Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Win 8.0 - slow performance and browser not connecting [Solved]

slow system browsers not connecting usb camera not seen by system

  • This topic is locked This topic is locked

#46
whittakerjr

whittakerjr

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts

Stayed at it.  I have the two reports now. Going to bed and will talk with you when you get a chance to respond.  3-day weekend, hope to get outdoors.  How is your personal time going - getting in some music time and friendship.

 

When I was using the msconfig to rest the boot, I saw Defender appear on the search for settings, not there the first time I searched.  Also, I notice under the general tab, the setting was Selective Startup, should it have been Normal?  I did not knowingly change it.

 

 

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 08-07-2020 01
Ran by HP Pavilion (10-07-2020 22:33:21) Run:4
Running from C:\Users\HP Pavilion\Desktop
Loaded Profiles: HP Pavilion
Boot Mode: Safe Mode (with Networking)
==============================================
 
fixlist content:
*****************
deletevalue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender|DisableAntiSpyware
 
*****************
 
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\\DisableAntiSpyware" => removed successfully
 
==== End of Fixlog 22:33:22 ====
 
Farbar Service Scanner Version: 14-12-2019
Ran by HP Pavilion (administrator) on 10-07-2020 at 22:57:59
Running from "C:\Users\HP Pavilion\Desktop"
Microsoft Windows 8.1  (X64)
Boot Mode: Normal
****************************************************************
 
Internet Services:
============
 
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.
 
 
Windows Firewall:
=============
 
Firewall Disabled Policy: 
==================
 
 
System Restore:
============
 
System Restore Policy: 
========================
 
 
Action Center:
============
 
 
Windows Update:
============
 
Windows Autoupdate Disabled Policy: 
============================
 
 
Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is OK.
The ImagePath of WinDefend: ""%ProgramFiles%\Windows Defender\MsMpEng.exe"".
 
 
Windows Defender Disabled Policy: 
==========================
 
 
Other Services:
==============
 
 
File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\dhcpcore.dll => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\System32\mpssvc.dll => File is digitally signed
C:\Windows\System32\bfe.dll => File is digitally signed
C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MsMpEng.exe => File is digitally signed
C:\Windows\System32\ipnathlp.dll => File is digitally signed
C:\Windows\System32\iphlpsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
 
 
**** End of log ****

  • 0

Advertisements


#47
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 2,665 posts
OK! Thank you!

I will be back to you later today.

Have a good rest! :)
  • 0

#48
whittakerjr

whittakerjr

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts

Good Morning,  First coat of paint is on the outdoor projects.

 

You summation is part right.  Yes, I was not able to get step 1 to do anything.  I could get to the restart and the system would close down, literally. - Power off.  When I powered it up, it was 5 minute or more and the visual was the standard desktop.

 

After I did msconfig the machine restarted in Safe Mode - four corners and the black background.  I did not look at the msconfig opening setting screen.  When I performed the msconfig the second time (to return the machine to launch normally, not is safe mode) I noticed the opening screen, General tab,  where the Selective startup button was selected and Load system services and load startup items were checked.


  • 0

#49
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 2,665 posts

Good morning to you. Not so much hot today I guess, to start outdoor projects. :)

 

 

When I performed the msconfig the second time (to return the machine to launch normally, not is safe mode) I noticed the opening screen, General tab,  where the Selective startup button was selected and Load system services and load startup items were checked.

 

This is OK. Nothing to worry about.

 

My instructor and I are currently discussing the situation of your friend's computer.


  • 0

#50
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 2,665 posts
Hi, Joseph.
 
It seems that the computer has issues, and as I already told you this might be due to several reasons, including corrupted system files or an outdated operating system.
 
Let's enable the Windows Defender first, see what happens and then plan the next steps.

1. Enable Windows Defender
  • Click on the Start button and in the search box, type Command Prompt
  • When you see Command Prompt on the list, right-click on it and select Run as administrator
  • Enter the command below and press on Enter;
sc start WinDefend
2. Fresh FRST logs
  • Double-click on the FRST icon to run it, as you did before. When the tool opens click Yes to disclaimer.
  • Press Scan button and wait for a while.
  • The scanner will produced two logs on your Desktop: FRST.txt and Addition.txt.
  • Please copy and paste the content of these two logs in your next reply.

  • 0

#51
whittakerjr

whittakerjr

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts

Yes, outdoor projects are early morning or later in the evening for me here.  I react to the sun, even with good sun screen on - long sleeve shirt, hat - you get the picture.  

 

Ugh!  the result was not positive..

 

 Microsoft Windows [Version 6.3.9600]

© 2013 Microsoft Corporation. All rights reserved.
 
C:\WINDOWS\system32>sc start WinDefend
[SC] StartService FAILED 577:
 
Windows cannot verify the digital signature for this file. A recent hardware or
software change might have installed a file that is signed incorrectly or damage
d, or that might be malicious software from an unknown source.
 
C:\WINDOWS\system32>
 
C:\WINDOWS\system32>
 
 
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-07-2020 01
Ran by HP Pavilion (administrator) on HPPAVILION (Hewlett-Packard 20-b010) (12-07-2020 01:43:42)
Running from C:\Users\HP Pavilion\Desktop
Loaded Profiles: HP Pavilion
Platform: Windows 8.1 (Update) (X64) Language: English (United States)
Default browser: IE
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(A.V.M. SOFTWARE, INC. -> AVM Software) C:\Program Files (x86)\Paltalk\update\pt_update_service.exe
(Advanced Micro Devices, Inc.) [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Andrea Electronics -> Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <9>
(Hewlett-Packard Company -> Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe
(Hewlett-Packard Company -> Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteUser.exe
(Logitech -> Logitech, Inc.) C:\Program Files\Logitech\SolarApp\L4301_Solar.exe
(Logitech Inc -> Logitech) C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\WINDOWS\System32\WirelessKB850NotificationService.exe
(Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\System32\SnippingTool.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\WINDOWS\System32\atieclxx.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\WINDOWS\System32\atiesrxx.exe
(Realtek Semiconductor Corp -> Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6844560 2013-11-19] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942232 2016-10-14] (Logitech -> Logitech, Inc.)
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\Run: [Chromium] => "c:\users\hp pavilion\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory=Default --restore-last-session
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27784672 2017-06-27] (Skype Software Sarl -> Skype Technologies S.A.)
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\Run: [Paltalk] => C:\Program Files (x86)\Paltalk\PALTALK.exe [27532728 2020-05-19] (A.V.M. SOFTWARE, INC. -> AVM Software)
HKU\S-1-5-18\...\Run: [Paltalk] => C:\Program Files (x86)\Paltalk\Paltalk.exe [27532728 2020-05-19] (A.V.M. SOFTWARE, INC. -> AVM Software)
HKLM\...\Print\Monitors\HP 7112 Status Monitor: C:\WINDOWS\system32\hpinksts7112LM.dll [328704 2014-03-03] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Co.)
HKLM\...\Print\Monitors\HP Universal Port Monitor: C:\WINDOWS\system32\hpbprtmon.dll [355840 2012-07-24] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\83.0.4103.116\Installer\chrmstp.exe [2020-06-25] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.81\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
 
==================== Scheduled Tasks (Whitelisted) ============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0DC0DAD2-F84F-429D-B085-411AE7CDE2D5} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4F47-879B-29A80C355D61}
Task: {145EF7F4-ECD0-4CD6-B44D-E92EFEB7BDDB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {287EB61E-849D-44F1-BF41-56B2A8081F95} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDFE067B1}
Task: {426C84D3-5DF0-4CC8-9486-251CC5F877B1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe
Task: {69A9BED9-2695-4FA6-ABEF-DB9C7F40DC6B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {7604A2BD-B1C7-4591-A0BB-AFA960B6026A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe
Task: {7B857988-3067-4E13-8891-998F430972F7} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316}
Task: {8447F5E5-2A40-44ED-869F-2FD08F7AF3E9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {8CA68387-B3CC-41B5-88D5-240C7A3E7715} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_CN49ADX0R9_backup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe
Task: {9768ABD2-EB67-498E-A669-15A536AF817A} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969}
Task: {9B50E759-DC50-4D5E-9238-094637C3F75D} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\HP Pavilion\Desktop\esetonlinescanner.exe [14827616 2020-06-25] (ESET, spol. s r.o. -> ESET spol. s r.o.)
Task: {BD0AA599-1290-4C17-8F27-F39B7AED26EB} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\HP Pavilion\Desktop\esetonlinescanner.exe [14827616 2020-06-25] (ESET, spol. s r.o. -> ESET spol. s r.o.)
Task: {C2D92648-7FFA-4B4E-BE32-ABCB7F598804} - System32\Tasks\{A7827154-50C7-4867-ADFD-1E8E30D0C7A2} => "c:\program files\internet explorer\iexplore.exe" hxxps://ui.skype.com/ui/0/7.33.0.105/en/abandoninstall?source=lightinstaller&page=tsMain
Task: {C415FE0E-DDCB-44E0-A459-B9164B72424B} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43DA-BFD7-FBEEA2180A1E}
Task: {CA019DD0-822D-49E1-A2FF-1991CECD8F38} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {DCB2E700-2511-45D2-B218-AE8BA4967108} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP SoftPaq Installer => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF_Tasks.exe
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Winsock: Catalog5 07 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 07 C:\Program Files\Bonjour\mdnsNSP.dll [132968 2011-08-30] (Apple Inc. -> Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{29B5CF79-3278-41A1-86F5-B3673D2C956F}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{CBC4812E-DD0B-4C8B-9F7F-46C2962A294B}: [DhcpNameServer] 192.168.0.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPDSK13/1
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.msn.com/?PC=UF01
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPDSK13/1
SearchScopes: HKU\S-1-5-21-176138252-3860332429-2761773572-1018 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = 
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
 
FireFox:
========
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll [2012-05-25] (Yahoo! Inc. -> Yahoo! Inc.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [No File]
 
Chrome: 
=======
CHR Profile: C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default [2020-07-12]
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Extension: (Slides) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-01-19]
CHR Extension: (Docs) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-19]
CHR Extension: (Google Drive) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-27]
CHR Extension: (YouTube) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-27]
CHR Extension: (Google Search) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-27]
CHR Extension: (Sheets) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-19]
CHR Extension: (Google Docs Offline) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-06-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-05]
CHR Extension: (Gmail) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-29]
CHR Extension: (Chrome Media Router) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-06-16]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [239616 2014-07-21] (Microsoft Windows Hardware Compatibility Publisher -> AMD)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-07-04] (Advanced Micro Devices, Inc.) [File not signed]
R2 HPConnectedRemote; c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe [35232 2012-07-19] (Hewlett-Packard Company -> Hewlett-Packard)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2468496 2013-11-19] (Realtek Semiconductor Corp -> Realsil Microelectronics Inc.)
R2 L4301_Solar; C:\Program Files\Logitech\SolarApp\L4301_Solar.exe [405744 2013-01-30] (Logitech -> Logitech, Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6933272 2020-06-16] (Malwarebytes Inc -> Malwarebytes)
R2 nebula; C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe [4477576 2018-06-18] (Logitech Inc -> Logitech)
R2 paltalk_update_service; C:\Program Files (x86)\Paltalk\update\pt_update_service.exe [1229688 2019-08-25] (A.V.M. SOFTWARE, INC. -> AVM Software)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation -> Microsoft Corporation)
S2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation -> Microsoft Corporation)
R2 WirelessKB850NotificationService; C:\WINDOWS\system32\WirelessKB850NotificationService.exe [176632 2018-05-14] (Microsoft Corporation -> Microsoft Corporation)
S2 HP Support Assistant Service; "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe" [X]
S2 SecurityHealthService; %SystemRoot%\system32\SecurityHealthService.exe [X]
S3 StateRepository; %SystemRoot%\system32\windows.staterepository.dll [X]
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [13209088 2014-07-21] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [626688 2014-07-21] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R1 CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink -> CyberLink)
R3 dc3d; C:\WINDOWS\System32\drivers\dc3d.sys [47616 2011-05-18] (Hardware Group Test Cert -> Microsoft Corporation)
R3 GKUPRO2D; C:\WINDOWS\system32\DRIVERS\GKUPRO2D.sys [120320 2012-11-05] (Microsoft Windows Hardware Compatibility Publisher -> Gemalto)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [216056 2020-07-11] (Malwarebytes Inc -> Malwarebytes)
R0 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248968 2020-06-16] (Malwarebytes Inc -> Malwarebytes)
R3 netr28x; C:\WINDOWS\system32\DRIVERS\netr28x.sys [2505904 2013-12-04] (Mediatek Inc. -> Ralink Technology, Corp.)
R3 usbfilter; C:\WINDOWS\System32\drivers\usbfilter.sys [56448 2012-03-30] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessKeyboardFilter; C:\WINDOWS\System32\drivers\WirelessKeyboardFilter.sys [49336 2018-03-11] (Microsoft Corporation -> Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) ===================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2020-07-11 00:09 - 2020-07-11 00:09 - 000216056 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2020-07-10 22:17 - 2020-07-10 22:17 - 000000000 ____D C:\WINDOWS\pss
2020-07-09 11:34 - 2020-07-09 11:34 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\VirtualStore
2020-07-09 10:08 - 2020-07-09 10:08 - 000000207 _____ C:\WINDOWS\tweaking.com-regbackup-HPPAVILION-Windows-8.1-(64-bit).dat
2020-07-09 10:07 - 2020-07-09 10:07 - 000000000 ____D C:\RegBackup
2020-07-09 09:50 - 2020-07-09 10:06 - 000000000 ____D C:\Users\HP Pavilion\Desktop\Tweaking.com - Windows Repair
2020-07-09 09:23 - 2020-07-09 09:23 - 037198272 _____ C:\Users\HP Pavilion\Downloads\tweaking.com_windows_repair_aio.zip
2020-07-08 08:15 - 2020-07-08 08:15 - 000000480 _____ C:\Users\HP Pavilion\Desktop\fix.reg
2020-07-07 09:25 - 2020-07-07 09:25 - 000000222 _____ C:\Users\HP Pavilion\Desktop\Warning.txt
2020-07-07 09:04 - 2020-07-07 09:04 - 000006768 _____ C:\Users\HP Pavilion\Desktop\Windows_Defender_Security_Center_Service.reg
2020-07-01 11:17 - 2020-07-01 11:17 - 000008404 _____ C:\Users\HP Pavilion\Desktop\State_Repository_Service.reg
2020-07-01 11:07 - 2020-07-01 11:07 - 000010762 _____ C:\Users\HP Pavilion\Desktop\Windows_Update.reg
2020-07-01 11:04 - 2020-07-01 11:04 - 000002203 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2020-07-01 11:04 - 2020-07-01 11:04 - 000002162 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2020-07-01 11:04 - 2020-07-01 11:04 - 000002162 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk
2020-07-01 11:03 - 2020-07-01 11:03 - 000003380 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2020-07-01 11:03 - 2020-07-01 11:03 - 000003252 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2020-07-01 10:36 - 2020-07-01 10:36 - 000007572 _____ C:\Users\HP Pavilion\Desktop\Windows_Defender_Service.reg
2020-06-30 09:11 - 2020-07-10 22:58 - 000002670 _____ C:\Users\HP Pavilion\Desktop\FSS.txt
2020-06-30 08:04 - 2020-06-30 08:04 - 000925696 _____ (Farbar) C:\Users\HP Pavilion\Desktop\FSS.exe
2020-06-30 07:35 - 2020-06-30 07:35 - 000000000 ____D C:\ProgramData\Norton
2020-06-30 06:17 - 2020-06-30 08:19 - 000001861 _____ C:\Users\HP Pavilion\Documents\DISM.txt
2020-06-27 16:59 - 2020-07-09 12:17 - 000036286 _____ C:\Users\HP Pavilion\Desktop\Addition.txt
2020-06-27 16:56 - 2020-07-12 01:47 - 000015704 _____ C:\Users\HP Pavilion\Desktop\FRST.txt
2020-06-25 16:49 - 2020-06-25 16:50 - 000003732 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onLogOn
2020-06-25 16:49 - 2020-06-25 16:50 - 000003292 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onTime
2020-06-25 16:49 - 2020-06-25 16:49 - 000006872 _____ C:\Users\HP Pavilion\Desktop\eset.txt
2020-06-25 11:53 - 2020-06-27 16:13 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\ESET
2020-06-25 11:53 - 2020-06-25 11:53 - 000000565 _____ C:\Users\HP Pavilion\Desktop\ESET Online Scanner.lnk
2020-06-25 11:51 - 2020-06-25 11:52 - 014827616 _____ (ESET spol. s r.o.) C:\Users\HP Pavilion\Desktop\esetonlinescanner.exe
2020-06-22 07:49 - 2020-06-25 11:42 - 000000000 ____D C:\AdwCleaner
2020-06-22 07:47 - 2020-06-22 07:48 - 008402608 _____ (Malwarebytes) C:\Users\HP Pavilion\Desktop\AdwCleaner.exe
2020-06-21 22:44 - 2020-07-10 22:34 - 000000565 _____ C:\Users\HP Pavilion\Desktop\Fixlog.txt
2020-06-20 11:33 - 2020-07-09 12:06 - 000000000 ____D C:\Users\HP Pavilion\Desktop\FRST-OlderVersion
2020-06-20 11:03 - 2020-06-20 11:04 - 012770472 _____ (Symantec Corporation) C:\Users\HP Pavilion\Desktop\NRnR.exe
2020-06-20 09:13 - 2020-06-20 09:13 - 000001093 _____ C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2020-06-20 09:13 - 2020-06-20 09:13 - 000001093 _____ C:\ProgramData\Desktop\Revo Uninstaller Pro.lnk
2020-06-20 09:13 - 2020-06-20 09:13 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\VS Revo Group
2020-06-20 09:13 - 2020-06-20 09:13 - 000000000 ____D C:\ProgramData\VS Revo Group
2020-06-20 09:13 - 2020-06-20 09:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2020-06-20 09:13 - 2020-06-20 09:13 - 000000000 ____D C:\Program Files\VS Revo Group
2020-06-20 09:13 - 2016-12-21 14:52 - 000040240 _____ (VS Revo Group) C:\WINDOWS\system32\Drivers\revoflt.sys
2020-06-20 09:11 - 2020-06-20 09:11 - 016926296 _____ (VS Revo Group ) C:\Users\HP Pavilion\Desktop\RevoUninProSetup.exe
2020-06-16 15:03 - 2020-07-12 01:45 - 000000000 ____D C:\FRST
2020-06-16 14:48 - 2020-07-09 12:06 - 002292736 _____ (Farbar) C:\Users\HP Pavilion\Desktop\FRST64.exe
2020-06-16 14:25 - 2020-06-16 14:26 - 000000000 ____D C:\Users\HP Pavilion\Downloads\priortoMalware
2020-06-16 12:55 - 2020-06-01 11:03 - 000835480 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2020-06-16 12:55 - 2020-06-01 11:03 - 000179608 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2020-06-16 09:43 - 2020-07-01 10:04 - 000000000 ____D C:\Users\HP Pavilion\AppData\LocalLow\IGDump
2020-06-16 09:42 - 2020-06-16 09:42 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\mbam
2020-06-16 09:41 - 2020-06-16 09:41 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2020-06-16 09:41 - 2020-06-16 09:41 - 000001976 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2020-06-16 09:41 - 2020-06-16 09:41 - 000001964 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2020-06-16 09:41 - 2020-06-16 09:41 - 000001964 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2020-06-16 09:41 - 2020-06-16 09:41 - 000000000 ____D C:\ProgramData\Malwarebytes
2020-06-16 09:40 - 2020-06-16 09:40 - 000000000 ____D C:\Program Files\Malwarebytes
2020-06-16 09:40 - 2020-06-16 09:40 - 000000000 ____D C:\Malwarebytes
2020-06-16 09:38 - 2020-06-16 09:38 - 000000000 ____D C:\Users\HP Pavilion\AppData\Roaming\Logitech
2020-06-16 09:38 - 2020-06-16 09:38 - 000000000 ____D C:\Users\HP Pavilion\AppData\Roaming\Logishrd
2020-06-16 09:06 - 2020-06-16 09:06 - 000000000 ____D C:\Program Files\KeyboardNotification
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2020-07-11 22:28 - 2016-02-19 13:55 - 000003814 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{2B2239C5-296B-46AF-9192-8557E01C177E}
2020-07-10 23:01 - 2014-09-24 00:15 - 000893332 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-07-10 23:01 - 2013-08-22 06:36 - 000000000 ____D C:\WINDOWS\Inf
2020-07-10 22:59 - 2012-09-11 06:21 - 000000000 ____D C:\ProgramData\Hewlett-Packard
2020-07-10 22:49 - 2013-08-22 07:45 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-07-10 21:57 - 2016-01-25 16:06 - 000000000 ____D C:\Users\HP Pavilion
2020-07-10 21:14 - 2013-08-22 06:25 - 000524288 ___SH C:\WINDOWS\system32\config\BBI
2020-07-10 07:26 - 2013-08-22 08:36 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-07-10 07:16 - 2012-07-26 00:59 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-07-09 12:23 - 2016-01-27 10:12 - 000003598 _____ C:\WINDOWS\system32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-176138252-3860332429-2761773572-1018
2020-07-09 12:11 - 2016-01-25 16:07 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\Packages
2020-07-09 11:26 - 2013-08-22 07:44 - 000346744 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-07-09 11:13 - 2013-08-22 06:25 - 000000128 _____ C:\WINDOWS\win.ini
2020-07-09 11:05 - 2014-11-01 10:23 - 000006636 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2020-07-08 08:17 - 2015-09-08 17:28 - 000253286 _____ C:\WINDOWS\ntbtlog.txt
2020-07-01 09:49 - 2017-04-06 19:56 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\CrashDumps
2020-06-29 21:57 - 2013-11-14 19:49 - 000000000 ____D C:\Program Files (x86)\Paltalk Messenger
2020-06-25 11:43 - 2012-09-11 06:18 - 000000000 ____D C:\Program Files (x86)\Hewlett-Packard
2020-06-25 11:43 - 2012-08-16 20:14 - 000000000 _RSHD C:\hp
2020-06-25 11:42 - 2016-01-25 16:08 - 000000000 ____D C:\Users\HP Pavilion\AppData\Roaming\Hewlett-Packard
2020-06-25 11:42 - 2013-11-05 17:57 - 000000000 ____D C:\Users\Joanne Endevoets\AppData\Local\Hewlett-Packard
2020-06-25 11:42 - 2013-11-05 15:11 - 000000000 ____D C:\Users\Joanne Endevoets\AppData\Roaming\Hewlett-Packard
2020-06-25 11:42 - 2012-09-11 06:33 - 000000000 ____D C:\Program Files (x86)\CyberLink
2020-06-25 06:35 - 2013-11-24 22:54 - 000002204 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-06-25 06:35 - 2013-11-24 22:54 - 000002163 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-06-25 06:35 - 2013-11-24 22:54 - 000002163 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-06-21 22:46 - 2018-11-13 17:12 - 000000000 ____D C:\WINDOWS\system32\Tasks\Remediation
2020-06-21 22:46 - 2017-04-13 16:40 - 000000000 ____D C:\Program Files\Common Files\AV
2020-06-21 22:46 - 2013-08-22 06:25 - 000000027 _____ C:\WINDOWS\system32\Drivers\etc\hosts_bak_31
2020-06-21 22:37 - 2013-08-22 08:36 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2020-06-16 13:21 - 2012-07-26 01:12 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2020-06-16 12:22 - 2013-08-22 08:36 - 000000000 ___RD C:\WINDOWS\ToastData
2020-06-16 11:18 - 2014-11-01 10:29 - 000000000 ____D C:\Users\Joanne Endevoets
2020-06-16 11:15 - 2016-01-26 11:34 - 000000000 ____D C:\ProgramData\iolo
2020-06-16 11:15 - 2016-01-26 11:31 - 000000000 ____D C:\Program Files (x86)\iolo
2020-06-16 09:41 - 2016-01-25 16:25 - 000248968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2020-06-16 09:39 - 2020-02-12 18:23 - 000000000 ____D C:\Program Files\Logitech
2020-06-16 09:39 - 2014-11-01 10:19 - 000000000 ____D C:\Program Files\Common Files\logishrd
2020-06-16 09:39 - 2014-02-20 18:51 - 000000000 ____D C:\ProgramData\LogiShrd
2020-06-16 09:39 - 2014-02-20 18:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
 
==================== Files in the root of some directories ========
 
2018-06-09 22:26 - 2020-06-10 14:48 - 000000175 _____ () C:\Users\HP Pavilion\AppData\Roaming\WB.CFG
2016-01-27 10:21 - 2016-01-27 10:21 - 000007601 _____ () C:\Users\HP Pavilion\AppData\Local\Resmon.ResmonCfg
2018-01-30 13:25 - 2019-04-16 12:51 - 000001376 _____ () C:\Users\HP Pavilion\AppData\Local\Temptoast_image.png
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
 
LastRegBack: 2016-05-28 12:50
==================== End of FRST.txt ========================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-07-2020 01
Ran by HP Pavilion (12-07-2020 01:49:07)
Running from C:\Users\HP Pavilion\Desktop
Windows 8.1 (Update) (X64) (2014-11-01 18:42:41)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-176138252-3860332429-2761773572-500 - Administrator - Disabled)
Guest (S-1-5-21-176138252-3860332429-2761773572-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-176138252-3860332429-2761773572-1003 - Limited - Enabled)
HP Pavilion (S-1-5-21-176138252-3860332429-2761773572-1018 - Administrator - Enabled) => C:\Users\HP Pavilion
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
AMD Catalyst Install Manager (HKLM\...\{5F769CF4-5263-4C7B-AEB2-C06A73AE4428}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CameraHelperMsi (HKLM-x32\...\{15634701-BACE-4449-8B25-1567DA8C9FD3}) (Version: 13.51.815.0 - Logitech) Hidden
Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD)
CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.1.1916 - CyberLink Corp.)
CyberLink PhotoDirector (HKLM-x32\...\InstallShield_{4862344A-A39C-4897-ACD4-A1BED5163C5A}) (Version: 2.0.1.3109 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.1.1925 - CyberLink Corp.)
Energy Star (HKLM\...\{0FA995CC-C849-4755-B14B-5404CC75DC24}) (Version: 1.0.8 - Hewlett-Packard)
erLT (HKLM-x32\...\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}) (Version: 1.20.138.34 - Logitech, Inc.) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 83.0.4103.116 - Google LLC)
Google Toolbar for Internet Explorer (HKLM-x32\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
HP Connected Music (Meridian - installer) (HKLM-x32\...\StartHPConnectedMusic) (Version: v1.0 - Meridian Audio Ltd)
HP Connected Remote (HKLM-x32\...\{F243A34B-AB7F-4065-B770-B85B767C247C}) (Version: 1.0.1202 - Hewlett-Packard)
HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.3.0 - WildTangent)
HP Quick Start (HKLM-x32\...\{574F0207-8E98-46CD-8F79-318348C98C46}) (Version: 1.0.4660.30220 - Hewlett-Packard)
Logitech Camera Settings (HKLM-x32\...\LogiUCDPP) (Version: 2.5.17.0 - Logitech Europe S.A.)
Logitech Solar App 1.10 (HKLM\...\SolarApp) (Version: 1.10.3 - Logitech)
Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.80 - Logitech Inc.)
Malwarebytes version 4.1.0.56 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.1.0.56 - Malwarebytes)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 83.0.478.50 - Microsoft Corporation)
Microsoft Edge Update (HKLM-x32\...\Microsoft Edge Update) (Version: 1.3.129.37 - )
Microsoft Office (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.6120.5004 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Paltalk (HKLM-x32\...\Paltalk) (Version:  - )
Ralink RT5390R 802.11bgn Wi-Fi Adapter (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 5.0.0.0 - Ralink)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.31.423.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6777 - Realtek Semiconductor Corp.)
Realtek PCIE Card Reader (HKLM-x32\...\{0D61A55C-3ADC-409F-BF5B-A1766D1F5944}) (Version: 6.2.9200.28137 - Realtek Semiconductor Corp.)
Recovery Manager (HKLM-x32\...\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.5.0.5530 - CyberLink Corp.) Hidden
Revo Uninstaller Pro 4.3.3 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 4.3.3 - VS Revo Group, Ltd.)
Skype™ 7.38 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.38.101 - Skype Technologies S.A.)
swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version:  - Yahoo! Inc.)
 
Packages:
=========
eBay -> C:\Program Files\WindowsApps\eBayInc.eBay_1.6.0.34_neutral__1618n3s9xq8tw [2014-11-07] (eBay, Inc)
Games -> C:\Program Files\WindowsApps\Microsoft.XboxLIVEGames_2.0.139.0_x64__8wekyb3d8bbwe [2014-09-24] (Microsoft Corporation) [MS Ad]
Getting Started with Windows 8 -> C:\Program Files\WindowsApps\AD2F1837.GettingStartedwithWindows8_1.6.0.0_neutral__v10z8vjag6ke6 [2015-03-03] (Hewlett-Packard Company)
HP Registration -> C:\Program Files\WindowsApps\AD2F1837.HPRegistration_1.2.1.166_neutral__v10z8vjag6ke6 [2014-11-27] (Hewlett-Packard Company)
HP+ -> C:\Program Files\WindowsApps\AD2F1837.HP_1.2.0.93_neutral__v10z8vjag6ke6 [2014-11-02] (Hewlett-Packard Company)
iHeartRadio -> C:\Program Files\WindowsApps\ClearChannelRadioDigital.iHeartRadio_4.5.1.0_x64__a76a11dkgb644 [2016-04-15] (iHeartMedia.)
Kindle -> C:\Program Files\WindowsApps\AMZNMobileLLC.KindleforWindows8_2.1.0.2_neutral__stfe6vwa9jnbp [2015-06-27] (AMZN Mobile LLC)
Microsoft Mahjong -> C:\Program Files\WindowsApps\Microsoft.MicrosoftMahjong_2.10.1812.2002_x86__8wekyb3d8bbwe [2019-02-02] (Microsoft Studios) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_2.11.1807.1002_x86__8wekyb3d8bbwe [2018-07-30] (Microsoft Studios) [MS Ad]
MSN Food & Drink -> C:\Program Files\WindowsApps\Microsoft.BingFoodAndDrink_3.0.4.336_x64__8wekyb3d8bbwe [2015-07-13] (Microsoft Corporation) [MS Ad]
MSN Health & Fitness -> C:\Program Files\WindowsApps\Microsoft.BingHealthAndFitness_3.0.4.336_x64__8wekyb3d8bbwe [2015-07-13] (Microsoft Corporation) [MS Ad]
MSN Money -> C:\Program Files\WindowsApps\Microsoft.BingFinance_3.0.4.344_x64__8wekyb3d8bbwe [2016-04-30] (Microsoft Corporation) [MS Ad]
MSN News -> C:\Program Files\WindowsApps\Microsoft.BingNews_3.0.4.344_x64__8wekyb3d8bbwe [2016-04-30] (Microsoft Corporation) [MS Ad]
MSN Sports -> C:\Program Files\WindowsApps\Microsoft.BingSports_3.0.4.345_x64__8wekyb3d8bbwe [2016-04-30] (Microsoft Corporation) [MS Ad]
MSN Travel -> C:\Program Files\WindowsApps\Microsoft.BingTravel_3.0.4.336_x64__8wekyb3d8bbwe [2015-07-13] (Microsoft Corporation) [MS Ad]
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_3.0.4.350_x64__8wekyb3d8bbwe [2016-11-25] (Microsoft Corporation) [MS Ad]
Music -> C:\Program Files\WindowsApps\Microsoft.ZuneMusic_2.6.672.0_x64__8wekyb3d8bbwe [2015-03-14] (Microsoft Corporation) [MS Ad]
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_2.22.0.39_x64__mcm4njqhnhss8 [2018-11-02] (Netflix, Inc.)
Norton Studio -> C:\Program Files\WindowsApps\SymantecCorporation.NortonStudio_1.5.0.41_x86__v68kp9n051hdp [2014-11-02] (Symantec Corporation)
Skype -> C:\Program Files\WindowsApps\Microsoft.SkypeApp_3.1.0.1016_x86__kzf8qxf38zg5c [2015-06-27] (Skype) [MS Ad]
Snapfish -> C:\Program Files\WindowsApps\AD2F1837.HPConnectedPhotopoweredbySnapfish_5.5.0.8_x86__v10z8vjag6ke6 [2016-05-03] (HP Inc.)
Video -> C:\Program Files\WindowsApps\Microsoft.ZuneVideo_2.6.446.0_x64__8wekyb3d8bbwe [2015-11-07] (Microsoft Corporation) [MS Ad]
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
ShellIconOverlayIdentifiers: [  OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} =>  -> No File
ShellIconOverlayIdentifiers: [  OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} =>  -> No File
ShellIconOverlayIdentifiers: [  OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} =>  -> No File
ShellIconOverlayIdentifiers-x32: [  OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} =>  -> No File
ShellIconOverlayIdentifiers-x32: [  OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} =>  -> No File
ShellIconOverlayIdentifiers-x32: [  OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} =>  -> No File
ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} =>  -> No File
ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} =>  -> No File
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-06-16] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} =>  -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2014-07-04] (Advanced Micro Devices, Inc.) [File not signed]
ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} =>  -> No File
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-06-16] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers6: [RUShellExt] -> {2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RUExt.dll [2019-03-29] (VS Revo Group Ltd. -> VS Revo Group)
 
==================== Codecs (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Drivers32: [vidc.i420] => C:\WINDOWS\system32\lvcod64.dll [175392 2012-10-26] (Logitech, Inc. -> Logitech Inc.)
HKLM\...\Drivers32: [vidc.i420] => C:\Windows\SysWOW64\lvcodec2.dll [305000 2012-10-26] (Logitech, Inc. -> Logitech Inc.)
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
Shortcut: C:\Users\HP Pavilion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Paltalk\Remove settings.lnk -> C:\Program Files (x86)\Paltalk\ng_clean_settings.bat (No File)
 
==================== Loaded Modules (Whitelisted) =============
 
2014-07-04 21:33 - 2014-07-04 21:33 - 000127488 _____ () [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
 
==================== Alternate Data Streams (Whitelisted) ========
 
==================== Safe Mode (Whitelisted) ==================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BFE => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\camsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dps => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lfsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MpsSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\semgrsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SharedAccess => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\shellhwdetection => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TokenBroker => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TweakingRemoveSafeBoot => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WSService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\camsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dps => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\lfsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SamSs => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\semgrsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\shellhwdetection => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SntpService => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv2 => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srvnet => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TokenBroker => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TweakingRemoveSafeBoot => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WSService => ""="Service"
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer trusted/restricted ==========
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 06:25 - 2020-07-09 11:14 - 000000855 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1       localhost
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> c:\Program Files (x86)\AMD APP\bin\x86_64;c:\Program Files (x86)\AMD APP\bin\x86;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files (x86)\Skype\Phone\
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\Control Panel\Desktop\\Wallpaper -> C:\Users\HP Pavilion\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(If an entry is included in the fixlist, it will be removed.)
 
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\StartupApproved\StartupFolder: => "PalTalk.lnk"
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\StartupApproved\Run: => "Chromium"
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_803D2E04332962AFAC352F92C208E650"
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\StartupApproved\Run: => "Paltalk"
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\StartupApproved\Run: => "Skype"
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [UDP Query User{E442E7B3-7B13-4BDA-B26D-0F28D846A538}C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe] => (Block) C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe => No File
FirewallRules: [TCP Query User{EE175E9E-556D-4C29-8E52-992A95F9A6CE}C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe] => (Block) C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe => No File
FirewallRules: [{1DA563F9-8F28-4085-9D23-2E0A03D8EC26}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE (CyberLink Corp. -> CyberLink Corp.)
FirewallRules: [UDP Query User{D48F9F75-6B2E-4094-9051-3EEF62A29FE1}C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe => No File
FirewallRules: [TCP Query User{C668418F-047A-4B32-84B0-E819D88A70E0}C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe => No File
FirewallRules: [{14852894-E754-4D88-B410-E365CBD58788}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc. -> Yahoo! Inc.)
FirewallRules: [{63569EEC-DC52-4EED-8DB2-E83112C70753}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc. -> Yahoo! Inc.)
FirewallRules: [UDP Query User{0326EAFC-8940-43FE-9164-E4A21A402C98}C:\program files (x86)\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk.exe => No File
FirewallRules: [TCP Query User{5A430BC0-D3BD-4121-8016-8EA23C276F90}C:\program files (x86)\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk.exe => No File
FirewallRules: [UDP Query User{29A929DE-9870-4957-A906-14B5642012FB}C:\windows\syswow64\msiexec.exe] => (Allow) C:\windows\syswow64\msiexec.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [TCP Query User{7DE345DD-8CFC-418A-B491-BB60FC69B658}C:\windows\syswow64\msiexec.exe] => (Allow) C:\windows\syswow64\msiexec.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{87010DB7-297E-435E-AB81-7C0757767CAC}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE (CyberLink -> CyberLink Corp.)
FirewallRules: [{B6D693E7-D84F-46D9-A816-DE973D437AF7}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{261379EE-DACD-4B61-9F8A-BF6F93F7DF35}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{27F4866A-85A9-4CBE-B396-6FD538FC22F3}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{5F0B061F-74AB-46A7-AA55-5DA60E86BD74}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{C19F3984-3DF2-4505-B50E-E2623874F167}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe => No File
FirewallRules: [TCP Query User{AC84FE58-503E-4351-8C1D-1B3550F0000F}C:\program files (x86)\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk.exe => No File
FirewallRules: [UDP Query User{A8FCFB61-3A9B-49D7-B998-60FB27AE20BB}C:\program files (x86)\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk.exe => No File
FirewallRules: [TCP Query User{B0241114-BEDC-46F5-BBAF-324BF2D6F0B4}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [UDP Query User{40E28967-F448-403E-B197-C27ECC80F3A9}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{FBA5429D-8BA2-4085-BDD5-F7E2BDB1C1B2}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{FABCC09D-24F4-49C0-8CD8-05798DCFEB32}] => (Allow) LPort=53000
FirewallRules: [{26350D1D-A0AD-46A3-8C88-07A46D70D51E}] => (Allow) LPort=52000
 
==================== Restore Points =========================
 
14-03-2020 14:22:36 Windows Update
17-04-2020 11:03:33 Windows Update
15-05-2020 11:36:32 Windows Update
16-06-2020 11:49:07 Windows Update
20-06-2020 08:46:08 Removed Java 7 Update 45
20-06-2020 09:21:59 Revo Uninstaller Pro's restore point - Sophos Anti-Virus
20-06-2020 09:24:02 Removed Sophos Anti-Virus
20-06-2020 10:02:29 Revo Uninstaller Pro's restore point - Sophos AutoUpdate
20-06-2020 10:16:28 Revo Uninstaller Pro's restore point - Sophos Network Threat Protection
20-06-2020 10:33:44 Revo Uninstaller Pro's restore point - Sophos AutoUpdate
20-06-2020 10:42:48 Revo Uninstaller Pro's restore point - Sophos Remote Management System
20-06-2020 10:46:21 Removed Sophos Remote Management System
20-06-2020 10:51:41 Revo Uninstaller Pro's restore point - Sophos System Protection
20-06-2020 10:52:19 Removed Sophos System Protection
21-06-2020 22:44:51 Restore Point Created by FRST
25-06-2020 11:41:37 AdwCleaner_BeforeCleaning_25/06/2020_11:41:29
27-06-2020 15:26:31 Windows Live Essentials
27-06-2020 15:27:34 WLSetup
01-07-2020 10:39:36 Windows Update
 
==================== Faulty Device Manager Devices ============
 
Name: HP High Definition 1MP Webcam
Description: USB Video Device
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Microsoft
Service: usbvideo
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (07/10/2020 10:19:17 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: MicrosoftEdgeUpdate.exe, version: 1.3.129.37, time stamp: 0x5edee5c2
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0xb7faffa0
Faulting process id: 0xf7c
Faulting application start time: 0x01d65742d2aa54e2
Faulting application path: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
Faulting module path: unknown
Report Id: 10fb6489-c336-11ea-bfac-4c72b9b3dc92
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (07/10/2020 09:10:40 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: HPPavilion)
Description: Activation of app windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (07/10/2020 09:10:25 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2486) (User: HPPavilion)
Description: App windows.immersivecontrolpanel_6.2.0.0_neutral_neutral_cw5n1h2txyewy+microsoft.windows.immersivecontrolpanel did not launch within its allotted time.
 
Error: (07/09/2020 08:50:43 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1937
 
Error: (07/09/2020 08:50:43 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1937
 
Error: (07/09/2020 08:50:43 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (07/09/2020 11:23:30 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3009) (User: HPPavilion)
Description: Installing the performance counter strings for service .NET CLR Data () failed. The first DWORD in the Data section contains the error code.
 
Error: (07/09/2020 11:23:30 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3009) (User: HPPavilion)
Description: Installing the performance counter strings for service .NET CLR Networking () failed. The first DWORD in the Data section contains the error code.
 
 
System errors:
=============
Error: (07/11/2020 10:34:37 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Defender Service service failed to start due to the following error: 
Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Error: (07/10/2020 10:59:12 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The HP Support Assistant Service service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (07/10/2020 10:57:13 PM) (Source: DCOM) (EventID: 10016) (User: HPPavilion)
Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{7022A3B3-D004-4F52-AF11-E9E987FEE25F}
 and APPID 
{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}
 to the user HPPavilion\HP Pavilion SID (S-1-5-21-176138252-3860332429-2761773572-1018) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/10/2020 10:57:13 PM) (Source: DCOM) (EventID: 10016) (User: HPPavilion)
Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{7022A3B3-D004-4F52-AF11-E9E987FEE25F}
 and APPID 
{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}
 to the user HPPavilion\HP Pavilion SID (S-1-5-21-176138252-3860332429-2761773572-1018) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/10/2020 10:57:13 PM) (Source: DCOM) (EventID: 10016) (User: HPPavilion)
Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{7022A3B3-D004-4F52-AF11-E9E987FEE25F}
 and APPID 
{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}
 to the user HPPavilion\HP Pavilion SID (S-1-5-21-176138252-3860332429-2761773572-1018) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/10/2020 10:57:04 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Defender Service service failed to start due to the following error: 
Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Error: (07/10/2020 10:53:11 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: The server {DDCFD26B-FEED-44CD-B71D-79487D2E5E5A} did not register with DCOM within the required timeout.
 
Error: (07/10/2020 10:51:11 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: The server {DDCFD26B-FEED-44CD-B71D-79487D2E5E5A} did not register with DCOM within the required timeout.
 
 
Windows Defender:
===================================
Date: 2014-02-04 17:15:55.337
Description: 
Windows Defender scan has been stopped before completion.
Scan ID: {9460D5A7-484E-4AD5-A8F8-E2957D93B006}
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2018-05-01 12:46:46.126
Description: 
Windows Defender has encountered an error trying to update signatures.
New Signature Version: 1.267.643.0
Previous Signature Version: 1.261.1097.0
Update Source: User
Signature Type: AntiSpyware
Update Type: Full
Current Engine Version: 1.1.14800.3
Previous Engine Version: 1.1.14500.5
Error code: 0x80509004
Error description: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support. 
 
Date: 2018-05-01 12:46:46.126
Description: 
Windows Defender has encountered an error trying to update signatures.
New Signature Version: 1.267.643.0
Previous Signature Version: 1.261.1097.0
Update Source: User
Signature Type: AntiVirus
Update Type: Full
Current Engine Version: 1.1.14800.3
Previous Engine Version: 1.1.14500.5
Error code: 0x80509004
Error description: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support. 
 
Date: 2018-05-01 12:46:46.125
Description: 
Windows Defender has encountered an error trying to update the engine.
New Engine Version: 1.1.14800.3
Previous Engine Version: 1.1.14500.5
Error Code: 0x80509004
Error description: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support. 
 
Date: 2018-02-12 15:30:23.776
Description: 
Windows Defender has encountered an error trying to update signatures.
New Signature Version: 
Previous Signature Version: 118.2.0.0
Update Source: Microsoft Malware Protection Center
Signature Type: Network Inspection System
Update Type: Full
Current Engine Version: 
Previous Engine Version: 2.1.14202.0
Error code: 0x80070652
Error description: Another installation is already in progress. Complete that installation before proceeding with this install. 
 
Date: 2018-02-12 15:30:22.001
Description: 
Windows Defender has encountered an error trying to update the engine.
New Engine Version: 
Previous Engine Version: 2.1.14202.0
Error Code: 0x80070666
Error description: Another version of this product is already installed. Installation of this version cannot continue. To configure or remove the existing version of this product, use Add/Remove Programs on the Control Panel. 
 
CodeIntegrity:
===================================
 
Date: 2020-07-11 22:34:37.596
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2020-07-10 22:57:04.727
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2020-07-10 22:43:42.779
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2020-07-10 22:29:16.566
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2020-07-10 22:16:19.429
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2020-07-10 21:49:26.300
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2020-07-10 21:24:41.336
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2020-07-10 21:13:14.825
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
==================== Memory info =========================== 
 
BIOS: AMI 8.06 09/07/2012
Motherboard: PEGATRON CORPORATION 2AF0
Processor: AMD E1-1200 APU with Radeon™ HD Graphics
Percentage of memory in use: 41%
Total physical RAM: 3665.86 MB
Available physical RAM: 2150.44 MB
Total Virtual: 4193.86 MB
Available Virtual: 2247.72 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:443.06 GB) (Free:362.06 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (Recovery Image) (Fixed) (Total:19.78 GB) (Free:2.47 GB) NTFS ==>[system with boot components (obtained from drive)]
 
\\?\Volume{d1de863d-cf84-4d64-8ee1-9cebae5d4872}\ () (Fixed) (Total:1 GB) (Free:0.66 GB) NTFS
\\?\Volume{02f74654-436d-45c5-a86d-fd54f1779603}\ (Windows RE tools) (Fixed) (Total:1 GB) (Free:0.65 GB) NTFS
\\?\Volume{6ec74e69-4ea4-4586-9114-4ec0583318ed}\ () (Fixed) (Total:0.44 GB) (Free:0.18 GB) NTFS
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 4A1F8D9C)
 
Partition: GPT.
 
==================== End of Addition.txt =======================

  • 0

#52
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 2,665 posts

Hi, Joseph.

 

I will be back to you as soon as possible, with a new set of instructions.


  • 0

#53
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 2,665 posts

Hi, Joseph.

It seems that the issues regarding the Windows Defender and other services can't be resolved with the way we tried so far. We believe that right now an in-place upgrade would help, upgrading and cleaning the system, resolving specific problems with it. This means that we are going to upgrade the operating system from 8.1 to 10. I would recommend that at the end of the procedure anyway, but it seems that it has to be now. Have in mind that it is important always to keep current with the latest security fixes from Microsoft. This can patch many of the security holes through which attackers can infect your computer.

If you are OK with that, please proceed to the following:

A. In-place upgrade

1. Go to this Microsoft page and under the title Create Windows 10 installation media press on Download tool now.
2. Save the tool on your Desktop and double click to run it.
3. On the License terms page, if you accept the license terms, select Accept.
4. On the What do you want to do page, select Upgrade this PC now, and then select Next.
6. Follow the instructions and select Keep personal files and apps, when you are asked to.
7. It might take a couple of hours, depending on your wifi speed connection, to install Windows 10. Your PC will restart a few times. Make sure you don’t turn off your PC.
8. After downloading and installing, the tool will walk you through how to set up Windows 10 on your PC.

When the upgrade is finished, please report here again, providing fresh FRST logs:

B. Fresh FRST logs

  • Double-click on the FRST icon to run it, as you did before. When the tool opens click Yes to disclaimer.
  • Press Scan button and wait for a while.
  • The scanner will produced two logs on your Desktop: FRST.txt and Addition.txt.
  • Please copy and paste the content of these two logs in your next reply.

  • 0

#54
whittakerjr

whittakerjr

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts

Upgraded.

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-07-2020 01
Ran by HP Pavilion (administrator) on HPPAVILION (Hewlett-Packard 20-b010) (15-07-2020 06:50:51)
Running from C:\Users\HP Pavilion\Desktop
Loaded Profiles: HP Pavilion
Platform: Windows 10 Home Version 2004 19041.388 (X64) Language: English (United States)
Default browser: IE
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(A.V.M. SOFTWARE, INC. -> AVM Software) C:\Program Files (x86)\Paltalk\update\pt_update_service.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Advanced Micro Devices, Inc.) [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Andrea Electronics -> Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <9>
(Google LLC -> Google) C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\SwReporter\83.238.200\software_reporter_tool.exe <4>
(Logitech -> Logitech, Inc.) C:\Program Files\Logitech\SolarApp\L4301_Solar.exe
(Logitech Inc -> Logitech) C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\HP Pavilion\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12007.1001.2.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\ByteCodeGenerator.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2007.4-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2007.4-0\NisSrv.exe
(Realtek Semiconductor Corp -> Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6844560 2013-11-19] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-21] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27784672 2017-06-27] (Skype Software Sarl -> Skype Technologies S.A.)
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\Run: [Paltalk] => C:\Program Files (x86)\Paltalk\PALTALK.exe [27532728 2020-05-19] (A.V.M. SOFTWARE, INC. -> AVM Software)
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\HP Pavilion\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\HP Pavilion\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\RunOnce: [Uninstall 19.043.0304.0013\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\HP Pavilion\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\amd64"
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\RunOnce: [Uninstall 19.043.0304.0013] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\HP Pavilion\AppData\Local\Microsoft\OneDrive\19.043.0304.0013"
HKLM\...\Print\Monitors\HP 7112 Status Monitor: C:\WINDOWS\system32\hpinksts7112LM.dll [328704 2014-03-03] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Co.)
HKLM\...\Print\Monitors\HP Universal Port Monitor: C:\WINDOWS\system32\hpbprtmon.dll [355840 2012-07-24] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\83.0.4103.116\Installer\chrmstp.exe [2020-06-25] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.81\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
 
==================== Scheduled Tasks (Whitelisted) ============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0DC0DAD2-F84F-429D-B085-411AE7CDE2D5} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4F47-879B-29A80C355D61}
Task: {10AD99B1-9990-4C73-B8E9-E6EA376A9E3D} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload => {EBF00FCB-0769-4B81-9BEC-6C05514111AA}
Task: {145EF7F4-ECD0-4CD6-B44D-E92EFEB7BDDB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {287EB61E-849D-44F1-BF41-56B2A8081F95} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDFE067B1}
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\WINDOWS\System32\AutoWorkplace.exe
Task: {426C84D3-5DF0-4CC8-9486-251CC5F877B1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe
Task: {5A3FB241-0B11-4EA5-BC66-0D9F1B406040} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\BthSQM => {C8367320-6F85-11E0-A1F0-0800200C9A66} C:\WINDOWS\System32\BthTelemetry.dll [30208 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Task: {69A9BED9-2695-4FA6-ABEF-DB9C7F40DC6B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task => {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Task: {7604A2BD-B1C7-4591-A0BB-AFA960B6026A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe
Task: {7B857988-3067-4E13-8891-998F430972F7} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316}
Task: {8447F5E5-2A40-44ED-869F-2FD08F7AF3E9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {849B52C8-C3E4-4267-B904-989667E7243C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.4-0\MpCmdRun.exe [516768 2020-07-15] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task => {1B1F472E-3221-4826-97DB-2C2324D389AE}
Task: {878F7985-E9A4-4DF2-8C57-79AE45F39B8D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.4-0\MpCmdRun.exe [516768 2020-07-15] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {8CA68387-B3CC-41B5-88D5-240C7A3E7715} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_CN49ADX0R9_backup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe
Task: {9768ABD2-EB67-498E-A669-15A536AF817A} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969}
Task: {BE50A7CB-4761-4560-99C3-95A759AD3012} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.4-0\MpCmdRun.exe [516768 2020-07-15] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C2D92648-7FFA-4B4E-BE32-ABCB7F598804} - System32\Tasks\{A7827154-50C7-4867-ADFD-1E8E30D0C7A2} => "c:\program files\internet explorer\iexplore.exe" hxxps://ui.skype.com/ui/0/7.33.0.105/en/abandoninstall?source=lightinstaller&page=tsMain
Task: {C415FE0E-DDCB-44E0-A459-B9164B72424B} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43DA-BFD7-FBEEA2180A1E}
Task: {CA019DD0-822D-49E1-A2FF-1991CECD8F38} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {CE2DE968-E342-40D7-9566-427D45E4A886} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40B4-8963-D3C761B18371}
Task: {DCB2E700-2511-45D2-B218-AE8BA4967108} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP SoftPaq Installer => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF_Tasks.exe
Task: {F896594B-E18E-4017-85DF-369B4D6F995D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.4-0\MpCmdRun.exe [516768 2020-07-15] (Microsoft Windows Publisher -> Microsoft Corporation)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{29B5CF79-3278-41A1-86F5-B3673D2C956F}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{CBC4812E-DD0B-4C8B-9F7F-46C2962A294B}: [DhcpNameServer] 192.168.0.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPDSK13/1
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.msn.com/?PC=UF01
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPDSK13/1
SearchScopes: HKU\S-1-5-21-176138252-3860332429-2761773572-1018 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = 
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
 
FireFox:
========
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll [2012-05-25] (Yahoo! Inc. -> Yahoo! Inc.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [No File]
 
Chrome: 
=======
CHR Profile: C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default [2020-07-15]
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Extension: (Slides) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-01-19]
CHR Extension: (Docs) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-19]
CHR Extension: (Google Drive) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-27]
CHR Extension: (YouTube) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-27]
CHR Extension: (Google Search) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-27]
CHR Extension: (Sheets) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-19]
CHR Extension: (Google Docs Offline) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-06-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-05]
CHR Extension: (Gmail) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-29]
CHR Extension: (Chrome Media Router) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-06-16]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [255472 2015-10-21] (Microsoft Windows Hardware Compatibility Publisher -> AMD)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-07-04] (Advanced Micro Devices, Inc.) [File not signed]
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2468496 2013-11-19] (Realtek Semiconductor Corp -> Realsil Microelectronics Inc.)
R2 L4301_Solar; C:\Program Files\Logitech\SolarApp\L4301_Solar.exe [405744 2013-01-30] (Logitech -> Logitech, Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6933272 2020-06-16] (Malwarebytes Inc -> Malwarebytes)
R2 nebula; C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe [4477576 2018-06-18] (Logitech Inc -> Logitech)
R2 paltalk_update_service; C:\Program Files (x86)\Paltalk\update\pt_update_service.exe [1229688 2019-08-25] (A.V.M. SOFTWARE, INC. -> AVM Software)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.4-0\NisSrv.exe [2169568 2020-07-15] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.4-0\MsMpEng.exe [128376 2020-07-15] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WirelessKB850NotificationService; C:\WINDOWS\system32\WirelessKB850NotificationService.exe [176632 2018-05-14] (Microsoft Corporation -> Microsoft Corporation)
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [21648880 2015-10-21] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [674288 2015-10-21] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R1 CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink -> CyberLink)
R3 dc3d; C:\WINDOWS\System32\drivers\dc3d.sys [47616 2011-05-18] (Hardware Group Test Cert -> Microsoft Corporation)
R3 GKUPRO2D; C:\WINDOWS\System32\drivers\GKUPRO2D.sys [120320 2012-11-05] (Microsoft Windows Hardware Compatibility Publisher -> Gemalto)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [216056 2020-07-15] (Malwarebytes Inc -> Malwarebytes)
R0 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248968 2020-06-16] (Malwarebytes Inc -> Malwarebytes)
R3 netr28x; C:\WINDOWS\System32\drivers\netr28x.sys [2537984 2019-12-07] (Microsoft Windows -> MediaTek Inc.)
R3 usbfilter; C:\WINDOWS\System32\drivers\usbfilter.sys [56448 2012-03-30] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [78216 2020-07-15] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [430312 2020-07-15] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [98536 2020-07-15] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessKeyboardFilter; C:\WINDOWS\System32\drivers\WirelessKeyboardFilter.sys [49336 2018-03-11] (Microsoft Corporation -> Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) ===================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2020-07-15 06:50 - 2020-07-15 06:55 - 000018312 _____ C:\Users\HP Pavilion\Desktop\FRST.txt
2020-07-15 06:43 - 2020-07-15 06:45 - 000003380 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-176138252-3860332429-2761773572-1018
2020-07-15 06:41 - 2020-07-15 06:41 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\Comms
2020-07-15 06:38 - 2020-07-15 06:38 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2020-07-15 06:38 - 2020-07-15 06:38 - 000000000 ____D C:\ProgramData\ATI
2020-07-15 02:32 - 2020-07-15 02:32 - 000216056 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2020-07-15 00:03 - 2020-07-14 23:47 - 000000000 ____D C:\Windows.old
2020-07-14 23:52 - 2020-07-14 23:52 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\Publishers
2020-07-14 23:50 - 2020-07-15 06:46 - 000000000 ____D C:\ProgramData\Packages
2020-07-14 23:50 - 2020-07-14 23:50 - 000000000 ___RD C:\Users\HP Pavilion\3D Objects
2020-07-14 23:48 - 2020-07-14 23:50 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\ConnectedDevicesPlatform
2020-07-14 23:48 - 2020-07-14 23:48 - 000000020 ___SH C:\Users\HP Pavilion\ntuser.ini
2020-07-14 23:45 - 2020-07-15 02:31 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-07-14 23:45 - 2020-07-15 01:59 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2020-07-14 23:45 - 2020-07-14 23:46 - 000003250 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2020-07-14 23:45 - 2020-07-14 23:46 - 000003204 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-07-14 23:45 - 2020-07-14 23:46 - 000002810 _____ C:\WINDOWS\system32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-176138252-3860332429-2761773572-1018
2020-07-14 23:45 - 2020-07-14 23:46 - 000002810 _____ C:\WINDOWS\system32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-176138252-3860332429-2761773572-1001
2020-07-14 23:45 - 2020-07-14 23:46 - 000002112 _____ C:\WINDOWS\system32\Tasks\{A7827154-50C7-4867-ADFD-1E8E30D0C7A2}
2020-07-14 23:45 - 2020-07-14 23:45 - 000003022 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2020-07-14 23:45 - 2020-07-14 23:45 - 000002976 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-07-14 23:45 - 2020-07-14 23:45 - 000002942 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{2B2239C5-296B-46AF-9192-8557E01C177E}
2020-07-14 23:45 - 2020-07-14 23:45 - 000000000 ____D C:\WINDOWS\system32\Tasks\WPD
2020-07-14 23:45 - 2020-07-14 23:45 - 000000000 ____D C:\WINDOWS\system32\Tasks\Remediation
2020-07-14 23:45 - 2020-07-14 23:45 - 000000000 ____D C:\WINDOWS\system32\Tasks\Hewlett-Packard
2020-07-14 23:45 - 2020-07-14 23:45 - 000000000 ____D C:\WINDOWS\system32\Tasks\{3572C762-1A49-A2DF-ED84-168A6500F9A0}
2020-07-14 23:43 - 2020-07-14 23:45 - 000011433 _____ C:\WINDOWS\diagwrn.xml
2020-07-14 23:43 - 2020-07-14 23:45 - 000011433 _____ C:\WINDOWS\diagerr.xml
2020-07-14 23:40 - 2020-07-15 00:03 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2020-07-14 23:40 - 2020-07-14 23:41 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2020-07-14 23:36 - 2020-07-15 02:35 - 000934858 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-07-14 23:35 - 2020-07-14 23:35 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2020-07-14 23:35 - 2020-07-14 23:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2020-07-14 23:23 - 2020-07-15 06:45 - 000002421 _____ C:\Users\HP Pavilion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-07-14 23:23 - 2020-07-14 23:50 - 000000000 ____D C:\Users\HP Pavilion
2020-07-14 23:23 - 2020-07-14 23:39 - 000000000 ____D C:\Users\Joanne Endevoets
2020-07-14 23:23 - 2020-07-14 23:12 - 002876416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2020-07-14 23:23 - 2019-12-07 02:10 - 000001105 _____ C:\Users\Joanne Endevoets\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-07-14 23:17 - 2020-07-14 23:17 - 011490816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 009493504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 004465664 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2020-07-14 23:17 - 2020-07-14 23:17 - 003364864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2020-07-14 23:17 - 2020-07-14 23:17 - 001583616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe
2020-07-14 23:17 - 2020-07-14 23:17 - 000967680 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000937472 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000742912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapi.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000690176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSCOMEX.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000588288 _____ (Microsoft Corporation) C:\WINDOWS\system32\msra.exe
2020-07-14 23:17 - 2020-07-14 23:17 - 000553984 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000514560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000503808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FXSCOMEX.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000478208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Picker.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000441344 _____ (Microsoft Corporation) C:\WINDOWS\system32\WalletService.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000421376 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000352256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapibase.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000351232 _____ (Microsoft Corporation) C:\WINDOWS\system32\APHostService.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000338944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Picker.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000288256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ConsoleLogon.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpdxm.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpdxm.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModelOOBE.exe
2020-07-14 23:17 - 2020-07-14 23:17 - 000055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeUISrv.exe
2020-07-14 23:16 - 2020-07-14 23:16 - 024264704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 019868672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 018766336 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 018068992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 008188928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 007534160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 007070208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 006404608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 005821952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 005337504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 004783328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 003859456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 003547280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 003431424 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2020-07-14 23:16 - 2020-07-14 23:16 - 002685440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 002520048 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 002202624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVidCtl.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 002193736 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001956016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001704960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmcndmgr.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001686528 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001470976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001411072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmc.exe
2020-07-14 23:16 - 2020-07-14 23:16 - 001357312 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMNetMgr.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001352232 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001337856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001312256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001301592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001246720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001111552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMNetMgr.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloSI.PCShell.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001014872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001005056 _____ (Microsoft Corporation) C:\WINDOWS\system32\tapi3.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000991744 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebcamUi.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000961192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000859136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imapi2fs.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000854016 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000850944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tapi3.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000843264 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicExtensions.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000837120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000832512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdosys.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000814592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebcamUi.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000804352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000784896 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000746808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000742400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000676560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000673792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000666624 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000611840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000600616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000598528 _____ (Microsoft Corporation) C:\WINDOWS\system32\psisdecd.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000580096 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr
2020-07-14 23:16 - 2020-07-14 23:16 - 000579072 _____ (Microsoft® Windows® Operating System) C:\WINDOWS\system32\wvc.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000568832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wiaaut.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000562688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000556544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000549888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000534016 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2020-07-14 23:16 - 2020-07-14 23:16 - 000530440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr
2020-07-14 23:16 - 2020-07-14 23:16 - 000498688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\azroles.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000485888 _____ (Microsoft Corporation) C:\WINDOWS\system32\msTextPrediction.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000484352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\psisdecd.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000474112 _____ (Microsoft® Windows® Operating System) C:\WINDOWS\SysWOW64\wvc.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsregcmd.exe
2020-07-14 23:16 - 2020-07-14 23:16 - 000453952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAudDecMFT.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000453632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsettingsprovider.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2020-07-14 23:16 - 2020-07-14 23:16 - 000435200 _____ (Microsoft Corporation) C:\WINDOWS\system32\termmgr.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000428544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mswmdm.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000423936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000423224 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imapi2.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MixedReality.Broker.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000419840 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000413208 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000398848 _____ (Microsoft Corporation) C:\WINDOWS\system32\qdvd.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000361472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\termmgr.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000359936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iassdo.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswmdm.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000343992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\VAN.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnphost.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000323072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LocationApi.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000300032 _____ (Microsoft Corporation) C:\WINDOWS\system32\CXHProvisioningServer.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WlanMM.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000267776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000266240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mpg2splt.ax
2020-07-14 23:16 - 2020-07-14 23:16 - 000264192 _____ (Microsoft Corporation) C:\WINDOWS\system32\wavemsp.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000249856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VAN.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\FileHistory.exe
2020-07-14 23:16 - 2020-07-14 23:16 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\RdpRelayTransport.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloShellRuntime.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wavemsp.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mpg2splt.ax
2020-07-14 23:16 - 2020-07-14 23:16 - 000204000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityCenterBroker.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagSvc.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000202752 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmidx.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000189440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
2020-07-14 23:16 - 2020-07-14 23:16 - 000180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\HoloShellRuntime.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dialclient.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Clipboard.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintWSDAHost.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cic.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000146944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmidx.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000142848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkspbrokerAx.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Feedback.Analog.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasrecst.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000127488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdWSD.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000123392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintWSDAHost.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imapi.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000110512 _____ (Microsoft Corporation) C:\WINDOWS\system32\devenum.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000107520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasnap.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkspbrokerAx.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFolders.exe
2020-07-14 23:16 - 2020-07-14 23:16 - 000101288 _____ (Microsoft Corporation) C:\WINDOWS\system32\FsIso.exe
2020-07-14 23:16 - 2020-07-14 23:16 - 000100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmjpegdec.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000093952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devenum.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmjpegdec.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000072704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2020-07-14 23:16 - 2020-07-14 23:16 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\udhisapi.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MiracastReceiverExt.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasads.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000041864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityCenterBrokerPS.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnpcont.exe
2020-07-14 23:16 - 2020-07-14 23:16 - 000028384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SecurityCenterBrokerPS.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimsg.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 026271744 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 023433216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 008892600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 007756288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 007593472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 005964496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 005420648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 004880384 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 003812304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 003332608 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 002827776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2020-07-14 23:15 - 2020-07-14 23:15 - 002744320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2020-07-14 23:15 - 2020-07-14 23:15 - 002631008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 002413056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmcndmgr.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001952392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001912320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmc.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 001714176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001654824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001640888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001606656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001588224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Perception.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001557824 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 001449280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001448448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001353216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001320448 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagperf.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001315328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001257472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001255744 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 001233408 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001230848 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdclt.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 001218560 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdengin2.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001090560 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001078784 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdosys.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001041408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001022976 _____ (Microsoft Corporation) C:\WINDOWS\system32\CBDHSvc.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001008184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001004032 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi2fs.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000945664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000942080 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000907456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000897536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windowsperformancerecordercontrol.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000886272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000886272 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000884736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000872448 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000866304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000849920 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000801560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 000798720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000774456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Services.TargetedContent.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000760832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000759608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DismApi.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000758784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000722944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000711680 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000705024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000696240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000687104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000682496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiaaut.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000681472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000673976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 000633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\azroles.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000617472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000612352 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000606880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000602184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryPS.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000583608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StateRepository.Core.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000552448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000546456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\IESettingSync.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 000535552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000523720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StructuredQuery.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000519168 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi2.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000499712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000482616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 000473088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000471040 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnphost.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000466928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MediaControl.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000463360 _____ (Microsoft Corporation) C:\WINDOWS\system32\iassdo.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000443704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000424448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000420936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000409552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000408576 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationApi.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000407864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spwizeng.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000407504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Enumeration.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000402944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000399360 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMM.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000391680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000388096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.LowLevel.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000379392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000368640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000368640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Geolocation.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000355328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTMediaFrame.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000335360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2020-07-14 23:15 - 2020-07-14 23:15 - 000328704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.Workflow.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000311920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000304128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnclient.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000297984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000296448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Diagnostics.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000276992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Lights.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000276480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PickerPlatform.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpviewerax.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovs.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000255488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.CredDialogController.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000247296 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialclient.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
2020-07-14 23:15 - 2020-07-14 23:15 - 000226304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.FileExplorer.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000223544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Dism.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 000221184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bthprops.cpl
2020-07-14 23:15 - 2020-07-14 23:15 - 000217912 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000216064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pku2u.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000215040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Devices.Sensors.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\cic.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000201016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 000195128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000192000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000190048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\logoncli.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000186880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wdigest.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasrecst.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000183296 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000182784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netprofm.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000179000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Management.Workplace.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\intl.cpl
2020-07-14 23:15 - 2020-07-14 23:15 - 000176440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CapabilityAccessManagerClient.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdWSD.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ErrorDetails.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdrsvc.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000151864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasnap.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000142000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmcmnutils.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintWorkflowService.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Energy.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdshext.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msaatext.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000117048 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.SerialCommunication.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000099640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryBroker.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EaseOfAccessDialog.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 000095032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2020-07-14 23:15 - 2020-07-14 23:15 - 000092952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WwanRadioManager.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2020-07-14 23:15 - 2020-07-14 23:15 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sethc.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasads.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000074752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DiagnosticInvoker.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MiracastReceiverExt.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\system32\udhisapi.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\keyiso.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Print.Workflow.Source.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000053760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtutils.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnrollCtrl.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnpcont.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 000042320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryCore.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\CIDiag.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 000030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000021304 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000020632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerEnc.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintWorkflowProxy.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDJPN.DLL
2020-07-14 23:15 - 2020-07-14 23:15 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.Workflow.Native.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000009269 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2020-07-14 23:15 - 2020-07-14 23:15 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kbd106n.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kbd106.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kbd101.DLL
2020-07-14 23:15 - 2020-07-14 23:15 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DMAlertListener.ProxyStub.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimg32.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6r.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2020-07-14 23:14 - 2020-07-14 23:15 - 006356008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 014754816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 010922808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 007593544 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 006920192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 006029312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 005371536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 004734976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 004629328 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 003925856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 003906048 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 003778560 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 003498216 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 002918216 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 002601472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 002568192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 002317312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 002198016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 002177528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 002104320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 002026496 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001978656 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001805184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2020-07-14 23:14 - 2020-07-14 23:14 - 001751424 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001710080 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001695744 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001668904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001641472 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001550336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.3D.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001538136 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 001509736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001477632 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001474048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.PointOfService.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001430528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001400216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001394032 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2020-07-14 23:14 - 2020-07-14 23:14 - 001374720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdprt.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001314120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001303040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001296384 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001286560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001255936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpsharercom.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001253888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001247232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.FaceAnalysis.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001239552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001208832 _____ (Microsoft Corporation) C:\WINDOWS\system32\windowsperformancerecordercontrol.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001197232 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 001126472 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001125888 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001125376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001071224 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001066304 _____ (Microsoft Corporation) C:\WINDOWS\system32\DismApi.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001006592 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001005056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001001472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000966872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputHost.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000957952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000933176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000912896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MiracastReceiver.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000906528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000903168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000889384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000887296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MdmDiagnostics.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000885760 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000881112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000877056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000876544 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000868352 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofmsvc.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000856328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000831016 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000824328 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000779360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000775768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000748360 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingWinRT.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000733184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BTAGService.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000721024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000720896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000711168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000706048 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000701952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000689664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InkObjCore.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Ocr.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000687616 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockController.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000651776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000640000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\agentactivationruntimewindows.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000634680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicensingWinRT.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000633856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\agentactivationruntime.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000632536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000623960 _____ (Microsoft Corporation) C:\WINDOWS\system32\sechost.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000623392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Perception.Stub.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000619520 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000614912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.ConversationalAgent.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000608256 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000607744 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000595512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.applicationmodel.datatransfer.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000590848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000573752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2020-07-14 23:14 - 2020-07-14 23:14 - 000572928 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000569344 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000568632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000568320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Input.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000563712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000555744 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000551424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000546816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000540672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.SmartCards.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000539960 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000538624 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000528696 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizeng.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000520192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Launcher.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000512512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000508720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000501248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000496128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys
2020-07-14 23:14 - 2020-07-14 23:14 - 000487936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Geolocation.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000487552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000480768 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000476160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.Workflow.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000475704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sechost.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000469936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000464896 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000457728 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockHostingFramework.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000455168 _____ C:\WINDOWS\SysWOW64\WindowManagementAPI.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000445440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.AllJoyn.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000434504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboutSettingsHandlers.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000433152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000429056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000418816 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000412672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.SmartCards.Phone.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Payments.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000405304 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000395600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000388608 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000380416 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000373760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MicrosoftAccountWAMExtension.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000373760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreShellAPI.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000360960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.WiFiDirect.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000340992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000335360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AarSvc.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000332288 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpviewerax.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.CredDialogController.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpr.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000319808 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostBroker.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000317952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2020-07-14 23:14 - 2020-07-14 23:14 - 000313152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemSettings.DataModel.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RASMM.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000303616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000290816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Preview.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000286720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000285496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Dism.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000281088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000280064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.NetworkOperators.ESim.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000277504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000272896 _____ (Microsoft Corporation) C:\WINDOWS\system32\InkEd.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.FileExplorer.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000260288 _____ (Microsoft Corporation) C:\WINDOWS\system32\logoncli.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000253016 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000248320 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Gpu.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000245248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\intl.cpl
2020-07-14 23:14 - 2020-07-14 23:14 - 000233984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000232448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InkEd.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000230912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncSettings.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000229376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofm.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000227640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdigest.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000195240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcmnutils.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000191488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000183296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Graphics.Display.DisplayColorManagement.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000181760 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintWorkflowService.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000180024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2020-07-14 23:14 - 2020-07-14 23:14 - 000171024 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\msaatext.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000163208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\coreglobconfig.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000162816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDeviceRegistration.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Core.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\useractivitybroker.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.Client.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000146432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Graphics.Display.DisplayEnhancementManagement.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppExtension.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000134968 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000133744 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpapi.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000131072 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptcatsvc.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\CaptureService.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000126976 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkStatus.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000126976 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAMM.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000116736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AxInstSv.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleprn.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssitlb.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.Authentication.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CameraCaptureUI.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\keyiso.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000086784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Credentials.UI.CredentialPicker.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\RpcEpMap.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Print.Workflow.Source.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkInternalPS.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\atl.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtutils.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000067072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.internal.shellcommon.AccountsControlExperience.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemUWPLauncher.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000061752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GameInput.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AxInstUI.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssprxy.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagnosticdataquery.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000052664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ResourcePolicyClient.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000049664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\npmproxy.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000040248 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkPS.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIMgrBroker.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\atlthunk.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmproxy.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintWorkflowProxy.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000024288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerEnc.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\slcext.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmsprep.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slcext.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.Workflow.Native.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDJPN.DLL
2020-07-14 23:14 - 2020-07-14 23:14 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIManagerBrokerps.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMAlertListener.ProxyStub.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000008704 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbd106n.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000008704 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbd106.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000008704 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbd101.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimg32.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 017540608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 010336896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 009034752 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 007992824 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 007964416 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 006709248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 006175232 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 006069888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 006060544 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 005858128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 005766168 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 004485216 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 003860480 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 003810816 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2020-07-14 23:13 - 2020-07-14 23:13 - 003779896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2020-07-14 23:13 - 2020-07-14 23:13 - 003752448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Service.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 003749376 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 003380736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 003304960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 003299840 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002974720 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002963456 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2020-07-14 23:13 - 2020-07-14 23:13 - 002647040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002631168 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002585912 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002566144 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002466864 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002399744 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002338304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Perception.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002311680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002305024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002286128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002245632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002131024 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002077696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002040832 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShell.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001876480 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001858560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001784488 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001766912 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdprt.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001712128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001705472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001701368 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001530880 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001507328 _____ (Microsoft Corporation) C:\WINDOWS\system32\MoUsoCoreWorker.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 001495552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001493504 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpsharercom.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001491968 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001473024 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 001473024 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001422336 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001414144 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 001403904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.FaceAnalysis.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001378568 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputHost.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001359872 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsf3gip.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001337168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryPS.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001323008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001305600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001257472 _____ (Microsoft Corporation) C:\WINDOWS\system32\MiracastReceiver.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001222656 _____ (Microsoft Corporation) C:\WINDOWS\system32\SEMgrSvc.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001207296 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001204968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 001195520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001182008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Services.TargetedContent.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001145344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001114112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001105408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001082168 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001069056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Signals.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001058816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001048480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Perception.Stub.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001047552 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001043456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Ocr.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000994248 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000975672 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000968192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\InkObjCore.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000937464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000935936 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000914200 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000908288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000902976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2020-07-14 23:13 - 2020-07-14 23:13 - 000833024 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000830464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000824832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Input.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000804864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000802816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000799552 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.applicationmodel.datatransfer.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000791552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000784896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000764456 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000753152 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.immersiveshell.serviceprovider.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000725600 _____ (Microsoft Corporation) C:\WINDOWS\system32\StateRepository.Core.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000704496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000683008 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000677888 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000676088 _____ (Microsoft Corporation) C:\WINDOWS\system32\StructuredQuery.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000670208 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000657920 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000646656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000644096 _____ C:\WINDOWS\system32\WindowManagementAPI.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000635824 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000614912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000608768 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000597504 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicesFlowBroker.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000596992 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2020-07-14 23:13 - 2020-07-14 23:13 - 000596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.LowLevel.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Payments.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000583168 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000565760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.Phone.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000565760 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000560400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000556032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000541696 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountWAMExtension.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000539256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Enumeration.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000534016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Activities.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Narrator.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000531456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64win.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000522040 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000508416 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTMediaFrame.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000504832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000488448 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000486912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000475648 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShellAPI.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000475136 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinDataModelServer.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000454968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2020-07-14 23:13 - 2020-07-14 23:13 - 000449536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wksprt.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000430592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountExtension.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000428680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000423424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000423224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DataModel.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000418816 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000398848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.NetworkOperators.ESim.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SpeechPrivacy.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Lights.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000389952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManager.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000388096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Preview.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000386048 _____ (Microsoft Corporation) C:\WINDOWS\system32\PickerPlatform.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000380632 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialEnrollmentManager.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000373064 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000370688 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuickActionsDataModel.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000367104 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnclient.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000362496 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicSvc.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000355328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Diagnostics.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Cortana.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000326144 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000321024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000319488 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultcli.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000316416 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.internal.shellcommon.shareexperience.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Devices.Sensors.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.HumanInterfaceDevice.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000283136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000281088 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000272384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthprops.cpl
2020-07-14 23:13 - 2020-07-14 23:13 - 000265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\PasswordEnrollmentManager.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicCapsule.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Graphics.Display.DisplayColorManagement.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000249656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000249656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Workplace.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000247296 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000242688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManagerClient.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.CapturePicker.Desktop.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeopleBand.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000222720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Core.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\MtcModel.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000220160 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000215896 _____ (Microsoft Corporation) C:\WINDOWS\system32\coreglobconfig.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000214840 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SIUF.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000214016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppExtension.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000203976 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsBroker.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ErrorDetails.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\useractivitybroker.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000183296 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3mm.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000181248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Energy.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000173056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.CapturePicker.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Graphics.Display.DisplayEnhancementManagement.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SerialCommunication.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000148280 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResourcePolicyServer.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000146944 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000143160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys
2020-07-14 23:13 - 2020-07-14 23:13 - 000140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Storage.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredDialogBroker.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000132728 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000131896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000131072 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssitlb.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000131072 _____ (Microsoft Corporation) C:\WINDOWS\system32\CameraCaptureUI.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\EaseOfAccessDialog.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000118072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000116024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000113112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Credentials.UI.CredentialPicker.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\sethc.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthRadioMedia.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairingExperienceMEM.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\bindfltapi.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagnosticInvoker.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\atl.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicAgent.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.internal.shellcommon.AccountsControlExperience.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\UsoClient.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemUWPLauncher.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000076992 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialEnrollmentManagerForUser.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000071792 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResourcePolicyClient.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000070968 _____ (Microsoft Corporation) C:\WINDOWS\system32\GameInput.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000068608 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanRadioManager.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnrollCtrl.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000064840 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthHost.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000064016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryCore.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\NfcRadioMedia.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MdmDiagnosticsTool.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.Common.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\atlthunk.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicPS.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6r.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 001869312 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 001762632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 001556480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 001540096 _____ (Microsoft Corporation) C:\WINDOWS\system32\TaskFlowDataEngine.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 001250816 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 001150752 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2020-07-14 23:12 - 2020-07-14 23:12 - 001021440 _____ (Microsoft Corporation) C:\WINDOWS\system32\BTAGService.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 001001984 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcRefreshTask.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Service.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000884224 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000879104 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntimewindows.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000858624 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntime.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000799232 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2020-07-14 23:12 - 2020-07-14 23:12 - 000781312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.ConversationalAgent.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000678200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2020-07-14 23:12 - 2020-07-14 23:12 - 000601400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2020-07-14 23:12 - 2020-07-14 23:12 - 000577392 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000506672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000439296 _____ (Microsoft Corporation) C:\WINDOWS\system32\AarSvc.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000436224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000287232 _____ (Microsoft Corporation) C:\WINDOWS\system32\netman.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000287232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceDirectoryClient.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcTok.exe
2020-07-14 23:12 - 2020-07-14 23:12 - 000215864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spacedump.sys
2020-07-14 23:12 - 2020-07-14 23:12 - 000202752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBAUDIO.sys
2020-07-14 23:12 - 2020-07-14 23:12 - 000198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Internal.Input.ExpressiveInput.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000159032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2020-07-14 23:12 - 2020-07-14 23:12 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleprn.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2020-07-14 23:12 - 2020-07-14 23:12 - 000069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxGipRadioManager.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000013312 _____ C:\WINDOWS\system32\agentactivationruntimestarter.exe
2020-07-14 23:05 - 2020-07-15 06:35 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-07-14 23:05 - 2020-07-14 23:05 - 000275400 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-07-14 23:04 - 2020-07-15 02:30 - 000008192 ___SH C:\DumpStack.log.tmp
2020-07-14 22:58 - 2019-12-06 22:30 - 000099840 _____ (Microsoft Corporation) C:\WINDOWS\system32\XPSSHHDR.dll
2020-07-14 22:58 - 2019-12-06 22:22 - 000883200 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsFilt.dll
2020-07-14 22:58 - 2019-12-06 20:49 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XPSSHHDR.dll
2020-07-14 22:58 - 2019-12-06 20:38 - 000561664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsFilt.dll
2020-07-14 22:58 - 2019-10-15 14:53 - 000076060 _____ C:\WINDOWS\system32\xpsrchvw.xml
2020-07-14 22:58 - 2019-04-18 19:49 - 000076060 _____ C:\WINDOWS\SysWOW64\xpsrchvw.xml
2020-07-14 22:40 - 2020-07-14 22:40 - 000000000 ____D C:\Program Files\Reference Assemblies
2020-07-14 22:40 - 2020-07-14 22:40 - 000000000 ____D C:\Program Files\MSBuild
2020-07-14 22:40 - 2020-07-14 22:40 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2020-07-14 22:40 - 2020-07-14 22:40 - 000000000 ____D C:\Program Files (x86)\MSBuild
2020-07-14 22:40 - 2020-07-14 22:40 - 000000000 ____D C:\inetpub
2020-07-14 22:38 - 2019-12-03 15:04 - 000781384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2020-07-14 22:38 - 2019-12-03 15:04 - 000105544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2020-07-14 22:38 - 2019-12-03 15:04 - 000037864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2020-07-14 22:38 - 2019-11-08 15:44 - 001168968 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2020-07-14 22:38 - 2019-11-08 15:44 - 000127056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2020-07-14 22:38 - 2019-11-08 15:44 - 000038072 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2020-07-14 22:37 - 2020-07-14 22:37 - 000495616 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2020-07-14 22:37 - 2020-07-14 22:37 - 000391168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2020-07-14 19:09 - 2020-07-14 23:48 - 000000000 ___DC C:\WINDOWS\Panther
2020-07-14 18:51 - 2020-07-14 19:09 - 000000000 ____D C:\ESD
2020-07-14 18:46 - 2020-07-14 18:46 - 000000000 ___HD C:\$Windows.~WS
2020-07-14 18:44 - 2020-07-14 18:44 - 019468312 _____ (Microsoft Corporation) C:\Users\HP Pavilion\Desktop\MediaCreationTool2004.exe
2020-07-10 22:17 - 2020-07-10 22:17 - 000000000 ____D C:\WINDOWS\pss
2020-07-09 11:34 - 2020-07-09 11:34 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\VirtualStore
2020-07-09 10:08 - 2020-07-09 10:08 - 000000207 _____ C:\WINDOWS\tweaking.com-regbackup-HPPAVILION-Windows-8.1-(64-bit).dat
2020-07-09 10:07 - 2020-07-09 10:07 - 000000000 ____D C:\RegBackup
2020-07-09 09:50 - 2020-07-09 10:06 - 000000000 ____D C:\Users\HP Pavilion\Desktop\Tweaking.com - Windows Repair
2020-07-09 09:23 - 2020-07-09 09:23 - 037198272 _____ C:\Users\HP Pavilion\Downloads\tweaking.com_windows_repair_aio.zip
2020-07-08 08:15 - 2020-07-08 08:15 - 000000480 _____ C:\Users\HP Pavilion\Desktop\fix.reg
2020-07-07 09:04 - 2020-07-07 09:04 - 000006768 _____ C:\Users\HP Pavilion\Desktop\Windows_Defender_Security_Center_Service.reg
2020-07-01 11:17 - 2020-07-01 11:17 - 000008404 _____ C:\Users\HP Pavilion\Desktop\State_Repository_Service.reg
2020-07-01 11:07 - 2020-07-01 11:07 - 000010762 _____ C:\Users\HP Pavilion\Desktop\Windows_Update.reg
2020-07-01 11:04 - 2020-07-14 23:34 - 000002421 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2020-07-01 11:04 - 2020-07-14 23:34 - 000002259 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2020-07-01 11:04 - 2020-07-14 23:34 - 000002259 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk
2020-07-01 10:36 - 2020-07-01 10:36 - 000007572 _____ C:\Users\HP Pavilion\Desktop\Windows_Defender_Service.reg
2020-06-30 08:04 - 2020-06-30 08:04 - 000925696 _____ (Farbar) C:\Users\HP Pavilion\Desktop\FSS.exe
2020-06-30 07:35 - 2020-06-30 07:35 - 000000000 ____D C:\ProgramData\Norton
2020-06-30 06:17 - 2020-06-30 08:19 - 000001861 _____ C:\Users\HP Pavilion\Documents\DISM.txt
2020-06-25 11:53 - 2020-07-14 06:27 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\ESET
2020-06-25 11:53 - 2020-06-25 11:53 - 000000565 _____ C:\Users\HP Pavilion\Desktop\ESET Online Scanner.lnk
2020-06-25 11:51 - 2020-06-25 11:52 - 014827616 _____ (ESET spol. s r.o.) C:\Users\HP Pavilion\Desktop\esetonlinescanner.exe
2020-06-22 07:49 - 2020-06-25 11:42 - 000000000 ____D C:\AdwCleaner
2020-06-22 07:47 - 2020-06-22 07:48 - 008402608 _____ (Malwarebytes) C:\Users\HP Pavilion\Desktop\AdwCleaner.exe
2020-06-20 11:33 - 2020-07-09 12:06 - 000000000 ____D C:\Users\HP Pavilion\Desktop\FRST-OlderVersion
2020-06-20 11:03 - 2020-06-20 11:04 - 012770472 _____ (Symantec Corporation) C:\Users\HP Pavilion\Desktop\NRnR.exe
2020-06-20 09:13 - 2020-07-15 00:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2020-06-20 09:13 - 2020-06-20 09:13 - 000001093 _____ C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2020-06-20 09:13 - 2020-06-20 09:13 - 000001093 _____ C:\ProgramData\Desktop\Revo Uninstaller Pro.lnk
2020-06-20 09:13 - 2020-06-20 09:13 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\VS Revo Group
2020-06-20 09:13 - 2020-06-20 09:13 - 000000000 ____D C:\ProgramData\VS Revo Group
2020-06-20 09:13 - 2020-06-20 09:13 - 000000000 ____D C:\Program Files\VS Revo Group
2020-06-20 09:13 - 2016-12-21 14:52 - 000040240 _____ (VS Revo Group) C:\WINDOWS\system32\Drivers\revoflt.sys
2020-06-20 09:11 - 2020-06-20 09:11 - 016926296 _____ (VS Revo Group ) C:\Users\HP Pavilion\Desktop\RevoUninProSetup.exe
2020-06-16 15:03 - 2020-07-15 06:53 - 000000000 ____D C:\FRST
2020-06-16 14:48 - 2020-07-09 12:06 - 002292736 _____ (Farbar) C:\Users\HP Pavilion\Desktop\FRST64.exe
2020-06-16 14:25 - 2020-06-16 14:26 - 000000000 ____D C:\Users\HP Pavilion\Downloads\priortoMalware
2020-06-16 09:43 - 2020-07-01 10:04 - 000000000 ____D C:\Users\HP Pavilion\AppData\LocalLow\IGDump
2020-06-16 09:42 - 2020-06-16 09:42 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\mbam
2020-06-16 09:41 - 2020-06-16 09:41 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2020-06-16 09:41 - 2020-06-16 09:41 - 000001976 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2020-06-16 09:41 - 2020-06-16 09:41 - 000001964 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2020-06-16 09:41 - 2020-06-16 09:41 - 000001964 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2020-06-16 09:41 - 2020-06-16 09:41 - 000000000 ____D C:\ProgramData\Malwarebytes
2020-06-16 09:40 - 2020-06-16 09:40 - 000000000 ____D C:\Program Files\Malwarebytes
2020-06-16 09:40 - 2020-06-16 09:40 - 000000000 ____D C:\Malwarebytes
2020-06-16 09:38 - 2020-06-16 09:38 - 000000000 ____D C:\Users\HP Pavilion\AppData\Roaming\Logitech
2020-06-16 09:38 - 2020-06-16 09:38 - 000000000 ____D C:\Users\HP Pavilion\AppData\Roaming\Logishrd
2020-06-16 09:06 - 2020-07-14 23:33 - 000000000 ____D C:\Program Files\KeyboardNotification
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2020-07-15 06:51 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-07-15 06:47 - 2019-12-07 02:14 - 000000000 ___HD C:\Program Files\WindowsApps
2020-07-15 06:47 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\ServiceState
2020-07-15 06:47 - 2016-01-25 16:07 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\Packages
2020-07-15 06:45 - 2016-01-30 12:17 - 000000000 ___RD C:\Users\HP Pavilion\OneDrive
2020-07-15 06:38 - 2019-12-07 02:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-07-15 03:32 - 2019-12-07 02:13 - 000000000 ____D C:\WINDOWS\INF
2020-07-15 03:31 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\appcompat
2020-07-15 02:30 - 2019-12-07 02:03 - 000262144 _____ C:\WINDOWS\system32\config\BBI
2020-07-15 02:04 - 2019-12-07 02:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-07-15 01:58 - 2019-12-07 02:14 - 000000000 ____D C:\Program Files\Windows Defender
2020-07-15 01:50 - 2014-02-04 17:43 - 000744808 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2020-07-15 00:04 - 2019-12-07 02:14 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2020-07-15 00:04 - 2013-08-22 08:36 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2020-07-15 00:03 - 2020-02-12 18:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech Camera Settings
2020-07-15 00:03 - 2019-12-07 02:18 - 000000000 ____D C:\WINDOWS\Setup
2020-07-15 00:03 - 2019-12-07 02:14 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
2020-07-15 00:03 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2020-07-15 00:03 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\IME
2020-07-15 00:03 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\spool
2020-07-15 00:03 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2020-07-15 00:03 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\IME
2020-07-15 00:03 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\Registration
2020-07-15 00:03 - 2019-12-07 02:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2020-07-15 00:03 - 2017-04-10 18:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2020-07-15 00:03 - 2014-11-01 10:22 - 000000000 ____D C:\Program Files (x86)\ATI Technologies
2020-07-15 00:03 - 2014-09-24 02:50 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Embedded Lockdown Manager
2020-07-15 00:03 - 2014-02-20 18:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2020-07-15 00:03 - 2013-11-13 17:07 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-07-15 00:03 - 2013-11-13 16:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yahoo! Messenger
2020-07-15 00:03 - 2013-11-05 15:12 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services
2020-07-15 00:03 - 2013-08-22 08:36 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2020-07-15 00:03 - 2012-09-11 06:45 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2020-07-15 00:03 - 2012-09-11 06:40 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Communication and Chat
2020-07-15 00:03 - 2012-09-11 06:35 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Productivity and Tools
2020-07-15 00:03 - 2012-09-11 06:31 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security and Protection
2020-07-15 00:03 - 2012-09-11 06:28 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
2020-07-15 00:03 - 2012-09-11 06:23 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Music, Photos and Videos
2020-07-15 00:03 - 2012-09-11 06:18 - 000000000 ____D C:\Program Files (x86)\Hewlett-Packard
2020-07-15 00:03 - 2012-08-01 19:05 - 000000000 ____D C:\ProgramData\PRICache
2020-07-15 00:01 - 2019-12-07 02:14 - 000000000 __RHD C:\Users\Public\Libraries
2020-07-14 23:55 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2020-07-14 23:55 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2020-07-14 23:55 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2020-07-14 23:55 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2020-07-14 23:55 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2020-07-14 23:55 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\InputMethod
2020-07-14 23:55 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2020-07-14 23:55 - 2013-08-22 08:36 - 000000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Shared
2020-07-14 23:55 - 2013-08-22 08:36 - 000000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared
2020-07-14 23:53 - 2019-12-07 02:14 - 000000000 ____D C:\ProgramData\USOPrivate
2020-07-14 23:50 - 2013-11-04 19:17 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-07-14 23:49 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2020-07-14 23:47 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-07-14 23:46 - 2019-12-07 02:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2020-07-14 23:40 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\InputMethod
2020-07-14 23:40 - 2014-11-01 10:19 - 000000000 ____D C:\Program Files\Realtek
2020-07-14 23:40 - 2014-11-01 10:18 - 000000000 ____D C:\Program Files\AMD
2020-07-14 23:34 - 2014-11-01 10:19 - 000000000 ____D C:\Program Files\Common Files\logishrd
2020-07-14 23:34 - 2013-11-24 22:54 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-07-14 23:34 - 2013-11-24 22:54 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-07-14 23:34 - 2013-11-24 22:54 - 000002260 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-07-14 23:33 - 2014-11-01 10:19 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2020-07-14 23:32 - 2014-11-01 10:19 - 000000000 ____D C:\AMD
2020-07-14 23:32 - 2013-11-19 18:32 - 000000000 ____D C:\WINDOWS\SysWOW64\sda
2020-07-14 23:30 - 2019-12-07 02:52 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2020-07-14 23:30 - 2019-12-07 02:52 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ___SD C:\WINDOWS\system32\F12
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SystemResources
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\Com
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\DiagTrack
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\Program Files\Common Files\System
2020-07-14 23:30 - 2019-12-07 02:03 - 000000000 ____D C:\WINDOWS\servicing
2020-07-14 23:28 - 2019-04-16 12:49 - 000000000 ____D C:\Users\HP Pavilion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Paltalk
2020-07-14 23:26 - 2013-11-05 15:10 - 000000000 ____D C:\Users\Joanne Endevoets\AppData\Local\Packages
2020-07-14 23:14 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2020-07-14 23:10 - 2019-12-07 02:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2020-07-14 23:10 - 2019-12-07 02:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2020-07-14 22:58 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2020-07-14 22:58 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2020-07-14 22:40 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2020-07-14 22:40 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\inetsrv
2020-07-14 22:39 - 2019-12-07 02:10 - 000208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2020-07-14 22:39 - 2019-12-07 02:10 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2020-07-14 22:39 - 2019-12-07 02:10 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2020-07-14 22:39 - 2019-12-07 02:10 - 000053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2020-07-14 22:39 - 2019-12-07 02:10 - 000048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2020-07-14 22:39 - 2019-12-07 02:10 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2020-07-14 22:39 - 2019-12-07 02:10 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2020-07-14 22:39 - 2019-12-07 02:10 - 000016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2020-07-14 22:39 - 2019-12-07 02:10 - 000015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2020-07-14 22:39 - 2019-12-07 02:10 - 000014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\cngkeyhelper.dll
2020-07-14 22:39 - 2019-12-07 02:10 - 000013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2020-07-14 22:39 - 2019-12-07 02:10 - 000011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2020-07-14 22:39 - 2019-12-07 02:10 - 000011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cngkeyhelper.dll
2020-07-14 22:39 - 2019-12-07 02:10 - 000009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2020-07-10 22:59 - 2012-09-11 06:21 - 000000000 ____D C:\ProgramData\Hewlett-Packard
2020-07-09 11:13 - 2013-08-22 06:25 - 000000128 _____ C:\WINDOWS\win.ini
2020-07-09 11:05 - 2014-11-01 10:23 - 000006636 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2020-07-08 08:17 - 2015-09-08 17:28 - 000253286 _____ C:\WINDOWS\ntbtlog.txt
2020-07-01 09:49 - 2017-04-06 19:56 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\CrashDumps
2020-06-29 21:57 - 2013-11-14 19:49 - 000000000 ____D C:\Program Files (x86)\Paltalk Messenger
2020-06-25 11:43 - 2012-08-16 20:14 - 000000000 _RSHD C:\hp
2020-06-25 11:42 - 2016-01-25 16:08 - 000000000 ____D C:\Users\HP Pavilion\AppData\Roaming\Hewlett-Packard
2020-06-25 11:42 - 2013-11-05 17:57 - 000000000 ____D C:\Users\Joanne Endevoets\AppData\Local\Hewlett-Packard
2020-06-25 11:42 - 2013-11-05 15:11 - 000000000 ____D C:\Users\Joanne Endevoets\AppData\Roaming\Hewlett-Packard
2020-06-25 11:42 - 2012-09-11 06:33 - 000000000 ____D C:\Program Files (x86)\CyberLink
2020-06-21 22:46 - 2017-04-13 16:40 - 000000000 ____D C:\Program Files\Common Files\AV
2020-06-21 22:46 - 2013-08-22 06:25 - 000000027 _____ C:\WINDOWS\system32\Drivers\etc\hosts_bak_31
2020-06-16 12:22 - 2013-08-22 08:36 - 000000000 ___RD C:\WINDOWS\ToastData
2020-06-16 11:15 - 2016-01-26 11:34 - 000000000 ____D C:\ProgramData\iolo
2020-06-16 11:15 - 2016-01-26 11:31 - 000000000 ____D C:\Program Files (x86)\iolo
2020-06-16 09:41 - 2016-01-25 16:25 - 000248968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2020-06-16 09:39 - 2020-02-12 18:23 - 000000000 ____D C:\Program Files\Logitech
2020-06-16 09:39 - 2014-02-20 18:51 - 000000000 ____D C:\ProgramData\LogiShrd
 
==================== Files in the root of some directories ========
 
2018-06-09 22:26 - 2020-06-10 14:48 - 000000175 _____ () C:\Users\HP Pavilion\AppData\Roaming\WB.CFG
2016-01-27 10:21 - 2016-01-27 10:21 - 000007601 _____ () C:\Users\HP Pavilion\AppData\Local\Resmon.ResmonCfg
2018-01-30 13:25 - 2019-04-16 12:51 - 000001376 _____ () C:\Users\HP Pavilion\AppData\Local\Temptoast_image.png
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-07-2020 01
Ran by HP Pavilion (15-07-2020 07:01:47)
Running from C:\Users\HP Pavilion\Desktop
Windows 10 Home Version 2004 19041.388 (X64) (2020-07-15 06:47:45)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-176138252-3860332429-2761773572-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-176138252-3860332429-2761773572-503 - Limited - Disabled)
Guest (S-1-5-21-176138252-3860332429-2761773572-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-176138252-3860332429-2761773572-1003 - Limited - Enabled)
HP Pavilion (S-1-5-21-176138252-3860332429-2761773572-1018 - Administrator - Enabled) => C:\Users\HP Pavilion
WDAGUtilityAccount (S-1-5-21-176138252-3860332429-2761773572-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD)
AMD Catalyst Install Manager (HKLM\...\{5F769CF4-5263-4C7B-AEB2-C06A73AE4428}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CameraHelperMsi (HKLM-x32\...\{15634701-BACE-4449-8B25-1567DA8C9FD3}) (Version: 13.51.815.0 - Logitech) Hidden
CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.1.1916 - CyberLink Corp.)
CyberLink PhotoDirector (HKLM-x32\...\InstallShield_{4862344A-A39C-4897-ACD4-A1BED5163C5A}) (Version: 2.0.1.3109 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.1.1925 - CyberLink Corp.)
Energy Star (HKLM\...\{0FA995CC-C849-4755-B14B-5404CC75DC24}) (Version: 1.0.8 - Hewlett-Packard)
erLT (HKLM-x32\...\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}) (Version: 1.20.138.34 - Logitech, Inc.) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 83.0.4103.116 - Google LLC)
Google Toolbar for Internet Explorer (HKLM-x32\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
HP Connected Music (Meridian - installer) (HKLM-x32\...\StartHPConnectedMusic) (Version: v1.0 - Meridian Audio Ltd)
HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.3.0 - WildTangent)
HP Quick Start (HKLM-x32\...\{574F0207-8E98-46CD-8F79-318348C98C46}) (Version: 1.0.4660.30220 - Hewlett-Packard)
Logitech Camera Settings (HKLM-x32\...\LogiUCDPP) (Version: 2.5.17.0 - Logitech Europe S.A.)
Logitech Solar App 1.10 (HKLM\...\SolarApp) (Version: 1.10.3 - Logitech)
Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.80 - Logitech Inc.)
Malwarebytes version 4.1.0.56 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.1.0.56 - Malwarebytes)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 83.0.478.50 - Microsoft Corporation)
Microsoft Edge Update (HKLM-x32\...\Microsoft Edge Update) (Version: 1.3.129.37 - )
Microsoft Office (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.6120.5004 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\OneDriveSetup.exe) (Version: 20.084.0426.0007 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Paltalk (HKLM-x32\...\Paltalk) (Version:  - )
Ralink RT5390R 802.11bgn Wi-Fi Adapter (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 5.0.0.0 - Ralink)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.31.423.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6777 - Realtek Semiconductor Corp.)
Realtek PCIE Card Reader (HKLM-x32\...\{0D61A55C-3ADC-409F-BF5B-A1766D1F5944}) (Version: 6.2.9200.28137 - Realtek Semiconductor Corp.)
Recovery Manager (HKLM-x32\...\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.5.0.5530 - CyberLink Corp.) Hidden
Revo Uninstaller Pro 4.3.3 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 4.3.3 - VS Revo Group, Ltd.)
Skype™ 7.38 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.38.101 - Skype Technologies S.A.)
swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version:  - Yahoo! Inc.)
 
Packages:
=========
eBay -> C:\Program Files\WindowsApps\eBayInc.eBay_1.6.0.34_neutral__1618n3s9xq8tw [2014-11-07] (eBay, Inc)
Getting Started with Windows 8 -> C:\Program Files\WindowsApps\AD2F1837.GettingStartedwithWindows8_1.6.0.0_neutral__v10z8vjag6ke6 [2015-03-03] (Hewlett-Packard Company)
HP Registration -> C:\Program Files\WindowsApps\AD2F1837.HPRegistration_1.2.1.166_neutral__v10z8vjag6ke6 [2014-11-27] (Hewlett-Packard Company)
HP+ -> C:\Program Files\WindowsApps\AD2F1837.HP_1.2.0.93_neutral__v10z8vjag6ke6 [2014-11-02] (Hewlett-Packard Company)
iHeartRadio -> C:\Program Files\WindowsApps\ClearChannelRadioDigital.iHeartRadio_6.0.47.0_x64__a76a11dkgb644 [2020-07-15] (iHeartMedia.)
Kindle -> C:\Program Files\WindowsApps\AMZNMobileLLC.KindleforWindows8_2.1.0.2_neutral__stfe6vwa9jnbp [2015-06-27] (AMZN Mobile LLC)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2020-07-15] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2020-07-15] (Microsoft Corporation) [MS Ad]
Microsoft Mahjong -> C:\Program Files\WindowsApps\Microsoft.MicrosoftMahjong_2.10.1812.2002_x86__8wekyb3d8bbwe [2019-02-02] (Microsoft Studios) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.7.7082.0_x64__8wekyb3d8bbwe [2020-07-15] (Microsoft Studios) [MS Ad]
MSN Food & Drink -> C:\Program Files\WindowsApps\Microsoft.BingFoodAndDrink_3.0.4.336_x64__8wekyb3d8bbwe [2015-07-13] (Microsoft Corporation) [MS Ad]
MSN Health & Fitness -> C:\Program Files\WindowsApps\Microsoft.BingHealthAndFitness_3.0.4.336_x64__8wekyb3d8bbwe [2015-07-13] (Microsoft Corporation) [MS Ad]
MSN Money -> C:\Program Files\WindowsApps\Microsoft.BingFinance_4.36.20714.0_x64__8wekyb3d8bbwe [2020-07-15] (Microsoft Corporation) [MS Ad]
MSN News -> C:\Program Files\WindowsApps\Microsoft.BingNews_3.0.4.344_x64__8wekyb3d8bbwe [2016-04-30] (Microsoft Corporation) [MS Ad]
MSN Sports -> C:\Program Files\WindowsApps\Microsoft.BingSports_4.36.20714.0_x64__8wekyb3d8bbwe [2020-07-15] (Microsoft Corporation) [MS Ad]
MSN Travel -> C:\Program Files\WindowsApps\Microsoft.BingTravel_3.0.4.336_x64__8wekyb3d8bbwe [2015-07-13] (Microsoft Corporation) [MS Ad]
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x64__8wekyb3d8bbwe [2020-07-15] (Microsoft Corporation) [MS Ad]
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.97.752.0_x64__mcm4njqhnhss8 [2020-07-15] (Netflix, Inc.)
Norton Studio -> C:\Program Files\WindowsApps\SymantecCorporation.NortonStudio_2.2.0.0_x86__v68kp9n051hdp [2020-07-15] (Symantec Corporation)
Snapfish -> C:\Program Files\WindowsApps\AD2F1837.HPConnectedPhotopoweredbySnapfish_6.1.736.0_x86__v10z8vjag6ke6 [2020-07-15] (Snapfish)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
ShellIconOverlayIdentifiers: [  OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} =>  -> No File
ShellIconOverlayIdentifiers: [  OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} =>  -> No File
ShellIconOverlayIdentifiers: [  OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} =>  -> No File
ShellIconOverlayIdentifiers-x32: [  OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} =>  -> No File
ShellIconOverlayIdentifiers-x32: [  OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} =>  -> No File
ShellIconOverlayIdentifiers-x32: [  OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} =>  -> No File
ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} =>  -> No File
ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} =>  -> No File
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-06-16] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} =>  -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2015-08-21] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} =>  -> No File
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-06-16] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers6: [RUShellExt] -> {2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RUExt.dll [2019-03-29] (VS Revo Group Ltd. -> VS Revo Group)
 
==================== Codecs (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Drivers32: [vidc.i420] => C:\WINDOWS\system32\lvcod64.dll [175392 2012-10-26] (Logitech, Inc. -> Logitech Inc.)
HKLM\...\Drivers32: [vidc.i420] => C:\Windows\SysWOW64\lvcodec2.dll [305000 2012-10-26] (Logitech, Inc. -> Logitech Inc.)
 
==================== Shortcuts & WMI ========================
 
==================== Loaded Modules (Whitelisted) =============
 
2014-07-04 21:33 - 2014-07-04 21:33 - 000127488 _____ () [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2014-07-04 21:33 - 2014-07-04 21:33 - 000102400 _____ () [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2015-08-21 22:06 - 2015-08-21 22:06 - 000004608 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiamenu.dll
 
==================== Alternate Data Streams (Whitelisted) ========
 
==================== Safe Mode (Whitelisted) ==================
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer trusted/restricted ==========
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 06:25 - 2020-07-09 11:14 - 000000855 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1       localhost
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> c:\Program Files (x86)\AMD APP\bin\x86_64;c:\Program Files (x86)\AMD APP\bin\x86;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files (x86)\Skype\Phone\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\Control Panel\Desktop\\Wallpaper -> C:\Users\HP Pavilion\AppData\Local\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(If an entry is included in the fixlist, it will be removed.)
 
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\StartupApproved\StartupFolder: => "PalTalk.lnk"
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\StartupApproved\Run: => "Chromium"
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_803D2E04332962AFAC352F92C208E650"
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\StartupApproved\Run: => "Paltalk"
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\StartupApproved\Run: => "Skype"
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{26350D1D-A0AD-46A3-8C88-07A46D70D51E}] => (Allow) LPort=52000
FirewallRules: [{FABCC09D-24F4-49C0-8CD8-05798DCFEB32}] => (Allow) LPort=53000
FirewallRules: [{FBA5429D-8BA2-4085-BDD5-F7E2BDB1C1B2}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [UDP Query User{40E28967-F448-403E-B197-C27ECC80F3A9}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [TCP Query User{B0241114-BEDC-46F5-BBAF-324BF2D6F0B4}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [UDP Query User{A8FCFB61-3A9B-49D7-B998-60FB27AE20BB}C:\program files (x86)\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk.exe => No File
FirewallRules: [TCP Query User{AC84FE58-503E-4351-8C1D-1B3550F0000F}C:\program files (x86)\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk.exe => No File
FirewallRules: [{C19F3984-3DF2-4505-B50E-E2623874F167}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe => No File
FirewallRules: [{5F0B061F-74AB-46A7-AA55-5DA60E86BD74}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{27F4866A-85A9-4CBE-B396-6FD538FC22F3}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{261379EE-DACD-4B61-9F8A-BF6F93F7DF35}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{B6D693E7-D84F-46D9-A816-DE973D437AF7}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{87010DB7-297E-435E-AB81-7C0757767CAC}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE (CyberLink -> CyberLink Corp.)
FirewallRules: [TCP Query User{7DE345DD-8CFC-418A-B491-BB60FC69B658}C:\windows\syswow64\msiexec.exe] => (Allow) C:\windows\syswow64\msiexec.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [UDP Query User{29A929DE-9870-4957-A906-14B5642012FB}C:\windows\syswow64\msiexec.exe] => (Allow) C:\windows\syswow64\msiexec.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [TCP Query User{5A430BC0-D3BD-4121-8016-8EA23C276F90}C:\program files (x86)\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk.exe => No File
FirewallRules: [UDP Query User{0326EAFC-8940-43FE-9164-E4A21A402C98}C:\program files (x86)\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk.exe => No File
FirewallRules: [{63569EEC-DC52-4EED-8DB2-E83112C70753}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc. -> Yahoo! Inc.)
FirewallRules: [{14852894-E754-4D88-B410-E365CBD58788}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc. -> Yahoo! Inc.)
FirewallRules: [TCP Query User{C668418F-047A-4B32-84B0-E819D88A70E0}C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe => No File
FirewallRules: [UDP Query User{D48F9F75-6B2E-4094-9051-3EEF62A29FE1}C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe => No File
FirewallRules: [{1DA563F9-8F28-4085-9D23-2E0A03D8EC26}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE (CyberLink Corp. -> CyberLink Corp.)
FirewallRules: [TCP Query User{EE175E9E-556D-4C29-8E52-992A95F9A6CE}C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe] => (Block) C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe => No File
FirewallRules: [UDP Query User{E442E7B3-7B13-4BDA-B26D-0F28D846A538}C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe] => (Block) C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe => No File
 
==================== Restore Points =========================
 
15-07-2020 02:00:26 Windows Modules Installer
 
==================== Faulty Device Manager Devices ============
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (07/15/2020 06:35:10 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Unexpected conflict discarding   20 1.0.0.127.in-addr.arpa. PTR HPPavilion-2.local.
 
Error: (07/15/2020 06:35:10 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 127.0.0.1:5353   18 1.0.0.127.in-addr.arpa. PTR HPPavilion.local.
 
Error: (07/15/2020 06:35:10 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Unexpected conflict discarding   20 A.4.0.1.E.D.2.D.5.C.E.C.6.7.9.6.0.0.0.0.0.0.0.0.0.0.0.0.0.8.E.F.ip6.arpa. PTR HPPavilion-2.local.
 
Error: (07/15/2020 06:35:10 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from FE80:0000:0000:0000:6976:CEC5:D2DE:104A:5353   18 A.4.0.1.E.D.2.D.5.C.E.C.6.7.9.6.0.0.0.0.0.0.0.0.0.0.0.0.0.8.E.F.ip6.arpa. PTR HPPavilion.local.
 
Error: (07/15/2020 06:35:10 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Local Hostname HPPavilion.local already in use; will try HPPavilion-2.local instead
 
Error: (07/15/2020 06:35:10 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: ProbeCount 2; will deregister   16 HPPavilion.local. AAAA FE80:0000:0000:0000:6976:CEC5:D2DE:104A
 
Error: (07/15/2020 06:35:10 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from FE80:0000:0000:0000:6976:CEC5:D2DE:104A:5353    4 HPPavilion.local. Addr 192.168.0.149
 
Error: (07/15/2020 06:35:10 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Ignoring response received before we even began probing:   16 HPPavilion.local. AAAA FE80:0000:0000:0000:6976:CEC5:D2DE:104A
 
 
System errors:
=============
Error: (07/15/2020 02:00:20 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80240017: Update for Windows Defender Antivirus antimalware platform - KB4052623 (Version 4.18.2001.10).
 
Error: (07/15/2020 12:00:13 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: The server {F3B4E234-7A68-4E43-B813-E4BA55A065F6} did not register with DCOM within the required timeout.
 
Error: (07/14/2020 11:24:51 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: The server {A47979D2-C419-11D9-A5B4-001185AD2B89} did not register with DCOM within the required timeout.
 
Error: (07/14/2020 11:23:47 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: The Printer Extensions and Notifications service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.
 
Error: (07/14/2020 11:22:51 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Network List Service service terminated with the following error: 
The device is not ready.
 
Error: (07/14/2020 11:22:46 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: The server {A47979D2-C419-11D9-A5B4-001185AD2B89} did not register with DCOM within the required timeout.
 
Error: (07/14/2020 11:20:46 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Network List Service service terminated with the following error: 
The device is not ready.
 
 
==================== Memory info =========================== 
 
BIOS: AMI 8.06 09/07/2012
Motherboard: PEGATRON CORPORATION 2AF0
Processor: AMD E1-1200 APU with Radeon™ HD Graphics
Percentage of memory in use: 65%
Total physical RAM: 3665.86 MB
Available physical RAM: 1252.27 MB
Total Virtual: 4065.86 MB
Available Virtual: 542.55 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:442.96 GB) (Free:368.21 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (Recovery Image) (Fixed) (Total:19.78 GB) (Free:2.48 GB) NTFS ==>[system with boot components (obtained from drive)]
 
\\?\Volume{02f74654-436d-45c5-a86d-fd54f1779603}\ (Windows RE tools) (Fixed) (Total:1 GB) (Free:0.66 GB) NTFS
\\?\Volume{1b95caa0-c5be-4e62-8d02-4cc02dfc934c}\ () (Fixed) (Total:0.54 GB) (Free:0.08 GB) NTFS
\\?\Volume{d1de863d-cf84-4d64-8ee1-9cebae5d4872}\ () (Fixed) (Total:1 GB) (Free:0.66 GB) NTFS
\\?\Volume{637f704c-e0b6-4d87-aedf-878d4ed48896}\ (SYSTEM) (Fixed) (Total:0.35 GB) (Free:0.31 GB) FAT32
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 4A1F8D9C)
 
Partition: GPT.
 
==================== End of Addition.txt =======================

  • 0

#55
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 2,665 posts

Hi, Joseph!

 

What you do for your friend is amazing!

 

I will review the logs and be back to you as soon as my fixes are approved.

 

From what I see in the new logs, we have Windows Defender antivirus enabled!


  • 0

Advertisements


#56
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 2,665 posts
Hi, Joseph.

Can I ask you if you installed Norton Studio again? We uninstalled it at the very beginning of the procedure and now it is shown in the logs again.

1. Uninstall two Windows applications
  • Click on Start button and find the following application:
    Norton Studio
  • Right click and select uninstall.
  • Do the same for the following application:
    Getting Started with Windows 8
  • Restart the computer.
2. Use Norton Removal Tool
  • Download Norton Remove and Reinstall tool. Save it on the Desktop.
  • Double-click the NRnR icon.
  • Read the license agreement, and click Agree.
  • Click Advanced Options.
  • Click Remove Only.
  • Click Remove.
  • Click Restart Now.
 
3. Uninstall Palltalk
We uninstalled the Messenger, but there is still a Paltalk program in the computer. We will reinstall the programs at the end of the procedure.
  • Press the Windows Key + R.
  • Type appwiz.cpl in the Run box and click OK.
  • The Add/Remove Programs list will open. Locate the following program on the list:
Paltalk
  • Select the above program and click Uninstall.
  • Restart the computer.
4. Fresh FRST logs
  • Double-click on the FRST icon to run it, as you did before. When the tool opens click Yes to disclaimer.
  • Press Scan button and wait for a while.
  • The scanner will produced two logs on your Desktop: FRST.txt and Addition.txt.
  • Please copy and paste the content of these two logs in your next reply.
 
In your next reply please post:
The new FRST and Addition text files
  • 0

#57
whittakerjr

whittakerjr

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts
Thank you for your kind words.  it is like why you help people who have issues with computers.  She is one of those people that gets taken advantage of, and has some physical issue that I don't mind working with.  
 
I only updated the operating system, Not sure when Norton was re-activated. 
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-07-2020 01
Ran by HP Pavilion (administrator) on HPPAVILION (Hewlett-Packard 20-b010) (15-07-2020 21:38:48)
Running from C:\Users\HP Pavilion\Desktop
Loaded Profiles: HP Pavilion
Platform: Windows 10 Home Version 2004 19041.388 (X64) Language: English (United States)
Default browser: IE
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Advanced Micro Devices, Inc.) [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Andrea Electronics -> Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <9>
(Logitech -> Logitech, Inc.) C:\Program Files\Logitech\SolarApp\L4301_Solar.exe
(Logitech Inc -> Logitech) C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\HP Pavilion\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2007.4-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2007.4-0\NisSrv.exe
(Realtek Semiconductor Corp -> Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6844560 2013-11-19] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942232 2016-10-14] (Logitech -> Logitech, Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-21] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27784672 2017-06-27] (Skype Software Sarl -> Skype Technologies S.A.)
HKLM\...\Print\Monitors\HP 7112 Status Monitor: C:\WINDOWS\system32\hpinksts7112LM.dll [328704 2014-03-03] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Co.)
HKLM\...\Print\Monitors\HP Universal Port Monitor: C:\WINDOWS\system32\hpbprtmon.dll [355840 2012-07-24] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\83.0.4103.116\Installer\chrmstp.exe [2020-06-25] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.81\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
 
==================== Scheduled Tasks (Whitelisted) ============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0DC0DAD2-F84F-429D-B085-411AE7CDE2D5} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4F47-879B-29A80C355D61}
Task: {10AD99B1-9990-4C73-B8E9-E6EA376A9E3D} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload => {EBF00FCB-0769-4B81-9BEC-6C05514111AA}
Task: {145EF7F4-ECD0-4CD6-B44D-E92EFEB7BDDB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {287EB61E-849D-44F1-BF41-56B2A8081F95} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDFE067B1}
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\WINDOWS\System32\AutoWorkplace.exe
Task: {426C84D3-5DF0-4CC8-9486-251CC5F877B1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe
Task: {5A3FB241-0B11-4EA5-BC66-0D9F1B406040} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\BthSQM => {C8367320-6F85-11E0-A1F0-0800200C9A66} C:\WINDOWS\System32\BthTelemetry.dll [30208 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
Task: {69A9BED9-2695-4FA6-ABEF-DB9C7F40DC6B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task => {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Task: {7604A2BD-B1C7-4591-A0BB-AFA960B6026A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe
Task: {7B857988-3067-4E13-8891-998F430972F7} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316}
Task: {8447F5E5-2A40-44ED-869F-2FD08F7AF3E9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {849B52C8-C3E4-4267-B904-989667E7243C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.4-0\MpCmdRun.exe [516768 2020-07-15] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task => {1B1F472E-3221-4826-97DB-2C2324D389AE}
Task: {878F7985-E9A4-4DF2-8C57-79AE45F39B8D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.4-0\MpCmdRun.exe [516768 2020-07-15] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {8CA68387-B3CC-41B5-88D5-240C7A3E7715} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_CN49ADX0R9_backup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe
Task: {9768ABD2-EB67-498E-A669-15A536AF817A} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969}
Task: {BE50A7CB-4761-4560-99C3-95A759AD3012} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.4-0\MpCmdRun.exe [516768 2020-07-15] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C2D92648-7FFA-4B4E-BE32-ABCB7F598804} - System32\Tasks\{A7827154-50C7-4867-ADFD-1E8E30D0C7A2} => "c:\program files\internet explorer\iexplore.exe" hxxps://ui.skype.com/ui/0/7.33.0.105/en/abandoninstall?source=lightinstaller&page=tsMain
Task: {C415FE0E-DDCB-44E0-A459-B9164B72424B} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43DA-BFD7-FBEEA2180A1E}
Task: {CA019DD0-822D-49E1-A2FF-1991CECD8F38} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {CE2DE968-E342-40D7-9566-427D45E4A886} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40B4-8963-D3C761B18371}
Task: {DCB2E700-2511-45D2-B218-AE8BA4967108} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP SoftPaq Installer => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF_Tasks.exe
Task: {F896594B-E18E-4017-85DF-369B4D6F995D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.4-0\MpCmdRun.exe [516768 2020-07-15] (Microsoft Windows Publisher -> Microsoft Corporation)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{29B5CF79-3278-41A1-86F5-B3673D2C956F}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{CBC4812E-DD0B-4C8B-9F7F-46C2962A294B}: [DhcpNameServer] 192.168.0.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPDSK13/1
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.msn.com/?PC=UF01
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPDSK13/1
SearchScopes: HKU\S-1-5-21-176138252-3860332429-2761773572-1018 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = 
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
 
FireFox:
========
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll [2012-05-25] (Yahoo! Inc. -> Yahoo! Inc.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [No File]
 
Chrome: 
=======
CHR Profile: C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default [2020-07-15]
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Extension: (Slides) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-01-19]
CHR Extension: (Docs) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-19]
CHR Extension: (Google Drive) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-27]
CHR Extension: (YouTube) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-27]
CHR Extension: (Google Search) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-27]
CHR Extension: (Sheets) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-19]
CHR Extension: (Google Docs Offline) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-06-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-05]
CHR Extension: (Gmail) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-29]
CHR Extension: (Chrome Media Router) - C:\Users\HP Pavilion\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-06-16]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [255472 2015-10-21] (Microsoft Windows Hardware Compatibility Publisher -> AMD)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-07-04] (Advanced Micro Devices, Inc.) [File not signed]
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2468496 2013-11-19] (Realtek Semiconductor Corp -> Realsil Microelectronics Inc.)
R2 L4301_Solar; C:\Program Files\Logitech\SolarApp\L4301_Solar.exe [405744 2013-01-30] (Logitech -> Logitech, Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6933272 2020-06-16] (Malwarebytes Inc -> Malwarebytes)
R2 nebula; C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe [4477576 2018-06-18] (Logitech Inc -> Logitech)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.4-0\NisSrv.exe [2169568 2020-07-15] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.4-0\MsMpEng.exe [128376 2020-07-15] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WirelessKB850NotificationService; C:\WINDOWS\system32\WirelessKB850NotificationService.exe [176632 2018-05-14] (Microsoft Corporation -> Microsoft Corporation)
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [21648880 2015-10-21] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [674288 2015-10-21] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R1 CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink -> CyberLink)
R3 dc3d; C:\WINDOWS\System32\drivers\dc3d.sys [47616 2011-05-18] (Hardware Group Test Cert -> Microsoft Corporation)
S3 GKUPRO2D; C:\WINDOWS\System32\drivers\GKUPRO2D.sys [120320 2012-11-05] (Microsoft Windows Hardware Compatibility Publisher -> Gemalto)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [216056 2020-07-15] (Malwarebytes Inc -> Malwarebytes)
R0 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248968 2020-06-16] (Malwarebytes Inc -> Malwarebytes)
R3 netr28x; C:\WINDOWS\System32\drivers\netr28x.sys [2537984 2019-12-07] (Microsoft Windows -> MediaTek Inc.)
R3 usbfilter; C:\WINDOWS\System32\drivers\usbfilter.sys [56448 2012-03-30] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [78216 2020-07-15] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [430312 2020-07-15] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [98536 2020-07-15] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessKeyboardFilter; C:\WINDOWS\System32\drivers\WirelessKeyboardFilter.sys [49336 2018-03-11] (Microsoft Corporation -> Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) ===================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2020-07-15 21:35 - 2020-07-15 21:35 - 000216056 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2020-07-15 21:12 - 2020-07-15 21:12 - 012787656 _____ (NortonLifeLock Inc.) C:\Users\HP Pavilion\Downloads\NRnR (1).exe
2020-07-15 21:11 - 2020-07-15 21:11 - 012787656 _____ (NortonLifeLock Inc.) C:\Users\HP Pavilion\Desktop\NRnR.exe
2020-07-15 07:01 - 2020-07-15 07:10 - 000025390 _____ C:\Users\HP Pavilion\Desktop\Addition.txt
2020-07-15 06:50 - 2020-07-15 21:42 - 000016631 _____ C:\Users\HP Pavilion\Desktop\FRST.txt
2020-07-15 06:43 - 2020-07-15 06:45 - 000003380 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-176138252-3860332429-2761773572-1018
2020-07-15 06:41 - 2020-07-15 06:41 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\Comms
2020-07-15 06:38 - 2020-07-15 06:38 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2020-07-15 06:38 - 2020-07-15 06:38 - 000000000 ____D C:\ProgramData\ATI
2020-07-15 00:03 - 2020-07-14 23:47 - 000000000 ____D C:\Windows.old
2020-07-14 23:52 - 2020-07-14 23:52 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\Publishers
2020-07-14 23:50 - 2020-07-15 06:46 - 000000000 ____D C:\ProgramData\Packages
2020-07-14 23:50 - 2020-07-14 23:50 - 000000000 ___RD C:\Users\HP Pavilion\3D Objects
2020-07-14 23:48 - 2020-07-14 23:50 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\ConnectedDevicesPlatform
2020-07-14 23:48 - 2020-07-14 23:48 - 000000020 ___SH C:\Users\HP Pavilion\ntuser.ini
2020-07-14 23:45 - 2020-07-15 21:35 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-07-14 23:45 - 2020-07-15 01:59 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2020-07-14 23:45 - 2020-07-14 23:46 - 000003250 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2020-07-14 23:45 - 2020-07-14 23:46 - 000003204 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-07-14 23:45 - 2020-07-14 23:46 - 000002810 _____ C:\WINDOWS\system32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-176138252-3860332429-2761773572-1018
2020-07-14 23:45 - 2020-07-14 23:46 - 000002810 _____ C:\WINDOWS\system32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-176138252-3860332429-2761773572-1001
2020-07-14 23:45 - 2020-07-14 23:46 - 000002112 _____ C:\WINDOWS\system32\Tasks\{A7827154-50C7-4867-ADFD-1E8E30D0C7A2}
2020-07-14 23:45 - 2020-07-14 23:45 - 000003022 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2020-07-14 23:45 - 2020-07-14 23:45 - 000002976 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-07-14 23:45 - 2020-07-14 23:45 - 000002942 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{2B2239C5-296B-46AF-9192-8557E01C177E}
2020-07-14 23:45 - 2020-07-14 23:45 - 000000000 ____D C:\WINDOWS\system32\Tasks\WPD
2020-07-14 23:45 - 2020-07-14 23:45 - 000000000 ____D C:\WINDOWS\system32\Tasks\Remediation
2020-07-14 23:45 - 2020-07-14 23:45 - 000000000 ____D C:\WINDOWS\system32\Tasks\Hewlett-Packard
2020-07-14 23:45 - 2020-07-14 23:45 - 000000000 ____D C:\WINDOWS\system32\Tasks\{3572C762-1A49-A2DF-ED84-168A6500F9A0}
2020-07-14 23:43 - 2020-07-14 23:45 - 000011433 _____ C:\WINDOWS\diagwrn.xml
2020-07-14 23:43 - 2020-07-14 23:45 - 000011433 _____ C:\WINDOWS\diagerr.xml
2020-07-14 23:40 - 2020-07-15 00:03 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2020-07-14 23:40 - 2020-07-14 23:41 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2020-07-14 23:36 - 2020-07-15 21:41 - 000934858 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-07-14 23:35 - 2020-07-14 23:35 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2020-07-14 23:35 - 2020-07-14 23:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2020-07-14 23:23 - 2020-07-15 06:45 - 000002421 _____ C:\Users\HP Pavilion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-07-14 23:23 - 2020-07-14 23:50 - 000000000 ____D C:\Users\HP Pavilion
2020-07-14 23:23 - 2020-07-14 23:39 - 000000000 ____D C:\Users\Joanne Endevoets
2020-07-14 23:23 - 2020-07-14 23:12 - 002876416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2020-07-14 23:23 - 2019-12-07 02:10 - 000001105 _____ C:\Users\Joanne Endevoets\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-07-14 23:17 - 2020-07-14 23:17 - 011490816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 009493504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 004465664 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2020-07-14 23:17 - 2020-07-14 23:17 - 003364864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2020-07-14 23:17 - 2020-07-14 23:17 - 001583616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe
2020-07-14 23:17 - 2020-07-14 23:17 - 000967680 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000937472 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000742912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapi.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000690176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSCOMEX.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000588288 _____ (Microsoft Corporation) C:\WINDOWS\system32\msra.exe
2020-07-14 23:17 - 2020-07-14 23:17 - 000553984 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000514560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000503808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FXSCOMEX.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000478208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Picker.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000441344 _____ (Microsoft Corporation) C:\WINDOWS\system32\WalletService.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000421376 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000352256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapibase.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000351232 _____ (Microsoft Corporation) C:\WINDOWS\system32\APHostService.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000338944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Picker.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000288256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ConsoleLogon.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpdxm.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpdxm.dll
2020-07-14 23:17 - 2020-07-14 23:17 - 000078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModelOOBE.exe
2020-07-14 23:17 - 2020-07-14 23:17 - 000055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeUISrv.exe
2020-07-14 23:16 - 2020-07-14 23:16 - 024264704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 019868672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 018766336 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 018068992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 008188928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 007534160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 007070208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 006404608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 005821952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 005337504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 004783328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 003859456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 003547280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 003431424 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2020-07-14 23:16 - 2020-07-14 23:16 - 002685440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 002520048 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 002202624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVidCtl.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 002193736 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001956016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001704960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmcndmgr.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001686528 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001470976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001411072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmc.exe
2020-07-14 23:16 - 2020-07-14 23:16 - 001357312 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMNetMgr.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001352232 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001337856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001312256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001301592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001246720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001111552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMNetMgr.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloSI.PCShell.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001014872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 001005056 _____ (Microsoft Corporation) C:\WINDOWS\system32\tapi3.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000991744 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebcamUi.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000961192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000859136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imapi2fs.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000854016 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000850944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tapi3.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000843264 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicExtensions.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000837120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000832512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdosys.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000814592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebcamUi.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000804352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000784896 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000746808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000742400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000676560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000673792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000666624 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000611840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000600616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000598528 _____ (Microsoft Corporation) C:\WINDOWS\system32\psisdecd.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000580096 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr
2020-07-14 23:16 - 2020-07-14 23:16 - 000579072 _____ (Microsoft® Windows® Operating System) C:\WINDOWS\system32\wvc.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000568832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wiaaut.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000562688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000556544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000549888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000534016 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2020-07-14 23:16 - 2020-07-14 23:16 - 000530440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr
2020-07-14 23:16 - 2020-07-14 23:16 - 000498688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\azroles.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000485888 _____ (Microsoft Corporation) C:\WINDOWS\system32\msTextPrediction.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000484352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\psisdecd.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000474112 _____ (Microsoft® Windows® Operating System) C:\WINDOWS\SysWOW64\wvc.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsregcmd.exe
2020-07-14 23:16 - 2020-07-14 23:16 - 000453952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAudDecMFT.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000453632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsettingsprovider.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2020-07-14 23:16 - 2020-07-14 23:16 - 000435200 _____ (Microsoft Corporation) C:\WINDOWS\system32\termmgr.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000428544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mswmdm.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000423936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000423224 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imapi2.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MixedReality.Broker.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000419840 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000413208 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000398848 _____ (Microsoft Corporation) C:\WINDOWS\system32\qdvd.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000361472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\termmgr.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000359936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iassdo.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswmdm.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000343992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\VAN.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnphost.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000323072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LocationApi.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000300032 _____ (Microsoft Corporation) C:\WINDOWS\system32\CXHProvisioningServer.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WlanMM.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000267776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000266240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mpg2splt.ax
2020-07-14 23:16 - 2020-07-14 23:16 - 000264192 _____ (Microsoft Corporation) C:\WINDOWS\system32\wavemsp.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000249856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VAN.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\FileHistory.exe
2020-07-14 23:16 - 2020-07-14 23:16 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\RdpRelayTransport.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloShellRuntime.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wavemsp.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mpg2splt.ax
2020-07-14 23:16 - 2020-07-14 23:16 - 000204000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityCenterBroker.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagSvc.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000202752 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmidx.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000189440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
2020-07-14 23:16 - 2020-07-14 23:16 - 000180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\HoloShellRuntime.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dialclient.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Clipboard.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintWSDAHost.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cic.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000146944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmidx.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000142848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkspbrokerAx.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Feedback.Analog.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasrecst.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000127488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdWSD.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000123392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintWSDAHost.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imapi.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000110512 _____ (Microsoft Corporation) C:\WINDOWS\system32\devenum.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000107520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasnap.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkspbrokerAx.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFolders.exe
2020-07-14 23:16 - 2020-07-14 23:16 - 000101288 _____ (Microsoft Corporation) C:\WINDOWS\system32\FsIso.exe
2020-07-14 23:16 - 2020-07-14 23:16 - 000100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmjpegdec.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000093952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devenum.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmjpegdec.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000072704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2020-07-14 23:16 - 2020-07-14 23:16 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\udhisapi.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MiracastReceiverExt.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasads.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000041864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityCenterBrokerPS.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnpcont.exe
2020-07-14 23:16 - 2020-07-14 23:16 - 000028384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SecurityCenterBrokerPS.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimsg.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll
2020-07-14 23:16 - 2020-07-14 23:16 - 000024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 026271744 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 023433216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 008892600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 007756288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 007593472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 005964496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 005420648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 004880384 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 003812304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 003332608 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 002827776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2020-07-14 23:15 - 2020-07-14 23:15 - 002744320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2020-07-14 23:15 - 2020-07-14 23:15 - 002631008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 002413056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmcndmgr.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001952392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001912320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmc.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 001714176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001654824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001640888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001606656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001588224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Perception.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001557824 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 001449280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001448448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001353216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001320448 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagperf.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001315328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001257472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001255744 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 001233408 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001230848 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdclt.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 001218560 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdengin2.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001090560 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001078784 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdosys.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001041408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001022976 _____ (Microsoft Corporation) C:\WINDOWS\system32\CBDHSvc.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001008184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 001004032 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi2fs.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000945664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000942080 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000907456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000897536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windowsperformancerecordercontrol.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000886272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000886272 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000884736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000872448 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000866304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000849920 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000801560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 000798720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000774456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Services.TargetedContent.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000760832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000759608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DismApi.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000758784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000722944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000711680 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000705024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000696240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000687104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000682496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiaaut.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000681472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000673976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 000633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\azroles.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000617472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000612352 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000606880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000602184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryPS.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000583608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StateRepository.Core.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000552448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000546456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\IESettingSync.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 000535552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000523720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StructuredQuery.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000519168 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi2.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000499712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000482616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 000473088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000471040 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnphost.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000466928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MediaControl.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000463360 _____ (Microsoft Corporation) C:\WINDOWS\system32\iassdo.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000443704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000424448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000420936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000409552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000408576 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationApi.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000407864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spwizeng.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000407504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Enumeration.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000402944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000399360 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMM.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000391680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000388096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.LowLevel.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000379392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000368640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000368640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Geolocation.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000355328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTMediaFrame.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000335360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2020-07-14 23:15 - 2020-07-14 23:15 - 000328704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.Workflow.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000311920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000304128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnclient.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000297984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000296448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Diagnostics.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000276992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Lights.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000276480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PickerPlatform.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpviewerax.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovs.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000255488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.CredDialogController.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000247296 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialclient.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
2020-07-14 23:15 - 2020-07-14 23:15 - 000226304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.FileExplorer.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000223544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Dism.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 000221184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bthprops.cpl
2020-07-14 23:15 - 2020-07-14 23:15 - 000217912 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000216064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pku2u.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000215040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Devices.Sensors.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\cic.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000201016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 000195128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000192000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000190048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\logoncli.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000186880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wdigest.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasrecst.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000183296 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000182784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netprofm.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000179000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Management.Workplace.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\intl.cpl
2020-07-14 23:15 - 2020-07-14 23:15 - 000176440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CapabilityAccessManagerClient.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdWSD.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ErrorDetails.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdrsvc.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000151864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasnap.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000142000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmcmnutils.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintWorkflowService.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Energy.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdshext.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msaatext.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000117048 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.SerialCommunication.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000099640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryBroker.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EaseOfAccessDialog.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 000095032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2020-07-14 23:15 - 2020-07-14 23:15 - 000092952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WwanRadioManager.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2020-07-14 23:15 - 2020-07-14 23:15 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sethc.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasads.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000074752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DiagnosticInvoker.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MiracastReceiverExt.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\system32\udhisapi.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\keyiso.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Print.Workflow.Source.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000053760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtutils.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnrollCtrl.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnpcont.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 000042320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryCore.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\CIDiag.exe
2020-07-14 23:15 - 2020-07-14 23:15 - 000030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000021304 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000020632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerEnc.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintWorkflowProxy.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDJPN.DLL
2020-07-14 23:15 - 2020-07-14 23:15 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.Workflow.Native.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000009269 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2020-07-14 23:15 - 2020-07-14 23:15 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kbd106n.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kbd106.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kbd101.DLL
2020-07-14 23:15 - 2020-07-14 23:15 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DMAlertListener.ProxyStub.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimg32.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6r.dll
2020-07-14 23:15 - 2020-07-14 23:15 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2020-07-14 23:14 - 2020-07-14 23:15 - 006356008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 014754816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 010922808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 007593544 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 006920192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 006029312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 005371536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 004734976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 004629328 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 003925856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 003906048 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 003778560 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 003498216 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 002918216 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 002601472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 002568192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 002317312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 002198016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 002177528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 002104320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 002026496 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001978656 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001805184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2020-07-14 23:14 - 2020-07-14 23:14 - 001751424 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001710080 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001695744 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001668904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001641472 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001550336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.3D.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001538136 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 001509736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001477632 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001474048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.PointOfService.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001430528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001400216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001394032 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2020-07-14 23:14 - 2020-07-14 23:14 - 001374720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdprt.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001314120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001303040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001296384 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001286560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001255936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpsharercom.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001253888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001247232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.FaceAnalysis.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001239552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001208832 _____ (Microsoft Corporation) C:\WINDOWS\system32\windowsperformancerecordercontrol.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001197232 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 001126472 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001125888 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001125376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001071224 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001066304 _____ (Microsoft Corporation) C:\WINDOWS\system32\DismApi.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001006592 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001005056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 001001472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000966872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputHost.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000957952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000933176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000912896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MiracastReceiver.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000906528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000903168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000889384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000887296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MdmDiagnostics.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000885760 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000881112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000877056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000876544 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000868352 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofmsvc.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000856328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000831016 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000824328 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000779360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000775768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000748360 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingWinRT.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000733184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BTAGService.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000721024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000720896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000711168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000706048 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000701952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000689664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InkObjCore.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Ocr.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000687616 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockController.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000651776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000640000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\agentactivationruntimewindows.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000634680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicensingWinRT.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000633856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\agentactivationruntime.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000632536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000623960 _____ (Microsoft Corporation) C:\WINDOWS\system32\sechost.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000623392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Perception.Stub.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000619520 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000614912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.ConversationalAgent.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000608256 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000607744 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000595512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.applicationmodel.datatransfer.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000590848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000573752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2020-07-14 23:14 - 2020-07-14 23:14 - 000572928 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000569344 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000568632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000568320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Input.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000563712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000555744 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000551424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000546816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000540672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.SmartCards.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000539960 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000538624 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000528696 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizeng.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000520192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Launcher.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000512512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000508720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000501248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000496128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys
2020-07-14 23:14 - 2020-07-14 23:14 - 000487936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Geolocation.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000487552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000480768 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000476160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.Workflow.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000475704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sechost.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000469936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000464896 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000457728 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockHostingFramework.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000455168 _____ C:\WINDOWS\SysWOW64\WindowManagementAPI.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000445440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.AllJoyn.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000434504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboutSettingsHandlers.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000433152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000429056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000418816 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000412672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.SmartCards.Phone.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Payments.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000405304 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000395600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000388608 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000380416 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000373760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MicrosoftAccountWAMExtension.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000373760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreShellAPI.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000360960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.WiFiDirect.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000340992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000335360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AarSvc.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000332288 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpviewerax.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.CredDialogController.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpr.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000319808 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostBroker.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000317952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2020-07-14 23:14 - 2020-07-14 23:14 - 000313152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemSettings.DataModel.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RASMM.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000303616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000290816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Preview.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000286720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000285496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Dism.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000281088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000280064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.NetworkOperators.ESim.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000277504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000272896 _____ (Microsoft Corporation) C:\WINDOWS\system32\InkEd.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.FileExplorer.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000260288 _____ (Microsoft Corporation) C:\WINDOWS\system32\logoncli.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000253016 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000248320 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Gpu.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000245248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\intl.cpl
2020-07-14 23:14 - 2020-07-14 23:14 - 000233984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000232448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InkEd.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000230912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncSettings.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000229376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofm.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000227640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdigest.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000195240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcmnutils.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000191488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000183296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Graphics.Display.DisplayColorManagement.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000181760 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintWorkflowService.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000180024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2020-07-14 23:14 - 2020-07-14 23:14 - 000171024 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\msaatext.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000163208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\coreglobconfig.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000162816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDeviceRegistration.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Core.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\useractivitybroker.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.Client.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000146432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Graphics.Display.DisplayEnhancementManagement.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppExtension.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000134968 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000133744 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpapi.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000131072 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptcatsvc.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\CaptureService.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000126976 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkStatus.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000126976 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAMM.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000116736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AxInstSv.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleprn.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssitlb.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.Authentication.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CameraCaptureUI.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\keyiso.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000086784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Credentials.UI.CredentialPicker.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\RpcEpMap.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Print.Workflow.Source.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkInternalPS.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\atl.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtutils.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000067072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.internal.shellcommon.AccountsControlExperience.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemUWPLauncher.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000061752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GameInput.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AxInstUI.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssprxy.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagnosticdataquery.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000052664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ResourcePolicyClient.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000049664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\npmproxy.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000040248 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkPS.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIMgrBroker.exe
2020-07-14 23:14 - 2020-07-14 23:14 - 000037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\atlthunk.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmproxy.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintWorkflowProxy.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000024288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerEnc.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\slcext.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmsprep.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slcext.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.Workflow.Native.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDJPN.DLL
2020-07-14 23:14 - 2020-07-14 23:14 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIManagerBrokerps.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMAlertListener.ProxyStub.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000008704 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbd106n.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000008704 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbd106.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000008704 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbd101.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimg32.dll
2020-07-14 23:14 - 2020-07-14 23:14 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 017540608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 010336896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 009034752 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 007992824 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 007964416 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 006709248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 006175232 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 006069888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 006060544 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 005858128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 005766168 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 004485216 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 003860480 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 003810816 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2020-07-14 23:13 - 2020-07-14 23:13 - 003779896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2020-07-14 23:13 - 2020-07-14 23:13 - 003752448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Service.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 003749376 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 003380736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 003304960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 003299840 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002974720 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002963456 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2020-07-14 23:13 - 2020-07-14 23:13 - 002647040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002631168 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002585912 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002566144 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002466864 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002399744 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002338304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Perception.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002311680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002305024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002286128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002245632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002131024 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002077696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 002040832 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShell.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001876480 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001858560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001784488 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001766912 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdprt.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001712128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001705472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001701368 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001530880 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001507328 _____ (Microsoft Corporation) C:\WINDOWS\system32\MoUsoCoreWorker.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 001495552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001493504 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpsharercom.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001491968 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001473024 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 001473024 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001422336 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001414144 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 001403904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.FaceAnalysis.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001378568 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputHost.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001359872 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsf3gip.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001337168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryPS.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001323008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001305600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001257472 _____ (Microsoft Corporation) C:\WINDOWS\system32\MiracastReceiver.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001222656 _____ (Microsoft Corporation) C:\WINDOWS\system32\SEMgrSvc.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001207296 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001204968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 001195520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001182008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Services.TargetedContent.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001145344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001114112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001105408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001082168 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001069056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Signals.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001058816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001048480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Perception.Stub.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001047552 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 001043456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Ocr.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000994248 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000975672 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000968192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\InkObjCore.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000937464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000935936 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000914200 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000908288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000902976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2020-07-14 23:13 - 2020-07-14 23:13 - 000833024 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000830464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000824832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Input.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000804864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000802816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000799552 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.applicationmodel.datatransfer.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000791552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000784896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000764456 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000753152 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.immersiveshell.serviceprovider.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000725600 _____ (Microsoft Corporation) C:\WINDOWS\system32\StateRepository.Core.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000704496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000683008 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000677888 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000676088 _____ (Microsoft Corporation) C:\WINDOWS\system32\StructuredQuery.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000670208 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000657920 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000646656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000644096 _____ C:\WINDOWS\system32\WindowManagementAPI.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000635824 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000614912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000608768 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000597504 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicesFlowBroker.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000596992 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2020-07-14 23:13 - 2020-07-14 23:13 - 000596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.LowLevel.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Payments.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000583168 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000565760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.Phone.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000565760 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000560400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000556032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000541696 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountWAMExtension.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000539256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Enumeration.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000534016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Activities.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Narrator.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000531456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64win.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000522040 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000508416 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTMediaFrame.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000504832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000488448 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000486912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000475648 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShellAPI.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000475136 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinDataModelServer.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000454968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2020-07-14 23:13 - 2020-07-14 23:13 - 000449536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wksprt.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000430592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountExtension.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000428680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000423424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000423224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DataModel.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000418816 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000398848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.NetworkOperators.ESim.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SpeechPrivacy.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Lights.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000389952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManager.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000388096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Preview.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000386048 _____ (Microsoft Corporation) C:\WINDOWS\system32\PickerPlatform.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000380632 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialEnrollmentManager.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000373064 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000370688 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuickActionsDataModel.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000367104 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnclient.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000362496 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicSvc.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000355328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Diagnostics.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Cortana.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000326144 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000321024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000319488 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultcli.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000316416 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.internal.shellcommon.shareexperience.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Devices.Sensors.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.HumanInterfaceDevice.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000283136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000281088 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000272384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthprops.cpl
2020-07-14 23:13 - 2020-07-14 23:13 - 000265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\PasswordEnrollmentManager.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicCapsule.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Graphics.Display.DisplayColorManagement.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000249656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000249656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Workplace.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000247296 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000242688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManagerClient.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.CapturePicker.Desktop.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeopleBand.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000222720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Core.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\MtcModel.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000220160 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000215896 _____ (Microsoft Corporation) C:\WINDOWS\system32\coreglobconfig.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000214840 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SIUF.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000214016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppExtension.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000203976 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsBroker.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ErrorDetails.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\useractivitybroker.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000183296 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3mm.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000181248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Energy.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000173056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.CapturePicker.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Graphics.Display.DisplayEnhancementManagement.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SerialCommunication.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000148280 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResourcePolicyServer.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000146944 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000143160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys
2020-07-14 23:13 - 2020-07-14 23:13 - 000140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Storage.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredDialogBroker.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000132728 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000131896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000131072 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssitlb.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000131072 _____ (Microsoft Corporation) C:\WINDOWS\system32\CameraCaptureUI.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\EaseOfAccessDialog.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000118072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000116024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000113112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Credentials.UI.CredentialPicker.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\sethc.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthRadioMedia.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairingExperienceMEM.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\bindfltapi.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagnosticInvoker.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\atl.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicAgent.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.internal.shellcommon.AccountsControlExperience.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\UsoClient.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemUWPLauncher.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000076992 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialEnrollmentManagerForUser.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000071792 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResourcePolicyClient.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000070968 _____ (Microsoft Corporation) C:\WINDOWS\system32\GameInput.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000068608 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanRadioManager.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnrollCtrl.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000064840 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthHost.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000064016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryCore.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\NfcRadioMedia.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MdmDiagnosticsTool.exe
2020-07-14 23:13 - 2020-07-14 23:13 - 000044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.Common.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\atlthunk.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicPS.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
2020-07-14 23:13 - 2020-07-14 23:13 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6r.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 001869312 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 001762632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 001556480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 001540096 _____ (Microsoft Corporation) C:\WINDOWS\system32\TaskFlowDataEngine.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 001250816 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 001150752 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2020-07-14 23:12 - 2020-07-14 23:12 - 001021440 _____ (Microsoft Corporation) C:\WINDOWS\system32\BTAGService.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 001001984 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcRefreshTask.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Service.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000884224 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000879104 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntimewindows.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000858624 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntime.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000799232 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2020-07-14 23:12 - 2020-07-14 23:12 - 000781312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.ConversationalAgent.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000678200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2020-07-14 23:12 - 2020-07-14 23:12 - 000601400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2020-07-14 23:12 - 2020-07-14 23:12 - 000577392 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000506672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000439296 _____ (Microsoft Corporation) C:\WINDOWS\system32\AarSvc.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000436224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000287232 _____ (Microsoft Corporation) C:\WINDOWS\system32\netman.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000287232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceDirectoryClient.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcTok.exe
2020-07-14 23:12 - 2020-07-14 23:12 - 000215864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spacedump.sys
2020-07-14 23:12 - 2020-07-14 23:12 - 000202752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBAUDIO.sys
2020-07-14 23:12 - 2020-07-14 23:12 - 000198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Internal.Input.ExpressiveInput.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000159032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2020-07-14 23:12 - 2020-07-14 23:12 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleprn.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2020-07-14 23:12 - 2020-07-14 23:12 - 000069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxGipRadioManager.dll
2020-07-14 23:12 - 2020-07-14 23:12 - 000013312 _____ C:\WINDOWS\system32\agentactivationruntimestarter.exe
2020-07-14 23:05 - 2020-07-15 20:57 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-07-14 23:05 - 2020-07-14 23:05 - 000275400 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-07-14 23:04 - 2020-07-15 21:35 - 000008192 ___SH C:\DumpStack.log.tmp
2020-07-14 22:58 - 2019-12-06 22:30 - 000099840 _____ (Microsoft Corporation) C:\WINDOWS\system32\XPSSHHDR.dll
2020-07-14 22:58 - 2019-12-06 22:22 - 000883200 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsFilt.dll
2020-07-14 22:58 - 2019-12-06 20:49 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XPSSHHDR.dll
2020-07-14 22:58 - 2019-12-06 20:38 - 000561664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsFilt.dll
2020-07-14 22:58 - 2019-10-15 14:53 - 000076060 _____ C:\WINDOWS\system32\xpsrchvw.xml
2020-07-14 22:58 - 2019-04-18 19:49 - 000076060 _____ C:\WINDOWS\SysWOW64\xpsrchvw.xml
2020-07-14 22:40 - 2020-07-14 22:40 - 000000000 ____D C:\Program Files\Reference Assemblies
2020-07-14 22:40 - 2020-07-14 22:40 - 000000000 ____D C:\Program Files\MSBuild
2020-07-14 22:40 - 2020-07-14 22:40 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2020-07-14 22:40 - 2020-07-14 22:40 - 000000000 ____D C:\Program Files (x86)\MSBuild
2020-07-14 22:40 - 2020-07-14 22:40 - 000000000 ____D C:\inetpub
2020-07-14 22:38 - 2019-12-03 15:04 - 000781384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2020-07-14 22:38 - 2019-12-03 15:04 - 000105544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2020-07-14 22:38 - 2019-12-03 15:04 - 000037864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2020-07-14 22:38 - 2019-11-08 15:44 - 001168968 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2020-07-14 22:38 - 2019-11-08 15:44 - 000127056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2020-07-14 22:38 - 2019-11-08 15:44 - 000038072 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2020-07-14 22:37 - 2020-07-14 22:37 - 000495616 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2020-07-14 22:37 - 2020-07-14 22:37 - 000391168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2020-07-14 19:09 - 2020-07-14 23:48 - 000000000 ___DC C:\WINDOWS\Panther
2020-07-14 18:51 - 2020-07-14 19:09 - 000000000 ____D C:\ESD
2020-07-14 18:46 - 2020-07-14 18:46 - 000000000 ___HD C:\$Windows.~WS
2020-07-14 18:44 - 2020-07-14 18:44 - 019468312 _____ (Microsoft Corporation) C:\Users\HP Pavilion\Desktop\MediaCreationTool2004.exe
2020-07-10 22:17 - 2020-07-10 22:17 - 000000000 ____D C:\WINDOWS\pss
2020-07-09 11:34 - 2020-07-09 11:34 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\VirtualStore
2020-07-09 10:08 - 2020-07-09 10:08 - 000000207 _____ C:\WINDOWS\tweaking.com-regbackup-HPPAVILION-Windows-8.1-(64-bit).dat
2020-07-09 10:07 - 2020-07-09 10:07 - 000000000 ____D C:\RegBackup
2020-07-09 09:50 - 2020-07-09 10:06 - 000000000 ____D C:\Users\HP Pavilion\Desktop\Tweaking.com - Windows Repair
2020-07-09 09:23 - 2020-07-09 09:23 - 037198272 _____ C:\Users\HP Pavilion\Downloads\tweaking.com_windows_repair_aio.zip
2020-07-08 08:15 - 2020-07-08 08:15 - 000000480 _____ C:\Users\HP Pavilion\Desktop\fix.reg
2020-07-07 09:04 - 2020-07-07 09:04 - 000006768 _____ C:\Users\HP Pavilion\Desktop\Windows_Defender_Security_Center_Service.reg
2020-07-01 11:17 - 2020-07-01 11:17 - 000008404 _____ C:\Users\HP Pavilion\Desktop\State_Repository_Service.reg
2020-07-01 11:07 - 2020-07-01 11:07 - 000010762 _____ C:\Users\HP Pavilion\Desktop\Windows_Update.reg
2020-07-01 11:04 - 2020-07-14 23:34 - 000002421 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2020-07-01 11:04 - 2020-07-14 23:34 - 000002259 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2020-07-01 11:04 - 2020-07-14 23:34 - 000002259 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk
2020-07-01 10:36 - 2020-07-01 10:36 - 000007572 _____ C:\Users\HP Pavilion\Desktop\Windows_Defender_Service.reg
2020-06-30 08:04 - 2020-06-30 08:04 - 000925696 _____ (Farbar) C:\Users\HP Pavilion\Desktop\FSS.exe
2020-06-30 07:35 - 2020-07-15 21:19 - 000000000 ____D C:\ProgramData\Norton
2020-06-30 06:17 - 2020-06-30 08:19 - 000001861 _____ C:\Users\HP Pavilion\Documents\DISM.txt
2020-06-25 11:53 - 2020-07-14 06:27 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\ESET
2020-06-25 11:53 - 2020-06-25 11:53 - 000000565 _____ C:\Users\HP Pavilion\Desktop\ESET Online Scanner.lnk
2020-06-25 11:51 - 2020-06-25 11:52 - 014827616 _____ (ESET spol. s r.o.) C:\Users\HP Pavilion\Desktop\esetonlinescanner.exe
2020-06-22 07:49 - 2020-06-25 11:42 - 000000000 ____D C:\AdwCleaner
2020-06-22 07:47 - 2020-06-22 07:48 - 008402608 _____ (Malwarebytes) C:\Users\HP Pavilion\Desktop\AdwCleaner.exe
2020-06-20 11:33 - 2020-07-09 12:06 - 000000000 ____D C:\Users\HP Pavilion\Desktop\FRST-OlderVersion
2020-06-20 09:13 - 2020-07-15 00:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2020-06-20 09:13 - 2020-06-20 09:13 - 000001093 _____ C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2020-06-20 09:13 - 2020-06-20 09:13 - 000001093 _____ C:\ProgramData\Desktop\Revo Uninstaller Pro.lnk
2020-06-20 09:13 - 2020-06-20 09:13 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\VS Revo Group
2020-06-20 09:13 - 2020-06-20 09:13 - 000000000 ____D C:\ProgramData\VS Revo Group
2020-06-20 09:13 - 2020-06-20 09:13 - 000000000 ____D C:\Program Files\VS Revo Group
2020-06-20 09:13 - 2016-12-21 14:52 - 000040240 _____ (VS Revo Group) C:\WINDOWS\system32\Drivers\revoflt.sys
2020-06-20 09:11 - 2020-06-20 09:11 - 016926296 _____ (VS Revo Group ) C:\Users\HP Pavilion\Desktop\RevoUninProSetup.exe
2020-06-16 15:03 - 2020-07-15 21:41 - 000000000 ____D C:\FRST
2020-06-16 14:48 - 2020-07-09 12:06 - 002292736 _____ (Farbar) C:\Users\HP Pavilion\Desktop\FRST64.exe
2020-06-16 14:25 - 2020-06-16 14:26 - 000000000 ____D C:\Users\HP Pavilion\Downloads\priortoMalware
2020-06-16 09:43 - 2020-07-01 10:04 - 000000000 ____D C:\Users\HP Pavilion\AppData\LocalLow\IGDump
2020-06-16 09:42 - 2020-06-16 09:42 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\mbam
2020-06-16 09:41 - 2020-06-16 09:41 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2020-06-16 09:41 - 2020-06-16 09:41 - 000001976 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2020-06-16 09:41 - 2020-06-16 09:41 - 000001964 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2020-06-16 09:41 - 2020-06-16 09:41 - 000001964 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2020-06-16 09:41 - 2020-06-16 09:41 - 000000000 ____D C:\ProgramData\Malwarebytes
2020-06-16 09:40 - 2020-06-16 09:40 - 000000000 ____D C:\Program Files\Malwarebytes
2020-06-16 09:40 - 2020-06-16 09:40 - 000000000 ____D C:\Malwarebytes
2020-06-16 09:38 - 2020-06-16 09:38 - 000000000 ____D C:\Users\HP Pavilion\AppData\Roaming\Logitech
2020-06-16 09:38 - 2020-06-16 09:38 - 000000000 ____D C:\Users\HP Pavilion\AppData\Roaming\Logishrd
2020-06-16 09:06 - 2020-07-14 23:33 - 000000000 ____D C:\Program Files\KeyboardNotification
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2020-07-15 21:41 - 2019-12-07 02:13 - 000000000 ____D C:\WINDOWS\INF
2020-07-15 21:38 - 2019-12-07 02:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-07-15 21:34 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-07-15 21:34 - 2019-12-07 02:03 - 000262144 _____ C:\WINDOWS\system32\config\BBI
2020-07-15 21:32 - 2018-01-30 13:25 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\A.V.M
2020-07-15 21:02 - 2016-01-25 16:07 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\Packages
2020-07-15 07:14 - 2016-01-25 16:11 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\AMD
2020-07-15 06:47 - 2019-12-07 02:14 - 000000000 ___HD C:\Program Files\WindowsApps
2020-07-15 06:47 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\ServiceState
2020-07-15 06:45 - 2016-01-30 12:17 - 000000000 ___RD C:\Users\HP Pavilion\OneDrive
2020-07-15 03:31 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\appcompat
2020-07-15 02:04 - 2019-12-07 02:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-07-15 01:58 - 2019-12-07 02:14 - 000000000 ____D C:\Program Files\Windows Defender
2020-07-15 01:50 - 2014-02-04 17:43 - 000744808 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2020-07-15 00:04 - 2019-12-07 02:14 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2020-07-15 00:04 - 2013-08-22 08:36 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2020-07-15 00:03 - 2020-02-12 18:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech Camera Settings
2020-07-15 00:03 - 2019-12-07 02:18 - 000000000 ____D C:\WINDOWS\Setup
2020-07-15 00:03 - 2019-12-07 02:14 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
2020-07-15 00:03 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2020-07-15 00:03 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\IME
2020-07-15 00:03 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\spool
2020-07-15 00:03 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2020-07-15 00:03 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\IME
2020-07-15 00:03 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\Registration
2020-07-15 00:03 - 2019-12-07 02:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2020-07-15 00:03 - 2017-04-10 18:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2020-07-15 00:03 - 2014-11-01 10:22 - 000000000 ____D C:\Program Files (x86)\ATI Technologies
2020-07-15 00:03 - 2014-09-24 02:50 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Embedded Lockdown Manager
2020-07-15 00:03 - 2014-02-20 18:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2020-07-15 00:03 - 2013-11-13 17:07 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-07-15 00:03 - 2013-11-13 16:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yahoo! Messenger
2020-07-15 00:03 - 2013-11-05 15:12 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services
2020-07-15 00:03 - 2013-08-22 08:36 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2020-07-15 00:03 - 2012-09-11 06:45 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2020-07-15 00:03 - 2012-09-11 06:40 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Communication and Chat
2020-07-15 00:03 - 2012-09-11 06:35 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Productivity and Tools
2020-07-15 00:03 - 2012-09-11 06:31 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security and Protection
2020-07-15 00:03 - 2012-09-11 06:28 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
2020-07-15 00:03 - 2012-09-11 06:23 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Music, Photos and Videos
2020-07-15 00:03 - 2012-09-11 06:18 - 000000000 ____D C:\Program Files (x86)\Hewlett-Packard
2020-07-15 00:03 - 2012-08-01 19:05 - 000000000 ____D C:\ProgramData\PRICache
2020-07-15 00:01 - 2019-12-07 02:14 - 000000000 __RHD C:\Users\Public\Libraries
2020-07-14 23:55 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2020-07-14 23:55 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2020-07-14 23:55 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2020-07-14 23:55 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2020-07-14 23:55 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2020-07-14 23:55 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\InputMethod
2020-07-14 23:55 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2020-07-14 23:55 - 2013-08-22 08:36 - 000000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Shared
2020-07-14 23:55 - 2013-08-22 08:36 - 000000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared
2020-07-14 23:53 - 2019-12-07 02:14 - 000000000 ____D C:\ProgramData\USOPrivate
2020-07-14 23:50 - 2013-11-04 19:17 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-07-14 23:49 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2020-07-14 23:47 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-07-14 23:46 - 2019-12-07 02:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2020-07-14 23:40 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\InputMethod
2020-07-14 23:40 - 2014-11-01 10:19 - 000000000 ____D C:\Program Files\Realtek
2020-07-14 23:40 - 2014-11-01 10:18 - 000000000 ____D C:\Program Files\AMD
2020-07-14 23:34 - 2014-11-01 10:19 - 000000000 ____D C:\Program Files\Common Files\logishrd
2020-07-14 23:34 - 2013-11-24 22:54 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-07-14 23:34 - 2013-11-24 22:54 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-07-14 23:34 - 2013-11-24 22:54 - 000002260 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-07-14 23:33 - 2014-11-01 10:19 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2020-07-14 23:32 - 2014-11-01 10:19 - 000000000 ____D C:\AMD
2020-07-14 23:32 - 2013-11-19 18:32 - 000000000 ____D C:\WINDOWS\SysWOW64\sda
2020-07-14 23:30 - 2019-12-07 02:52 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2020-07-14 23:30 - 2019-12-07 02:52 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ___SD C:\WINDOWS\system32\F12
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SystemResources
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\Com
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\DiagTrack
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-07-14 23:30 - 2019-12-07 02:14 - 000000000 ____D C:\Program Files\Common Files\System
2020-07-14 23:30 - 2019-12-07 02:03 - 000000000 ____D C:\WINDOWS\servicing
2020-07-14 23:26 - 2013-11-05 15:10 - 000000000 ____D C:\Users\Joanne Endevoets\AppData\Local\Packages
2020-07-14 23:14 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2020-07-14 23:10 - 2019-12-07 02:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2020-07-14 23:10 - 2019-12-07 02:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2020-07-14 22:58 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2020-07-14 22:58 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2020-07-14 22:40 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2020-07-14 22:40 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\inetsrv
2020-07-14 22:39 - 2019-12-07 02:10 - 000208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2020-07-14 22:39 - 2019-12-07 02:10 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2020-07-14 22:39 - 2019-12-07 02:10 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2020-07-14 22:39 - 2019-12-07 02:10 - 000053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2020-07-14 22:39 - 2019-12-07 02:10 - 000048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2020-07-14 22:39 - 2019-12-07 02:10 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2020-07-14 22:39 - 2019-12-07 02:10 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2020-07-14 22:39 - 2019-12-07 02:10 - 000016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2020-07-14 22:39 - 2019-12-07 02:10 - 000015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2020-07-14 22:39 - 2019-12-07 02:10 - 000014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\cngkeyhelper.dll
2020-07-14 22:39 - 2019-12-07 02:10 - 000013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2020-07-14 22:39 - 2019-12-07 02:10 - 000011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2020-07-14 22:39 - 2019-12-07 02:10 - 000011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cngkeyhelper.dll
2020-07-14 22:39 - 2019-12-07 02:10 - 000009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2020-07-10 22:59 - 2012-09-11 06:21 - 000000000 ____D C:\ProgramData\Hewlett-Packard
2020-07-09 11:13 - 2013-08-22 06:25 - 000000128 _____ C:\WINDOWS\win.ini
2020-07-09 11:05 - 2014-11-01 10:23 - 000006636 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2020-07-08 08:17 - 2015-09-08 17:28 - 000253286 _____ C:\WINDOWS\ntbtlog.txt
2020-07-01 09:49 - 2017-04-06 19:56 - 000000000 ____D C:\Users\HP Pavilion\AppData\Local\CrashDumps
2020-06-29 21:57 - 2013-11-14 19:49 - 000000000 ____D C:\Program Files (x86)\Paltalk Messenger
2020-06-25 11:43 - 2012-08-16 20:14 - 000000000 _RSHD C:\hp
2020-06-25 11:42 - 2016-01-25 16:08 - 000000000 ____D C:\Users\HP Pavilion\AppData\Roaming\Hewlett-Packard
2020-06-25 11:42 - 2013-11-05 17:57 - 000000000 ____D C:\Users\Joanne Endevoets\AppData\Local\Hewlett-Packard
2020-06-25 11:42 - 2013-11-05 15:11 - 000000000 ____D C:\Users\Joanne Endevoets\AppData\Roaming\Hewlett-Packard
2020-06-25 11:42 - 2012-09-11 06:33 - 000000000 ____D C:\Program Files (x86)\CyberLink
2020-06-21 22:46 - 2017-04-13 16:40 - 000000000 ____D C:\Program Files\Common Files\AV
2020-06-21 22:46 - 2013-08-22 06:25 - 000000027 _____ C:\WINDOWS\system32\Drivers\etc\hosts_bak_31
2020-06-16 12:22 - 2013-08-22 08:36 - 000000000 ___RD C:\WINDOWS\ToastData
2020-06-16 11:15 - 2016-01-26 11:34 - 000000000 ____D C:\ProgramData\iolo
2020-06-16 11:15 - 2016-01-26 11:31 - 000000000 ____D C:\Program Files (x86)\iolo
2020-06-16 09:41 - 2016-01-25 16:25 - 000248968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2020-06-16 09:39 - 2020-02-12 18:23 - 000000000 ____D C:\Program Files\Logitech
2020-06-16 09:39 - 2014-02-20 18:51 - 000000000 ____D C:\ProgramData\LogiShrd
 
==================== Files in the root of some directories ========
 
2018-06-09 22:26 - 2020-06-10 14:48 - 000000175 _____ () C:\Users\HP Pavilion\AppData\Roaming\WB.CFG
2016-01-27 10:21 - 2016-01-27 10:21 - 000007601 _____ () C:\Users\HP Pavilion\AppData\Local\Resmon.ResmonCfg
2018-01-30 13:25 - 2019-04-16 12:51 - 000001376 _____ () C:\Users\HP Pavilion\AppData\Local\Temptoast_image.png
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-07-2020 01
Ran by HP Pavilion (15-07-2020 21:45:57)
Running from C:\Users\HP Pavilion\Desktop
Windows 10 Home Version 2004 19041.388 (X64) (2020-07-15 06:47:45)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-176138252-3860332429-2761773572-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-176138252-3860332429-2761773572-503 - Limited - Disabled)
Guest (S-1-5-21-176138252-3860332429-2761773572-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-176138252-3860332429-2761773572-1003 - Limited - Enabled)
HP Pavilion (S-1-5-21-176138252-3860332429-2761773572-1018 - Administrator - Enabled) => C:\Users\HP Pavilion
WDAGUtilityAccount (S-1-5-21-176138252-3860332429-2761773572-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD)
AMD Catalyst Install Manager (HKLM\...\{5F769CF4-5263-4C7B-AEB2-C06A73AE4428}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CameraHelperMsi (HKLM-x32\...\{15634701-BACE-4449-8B25-1567DA8C9FD3}) (Version: 13.51.815.0 - Logitech) Hidden
CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.1.1916 - CyberLink Corp.)
CyberLink PhotoDirector (HKLM-x32\...\InstallShield_{4862344A-A39C-4897-ACD4-A1BED5163C5A}) (Version: 2.0.1.3109 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.1.1925 - CyberLink Corp.)
Energy Star (HKLM\...\{0FA995CC-C849-4755-B14B-5404CC75DC24}) (Version: 1.0.8 - Hewlett-Packard)
erLT (HKLM-x32\...\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}) (Version: 1.20.138.34 - Logitech, Inc.) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 83.0.4103.116 - Google LLC)
Google Toolbar for Internet Explorer (HKLM-x32\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
HP Connected Music (Meridian - installer) (HKLM-x32\...\StartHPConnectedMusic) (Version: v1.0 - Meridian Audio Ltd)
HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.3.0 - WildTangent)
HP Quick Start (HKLM-x32\...\{574F0207-8E98-46CD-8F79-318348C98C46}) (Version: 1.0.4660.30220 - Hewlett-Packard)
Logitech Camera Settings (HKLM-x32\...\LogiUCDPP) (Version: 2.5.17.0 - Logitech Europe S.A.)
Logitech Solar App 1.10 (HKLM\...\SolarApp) (Version: 1.10.3 - Logitech)
Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.80 - Logitech Inc.)
Malwarebytes version 4.1.0.56 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.1.0.56 - Malwarebytes)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 83.0.478.50 - Microsoft Corporation)
Microsoft Edge Update (HKLM-x32\...\Microsoft Edge Update) (Version: 1.3.129.37 - )
Microsoft Office (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.6120.5004 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\OneDriveSetup.exe) (Version: 20.084.0426.0007 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Ralink RT5390R 802.11bgn Wi-Fi Adapter (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 5.0.0.0 - Ralink)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.31.423.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6777 - Realtek Semiconductor Corp.)
Realtek PCIE Card Reader (HKLM-x32\...\{0D61A55C-3ADC-409F-BF5B-A1766D1F5944}) (Version: 6.2.9200.28137 - Realtek Semiconductor Corp.)
Recovery Manager (HKLM-x32\...\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.5.0.5530 - CyberLink Corp.) Hidden
Revo Uninstaller Pro 4.3.3 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 4.3.3 - VS Revo Group, Ltd.)
Skype™ 7.38 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.38.101 - Skype Technologies S.A.)
swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version:  - Yahoo! Inc.)
 
Packages:
=========
eBay -> C:\Program Files\WindowsApps\eBayInc.eBay_1.6.0.34_neutral__1618n3s9xq8tw [2014-11-07] (eBay, Inc)
HP Registration -> C:\Program Files\WindowsApps\AD2F1837.HPRegistration_1.2.1.166_neutral__v10z8vjag6ke6 [2014-11-27] (Hewlett-Packard Company)
HP+ -> C:\Program Files\WindowsApps\AD2F1837.HP_1.2.0.93_neutral__v10z8vjag6ke6 [2014-11-02] (Hewlett-Packard Company)
iHeartRadio -> C:\Program Files\WindowsApps\ClearChannelRadioDigital.iHeartRadio_6.0.47.0_x64__a76a11dkgb644 [2020-07-15] (iHeartMedia.)
Kindle -> C:\Program Files\WindowsApps\AMZNMobileLLC.KindleforWindows8_2.1.0.2_neutral__stfe6vwa9jnbp [2015-06-27] (AMZN Mobile LLC)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2020-07-15] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2020-07-15] (Microsoft Corporation) [MS Ad]
Microsoft Mahjong -> C:\Program Files\WindowsApps\Microsoft.MicrosoftMahjong_2.10.1812.2002_x86__8wekyb3d8bbwe [2019-02-02] (Microsoft Studios) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.7.7082.0_x64__8wekyb3d8bbwe [2020-07-15] (Microsoft Studios) [MS Ad]
MSN Food & Drink -> C:\Program Files\WindowsApps\Microsoft.BingFoodAndDrink_3.0.4.336_x64__8wekyb3d8bbwe [2015-07-13] (Microsoft Corporation) [MS Ad]
MSN Health & Fitness -> C:\Program Files\WindowsApps\Microsoft.BingHealthAndFitness_3.0.4.336_x64__8wekyb3d8bbwe [2015-07-13] (Microsoft Corporation) [MS Ad]
MSN Money -> C:\Program Files\WindowsApps\Microsoft.BingFinance_4.36.20714.0_x64__8wekyb3d8bbwe [2020-07-15] (Microsoft Corporation) [MS Ad]
MSN News -> C:\Program Files\WindowsApps\Microsoft.BingNews_3.0.4.344_x64__8wekyb3d8bbwe [2016-04-30] (Microsoft Corporation) [MS Ad]
MSN Sports -> C:\Program Files\WindowsApps\Microsoft.BingSports_4.36.20714.0_x64__8wekyb3d8bbwe [2020-07-15] (Microsoft Corporation) [MS Ad]
MSN Travel -> C:\Program Files\WindowsApps\Microsoft.BingTravel_3.0.4.336_x64__8wekyb3d8bbwe [2015-07-13] (Microsoft Corporation) [MS Ad]
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x64__8wekyb3d8bbwe [2020-07-15] (Microsoft Corporation) [MS Ad]
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.97.752.0_x64__mcm4njqhnhss8 [2020-07-15] (Netflix, Inc.)
Snapfish -> C:\Program Files\WindowsApps\AD2F1837.HPConnectedPhotopoweredbySnapfish_6.1.736.0_x86__v10z8vjag6ke6 [2020-07-15] (Snapfish)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
ShellIconOverlayIdentifiers: [  OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} =>  -> No File
ShellIconOverlayIdentifiers: [  OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} =>  -> No File
ShellIconOverlayIdentifiers: [  OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} =>  -> No File
ShellIconOverlayIdentifiers-x32: [  OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} =>  -> No File
ShellIconOverlayIdentifiers-x32: [  OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} =>  -> No File
ShellIconOverlayIdentifiers-x32: [  OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} =>  -> No File
ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} =>  -> No File
ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} =>  -> No File
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-06-16] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} =>  -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2015-08-21] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} =>  -> No File
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-06-16] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers6: [RUShellExt] -> {2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RUExt.dll [2019-03-29] (VS Revo Group Ltd. -> VS Revo Group)
 
==================== Codecs (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Drivers32: [vidc.i420] => C:\WINDOWS\system32\lvcod64.dll [175392 2012-10-26] (Logitech, Inc. -> Logitech Inc.)
HKLM\...\Drivers32: [vidc.i420] => C:\Windows\SysWOW64\lvcodec2.dll [305000 2012-10-26] (Logitech, Inc. -> Logitech Inc.)
 
==================== Shortcuts & WMI ========================
 
==================== Loaded Modules (Whitelisted) =============
 
2014-07-04 21:33 - 2014-07-04 21:33 - 000127488 _____ () [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2014-07-04 21:33 - 2014-07-04 21:33 - 000102400 _____ () [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
 
==================== Alternate Data Streams (Whitelisted) ========
 
==================== Safe Mode (Whitelisted) ==================
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer trusted/restricted ==========
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 06:25 - 2020-07-09 11:14 - 000000855 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1       localhost
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> c:\Program Files (x86)\AMD APP\bin\x86_64;c:\Program Files (x86)\AMD APP\bin\x86;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files (x86)\Skype\Phone\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\Control Panel\Desktop\\Wallpaper -> C:\Users\HP Pavilion\AppData\Local\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(If an entry is included in the fixlist, it will be removed.)
 
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\StartupApproved\StartupFolder: => "PalTalk.lnk"
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\StartupApproved\Run: => "Chromium"
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_803D2E04332962AFAC352F92C208E650"
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\StartupApproved\Run: => "Paltalk"
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\StartupApproved\Run: => "Skype"
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{26350D1D-A0AD-46A3-8C88-07A46D70D51E}] => (Allow) LPort=52000
FirewallRules: [{FABCC09D-24F4-49C0-8CD8-05798DCFEB32}] => (Allow) LPort=53000
FirewallRules: [{FBA5429D-8BA2-4085-BDD5-F7E2BDB1C1B2}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [UDP Query User{40E28967-F448-403E-B197-C27ECC80F3A9}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [TCP Query User{B0241114-BEDC-46F5-BBAF-324BF2D6F0B4}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [UDP Query User{A8FCFB61-3A9B-49D7-B998-60FB27AE20BB}C:\program files (x86)\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk.exe => No File
FirewallRules: [TCP Query User{AC84FE58-503E-4351-8C1D-1B3550F0000F}C:\program files (x86)\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk.exe => No File
FirewallRules: [{C19F3984-3DF2-4505-B50E-E2623874F167}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe => No File
FirewallRules: [{5F0B061F-74AB-46A7-AA55-5DA60E86BD74}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{27F4866A-85A9-4CBE-B396-6FD538FC22F3}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{261379EE-DACD-4B61-9F8A-BF6F93F7DF35}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{B6D693E7-D84F-46D9-A816-DE973D437AF7}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{87010DB7-297E-435E-AB81-7C0757767CAC}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE (CyberLink -> CyberLink Corp.)
FirewallRules: [TCP Query User{7DE345DD-8CFC-418A-B491-BB60FC69B658}C:\windows\syswow64\msiexec.exe] => (Allow) C:\windows\syswow64\msiexec.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [UDP Query User{29A929DE-9870-4957-A906-14B5642012FB}C:\windows\syswow64\msiexec.exe] => (Allow) C:\windows\syswow64\msiexec.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [TCP Query User{5A430BC0-D3BD-4121-8016-8EA23C276F90}C:\program files (x86)\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk.exe => No File
FirewallRules: [UDP Query User{0326EAFC-8940-43FE-9164-E4A21A402C98}C:\program files (x86)\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk.exe => No File
FirewallRules: [{63569EEC-DC52-4EED-8DB2-E83112C70753}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc. -> Yahoo! Inc.)
FirewallRules: [{14852894-E754-4D88-B410-E365CBD58788}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc. -> Yahoo! Inc.)
FirewallRules: [TCP Query User{C668418F-047A-4B32-84B0-E819D88A70E0}C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe => No File
FirewallRules: [UDP Query User{D48F9F75-6B2E-4094-9051-3EEF62A29FE1}C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe => No File
FirewallRules: [{1DA563F9-8F28-4085-9D23-2E0A03D8EC26}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE (CyberLink Corp. -> CyberLink Corp.)
FirewallRules: [TCP Query User{EE175E9E-556D-4C29-8E52-992A95F9A6CE}C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe] => (Block) C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe => No File
FirewallRules: [UDP Query User{E442E7B3-7B13-4BDA-B26D-0F28D846A538}C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe] => (Block) C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe => No File
 
==================== Restore Points =========================
 
15-07-2020 02:00:26 Windows Modules Installer
 
==================== Faulty Device Manager Devices ============
 
Name: Wireless Device
Description: Wireless Device
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Surface
Service: WUDFRd
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
 This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (07/15/2020 09:05:22 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x8007045b, A system shutdown is in progress.
.
 
Error: (07/15/2020 09:05:22 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.
]
 
Error: (07/15/2020 09:05:22 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x8007045b, A system shutdown is in progress.
.
 
Error: (07/15/2020 09:05:22 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.
]
 
Error: (07/15/2020 06:35:10 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Unexpected conflict discarding   20 1.0.0.127.in-addr.arpa. PTR HPPavilion-2.local.
 
Error: (07/15/2020 06:35:10 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 127.0.0.1:5353   18 1.0.0.127.in-addr.arpa. PTR HPPavilion.local.
 
Error: (07/15/2020 06:35:10 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Unexpected conflict discarding   20 A.4.0.1.E.D.2.D.5.C.E.C.6.7.9.6.0.0.0.0.0.0.0.0.0.0.0.0.0.8.E.F.ip6.arpa. PTR HPPavilion-2.local.
 
Error: (07/15/2020 06:35:10 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from FE80:0000:0000:0000:6976:CEC5:D2DE:104A:5353   18 A.4.0.1.E.D.2.D.5.C.E.C.6.7.9.6.0.0.0.0.0.0.0.0.0.0.0.0.0.8.E.F.ip6.arpa. PTR HPPavilion.local.
 
 
System errors:
=============
Error: (07/15/2020 07:37:29 AM) (Source: SCardSvr) (EventID: 616) (User: )
Description: Reader monitor 'Dell Smart Card Reader Keyboard 0' received uncaught error code:  Access is denied.
 
Error: (07/15/2020 07:37:29 AM) (Source: SCardSvr) (EventID: 615) (User: )
Description: Reader removal monitor error retry threshold reached:  Access is denied.
 
Error: (07/15/2020 02:00:20 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80240017: Update for Windows Defender Antivirus antimalware platform - KB4052623 (Version 4.18.2001.10).
 
Error: (07/15/2020 12:00:13 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: The server {F3B4E234-7A68-4E43-B813-E4BA55A065F6} did not register with DCOM within the required timeout.
 
Error: (07/14/2020 11:24:51 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: The server {A47979D2-C419-11D9-A5B4-001185AD2B89} did not register with DCOM within the required timeout.
 
Error: (07/14/2020 11:23:47 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: The Printer Extensions and Notifications service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.
 
Error: (07/14/2020 11:22:51 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Network List Service service terminated with the following error: 
The device is not ready.
 
Error: (07/14/2020 11:22:46 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: The server {A47979D2-C419-11D9-A5B4-001185AD2B89} did not register with DCOM within the required timeout.
 
 
==================== Memory info =========================== 
 
BIOS: AMI 8.06 09/07/2012
Motherboard: PEGATRON CORPORATION 2AF0
Processor: AMD E1-1200 APU with Radeon™ HD Graphics
Percentage of memory in use: 60%
Total physical RAM: 3665.86 MB
Available physical RAM: 1457.27 MB
Total Virtual: 4065.86 MB
Available Virtual: 1712.33 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:442.96 GB) (Free:368.14 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (Recovery Image) (Fixed) (Total:19.78 GB) (Free:2.48 GB) NTFS ==>[system with boot components (obtained from drive)]
 
\\?\Volume{02f74654-436d-45c5-a86d-fd54f1779603}\ (Windows RE tools) (Fixed) (Total:1 GB) (Free:0.66 GB) NTFS
\\?\Volume{1b95caa0-c5be-4e62-8d02-4cc02dfc934c}\ () (Fixed) (Total:0.54 GB) (Free:0.08 GB) NTFS
\\?\Volume{d1de863d-cf84-4d64-8ee1-9cebae5d4872}\ () (Fixed) (Total:1 GB) (Free:0.66 GB) NTFS
\\?\Volume{637f704c-e0b6-4d87-aedf-878d4ed48896}\ (SYSTEM) (Fixed) (Total:0.35 GB) (Free:0.31 GB) FAT32
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 4A1F8D9C)
 
Partition: GPT.
 
==================== End of Addition.txt =======================

  • 0

#58
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 2,665 posts

Good morning to you, Joseph.
 

She is one of those people that gets taken advantage of, and has some physical issue that I don't mind working with.

 

This makes it even nicer. I only hope that the issues will be resolved soon, so she can use her computer without problems. I will be back with a new fix (some tiding up) and to check Windows Defender again.


  • 0

#59
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 2,665 posts

New set of instructions here. :)

1. Run a fix with FRST

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system

  • Please select the entire contents of the code box below, from the "Start::" line to "End::", including both lines. Right-click and select "Copy ". No need to paste anything to anywhere.
Start::
CreateRestorePoint:
CloseProcesses:
Task: {0DC0DAD2-F84F-429D-B085-411AE7CDE2D5} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4F47-879B-29A80C355D61}
Task: {287EB61E-849D-44F1-BF41-56B2A8081F95} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDFE067B1}
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task => {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Task: {7B857988-3067-4E13-8891-998F430972F7} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316}
Task: {9768ABD2-EB67-498E-A669-15A536AF817A} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969}
SearchScopes: HKU\S-1-5-21-176138252-3860332429-2761773572-1018 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [No File]
ShellIconOverlayIdentifiers: [  OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} =>  -> No File
ShellIconOverlayIdentifiers: [  OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} =>  -> No File
ShellIconOverlayIdentifiers: [  OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} =>  -> No File
ShellIconOverlayIdentifiers-x32: [  OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} =>  -> No File
ShellIconOverlayIdentifiers-x32: [  OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} =>  -> No File
ShellIconOverlayIdentifiers-x32: [  OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} =>  -> No File
ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} =>  -> No File
ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} =>  -> No File
ContextMenuHandlers4: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} =>  -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} =>  -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\StartupApproved\Run: => "Chromium"
FirewallRules: [UDP Query User{A8FCFB61-3A9B-49D7-B998-60FB27AE20BB}C:\program files (x86)\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk.exe => No File
FirewallRules: [TCP Query User{AC84FE58-503E-4351-8C1D-1B3550F0000F}C:\program files (x86)\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk.exe => No File
FirewallRules: [{C19F3984-3DF2-4505-B50E-E2623874F167}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe => No File
FirewallRules: [TCP Query User{5A430BC0-D3BD-4121-8016-8EA23C276F90}C:\program files (x86)\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk.exe => No File
FirewallRules: [UDP Query User{0326EAFC-8940-43FE-9164-E4A21A402C98}C:\program files (x86)\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk.exe => No File
FirewallRules: [TCP Query User{C668418F-047A-4B32-84B0-E819D88A70E0}C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe => No File
FirewallRules: [UDP Query User{D48F9F75-6B2E-4094-9051-3EEF62A29FE1}C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe => No File
FirewallRules: [TCP Query User{EE175E9E-556D-4C29-8E52-992A95F9A6CE}C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe] => (Block) C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe => No File
FirewallRules: [UDP Query User{E442E7B3-7B13-4BDA-B26D-0F28D846A538}C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe] => (Block) C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe => No File
C:\ProgramData\Norton
C:\Program Files (x86)\Paltalk
C:\Program Files (x86)\Windows Live
C:\program files (x86)\paltalk messenger
EmptyTemp:
End::
  • Please right-click on FRST64 on your Desktop, to run it as administrator. When the tool opens, click "yes" to the disclaimer.
  • Press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt on your Desktop.
  • Please post the log in your next reply.

 

2. Check Windows Defender

  • Go to Settings (Windows icon on the keyboard + i)
  • Select Privacy & Security
  • From the left pane, Windows Security
  • Open Windows Security
  • Please take a screenshot of what you see at the Security at a glance screen (Microsoft's instructions of how to take screenshots using snipping tool are here)

  • 0

#60
whittakerjr

whittakerjr

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts
Here we go
 
 
 
Fix result of Farbar Recovery Scan Tool (x64) Version: 08-07-2020 01
Ran by HP Pavilion (16-07-2020 10:25:46) Run:5
Running from C:\Users\HP Pavilion\Desktop
Loaded Profiles: HP Pavilion
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CreateRestorePoint:
CloseProcesses:
Task: {0DC0DAD2-F84F-429D-B085-411AE7CDE2D5} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4F47-879B-29A80C355D61}
Task: {287EB61E-849D-44F1-BF41-56B2A8081F95} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDFE067B1}
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task => {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Task: {7B857988-3067-4E13-8891-998F430972F7} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316}
Task: {9768ABD2-EB67-498E-A669-15A536AF817A} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969}
SearchScopes: HKU\S-1-5-21-176138252-3860332429-2761773572-1018 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [No File]
ShellIconOverlayIdentifiers: [  OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} =>  -> No File
ShellIconOverlayIdentifiers: [  OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} =>  -> No File
ShellIconOverlayIdentifiers: [  OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} =>  -> No File
ShellIconOverlayIdentifiers-x32: [  OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} =>  -> No File
ShellIconOverlayIdentifiers-x32: [  OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} =>  -> No File
ShellIconOverlayIdentifiers-x32: [  OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} =>  -> No File
ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} =>  -> No File
ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} =>  -> No File
ContextMenuHandlers4: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} =>  -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} =>  -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\...\StartupApproved\Run: => "Chromium"
FirewallRules: [UDP Query User{A8FCFB61-3A9B-49D7-B998-60FB27AE20BB}C:\program files (x86)\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk.exe => No File
FirewallRules: [TCP Query User{AC84FE58-503E-4351-8C1D-1B3550F0000F}C:\program files (x86)\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk.exe => No File
FirewallRules: [{C19F3984-3DF2-4505-B50E-E2623874F167}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe => No File
FirewallRules: [TCP Query User{5A430BC0-D3BD-4121-8016-8EA23C276F90}C:\program files (x86)\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk.exe => No File
FirewallRules: [UDP Query User{0326EAFC-8940-43FE-9164-E4A21A402C98}C:\program files (x86)\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk.exe => No File
FirewallRules: [TCP Query User{C668418F-047A-4B32-84B0-E819D88A70E0}C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe => No File
FirewallRules: [UDP Query User{D48F9F75-6B2E-4094-9051-3EEF62A29FE1}C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe] => (Allow) C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe => No File
FirewallRules: [TCP Query User{EE175E9E-556D-4C29-8E52-992A95F9A6CE}C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe] => (Block) C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe => No File
FirewallRules: [UDP Query User{E442E7B3-7B13-4BDA-B26D-0F28D846A538}C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe] => (Block) C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe => No File
C:\ProgramData\Norton
C:\Program Files (x86)\Paltalk
C:\Program Files (x86)\Windows Live
C:\program files (x86)\paltalk messenger
EmptyTemp:
 
*****************
 
Restore point was successfully created.
Processes closed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0DC0DAD2-F84F-429D-B085-411AE7CDE2D5}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0DC0DAD2-F84F-429D-B085-411AE7CDE2D5}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SideShow\GadgetManager" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{287EB61E-849D-44F1-BF41-56B2A8081F95}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{287EB61E-849D-44F1-BF41-56B2A8081F95}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SideShow\SessionAgent" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6DFCB649-0769-4F83-BB10-F60F235F6D3D}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6DFCB649-0769-4F83-BB10-F60F235F6D3D}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7B857988-3067-4E13-8891-998F430972F7}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7B857988-3067-4E13-8891-998F430972F7}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\SideShow\AutoWake => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SideShow\AutoWake" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9768ABD2-EB67-498E-A669-15A536AF817A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9768ABD2-EB67-498E-A669-15A536AF817A}" => removed successfully
C:\WINDOWS\System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SideShow\SystemDataProviders" => removed successfully
HKU\S-1-5-21-176138252-3860332429-2761773572-1018\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC} => removed successfully
HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922 => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\  OverlayExcluded => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\  OverlayPending => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\  OverlayProtected => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\  OverlayExcluded => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\  OverlayPending => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\  OverlayProtected => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\CLVDShellExt => removed successfully
HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers\CLVDShellExt => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\MSSE => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Offline Files => removed successfully
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\Gadgets => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Offline Files => removed successfully
"HKU\S-1-5-21-176138252-3860332429-2761773572-1018\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\Chromium" => removed successfully
"HKU\S-1-5-21-176138252-3860332429-2761773572-1018\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Chromium" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{A8FCFB61-3A9B-49D7-B998-60FB27AE20BB}C:\program files (x86)\paltalk messenger\paltalk.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{AC84FE58-503E-4351-8C1D-1B3550F0000F}C:\program files (x86)\paltalk messenger\paltalk.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C19F3984-3DF2-4505-B50E-E2623874F167}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{5A430BC0-D3BD-4121-8016-8EA23C276F90}C:\program files (x86)\paltalk messenger\paltalk.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{0326EAFC-8940-43FE-9164-E4A21A402C98}C:\program files (x86)\paltalk messenger\paltalk.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{C668418F-047A-4B32-84B0-E819D88A70E0}C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{D48F9F75-6B2E-4094-9051-3EEF62A29FE1}C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{EE175E9E-556D-4C29-8E52-992A95F9A6CE}C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{E442E7B3-7B13-4BDA-B26D-0F28D846A538}C:\program files (x86)\paltalk messenger\paltalk messenger\paltalk.exe" => removed successfully
C:\ProgramData\Norton => moved successfully
"C:\Program Files (x86)\Paltalk" => not found
"C:\Program Files (x86)\Windows Live" => not found
C:\program files (x86)\paltalk messenger => moved successfully
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 6578176 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 29694499 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 123583 B
Edge => 0 B
Chrome => 180767261 B
Firefox => 0 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 2768 B
NetworkService => 13984 B
Joanne Endevoets => 13984 B
HP Pavilion => 98209069 B
 
RecycleBin => 12990723 B
EmptyTemp: => 313.2 MB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 10:29:32 ====

Attached Thumbnails

  • ataGlance.png

  • 0






Similar Topics


Also tagged with one or more of these keywords: slow system, browsers not connecting, usb camera not seen by system

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP