Hi, brief description of my symptoms are something has basically taken over, I can no longer open device manager, or other admin items, unless in safe mode. Been ongoing for a while. Seemingly it's replicating existing programs, I use Eset as antivirus, I had them log into my pc, and they didn't find any malware, but couldn't explain why I had the issues currently.
I've used Microsoft removal tools, both, the first malicious removal tool, found 9 infected files, during scan, then once completed, it said no infected files. It's done the same thing 2x, then I used the Microsoft Support Emergency Response Tool, if found and removed one Trojan.
I'm happy to paste those results, if you let me know where the logs are located. )
I also ran the Farbar Recovery tool, and results for that are as follows.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-07-2017
Ran by AIRWORX 2 (administrator) on AIRWORX2-PC (11-07-2017 05:31:31)
Running from C:\Users\AIRWORX 2\Desktop
Loaded Profiles: AIRWORX 2 (Available Profiles: AIRWORX 2 & AirworxAZ & Administrator)
Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\HelpPane.exe
(DigiData Corp.) C:\Program Files (x86)\Cox\Drag and Drop Backup\vewatch.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(OldTimer Tools) C:\Users\AIRWORX 2\Desktop\OTL.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Seagate Scheduler2 Service] => C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe [395152 2011-06-30] (Seagate)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe
HKLM\...\Run: [BeatsOSDApp] => C:\Program Files\IDT\WDM\beats64.exe [41664 2012-08-22] (Hewlett-Packard )
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-11-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\isuspm.exe [2068856 2011-10-12] (Flexera Software LLC.)
HKLM-x32\...\Run: [PaperPort PTD] => C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe [36168 2013-05-14] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [IndexSearch] => C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe [18248 2013-05-14] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PPort14reminder] => "C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\14\Config\Ereg\Ereg.ini"
HKLM-x32\...\Run: [PDFProHook] => C:\Program Files (x86)\Nuance\PDFViewer\pdfpro7hook.exe [641864 2013-03-20] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PDFCreHook] => C:\Program Files (x86)\Nuance\PDFCreate\pdfcreate7hook.exe [605512 2013-03-26] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PDF7 Registry Controller] => C:\Program Files (x86)\Nuance\PDFCreate\RegistryController.exe [140616 2013-03-26] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [Adobe Photo Downloader] => C:\Program Files (x86)\Adobe\Photoshop Elements 4.0\apdproxy.exe [57344 2005-09-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-07-08] (Apple Inc.)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [673616 2009-04-07] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [143360 2012-09-06] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [3076096 2012-06-06] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3486520 2017-06-26] (Dropbox, Inc.)
HKLM-x32\...\Run: [WDAppManager] => C:\Program Files (x86)\Western Digital\WD App Manager\AppManagerLauncher.exe [21384 2016-04-15] (Western Digital Technologies, Inc.)
HKLM-x32\...\Run: [DiscWizardMonitor.exe] => C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe [2638152 2011-06-30] (Seagate)
HKLM-x32\...\Run: [Fitbit Connect] => C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [4567720 2015-10-28] (Fitbit, Inc.)
HKLM-x32\...\Run: [Vault Explorer Cache Watcher] => C:\Program Files (x86)\Cox\Drag and Drop Backup\vewatch.exe [17408 2013-02-21] (DigiData Corp.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation)
HKLM\...\Policies\Explorer: [0] 0
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\Run: [Fitbit Connect] => C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [4567720 2015-10-28] (Fitbit, Inc.)
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\Run: [SmartSwitchPDLR.exe] => C:\Program Files (x86)\Samsung\Smart Switch PC\SmartSwitchPDLR.exe [1037984 2017-05-20] (Samsung)
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\RunOnce: [Uninstall C:\Users\AIRWORX 2\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\AIRWORX 2\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64"
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\RunOnce: [Uninstall C:\Users\AIRWORX 2\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_2\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\AIRWORX 2\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_2\amd64"
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\MountPoints2: {2a988f7c-9489-11e6-becf-a4db308c6ca7} - "H:\VZW_Software_upgrade_assistant.exe"
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\MountPoints2: {2efe6986-41be-11e7-bee9-78e3b588cafb} - "G:\VZW_Software_upgrade_assistant.exe"
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\MountPoints2: {3d56dcb9-5538-11e7-beec-78e3b588cafb} - "G:\VZW_Software_upgrade_assistant.exe"
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\MountPoints2: {a218bcf3-19fb-11e7-bee0-78e3b588cafb} - "H:\VZW_Software_upgrade_assistant.exe"
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\MountPoints2: {ea1fc76b-f3ff-11e6-bed7-a4db308c6ca7} - "G:\VZW_Software_upgrade_assistant.exe"
Startup: C:\Users\AIRWORX 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk [2015-06-18]
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\AIRWORX 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Verizon Wireless Software Utility Application for Android – Samsung.lnk [2017-02-20]
ShortcutTarget: Verizon Wireless Software Utility Application for Android – Samsung.lnk -> C:\Users\AIRWORX 2\AppData\Roaming\VERIZON\UA_ar\UA.exe (SAMSUNG Electornics Co., Ltd.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BackupRemind.lnk [2017-02-16]
ShortcutTarget: BackupRemind.lnk -> C:\Program Files (x86)\Wondershare\dr.fone toolkit for Android\Addins\AndroidBackupRestore\BackupRemind.exe (No File)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Cox Cloud Drive.lnk [2017-04-21]
ShortcutTarget: Cox Cloud Drive.lnk -> C:\Program Files (x86)\Cox Secure Online Backup for Windows\DigiData.Host.exe (DigiData)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Shutterfly Uploader.lnk [2017-05-10]
ShortcutTarget: Shutterfly Uploader.lnk -> C:\Program Files (x86)\Shutterfly Uploader\ThisLife.Uploader.exe (Shutterfly, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
Tcpip\..\Interfaces\{fa3ce8d6-7afe-4ad0-a04f-b501407fe7a5}: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPDSK13/1
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://login.secureserver.net/index.php?app=wbe&domain=email.airworx.us
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPDSK13/1
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKU\S-1-5-21-2671885098-678752524-1400920573-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2671885098-678752524-1400920573-1001 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-02-25] (HP)
BHO-x32: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> C:\Program Files (x86)\Nuance\PDFViewer\Bin\PlusIEContextMenu.dll [2011-06-30] (Zeon Corporation)
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\ssv.dll [2017-05-24] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: ZeonIEEventHelper Class -> {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} -> C:\Program Files (x86)\Nuance\PDFCreate\Bin\ZeonIEFavClient.dll [2011-03-26] (Zeon Corporation)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-05-24] (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-02-25] (HP)
Toolbar: HKLM-x32 - DocuCom PDF - {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files (x86)\Nuance\PDFCreate\Bin\ZeonIEFavClient.dll [2011-03-26] (Zeon Corporation)
Toolbar: HKU\S-1-5-21-2671885098-678752524-1400920573-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
DPF: HKLM-x32 {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1499697116239
DPF: HKLM-x32 {D66F9BB1-7D8E-4A96-9166-20FCC91CBFE9} hxxp://99.7.214.118/FDSH_DVR.CAB
DPF: HKLM-x32 {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} hxxps://secure.logmein.com//activex/ractrl.cab?lmi=3379
FireFox:
========
FF HKLM\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird => not found
FF HKLM-x32\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird => not found
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-21] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-05-24] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-05-24] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-29] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2012-10-12] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-02] (Adobe Systems Inc.)
FF Plugin-x32: ZEON/PDF,version=2.0 -> C:\Program Files (x86)\Nuance\PDFViewer\bin\nppdf.dll [2011-07-15] (Zeon Corporation)
FF Plugin HKU\S-1-5-21-2671885098-678752524-1400920573-1001: @citrixonline.com/appdetectorplugin -> C:\Users\AIRWORX 2\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2014-04-02] (Citrix Online)
Chrome:
=======
CHR DefaultProfile: Profile 9
CHR Profile: C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Guest Profile [2017-06-24]
CHR Profile: C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 9 [2017-07-10]
CHR Extension: (Google Docs) - C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\aohghmighlieiainnegkcijnfilokake [2017-07-10]
CHR Extension: (Google Drive) - C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-07-10]
CHR Extension: (YouTube) - C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-07-10]
CHR Extension: (Google Docs Offline) - C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-07-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-07-10]
CHR Extension: (Gmail) - C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-07-10]
CHR Extension: (Chrome Media Router) - C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-07-10]
CHR Profile: C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\System Profile [2017-07-10]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ATTENTION: => Could not perform signature verification. Cryptographic Service is not running.
S2 AdobeActiveFileMonitor4.0; C:\Program Files (x86)\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe [102400 2005-09-09] ()
S2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2246256 2017-05-18] (Adobe Systems, Incorporated)
S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [351944 2015-11-04] (Advanced Micro Devices, Inc.)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-08-24] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-08-24] (Dropbox, Inc.)
S2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [49992 2017-06-26] (Dropbox, Inc.)
S2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2624856 2017-03-09] (ESET)
S2 Fitbit Connect; C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe [5906088 2015-10-28] (Fitbit, Inc.)
S2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [321056 2017-06-01] (HP Inc.)
S2 MySQL; C:\Program Files (x86)\MySQL\MySQL Server 5.0\my.ini [8934 2016-01-14] ()
S2 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [77640 2013-05-14] (Nuance Communications, Inc.)
S3 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2017-01-15] (DEVGURU Co., LTD.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-27] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103712 2017-04-27] (Microsoft Corporation)
S3 WsDrvInst; C:\Program Files (x86)\Wondershare\MobileGo\DriverInstall.exe [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
S3 athr; C:\WINDOWS\System32\drivers\athw10x.sys [4301304 2015-05-17] (Qualcomm Atheros Communications, Inc.)
S1 CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-15] (CyberLink)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.)
S1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [132848 2017-03-09] (ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [107344 2017-03-09] (ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [14880 2017-03-09] (ESET)
S1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [178056 2017-03-09] (ESET)
S4 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [50752 2017-03-09] (ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [78192 2017-03-09] (ESET)
S1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [101648 2017-03-09] (ESET)
S3 ESETCleanersDriver; C:\WINDOWS\system32\Drivers\ESETCleanersDriver.sys [181160 2017-06-28] (ESET)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
S2 NPF; C:\WINDOWS\system32\drivers\npf.sys [35344 2015-01-08] (CACE Technologies, Inc.)
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [402136 2016-10-27] (Realsil Semiconductor Corporation)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd.)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2017-07-11] ()
S3 usbrndis6; C:\WINDOWS\System32\drivers\usb80236.sys [23040 2016-07-16] (Microsoft Corporation)
R0 vidsflt53; C:\WINDOWS\System32\DRIVERS\vsflt53.sys [141920 2016-03-03] (Acronis)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
========================== Drivers MD5 =======================
C:\WINDOWS\System32\drivers\1394ohci.sys A7901875F89D011C38CF52C98ACF5B29
C:\WINDOWS\System32\drivers\3ware.sys EE1CCC54F75C24727A218F98FC5349DA
C:\WINDOWS\System32\drivers\ACPI.sys 73C73E1AA0D4D727A04AAAB120B7F56A
C:\WINDOWS\System32\drivers\AcpiDev.sys 0935496EF9624B46B935CB35ECE1F205
C:\WINDOWS\System32\Drivers\acpiex.sys D6794C31F4077B71433988787BAA926E
C:\WINDOWS\System32\drivers\acpipagr.sys FE5F656D6B35089DA39112E74EC6A85A
C:\WINDOWS\System32\drivers\acpipmi.sys 2F242941E4DFF69B883D77A16F039557
C:\WINDOWS\System32\drivers\acpitime.sys C247E35A21682DA8D0DC3AF9F025FCC5
C:\WINDOWS\System32\drivers\ADP80XX.SYS 49B9DB97AFC85DCCBDACDAB2E90085B7
C:\WINDOWS\system32\drivers\afd.sys 323AA1953ED9C01E23F740FA891FE064
C:\WINDOWS\System32\DRIVERS\ahcache.sys 23522E5D581F7722B1B5B86737CAE39C
C:\WINDOWS\System32\drivers\amdk8.sys DF21E05E41E5AC3F13F304D91457649A
C:\WINDOWS\system32\DRIVERS\atikmdag.sys F992CE57F4D2A2F988135A1F87337EBC
C:\WINDOWS\system32\DRIVERS\atikmpag.sys 17BA5C907E14947574CBB788F4CEB85F
C:\WINDOWS\System32\drivers\amdppm.sys 45D0AA4BB90B821DF92E8F19ABED0C5E
C:\WINDOWS\System32\drivers\amdsata.sys 74FFBC43B4B899C9A8CA06A892F2CE73
C:\WINDOWS\System32\drivers\amdsbs.sys AAB0F1D8D7E54761ABAB13AF161F1680
C:\WINDOWS\System32\drivers\amdxata.sys F91BAAC4237C40352A807000F3B716F9
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys C3D487827E48CC5EC17994FEC5BDFF87
C:\WINDOWS\System32\drivers\appid.sys BC121C099C6C659126AD2102AFDFF8CF
C:\WINDOWS\System32\drivers\applockerfltr.sys 68190E2BADF23BD782344970E5B5DE9E
C:\WINDOWS\System32\drivers\arcsas.sys E6AB1F0B4C3D4E0D2A88332D76FECD03
C:\WINDOWS\System32\drivers\asyncmac.sys 61C5A480C43E7E8E49C42869F49D0D3E
C:\WINDOWS\System32\drivers\atapi.sys A10F989A812B57B9695F6C305907C9C6
C:\WINDOWS\System32\drivers\athw10x.sys 477906D31E1A5FDA0E5CD8D189DAD61F
C:\WINDOWS\System32\drivers\bxvbda.sys 61BAC67048CA5C1D08C48FCC8012B613
C:\WINDOWS\System32\drivers\BasicDisplay.sys 94D6B95485BFA35D81524B0EBA0F7569
C:\WINDOWS\System32\drivers\BasicRender.sys 72ABA6AC74F7AA9C9A4AC61BE628ADD1
C:\WINDOWS\System32\drivers\bcmfn.sys 3F5523DCEFE42B385659C5CB46A6B810
C:\WINDOWS\System32\drivers\bcmfn2.sys 0B750A6A6D847E73CA48ADD7A0F5A393
C:\Windows\System32\Drivers\Beep.sys 0A508274355745EEF01C6BE3198D02C4
C:\WINDOWS\System32\DRIVERS\bowser.sys 9CD2A4821DE379305CACB2E99AD8953A
C:\WINDOWS\system32\DRIVERS\BrSerIb.sys 63A00CDBEB300522C49EC7CA77324060
C:\WINDOWS\system32\DRIVERS\BrSerId.sys 4882F0042EE18681D26294535DE4E1BD
C:\WINDOWS\system32\DRIVERS\BrUsbSer.sys ==> MD5 is legit
C:\WINDOWS\system32\DRIVERS\BrUsbSIb.sys BBCFD6C6EF66449F55AF1BFDB08C9B12
C:\WINDOWS\System32\drivers\BthAvrcpTg.sys 722036C26D2C4E50EC2A2EC5FD678846
C:\WINDOWS\System32\drivers\bthhfenum.sys C2E31BE025D46D189E38DD1EDF07837A
C:\WINDOWS\System32\drivers\BthHFHid.sys F7CD605FC0B0B22F3F6F247595E3A655
C:\WINDOWS\System32\drivers\bthmodem.sys 535DC41A33630AE4C262406F9E981C03
C:\WINDOWS\System32\drivers\buttonconverter.sys 23F9EF739F685E07482116425E7879AA
C:\WINDOWS\System32\drivers\capimg.sys 60EB6A4CE3E21887D302350631C16F26
C:\WINDOWS\System32\DRIVERS\cdfs.sys F8FB51B9EF6372610E9B31A1D86B62FC
C:\WINDOWS\System32\drivers\cdrom.sys 613D0137C269187FA298A157E3D14A18
C:\WINDOWS\System32\drivers\cht4sx64.sys 0AED948DA8D5F08B3D6F12E4E2089736
C:\WINDOWS\System32\drivers\cht4vx64.sys 0002A0FDE087C1657AB31CE73077539C
C:\WINDOWS\System32\drivers\circlass.sys 6B4F90A287D75CCD78694F6790C911B2
C:\WINDOWS\System32\drivers\CLFS.sys B72D26074E72A757D788FB1BEF8B2F2E
C:\WINDOWS\System32\drivers\registry.sys EEC3A4A98AE1A337E3CD1483AD6F2E15
C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys 3A0028F785F7DD320FD4756E27CAB343
C:\WINDOWS\System32\drivers\CmBatt.sys 429623E266EF067A44E8CF148E9DFB9B
C:\WINDOWS\System32\Drivers\cng.sys 8360BD603D3596E1D6D9BD04E69DE5E9
C:\WINDOWS\System32\DRIVERS\cnghwassist.sys 3DB10C59405931E2C72EFB82C1AF97D1
C:\WINDOWS\System32\DriverStore\FileRepository\compositebus.inf_amd64_a140581a8f8b58b7\CompositeBus.sys 34C935AF2A414572B412B3556586D783
C:\WINDOWS\System32\drivers\condrv.sys 44EEEB2382F566999287E13F2067693C
C:\WINDOWS\System32\drivers\dam.sys 3BBD0073265DA6D3EFBA54B26E5D8236
C:\WINDOWS\System32\Drivers\dfsc.sys 4BC21E937E9F9F408672D2C2CBE4A153
C:\WINDOWS\system32\DRIVERS\ssudbus.sys 5F78930AAB3900102EA8ACDD38F97324
C:\WINDOWS\System32\drivers\disk.sys 35B9D46560339A5A7F0CAC6ED702C817
C:\WINDOWS\System32\drivers\dmvsc.sys 815F45161A4571C2C44491564F3D5968
C:\WINDOWS\system32\DRIVERS\drmkaud.sys AE6BD4C879A8C849E53947C92DF3B3A0
C:\WINDOWS\System32\drivers\dxgkrnl.sys C867FABEFF1A553330093384D022F963
C:\WINDOWS\System32\DRIVERS\eamonm.sys C3E4C744BABD52F15AB3B64E8CA1C4C2
C:\WINDOWS\System32\drivers\evbda.sys 7EC6FC0266D74BD47ABB130A328B70EC
C:\WINDOWS\System32\DRIVERS\edevmon.sys 72353F0A92CDA8451FFA0B05257D6A7A
C:\WINDOWS\System32\DRIVERS\eelam.sys ED9A634DBA39221A2D8D57BED5173E87
C:\WINDOWS\system32\DRIVERS\ehdrv.sys 44A43B00191FAE1AFC8C6589041ABF26
C:\WINDOWS\System32\drivers\EhStorClass.sys 8D74B8B5D6F7C5BC4C525BAF2B083FF1
C:\WINDOWS\System32\drivers\EhStorTcgDrv.sys 2A9817B5A9260D8F60D52E36BEF10443
C:\WINDOWS\system32\DRIVERS\ekbdflt.sys A745F6769CDC98DF7E89B8FE8A6C1F86
C:\WINDOWS\system32\DRIVERS\epfw.sys 3D2CC73713E18E82B3B7BE3A64487BD2
C:\WINDOWS\system32\DRIVERS\epfwwfp.sys E896BFAEDA9AF51D9C9A310DBC673CC0
C:\WINDOWS\System32\drivers\errdev.sys 77B60DEC7DCB4233E4A69D3F52E5DB24
C:\WINDOWS\system32\Drivers\ESETCleanersDriver.sys 926B2B7400E15FFA9630170C1B26E1AC
C:\Windows\System32\Drivers\exfat.sys FCD2C63754C2E739A8EEAD9BC63F9DDC
C:\Windows\System32\Drivers\fastfat.sys FA918EC296EB410FF02867D008D02421
C:\WINDOWS\System32\drivers\fdc.sys 99598ECA5E41996E005D5B9D9FF1EFA2
C:\WINDOWS\System32\drivers\filecrypt.sys F44F666B0EACC3181544FFCF8CA0FFC7
C:\WINDOWS\System32\drivers\fileinfo.sys 78A210DDFDF2C9EC884631D2DAA573F0
C:\WINDOWS\System32\drivers\filetrace.sys 1A97DB5E701A186989F3795223C3BE39
C:\WINDOWS\System32\drivers\flpydisk.sys 46626665F0E5906E45619B4EFD6186B8
C:\WINDOWS\System32\drivers\fltmgr.sys FDA72ACA14D516D18C33AFCD0FD9260F
C:\WINDOWS\System32\drivers\FsDepends.sys B07A40B5A7A58B8C75663A572A46084C
C:\Windows\System32\Drivers\Fs_Rec.sys 6D6BB5C7363CD35FA715E826F3D029EE
C:\WINDOWS\System32\DRIVERS\fvevol.sys 8EEC4925C03E375C4EC496E45C44139A
C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 8E98D21EE06192492A5671A6144D092F
C:\WINDOWS\System32\drivers\vmgencounter.sys EF78034773CE506323655A868C949144
C:\WINDOWS\System32\drivers\genericusbfn.sys B55FEBC6A00DAA1FE074F020B6907516
C:\WINDOWS\System32\Drivers\msgpioclx.sys DDD8A8CDDC7F13EF57D1DAAE71865936
C:\WINDOWS\System32\drivers\gpuenergydrv.sys 7ACD8F69B5D6EC97E6D2C006E19BED88
C:\WINDOWS\System32\drivers\HDAudBus.sys 10E3515FE5DBA6656FA62C29342EC4A1
C:\WINDOWS\System32\drivers\HidBatt.sys B90D284B97CD4CA9DE7430AAAD887A56
C:\WINDOWS\System32\drivers\hidbth.sys B2FE11643CC6ACDEE6C247DD36018FDB
C:\WINDOWS\System32\drivers\hidi2c.sys D24355488A2D4D2323518EC1AC7A6D9E
C:\WINDOWS\System32\drivers\hidinterrupt.sys 0AF9ABBA4F3F55C6C803890D64BC3C29
C:\WINDOWS\System32\drivers\hidir.sys CDBCF8E9AB06D88A1E1191D32F320C5D
C:\WINDOWS\System32\drivers\hidusb.sys D8536CB438CC4CCDAE047B768EED22B2
C:\WINDOWS\System32\drivers\HpSAMD.sys F5CA18197B4646E04DB9EB2D6642CC4D
C:\WINDOWS\System32\drivers\HTTP.sys A10C7C1E69FC90620C7BF2E51302A01F
C:\WINDOWS\System32\drivers\hvservice.sys 74FC79C52395B10FFD0B55CF22CF88FC
C:\WINDOWS\System32\drivers\hwpolicy.sys 771EDDA9830A3079F996F34D681FB6E5
C:\WINDOWS\System32\drivers\hyperkbd.sys 3B9F315E7FA72CC25228EB097DD9C694
C:\WINDOWS\System32\drivers\i8042prt.sys B54B30992620C97230013A74461C8517
C:\WINDOWS\System32\drivers\iagpio.sys C6B8743B213F06AA60943D8366FE968F
C:\WINDOWS\System32\drivers\iai2c.sys 9A2A2F3C69B9A30B6E78536F6D258BAD
C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys 5A0E850F8CD17791A3E6A3CF81D0CA28
C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys 7508F1096803385D6376BFD0BD473AC4
C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys 16A10CCEDCF5AC4CAAE43DC9FC40392F
C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys EB82A11613326691508D9ED9A4FE29E7
C:\WINDOWS\System32\drivers\iaStorAV.sys 97E553D03219D3D51705C7235D9EAEBD
C:\WINDOWS\System32\drivers\iaStorV.sys 8350FE3BCDE3428BC040877BB7E9EAEB
C:\WINDOWS\System32\drivers\ibbus.sys 3BA03F7C7700DDF4C383DDE9252F5817
C:\WINDOWS\System32\drivers\IndirectKmd.sys 2A01C96DF5802D3434634E55C91232D8
C:\WINDOWS\System32\drivers\intelide.sys 9F7E87F6595D065A8A200A291043045E
C:\WINDOWS\System32\drivers\intelpep.sys A6BD2E20AE1BC5CB2776C87C28E4F4CA
C:\WINDOWS\System32\drivers\intelppm.sys 2A48DA39542636DB0FA3BA915385D1B3
C:\WINDOWS\System32\drivers\iorate.sys DB32758F3A7F6CCE81A5430080A2EA65
C:\WINDOWS\System32\DRIVERS\ipfltdrv.sys FE85D0A86CA7A5A99CF8CD04DE7F80AE
C:\WINDOWS\System32\drivers\IPMIDrv.sys 10D01A3657AC8E8004C83D613163DE1E
C:\WINDOWS\System32\drivers\ipnat.sys F1DAECC3B3D6399875D4F10529D6A77C
C:\WINDOWS\system32\drivers\irda.sys 7475A2903BB704B446AA6309E34D3362
C:\WINDOWS\System32\drivers\irenum.sys 9725E7F0C64CE9916A5CDABE8D6E13C3
C:\WINDOWS\System32\drivers\isapnp.sys 58040898883A96160D41739C80328BBF
C:\WINDOWS\System32\drivers\msiscsi.sys CA20F4621AB8CD3F69199DE21B5B41C4
C:\WINDOWS\System32\drivers\kbdclass.sys 210808437570BDDEE71A43535E3A2D30
C:\WINDOWS\System32\drivers\kbdhid.sys 0B779E9FC426CA2268D28181FA6C222F
C:\WINDOWS\System32\drivers\kdnic.sys 813BA3EB2CE038F2A5382DDD75CAD60B
C:\WINDOWS\System32\Drivers\ksecdd.sys 705C0F8BCCEF6E7CB704CCB454192D7E
C:\WINDOWS\System32\Drivers\ksecpkg.sys 55AD13E2BAFC5AB53A10F8C271F5D242
C:\WINDOWS\system32\drivers\ksthunk.sys 4ED115CD1A1099705F56B5E0FFF97CC6
C:\WINDOWS\System32\drivers\L1C63x64.sys 4E444F41E69BBE2E0BAE34D5DFCB5732
C:\WINDOWS\System32\drivers\lltdio.sys 5933A6673F00D8255C52957E40C2D601
C:\WINDOWS\system32\drivers\LMIRfsDriver.sys C57D3FAA50E6F395759FFB7C709BD944
C:\WINDOWS\System32\drivers\lsi_sas.sys 8E1B0946948CCC0BC1FA3CB70374A795
C:\WINDOWS\System32\drivers\lsi_sas2i.sys 4F68163FC04C973500DC4DA0946917B0
C:\WINDOWS\System32\drivers\lsi_sas3i.sys E5AC5F2815938651CDCC27F425474673
C:\WINDOWS\System32\drivers\lsi_sss.sys CCF6EC9FB9B8F18E05B4253E81013E48
C:\WINDOWS\system32\drivers\luafv.sys C9579D32219E5B936AC3A48D470117EC
C:\WINDOWS\System32\drivers\megasas.sys C3CDCCF07486BD2616A7B82946E07AC0
C:\WINDOWS\System32\drivers\MegaSas2i.sys 2CF0CB2A0ED68C5455371E84C16F9627
C:\WINDOWS\System32\drivers\megasr.sys FADB2FE017E69EECE0E1BA78661C2E8C
C:\WINDOWS\System32\drivers\mlx4_bus.sys FD60818B66B2E8A5415EA840E99A9D8F
C:\WINDOWS\system32\drivers\mmcss.sys 68F6977F1CFBAAC770D940A8C0326FA1
C:\WINDOWS\System32\drivers\modem.sys 0D50B3F3AB32D416786B58D4553859CE
C:\WINDOWS\System32\drivers\monitor.sys 9CCCB7FC3EDADEBA461D78615A6011A6
C:\WINDOWS\System32\drivers\mouclass.sys 27A07B2FB2E3057DA8DAEA4F25D843C7
C:\WINDOWS\System32\drivers\mouhid.sys 7BD6E7F7C9001AB21B8362CFFEE80B25
C:\WINDOWS\System32\drivers\mountmgr.sys F5BDAEE4B7D369D4C74668DCFBA3FF10
C:\WINDOWS\System32\drivers\mpsdrv.sys 30844BD376F9D01E62C820BEF446F1F8
C:\WINDOWS\system32\drivers\mrxdav.sys 25D32BE04FE0A23FDF57FD5382757672
C:\WINDOWS\System32\DRIVERS\mrxsmb.sys D559FF28B1AD9B1E15A4186E785E61F6
C:\WINDOWS\System32\DRIVERS\mrxsmb10.sys D4D12BC29DE0F09280868FDCA65B3474
C:\WINDOWS\System32\DRIVERS\mrxsmb20.sys 0698B15E21EA1B8742F2E7BB3142B754
C:\WINDOWS\System32\drivers\bridge.sys BEF575A5A8EC38F3BA6DB68D3CFFBD9A
C:\Windows\System32\Drivers\Msfs.sys F01B849D9D4A8CEAF32D4FDBD0B83C92
C:\WINDOWS\System32\drivers\msgpiowin32.sys 22ECD8F5D1DFADF2011BBB1700CB871D
C:\WINDOWS\System32\drivers\mshidkmdf.sys FD870F6968A145E4D2BA8A8842686B03
C:\WINDOWS\System32\drivers\mshidumdf.sys 30364757963A028CE5DF0FBAAC270173
C:\WINDOWS\System32\drivers\msisadrv.sys 6BB0FEDDAE7135FA37FFAFF4D9E0E876
C:\WINDOWS\system32\DRIVERS\MSKSSRV.sys 4586CDA25B7866DD9505CEECF9DB3C74
C:\WINDOWS\System32\drivers\mslldp.sys 642CDE46351D5D2D90311E77072AB46D
C:\WINDOWS\system32\DRIVERS\MSPCLOCK.sys F2302A5CE63CA7673200FAFCEEEDB6AF
C:\WINDOWS\system32\DRIVERS\MSPQM.sys 6114512EA26E835BA522C63635429DB5
C:\Windows\System32\Drivers\MsRPC.sys AA538E16E644D00E3BA5349BBA9598EC
C:\WINDOWS\System32\drivers\mssmbios.sys 0543BEFD41EC4D25C7F7CF36409CEC7D
C:\WINDOWS\system32\DRIVERS\MSTEE.sys C1569E4DB8EFE3617847BF041A3C842F
C:\WINDOWS\System32\drivers\MTConfig.sys 130B16970154BA9876B09E5C4BAC63BE
C:\WINDOWS\System32\Drivers\mup.sys 15D987C8F6CCD4AC94E070C5986762CB
C:\WINDOWS\System32\drivers\mvumis.sys 3D2C5B4995CA0751D32DEA0DE9FDFE44
C:\WINDOWS\System32\DRIVERS\nwifi.sys A5FA29F748BBF38FC3FAE4B54FA20A93
C:\WINDOWS\System32\drivers\ndfltr.sys 629CB21AC49C8867E0F29DF1C16DB7B4
C:\WINDOWS\System32\drivers\ndis.sys A530D0C58A657BCD1629816B887661CB
C:\WINDOWS\System32\drivers\ndiscap.sys 6DD605338FAAF6BA17662AA874E0D162
C:\WINDOWS\System32\drivers\NdisImPlatform.sys E34196F285F8B8879E1FF36C31F7179E
C:\WINDOWS\System32\DRIVERS\ndistapi.sys 1FAD2398673F30CEC616B89C46B7DCBA
C:\WINDOWS\System32\drivers\ndisuio.sys AEB8ECBE66CC46854066CB1F5623E179
C:\WINDOWS\System32\drivers\NdisVirtualBus.sys 7340104C2BF2F126714F7CDE85E63610
C:\WINDOWS\System32\drivers\ndiswan.sys 07ADC1F8DCBEB8104D75129B11584B8C
C:\WINDOWS\System32\DRIVERS\ndiswan.sys 07ADC1F8DCBEB8104D75129B11584B8C
C:\WINDOWS\System32\DRIVERS\NDProxy.sys 78A12E3DF035B5D054986949B19BE43C
C:\WINDOWS\System32\drivers\Ndu.sys 04C8859355C1DC9C0FA198D1894D71C2
C:\WINDOWS\system32\DRIVERS\netaapl64.sys EE00C544C025958AF50C7B199F3C8595
C:\WINDOWS\System32\drivers\NetAdapterCx.sys 6C76780A01FC2B885BD6E957B5C36B02
C:\WINDOWS\System32\drivers\netbios.sys 5D1513BD6430307C9DB86C6E351372ED
C:\WINDOWS\System32\DRIVERS\netbt.sys 6FEBB0A847FFD5F057B9AC8889F1B9A7
C:\WINDOWS\system32\drivers\npf.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Npfs.sys 001CBD7A2CD45C4EB39C01C3C677EF73
C:\WINDOWS\System32\drivers\npsvctrig.sys 90F5DC9802AAA00CD0B6E2AD9E7FFADC
C:\WINDOWS\System32\drivers\nsiproxy.sys 0C6218321A09A7B51BA7FFAFBA4CCB21
C:\Windows\System32\Drivers\NTFS.sys 8DB6A6B731CEC9046CD8CA0267EC5679
C:\Windows\System32\Drivers\Null.sys 6E6DD6F9DD2A034CF85E94047DBDB992
C:\WINDOWS\System32\drivers\nvraid.sys D261DF41F0840F734856A2B4F5E072C7
C:\WINDOWS\System32\drivers\nvstor.sys 23B702B555EB0436B9DAA0BC63DA65CE
C:\WINDOWS\System32\drivers\parport.sys 6B81BF7853D161DB8AC62CD8B9C2DE6B
C:\WINDOWS\System32\drivers\partmgr.sys 0553ECB742278C8F4CFA28B43FF20EAD
C:\WINDOWS\System32\drivers\pci.sys 29AF16726F4DD84376ECA85AB6AFF2C6
C:\WINDOWS\System32\drivers\pciide.sys 214DCC87E3898F738075D1341252A552
C:\WINDOWS\System32\drivers\pcmcia.sys AED76A3333B3A31536E430020E0226FC
C:\WINDOWS\System32\drivers\pcw.sys E63FB38B6E75B39467492FBAD2CD512A
C:\WINDOWS\System32\drivers\pdc.sys CA979960D3A580C78EDB4BBD6BD3ABCC
C:\WINDOWS\System32\drivers\peauth.sys 1509A77F840AA9E72CF8247D0CF2FBDE
C:\WINDOWS\System32\drivers\percsas2i.sys 540116170E2135FCD5DDE77702166B67
C:\WINDOWS\System32\drivers\percsas3i.sys 8356F87553BF49C703CF382033815898
C:\WINDOWS\System32\drivers\raspptp.sys 5645B9D9788CCA2C88B9534996ED2D6D
C:\WINDOWS\System32\drivers\processr.sys 372913E12677A8CBBBABDD8311894F9D
C:\WINDOWS\System32\drivers\pacer.sys FC98407B85A31161851FDE245517574F
C:\WINDOWS\system32\drivers\qwavedrv.sys 819602BBBFDB0BD46DEA3715BF0DD452
C:\WINDOWS\System32\DRIVERS\rasacd.sys CDF47037A0939F56D11F699629C276AD
C:\WINDOWS\System32\drivers\AgileVpn.sys 28C2EA278070EE12701D0EDF8CB0EC36
C:\WINDOWS\System32\drivers\rasl2tp.sys 17E565710172ED71B8531D8822E1C5D1
C:\WINDOWS\System32\DRIVERS\raspppoe.sys 726857E441D1D67F57694A1B613ABD34
C:\WINDOWS\System32\drivers\rassstp.sys F0F4EEDEEBEE7A4244FAFB96A16B5712
C:\WINDOWS\System32\DRIVERS\rdbss.sys 1A49C9F966A04D031DAD4C73C49D5288
C:\WINDOWS\System32\drivers\rdpbus.sys 79A415E6FA915EFC00297DAB16EC2635
C:\WINDOWS\System32\drivers\rdpdr.sys 7135785C21CA79D270D11037C43D3F19
C:\WINDOWS\System32\drivers\rdpvideominiport.sys 97A61A3CB2B5CB4FC32B3224EF333448
C:\WINDOWS\System32\drivers\rdyboost.sys 69BB204AE07EE84ECFAB1BF13C4BD04B
C:\Windows\System32\Drivers\ReFSv1.sys 940D6F5A2B0A61EE4170DF84F6C95C20
C:\WINDOWS\System32\drivers\rspndr.sys 5FF28F097C9699097B473F8FC7C1AA7D
C:\WINDOWS\system32\Drivers\RtsUer.sys AB959F26FBB851A9D31E2F229DB3FA1A
C:\WINDOWS\System32\drivers\vms3cap.sys B5DAEE69BACA64D2BB004568E22D8756
C:\WINDOWS\System32\drivers\sbp2port.sys 5E73FB63E2DBC75FE0C17DEB0010CE0E
C:\WINDOWS\System32\DRIVERS\scfilter.sys 3D9A82B03C92D1FEC42CB171D6F57778
C:\WINDOWS\System32\drivers\scmbus.sys B8B1D49283F33E3FFFDB611E51BCA7E5
C:\WINDOWS\System32\drivers\scmdisk0101.sys B6F2363584E62960846F7C3F00124A4F
C:\WINDOWS\System32\drivers\sdbus.sys 08ED027CD8A43E3412BDD134A43B13E8
C:\WINDOWS\System32\drivers\sdstor.sys 120DFCB71D6C502613A9E2D50E16850C
C:\WINDOWS\System32\drivers\SerCx.sys 401D706DDC0A7AF18C3DD228ADF74551
C:\WINDOWS\System32\drivers\SerCx2.sys 7084D11083F0CDCA8B5C76F9846ABF5D
C:\WINDOWS\System32\drivers\serenum.sys 3FF478A8ED32A83C36581425F6282B6C
C:\WINDOWS\System32\drivers\serial.sys 92509187AA171A80521528B36F753E1D
C:\WINDOWS\System32\drivers\sermouse.sys 433D38FF6D08B993847EA2A10EB8CB52
C:\WINDOWS\System32\drivers\sfloppy.sys 697D3EE0740AEAB62B66ABCA1C83D13B
C:\WINDOWS\System32\drivers\SiSRaid2.sys A34CE1830E45DA98932295FDE4B7908A
C:\WINDOWS\System32\drivers\sisraid4.sys A7B5C670770E908DA5FEF5BF1136E933
C:\WINDOWS\System32\DRIVERS\snapman.sys 32CDE417100C530964E79C53B4E994CA
C:\WINDOWS\System32\drivers\spaceport.sys A265FF86BF4C03F47EC277881138675D
C:\WINDOWS\System32\drivers\SpbCx.sys E03264C4C25B568F92ED1656AD541E64
C:\WINDOWS\System32\DRIVERS\srv.sys 2E0F160AFE1EB7E8C21D6FE782FFFE0B
C:\WINDOWS\System32\DRIVERS\srv2.sys A0BDA7332A9EE59062A7037D161C8715
C:\WINDOWS\System32\DRIVERS\srvnet.sys F13EE0DB1FB1D6946AC3228D7EFCFC8F
C:\WINDOWS\system32\DRIVERS\ssudmdm.sys F0B59ADCD06BCEB9D47311B7041CA2C9
C:\WINDOWS\System32\drivers\stexstor.sys 29D26E1347AE1BBD4201014E19880B2C
C:\WINDOWS\system32\DRIVERS\stwrt64.sys 71CB3BB20F08BB724769DAAAFD5AB26E
C:\WINDOWS\system32\DRIVERS\serscan.sys B11724BFE7DA1BA55903B4D849415F1A
C:\WINDOWS\System32\drivers\storahci.sys 6BC6023E866489D22CE30E18846B80D9
C:\WINDOWS\System32\drivers\vmstorfl.sys C5E0ACE4771F5575D9D5B457ABF3AD03
C:\WINDOWS\System32\drivers\stornvme.sys B66D8C75C9BC59D637177AB3B1C569A6
C:\WINDOWS\System32\drivers\storqosflt.sys BEBF85EB4D90E6996047DA027D0ED26E
C:\WINDOWS\System32\drivers\storufs.sys 8E73037A6F8938475692FFCC26EBF385
C:\WINDOWS\System32\drivers\storvsc.sys 9D9DED47DA10E845EFF2DD57C94C809B
C:\WINDOWS\System32\drivers\swenum.sys 505E0C40B5D0ADDCBB414640F59BD2E0
C:\WINDOWS\System32\drivers\Synth3dVsc.sys 32F46FB0F290D16DAA452B289C985795
C:\WINDOWS\System32\drivers\tcpip.sys 4ED37041ADB4BD4BEEB1279AFA5808A9
C:\WINDOWS\System32\drivers\tcpip.sys 4ED37041ADB4BD4BEEB1279AFA5808A9
C:\WINDOWS\System32\drivers\tcpipreg.sys EC9450227A4C661513661F1F9C1F7DD6
C:\WINDOWS\system32\DRIVERS\tdx.sys A7C267671EDDF066E8CFBF897BC4B626
C:\WINDOWS\System32\drivers\terminpt.sys 06130AFFECEB94525FC2352936576B70
C:\WINDOWS\System32\drivers\timntr.sys 6ADC063FD51F03EF0CAB3E716A725BD2
C:\WINDOWS\System32\drivers\tpm.sys 46171262D0E806779DEEDFCAB2F830CC
C:\Windows\System32\drivers\TrueSight.sys 0D5A09B08568760AE85A801FCBC0F83D
C:\WINDOWS\System32\drivers\TsUsbFlt.sys A6F4025664C9D4BC2A9EDAB4092706D7
C:\WINDOWS\System32\drivers\TsUsbGD.sys 37A96AD493E110C0BF1EE0AC0F9E7DBD
C:\WINDOWS\System32\drivers\tunnel.sys 79E264287F17D56D768440B0270466DE
C:\WINDOWS\System32\drivers\uaspstor.sys AA65954F512BA097DD190790876DD991
C:\WINDOWS\System32\Drivers\UcmCx.sys AB6268022C3A5B529075A39C33904DA6
C:\WINDOWS\System32\Drivers\UcmTcpciCx.sys 7ED2EDA43D21C7A5F589A7960E265C52
C:\WINDOWS\System32\drivers\UcmUcsi.sys 169351463039B45F5CDED9768879F712
C:\WINDOWS\System32\drivers\ucx01000.sys 08A9E3AD29B215484FBB68CDC175DF3A
C:\WINDOWS\System32\drivers\udecx.sys DA70AEE267491AA56BC63AA0C0C96CA2
C:\WINDOWS\System32\DRIVERS\udfs.sys FBC5ECF6D5A868D0B116C2DBB02B8168
C:\WINDOWS\System32\drivers\UEFI.sys B918E40FAA9CD118CCA4AD388B748C98
C:\WINDOWS\System32\drivers\ufx01000.sys 0FD75222C1AD2687AB365BEBEA400DD4
C:\WINDOWS\System32\drivers\UfxChipidea.sys C1A78C53E01C641AE41BFA65797819F5
C:\WINDOWS\System32\drivers\ufxsynopsys.sys 767307212110EBEFB93EC9A5BE9E85B9
C:\WINDOWS\System32\drivers\umbus.sys DC460AAA18CA2342FBBFB2DF9B044472
C:\WINDOWS\System32\drivers\umpass.sys C3CF0377917ECE6D65D7623E1E61568F
C:\WINDOWS\System32\drivers\urschipidea.sys 6B46FC140C9AF68E6E7697D66D59CB4D
C:\WINDOWS\System32\drivers\urscx01000.sys B4402E7F0923F660270442CE76877ABE
C:\WINDOWS\System32\drivers\urssynopsys.sys 9DD431F1B94789CFB527E5D19261F124
C:\WINDOWS\System32\Drivers\usbaapl64.sys C9E9D59C0099A9FF51697E9306A44240
C:\WINDOWS\system32\drivers\usbaudio.sys 93F169DE94DBAC5DAF4755AFF10193DD
C:\WINDOWS\System32\drivers\usbccgp.sys C87E32B90F085970D9637FBAD45EF6FE
C:\WINDOWS\System32\drivers\usbcir.sys 0B663856474AC41924D9E9112203858F
C:\WINDOWS\System32\drivers\usbehci.sys F83D2250256203AC5DA5E8601C1AFDD7
C:\WINDOWS\System32\drivers\usbhub.sys 7FFD26742321919590ED77FCA556D65F
C:\WINDOWS\System32\drivers\UsbHub3.sys 7A749B2863B5561BE34B39E8E249AD8F
C:\WINDOWS\System32\drivers\usbohci.sys D2109F1F4FEBF1DAC415CDC5DE876479
C:\WINDOWS\System32\drivers\usbprint.sys 29C9572F2D061CFC3C0BD48A3163E343
C:\WINDOWS\System32\drivers\usb80236.sys 4BAAADF7DA222BB74E9A0A01CCF42A80
C:\WINDOWS\system32\DRIVERS\usbscan.sys 2EC7B2C8123236B1233A77281D378DF7
C:\WINDOWS\System32\drivers\usbser.sys 429477D6DEF3321FF7D3EF23CAAADA00
C:\WINDOWS\System32\drivers\USBSTOR.SYS 0CC16F7B91C57AE9A4E44425A295FDAA
C:\WINDOWS\System32\drivers\usbuhci.sys C917D09064CDBD18F75ADC9B2C48F847
C:\WINDOWS\System32\drivers\USBXHCI.SYS 58827BEFC54D4396D3FD191F5DD31C1D
C:\WINDOWS\System32\drivers\usb8023x.sys 836828E40B9EEFBC77B3032DB677555C
C:\WINDOWS\System32\drivers\vdrvroot.sys 0CBDE344FB48E42D78E29469F202ADBC
C:\WINDOWS\System32\drivers\VerifierExt.sys 723195568C8755CAD57F7933C5F2C5C2
C:\WINDOWS\System32\drivers\vhdmp.sys F7F3E80E84E51A6F89831A6F26056A98
C:\WINDOWS\System32\drivers\vhf.sys 7929228F0E8B0C2FA0495A17A4FC27F6
C:\WINDOWS\System32\drivers\vididr.sys 96A4F56CBBA3DCF5D90CDA1BC218D040
C:\WINDOWS\System32\DRIVERS\vsflt53.sys C69A784BEC737CD7460EBF3C3834D65E
C:\WINDOWS\System32\drivers\vmbus.sys AEE432ED868831B1F068E373598F6D93
C:\WINDOWS\System32\drivers\VMBusHID.sys 9444B23FC694B5F90F21B0FC7F10D8DD
C:\WINDOWS\System32\drivers\vmgid.sys 4D0287F566B36536DD812A54C015FC4A
C:\WINDOWS\System32\drivers\volmgr.sys 29075915F9BDC3437F8BED71C067D399
C:\WINDOWS\System32\drivers\volmgrx.sys 6BDB6CE6D2D9E3D3F28F1C97E12B62E2
C:\WINDOWS\System32\drivers\volsnap.sys BF2546583BB75F01DDA60A7921DFB230
C:\WINDOWS\System32\drivers\volume.sys AC2E20A74D09D24485BE8396CE04F07B
C:\WINDOWS\System32\drivers\vpci.sys 92F6E3E6D3F1795263EB34B37F74AEF7
C:\WINDOWS\System32\drivers\vsmraid.sys FD9BCB8920973CEAD4D49DC7A6D8A618
C:\WINDOWS\System32\drivers\vstxraid.sys 0C111F220798CCE80484026E06822379
C:\WINDOWS\System32\drivers\vwifibus.sys 607639716E9DB1CEF4E18B5B229293B4
C:\WINDOWS\System32\drivers\vwififlt.sys B1ED64E628763148BF84FBE23F2AD711
C:\WINDOWS\System32\drivers\vwifimp.sys B1133B813E4CBF258A392CA08255BA24
C:\WINDOWS\System32\drivers\wacompen.sys 55D00B785A7587F4263D125817871283
C:\WINDOWS\System32\DRIVERS\wanarp.sys CEF3D306C09BEC1A800E9B4A06F859F6
C:\WINDOWS\System32\DRIVERS\wanarp.sys CEF3D306C09BEC1A800E9B4A06F859F6
C:\WINDOWS\system32\drivers\wcifs.sys E330144B97D493AA886000DCAAA8DAF5
C:\WINDOWS\system32\drivers\wcnfs.sys AEA1093B751339267D8C8C1EF3D669CF
C:\WINDOWS\system32\drivers\WdBoot.sys D520B1B849B6D4D707AB31722B952C2D
C:\WINDOWS\System32\drivers\Wdf01000.sys 5030C76047D756263093A47B82970868
C:\WINDOWS\system32\drivers\WdFilter.sys 29FF9199EDEB4F5470BB134D1A2563D2
C:\WINDOWS\System32\DRIVERS\wdiwifi.sys EDC08B8D3E67F96688774841C247B82A
C:\WINDOWS\System32\Drivers\WdNisDrv.sys 17CF416CFF408190F5A4CBD79AB12E55
C:\WINDOWS\System32\drivers\wfplwfs.sys E1785942AC51FEE6826CDF02075C5AA9
C:\WINDOWS\System32\drivers\wimmount.sys 0CF79A0EACFFBB75A50A469A27696D02
C:\WINDOWS\System32\drivers\WindowsTrustedRT.sys 0DE131733317EB4BE67028366B0CAAC6
C:\WINDOWS\System32\drivers\WindowsTrustedRTProxy.sys 92EB5D38BDF10C790450F3E46BF93A0E
C:\WINDOWS\System32\drivers\winmad.sys F95DE20312ACCA7761446DE152BD1F7C
C:\WINDOWS\System32\drivers\WinUSB.SYS 4EFB346BFDAEEB29316AA52BBB9852B1
C:\WINDOWS\System32\drivers\winverbs.sys 8B9AFF5F08E66A6F1F1063DEC9457FB6
C:\WINDOWS\System32\drivers\wmiacpi.sys 6F4F4F5A007D1710BD76FB311DA97C07
C:\Windows\System32\Drivers\Wof.sys 43C8D087B31C592163B33A4BDA540E40
C:\WINDOWS\System32\drivers\WpdUpFltr.sys 75A9284F01FE7CB1A7D5EAE5C1EB4F33
C:\WINDOWS\system32\drivers\ws2ifsl.sys 36D7B73ADC3E10607ED6EC874AFB5D1E
C:\WINDOWS\System32\drivers\WudfPf.sys AED7FE551E8672B824A56324076183EB
C:\WINDOWS\System32\drivers\WudfRd.sys CEFAB17FD7DFCFA515626C306262E89D
C:\WINDOWS\system32\DRIVERS\WUDFRd.sys CEFAB17FD7DFCFA515626C306262E89D
C:\WINDOWS\system32\DRIVERS\WUDFRd.sys CEFAB17FD7DFCFA515626C306262E89D
C:\WINDOWS\System32\drivers\xboxgip.sys DB77764B46D02DCB9777D9E00A3F7D63
C:\WINDOWS\System32\drivers\xinputhid.sys 63088A3361D9A308F328F11E9099DD87
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Three Months Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-11 05:28 - 2017-07-11 05:28 - 00143683 _____ C:\Users\AIRWORX 2\Desktop\Shortcut.txt
2017-07-11 05:27 - 2017-07-11 05:28 - 00060261 _____ C:\Users\AIRWORX 2\Desktop\Addition.txt
2017-07-11 05:26 - 2017-07-11 05:31 - 00044901 _____ C:\Users\AIRWORX 2\Desktop\FRST.txt
2017-07-11 05:23 - 2017-07-11 05:31 - 00000000 ____D C:\FRST
2017-07-11 05:23 - 2017-07-11 05:23 - 02437120 _____ (Farbar) C:\Users\AIRWORX 2\Desktop\FRST64.exe
2017-07-11 05:08 - 2017-07-11 05:09 - 05659194 _____ (Swearware) C:\Users\AIRWORX 2\Desktop\ComboFix.exe
2017-07-11 05:07 - 2017-07-11 05:07 - 00005552 _____ C:\Users\AIRWORX 2\Desktop\rk_7112.tmp
2017-07-11 04:04 - 2017-07-11 04:04 - 00028272 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2017-07-11 04:03 - 2017-07-11 05:12 - 00000000 ____D C:\ProgramData\RogueKiller
2017-07-11 04:03 - 2017-07-11 04:03 - 00000906 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2017-07-11 04:03 - 2017-07-11 04:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2017-07-11 04:03 - 2017-07-11 04:03 - 00000000 ____D C:\Program Files\RogueKiller
2017-07-11 03:59 - 2017-07-11 04:00 - 00000000 _____ C:\Users\AIRWORX 2\Desktop\RogueKiller.exe
2017-07-11 03:45 - 2017-07-11 03:45 - 00142648 _____ C:\Users\AIRWORX 2\Desktop\Extras.Txt
2017-07-11 03:42 - 2017-07-11 03:48 - 00234236 _____ C:\Users\AIRWORX 2\Desktop\OTL.Txt
2017-07-11 03:23 - 2017-07-11 03:24 - 00602112 _____ (OldTimer Tools) C:\Users\AIRWORX 2\Desktop\OTL.exe
2017-07-10 10:51 - 2017-07-10 10:51 - 00000000 ____D C:\Users\AirworxAZ\AppData\LocalLow\Adobe
2017-07-10 10:51 - 2017-07-10 10:51 - 00000000 ____D C:\Users\AirworxAZ\AppData\Local\Adobe
2017-07-10 10:36 - 2017-07-10 10:36 - 00000000 ____D C:\Users\AirworxAZ\AppData\Roaming\Macromedia
2017-07-10 10:31 - 2017-07-10 10:51 - 00000000 ____D C:\Users\AirworxAZ\AppData\Roaming\Adobe
2017-07-10 10:15 - 2017-07-10 10:15 - 00000000 ____D C:\Users\AirworxAZ\AppData\Roaming\Zeon
2017-07-10 10:15 - 2017-07-10 10:15 - 00000000 ____D C:\Users\AirworxAZ\AppData\Local\Packages
2017-07-10 10:14 - 2017-07-10 10:31 - 00000000 ____D C:\Users\AirworxAZ
2017-07-10 10:14 - 2017-07-10 10:14 - 00000020 ___SH C:\Users\AirworxAZ\ntuser.ini
2017-07-10 10:14 - 2017-07-10 10:14 - 00000000 _SHDL C:\Users\AirworxAZ\My Documents
2017-07-10 10:14 - 2017-07-10 10:14 - 00000000 _SHDL C:\Users\AirworxAZ\Documents\My Videos
2017-07-10 10:14 - 2017-07-10 10:14 - 00000000 _SHDL C:\Users\AirworxAZ\Documents\My Pictures
2017-07-10 10:14 - 2017-07-10 10:14 - 00000000 _SHDL C:\Users\AirworxAZ\Documents\My Music
2017-07-10 10:14 - 2017-07-10 10:14 - 00000000 ____D C:\Users\AirworxAZ\AppData\Local\TileDataLayer
2017-07-10 10:14 - 2017-07-10 10:14 - 00000000 ____D C:\Users\AirworxAZ\AppData\Local\ConnectedDevicesPlatform
2017-07-10 10:14 - 2016-09-30 14:21 - 00000000 ____D C:\Users\AirworxAZ\Documents\hp.system.package.metadata
2017-07-10 10:14 - 2016-09-30 14:21 - 00000000 ____D C:\Users\AirworxAZ\Documents\hp.applications.package.appdata
2017-07-10 10:14 - 2016-09-30 14:21 - 00000000 ____D C:\Users\AirworxAZ\AppData\Local\Microsoft Help
2017-07-10 10:14 - 2016-09-30 14:21 - 00000000 ____D C:\Users\AirworxAZ\AppData\Local\Google
2017-07-10 09:38 - 2017-07-10 09:38 - 00002339 _____ C:\Users\AIRWORX 2\Desktop\Google Chrome.lnk
2017-07-10 07:25 - 2017-07-10 07:25 - 00195346 _____ C:\Users\AIRWORX 2\Documents\wu170509.diagcab
2017-07-10 07:16 - 2017-07-10 07:16 - 130903960 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\MRT.exe
2017-07-10 06:58 - 2017-07-10 15:44 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2017-07-10 04:54 - 2017-07-10 04:53 - 00009804 _____ C:\Users\AIRWORX 2\Documents\GatewaySettings.bin
2017-07-10 04:53 - 2017-07-10 04:53 - 00009804 _____ C:\Users\AIRWORX 2\Downloads\GatewaySettings.bin
2017-07-10 04:53 - 2017-07-10 04:53 - 00009804 _____ C:\Users\AIRWORX 2\Downloads\GatewaySettings (1).bin
2017-07-08 03:06 - 2017-07-08 03:06 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\GoToMeeting
2017-07-07 09:56 - 2017-07-10 06:17 - 14379154 _____ C:\Users\AIRWORX 2\Desktop\calls and txtsBook2.xlsx
2017-07-07 09:40 - 2017-07-06 14:49 - 10381776 ____N C:\Users\AIRWORX 2\Desktop\SMSBackup.xml
2017-07-07 09:40 - 2017-07-06 14:48 - 00229555 ____N C:\Users\AIRWORX 2\Desktop\CallLogBackup.xml
2017-07-07 09:39 - 2017-07-07 09:39 - 00229555 _____ C:\Users\AIRWORX 2\Documents\CallLogBackup.xml
2017-07-07 09:34 - 2017-07-07 09:34 - 02066258 _____ C:\Users\AIRWORX 2\Downloads\Backup_Archive (1).zip
2017-07-07 09:31 - 2017-07-07 09:31 - 00190279 _____ C:\Users\AIRWORX 2\Documents\calls.txt
2017-07-07 09:29 - 2017-07-07 09:29 - 02052994 _____ C:\Users\AIRWORX 2\Downloads\Backup_20170627192522.zip
2017-07-07 09:29 - 2017-06-27 19:25 - 10333207 ____N C:\Users\AIRWORX 2\Downloads\SMSBackup.xml
2017-07-07 09:29 - 2017-06-27 19:25 - 00190279 ____N C:\Users\AIRWORX 2\Downloads\CallLogBackup.xml
2017-07-07 09:28 - 2017-07-07 09:28 - 02066258 _____ C:\Users\AIRWORX 2\Downloads\Backup_Archive.zip
2017-07-06 12:30 - 2017-07-06 12:30 - 00002603 _____ C:\Users\Public\Desktop\POS - Rock Gym Pro.lnk
2017-07-06 12:30 - 2017-07-06 12:30 - 00002603 _____ C:\Users\Public\Desktop\Data Entry - Rock Gym Pro.lnk
2017-07-06 11:46 - 2017-07-06 11:46 - 00002775 _____ C:\Users\AIRWORX 2\Downloads\images.jpeg
2017-06-30 10:07 - 2017-06-30 10:08 - 00318450 _____ C:\Users\AIRWORX 2\Documents\CallLogBackup.pdf
2017-06-29 14:34 - 2017-06-29 14:49 - 00024040 _____ C:\Users\AIRWORX 2\Documents\scan333.pdf
2017-06-29 10:52 - 2017-06-29 10:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-06-29 10:44 - 2017-06-29 10:44 - 00000000 __SHD C:\found.000
2017-06-29 10:39 - 2017-06-29 10:39 - 00022330 _____ C:\Users\AIRWORX 2\Documents\support_chat_transcript_c6910346d48b4a6ea2b2f7e1f65f9d4d.txt
2017-06-29 10:02 - 2017-06-29 10:02 - 00000165 ____H C:\Users\AIRWORX 2\Documents\~$SmsBackup.xlsx
2017-06-29 10:02 - 2017-06-29 10:02 - 00000165 ____H C:\Users\AIRWORX 2\Documents\~$CallLogBackup.xlsx
2017-06-29 09:43 - 2017-06-29 09:44 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\.bomgartemp-d443567a9bbd939a6ce635dd5b61ef55-shl-screen_sharingcontextId-cs-2
2017-06-29 09:42 - 2017-06-29 09:43 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\.bomgartemp-d443567a9bbd939a6ce635dd5b61ef55-shl-screen_sharingcontextId-cs-1
2017-06-29 08:54 - 2017-06-29 09:44 - 00000000 ____D C:\CCSupport
2017-06-29 08:54 - 2017-06-29 08:55 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\.bomgartemp-d443567a9bbd939a6ce635dd5b61ef55-shl-screen_sharingcontextId-cs-0
2017-06-29 08:30 - 2017-06-29 08:31 - 00000000 _____ C:\Users\AIRWORX 2\AppData\Local\{3E1C46B4-AE1C-47D4-A253-B086FFB08406}
2017-06-29 08:28 - 2017-06-29 08:31 - 00000000 _____ C:\Users\AIRWORX 2\AppData\Local\{78ACC633-3A05-418D-841A-B650CBA92BFF}
2017-06-29 08:15 - 2017-06-29 08:15 - 00000000 _____ C:\Users\AIRWORX 2\AppData\Local\{A8386299-DD6B-4871-AC75-168430E1797F}
2017-06-29 08:14 - 2017-06-29 08:14 - 00000000 _____ C:\Users\AIRWORX 2\AppData\Local\{F4796B34-AD33-4594-B511-F95371E88EEA}
2017-06-29 08:14 - 2017-06-29 08:14 - 00000000 _____ C:\Users\AIRWORX 2\AppData\Local\{E908C560-4859-4F24-905D-9A65B1BE63E1}
2017-06-29 08:14 - 2017-06-29 08:14 - 00000000 _____ C:\Users\AIRWORX 2\AppData\Local\{E626A012-0E1A-494A-9AB8-0870767076F6}
2017-06-29 08:14 - 2017-06-29 08:14 - 00000000 _____ C:\Users\AIRWORX 2\AppData\Local\{89363267-36DC-427C-A99A-0AEA97994C65}
2017-06-29 08:14 - 2017-06-29 08:14 - 00000000 _____ C:\Users\AIRWORX 2\AppData\Local\{2A86C33F-824B-4295-8831-2FA8CE8A3C08}
2017-06-28 16:45 - 2017-07-10 06:30 - 00000372 _____ C:\WINDOWS\Tasks\HPCeeScheduleForAIRWORX 2.job
2017-06-28 16:45 - 2017-07-05 16:19 - 00003280 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForAIRWORX 2
2017-06-27 16:06 - 2017-07-10 06:57 - 00000000 ____D C:\WINDOWS\pss
2017-06-27 14:40 - 2017-06-27 14:40 - 00000000 ____H C:\Users\AIRWORX 2\Documents\~WRL2295.tmp
2017-06-27 14:16 - 2017-06-30 10:10 - 03060490 _____ C:\Users\AIRWORX 2\Documents\SmsBackup.xlsx
2017-06-27 12:46 - 2017-06-27 12:55 - 00157872 _____ C:\Users\AIRWORX 2\Desktop\webmail.htm
2017-06-27 11:16 - 2017-07-10 06:17 - 24330548 _____ C:\Users\AIRWORX 2\Documents\CallLogBackup.xlsx
2017-06-27 09:55 - 2017-06-27 09:55 - 01827895 _____ C:\Users\AIRWORX 2\Documents\Backup_2017-06-27 08-04-03.zip
2017-06-27 05:05 - 2017-06-27 05:05 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\Belkasoft
2017-06-27 05:02 - 2017-06-27 05:02 - 00002244 _____ C:\Users\Public\Desktop\Belkasoft Evidence Center Ultimate.lnk
2017-06-27 05:02 - 2017-06-27 05:02 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\Passware
2017-06-27 05:02 - 2017-06-27 05:02 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\Belkasoft
2017-06-27 05:02 - 2017-06-27 05:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belkasoft Evidence Center Ultimate
2017-06-27 05:02 - 2017-06-27 05:02 - 00000000 ____D C:\ProgramData\Belkasoft
2017-06-27 05:01 - 2017-06-27 05:02 - 00000000 ____D C:\Program Files (x86)\Belkasoft Evidence Center Ultimate
2017-06-26 18:44 - 2017-06-26 18:44 - 00000000 _____ C:\Users\AIRWORX 2\AppData\Local\{A5A12D5E-AE8C-4443-9C77-6230BEBDBB88}
2017-06-26 13:56 - 2017-06-26 13:57 - 44060880 _____ (Microsoft Corporation) C:\Users\AIRWORX 2\Documents\Windows-KB890830-x64-V5.49.exe
2017-06-26 10:24 - 2017-06-26 10:25 - 06754944 _____ (ESET spol. s r.o.) C:\Users\AIRWORX 2\Documents\esetonlinescanner_enu.exe
2017-06-26 09:52 - 2017-06-28 07:52 - 00181160 _____ (ESET) C:\WINDOWS\system32\Drivers\ESETCleanersDriver.sys
2017-06-26 07:43 - 2017-07-10 06:49 - 00002065 _____ C:\Users\Public\Desktop\ESET Banking & Payment protection.lnk
2017-06-26 07:42 - 2017-06-26 07:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2017-06-26 07:42 - 2017-06-26 07:42 - 00000000 ____D C:\ProgramData\ESET
2017-06-26 07:38 - 2017-06-26 07:40 - 120950400 _____ (ESET) C:\Users\AIRWORX 2\Documents\ess_nt64_enu.exe
2017-06-26 07:35 - 2017-06-26 07:36 - 114369664 _____ (ESET) C:\Users\AIRWORX 2\Documents\ess_nt32_enu.exe
2017-06-26 07:22 - 2017-06-26 07:22 - 00228669 _____ C:\Users\AIRWORX 2\Downloads\0,2817,2346862,00.asp
2017-06-26 07:22 - 2017-06-26 07:22 - 00165520 _____ C:\Users\AIRWORX 2\Downloads\download (2).htm
2017-06-26 07:22 - 2017-06-26 07:22 - 00029518 _____ C:\Users\AIRWORX 2\Downloads\hitmanpro.aspx
2017-06-26 07:22 - 2017-06-26 07:22 - 00005247 _____ C:\Users\AIRWORX 2\Downloads\download (3).htm
2017-06-26 07:22 - 2017-06-26 07:22 - 00000886 _____ C:\Users\AIRWORX 2\Downloads\downloadcsi.asp
2017-06-26 07:21 - 2017-06-26 07:22 - 00008705 _____ C:\Users\AIRWORX 2\Downloads\download (1).htm
2017-06-26 07:21 - 2017-06-26 07:21 - 00123745 _____ C:\Users\AIRWORX 2\Downloads\malicious-software-removal-tool-details.htm
2017-06-26 07:21 - 2017-06-26 07:21 - 00070351 _____ C:\Users\AIRWORX 2\Downloads\download.htm
2017-06-26 03:27 - 2017-06-26 03:27 - 00049992 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2017-06-26 03:27 - 2017-06-26 03:27 - 00045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2017-06-26 03:27 - 2017-06-26 03:27 - 00045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2017-06-26 03:27 - 2017-06-26 03:27 - 00045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2017-06-25 07:56 - 2017-06-25 07:56 - 00004425 _____ C:\Users\AIRWORX 2\Downloads\taxcard.pdf
2017-06-23 03:59 - 2017-06-23 04:10 - 381811920 _____ C:\Users\AIRWORX 2\Downloads\Photos (5).zip
2017-06-22 13:22 - 2017-06-22 13:22 - 01619628 _____ C:\Users\AIRWORX 2\Downloads\Welcome Kit_TX FIXED PRICE PRODUCT.pdf
2017-06-22 13:22 - 2017-06-22 13:22 - 00243287 _____ C:\Users\AIRWORX 2\Downloads\ENGIE Resources LLC Energy agreement with National Trampoline Entertainment Dallas LLC - 3006 - CONT24780_encrypted_.pdf
2017-06-22 12:52 - 2017-06-22 12:52 - 00204075 _____ C:\Users\AIRWORX 2\Downloads\countersigned agreement .pdf
2017-06-22 11:44 - 2017-06-22 11:44 - 00043808 _____ C:\Users\AIRWORX 2\Downloads\CCR statement as of 06 June 2017 - 95269325.pdf
2017-06-21 06:06 - 2017-06-21 06:06 - 03357542 _____ C:\Users\AIRWORX 2\Downloads\acw-dg.pdf
2017-06-20 13:52 - 2017-06-20 13:52 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\LG Electronics
2017-06-20 08:54 - 2017-06-20 08:54 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\LG Electronics
2017-06-20 08:51 - 2017-06-23 13:26 - 00000000 ____D C:\ProgramData\LGMOBILEAX
2017-06-20 08:51 - 2017-06-23 13:17 - 00002760 _____ C:\WINDOWS\SysWOW64\lgAxconfig.ini
2017-06-20 08:51 - 2017-06-20 08:51 - 04009163 _____ C:\Users\AIRWORX 2\Downloads\LG-H811M_TMO_UG_Web_EN_V1.0_151216 (1).pdf
2017-06-20 08:51 - 2011-05-06 10:37 - 00655872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr90.dll
2017-06-20 08:51 - 2011-05-06 10:37 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp90.dll
2017-06-20 08:51 - 2011-05-06 10:37 - 00224768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcm90.dll
2017-06-20 08:51 - 2006-04-30 05:33 - 00053248 _____ () C:\WINDOWS\SysWOW64\CommonDL.dll
2017-06-20 08:51 - 2005-11-19 23:34 - 00082432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml4r.dll
2017-06-20 08:51 - 2005-09-29 22:39 - 00044544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml4a.dll
2017-06-20 08:51 - 2005-09-07 11:51 - 01233920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml4.dll
2017-06-20 08:47 - 2017-07-10 09:49 - 00000000 ____D C:\Program Files (x86)\LG Electronics
2017-06-17 12:29 - 2017-06-17 12:30 - 00000000 ____D C:\Users\AIRWORX 2\Desktop\Bluejay comps
2017-06-17 06:45 - 2017-06-17 06:45 - 00000000 ____D C:\Users\Public\Documents\CrashDump
2017-06-16 12:04 - 2017-07-10 15:42 - 00000000 ____D C:\Users\AIRWORX 2\Desktop\Babe
2017-06-16 06:17 - 2017-06-16 06:17 - 00002203 _____ C:\Users\Public\Desktop\Smart Switch.lnk
2017-06-15 14:47 - 2017-06-15 14:47 - 00368991 _____ C:\Users\AIRWORX 2\Downloads\CCF06142017 (1).pdf
2017-06-15 14:46 - 2017-06-15 14:46 - 00368991 _____ C:\Users\AIRWORX 2\Downloads\CCF06142017.pdf
2017-06-15 08:08 - 2017-06-15 08:08 - 00134695 _____ C:\Users\AIRWORX 2\Downloads\Payment Confirmationallen.pdf
2017-06-15 08:04 - 2017-06-15 08:04 - 00147005 _____ C:\Users\AIRWORX 2\Downloads\Payment Confirmation.pdf
2017-06-14 14:02 - 2017-06-14 14:02 - 01283439 _____ C:\Users\AIRWORX 2\Documents\scan332.pdf
2017-06-14 13:08 - 2017-06-14 13:08 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\UNP
2017-06-13 19:20 - 2017-06-13 19:21 - 00000000 ____D C:\Program Files\UNP
2017-06-13 19:20 - 2017-06-13 19:20 - 00000000 ____D C:\WINDOWS\system32\UNP
2017-06-13 19:13 - 2017-06-13 19:13 - 00000000 ___SD C:\WINDOWS\UpdateAssistantV2
2017-06-13 11:19 - 2017-06-03 03:50 - 00315744 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2017-06-13 11:19 - 2017-06-03 03:16 - 00279904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2017-06-13 11:19 - 2017-06-03 03:11 - 01706488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2017-06-13 11:19 - 2017-06-03 03:09 - 02213760 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2017-06-13 11:19 - 2017-06-03 03:06 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-06-13 11:19 - 2017-06-03 02:59 - 01181024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2017-06-13 11:19 - 2017-06-03 02:59 - 00118112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2017-06-13 11:19 - 2017-06-03 02:58 - 00340832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2017-06-13 11:19 - 2017-06-03 02:55 - 00780640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2017-06-13 11:19 - 2017-06-03 02:54 - 00187232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2017-06-13 11:19 - 2017-06-03 02:52 - 01021784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2017-06-13 11:19 - 2017-06-03 02:52 - 00607072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2017-06-13 11:19 - 2017-06-03 02:52 - 00111968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2017-06-13 11:19 - 2017-06-03 02:50 - 00857440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2017-06-13 11:19 - 2017-06-03 02:50 - 00381792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2017-06-13 11:19 - 2017-06-03 02:49 - 20967840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-06-13 11:19 - 2017-06-03 02:48 - 00857952 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2017-06-13 11:19 - 2017-06-03 02:48 - 00148832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2017-06-13 11:19 - 2017-06-03 02:45 - 22220864 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-06-13 11:19 - 2017-06-03 02:44 - 01412640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2017-06-13 11:19 - 2017-06-03 02:44 - 00545944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2017-06-13 11:19 - 2017-06-03 02:39 - 05686272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2017-06-13 11:19 - 2017-06-03 02:39 - 02532192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2017-06-13 11:19 - 2017-06-03 02:33 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2017-06-13 11:19 - 2017-06-03 02:32 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2017-06-13 11:19 - 2017-06-03 02:31 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll
2017-06-13 11:19 - 2017-06-03 02:31 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2017-06-13 11:19 - 2017-06-03 02:28 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll
2017-06-13 11:19 - 2017-06-03 02:28 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edputil.dll
2017-06-13 11:19 - 2017-06-03 02:26 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2017-06-13 11:19 - 2017-06-03 02:26 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthBrokerUI.dll
2017-06-13 11:19 - 2017-06-03 02:22 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2017-06-13 11:19 - 2017-06-03 02:22 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcorehc.dll
2017-06-13 11:19 - 2017-06-03 02:22 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tcpipcfg.dll
2017-06-13 11:19 - 2017-06-03 02:20 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2017-06-13 11:19 - 2017-06-03 02:19 - 01164288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certutil.exe
2017-06-13 11:19 - 2017-06-03 02:16 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2017-06-13 11:19 - 2017-06-03 02:16 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-06-13 11:19 - 2017-06-03 02:15 - 00886272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2017-06-13 11:19 - 2017-06-03 02:15 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2017-06-13 11:19 - 2017-06-03 02:15 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
2017-06-13 11:19 - 2017-06-03 02:14 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2017-06-13 11:19 - 2017-06-03 02:14 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2017-06-13 11:19 - 2017-06-03 02:14 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2017-06-13 11:19 - 2017-06-03 02:12 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdProxy.dll
2017-06-13 11:19 - 2017-06-03 02:08 - 02643968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2017-06-13 11:19 - 2017-06-03 02:08 - 01221120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2017-06-13 11:19 - 2017-06-03 02:07 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-06-13 11:19 - 2017-06-03 02:07 - 00456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2017-06-13 11:19 - 2017-06-03 02:05 - 01883648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2017-06-13 11:19 - 2017-06-03 02:05 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hnetcfg.dll
2017-06-13 11:19 - 2017-06-03 02:04 - 02006528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2017-06-13 11:19 - 2017-06-03 02:04 - 00773120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2017-06-13 11:19 - 2017-06-03 02:03 - 01988096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2017-06-13 11:19 - 2017-06-03 02:02 - 02997760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-06-13 11:19 - 2017-06-03 01:54 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2017-06-13 11:19 - 2017-06-03 01:52 - 03403264 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2017-06-13 11:19 - 2017-06-03 01:51 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2017-06-13 11:19 - 2017-06-03 01:50 - 02538496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2017-06-13 11:19 - 2017-06-03 01:49 - 00903680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2017-06-13 11:19 - 2017-06-03 01:48 - 01131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2017-06-13 11:19 - 2017-06-03 01:48 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2017-06-13 11:19 - 2017-06-03 01:48 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2017-06-13 11:19 - 2017-06-03 01:40 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-06-13 11:19 - 2017-05-24 22:56 - 00038752 _____ (Microsoft Corporation) C:\WINDOWS\system32\OOBEUpdater.exe
2017-06-13 11:19 - 2017-03-03 23:16 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2017-06-13 11:19 - 2017-03-03 23:16 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
2017-06-13 11:19 - 2016-09-06 21:53 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll
2017-06-13 11:18 - 2017-06-03 03:50 - 00192856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2017-06-13 11:18 - 2017-06-03 03:14 - 01564512 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2017-06-13 11:18 - 2017-06-03 03:14 - 01214816 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2017-06-13 11:18 - 2017-06-03 03:14 - 00629088 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2017-06-13 11:18 - 2017-06-03 03:14 - 00544096 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2017-06-13 11:18 - 2017-06-03 03:14 - 00379232 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2017-06-13 11:18 - 2017-06-03 03:14 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2017-06-13 11:18 - 2017-06-03 03:14 - 00334176 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2017-06-13 11:18 - 2017-06-03 03:14 - 00233824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2017-06-13 11:18 - 2017-06-03 03:14 - 00136032 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2017-06-13 11:18 - 2017-06-03 03:14 - 00136024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll
2017-06-13 11:18 - 2017-06-03 03:14 - 00096608 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2017-06-13 11:18 - 2017-06-03 03:14 - 00034648 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2017-06-13 11:18 - 2017-06-03 03:11 - 00128864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2017-06-13 11:18 - 2017-06-03 03:08 - 07783256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-06-13 11:18 - 2017-06-03 03:01 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2017-06-13 11:18 - 2017-06-03 02:59 - 00764392 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-06-13 11:18 - 2017-06-03 02:53 - 00404824 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2017-06-13 11:18 - 2017-06-03 02:51 - 02187104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-06-13 11:18 - 2017-06-03 02:51 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2017-06-13 11:18 - 2017-06-03 02:49 - 00624048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-06-13 11:18 - 2017-06-03 02:49 - 00509280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2017-06-13 11:18 - 2017-06-03 02:48 - 01112416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2017-06-13 11:18 - 2017-06-03 02:48 - 01100128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-06-13 11:18 - 2017-06-03 02:48 - 00989024 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-06-13 11:18 - 2017-06-03 02:44 - 01600624 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2017-06-13 11:18 - 2017-06-03 02:40 - 01566552 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-06-13 11:18 - 2017-06-03 02:40 - 00628552 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2017-06-13 11:18 - 2017-06-03 02:39 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2017-06-13 11:18 - 2017-06-03 02:23 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-06-13 11:18 - 2017-06-03 02:22 - 07217152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-06-13 11:18 - 2017-06-03 02:18 - 22569984 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-06-13 11:18 - 2017-06-03 02:16 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2017-06-13 11:18 - 2017-06-03 02:15 - 19414016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-06-13 11:18 - 2017-06-03 02:15 - 18364928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-06-13 11:18 - 2017-06-03 02:14 - 00045056 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2017-06-13 11:18 - 2017-06-03 02:11 - 00353792 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2017-06-13 11:18 - 2017-06-03 02:10 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2017-06-13 11:18 - 2017-06-03 02:10 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\edputil.dll
2017-06-13 11:18 - 2017-06-03 02:10 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBrokerUI.dll
2017-06-13 11:18 - 2017-06-03 02:09 - 00489472 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2017-06-13 11:18 - 2017-06-03 02:09 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcorehc.dll
2017-06-13 11:18 - 2017-06-03 02:09 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll
2017-06-13 11:18 - 2017-06-03 02:08 - 12187648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-06-13 11:18 - 2017-06-03 02:08 - 00691200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-06-13 11:18 - 2017-06-03 02:08 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2017-06-13 11:18 - 2017-06-03 02:08 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-06-13 11:18 - 2017-06-03 02:07 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\HNetCfgClient.dll
2017-06-13 11:18 - 2017-06-03 02:06 - 03664384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-06-13 11:18 - 2017-06-03 02:06 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2017-06-13 11:18 - 2017-06-03 02:04 - 06042624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-06-13 11:18 - 2017-06-03 02:03 - 00932864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2017-06-13 11:18 - 2017-06-03 02:01 - 00856064 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2017-06-13 11:18 - 2017-06-03 02:00 - 23677440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-06-13 11:18 - 2017-06-03 01:58 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdProxy.dll
2017-06-13 11:18 - 2017-06-03 01:56 - 13091840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-06-13 11:18 - 2017-06-03 01:53 - 08125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-06-13 11:18 - 2017-06-03 01:52 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-06-13 11:18 - 2017-06-03 01:52 - 00975872 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2017-06-13 11:18 - 2017-06-03 01:52 - 00886784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2017-06-13 11:18 - 2017-06-03 01:51 - 01418240 _____ (Microsoft Corporation) C:\WINDOWS\system32\certutil.exe
2017-06-13 11:18 - 2017-06-03 01:50 - 04744704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-06-13 11:18 - 2017-06-03 01:49 - 03615744 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-06-13 11:18 - 2017-06-03 01:49 - 02691072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-06-13 11:18 - 2017-06-03 01:49 - 02475520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2017-06-13 11:18 - 2017-06-03 01:49 - 02318848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-06-13 11:18 - 2017-06-03 01:49 - 01845248 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2017-06-13 11:18 - 2017-06-03 01:49 - 01513472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-06-13 11:18 - 2017-06-03 01:49 - 00351744 _____ (Microsoft Corporation) C:\WINDOWS\system32\hnetcfg.dll
2017-06-13 11:18 - 2017-06-03 01:48 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2017-06-13 11:18 - 2017-06-03 01:46 - 01121280 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-06-13 11:18 - 2017-06-02 23:08 - 00080078 _____ C:\WINDOWS\system32\normidna.nls
2017-06-13 11:18 - 2017-03-03 23:22 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2017-06-13 11:18 - 2017-03-03 23:19 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2017-06-08 08:24 - 2017-06-08 08:25 - 00023408 _____ C:\Users\AIRWORX 2\Desktop\backup 6-8-17.crd
2017-06-08 07:09 - 2017-06-08 07:09 - 00002211 _____ C:\Users\AIRWORX 2\Downloads\data (34).csv
2017-06-08 07:07 - 2017-06-08 07:07 - 00002211 _____ C:\Users\AIRWORX 2\Downloads\data (33).csv
2017-06-08 07:03 - 2017-06-08 07:03 - 00002435 _____ C:\Users\AIRWORX 2\Downloads\data (32).csv
2017-06-07 13:52 - 2017-06-07 13:52 - 00000754 _____ C:\Users\AIRWORX 2\Downloads\GMB insights (Discovery Report) - Cosmic Jump - 2017-3-7 - 2017-6-4.csv
2017-06-07 05:50 - 2017-06-07 05:50 - 00364044 _____ C:\Users\AIRWORX 2\Downloads\Today%27s New Q Items May 31%2c 2017.xls
2017-06-07 05:04 - 2017-06-07 05:04 - 01700352 _____ C:\Users\AIRWORX 2\Downloads\allen 3 (Autosaved).xls
2017-06-07 02:49 - 2017-06-07 02:49 - 00035171 _____ C:\Users\AIRWORX 2\Downloads\2017 Prescott JUNE 6-9 TOURNAMENT.pdf
2017-06-06 08:57 - 2017-06-06 08:57 - 08580225 _____ C:\Users\AIRWORX 2\Downloads\Android_Security_Internals-An_In-Depth_Guide_to_Android_s_Security_Architecture.pdf
2017-06-05 15:00 - 2017-06-05 15:04 - 00054629 _____ C:\Users\AIRWORX 2\Downloads\email_campaigns_report.xlsx
2017-06-05 14:55 - 2017-06-05 15:00 - 00051823 _____ C:\Users\AIRWORX 2\Downloads\email_campaigns_report.csv
2017-06-05 13:22 - 2017-06-05 13:22 - 02158201 _____ C:\Users\AIRWORX 2\Downloads\Backup_17-06-04 20-18-39.zip
2017-06-05 04:26 - 2017-06-05 04:26 - 00080268 _____ C:\Users\AIRWORX 2\Downloads\CJ Allen Deposits 4-21-17 to 4-23-2017.pdf
2017-06-05 04:25 - 2017-06-05 04:25 - 00096106 _____ C:\Users\AIRWORX 2\Downloads\CJ Allen Deposits 4-24-17 to 4-27-2017.pdf
2017-06-05 04:25 - 2017-06-05 04:25 - 00080904 _____ C:\Users\AIRWORX 2\Downloads\CJ Allen Deposits 4-28-17 to 4-30-2017.pdf
2017-06-05 04:24 - 2017-06-05 04:24 - 00011327 _____ C:\Users\AIRWORX 2\Downloads\mail from today 5-4-2017 (1).pdf
2017-06-05 04:22 - 2017-06-05 04:22 - 00082193 _____ C:\Users\AIRWORX 2\Downloads\CJ Allen Deposits 5-1-17 to 5-4-2017.pdf
2017-06-05 04:19 - 2017-06-05 04:19 - 00073504 _____ C:\Users\AIRWORX 2\Downloads\CJ Allen Deposits 5-5-17 to 5-7-2017.pdf
2017-06-05 04:17 - 2017-06-05 04:17 - 02721364 _____ C:\Users\AIRWORX 2\Downloads\DOC051117-007.pdf
2017-06-05 04:17 - 2017-06-05 04:17 - 00099443 _____ C:\Users\AIRWORX 2\Downloads\CJ Allen Deposits 5-8-17 to 5-11-2017 (1).pdf
2017-06-05 04:17 - 2017-06-05 04:17 - 00074883 _____ C:\Users\AIRWORX 2\Downloads\CJ Allen Deposits 5-12-17 to 5-14-2017.pdf
2017-06-05 04:15 - 2017-06-05 04:15 - 00109472 _____ C:\Users\AIRWORX 2\Downloads\CJ Allen Deposits 5-26-17 to 5-29-2017.pdf
2017-06-05 04:15 - 2017-06-05 04:15 - 00101328 _____ C:\Users\AIRWORX 2\Downloads\CJ Allen Deposits 5-15-17 to 5-18-2017.pdf
2017-06-05 04:15 - 2017-06-05 04:15 - 00087719 _____ C:\Users\AIRWORX 2\Downloads\CJ Allen Deposits 5-22-17 to 5-25-2017.pdf
2017-06-05 04:15 - 2017-06-05 04:15 - 00076880 _____ C:\Users\AIRWORX 2\Downloads\CJ Allen Deposits 5-19-17 to 5-21-2017.pdf
2017-06-05 04:14 - 2017-06-05 04:14 - 00074677 _____ C:\Users\AIRWORX 2\Downloads\CJ Allen Deposits 5-30-17 to 6-1-2017.pdf
2017-06-05 03:44 - 2017-06-05 03:44 - 00003340 _____ C:\Users\AIRWORX 2\Downloads\958942 (1).pdf
2017-06-05 03:05 - 2017-06-05 03:05 - 00004051 _____ C:\Users\AIRWORX 2\Downloads\1252765.pdf
2017-06-05 03:05 - 2017-06-05 03:05 - 00003745 _____ C:\Users\AIRWORX 2\Downloads\1201427.pdf
2017-06-05 03:05 - 2017-06-05 03:05 - 00003556 _____ C:\Users\AIRWORX 2\Downloads\1057066 (1).pdf
2017-06-05 03:05 - 2017-06-05 03:05 - 00003497 _____ C:\Users\AIRWORX 2\Downloads\1077227 (1).pdf
2017-06-05 03:04 - 2017-06-05 03:04 - 00003573 _____ C:\Users\AIRWORX 2\Downloads\1001231 (2).pdf
2017-06-05 03:04 - 2017-06-05 03:04 - 00003540 _____ C:\Users\AIRWORX 2\Downloads\1036189 (1).pdf
2017-06-05 03:04 - 2017-06-05 03:04 - 00003434 _____ C:\Users\AIRWORX 2\Downloads\966682 (1).pdf
2017-06-05 03:04 - 2017-06-05 03:04 - 00003340 _____ C:\Users\AIRWORX 2\Downloads\958942.pdf
2017-06-03 14:08 - 2017-06-03 14:08 - 00034833 _____ C:\Users\AIRWORX 2\Downloads\coke, sam's and Yumi invoices.pdf
2017-06-02 13:48 - 2017-06-02 13:48 - 00026293 _____ C:\Users\AIRWORX 2\Downloads\today's mail 5-26-17.pdf
2017-06-02 13:44 - 2017-06-02 13:44 - 00030169 _____ C:\Users\AIRWORX 2\Downloads\06.01.17 Olathe-Holmes Stmt.pdf
2017-06-02 13:43 - 2017-06-02 13:43 - 00660716 _____ C:\Users\AIRWORX 2\Downloads\05.12.17 AMEX Stmt.pdf
2017-06-02 13:42 - 2017-06-02 13:42 - 01064032 _____ C:\Users\AIRWORX 2\Downloads\05.24.17 Allen - Appraisal.pdf
2017-06-02 13:42 - 2017-06-02 13:42 - 00848212 _____ C:\Users\AIRWORX 2\Downloads\05.26.17 Allen - Direct Energy.pdf
2017-06-02 13:41 - 2017-06-02 13:41 - 00289777 _____ C:\Users\AIRWORX 2\Downloads\05.26.17 Olathe TAx Stmt.pdf
2017-05-31 10:16 - 2017-05-31 10:16 - 02118422 _____ C:\Users\AIRWORX 2\Downloads\Backup_17-05-26 14-45-58.zip
2017-05-31 09:53 - 2017-05-18 22:17 - 00166288 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\Drivers\ssudmdm.sys
2017-05-31 09:53 - 2017-05-18 22:17 - 00131984 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\Drivers\ssudbus.sys
2017-05-31 09:49 - 2017-05-31 09:50 - 39771304 _____ (Samsung Electronics) C:\Users\AIRWORX 2\Downloads\Smart_Switch_pc_setup.exe
2017-05-31 09:35 - 2017-06-26 06:58 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\Samsung
2017-05-31 09:35 - 2017-06-26 06:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2017-05-31 09:35 - 2017-06-26 06:58 - 00000000 ____D C:\Program Files (x86)\Samsung
2017-05-31 09:35 - 2017-05-31 10:09 - 00000000 ____D C:\Users\AIRWORX 2\Documents\samsung
2017-05-31 09:35 - 2017-05-31 09:35 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log
2017-05-31 09:35 - 2014-05-07 17:42 - 00144664 _____ (MAPILab Ltd. & Add-in Express Ltd.) C:\WINDOWS\SysWOW64\secman.dll
2017-05-31 09:33 - 2017-05-31 09:33 - 00000000 ____D C:\Program Files\Samsung
2017-05-31 09:32 - 2017-05-31 09:57 - 00000000 ____D C:\ProgramData\Samsung
2017-05-31 09:32 - 2017-05-31 09:34 - 40758048 _____ (Samsung Electronics Co., Ltd.) C:\Users\AIRWORX 2\Downloads\Kies3Setup.exe
2017-05-31 09:30 - 2017-05-31 09:32 - 16007072 _____ (SAMSUNG Electronics Co., Ltd.) C:\Users\AIRWORX 2\Downloads\SAMSUNG_USB_Driver_for_Mobile_Phones_v1.5.45.00.exe
2017-05-31 08:02 - 2017-06-16 12:10 - 00000000 ____D C:\Users\AIRWORX 2\Desktop\Queen palm and yard info
2017-05-30 07:02 - 2017-05-30 07:02 - 01739256 _____ C:\Users\AIRWORX 2\Downloads\FlexiKiller (1).exe
2017-05-30 07:01 - 2017-05-30 07:02 - 01739256 _____ C:\Users\AIRWORX 2\Downloads\FlexiKiller.exe
2017-05-26 03:56 - 2017-05-26 03:56 - 00756804 _____ C:\Users\AIRWORX 2\Downloads\SIMalliance-Mobile-Open-API-Paper-V2_FINAL.pdf
2017-05-25 06:33 - 2017-05-25 06:33 - 00000000 ____D C:\Program Files (x86)\Secunia
2017-05-25 05:58 - 2017-05-25 05:58 - 00000000 ____D C:\WINDOWS\Minidump
2017-05-25 04:32 - 2017-05-25 04:32 - 00647567 _____ C:\Users\AIRWORX 2\Downloads\TEXTML_datasheet_download.pdf
2017-05-24 13:58 - 2017-05-24 14:30 - 04463104 _____ C:\Users\AIRWORX 2\Downloads\allen 1.xls
2017-05-24 13:29 - 2017-05-24 13:29 - 00940032 _____ C:\Users\AIRWORX 2\Downloads\allen 2.xls
2017-05-24 13:26 - 2017-05-24 13:26 - 01700352 _____ C:\Users\AIRWORX 2\Downloads\allen 3.xls
2017-05-24 13:26 - 2017-05-24 13:26 - 01444864 _____ C:\Users\AIRWORX 2\Downloads\Allen 4.xls
2017-05-24 13:23 - 2017-05-24 13:58 - 01105920 _____ C:\Users\AIRWORX 2\Downloads\contact_export_052417_1503 (2).xls
2017-05-24 13:23 - 2017-05-24 13:42 - 01682944 _____ C:\Users\AIRWORX 2\Downloads\contact_export_052417_1503.xls
2017-05-24 13:23 - 2017-05-24 13:23 - 01426432 _____ C:\Users\AIRWORX 2\Downloads\contact_export_052417_1504.xls
2017-05-24 13:23 - 2017-05-24 13:23 - 01345536 _____ C:\Users\AIRWORX 2\Downloads\contact_export_052417_1502.xls
2017-05-24 13:23 - 2017-05-24 13:23 - 00922112 _____ C:\Users\AIRWORX 2\Downloads\contact_export_052417_1503 (1).xls
2017-05-24 12:47 - 2017-05-24 13:05 - 01207808 _____ C:\Users\AIRWORX 2\Downloads\report_export_051917_1056.xls
2017-05-24 11:59 - 2017-05-24 11:59 - 00000165 ____H C:\Users\AIRWORX 2\Documents\~$My Vendor List 8-15-12.xlsx
2017-05-23 16:37 - 2017-05-23 16:37 - 00051246 _____ C:\Users\AIRWORX 2\Downloads\Copas+travelers+home+quote (1) (1).pdf
2017-05-21 10:23 - 2017-05-21 10:23 - 00000000 ____D C:\WINDOWS\Panther
2017-05-19 11:09 - 2017-05-19 11:09 - 00023408 _____ C:\Users\AIRWORX 2\Desktop\backup.crd
2017-05-19 04:04 - 2017-05-19 04:04 - 02754106 _____ C:\Users\AIRWORX 2\Downloads\Cosmic Jump Summer Cal (1) (1).pdf
2017-05-19 02:48 - 2017-05-19 02:49 - 02754106 _____ C:\Users\AIRWORX 2\Downloads\Cosmic Jump Summer Cal (1).pdf
2017-05-19 02:48 - 2017-05-19 02:48 - 00670328 _____ C:\Users\AIRWORX 2\Downloads\Cosmic Jump Summer ad (1).pdf
2017-05-18 13:05 - 2017-05-18 13:06 - 00000000 ____D C:\Users\AIRWORX 2\Documents\Dispute
2017-05-18 13:00 - 2017-05-18 13:00 - 00000082 ____H C:\Users\AIRWORX 2\Downloads\~$email gc with names.pdf.ppwritelock
2017-05-18 12:22 - 2017-05-18 12:22 - 00001013 _____ C:\Users\AIRWORX 2\Downloads\disputes (1).csv
2017-05-18 09:52 - 2017-05-18 12:58 - 00053938 _____ C:\Users\AIRWORX 2\Documents\disputes.xlsx
2017-05-18 09:51 - 2017-05-18 09:51 - 00002392 _____ C:\Users\AIRWORX 2\Documents\disputes.csv
2017-05-18 09:45 - 2017-05-18 09:45 - 00076304 _____ C:\Users\AIRWORX 2\Downloads\PayNow_ Confirmation.pdf
2017-05-18 03:43 - 2017-05-18 03:43 - 00002142 _____ C:\Users\AIRWORX 2\Downloads\billCompare.csv
2017-05-18 03:41 - 2017-05-18 03:41 - 00106792 _____ C:\Users\AIRWORX 2\Downloads\https___ala.kcpl.com_ALA__payBill_PrinterReceipt.pdf
2017-05-18 03:25 - 2017-05-18 03:25 - 00094883 _____ C:\Users\AIRWORX 2\Downloads\National Trampoline Entertainment, LLC (1).pdf
2017-05-18 03:10 - 2017-05-18 03:10 - 01191120 _____ C:\Users\AIRWORX 2\Downloads\Cosmic jump_proof_B.PDF
2017-05-18 03:10 - 2017-05-18 03:10 - 00271307 _____ C:\Users\AIRWORX 2\Downloads\Cosmic jump_proof_A.PDF
2017-05-16 13:17 - 2017-05-16 13:17 - 00100175 _____ C:\Users\AIRWORX 2\Downloads\05.08.17 Allen- Property Tax Ltr.pdf
2017-05-16 13:17 - 2017-05-16 13:17 - 00057802 _____ C:\Users\AIRWORX 2\Downloads\05.09.17 Olathe-Annual Report.pdf
2017-05-16 13:17 - 2017-05-16 13:17 - 00057802 _____ C:\Users\AIRWORX 2\Downloads\05.09.17 Olathe-Annual Report (1).pdf
2017-05-16 13:01 - 2017-05-16 13:01 - 00017010 _____ C:\Users\AIRWORX 2\Documents\each stores log ins (Autosaved).xlsx
2017-05-16 06:20 - 2017-05-16 06:20 - 00057229 _____ C:\Users\AIRWORX 2\Downloads\2.pdf
2017-05-16 06:20 - 2017-05-16 06:20 - 00056323 _____ C:\Users\AIRWORX 2\Downloads\1.pdf
2017-05-16 06:18 - 2017-05-16 06:18 - 00110949 _____ C:\Users\AIRWORX 2\Downloads\04.30.17 Lewisville Coke Stmt.pdf
2017-05-16 06:17 - 2017-05-16 06:17 - 00065304 _____ C:\Users\AIRWORX 2\Downloads\04.30.17 Allen-Coke Stmt.pdf
2017-05-16 06:15 - 2017-05-16 06:15 - 00492043 _____ C:\Users\AIRWORX 2\Downloads\05.08.17 Olathe BOA Stmt.pdf
2017-05-16 05:14 - 2017-05-16 05:14 - 02754106 _____ C:\Users\AIRWORX 2\Downloads\Cosmic Jump Summer Cal.pdf
2017-05-16 05:13 - 2017-05-16 05:13 - 00670328 _____ C:\Users\AIRWORX 2\Downloads\Cosmic Jump Summer ad.pdf
2017-05-15 12:44 - 2017-05-15 12:44 - 00099443 _____ C:\Users\AIRWORX 2\Downloads\CJ Allen Deposits 5-8-17 to 5-11-2017.pdf
2017-05-15 12:39 - 2017-05-15 12:39 - 01287541 _____ C:\Users\AIRWORX 2\Documents\scan331.pdf
2017-05-15 11:04 - 2017-05-16 13:09 - 00020005 _____ C:\Users\AIRWORX 2\Documents\Mary Brooks.flp
2017-05-12 09:31 - 2017-05-12 09:31 - 00000000 ____D C:\Users\AIRWORX 2\Desktop\2017 Incident Files
2017-05-12 08:31 - 2017-05-12 08:31 - 00001013 _____ C:\Users\AIRWORX 2\Downloads\disputes.csv
2017-05-11 12:15 - 2017-05-11 12:15 - 00003486 _____ C:\Users\AIRWORX 2\Downloads\Billing_Statement_648-18938.pdf
2017-05-11 08:33 - 2017-05-11 08:33 - 00094883 _____ C:\Users\AIRWORX 2\Downloads\National Trampoline Entertainment, LLC.pdf
2017-05-10 18:09 - 2017-05-10 18:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shutterfly Uploader
2017-05-10 18:09 - 2017-05-10 18:09 - 00000000 ____D C:\Program Files (x86)\Shutterfly Uploader
2017-05-10 18:07 - 2017-05-10 18:07 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\Shutterfly Uploader 2.9.0.737
2017-05-10 12:01 - 2017-05-10 14:10 - 00003035 _____ C:\Users\AIRWORX 2\Downloads\data (31).csv
2017-05-10 11:54 - 2017-05-10 11:54 - 00003329 _____ C:\Users\AIRWORX 2\Downloads\data (30).csv
2017-05-10 05:55 - 2017-05-10 05:55 - 03037184 _____ C:\Users\AIRWORX 2\Downloads\NCAA ELIGIBILITY 2.pps
2017-05-10 02:46 - 2017-05-10 02:46 - 00048292 _____ C:\Users\AIRWORX 2\Downloads\Allen Service Sheets 5-9-17.pdf
2017-05-10 02:45 - 2017-05-10 02:45 - 00032965 _____ C:\Users\AIRWORX 2\Downloads\Allen Supplies 5-8-2017.pdf
2017-05-09 22:08 - 2017-04-27 18:28 - 00965472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
2017-05-09 22:08 - 2017-04-27 17:59 - 00601712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2017-05-09 22:08 - 2017-04-27 17:55 - 00088416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\scmbus.sys
2017-05-09 22:08 - 2017-04-27 17:53 - 00616048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2017-05-09 22:08 - 2017-04-27 17:48 - 00263472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2017-05-09 22:08 - 2017-04-27 17:46 - 05722320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2017-05-09 22:08 - 2017-04-27 17:46 - 01504056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2017-05-09 22:08 - 2017-04-27 17:46 - 01431232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2017-05-09 22:08 - 2017-04-27 17:45 - 02263832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2017-05-09 22:08 - 2017-04-27 17:45 - 00975744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2017-05-09 22:08 - 2017-04-27 17:45 - 00861024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2017-05-09 22:08 - 2017-04-27 17:45 - 00493920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2017-05-09 22:08 - 2017-04-27 17:45 - 00116576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll
2017-05-09 22:08 - 2017-04-27 17:43 - 02168288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2017-05-09 22:08 - 2017-04-27 17:43 - 01980768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2017-05-09 22:08 - 2017-04-27 17:43 - 01557224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2017-05-09 22:08 - 2017-04-27 17:43 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2017-05-09 22:08 - 2017-04-27 17:41 - 00361104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll
2017-05-09 22:08 - 2017-04-27 17:40 - 06665952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-05-09 22:08 - 2017-04-27 17:40 - 04023008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2017-05-09 22:08 - 2017-04-27 17:40 - 01851696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2017-05-09 22:08 - 2017-04-27 17:40 - 01360456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2017-05-09 22:08 - 2017-04-27 17:40 - 01277856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2017-05-09 22:08 - 2017-04-27 17:40 - 01202936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2017-05-09 22:08 - 2017-04-27 17:40 - 00981888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2017-05-09 22:08 - 2017-04-27 17:40 - 00352760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MMDevAPI.dll
2017-05-09 22:08 - 2017-04-27 17:39 - 04312248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2017-05-09 22:08 - 2017-04-27 17:39 - 00962760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2017-05-09 22:08 - 2017-04-27 17:39 - 00715104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2017-05-09 22:08 - 2017-04-27 17:38 - 00557408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2017-05-09 22:08 - 2017-04-27 17:35 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\input.dll
2017-05-09 22:08 - 2017-04-27 17:23 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2017-05-09 22:08 - 2017-04-27 17:22 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
2017-05-09 22:08 - 2017-04-27 17:20 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Radios.dll
2017-05-09 22:08 - 2017-04-27 17:19 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDeviceRegistration.dll
2017-05-09 22:08 - 2017-04-27 17:19 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2017-05-09 22:08 - 2017-04-27 17:18 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2017-05-09 22:08 - 2017-04-27 17:18 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unimdm.tsp
2017-05-09 22:08 - 2017-04-27 17:17 - 00142336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.WiFi.dll
2017-05-09 22:08 - 2017-04-27 17:17 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinRtTracing.dll
2017-05-09 22:08 - 2017-04-27 17:17 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BluetoothApis.dll
2017-05-09 22:08 - 2017-04-27 17:17 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll
2017-05-09 22:08 - 2017-04-27 17:16 - 00392192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Input.dll
2017-05-09 22:08 - 2017-04-27 17:16 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.LowLevel.dll
2017-05-09 22:08 - 2017-04-27 17:16 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.XboxLive.Storage.dll
2017-05-09 22:08 - 2017-04-27 17:16 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
2017-05-09 22:08 - 2017-04-27 17:16 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2017-05-09 22:08 - 2017-04-27 17:16 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Lights.dll
2017-05-09 22:08 - 2017-04-27 17:15 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2017-05-09 22:08 - 2017-04-27 17:15 - 00237568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncSettings.dll
2017-05-09 22:08 - 2017-04-27 17:15 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bthprops.cpl
2017-05-09 22:08 - 2017-04-27 17:15 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthBroker.dll
2017-05-09 22:08 - 2017-04-27 17:15 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Core.dll
2017-05-09 22:08 - 2017-04-27 17:14 - 00670208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.PointOfService.dll
2017-05-09 22:08 - 2017-04-27 17:14 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.AllJoyn.dll
2017-05-09 22:08 - 2017-04-27 17:14 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe
2017-05-09 22:08 - 2017-04-27 17:13 - 13873664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2017-05-09 22:08 - 2017-04-27 17:13 - 01243136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.FaceAnalysis.dll
2017-05-09 22:08 - 2017-04-27 17:13 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.SmartCards.dll
2017-05-09 22:08 - 2017-04-27 17:13 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Wallet.dll
2017-05-09 22:08 - 2017-04-27 17:13 - 00386048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.WiFiDirect.dll
2017-05-09 22:08 - 2017-04-27 17:13 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2017-05-09 22:08 - 2017-04-27 17:13 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll
2017-05-09 22:08 - 2017-04-27 17:13 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2017-05-09 22:08 - 2017-04-27 17:13 - 00271360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
2017-05-09 22:08 - 2017-04-27 17:13 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WwaApi.dll
2017-05-09 22:08 - 2017-04-27 17:13 - 00202752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll
2017-05-09 22:08 - 2017-04-27 17:13 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll
2017-05-09 22:08 - 2017-04-27 17:13 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll
2017-05-09 22:08 - 2017-04-27 17:13 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll
2017-05-09 22:08 - 2017-04-27 17:12 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mbsmsapi.dll
2017-05-09 22:08 - 2017-04-27 17:12 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
2017-05-09 22:08 - 2017-04-27 17:12 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll
2017-05-09 22:08 - 2017-04-27 17:12 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Picker.dll
2017-05-09 22:08 - 2017-04-27 17:11 - 00747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Ocr.dll
2017-05-09 22:08 - 2017-04-27 17:11 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2017-05-09 22:08 - 2017-04-27 17:10 - 00857600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2017-05-09 22:08 - 2017-04-27 17:10 - 00819200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll
2017-05-09 22:08 - 2017-04-27 17:10 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NaturalLanguage6.dll
2017-05-09 22:08 - 2017-04-27 17:10 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprddm.dll
2017-05-09 22:08 - 2017-04-27 17:10 - 00314368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll
2017-05-09 22:08 - 2017-04-27 17:10 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.dll
2017-05-09 22:08 - 2017-04-27 17:10 - 00238080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2017-05-09 22:08 - 2017-04-27 17:09 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2017-05-09 22:08 - 2017-04-27 17:09 - 00352256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Enumeration.dll
2017-05-09 22:08 - 2017-04-27 17:08 - 07626752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2017-05-09 22:08 - 2017-04-27 17:08 - 01534464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.3D.dll
2017-05-09 22:08 - 2017-04-27 17:08 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll
2017-05-09 22:08 - 2017-04-27 17:08 - 00653312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
2017-05-09 22:08 - 2017-04-27 17:08 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CryptoWinRT.dll
2017-05-09 22:08 - 2017-04-27 17:07 - 00525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2017-05-09 22:08 - 2017-04-27 17:07 - 00256512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll
2017-05-09 22:08 - 2017-04-27 17:06 - 04614656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2017-05-09 22:08 - 2017-04-27 17:06 - 02333184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2017-05-09 22:08 - 2017-04-27 17:06 - 00901120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2017-05-09 22:08 - 2017-04-27 17:06 - 00675840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2017-05-09 22:08 - 2017-04-27 17:05 - 03733504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2017-05-09 22:08 - 2017-04-27 17:05 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2017-05-09 22:08 - 2017-04-27 17:04 - 01323008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2017-05-09 22:08 - 2017-04-27 17:03 - 01137152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2017-05-09 22:08 - 2017-04-27 17:03 - 01077760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll
2017-05-09 22:08 - 2017-04-27 17:03 - 00355328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTMediaFrame.dll
2017-05-09 22:08 - 2017-04-27 17:03 - 00291328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adsnt.dll
2017-05-09 22:08 - 2017-04-27 17:02 - 03307008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2017-05-09 22:08 - 2017-04-27 17:01 - 00795648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MiracastReceiver.dll
2017-05-09 22:08 - 2017-04-27 17:01 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2017-05-09 22:08 - 2017-04-27 17:01 - 00343040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
2017-05-09 22:08 - 2017-04-27 17:01 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dlnashext.dll
2017-05-09 22:08 - 2017-04-27 17:01 - 00141312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dialclient.dll
2017-05-09 22:08 - 2017-04-27 17:00 - 02749440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2017-05-09 22:08 - 2017-04-27 17:00 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2017-05-09 22:08 - 2017-04-27 16:59 - 02154496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi.dll
2017-05-09 22:08 - 2017-04-27 16:59 - 00895488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2017-05-09 22:08 - 2017-04-27 16:59 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToReceiver.dll
2017-05-09 22:08 - 2017-04-27 16:58 - 07468544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2017-05-09 22:08 - 2017-04-27 16:58 - 00546304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
2017-05-09 22:08 - 2017-04-27 16:58 - 00134144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ErrorDetails.dll
2017-05-09 22:08 - 2017-04-27 16:58 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2017-05-09 22:08 - 2017-04-27 16:57 - 01247232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
2017-05-09 22:08 - 2017-04-27 16:57 - 00719872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_sr.dll
2017-05-09 22:08 - 2017-04-27 16:57 - 00641024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2017-05-09 22:08 - 2017-04-27 16:56 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2017-05-09 22:08 - 2017-04-27 16:56 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Geolocation.dll
2017-05-09 22:08 - 2017-04-27 16:56 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll
2017-05-09 22:08 - 2017-04-27 16:55 - 01993216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2017-05-09 22:08 - 2017-04-27 16:55 - 01656320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Perception.dll
2017-05-09 22:08 - 2017-04-27 16:55 - 01413632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpcServices.dll
2017-05-09 22:08 - 2017-04-27 16:55 - 01232384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Maps.dll
2017-05-09 22:08 - 2017-04-27 16:55 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2017-05-09 22:08 - 2017-04-27 16:55 - 01004544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2017-05-09 22:08 - 2017-04-27 16:54 - 02747904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
2017-05-09 22:08 - 2017-04-27 16:54 - 02646528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2017-05-09 22:08 - 2017-04-27 16:54 - 02483200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-05-09 22:08 - 2017-04-27 16:54 - 01013248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2017-05-09 22:08 - 2017-04-27 16:54 - 00654336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
2017-05-09 22:08 - 2017-04-27 16:54 - 00598528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2017-05-09 22:08 - 2017-04-27 16:54 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
2017-05-09 22:08 - 2017-04-27 16:54 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll
2017-05-09 22:08 - 2017-04-27 16:53 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Phone.dll
2017-05-09 22:08 - 2017-04-27 16:53 - 00798208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2017-05-09 22:08 - 2017-04-27 16:53 - 00751104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2017-05-09 22:08 - 2017-04-27 16:53 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2017-05-09 22:08 - 2017-04-27 16:52 - 03106304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2017-05-09 22:08 - 2017-04-27 16:52 - 01600000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-05-09 22:08 - 2017-04-27 16:50 - 00783360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2017-05-09 22:08 - 2017-03-04 00:57 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2017-05-09 22:08 - 2017-03-03 23:23 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2017-05-09 22:08 - 2017-03-03 23:22 - 00265728 _____ C:\WINDOWS\SysWOW64\Windows.Perception.Stub.dll
2017-05-09 22:08 - 2017-03-03 23:17 - 00529920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StructuredQuery.dll
2017-05-09 22:08 - 2017-03-03 23:16 - 00500224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.dll
2017-05-09 22:08 - 2017-03-03 23:01 - 00827904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2017-05-09 22:08 - 2017-03-03 23:00 - 00691200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2017-05-09 22:07 - 2017-04-27 17:57 - 00794928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2017-05-09 22:07 - 2017-04-27 17:53 - 00774224 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2017-05-09 22:07 - 2017-04-27 17:40 - 07220184 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2017-05-09 22:07 - 2017-04-27 17:40 - 01860288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2017-05-09 22:07 - 2017-04-27 17:36 - 00408600 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll
2017-05-09 22:07 - 2017-04-27 17:36 - 00092512 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2017-05-09 22:07 - 2017-04-27 17:35 - 08170600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-05-09 22:07 - 2017-04-27 17:35 - 04260576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2017-05-09 22:07 - 2017-04-27 17:35 - 01988048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-05-09 22:07 - 2017-04-27 17:35 - 01702392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2017-05-09 22:07 - 2017-04-27 17:35 - 01302136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2017-05-09 22:07 - 2017-04-27 17:35 - 00596040 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2017-05-09 22:07 - 2017-04-27 17:34 - 01072248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2017-05-09 22:07 - 2017-04-27 17:34 - 00443232 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMDevAPI.dll
2017-05-09 22:07 - 2017-04-27 17:34 - 00244824 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2017-05-09 22:07 - 2017-04-27 17:28 - 00453536 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2017-05-09 22:07 - 2017-04-27 17:28 - 00387864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
2017-05-09 22:07 - 2017-04-27 17:22 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReInfo.dll
2017-05-09 22:07 - 2017-04-27 17:21 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BthTelemetry.dll
2017-05-09 22:07 - 2017-04-27 17:20 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\virtdisk.dll
2017-05-09 22:07 - 2017-04-27 17:19 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2017-05-09 22:07 - 2017-04-27 17:17 - 00328192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2017-05-09 22:07 - 2017-04-27 17:16 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
2017-05-09 22:07 - 2017-04-27 17:15 - 00404992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsreg.dll
2017-05-09 22:07 - 2017-04-27 17:15 - 00334848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastlsext.dll
2017-05-09 22:07 - 2017-04-27 17:14 - 00270336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2017-05-09 22:07 - 2017-04-27 17:13 - 01755136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll
2017-05-09 22:07 - 2017-04-27 17:13 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll
2017-05-09 22:07 - 2017-04-27 17:13 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vaultcli.dll
2017-05-09 22:07 - 2017-04-27 17:13 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupugc.exe
2017-05-09 22:07 - 2017-04-27 17:11 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebcamUi.dll
2017-05-09 22:07 - 2017-04-27 17:11 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2017-05-09 22:07 - 2017-04-27 17:09 - 00525824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintDialogs.dll
2017-05-09 22:07 - 2017-04-27 17:09 - 00509440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2017-05-09 22:07 - 2017-04-27 17:07 - 03689984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2017-05-09 22:07 - 2017-04-27 17:07 - 00372736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2017-05-09 22:07 - 2017-04-27 17:06 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2017-05-09 22:07 - 2017-04-27 17:03 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LocationApi.dll
2017-05-09 22:07 - 2017-04-27 17:03 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Energy.dll
2017-05-09 22:07 - 2017-04-27 17:03 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\raspppoe.sys
2017-05-09 22:07 - 2017-04-27 17:02 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bridge.sys
2017-05-09 22:07 - 2017-04-27 17:02 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwifimp.sys
2017-05-09 22:07 - 2017-04-27 17:01 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\unimdm.tsp
2017-05-09 22:07 - 2017-04-27 17:00 - 12349440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2017-05-09 22:07 - 2017-04-27 17:00 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinRtTracing.dll
2017-05-09 22:07 - 2017-04-27 17:00 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2017-05-09 22:07 - 2017-04-27 17:00 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Core.dll
2017-05-09 22:07 - 2017-04-27 16:59 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.XboxLive.Storage.dll
2017-05-09 22:07 - 2017-04-27 16:59 - 00375296 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastlsext.dll
2017-05-09 22:07 - 2017-04-27 16:58 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imapi2.dll
2017-05-09 22:07 - 2017-04-27 16:58 - 00418304 _____ C:\WINDOWS\system32\Windows.Perception.Stub.dll
2017-05-09 22:07 - 2017-04-27 16:58 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
2017-05-09 22:07 - 2017-04-27 16:58 - 00276992 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2017-05-09 22:07 - 2017-04-27 16:58 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2017-05-09 22:07 - 2017-04-27 16:57 - 01507840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.FaceAnalysis.dll
2017-05-09 22:07 - 2017-04-27 16:57 - 00502784 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2017-05-09 22:07 - 2017-04-27 16:57 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2017-05-09 22:07 - 2017-04-27 16:57 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2017-05-09 22:07 - 2017-04-27 16:57 - 00132096 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintWSDAHost.dll
2017-05-09 22:07 - 2017-04-27 16:57 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CameraCaptureUI.dll
2017-05-09 22:07 - 2017-04-27 16:56 - 00748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2017-05-09 22:07 - 2017-04-27 16:56 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2017-05-09 22:07 - 2017-04-27 16:56 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2017-05-09 22:07 - 2017-04-27 16:56 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.dll
2017-05-09 22:07 - 2017-04-27 16:56 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2017-05-09 22:07 - 2017-04-27 16:56 - 00293888 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2017-05-09 22:07 - 2017-04-27 16:56 - 00260608 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
2017-05-09 22:07 - 2017-04-27 16:56 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2017-05-09 22:07 - 2017-04-27 16:55 - 00561664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll
2017-05-09 22:07 - 2017-04-27 16:55 - 00307200 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs3D.dll
2017-05-09 22:07 - 2017-04-27 16:55 - 00252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2017-05-09 22:07 - 2017-04-27 16:54 - 02027008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2017-05-09 22:07 - 2017-04-27 16:54 - 01509376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2017-05-09 22:07 - 2017-04-27 16:54 - 00284160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2017-05-09 22:07 - 2017-04-27 16:53 - 06288384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2017-05-09 22:07 - 2017-04-27 16:53 - 03059200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2017-05-09 22:07 - 2017-04-27 16:53 - 00671744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mbsmsapi.dll
2017-05-09 22:07 - 2017-04-27 16:53 - 00579584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll
2017-05-09 22:07 - 2017-04-27 16:53 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\WwaApi.dll
2017-05-09 22:07 - 2017-04-27 16:51 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2017-05-09 22:07 - 2017-04-27 16:51 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTMediaFrame.dll
2017-05-09 22:07 - 2017-04-27 16:51 - 00409600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2017-05-09 22:07 - 2017-04-27 16:50 - 03778048 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2017-05-09 22:07 - 2017-04-27 16:50 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
2017-05-09 22:07 - 2017-04-27 16:49 - 00864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2017-05-09 22:07 - 2017-04-27 16:47 - 01908224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-05-09 22:07 - 2017-04-27 16:47 - 01078784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2017-05-09 22:07 - 2017-04-27 16:47 - 00796672 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2017-05-09 22:07 - 2017-04-27 16:47 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceControl.dll
2017-05-09 22:07 - 2017-04-27 16:45 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2017-05-09 22:07 - 2017-04-27 16:44 - 01366016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2017-05-09 22:07 - 2017-04-27 16:44 - 01145344 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2017-05-09 22:07 - 2017-04-27 16:44 - 00583680 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs.dll
2017-05-09 22:07 - 2017-04-27 16:44 - 00548864 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2017-05-09 22:07 - 2017-04-27 16:43 - 01184256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2017-05-09 22:07 - 2017-04-27 16:43 - 00963584 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebcamUi.dll
2017-05-09 22:07 - 2017-04-27 16:43 - 00646656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiaservc.dll
2017-05-09 22:07 - 2017-04-27 16:43 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2017-05-09 22:07 - 2017-04-27 16:43 - 00331264 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrSvc.dll
2017-05-09 22:07 - 2017-04-27 16:42 - 13441536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2017-05-09 22:07 - 2017-04-27 16:42 - 08076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2017-05-09 22:07 - 2017-04-27 16:42 - 02390016 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
2017-05-09 22:07 - 2017-04-27 16:41 - 01080320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Ocr.dll
2017-05-09 22:07 - 2017-04-27 16:41 - 00983040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2017-05-09 22:07 - 2017-04-27 16:41 - 00860160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprddm.dll
2017-05-09 22:07 - 2017-04-27 16:41 - 00759296 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2017-05-09 22:07 - 2017-04-27 16:41 - 00611328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2017-05-09 22:07 - 2017-04-27 16:40 - 02096640 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2017-05-09 22:07 - 2017-04-27 16:40 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2017-05-09 22:07 - 2017-04-27 16:39 - 04596224 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2017-05-09 22:07 - 2017-04-27 16:39 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2017-05-09 22:07 - 2017-04-27 16:38 - 02424320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Perception.dll
2017-05-09 22:07 - 2017-04-27 16:38 - 01359360 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
2017-05-09 22:07 - 2017-04-27 16:38 - 00765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2017-05-09 22:07 - 2017-04-27 16:37 - 04149248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2017-05-09 22:07 - 2017-04-27 16:37 - 03134976 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2017-05-09 22:07 - 2017-04-27 16:37 - 01984000 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2017-05-09 22:07 - 2017-04-27 16:37 - 01783296 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-05-09 22:07 - 2017-04-27 16:37 - 01424896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll
2017-05-09 22:07 - 2017-04-27 16:37 - 01266176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2017-05-09 22:07 - 2017-04-27 16:35 - 03299840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2017-05-09 22:07 - 2017-04-27 16:34 - 00999424 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2017-05-09 22:07 - 2017-04-27 16:34 - 00439296 _____ (Microsoft Corporation) C:\WINDOWS\system32\wksprt.exe
2017-05-09 22:07 - 2017-04-27 16:34 - 00394240 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2017-05-09 22:07 - 2017-03-04 00:09 - 01293152 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2017-05-09 22:07 - 2017-03-03 23:25 - 01388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2017-05-09 22:07 - 2017-03-03 23:19 - 01403392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll
2017-05-09 22:07 - 2017-03-03 23:06 - 01369088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
2017-05-09 22:07 - 2017-03-03 23:05 - 03520512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2017-05-09 22:06 - 2017-04-27 17:57 - 00603488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2017-05-09 22:06 - 2017-04-27 17:56 - 01117024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2017-05-09 22:06 - 2017-04-27 17:52 - 02255712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2017-05-09 22:06 - 2017-04-27 17:49 - 00700936 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2017-05-09 22:06 - 2017-04-27 17:47 - 00699744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2017-05-09 22:06 - 2017-04-27 17:47 - 00501088 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizeng.dll
2017-05-09 22:06 - 2017-04-27 17:46 - 00410464 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
2017-05-09 22:06 - 2017-04-27 17:44 - 00062816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fsdepends.sys
2017-05-09 22:06 - 2017-04-27 17:42 - 00526176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2017-05-09 22:06 - 2017-04-27 17:42 - 00328008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2017-05-09 22:06 - 2017-04-27 17:40 - 02759704 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2017-05-09 22:06 - 2017-04-27 17:40 - 01738560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2017-05-09 22:06 - 2017-04-27 17:40 - 01157000 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2017-05-09 22:06 - 2017-04-27 17:40 - 00578400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2017-05-09 22:06 - 2017-04-27 17:40 - 00146784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2017-05-09 22:06 - 2017-04-27 17:40 - 00026976 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser_broker.exe
2017-05-09 22:06 - 2017-04-27 17:38 - 02915704 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2017-05-09 22:06 - 2017-04-27 17:38 - 02446704 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2017-05-09 22:06 - 2017-04-27 17:38 - 01852200 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2017-05-09 22:06 - 2017-04-27 17:38 - 01267512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2017-05-09 22:06 - 2017-04-27 17:38 - 00431968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2017-05-09 22:06 - 2017-04-27 17:34 - 04674360 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2017-05-09 22:06 - 2017-04-27 17:34 - 01277824 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2017-05-09 22:06 - 2017-04-27 17:34 - 00241504 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2017-05-09 22:06 - 2017-04-27 17:30 - 00322912 _____ (Microsoft Corporation) C:\WINDOWS\system32\input.dll
2017-05-09 22:06 - 2017-04-27 17:21 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2017-05-09 22:06 - 2017-04-27 17:19 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2017-05-09 22:06 - 2017-04-27 17:15 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2017-05-09 22:06 - 2017-04-27 17:12 - 00236544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2017-05-09 22:06 - 2017-04-27 17:10 - 00661504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2017-05-09 22:06 - 2017-04-27 17:05 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2017-05-09 22:06 - 2017-04-27 17:03 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2017-05-09 22:06 - 2017-04-27 17:03 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2017-05-09 22:06 - 2017-04-27 17:03 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthTelemetry.dll
2017-05-09 22:06 - 2017-04-27 17:03 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2017-05-09 22:06 - 2017-04-27 17:02 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidcertstorecheck.exe
2017-05-09 22:06 - 2017-04-27 17:01 - 00259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.SyncEngine.dll
2017-05-09 22:06 - 2017-04-27 17:01 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2017-05-09 22:06 - 2017-04-27 17:01 - 00156160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.Client.dll
2017-05-09 22:06 - 2017-04-27 17:01 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_ClosedCaptioning.dll
2017-05-09 22:06 - 2017-04-27 17:01 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Printers.dll
2017-05-09 22:06 - 2017-04-27 17:01 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\virtdisk.dll
2017-05-09 22:06 - 2017-04-27 17:00 - 00196096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.dll
2017-05-09 22:06 - 2017-04-27 17:00 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFi.dll
2017-05-09 22:06 - 2017-04-27 17:00 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Profile.RetailInfo.dll
2017-05-09 22:06 - 2017-04-27 17:00 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll
2017-05-09 22:06 - 2017-04-27 17:00 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.Ngc.dll
2017-05-09 22:06 - 2017-04-27 17:00 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2017-05-09 22:06 - 2017-04-27 17:00 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2017-05-09 22:06 - 2017-04-27 16:59 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll
2017-05-09 22:06 - 2017-04-27 16:59 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
2017-05-09 22:06 - 2017-04-27 16:59 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Radios.dll
2017-05-09 22:06 - 2017-04-27 16:59 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidsvc.dll
2017-05-09 22:06 - 2017-04-27 16:59 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2017-05-09 22:06 - 2017-04-27 16:58 - 00547840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Input.dll
2017-05-09 22:06 - 2017-04-27 16:58 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2017-05-09 22:06 - 2017-04-27 16:58 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2017-05-09 22:06 - 2017-04-27 16:58 - 00150016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2017-05-09 22:06 - 2017-04-27 16:58 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Lights.dll
2017-05-09 22:06 - 2017-04-27 16:58 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsentUX.dll
2017-05-09 22:06 - 2017-04-27 16:57 - 00651264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
2017-05-09 22:06 - 2017-04-27 16:57 - 00568320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.LowLevel.dll
2017-05-09 22:06 - 2017-04-27 16:57 - 00505856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
2017-05-09 22:06 - 2017-04-27 16:57 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.HumanInterfaceDevice.dll
2017-05-09 22:06 - 2017-04-27 16:57 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2017-05-09 22:06 - 2017-04-27 16:57 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2017-05-09 22:06 - 2017-04-27 16:57 - 00241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2017-05-09 22:06 - 2017-04-27 16:57 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthserv.dll
2017-05-09 22:06 - 2017-04-27 16:57 - 00139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2017-05-09 22:06 - 2017-04-27 16:56 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2017-05-09 22:06 - 2017-04-27 16:56 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.dll
2017-05-09 22:06 - 2017-04-27 16:56 - 00692224 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
2017-05-09 22:06 - 2017-04-27 16:56 - 00379904 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
2017-05-09 22:06 - 2017-04-27 16:56 - 00311296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll
2017-05-09 22:06 - 2017-04-27 16:56 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultcli.dll
2017-05-09 22:06 - 2017-04-27 16:56 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll
2017-05-09 22:06 - 2017-04-27 16:55 - 02084352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll
2017-05-09 22:06 - 2017-04-27 16:55 - 00657920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2017-05-09 22:06 - 2017-04-27 16:55 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2017-05-09 22:06 - 2017-04-27 16:55 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2017-05-09 22:06 - 2017-04-27 16:55 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll
2017-05-09 22:06 - 2017-04-27 16:55 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Picker.dll
2017-05-09 22:06 - 2017-04-27 16:55 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthprops.cpl
2017-05-09 22:06 - 2017-04-27 16:55 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
2017-05-09 22:06 - 2017-04-27 16:54 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2017-05-09 22:06 - 2017-04-27 16:54 - 00472064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2017-05-09 22:06 - 2017-04-27 16:54 - 00425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2017-05-09 22:06 - 2017-04-27 16:54 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll
2017-05-09 22:06 - 2017-04-27 16:54 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2017-05-09 22:06 - 2017-04-27 16:54 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2017-05-09 22:06 - 2017-04-27 16:53 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Enumeration.dll
2017-05-09 22:06 - 2017-04-27 16:53 - 00437248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll
2017-05-09 22:06 - 2017-04-27 16:51 - 02104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2017-05-09 22:06 - 2017-04-27 16:51 - 01913856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2017-05-09 22:06 - 2017-04-27 16:51 - 01589760 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
2017-05-09 22:06 - 2017-04-27 16:51 - 01584128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2017-05-09 22:06 - 2017-04-27 16:51 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Energy.dll
2017-05-09 22:06 - 2017-04-27 16:50 - 01476608 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2017-05-09 22:06 - 2017-04-27 16:50 - 00380416 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationApi.dll
2017-05-09 22:06 - 2017-04-27 16:50 - 00338944 _____ (Microsoft Corporation) C:\WINDOWS\system32\adsnt.dll
2017-05-09 22:06 - 2017-04-27 16:49 - 17198592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-05-09 22:06 - 2017-04-27 16:49 - 01105408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MiracastReceiver.dll
2017-05-09 22:06 - 2017-04-27 16:49 - 00442368 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
2017-05-09 22:06 - 2017-04-27 16:48 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2017-05-09 22:06 - 2017-04-27 16:48 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll
2017-05-09 22:06 - 2017-04-27 16:48 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialclient.dll
2017-05-09 22:06 - 2017-04-27 16:47 - 09131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2017-05-09 22:06 - 2017-04-27 16:47 - 03290112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2017-05-09 22:06 - 2017-04-27 16:47 - 01790464 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2017-05-09 22:06 - 2017-04-27 16:47 - 00942080 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2017-05-09 22:06 - 2017-04-27 16:47 - 00649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\vds.exe
2017-05-09 22:06 - 2017-04-27 16:46 - 02861056 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll
2017-05-09 22:06 - 2017-04-27 16:46 - 01547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe
2017-05-09 22:06 - 2017-04-27 16:46 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe
2017-05-09 22:06 - 2017-04-27 16:46 - 00501248 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi2.dll
2017-05-09 22:06 - 2017-04-27 16:46 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2017-05-09 22:06 - 2017-04-27 16:46 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToReceiver.dll
2017-05-09 22:06 - 2017-04-27 16:46 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvps.dll
2017-05-09 22:06 - 2017-04-27 16:45 - 00946688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_sr.dll
2017-05-09 22:06 - 2017-04-27 16:45 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2017-05-09 22:06 - 2017-04-27 16:45 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2017-05-09 22:06 - 2017-04-27 16:45 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ErrorDetails.dll
2017-05-09 22:06 - 2017-04-27 16:45 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceAgent.exe
2017-05-09 22:06 - 2017-04-27 16:45 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\CameraCaptureUI.dll
2017-05-09 22:06 - 2017-04-27 16:44 - 04749824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-05-09 22:06 - 2017-04-27 16:44 - 01010176 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2017-05-09 22:06 - 2017-04-27 16:44 - 00937984 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2017-05-09 22:06 - 2017-04-27 16:44 - 00896512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2017-05-09 22:06 - 2017-04-27 16:44 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2017-05-09 22:06 - 2017-04-27 16:44 - 00410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicesFlowBroker.dll
2017-05-09 22:06 - 2017-04-27 16:44 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll
2017-05-09 22:06 - 2017-04-27 16:43 - 00634368 _____ (Microsoft Corporation) C:\WINDOWS\system32\StructuredQuery.dll
2017-05-09 22:06 - 2017-04-27 16:43 - 00600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll
2017-05-09 22:06 - 2017-04-27 16:43 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2017-05-09 22:06 - 2017-04-27 16:43 - 00539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2017-05-09 22:06 - 2017-04-27 16:43 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Geolocation.dll
2017-05-09 22:06 - 2017-04-27 16:43 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll
2017-05-09 22:06 - 2017-04-27 16:43 - 00320512 _____ (Microsoft Corporation) C:\WINDOWS\system32\thumbcache.dll
2017-05-09 22:06 - 2017-04-27 16:42 - 01692160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-05-09 22:06 - 2017-04-27 16:42 - 01021440 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2017-05-09 22:06 - 2017-04-27 16:42 - 00945664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2017-05-09 22:06 - 2017-04-27 16:42 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2017-05-09 22:06 - 2017-04-27 16:41 - 01359872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2017-05-09 22:06 - 2017-04-27 16:41 - 00890368 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2017-05-09 22:06 - 2017-04-27 16:41 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
2017-05-09 22:06 - 2017-04-27 16:41 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2017-05-09 22:06 - 2017-04-27 16:41 - 00591360 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2017-05-09 22:06 - 2017-04-27 16:41 - 00376832 _____ (Microsoft Corporation) C:\WINDOWS\system32\CryptoWinRT.dll
2017-05-09 22:06 - 2017-04-27 16:40 - 04474368 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2017-05-09 22:06 - 2017-04-27 16:40 - 02914816 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2017-05-09 22:06 - 2017-04-27 16:40 - 02208768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll
2017-05-09 22:06 - 2017-04-27 16:40 - 01643008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2017-05-09 22:06 - 2017-04-27 16:40 - 01586176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2017-05-09 22:06 - 2017-04-27 16:40 - 01040896 _____ (Microsoft Corporation) C:\WINDOWS\system32\NaturalLanguage6.dll
2017-05-09 22:06 - 2017-04-27 16:40 - 00971264 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2017-05-09 22:06 - 2017-04-27 16:40 - 00913920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2017-05-09 22:06 - 2017-04-27 16:40 - 00770560 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2017-05-09 22:06 - 2017-04-27 16:39 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2017-05-09 22:06 - 2017-04-27 16:38 - 05611008 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2017-05-09 22:06 - 2017-04-27 16:38 - 01275392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2017-05-09 22:06 - 2017-04-27 16:37 - 02895872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-05-09 22:06 - 2017-04-27 16:37 - 02286592 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2017-05-09 22:06 - 2017-04-27 16:37 - 02216960 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll
2017-05-09 22:06 - 2017-04-27 16:37 - 01637888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2017-05-09 22:06 - 2017-04-27 16:37 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2017-05-09 22:06 - 2017-04-27 16:37 - 00875520 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2017-05-09 22:06 - 2017-04-27 16:36 - 01328640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2017-05-09 22:06 - 2017-04-27 16:36 - 00774656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2017-05-09 22:06 - 2017-04-27 16:36 - 00735744 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2017-05-09 22:06 - 2017-04-27 16:36 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2017-05-09 22:06 - 2017-04-27 16:35 - 00924672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2017-05-09 22:06 - 2017-04-27 16:34 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\spaceman.exe
2017-05-09 22:06 - 2017-04-27 16:33 - 01817088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2017-05-09 22:06 - 2017-03-03 23:26 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll
2017-05-09 22:06 - 2017-03-03 23:25 - 01060352 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll
2017-05-09 22:06 - 2016-12-21 00:09 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneBackupHandler.dll
2017-05-09 09:43 - 2017-05-09 09:43 - 00098285 _____ C:\Users\AIRWORX 2\Downloads\Statement.pdf
2017-05-09 09:43 - 2017-05-09 09:43 - 00059467 _____ C:\Users\AIRWORX 2\Downloads\HS-5.8.17 #3104 CJump Allen April Inv&Rep SH.pdf
2017-05-09 07:28 - 2017-05-09 07:28 - 00043893 _____ C:\Users\AIRWORX 2\Downloads\CCR statement as of 21 February 2017 - 95270937 (1).pdf
2017-05-09 07:24 - 2017-05-09 07:24 - 00374670 _____ C:\Users\AIRWORX 2\Downloads\PROD LIST 110510.xlsx
2017-05-09 07:24 - 2017-05-09 07:24 - 00191488 _____ C:\Users\AIRWORX 2\Downloads\Pricing 2010 (042310).ppt
2017-05-09 07:22 - 2017-05-09 07:22 - 00154743 _____ C:\Users\AIRWORX 2\Downloads\Cosmic Jump 11 30 2018 (1).pdf
2017-05-09 07:10 - 2017-05-09 07:10 - 00147945 _____ C:\Users\AIRWORX 2\Downloads\Airworx Contract.pdf
2017-05-09 07:08 - 2017-05-09 07:08 - 00019698 _____ C:\Users\AIRWORX 2\Downloads\img079.pdf
2017-05-09 07:06 - 2017-05-09 07:06 - 00161097 _____ C:\Users\AIRWORX 2\Downloads\CJ Allen - CocaCola Invoices.pdf
2017-05-09 07:05 - 2017-05-09 07:05 - 00027989 _____ C:\Users\AIRWORX 2\Downloads\CJ 11.16.15 (1).tif
2017-05-09 07:05 - 2017-05-09 07:05 - 00021997 _____ C:\Users\AIRWORX 2\Downloads\CJ 12.21.15 (1).tif
2017-05-09 07:05 - 2017-05-09 07:05 - 00019815 _____ C:\Users\AIRWORX 2\Downloads\CJ 11.30.15 (1).tif
2017-05-09 06:57 - 2017-05-09 06:57 - 00435261 _____ C:\Users\AIRWORX 2\Downloads\251525c8_5912smart.PDF
2017-05-09 06:57 - 2017-05-09 06:57 - 00101084 _____ C:\Users\AIRWORX 2\Downloads\OTC---Z01---Customer-Invoice-(9700104306)-for-Customer-ID-600932145.pdf
2017-05-09 06:57 - 2017-05-09 06:57 - 00098532 _____ C:\Users\AIRWORX 2\Downloads\OTC---Z01---Customer-Invoice-(9700058437)-for-Customer-ID-600932145.pdf
2017-05-09 06:57 - 2017-05-09 06:57 - 00096973 _____ C:\Users\AIRWORX 2\Downloads\OTC---Z01---Customer-Invoice-(9700180809)-for-Customer-ID-600932145.pdf
2017-05-09 06:57 - 2017-05-09 06:57 - 00095005 _____ C:\Users\AIRWORX 2\Downloads\OTC---Z01---Customer-Invoice-(9700030432)-for-Customer-ID-600932145.pdf
2017-05-09 06:57 - 2017-05-09 06:57 - 00092177 _____ C:\Users\AIRWORX 2\Downloads\OTC---Z01---Customer-Invoice-(9700012338)-for-Customer-ID-600932145.pdf
2017-05-09 06:57 - 2017-05-09 06:57 - 00088715 _____ C:\Users\AIRWORX 2\Downloads\OTC---Z01---Customer-Invoice-(9700081692)-for-Customer-ID-600932145.pdf
2017-05-09 06:57 - 2017-05-09 06:57 - 00085982 _____ C:\Users\AIRWORX 2\Downloads\OTC---Z01---Customer-Invoice-(9700224605)-for-Customer-ID-600932145.pdf
2017-05-08 05:12 - 2017-05-08 05:12 - 00675070 _____ C:\Users\AIRWORX 2\Downloads\rwhoisd-master.zip
2017-05-08 03:04 - 2017-05-08 03:05 - 02017150 _____ C:\Users\AIRWORX 2\Downloads\Backup_17-05-07 20-10-26.zip
2017-05-05 11:02 - 2017-05-05 11:03 - 02865173 _____ C:\Users\AIRWORX 2\Downloads\Lakeview Crossing - Rowlett.pdf
2017-05-05 11:01 - 2017-05-05 11:01 - 00011327 _____ C:\Users\AIRWORX 2\Downloads\mail from today 5-4-2017.pdf
2017-05-05 10:33 - 2017-05-05 10:33 - 00043808 _____ C:\Users\AIRWORX 2\Downloads\CCR statement as of 03 May 2017 - 95269325.pdf
2017-05-05 10:32 - 2017-05-05 10:32 - 00044095 _____ C:\Users\AIRWORX 2\Downloads\CCR statement as of 04 March 2017 - 95270937.pdf
2017-05-05 10:31 - 2017-05-05 10:31 - 00029115 _____ C:\Users\AIRWORX 2\Downloads\CCR statement as of 04 March 2017 - 95269325.pdf
2017-05-05 09:18 - 2017-05-05 09:18 - 00218902 _____ C:\Users\AIRWORX 2\Downloads\04.28.17 Olathe CC Stmt.pdf
2017-05-05 09:18 - 2017-05-05 09:18 - 00196417 _____ C:\Users\AIRWORX 2\Downloads\04.28.17 CC Stmt.pdf
2017-05-05 09:18 - 2017-05-05 09:18 - 00065979 _____ C:\Users\AIRWORX 2\Downloads\04.29.17 Kessinger Law Firm.pdf
2017-05-05 07:06 - 2017-05-05 07:06 - 00051246 _____ C:\Users\AIRWORX 2\Downloads\Copas+travelers+home+quote (1).pdf
2017-05-04 05:56 - 2017-05-04 05:56 - 04161569 _____ C:\Users\AIRWORX 2\Downloads\2017-February-State-Abstract.xlsx
2017-05-03 11:17 - 2017-05-03 11:17 - 00656897 _____ C:\Users\AIRWORX 2\Downloads\AIRWORX Slam Dunk Rules Poster 18 x 24.pdf
2017-05-03 10:10 - 2017-05-03 10:10 - 00197252 _____ C:\Users\AIRWORX 2\Downloads\NTE Pymts for Tax Work.pdf
2017-05-03 08:46 - 2017-05-03 09:35 - 00030282 _____ C:\Users\AIRWORX 2\Documents\Brandi Copas.flp
2017-05-03 08:35 - 2017-05-16 13:09 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\Family Lawyer
2017-05-03 08:35 - 2017-05-11 03:42 - 00001884 _____ C:\Users\AIRWORX 2\Desktop\Broderbund Family Lawyer.lnk
2017-05-03 08:26 - 2017-05-03 09:35 - 00000000 ____D C:\Program Files (x86)\Family Lawyer
2017-05-03 08:26 - 2017-05-03 08:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Family Lawyer
2017-05-03 04:00 - 2017-05-03 04:06 - 00000410 _____ C:\WINDOWS\MSREGUSR.INI
2017-05-03 03:47 - 2017-05-03 03:47 - 00000598 _____ C:\Users\AIRWORX 2\Documents\Untitled.ivb
2017-05-02 08:49 - 2017-05-02 08:49 - 00000003 _____ C:\Users\AIRWORX 2\Desktop\cj site.css
2017-05-02 07:44 - 2017-05-02 07:44 - 00428344 _____ C:\Users\AIRWORX 2\Desktop\2016 and 2017 emails.txt
2017-05-02 06:44 - 2012-09-11 10:04 - 00025947 _____ C:\Users\AIRWORX 2\Desktop\Minor_Waiver_10_7_2011[1].pdf
2017-05-01 05:09 - 2017-05-01 05:09 - 00000005 _____ C:\Users\AIRWORX 2\Downloads\download (1)
2017-04-27 12:34 - 2017-04-27 12:34 - 00023823 _____ C:\Users\AIRWORX 2\Downloads\img267.pdf
2017-04-26 13:10 - 2017-04-26 13:10 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\Google
2017-04-25 12:36 - 2017-04-25 12:36 - 00067609 _____ C:\Users\AIRWORX 2\Downloads\Call_Incoming-15413165747--1775769324.mp4
2017-04-25 06:58 - 2017-04-25 06:58 - 00023340 _____ C:\Users\AIRWORX 2\Documents\escape actual bookings.xlsx
2017-04-25 06:53 - 2017-04-28 08:17 - 00010886 _____ C:\Users\AIRWORX 2\Documents\escape booking report.xlsx
2017-04-25 06:51 - 2017-04-25 06:51 - 00010076 _____ C:\Users\AIRWORX 2\Documents\escape grid.xlsx
2017-04-25 06:46 - 2017-04-28 07:30 - 00012967 _____ C:\Users\AIRWORX 2\Documents\escape rooms.xlsx
2017-04-24 15:05 - 2017-04-24 15:05 - 00019208 _____ C:\Users\AIRWORX 2\Downloads\file____C__Users_AIRWORX 2_AppData_Local_Temp_rgp4075acd9-9f4.pdf
2017-04-24 10:20 - 2017-04-24 12:20 - 00079224 ____N C:\Users\AIRWORX 2\Downloads\CJ Allen Direct Deposit - Carson Lewis.pdf
2017-04-24 10:20 - 2017-04-24 10:20 - 00612509 _____ C:\Users\AIRWORX 2\Downloads\Correspondence.zip
2017-04-24 10:12 - 2017-04-24 10:12 - 00017215 _____ C:\Users\AIRWORX 2\Downloads\Joplins signed agreement.pdf
2017-04-24 09:37 - 2017-04-24 09:37 - 00271215 _____ C:\Users\AIRWORX 2\Downloads\PrioritizedApproach (1).xlsx
2017-04-24 09:33 - 2017-04-24 09:33 - 00056980 _____ C:\Users\AIRWORX 2\Downloads\BOA Letter 04.07.17.pdf
2017-04-24 09:31 - 2017-04-24 09:31 - 00513081 _____ C:\Users\AIRWORX 2\Downloads\BOA Stmt 04.08.17.pdf
2017-04-24 09:27 - 2017-04-24 09:27 - 00101803 _____ C:\Users\AIRWORX 2\Downloads\Collin Co Tax Assessor 4.7.17.pdf
2017-04-24 09:26 - 2017-04-24 09:26 - 00058024 _____ C:\Users\AIRWORX 2\Downloads\Delinquent Tax Denton Co 04.17.pdf
2017-04-24 09:25 - 2017-04-24 09:25 - 00109232 _____ C:\Users\AIRWORX 2\Downloads\Linebarger Goggan Blair & Sampso.pdf
2017-04-24 09:24 - 2017-04-24 09:24 - 01492955 _____ C:\Users\AIRWORX 2\Downloads\AMEX 04.11.17.pdf
2017-04-24 09:18 - 2017-04-24 09:18 - 00293233 _____ C:\Users\AIRWORX 2\Downloads\04.11.17 AT&T.pdf
2017-04-24 08:57 - 2017-04-24 08:57 - 00098351 _____ C:\Users\AIRWORX 2\Downloads\CJ Allen Deposits 4-14-17 to 4-20-2017.pdf
2017-04-24 08:55 - 2017-04-24 08:55 - 00072066 _____ C:\Users\AIRWORX 2\Downloads\CosmicJumpInv7749.pdf
2017-04-24 08:55 - 2017-04-24 08:55 - 00071545 _____ C:\Users\AIRWORX 2\Downloads\CosmicJumpInv7847.pdf
2017-04-24 06:57 - 2017-04-24 06:57 - 00000000 ____D C:\Users\AIRWORX 2\Desktop\Renewal
2017-04-24 04:32 - 2017-04-24 04:32 - 00020420 _____ C:\Users\AIRWORX 2\Downloads\Checking2 (5).csv
2017-04-21 08:44 - 2017-04-21 08:44 - 04145664 _____ C:\Users\AIRWORX 2\Downloads\Drag and Drop Backup-2.1.33-prod.msi
2017-04-21 08:44 - 2017-04-21 08:44 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\DigiData
2017-04-21 08:44 - 2017-04-21 08:44 - 00000000 ____D C:\ProgramData\DigiData
2017-04-21 08:44 - 2017-04-21 08:44 - 00000000 ____D C:\Program Files (x86)\Cox
2017-04-21 05:35 - 2017-04-21 05:35 - 00002258 _____ C:\Users\AIRWORX 2\Desktop\Cox Cloud Drive.lnk
2017-04-21 05:35 - 2017-04-21 05:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cox Cloud Drive
2017-04-21 05:35 - 2017-04-21 05:35 - 00000000 ____D C:\ProgramData\CoxBackup
2017-04-21 05:35 - 2017-04-21 05:35 - 00000000 ____D C:\Program Files (x86)\Cox Secure Online Backup for Windows
2017-04-21 05:33 - 2017-04-21 05:33 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\Downloaded Installations
2017-04-21 05:22 - 2017-04-21 05:22 - 00772659 _____ C:\Users\AIRWORX 2\Downloads\F2970.1654435-1.pdf
2017-04-20 07:27 - 2017-04-20 07:38 - 00727375 _____ C:\Users\AIRWORX 2\Documents\First aid training.pdf
2017-04-20 07:16 - 2017-04-20 07:31 - 00471501 _____ C:\Users\AIRWORX 2\Documents\scan328.pdf
2017-04-20 05:40 - 2017-04-20 05:40 - 00726376 _____ C:\Users\AIRWORX 2\Downloads\2017-04-04-08-23-18_AzMerit Testing Information.pdf
2017-04-20 03:16 - 2017-04-20 03:16 - 00162854 _____ C:\Users\AIRWORX 2\Downloads\ppinfocache
2017-04-20 02:48 - 2017-04-20 02:48 - 00350330 _____ C:\Users\AIRWORX 2\Downloads\Allen new.pdf
2017-04-19 10:21 - 2017-04-19 10:21 - 00097121 _____ C:\Users\AIRWORX 2\Downloads\CJ Allen Deposits 4-10-17 to 4-13-2017 (1).pdf
2017-04-19 10:21 - 2017-04-19 10:21 - 00062104 _____ C:\Users\AIRWORX 2\Downloads\CJ Allen Deposits 4-14-17 to 4-16-2017.pdf
2017-04-19 10:18 - 2017-04-19 10:18 - 00072858 _____ C:\Users\AIRWORX 2\Downloads\CJ Allen Deposits 3-31-17 to 4-2-2017.pdf
2017-04-19 04:42 - 2017-04-19 04:42 - 00090691 _____ C:\Users\AIRWORX 2\Downloads\CJ Allen Deposits 3-27-17 to 3-30-2017.pdf
2017-04-19 04:36 - 2017-04-19 04:38 - 00013819 _____ C:\Users\AIRWORX 2\Downloads\Cosmic Jump mats.xlsx
2017-04-19 04:35 - 2017-04-19 04:35 - 00043810 _____ C:\Users\AIRWORX 2\Downloads\CCR statement as of 06 April 2017 - 95269325 (1).pdf
2017-04-19 04:10 - 2017-04-19 04:10 - 00103453 _____ C:\Users\AIRWORX 2\Downloads\CJ Allen Deposits 4-3-17 to 4-7-2017 (1).pdf
2017-04-19 04:10 - 2017-04-19 04:10 - 00085627 _____ C:\Users\AIRWORX 2\Downloads\CJ Allen Deposits 4-7-17 to 4-9-2017.pdf
2017-04-19 04:10 - 2017-04-19 04:10 - 00049938 _____ C:\Users\AIRWORX 2\Downloads\Allen Service Sheets 4-10-17.pdf
2017-04-19 04:09 - 2017-04-19 04:09 - 00068343 _____ C:\Users\AIRWORX 2\Downloads\CJ Allen Deposits 4-10-17 to 4-13-2017.pdf
2017-04-18 11:52 - 2017-04-18 11:52 - 00308913 _____ C:\Users\AIRWORX 2\Documents\Account 8Details Print Friendly.pdf
2017-04-18 11:52 - 2017-04-18 11:52 - 00299476 _____ C:\Users\AIRWORX 2\Documents\Account9 Details Print Friendly.pdf
2017-04-18 11:51 - 2017-04-18 11:51 - 00305055 _____ C:\Users\AIRWORX 2\Documents\Account6 Details Print Friendly.pdf
2017-04-18 11:51 - 2017-04-18 11:51 - 00301841 _____ C:\Users\AIRWORX 2\Documents\Account7 Details Print Friendly.pdf
2017-04-18 11:50 - 2017-04-18 11:50 - 00304728 _____ C:\Users\AIRWORX 2\Documents\Account4 Details Print Friendly.pdf
2017-04-18 11:50 - 2017-04-18 11:50 - 00293038 _____ C:\Users\AIRWORX 2\Documents\Account Details Print Friendly(1).pdf
2017-04-18 11:50 - 2017-04-18 11:50 - 00283244 _____ C:\Users\AIRWORX 2\Documents\Account 5Details Print Friendly.pdf
2017-04-18 11:48 - 2017-04-18 11:49 - 00284773 _____ C:\Users\AIRWORX 2\Documents\Account 2Details Print Friendly.pdf
2017-04-18 11:48 - 2017-04-18 11:48 - 00284843 _____ C:\Users\AIRWORX 2\Documents\Account1 Details Print Friendly.pd1f.pdf
2017-04-18 11:47 - 2017-04-18 11:48 - 00264076 _____ C:\Users\AIRWORX 2\Documents\Account Details Print Friendly.pdf
2017-04-18 08:07 - 2017-04-25 15:55 - 00011237 _____ C:\Users\AIRWORX 2\Downloads\Checking2 (4).csv
2017-04-18 06:57 - 2017-04-18 06:57 - 00003380 _____ C:\Users\AIRWORX 2\Downloads\data (27).csv
2017-04-18 06:57 - 2017-04-18 06:57 - 00003380 _____ C:\Users\AIRWORX 2\Downloads\data (26).csv
2017-04-18 06:57 - 2017-04-18 06:57 - 00003379 _____ C:\Users\AIRWORX 2\Downloads\data (29).csv
2017-04-18 06:57 - 2017-04-18 06:57 - 00003379 _____ C:\Users\AIRWORX 2\Downloads\data (28).csv
2017-04-18 06:55 - 2017-04-18 06:55 - 00007892 _____ C:\Users\AIRWORX 2\Downloads\data (25).csv
2017-04-18 06:53 - 2017-04-18 06:53 - 00004128 _____ C:\Users\AIRWORX 2\Downloads\data (24).csv
2017-04-18 04:18 - 2017-04-18 04:18 - 00014070 _____ C:\Users\AIRWORX 2\Downloads\com.android.defcontainer-23-6.0.1.properties
2017-04-18 04:16 - 2017-04-18 04:16 - 00030216 _____ C:\Users\AIRWORX 2\Downloads\com.android.stk-23-6.0.1.properties
2017-04-18 04:16 - 2017-04-18 04:16 - 00028685 _____ C:\Users\AIRWORX 2\Downloads\com.cequint.ecid-120507-1.22.29.properties
2017-04-18 04:16 - 2017-04-18 04:16 - 00028685 _____ C:\Users\AIRWORX 2\Downloads\com.cequint.ecid-120507-1.22.29 (2).properties
2017-04-18 04:16 - 2017-04-18 04:16 - 00028685 _____ C:\Users\AIRWORX 2\Downloads\com.cequint.ecid-120507-1.22.29 (1).properties
2017-04-18 04:16 - 2017-04-18 04:16 - 00025641 _____ C:\Users\AIRWORX 2\Downloads\com.android.systemui-23-6.0.1.properties
2017-04-18 04:16 - 2017-04-18 04:16 - 00016497 _____ C:\Users\AIRWORX 2\Downloads\com.android.vending-80760800-.properties
2017-04-18 04:15 - 2017-04-18 04:15 - 00036581 _____ C:\Users\AIRWORX 2\Downloads\com.dsi.ant.server-30000-3.0.0.properties
2017-04-18 04:15 - 2017-04-18 04:15 - 00017778 _____ C:\Users\AIRWORX 2\Downloads\com.dsi.ant.plugins.antplus-30610-3.6.10.properties
2017-04-18 04:15 - 2017-04-18 04:15 - 00013838 _____ C:\Users\AIRWORX 2\Downloads\com.dsi.ant.service.socket-41420-4.14.20.properties
2017-04-18 04:15 - 2017-04-18 04:15 - 00000241 _____ C:\Users\AIRWORX 2\Downloads\com.enhance.gameservice-115100000-1.1.51.properties
2017-04-18 04:14 - 2017-04-18 04:14 - 00033703 _____ C:\Users\AIRWORX 2\Downloads\com.gc.android-60500000-6.5.0.0.properties
2017-04-18 04:14 - 2017-04-18 04:14 - 00014048 _____ C:\Users\AIRWORX 2\Downloads\com.gd.mobicore.pa-196687-.properties
2017-04-18 04:13 - 2017-04-18 04:13 - 00045127 _____ C:\Users\AIRWORX 2\Downloads\com.mm.android.direct.gdmssphoneLite-43-3.43.000.properties
2017-04-18 04:13 - 2017-04-18 04:13 - 00034780 _____ C:\Users\AIRWORX 2\Downloads\com.lookout-9301315-9.30.13-56280bf.properties
2017-04-18 04:13 - 2017-04-18 04:13 - 00013327 _____ C:\Users\AIRWORX 2\Downloads\com.LogiaGroup.LogiaDeck-16935-1.6.935.properties
2017-04-18 04:13 - 2017-04-18 04:13 - 00004224 _____ C:\Users\AIRWORX 2\Downloads\com.ipsec.service-8-3.5.properties
2017-04-18 04:12 - 2017-04-18 04:12 - 00014069 _____ C:\Users\AIRWORX 2\Downloads\com.policydm-418000000-4.1.80.properties
2017-04-18 04:12 - 2017-04-18 04:12 - 00012767 _____ C:\Users\AIRWORX 2\Downloads\com.osp.app.signin-210314-2.1.0314.properties
2017-04-18 04:12 - 2017-04-18 04:12 - 00008538 _____ C:\Users\AIRWORX 2\Downloads\com.mobisystems.fileman-14896-3.9.14896.properties
2017-04-18 04:08 - 2017-04-18 04:08 - 00028580 _____ C:\Users\AIRWORX 2\Downloads\com.samsung.oh-9000-10.2.14.0.properties
2017-04-18 04:07 - 2017-04-18 04:07 - 00038033 _____ C:\Users\AIRWORX 2\Downloads\com.sec.android.app.automotive.carmoderemote-2-2.0.2.1250855.properties
2017-04-18 04:07 - 2017-04-18 04:07 - 00017352 _____ C:\Users\AIRWORX 2\Downloads\com.samsung.ucs.agent.boot-23-6.0.1.properties
2017-04-18 04:06 - 2017-04-18 04:06 - 00024308 _____ C:\Users\AIRWORX 2\Downloads\com.sec.android.app.launcher-108000100-1.0.80.properties
2017-04-18 04:06 - 2017-04-18 04:06 - 00017342 _____ C:\Users\AIRWORX 2\Downloads\com.sec.android.app.interactivekeyguardtutorial-1-1.0.properties
2017-04-18 04:06 - 2017-04-18 04:06 - 00000231 _____ C:\Users\AIRWORX 2\Downloads\com.sec.android.app.hwmoduletest-23-6.0.1.properties
2017-04-18 04:05 - 2017-04-18 04:05 - 00038567 _____ C:\Users\AIRWORX 2\Downloads\com.sec.android.app.mt-100100000-1.0.01-0.properties
2017-04-18 04:05 - 2017-04-18 04:05 - 00014071 _____ C:\Users\AIRWORX 2\Downloads\com.sec.android.app.ocrseg-402501000-4.0.25.properties
2017-04-18 04:05 - 2017-04-18 04:05 - 00014061 _____ C:\Users\AIRWORX 2\Downloads\com.sec.android.app.parser-1-1.0.properties
2017-04-18 04:05 - 2017-04-18 04:05 - 00012126 _____ C:\Users\AIRWORX 2\Downloads\com.sec.android.app.myfiles-207701100-2.0.77.properties
2017-04-18 04:04 - 2017-04-18 04:04 - 00058818 _____ C:\Users\AIRWORX 2\Downloads\com.sec.android.app.SamsungContentsAgent-100400000-1.0.04.properties
2017-04-18 04:04 - 2017-04-18 04:04 - 00024094 _____ C:\Users\AIRWORX 2\Downloads\com.sec.android.app.sysscope-137800100-1.3.78.properties
2017-04-18 04:04 - 2017-04-18 04:04 - 00014072 _____ C:\Users\AIRWORX 2\Downloads\com.sec.android.app.servicemodeapp-23-6.0.1.properties
2017-04-18 04:02 - 2017-04-18 04:03 - 00038021 _____ C:\Users\AIRWORX 2\Downloads\com.sec.android.cloudagent.dropboxoobedummy-1-1.0.properties
2017-04-18 04:02 - 2017-04-18 04:02 - 00059350 _____ C:\Users\AIRWORX 2\Downloads\com.sec.android.diagmonagent-411300100-4.1.13.properties
2017-04-18 04:00 - 2017-04-18 04:00 - 00038570 _____ C:\Users\AIRWORX 2\Downloads\com.sec.android.RilServiceModeApp-23-6.0.1.properties
2017-04-18 04:00 - 2017-04-18 04:00 - 00034251 _____ C:\Users\AIRWORX 2\Downloads\com.sec.android.providers.tasks-23-6.0.1.properties
2017-04-18 04:00 - 2017-04-18 04:00 - 00004995 _____ C:\Users\AIRWORX 2\Downloads\com.sec.android.soagent-311200000-3.1.12.properties
2017-04-18 03:59 - 2017-04-18 03:59 - 00014086 _____ C:\Users\AIRWORX 2\Downloads\com.sec.app.TransmitPowerService-1-1.0.properties
2017-04-18 03:59 - 2017-04-18 03:59 - 00014061 _____ C:\Users\AIRWORX 2\Downloads\com.sec.automation-1-1.0.1.properties
2017-04-18 03:59 - 2017-04-18 03:59 - 00014056 _____ C:\Users\AIRWORX 2\Downloads\com.sec.bcservice-2-2.0.properties
2017-04-18 03:59 - 2017-04-18 03:59 - 00014056 _____ C:\Users\AIRWORX 2\Downloads\com.sec.bcservice-2-2.0 (1).properties
2017-04-18 03:58 - 2017-04-18 03:58 - 00014088 _____ C:\Users\AIRWORX 2\Downloads\com.sec.enterprise.mdm.services.simpin-23-6.0.1.properties
2017-04-18 03:58 - 2017-04-18 03:58 - 00014072 _____ C:\Users\AIRWORX 2\Downloads\com.sec.enterprise.mdm.vpn-13-1.3.properties
2017-04-18 03:58 - 2017-04-18 03:58 - 00000218 _____ C:\Users\AIRWORX 2\Downloads\com.sec.esdk.elm-500700000-5.0.07.properties
2017-04-18 03:58 - 2017-04-18 03:58 - 00000218 _____ C:\Users\AIRWORX 2\Downloads\com.sec.esdk.elm-500700000-5.0.07 (1).properties
2017-04-18 03:57 - 2017-04-18 03:57 - 00038333 _____ C:\Users\AIRWORX 2\Downloads\com.sec.imslogger-20160316-1.20160316_LDM.properties
2017-04-18 03:57 - 2017-04-18 03:57 - 00014052 _____ C:\Users\AIRWORX 2\Downloads\com.sec.imsservice-1-1.0.properties
2017-04-18 03:57 - 2017-04-18 03:57 - 00014045 _____ C:\Users\AIRWORX 2\Downloads\com.sec.ims-1-1.0.properties
2017-04-18 03:46 - 2017-04-18 03:55 - 00014063 _____ C:\Users\AIRWORX 2\Downloads\com.sec.vsimservice-1-1.0.properties
2017-04-14 12:41 - 2017-04-14 12:41 - 00169665 _____ C:\Users\AIRWORX 2\Downloads\CC Stmt (1).pdf
2017-04-14 12:37 - 2017-04-14 12:37 - 00385818 _____ C:\Users\AIRWORX 2\Downloads\3-24-2017.pdf
2017-04-14 11:20 - 2017-04-14 11:20 - 04201433 _____ C:\Users\AIRWORX 2\Downloads\bills (1).pdf
2017-04-14 11:02 - 2017-04-14 11:02 - 00018312 _____ C:\Users\AIRWORX 2\Downloads\BetterBatteryStats-2013-12-11_085650990.txt
2017-04-14 09:58 - 2017-04-14 09:58 - 00016758 _____ C:\Users\AIRWORX 2\Downloads\Jared Reese Info (1).pdf
2017-04-14 06:58 - 2017-04-14 06:58 - 00000000 _____ C:\Users\AIRWORX 2\AppData\Roaming\IVOPEN.$$$
2017-04-14 04:21 - 2017-04-14 04:21 - 67414726 _____ C:\Users\AIRWORX 2\Documents\cust all.csv.txt
2017-04-14 03:56 - 2017-04-14 03:56 - 00041602 _____ C:\Users\AIRWORX 2\Downloads\170540030194200.pdf
2017-04-13 07:10 - 2017-04-13 07:10 - 02004966 _____ C:\Users\AIRWORX 2\Downloads\Backup_17-04-10 03-43-12.zip
2017-04-13 07:09 - 2017-03-27 23:04 - 00277344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys
2017-04-13 07:09 - 2017-03-27 22:58 - 01344448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2017-04-13 07:09 - 2017-03-27 22:36 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.SerialCommunication.dll
2017-04-13 07:09 - 2017-03-27 22:17 - 06109696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2017-04-13 07:09 - 2017-03-27 22:16 - 03198464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2017-04-13 07:09 - 2017-03-27 22:12 - 00542208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2017-04-13 07:09 - 2017-03-27 22:08 - 01564160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
2017-04-13 07:08 - 2017-03-27 23:32 - 00198856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2017-04-13 07:08 - 2017-03-27 23:26 - 00218520 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
2017-04-13 07:08 - 2017-03-27 23:21 - 00167848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll
2017-04-13 07:08 - 2017-03-27 23:11 - 00360040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2017-04-13 07:08 - 2017-03-27 23:09 - 00097128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Credentials.UI.CredentialPicker.dll
2017-04-13 07:08 - 2017-03-27 23:05 - 01848584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2017-04-13 07:08 - 2017-03-27 23:04 - 00160088 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostBroker.dll
2017-04-13 07:08 - 2017-03-27 23:04 - 00136032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostUser.dll
2017-04-13 07:08 - 2017-03-27 23:02 - 00576408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2017-04-13 07:08 - 2017-03-27 22:52 - 00306800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MediaControl.dll
2017-04-13 07:08 - 2017-03-27 22:42 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2017-04-13 07:08 - 2017-03-27 22:40 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthManagerProxy.dll
2017-04-13 07:08 - 2017-03-27 22:39 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerUI.dll
2017-04-13 07:08 - 2017-03-27 22:38 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthTokenBrokerExt.dll
2017-04-13 07:08 - 2017-03-27 22:37 - 00215552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apds.dll
2017-04-13 07:08 - 2017-03-27 22:37 - 00177664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Diagnostics.dll
2017-04-13 07:08 - 2017-03-27 22:37 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.HostName.dll
2017-04-13 07:08 - 2017-03-27 22:37 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.SystemManagement.dll
2017-04-13 07:08 - 2017-03-27 22:36 - 00769024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ipsecsnp.dll
2017-04-13 07:08 - 2017-03-27 22:36 - 00237568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Diagnostics.dll
2017-04-13 07:08 - 2017-03-27 22:36 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\RdpRelayTransport.dll
2017-04-13 07:08 - 2017-03-27 22:36 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-04-13 07:08 - 2017-03-27 22:36 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.UserDeviceAssociation.dll
2017-04-13 07:08 - 2017-03-27 22:36 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicDisplay.sys
2017-04-13 07:08 - 2017-03-27 22:35 - 00505856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2017-04-13 07:08 - 2017-03-27 22:35 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2017-04-13 07:08 - 2017-03-27 22:34 - 00113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-04-13 07:08 - 2017-03-27 22:33 - 00609280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll
2017-04-13 07:08 - 2017-03-27 22:33 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ipsmsnap.dll
2017-04-13 07:08 - 2017-03-27 22:31 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2017-04-13 07:08 - 2017-03-27 22:31 - 00390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2017-04-13 07:08 - 2017-03-27 22:31 - 00343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.Phone.dll
2017-04-13 07:08 - 2017-03-27 22:30 - 00787968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sbe.dll
2017-04-13 07:08 - 2017-03-27 22:27 - 00441856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AccountsRt.dll
2017-04-13 07:08 - 2017-03-27 22:26 - 00642048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.InkControls.dll
2017-04-13 07:08 - 2017-03-27 22:26 - 00468992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.InkControls.dll
2017-04-13 07:08 - 2017-03-27 22:26 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2017-04-13 07:08 - 2017-03-27 22:25 - 01196544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl
2017-04-13 07:08 - 2017-03-27 22:24 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2017-04-13 07:08 - 2017-03-27 22:24 - 01220096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl
2017-04-13 07:08 - 2017-03-27 22:23 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2017-04-13 07:08 - 2017-03-27 22:22 - 00516096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll
2017-04-13 07:08 - 2017-03-27 22:22 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2017-04-13 07:08 - 2017-03-27 22:22 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enrollmentapi.dll
2017-04-13 07:08 - 2017-03-27 22:20 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmjpegdec.dll
2017-04-13 07:08 - 2017-03-27 22:19 - 07655424 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2017-04-13 07:08 - 2017-03-27 22:19 - 00746496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcprx.dll
2017-04-13 07:08 - 2017-03-27 22:14 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVP9DEC.dll
2017-04-13 07:08 - 2017-03-27 22:14 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2017-04-13 07:08 - 2017-03-27 22:13 - 02138112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2017-04-13 07:08 - 2017-03-27 22:13 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2017-04-13 07:08 - 2017-03-27 22:12 - 02682880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll
2017-04-13 07:08 - 2017-03-27 22:12 - 00862208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2017-04-13 07:08 - 2017-03-27 22:11 - 01576448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2017-04-13 07:08 - 2017-03-27 22:08 - 00299008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RADCUI.dll
2017-04-13 07:08 - 2017-03-27 22:07 - 00908800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2017-04-13 07:08 - 2017-03-27 22:05 - 01633792 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2017-04-13 07:08 - 2017-03-15 21:38 - 00034088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CompPkgSup.dll
2017-04-13 07:07 - 2017-03-27 23:10 - 00178528 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostUser.dll
2017-04-13 07:07 - 2017-03-27 23:09 - 00682816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2017-04-13 07:07 - 2017-03-27 22:58 - 00372440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2017-04-13 07:07 - 2017-03-27 22:37 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManagerProxy.dll
2017-04-13 07:07 - 2017-03-27 22:37 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DdcWnsListener.dll
2017-04-13 07:07 - 2017-03-27 22:35 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.SystemManagement.dll
2017-04-13 07:07 - 2017-03-27 22:34 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2017-04-13 07:07 - 2017-03-27 22:34 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
2017-04-13 07:07 - 2017-03-27 22:33 - 00182272 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceDirectoryClient.dll
2017-04-13 07:07 - 2017-03-27 22:33 - 00082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.UserDeviceAssociation.dll
2017-04-13 07:07 - 2017-03-27 22:31 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinDataModelServer.dll
2017-04-13 07:07 - 2017-03-27 22:31 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SerialCommunication.dll
2017-04-13 07:07 - 2017-03-27 22:30 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafpos.dll
2017-04-13 07:07 - 2017-03-27 22:30 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerUI.dll
2017-04-13 07:07 - 2017-03-27 22:29 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll
2017-04-13 07:07 - 2017-03-27 22:29 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2017-04-13 07:07 - 2017-03-27 22:27 - 00645120 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2017-04-13 07:07 - 2017-03-27 22:25 - 00966144 _____ (Microsoft Corporation) C:\WINDOWS\system32\sbe.dll
2017-04-13 07:07 - 2017-03-27 22:24 - 00410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-04-13 07:07 - 2017-03-27 22:21 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CastLaunch.dll
2017-04-13 07:07 - 2017-03-27 22:20 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmjpegdec.dll
2017-04-13 07:07 - 2017-03-27 22:19 - 00235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\flvprophandler.dll
2017-04-13 07:07 - 2017-03-27 22:17 - 05114368 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2017-04-13 07:07 - 2017-03-27 22:16 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\vss_ps.dll
2017-04-13 07:07 - 2017-03-27 22:15 - 00981504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
2017-04-13 07:07 - 2017-03-27 22:14 - 00869888 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2017-04-13 07:07 - 2017-03-27 22:10 - 01231872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2017-04-13 07:07 - 2017-03-27 22:09 - 01064448 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2017-04-13 07:07 - 2017-03-27 22:08 - 03542016 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2017-04-13 07:07 - 2017-03-27 22:08 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2017-04-13 07:07 - 2017-03-27 22:07 - 00701952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2017-04-13 07:07 - 2017-03-27 22:07 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\FontProvider.dll
2017-04-13 07:07 - 2017-03-18 09:50 - 00956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2017-04-13 07:07 - 2017-03-18 09:35 - 02278400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-04-13 07:07 - 2017-03-15 21:47 - 00038768 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompPkgSup.dll
2017-04-13 05:14 - 2017-04-13 05:14 - 00895197 _____ C:\Users\AIRWORX 2\Downloads\CCF10122016 (4).pdf
2017-04-13 05:14 - 2017-04-13 05:14 - 00297507 _____ C:\Users\AIRWORX 2\Downloads\CCF10112016 (4).pdf
2017-04-13 05:13 - 2017-04-13 05:13 - 00458582 _____ C:\Users\AIRWORX 2\Downloads\9.7.16.pdf
2017-04-13 04:47 - 2017-04-13 07:11 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\SPTemp
2017-04-12 13:47 - 2017-04-12 13:47 - 00264410 _____ C:\Users\AIRWORX 2\Downloads\2143831400724_20141211.pdf
2017-04-12 13:42 - 2017-04-12 13:42 - 00258800 _____ C:\Users\AIRWORX 2\Downloads\2143831400724_20151011.pdf
2017-04-12 13:29 - 2017-04-12 13:29 - 00257249 _____ C:\Users\AIRWORX 2\Downloads\2143831400724_20170211.pdf
2017-04-12 11:57 - 2017-04-12 11:57 - 00256768 _____ C:\Users\AIRWORX 2\Downloads\9133977700145_20170401.pdf
2017-04-12 09:41 - 2017-04-12 09:41 - 00194438 _____ C:\Users\AIRWORX 2\Documents\dla 2-23-14.pdf
2017-04-12 09:34 - 2017-04-12 09:34 - 00268317 _____ C:\Users\AIRWORX 2\Downloads\Allen HVAC Invoices 2015.pdf
2017-04-12 09:34 - 2017-04-12 09:34 - 00133875 _____ C:\Users\AIRWORX 2\Downloads\Allen HVAC Invoices 2016.pdf
2017-04-12 09:34 - 2017-04-12 09:34 - 00032962 _____ C:\Users\AIRWORX 2\Downloads\Maintenance Contract.pdf
2017-04-12 09:13 - 2017-04-12 09:13 - 00661059 _____ C:\Users\AIRWORX 2\Documents\scan327.pdf
2017-04-12 09:11 - 2017-04-12 09:11 - 00306365 _____ C:\Users\AIRWORX 2\Documents\Auto326.pdf
2017-04-12 05:05 - 2017-04-12 05:05 - 00000159 _____ C:\Users\AIRWORX 2\Documents\dl error.csv
2017-04-12 04:28 - 2017-04-12 04:28 - 00065874 _____ C:\Users\AIRWORX 2\Documents\Geise 2-23-14.pdf
2017-04-12 04:27 - 2017-04-12 04:27 - 00070812 _____ C:\Users\AIRWORX 2\Documents\Lynn vig 2-23-14 lives close to Catalina.pdf
2017-04-12 04:26 - 2017-04-12 04:26 - 00067498 _____ C:\Users\AIRWORX 2\Documents\batterjee 2-23-14.pdf
2017-04-12 04:25 - 2017-04-12 04:25 - 00062597 _____ C:\Users\AIRWORX 2\Documents\schultz 2-23-14.pdf
2017-04-12 04:24 - 2017-04-12 04:24 - 00062765 _____ C:\Users\AIRWORX 2\Documents\david bayba 2-23-14.pdf
2017-04-12 04:08 - 2017-04-12 04:08 - 00167241 _____ C:\Users\AIRWORX 2\Documents\HVAC Service Log.pdf
2017-04-12 03:54 - 2017-04-12 03:54 - 00167162 _____ C:\Users\AIRWORX 2\Downloads\HVAC service log (1).pdf
==================== Three Months Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-11 05:16 - 2015-01-29 18:03 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\ElevatedDiagnostics
2017-07-11 05:04 - 2016-09-30 14:04 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-07-11 04:53 - 2013-08-22 08:36 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2017-07-10 15:48 - 2016-09-30 14:11 - 01773902 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-07-10 15:47 - 2014-03-26 16:20 - 00000000 ___RD C:\Users\AIRWORX 2\Dropbox
2017-07-10 15:43 - 2016-07-15 23:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2017-07-10 10:26 - 2017-02-16 07:35 - 00000000 ____D C:\Program Files (x86)\Wondershare
2017-07-10 08:08 - 2016-07-16 04:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-07-10 07:32 - 2016-07-16 04:47 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files
2017-07-10 07:17 - 2014-03-06 03:09 - 133627792 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-07-10 07:08 - 2016-07-16 04:45 - 00000000 ____D C:\WINDOWS\INF
2017-07-10 06:57 - 2016-09-30 14:11 - 00000000 ____D C:\Users\AIRWORX 2
2017-07-10 06:57 - 2016-07-01 17:30 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin
2017-07-10 06:42 - 2016-07-01 14:24 - 00000000 ____D C:\Windows10Upgrade
2017-07-10 06:30 - 2016-09-30 14:41 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-07-10 06:30 - 2015-09-07 08:21 - 00000678 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-2671885098-678752524-1400920573-1001.job
2017-07-10 06:30 - 2014-04-02 13:11 - 00000582 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-2671885098-678752524-1400920573-1001.job
2017-07-10 05:56 - 2014-03-12 15:44 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\CrashDumps
2017-07-07 10:46 - 2015-12-14 11:13 - 00113371 _____ C:\Users\AIRWORX 2\Desktop\Book2.xlsx
2017-07-06 12:30 - 2014-10-23 16:52 - 00002603 _____ C:\Users\Public\Desktop\Calendar - Rock Gym Pro.lnk
2017-07-06 12:30 - 2014-03-04 13:30 - 00002603 _____ C:\Users\Public\Desktop\CheckIn - Rock Gym Pro.lnk
2017-07-06 12:30 - 2014-03-04 13:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rock Gym Pro
2017-07-06 12:30 - 2014-03-04 13:30 - 00000000 ____D C:\Program Files (x86)\Rock Gym Pro
2017-07-03 15:52 - 2017-02-20 08:22 - 00000000 ____D C:\Program Files\Recuva
2017-07-03 15:04 - 2016-10-27 13:08 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\ThisLife
2017-06-29 14:49 - 2017-02-10 07:53 - 00003072 ___SH C:\Users\AIRWORX 2\Documents\PPMetaData.bin
2017-06-29 14:49 - 2014-03-26 13:01 - 00311230 ____H C:\Users\AIRWORX 2\Documents\.ppinfocache
2017-06-29 14:49 - 2014-03-26 12:59 - 00042262 ____H C:\Users\AIRWORX 2\Documents\PP11Thumbs.ptn2
2017-06-29 14:49 - 2014-03-26 12:59 - 00026319 ____H C:\Users\AIRWORX 2\Documents\maxdesk.ini2
2017-06-29 14:49 - 2014-03-26 12:57 - 33680638 ____H C:\Users\AIRWORX 2\Documents\PP11Thumbs.ptn
2017-06-29 14:49 - 2014-03-12 15:25 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\.oit
2017-06-29 10:53 - 2015-10-19 12:01 - 00000000 ____D C:\Program Files (x86)\Dropbox
2017-06-28 02:52 - 2014-12-23 11:08 - 00000000 ____D C:\Program Files\ESET
2017-06-26 19:33 - 2014-07-02 11:24 - 00002279 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-06-26 10:25 - 2014-03-04 13:12 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\ESET
2017-06-26 10:07 - 2014-03-04 13:12 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\ESET
2017-06-26 07:03 - 2016-09-30 14:04 - 00470992 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-06-26 07:02 - 2014-12-30 17:01 - 00000000 ____D C:\Program Files (x86)\Video Client
2017-06-26 07:01 - 2013-10-14 16:54 - 00000000 ____D C:\Program Files (x86)\Windows Live
2017-06-26 06:59 - 2014-03-27 12:37 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\Windows Live
2017-06-26 06:58 - 2013-10-14 16:33 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-06-25 10:19 - 2014-05-28 14:16 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\Google
2017-06-24 10:28 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-06-24 00:35 - 2017-02-16 09:34 - 00000000 ___HD C:\DrFoneForAndroid
2017-06-23 16:07 - 2014-03-20 11:21 - 00000000 ____D C:\ProgramData\WebEx
2017-06-23 16:07 - 2013-10-14 16:40 - 00000000 ____D C:\ProgramData\Apple
2017-06-23 16:06 - 2014-04-02 13:10 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\Citrix
2017-06-23 16:06 - 2014-03-11 15:49 - 00000000 ____D C:\Program Files (x86)\epson
2017-06-23 03:57 - 2016-07-16 04:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-06-16 12:41 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\rescache
2017-06-16 07:57 - 2014-09-11 15:41 - 00000496 _____ C:\Users\AIRWORX 2\Desktop\ITSupport247 (3).website
2017-06-16 07:54 - 2014-03-13 11:19 - 00000000 ____D C:\ProgramData\LogMeIn
2017-06-14 12:40 - 2015-06-17 11:34 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\Dropbox
2017-06-14 12:15 - 2016-04-26 23:39 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-06-13 19:14 - 2016-04-28 08:23 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-06-13 19:14 - 2016-04-28 08:23 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-06-13 19:13 - 2016-07-16 04:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-06-13 19:13 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-06-13 19:13 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
2017-06-13 11:46 - 2014-03-06 03:09 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-06-13 11:40 - 2016-04-28 08:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
==================== Files in the root of some directories =======
2015-04-01 09:26 - 2005-12-08 19:51 - 0000060 ____R () C:\Program Files (x86)\BRINST.INI
2017-04-14 06:58 - 2017-04-14 06:58 - 0000000 _____ () C:\Users\AIRWORX 2\AppData\Roaming\IVOPEN.$$$
2014-12-17 10:09 - 2014-12-17 10:10 - 0012962 _____ () C:\Users\AIRWORX 2\AppData\Roaming\Microsoft Excel 97-2003.CAL
2014-03-26 13:47 - 2017-05-22 04:36 - 0007607 _____ () C:\Users\AIRWORX 2\AppData\Local\resmon.resmoncfg
2017-06-29 08:14 - 2017-06-29 08:14 - 0000000 _____ () C:\Users\AIRWORX 2\AppData\Local\{2A86C33F-824B-4295-8831-2FA8CE8A3C08}
2017-06-29 08:30 - 2017-06-29 08:31 - 0000000 _____ () C:\Users\AIRWORX 2\AppData\Local\{3E1C46B4-AE1C-47D4-A253-B086FFB08406}
2017-06-29 08:28 - 2017-06-29 08:31 - 0000000 _____ () C:\Users\AIRWORX 2\AppData\Local\{78ACC633-3A05-418D-841A-B650CBA92BFF}
2017-06-29 08:14 - 2017-06-29 08:14 - 0000000 _____ () C:\Users\AIRWORX 2\AppData\Local\{89363267-36DC-427C-A99A-0AEA97994C65}
2017-06-26 18:44 - 2017-06-26 18:44 - 0000000 _____ () C:\Users\AIRWORX 2\AppData\Local\{A5A12D5E-AE8C-4443-9C77-6230BEBDBB88}
2017-06-29 08:15 - 2017-06-29 08:15 - 0000000 _____ () C:\Users\AIRWORX 2\AppData\Local\{A8386299-DD6B-4871-AC75-168430E1797F}
2017-06-29 08:14 - 2017-06-29 08:14 - 0000000 _____ () C:\Users\AIRWORX 2\AppData\Local\{E626A012-0E1A-494A-9AB8-0870767076F6}
2017-06-29 08:14 - 2017-06-29 08:14 - 0000000 _____ () C:\Users\AIRWORX 2\AppData\Local\{E908C560-4859-4F24-905D-9A65B1BE63E1}
2017-06-29 08:14 - 2017-06-29 08:14 - 0000000 _____ () C:\Users\AIRWORX 2\AppData\Local\{F4796B34-AD33-4594-B511-F95371E88EEA}
2015-12-09 12:34 - 2015-12-09 12:34 - 0000145 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
2014-03-24 15:02 - 2014-10-23 13:06 - 0000226 _____ () C:\ProgramData\RSUserCfg.ini
Files to move or delete:
====================
C:\Users\AIRWORX 2\ASAP_Utilities_5-2-1_HS_Setup.exe
C:\Users\AIRWORX 2\WDMyCloud_win.exe
Some files in TEMP:
====================
2017-06-16 06:16 - 2017-06-16 06:16 - 0066048 _____ () C:\Users\AIRWORX 2\AppData\Local\Temp\Execute2App.exe
2017-05-24 03:36 - 2017-05-24 03:36 - 0739904 _____ (Oracle Corporation) C:\Users\AIRWORX 2\AppData\Local\Temp\jre-8u131-windows-au.exe
2017-06-16 06:16 - 2016-12-09 09:03 - 0568832 _____ (Microsoft Corporation) C:\Users\AIRWORX 2\AppData\Local\Temp\msvcp90.dll
2017-06-16 06:16 - 2016-12-09 09:03 - 0655872 _____ (Microsoft Corporation) C:\Users\AIRWORX 2\AppData\Local\Temp\msvcr90.dll
2017-06-23 16:06 - 2006-05-23 08:10 - 0455600 _____ (Macrovision Corporation) C:\Users\AIRWORX 2\AppData\Local\Temp\_isBC5D.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe
[2017-05-09 22:06] - [2017-04-27 16:39] - 0673792 _____ (Microsoft Corporation) B2151FE002A8D3F41E2DF935F260E3A8
C:\WINDOWS\system32\wininit.exe
[2016-07-16 04:42] - [2016-07-16 04:42] - 0304240 _____ (Microsoft Corporation) 99A19C9A74E2F9820E501DCE77F84F70
C:\WINDOWS\explorer.exe
[2017-05-09 22:06] - [2017-04-27 17:34] - 4674360 _____ (Microsoft Corporation) 679D17F8CDB938C7100D7A647953677E
C:\WINDOWS\SysWOW64\explorer.exe
[2017-05-09 22:08] - [2017-04-27 17:39] - 4312248 _____ (Microsoft Corporation) 6E46F7CBC16009E381015C69F4FA22B1
C:\WINDOWS\system32\svchost.exe
[2016-07-16 04:42] - [2016-07-16 04:42] - 0044496 _____ (Microsoft Corporation) 36F670D89040709013F6A460176767EC
C:\WINDOWS\SysWOW64\svchost.exe
[2016-07-16 04:42] - [2016-07-16 04:42] - 0038792 _____ (Microsoft Corporation) 1F8434DD4907C832E6E90D6298EAB85B
C:\WINDOWS\system32\services.exe
[2017-05-09 22:07] - [2017-04-27 17:28] - 0453536 _____ (Microsoft Corporation) 9A3B47CD17283B299311013AD3D21D26
C:\WINDOWS\system32\User32.dll
[2016-12-15 10:05] - [2016-12-09 03:10] - 1461200 _____ (Microsoft Corporation) C46EA86BF0E7C96235E9064CBAD6ED26
C:\WINDOWS\SysWOW64\User32.dll
[2016-12-15 10:05] - [2016-12-09 02:52] - 1435896 _____ (Microsoft Corporation) 4BEC594A3D4AEAFAC400D88F7E328C7B
C:\WINDOWS\system32\userinit.exe
[2016-07-16 04:42] - [2016-07-16 04:42] - 0033280 _____ (Microsoft Corporation) C1B1FFC800BE2F31EB2CF8CB40629C69
C:\WINDOWS\SysWOW64\userinit.exe
[2016-07-16 04:42] - [2016-07-16 04:42] - 0027648 _____ (Microsoft Corporation) FA900E6CCCF0A429D5B720C6F0E2274B
C:\WINDOWS\system32\rpcss.dll
[2017-05-09 22:06] - [2017-04-27 16:41] - 0890368 _____ (Microsoft Corporation) 4A7015195E49A3BA7DB967B277B21E9D
C:\WINDOWS\system32\dnsapi.dll
[2017-03-15 05:39] - [2017-03-04 00:24] - 0646688 _____ (Microsoft Corporation) 2813C62F5BE7FAF0A1C5CC37E5C2F25D
C:\WINDOWS\SysWOW64\dnsapi.dll
[2017-03-15 05:40] - [2017-03-04 00:09] - 0497416 _____ (Microsoft Corporation) AA86DC342B4ED1C1F839C3BC8AEA64B1
C:\WINDOWS\system32\Drivers\volsnap.sys
[2016-07-16 04:42] - [2016-07-16 04:42] - 0391520 _____ (Microsoft Corporation) BF2546583BB75F01DDA60A7921DFB230
==================== BCD ================================
Firmware Boot Manager
---------------------
identifier {fwbootmgr}
displayorder {bootmgr}
{4b7a2ef2-3541-11e3-b150-8a50d101b6a2}
{4b7a2ef3-3541-11e3-b150-8a50d101b6a2}
{9a6e2421-7ab0-11e3-be6f-806e6f6e6963}
{06729fc1-3539-11e3-be6c-806e6f6e6963}
{4b7a2ef7-3541-11e3-b150-8a50d101b6a2}
{4b7a2ef8-3541-11e3-b150-8a50d101b6a2}
timeout 2
Windows Boot Manager
--------------------
identifier {bootmgr}
device partition=\Device\HarddiskVolume2
path \EFI\Microsoft\Boot\bootmgfw.efi
description Windows Boot Manager
locale en-US
inherit {globalsettings}
default {current}
resumeobject {b9cacd1e-7ab0-11e3-be6f-a4db308c6ca7}
displayorder {current}
toolsdisplayorder {memdiag}
timeout 30
Firmware Application (101fffff)
-------------------------------
identifier {06729fc1-3539-11e3-be6c-806e6f6e6963}
description UEFI: Ipv6 Network Card
Firmware Application (101fffff)
-------------------------------
identifier {4b7a2ef2-3541-11e3-b150-8a50d101b6a2}
description USB Floppy/CD
Firmware Application (101fffff)
-------------------------------
identifier {4b7a2ef3-3541-11e3-b150-8a50d101b6a2}
description USB Hard Drive
Firmware Application (101fffff)
-------------------------------
identifier {4b7a2ef7-3541-11e3-b150-8a50d101b6a2}
description USB Floppy/CD
Firmware Application (101fffff)
-------------------------------
identifier {4b7a2ef8-3541-11e3-b150-8a50d101b6a2}
description Hard Drive
Firmware Application (101fffff)
-------------------------------
identifier {9a6e2421-7ab0-11e3-be6f-806e6f6e6963}
description UEFI: Ipv4 Network Card
Windows Boot Loader
-------------------
identifier {b9cacd0f-7ab0-11e3-be6f-a4db308c6ca7}
device ramdisk=[\Device\HarddiskVolume1]\Recovery\WindowsRE\Winre.wim,{b9cacd10-7ab0-11e3-be6f-a4db308c6ca7}
path \windows\system32\winload.efi
description Windows Recovery Environment
locale en-US
inherit {bootloadersettings}
displaymessage Recovery
osdevice ramdisk=[\Device\HarddiskVolume1]\Recovery\WindowsRE\Winre.wim,{b9cacd10-7ab0-11e3-be6f-a4db308c6ca7}
systemroot \windows
nx OptIn
bootmenupolicy Standard
winpe Yes
Windows Boot Loader
-------------------
identifier {b9cacd16-7ab0-11e3-be6f-a4db308c6ca7}
device ramdisk=[\Device\HarddiskVolume5]\Recovery\WindowsRE\Winre.wim,{b9cacd17-7ab0-11e3-be6f-a4db308c6ca7}
path \windows\system32\winload.efi
description Windows Recovery Environment
locale en-US
inherit {bootloadersettings}
displaymessage Recovery
displaymessageoverride Recovery
osdevice ramdisk=[\Device\HarddiskVolume5]\Recovery\WindowsRE\Winre.wim,{b9cacd17-7ab0-11e3-be6f-a4db308c6ca7}
systemroot \windows
nx OptIn
bootmenupolicy Standard
winpe Yes
Windows Boot Loader
-------------------
identifier {b9cacd1b-7ab0-11e3-be6f-a4db308c6ca7}
device ramdisk=[\Device\HarddiskVolume5]\Recovery\WindowsRE\Winre.wim,{b9cacd1c-7ab0-11e3-be6f-a4db308c6ca7}
path \windows\system32\winload.efi
description Windows Recovery Environment
locale en-US
inherit {bootloadersettings}
displaymessage Recovery
displaymessageoverride Recovery
osdevice ramdisk=[\Device\HarddiskVolume5]\Recovery\WindowsRE\Winre.wim,{b9cacd1c-7ab0-11e3-be6f-a4db308c6ca7}
systemroot \windows
nx OptIn
bootmenupolicy Standard
winpe Yes
Windows Boot Loader
-------------------
identifier {current}
device partition=C:
path \WINDOWS\system32\winload.efi
description Windows 10
locale en-US
inherit {bootloadersettings}
recoverysequence {b9cacd20-7ab0-11e3-be6f-a4db308c6ca7}
recoveryenabled Yes
isolatedcontext Yes
allowedinmemorysettings 0x15000075
osdevice partition=C:
systemroot \WINDOWS
resumeobject {b9cacd1e-7ab0-11e3-be6f-a4db308c6ca7}
nx OptIn
safeboot Network
bootmenupolicy Standard
Windows Boot Loader
-------------------
identifier {b9cacd20-7ab0-11e3-be6f-a4db308c6ca7}
device ramdisk=[\Device\HarddiskVolume5]\Recovery\WindowsRE\Winre.wim,{b9cacd21-7ab0-11e3-be6f-a4db308c6ca7}
path \windows\system32\winload.efi
description Windows Recovery Environment
locale en-US
inherit {bootloadersettings}
displaymessage Recovery
osdevice ramdisk=[\Device\HarddiskVolume5]\Recovery\WindowsRE\Winre.wim,{b9cacd21-7ab0-11e3-be6f-a4db308c6ca7}
systemroot \windows
nx OptIn
bootmenupolicy Standard
winpe Yes
Resume from Hibernate
---------------------
identifier {b9cacd11-7ab0-11e3-be6f-a4db308c6ca7}
device partition=C:
path \windows\system32\winresume.efi
description Windows Resume Application
locale en-US
inherit {resumeloadersettings}
recoverysequence {b9cacd0f-7ab0-11e3-be6f-a4db308c6ca7}
recoveryenabled Yes
isolatedcontext Yes
allowedinmemorysettings 0x15000075
filedevice partition=C:
filepath \hiberfil.sys
bootmenupolicy Standard
debugoptionenabled No
Resume from Hibernate
---------------------
identifier {b9cacd14-7ab0-11e3-be6f-a4db308c6ca7}
device partition=C:
path \WINDOWS\system32\winresume.efi
description Windows Resume Application
locale en-US
inherit {resumeloadersettings}
recoverysequence {b9cacd16-7ab0-11e3-be6f-a4db308c6ca7}
recoveryenabled Yes
isolatedcontext Yes
allowedinmemorysettings 0x15000075
filedevice partition=C:
filepath \hiberfil.sys
bootmenupolicy Standard
debugoptionenabled No
Resume from Hibernate
---------------------
identifier {b9cacd19-7ab0-11e3-be6f-a4db308c6ca7}
device partition=C:
path \WINDOWS\system32\winresume.efi
description Windows Resume Application
locale en-US
inherit {resumeloadersettings}
recoverysequence {b9cacd1b-7ab0-11e3-be6f-a4db308c6ca7}
recoveryenabled Yes
isolatedcontext Yes
allowedinmemorysettings 0x15000075
filedevice partition=C:
filepath \hiberfil.sys
bootmenupolicy Standard
debugoptionenabled No
Resume from Hibernate
---------------------
identifier {b9cacd1e-7ab0-11e3-be6f-a4db308c6ca7}
device partition=C:
path \WINDOWS\system32\winresume.efi
description Windows Resume Application
locale en-US
inherit {resumeloadersettings}
recoverysequence {b9cacd20-7ab0-11e3-be6f-a4db308c6ca7}
recoveryenabled Yes
isolatedcontext Yes
allowedinmemorysettings 0x15000075
filedevice partition=C:
filepath \hiberfil.sys
bootmenupolicy Standard
debugoptionenabled No
Windows Memory Tester
---------------------
identifier {memdiag}
device partition=\Device\HarddiskVolume2
path \EFI\Microsoft\Boot\memtest.efi
description Windows Memory Diagnostic
locale en-US
inherit {globalsettings}
badmemoryaccess Yes
EMS Settings
------------
identifier {emssettings}
bootems No
Debugger Settings
-----------------
identifier {dbgsettings}
debugtype Serial
debugport 1
baudrate 115200
RAM Defects
-----------
identifier {badmemory}
Global Settings
---------------
identifier {globalsettings}
inherit {dbgsettings}
{emssettings}
{badmemory}
Boot Loader Settings
--------------------
identifier {bootloadersettings}
inherit {globalsettings}
{hypervisorsettings}
Hypervisor Settings
-------------------
identifier {hypervisorsettings}
hypervisordebugtype Serial
hypervisordebugport 1
hypervisorbaudrate 115200
Resume Loader Settings
----------------------
identifier {resumeloadersettings}
inherit {globalsettings}
Device options
--------------
identifier {b9cacd10-7ab0-11e3-be6f-a4db308c6ca7}
description Windows Recovery
ramdisksdidevice partition=\Device\HarddiskVolume1
ramdisksdipath \Recovery\WindowsRE\boot.sdi
Device options
--------------
identifier {b9cacd13-7ab0-11e3-be6f-a4db308c6ca7}
description Windows Setup
ramdisksdidevice partition=C:
ramdisksdipath \$WINDOWS.~BT\Sources\SafeOS\boot.sdi
Device options
--------------
identifier {b9cacd17-7ab0-11e3-be6f-a4db308c6ca7}
description Windows Recovery
ramdisksdidevice partition=\Device\HarddiskVolume5
ramdisksdipath \Recovery\WindowsRE\boot.sdi
Device options
--------------
identifier {b9cacd18-7ab0-11e3-be6f-a4db308c6ca7}
description Windows Setup
ramdisksdidevice partition=C:
ramdisksdipath \$WINDOWS.~BT\Sources\SafeOS\boot.sdi
Device options
--------------
identifier {b9cacd1c-7ab0-11e3-be6f-a4db308c6ca7}
description Windows Recovery
ramdisksdidevice partition=\Device\HarddiskVolume5
ramdisksdipath \Recovery\WindowsRE\boot.sdi
Device options
--------------
identifier {b9cacd1d-7ab0-11e3-be6f-a4db308c6ca7}
description Windows Setup
ramdisksdidevice partition=C:
ramdisksdipath \$WINDOWS.~BT\Sources\SafeOS\boot.sdi
Device options
--------------
identifier {b9cacd21-7ab0-11e3-be6f-a4db308c6ca7}
description Windows Recovery
ramdisksdidevice partition=\Device\HarddiskVolume5
ramdisksdipath \Recovery\WindowsRE\boot.sdi
LastRegBack: 2017-07-03 16:00
==================== End of FRST.txt ============================
ADDITION RESULTS-
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-07-2017
Ran by AIRWORX 2 (11-07-2017 05:32:23)
Running from C:\Users\AIRWORX 2\Desktop
Windows 10 Home Version 1607 (X64) (2016-09-30 21:46:03)
Boot Mode: Safe Mode (with Networking)
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2671885098-678752524-1400920573-500 - Administrator - Disabled) => C:\Users\Administrator
AIRWORX 2 (S-1-5-21-2671885098-678752524-1400920573-1001 - Administrator - Enabled) => C:\Users\AIRWORX 2
AirworxAZ (S-1-5-21-2671885098-678752524-1400920573-1007 - Administrator - Enabled) => C:\Users\AirworxAZ
DefaultAccount (S-1-5-21-2671885098-678752524-1400920573-503 - Limited - Disabled)
Guest (S-1-5-21-2671885098-678752524-1400920573-501 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: ESET Smart Security (Enabled - Up to date) {EC1D6F37-E411-475A-DF50-12FF7FE4AC70}
AS: ESET Smart Security (Enabled - Up to date) {577C8ED3-C22B-48D4-E5E0-298D0463E6CD}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ESET Personal firewall (Enabled) {D426EE12-AE7E-4602-F40F-BBCA8137EB0B}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
4 Elements II (HKLM-x32\...\WTA-ab750ac1-a75f-4faa-9130-cb24f10deff9) (Version: 2.2.0.98 - WildTangent) Hidden
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Photoshop Elements 4.0 (HKLM-x32\...\Adobe Photoshop Elements 4) (Version: 4.0 - Adobe Systems Inc.)
Adobe Reader XI (11.0.10) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Airport Mania (HKLM-x32\...\WTA-874faa05-ffea-49ac-b3f3-cdd8551b12c4) (Version: 2.2.0.95 - WildTangent) Hidden
Alcor Micro USB Card Reader Driver (HKLM-x32\...\{05E5AD66-7CD0-4719-A229-0D3A7A5240D2}) (Version: 20.22.2217.13862 - Alcor Micro Corp.) Hidden
Alcor Micro USB Card Reader Driver (HKLM-x32\...\AmUStor) (Version: 20.22.2217.13862 - Alcor Micro Corp.)
AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD)
AMD Catalyst Install Manager (HKLM\...\{40959651-122E-1A16-9011-40629C01703F}) (Version: 8.0.911.0 - Advanced Micro Devices, Inc.)
Apple Mobile Device Support (HKLM\...\{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}) (Version: 7.1.2.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ASAP Utilities (HKLM-x32\...\ASAP Utilities_is1) (Version: 7.1 - Bastien Mensink - A Must in Every Office BV)
AVIGenerator2.0 2.0.0.3 (HKLM-x32\...\AVIGenerator2.0) (Version: 2.0.0.3 - )
Azteca (HKLM-x32\...\WTA-7fcea35d-1fcb-401a-8585-67a0d6c08581) (Version: 2.2.0.97 - WildTangent) Hidden
Bejeweled 3 (HKLM-x32\...\WTA-bfcc4dec-b73e-414b-a9dc-5e709e9805a3) (Version: 2.2.0.98 - WildTangent) Hidden
Belkasoft Evidence Center Ultimate (HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\Belkasoft Evidence Center Ultimate) (Version: - )
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Bonjour Print Services (HKLM\...\{0DA20600-6130-443B-9D4B-F30520315FA6}) (Version: 2.0.2.0 - Apple Inc.)
Bounce Symphony (HKLM-x32\...\WTA-77e25129-9e1c-4394-bcaa-608574b026dd) (Version: 2.2.0.97 - WildTangent) Hidden
Broderbund Family Lawyer (HKLM-x32\...\{ED95E1BA-8C35-4D78-8A20-FD5A728711E2}) (Version: 1.00.0000 - Bluecase) Hidden
Broderbund Family Lawyer (HKLM-x32\...\InstallShield_{ED95E1BA-8C35-4D78-8A20-FD5A728711E2}) (Version: 1.00.0000 - Bluecase)
Brother MFL-Pro Suite MFC-7860DW (HKLM-x32\...\{3ACCCFB3-7B17-4E9F-ACB0-46868FCD4487}) (Version: 1.1.3.0 - Brother Industries, Ltd.)
Build-a-lot (HKLM-x32\...\WTA-a8fede7f-8904-49b7-affe-a398e5e5821d) (Version: 2.2.0.98 - WildTangent) Hidden
Cloud Drive (HKLM-x32\...\{F40EC703-6B64-4C2D-80BC-5ED2D8295C04}) (Version: 5.1.30.18 - Cox Secure Online Backup for Windows)
CMS (HKLM-x32\...\{2A0DCCF2-C699-4445-BFAD-888EC538EB7F}) (Version: 3.51.1.8 - )
Cradle Of Egypt Collector's Edition (HKLM-x32\...\WTA-5f5453eb-ce7a-4d33-a38a-7959b83f6adf) (Version: 2.2.0.110 - WildTangent) Hidden
Cradle of Rome 2 (HKLM-x32\...\WTA-02b2e41e-0339-45e8-bd8a-21b8e5cfbe2c) (Version: 2.2.0.98 - WildTangent) Hidden
Curse at Twilight (HKLM-x32\...\WTA-2f1d8c60-0e50-4c9f-9403-24ea1ebf5aa5) (Version: 3.0.2.32 - WildTangent) Hidden
CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.4.3003 - CyberLink Corp.)
Cyberlink PhotoDirector (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.3.4608 - CyberLink Corp.)
CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.4.2921 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.4.3007 - CyberLink Corp.)
DB Browser for SQLite (HKLM-x32\...\DB Browser for SQLite) (Version: 3.9.1 - DB Browser for SQLite Team)
Delicious: Emily's Childhood Memories Premium Edition (HKLM-x32\...\WTA-4ea8b31e-ca28-4b94-80e5-8b74992de5bf) (Version: 3.0.2.32 - WildTangent) Hidden
Drag and Drop Backup (HKLM-x32\...\{480EA68A-699D-450D-9869-2216AC49D23C}) (Version: 2.1.33 - Cox)
Dropbox (HKLM-x32\...\Dropbox) (Version: 29.4.20 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.59.1 - Dropbox, Inc.) Hidden
Epson Copy Utility 3.5 (HKLM-x32\...\{AA72FB28-73B4-49E5-B6B4-E78F44BBD0AD}) (Version: 3.5.0.0 - )
Epson Event Manager (HKLM-x32\...\{48F22622-1CC2-4A83-9C1E-644DD96F832D}) (Version: 2.30.01 - SEIKO EPSON Corporation)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - )
Escaperoom Software (HKLM-x32\...\{7BAA7E0D-9B92-4FE7-AEC8-F11EAE801922}) (Version: 3.1.0.0 - Escaperoom Software)
ESET Smart Security (HKLM\...\{2B587448-4CE3-4196-A237-A425E557F052}) (Version: 10.1.204.0 - ESET, spol. s r.o.)
Farm Frenzy (HKLM-x32\...\WTA-6629a81c-b2e5-437c-a199-8f3afce2b7fc) (Version: 2.2.0.98 - WildTangent) Hidden
Fitbit Connect (HKLM-x32\...\{6EB73D9D-645E-415B-8008-83C3CB865968}) (Version: 2.0.1.6742 - Fitbit Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 59.0.3071.115 - Google Inc.)
Google Drive (HKLM-x32\...\{A1238426-ECDF-4639-BE2F-8D12A97AE23C}) (Version: 2.34.5075.1619 - Google, Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Governor of Poker 2 Premium Edition (HKLM-x32\...\WTA-aacfbe1b-a691-4a64-a94c-4f1f06e2f022) (Version: 2.2.0.110 - WildTangent) Hidden
Hewlett-Packard ACLM.NET v1.2.2.1 (HKLM-x32\...\{6F340107-F9AA-47C6-B54C-C3A19F11553F}) (Version: 1.00.0000 - Hewlett-Packard Company) Hidden
House of 1000 Doors: Family Secrets (HKLM-x32\...\WTA-2a60eac8-171f-48cd-9ea4-e2b5cb6de8ee) (Version: 2.2.0.98 - WildTangent) Hidden
HP Quick Start (HKLM-x32\...\{574F0207-8E98-46CD-8F79-318348C98C46}) (Version: 1.0.4660.30220 - Hewlett-Packard)
HP Registration Service (HKLM\...\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.6668.4491 - Hewlett-Packard)
HP Support Assistant (HKLM-x32\...\{79C54A05-F146-4EA0-8A70-D4EFE6181E52}) (Version: 8.4.19.3 - Hewlett-Packard Company)
HP Support Information (HKLM-x32\...\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 12.00.0000 - Hewlett-Packard)
HP Support Solutions Framework (HKLM-x32\...\{E2CB09C1-3C76-4395-BB47-50C066535CF8}) (Version: 12.7.22.13 - HP)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6482.0 - IDT)
iTunes (HKLM\...\{33E28B58-7BA0-47B7-AA01-9225ABA2B8A9}) (Version: 11.3.0.54 - Apple Inc.)
Java 8 Update 131 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180131F0}) (Version: 8.0.1310.11 - Oracle Corporation)
Jewel Match 3 (HKLM-x32\...\WTA-39f32991-6764-4234-93c1-68ef23fdea34) (Version: 2.2.0.98 - WildTangent) Hidden
LG Mobile Driver (HKLM-x32\...\{3F490D0E-3131-438C-BCF9-7549CB88DF41}) (Version: 4.2.0 - LG Electronics)
LG United Mobile Drivers (HKLM-x32\...\{4DE95ED9-0A29-4C4F-8463-35857CF9BA36}) (Version: 3.14.1 - LG Electronics)
Luxor Evolved (HKLM-x32\...\WTA-c41ecf4f-19c8-43b0-b9b0-4301bbf25cf8) (Version: 2.2.0.98 - WildTangent) Hidden
Mah Jong Medley (HKLM-x32\...\WTA-c45d13aa-6627-4559-aa01-7ff9eb4c9d83) (Version: 2.2.0.95 - WildTangent) Hidden
Mahjongg Dimensions Deluxe: Tiles in Time (HKLM-x32\...\WTA-c82c2923-55d5-4984-b016-2f02bc3801ea) (Version: 2.2.0.98 - WildTangent) Hidden
Microsoft Office Professional 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4048 (HKLM\...\{91415F19-4C22-3609-A105-92ED3522D83C}) (Version: 9.0.30729.4048 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4048 (HKLM-x32\...\{5B1F2843-B379-3FF2-B0D3-64DD143ED53A}) (Version: 9.0.30729.4048 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM-x32\...\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}) (Version: 14.0.23918.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
MsBackupViewer (HKLM-x32\...\{EA75EA52-124B-4A5D-994C-87DD4428DEF9}) (Version: 6.1.2.1 - )
MySQL Connector/ODBC 5.1 (HKLM-x32\...\{38CDEC3E-ABC4-4EB8-BE3B-2181A97813AE}) (Version: 5.1.12 - Oracle Corporation)
MySQL Server 5.0 (HKLM-x32\...\{97EFE060-CE35-4709-9B3A-5D3C8F686FED}) (Version: 5.0.90 - MySQL AB)
Mystery P.I. - Curious Case of Counterfeit Cove (HKLM-x32\...\WTA-f16433ca-8978-4040-a336-1bb274fa0fa1) (Version: 2.2.0.98 - WildTangent) Hidden
Nuance PaperPort 14 (HKLM-x32\...\{14CB3B82-FBDC-4462-919E-86147983F09B}) (Version: 14.5.0000 - Nuance Communications, Inc.)
Nuance PDF Create 7 (HKLM\...\{AAA715B7-02F9-4F2D-92C9-80EC63835AA1}) (Version: 7.10.6408 - Nuance Communications, Inc.)
Nuance PDF Create 7 (HKLM-x32\...\{AAA715B7-02F9-4F2D-92C9-80EC63835AA1}) (Version: 7.10.6408 - Nuance Communications, Inc.)
Nuance PDF Viewer Plus (HKLM-x32\...\{FC984E39-43D0-4AB2-ACC7-A7B87977B009}) (Version: 7.20.3274 - Nuance Communications, Inc.)
PaperPort Image Printer 64-bit (HKLM\...\{715CAACC-579B-4831-A5F4-A83A8DE3EFE2}) (Version: 14.00.0001 - Nuance Communications, Inc.)
Peggle Nights (HKLM-x32\...\WTA-cbad1f24-f6a9-4577-b532-eef76097e0eb) (Version: 2.2.0.98 - WildTangent) Hidden
Pinger (HKLM-x32\...\{9B56B031-A6C0-4BB7-8F61-938548C1B759}) (Version: 1.1.1.2 - Pinger Inc.) Hidden
Pinger (HKLM-x32\...\Pinger 1.1.1.2) (Version: 1.1.1.2 - Pinger Inc.)
Plants vs. Zombies - Game of the Year (HKLM-x32\...\WTA-086f8638-4cc0-4c1f-aef2-4976e72a6644) (Version: 2.2.0.98 - WildTangent) Hidden
Polar Bowler (HKLM-x32\...\WTA-2431d870-53dd-43a3-a554-b4ecc25c4869) (Version: 2.2.0.97 - WildTangent) Hidden
Qualcomm Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 10.0 - Qualcomm Atheros)
QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10125.31214 - Realtek Semiconductor Corp.)
Recovery Manager (HKLM-x32\...\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.5.0.6208 - CyberLink Corp.) Hidden
Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform)
Roads of Rome 3 (HKLM-x32\...\WTA-4ed08251-5255-45ff-bac1-ba4246a693fe) (Version: 2.2.0.98 - WildTangent) Hidden
Rock Gym Pro (HKLM-x32\...\{827570FB-0E88-444C-ADBC-9E799571E292}) (Version: 1.1.21247 - RGP Development LLC)
RogueKiller version 12.11.6.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.11.6.0 - Adlice Software)
Royal Envoy 2 Collector's Edition (HKLM-x32\...\WTA-eaf39489-2639-4bad-8db1-886233f1c823) (Version: 3.0.2.32 - WildTangent) Hidden
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.63.0 - Samsung Electronics Co., Ltd.)
Scansoft PDF Create (HKLM-x32\...\{068724F8-D8BE-4B43-8DDD-B9FE9E49FD76}) (Version: - ) Hidden
Seagate DiscWizard (HKLM-x32\...\{8FB2A014-A0B0-42D8-8E18-9AFC6A6E2814}) (Version: 13.0.14387 - Seagate)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Shutterfly Uploader (HKLM-x32\...\{CD928A00-1C70-4353-B9B9-7BC8600F3E43}) (Version: 2.9.0.737 - Shutterfly, Inc.)
Smart Player (HKLM-x32\...\Smart Player3.00.0) (Version: 3.00.0 - Zhejiang Dahua Technology Co.,LTD.)
Smart Switch (HKLM-x32\...\{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.1.17054.16 - Samsung Electronics Co., Ltd.) Hidden
Smart Switch (HKLM-x32\...\InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.1.17054.16 - Samsung Electronics Co., Ltd.)
SyncFileSetup (x86) (HKLM-x32\...\{04848A0A-02B1-4703-B15D-6E7DCF95FB84}) (Version: 1.3.5949.26210 - Western Digital Technologies, Inc) Hidden
Tales of Lagoona (HKLM-x32\...\WTA-470d59ed-9736-4c67-b51b-6ac9f1154d0b) (Version: 2.2.0.110 - WildTangent) Hidden
TaxAct 2015 1040 Edition (HKLM-x32\...\TaxAct 2015 1040 Edition) (Version: 1.03 - TaxAct, Inc.)
TaxAct 2015 Arizona (HKLM-x32\...\TaxAct 2015 Arizona) (Version: 1.02 - TaxAct, Inc.)
TaxAct 2016 1040 Edition (HKLM-x32\...\TaxAct 2016 1040 Edition) (Version: 1.03 - TaxAct, Inc.)
Update Installer for WildTangent Games App (HKLM-x32\...\{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App) (Version: - WildTangent) Hidden
Vacation Quest™ - Australia (HKLM-x32\...\WTA-31fd45f1-c713-47cd-af58-12bc5c8d560e) (Version: 3.0.2.32 - WildTangent) Hidden
Verizon Wireless Software Utility Application for Android - Samsung (HKLM-x32\...\{69258FD1-F4EE-475A-83D1-BF68C8029592}) (Version: 2.14.0402 - Samsung Electronics Co., Ltd.)
WD Sync (HKLM-x32\...\{0d591303-bbc5-4645-a03b-1c3f75f1a762}) (Version: 1.3.5949.26210 - Western Digital Technologies, Inc.)
WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent)
WildTangent Games App (HP Games) (HKLM-x32\...\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp) (Version: 4.0.10.5 - WildTangent) Hidden
Windows 10 Update and Privacy Settings (HKLM\...\{293F2009-0145-450B-B4AA-063D43FB368C}) (Version: 1.0.13.0 - Microsoft Corporation)
Windows 10 Upgrade Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.17332 - Microsoft Corporation)
WorkForce GT-1500 Scanner Driver Update (HKLM-x32\...\{37D0F29D-AB95-4598-ACF0-D3CC38C161D9}) (Version: - )
Youda Jewel Shop (HKLM-x32\...\WTA-a598a80f-5731-473e-a23c-0d29c1c3fc08) (Version: 3.0.2.32 - WildTangent) Hidden
Zuma's Revenge (HKLM-x32\...\WTA-74ec95d8-a8c7-4ca8-b647-5ddcb27191c2) (Version: 2.2.0.98 - WildTangent) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2671885098-678752524-1400920573-1001_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\AIRWORX 2\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileCoAuthLib64.dll => No File
CustomCLSID: HKU\S-1-5-21-2671885098-678752524-1400920573-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\AIRWORX 2\AppData\Local\Citrix\GoToMeeting\1350\G2MOutlookAddin64.dll => No File
ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-03-21] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-03-21] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-03-21] (Google)
ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
ContextMenuHandlers01: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov)
ContextMenuHandlers01: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2013-05-24] (Cyberlink)
ContextMenuHandlers01: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ContextMenuHandlers01: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2017-03-09] (ESET)
ContextMenuHandlers01: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-03-21] (Google)
ContextMenuHandlers01: [WDSyncContextMenuHandler] -> {5A51BDCB-F8C2-4698-B79C-A77DF0AA466B} => C:\WINDOWS\system32\mscoree.dll [2016-07-16] (Microsoft Corporation)
ContextMenuHandlers01: [Zeon.MFCDirectShellExt] -> {353C642C-F13D-4699-9FF2-EFAF490B6C69} => C:\Program Files (x86)\Nuance\PDFCreate\bin\DirectShellExt.dll [2010-07-16] (Zeon International Investment Corp. )
ContextMenuHandlers02: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2013-05-24] (Cyberlink)
ContextMenuHandlers02: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2017-03-09] (ESET)
ContextMenuHandlers04: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov)
ContextMenuHandlers04: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ContextMenuHandlers04: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-03-21] (Google)
ContextMenuHandlers04: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd)
ContextMenuHandlers05: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2015-11-04] (Advanced Micro Devices, Inc.)
ContextMenuHandlers05: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
ContextMenuHandlers06: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2017-03-09] (ESET)
ContextMenuHandlers06: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd)
ContextMenuHandlers06: [WDSyncContextMenuHandler] -> {5A51BDCB-F8C2-4698-B79C-A77DF0AA466B} => C:\WINDOWS\system32\mscoree.dll [2016-07-16] (Microsoft Corporation)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {005B78DE-9ECF-4C1D-85D3-6330FE864BA6} - System32\Tasks\GoogleUpdateTaskMachineCore1d040ece2e11a19 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {073958F3-8E5F-4CF7-8625-ABD15377481E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2017-06-22] (HP Inc.)
Task: {0A1E4A40-752E-425E-B7D0-0A0AE002C93C} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {177104C1-EBE5-47D0-B491-392F53A58E9C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-04-06] (HP Inc.)
Task: {240692C1-B6D2-4FFA-B520-9689EC0B8131} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-11-07] (HP Inc.)
Task: {259AE203-7AAC-4A0D-93DD-5EB4EE090A28} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {264F49CB-3415-488D-B8DA-9F6F8BE48331} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
Task: {2E84AC4F-16D2-4F2F-AF13-EF11260452E1} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {2EE58945-C40B-43A8-A167-173E412D9D98} - System32\Tasks\GoogleUpdateTaskMachineCore1d0bf681e553bf8 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\WINDOWS\System32\AutoWorkplace.exe
Task: {3595EBB4-1238-4EA2-933E-200658FBF56C} - System32\Tasks\CLVDLauncher => c:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe [2013-03-12] (CyberLink Corp.)
Task: {37C32B19-9630-4A28-9E5A-8EA8CD06CFA2} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-08-24] (Dropbox, Inc.)
Task: {438F072B-AAE9-40AF-AC57-02A64C04DE3D} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {46064571-564C-4D46-9842-A167DDF1D942} - System32\Tasks\GoogleUpdateTaskMachineCore1d08f601e825b6 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {4AE24562-AD31-4B90-9AE5-ED4C785E4F09} - System32\Tasks\G2MUpdateTask-S-1-5-21-2671885098-678752524-1400920573-1001 => C:\Users\AIRWORX 2\AppData\Local\Citrix\GoToMeeting\5530\g2mupdate.exe [2016-09-03] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {4F1C7B6F-3451-443B-A7EA-F05EF590C939} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {4FD0925E-6E79-4BC0-A382-3D5CCA5C36B1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2017-05-25] (HP Inc.)
Task: {5DB34D0B-4B82-47F6-B06D-2D195446A83A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {70DBC4DD-6DE6-48DB-A77B-732338AD113D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {78F037B8-98B7-4FB4-8208-86D30D156F8F} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {7A8C073B-9921-4385-A061-FF8B5410A453} - System32\Tasks\{39393239-4118-43A9-9EF4-579F68CFC882} => pcalua.exe -a C:\PROGRA~2\SAAZOD\Uninstall\uninstall.exe -c "/U:C:\PROGRA~2\SAAZOD\Uninstall\uninstall.xml"
Task: {8258540A-E194-4B1C-A446-B100E53A7B7B} - System32\Tasks\Adobe Uninstaller => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
Task: {8A6CE6D2-BAFF-47BD-B636-5632FA76D78E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2017-04-07] (HP Inc.)
Task: {8EE60D19-E484-4EC5-87B6-BEB1AE19CF50} - System32\Tasks\GoogleUpdateTaskMachineUA1cf8dc0ce6bb10d => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {8F630B83-069D-434E-B4C4-59AD3C10A507} - System32\Tasks\[email protected] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
Task: {A06C2463-6FDA-437F-BFAC-91F03898B57C} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {A7CF62C0-17A6-42AB-A10F-9A6C446B7B33} - System32\Tasks\G2MUploadTask-S-1-5-21-2671885098-678752524-1400920573-1001 => C:\Users\AIRWORX 2\AppData\Local\Citrix\GoToMeeting\5530\g2mupload.exe [2016-09-03] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {AB0E99A1-1E16-4305-B60A-C2AFCE260919} - System32\Tasks\HPCeeScheduleForAIRWORX 2 => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard)
Task: {ACE8B2E6-FDA5-4314-A2D5-4B96CC439AEB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2017-04-07] (HP Inc.)
Task: {AF0278DE-91EC-48AE-BDAF-F7FE516AF428} - System32\Tasks\{32B26120-173E-4516-BA92-CE080FB3608E} => pcalua.exe -a F:\Display_menu.exe -d F:\
Task: {B9FA1D84-F00D-445B-8400-F7C7E90DD53E} - System32\Tasks\RGP Backup => C:\Program Files (x86)\Rock Gym Pro\Backup.exe [2017-06-04] ()
Task: {BB6E2A61-B56E-4672-A28A-0F8C30187EBA} - System32\Tasks\CLMLSvc_P2G8 => c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2013-03-12] (CyberLink)
Task: {CE775C70-F807-4E1F-891C-712F82A9408E} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {D7E60E76-AB93-449D-99DB-17494EB2C958} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {E622463C-A190-4A30-A528-A6EF1AACE5FC} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-08-24] (Dropbox, Inc.)
Task: {E6505B7C-6B08-451F-A300-AF1087B421C6} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-2671885098-678752524-1400920573-1001.job => C:\Users\AIRWORX 2\AppData\Local\GoToMeeting\7297\g2mupdate.exe
Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-2671885098-678752524-1400920573-1001.job => C:\Users\AIRWORX 2\AppData\Local\GoToMeeting\7297\g2mupload.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d040ece2e11a19.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d08f601e825b6.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\HPCeeScheduleForAIRWORX 2.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
ShortcutWithArgument: C:\Users\AIRWORX 2\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9501e18d7c2ab92e\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 2"
ShortcutWithArgument: C:\Users\AIRWORX 2\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 1"
ShortcutWithArgument: C:\Users\AIRWORX 2\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\48499db33039e897\Brandi - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 4"
==================== Loaded Modules (Whitelisted) ==============
2016-07-16 04:42 - 2016-07-16 04:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2017-06-13 11:18 - 2017-06-03 03:01 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-10-03 00:38 - 2016-09-06 21:56 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-03-15 05:38 - 2017-03-03 23:31 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2017-03-15 05:38 - 2017-03-03 23:12 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-03-15 05:38 - 2017-03-03 23:05 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-03-15 05:38 - 2017-03-03 23:05 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-06-13 11:18 - 2017-06-03 01:47 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2017-06-13 11:18 - 2017-06-03 01:47 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-06-13 11:18 - 2017-06-03 01:51 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"
iver"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\cornell.edu -> hxxps://www.kronos.cornell.edu
IE trusted site: HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\secureserver.net -> hxxps://login.secureserver.net
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 06:25 - 2013-08-22 06:25 - 00000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\AIRWORX 2\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 68.105.28.11 - 68.105.29.11
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is disabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
MSCONFIG\Services: CDPUserSvc_492c3 => 2
MSCONFIG\Services: CDPUserSvc_5d4d8 => 2
MSCONFIG\Services: GoToAssist => 3
MSCONFIG\Services: lfsvc => 3
MSCONFIG\Services: MessagingService_492c3 => 3
MSCONFIG\Services: MessagingService_5d4d8 => 3
MSCONFIG\Services: OneSyncSvc_492c3 => 2
MSCONFIG\Services: OneSyncSvc_5d4d8 => 2
HKLM\...\StartupApproved\StartupFolder: => "BackupRemind.lnk"
HKLM\...\StartupApproved\StartupFolder: => "Cox Cloud Drive.lnk"
HKLM\...\StartupApproved\Run: => "SysTrayApp"
HKLM\...\StartupApproved\Run: => "BeatsOSDApp"
HKLM\...\StartupApproved\Run: => "Lathem.USBTM.UI"
HKLM\...\StartupApproved\Run: => "Seagate Scheduler2 Service"
HKLM\...\StartupApproved\Run32: => "StartCCC"
HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKLM\...\StartupApproved\Run32: => "ISUSPM"
HKLM\...\StartupApproved\Run32: => "PPort14reminder"
HKLM\...\StartupApproved\Run32: => "IndexSearch"
HKLM\...\StartupApproved\Run32: => "PaperPort PTD"
HKLM\...\StartupApproved\Run32: => "PDFCreHook"
HKLM\...\StartupApproved\Run32: => "PDFProHook"
HKLM\...\StartupApproved\Run32: => "PDF7 Registry Controller"
HKLM\...\StartupApproved\Run32: => "EEventManager"
HKLM\...\StartupApproved\Run32: => "Adobe Photo Downloader"
HKLM\...\StartupApproved\Run32: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "DiscWizardMonitor.exe"
HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud"
HKLM\...\StartupApproved\Run32: => "Vault Explorer Cache Watcher"
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\StartupApproved\StartupFolder: => "OneNote 2010 Screen Clipper and Launcher.lnk"
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\StartupApproved\StartupFolder: => "Verizon Wireless Software Utility Application for Android – Samsung.lnk"
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\StartupApproved\Run: => "SmartSwitchPDLR.exe"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{C46B9912-D1C2-4E45-9AD8-D8BCB129F043}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{DC1F597B-7AF8-4E42-800A-A1D016805D6B}] => (Allow) C:\Users\AIRWORX 2\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{DF41382D-7C4B-452D-95F1-8086F0DAC591}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{40460E99-D235-4736-A77C-629162D4C564}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe
FirewallRules: [{68E02351-34A3-4E1C-B584-1408332366E9}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe
FirewallRules: [{94B15C71-D0F4-4920-92AA-CFB64A40F500}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe
FirewallRules: [{506FBEB2-08E3-4748-AA99-035C39352EC2}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe
FirewallRules: [{D0AF0B79-A58E-4981-AE18-493996ED77D1}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe
FirewallRules: [{B5519C34-E5E2-4002-BC5C-43764B8FE077}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe
FirewallRules: [{0AF54D7F-6D16-45D1-B795-D5E09C279A94}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe
FirewallRules: [{7683262D-2F71-4302-A78C-09531E02C619}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe
FirewallRules: [{20796F92-7CAA-439B-BDBC-424E5856A4B8}] => (Allow) LPort=1900
FirewallRules: [{2BB9BD43-1798-4BA0-ADC5-65DED0EA0609}] => (Allow) LPort=2869
FirewallRules: [{0FE1E20F-FA13-4A99-9282-E018DFB376A7}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{929B0F01-026B-4E9C-9C9F-034A6A3DF20E}] => (Allow) LPort=3306
FirewallRules: [{4C55D636-1062-42F2-83E0-88F52AC05F10}] => (Allow) C:\Users\Administrator\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{35652560-AE8B-4178-B991-B3BAC7F69C8A}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
FirewallRules: [{9B100BC8-9E14-4408-884D-571C33BF4424}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
FirewallRules: [{3F3018C7-7AB1-4BB7-8451-CF1337B3E27F}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe
FirewallRules: [{04B1FBED-801F-4783-AC19-44912DC3B82A}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
FirewallRules: [{AB24DE43-BA75-4A2C-BE62-50EC8A6E71CA}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe
FirewallRules: [{A8F82A93-7DDC-4A37-B9F0-2246585ABAE8}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe
FirewallRules: [{631897A6-FD9C-4FDB-A1EF-BE752E9D1AEF}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{37B1CC24-7FE3-4E38-A0BB-779278DD3824}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{B542B111-518D-4929-A9BE-87750DC19803}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{1E1FA9F8-B6FA-4E19-BCC7-036EC3CF76E7}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{E54DD560-4B3D-4D46-BCCE-AA81477764BF}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{8665DBEC-6D37-4A9B-9101-D2CAC7461032}] => (Allow) %LocalAppData%\HPConnectedMusic\Application\spotify_helper.exe
FirewallRules: [{3C4B403A-085B-4A2C-8D80-C00DBEC9724B}] => (Allow) %LocalAppData%\HPConnectedMusic\Application\spotify_helper.exe
FirewallRules: [{83B9CC3B-B79F-4C88-8D43-C8F3688F8D6C}] => (Allow) %LocalAppData%\HPConnectedMusic\Application\HPConnectedMusic.exe
FirewallRules: [{6A3DD6EE-BED5-4AD1-914E-140E9866E1F6}] => (Allow) %LocalAppData%\HPConnectedMusic\Application\HPConnectedMusic.exe
FirewallRules: [{82544E8E-2A02-40DA-8F04-ED87E9486D8B}] => (Allow) C:\Program Files (x86)\HPConnectedMusic\HPConnectedMusic.exe
FirewallRules: [{E4860DBD-DEE5-4EA8-A8C1-AD6BD8BEAD6E}] => (Allow) C:\Program Files (x86)\HPConnectedMusic\HPConnectedMusic.exe
FirewallRules: [{D28E8D57-6792-4E93-B3C2-F4A80976A2B9}] => (Allow) C:\Program Files (x86)\Brother\Brmfl10f\FAXRX.exe
FirewallRules: [{59577291-5221-4BDA-BA72-221D3ABCEF98}] => (Allow) C:\Program Files (x86)\Brother\Brmfl10f\FAXRX.exe
FirewallRules: [{A318E63F-3B16-4801-9A52-8B4EF2D8CBF2}] => (Allow) LPort=54925
FirewallRules: [{6607E655-6A17-4AEB-9CF3-D2F10926B44A}] => (Allow) C:\Users\AIRWORX 2\AppData\Local\Microsoft\OneDrive\OneDrive.exe
FirewallRules: [{F85989A3-85BC-4C4B-82F9-1C84A5776FDE}] => (Allow) F:\PayClockInstaller.exe
FirewallRules: [{6A610D4B-D3E3-4498-AFD1-0FCB8D9A127F}] => (Allow) F:\PayClockInstaller.exe
FirewallRules: [{461F524A-493F-40ED-95E3-8EE4AB1CB731}] => (Allow) F:\PayClock.msi
FirewallRules: [{3FB4674A-0747-4F9B-AB77-6BA7352B143C}] => (Allow) F:\PayClock.msi
FirewallRules: [{E94B8338-1446-4CB1-A308-71B8E309A6D4}] => (Allow) LPort=9156
FirewallRules: [{1C209DE4-FE08-436D-94BA-E53EE4D90DC0}] => (Allow) LPort=9156
FirewallRules: [{A3C86F44-8286-42C0-A02E-B6338B0F2D39}] => (Allow) LPort=9157
FirewallRules: [{9DE5CCA7-5467-497F-8EB6-CFF0F22D8764}] => (Allow) LPort=9157
FirewallRules: [{29DAB202-4C52-4BA9-BD9B-FBB66BFE4FAF}] => (Allow) LPort=9158
FirewallRules: [{F6DCAE84-2BCF-4B40-9981-5766F41C4BAA}] => (Allow) LPort=9158
FirewallRules: [{C88BD0D7-5FE7-444C-AD90-A5D04A20DE32}] => (Allow) F:\PayClockInstaller.exe
FirewallRules: [{0CCAB027-1E9B-46F0-87B7-5F4E8B60C6FC}] => (Allow) F:\PayClockInstaller.exe
FirewallRules: [{D2A228E4-87A0-41F2-8492-E05EDA4722EF}] => (Allow) F:\PayClock.msi
FirewallRules: [{9CE3BD30-DCEF-46F5-A6ED-18A72FDBA743}] => (Allow) F:\PayClock.msi
FirewallRules: [{C2CED3BA-1EF3-4A52-B85B-6A2C09B4735A}] => (Allow) LPort=9156
FirewallRules: [{5437C8FE-5F22-46EC-B6B2-0B5AB952D957}] => (Allow) LPort=9156
FirewallRules: [{8A44508B-F996-4654-837E-DAB5F21218A1}] => (Allow) LPort=9157
FirewallRules: [{2956BC6B-6623-4958-A14F-5E00BC677ABF}] => (Allow) LPort=9157
FirewallRules: [{543FD946-F6B3-40D9-9BBF-ACCF81C0236F}] => (Allow) LPort=9158
FirewallRules: [{6E8725CD-1AF4-456C-95BE-7433E0345F7E}] => (Allow) LPort=9158
FirewallRules: [{C3205BCA-4BA3-41FC-AA89-9CB74ED73D31}] => (Allow) LPort=3306
FirewallRules: [TCP Query User{52A14CC1-81FA-4EE6-B8DE-2CACF81CFFC6}C:\program files (x86)\internet explorer\iexplore.exe] => (Allow) C:\program files (x86)\internet explorer\iexplore.exe
FirewallRules: [UDP Query User{8E8846C5-505D-4C71-8E8C-191B20CE8CC1}C:\program files (x86)\internet explorer\iexplore.exe] => (Allow) C:\program files (x86)\internet explorer\iexplore.exe
FirewallRules: [{50984AD4-0142-46A0-A1BA-A911B0EC88FD}] => (Block) C:\program files (x86)\internet explorer\iexplore.exe
FirewallRules: [{6C601AEC-C783-4F4C-9EE1-47CAA6B853EF}] => (Block) C:\program files (x86)\internet explorer\iexplore.exe
FirewallRules: [{F86D4BC7-A6B7-4C8C-A170-9513779233C6}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe
FirewallRules: [TCP Query User{A1B22892-C13F-42B1-8B86-AEBC5293F339}C:\program files (x86)\escaperoom software\escaperoom.exe] => (Allow) C:\program files (x86)\escaperoom software\escaperoom.exe
FirewallRules: [UDP Query User{13D4495E-1B20-4E5F-BB5C-A466C9AF6EB6}C:\program files (x86)\escaperoom software\escaperoom.exe] => (Allow) C:\program files (x86)\escaperoom software\escaperoom.exe
FirewallRules: [{2042F16E-3442-4D60-B82C-3EBE56757C77}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{57CE1D01-0DD4-4864-9D49-CCD8D0024DB5}] => (Allow) %systemroot%\system32\alg.exe
FirewallRules: [{76B00221-8ED9-44B4-A9A8-180AA9701989}] => (Allow) %systemroot%\system32\alg.exe
FirewallRules: [{97357220-4D2F-4FFD-8DC2-EE30F08F979A}] => (Allow) %systemroot%\system32\alg.exe
FirewallRules: [{1A86BD2B-5F5A-44F1-90F4-EF0D20C7A9BC}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
==================== Restore Points =========================
08-07-2017 21:45:10 Scheduled Checkpoint
==================== Faulty Device Manager Devices =============
Name: Qualcomm Atheros AR9485 802.11b|g|n WiFi Adapter
Description: Qualcomm Atheros AR9485 802.11b|g|n WiFi Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Qualcomm Atheros Communications Inc.
Service: athr
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (07/11/2017 04:54:40 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: wmiprvse.exe, version: 10.0.14393.0, time stamp: 0x57899ab2
Faulting module name: NetEventPacketCapture.dll, version: 10.0.14393.953, time stamp: 0x58ba5f01
Exception code: 0xc0000005
Fault offset: 0x00000000000160cc
Faulting process id: 0x7cc
Faulting application start time: 0x01d2fa3c57479406
Faulting application path: C:\WINDOWS\system32\wbem\wmiprvse.exe
Faulting module path: C:\WINDOWS\system32\wbem\NetEventPacketCapture.dll
Report Id: a1a90289-6fa7-421d-af47-bbee5fa733d4
Faulting package full name:
Faulting package-relative application ID:
Error: (07/11/2017 04:54:10 AM) (Source: Microsoft Security Client) (EventID: 5000) (User: )
Description: Event-ID 5000
Error: (07/11/2017 04:54:10 AM) (Source: Microsoft Security Client) (EventID: 5000) (User: )
Description: Event-ID 5000
Error: (07/11/2017 04:53:57 AM) (Source: Microsoft Security Client) (EventID: 5000) (User: )
Description: Event-ID 5000
Error: (07/11/2017 04:53:57 AM) (Source: Microsoft Security Client) (EventID: 5000) (User: )
Description: Event-ID 5000
Error: (07/11/2017 02:57:28 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: AIRWORX2-PC)
Description: Activation of app Microsoft.MicrosoftEdge_38.14393.1066.0_neutral__8wekyb3d8bbwe:MicrosoftEdge.AppXxat4m5y1bf9ghax409y1vwyatpqea4s8.mca failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (07/10/2017 01:03:02 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Setup.exe Files (x86)\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Setup.exe" -Embedding; Description = Configured Microsoft Office Professional 2010; Error = 0x8007043c).
Error: (07/10/2017 10:15:58 AM) (Source: PerfNet) (EventID: 2004) (User: )
Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.
Error: (07/10/2017 10:09:58 AM) (Source: PerfNet) (EventID: 2004) (User: )
Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.
Error: (07/10/2017 10:09:58 AM) (Source: MSDTC Client 2) (EventID: 4104) (User: )
Description: Failed trying to get the state of the cluster node: .The error code returned: 0x8007085A
System errors:
=============
Error: (07/11/2017 05:32:27 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Cryptographic Services service failed to start due to the following error:
The account specified for this service is different from the account specified for other services running in the same process.
Error: (07/11/2017 05:32:27 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Cryptographic Services service failed to start due to the following error:
The account specified for this service is different from the account specified for other services running in the same process.
Error: (07/11/2017 05:32:24 AM) (Source: DCOM) (EventID: 10005) (User: AIRWORX2-PC)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
Error: (07/11/2017 05:32:24 AM) (Source: DCOM) (EventID: 10005) (User: AIRWORX2-PC)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
Error: (07/11/2017 05:32:24 AM) (Source: DCOM) (EventID: 10005) (User: AIRWORX2-PC)
Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server:
{DD522ACC-F821-461A-A407-50B198B896DC}
Error: (07/11/2017 05:31:32 AM) (Source: DCOM) (EventID: 10005) (User: AIRWORX2-PC)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
Error: (07/11/2017 05:31:32 AM) (Source: DCOM) (EventID: 10005) (User: AIRWORX2-PC)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
Error: (07/11/2017 05:31:32 AM) (Source: DCOM) (EventID: 10005) (User: AIRWORX2-PC)
Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server:
{DD522ACC-F821-461A-A407-50B198B896DC}
Error: (07/11/2017 05:31:22 AM) (Source: DCOM) (EventID: 10005) (User: AIRWORX2-PC)
Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server:
{DD522ACC-F821-461A-A407-50B198B896DC}
Error: (07/11/2017 05:30:53 AM) (Source: DCOM) (EventID: 10005) (User: AIRWORX2-PC)
Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server:
{DD522ACC-F821-461A-A407-50B198B896DC}
CodeIntegrity:
===================================
Date: 2017-07-10 06:49:28.402
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-07-10 06:49:28.381
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-07-10 06:49:27.490
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-07-10 06:49:27.468
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-07-10 06:49:22.444
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-07-10 06:49:22.424
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-07-10 06:49:17.402
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-07-10 06:49:17.382
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-07-10 06:49:12.360
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-07-10 06:49:12.340
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
Processor: AMD A8-6500 APU with Radeon HD Graphics
Percentage of memory in use: 32%
Total physical RAM: 7365.48 MB
Available physical RAM: 4966.54 MB
Total Virtual: 7765.48 MB
Available Virtual: 6078.58 MB
==================== Drives ================================
Drive c: (Windows) (Fixed) (Total:1842.47 GB) (Free:1674.27 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (Recovery Image) (Fixed) (Total:18.63 GB) (Free:2.32 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive e: (HP_TOOLS) (Removable) (Total:1.91 GB) (Free:1.76 GB) FAT32
Drive g: (TOSHIBA) (Removable) (Total:14.89 GB) (Free:6.99 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 1863 GB) (Disk ID: 8834CD72)
Partition: GPT.
========================================================
Disk: 1 (Size: 1.9 GB) (Disk ID: 500A0DFF)
No partition Table on disk 1.
========================================================
Disk: 2 (MBR Code: Windows XP) (Size: 14.9 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=14.9 GB) - (Type=0C)
==================== End of Addition.txt ============================
Please advise any recommendations you have. I also have eset logs I can provide, as well as a few other tools I found on this site, and have run.
I created the AIRWORX-2 and AIRWORXAZ users, and I suppose obviously admin, the others have been created by whomever.
Also, the [email protected] email is being used by someone else, that's associated with this pc login. I changed pw, but he receives email, which I also receive, since I'd set it up originally.
Hopeful,
Brandi Copas )
Edited by BrandiCopas, 11 July 2017 - 08:30 AM.