indre)
Platform: Windows 10 Pro Version 1903 18362.239 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
() [File not signed] C:\Program Files (x86)\DELL\DELLOSD\DellOSDService.exe
() [File not signed] C:\Program Files (x86)\DELL\DELLOSD\MediaButtons.exe
() [File not signed] C:\Program Files (x86)\Intel\Intel® Security Assist\isaHelperService.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.YourPhone_1.19062.451.0_x64__8wekyb3d8bbwe\YourPhone.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(CyberLink Corp. -> CyberLink) C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvc_P2G8.exe
(CyberLink Corp. -> CyberLink) C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Dell Inc -> CREDANT Technologies, Inc.) C:\Program Files\Dell\Dell Data Protection\Client Security Framework\Dell.SecurityFramework.Agent.exe
(Dell Inc -> CREDANT Technologies, Inc.) C:\Program Files\Dell\Dell Data Protection\Client Security Framework\Dell.SecurityFramework.UserProcess.exe
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\Dell Data Protection\Client Security Framework\DCF.Loader.exe
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe
(Dell Inc -> Dell, Inc.) C:\Program Files\Dell\Dell Data Protection\Client Security Framework\Dell.SecurityFramework.LocalServer.exe
(Dell Inc. -> Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(Dell Inc. -> Dell Products, LP.) C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
(FabulaTech -> ) C:\Program Files (x86)\VMware\ScannerRedirection\ftscanmgr.exe
(FabulaTech -> ) C:\Program Files\Common Files\VMware\DeviceRedirectionCommon\ftnlsv.exe
(FabulaTech -> VMware) C:\Program Files (x86)\Common Files\VMware\SerialPortRedirection\Client\vmwsprrdpwks.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler64.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PrivacyIconClient.exe
(Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel® Intel Network Drivers -> Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Intel® Intel Network Drivers -> Intel® Corporation) C:\Program Files\Intel\NCS2\WMIProv\ncs2prov.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127171.inf_amd64_368f8c7337214025\igfxCUIService.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127171.inf_amd64_368f8c7337214025\igfxEM.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127171.inf_amd64_368f8c7337214025\IntelCpHDCPSvc.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127171.inf_amd64_368f8c7337214025\IntelCpHeciSvc.exe
(Intel® Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Intel® Wireless Display -> Intel) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksde.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksdeui.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\avp.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\avpui.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\indre\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c\SkypeApp.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.WindowsStore_11905.1001.4.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(PC-Doctor, Inc. -> PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7033.2285\DSAPI.exe
(PC-Doctor, Inc. -> PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7033.2285\pcdrwi.exe
(Plex, Inc -> ) C:\Program Files (x86)\Plex\Plex Media Server\Plex Tuner Service.exe
(Plex, Inc -> Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex DLNA Server.exe
(Plex, Inc -> Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe
(Plex, Inc -> Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe
(Plex, Inc -> Python Software Foundation) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
(Plex, Inc -> Python Software Foundation) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(TEFINCOM S.A. -> ) C:\Program Files (x86)\NordVPN\nordvpn-service.exe
(TEFINCOM S.A. -> NordVPN) C:\Program Files (x86)\NordVPN\NordVPN.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\VMware\VMware Horizon View Client\bin\vmware-view-usbd.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\VMware\VMware Horizon View Client\wsnm\wsnm.exe
(Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe
(Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe
(Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD App Manager\Plugins\WD Backup\App\WDBackupService.exe
(Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD App Manager\WDAppManager.exe
(Western Digital Techologies -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8853248 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_MAXX6] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1419008 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [VMware Netlink 3 HV Install Utility] => C:\Program Files\Common Files\VMware\DeviceRedirectionCommon\ftnliu.exe [70080 2015-11-04] (FabulaTech -> )
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [302904 2019-05-07] (Apple Inc. -> Apple Inc.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [322120 2019-03-15] (Intel® Rapid Storage Technology -> Intel Corporation)
HKLM\...\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [718256 2015-12-22] (Waves Inc -> Waves Audio Ltd.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942864 2016-10-13] (Logitech -> Logitech, Inc.)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PrivacyIconClient.exe [1176208 2017-11-09] (Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation)
HKLM-x32\...\Run: [WDDiscovery] => C:\Program Files (x86)\Western Digital\Discovery\Current\WD Discovery.exe [81376496 2019-07-12] (Western Digital Technologies, Inc. -> Western Digital Corporation)
HKLM-x32\...\Run: [WDAppManager] => C:\Program Files (x86)\Western Digital\WD App Manager\AppManagerLauncher.exe [21888 2019-01-02] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\Run: [Plex Media Server] => C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe [23081448 2019-04-04] (Plex, Inc -> Plex, Inc.)
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\Run: [NordVPN] => C:\Program Files (x86)\NordVPN\NordVPN.exe [2186704 2019-05-22] (TEFINCOM S.A. -> NordVPN)
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\Run: [kpm.exe] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe [584128 2019-02-08] (Kaspersky Lab -> AO Kaspersky Lab)
HKLM\...\Drivers32-x32: [vidc.pDAD] => prodad-codec.dll
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.100\Installer\chrmstp.exe [2019-06-20] (Google LLC -> Google LLC)
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {08E2F16C-4C59-4C34-A03C-C83EEEDEBBDE} - System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec-Logon => C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-17] (Intel® Software Asset Manager -> Intel Corporation)
Task: {0C0614F0-18B6-495C-99F1-B61633EE7B2A} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel® Update Manager\bin\iumsvc.exe
Task: {1D566C7D-1CD5-4E77-826C-E0DF557F6BFA} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_223_Plugin.exe [1457208 2019-07-10] (Adobe Inc. -> Adobe)
Task: {1E20F289-46AA-4529-B808-962BFEF268A3} - System32\Tasks\RtHDVBg_PushButton => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1419008 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {267B2E60-3693-45B1-B32D-E5AA4FA083F4} - System32\Tasks\WD Discovery Service Task indre => C:\Program Files (x86)\Western Digital\Discovery\Current\Service\WDDiscoveryService.exe [71408 2019-07-12] (Western Digital Technologies, Inc. -> )
Task: {27CEA27E-1BF2-4A16-B5AE-DCA79020DF0D} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [816960 2017-10-11] (Intel® Trust Services -> Intel® Corporation)
Task: {2BE02930-09E5-4DB5-86B2-C883307D310D} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_223_pepper.exe [1453112 2019-07-10] (Adobe Inc. -> Adobe)
Task: {39820E81-9B7D-411F-A870-C6BEBCB2BF30} - System32\Tasks\Intel\Intel Telemetry 2 => C:\Program Files\Intel\Telemetry 2.0\lrio.exe [1698000 2015-06-05] (Intel® Software -> Intel Corporation)
Task: {42854805-A985-4C19-9336-2E724C851DA1} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [113616 2019-07-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {4336A3CB-532E-423B-9674-2DF223FA5E83} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26804232 2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {4DF09A94-B680-4D73-A2BA-B28905CCA70D} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [39920 2018-10-24] (Garmin International, Inc. -> )
Task: {53926FCA-0182-464C-A702-AEC117C4AF2D} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26804232 2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {5EF9065E-7942-4205-9A7E-625FDF39B32F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [136056 2019-01-02] (HP Inc. -> HP Inc.)
Task: {6B5B7726-D2CB-4DB7-B19E-39D4BB205AFB} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [113616 2019-07-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {6D0AA64B-75B4-49CF-9C53-3BF5D9356A9D} - System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec => C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-17] (Intel® Software Asset Manager -> Intel Corporation)
Task: {82F39D33-C846-4F84-8898-8F68198ADD97} - System32\Tasks\CLVDLauncher => C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLVDLauncher.exe [340440 2015-01-28] (CyberLink Corp. -> CyberLink Corp.)
Task: {83C8BC3C-312F-4391-A237-23638EBA6AD3} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1448512 2019-07-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {8B3F29DA-404A-4CB9-8309-9D94ECAA8D3F} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvc_P2G8.exe [110008 2016-04-27] (CyberLink Corp. -> CyberLink)
Task: {8D960D58-2C65-4690-A008-63A3B9664FD6} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [654712 2019-06-05] (HP Inc. -> HP Inc.)
Task: {A5585A2F-2224-44F3-B48A-C02AA6E9CD5D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-09-11] (Google Inc -> Google Inc.)
Task: {BEEC0D34-AA7B-4933-B79B-EE5F2DA284E3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-07-10] (Adobe Inc. -> Adobe)
Task: {C9DAB848-B95A-4118-8DAB-0AA8CAE862C4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1195544 2018-12-16] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Task: {D3E17C23-CA8A-4B0D-A146-AC1F38D7DF2A} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1448512 2019-07-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {DCF36F4E-53FF-403E-B92A-CAFE9380489C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616320 2018-01-08] (Apple Inc. -> Apple Inc.)
Task: {ECD51CA1-564E-49C6-A83B-0A4B7EC42B15} - System32\Tasks\WD Device Agent Task indre => C:\Users\indre\AppData\Roaming\WD Discovery\plugins\com.wdc.plugin.catalog\current\library\WD Device Agent.exe [724008 2019-06-18] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
Task: {F219FE43-71D7-4843-8134-11FF7BD69ACF} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistInstaller.exe [1512920 2019-05-24] (Dell Inc. -> Dell Inc.)
Task: {F266FDCC-EAB9-4691-867D-FA95BDE06352} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [791232 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
Task: {F932D694-A1C8-4A80-9BEA-DAAFEF0B6FE1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-09-11] (Google Inc -> Google Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{6fbafdae-3f34-452d-bbc1-3182c4eed1fc}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{df5feca7-b365-4e54-a128-6afee4fc4200}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{eb569711-9ed4-49b4-a209-84f1068bb002}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell17win10.msn.com/?pc=DCTE
SearchScopes: HKU\S-1-5-21-1593158232-969496310-2340663774-1001 -> DefaultScope {97FF47F7-FF6D-4CCE-B19F-284086150FBF} URL = 
SearchScopes: HKU\S-1-5-21-1593158232-969496310-2340663774-1001 -> {97FF47F7-FF6D-4CCE-B19F-284086150FBF} URL = 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2019-06-25] (Microsoft Corporation -> Microsoft Corporation)
BHO: No Name -> {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2}' -> No File
BHO: Kaspersky Protection -> {EC1E29BB-F56A-45D8-B023-D3EF710FA0E0} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
BHO: Kaspersky Password Manager -> {F710F7E5-A520-471D-989C-F653AC328FB2} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\x64\ie_engine.dll [2019-05-08] (Kaspersky Lab -> AO Kaspersky Lab)
BHO-x32: No Name -> {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2}' -> No File
BHO-x32: CutePDF Form Filler Helper -> {D41289F2-69C6-417B-897E-C653D677CBAF} -> C:\Program Files (x86)\Acro Software\CutePDF Filler Evaluation\CPFillerCoE.dll [2014-03-27] (Acro Software Inc. -> Acro Software Inc.)
BHO-x32: Kaspersky Protection -> {EC1E29BB-F56A-45D8-B023-D3EF710FA0E0} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
BHO-x32: Kaspersky Password Manager -> {F710F7E5-A520-471D-989C-F653AC328FB2} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\ie_engine.dll [2019-05-08] (Kaspersky Lab -> AO Kaspersky Lab)
Toolbar: HKLM - Kaspersky Protection Toolbar - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
Toolbar: HKLM-x32 - Kaspersky Protection Toolbar - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
Toolbar: HKU\S-1-5-21-1593158232-969496310-2340663774-1001 -> Kaspersky Protection Toolbar - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} hxxps://meetny.webex.com/client/WBXclient-T30L10NSP6EP6-20000/webex/ieatgpc1.cab
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-07-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-07-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-07-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-07-14] (Microsoft Corporation -> Microsoft Corporation)
 
FireFox:
========
FF DefaultProfile: 1cu7vqt4.default-1534000050440
FF ProfilePath: C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440 [2019-07-11]
FF Homepage: Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440 -> hxxps://www.google.com/
FF Extension: (ETP Search Volume Study) - C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440\Extensions\[email protected] [2019-06-26]
FF Extension: (Notifier for Gmail™) - C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440\Extensions\[email protected] [2019-03-31]
FF Extension: (Honey) - C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440\Extensions\[email protected] [2019-05-18]
FF Extension: (Kaspersky Password Manager) - C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440\Extensions\[email protected] [2019-05-08] [UpdateUrl:hxxps://special.s.kaspersky-labs.com/firefox_extensions/kpm_win_add_on/update.json]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Extension: (Kaspersky Protection) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\FFExt\light_plugin_firefox\addon.xpi [2019-07-06]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_223.dll [2019-07-10] (Adobe Inc. -> )
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_223.dll [2019-07-10] (Adobe Inc. -> )
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2019-04-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-14] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-14] (Google Inc -> Google LLC)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-05-02] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1593158232-969496310-2340663774-1001: @zoom.us/ZoomVideoPlugin -> C:\Users\indre\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2018-04-06] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\kl_prefs_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.js [2019-07-07] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\kl_config_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.cfg [2019-07-07] <==== ATTENTION
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default [2019-07-14]
CHR Extension: (Slides) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-12]
CHR Extension: (Kaspersky Protection) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\amkpcclbbgegoafihnpgomddadjhcadd [2019-07-06]
CHR Extension: (Docs) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12]
CHR Extension: (Google Drive) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-09-11]
CHR Extension: (YouTube) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-09-11]
CHR Extension: (Honey) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2019-07-11]
CHR Extension: (uBlock Origin) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2019-07-13]
CHR Extension: (Notifier for Gmail™) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcjichoefijpinlfnjghokpkojhlhkgl [2019-03-25]
CHR Extension: (Kaspersky Password Manager) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhnkblpjbkfklfloegejegedcafpliaa [2019-07-12]
CHR Extension: (Adobe Acrobat) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2019-06-11]
CHR Extension: (Sheets) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-12]
CHR Extension: (Google Docs Offline) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-22]
CHR Extension: (Avast Online Security) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2019-07-01]
CHR Extension: (F.B.(FluffBusting)Purity) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmkinhboiljjkhaknpaeaicmdjhagpep [2019-07-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-07]
CHR Extension: (Gmail) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-03-26]
CHR Extension: (Chrome Media Router) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-06-20]
CHR Profile: C:\Users\indre\AppData\Local\Google\Chrome\User Data\Guest Profile [2019-07-08]
CHR Profile: C:\Users\indre\AppData\Local\Google\Chrome\User Data\System Profile [2019-07-08]
CHR HKLM\...\Chrome\Extension: [amkpcclbbgegoafihnpgomddadjhcadd] - hxxps://chrome.google.com/webstore/detail/amkpcclbbgegoafihnpgomddadjhcadd
CHR HKU\S-1-5-21-1593158232-969496310-2340663774-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhnkblpjbkfklfloegejegedcafpliaa] - hxxps://chrome.google.com/webstore/detail/dhnkblpjbkfklfloegejegedcafpliaa
CHR HKLM-x32\...\Chrome\Extension: [amkpcclbbgegoafihnpgomddadjhcadd] - hxxps://chrome.google.com/webstore/detail/amkpcclbbgegoafihnpgomddadjhcadd
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [96056 2019-04-29] (Apple Inc. -> Apple Inc.)
R2 AVP19.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\avp.exe [619640 2018-02-28] (Kaspersky Lab -> AO Kaspersky Lab)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11413600 2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
S4 dcu-oobe; C:\Program Files (x86)\Dell\CommandUpdate\OobeService.exe [84408 2016-06-07] (Dell Inc. -> Dell Inc.)
R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [209392 2019-02-28] (Dell Inc -> Dell Inc.)
R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3363824 2019-02-28] (Dell Inc -> Dell Inc.)
R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [218096 2019-02-28] (Dell Inc -> Dell Inc.)
R2 Dell Hardware Support; C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7033.2285\DSAPI.exe [1050952 2019-06-02] (PC-Doctor, Inc. -> PC-Doctor, Inc.)
R2 Dell WMI Service; C:\Program Files (x86)\DELL\DELLOSD\DellOSDService.exe [151552 2015-06-29] () [File not signed]
R2 DellMgmtAgent; C:\Program Files\Dell\Dell Data Protection\Client Security Framework\Dell.SecurityFramework.Agent.exe [22280 2016-07-13] (Dell Inc -> CREDANT Technologies, Inc.)
R2 DellMgmtLoader; C:\Program Files\Dell\Dell Data Protection\Client Security Framework\DCF.Loader.exe [35080 2016-07-13] (Dell Inc -> Dell Inc.)
R3 DellMgmtServer; C:\Program Files\Dell\Dell Data Protection\Client Security Framework\Dell.SecurityFramework.LocalServer.exe [52488 2016-07-13] (Dell Inc -> Dell, Inc.)
R2 ftnlsv3hv; C:\Program Files\Common Files\VMware\DeviceRedirectionCommon\ftnlsv.exe [233920 2015-11-04] (FabulaTech -> )
R2 ftscanmgr; C:\Program Files (x86)\VMware\ScannerRedirection\ftscanmgr.exe [6363792 2015-07-31] (FabulaTech -> )
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [356728 2019-06-12] (HP Inc. -> HP Inc.)
S3 iaStorAfsService; C:\WINDOWS\IAStorAfsService\iaStorAfsService.exe [2413752 2017-08-18] (Intel® Rapid Storage Technology -> Intel Corporation)
R2 ibtsiva; C:\WINDOWS\system32\ibtsiva.exe [190208 2016-10-15] (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation)
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [742704 2017-10-11] (Intel® Trust Services -> Intel® Corporation)
S3 Intel® Security Assist; C:\Program Files (x86)\Intel\Intel® Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed]
S2 Intel® TPM Provisioning Service; C:\Program Files\Intel\iCLS Client\TPMProvisioningService.exe [668472 2017-10-11] (Intel® Trust Services -> Intel® Corporation)
R3 Intel® WiDi SAM; C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-17] (Intel® Software Asset Manager -> Intel Corporation)
R2 IntelUSBoverIP; C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe [396992 2015-07-06] (Intel® Wireless Display -> Intel)
R2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel® Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [213648 2017-11-09] (Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation)
S3 klvssbridge64_19.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\vssbridge64.exe [414352 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R2 kpm_launch_service; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe [354008 2019-02-08] (Kaspersky Lab -> AO Kaspersky Lab)
R2 KSDE3.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksde.exe [617016 2018-02-28] (Kaspersky Lab -> AO Kaspersky Lab)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [310880 2019-01-23] (Intel Corporation -> )
R2 nordvpn-service; C:\Program Files (x86)\NordVPN\nordvpn-service.exe [217040 2019-05-22] (TEFINCOM S.A. -> )
R2 PlexUpdateService; C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe [1140200 2019-04-04] (Plex, Inc -> Plex, Inc.)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [253776 2015-09-02] (CyberLink Corp. -> CyberLink)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [310016 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5773384 2019-07-14] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [39896 2019-05-24] (Dell Inc. -> Dell Inc.)
S2 tcsd_win32.exe; C:\Program Files\Dell\Dell Data Protection\Drivers\TSS\bin\tcsd_win32.exe [1636352 2012-12-10] (Security Innovation, Inc.) [File not signed]
R2 vmware-view-usbd; C:\Program Files (x86)\VMware\VMware Horizon View Client\bin\vmware-view-usbd.exe [1158984 2016-02-23] (VMware, Inc. -> VMware, Inc.)
R2 vmwsprrdpwks; C:\Program Files (x86)\Common Files\VMware\SerialPortRedirection\Client\vmwsprrdpwks.exe [261776 2015-05-08] (FabulaTech -> VMware)
R2 WavesSysSvc; C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe [613296 2015-12-22] (Waves Inc -> Waves Audio Ltd.)
S3 WD Backup Drive Helper; C:\WINDOWS\SysWOW64\dllhost.exe /Processid:{4AB831D3-8315-414C-8A7A-303105288D0B} [19256 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
S3 WD Backup Drive Helper; C:\WINDOWS\SysWOW64\dllhost.exe /Processid:{4AB831D3-8315-414C-8A7A-303105288D0B} [19256 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
S3 WD Backup Snapshot; C:\WINDOWS\SysWOW64\dllhost.exe /Processid:{302480DF-3AC5-4400-BE7B-DD77AF93B6DD} [19256 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
S3 WD Backup Snapshot; C:\WINDOWS\SysWOW64\dllhost.exe /Processid:{302480DF-3AC5-4400-BE7B-DD77AF93B6DD} [19256 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [524632 2018-03-26] (Western Digital Techologies -> Western Digital Technologies, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [4098056 2019-03-19] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [113992 2019-03-19] (Microsoft Corporation -> Microsoft Corporation)
R2 wsnm; C:\Program Files (x86)\VMware\VMware Horizon View Client\wsnm\wsnm.exe [541400 2016-03-25] (VMware, Inc. -> VMware, Inc.)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [4107360 2019-01-23] (Intel Corporation -> Intel® Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R0 cm_km; C:\WINDOWS\System32\DRIVERS\cm_km.sys [243400 2018-01-27] (Kaspersky Lab -> AO Kaspersky Lab)
R3 DDDriver; C:\WINDOWS\System32\drivers\dddriver64Dcsa.sys [40824 2019-02-27] (Microsoft Windows Hardware Compatibility Publisher -> Dell Inc.)
S3 DellProf; C:\WINDOWS\system32\drivers\DellProf.sys [41208 2018-05-08] (Techporch Incorporated -> Dell Computer Corporation)
S3 iaStorAfs; C:\WINDOWS\System32\drivers\iaStorAfs.sys [70664 2017-08-18] (Intel® Rapid Storage Technology -> Intel Corporation)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [732416 2016-10-15] (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation)
R3 IntcAzAudAddService; C:\WINDOWS\system32\drivers\RTDVHD64.sys [2677504 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.)
R0 klbackupdisk; C:\WINDOWS\System32\DRIVERS\klbackupdisk.sys [75600 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klbackupflt; C:\WINDOWS\System32\DRIVERS\klbackupflt.sys [125568 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [91472 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
S0 klelam; C:\WINDOWS\System32\DRIVERS\klelam.sys [29208 2017-03-30] (Microsoft Windows Early Launch Anti-malware Publisher -> AO Kaspersky Lab)
R3 klflt; C:\WINDOWS\system32\DRIVERS\klflt.sys [236672 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klhk; C:\WINDOWS\System32\drivers\klhk.sys [1093248 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klids; C:\ProgramData\Kaspersky Lab\AVP19.0.0\Bases\klids.sys [197464 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [1168000 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klim6; C:\WINDOWS\system32\DRIVERS\klim6.sys [58704 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klkbdflt; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [60536 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klmouflt; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [60784 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klpd; C:\WINDOWS\System32\DRIVERS\klpd.sys [50304 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
S3 klpnpflt; C:\WINDOWS\system32\DRIVERS\klpnpflt.sys [46416 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 kltap; C:\WINDOWS\System32\drivers\kltap.sys [48080 2018-02-12] (AnchorFree Inc -> The OpenVPN Project)
R0 klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [245272 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klupd_klif_kimul; C:\WINDOWS\System32\Drivers\klupd_klif_kimul.sys [99152 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
S3 klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [302368 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R0 klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [116104 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [198768 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [104576 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klwtp; C:\WINDOWS\system32\DRIVERS\klwtp.sys [184960 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [218240 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 Netwtw06; C:\WINDOWS\System32\drivers\Netwtw06.sys [8832800 2019-05-17] (Intel® Wireless Connectivity Solutions -> Intel Corporation)
R3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [779232 2016-08-04] (Realtek Semiconductor Corp. -> Realsil Semiconductor Corporation)
R0 SEDFilter; C:\WINDOWS\System32\DRIVERS\SEDFilter.sys [197808 2016-07-13] (Dell Inc -> Dell Inc.)
S3 SWDUMon; C:\WINDOWS\system32\DRIVERS\SWDUMon.sys [13920 2016-09-11] (SlimWare Utilities Inc. -> )
R3 tapnordvpn; C:\WINDOWS\System32\drivers\tapnordvpn.sys [44896 2018-07-24] (TEFINCOM S.A. -> The OpenVPN Project)
R3 usb3Hub; C:\WINDOWS\System32\drivers\usb3Hub.sys [212056 2015-07-06] (Intel® Wireless Display -> Windows ® Win 7 DDK provider)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46472 2019-03-19] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [333784 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
R1 wdfsconnect2017; C:\WINDOWS\system32\drivers\wdfsconnect2017.sys [468112 2017-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies, Inc.)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [62432 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
R3 wdvpnpbus; C:\WINDOWS\System32\drivers\wdvpnpbus.sys [20624 2017-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies, Inc.)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-07-14 13:24 - 2019-07-14 13:25 - 000045801 ____C C:\Users\indre\Desktop\FRST.txt
2019-07-14 13:19 - 2019-07-14 13:19 - 000000000 ___HD C:\OneDriveTemp
2019-07-14 13:17 - 2019-07-14 13:18 - 000004131 ____C C:\Users\indre\Desktop\Fixlog.txt
2019-07-14 13:15 - 2019-07-14 13:15 - 000002660 _____ C:\Users\indre\Downloads\fixlist (1).txt
2019-07-14 12:57 - 2019-07-14 13:15 - 000000935 ____C C:\Users\indre\Desktop\response.txt
2019-07-14 11:06 - 2019-07-14 11:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2019-07-14 05:05 - 2019-07-14 01:14 - 000000000 ____D C:\Windows.old
2019-07-14 04:54 - 2019-07-14 05:05 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2019-07-14 04:53 - 2019-07-14 04:54 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2019-07-14 04:53 - 2019-07-14 04:53 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2019-07-14 04:51 - 2019-07-14 04:51 - 025902080 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 025444864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 022625280 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 019849216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 019811328 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 018017792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 008011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 007802224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 007758336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 007175168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 007008768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 006218752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 005919744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 005745504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 005500416 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 005083352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 005014016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 004863488 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 004578816 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 004481536 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 004348408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 004306432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 004129416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 003837440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 003635200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 003525592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 003487232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 003365376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 003243080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 002956984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2019-07-14 04:51 - 2019-07-14 04:51 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2019-07-14 04:51 - 2019-07-14 04:51 - 002494232 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 002398208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 002314440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 002235936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 002216448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 002190648 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 002072152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001866064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001847808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsservices.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001715000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntVirtualization.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001611576 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVIntegration.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001608192 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001555688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001539584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001510960 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001501496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001493944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001391416 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 001383736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystemController.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001319936 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001283384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2019-07-14 04:51 - 2019-07-14 04:51 - 001282560 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001273344 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001273176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001248256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOE.DLL
2019-07-14 04:51 - 2019-07-14 04:51 - 001244728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001192096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 001151816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001124864 _____ (Microsoft Corporation) C:\WINDOWS\system32\CBDHSvc.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001105776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001098712 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001080832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001071928 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 001060352 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001043768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPolicy.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001039872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOE.DLL
2019-07-14 04:51 - 2019-07-14 04:51 - 001012792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001007104 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001000960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000986112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000957240 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVManifest.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000912896 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000875008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000843776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000833536 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000829544 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioIso.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000827192 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVOrchestration.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000816440 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntStreamingManager.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000813568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000806400 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000801592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2019-07-14 04:51 - 2019-07-14 04:51 - 000782120 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000774152 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000769336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000744248 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOE.DLL
2019-07-14 04:51 - 2019-07-14 04:51 - 000743424 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000741176 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVReporting.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000737552 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOD.DLL
2019-07-14 04:51 - 2019-07-14 04:51 - 000705536 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000700928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapi.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000682744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOE.DLL
2019-07-14 04:51 - 2019-07-14 04:51 - 000669496 _____ (Microsoft Corporation) C:\WINDOWS\system32\computecore.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000666280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOD.DLL
2019-07-14 04:51 - 2019-07-14 04:51 - 000665912 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVCatalog.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000649016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPublishing.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000612352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000568336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000551824 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000537608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000529408 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000516752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000510768 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000500224 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2019-07-14 04:51 - 2019-07-14 04:51 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpshell.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000496128 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000494904 _____ (Microsoft Corporation) C:\WINDOWS\system32\TransportDSA.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000472576 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedRealitySvc.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000463272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000460288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcSpecfc.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000450048 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000429568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000422912 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000422008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2019-07-14 04:51 - 2019-07-14 04:51 - 000420360 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000400896 _____ (Microsoft Corporation) C:\WINDOWS\system32\DispBroker.Desktop.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000394040 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVScripting.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\provplatformdesktop.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000382976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcLayers.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000376320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspbde40.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000366184 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000363008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000357376 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000333824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapibase.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000321024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.FileExplorer.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000317952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000316216 _____ (Microsoft Corporation) C:\WINDOWS\system32\computestorage.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000307200 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000300184 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscobj.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000294400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_AnalogShell.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000267528 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000261016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityUxHost.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000257848 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVFileSystemMetadata.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000257536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\provplatformdesktop.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\RdpRelayTransport.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msltus40.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000231432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVShNotify.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000228664 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVStreamMap.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
2019-07-14 04:51 - 2019-07-14 04:51 - 000210440 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000202752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cscobj.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000202552 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVStreamingUX.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000186880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
2019-07-14 04:51 - 2019-07-14 04:51 - 000183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngOnline.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000181560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVDllSurrogate.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000177664 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetpp.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000172856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVNice.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000136720 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-kernel-processor-power-events.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\appvetwclientres.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000129088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000099712 _____ (Microsoft Corporation) C:\WINDOWS\system32\FsIso.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000093496 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000093312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpfve.sys
2019-07-14 04:51 - 2019-07-14 04:51 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompMgmtLauncher.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmlib.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000088064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000084280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winhvr.sys
2019-07-14 04:51 - 2019-07-14 04:51 - 000084280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2019-07-14 04:51 - 2019-07-14 04:51 - 000078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000058825 _____ C:\WINDOWS\system32\srms.dat
2019-07-14 04:51 - 2019-07-14 04:51 - 000053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeUISrv.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000042296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000037904 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncAppvPublishingServer.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimsg.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000022024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ScriptRunner.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000021304 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\appvetwstreamingux.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 017786368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 014816256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 009917752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 007887440 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 007831368 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 007636616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 007275008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 007242312 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 006534712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 006381568 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 006224296 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 006068840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 006036480 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 005939712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 005071360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 005040640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 004562920 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 004552336 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 004537344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 004470784 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 004034048 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 004012032 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 004008960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Service.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003947520 _____ (Microsoft Corporation) C:\WINDOWS\system32\tellib.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003914480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 003771392 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003748864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003734456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003725312 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 003698176 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003654656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003590968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 003550720 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003372952 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003327256 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003263488 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003261440 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003106304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003084800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002990608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 002876416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002871824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 002870784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002798592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 002771008 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002763552 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002725376 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 002698552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 002697728 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002656768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002587328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002576384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002561536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002550584 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002490712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002449456 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002443264 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002321408 _____ (The ICU Project) C:\WINDOWS\system32\icu.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002306048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002281984 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002258336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002178048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmgaclient.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002117160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002081976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001999440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001979392 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001954960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001945600 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001940952 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001918976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001893888 _____ (The ICU Project) C:\WINDOWS\SysWOW64\icu.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001884672 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001856000 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001856000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConstraintIndex.Search.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001841152 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001830416 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001815040 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001784832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001781248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001761792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001754232 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2019-07-14 04:50 - 2019-07-14 04:50 - 001745920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001743672 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001721344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001721144 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001717560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001697792 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001697280 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001690624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001687552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001657856 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001651848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001647280 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001635328 _____ (Microsoft Corporation) C:\WINDOWS\system32\TaskFlowDataEngine.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001633648 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001608704 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001587712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001562640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001553408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmgaserver.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 001535288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001515008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmgaclient.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001509936 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 001505808 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpbase.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001480704 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpsharercom.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001473488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001458176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001437184 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 001422848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 001413704 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001413632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001395600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001393960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001375232 _____ (Microsoft Corporation) C:\WINDOWS\system32\APMon.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001366528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001366128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2019-07-14 04:50 - 2019-07-14 04:50 - 001362432 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001356800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001345024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001337656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001333248 _____ (Microsoft Corporation) C:\WINDOWS\system32\MiracastReceiver.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001321472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001313792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001304888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001282048 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsf3gip.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001262864 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001261568 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001260032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpsharercom.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001250432 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 001213456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpbase.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001182232 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 001159680 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001149928 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 001146880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001101312 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001092096 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001068856 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001067008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001065984 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001063944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001062912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmgaserver.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 001062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\BTAGService.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001042944 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2019-07-14 04:50 - 2019-07-14 04:50 - 001040896 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcRefreshTask.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001010176 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001007160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001006592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000984376 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000947200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000939504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000928776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000919040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000916480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000913408 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000911360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MiracastReceiver.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000910272 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000900608 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000892696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000889656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000888056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000879792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000878080 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2019-07-14 04:50 - 2019-07-14 04:50 - 000876856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000864768 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000862720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Service.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000861696 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000858112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000858112 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000830976 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000824832 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000822072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000821696 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000818656 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000817152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\PEAuth.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000811192 _____ C:\WINDOWS\SysWOW64\locale.nls
2019-07-14 04:50 - 2019-07-14 04:50 - 000811192 _____ C:\WINDOWS\system32\locale.nls
2019-07-14 04:50 - 2019-07-14 04:50 - 000810512 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000804880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000797112 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000773168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000772656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000771584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000751256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000740664 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000739328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000727040 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000726328 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000722072 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000706544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mscms.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntime.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000701952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000696320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsreg.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000680760 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000680448 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000679368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000678400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000675328 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntimewindows.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000674816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000674072 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000673152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000673080 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000668160 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000667272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000663552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000645632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000644096 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000642008 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000637968 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000628616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000621568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000613904 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000611328 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000602432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mscms.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_9.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000592896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000589592 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000588464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000586552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000574976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_9.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000562176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2019-07-14 04:50 - 2019-07-14 04:50 - 000537088 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000537088 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000532992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.UserService.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000531976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2019-07-14 04:50 - 2019-07-14 04:50 - 000531464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000523912 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000516608 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000515896 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000513336 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000511288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000509440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000505856 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000481592 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000480768 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskcomp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000477496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2019-07-14 04:50 - 2019-07-14 04:50 - 000474112 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinDataModelServer.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000472064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000467456 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2019-07-14 04:50 - 2019-07-14 04:50 - 000466624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000464696 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000462848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000462352 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000461824 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000457016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.ConversationalAgent.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000455680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000451896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000441144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000435200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000435000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000425264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000423936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000420152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmicmiplugin.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000415800 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000415544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2019-07-14 04:50 - 2019-07-14 04:50 - 000406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000404392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000401416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000390456 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000388608 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000386016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000381240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000379192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000375808 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskcomp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000363624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000358944 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsta.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\MbbCx.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000353960 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000350208 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManager.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000344064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.BlueLightReduction.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000339520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbt.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000336928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000336752 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSrvPolicyManager.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000327680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000324624 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcommdlg.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000312320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL
2019-07-14 04:50 - 2019-07-14 04:50 - 000309760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000307712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000301568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000296976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000296448 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000284536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000283152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mssecflt.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000283136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000280576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000279624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winsta.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000278528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000274128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcTok.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000270336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\DesktopSwitcherDataModel.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3svc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000268216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000257536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbaudio2.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000248088 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000246784 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerCsp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000242688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_CapabilityAccess.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpnServiceDS.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000233984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\schtasks.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManagerClient.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000223248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelppm.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000220680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdigest.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000214032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ifsutil.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000211968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\hidclass.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000208184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\processr.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000205112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winquic.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000202040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000201256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdppm.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000199688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdk8.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000199184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000199176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000194176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winquic.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000193848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000193800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000187920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ifsutil.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000187392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schtasks.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\AarSvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000182072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpioclx.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000180536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000180024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ulib.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000179512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000178192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000164152 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000161848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000159232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BitLockerCsp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmgaproxystub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000149512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ulib.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000146920 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000146744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleprn.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\GraphicsCapture.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000142544 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingUI.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000142136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbus.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\luafv.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000139472 _____ (Microsoft Corporation) C:\WINDOWS\system32\userenv.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000134760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000132096 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000129848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mup.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000129024 _____ (Microsoft Corporation) C:\WINDOWS\system32\GameChatTranscription.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssitlb.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000127296 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000123912 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdnet.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinAUG.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000120352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapistub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapi32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000117048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000116184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\userenv.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000115200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleprn.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000115120 _____ (Microsoft Corporation) C:\WINDOWS\system32\phoneactivate.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\agilevpn.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Taskbar.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssitlb.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpoext.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GraphicsCapture.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3msm.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000102216 _____ (Microsoft Corporation) C:\WINDOWS\system32\changepk.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mapistub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mapi32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000098816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GameChatTranscription.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000098816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2019-07-14 04:50 - 2019-07-14 04:50 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3api.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000089544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000088560 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3api.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3msm.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApiSetHost.AppExecutionAlias.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\efsext.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000071720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwm.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\monitor.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\UsoClient.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000066360 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptdll.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000065064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsManagementServiceWinRt.ProxyStub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcadm.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ApiSetHost.AppExecutionAlias.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmgaproxystub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssprxy.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\audioresourceregistrar.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000056008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptdll.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000055608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storufs.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efsext.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000047000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\hidparse.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\hidusb.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidusb.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiredNetworkCSP.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpgradeResultsUI.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000037888 _____ C:\WINDOWS\system32\usocoreps.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthMini.SYS
2019-07-14 04:50 - 2019-07-14 04:50 - 000036152 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mskssrv.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxssrv.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\FaxPrinterInstaller.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\KNetPwrDepBroker.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000028936 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmbuspipe.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilotdiag.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wci.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\fixmapi.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\bindflt.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fixmapi.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDJPN.DLL
2019-07-14 04:50 - 2019-07-14 04:50 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaevts.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\pacjsworker.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimg32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimg32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCertResources.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCertResources.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6r.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3r.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tier2punctuations.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6r.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3r.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 004470272 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2019-07-14 04:48 - 2019-07-14 04:48 - 001166488 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 000903168 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsFilt.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 000778912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 000568320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsFilt.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 000124568 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 000103072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\XPSSHHDR.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 000081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XPSSHHDR.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 000076060 _____ C:\WINDOWS\SysWOW64\xpsrchvw.xml
2019-07-14 04:48 - 2019-07-14 04:48 - 000076060 _____ C:\WINDOWS\system32\xpsrchvw.xml
2019-07-14 04:48 - 2019-07-14 04:48 - 000035592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2019-07-14 04:48 - 2019-07-14 04:48 - 000035592 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2019-07-14 04:48 - 2019-07-14 04:48 - 000000000 ____D C:\Program Files\Reference Assemblies
2019-07-14 04:48 - 2019-07-14 04:48 - 000000000 ____D C:\Program Files\MSBuild
2019-07-14 04:48 - 2019-07-14 04:48 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2019-07-14 04:48 - 2019-07-14 04:48 - 000000000 ____D C:\Program Files (x86)\MSBuild
2019-07-14 01:49 - 2019-07-14 01:49 - 000159969 ____C C:\Users\indre\Desktop\FRST 6.txt
2019-07-14 01:49 - 2019-07-14 01:49 - 000044556 ____C C:\Users\indre\Desktop\Addition 6.txt
2019-07-14 01:16 - 2019-07-14 13:25 - 000842664 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-07-14 01:15 - 2019-07-14 01:15 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2019-07-14 01:14 - 2019-07-14 01:14 - 000000020 ___SH C:\Users\indre\ntuser.ini
2019-07-14 01:13 - 2019-07-14 13:19 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-07-14 01:13 - 2019-07-14 13:12 - 000004166 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{71AF15CB-04B4-4B18-8047-5E35B9C7421E}
2019-07-14 01:13 - 2019-07-14 13:04 - 000000000 ____D C:\WINDOWS\System32\Tasks\Intel
2019-07-14 01:13 - 2019-07-14 01:13 - 000007623 _____ C:\WINDOWS\diagwrn.xml
2019-07-14 01:13 - 2019-07-14 01:13 - 000007623 _____ C:\WINDOWS\diagerr.xml
2019-07-14 01:13 - 2019-07-14 01:13 - 000003762 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2019-07-14 01:13 - 2019-07-14 01:13 - 000003750 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier
2019-07-14 01:13 - 2019-07-14 01:13 - 000003482 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2019-07-14 01:13 - 2019-07-14 01:13 - 000003346 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2019-07-14 01:13 - 2019-07-14 01:13 - 000003298 _____ C:\WINDOWS\System32\Tasks\Dell SupportAssistAgent AutoUpdate
2019-07-14 01:13 - 2019-07-14 01:13 - 000003278 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2019-07-14 01:13 - 2019-07-14 01:13 - 000003122 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2019-07-14 01:13 - 2019-07-14 01:13 - 000003118 _____ C:\WINDOWS\System32\Tasks\Intel PTT EK Recertification
2019-07-14 01:13 - 2019-07-14 01:13 - 000003042 _____ C:\WINDOWS\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473
2019-07-14 01:13 - 2019-07-14 01:13 - 000003040 _____ C:\WINDOWS\System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec
2019-07-14 01:13 - 2019-07-14 01:13 - 000002858 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1593158232-969496310-2340663774-1001
2019-07-14 01:13 - 2019-07-14 01:13 - 000002702 _____ C:\WINDOWS\System32\Tasks\GarminUpdaterTask
2019-07-14 01:13 - 2019-07-14 01:13 - 000002674 _____ C:\WINDOWS\System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec-Logon
2019-07-14 01:13 - 2019-07-14 01:13 - 000002638 _____ C:\WINDOWS\System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901}
2019-07-14 01:13 - 2019-07-14 01:13 - 000002528 _____ C:\WINDOWS\System32\Tasks\CLVDLauncher
2019-07-14 01:13 - 2019-07-14 01:13 - 000002528 _____ C:\WINDOWS\System32\Tasks\CLMLSvc_P2G8
2019-07-14 01:13 - 2019-07-14 01:13 - 000002422 _____ C:\WINDOWS\System32\Tasks\WD Device Agent Task indre
2019-07-14 01:13 - 2019-07-14 01:13 - 000002418 _____ C:\WINDOWS\System32\Tasks\WD Discovery Service Task indre
2019-07-14 01:13 - 2019-07-14 01:13 - 000002304 _____ C:\WINDOWS\System32\Tasks\RtHDVBg_PushButton
2019-07-14 01:13 - 2019-07-14 01:13 - 000000000 ____D C:\WINDOWS\System32\Tasks\Hewlett-Packard
2019-07-14 01:13 - 2019-07-14 01:13 - 000000000 ____D C:\WINDOWS\System32\Tasks\Dell
2019-07-14 01:13 - 2019-07-14 01:13 - 000000000 ____D C:\WINDOWS\System32\Tasks\Apple
2019-07-14 01:12 - 2019-07-14 01:12 - 000000000 ____D C:\ProgramData\USOShared
2019-07-14 01:08 - 2019-07-14 04:50 - 002874368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2019-07-14 01:08 - 2019-07-14 01:14 - 000000000 ____D C:\Users\indre
2019-07-14 01:08 - 2019-03-19 00:46 - 000001105 _____ C:\Users\indre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-07-14 01:07 - 2019-07-14 01:07 - 000000000 ____D C:\Program Files\Waves
2019-07-14 01:07 - 2018-03-22 02:24 - 000144832 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2019-07-14 01:05 - 2019-07-14 12:39 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-07-14 01:05 - 2019-07-14 01:09 - 000444408 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-07-14 00:01 - 2019-07-14 01:14 - 000000000 ___DC C:\WINDOWS\Panther
2019-07-13 22:13 - 2019-07-13 22:13 - 000100185 ____C C:\Users\indre\Desktop\FRST 5.txt
2019-07-13 22:13 - 2019-07-13 22:13 - 000044036 ____C C:\Users\indre\Desktop\Addition 5.txt
2019-07-13 21:28 - 2019-07-13 21:28 - 002095104 ____C (Farbar) C:\Users\indre\Desktop\FRST64.exe
2019-07-13 21:28 - 2019-07-13 21:28 - 002095104 _____ (Farbar) C:\Users\indre\Downloads\FRST64 (4).exe
2019-07-13 13:07 - 2019-07-14 01:29 - 000002865 ____C C:\Users\indre\Desktop\OOSU10.ini
2019-07-13 13:06 - 2019-07-13 13:06 - 001068584 ____C (O&O Software GmbH) C:\Users\indre\Desktop\OOSU10.exe
2019-07-13 13:06 - 2019-07-13 13:06 - 001068584 _____ (O&O Software GmbH) C:\Users\indre\Downloads\OOSU10.exe
2019-07-13 11:53 - 2019-07-13 11:53 - 021820224 ____C (Intel® Corporation) C:\Users\indre\Desktop\WiFi_21.20.0_Driver64_Win10.exe
2019-07-13 11:53 - 2019-07-13 11:53 - 021820224 _____ (Intel® Corporation) C:\Users\indre\Downloads\WiFi_21.20.0_Driver64_Win10.exe
2019-07-13 01:16 - 2019-07-13 01:16 - 000042265 ____C C:\Users\indre\Desktop\Addition 4.txt
2019-07-13 00:42 - 2019-07-13 00:42 - 000100258 ____C C:\Users\indre\Desktop\FRST 4.txt
2019-07-13 00:25 - 2019-07-13 00:25 - 014543816 ____C (Intel Corporation) C:\Users\indre\Desktop\SetupRST.exe
2019-07-13 00:25 - 2019-07-13 00:25 - 014543816 _____ (Intel Corporation) C:\Users\indre\Downloads\SetupRST (2).exe
2019-07-13 00:21 - 2019-07-13 00:21 - 014543816 _____ (Intel Corporation) C:\Users\indre\Downloads\SetupRST (1).exe
2019-07-12 21:35 - 2019-07-12 21:35 - 000000000 ____D C:\Users\indre\Intel
2019-07-12 21:31 - 2019-07-12 21:31 - 021816776 _____ (Intel Corporation) C:\Users\indre\Downloads\SetupRST.exe
2019-07-12 19:03 - 2019-07-12 19:03 - 000042006 ____C C:\Users\indre\Desktop\Addition 3.txt
2019-07-12 19:00 - 2019-07-12 19:00 - 000117354 ____C C:\Users\indre\Desktop\FRST 3.txt
2019-07-12 18:49 - 2019-07-12 18:49 - 000062468 _____ C:\ProgramData\agent.uninstall.1562971733.bdinstall.v2.bin
2019-07-12 18:49 - 2019-07-12 18:49 - 000002522 _____ C:\Users\indre\Downloads\fixlist.txt
2019-07-12 13:55 - 2019-07-12 13:56 - 000169646 ____C C:\Users\indre\Desktop\DESKTOP-EL88UDV 2.txt
2019-07-12 13:50 - 2019-07-12 13:50 - 000117516 ____C C:\Users\indre\Desktop\FRST 2.txt
2019-07-12 13:50 - 2019-07-12 13:50 - 000043949 ____C C:\Users\indre\Desktop\Addition 2.txt
2019-07-12 13:32 - 2019-07-13 00:38 - 000042262 ____C C:\Users\indre\Desktop\Addition 1.txt
2019-07-12 13:28 - 2019-07-12 13:28 - 002095104 _____ (Farbar) C:\Users\indre\Downloads\FRST64 (3).exe
2019-07-12 13:27 - 2019-07-12 13:27 - 002095104 _____ (Farbar) C:\Users\indre\Downloads\FRST64 (2).exe
2019-07-12 12:51 - 2019-07-12 12:51 - 000001301 _____ C:\Users\Public\Desktop\WD Discovery.lnk
2019-07-12 12:51 - 2019-07-12 12:51 - 000000000 ___DC C:\Users\indre\AppData\Roaming\WDDesktop
2019-07-12 12:50 - 2019-07-14 13:20 - 000000000 ___DC C:\Users\indre\AppData\Roaming\WD Discovery
2019-07-12 12:50 - 2019-07-14 13:20 - 000000000 ____D C:\Users\indre\.wdc
2019-07-12 12:50 - 2019-07-12 12:54 - 000000000 ____D C:\Program Files\WD Desktop App
2019-07-12 12:50 - 2017-11-21 12:03 - 000468112 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\Drivers\wdfsconnect2017.sys
2019-07-12 12:50 - 2017-11-21 12:03 - 000020624 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\Drivers\wdvpnpbus.sys
2019-07-12 12:50 - 2017-11-10 12:51 - 000223744 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\SysWOW64\wdfsconnectNetRdr2017.dll
2019-07-12 12:50 - 2017-11-10 12:51 - 000180224 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll
2019-07-12 12:50 - 2017-11-10 12:51 - 000154112 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\SysWOW64\wdfsconnectMntNtf2017.dll
2019-07-12 12:50 - 2017-11-10 12:51 - 000118272 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\wdfsconnectNetRdr2017.dll
2019-07-12 12:50 - 2017-11-10 12:51 - 000002560 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\wdfsconnectevtmsg.dll
2019-07-12 12:16 - 2019-07-12 12:16 - 000001192 _____ C:\Users\Public\Desktop\WD Drive Utilities.lnk
2019-07-12 12:14 - 2019-07-14 05:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WD Discovery
2019-07-12 12:14 - 2019-07-12 13:23 - 000002228 _____ C:\Users\Public\Desktop\WD Backup.lnk
2019-07-12 12:14 - 2019-07-12 13:23 - 000000000 ____D C:\Program Files (x86)\Western Digital
2019-07-12 12:14 - 2019-07-12 12:14 - 000000000 ___DC C:\Users\indre\AppData\Roaming\Western Digital
2019-07-12 12:14 - 2019-07-12 12:14 - 000000000 ____D C:\ProgramData\Western Digital
2019-07-12 11:29 - 2019-07-12 11:29 - 005278464 _____ (Paramount Software UK Ltd) C:\Users\indre\Downloads\ReflectDLHF (1).exe
2019-07-12 11:25 - 2019-07-12 11:31 - 000000000 ____D C:\ProgramData\Macrium
2019-07-12 11:25 - 2019-07-12 11:25 - 000000000 ____D C:\Users\indre\Downloads\Macrium
2019-07-12 11:24 - 2019-07-12 11:25 - 005278464 _____ (Paramount Software UK Ltd) C:\Users\indre\Downloads\ReflectDLHF.exe
2019-07-11 12:12 - 2019-07-11 12:12 - 000000000 ___DC C:\Users\indre\Documents\Kaspersky Password Manager
2019-07-10 22:50 - 2019-07-10 22:50 - 000000000 ___DC C:\Users\indre\AppData\Local\Garmin
2019-07-09 13:11 - 2019-07-09 13:11 - 004730179 _____ C:\Users\indre\Downloads\Master Folder For Cleared Checks INDY (2).xlsx
2019-07-09 13:09 - 2019-07-09 13:09 - 008141856 _____ C:\Users\indre\Downloads\MASTER ALL CHECKS (4).xlsx
2019-07-08 13:49 - 2019-07-08 13:49 - 000000000 ___DC C:\Users\indre\Documents\ED stuff
2019-07-08 11:03 - 2019-07-08 11:04 - 000188559 ____C C:\Users\indre\Desktop\DESKTOP-EL88UDV.txt
2019-07-08 11:01 - 2019-07-14 05:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2019-07-08 11:01 - 2019-07-08 11:01 - 000000839 _____ C:\Users\Public\Desktop\Speccy.lnk
2019-07-08 11:01 - 2019-07-08 11:01 - 000000000 ____D C:\Program Files\Speccy
2019-07-08 10:59 - 2019-07-08 10:59 - 006889184 _____ (Piriform Ltd) C:\Users\indre\Downloads\spsetup132.exe
2019-07-08 10:59 - 2019-07-08 10:59 - 001309592 _____ (BraveSoftware Inc.) C:\Users\indre\Downloads\BraveBrowserSetup-TPF550.exe
2019-07-08 10:56 - 2019-07-08 10:56 - 000019118 _____ C:\junk.txt
2019-07-08 10:54 - 2019-07-08 10:54 - 000026673 ____C C:\Users\indre\Desktop\Registry 070819.txt
2019-07-08 10:50 - 2019-07-08 10:50 - 002826520 _____ (Sysinternals - www.sysinternals.com) C:\Users\indre\Downloads\procexp (1).exe
2019-07-08 10:50 - 2019-07-08 10:50 - 000043192 _____ (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP152.SYS
2019-07-08 10:49 - 2019-07-08 10:49 - 002826520 _____ (Sysinternals - www.sysinternals.com) C:\Users\indre\Downloads\procexp.exe
2019-07-08 10:47 - 2019-07-08 10:47 - 000023010 ____C C:\Users\indre\Desktop\VEW Application 070819.txt
2019-07-08 10:44 - 2019-07-08 10:44 - 000007664 ____C C:\Users\indre\Desktop\VEW Events 070819.txt
2019-07-08 10:43 - 2019-07-08 10:46 - 000023010 _____ C:\VEW.txt
2019-07-08 10:40 - 2019-07-08 10:40 - 000061440 _____ ( ) C:\Users\indre\Downloads\VEW.exe
2019-07-06 13:06 - 2019-07-06 13:06 - 000302368 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klark.sys
2019-07-06 13:04 - 2019-07-14 05:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Password Manager
2019-07-06 13:04 - 2019-07-06 13:04 - 000001371 _____ C:\Users\Public\Desktop\Kaspersky Password Manager.lnk
2019-07-06 13:04 - 2019-07-06 13:04 - 000000000 ___DC C:\Users\indre\AppData\Local\Kaspersky Lab
2019-07-06 13:00 - 2019-07-14 05:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Secure Connection
2019-07-06 13:00 - 2019-07-06 13:00 - 000245272 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_arkmon.sys
2019-07-06 13:00 - 2019-07-06 13:00 - 000198768 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_mark.sys
2019-07-06 13:00 - 2019-07-06 13:00 - 000116104 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klbg.sys
2019-07-06 13:00 - 2019-07-06 13:00 - 000099152 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_kimul.sys
2019-07-06 12:59 - 2019-07-14 13:21 - 000000000 ____D C:\ProgramData\Kaspersky Lab
2019-07-06 12:59 - 2019-07-14 05:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Total Security
2019-07-06 12:59 - 2019-07-06 13:17 - 000236672 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klflt.sys
2019-07-06 12:59 - 2019-07-06 13:16 - 001168000 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klif.sys
2019-07-06 12:59 - 2019-07-06 13:04 - 000000000 ____D C:\Program Files (x86)\Kaspersky Lab
2019-07-06 12:59 - 2019-07-06 12:59 - 000002210 _____ C:\Users\Public\Desktop\Safe Money.lnk
2019-07-06 12:59 - 2019-07-06 12:59 - 000002182 _____ C:\Users\Public\Desktop\Kaspersky Total Security.lnk
2019-07-06 12:59 - 2013-05-06 08:13 - 000110176 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\klfphc.dll
2019-07-06 12:57 - 2019-07-06 12:56 - 000592616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2019-07-06 12:54 - 2019-07-06 12:55 - 000000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2019-07-06 12:54 - 2019-07-06 12:54 - 002660224 _____ (Kaspersky Lab) C:\Users\indre\Downloads\startup_14445.exe
2019-07-06 10:01 - 2019-07-06 10:01 - 002420224 _____ (Farbar) C:\Users\indre\Downloads\FRST64 (1).exe
2019-07-06 10:00 - 2019-07-13 00:38 - 000100255 ____C C:\Users\indre\Desktop\FRST 1.txt
2019-07-06 09:58 - 2019-07-06 10:00 - 000039445 _____ C:\Users\indre\Downloads\Addition.txt
2019-07-06 09:55 - 2019-07-06 09:59 - 000079818 _____ C:\Users\indre\Downloads\FRST.txt
2019-07-06 09:54 - 2019-07-14 13:24 - 000000000 ____D C:\FRST
2019-07-06 09:53 - 2019-07-06 09:53 - 002420224 _____ (Farbar) C:\Users\indre\Downloads\FRST64.exe
2019-06-29 23:56 - 2019-06-29 23:56 - 011069444 _____ C:\Users\indre\Downloads\thecourtshipofeddiesfather-1st (1).mpg
2019-06-29 23:55 - 2019-06-29 23:55 - 011069444 _____ C:\Users\indre\Downloads\thecourtshipofeddiesfather-1st.mpg
2019-06-29 11:29 - 2019-06-29 11:29 - 000074636 _____ C:\ProgramData\agent.update.1561822169.bdinstall.v2.bin
2019-06-27 20:31 - 2019-06-27 20:31 - 022709477 _____ C:\Users\indre\Downloads\20190627_202829_19399014677980 (1).mp4
2019-06-27 20:30 - 2019-06-27 20:30 - 022709477 _____ C:\Users\indre\Downloads\20190627_202829_19399014677980.mp4
2019-06-27 19:53 - 2019-06-27 19:53 - 000000054 ____C C:\Users\indre\Desktop\cryptic stacey 062719.txt
2019-06-24 00:13 - 2019-07-07 22:03 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2019-06-23 23:58 - 2019-06-23 23:58 - 000068279 _____ C:\Users\indre\Downloads\Iulo_Susan_References_2019.pdf
2019-06-23 14:04 - 2019-06-23 14:04 - 000128245 _____ C:\Users\indre\Downloads\Iulo_Susan_-_Resume_2019.pdf
2019-06-21 20:51 - 2019-06-21 20:51 - 000128344 _____ C:\Users\indre\Downloads\Iulo_Susan_-_resume_June_2019_FIRST DRAFT (2).pdf
2019-06-21 20:28 - 2019-06-21 20:28 - 000128344 _____ C:\Users\indre\Downloads\Iulo_Susan_-_resume_June_2019_FIRST DRAFT (1).pdf
2019-06-21 20:25 - 2019-06-21 20:25 - 000128344 _____ C:\Users\indre\Downloads\Iulo_Susan_-_resume_June_2019_FIRST DRAFT.pdf
2019-06-20 12:13 - 2019-06-20 12:13 - 000004919 _____ C:\Users\indre\Downloads\imp8A93.pdf
2019-06-20 12:13 - 2019-06-20 12:13 - 000004919 _____ C:\Users\indre\Downloads\imp8A93 (1).pdf
2019-06-18 21:05 - 2019-06-18 21:05 - 000039557 _____ C:\Users\indre\Downloads\Letters_2019_06_14_12_42_30_156.pdf
2019-06-18 02:30 - 2019-06-18 02:30 - 000363078 _____ C:\Users\indre\Downloads\Preprinted UPS label for Treasury to Farmingdale 010918.pdf
2019-06-17 14:37 - 2019-06-17 14:37 - 000350164 _____ C:\Users\indre\Downloads\Statement_062019_8810.pdf
 
==================== One month (modified) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-07-14 13:19 - 2019-03-19 00:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-07-14 13:19 - 2016-09-11 19:32 - 000000000 ___RD C:\Users\indre\OneDrive
2019-07-14 13:19 - 2016-09-11 19:30 - 000000000 __SHD C:\Users\indre\IntelGraphicsProfiles
2019-07-14 13:18 - 2019-03-19 00:37 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2019-07-14 13:13 - 2018-11-16 12:19 - 000000000 ____D C:\Program Files\rempl
2019-07-14 13:09 - 2019-03-19 00:50 - 000000000 ____D C:\WINDOWS\INF
2019-07-14 13:03 - 2019-03-19 00:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-07-14 11:06 - 2019-05-14 13:15 - 000002495 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2019-07-14 11:06 - 2019-05-14 13:15 - 000002494 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2019-07-14 11:06 - 2019-05-14 13:15 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2019-07-14 11:06 - 2019-05-14 13:15 - 000002451 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2019-07-14 11:06 - 2019-05-14 13:15 - 000002437 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2019-07-14 11:05 - 2016-08-09 19:40 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2019-07-14 11:01 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\Registration
2019-07-14 11:00 - 2019-03-19 00:56 - 000835688 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2019-07-14 11:00 - 2019-03-19 00:56 - 000179816 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2019-07-14 05:05 - 2019-06-13 20:33 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless
2019-07-14 05:05 - 2019-05-28 22:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2019-07-14 05:05 - 2019-05-24 22:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NordVPN
2019-07-14 05:05 - 2019-04-21 20:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Plex Media Server
2019-07-14 05:05 - 2019-03-19 00:56 - 000000000 ____D C:\WINDOWS\Setup
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 __RHD C:\Users\Public\Libraries
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\spool
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\NDF
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\Macromed
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\Drivers\DriverData
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2019-07-14 05:05 - 2019-03-19 00:49 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2019-07-14 05:05 - 2018-10-28 02:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
2019-07-14 05:05 - 2018-07-25 13:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CutePDF
2019-07-14 05:05 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2019-07-14 05:05 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2019-07-14 05:05 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\InfusedApps
2019-07-14 05:05 - 2017-10-14 21:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2019-07-14 05:05 - 2017-05-21 14:10 - 000000000 ____D C:\Program Files\Intel
2019-07-14 05:05 - 2017-05-09 21:49 - 000000000 ____D C:\Program Files\UNP
2019-07-14 05:05 - 2016-09-16 23:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TextPad 8
2019-07-14 05:05 - 2016-09-16 23:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2019-07-14 05:05 - 2016-09-16 22:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pretty Good Solitaire
2019-07-14 05:05 - 2016-09-16 13:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware
2019-07-14 05:05 - 2016-09-13 22:50 - 000000000 ____D C:\WINDOWS\system32\appmgmt
2019-07-14 05:05 - 2016-08-09 19:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
2019-07-14 05:05 - 2016-08-09 19:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Media Suite
2019-07-14 05:05 - 2016-08-09 19:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
2019-07-14 05:05 - 2016-08-09 19:34 - 000000000 ___HD C:\WINDOWS\system32\WLANProfiles
2019-07-14 05:05 - 2016-08-09 19:33 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2019-07-14 04:54 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\oobe
2019-07-14 04:54 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\Resources
2019-07-14 04:54 - 2017-05-21 14:10 - 000000000 ____D C:\Program Files\Realtek
2019-07-14 04:54 - 2016-09-17 01:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rovio
2019-07-14 04:54 - 2016-09-16 20:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2019-07-14 04:54 - 2016-08-09 19:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewBlue
2019-07-14 04:52 - 2019-03-19 02:23 - 000000000 ___SD C:\WINDOWS\system32\AppV
2019-07-14 04:52 - 2019-03-19 02:23 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2019-07-14 04:52 - 2019-03-19 00:52 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2019-07-14 04:52 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\SystemResources
2019-07-14 04:52 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\migwiz
2019-07-14 04:52 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\appraiser
2019-07-14 04:52 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\ShellExperiences
2019-07-14 04:52 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\ShellComponents
2019-07-14 04:52 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\bcastdvr
2019-07-14 04:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2019-07-14 04:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2019-07-14 04:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2019-07-14 04:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2019-07-14 04:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2019-07-14 04:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2019-07-14 04:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\et-EE
2019-07-14 04:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\es-MX
2019-07-14 03:32 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\appcompat
2019-07-14 03:26 - 2019-03-19 00:37 - 000008192 _____ C:\WINDOWS\system32\config\ELAM
2019-07-14 02:36 - 2019-03-19 00:52 - 000000000 ___HD C:\Program Files\WindowsApps
2019-07-14 02:36 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-07-14 02:36 - 2018-07-04 13:52 - 000000000 ____D C:\ProgramData\Packages
2019-07-14 01:32 - 2017-11-15 23:37 - 000000000 ___DC C:\Users\indre\AppData\Local\Packages
2019-07-14 01:31 - 2018-12-15 03:16 - 000000000 ___DC C:\Users\indre\AppData\Local\PlaceholderTileLogoFolder
2019-07-14 01:14 - 2017-11-15 23:45 - 000000000 ___RD C:\Users\indre\3D Objects
2019-07-14 01:14 - 2016-09-30 22:13 - 000000000 ___DC C:\Users\indre\AppData\Local\ConnectedDevicesPlatform
2019-07-14 01:14 - 2016-08-09 19:48 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-07-14 01:13 - 2016-08-09 19:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Audio
2019-07-14 01:12 - 2019-03-19 00:52 - 000000000 ____D C:\ProgramData\USOPrivate
2019-07-14 01:12 - 2016-09-11 19:57 - 000002303 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-07-14 01:12 - 2016-09-11 19:57 - 000002262 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2019-07-14 01:10 - 2016-09-30 22:09 - 000027452 _____ C:\WINDOWS\system32\emptyregdb.dat
2019-07-14 01:08 - 2018-04-06 21:09 - 000000000 ___DC C:\Users\indre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom
2019-07-14 01:07 - 2019-03-19 00:52 - 000000000 ___RD C:\WINDOWS\PrintDialog
2019-07-14 01:07 - 2017-05-21 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\sda
2019-07-14 01:07 - 2017-05-21 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2019-07-14 01:07 - 2017-05-21 14:10 - 000000000 ____D C:\WINDOWS\system32\RTCOM
2019-07-14 01:06 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\ServiceState
2019-07-14 01:06 - 2018-05-23 18:30 - 000000000 ____D C:\WINDOWS\IAStorAfsService
2019-07-12 21:35 - 2017-05-21 14:10 - 000000000 ____D C:\Program Files (x86)\Intel
2019-07-12 19:21 - 2016-09-17 01:09 - 000000000 ___DC C:\Users\indre\Documents\Letters
2019-07-12 13:23 - 2016-08-09 19:33 - 000000000 ____D C:\ProgramData\Package Cache
2019-07-12 11:43 - 2016-09-16 22:45 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-07-11 04:01 - 2016-11-18 22:39 - 000000000 ___DC C:\Users\indre\AppData\LocalLow\Mozilla
2019-07-10 07:49 - 2016-09-12 20:21 - 000000000 ____D C:\WINDOWS\system32\MRT
2019-07-10 07:36 - 2016-09-12 20:20 - 136618864 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2019-07-08 14:37 - 2016-09-18 09:35 - 000000000 ___DC C:\Users\indre\AppData\Local\CrashDumps
2019-07-08 13:50 - 2016-09-17 01:49 - 000000000 ___DC C:\Users\indre\Documents\Funny stuff
2019-07-08 13:43 - 2018-12-02 19:00 - 000000000 ___DC C:\Users\indre\Documents\Editing for Josh
2019-07-06 13:17 - 2019-02-13 14:10 - 000184960 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klwtp.sys
2019-07-06 13:17 - 2019-02-13 14:10 - 000125568 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klbackupflt.sys
2019-07-06 13:17 - 2019-02-13 14:10 - 000091472 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\kldisk.sys
2019-07-06 13:17 - 2018-02-24 05:17 - 000218240 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\kneps.sys
2019-07-06 13:17 - 2018-02-17 02:50 - 000104576 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klwfp.sys
2019-07-06 13:17 - 2018-01-15 05:13 - 000060536 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klkbdflt.sys
2019-07-06 13:16 - 2019-02-13 14:10 - 001093248 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klhk.sys
2019-07-06 13:16 - 2019-02-13 14:10 - 000152288 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\klhkum.dll
2019-07-06 13:16 - 2019-02-13 14:10 - 000075600 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klbackupdisk.sys
2019-07-06 13:16 - 2019-02-13 14:10 - 000046416 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klpnpflt.sys
2019-07-06 13:16 - 2018-02-12 04:17 - 000058704 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klim6.sys
2019-07-06 13:16 - 2017-12-11 11:49 - 000060784 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klmouflt.sys
2019-07-06 13:16 - 2017-05-30 18:51 - 000050304 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klpd.sys
2019-07-06 13:00 - 2017-02-04 10:05 - 000000000 ____D C:\Program Files\Common Files\AV
2019-07-06 01:15 - 2018-06-20 22:44 - 000002365 ____C C:\Users\indre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive (1).lnk
2019-06-29 23:58 - 2017-10-14 21:56 - 000000000 ___DC C:\Users\indre\AppData\Roaming\vlc
2019-06-29 23:56 - 2017-10-14 21:56 - 000001141 _____ C:\Users\Public\Desktop\VLC media player.lnk
2019-06-28 08:30 - 2016-09-16 13:57 - 000000000 ___DC C:\Users\indre\AppData\Roaming\VMware
2019-06-27 18:32 - 2016-09-11 19:59 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2019-06-27 00:47 - 2017-07-15 20:02 - 000014706 ____C C:\Users\indre\Documents\Indy's Finances.xlsx
2019-06-26 22:10 - 2016-09-11 19:59 - 000001007 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2019-06-21 21:34 - 2016-09-17 01:09 - 000000000 ___DC C:\Users\indre\Documents\Resumes etc
2019-06-21 16:50 - 2016-09-17 01:09 - 000000000 ___DC C:\Users\indre\Documents\Recipes
2019-06-18 05:52 - 2016-09-17 01:38 - 000000000 ___DC C:\Users\indre\Documents\Akiko stuff
 
==================== Files in the root of some directories ================
 
2018-11-19 21:23 - 2018-11-19 21:23 - 000000017 ____C () C:\Users\indre\AppData\Local\resmon.resmoncfg
 
==================== SigCheck ===============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ============================
 
Addition scan:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-07-2019
Ran by indre (14-07-2019 13:25:30)
Running from C:\Users\indre\Desktop
Windows 10 Pro Version 1903 18362.239 (X64) (2019-07-14 05:14:02)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1593158232-969496310-2340663774-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1593158232-969496310-2340663774-503 - Limited - Disabled)
Guest (S-1-5-21-1593158232-969496310-2340663774-501 - Limited - Disabled)
indre (S-1-5-21-1593158232-969496310-2340663774-1001 - Administrator - Enabled) => C:\Users\indre
WDAGUtilityAccount (S-1-5-21-1593158232-969496310-2340663774-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Kaspersky Total Security (Enabled - Up to date) {0AB30972-4BAC-7BEE-CBCA-B8F9E68797D8}
AS: Kaspersky Total Security (Enabled - Up to date) {B1D2E896-6D96-7460-F17A-838B9D00DD65}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Total Security (Enabled) {32888857-01C3-7AB6-E095-11CC1854D0A3}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Across Lite (HKLM-x32\...\{5F5C7350-9731-420F-97CC-8CAFEE7DA7A3}) (Version: 2.4.2451.1 - Literate Software)
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 19.012.20035 - Adobe Systems Incorporated)
Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.223 - Adobe)
Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.223 - Adobe)
Angry Birds (HKLM-x32\...\{2F7D5734-056F-4A0A-A1C7-CA1AAE5BB1EB}) (Version: 1.6.3.1 - Rovio)
ANT Drivers Installer x64 (HKLM\...\{D559687A-60C5-4786-9429-C21EC195789D}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Application Support (32-bit) (HKLM-x32\...\{C1BCFECF-6EC2-4750-9072-5E2489423F8F}) (Version: 7.5 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{B202C7F5-7DE3-4FBF-B259-E70E625F56FC}) (Version: 7.5 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B5A46811-3612-4DA5-8A5A-E6DED5D7C523}) (Version: 12.2.1.12 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{A30EA700-5515-48F0-88B0-9E99DC356B88}) (Version: 2.6.0.1 - Apple Inc.)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Cisco WebEx Meetings (HKLM-x32\...\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
CmgMasterPrerequisites (HKLM\...\{EE34FA4E-715A-46FA-9CAF-06E26AE4217D}) (Version: 1.10.0.34 - Dell, Inc.) Hidden
CutePDF Form Filler 3.6 (Evaluation) (HKLM-x32\...\CutePDF Form Filler (Evaluation)_is1) (Version:  - Acro Software Inc.)
CyberLink Media Suite Essentials (HKLM-x32\...\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 12 - CyberLink Corp.)
Dell Command | Update (HKLM-x32\...\{EC542D5D-B608-4145-A8F7-749C02BE6D94}) (Version: 2.2.0 - Dell Inc.)
Dell Data Protection | Client Security Framework (HKLM\...\{FAE38E46-ECB2-44EA-A52B-6955AA6B1B3A}) (Version: 8.10.0.39 - Dell, Inc.)
Dell Data Protection | Security Tools (HKLM-x32\...\{812AA6D3-5BEB-4577-88B1-00998B91AB41}) (Version: 1.10.0.34 - Dell, Inc.) Hidden
Dell Data Protection | Security Tools (HKLM-x32\...\InstallShield_{812AA6D3-5BEB-4577-88B1-00998B91AB41}) (Version: 1.10.0.34 - Dell, Inc.)
Dell Digital Delivery (HKLM-x32\...\{AB7F2792-2ED1-4C5C-9F28-680E5110BF72}) (Version: 3.1.1018.0 - Dell Products, LP)
Dell SupportAssist (HKLM\...\{806422F1-FC4E-4D7C-8855-05748AEFC031}) (Version: 3.2.2.119 - Dell Inc.)
DELLOSD (HKLM-x32\...\{BED3193A-897B-47F6-AEDC-45D147122957}) (Version: 1.0.0.0 - DELL)
Elevated Installer (HKLM-x32\...\{0BF90608-2F95-4C7C-9A85-E90E0CAF4FE9}) (Version: 6.9.1.0 - Garmin Ltd or its subsidiaries) Hidden
FileZilla Client 3.25.1 (HKLM-x32\...\FileZilla Client) (Version: 3.25.1 - Tim Kosse)
Garmin Express (HKLM-x32\...\{95D0EADA-5123-41C0-931A-F37946BC0E8E}) (Version: 6.9.1.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express (HKLM-x32\...\{eab4691c-4022-41cd-8d39-c3097ba62d4b}) (Version: 6.9.1.0 - Garmin Ltd or its subsidiaries)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 75.0.3770.100 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.11 - Google LLC) Hidden
HP Support Solutions Framework (HKLM-x32\...\{2B5A1E68-6617-406D-B797-5DAB5B4630B8}) (Version: 12.11.24.11 - HP Inc.)
Intel® Chipset Device Software (HKLM-x32\...\{fb610cea-ba50-4d4b-a717-cf025419035c}) (Version: 10.1.1.13 - Intel® Corporation) Hidden
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1054 - Intel Corporation)
Intel® Network Connections 20.3.300.1 (HKLM\...\PROSetDX) (Version: 20.3.300.1 - Intel)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 23.20.16.4973 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.8.16.1063 - Intel Corporation)
Intel® Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.47.866.0 - Intel Corporation) Hidden
Intel® Trusted Connect Services Client (HKLM-x32\...\{246c6cc0-9810-4728-9a29-28474de2eec5}) (Version: 1.47.866.0 - Intel Corporation) Hidden
Intel® WiDi (HKLM\...\{C7CD6D54-26AF-4D93-B06F-D81ACE8624CB}) (Version: 6.0.40.0 - Intel Corporation)
Intel® WiDi Software Asset Manager (HKLM-x32\...\{5B5CD20C-29F0-4857-A4FA-A4F4C716B019}) (Version: 1.1.347 - Intel Corporation) Hidden
Intel® Wireless Bluetooth® (HKLM-x32\...\{5068B0F8-CE24-4B61-9C2F-301B411FFB9C}) (Version: 18.1.1611.3223 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{f430aa46-62c4-47a0-8a03-42e7fff664b7}) (Version: 20.120.0 - Intel Corporation)
Intel® Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation)
iTunes (HKLM\...\{A8AF3EF8-5010-4A92-BCCA-90F62A7D62B8}) (Version: 12.9.5.7 - Apple Inc.)
Kaspersky Password Manager (HKLM-x32\...\{B2F7333E-6C8D-4994-AAC4-FEC8EBBF9611}) (Version: 9.0.2.767 - Kaspersky Lab) Hidden
Kaspersky Password Manager (HKLM-x32\...\InstallWIX_{B2F7333E-6C8D-4994-AAC4-FEC8EBBF9611}) (Version: 9.0.2.767 - Kaspersky Lab)
Kaspersky Secure Connection (HKLM-x32\...\{F10AA188-7166-430E-8810-FEAB2AD73DE3}) (Version: 19.0.0.1088 - Kaspersky Lab) Hidden
Kaspersky Secure Connection (HKLM-x32\...\InstallWIX_{F10AA188-7166-430E-8810-FEAB2AD73DE3}) (Version: 19.0.0.1088 - Kaspersky Lab)
Kaspersky Total Security (HKLM-x32\...\{718613F4-492D-4272-ACC3-D04A8EF0F883}) (Version: 19.0.0.1088 - Kaspersky Lab) Hidden
Kaspersky Total Security (HKLM-x32\...\InstallWIX_{718613F4-492D-4272-ACC3-D04A8EF0F883}) (Version: 19.0.0.1088 - Kaspersky Lab)
LaserJet 1020 series (HKLM-x32\...\HP-LaserJet 1020 series) (Version:  - )
Maxx Audio Installer (x64) (HKLM\...\{307032B2-6AF2-46D7-B933-62438DEB2B9A}) (Version: 2.6.8006.3 - Waves Audio Ltd.) Hidden
Microsoft Office Famille et Petite Entreprise 2016 - fr-fr (HKLM\...\HomeBusinessRetail - fr-fr) (Version: 16.0.11727.20244 - Microsoft Corporation)
Microsoft Office Hogar y Empresas 2016 - es-es (HKLM\...\HomeBusinessRetail - es-es) (Version: 16.0.11727.20244 - Microsoft Corporation)
Microsoft Office Home and Business 2016 - en-us (HKLM\...\HomeBusinessRetail - en-us) (Version: 16.0.11727.20244 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\OneDriveSetup.exe) (Version: 19.103.0527.0003 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (HKLM-x32\...\{6e8f74e0-43bd-4dce-8477-6ff6828acc07}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 (HKLM-x32\...\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24210 (HKLM-x32\...\{23658c02-145e-483d-ba6b-1eb82c580529}) (Version: 14.0.24210.0 - Microsoft Corporation)
Mozilla Firefox 67.0.4 (x64 en-US) (HKLM\...\Mozilla Firefox 67.0.4 (x64 en-US)) (Version: 67.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 66.0.3 - Mozilla)
NewBlue Video Essentials for Windows (HKLM-x32\...\NewBlue Video Essentials for Windows) (Version: 3.0 - NewBlue)
NordVPN (HKLM-x32\...\{F4325B30-A8A0-4D09-B0DE-7CBB485A52D8}) (Version: 6.22.6 - NordVPN) Hidden
NordVPN (HKLM-x32\...\NordVPN 6.22.6) (Version: 6.22.6 - NordVPN)
NordVPN network TAP (HKLM-x32\...\{97DEC5D6-2BE9-45BB-BFC5-274B851B486B}) (Version: 1.0.1 - NordVPN)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.11727.20244 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.11727.20244 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.11727.20244 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.11727.20244 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-040C-0000-0000000FF1CE}) (Version: 16.0.11727.20244 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0C0A-0000-0000000FF1CE}) (Version: 16.0.11727.20244 - Microsoft Corporation) Hidden
Plex Media Server (HKLM-x32\...\{72238E55-A877-4785-A5E9-0C35EAFB0746}) (Version: 1.15.876 - Plex, Inc.) Hidden
Plex Media Server (HKLM-x32\...\{9203fc01-57c0-4cc8-858d-92911b5142de}) (Version: 1.15.3.876 - Plex, Inc.)
Pretty Good Solitaire version 12.4.0 (HKLM-x32\...\Pretty Good Solitaire_is1) (Version: 12.4.0 - Goodsol Development Inc.)
proDAD Adorage 3.0 (HKLM-x32\...\proDAD-Adorage-3.0) (Version: 3.0.114.1 - proDAD GmbH)
Realtek Audio COM Components (HKLM-x32\...\{2355B503-9B11-4449-861D-1C1748B26320}) (Version: 1.0.2 - Realtek Semiconductor Corp.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.14393.21292 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6105 - Realtek Semiconductor Corp.)
Security Innovation TSS (HKLM\...\{0C11FE22-53F2-4C9B-9E79-824B10D0976E}) (Version: 2.1.42 - Security Innovation) Hidden
Speccy (HKLM\...\Speccy) (Version: 1.32 - Piriform)
Spotify (HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\Spotify) (Version: 1.0.96.181.gf6bc1b6b - Spotify AB)
Stopping Plex (HKLM-x32\...\{3C6D43CB-1211-4C3F-8F3C-2B4F90C5BB95}) (Version: 1.15.876 - Plex, Inc.) Hidden
TextPad 8 (HKLM\...\{861AB1C1-1967-4C4A-BF86-C255E2D2B8FD}) (Version: 8.0.2 - Helios)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{F14FB68A-9188-4036-AD0D-D054BC9C9291}) (Version: 2.59.0.0 - Microsoft Corporation)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.7.1 - VideoLAN)
VMware Horizon Client (HKLM\...\{93CEC220-0D24-41C0-8647-BA1C62A3EE89}) (Version: 4.0.1.781 - VMware, Inc.)
Vulkan Run Time Libraries 1.0.33.0 (HKLM\...\VulkanRT1.0.33.0) (Version: 1.0.33.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.33.0 (HKLM\...\VulkanRT1.0.33.0-2) (Version: 1.0.33.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1) (Version: 1.0.54.1 - Intel Corporation Inc.)
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-2) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-3) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
WD Backup (HKLM-x32\...\{50C6CAE8-562E-440D-8616-E0514D41CC10}) (Version: 1.9.6941.25593 - Western Digital Technologies, Inc) Hidden
WD Backup (HKLM-x32\...\{6531bf4b-4bad-46a5-9562-766d0a858003}) (Version: 1.9.6941.25593 - Western Digital Technologies, Inc.)
WD Desktop App 2.1.0.245 (HKLM-x32\...\{d303f1fe-6729-4693-b2e1-51d13b450de5}) (Version: 2.1.0.245 - Western Digital Corporation) Hidden
WD Desktop App 2.1.0.245 (x64) (HKLM\...\{CA7F7232-526E-41BD-971A-47BE28C18516}) (Version: 2.1.0.245 - Western Digital Corporation) Hidden
WD Discovery (HKLM-x32\...\WDDiscovery) (Version: 3.3.34 - Western Digital Technologies, Inc.)
WD Drive Utilities (HKLM-x32\...\{5ea95ccc-fc68-4182-88a9-e563ba3900ed}) (Version: 2.0.0.26 - Western Digital Technologies, Inc.)
WD Drive Utilities (HKLM-x32\...\{893C7059-0464-47FB-85A4-5E1ADDA56141}) (Version: 2.0.0.26 - Western Digital Technologies, Inc.) Hidden
WD SES Driver Setup (HKLM-x32\...\{924A274D-38B6-4930-8859-F3F51CFA8DDD}) (Version: 1.1.0.25 - Western Digital) Hidden
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Intel Corporation (iaStorA) HDC  (08/10/2017 15.7.5.1025) (HKLM\...\FF1B55CEF8D39B696D1F5DF141ACFA7A5D1F2743) (Version: 08/10/2017 15.7.5.1025 - Intel Corporation)
Windows Driver Package - Intel Corporation (iaStorA) SCSIAdapter  (08/10/2017 15.7.5.1025) (HKLM\...\6D773A6E21B2A480569157737F58E8FF7DC6608A) (Version: 08/10/2017 15.7.5.1025 - Intel Corporation)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Zoom (HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\ZoomUMX) (Version: 4.1 - Zoom Video Communications, Inc.)
 
Packages:
=========
CyberLink Media Suite Essentials -> C:\Program Files\WindowsApps\DB6EA5DB.CyberLinkMediaSuiteEssentials_1.0.10.0_x86__mcezb6ze687jp [2018-03-13] (CYBERLINK CORPORATION.)
Dell SupportAssist for PCs -> C:\Program Files\WindowsApps\DellInc.DellSupportAssistforPCs_3.2.5.0_x64__htrsf667h5kn2 [2019-05-29] (Dell Inc)
Facebook -> C:\Program Files\WindowsApps\Facebook.Facebook_186.2191.46880.0_x86__8xx8rvfyw5nnt [2019-07-14] (Facebook Inc)
Mail and Calendar -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe [2019-07-10] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1808.3.0_x64__8wekyb3d8bbwe [2019-07-14] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-12] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-12] (Microsoft Corporation) [MS Ad]
Microsoft Jigsaw -> C:\Program Files\WindowsApps\Microsoft.MicrosoftJigsaw_1.8.1812.301_x86__8wekyb3d8bbwe [2019-03-14] (Microsoft Studios) [MS Ad]
Microsoft Mahjong -> C:\Program Files\WindowsApps\Microsoft.MicrosoftMahjong_3.9.4100.0_x64__8wekyb3d8bbwe [2019-04-18] (Microsoft Studios) [MS Ad]
Microsoft Minesweeper -> C:\Program Files\WindowsApps\Microsoft.MicrosoftMinesweeper_2.7.4300.0_x86__8wekyb3d8bbwe [2019-02-18] (Microsoft Studios) [MS Ad]
Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.31.11723.0_x64__8wekyb3d8bbwe [2019-06-26] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.4.6132.0_x64__8wekyb3d8bbwe [2019-06-17] (Microsoft Studios) [MS Ad]
MSN Money -> C:\Program Files\WindowsApps\Microsoft.BingFinance_4.29.10701.0_x64__8wekyb3d8bbwe [2019-03-22] (Microsoft Corporation) [MS Ad]
MSN Sports -> C:\Program Files\WindowsApps\Microsoft.BingSports_4.28.3242.0_x64__8wekyb3d8bbwe [2018-12-15] (Microsoft Corporation) [MS Ad]
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.28.10351.0_x64__8wekyb3d8bbwe [2019-02-12] (Microsoft Corporation) [MS Ad]
PAC-MAN Battle -> C:\Program Files\WindowsApps\50867PocketKingGames.PAC-MANBattle_1.1.0.0_x64__m8bdd0rdw5vr0 [2018-12-15] (Pocket King Games) [MS Ad]
The Backgammon -> C:\Program Files\WindowsApps\6918E89D.TheBackgammon_1.2.0.0_x64__66n08swfvvka0 [2018-12-15] (UNBALANCE corp.) [MS Ad]
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.Twitter_6.1.4.1000_neutral__wgeqdkkx372wm [2018-09-08] (Twitter Inc.)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1593158232-969496310-2340663774-1001_Classes\CLSID\{5A9E21A2-851A-4BEB-B16F-DBBE7D648AF9}\InprocServer32 -> C:\Program Files\TextPad 8\System\ShellExt64.dll (Helios Software Solutions Ltd -> )
SSODL: WDFSMountNotificator-wdfsconnect2017 - {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2} - C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll (Western Digital Technologies, Inc.) [File not signed]
SSODL-x32: WDFSMountNotificator-wdfsconnect2017 - {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2} - C:\WINDOWS\SysWOW64\wdfsconnectMntNtf2017.dll (Western Digital Technologies, Inc.) [File not signed]
ShellServiceObjects: Virtual Storage Mount Notification -> {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2} => C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll [2017-11-10] (Western Digital Technologies, Inc.) [File not signed]
ShellServiceObjects-x32: Virtual Storage Mount Notification -> {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2} => C:\WINDOWS\SysWOW64\wdfsconnectMntNtf2017.dll [2017-11-10] (Western Digital Technologies, Inc.) [File not signed]
ShellIconOverlayIdentifiers: [  WDDesktopIconOverlay01] -> {4F8A325E-9DAF-44B8-A825-1A14DFA0FA78} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [  WDDesktopIconOverlay02] -> {0176BDDE-B59A-4A1E-808B-CAD461415CCA} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [  WDDesktopIconOverlay03] -> {B65909D1-57AF-41F5-AB94-BEB733F62B35} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [  WDDesktopIconOverlay04] -> {C6C2397D-8238-4332-8935-86C39C7C165F} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [  WDDesktopIconOverlay05] -> {E7B3BCF9-0386-4B5F-AE6A-91B9F1423973} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ShellIconOverlayIdentifiers: [  WDDesktopIconOverlay06] -> {564EA121-D9DA-485D-82C2-C2ED7BFCCEAD} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2016-04-27] (CyberLink Corp. -> Cyberlink)
ContextMenuHandlers1: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\ShellEx.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers1: [WDDesktopContextMenu] -> {4961b028-350a-3bb9-9d6c-079dc724e5f0} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2016-04-27] (CyberLink Corp. -> Cyberlink)
ContextMenuHandlers2: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\ShellEx.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers4: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\ShellEx.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers4: [WDDesktopContextMenu] -> {4961b028-350a-3bb9-9d6c-079dc724e5f0} => C:\Program Files\WD Desktop App\kda.DLL [2019-05-08] (Western Digital Technologies, Inc. -> Western Digital Corporation)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\ki127171.inf_amd64_368f8c7337214025\igfxDTCM.dll [2018-03-22] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\ShellEx.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers1_S-1-5-21-1593158232-969496310-2340663774-1001: [TextPad8] -> {5A9E21A2-851A-4BEB-B16F-DBBE7D648AF9} => C:\Program Files\TextPad 8\System\ShellExt64.dll [2016-02-28] (Helios Software Solutions Ltd -> )
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2016-08-09 19:32 - 2015-06-29 20:13 - 000151552 _____ () [File not signed] C:\Program Files (x86)\DELL\DELLOSD\DellOSDService.exe
2016-08-09 19:32 - 2015-06-29 20:09 - 000548864 _____ () [File not signed] C:\Program Files (x86)\DELL\DELLOSD\MediaButtons.exe
2015-05-19 12:11 - 2015-05-19 12:11 - 000007680 _____ () [File not signed] C:\Program Files (x86)\Intel\Intel® Security Assist\isaHelperService.exe
2019-01-21 07:55 - 2019-01-21 07:55 - 000251392 _____ () [File not signed] C:\Program Files (x86)\NordVPN\x86\Liberation.Native.Firewall.dll
2016-03-25 23:50 - 2016-03-25 23:50 - 001491968 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\VMware\VMware Horizon View Client\bin\LIBEAY32.dll
2016-03-25 23:50 - 2016-03-25 23:50 - 000298496 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\VMware\VMware Horizon View Client\bin\SSLEAY32.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\webcompanion.com -> hxxp://webcompanion.com
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2015-10-30 03:24 - 2019-01-10 23:55 - 000002507 _____ C:\WINDOWS\system32\drivers\etc\hosts
 
0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
0.0.0.0 media.opencandy.com
0.0.0.0 cdn.opencandy.com
0.0.0.0 tracking.opencandy.com
0.0.0.0 api.opencandy.com
0.0.0.0 api.recommendedsw.com
0.0.0.0 rp.yefeneri2.com
0.0.0.0 os.yefeneri2.com
0.0.0.0 os2.yefeneri2.com
0.0.0.0 installer.betterinstaller.com
0.0.0.0 installer.filebulldog.com
0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
0.0.0.0 inno.bisrv.com
0.0.0.0 nsis.bisrv.com
0.0.0.0 cdn.file2desktop.com
0.0.0.0 cdn.goateastcach.us
0.0.0.0 cdn.guttastatdk.us
0.0.0.0 cdn.inskinmedia.com
0.0.0.0 cdn.insta.oibundles2.com
0.0.0.0 cdn.insta.playbryte.com
0.0.0.0 cdn.llogetfastcach.us
0.0.0.0 cdn.montiera.com
0.0.0.0 cdn.msdwnld.com
0.0.0.0 cdn.mypcbackup.com
0.0.0.0 cdn.ppdownload.com
0.0.0.0 cdn.riceateastcach.us
0.0.0.0 cdn.shyapotato.us
0.0.0.0 cdn.solimba.com
0.0.0.0 cdn.tuto4pc.com
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Dell\Dell Data Protection\Drivers\TSS\bin\;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL;C:\Program Files\Intel\Intel® Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT;C:\Program Files\Intel\Intel® Management Engine Components\IPT;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\indre\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Warn)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
If an entry is included in the fixlist, it will be removed.
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{F29C6F66-709F-4614-A9A3-B60FCED2E26A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{4D93D1F7-7788-460E-AB49-CA919F927793}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe (Intel Corporation -> )
FirewallRules: [{35F1740E-5C7F-48A0-9424-553F25A67238}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{F52C8ACB-334D-404D-AC77-F60981439024}] => (Allow) C:\Program Files\iTunes\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{FCB7161E-863C-4365-A934-94FC0E83A38E}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex Tuner Service.exe (Plex, Inc -> )
FirewallRules: [{73C29C77-9A88-433D-8F93-2CEF6E260A57}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex DLNA Server.exe (Plex, Inc -> Plex, Inc.)
FirewallRules: [{B9F683A9-6869-4425-ACDF-4BBE734023A1}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe (Plex, Inc -> Python Software Foundation)
FirewallRules: [{835008C9-6A51-4365-AFEC-F24E67C44C2E}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe (Plex, Inc -> Plex, Inc.)
FirewallRules: [{56381F91-7873-4CEA-8ABE-E10213107A2E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{DED84BE3-3BD6-4E0D-A420-B30E49FC626F}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{FE7FEA92-FE61-4E07-AB28-B07698433507}] => (Allow) LPort=8889
FirewallRules: [{69A76876-400F-4C97-9AC9-188D74D4DEA6}] => (Block) C:\users\indre\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{3E499D19-4DBA-4DEF-8CF8-19DA405CDB89}] => (Block) C:\users\indre\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{1DC4DC8A-7F42-44CE-9FE4-78B806402CE0}C:\users\indre\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\indre\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [TCP Query User{56C4283E-A791-4CBC-9F68-AC60C8E0C7B4}C:\users\indre\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\indre\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{881A5D70-E076-4553-AFB1-5DCEB88E106E}C:\program files (x86)\vmware\vmware horizon view client\vmware-remotemks.exe] => (Allow) C:\program files (x86)\vmware\vmware horizon view client\vmware-remotemks.exe (VMware, Inc. -> VMware, Inc.)
FirewallRules: [TCP Query User{3696DD75-4C0C-490B-A914-59C0D82CE209}C:\program files (x86)\vmware\vmware horizon view client\vmware-remotemks.exe] => (Allow) C:\program files (x86)\vmware\vmware horizon view client\vmware-remotemks.exe (VMware, Inc. -> VMware, Inc.)
FirewallRules: [{B768845C-68FA-4F5D-8CB0-8915F5518FBE}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe (Intel® Wireless Display -> Intel)
FirewallRules: [{277A97E1-8E11-4C68-985D-B7CC9AFC4A42}] => (Allow) LPort=8888
FirewallRules: [{6CC73312-41C6-4002-A0B0-4F73A84DBE2F}] => (Allow) LPort=8888
FirewallRules: [{AD297B5D-2C9A-4E26-9193-5DEFE2B8D5DD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{6A551C3A-B926-43D8-9A75-06A3CEEB5AAF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{FF6FAF1B-3C9B-4453-9D51-82A62172D810}C:\program files\itunes\itunes.exe] => (Allow) C:\program files\itunes\itunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [UDP Query User{B71B19F6-E012-4D87-BC64-170CDB9AE748}C:\program files\itunes\itunes.exe] => (Allow) C:\program files\itunes\itunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{F26FF42A-FABC-4237-AF27-9A74BAD6E0C7}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc. -> Apple Inc.)
 
==================== Restore Points =========================
 
14-07-2019 11:00:27 Windows Update
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (07/14/2019 01:21:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IAStorDataMgrSvc.exe, version: 14.8.16.1063, time stamp: 0x58eb8338
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0707b21d
Faulting process id: 0x409c
Faulting application start time: 0x01d53a689146358e
Faulting application path: C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
Faulting module path: unknown
Report Id: a27d4980-3f0e-4fa7-9e12-89b764628748
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (07/14/2019 01:21:30 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: IAStorDataMgrSvc.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.NullReferenceException
   at IAStorUtil.SystemDataModelListener.ProcessSystemDataModelChanges()
   at IAStorUtil.SystemDataModelListener.LoadSavedSystemState()
   at IAStorDataMgr.EventRelay.<Start>b__0(System.Object)
   at System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
   at System.Threading.ThreadPoolWorkQueue.Dispatch()
   at System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()
 
 
System errors:
=============
Error: (07/14/2019 01:21:31 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel® Rapid Storage Technology service terminated unexpectedly.  It has done this 1 time(s).
 
 
CodeIntegrity:
===================================
 
Date: 2019-07-14 13:21:08.299
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.
 
Date: 2019-07-14 13:21:08.284
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.
 
Date: 2019-07-14 13:21:07.974
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.
 
Date: 2019-07-14 13:21:07.968
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.
 
==================== Memory info =========================== 
 
BIOS: Dell Inc. 1.8.6 12/12/2017
Motherboard: Dell Inc. 0X2MKR
Processor: Intel® Core™ i7-6700 CPU @ 3.40GHz
Percentage of memory in use: 62%
Total physical RAM: 8048.94 MB
Available physical RAM: 2986.91 MB
Total Virtual: 9968.94 MB
Available Virtual: 4116.73 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:224.66 GB) (Free:97.28 GB) NTFS
Drive e: (My Passport) (Fixed) (Total:1862.98 GB) (Free:1811 GB) NTFS
 
\\?\Volume{9418ee22-8e7f-4668-b204-a94b09d00e55}\ () (Fixed) (Total:0.51 GB) (Free:0.08 GB) NTFS
\\?\Volume{616afac5-ee60-493d-8f6b-5152f9f29468}\ (Image) (Fixed) (Total:12.69 GB) (Free:0.63 GB) NTFS
\\?\Volume{dbd7410f-196c-49b5-bb90-bbf877a175c2}\ (ESP) (Fixed) (Total:0.48 GB) (Free:0.44 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: 4FCEFFCB)
 
Partition: GPT.
 
========================================================
Disk: 1 (Size: 1863 GB) (Disk ID: 16F2A91F)
 
Partition: GPT.
 
==================== End of Addition.txt ============================

**************************************************************************************************************

Please let me know if I need to do anything else. Maybe it's my imagination, but my computer seems to be running more quickly and efficiently, which is nice.

Thank you!!!
 

  • 0

#44
RKinner

RKinner

    Malware Expert

  • Expert
  • 21,737 posts
  • MVP

We are getting iastor errors again and also Windows is complaining that a Kaspersky file is not signed.  I wonder if the newest iastor will work on your system?

 

Go to

 

https://downloadcent...r?product=55005

 

Download SetupRST.exe, Save and then right click and Run As Admin.  It will tell you if it's not happy and won't install.

 

Perhaps a new install of Kaspersky would help?


  • 0

#45
IndyBlue

IndyBlue

    Member

  • Topic Starter
  • Member
  • PipPip
  • 95 posts
OK, I installed the very latest version of iastor (my computer had no problem with it).
 
I can't imagine why a new install of Kaspersky would change anything? I just got it a few days ago--it's brand spanking new. And I got the total package. Why would Kaspersky be causing problems?
 
Anyway, below are the scans, and it looks like the IASTOR errors are still there.

By the way, I keep getting this weird prompt. Usually I ignore it; a few times I said "Yes." But it always comes back. I've attached an image. (I was unable to grab a screenshot [it disappears too quickly] but I grabbed one from google.)
 
(1) FRSRT
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 13-07-2019
Ran by indre (administrator) on DESKTOP-EL88UDV (Dell Inc. OptiPlex 7440 AIO) (14-07-2019 19:26:12)
Running from C:\Users\indre\Desktop
Loaded Profiles: indre (Available Profiles: indre)
Platform: Windows 10 Pro Version 1903 18362.239 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
() [File not signed] C:\Program Files (x86)\DELL\DELLOSD\DellOSDService.exe
() [File not signed] C:\Program Files (x86)\DELL\DELLOSD\MediaButtons.exe
() [File not signed] C:\Program Files (x86)\Intel\Intel® Security Assist\isaHelperService.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.YourPhone_1.19062.451.0_x64__8wekyb3d8bbwe\YourPhone.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(CyberLink Corp. -> CyberLink) C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvc_P2G8.exe
(Dell Inc -> CREDANT Technologies, Inc.) C:\Program Files\Dell\Dell Data Protection\Client Security Framework\Dell.SecurityFramework.Agent.exe
(Dell Inc -> Dell Inc.) C:\Program Files\Dell\Dell Data Protection\Client Security Framework\DCF.Loader.exe
(Dell Inc -> Dell, Inc.) C:\Program Files\Dell\Dell Data Protection\Client Security Framework\Dell.SecurityFramework.LocalServer.exe
(FabulaTech -> ) C:\Program Files (x86)\VMware\ScannerRedirection\ftscanmgr.exe
(FabulaTech -> ) C:\Program Files\Common Files\VMware\DeviceRedirectionCommon\ftnlsv.exe
(FabulaTech -> VMware) C:\Program Files (x86)\Common Files\VMware\SerialPortRedirection\Client\vmwsprrdpwks.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler64.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe
(Intel® Intel Network Drivers -> Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Intel® Intel Network Drivers -> Intel® Corporation) C:\Program Files\Intel\NCS2\WMIProv\ncs2prov.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127171.inf_amd64_368f8c7337214025\igfxCUIService.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127171.inf_amd64_368f8c7337214025\igfxEM.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127171.inf_amd64_368f8c7337214025\IntelCpHDCPSvc.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127171.inf_amd64_368f8c7337214025\IntelCpHeciSvc.exe
(Intel® Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe
(Intel® Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_5d83605e8696144c\RstMwService.exe
(Intel® Wireless Display -> Intel) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\avp.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\avpui.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\indre\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c\SkypeApp.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.WindowsStore_11905.1001.4.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Plex, Inc -> ) C:\Program Files (x86)\Plex\Plex Media Server\Plex Tuner Service.exe
(Plex, Inc -> Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex DLNA Server.exe
(Plex, Inc -> Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe
(Plex, Inc -> Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe
(Plex, Inc -> Python Software Foundation) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
(Plex, Inc -> Python Software Foundation) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(TEFINCOM S.A. -> ) C:\Program Files (x86)\NordVPN\nordvpn-service.exe
(TEFINCOM S.A. -> NordVPN) C:\Program Files (x86)\NordVPN\NordVPN.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\VMware\VMware Horizon View Client\bin\vmware-view-usbd.exe
(VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\VMware\VMware Horizon View Client\wsnm\wsnm.exe
(Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe
(Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe
(Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD App Manager\Plugins\WD Backup\App\WDBackupService.exe
(Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD App Manager\WDAppManager.exe
(Western Digital Techologies -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8853248 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_MAXX6] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1419008 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [VMware Netlink 3 HV Install Utility] => C:\Program Files\Common Files\VMware\DeviceRedirectionCommon\ftnliu.exe [70080 2015-11-04] (FabulaTech -> )
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [302904 2019-05-07] (Apple Inc. -> Apple Inc.)
HKLM\...\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [718256 2015-12-22] (Waves Inc -> Waves Audio Ltd.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942864 2016-10-13] (Logitech -> Logitech, Inc.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [319544 2019-02-26] (Intel® Rapid Storage Technology -> Intel Corporation)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PrivacyIconClient.exe [1176208 2017-11-09] (Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation)
HKLM-x32\...\Run: [WDDiscovery] => C:\Program Files (x86)\Western Digital\Discovery\Current\WD Discovery.exe [81376496 2019-07-12] (Western Digital Technologies, Inc. -> Western Digital Corporation)
HKLM-x32\...\Run: [WDAppManager] => C:\Program Files (x86)\Western Digital\WD App Manager\AppManagerLauncher.exe [21888 2019-01-02] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\Run: [Plex Media Server] => C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe [23081448 2019-04-04] (Plex, Inc -> Plex, Inc.)
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\Run: [NordVPN] => C:\Program Files (x86)\NordVPN\NordVPN.exe [2186704 2019-05-22] (TEFINCOM S.A. -> NordVPN)
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\Run: [kpm.exe] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe [584128 2019-02-08] (Kaspersky Lab -> AO Kaspersky Lab)
HKLM\...\Drivers32-x32: [vidc.pDAD] => prodad-codec.dll
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.100\Installer\chrmstp.exe [2019-06-20] (Google LLC -> Google LLC)
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {08E2F16C-4C59-4C34-A03C-C83EEEDEBBDE} - System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec-Logon => C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-17] (Intel® Software Asset Manager -> Intel Corporation)
Task: {0C0614F0-18B6-495C-99F1-B61633EE7B2A} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel® Update Manager\bin\iumsvc.exe
Task: {1D566C7D-1CD5-4E77-826C-E0DF557F6BFA} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_223_Plugin.exe [1457208 2019-07-10] (Adobe Inc. -> Adobe)
Task: {1E20F289-46AA-4529-B808-962BFEF268A3} - System32\Tasks\RtHDVBg_PushButton => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1419008 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {267B2E60-3693-45B1-B32D-E5AA4FA083F4} - System32\Tasks\WD Discovery Service Task indre => C:\Program Files (x86)\Western Digital\Discovery\Current\Service\WDDiscoveryService.exe [71408 2019-07-12] (Western Digital Technologies, Inc. -> )
Task: {27CEA27E-1BF2-4A16-B5AE-DCA79020DF0D} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [816960 2017-10-11] (Intel® Trust Services -> Intel® Corporation)
Task: {2BE02930-09E5-4DB5-86B2-C883307D310D} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_223_pepper.exe [1453112 2019-07-10] (Adobe Inc. -> Adobe)
Task: {39820E81-9B7D-411F-A870-C6BEBCB2BF30} - System32\Tasks\Intel\Intel Telemetry 2 => C:\Program Files\Intel\Telemetry 2.0\lrio.exe [1698000 2015-06-05] (Intel® Software -> Intel Corporation)
Task: {42854805-A985-4C19-9336-2E724C851DA1} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [113616 2019-07-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {4336A3CB-532E-423B-9674-2DF223FA5E83} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26804232 2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {4DF09A94-B680-4D73-A2BA-B28905CCA70D} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [39920 2018-10-24] (Garmin International, Inc. -> )
Task: {53926FCA-0182-464C-A702-AEC117C4AF2D} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26804232 2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {5EF9065E-7942-4205-9A7E-625FDF39B32F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [136056 2019-01-02] (HP Inc. -> HP Inc.)
Task: {6B5B7726-D2CB-4DB7-B19E-39D4BB205AFB} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [113616 2019-07-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {6D0AA64B-75B4-49CF-9C53-3BF5D9356A9D} - System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec => C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-17] (Intel® Software Asset Manager -> Intel Corporation)
Task: {82F39D33-C846-4F84-8898-8F68198ADD97} - System32\Tasks\CLVDLauncher => C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLVDLauncher.exe [340440 2015-01-28] (CyberLink Corp. -> CyberLink Corp.)
Task: {83C8BC3C-312F-4391-A237-23638EBA6AD3} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1448512 2019-07-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {8B3F29DA-404A-4CB9-8309-9D94ECAA8D3F} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvc_P2G8.exe [110008 2016-04-27] (CyberLink Corp. -> CyberLink)
Task: {8D960D58-2C65-4690-A008-63A3B9664FD6} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [654712 2019-06-05] (HP Inc. -> HP Inc.)
Task: {A5585A2F-2224-44F3-B48A-C02AA6E9CD5D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-09-11] (Google Inc -> Google Inc.)
Task: {BEEC0D34-AA7B-4933-B79B-EE5F2DA284E3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-07-10] (Adobe Inc. -> Adobe)
Task: {C9DAB848-B95A-4118-8DAB-0AA8CAE862C4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1195544 2018-12-16] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Task: {D3E17C23-CA8A-4B0D-A146-AC1F38D7DF2A} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1448512 2019-07-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {DCF36F4E-53FF-403E-B92A-CAFE9380489C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616320 2018-01-08] (Apple Inc. -> Apple Inc.)
Task: {ECD51CA1-564E-49C6-A83B-0A4B7EC42B15} - System32\Tasks\WD Device Agent Task indre => C:\Users\indre\AppData\Roaming\WD Discovery\plugins\com.wdc.plugin.catalog\current\library\WD Device Agent.exe [724008 2019-06-18] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
Task: {F219FE43-71D7-4843-8134-11FF7BD69ACF} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistInstaller.exe [1512920 2019-05-24] (Dell Inc. -> Dell Inc.)
Task: {F266FDCC-EAB9-4691-867D-FA95BDE06352} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [791232 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
Task: {F932D694-A1C8-4A80-9BEA-DAAFEF0B6FE1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-09-11] (Google Inc -> Google Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{6fbafdae-3f34-452d-bbc1-3182c4eed1fc}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{df5feca7-b365-4e54-a128-6afee4fc4200}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{eb569711-9ed4-49b4-a209-84f1068bb002}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
HKU\S-1-5-21-1593158232-969496310-2340663774-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell17win10.msn.com/?pc=DCTE
SearchScopes: HKU\S-1-5-21-1593158232-969496310-2340663774-1001 -> DefaultScope {97FF47F7-FF6D-4CCE-B19F-284086150FBF} URL = 
SearchScopes: HKU\S-1-5-21-1593158232-969496310-2340663774-1001 -> {97FF47F7-FF6D-4CCE-B19F-284086150FBF} URL = 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2019-06-25] (Microsoft Corporation -> Microsoft Corporation)
BHO: No Name -> {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2}' -> No File
BHO: Kaspersky Protection -> {EC1E29BB-F56A-45D8-B023-D3EF710FA0E0} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
BHO: Kaspersky Password Manager -> {F710F7E5-A520-471D-989C-F653AC328FB2} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\x64\ie_engine.dll [2019-05-08] (Kaspersky Lab -> AO Kaspersky Lab)
BHO-x32: No Name -> {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2}' -> No File
BHO-x32: CutePDF Form Filler Helper -> {D41289F2-69C6-417B-897E-C653D677CBAF} -> C:\Program Files (x86)\Acro Software\CutePDF Filler Evaluation\CPFillerCoE.dll [2014-03-27] (Acro Software Inc. -> Acro Software Inc.)
BHO-x32: Kaspersky Protection -> {EC1E29BB-F56A-45D8-B023-D3EF710FA0E0} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
BHO-x32: Kaspersky Password Manager -> {F710F7E5-A520-471D-989C-F653AC328FB2} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\ie_engine.dll [2019-05-08] (Kaspersky Lab -> AO Kaspersky Lab)
Toolbar: HKLM - Kaspersky Protection Toolbar - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
Toolbar: HKLM-x32 - Kaspersky Protection Toolbar - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
Toolbar: HKU\S-1-5-21-1593158232-969496310-2340663774-1001 -> Kaspersky Protection Toolbar - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\IEExt\ie_plugin.dll [2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} hxxps://meetny.webex.com/client/WBXclient-T30L10NSP6EP6-20000/webex/ieatgpc1.cab
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-07-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-07-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-07-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-07-14] (Microsoft Corporation -> Microsoft Corporation)
 
FireFox:
========
FF DefaultProfile: 1cu7vqt4.default-1534000050440
FF ProfilePath: C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440 [2019-07-11]
FF Homepage: Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440 -> hxxps://www.google.com/
FF Extension: (ETP Search Volume Study) - C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440\Extensions\[email protected] [2019-06-26]
FF Extension: (Notifier for Gmail™) - C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440\Extensions\[email protected] [2019-03-31]
FF Extension: (Honey) - C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440\Extensions\[email protected] [2019-05-18]
FF Extension: (Kaspersky Password Manager) - C:\Users\indre\AppData\Roaming\Mozilla\Firefox\Profiles\1cu7vqt4.default-1534000050440\Extensions\[email protected] [2019-05-08] [UpdateUrl:hxxps://special.s.kaspersky-labs.com/firefox_extensions/kpm_win_add_on/update.json]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Extension: (Kaspersky Protection) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\FFExt\light_plugin_firefox\addon.xpi [2019-07-06]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_223.dll [2019-07-10] (Adobe Inc. -> )
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_223.dll [2019-07-10] (Adobe Inc. -> )
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2019-04-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-14] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-14] (Google Inc -> Google LLC)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-05-02] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1593158232-969496310-2340663774-1001: @zoom.us/ZoomVideoPlugin -> C:\Users\indre\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2018-04-06] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\kl_prefs_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.js [2019-07-07] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\kl_config_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.cfg [2019-07-07] <==== ATTENTION
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default [2019-07-14]
CHR Extension: (Slides) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-12]
CHR Extension: (Kaspersky Protection) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\amkpcclbbgegoafihnpgomddadjhcadd [2019-07-06]
CHR Extension: (Docs) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12]
CHR Extension: (Google Drive) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-09-11]
CHR Extension: (YouTube) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-09-11]
CHR Extension: (Honey) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2019-07-11]
CHR Extension: (uBlock Origin) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2019-07-13]
CHR Extension: (Notifier for Gmail™) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcjichoefijpinlfnjghokpkojhlhkgl [2019-03-25]
CHR Extension: (Kaspersky Password Manager) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhnkblpjbkfklfloegejegedcafpliaa [2019-07-12]
CHR Extension: (Adobe Acrobat) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2019-06-11]
CHR Extension: (Sheets) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-12]
CHR Extension: (Google Docs Offline) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-22]
CHR Extension: (Avast Online Security) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2019-07-01]
CHR Extension: (F.B.(FluffBusting)Purity) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmkinhboiljjkhaknpaeaicmdjhagpep [2019-07-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-07]
CHR Extension: (Gmail) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-03-26]
CHR Extension: (Chrome Media Router) - C:\Users\indre\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-06-20]
CHR Profile: C:\Users\indre\AppData\Local\Google\Chrome\User Data\Guest Profile [2019-07-08]
CHR Profile: C:\Users\indre\AppData\Local\Google\Chrome\User Data\System Profile [2019-07-08]
CHR HKLM\...\Chrome\Extension: [amkpcclbbgegoafihnpgomddadjhcadd] - hxxps://chrome.google.com/webstore/detail/amkpcclbbgegoafihnpgomddadjhcadd
CHR HKU\S-1-5-21-1593158232-969496310-2340663774-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhnkblpjbkfklfloegejegedcafpliaa] - hxxps://chrome.google.com/webstore/detail/dhnkblpjbkfklfloegejegedcafpliaa
CHR HKLM-x32\...\Chrome\Extension: [amkpcclbbgegoafihnpgomddadjhcadd] - hxxps://chrome.google.com/webstore/detail/amkpcclbbgegoafihnpgomddadjhcadd
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [96056 2019-04-29] (Apple Inc. -> Apple Inc.)
R2 AVP19.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\avp.exe [619640 2018-02-28] (Kaspersky Lab -> AO Kaspersky Lab)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11413600 2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
S4 dcu-oobe; C:\Program Files (x86)\Dell\CommandUpdate\OobeService.exe [84408 2016-06-07] (Dell Inc. -> Dell Inc.)
S2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [209392 2019-02-28] (Dell Inc -> Dell Inc.)
S2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3363824 2019-02-28] (Dell Inc -> Dell Inc.)
S2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [218096 2019-02-28] (Dell Inc -> Dell Inc.)
S2 Dell Hardware Support; C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.7033.2285\DSAPI.exe [1050952 2019-06-02] (PC-Doctor, Inc. -> PC-Doctor, Inc.)
R2 Dell WMI Service; C:\Program Files (x86)\DELL\DELLOSD\DellOSDService.exe [151552 2015-06-29] () [File not signed]
R2 DellMgmtAgent; C:\Program Files\Dell\Dell Data Protection\Client Security Framework\Dell.SecurityFramework.Agent.exe [22280 2016-07-13] (Dell Inc -> CREDANT Technologies, Inc.)
R2 DellMgmtLoader; C:\Program Files\Dell\Dell Data Protection\Client Security Framework\DCF.Loader.exe [35080 2016-07-13] (Dell Inc -> Dell Inc.)
R3 DellMgmtServer; C:\Program Files\Dell\Dell Data Protection\Client Security Framework\Dell.SecurityFramework.LocalServer.exe [52488 2016-07-13] (Dell Inc -> Dell, Inc.)
R2 ftnlsv3hv; C:\Program Files\Common Files\VMware\DeviceRedirectionCommon\ftnlsv.exe [233920 2015-11-04] (FabulaTech -> )
R2 ftscanmgr; C:\Program Files (x86)\VMware\ScannerRedirection\ftscanmgr.exe [6363792 2015-07-31] (FabulaTech -> )
S4 HfcDisableService; C:\WINDOWS\System32\DriverStore\FileRepository\iastorac.inf_amd64_5d83605e8696144c\HfcDisableService.exe [1860272 2019-02-26] (Intel® Rapid Storage Technology -> Intel Corporation)
S2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [356728 2019-06-12] (HP Inc. -> HP Inc.)
S3 iaStorAfsService; C:\WINDOWS\System32\iaStorAfsService.exe [2833584 2019-02-26] (Intel® Rapid Storage Technology -> Intel Corporation)
R2 ibtsiva; C:\WINDOWS\system32\ibtsiva.exe [190208 2016-10-15] (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation)
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [742704 2017-10-11] (Intel® Trust Services -> Intel® Corporation)
S3 Intel® Security Assist; C:\Program Files (x86)\Intel\Intel® Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed]
S2 Intel® TPM Provisioning Service; C:\Program Files\Intel\iCLS Client\TPMProvisioningService.exe [668472 2017-10-11] (Intel® Trust Services -> Intel® Corporation)
S3 Intel® WiDi SAM; C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-17] (Intel® Software Asset Manager -> Intel Corporation)
R2 IntelUSBoverIP; C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe [396992 2015-07-06] (Intel® Wireless Display -> Intel)
R2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel® Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed]
S2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [213648 2017-11-09] (Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation)
S3 klvssbridge64_19.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 19.0.0\x64\vssbridge64.exe [414352 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R2 kpm_launch_service; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe [354008 2019-02-08] (Kaspersky Lab -> AO Kaspersky Lab)
S2 KSDE3.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksde.exe [617016 2018-02-28] (Kaspersky Lab -> AO Kaspersky Lab)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [310880 2019-01-23] (Intel Corporation -> )
R2 nordvpn-service; C:\Program Files (x86)\NordVPN\nordvpn-service.exe [217040 2019-05-22] (TEFINCOM S.A. -> )
R2 PlexUpdateService; C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe [1140200 2019-04-04] (Plex, Inc -> Plex, Inc.)
S2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [253776 2015-09-02] (CyberLink Corp. -> CyberLink)
R2 RstMwService; C:\WINDOWS\System32\DriverStore\FileRepository\iastorac.inf_amd64_5d83605e8696144c\RstMwService.exe [2115248 2019-02-26] (Intel® Rapid Storage Technology -> Intel Corporation)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [310016 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5773384 2019-07-14] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [39896 2019-05-24] (Dell Inc. -> Dell Inc.)
S2 tcsd_win32.exe; C:\Program Files\Dell\Dell Data Protection\Drivers\TSS\bin\tcsd_win32.exe [1636352 2012-12-10] (Security Innovation, Inc.) [File not signed]
R2 vmware-view-usbd; C:\Program Files (x86)\VMware\VMware Horizon View Client\bin\vmware-view-usbd.exe [1158984 2016-02-23] (VMware, Inc. -> VMware, Inc.)
R2 vmwsprrdpwks; C:\Program Files (x86)\Common Files\VMware\SerialPortRedirection\Client\vmwsprrdpwks.exe [261776 2015-05-08] (FabulaTech -> VMware)
R2 WavesSysSvc; C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe [613296 2015-12-22] (Waves Inc -> Waves Audio Ltd.)
S3 WD Backup Drive Helper; C:\WINDOWS\SysWOW64\dllhost.exe /Processid:{4AB831D3-8315-414C-8A7A-303105288D0B} [19256 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
S3 WD Backup Drive Helper; C:\WINDOWS\SysWOW64\dllhost.exe /Processid:{4AB831D3-8315-414C-8A7A-303105288D0B} [19256 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
S3 WD Backup Snapshot; C:\WINDOWS\SysWOW64\dllhost.exe /Processid:{302480DF-3AC5-4400-BE7B-DD77AF93B6DD} [19256 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
S3 WD Backup Snapshot; C:\WINDOWS\SysWOW64\dllhost.exe /Processid:{302480DF-3AC5-4400-BE7B-DD77AF93B6DD} [19256 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [524632 2018-03-26] (Western Digital Techologies -> Western Digital Technologies, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [4098056 2019-03-19] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [113992 2019-03-19] (Microsoft Corporation -> Microsoft Corporation)
R2 wsnm; C:\Program Files (x86)\VMware\VMware Horizon View Client\wsnm\wsnm.exe [541400 2016-03-25] (VMware, Inc. -> VMware, Inc.)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [4107360 2019-01-23] (Intel Corporation -> Intel® Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R0 cm_km; C:\WINDOWS\System32\DRIVERS\cm_km.sys [243400 2018-01-27] (Kaspersky Lab -> AO Kaspersky Lab)
R3 DDDriver; C:\WINDOWS\System32\drivers\dddriver64Dcsa.sys [40824 2019-02-27] (Microsoft Windows Hardware Compatibility Publisher -> Dell Inc.)
S3 DellProf; C:\WINDOWS\system32\drivers\DellProf.sys [41208 2018-05-08] (Techporch Incorporated -> Dell Computer Corporation)
R0 iaStorAC; C:\WINDOWS\System32\drivers\iaStorAC.sys [1018032 2019-02-26] (Intel® Rapid Storage Technology -> Intel Corporation)
S3 iaStorAfs; C:\WINDOWS\System32\drivers\iaStorAfs.sys [73416 2019-02-26] (Intel® Rapid Storage Technology -> Intel Corporation)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [732416 2016-10-15] (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation)
R3 IntcAzAudAddService; C:\WINDOWS\system32\drivers\RTDVHD64.sys [2677504 2016-04-14] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.)
R0 klbackupdisk; C:\WINDOWS\System32\DRIVERS\klbackupdisk.sys [75600 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klbackupflt; C:\WINDOWS\System32\DRIVERS\klbackupflt.sys [125568 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [91472 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
S0 klelam; C:\WINDOWS\System32\DRIVERS\klelam.sys [29208 2017-03-30] (Microsoft Windows Early Launch Anti-malware Publisher -> AO Kaspersky Lab)
R3 klflt; C:\WINDOWS\system32\DRIVERS\klflt.sys [236672 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klhk; C:\WINDOWS\System32\drivers\klhk.sys [1093248 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klids; C:\ProgramData\Kaspersky Lab\AVP19.0.0\Bases\klids.sys [197464 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [1168000 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klim6; C:\WINDOWS\system32\DRIVERS\klim6.sys [58704 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klkbdflt; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [60536 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klmouflt; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [60784 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klpd; C:\WINDOWS\System32\DRIVERS\klpd.sys [50304 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
S3 klpnpflt; C:\WINDOWS\system32\DRIVERS\klpnpflt.sys [46416 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 kltap; C:\WINDOWS\System32\drivers\kltap.sys [48080 2018-02-12] (AnchorFree Inc -> The OpenVPN Project)
R0 klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [245272 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klupd_klif_kimul; C:\WINDOWS\System32\Drivers\klupd_klif_kimul.sys [99152 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
S3 klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [302368 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R0 klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [116104 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [198768 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [104576 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klwtp; C:\WINDOWS\system32\DRIVERS\klwtp.sys [184960 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [218240 2019-07-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 Netwtw06; C:\WINDOWS\System32\drivers\Netwtw06.sys [8832800 2019-05-17] (Intel® Wireless Connectivity Solutions -> Intel Corporation)
R3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [779232 2016-08-04] (Realtek Semiconductor Corp. -> Realsil Semiconductor Corporation)
R0 SEDFilter; C:\WINDOWS\System32\DRIVERS\SEDFilter.sys [197808 2016-07-13] (Dell Inc -> Dell Inc.)
S3 SWDUMon; C:\WINDOWS\system32\DRIVERS\SWDUMon.sys [13920 2016-09-11] (SlimWare Utilities Inc. -> )
R3 tapnordvpn; C:\WINDOWS\System32\drivers\tapnordvpn.sys [44896 2018-07-24] (TEFINCOM S.A. -> The OpenVPN Project)
R3 usb3Hub; C:\WINDOWS\System32\drivers\usb3Hub.sys [212056 2015-07-06] (Intel® Wireless Display -> Windows ® Win 7 DDK provider)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46472 2019-03-19] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [333784 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
R1 wdfsconnect2017; C:\WINDOWS\system32\drivers\wdfsconnect2017.sys [468112 2017-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies, Inc.)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [62432 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
R3 wdvpnpbus; C:\WINDOWS\System32\drivers\wdvpnpbus.sys [20624 2017-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies, Inc.)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-07-14 19:25 - 2019-07-14 19:25 - 000000000 ___HD C:\OneDriveTemp
2019-07-14 19:11 - 2019-07-14 19:11 - 000000318 ____C C:\Users\indre\Desktop\respond.txt
2019-07-14 18:49 - 2019-07-14 18:49 - 000042129 ____C C:\Users\indre\Desktop\Addition.txt
2019-07-14 18:47 - 2019-07-14 19:26 - 000043554 ____C C:\Users\indre\Desktop\FRST.txt
2019-07-14 18:44 - 2019-07-14 18:44 - 000002341 _____ C:\Users\Public\Desktop\Intel® Rapid Storage Technology.lnk
2019-07-14 18:44 - 2019-07-14 18:44 - 000000000 ____D C:\Program Files\Common Files\Intel Corporation
2019-07-14 18:40 - 2019-07-14 18:40 - 021816776 _____ (Intel Corporation) C:\Users\indre\Downloads\SetupRST (3).exe
2019-07-14 13:25 - 2019-07-14 13:26 - 000037892 ____C C:\Users\indre\Desktop\Addition 7.txt
2019-07-14 13:24 - 2019-07-14 13:26 - 000159315 ____C C:\Users\indre\Desktop\FRST 7.txt
2019-07-14 13:17 - 2019-07-14 13:18 - 000004131 ____C C:\Users\indre\Desktop\Fixlog.txt
2019-07-14 13:15 - 2019-07-14 13:15 - 000002660 _____ C:\Users\indre\Downloads\fixlist (1).txt
2019-07-14 11:06 - 2019-07-14 11:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2019-07-14 05:05 - 2019-07-14 01:14 - 000000000 ____D C:\Windows.old
2019-07-14 04:54 - 2019-07-14 05:05 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2019-07-14 04:53 - 2019-07-14 04:54 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2019-07-14 04:53 - 2019-07-14 04:53 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2019-07-14 04:51 - 2019-07-14 04:51 - 025902080 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 025444864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 022625280 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 019849216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 019811328 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 018017792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 008011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 007802224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 007758336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 007175168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 007008768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 006218752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 005919744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 005745504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 005500416 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 005083352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 005014016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 004863488 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 004578816 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 004481536 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 004348408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 004306432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 004129416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 003837440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 003635200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 003525592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 003487232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 003365376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 003243080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 002956984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2019-07-14 04:51 - 2019-07-14 04:51 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2019-07-14 04:51 - 2019-07-14 04:51 - 002494232 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 002398208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 002314440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 002235936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 002216448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 002190648 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 002072152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001866064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001847808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsservices.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001715000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntVirtualization.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001611576 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVIntegration.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001608192 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001555688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001539584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001510960 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001501496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001493944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001391416 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 001383736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystemController.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001319936 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001283384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2019-07-14 04:51 - 2019-07-14 04:51 - 001282560 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001273344 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001273176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001248256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOE.DLL
2019-07-14 04:51 - 2019-07-14 04:51 - 001244728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001192096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 001151816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001124864 _____ (Microsoft Corporation) C:\WINDOWS\system32\CBDHSvc.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001105776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001098712 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001080832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001071928 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 001060352 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001043768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPolicy.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001039872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOE.DLL
2019-07-14 04:51 - 2019-07-14 04:51 - 001012792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001007104 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 001000960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000986112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000957240 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVManifest.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000912896 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000875008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000843776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000833536 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000829544 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioIso.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000827192 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVOrchestration.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000816440 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntStreamingManager.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000813568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000806400 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000801592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2019-07-14 04:51 - 2019-07-14 04:51 - 000782120 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000774152 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000769336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000744248 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOE.DLL
2019-07-14 04:51 - 2019-07-14 04:51 - 000743424 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000741176 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVReporting.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000737552 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOD.DLL
2019-07-14 04:51 - 2019-07-14 04:51 - 000705536 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000700928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapi.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000682744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOE.DLL
2019-07-14 04:51 - 2019-07-14 04:51 - 000669496 _____ (Microsoft Corporation) C:\WINDOWS\system32\computecore.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000666280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOD.DLL
2019-07-14 04:51 - 2019-07-14 04:51 - 000665912 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVCatalog.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000649016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPublishing.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000612352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000568336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000551824 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000537608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000529408 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000516752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000510768 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000500224 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2019-07-14 04:51 - 2019-07-14 04:51 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpshell.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000496128 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000494904 _____ (Microsoft Corporation) C:\WINDOWS\system32\TransportDSA.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000472576 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedRealitySvc.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000463272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000460288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcSpecfc.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000450048 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000429568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000422912 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000422008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2019-07-14 04:51 - 2019-07-14 04:51 - 000420360 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000400896 _____ (Microsoft Corporation) C:\WINDOWS\system32\DispBroker.Desktop.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000394040 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVScripting.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\provplatformdesktop.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000382976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcLayers.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000376320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspbde40.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000366184 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000363008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000357376 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000333824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapibase.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000321024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.FileExplorer.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000317952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000316216 _____ (Microsoft Corporation) C:\WINDOWS\system32\computestorage.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000307200 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000300184 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscobj.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000294400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_AnalogShell.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000267528 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000261016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityUxHost.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000257848 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVFileSystemMetadata.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000257536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\provplatformdesktop.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\RdpRelayTransport.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msltus40.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000231432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVShNotify.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000228664 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVStreamMap.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
2019-07-14 04:51 - 2019-07-14 04:51 - 000210440 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000202752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cscobj.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000202552 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVStreamingUX.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000186880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
2019-07-14 04:51 - 2019-07-14 04:51 - 000183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngOnline.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000181560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVDllSurrogate.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000177664 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetpp.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000172856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVNice.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000136720 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-kernel-processor-power-events.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\appvetwclientres.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000129088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000099712 _____ (Microsoft Corporation) C:\WINDOWS\system32\FsIso.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000093496 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000093312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpfve.sys
2019-07-14 04:51 - 2019-07-14 04:51 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompMgmtLauncher.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmlib.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000088064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000084280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winhvr.sys
2019-07-14 04:51 - 2019-07-14 04:51 - 000084280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2019-07-14 04:51 - 2019-07-14 04:51 - 000078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000058825 _____ C:\WINDOWS\system32\srms.dat
2019-07-14 04:51 - 2019-07-14 04:51 - 000053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeUISrv.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000042296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000037904 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncAppvPublishingServer.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimsg.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000022024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ScriptRunner.exe
2019-07-14 04:51 - 2019-07-14 04:51 - 000021304 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\appvetwstreamingux.dll
2019-07-14 04:51 - 2019-07-14 04:51 - 000011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 017786368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 014816256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 009917752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 007887440 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 007831368 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 007636616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 007275008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 007242312 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 006534712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 006381568 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 006224296 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 006068840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 006036480 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 005939712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 005071360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 005040640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 004562920 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 004552336 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 004537344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 004470784 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 004034048 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 004012032 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 004008960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Service.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003947520 _____ (Microsoft Corporation) C:\WINDOWS\system32\tellib.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003914480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 003771392 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003748864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003734456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003725312 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 003698176 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003654656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003590968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 003550720 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003372952 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003327256 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003263488 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003261440 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003106304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 003084800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002990608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 002876416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002871824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 002870784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002798592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 002771008 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002763552 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002725376 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 002698552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 002697728 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002656768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002587328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002576384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002561536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002550584 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002490712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002449456 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002443264 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002321408 _____ (The ICU Project) C:\WINDOWS\system32\icu.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002306048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002281984 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002258336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002178048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmgaclient.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002117160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 002081976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001999440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001979392 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001954960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001945600 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001940952 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001918976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001893888 _____ (The ICU Project) C:\WINDOWS\SysWOW64\icu.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001884672 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001856000 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001856000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConstraintIndex.Search.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001841152 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001830416 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001815040 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001784832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001781248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001761792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001754232 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2019-07-14 04:50 - 2019-07-14 04:50 - 001745920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001743672 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001721344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001721144 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001717560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001697792 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001697280 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001690624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001687552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001657856 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001651848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001647280 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001635328 _____ (Microsoft Corporation) C:\WINDOWS\system32\TaskFlowDataEngine.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001633648 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001608704 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001587712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001562640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001553408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmgaserver.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 001535288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001515008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmgaclient.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001509936 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 001505808 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpbase.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001480704 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpsharercom.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001473488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001458176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001437184 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 001422848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 001413704 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001413632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001395600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001393960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001375232 _____ (Microsoft Corporation) C:\WINDOWS\system32\APMon.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001366528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001366128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2019-07-14 04:50 - 2019-07-14 04:50 - 001362432 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001356800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001345024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001337656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001333248 _____ (Microsoft Corporation) C:\WINDOWS\system32\MiracastReceiver.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001321472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001313792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001304888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001282048 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsf3gip.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001262864 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001261568 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001260032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpsharercom.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001250432 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 001213456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpbase.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001182232 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 001159680 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001149928 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 001146880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001101312 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001092096 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001068856 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001067008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001065984 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001063944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001062912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmgaserver.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 001062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\BTAGService.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001042944 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2019-07-14 04:50 - 2019-07-14 04:50 - 001040896 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcRefreshTask.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001010176 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001007160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 001006592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000984376 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000947200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000939504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000928776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000919040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000916480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000913408 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000911360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MiracastReceiver.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000910272 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000900608 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000892696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000889656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000888056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000879792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000878080 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2019-07-14 04:50 - 2019-07-14 04:50 - 000876856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000864768 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000862720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Service.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000861696 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000858112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000858112 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000830976 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000824832 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000822072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000821696 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000818656 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000817152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\PEAuth.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000811192 _____ C:\WINDOWS\SysWOW64\locale.nls
2019-07-14 04:50 - 2019-07-14 04:50 - 000811192 _____ C:\WINDOWS\system32\locale.nls
2019-07-14 04:50 - 2019-07-14 04:50 - 000810512 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000804880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000797112 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000773168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000772656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000771584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000751256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000740664 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000739328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000727040 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000726328 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000722072 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000706544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mscms.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntime.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000701952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000696320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsreg.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000680760 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000680448 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000679368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000678400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000675328 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntimewindows.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000674816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000674072 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000673152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000673080 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000668160 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000667272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000663552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000645632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000644096 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000642008 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000637968 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000628616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000621568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000613904 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000611328 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000602432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mscms.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_9.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000592896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000589592 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000588464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000586552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000574976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_9.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000562176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2019-07-14 04:50 - 2019-07-14 04:50 - 000537088 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000537088 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000532992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.UserService.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000531976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2019-07-14 04:50 - 2019-07-14 04:50 - 000531464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000523912 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000516608 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000515896 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000513336 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000511288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000509440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000505856 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000481592 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000480768 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskcomp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000477496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2019-07-14 04:50 - 2019-07-14 04:50 - 000474112 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinDataModelServer.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000472064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000467456 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2019-07-14 04:50 - 2019-07-14 04:50 - 000466624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000464696 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000462848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000462352 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000461824 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000457016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.ConversationalAgent.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000455680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000451896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000441144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000435200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000435000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000425264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000423936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000420152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmicmiplugin.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000415800 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000415544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2019-07-14 04:50 - 2019-07-14 04:50 - 000406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000404392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000401416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000390456 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000388608 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000386016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000381240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000379192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000375808 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskcomp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000363624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000358944 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsta.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\MbbCx.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000353960 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000350208 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManager.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000344064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.BlueLightReduction.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000339520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbt.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000336928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000336752 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSrvPolicyManager.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000327680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000324624 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcommdlg.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000312320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL
2019-07-14 04:50 - 2019-07-14 04:50 - 000309760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000307712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000301568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000296976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000296448 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000284536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000283152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mssecflt.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000283136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000280576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000279624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winsta.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000278528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000274128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcTok.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000270336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\DesktopSwitcherDataModel.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3svc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000268216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000257536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbaudio2.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000248088 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000246784 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerCsp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000242688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_CapabilityAccess.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpnServiceDS.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000233984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\schtasks.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManagerClient.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000223248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelppm.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000220680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdigest.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000214032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ifsutil.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000211968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\hidclass.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000208184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\processr.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000205112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winquic.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000202040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000201256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdppm.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000199688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdk8.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000199184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000199176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000194176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winquic.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000193848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000193800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000187920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ifsutil.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000187392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schtasks.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\AarSvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000182072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpioclx.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000180536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000180024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ulib.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000179512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000178192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000164152 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000161848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000159232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BitLockerCsp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmgaproxystub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000149512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ulib.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000146920 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000146744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleprn.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\GraphicsCapture.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000142544 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingUI.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000142136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbus.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\luafv.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000139472 _____ (Microsoft Corporation) C:\WINDOWS\system32\userenv.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000134760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000132096 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000129848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mup.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000129024 _____ (Microsoft Corporation) C:\WINDOWS\system32\GameChatTranscription.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssitlb.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000127296 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000123912 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdnet.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinAUG.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000120352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapistub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapi32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000117048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000116184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\userenv.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000115200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleprn.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000115120 _____ (Microsoft Corporation) C:\WINDOWS\system32\phoneactivate.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\agilevpn.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Taskbar.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssitlb.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpoext.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GraphicsCapture.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3msm.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000102216 _____ (Microsoft Corporation) C:\WINDOWS\system32\changepk.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mapistub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mapi32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000098816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GameChatTranscription.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000098816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2019-07-14 04:50 - 2019-07-14 04:50 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3api.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000089544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000088560 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3api.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3msm.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApiSetHost.AppExecutionAlias.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\efsext.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000071720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwm.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\monitor.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\UsoClient.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000066360 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptdll.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000065064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsManagementServiceWinRt.ProxyStub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcadm.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ApiSetHost.AppExecutionAlias.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmgaproxystub.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssprxy.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\audioresourceregistrar.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000056008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptdll.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000055608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storufs.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efsext.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000047000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\hidparse.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\hidusb.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidusb.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiredNetworkCSP.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpgradeResultsUI.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000037888 _____ C:\WINDOWS\system32\usocoreps.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthMini.SYS
2019-07-14 04:50 - 2019-07-14 04:50 - 000036152 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mskssrv.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxssrv.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\FaxPrinterInstaller.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\KNetPwrDepBroker.sys
2019-07-14 04:50 - 2019-07-14 04:50 - 000028936 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmbuspipe.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilotdiag.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wci.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\fixmapi.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\bindflt.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fixmapi.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDJPN.DLL
2019-07-14 04:50 - 2019-07-14 04:50 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaevts.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\pacjsworker.exe
2019-07-14 04:50 - 2019-07-14 04:50 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimg32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimg32.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCertResources.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCertResources.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6r.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3r.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tier2punctuations.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6r.dll
2019-07-14 04:50 - 2019-07-14 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3r.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 004470272 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2019-07-14 04:48 - 2019-07-14 04:48 - 001166488 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 000903168 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsFilt.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 000778912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 000568320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsFilt.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 000124568 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 000103072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\XPSSHHDR.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 000081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XPSSHHDR.dll
2019-07-14 04:48 - 2019-07-14 04:48 - 000076060 _____ C:\WINDOWS\SysWOW64\xpsrchvw.xml
2019-07-14 04:48 - 2019-07-14 04:48 - 000076060 _____ C:\WINDOWS\system32\xpsrchvw.xml
2019-07-14 04:48 - 2019-07-14 04:48 - 000035592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2019-07-14 04:48 - 2019-07-14 04:48 - 000035592 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2019-07-14 04:48 - 2019-07-14 04:48 - 000000000 ____D C:\Program Files\Reference Assemblies
2019-07-14 04:48 - 2019-07-14 04:48 - 000000000 ____D C:\Program Files\MSBuild
2019-07-14 04:48 - 2019-07-14 04:48 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2019-07-14 04:48 - 2019-07-14 04:48 - 000000000 ____D C:\Program Files (x86)\MSBuild
2019-07-14 01:49 - 2019-07-14 01:49 - 000159969 ____C C:\Users\indre\Desktop\FRST 6.txt
2019-07-14 01:49 - 2019-07-14 01:49 - 000044556 ____C C:\Users\indre\Desktop\Addition 6.txt
2019-07-14 01:16 - 2019-07-14 18:50 - 000842664 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-07-14 01:15 - 2019-07-14 01:15 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2019-07-14 01:14 - 2019-07-14 01:14 - 000000020 ___SH C:\Users\indre\ntuser.ini
2019-07-14 01:13 - 2019-07-14 19:25 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-07-14 01:13 - 2019-07-14 19:11 - 000004166 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{71AF15CB-04B4-4B18-8047-5E35B9C7421E}
2019-07-14 01:13 - 2019-07-14 13:04 - 000000000 ____D C:\WINDOWS\System32\Tasks\Intel
2019-07-14 01:13 - 2019-07-14 01:13 - 000007623 _____ C:\WINDOWS\diagwrn.xml
2019-07-14 01:13 - 2019-07-14 01:13 - 000007623 _____ C:\WINDOWS\diagerr.xml
2019-07-14 01:13 - 2019-07-14 01:13 - 000003762 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2019-07-14 01:13 - 2019-07-14 01:13 - 000003750 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier
2019-07-14 01:13 - 2019-07-14 01:13 - 000003482 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2019-07-14 01:13 - 2019-07-14 01:13 - 000003346 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2019-07-14 01:13 - 2019-07-14 01:13 - 000003298 _____ C:\WINDOWS\System32\Tasks\Dell SupportAssistAgent AutoUpdate
2019-07-14 01:13 - 2019-07-14 01:13 - 000003278 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2019-07-14 01:13 - 2019-07-14 01:13 - 000003122 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2019-07-14 01:13 - 2019-07-14 01:13 - 000003118 _____ C:\WINDOWS\System32\Tasks\Intel PTT EK Recertification
2019-07-14 01:13 - 2019-07-14 01:13 - 000003042 _____ C:\WINDOWS\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473
2019-07-14 01:13 - 2019-07-14 01:13 - 000003040 _____ C:\WINDOWS\System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec
2019-07-14 01:13 - 2019-07-14 01:13 - 000002858 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1593158232-969496310-2340663774-1001
2019-07-14 01:13 - 2019-07-14 01:13 - 000002702 _____ C:\WINDOWS\System32\Tasks\GarminUpdaterTask
2019-07-14 01:13 - 2019-07-14 01:13 - 000002674 _____ C:\WINDOWS\System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec-Logon
2019-07-14 01:13 - 2019-07-14 01:13 - 000002638 _____ C:\WINDOWS\System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901}
2019-07-14 01:13 - 2019-07-14 01:13 - 000002528 _____ C:\WINDOWS\System32\Tasks\CLVDLauncher
2019-07-14 01:13 - 2019-07-14 01:13 - 000002528 _____ C:\WINDOWS\System32\Tasks\CLMLSvc_P2G8
2019-07-14 01:13 - 2019-07-14 01:13 - 000002422 _____ C:\WINDOWS\System32\Tasks\WD Device Agent Task indre
2019-07-14 01:13 - 2019-07-14 01:13 - 000002418 _____ C:\WINDOWS\System32\Tasks\WD Discovery Service Task indre
2019-07-14 01:13 - 2019-07-14 01:13 - 000002304 _____ C:\WINDOWS\System32\Tasks\RtHDVBg_PushButton
2019-07-14 01:13 - 2019-07-14 01:13 - 000000000 ____D C:\WINDOWS\System32\Tasks\Hewlett-Packard
2019-07-14 01:13 - 2019-07-14 01:13 - 000000000 ____D C:\WINDOWS\System32\Tasks\Dell
2019-07-14 01:13 - 2019-07-14 01:13 - 000000000 ____D C:\WINDOWS\System32\Tasks\Apple
2019-07-14 01:12 - 2019-07-14 01:12 - 000000000 ____D C:\ProgramData\USOShared
2019-07-14 01:08 - 2019-07-14 17:01 - 000000000 ____D C:\Users\indre
2019-07-14 01:08 - 2019-07-14 04:50 - 002874368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2019-07-14 01:08 - 2019-03-19 00:46 - 000001105 _____ C:\Users\indre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-07-14 01:07 - 2019-07-14 01:07 - 000000000 ____D C:\Program Files\Waves
2019-07-14 01:07 - 2018-03-22 02:24 - 000144832 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2019-07-14 01:05 - 2019-07-14 16:51 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-07-14 01:05 - 2019-07-14 01:09 - 000444408 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-07-14 00:01 - 2019-07-14 01:14 - 000000000 ___DC C:\WINDOWS\Panther
2019-07-13 22:13 - 2019-07-13 22:13 - 000100185 ____C C:\Users\indre\Desktop\FRST 5.txt
2019-07-13 22:13 - 2019-07-13 22:13 - 000044036 ____C C:\Users\indre\Desktop\Addition 5.txt
2019-07-13 21:28 - 2019-07-13 21:28 - 002095104 ____C (Farbar) C:\Users\indre\Desktop\FRST64.exe
2019-07-13 21:28 - 2019-07-13 21:28 - 002095104 _____ (Farbar) C:\Users\indre\Downloads\FRST64 (4).exe
2019-07-13 13:07 - 2019-07-14 01:29 - 000002865 ____C C:\Users\indre\Desktop\OOSU10.ini
2019-07-13 13:06 - 2019-07-13 13:06 - 001068584 ____C (O&O Software GmbH) C:\Users\indre\Desktop\OOSU10.exe
2019-07-13 13:06 - 2019-07-13 13:06 - 001068584 _____ (O&O Software GmbH) C:\Users\indre\Downloads\OOSU10.exe
2019-07-13 11:53 - 2019-07-13 11:53 - 021820224 ____C (Intel® Corporation) C:\Users\indre\Desktop\WiFi_21.20.0_Driver64_Win10.exe
2019-07-13 11:53 - 2019-07-13 11:53 - 021820224 _____ (Intel® Corporation) C:\Users\indre\Downloads\WiFi_21.20.0_Driver64_Win10.exe
2019-07-13 01:16 - 2019-07-13 01:16 - 000042265 ____C C:\Users\indre\Desktop\Addition 4.txt
2019-07-13 00:42 - 2019-07-13 00:42 - 000100258 ____C C:\Users\indre\Desktop\FRST 4.txt
2019-07-13 00:25 - 2019-07-13 00:25 - 014543816 _____ (Intel Corporation) C:\Users\indre\Downloads\SetupRST (2).exe
2019-07-13 00:21 - 2019-07-13 00:21 - 014543816 _____ (Intel Corporation) C:\Users\indre\Downloads\SetupRST (1).exe
2019-07-12 21:35 - 2019-07-12 21:35 - 000000000 ____D C:\Users\indre\Intel
2019-07-12 21:31 - 2019-07-12 21:31 - 021816776 _____ (Intel Corporation) C:\Users\indre\Downloads\SetupRST.exe
2019-07-12 19:03 - 2019-07-12 19:03 - 000042006 ____C C:\Users\indre\Desktop\Addition 3.txt
2019-07-12 19:00 - 2019-07-12 19:00 - 000117354 ____C C:\Users\indre\Desktop\FRST 3.txt
2019-07-12 18:49 - 2019-07-12 18:49 - 000062468 _____ C:\ProgramData\agent.uninstall.1562971733.bdinstall.v2.bin
2019-07-12 18:49 - 2019-07-12 18:49 - 000002522 _____ C:\Users\indre\Downloads\fixlist.txt
2019-07-12 13:55 - 2019-07-12 13:56 - 000169646 ____C C:\Users\indre\Desktop\DESKTOP-EL88UDV 2.txt
2019-07-12 13:50 - 2019-07-12 13:50 - 000117516 ____C C:\Users\indre\Desktop\FRST 2.txt
2019-07-12 13:50 - 2019-07-12 13:50 - 000043949 ____C C:\Users\indre\Desktop\Addition 2.txt
2019-07-12 13:32 - 2019-07-13 00:38 - 000042262 ____C C:\Users\indre\Desktop\Addition 1.txt
2019-07-12 13:28 - 2019-07-12 13:28 - 002095104 _____ (Farbar) C:\Users\indre\Downloads\FRST64 (3).exe
2019-07-12 13:27 - 2019-07-12 13:27 - 002095104 _____ (Farbar) C:\Users\indre\Downloads\FRST64 (2).exe
2019-07-12 12:51 - 2019-07-12 12:51 - 000001301 _____ C:\Users\Public\Desktop\WD Discovery.lnk
2019-07-12 12:51 - 2019-07-12 12:51 - 000000000 ___DC C:\Users\indre\AppData\Roaming\WDDesktop
2019-07-12 12:50 - 2019-07-14 19:25 - 000000000 ___DC C:\Users\indre\AppData\Roaming\WD Discovery
2019-07-12 12:50 - 2019-07-14 19:25 - 000000000 ____D C:\Users\indre\.wdc
2019-07-12 12:50 - 2019-07-12 12:54 - 000000000 ____D C:\Program Files\WD Desktop App
2019-07-12 12:50 - 2017-11-21 12:03 - 000468112 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\Drivers\wdfsconnect2017.sys
2019-07-12 12:50 - 2017-11-21 12:03 - 000020624 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\Drivers\wdvpnpbus.sys
2019-07-12 12:50 - 2017-11-10 12:51 - 000223744 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\SysWOW64\wdfsconnectNetRdr2017.dll
2019-07-12 12:50 - 2017-11-10 12:51 - 000180224 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll
2019-07-12 12:50 - 2017-11-10 12:51 - 000154112 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\SysWOW64\wdfsconnectMntNtf2017.dll
2019-07-12 12:50 - 2017-11-10 12:51 - 000118272 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\wdfsconnectNetRdr2017.dll
2019-07-12 12:50 - 2017-11-10 12:51 - 000002560 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\wdfsconnectevtmsg.dll
2019-07-12 12:16 - 2019-07-12 12:16 - 000001192 _____ C:\Users\Public\Desktop\WD Drive Utilities.lnk
2019-07-12 12:14 - 2019-07-14 05:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WD Discovery
2019-07-12 12:14 - 2019-07-12 13:23 - 000002228 _____ C:\Users\Public\Desktop\WD Backup.lnk
2019-07-12 12:14 - 2019-07-12 13:23 - 000000000 ____D C:\Program Files (x86)\Western Digital
2019-07-12 12:14 - 2019-07-12 12:14 - 000000000 ___DC C:\Users\indre\AppData\Roaming\Western Digital
2019-07-12 12:14 - 2019-07-12 12:14 - 000000000 ____D C:\ProgramData\Western Digital
2019-07-12 11:29 - 2019-07-12 11:29 - 005278464 _____ (Paramount Software UK Ltd) C:\Users\indre\Downloads\ReflectDLHF (1).exe
2019-07-12 11:25 - 2019-07-12 11:31 - 000000000 ____D C:\ProgramData\Macrium
2019-07-12 11:25 - 2019-07-12 11:25 - 000000000 ____D C:\Users\indre\Downloads\Macrium
2019-07-12 11:24 - 2019-07-12 11:25 - 005278464 _____ (Paramount Software UK Ltd) C:\Users\indre\Downloads\ReflectDLHF.exe
2019-07-11 12:12 - 2019-07-11 12:12 - 000000000 ___DC C:\Users\indre\Documents\Kaspersky Password Manager
2019-07-10 22:50 - 2019-07-10 22:50 - 000000000 ___DC C:\Users\indre\AppData\Local\Garmin
2019-07-09 13:11 - 2019-07-09 13:11 - 004730179 _____ C:\Users\indre\Downloads\Master Folder For Cleared Checks INDY (2).xlsx
2019-07-09 13:09 - 2019-07-09 13:09 - 008141856 _____ C:\Users\indre\Downloads\MASTER ALL CHECKS (4).xlsx
2019-07-08 13:49 - 2019-07-08 13:49 - 000000000 ___DC C:\Users\indre\Documents\ED stuff
2019-07-08 11:03 - 2019-07-08 11:04 - 000188559 ____C C:\Users\indre\Desktop\DESKTOP-EL88UDV.txt
2019-07-08 11:01 - 2019-07-14 05:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2019-07-08 11:01 - 2019-07-08 11:01 - 000000839 _____ C:\Users\Public\Desktop\Speccy.lnk
2019-07-08 11:01 - 2019-07-08 11:01 - 000000000 ____D C:\Program Files\Speccy
2019-07-08 10:59 - 2019-07-08 10:59 - 006889184 _____ (Piriform Ltd) C:\Users\indre\Downloads\spsetup132.exe
2019-07-08 10:59 - 2019-07-08 10:59 - 001309592 _____ (BraveSoftware Inc.) C:\Users\indre\Downloads\BraveBrowserSetup-TPF550.exe
2019-07-08 10:56 - 2019-07-08 10:56 - 000019118 _____ C:\junk.txt
2019-07-08 10:54 - 2019-07-08 10:54 - 000026673 ____C C:\Users\indre\Desktop\Registry 070819.txt
2019-07-08 10:50 - 2019-07-08 10:50 - 002826520 _____ (Sysinternals - www.sysinternals.com) C:\Users\indre\Downloads\procexp (1).exe
2019-07-08 10:50 - 2019-07-08 10:50 - 000043192 _____ (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP152.SYS
2019-07-08 10:49 - 2019-07-08 10:49 - 002826520 _____ (Sysinternals - www.sysinternals.com) C:\Users\indre\Downloads\procexp.exe
2019-07-08 10:47 - 2019-07-08 10:47 - 000023010 ____C C:\Users\indre\Desktop\VEW Application 070819.txt
2019-07-08 10:44 - 2019-07-08 10:44 - 000007664 ____C C:\Users\indre\Desktop\VEW Events 070819.txt
2019-07-08 10:43 - 2019-07-08 10:46 - 000023010 _____ C:\VEW.txt
2019-07-08 10:40 - 2019-07-08 10:40 - 000061440 _____ ( ) C:\Users\indre\Downloads\VEW.exe
2019-07-06 13:06 - 2019-07-06 13:06 - 000302368 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klark.sys
2019-07-06 13:04 - 2019-07-14 05:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Password Manager
2019-07-06 13:04 - 2019-07-06 13:04 - 000001371 _____ C:\Users\Public\Desktop\Kaspersky Password Manager.lnk
2019-07-06 13:04 - 2019-07-06 13:04 - 000000000 ___DC C:\Users\indre\AppData\Local\Kaspersky Lab
2019-07-06 13:00 - 2019-07-14 05:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Secure Connection
2019-07-06 13:00 - 2019-07-06 13:00 - 000245272 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_arkmon.sys
2019-07-06 13:00 - 2019-07-06 13:00 - 000198768 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_mark.sys
2019-07-06 13:00 - 2019-07-06 13:00 - 000116104 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klbg.sys
2019-07-06 13:00 - 2019-07-06 13:00 - 000099152 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_kimul.sys
2019-07-06 12:59 - 2019-07-14 19:25 - 000000000 ____D C:\ProgramData\Kaspersky Lab
2019-07-06 12:59 - 2019-07-14 05:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Total Security
2019-07-06 12:59 - 2019-07-06 13:17 - 000236672 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klflt.sys
2019-07-06 12:59 - 2019-07-06 13:16 - 001168000 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klif.sys
2019-07-06 12:59 - 2019-07-06 13:04 - 000000000 ____D C:\Program Files (x86)\Kaspersky Lab
2019-07-06 12:59 - 2019-07-06 12:59 - 000002210 _____ C:\Users\Public\Desktop\Safe Money.lnk
2019-07-06 12:59 - 2019-07-06 12:59 - 000002182 _____ C:\Users\Public\Desktop\Kaspersky Total Security.lnk
2019-07-06 12:59 - 2013-05-06 08:13 - 000110176 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\klfphc.dll
2019-07-06 12:57 - 2019-07-06 12:56 - 000592616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2019-07-06 12:54 - 2019-07-06 12:55 - 000000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2019-07-06 12:54 - 2019-07-06 12:54 - 002660224 _____ (Kaspersky Lab) C:\Users\indre\Downloads\startup_14445.exe
2019-07-06 10:01 - 2019-07-06 10:01 - 002420224 _____ (Farbar) C:\Users\indre\Downloads\FRST64 (1).exe
2019-07-06 10:00 - 2019-07-13 00:38 - 000100255 ____C C:\Users\indre\Desktop\FRST 1.txt
2019-07-06 09:58 - 2019-07-06 10:00 - 000039445 _____ C:\Users\indre\Downloads\Addition.txt
2019-07-06 09:55 - 2019-07-06 09:59 - 000079818 _____ C:\Users\indre\Downloads\FRST.txt
2019-07-06 09:54 - 2019-07-14 19:26 - 000000000 ____D C:\FRST
2019-07-06 09:53 - 2019-07-06 09:53 - 002420224 _____ (Farbar) C:\Users\indre\Downloads\FRST64.exe
2019-06-29 23:56 - 2019-06-29 23:56 - 011069444 _____ C:\Users\indre\Downloads\thecourtshipofeddiesfather-1st (1).mpg
2019-06-29 23:55 - 2019-06-29 23:55 - 011069444 _____ C:\Users\indre\Downloads\thecourtshipofeddiesfather-1st.mpg
2019-06-29 11:29 - 2019-06-29 11:29 - 000074636 _____ C:\ProgramData\agent.update.1561822169.bdinstall.v2.bin
2019-06-27 20:31 - 2019-06-27 20:31 - 022709477 _____ C:\Users\indre\Downloads\20190627_202829_19399014677980 (1).mp4
2019-06-27 20:30 - 2019-06-27 20:30 - 022709477 _____ C:\Users\indre\Downloads\20190627_202829_19399014677980.mp4
2019-06-27 19:53 - 2019-06-27 19:53 - 000000054 ____C C:\Users\indre\Desktop\cryptic stacey 062719.txt
2019-06-24 00:13 - 2019-07-07 22:03 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2019-06-23 23:58 - 2019-06-23 23:58 - 000068279 _____ C:\Users\indre\Downloads\Iulo_Susan_References_2019.pdf
2019-06-23 14:04 - 2019-06-23 14:04 - 000128245 _____ C:\Users\indre\Downloads\Iulo_Susan_-_Resume_2019.pdf
2019-06-21 20:51 - 2019-06-21 20:51 - 000128344 _____ C:\Users\indre\Downloads\Iulo_Susan_-_resume_June_2019_FIRST DRAFT (2).pdf
2019-06-21 20:28 - 2019-06-21 20:28 - 000128344 _____ C:\Users\indre\Downloads\Iulo_Susan_-_resume_June_2019_FIRST DRAFT (1).pdf
2019-06-21 20:25 - 2019-06-21 20:25 - 000128344 _____ C:\Users\indre\Downloads\Iulo_Susan_-_resume_June_2019_FIRST DRAFT.pdf
2019-06-20 12:13 - 2019-06-20 12:13 - 000004919 _____ C:\Users\indre\Downloads\imp8A93.pdf
2019-06-20 12:13 - 2019-06-20 12:13 - 000004919 _____ C:\Users\indre\Downloads\imp8A93 (1).pdf
2019-06-18 21:05 - 2019-06-18 21:05 - 000039557 _____ C:\Users\indre\Downloads\Letters_2019_06_14_12_42_30_156.pdf
2019-06-18 02:30 - 2019-06-18 02:30 - 000363078 _____ C:\Users\indre\Downloads\Preprinted UPS label for Treasury to Farmingdale 010918.pdf
2019-06-17 14:37 - 2019-06-17 14:37 - 000350164 _____ C:\Users\indre\Downloads\Statement_062019_8810.pdf
 
==================== One month (modified) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-07-14 19:25 - 2019-03-19 00:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-07-14 19:25 - 2016-09-11 19:32 - 000000000 ___RD C:\Users\indre\OneDrive
2019-07-14 19:25 - 2016-09-11 19:30 - 000000000 __SHD C:\Users\indre\IntelGraphicsProfiles
2019-07-14 19:24 - 2019-03-19 00:37 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2019-07-14 19:01 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\Registration
2019-07-14 18:50 - 2019-03-19 00:50 - 000000000 ____D C:\WINDOWS\INF
2019-07-14 18:50 - 2019-03-19 00:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-07-14 18:45 - 2017-05-21 14:10 - 000000000 ____D C:\Program Files\Intel
2019-07-14 18:44 - 2016-08-09 19:33 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2019-07-14 18:43 - 2019-06-13 20:32 - 000000000 ____D C:\Program Files\Common Files\Intel
2019-07-14 14:16 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-07-14 14:11 - 2019-03-19 00:52 - 000000000 ___HD C:\Program Files\WindowsApps
2019-07-14 13:13 - 2018-11-16 12:19 - 000000000 ____D C:\Program Files\rempl
2019-07-14 11:06 - 2019-05-14 13:15 - 000002495 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2019-07-14 11:06 - 2019-05-14 13:15 - 000002494 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2019-07-14 11:06 - 2019-05-14 13:15 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2019-07-14 11:06 - 2019-05-14 13:15 - 000002451 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2019-07-14 11:06 - 2019-05-14 13:15 - 000002437 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2019-07-14 11:05 - 2016-08-09 19:40 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2019-07-14 11:00 - 2019-03-19 00:56 - 000835688 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2019-07-14 11:00 - 2019-03-19 00:56 - 000179816 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2019-07-14 05:05 - 2019-06-13 20:33 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless
2019-07-14 05:05 - 2019-05-28 22:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2019-07-14 05:05 - 2019-05-24 22:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NordVPN
2019-07-14 05:05 - 2019-04-21 20:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Plex Media Server
2019-07-14 05:05 - 2019-03-19 00:56 - 000000000 ____D C:\WINDOWS\Setup
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 __RHD C:\Users\Public\Libraries
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\spool
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\NDF
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\Macromed
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\Drivers\DriverData
2019-07-14 05:05 - 2019-03-19 00:52 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2019-07-14 05:05 - 2019-03-19 00:49 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2019-07-14 05:05 - 2018-10-28 02:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
2019-07-14 05:05 - 2018-07-25 13:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CutePDF
2019-07-14 05:05 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2019-07-14 05:05 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2019-07-14 05:05 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\InfusedApps
2019-07-14 05:05 - 2017-10-14 21:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2019-07-14 05:05 - 2017-05-09 21:49 - 000000000 ____D C:\Program Files\UNP
2019-07-14 05:05 - 2016-09-16 23:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TextPad 8
2019-07-14 05:05 - 2016-09-16 23:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2019-07-14 05:05 - 2016-09-16 22:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pretty Good Solitaire
2019-07-14 05:05 - 2016-09-16 13:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware
2019-07-14 05:05 - 2016-09-13 22:50 - 000000000 ____D C:\WINDOWS\system32\appmgmt
2019-07-14 05:05 - 2016-08-09 19:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
2019-07-14 05:05 - 2016-08-09 19:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Media Suite
2019-07-14 05:05 - 2016-08-09 19:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
2019-07-14 05:05 - 2016-08-09 19:34 - 000000000 ___HD C:\WINDOWS\system32\WLANProfiles
2019-07-14 04:54 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\oobe
2019-07-14 04:54 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\Resources
2019-07-14 04:54 - 2017-05-21 14:10 - 000000000 ____D C:\Program Files\Realtek
2019-07-14 04:54 - 2016-09-17 01:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rovio
2019-07-14 04:54 - 2016-09-16 20:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2019-07-14 04:54 - 2016-08-09 19:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewBlue
2019-07-14 04:52 - 2019-03-19 02:23 - 000000000 ___SD C:\WINDOWS\system32\AppV
2019-07-14 04:52 - 2019-03-19 02:23 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2019-07-14 04:52 - 2019-03-19 00:52 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2019-07-14 04:52 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\SystemResources
2019-07-14 04:52 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\migwiz
2019-07-14 04:52 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\appraiser
2019-07-14 04:52 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\ShellExperiences
2019-07-14 04:52 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\ShellComponents
2019-07-14 04:52 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\bcastdvr
2019-07-14 04:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2019-07-14 04:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2019-07-14 04:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2019-07-14 04:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2019-07-14 04:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2019-07-14 04:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2019-07-14 04:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\et-EE
2019-07-14 04:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\es-MX
2019-07-14 03:32 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\appcompat
2019-07-14 03:26 - 2019-03-19 00:37 - 000008192 _____ C:\WINDOWS\system32\config\ELAM
2019-07-14 02:36 - 2018-07-04 13:52 - 000000000 ____D C:\ProgramData\Packages
2019-07-14 01:32 - 2017-11-15 23:37 - 000000000 ___DC C:\Users\indre\AppData\Local\Packages
2019-07-14 01:31 - 2018-12-15 03:16 - 000000000 ___DC C:\Users\indre\AppData\Local\PlaceholderTileLogoFolder
2019-07-14 01:14 - 2017-11-15 23:45 - 000000000 ___RD C:\Users\indre\3D Objects
2019-07-14 01:14 - 2016-09-30 22:13 - 000000000 ___DC C:\Users\indre\AppData\Local\ConnectedDevicesPlatform
2019-07-14 01:14 - 2016-08-09 19:48 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-07-14 01:13 - 2016-08-09 19:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Audio
2019-07-14 01:12 - 2019-03-19 00:52 - 000000000 ____D C:\ProgramData\USOPrivate
2019-07-14 01:12 - 2016-09-11 19:57 - 000002303 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-07-14 01:12 - 2016-09-11 19:57 - 000002262 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2019-07-14 01:10 - 2016-09-30 22:09 - 000027452 _____ C:\WINDOWS\system32\emptyregdb.dat
2019-07-14 01:08 - 2018-04-06 21:09 - 000000000 ___DC C:\Users\indre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom
2019-07-14 01:07 - 2019-03-19 00:52 - 000000000 ___RD C:\WINDOWS\PrintDialog
2019-07-14 01:07 - 2017-05-21 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\sda
2019-07-14 01:07 - 2017-05-21 14:10 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2019-07-14 01:07 - 2017-05-21 14:10 - 000000000 ____D C:\WINDOWS\system32\RTCOM
2019-07-14 01:06 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\ServiceState
2019-07-14 01:06 - 2018-05-23 18:30 - 000000000 ____D C:\WINDOWS\IAStorAfsService
2019-07-12 21:35 - 2017-05-21 14:10 - 000000000 ____D C:\Program Files (x86)\Intel
2019-07-12 19:21 - 2016-09-17 01:09 - 000000000 ___DC C:\Users\indre\Documents\Letters
2019-07-12 13:23 - 2016-08-09 19:33 - 000000000 ____D C:\ProgramData\Package Cache
2019-07-12 11:43 - 2016-09-16 22:45 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-07-11 04:01 - 2016-11-18 22:39 - 000000000 ___DC C:\Users\indre\AppData\LocalLow\Mozilla
2019-07-10 07:49 - 2016-09-12 20:21 - 000000000 ____D C:\WINDOWS\system32\MRT
2019-07-10 07:36 - 2016-09-12 20:20 - 136618864 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2019-07-08 14:37 - 2016-09-18 09:35 - 000000000 ___DC C:\Users\indre\AppData\Local\CrashDumps
2019-07-08 13:50 - 2016-09-17 01:49 - 000000000 ___DC C:\Users\indre\Documents\Funny stuff
2019-07-08 13:43 - 2018-12-02 19:00 - 000000000 ___DC C:\Users\indre\Documents\Editing for Josh
2019-07-06 13:17 - 2019-02-13 14:10 - 000184960 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klwtp.sys
2019-07-06 13:17 - 2019-02-13 14:10 - 000125568 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klbackupflt.sys
2019-07-06 13:17 - 2019-02-13 14:10 - 000091472 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\kldisk.sys
2019-07-06 13:17 - 2018-02-24 05:17 - 000218240 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\kneps.sys
2019-07-06 13:17 - 2018-02-17 02:50 - 000104576 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klwfp.sys
2019-07-06 13:17 - 2018-01-15 05:13 - 000060536 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klkbdflt.sys
2019-07-06 13:16 - 2019-02-13 14:10 - 001093248 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klhk.sys
2019-07-06 13:16 - 2019-02-13 14:10 - 000152288 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\klhkum.dll
2019-07-06 13:16 - 2019-02-13 14:10 - 000075600 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klbackupdisk.sys
2019-07-06 13:16 - 2019-02-13 14:10 - 000046416 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klpnpflt.sys
2019-07-06 13:16 - 2018-02-12 04:17 - 000058704 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klim6.sys
2019-07-06 13:16 - 2017-12-11 11:49 - 000060784 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klmouflt.sys
2019-07-06 13:16 - 2017-05-30 18:51 - 000050304 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klpd.sys
2019-07-06 13:00 - 2017-02-04 10:05 - 000000000 ____D C:\Program Files\Common Files\AV
2019-07-06 01:15 - 2018-06-20 22:44 - 000002365 ____C C:\Users\indre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive (1).lnk
2019-06-29 23:58 - 2017-10-14 21:56 - 000000000 ___DC C:\Users\indre\AppData\Roaming\vlc
2019-06-29 23:56 - 2017-10-14 21:56 - 000001141 _____ C:\Users\Public\Desktop\VLC media player.lnk
2019-06-28 08:30 - 2016-09-16 13:57 - 000000000 ___DC C:\Users\indre\AppData\Roaming\VMware
2019-06-27 18:32 - 2016-09-11 19:59 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2019-06-27 00:47 - 2017-07-15 20:02 - 000014706 ____C C:\Users\indre\Documents\Indy's Finances.xlsx
2019-06-26 22:10 - 2016-09-11 19:59 - 000001007 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2019-06-21 21:34 - 2016-09-17 01:09 - 000000000 ___DC C:\Users\indre\Documents\Resumes etc
2019-06-21 16:50 - 2016-09-17 01:09 - 000000000 ___DC C:\Users\indre\Documents\Recipes
2019-06-18 05:52 - 2016-09-17 01:38 - 000000000 ___DC C:\Users\indre\Documents\Akiko stuff
 
==================== Files in the root of some directories ================
 
2018-11-19 21:23 - 2018-11-19 21:23 - 000000017 ____C () C:\Users\indre\AppData\Local\resmon.resmoncfg
 
==================== SigCheck ===============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ============================
 
(2) Addition scan:
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-07-2019
Ran by indre (14-07-2019 19:27:05)
Running from C:\Users\indre\Desktop
Windows 10 Pro Version 1903 18362.239 (X64) (2019-07-14 05:14:02)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1593158232-969496310-2340663774-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1593158232-969496310-2340663774-503 - Limited - Disabled)
Guest (S-1-5-21-1593158232-969496310-2340663774-501 - Limited - Disabled)
indre (S-1-5-21-1593158232-969496310-2340663774-1001 - Administrator - Enabled) => C:\Users\indre
WDAGUtilityAccount (S-1-5-21-1593158232-969496310-2340663774-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Kaspersky Total Security (Enabled - Up to date) {0AB30972-4BAC-7BEE-CBCA-B8F9E68797D8}
AS: Kaspersky Total Security (Enabled - Up to date) {B1D2E896-6D96-7460-F17A-838B9D00DD65}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Total Security (Enabled) {32888857-01C3-7AB6-E095-11CC1854D0A3}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Across Lite (HKLM-x32\...\{5F5C7350-9731-420F-97CC-8CAFEE7DA7A3}) (Version: 2.4.2451.1 - Literate Software)
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 19.012.20035 - Adobe Systems Incorporated)
Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.223 - Adobe)
Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.223 - Adobe)
Angry Birds (HKLM-x32\...\{2F7D5734-056F-4A0A-A1C7-CA1AAE5BB1EB}) (Version: 1.6.3.1 - Rovio)
ANT Drivers Installer x64 (HKLM\...\{D559687A-60C5-4786-9429-C21EC195789D}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Application Support (32-bit) (HKLM-x32\...\{C1BCFECF-6EC2-4750-9072-5E2489423F8F}) (Version: 7.5 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{B202C7F5-7DE3-4FBF-B259-E70E625F56FC}) (Version: 7.5 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B5A46811-3612-4DA5-8A5A-E6DED5D7C523}) (Version: 12.2.1.12 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{A30EA700-5515-48F0-88B0-9E99DC356B88}) (Version: 2.6.0.1 - Apple Inc.)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Cisco WebEx Meetings (HKLM-x32\...\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
CmgMasterPrerequisites (HKLM\...\{EE34FA4E-715A-46FA-9CAF-06E26AE4217D}) (Version: 1.10.0.34 - Dell, Inc.) Hidden
CutePDF Form Filler 3.6 (Evaluation) (HKLM-x32\...\CutePDF Form Filler (Evaluation)_is1) (Version:  - Acro Software Inc.)
CyberLink Media Suite Essentials (HKLM-x32\...\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 12 - CyberLink Corp.)
Dell Command | Update (HKLM-x32\...\{EC542D5D-B608-4145-A8F7-749C02BE6D94}) (Version: 2.2.0 - Dell Inc.)
Dell Data Protection | Client Security Framework (HKLM\...\{FAE38E46-ECB2-44EA-A52B-6955AA6B1B3A}) (Version: 8.10.0.39 - Dell, Inc.)
Dell Data Protection | Security Tools (HKLM-x32\...\{812AA6D3-5BEB-4577-88B1-00998B91AB41}) (Version: 1.10.0.34 - Dell, Inc.) Hidden
Dell Data Protection | Security Tools (HKLM-x32\...\InstallShield_{812AA6D3-5BEB-4577-88B1-00998B91AB41}) (Version: 1.10.0.34 - Dell, Inc.)
Dell Digital Delivery (HKLM-x32\...\{AB7F2792-2ED1-4C5C-9F28-680E5110BF72}) (Version: 3.1.1018.0 - Dell Products, LP)
Dell SupportAssist (HKLM\...\{806422F1-FC4E-4D7C-8855-05748AEFC031}) (Version: 3.2.2.119 - Dell Inc.)
DELLOSD (HKLM-x32\...\{BED3193A-897B-47F6-AEDC-45D147122957}) (Version: 1.0.0.0 - DELL)
Elevated Installer (HKLM-x32\...\{0BF90608-2F95-4C7C-9A85-E90E0CAF4FE9}) (Version: 6.9.1.0 - Garmin Ltd or its subsidiaries) Hidden
FileZilla Client 3.25.1 (HKLM-x32\...\FileZilla Client) (Version: 3.25.1 - Tim Kosse)
Garmin Express (HKLM-x32\...\{95D0EADA-5123-41C0-931A-F37946BC0E8E}) (Version: 6.9.1.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express (HKLM-x32\...\{eab4691c-4022-41cd-8d39-c3097ba62d4b}) (Version: 6.9.1.0 - Garmin Ltd or its subsidiaries)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 75.0.3770.100 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.11 - Google LLC) Hidden
HP Support Solutions Framework (HKLM-x32\...\{2B5A1E68-6617-406D-B797-5DAB5B4630B8}) (Version: 12.11.24.11 - HP Inc.)
Intel® Chipset Device Software (HKLM-x32\...\{fb610cea-ba50-4d4b-a717-cf025419035c}) (Version: 10.1.1.13 - Intel® Corporation) Hidden
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1054 - Intel Corporation)
Intel® Network Connections 20.3.300.1 (HKLM\...\PROSetDX) (Version: 20.3.300.1 - Intel)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 23.20.16.4973 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 17.2.0.1009 - Intel Corporation)
Intel® Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.47.866.0 - Intel Corporation) Hidden
Intel® Trusted Connect Services Client (HKLM-x32\...\{246c6cc0-9810-4728-9a29-28474de2eec5}) (Version: 1.47.866.0 - Intel Corporation) Hidden
Intel® WiDi (HKLM\...\{C7CD6D54-26AF-4D93-B06F-D81ACE8624CB}) (Version: 6.0.40.0 - Intel Corporation)
Intel® WiDi Software Asset Manager (HKLM-x32\...\{5B5CD20C-29F0-4857-A4FA-A4F4C716B019}) (Version: 1.1.347 - Intel Corporation) Hidden
Intel® Wireless Bluetooth® (HKLM-x32\...\{5068B0F8-CE24-4B61-9C2F-301B411FFB9C}) (Version: 18.1.1611.3223 - Intel Corporation)
Intel® Optane™ Pinning Explorer Extensions (HKLM\...\{F4F771E2-6E23-4F27-93E1-27C22C71B7E2}) (Version: 17.2.0.1009 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{f430aa46-62c4-47a0-8a03-42e7fff664b7}) (Version: 20.120.0 - Intel Corporation)
Intel® Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation)
iTunes (HKLM\...\{A8AF3EF8-5010-4A92-BCCA-90F62A7D62B8}) (Version: 12.9.5.7 - Apple Inc.)
Kaspersky Password Manager (HKLM-x32\...\{B2F7333E-6C8D-4994-AAC4-FEC8EBBF9611}) (Version: 9.0.2.767 - Kaspersky Lab) Hidden
Kaspersky Password Manager (HKLM-x32\...\InstallWIX_{B2F7333E-6C8D-4994-AAC4-FEC8EBBF9611}) (Version: 9.0.2.767 - Kaspersky Lab)
Kaspersky Secure Connection (HKLM-x32\...\{F10AA188-7166-430E-8810-FEAB2AD73DE3}) (Version: 19.0.0.1088 - Kaspersky Lab) Hidden
Kaspersky Secure Connection (HKLM-x32\...\InstallWIX_{F10AA188-7166-430E-8810-FEAB2AD73DE3}) (Version: 19.0.0.1088 - Kaspersky Lab)
Kaspersky Total Security (HKLM-x32\...\{718613F4-492D-4272-ACC3-D04A8EF0F883}) (Version: 19.0.0.1088 - Kaspersky Lab) Hidden
Kaspersky Total Security (HKLM-x32\...\InstallWIX_{718613F4-492D-4272-ACC3-D04A8EF0F883}) (Version: 19.0.0.1088 - Kaspersky Lab)
LaserJet 1020 series (HKLM-x32\...\HP-LaserJet 1020 series) (Version:  - )
Maxx Audio Installer (x64) (HKLM\...\{307032B2-6AF2-46D7-B933-62438DEB2B9A}) (Version: 2.6.8006.3 - Waves Audio Ltd.) Hidden
Microsoft Office Famille et Petite Entreprise 2016 - fr-fr (HKLM\...\HomeBusinessRetail - fr-fr) (Version: 16.0.11727.20244 - Microsoft Corporation)
Microsoft Office Hogar y Empresas 2016 - es-es (HKLM\...\HomeBusinessRetail - es-es) (Version: 16.0.11727.20244 - Microsoft Corporation)
Microsoft Office Home and Business 2016 - en-us (HKLM\...\HomeBusinessRetail - en-us) (Version: 16.0.11727.20244 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\OneDriveSetup.exe) (Version: 19.103.0527.0003 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (HKLM-x32\...\{6e8f74e0-43bd-4dce-8477-6ff6828acc07}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 (HKLM-x32\...\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24210 (HKLM-x32\...\{23658c02-145e-483d-ba6b-1eb82c580529}) (Version: 14.0.24210.0 - Microsoft Corporation)
Mozilla Firefox 67.0.4 (x64 en-US) (HKLM\...\Mozilla Firefox 67.0.4 (x64 en-US)) (Version: 67.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 66.0.3 - Mozilla)
NewBlue Video Essentials for Windows (HKLM-x32\...\NewBlue Video Essentials for Windows) (Version: 3.0 - NewBlue)
NordVPN (HKLM-x32\...\{F4325B30-A8A0-4D09-B0DE-7CBB485A52D8}) (Version: 6.22.6 - NordVPN) Hidden
NordVPN (HKLM-x32\...\NordVPN 6.22.6) (Version: 6.22.6 - NordVPN)
NordVPN network TAP (HKLM-x32\...\{97DEC5D6-2BE9-45BB-BFC5-274B851B486B}) (Version: 1.0.1 - NordVPN)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.11727.20244 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.11727.20244 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.11727.20244 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.11727.20244 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-040C-0000-0000000FF1CE}) (Version: 16.0.11727.20244 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0C0A-0000-0000000FF1CE}) (Version: 16.0.11727.20244 - Microsoft Corporation) Hidden
Plex Media Server (HKLM-x32\...\{72238E55-A877-4785-A5E9-0C35EAFB0746}) (Version: 1.15.876 - Plex, Inc.) Hidden
Plex Media Server (HKLM-x32\...\{9203fc01-57c0-4cc8-858d-92911b5142de}) (Version: 1.15.3.876 - Plex, Inc.)
Pretty Good Solitaire version 12.4.0 (HKLM-x32\...\Pretty Good Solitaire_is1) (Version: 12.4.0 - Goodsol Development Inc.)
proDAD Adorage 3.0 (HKLM-x32\...\proDAD-Adorage-3.0) (Version: 3.0.114.1 - proDAD GmbH)
Realtek Audio COM Components (HKLM-x32\...\{2355B503-9B11-4449-861D-1C1748B26320}) (Version: 1.0.2 - Realtek Semiconductor Corp.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.14393.21292 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6105 - Realtek Semiconductor Corp.)
Security Innovation TSS (HKLM\...\{0C11FE22-53F2-4C9B-9E79-824B10D0976E}) (Version: 2.1.42 - Security Innovation) Hidden
Speccy (HKLM\...\Speccy) (Version: 1.32 - Piriform)
Spotify (HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\Spotify) (Version: 1.0.96.181.gf6bc1b6b - Spotify AB)
Stopping Plex (HKLM-x32\...\{3C6D43CB-1211-4C3F-8F3C-2B4F90C5BB95}) (Version: 1.15.876 - Plex, Inc.) Hidden
TextPad 8 (HKLM\...\{861AB1C1-1967-4C4A-BF86-C255E2D2B8FD}) (Version: 8.0.2 - Helios)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{F14FB68A-9188-4036-AD0D-D054BC9C9291}) (Version: 2.59.0.0 - Microsoft Corporation)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.7.1 - VideoLAN)
VMware Horizon Client (HKLM\...\{93CEC220-0D24-41C0-8647-BA1C62A3EE89}) (Version: 4.0.1.781 - VMware, Inc.)
Vulkan Run Time Libraries 1.0.33.0 (HKLM\...\VulkanRT1.0.33.0) (Version: 1.0.33.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.33.0 (HKLM\...\VulkanRT1.0.33.0-2) (Version: 1.0.33.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1) (Version: 1.0.54.1 - Intel Corporation Inc.)
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-2) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-3) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
WD Backup (HKLM-x32\...\{50C6CAE8-562E-440D-8616-E0514D41CC10}) (Version: 1.9.6941.25593 - Western Digital Technologies, Inc) Hidden
WD Backup (HKLM-x32\...\{6531bf4b-4bad-46a5-9562-766d0a858003}) (Version: 1.9.6941.25593 - Western Digital Technologies, Inc.)
WD Desktop App 2.1.0.245 (HKLM-x32\...\{d303f1fe-6729-4693-b2e1-51d13b450de5}) (Version: 2.1.0.245 - Western Digital Corporation) Hidden
WD Desktop App 2.1.0.245 (x64) (HKLM\...\{CA7F7232-526E-41BD-971A-47BE28C18516}) (Version: 2.1.0.245 - Western Digital Corporation) Hidden
WD Discovery (HKLM-x32\...\WDDiscovery) (Version: 3.3.34 - Western Digital Technologies, Inc.)
WD Drive Utilities (HKLM-x32\...\{5ea95ccc-fc68-4182-88a9-e563ba3900ed}) (Version: 2.0.0.26 - Western Digital Technologies, Inc.)
WD Drive Utilities (HKLM-x32\...\{893C7059-0464-47FB-85A4-5E1ADDA56141}) (Version: 2.0.0.26 - Western Digital Technologies, Inc.) Hidden
WD SES Driver Setup (HKLM-x32\...\{924A274D-38B6-4930-8859-F3F51CFA8DDD}) (Version: 1.1.0.25 - Western Digital) Hidden
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Intel Corporation (iaStorA) HDC  (08/10/2017 15.7.5.1025) (HKLM\...\FF1B55CEF8D39B696D1F5DF141ACFA7A5D1F2743) (Version: 08/10/2017 15.7.5.1025 - Intel Corporation)
Windows Driver Package - Intel Corporation (iaStorA) SCSIAdapter  (08/10/2017 15.7.5.1025) (HKLM\...\6D773A6E21B2A480569157737F58E8FF7DC6608A) (Version: 08/10/2017 15.7.5.1025 - Intel Corporation)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Zoom (HKU\S-1-5-21-1593158232-969496310-2340663774-1001\...\ZoomUMX) (Version: 4.1 - Zoom Video Communications, Inc.)
 
Packages:
=========
CyberLink Media Suite Essentials -> C:\Program Files\WindowsApps\DB6EA5DB.CyberLinkMediaSuiteEssentials_1.0.10.0_x86__mcezb6ze687jp [2018-03-13] (CYBERLINK CORPORATION.)
Dell SupportAssist for PCs -> C:\Program Files\WindowsApps\DellInc.DellSupportAssistforPCs_3.2.5.0_x64__htrsf667h5kn2 [2019-05-29] (Dell Inc)
Facebook -> C:\Program Files\WindowsApps\Facebook.Facebook_186.2191.46880.0_x86__8xx8rvfyw5nnt [2019-07-14] (Facebook Inc)
Mail and Calendar -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe [2019-07-10] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1808.3.0_x64__8wekyb3d8bbwe [2019-07-14] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-12] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-12] (Microsoft Corporation) [MS Ad]
Microsoft Jigsaw -> C:\Program Files\WindowsApps\Microsoft.MicrosoftJigsaw_1.8.1812.301_x86__8wekyb3d8bbwe [2019-03-14] (Microsoft Studios) [MS Ad]
Microsoft Mahjong -> C:\Program Files\WindowsApps\Microsoft.MicrosoftMahjong_3.9.4100.0_x64__8wekyb3d8bbwe [2019-04-18] (Microsoft Studios) [MS Ad]
Microsoft Minesweeper -> C:\Program Files\WindowsApps\Microsoft.MicrosoftMinesweeper_2.7.4300.0_x86__8wekyb3d8bbwe [2019-02-18] (Microsoft Studios) [MS Ad]
Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.31.11723.0_x64__8wekyb3d8bbwe [2019-06-26] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.4.6132.0_x64__8wekyb3d8bbwe [2019-06-17] (Microsoft Studios) [MS Ad]
MSN Money -> C:\Program Files\WindowsApps\Microsoft.BingFinance_4.29.10701.0_x64__8wekyb3d8bbwe [2019-03-22] (Microsoft Corporation) [MS Ad]
MSN Sports -> C:\Program Files\WindowsApps\Microsoft.BingSports_4.28.3242.0_x64__8wekyb3d8bbwe [2018-12-15] (Microsoft Corporation) [MS Ad]
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.28.10351.0_x64__8wekyb3d8bbwe [2019-02-12] (Microsoft Corporation) [MS Ad]
PAC-MAN Battle -> C:\Program Files\WindowsApps\50867PocketKingGames.PAC-MANBattle_1.1.0.0_x64__m8bdd0rdw5vr0 [2018-12-15] (Pocket King Games) [MS Ad]
The Backgammon -> C:\Program Files\WindowsApps\6918E89D.TheBackgammon_1.2.0.0_x64__66n08swfvvka0 [2018-12-15] (UNBALANCE corp.) [MS Ad]
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.Twitter_6.1.4.1000_neutral__wgeqdkkx372wm [2018-09-08] (Twitter Inc.)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1593158232-969496310-2340663774-1001_Classes\CLSID\{5A9E21A2-851A-4BEB-B16F-DBBE7D648AF9}\InprocServer32 -> C:\Program Files\TextPad 8\System\ShellExt64.dll (Helios Software Solutions Ltd -> )
SSODL: WDFSMountNotificator-wdfsconnect2017 - {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2} - C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll (Western Digital Technologies, Inc.) [File not signed]
SSODL-x32: WDFSMountNotificator-wdfsconnect2017 - {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2} - C:\WINDOWS\SysWOW64\wdfsconnectMntNtf2017.dll (Western Digital Technologies, Inc.) [File not signed]
ShellServiceObjects: Virtual Storage Mount Notification -> {5F3C2DA0-75C3-4F79-B70F-ADB47AD8D0E2} => C:\WINDOWS\system32\wdfsconnectMntNtf2017.dll [2017-11-10] (Western Digital Technologies, Inc.) [File not signed]
Shell