Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Windapp- Malware/Spyware


  • This topic is locked This topic is locked
23 replies to this topic

#1 Henniee

Henniee

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:11:38 PM

Posted 27 August 2015 - 03:42 AM

My Windows 10 Machine seem to have picked up WINDAPP, 

 

One of the characteristics of Windapp is it Disables you Anti Virus at Admin level

 

When you go to uninstall it, it reinstall more Spyware and reinstall itself, 

 

I have use Norton Power Erase to remove some of the files, but under the Application Tab you can still see Windapp

 

 



BC AdBot (Login to Remove)

 


#2 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,078 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:12:38 AM

Posted 27 August 2015 - 12:06 PM

Greetings and :welcome: to BleepingComputer,
My name is xXToffeeXx, but feel free to call me Toffee if it is easier for you. I will be helping you with your malware problems.
 
A few points to cover before we start:

  • Do not run any tools without being instructed to as this makes my job much harder in trying to figure out what you have done.
  • Make sure to read my instructions fully before attempting a step.
  • If you have problems or questions with any of the steps, feel free to ask me. I will be happy to answer any questions you have.
  • Please follow the topic by clicking on the "Follow this topic" button, and make sure a tick is in the "receive notifications" and is set to "Instantly". Any replies should be made in this topic by clicking the "Reply to this topic" button.
  • Important information in my posts will often be in bold, make sure to take note of these.
  • I will attempt to reply as soon as possible, and normally within 24 hours of your reply. If this is not possible or I have a delay then I will let you know.
  • I will bump a topic after 3 days of no activity, and then will give you another 2 days to reply before a topic is closed. If you need more time than this please let me know.
  • Let's get going now :thumbup2:

==========================
 
Hi Henniee,
 
Please download Farbar Recovery Scan Tool and save it to your Desktop.
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system, download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Right-click FRST then click "Run as administrator" (XP users: click run after receipt of Windows Security Warning - Open File).
  • When the tool opens, click Yes to disclaimer.
  • Press the Scan button.
  • When finished, it will produce a log called FRST.txt in the same directory the tool was run from.
  • Please copy and paste the log in your next reply.

Note 2: The first time the tool is run it generates another log (Addition.txt - also located in the same directory the tool was run from). Please also paste that, along with the FRST.txt into your next reply.
 
--------------
 
To recap, in your next reply I would like to see the following. Make sure to copy & paste them unless I ask otherwise:

  • FRST.txt
  • Addition.txt

xXToffeeXx~


~If I am helping you and you have not had a reply from me in two days, please send me a PM~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


#3 Henniee

Henniee
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:11:38 PM

Posted 27 August 2015 - 04:14 PM

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:27-08-2015

Ran by User (administrator) on USER-PC (27-08-2015 22:10:00)

Running from C:\Security

Loaded Profiles: User (Available Profiles: User & DefaultAppPool)

Platform: Windows 10 Pro (X64) Language: English (United States)

Internet Explorer Version 11 (Default browser: Chrome)

Boot Mode: Normal

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe

(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe

(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidMonitorSvc.exe

(Broadcom Corporation.) C:\WINDOWS\System32\BtwRSupportService.exe

(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe

(Microsoft Corporation) C:\WINDOWS\System32\mqsvc.exe

(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

(O2Micro International) C:\WINDOWS\System32\drivers\o2flash.exe

(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe

(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe

(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe

(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe

(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe

(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe

(Microsoft Corporation) C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe

(Microsoft Corporation) C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe

(Intel Corporation) C:\WINDOWS\System32\igfxtray.exe

(Intel Corporation) C:\WINDOWS\System32\hkcmd.exe

(Intel Corporation) C:\WINDOWS\System32\igfxpers.exe

(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe

(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe

(Microsoft Corporation) C:\Users\User\AppData\Local\Microsoft\OneDrive\OneDrive.exe

(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe

(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE

(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe

() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.820.12440.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe

(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6120.42011.0_x64__8wekyb3d8bbwe\HxMail.exe

(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6120.42011.0_x64__8wekyb3d8bbwe\HxTsr.exe

(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXE

(Microsoft Corporation) C:\WINDOWS\System32\SppExtComObj.Exe

(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe

(Microsoft Corporation) C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe

(Microsoft Corporation) C:\WINDOWS\System32\browser_broker.exe

(Microsoft Corporation) C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe

(Microsoft Corporation) C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe

 

==================== Registry (Whitelisted) ===========================

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

 

HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [727896 2014-03-13] (Alps Electric Co., Ltd.)

HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170280 2015-07-11] (Apple Inc.)

HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-25] (IDT, Inc.)

Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)

HKU\S-1-5-19\...\Run: [OneDriveSetup] => C:\Windows\SysWOW64\OneDriveSetup.exe [7805120 2015-07-10] (Microsoft Corporation)

HKU\S-1-5-20\...\Run: [OneDriveSetup] => C:\Windows\SysWOW64\OneDriveSetup.exe [7805120 2015-07-10] (Microsoft Corporation)

HKU\S-1-5-21-1394956801-2065374029-3886242179-1000\...\Run: [OneDrive] => C:\Users\User\AppData\Local\Microsoft\OneDrive\OneDrive.exe [404064 2015-08-24] (Microsoft Corporation)

GroupPolicyScripts: Group Policy detected <======= ATTENTION

GroupPolicyScripts\User: Group Policy detected <======= ATTENTION

 

==================== Internet (Whitelisted) ====================

 

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

 

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION

HKU\S-1-5-21-1394956801-2065374029-3886242179-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION

HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings: [ProxySettingsPerUser] 1 <======= ATTENTION (Policy restriction on ProxySettings)

ProxyEnable: [HKLM] => Proxy is enabled.

ProxyEnable: [HKLM-x32] => Proxy is enabled.

ProxyServer: [HKLM] => http=127.0.0.1:8877;https=127.0.0.1:8877

ProxyServer: [HKLM-x32] => http=127.0.0.1:8877;https=127.0.0.1:8877

HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm

HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm

HKU\S-1-5-21-1394956801-2065374029-3886242179-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/

HKU\S-1-5-21-1394956801-2065374029-3886242179-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/en-gb/?ocid=iehp

SearchScopes: HKU\S-1-5-21-1394956801-2065374029-3886242179-1000 -> {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3323129&octid=EB_ORIGINAL_CTID&ISID=M425BB975-22C4-4C83-A233-FD46A5CCFE64&SearchSource=58&CUI=&UM=8&UP=SP55390217-8BC1-4703-9A4A-6630B64D443E&D=082015&q={searchTerms}&SSPV=

BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-07-14] (Microsoft Corporation)

BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-07-14] (Microsoft Corporation)

BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-07-14] (Microsoft Corporation)

BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-07-14] (Microsoft Corporation)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

Tcpip\..\Interfaces\{bcce3918-b299-42e3-b3b1-7417ac10c904}: [DhcpNameServer] 192.168.0.1

FireFox:

========

FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] ()

FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-04-22] (Microsoft Corporation)

FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)

FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [No File]

FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [No File]

FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-23] (Google Inc.)

FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-23] (Google Inc.)

FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-04-22] (Microsoft Corporation)

 

Chrome:

=======

CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default

CHR Extension: (Google Slides) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-07-23]

CHR Extension: (Google Docs) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-07-23]

CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-07-23]

CHR Extension: (Rapport) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjllphbppobebmjpjcijfbakobcheof [2015-08-08]

CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-07-23]

CHR Extension: (Google Search) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-07-23]

CHR Extension: (SmartSaver+ 3) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekpibplnnkfdcafdpoekhoffegcajene [2015-08-26]

CHR Extension: (Google Play Music) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2015-07-23]

CHR Extension: (Google Sheets) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-07-23]

CHR Extension: (Chrome Hotword Shared Module) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-08-08]

CHR Extension: (Chrome Web Store Payments) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-28]

CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-23]

CHR HKU\S-1-5-21-1394956801-2065374029-3886242179-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bbjllphbppobebmjpjcijfbakobcheof] - https://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ApHidMonitorService; C:\Program Files\DellTPad\HidMonitorSvc.exe [87384 2014-03-27] (Alps Electric Co., Ltd.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)

R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2255064 2013-10-28] (Broadcom Corporation.)

S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [326144 2015-07-10] (Microsoft Corporation)

S3 CDPSvc; C:\Windows\System32\CDPSvc.dll [134144 2015-07-10] (Microsoft Corporation)

R2 CoreMessagingRegistrar; C:\Windows\system32\coremessaging.dll [808856 2015-08-10] (Microsoft Corporation)

R2 CoreMessagingRegistrar; C:\Windows\SysWOW64\coremessaging.dll [510976 2015-08-10] (Microsoft Corporation)

S3 diagnosticshub.standardcollector.service; C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [27136 2015-07-10] (Microsoft Corporation)

S3 DmEnrollmentSvc; C:\Windows\system32\Windows.Internal.Management.dll [267776 2015-07-10] (Microsoft Corporation)

S3 DmEnrollmentSvc; C:\Windows\SysWOW64\Windows.Internal.Management.dll [193024 2015-07-10] (Microsoft Corporation)

S3 embeddedmode; C:\Windows\System32\embeddedmodesvc.dll [87040 2015-07-10] (Microsoft Corporation)

S3 EntAppSvc; C:\Windows\system32\EnterpriseAppMgmtSvc.dll [275456 2015-07-10] (Microsoft Corporation)

S3 icssvc; C:\Windows\System32\tetheringservice.dll [148992 2015-08-11] (Microsoft Corporation)

R3 lfsvc; C:\Windows\SysWOW64\lfsvc.dll [22528 2015-07-10] (Microsoft Corporation)

R3 LicenseManager; C:\Windows\system32\LicenseManagerSvc.dll [21504 2015-07-10] (Microsoft Corporation)

S2 MapsBroker; C:\Windows\System32\moshost.dll [62464 2015-07-10] (Microsoft Corporation)

R2 MSMQ; C:\Windows\system32\mqsvc.exe [26112 2015-08-10] (Microsoft Corporation)

S2 OneSyncSvc; C:\Windows\System32\APHostService.dll [296960 2015-07-10] (Microsoft Corporation)

R2 OneSyncSvc_Session1; C:\WINDOWS\system32\svchost.exe [39856 2015-07-10] (Microsoft Corporation)

R2 OneSyncSvc_Session1; C:\WINDOWS\SysWOW64\svchost.exe [35176 2015-07-10] (Microsoft Corporation)

S3 PimIndexMaintenanceSvc; C:\Windows\System32\PimIndexMaintenance.dll [289280 2015-07-10] (Microsoft Corporation)

R3 PimIndexMaintenanceSvc_Session1; C:\WINDOWS\system32\svchost.exe [39856 2015-07-10] (Microsoft Corporation)

R3 PimIndexMaintenanceSvc_Session1; C:\WINDOWS\SysWOW64\svchost.exe [35176 2015-07-10] (Microsoft Corporation)

S3 RetailDemo; C:\Windows\system32\RDXService.dll [996352 2015-08-11] (Microsoft Corporation)

S3 SensorDataService; C:\Windows\System32\SensorDataService.exe [1031680 2015-08-10] (Microsoft Corporation)

R3 StateRepository; C:\Windows\system32\windows.staterepository.dll [2674176 2015-07-10] (Microsoft Corporation)

R3 StateRepository; C:\Windows\SysWOW64\windows.staterepository.dll [2049024 2015-07-10] (Microsoft Corporation)

S3 UnistoreSvc; C:\Windows\System32\unistore.dll [1203200 2015-08-10] (Microsoft Corporation)

S3 UnistoreSvc; C:\Windows\SysWOW64\unistore.dll [925696 2015-08-10] (Microsoft Corporation)

R3 UnistoreSvc_Session1; C:\WINDOWS\System32\svchost.exe [39856 2015-07-10] (Microsoft Corporation)

R3 UnistoreSvc_Session1; C:\WINDOWS\SysWOW64\svchost.exe [35176 2015-07-10] (Microsoft Corporation)

S3 UserDataSvc; C:\Windows\System32\userdataservice.dll [1420288 2015-07-30] (Microsoft Corporation)

R3 UserDataSvc_Session1; C:\WINDOWS\system32\svchost.exe [39856 2015-07-10] (Microsoft Corporation)

R3 UserDataSvc_Session1; C:\WINDOWS\SysWOW64\svchost.exe [35176 2015-07-10] (Microsoft Corporation)

S3 vmicvmsession; C:\Windows\System32\ICSvc.dll [506880 2015-07-10] (Microsoft Corporation)

S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [84480 2015-08-10] (Microsoft Corporation)

R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [578560 2015-08-10] (Microsoft Corporation)

S3 WalletService; C:\Windows\system32\WalletService.dll [504320 2015-07-10] (Microsoft Corporation)

R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)

R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)

S3 XblAuthManager; C:\Windows\System32\XblAuthManager.dll [918016 2015-07-10] (Microsoft Corporation)

S3 XblGameSave; C:\Windows\System32\XblGameSave.dll [1149440 2015-07-10] (Microsoft Corporation)

S3 XboxNetApiSvc; C:\Windows\system32\XboxNetApiSvc.dll [1019392 2015-07-10] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-10-28] (Broadcom Corporation.)

R3 CompositeBus; C:\Windows\System32\DriverStore\FileRepository\compositebus.inf_amd64_98334ba6e76853ba\CompositeBus.sys [39936 2015-07-10] (Microsoft Corporation)

S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3436896 2015-07-10] (QLogic Corporation)

R1 FileCrypt; C:\Windows\System32\drivers\filecrypt.sys [83968 2015-07-10] (Microsoft Corporation)

S3 genericusbfn; C:\Windows\System32\drivers\genericusbfn.sys [20992 2015-07-10] (Microsoft Corporation)

R1 GpuEnergyDrv; C:\Windows\System32\drivers\gpuenergydrv.sys [8192 2015-07-10] (Microsoft Corporation)

S3 ibbus; C:\Windows\System32\drivers\ibbus.sys [424800 2015-07-10] (Mellanox)

S3 IoQos; C:\Windows\System32\drivers\ioqos.sys [26624 2015-07-10] (Microsoft Corporation)

S0 LSI_SAS3i; C:\Windows\System32\drivers\lsi_sas3i.sys [99168 2015-07-10] (Avago Technologies)

S3 mlx4_bus; C:\Windows\System32\drivers\mlx4_bus.sys [705376 2015-07-10] (Mellanox)

R3 MQAC; C:\Windows\System32\drivers\mqac.sys [175104 2015-08-10] (Microsoft Corporation)

S3 ndfltr; C:\Windows\System32\drivers\ndfltr.sys [76128 2015-07-10] (Mellanox)

R3 NETwNe64; C:\Windows\System32\drivers\NETwew01.sys [3354384 2015-07-10] (Intel Corporation)

R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33448 2015-03-20] (Synaptics Incorporated)

R2 storqosflt; C:\Windows\System32\drivers\storqosflt.sys [61952 2015-07-10] (Microsoft Corporation)

R3 ST_Accel; C:\Windows\system32\DRIVERS\ST_Accel.sys [73928 2013-11-21] (STMicroelectronics)

R3 swenum; C:\Windows\System32\DriverStore\FileRepository\swenum.inf_amd64_2a699e44676b7781\swenum.sys [17760 2015-07-10] (Microsoft Corporation)

S3 UcmCx0101; C:\Windows\System32\Drivers\UcmCx.sys [61952 2015-07-10] (Microsoft Corporation)

S3 UcmUcsi; C:\Windows\System32\drivers\UcmUcsi.sys [46080 2015-08-10] (Microsoft Corporation)

S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()

R0 WindowsTrustedRT; C:\Windows\System32\drivers\WindowsTrustedRT.sys [106520 2015-07-10] (Microsoft Corporation)

R0 WindowsTrustedRTProxy; C:\Windows\System32\drivers\WindowsTrustedRTProxy.sys [17944 2015-07-10] (Microsoft Corporation)

S3 WinMad; C:\Windows\System32\drivers\winmad.sys [26976 2015-07-10] (Mellanox)

S3 WinVerbs; C:\Windows\System32\drivers\winverbs.sys [59232 2015-07-10] (Mellanox)

S3 xboxgip; C:\Windows\System32\drivers\xboxgip.sys [222720 2015-07-10] (Microsoft Corporation)

S3 xinputhid; C:\Windows\System32\drivers\xinputhid.sys [25600 2015-07-10] (Microsoft Corporation)

U3 idsvc; no ImagePath

S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]

U3 wpcsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

==================== One Month Created files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2015-08-27 22:09 - 2015-08-27 22:10 - 00000000 ____D C:\Security

2015-08-27 22:09 - 2015-08-27 22:10 - 00000000 ____D C:\FRST

2015-08-27 22:08 - 2015-08-27 22:08 - 02186752 _____ (Farbar) C:\Users\User\Downloads\FRST64.exe

2015-08-27 22:06 - 2015-08-27 22:06 - 00016148 _____ C:\WINDOWS\system32\USER-PC_User_HistoryPrediction.bin

2015-08-27 08:00 - 2015-08-27 08:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype

2015-08-27 07:56 - 2015-08-27 07:56 - 00000000 ___HD C:\OneDriveTemp

2015-08-26 23:43 - 2015-08-27 17:43 - 00002444 _____ C:\WINDOWS\Tasks\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-5_user.job

2015-08-26 23:43 - 2015-08-27 17:43 - 00002444 _____ C:\WINDOWS\Tasks\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-5.job

2015-08-26 23:43 - 2015-08-26 23:43 - 00005560 _____ C:\WINDOWS\System32\Tasks\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-5

2015-08-26 23:42 - 2015-08-27 17:42 - 00003136 _____ C:\WINDOWS\Tasks\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-1-7.job

2015-08-26 23:42 - 2015-08-27 00:09 - 00000000 ____D C:\Program Files (x86)\globalUpdate

2015-08-26 23:42 - 2015-08-26 23:56 - 00000004 _____ C:\WINDOWS\SysWOW64\029B560A371F4E00AB32838EBC01B9E7

2015-08-26 23:42 - 2015-08-26 23:43 - 00006256 _____ C:\WINDOWS\System32\Tasks\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-1-7

2015-08-26 23:42 - 2015-08-26 23:42 - 00000000 ____D C:\Users\User\AppData\Local\globalUpdate

2015-08-26 23:42 - 2015-08-26 23:42 - 00000000 ____D C:\Program Files (x86)\e315fa42-f04d-4036-8ae9-d3eb41dc5bf9

2015-08-26 23:14 - 2015-08-27 18:20 - 00004150 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{35D4F0C9-276E-43E9-9B33-72962D950766}

2015-08-26 22:51 - 2015-08-27 02:18 - 00000000 ____D C:\NPE

2015-08-26 22:42 - 2015-08-27 07:59 - 00000000 ____D C:\Users\User\AppData\Local\CrashDumps

2015-08-26 22:35 - 2015-08-26 22:37 - 00000000 ____D C:\Users\User\Desktop\backups

2015-08-26 22:29 - 2015-08-26 22:30 - 02494560 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HousecallLauncher64 (3).exe

2015-08-26 22:18 - 2015-08-26 22:18 - 02494560 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HousecallLauncher64 (2).exe

2015-08-26 22:18 - 2015-08-26 22:18 - 02494560 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HousecallLauncher64 (1).exe

2015-08-26 22:17 - 2015-08-26 22:17 - 00388608 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HijackThis (1).exe

2015-08-26 22:17 - 2015-08-26 22:15 - 00388608 _____ (Trend Micro Inc.) C:\Users\User\Desktop\HijackThis.exe

2015-08-26 22:15 - 2015-08-26 22:15 - 00388608 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HijackThis.exe

2015-08-26 22:11 - 2015-08-26 22:11 - 01618432 _____ C:\Users\User\Downloads\adwcleaner_5.004.exe

2015-08-26 22:06 - 2015-08-27 07:57 - 00000000 ____D C:\Users\User\AppData\Local\NPE

2015-08-26 22:06 - 2015-08-26 22:06 - 03088296 _____ (Symantec Corporation) C:\Users\User\Downloads\NPE.exe

2015-08-26 22:06 - 2015-08-26 22:06 - 00000000 ____D C:\ProgramData\Norton

2015-08-25 20:43 - 2015-08-25 20:43 - 02073112 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HousecallLauncher.exe

2015-08-25 20:43 - 2015-08-25 20:43 - 02073112 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HousecallLauncher (1).exe

2015-08-25 17:01 - 2015-08-25 17:01 - 00000000 _____ C:\Recovery.txt

2015-08-25 09:46 - 2015-08-25 09:46 - 00000000 ____D C:\Recovery

2015-08-25 09:21 - 2015-08-25 09:43 - 00000000 ___HD C:\$Windows.~BT

2015-08-25 08:16 - 2015-08-26 22:36 - 00498461 _____ C:\Users\User\AppData\Local\census.cache

2015-08-25 08:16 - 2015-08-26 22:35 - 00180062 _____ C:\Users\User\AppData\Local\ars.cache

2015-08-25 08:12 - 2015-08-26 22:27 - 00000010 _____ C:\Users\User\AppData\Local\sponge.last.runtime.cache

2015-08-25 08:07 - 2015-08-25 08:07 - 00000036 _____ C:\Users\User\AppData\Local\housecall.guid.cache

2015-08-25 08:06 - 2015-08-25 08:07 - 02494560 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HousecallLauncher64.exe

2015-08-25 00:18 - 2015-08-25 00:18 - 00000000 ____D C:\WINDOWS\system32\appmgmt

2015-08-24 21:32 - 2015-08-26 23:09 - 00000008 __RSH C:\ProgramData\ntuser.pol

2015-08-24 21:16 - 2015-08-24 21:17 - 14243008 _____ (Microsoft Corporation) C:\Users\User\Downloads\mseinstall (1).exe

2015-08-24 21:11 - 2015-08-24 21:11 - 14243008 _____ (Microsoft Corporation) C:\Users\User\Downloads\mseinstall.exe

2015-08-24 21:11 - 2015-08-24 21:11 - 00000000 ____D C:\c8fdacbef381ec7fe3

2015-08-24 17:54 - 2015-08-24 17:54 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf

2015-08-24 17:02 - 2015-08-24 17:02 - 00003302 _____ C:\WINDOWS\System32\Tasks\{72B56432-498F-4EFA-BF3D-DAE4E9CCAA92}

2015-08-24 17:00 - 2015-08-24 17:00 - 00000020 ___SH C:\Users\DefaultAppPool\ntuser.ini

2015-08-24 17:00 - 2015-08-24 17:00 - 00000000 ____D C:\Users\DefaultAppPool

2015-08-24 17:00 - 2015-08-12 13:26 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Local\Trusteer

2015-08-24 17:00 - 2015-08-12 13:19 - 00000000 ___RD C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories

2015-08-24 17:00 - 2015-08-09 16:56 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Local\Microsoft Help

2015-08-24 17:00 - 2015-07-10 12:04 - 00000000 __RSD C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell

2015-08-24 17:00 - 2015-07-10 12:04 - 00000000 ___RD C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools

2015-08-24 17:00 - 2015-07-10 12:04 - 00000000 ___RD C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility

2015-08-24 17:00 - 2015-07-10 12:04 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance

2015-08-24 16:52 - 2015-08-26 23:21 - 00002226 _____ C:\Users\User\Desktop\Google Chrome.lnk

2015-08-24 07:55 - 2015-08-26 23:02 - 00000000 ___HD C:\a

2015-08-24 07:55 - 2015-08-24 17:02 - 00000000 ____D C:\Program Files (x86)\FastInternet

2015-08-24 07:45 - 2015-08-24 07:45 - 00000019 _____ C:\WINDOWS\SysWOW64\19262648.bat

2015-08-20 12:01 - 2015-08-20 12:01 - 00000918 _____ C:\WINDOWS\SysWOW64\${LOGFILE}

2015-08-20 11:54 - 2015-08-20 11:54 - 00004088 _____ C:\WINDOWS\System32\Tasks\LaunchPreSignup

2015-08-20 11:53 - 2015-08-26 23:43 - 00000000 ____D C:\Users\User\AppData\Roaming\Store

2015-08-20 11:53 - 2015-08-24 17:01 - 00000000 ____D C:\Users\User\AppData\Roaming\WTools

2015-08-20 11:53 - 2015-08-24 07:48 - 00000000 ____D C:\ProgramData\Cegeespe

2015-08-20 11:53 - 2015-08-20 11:53 - 00000078 _____ C:\Users\User\AppData\Roaming\WindApp.installation.log

2015-08-20 11:53 - 2015-08-20 11:53 - 00000078 _____ C:\Users\User\AppData\Roaming\Selection Tools.installation.log

2015-08-20 11:52 - 2015-08-20 12:01 - 00000000 ____D C:\Users\User\AppData\Roaming\Nosibay

2015-08-20 11:52 - 2015-08-20 11:52 - 00005709 _____ C:\Users\User\AppData\Roaming\Bubble Dock.installation.log

2015-08-20 11:50 - 2015-08-27 11:00 - 00000290 _____ C:\WINDOWS\Tasks\One System CarePeriod.job

2015-08-20 11:50 - 2015-08-20 11:53 - 00001322 _____ C:\Users\User\AppData\Roaming\Bubble Dock.boostrap.log

2015-08-20 11:50 - 2015-08-20 11:50 - 00002916 _____ C:\WINDOWS\System32\Tasks\One System CarePeriod

2015-08-20 11:50 - 2015-08-20 11:50 - 00000097 _____ C:\Users\User\AppData\Roaming\WindApp.boostrap.log

2015-08-20 11:43 - 2015-08-20 11:43 - 00000000 ____D C:\Users\User\AppData\Local\Adobe

2015-08-20 09:54 - 2015-08-20 09:55 - 00000348 _____ C:\WINDOWS\BRRBCOM.INI

2015-08-20 09:54 - 2015-08-20 09:54 - 00000000 ____D C:\ProgramData\Brother

2015-08-20 09:53 - 2015-08-20 09:53 - 00224256 _____ (Brother Industries, Ltd.) C:\WINDOWS\system32\BRCOC12A.DLL

2015-08-20 09:53 - 2015-08-20 09:53 - 00180224 _____ (Brother Industries, Ltd.) C:\WINDOWS\SysWOW64\BROSNMP.DLL

2015-08-20 09:53 - 2015-08-20 09:53 - 00136456 _____ (Brother Industries Ltd) C:\WINDOWS\SysWOW64\BRRBTOOL.EXE

2015-08-20 09:53 - 2015-08-20 09:53 - 00077824 _____ (Brother Industries, Ltd.) C:\WINDOWS\SysWOW64\BRLMW03A.DLL

2015-08-20 09:53 - 2015-08-20 09:53 - 00045056 _____ C:\WINDOWS\SysWOW64\BRTCPCON.DLL

2015-08-20 09:53 - 2015-08-20 09:53 - 00025299 _____ (Brother Industries, Ltd) C:\WINDOWS\SysWOW64\BRLM03A.DLL

2015-08-20 09:53 - 2015-08-20 09:53 - 00000114 _____ C:\WINDOWS\SysWOW64\BRLMW03A.INI

2015-08-20 09:53 - 2015-08-20 09:53 - 00000050 _____ C:\WINDOWS\system32\BRADC12A.DAT

2015-08-19 14:15 - 2015-08-19 14:16 - 00000000 ____D C:\Program Files\IDT

2015-08-19 14:15 - 2015-08-19 14:15 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information

2015-08-19 14:15 - 2011-01-25 02:57 - 11941376 _____ (IDT, Inc.) C:\WINDOWS\system32\idtsg64.cpl

2015-08-19 14:15 - 2011-01-25 02:57 - 04637184 _____ (IDT, Inc.) C:\WINDOWS\system32\stlang64.dll

2015-08-19 14:15 - 2011-01-25 02:57 - 01499136 _____ (IDT, Inc.) C:\WINDOWS\system32\stapo64.dll

2015-08-19 14:15 - 2011-01-25 02:57 - 00651776 ____N (IDT, Inc.) C:\WINDOWS\system32\stapi64.dll

2015-08-19 14:15 - 2011-01-25 02:57 - 00520192 _____ (IDT, Inc.) C:\WINDOWS\system32\Drivers\stwrt64.sys

2015-08-19 14:15 - 2011-01-25 02:57 - 00431616 _____ (IDT, Inc.) C:\WINDOWS\system32\stcplx64.dll

2015-08-19 14:15 - 2011-01-25 02:57 - 00220160 _____ (IDT, Inc.) C:\WINDOWS\system32\st646324.dll

2015-08-19 14:15 - 2010-01-27 03:30 - 00162816 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AESTAC64.dll

2015-08-19 14:15 - 2009-10-10 00:45 - 00442368 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AESTEC64.dll

2015-08-19 14:15 - 2009-03-03 02:58 - 00068608 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AESTAR64.dll

2015-08-19 14:14 - 2015-08-19 14:14 - 28859960 _____ (Dell Inc.) C:\Users\User\Downloads\DRVR_WIN_R297613 (1).EXE

2015-08-19 14:14 - 2015-08-19 14:14 - 03081720 _____ C:\Users\User\Downloads\E5520A14.exe

2015-08-19 14:13 - 2015-08-19 14:13 - 28859960 _____ (Dell Inc.) C:\Users\User\Downloads\DRVR_WIN_R297613.EXE

2015-08-19 14:13 - 2015-08-19 14:13 - 00000000 ____D C:\Users\User\AppData\Local\Dell

2015-08-19 14:11 - 2015-08-24 17:09 - 00000000 ____D C:\Users\User\AppData\Local\Deployment

2015-08-19 14:11 - 2015-08-19 14:11 - 00417064 _____ () C:\Users\User\Downloads\DellSystemDetectLauncher.exe

2015-08-19 14:11 - 2015-08-19 14:11 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell

2015-08-19 13:58 - 2015-08-13 05:33 - 24593408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll

2015-08-19 13:58 - 2015-08-13 05:23 - 02178560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll

2015-08-19 13:58 - 2015-08-13 05:22 - 02093056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll

2015-08-19 13:58 - 2015-08-13 05:20 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll

2015-08-19 13:58 - 2015-08-13 05:17 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll

2015-08-19 13:58 - 2015-08-13 05:07 - 19323392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll

2015-08-19 13:58 - 2015-08-13 04:53 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll

2015-08-19 13:58 - 2015-08-11 11:04 - 04532304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe

2015-08-19 13:58 - 2015-08-11 11:04 - 02462648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll

2015-08-19 13:58 - 2015-08-11 11:04 - 01087296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll

2015-08-19 13:58 - 2015-08-11 11:03 - 08021840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe

2015-08-19 13:58 - 2015-08-11 11:03 - 00442208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys

2015-08-19 13:58 - 2015-08-11 11:02 - 00554744 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll

2015-08-19 13:58 - 2015-08-11 11:02 - 00292856 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe

2015-08-19 13:58 - 2015-08-11 11:02 - 00080720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys

2015-08-19 13:58 - 2015-08-11 10:57 - 03622256 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll

2015-08-19 13:58 - 2015-08-11 10:52 - 00993104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll

2015-08-19 13:58 - 2015-08-11 10:50 - 01643872 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll

2015-08-19 13:58 - 2015-08-11 10:40 - 04048808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe

2015-08-19 13:58 - 2015-08-11 10:40 - 02151208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll

2015-08-19 13:58 - 2015-08-11 10:40 - 00918320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll

2015-08-19 13:58 - 2015-08-11 10:38 - 00454000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll

2015-08-19 13:58 - 2015-08-11 10:37 - 00243800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe

2015-08-19 13:58 - 2015-08-11 10:31 - 02880032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll

2015-08-19 13:58 - 2015-08-11 10:26 - 00845664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll

2015-08-19 13:58 - 2015-08-11 10:23 - 16706560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll

2015-08-19 13:58 - 2015-08-11 10:22 - 21875200 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll

2015-08-19 13:58 - 2015-08-11 10:21 - 00148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll

2015-08-19 13:58 - 2015-08-11 10:21 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll

2015-08-19 13:58 - 2015-08-11 10:20 - 02224640 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll

2015-08-19 13:58 - 2015-08-11 10:20 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll

2015-08-19 13:58 - 2015-08-11 10:19 - 00235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll

2015-08-19 13:58 - 2015-08-11 10:18 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll

2015-08-19 13:58 - 2015-08-11 10:16 - 02416640 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll

2015-08-19 13:58 - 2015-08-11 10:14 - 00404480 _____ C:\WINDOWS\system32\diagtrack_wininternal.dll

2015-08-19 13:58 - 2015-08-11 10:13 - 00413184 _____ C:\WINDOWS\system32\diagtrack_win.dll

2015-08-19 13:58 - 2015-08-11 10:11 - 02446336 _____ C:\WINDOWS\system32\InputService.dll

2015-08-19 13:58 - 2015-08-11 10:11 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe

2015-08-19 13:58 - 2015-08-11 10:10 - 00778752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll

2015-08-19 13:58 - 2015-08-11 10:10 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll

2015-08-19 13:58 - 2015-08-11 10:10 - 00293376 _____ C:\WINDOWS\system32\TextInputFramework.dll

2015-08-19 13:58 - 2015-08-11 10:09 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll

2015-08-19 13:58 - 2015-08-11 10:08 - 00893440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll

2015-08-19 13:58 - 2015-08-11 10:08 - 00563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll

2015-08-19 13:58 - 2015-08-11 10:07 - 01178112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll

2015-08-19 13:58 - 2015-08-11 10:07 - 00593920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll

2015-08-19 13:58 - 2015-08-11 10:07 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeParserTask.exe

2015-08-19 13:58 - 2015-08-11 10:06 - 07523328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll

2015-08-19 13:58 - 2015-08-11 10:06 - 02662400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll

2015-08-19 13:58 - 2015-08-11 10:05 - 03527168 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll

2015-08-19 13:58 - 2015-08-11 10:05 - 00996352 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll

2015-08-19 13:58 - 2015-08-11 10:05 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationGeofences.dll

2015-08-19 13:58 - 2015-08-11 10:05 - 00269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll

2015-08-19 13:58 - 2015-08-11 10:05 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPermissions.dll

2015-08-19 13:58 - 2015-08-11 10:05 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkInternalPS.dll

2015-08-19 13:58 - 2015-08-11 10:03 - 02558976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll

2015-08-19 13:58 - 2015-08-11 10:02 - 03588096 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys

2015-08-19 13:58 - 2015-08-11 10:02 - 01890304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll

2015-08-19 13:58 - 2015-08-11 10:02 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll

2015-08-19 13:58 - 2015-08-11 10:02 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll

2015-08-19 13:58 - 2015-08-11 10:01 - 01334784 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll

2015-08-19 13:58 - 2015-08-11 10:00 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe

2015-08-19 13:58 - 2015-08-11 10:00 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncutil.dll

2015-08-19 13:58 - 2015-08-11 09:59 - 01106432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll

2015-08-19 13:58 - 2015-08-11 09:59 - 00642560 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll

2015-08-19 13:58 - 2015-08-11 09:59 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll

2015-08-19 13:58 - 2015-08-11 09:59 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tetheringclient.dll

2015-08-19 13:58 - 2015-08-11 09:58 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll

2015-08-19 13:58 - 2015-08-11 09:57 - 13024768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll

2015-08-19 13:58 - 2015-08-11 09:57 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll

2015-08-19 13:58 - 2015-08-11 09:51 - 01916928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll

2015-08-19 13:58 - 2015-08-11 09:51 - 01823232 _____ C:\WINDOWS\SysWOW64\InputService.dll

2015-08-19 13:58 - 2015-08-11 09:50 - 00420352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe

2015-08-19 13:58 - 2015-08-11 09:50 - 00200704 _____ C:\WINDOWS\SysWOW64\TextInputFramework.dll

2015-08-19 13:58 - 2015-08-11 09:50 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll

2015-08-19 13:58 - 2015-08-11 09:49 - 00586752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll

2015-08-19 13:58 - 2015-08-11 09:49 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll

2015-08-19 13:58 - 2015-08-11 09:48 - 00671232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll

2015-08-19 13:58 - 2015-08-11 09:47 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll

2015-08-19 13:58 - 2015-08-11 09:45 - 18805760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll

2015-08-19 13:58 - 2015-08-11 09:45 - 01820672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll

2015-08-19 13:58 - 2015-08-11 09:43 - 02748416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll

2015-08-19 13:58 - 2015-08-11 09:42 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll

2015-08-19 13:58 - 2015-08-11 09:40 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll

2015-08-19 13:58 - 2015-08-11 09:40 - 01593856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll

2015-08-19 13:58 - 2015-08-11 09:40 - 01112064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll

2015-08-19 13:58 - 2015-08-11 09:39 - 00280576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe

2015-08-19 13:58 - 2015-08-11 09:38 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReInfo.dll

2015-08-16 15:13 - 2015-08-16 15:13 - 00000000 ____D C:\Users\User\Desktop\sa visit

2015-08-16 14:55 - 2015-08-16 14:55 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf

2015-08-14 12:07 - 2015-08-14 12:07 - 00000000 ____D C:\Users\User\AppData\Roaming\Macromedia

2015-08-14 11:36 - 2015-08-14 11:36 - 00000000 ____D C:\Users\User\AppData\Local\NetworkTiles

2015-08-12 15:16 - 2015-08-12 15:22 - 00000000 ____D C:\Users\User\AppData\Roaming\Apple Computer

2015-08-12 15:16 - 2015-08-12 15:16 - 00001822 _____ C:\Users\Public\Desktop\iTunes.lnk

2015-08-12 15:16 - 2015-08-12 15:16 - 00000000 ____D C:\Users\User\AppData\Local\Apple Computer

2015-08-12 15:16 - 2015-08-12 15:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes

2015-08-12 15:13 - 2015-08-12 15:16 - 00000000 ____D C:\Program Files\iTunes

2015-08-12 15:13 - 2015-08-12 15:13 - 00000000 ____D C:\ProgramData\Apple Computer

2015-08-12 15:13 - 2015-08-12 15:13 - 00000000 ____D C:\Program Files\iPod

2015-08-12 15:13 - 2015-08-12 15:13 - 00000000 ____D C:\Program Files (x86)\iTunes

2015-08-12 15:12 - 2015-08-12 15:12 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk

2015-08-12 15:12 - 2015-08-12 15:12 - 00000000 ____D C:\WINDOWS\System32\Tasks\Apple

2015-08-12 15:12 - 2015-08-12 15:12 - 00000000 ____D C:\Users\User\AppData\Local\Apple

2015-08-12 15:12 - 2015-08-12 15:12 - 00000000 ____D C:\Program Files (x86)\Apple Software Update

2015-08-12 15:11 - 2015-08-26 23:42 - 00000000 ____D C:\Program Files (x86)\Bonjour

2015-08-12 15:11 - 2015-08-12 15:11 - 00000000 ____D C:\Program Files\Bonjour

2015-08-12 15:10 - 2015-08-12 15:13 - 00000000 ____D C:\Program Files\Common Files\Apple

2015-08-12 15:09 - 2015-08-12 15:12 - 00000000 ____D C:\ProgramData\Apple

2015-08-12 15:04 - 2015-08-12 15:07 - 155875632 _____ (Apple Inc.) C:\Users\User\Downloads\iTunes6464Setup.exe

2015-08-12 14:53 - 2015-08-12 14:55 - 46141524 _____ C:\Users\User\Downloads\rise_up_a_warrior.zip

2015-08-12 13:26 - 2015-08-12 13:26 - 00000000 ____D C:\Users\Default\AppData\Local\Trusteer

2015-08-12 13:26 - 2015-08-12 13:26 - 00000000 ____D C:\Users\Default User\AppData\Local\Trusteer

2015-08-12 13:15 - 2015-08-12 13:15 - 00000000 ____D C:\Users\User\Tracing

2015-08-12 13:11 - 2015-08-12 13:11 - 00000000 ____D C:\WINDOWS\PCHEALTH

2015-08-12 10:50 - 2015-08-03 03:18 - 08613200 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll

2015-08-12 10:50 - 2015-08-03 02:56 - 06878256 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll

2015-08-12 10:49 - 2015-08-08 08:19 - 00608936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe

2015-08-12 10:49 - 2015-08-08 07:40 - 00365056 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll

2015-08-12 10:49 - 2015-08-08 07:24 - 02415104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll

2015-08-12 10:49 - 2015-08-08 07:24 - 01679360 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll

2015-08-12 10:49 - 2015-08-08 07:15 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll

2015-08-12 10:49 - 2015-08-08 07:00 - 01985024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll

2015-08-12 10:49 - 2015-08-05 05:49 - 00783112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll

2015-08-12 10:49 - 2015-08-05 05:29 - 00644128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll

2015-08-12 10:49 - 2015-08-05 05:00 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenter.dll

2015-08-12 10:49 - 2015-08-05 04:47 - 01383424 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys

2015-08-12 10:49 - 2015-08-04 05:06 - 00583128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll

2015-08-12 10:49 - 2015-08-04 03:59 - 01212416 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll

2015-08-12 10:49 - 2015-08-04 03:47 - 00898560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll

2015-08-12 10:49 - 2015-08-03 03:19 - 00505696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys

2015-08-12 10:49 - 2015-08-03 03:18 - 01983840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys

2015-08-12 10:49 - 2015-08-03 03:13 - 22322624 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll

2015-08-12 10:49 - 2015-08-03 03:12 - 00801632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe

2015-08-12 10:49 - 2015-08-03 02:50 - 20857848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll

2015-08-12 10:49 - 2015-08-03 02:49 - 00700256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe

2015-08-12 10:49 - 2015-08-03 02:22 - 01601536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll

2015-08-12 10:49 - 2015-08-03 02:22 - 01008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll

2015-08-12 10:49 - 2015-08-03 02:18 - 12503552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll

2015-08-12 10:49 - 2015-08-03 02:18 - 03780096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll

2015-08-12 10:49 - 2015-08-03 02:18 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll

2015-08-12 10:49 - 2015-08-03 02:18 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkStatus.dll

2015-08-12 10:49 - 2015-08-03 02:15 - 00595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll

2015-08-12 10:49 - 2015-08-03 02:14 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll

2015-08-12 10:49 - 2015-08-03 02:14 - 00247808 _____ C:\WINDOWS\system32\facecredentialprovider.dll

2015-08-12 10:49 - 2015-08-03 02:10 - 01162240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll

2015-08-12 10:49 - 2015-08-03 02:03 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll

2015-08-12 10:49 - 2015-08-03 02:02 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll

2015-08-12 10:49 - 2015-08-03 02:01 - 11262464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll

2015-08-12 10:48 - 2015-08-08 08:29 - 01822280 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll

2015-08-12 10:48 - 2015-08-08 08:01 - 01533496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll

2015-08-12 10:48 - 2015-08-08 07:48 - 00539728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe

2015-08-12 10:48 - 2015-08-06 04:17 - 00237392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdyboost.sys

2015-08-12 10:48 - 2015-08-06 04:17 - 00200528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys

2015-08-12 10:48 - 2015-08-06 03:22 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys

2015-08-12 10:48 - 2015-08-05 04:54 - 01274880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll

2015-08-12 10:48 - 2015-08-05 04:39 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActionCenter.dll

2015-08-12 10:48 - 2015-08-04 05:07 - 00102752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys

2015-08-12 10:48 - 2015-08-04 05:06 - 00243248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll

2015-08-12 10:48 - 2015-08-04 04:23 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll

2015-08-12 10:48 - 2015-08-03 03:32 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll

2015-08-12 10:48 - 2015-08-03 03:28 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll

2015-08-12 10:48 - 2015-08-03 03:19 - 00393568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys

2015-08-12 10:48 - 2015-08-03 03:18 - 00594472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll

2015-08-12 10:48 - 2015-08-03 03:18 - 00046432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpiowin32.sys

2015-08-12 10:48 - 2015-08-03 03:17 - 00516960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS

2015-08-12 10:48 - 2015-08-03 03:17 - 00052264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wpcfltr.sys

2015-08-12 10:48 - 2015-08-03 02:31 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll

2015-08-12 10:48 - 2015-08-03 02:30 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_UserAccount.dll

2015-08-12 10:48 - 2015-08-03 02:24 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll

2015-08-12 10:48 - 2015-08-03 02:24 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll

2015-08-12 10:48 - 2015-08-03 02:24 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModelShim.dll

2015-08-12 10:48 - 2015-08-03 02:23 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll

2015-08-12 10:48 - 2015-08-03 02:22 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll

2015-08-12 10:48 - 2015-08-03 02:21 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\coredpus.dll

2015-08-12 10:48 - 2015-08-03 02:19 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\notepad.exe

2015-08-12 10:48 - 2015-08-03 02:19 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\notepad.exe

2015-08-12 10:48 - 2015-08-03 02:15 - 01290752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll

2015-08-12 10:48 - 2015-08-03 02:15 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll

2015-08-12 10:48 - 2015-08-03 02:15 - 00384000 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll

2015-08-12 10:48 - 2015-08-03 02:15 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll

2015-08-12 10:48 - 2015-08-03 02:12 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll

2015-08-12 10:48 - 2015-08-03 02:12 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll

2015-08-12 10:48 - 2015-08-03 02:11 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfuimanager.dll

2015-08-12 10:48 - 2015-08-03 02:06 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe

2015-08-12 10:48 - 2015-08-03 02:02 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll

2015-08-12 10:48 - 2015-08-03 01:59 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfuimanager.dll

2015-08-10 20:34 - 2015-08-10 20:34 - 00000000 ____D C:\WINDOWS\system32\SleepStudy

2015-08-10 19:44 - 2015-07-30 07:24 - 01561872 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll

2015-08-10 19:44 - 2015-07-30 07:23 - 00527952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll

2015-08-10 19:44 - 2015-07-30 07:21 - 00816576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll

2015-08-10 19:44 - 2015-07-30 07:17 - 01200400 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll

2015-08-10 19:44 - 2015-07-30 07:17 - 01025840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll

2015-08-10 19:44 - 2015-07-30 07:16 - 02147080 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll

2015-08-10 19:44 - 2015-07-30 07:14 - 00333168 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll

2015-08-10 19:44 - 2015-07-30 07:09 - 01562968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll

2015-08-10 19:44 - 2015-07-30 07:06 - 01043872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll

2015-08-10 19:44 - 2015-07-30 07:05 - 02498808 _____ C:\WINDOWS\system32\CoreUIComponents.dll

2015-08-10 19:44 - 2015-07-30 07:05 - 00501008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll

2015-08-10 19:44 - 2015-07-30 07:04 - 01396064 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll

2015-08-10 19:44 - 2015-07-30 07:03 - 02116448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys

2015-08-10 19:44 - 2015-07-30 06:24 - 00252768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll

2015-08-10 19:44 - 2015-07-30 05:29 - 00705520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll

2015-08-10 19:44 - 2015-07-30 05:26 - 01867160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll

2015-08-10 19:44 - 2015-07-30 05:26 - 00877016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll

2015-08-10 19:44 - 2015-07-30 05:25 - 01356368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll

2015-08-10 19:44 - 2015-07-30 05:25 - 00713312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll

2015-08-10 19:44 - 2015-07-30 05:24 - 01769056 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll

2015-08-10 19:44 - 2015-07-30 05:24 - 00445240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll

2015-08-10 19:44 - 2015-07-30 05:24 - 00285632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll

2015-08-10 19:44 - 2015-07-30 05:21 - 00962400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll

2015-08-10 19:44 - 2015-07-30 05:12 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll

2015-08-10 19:44 - 2015-07-30 05:12 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll

2015-08-10 19:44 - 2015-07-30 05:08 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe

2015-08-10 19:44 - 2015-07-30 04:52 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll

2015-08-10 19:44 - 2015-07-30 04:52 - 00521216 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll

2015-08-10 19:44 - 2015-07-30 04:52 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll

2015-08-10 19:44 - 2015-07-30 04:49 - 11557888 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll

2015-08-10 19:44 - 2015-07-30 04:46 - 02125312 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll

2015-08-10 19:44 - 2015-07-30 04:44 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll

2015-08-10 19:44 - 2015-07-30 04:44 - 00229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll

2015-08-10 19:44 - 2015-07-30 04:42 - 00518144 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll

2015-08-10 19:44 - 2015-07-30 04:41 - 00407040 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll

2015-08-10 19:44 - 2015-07-30 04:40 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll

2015-08-10 19:44 - 2015-07-30 04:38 - 01420288 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll

2015-08-10 19:44 - 2015-07-30 04:34 - 00599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll

2015-08-10 19:44 - 2015-07-30 04:29 - 00654848 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll

2015-08-10 19:44 - 2015-07-30 04:15 - 09889792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll

2015-08-10 19:44 - 2015-07-30 04:04 - 01714176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll

2015-08-10 19:44 - 2015-07-30 04:04 - 00335360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll

2015-08-10 19:44 - 2015-07-30 03:58 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll

2015-08-10 19:43 - 2015-07-30 07:15 - 00632168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll

2015-08-10 19:43 - 2015-07-30 05:24 - 00407616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll

2015-08-10 19:43 - 2015-07-30 05:22 - 00896144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll

2015-08-10 19:43 - 2015-07-30 05:22 - 00507696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll

2015-08-10 19:43 - 2015-07-30 05:09 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe

2015-08-10 19:43 - 2015-07-30 05:08 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll

2015-08-10 19:43 - 2015-07-30 05:08 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe

2015-08-10 19:43 - 2015-07-30 04:59 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll

2015-08-10 19:43 - 2015-07-30 04:46 - 00487424 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll

2015-08-10 19:43 - 2015-07-30 04:46 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll

2015-08-10 19:43 - 2015-07-30 04:45 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll

2015-08-10 19:43 - 2015-07-30 04:45 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tunnel.sys

2015-08-10 19:43 - 2015-07-30 04:44 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll

2015-08-10 19:43 - 2015-07-30 04:44 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys

2015-08-10 19:43 - 2015-07-30 04:44 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\VoiceActivationManager.dll

2015-08-10 19:43 - 2015-07-30 04:41 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll

2015-08-10 19:43 - 2015-07-30 04:38 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll

2015-08-10 19:43 - 2015-07-30 04:07 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll

2015-08-10 19:43 - 2015-07-30 04:06 - 00373248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll

2015-08-10 19:43 - 2015-07-30 04:06 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll

2015-08-10 19:43 - 2015-07-30 04:06 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VoiceActivationManager.dll

2015-08-10 19:43 - 2015-07-30 03:59 - 00473088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll

2015-08-10 01:45 - 2015-08-25 17:01 - 00000000 ___DC C:\WINDOWS\Panther

2015-08-10 01:42 - 2015-08-10 01:42 - 14241792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 12589056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 04791296 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 04760576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 04398080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 04350464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 04169728 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 03687936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 03579904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 03443200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 03248640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 02646528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 01611264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 01411072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 01201664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 01168736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys

2015-08-10 01:42 - 2015-08-10 01:42 - 01067520 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 01043968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 01031680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorDataService.exe

2015-08-10 01:42 - 2015-08-10 01:42 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi

2015-08-10 01:42 - 2015-08-10 01:42 - 00872448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00799232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpccpl.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00798208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00754688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00750592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00670208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efscore.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00584544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00569344 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00485888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00437248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00356352 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00291840 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemcpl.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\systemcpl.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe

2015-08-10 01:42 - 2015-08-10 01:42 - 00251392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00181088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SignInOptions.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00179200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srumsvc.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00116736 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00097128 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcd.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00082616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcd.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spbcd.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msiexec.exe

2015-08-10 01:42 - 2015-08-10 01:42 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.PAL.Desktop.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll

2015-08-10 01:42 - 2015-08-10 01:42 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\calc.exe

2015-08-10 01:42 - 2015-08-10 01:42 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\calc.exe

2015-08-10 01:41 - 2015-08-10 01:41 - 07569408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 07051264 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 06488312 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 06305792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 06101504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 05118024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 05076480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 04611584 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 03362816 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 03248128 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 02741760 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 02606080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 02235904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 02207744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 02112512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 01773056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 01602560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 01591856 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 01521664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 01418240 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe

2015-08-10 01:41 - 2015-08-10 01:41 - 01417216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 01380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 01365072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 01294352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi

2015-08-10 01:41 - 2015-08-10 01:41 - 01203200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 01203200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 01169408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 01135312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe

2015-08-10 01:41 - 2015-08-10 01:41 - 01123400 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe

2015-08-10 01:41 - 2015-08-10 01:41 - 01101792 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 01061888 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 01018568 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi

2015-08-10 01:41 - 2015-08-10 01:41 - 00966424 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00934752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refsv1.sys

2015-08-10 01:41 - 2015-08-10 01:41 - 00925696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00902656 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe

2015-08-10 01:41 - 2015-08-10 01:41 - 00869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00858408 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe

2015-08-10 01:41 - 2015-08-10 01:41 - 00856064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00850432 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00841728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00832512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00823336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00808856 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00783872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00762896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe

2015-08-10 01:41 - 2015-08-10 01:41 - 00695136 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00680448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00679424 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00677888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00658568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00630160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00607008 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00601344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys

2015-08-10 01:41 - 2015-08-10 01:41 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00578048 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe

2015-08-10 01:41 - 2015-08-10 01:41 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00565088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys

2015-08-10 01:41 - 2015-08-10 01:41 - 00542720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00521568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe

2015-08-10 01:41 - 2015-08-10 01:41 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00505344 _____ C:\WINDOWS\system32\EditionUpgradeManagerObj.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00498016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys

2015-08-10 01:41 - 2015-08-10 01:41 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00430592 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcomapi.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00425824 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00416256 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe

2015-08-10 01:41 - 2015-08-10 01:41 - 00366592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00343040 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe

2015-08-10 01:41 - 2015-08-10 01:41 - 00335248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00328704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00325984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys

2015-08-10 01:41 - 2015-08-10 01:41 - 00303616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00290312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe

2015-08-10 01:41 - 2015-08-10 01:41 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00265480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00263168 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00242176 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicesFlowBroker.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00208736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\srumsvc.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\OmaDmAgent.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00191488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReInfo.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe

2015-08-10 01:41 - 2015-08-10 01:41 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Privacy.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabSvc.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe

2015-08-10 01:41 - 2015-08-10 01:41 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe

2015-08-10 01:41 - 2015-08-10 01:41 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\spbcd.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\setbcdlocale.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.ProxyStub.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys

2015-08-10 01:41 - 2015-08-10 01:41 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe

2015-08-10 01:41 - 2015-08-10 01:41 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\unenrollhook.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00061280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys

2015-08-10 01:41 - 2015-08-10 01:41 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.OneCore.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\hmkd.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmprc.exe

2015-08-10 01:41 - 2015-08-10 01:41 - 00046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmUcsi.sys

2015-08-10 01:41 - 2015-08-10 01:41 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hmkd.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll

2015-08-10 01:41 - 2015-08-10 01:41 - 00032768 _____ C:\WINDOWS\system32\LicenseManagerApi.dll

2015-08-10 01:39 - 2015-08-10 01:39 - 00008192 _____ C:\WINDOWS\system32\config\userdiff

2015-08-10 01:37 - 2015-08-10 01:37 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices

2015-08-10 01:37 - 2015-08-10 01:37 - 00000000 ____D C:\WINDOWS\system32\msmq

2015-08-10 01:37 - 2015-08-10 01:37 - 00000000 ____D C:\WINDOWS\system32\BestPractices

2015-08-10 01:37 - 2015-08-10 01:37 - 00000000 ____D C:\Program Files\Reference Assemblies

2015-08-10 01:37 - 2015-08-10 01:37 - 00000000 ____D C:\Program Files\MSBuild

2015-08-10 01:37 - 2015-08-10 01:37 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies

2015-08-10 01:37 - 2015-08-10 01:37 - 00000000 ____D C:\Program Files (x86)\MSBuild

2015-08-10 01:37 - 2015-08-10 01:37 - 00000000 ____D C:\inetpub

2015-08-10 01:37 - 2015-05-30 06:07 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll

2015-08-10 01:37 - 2015-05-30 06:07 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll

2015-08-10 01:37 - 2015-05-30 06:07 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe

2015-08-10 01:36 - 2015-06-18 03:10 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll

2015-08-10 01:36 - 2015-06-18 03:10 - 00124112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll

2015-08-10 01:36 - 2015-06-18 03:10 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe

2015-08-09 18:11 - 2015-08-09 18:11 - 00000000 ____D C:\Users\User\AppData\Local\PeerDistRepub

2015-08-09 17:13 - 2015-08-27 07:56 - 00000000 ____D C:\Users\User\OneDrive

2015-08-09 17:13 - 2015-08-24 07:45 - 00002335 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk

2015-08-09 17:12 - 2015-08-14 11:10 - 00000000 ____D C:\Users\User\AppData\Local\MicrosoftEdge

2015-08-09 17:12 - 2015-08-09 17:15 - 00000000 ____D C:\Users\User\AppData\Local\Comms

2015-08-09 17:12 - 2015-08-09 17:12 - 00000000 ____D C:\ProgramData\Microsoft OneDrive

2015-08-09 17:11 - 2015-08-09 17:11 - 00001051 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optional Features.lnk

2015-08-09 17:09 - 2015-08-09 17:09 - 00000000 ____D C:\Users\User\AppData\Local\Publishers

2015-08-09 17:08 - 2015-08-25 08:53 - 00000000 ____D C:\Users\User\AppData\Local\Packages

2015-08-09 17:08 - 2015-08-09 17:08 - 00000020 ___SH C:\Users\User\ntuser.ini

2015-08-09 17:08 - 2015-08-09 17:08 - 00000000 ____D C:\Users\User\AppData\Local\TileDataLayer

2015-08-09 17:03 - 2015-08-09 17:03 - 00022744 _____ C:\WINDOWS\system32\emptyregdb.dat

2015-08-09 16:56 - 2015-08-09 16:56 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk

2015-08-09 16:56 - 2015-08-09 16:56 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help

2015-08-09 16:56 - 2015-08-09 16:56 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help

2015-08-09 16:54 - 2015-08-09 16:54 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines

2015-08-09 16:53 - 2015-08-09 17:08 - 00000000 ___RD C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories

2015-08-09 16:53 - 2015-07-10 12:04 - 00000000 __RSD C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell

2015-08-09 16:53 - 2015-07-10 12:04 - 00000000 ___RD C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools

2015-08-09 16:53 - 2015-07-10 12:04 - 00000000 ___RD C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility

2015-08-09 16:53 - 2015-07-10 12:04 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance

2015-08-09 16:51 - 2015-08-27 22:07 - 01005534 _____ C:\WINDOWS\system32\PerfStringBackup.INI

2015-08-09 16:51 - 2015-08-09 16:52 - 00021209 _____ C:\WINDOWS\iis.log

2015-08-09 16:51 - 2015-08-09 16:51 - 00961296 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI

2015-08-09 16:50 - 2015-07-10 11:59 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll

2015-08-09 16:49 - 2015-08-09 16:49 - 00006352 _____ C:\WINDOWS\DPINST.LOG

2015-08-09 16:49 - 2015-08-09 16:49 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_ST_Accel_01009.Wdf

2015-08-09 16:49 - 2015-08-09 16:49 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf

2015-08-09 16:49 - 2015-08-09 16:49 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_Apfiltr_01009.Wdf

2015-08-09 16:49 - 2015-08-09 16:49 - 00000000 ____D C:\Program Files\Synaptics

2015-08-09 16:49 - 2015-08-09 16:49 - 00000000 ____D C:\Program Files\STMicroelectronics

2015-08-09 16:49 - 2015-08-09 16:49 - 00000000 ____D C:\Program Files\DIFX

2015-08-09 16:49 - 2015-08-09 16:49 - 00000000 ____D C:\Program Files\DellTPad

2015-08-09 16:49 - 2015-08-09 16:49 - 00000000 ____D C:\Intel

2015-08-09 16:49 - 2011-07-15 21:31 - 00022128 _____ (ST Microelectronics) C:\WINDOWS\system32\Drivers\stdcfltn.sys

2015-08-09 16:47 - 2015-08-09 16:48 - 00024923 _____ C:\WINDOWS\system32\NetSetupMig.log

2015-08-09 16:46 - 2015-08-25 00:08 - 00010134 _____ C:\WINDOWS\PFRO.log

2015-08-09 16:21 - 2015-08-09 17:04 - 00006506 _____ C:\WINDOWS\comsetup.log

2015-08-09 16:19 - 2015-08-09 17:05 - 00010447 _____ C:\WINDOWS\diagerr.xml

2015-08-09 16:19 - 2015-08-09 17:05 - 00009528 _____ C:\WINDOWS\diagwrn.xml

2015-07-31 12:30 - 2015-07-31 12:30 - 00091648 _____ C:\Users\User\Documents\YCS 2015 enquiries.xls

2015-07-30 21:50 - 2015-07-30 21:50 - 00000000 ____D C:\Users\User\AppData\Local\Trusteer

2015-07-30 21:42 - 2015-07-30 21:42 - 00000000 ____D C:\ProgramData\Trusteer

2015-07-30 21:40 - 2015-07-30 21:40 - 00436504 _____ (IBM Corp.) C:\Users\User\Downloads\RapportSetup.exe

2015-07-30 03:03 - 2015-07-30 03:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox

2015-07-29 16:45 - 2015-08-27 22:10 - 00000000 ____D C:\Users\User\AppData\Roaming\Skype

2015-07-29 16:45 - 2015-08-27 08:00 - 00002640 _____ C:\Users\Public\Desktop\Skype.lnk

2015-07-29 16:45 - 2015-08-27 08:00 - 00000000 ___RD C:\Program Files (x86)\Skype

2015-07-29 16:45 - 2015-08-27 08:00 - 00000000 ____D C:\ProgramData\Skype

2015-07-29 16:45 - 2015-07-29 16:45 - 00000000 ____D C:\Users\User\AppData\Local\Skype

2015-07-29 16:43 - 2015-07-29 16:43 - 01384064 _____ (Skype Technologies S.A.) C:\Users\User\Downloads\SkypeSetup.exe

2015-07-29 16:41 - 2015-08-27 12:43 - 00142433 _____ C:\lm.log

2015-07-29 16:41 - 2014-11-14 13:30 - 00538624 _____ (Dell Inc.) C:\WINDOWS\system32\dlhlszci-1.dll

2015-07-29 16:41 - 2014-11-14 13:30 - 00188928 _____ (Dell Inc.) C:\WINDOWS\system32\DLHLSZIL.DLL

2015-07-29 14:37 - 2015-07-29 15:37 - 00000000 ____D C:\Users\User\Documents\resepte

2015-07-29 14:32 - 2015-07-29 14:34 - 00000000 ____D C:\Users\User\Documents\Amazon MP3

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-27 22:08 - 2015-07-10 13:22 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log

2015-08-27 22:06 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\sru

2015-08-27 21:25 - 2015-07-23 14:14 - 00000898 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job

2015-08-27 15:25 - 2015-07-23 14:14 - 00000894 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job

2015-08-27 07:55 - 2015-07-10 13:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT

2015-08-27 07:48 - 2015-07-10 10:05 - 00131072 ___SH C:\WINDOWS\system32\config\BBI

2015-08-27 03:31 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\rescache

2015-08-26 23:48 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\AppReadiness

2015-08-26 22:15 - 2015-06-04 12:35 - 00000000 ____D C:\Users\User\AppData\Local\VirtualStore

2015-08-26 12:24 - 2013-04-29 19:45 - 00000000 ____D C:\Users\User\Documents\invoices ycs

2015-08-24 21:33 - 2015-07-22 23:02 - 00002259 _____ C:\WINDOWS\epplauncher.mif

2015-08-24 21:26 - 2009-07-14 04:20 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy

2015-08-24 17:54 - 2015-07-10 13:20 - 00013466 _____ C:\WINDOWS\setupact.log

2015-08-24 16:57 - 2015-07-23 14:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome

2015-08-20 11:56 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase

2015-08-20 11:54 - 2012-10-24 12:25 - 00000000 ____D C:\Users\User\Documents\Your counselling S client notes

2015-08-19 16:01 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns

2015-08-19 16:01 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\appraiser

2015-08-19 14:31 - 2015-07-10 11:55 - 00000000 ____D C:\WINDOWS\CbsTemp

2015-08-17 22:29 - 2013-10-07 13:13 - 00000000 ____D C:\Users\User\Documents\YCS Admin

2015-08-16 14:52 - 2015-07-10 13:20 - 00334968 _____ C:\WINDOWS\system32\FNTCACHE.DAT

2015-08-12 13:21 - 2015-07-23 19:19 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013

2015-08-12 13:20 - 2015-07-23 19:15 - 00000000 ____D C:\ProgramData\Microsoft Help

2015-08-12 13:19 - 2015-07-10 12:04 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories

2015-08-12 13:19 - 2015-07-10 12:04 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories

2015-08-12 13:19 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\oobe

2015-08-12 13:14 - 2015-06-02 14:07 - 00000000 ____D C:\Users\User\Documents\C3 counselling admin docs

2015-08-12 13:14 - 2012-11-07 11:53 - 00000000 ____D C:\Users\User\Documents\counselling docs

2015-08-12 13:10 - 2009-07-14 03:34 - 00000478 _____ C:\WINDOWS\win.ini

2015-08-11 03:30 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\Provisioning

2015-08-10 21:25 - 2015-07-23 19:15 - 00000000 ____D C:\Users\User\AppData\Local\Microsoft Help

2015-08-10 08:19 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\appcompat

2015-08-10 01:45 - 2015-07-10 12:04 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template

2015-08-10 01:42 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe

2015-08-10 01:42 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform

2015-08-10 01:42 - 2015-07-10 10:05 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism

2015-08-10 01:42 - 2015-07-10 10:05 - 00000000 ____D C:\WINDOWS\system32\Dism

2015-08-10 01:37 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv

2015-08-10 01:37 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\inetsrv

2015-08-10 01:37 - 2015-07-10 12:01 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll

2015-08-10 01:37 - 2015-07-10 12:01 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqutil.dll

2015-08-10 01:37 - 2015-07-10 12:01 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.dll

2015-08-10 01:37 - 2015-07-10 12:01 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll

2015-08-10 01:37 - 2015-07-10 12:01 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqrt.dll

2015-08-10 01:37 - 2015-07-10 12:01 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.tlb

2015-08-10 01:37 - 2015-07-10 12:01 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa30.tlb

2015-08-10 01:37 - 2015-07-10 12:01 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa20.tlb

2015-08-10 01:37 - 2015-07-10 12:01 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll

2015-08-10 01:37 - 2015-07-10 12:01 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa10.tlb

2015-08-10 01:37 - 2015-07-10 12:01 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll

2015-08-10 01:37 - 2015-07-10 12:01 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe

2015-08-10 01:37 - 2015-07-10 12:01 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll

2015-08-10 01:37 - 2015-07-10 12:01 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll

2015-08-10 01:37 - 2015-07-10 12:01 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll

2015-08-10 01:37 - 2015-07-10 12:01 - 00009096 _____ C:\WINDOWS\SysWOW64\msmqtrc.mof

2015-08-10 01:37 - 2015-07-10 12:00 - 01417728 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqqm.dll

2015-08-10 01:37 - 2015-07-10 12:00 - 00813056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll

2015-08-10 01:37 - 2015-07-10 12:00 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqutil.dll

2015-08-10 01:37 - 2015-07-10 12:00 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.dll

2015-08-10 01:37 - 2015-07-10 12:00 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqrt.dll

2015-08-10 01:37 - 2015-07-10 12:00 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll

2015-08-10 01:37 - 2015-07-10 12:00 - 00175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mqac.sys

2015-08-10 01:37 - 2015-07-10 12:00 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqlogmgr.dll

2015-08-10 01:37 - 2015-07-10 12:00 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.tlb

2015-08-10 01:37 - 2015-07-10 12:00 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa30.tlb

2015-08-10 01:37 - 2015-07-10 12:00 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa20.tlb

2015-08-10 01:37 - 2015-07-10 12:00 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll

2015-08-10 01:37 - 2015-07-10 12:00 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll

2015-08-10 01:37 - 2015-07-10 12:00 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqbkup.exe

2015-08-10 01:37 - 2015-07-10 12:00 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa10.tlb

2015-08-10 01:37 - 2015-07-10 12:00 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe

2015-08-10 01:37 - 2015-07-10 12:00 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcertui.dll

2015-08-10 01:37 - 2015-07-10 12:00 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe

2015-08-10 01:37 - 2015-07-10 12:00 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll

2015-08-10 01:37 - 2015-07-10 12:00 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll

2015-08-10 01:37 - 2015-07-10 12:00 - 00009096 _____ C:\WINDOWS\system32\msmqtrc.mof

2015-08-09 17:54 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\restore

2015-08-09 17:11 - 2015-07-10 14:12 - 00000000 ____D C:\WINDOWS\OCR

2015-08-09 17:09 - 2015-07-10 12:04 - 00000000 ___RD C:\WINDOWS\PurchaseDialog

2015-08-09 17:09 - 2015-07-10 12:04 - 00000000 ___RD C:\WINDOWS\PrintDialog

2015-08-09 17:09 - 2015-07-10 12:04 - 00000000 ___RD C:\WINDOWS\MiracastView

2015-08-09 17:09 - 2015-07-10 12:04 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel

2015-08-09 17:05 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\Registration

2015-08-09 17:03 - 2015-07-23 14:14 - 00004004 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA

2015-08-09 17:03 - 2015-07-23 14:14 - 00003752 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore

2015-08-09 17:03 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\spool

2015-08-09 17:01 - 2015-07-10 12:04 - 00000000 __RSD C:\WINDOWS\Media

2015-08-09 17:01 - 2015-07-10 12:04 - 00000000 __RHD C:\Users\Public\Libraries

2015-08-09 16:56 - 2015-07-10 14:14 - 00000000 ____D C:\WINDOWS\ShellNew

2015-08-09 16:56 - 2015-07-10 12:05 - 00004362 _____ C:\WINDOWS\DtcInstall.log

2015-08-09 16:56 - 2015-07-10 12:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories

2015-08-09 16:56 - 2015-07-10 10:05 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM

2015-08-09 16:56 - 2009-07-14 04:20 - 00000000 ____D C:\Users\Default.migrated

2015-08-09 16:55 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\SysWOW64\zh-HK

2015-08-09 16:55 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\SysWOW64\tr-TR

2015-08-09 16:55 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz

2015-08-09 16:55 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\SysWOW64\IME

2015-08-09 16:55 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\zh-HK

2015-08-09 16:55 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\tr-TR

2015-08-09 16:55 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\IME

2015-08-09 16:54 - 2015-07-10 12:04 - 00000000 __SHD C:\Program Files\Windows Sidebar

2015-08-09 16:54 - 2015-07-10 12:04 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar

2015-08-09 16:54 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\schemas

2015-08-09 16:54 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\PolicyDefinitions

2015-08-09 16:54 - 2015-07-10 12:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared

2015-08-09 16:54 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\DVD Maker

2015-08-09 16:53 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\Recovery

2015-08-09 16:51 - 2015-07-10 10:05 - 00000000 ____D C:\WINDOWS\system32\Sysprep

2015-08-09 16:46 - 2015-07-10 10:05 - 00000000 __RHD C:\Users\Default

2015-08-09 16:27 - 2015-06-04 12:32 - 01618734 _____ C:\WINDOWS\WindowsUpdate (1).log

2015-08-09 16:23 - 2009-07-14 05:45 - 00022096 ____H C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2015-08-09 16:23 - 2009-07-14 05:45 - 00022096 ____H C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2015-08-08 16:38 - 2015-07-10 12:06 - 00794088 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe

2015-08-08 16:38 - 2015-07-10 12:06 - 00179688 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl

2015-07-30 03:50 - 2015-06-04 16:26 - 00111536 _____ C:\Users\User\AppData\Local\GDIPFONTCACHEV1.DAT

2015-07-29 15:38 - 2015-07-02 09:44 - 00000000 ____D C:\Users\User\Documents\C3 invoices

2015-07-29 15:38 - 2013-05-22 18:08 - 00000000 ____D C:\Users\User\Documents\references

2015-07-29 15:34 - 2015-04-10 13:01 - 00000000 ____D C:\Users\User\Documents\ashridge 10 april 15

2015-07-29 15:34 - 2014-06-11 22:11 - 00000000 ____D C:\Users\User\Documents\c3counselling logo sets

2015-07-29 15:34 - 2013-05-22 18:09 - 00000000 ____D C:\Users\User\Documents\CV's

2015-07-29 15:34 - 2013-03-13 15:43 - 00000000 ____D C:\Users\User\Documents\crochet patrone

2015-07-29 15:34 - 2012-07-12 14:48 - 00000000 ____D C:\Users\User\Documents\counselling psychology

2015-07-29 15:33 - 2015-01-28 15:07 - 00000000 ____D C:\Users\User\Documents\waterfalls

2015-07-29 15:33 - 2014-12-20 15:55 - 00000000 ____D C:\Users\User\Documents\sage journals eating disorders

2015-07-29 15:33 - 2014-03-24 22:22 - 00000000 ____D C:\Users\User\Documents\musiek niki

2015-07-29 15:33 - 2013-03-13 15:43 - 00000000 ____D C:\Users\User\Documents\quilt patrone

2015-07-29 15:31 - 2014-06-17 20:26 - 00000000 ____D C:\Users\User\Documents\jesus culture

2015-07-29 15:31 - 2014-04-11 12:10 - 00000000 ____D C:\Users\User\Documents\infant loss training

2015-07-29 15:30 - 2014-06-09 20:12 - 00000000 ____D C:\Users\User\Documents\freedom series robert morris

2015-07-29 15:30 - 2013-05-22 18:09 - 00000000 ____D C:\Users\User\Documents\hekel en brei

2015-07-29 15:30 - 2012-04-25 07:31 - 00000000 ____D C:\Users\User\Documents\id doks

2015-07-29 15:29 - 2012-03-25 18:58 - 00000000 ____D C:\Users\User\Documents\fotos 25 mart 12

2015-07-29 15:28 - 2014-07-11 21:37 - 00000000 ____D C:\Users\User\Documents\fotos

2015-07-29 15:28 - 2013-01-19 21:40 - 00000000 ____D C:\Users\User\Documents\fotos 19 jan 13

2015-07-29 15:27 - 2013-03-13 15:44 - 00000000 ____D C:\Users\User\Documents\dolls

2015-07-29 14:45 - 2014-11-18 19:19 - 00000000 ____D C:\Users\User\Documents\Magna

2015-07-29 14:45 - 2014-09-04 15:58 - 00000000 ____D C:\Users\User\Documents\ycs company invoices

2015-07-29 14:45 - 2014-07-19 21:53 - 00000000 ____D C:\Users\User\Documents\supervision with jane

2015-07-29 14:45 - 2014-04-23 17:05 - 00000000 ____D C:\Users\User\Documents\trauma

2015-07-29 14:45 - 2014-04-08 21:39 - 00000000 ____D C:\Users\User\Documents\YCS case studies

2015-07-29 14:45 - 2013-09-30 21:35 - 00000000 ____D C:\Users\User\Documents\year 3 diploma docs

2015-07-29 14:45 - 2012-12-07 22:53 - 00000000 ____D C:\Users\User\Documents\My Digital Editions

2015-07-29 14:45 - 2012-04-02 11:32 - 00000000 ____D C:\Users\User\Documents\My Received Files

2015-07-29 14:44 - 2015-06-02 14:32 - 00000000 ____D C:\Users\User\Documents\c3 legal notes

2015-07-28 13:16 - 2012-03-18 20:37 - 00000000 ____D C:\Users\User\Documents\Outlook Files

==================== Files in the root of some directories =======

2015-08-20 11:50 - 2015-08-20 11:53 - 0001322 _____ () C:\Users\User\AppData\Roaming\Bubble Dock.boostrap.log

2015-08-20 11:52 - 2015-08-20 11:52 - 0005709 _____ () C:\Users\User\AppData\Roaming\Bubble Dock.installation.log

2015-08-20 11:53 - 2015-08-20 11:53 - 0000078 _____ () C:\Users\User\AppData\Roaming\Selection Tools.installation.log

2015-08-20 11:50 - 2015-08-20 11:50 - 0000097 _____ () C:\Users\User\AppData\Roaming\WindApp.boostrap.log

2015-08-20 11:53 - 2015-08-20 11:53 - 0000078 _____ () C:\Users\User\AppData\Roaming\WindApp.installation.log

2015-08-25 08:16 - 2015-08-26 22:35 - 0180062 _____ () C:\Users\User\AppData\Local\ars.cache

2015-08-25 08:16 - 2015-08-26 22:36 - 0498461 _____ () C:\Users\User\AppData\Local\census.cache

2015-08-25 08:07 - 2015-08-25 08:07 - 0000036 _____ () C:\Users\User\AppData\Local\housecall.guid.cache

2015-08-25 08:12 - 2015-08-26 22:27 - 0000010 _____ () C:\Users\User\AppData\Local\sponge.last.runtime.cache

Some files in TEMP:

====================

C:\Users\User\AppData\Local\Temp\adobe_reader.exe

C:\Users\User\AppData\Local\Temp\SkypeSetup.exe

 

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed

C:\WINDOWS\system32\wininit.exe => File is digitally signed

C:\WINDOWS\explorer.exe => File is digitally signed

C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed

C:\WINDOWS\system32\svchost.exe => File is digitally signed

C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed

C:\WINDOWS\system32\services.exe => File is digitally signed

C:\WINDOWS\system32\User32.dll => File is digitally signed

C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed

C:\WINDOWS\system32\userinit.exe => File is digitally signed

C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed

C:\WINDOWS\system32\rpcss.dll => File is digitally signed

C:\WINDOWS\system32\dnsapi.dll => File is digitally signed

C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed

C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

 

LastRegBack: 2015-08-27 02:28

 

==================== End of FRST.txt ============================


Additional scan result of Farbar Recovery Scan Tool (x64) Version:27-08-2015

Ran by User (2015-08-27 22:11:26)

Running from C:\Security

Boot Mode: Normal

==========================================================

 

==================== Accounts: =============================

Administrator (S-1-5-21-1394956801-2065374029-3886242179-500 - Administrator - Disabled)

DefaultAccount (S-1-5-21-1394956801-2065374029-3886242179-503 - Limited - Disabled)

Guest (S-1-5-21-1394956801-2065374029-3886242179-501 - Limited - Disabled)

User (S-1-5-21-1394956801-2065374029-3886242179-1000 - Administrator - Enabled) => C:\Users\User

 

==================== Security Center ========================

 

(If an entry is included in the fixlist, it will be removed.)

 

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Apple Application Support (32-bit) (HKLM-x32\...\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.)

Apple Application Support (64-bit) (HKLM\...\{B255D495-4734-4E9B-B4F5-96702FD4A7B9}) (Version: 3.2 - Apple Inc.)

Apple Mobile Device Support (HKLM\...\{5D61F006-168C-4B8B-B7FD-F113C10AE0E4}) (Version: 8.2.1.3 - Apple Inc.)

Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)

Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)

Dell System Detect (HKU\S-1-5-21-1394956801-2065374029-3886242179-1000\...\73f463568823ebbe) (Version: 6.6.0.1 - Dell)

Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 8.1206.101.112 - ALPS ELECTRIC CO., LTD.)

globalupdate Helper (x32 Version: 1.3.25.0 - globalupdate Inc.) Hidden <==== ATTENTION

Google Chrome (HKLM-x32\...\Google Chrome) (Version: 44.0.2403.157 - Google Inc.)

Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden

IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6324.0 - IDT)

iTunes (HKLM\...\{6CF1A7E2-8001-4870-9F18-3C6CDD6FE9E3}) (Version: 12.2.1.16 - Apple Inc.)

Microsoft Office Professional Plus 2013 (HKLM-x32\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation)

Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)

Outils de vérification linguistique 2013 de Microsoft Office

- Français (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden

Skype™ 7.8 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.8.102 - Skype Technologies S.A.)

SmartSaver+ 3 (HKLM-x32\...\SmartSaver+ 3) (Version: 1.36.01.22 - smart-saverplus) <==== ATTENTION

Software Version Updater (HKLM-x32\...\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}) (Version:  - ) <==== ATTENTION

Update for Skype for Business 2015 (KB2889853) 32-Bit Edition (HKLM-x32\...\{90150000-012B-0409-0000-0000000FF1CE}_Office15.PROPLUS_{BF1B3F01-93F3-4B83-93DB-132EB1AED259}) (Version:  - Microsoft)

 

==================== Custom CLSID (Whitelisted): ==========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

CustomCLSID: HKU\S-1-5-21-1394956801-2065374029-3886242179-1000_Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\InprocServer32 -> C:\Windows\system32\shell32.dll (Microsoft Corporation)

CustomCLSID: HKU\S-1-5-21-1394956801-2065374029-3886242179-1000_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)

CustomCLSID: HKU\S-1-5-21-1394956801-2065374029-3886242179-1000_Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)

CustomCLSID: HKU\S-1-5-21-1394956801-2065374029-3886242179-1000_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)

CustomCLSID: HKU\S-1-5-21-1394956801-2065374029-3886242179-1000_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)

CustomCLSID: HKU\S-1-5-21-1394956801-2065374029-3886242179-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)

CustomCLSID: HKU\S-1-5-21-1394956801-2065374029-3886242179-1000_Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)

CustomCLSID: HKU\S-1-5-21-1394956801-2065374029-3886242179-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)

CustomCLSID: HKU\S-1-5-21-1394956801-2065374029-3886242179-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)

CustomCLSID: HKU\S-1-5-21-1394956801-2065374029-3886242179-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)

CustomCLSID: HKU\S-1-5-21-1394956801-2065374029-3886242179-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncApi64.dll (Microsoft Corporation)

 

==================== Restore Points =========================

 

26-08-2015 22:56:18 Norton_Power_Eraser_20150826225617944

 

==================== Hosts content: ===============================

 

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

 

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts

 

==================== Scheduled Tasks (Whitelisted) =============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

Task: {00EEBA9C-F9EF-4272-B793-C830FBADD359} - System32\Tasks\Microsoft\Windows\ApplicationData\DsSvcCleanup => C:\Windows\system32\dstokenclean.exe [2015-07-10] (Microsoft Corporation)

Task: {01252ED2-B1B5-43D7-A379-45FE9036AAD7} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe

Task: {02CFDE2A-D075-4526-B0E0-156D9D8930B5} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe

Task: {0550A230-30B7-43C8-B066-B0447B431D85} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe

Task: {080D4F7C-540F-4381-B6B8-C19DAC6D224B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-21] (Microsoft Corporation)

Task: {0843A2FF-F6C0-4F4A-A0F5-5F2E061FAF67} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe

Task: {0999BC8D-B743-47F4-8D23-6B37BE489C70} - \8573a892-e4b5-4e4d-b10a-9b0136cad0b0-10_user -> No File <==== ATTENTION

Task: {0CCA7916-2916-4F12-BD32-1E3BE31E1269} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Device-Join => C:\Windows\System32\dsregcmd.exe [2015-07-10] (Microsoft Corporation)

Task: {10EE38F6-9B0C-4A45-90E3-2D5B2BFB0A01} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe

Task: {131FD00E-EDDD-460B-AB0C-C026327559DF} - \8573a892-e4b5-4e4d-b10a-9b0136cad0b0-3 -> No File <==== ATTENTION

Task: {19865544-CE08-40BE-8B8C-87C47681433D} - System32\Tasks\Microsoft\Windows\WindowsUpdate\sihboot => C:\Windows\System32\sihclient.exe [2015-07-10] (Microsoft Corporation)

Task: {2468E951-53EB-4A44-8F28-B2607C09435C} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe

Task: {29E29F8E-92F7-4617-BC75-06792E01D24D} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION

Task: {2A10BE05-1194-4188-BE08-8F9D864B486C} - System32\Tasks\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-5_user => C:\Program Files (x86)\SmartSaver+ 3\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-5.exe <==== ATTENTION

Task: {37F1AFD9-D862-4CC1-98DE-D14252175D00} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe

Task: {394FAE3B-4366-4711-86DA-880291CD975A} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe

Task: {3BBFEB67-09C8-4073-BF20-C06BA089DA32} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION

Task: {3C8DEB4B-1D82-4996-991F-2B46B9C83E6D} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe

Task: {3CC601CC-FB93-49E9-991C-AF88942231DD} - System32\Tasks\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-1-7 => C:\Program Files (x86)\SmartSaver+ 3\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-1-7.exe <==== ATTENTION

Task: {3CE3C244-5E40-4323-8628-677F1F11BB13} - \globalUpdateUpdateTaskMachineCore -> No File <==== ATTENTION

Task: {3E0BACB7-DBB3-4C53-9895-0F4B6AD54A99} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe

Task: {3F6E048D-6404-433B-8F5F-CFF4D89BF89E} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => Rundll32.exe generaltel.dll,RunTelemetryW

Task: {41160EA0-208B-4C3E-B4DB-805BBABC6B93} - System32\Tasks\Microsoft\Windows\Feedback\Siuf\DmClient => C:\Windows\system32\dmclient.exe [2015-07-10] (Microsoft Corporation)

Task: {449D2131-DE4A-42BD-A6E6-D204EBC8EA6F} - \8573a892-e4b5-4e4d-b10a-9b0136cad0b0-7 -> No File <==== ATTENTION

Task: {46FDF814-7F36-4646-BD97-502B6113012B} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION

Task: {490A0505-41A3-48D2-9C65-9CA7F710BA6A} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe

Task: {50F8E166-2837-4374-958E-7E64A3392B1B} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION

Task: {530CF08D-6183-4685-932F-CAB80FA8A7D0} - System32\Tasks\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-5 => C:\Program Files (x86)\SmartSaver+ 3\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-5.exe <==== ATTENTION

Task: {537F5EE0-51A9-4DBB-8FBA-B900C980D424} - \AmiUpdXp -> No File <==== ATTENTION

Task: {54A4C0C7-2321-49CC-8EE8-332C911F099A} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe

Task: {5A78753B-6494-44B3-B452-9D078C90B02A} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION

Task: {6BA796DF-9F45-43C7-B343-B66452A11AB7} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe

Task: {70D68711-DA7C-4D88-AC29-69922F38D309} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION

Task: {73551810-E5F4-433E-9494-0D00B55C855E} - System32\Tasks\Microsoft\Windows\Maps\MapsToastTask

Task: {75A70746-8148-40B3-BF6F-47244924D316} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-23] (Google Inc.)

Task: {77C84E4D-AD57-46E5-9D4F-DC27DCA9638A} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe

Task: {78B77FA3-9D97-441D-97B6-68CEA40B4F74} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe generaltel.dll,RunTelemetry -maintenance

Task: {79BD7177-339D-4506-B34A-DA17C972840D} - \8573a892-e4b5-4e4d-b10a-9b0136cad0b0-1-6 -> No File <==== ATTENTION

Task: {8982802C-022A-4583-9160-96E0B3185367} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe

Task: {89B7BB24-0CEA-44E8-ACE3-4F75B41FAB34} - \globalUpdateUpdateTaskMachineUA -> No File <==== ATTENTION

Task: {8D9247B1-CC21-4CC1-89DA-5347C13A384C} - System32\Tasks\One System CarePeriod => C:\Program Files (x86)\OneSystemCare\OneSystemCare.exe

Task: {8DF84CB3-D8E0-4307-A35B-CA74E21786DB} - System32\Tasks\Microsoft\Windows\Clip\License Validation => C:\Windows\system32\ClipUp.exe [2015-08-10] (Microsoft Corporation)

Task: {8F338595-77E4-4BCC-9844-E815BB03F10C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION

Task: {8F4C3A2F-D807-437E-BAA4-10DF9721ED47} - \Microsoft\Windows\File Classification Infrastructure\Property Definition Sync -> No File <==== ATTENTION

Task: {931FF5AD-3039-4233-B34F-0B4EE99BF52C} - \8573a892-e4b5-4e4d-b10a-9b0136cad0b0-6 -> No File <==== ATTENTION

Task: {9A6849DE-B5D2-4646-8371-2777F51DA4F8} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe

Task: {A2570BF4-BDF0-4CAB-AA16-2054CE4CBAF4} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION

Task: {A5B6CD85-1B57-49B9-BA80-5D5D65F02826} - System32\Tasks\Microsoft\Windows\AppID\EDP Policy Manager

Task: {A9E76ECB-1DE7-4847-A90A-BF55ED4BA5F1} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe

Task: {AB6D0376-4D7F-43B8-82C6-E4BF5F65CF46} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION

Task: {B01693F0-0647-4F86-BB3D-411263CC5EC4} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe

Task: {C11267D7-C61A-4C4E-91FA-78E92FD4005F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-21] (Microsoft Corporation)

Task: {C56AFFD3-06B8-4A16-AF7E-F7A6EB3FAE9E} - System32\Tasks\Microsoft\Windows\TPM\Tpm-HASCertRetr

Task: {C5EE2EA2-5312-4D1F-B9D0-41B18DF31B78} - System32\Tasks\Microsoft\Windows\WindowsUpdate\sih => C:\Windows\System32\sihclient.exe [2015-07-10] (Microsoft Corporation)

Task: {C7A236B2-12E1-46DC-9501-3B1B0209CC09} - System32\Tasks\Microsoft\Windows\Location\WindowsActionDialog => C:\Windows\System32\WindowsActionDialog.exe [2015-07-10] (Microsoft Corporation)

Task: {CAD2AEFD-9817-42F7-829E-21C9621FB906} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)

Task: {CCCF07A6-CADA-4D5B-8BD9-D6C89A83D02A} - System32\Tasks\{72B56432-498F-4EFA-BF3D-DAE4E9CCAA92} => pcalua.exe -a "C:\Users\User\AppData\Roaming\Store\WindApp\WindApp Uninstall.exe" -c /cpanel=1

Task: {CF8BA5B0-73E4-4385-A8A0-2B2218F2E581} - System32\Tasks\LaunchPreSignup => C:\Program Files (x86)\OLBPre\OLBPre.exe <==== ATTENTION

Task: {D2464688-94AB-48BE-ACFE-528AFAFAED1A} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe

Task: {D3408DE8-6B9C-429C-A135-89245FFEAF23} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe

Task: {DACFF8DE-A100-49F3-BFE8-E0A65C68B7DF} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION

Task: {DF250A4D-8F2B-4FEF-B00F-C5EC145B736B} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe

Task: {E3ACACC0-3560-4BAE-B796-552F3CA20DAF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-23] (Google Inc.)

Task: {E9B52024-AAFD-41A0-AA2E-4AB0E2C3937A} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe

Task: {EBEC0615-2C1C-4683-8E46-699874520E11} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION

Task: {F3AF72F7-A8F2-4712-A6BE-0451351DFA9D} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe

Task: {FB1B44C6-6FDD-48F2-91B6-C1D02EBA04F8} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe

 

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

 

Task: C:\WINDOWS\Tasks\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-1-7.job => C:\Program Files (x86)\SmartSaver+ 3\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-1-7.exe <==== ATTENTION

Task: C:\WINDOWS\Tasks\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-5.job => C:\Program Files (x86)\SmartSaver+ 3\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-5.exe <==== ATTENTION

Task: C:\WINDOWS\Tasks\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-5_user.job => C:\Program Files (x86)\SmartSaver+ 3\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-5.exe <==== ATTENTION

Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Task: C:\WINDOWS\Tasks\One System CarePeriod.job => C:\Program Files (x86)\OneSystemCare\OneSystemCare.exe

==================== Loaded Modules (Whitelisted) ==============

2015-08-10 01:41 - 2015-08-10 01:41 - 00032768 _____ () C:\WINDOWS\SYSTEM32\licensemanagerapi.dll

2015-08-19 13:58 - 2015-08-11 10:14 - 00404480 _____ () C:\WINDOWS\System32\diagtrack_wininternal.dll

2015-05-15 16:26 - 2015-05-15 16:26 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll

2015-05-15 16:26 - 2015-05-15 16:26 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll

2015-08-10 19:44 - 2015-07-30 07:05 - 02498808 _____ () C:\WINDOWS\system32\CoreUIComponents.dll

2015-08-10 19:44 - 2015-07-30 07:05 - 02498808 _____ () C:\WINDOWS\System32\CoreUIComponents.dll

2015-06-16 16:31 - 2015-06-16 16:31 - 08898720 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll

2015-07-10 11:59 - 2015-07-10 11:59 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll

2015-08-12 10:48 - 2015-08-03 02:30 - 00642048 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\MtcUvc.dll

2015-08-12 10:48 - 2015-08-03 02:11 - 06569472 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll

2015-07-10 12:00 - 2015-07-10 14:14 - 00471040 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll

2015-08-19 13:58 - 2015-08-11 09:58 - 01808384 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll

2015-08-12 10:48 - 2015-08-03 02:09 - 02274816 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll

2015-06-01 21:00 - 2015-06-01 21:00 - 00102912 _____ () C:\WINDOWS\System32\IccLibDll_x64.dll

2015-08-26 23:39 - 2015-08-26 23:41 - 00007168 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.820.12440.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe

2015-08-26 23:39 - 2015-08-26 23:41 - 11603456 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.820.12440.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll

2015-07-10 14:17 - 2015-07-10 14:17 - 07897088 _____ () C:\Program Files\WindowsApps\Microsoft.NET.Native.Framework.1.0_1.0.22929.0_x64__8wekyb3d8bbwe\SharedLibrary.dll

2015-08-19 13:58 - 2015-08-11 10:10 - 00293376 _____ () C:\WINDOWS\SYSTEM32\textinputframework.dll

2015-04-22 17:20 - 2015-04-22 17:20 - 01754296 _____ () C:\Program Files (x86)\Microsoft Office\Office15\tmpod.dll

2014-01-23 07:55 - 2014-01-23 07:55 - 01030312 _____ () C:\Program Files (x86)\Microsoft Office\Office15\ADDINS\UmOutlookAddin.dll

 

==================== Alternate Data Streams (Whitelisted) =========

 

(If an entry is included in the fixlist, only the ADS will be removed.)

 

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys => ""="Driver"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ahcache.sys => ""="Driver"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CoreMessagingRegistrar => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\StateRepository => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TileDataModelSvc => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UserManager => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

 

==================== EXE Association (Whitelisted) ===============

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

 

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

 

==================== Other Areas ============================

 

(Currently there is no automatic fix for this section.)

 

HKU\S-1-5-21-1394956801-2065374029-3886242179-1000\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg

DNS Servers: 192.168.0.1

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)

Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

 

==================== FirewallRules (Whitelisted) ===============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139

FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppextcomobj.exe

FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppextcomobj.exe

FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe

FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe

FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe

FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe

FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808

FirewallRules: [{1C11066B-4073-4612-BA2A-EC5DCAC4FC1B}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe

FirewallRules: [{BC2E4312-EADB-4E81-A821-ECBB515CD54F}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe

FirewallRules: [{3B8461EF-88AA-4573-A618-31D4C97BBF8B}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe

FirewallRules: [{ECFD985E-512F-4972-921F-A25969490254}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe

FirewallRules: [{94F532A0-C8FB-4584-B0A5-6E65E92BDDFD}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe

FirewallRules: [UDP Query User{D643D4BC-DE2B-4BE1-B813-5F54080F1E49}E:\(sdi)\sdi.exe] => (Allow) E:\(sdi)\sdi.exe

FirewallRules: [TCP Query User{343782DD-3726-4949-B638-D0B5CD5C025B}E:\(sdi)\sdi.exe] => (Allow) E:\(sdi)\sdi.exe

FirewallRules: [{AD36E2C8-8C37-4F2E-B8B2-B6567DAEAFE0}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe

FirewallRules: [{8F2326E3-2A42-460C-B098-2411EFE2A28A}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe

FirewallRules: [{3A3067C1-2881-4449-BB07-31F93797C179}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe

FirewallRules: [{E69ACA0F-52E7-4B22-9A87-23DE43A83F0B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe

FirewallRules: [{7C9535A2-5BB8-41D3-B287-0FD6840366E9}] => (Allow) C:\Program Files\iTunes\iTunes.exe

FirewallRules: [{E93C9661-2D0D-4B13-AE4F-6495CD6DAC75}] => (Allow) C:\a\wincox.exe

FirewallRules: [{E2CFE847-7515-43EF-9E31-548DDF3373E0}] => (Allow) C:\a\wincox.exe

FirewallRules: [{41880748-78B6-4173-B159-FD26656ECB93}] => (Allow) C:\a\getcap.exe

FirewallRules: [{BD70661F-200D-47E4-A756-F9CB35DA5A16}] => (Allow) C:\a\getcap.exe

FirewallRules: [{A12C8C5E-7EE4-49EE-95E5-DF4B21507B49}] => (Allow) C:\a\wincheckfe.exe

FirewallRules: [{66E284EB-8077-44A4-A436-A4250894525B}] => (Allow) C:\a\wincheckfe.exe

FirewallRules: [{9A6C603D-74E9-416E-A6C8-7A2035D970E8}] => (Allow) C:\a\winonit.exe

FirewallRules: [{8A287C89-06CB-486A-9053-0CFD57E384E9}] => (Allow) C:\a\winonit.exe

FirewallRules: [{39E4B800-7B19-45F8-ADC3-F469D2B519F7}] => (Allow) C:\a\wcheckf.exe

FirewallRules: [{B7C87968-6CE9-466B-B2EF-FC7ED9BED5E0}] => (Allow) C:\a\wcheckf.exe

FirewallRules: [{2E0FE26C-FC8F-4557-8A65-46E4585F153B}] => (Allow) C:\a\vchk.exe

FirewallRules: [{3D9B29AE-62DB-471C-AD7F-BDAE2681621B}] => (Allow) C:\a\vchk.exe

FirewallRules: [{8184D1C4-6188-40C9-9D6F-F4A72D479C26}] => (Allow) C:\a\Cx43u4b3TclFsH28y536-ni-2015-08-24-ni-11954.exe

FirewallRules: [{717A6371-CD28-407F-93F0-67E89F32F13E}] => (Allow) C:\a\Cx43u4b3TclFsH28y536-ni-2015-08-24-ni-11954.exe

FirewallRules: [{CD5312D0-C59A-4B04-AE30-D9621796FE66}] => (Allow) C:\a\chromecheck.exe

FirewallRules: [{088017D7-202F-4A86-AA1C-1E4CBFF4BD34}] => (Allow) C:\a\chromecheck.exe

FirewallRules: [{64B9892D-B97A-4EE5-BDD7-9F2EA7EFCB7C}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

 

==================== Faulty Device Manager Devices =============

 

==================== Event log errors: =========================

Application errors:

==================

Error: (08/27/2015 07:59:51 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: OHub.exe, version: 16.0.6106.2350, time stamp: 0x55c40ea1

Faulting module name: ntdll.dll, version: 10.0.10240.16430, time stamp: 0x55c59f92

Exception code: 0xc0000374

Fault offset: 0x00000000000ea28c

Faulting process id: 0x110

Faulting application start time: 0xOHub.exe0

Faulting application path: OHub.exe1

Faulting module path: OHub.exe2

Report Id: OHub.exe3

Faulting package full name: OHub.exe4

Faulting package-relative application ID: OHub.exe5

 

Error: (08/27/2015 02:21:59 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: OHub.exe, version: 16.0.6106.2350, time stamp: 0x55c40ea1

Faulting module name: ntdll.dll, version: 10.0.10240.16430, time stamp: 0x55c59f92

Exception code: 0xc0000374

Fault offset: 0x00000000000ea28c

Faulting process id: 0x740

Faulting application start time: 0xOHub.exe0

Faulting application path: OHub.exe1

Faulting module path: OHub.exe2

Report Id: OHub.exe3

Faulting package full name: OHub.exe4

Faulting package-relative application ID: OHub.exe5

Error: (08/27/2015 02:15:37 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: OHub.exe, version: 16.0.6106.2350, time stamp: 0x55c40ea1

Faulting module name: ntdll.dll, version: 10.0.10240.16430, time stamp: 0x55c59f92

Exception code: 0xc0000374

Fault offset: 0x00000000000ea28c

Faulting process id: 0x6a8

Faulting application start time: 0xOHub.exe0

Faulting application path: OHub.exe1

Faulting module path: OHub.exe2

Report Id: OHub.exe3

Faulting package full name: OHub.exe4

Faulting package-relative application ID: OHub.exe5

 

Error: (08/27/2015 12:00:41 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: OHub.exe, version: 16.0.6106.2350, time stamp: 0x55c40ea1

Faulting module name: ntdll.dll, version: 10.0.10240.16430, time stamp: 0x55c59f92

Exception code: 0xc0000374

Fault offset: 0x00000000000ea28c

Faulting process id: 0x1944

Faulting application start time: 0xOHub.exe0

Faulting application path: OHub.exe1

Faulting module path: OHub.exe2

Report Id: OHub.exe3

Faulting package full name: OHub.exe4

Faulting package-relative application ID: OHub.exe5

Error: (08/26/2015 11:54:05 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: OHub.exe, version: 16.0.6106.2350, time stamp: 0x55c40ea1

Faulting module name: ntdll.dll, version: 10.0.10240.16430, time stamp: 0x55c59f92

Exception code: 0xc0000374

Fault offset: 0x00000000000ea28c

Faulting process id: 0x1728

Faulting application start time: 0xOHub.exe0

Faulting application path: OHub.exe1

Faulting module path: OHub.exe2

Report Id: OHub.exe3

Faulting package full name: OHub.exe4

Faulting package-relative application ID: OHub.exe5

 

Error: (08/26/2015 11:49:09 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: User-PC)

Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (08/26/2015 11:17:04 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: OHub.exe, version: 16.0.6106.2350, time stamp: 0x55c40ea1

Faulting module name: ntdll.dll, version: 10.0.10240.16430, time stamp: 0x55c59f92

Exception code: 0xc0000374

Fault offset: 0x00000000000ea28c

Faulting process id: 0x1af0

Faulting application start time: 0xOHub.exe0

Faulting application path: OHub.exe1

Faulting module path: OHub.exe2

Report Id: OHub.exe3

Faulting package full name: OHub.exe4

Faulting package-relative application ID: OHub.exe5

 

Error: (08/26/2015 11:09:53 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: User-PC)

Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (08/26/2015 11:05:43 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: OHub.exe, version: 16.0.6106.2350, time stamp: 0x55c40ea1

Faulting module name: ntdll.dll, version: 10.0.10240.16430, time stamp: 0x55c59f92

Exception code: 0xc0000374

Fault offset: 0x00000000000ea28c

Faulting process id: 0x17ac

Faulting application start time: 0xOHub.exe0

Faulting application path: OHub.exe1

Faulting module path: OHub.exe2

Report Id: OHub.exe3

Faulting package full name: OHub.exe4

Faulting package-relative application ID: OHub.exe5

 

Error: (08/26/2015 10:56:25 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )

Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:

AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

 

System Error:

Access is denied.

.

 

System errors:

=============

Error: (08/27/2015 07:55:57 AM) (Source: Service Control Manager) (EventID: 7001) (User: )

Description: The Net.Tcp Listener Adapter service depends on the Net.Tcp Port Sharing Service service which failed to start because of the following error:

%%1058

Error: (08/27/2015 07:52:58 AM) (Source: Service Control Manager) (EventID: 7001) (User: )

Description: The Net.Tcp Listener Adapter service depends on the Net.Tcp Port Sharing Service service which failed to start because of the following error:

%%1058

Error: (08/27/2015 07:49:02 AM) (Source: Service Control Manager) (EventID: 7001) (User: )

Description: The Net.Tcp Listener Adapter service depends on the Net.Tcp Port Sharing Service service which failed to start because of the following error:

%%1058

Error: (08/27/2015 07:48:18 AM) (Source: Service Control Manager) (EventID: 7031) (User: )

Description: The User Data Access_Session1 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.

 

Error: (08/27/2015 07:48:18 AM) (Source: Service Control Manager) (EventID: 7031) (User: )

Description: The User Data Storage_Session1 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.

Error: (08/27/2015 07:48:18 AM) (Source: Service Control Manager) (EventID: 7031) (User: )

Description: The Contact Data_Session1 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.

 

Error: (08/27/2015 07:48:18 AM) (Source: Service Control Manager) (EventID: 7031) (User: )

Description: The Sync Host_Session1 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.

Error: (08/27/2015 02:30:54 AM) (Source: Service Control Manager) (EventID: 7011) (User: )

Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WinDefend service.

 

Error: (08/27/2015 02:30:21 AM) (Source: Service Control Manager) (EventID: 7011) (User: )

Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WinDefend service.

Error: (08/27/2015 02:17:47 AM) (Source: Service Control Manager) (EventID: 7001) (User: )

Description: The Net.Tcp Listener Adapter service depends on the Net.Tcp Port Sharing Service service which failed to start because of the following error:

%%1058

 

Microsoft Office:

=========================

Error: (08/27/2015 07:59:51 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: OHub.exe16.0.6106.235055c40ea1ntdll.dll10.0.10240.1643055c59f92c000037400000000000ea28c11001d0e095ef794b6bC:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.6106.23501.0_x64__8wekyb3d8bbwe\OHub.exeC:\WINDOWS\SYSTEM32\ntdll.dll4af37651-6cce-4c9f-9f38-e1f8c53dadf6Microsoft.MicrosoftOfficeHub_17.6106.23501.0_x64__8wekyb3d8bbweMicrosoft.MicrosoftOfficeHub

Error: (08/27/2015 02:21:59 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: OHub.exe16.0.6106.235055c40ea1ntdll.dll10.0.10240.1643055c59f92c000037400000000000ea28c74001d0e066bb6d3355C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.6106.23501.0_x64__8wekyb3d8bbwe\OHub.exeC:\WINDOWS\SYSTEM32\ntdll.dll4e0973e8-8d86-429f-b275-f68311c7219fMicrosoft.MicrosoftOfficeHub_17.6106.23501.0_x64__8wekyb3d8bbweMicrosoft.MicrosoftOfficeHub

 

Error: (08/27/2015 02:15:37 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: OHub.exe16.0.6106.235055c40ea1ntdll.dll10.0.10240.1643055c59f92c000037400000000000ea28c6a801d0e065d583bc2eC:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.6106.23501.0_x64__8wekyb3d8bbwe\OHub.exeC:\WINDOWS\SYSTEM32\ntdll.dlld953720c-9136-4c46-9b25-b3cac2100152Microsoft.MicrosoftOfficeHub_17.6106.23501.0_x64__8wekyb3d8bbweMicrosoft.MicrosoftOfficeHub

Error: (08/27/2015 12:00:41 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: OHub.exe16.0.6106.235055c40ea1ntdll.dll10.0.10240.1643055c59f92c000037400000000000ea28c194401d0e052f95f2057C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.6106.23501.0_x64__8wekyb3d8bbwe\OHub.exeC:\WINDOWS\SYSTEM32\ntdll.dllcfffc4e3-aa90-493f-98f5-e299d848cac6Microsoft.MicrosoftOfficeHub_17.6106.23501.0_x64__8wekyb3d8bbweMicrosoft.MicrosoftOfficeHub

 

Error: (08/26/2015 11:54:05 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: OHub.exe16.0.6106.235055c40ea1ntdll.dll10.0.10240.1643055c59f92c000037400000000000ea28c172801d0e0520da9747dC:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.6106.23501.0_x64__8wekyb3d8bbwe\OHub.exeC:\WINDOWS\SYSTEM32\ntdll.dll0a93416c-2d62-4746-b76d-63412b08b118Microsoft.MicrosoftOfficeHub_17.6106.23501.0_x64__8wekyb3d8bbweMicrosoft.MicrosoftOfficeHub

Error: (08/26/2015 11:49:09 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: User-PC)

Description: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI-2144927141

 

Error: (08/26/2015 11:17:04 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: OHub.exe16.0.6106.235055c40ea1ntdll.dll10.0.10240.1643055c59f92c000037400000000000ea28c1af001d0e04ce269af5bC:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.6106.23501.0_x64__8wekyb3d8bbwe\OHub.exeC:\WINDOWS\SYSTEM32\ntdll.dllfd8b063a-2139-48c1-82a4-1e1abec7e328Microsoft.MicrosoftOfficeHub_17.6106.23501.0_x64__8wekyb3d8bbweMicrosoft.MicrosoftOfficeHub

Error: (08/26/2015 11:09:53 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: User-PC)

Description: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI-2144927141

 

Error: (08/26/2015 11:05:43 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: OHub.exe16.0.6106.235055c40ea1ntdll.dll10.0.10240.1643055c59f92c000037400000000000ea28c17ac01d0e04b4f0926b1C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.6106.23501.0_x64__8wekyb3d8bbwe\OHub.exeC:\WINDOWS\SYSTEM32\ntdll.dllee51f0fd-9b34-4f68-bc37-6ed29f65d6c1Microsoft.MicrosoftOfficeHub_17.6106.23501.0_x64__8wekyb3d8bbweMicrosoft.MicrosoftOfficeHub

Error: (08/26/2015 10:56:25 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )

Description: Details:

AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:

Access is denied.

 

CodeIntegrity:

===================================

  Date: 2015-08-27 15:04:30.455

  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

 

  Date: 2015-08-27 02:35:44.320

  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\WINDOWS\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

  Date: 2015-08-27 02:35:44.267

  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\WINDOWS\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

 

  Date: 2015-08-27 02:35:44.215

  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\WINDOWS\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

  Date: 2015-08-27 02:35:44.101

  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\WINDOWS\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

 

  Date: 2015-08-27 02:35:44.068

  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\WINDOWS\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

  Date: 2015-08-27 02:35:44.023

  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\WINDOWS\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

 

  Date: 2015-08-27 02:35:42.103

  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\WINDOWS\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

  Date: 2015-08-27 02:35:41.845

  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\WINDOWS\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

 

  Date: 2015-08-27 02:33:48.076

  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\WINDOWS\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

 

==================== Memory info ===========================

 

Processor: Intel® Core™ i5-2520M CPU @ 2.50GHz

Percentage of memory in use: 58%

Total physical RAM: 3992.93 MB

Available physical RAM: 1658.99 MB

Total Virtual: 8088.93 MB

Available Virtual: 5697.5 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:232.35 GB) (Free:193.01 GB) NTFS

Drive e: () (Removable) (Total:14.63 GB) (Free:9.6 GB) FAT32

 

==================== MBR & Partition Table ==================

 

========================================================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: D2CBE7D4)

Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)

Partition 2: (Not Active) - (Size=232.3 GB) - (Type=07 NTFS)

Partition 3: (Not Active) - (Size=450 MB) - (Type=27)

 

========================================================

Disk: 1 (Size: 14.6 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt ============================



#4 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,078 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:12:38 AM

Posted 29 August 2015 - 06:16 AM

Hi Henniee,
 
We need to run a fix with FRST:

  • Press the windows key Windows_Logo_key.gif + r on your keyboard at the same time. Type in notepad and press Enter.
  • Copy and paste the script below in the notepad document:​
globalupdate Helper (x32 Version: 1.3.25.0 - globalupdate Inc.) Hidden <==== ATTENTION
  • Save the file to your desktop and name it as fixlist.txt

Note: It's important that both files, FRST.exe/FRST64.exe and fixlist.txt are in the same location or the fix will not work
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

  • Run FRST.exe/FRST64.exe and press the Fix button just once and wait
  • If for some reason the tool needs a restart, please make sure you let the system restart normally, then let the tool complete its run

--------------
 
We need to remove programs using "Programs and Features"

Open Computer and click on the "Computer" tab, then click on Uninstall or Change a Program.

A list of programs installed will be "populated" (this may take a bit of time).
If they exist, uninstall the following by clicking the below entries and selecting "Remove":

globalupdate Helper
SmartSaver+ 3
Software Version Updater

Additional instructions can be found here if needed.
 
--------------
 
Please download AdwCleaner by Xplode and save to your Desktop.

  • Double click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator
  • The tool will start to update the database, please wait a bit.
  • Click on I agree button.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

xXToffeeXx~


~If I am helping you and you have not had a reply from me in two days, please send me a PM~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


#5 Henniee

Henniee
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:11:38 PM

Posted 29 August 2015 - 03:01 PM

# AdwCleaner v5.004 - Logfile created 29/08/2015 at 20:14:00
# Updated 26/08/2015 by Xplode
# Database : 2015-08-25.1 [Server]
# Operating system : Windows 10 Pro  (x64)
# Username : User - USER-PC
# Running from : C:\Users\User\Desktop\adwcleaner_5.004.exe
# Option : Cleaning
 
 [ Services ] 
 
 
 [ Folders ] 
 
 
 [ Files ] 
 
[-] File Deleted : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_ekpibplnnkfdcafdpoekhoffegcajene_0
[-] File Deleted : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ekpibplnnkfdcafdpoekhoffegcajene
 
 [ Shortcuts ] 
 
 
 [ Scheduled tasks ] 
 
 
 [ Registry ] 
 
 
 [ Web browsers ] 
 
 
*************************
 
:: Winsock settings cleared
 
########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [882 bytes] ##########


#6 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,078 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:12:38 AM

Posted 29 August 2015 - 03:17 PM

Hi Henniee,

 

Please re-run FRST from the desktop (like you did before), put a check into the box next to Addition.txt and press the scan button. It will produce FRST.txt and Addition.txt logs located on the desktop. Please copy and paste the logs into your next reply.

 

xXToffeeXx~


~If I am helping you and you have not had a reply from me in two days, please send me a PM~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


#7 Henniee

Henniee
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:11:38 PM

Posted 01 September 2015 - 04:24 PM

sorry it says the post is too long, i am attacking the file

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:27-08-2015
Ran by User (administrator) on USER-PC (30-08-2015 10:55:24)
Running from C:\Users\User\Desktop
Loaded Profiles: User (Available Profiles: User & DefaultAppPool)
Platform: Windows 10 Pro (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidMonitorSvc.exe
(Broadcom Corporation.) C:\WINDOWS\System32\BtwRSupportService.exe
(Microsoft Corporation) C:\WINDOWS\System32\mqsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(O2Micro International) C:\WINDOWS\System32\drivers\o2flash.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(Microsoft Corporation) C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
(Microsoft Corporation) C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
(Intel Corporation) C:\WINDOWS\System32\igfxtray.exe
(Intel Corporation) C:\WINDOWS\System32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\System32\igfxpers.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Microsoft Corporation) C:\Users\User\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\WINDOWS\System32\SppExtComObj.Exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.827.16340.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6120.42011.0_x64__8wekyb3d8bbwe\HxMail.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6120.42011.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Corporation) C:\WINDOWS\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16464_none_116100d161f6ab1d\TiWorker.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [727896 2014-03-13] (Alps Electric Co., Ltd.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170280 2015-07-11] (Apple Inc.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-25] (IDT, Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-19\...\Run: [OneDriveSetup] => C:\Windows\SysWOW64\OneDriveSetup.exe [7805120 2015-07-10] (Microsoft Corporation)
HKU\S-1-5-20\...\Run: [OneDriveSetup] => C:\Windows\SysWOW64\OneDriveSetup.exe [7805120 2015-07-10] (Microsoft Corporation)
HKU\S-1-5-21-1394956801-2065374029-3886242179-1000\...\Run: [OneDrive] => C:\Users\User\AppData\Local\Microsoft\OneDrive\OneDrive.exe [404064 2015-08-24] (Microsoft Corporation)
HKU\S-1-5-21-1394956801-2065374029-3886242179-1000\...\Run: [Lync] => C:\Program Files (x86)\Microsoft Office\Office15\lync.exe [24107176 2015-07-14] (Microsoft Corporation)
GroupPolicyScripts: Group Policy detected <======= ATTENTION
GroupPolicyScripts\User: Group Policy detected <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1394956801-2065374029-3886242179-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings: [ProxySettingsPerUser] 1 <======= ATTENTION (Policy restriction on ProxySettings)
ProxyEnable: [HKLM] => Proxy is enabled.
ProxyEnable: [HKLM-x32] => Proxy is enabled.
ProxyServer: [HKLM] => http=127.0.0.1:8877;https=127.0.0.1:8877
ProxyServer: [HKLM-x32] => http=127.0.0.1:8877;https=127.0.0.1:8877
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
HKU\S-1-5-21-1394956801-2065374029-3886242179-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
HKU\S-1-5-21-1394956801-2065374029-3886242179-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/en-gb/?ocid=iehp
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-07-14] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-07-14] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-07-14] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-07-14] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{bcce3918-b299-42e3-b3b1-7417ac10c904}: [DhcpNameServer] 192.168.0.1
 
FireFox:
========
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-04-22] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-28] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-04-22] (Microsoft Corporation)
 
Chrome: 
=======
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-07-23]
CHR Extension: (Google Docs) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-07-23]
CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-07-23]
CHR Extension: (Rapport) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjllphbppobebmjpjcijfbakobcheof [2015-08-08]
CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-07-23]
CHR Extension: (Google Search) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-07-23]
CHR Extension: (Google Play Music) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2015-07-23]
CHR Extension: (Google Sheets) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-07-23]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-08-08]
CHR Extension: (Chrome Web Store Payments) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-28]
CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-23]
CHR HKU\S-1-5-21-1394956801-2065374029-3886242179-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bbjllphbppobebmjpjcijfbakobcheof] - https://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 ApHidMonitorService; C:\Program Files\DellTPad\HidMonitorSvc.exe [87384 2014-03-27] (Alps Electric Co., Ltd.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2255064 2013-10-28] (Broadcom Corporation.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [326144 2015-07-10] (Microsoft Corporation)
S3 CDPSvc; C:\Windows\System32\CDPSvc.dll [134144 2015-07-10] (Microsoft Corporation)
R2 CoreMessagingRegistrar; C:\Windows\system32\coremessaging.dll [808856 2015-08-10] (Microsoft Corporation)
R2 CoreMessagingRegistrar; C:\Windows\SysWOW64\coremessaging.dll [510976 2015-08-10] (Microsoft Corporation)
S3 diagnosticshub.standardcollector.service; C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [27136 2015-07-10] (Microsoft Corporation)
S3 DmEnrollmentSvc; C:\Windows\system32\Windows.Internal.Management.dll [267776 2015-07-10] (Microsoft Corporation)
S3 DmEnrollmentSvc; C:\Windows\SysWOW64\Windows.Internal.Management.dll [193024 2015-07-10] (Microsoft Corporation)
S3 embeddedmode; C:\Windows\System32\embeddedmodesvc.dll [87040 2015-07-10] (Microsoft Corporation)
S3 EntAppSvc; C:\Windows\system32\EnterpriseAppMgmtSvc.dll [275456 2015-07-10] (Microsoft Corporation)
S3 icssvc; C:\Windows\System32\tetheringservice.dll [148992 2015-08-11] (Microsoft Corporation)
S3 lfsvc; C:\Windows\SysWOW64\lfsvc.dll [22528 2015-07-10] (Microsoft Corporation)
R3 LicenseManager; C:\Windows\system32\LicenseManagerSvc.dll [21504 2015-07-10] (Microsoft Corporation)
S2 MapsBroker; C:\Windows\System32\moshost.dll [62464 2015-07-10] (Microsoft Corporation)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [26112 2015-08-10] (Microsoft Corporation)
S2 OneSyncSvc; C:\Windows\System32\APHostService.dll [296960 2015-07-10] (Microsoft Corporation)
R2 OneSyncSvc_Session1; C:\WINDOWS\system32\svchost.exe [39856 2015-07-10] (Microsoft Corporation)
R2 OneSyncSvc_Session1; C:\WINDOWS\SysWOW64\svchost.exe [35176 2015-07-10] (Microsoft Corporation)
S3 PimIndexMaintenanceSvc; C:\Windows\System32\PimIndexMaintenance.dll [289280 2015-07-10] (Microsoft Corporation)
R3 PimIndexMaintenanceSvc_Session1; C:\WINDOWS\system32\svchost.exe [39856 2015-07-10] (Microsoft Corporation)
R3 PimIndexMaintenanceSvc_Session1; C:\WINDOWS\SysWOW64\svchost.exe [35176 2015-07-10] (Microsoft Corporation)
S3 RetailDemo; C:\Windows\system32\RDXService.dll [996352 2015-08-11] (Microsoft Corporation)
S3 SensorDataService; C:\Windows\System32\SensorDataService.exe [1031680 2015-08-10] (Microsoft Corporation)
R3 StateRepository; C:\Windows\system32\windows.staterepository.dll [2674176 2015-07-10] (Microsoft Corporation)
R3 StateRepository; C:\Windows\SysWOW64\windows.staterepository.dll [2049024 2015-07-10] (Microsoft Corporation)
S3 UnistoreSvc; C:\Windows\System32\unistore.dll [1203200 2015-08-10] (Microsoft Corporation)
S3 UnistoreSvc; C:\Windows\SysWOW64\unistore.dll [925696 2015-08-10] (Microsoft Corporation)
R3 UnistoreSvc_Session1; C:\WINDOWS\System32\svchost.exe [39856 2015-07-10] (Microsoft Corporation)
R3 UnistoreSvc_Session1; C:\WINDOWS\SysWOW64\svchost.exe [35176 2015-07-10] (Microsoft Corporation)
S3 UserDataSvc; C:\Windows\System32\userdataservice.dll [1420288 2015-07-30] (Microsoft Corporation)
R3 UserDataSvc_Session1; C:\WINDOWS\system32\svchost.exe [39856 2015-07-10] (Microsoft Corporation)
R3 UserDataSvc_Session1; C:\WINDOWS\SysWOW64\svchost.exe [35176 2015-07-10] (Microsoft Corporation)
S3 vmicvmsession; C:\Windows\System32\ICSvc.dll [506880 2015-07-10] (Microsoft Corporation)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [84480 2015-08-10] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [578560 2015-08-10] (Microsoft Corporation)
S3 WalletService; C:\Windows\system32\WalletService.dll [504320 2015-07-10] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
S3 XblAuthManager; C:\Windows\System32\XblAuthManager.dll [918016 2015-07-10] (Microsoft Corporation)
S3 XblGameSave; C:\Windows\System32\XblGameSave.dll [1149440 2015-07-10] (Microsoft Corporation)
S3 XboxNetApiSvc; C:\Windows\system32\XboxNetApiSvc.dll [1019392 2015-07-10] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-10-28] (Broadcom Corporation.)
R3 CompositeBus; C:\Windows\System32\DriverStore\FileRepository\compositebus.inf_amd64_98334ba6e76853ba\CompositeBus.sys [39936 2015-07-10] (Microsoft Corporation)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3436896 2015-07-10] (QLogic Corporation)
R1 FileCrypt; C:\Windows\System32\drivers\filecrypt.sys [83968 2015-07-10] (Microsoft Corporation)
S3 genericusbfn; C:\Windows\System32\drivers\genericusbfn.sys [20992 2015-07-10] (Microsoft Corporation)
R1 GpuEnergyDrv; C:\Windows\System32\drivers\gpuenergydrv.sys [8192 2015-07-10] (Microsoft Corporation)
S3 ibbus; C:\Windows\System32\drivers\ibbus.sys [424800 2015-07-10] (Mellanox)
S3 IoQos; C:\Windows\System32\drivers\ioqos.sys [26624 2015-07-10] (Microsoft Corporation)
S0 LSI_SAS3i; C:\Windows\System32\drivers\lsi_sas3i.sys [99168 2015-07-10] (Avago Technologies)
S3 mlx4_bus; C:\Windows\System32\drivers\mlx4_bus.sys [705376 2015-07-10] (Mellanox)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [175104 2015-08-10] (Microsoft Corporation)
S3 ndfltr; C:\Windows\System32\drivers\ndfltr.sys [76128 2015-07-10] (Mellanox)
R3 NETwNe64; C:\Windows\System32\drivers\NETwew01.sys [3354384 2015-07-10] (Intel Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33448 2015-03-20] (Synaptics Incorporated)
R2 storqosflt; C:\Windows\System32\drivers\storqosflt.sys [61952 2015-07-10] (Microsoft Corporation)
R3 ST_Accel; C:\Windows\system32\DRIVERS\ST_Accel.sys [73928 2013-11-21] (STMicroelectronics)
R3 swenum; C:\Windows\System32\DriverStore\FileRepository\swenum.inf_amd64_2a699e44676b7781\swenum.sys [17760 2015-07-10] (Microsoft Corporation)
S3 UcmCx0101; C:\Windows\System32\Drivers\UcmCx.sys [61952 2015-07-10] (Microsoft Corporation)
S3 UcmUcsi; C:\Windows\System32\drivers\UcmUcsi.sys [46080 2015-08-10] (Microsoft Corporation)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
R0 WindowsTrustedRT; C:\Windows\System32\drivers\WindowsTrustedRT.sys [106520 2015-07-10] (Microsoft Corporation)
R0 WindowsTrustedRTProxy; C:\Windows\System32\drivers\WindowsTrustedRTProxy.sys [17944 2015-07-10] (Microsoft Corporation)
S3 WinMad; C:\Windows\System32\drivers\winmad.sys [26976 2015-07-10] (Mellanox)
S3 WinVerbs; C:\Windows\System32\drivers\winverbs.sys [59232 2015-07-10] (Mellanox)
S3 xboxgip; C:\Windows\System32\drivers\xboxgip.sys [222720 2015-07-10] (Microsoft Corporation)
S3 xinputhid; C:\Windows\System32\drivers\xinputhid.sys [25600 2015-07-10] (Microsoft Corporation)
U3 idsvc; no ImagePath
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-30 10:55 - 2015-08-30 10:56 - 00017573 _____ C:\Users\User\Desktop\FRST.txt
2015-08-30 10:54 - 2015-08-30 10:54 - 00016148 _____ C:\WINDOWS\system32\USER-PC_User_HistoryPrediction.bin
2015-08-29 20:06 - 2015-08-29 20:14 - 00000000 ____D C:\AdwCleaner
2015-08-29 20:06 - 2015-08-29 20:06 - 01618432 _____ C:\Users\User\Desktop\adwcleaner_5.004.exe
2015-08-29 20:01 - 2015-08-29 20:01 - 02186752 _____ (Farbar) C:\Users\User\Desktop\FRST64.exe
2015-08-29 19:57 - 2015-08-29 19:57 - 00000000 ___HD C:\OneDriveTemp
2015-08-28 16:45 - 2015-08-19 05:50 - 00609592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2015-08-27 22:09 - 2015-08-30 10:55 - 00000000 ____D C:\FRST
2015-08-27 22:09 - 2015-08-27 22:11 - 00000000 ____D C:\Security
2015-08-27 22:08 - 2015-08-27 22:08 - 02186752 _____ (Farbar) C:\Users\User\Downloads\FRST64.exe
2015-08-27 08:00 - 2015-08-27 08:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-08-26 23:42 - 2015-08-26 23:56 - 00000004 _____ C:\WINDOWS\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-08-26 23:42 - 2015-08-26 23:42 - 00000000 ____D C:\Program Files (x86)\e315fa42-f04d-4036-8ae9-d3eb41dc5bf9
2015-08-26 23:14 - 2015-08-29 21:11 - 00004150 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{35D4F0C9-276E-43E9-9B33-72962D950766}
2015-08-26 22:51 - 2015-08-27 02:18 - 00000000 ____D C:\NPE
2015-08-26 22:42 - 2015-08-29 20:57 - 00000000 ____D C:\Users\User\AppData\Local\CrashDumps
2015-08-26 22:35 - 2015-08-26 22:37 - 00000000 ____D C:\Users\User\Desktop\backups
2015-08-26 22:29 - 2015-08-26 22:30 - 02494560 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HousecallLauncher64 (3).exe
2015-08-26 22:18 - 2015-08-26 22:18 - 02494560 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HousecallLauncher64 (2).exe
2015-08-26 22:18 - 2015-08-26 22:18 - 02494560 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HousecallLauncher64 (1).exe
2015-08-26 22:17 - 2015-08-26 22:17 - 00388608 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HijackThis (1).exe
2015-08-26 22:17 - 2015-08-26 22:15 - 00388608 _____ (Trend Micro Inc.) C:\Users\User\Desktop\HijackThis.exe
2015-08-26 22:15 - 2015-08-26 22:15 - 00388608 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HijackThis.exe
2015-08-26 22:11 - 2015-08-26 22:11 - 01618432 _____ C:\Users\User\Downloads\adwcleaner_5.004.exe
2015-08-26 22:06 - 2015-08-27 07:57 - 00000000 ____D C:\Users\User\AppData\Local\NPE
2015-08-26 22:06 - 2015-08-26 22:06 - 03088296 _____ (Symantec Corporation) C:\Users\User\Downloads\NPE.exe
2015-08-26 22:06 - 2015-08-26 22:06 - 00000000 ____D C:\ProgramData\Norton
2015-08-25 20:43 - 2015-08-25 20:43 - 02073112 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HousecallLauncher.exe
2015-08-25 20:43 - 2015-08-25 20:43 - 02073112 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HousecallLauncher (1).exe
2015-08-25 17:01 - 2015-08-25 17:01 - 00000000 _____ C:\Recovery.txt
2015-08-25 09:46 - 2015-08-25 09:46 - 00000000 ____D C:\Recovery
2015-08-25 09:21 - 2015-08-25 09:43 - 00000000 ___HD C:\$Windows.~BT
2015-08-25 08:16 - 2015-08-26 22:36 - 00498461 _____ C:\Users\User\AppData\Local\census.cache
2015-08-25 08:16 - 2015-08-26 22:35 - 00180062 _____ C:\Users\User\AppData\Local\ars.cache
2015-08-25 08:12 - 2015-08-26 22:27 - 00000010 _____ C:\Users\User\AppData\Local\sponge.last.runtime.cache
2015-08-25 08:07 - 2015-08-25 08:07 - 00000036 _____ C:\Users\User\AppData\Local\housecall.guid.cache
2015-08-25 08:06 - 2015-08-25 08:07 - 02494560 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HousecallLauncher64.exe
2015-08-25 00:18 - 2015-08-25 00:18 - 00000000 ____D C:\WINDOWS\system32\appmgmt
2015-08-24 21:32 - 2015-08-26 23:09 - 00000008 __RSH C:\ProgramData\ntuser.pol
2015-08-24 21:16 - 2015-08-24 21:17 - 14243008 _____ (Microsoft Corporation) C:\Users\User\Downloads\mseinstall (1).exe
2015-08-24 21:11 - 2015-08-24 21:11 - 14243008 _____ (Microsoft Corporation) C:\Users\User\Downloads\mseinstall.exe
2015-08-24 21:11 - 2015-08-24 21:11 - 00000000 ____D C:\c8fdacbef381ec7fe3
2015-08-24 17:54 - 2015-08-24 17:54 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2015-08-24 17:02 - 2015-08-24 17:02 - 00003302 _____ C:\WINDOWS\System32\Tasks\{72B56432-498F-4EFA-BF3D-DAE4E9CCAA92}
2015-08-24 17:00 - 2015-08-24 17:00 - 00000020 ___SH C:\Users\DefaultAppPool\ntuser.ini
2015-08-24 17:00 - 2015-08-24 17:00 - 00000000 ____D C:\Users\DefaultAppPool
2015-08-24 17:00 - 2015-08-12 13:26 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Local\Trusteer
2015-08-24 17:00 - 2015-08-12 13:19 - 00000000 ___RD C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-24 17:00 - 2015-08-09 16:56 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Local\Microsoft Help
2015-08-24 17:00 - 2015-07-10 12:04 - 00000000 __RSD C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-08-24 17:00 - 2015-07-10 12:04 - 00000000 ___RD C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-24 17:00 - 2015-07-10 12:04 - 00000000 ___RD C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-24 17:00 - 2015-07-10 12:04 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-24 16:52 - 2015-08-26 23:21 - 00002226 _____ C:\Users\User\Desktop\Google Chrome.lnk
2015-08-24 07:55 - 2015-08-26 23:02 - 00000000 ___HD C:\a
2015-08-24 07:55 - 2015-08-24 17:02 - 00000000 ____D C:\Program Files (x86)\FastInternet
2015-08-24 07:45 - 2015-08-24 07:45 - 00000019 _____ C:\WINDOWS\SysWOW64\19262648.bat
2015-08-20 12:01 - 2015-08-20 12:01 - 00000918 _____ C:\WINDOWS\SysWOW64\${LOGFILE}
2015-08-20 11:53 - 2015-08-24 07:48 - 00000000 ____D C:\ProgramData\Cegeespe
2015-08-20 11:43 - 2015-08-20 11:43 - 00000000 ____D C:\Users\User\AppData\Local\Adobe
2015-08-20 09:54 - 2015-08-20 09:55 - 00000348 _____ C:\WINDOWS\BRRBCOM.INI
2015-08-20 09:54 - 2015-08-20 09:54 - 00000000 ____D C:\ProgramData\Brother
2015-08-20 09:53 - 2015-08-20 09:53 - 00224256 _____ (Brother Industries, Ltd.) C:\WINDOWS\system32\BRCOC12A.DLL
2015-08-20 09:53 - 2015-08-20 09:53 - 00180224 _____ (Brother Industries, Ltd.) C:\WINDOWS\SysWOW64\BROSNMP.DLL
2015-08-20 09:53 - 2015-08-20 09:53 - 00136456 _____ (Brother Industries Ltd) C:\WINDOWS\SysWOW64\BRRBTOOL.EXE
2015-08-20 09:53 - 2015-08-20 09:53 - 00077824 _____ (Brother Industries, Ltd.) C:\WINDOWS\SysWOW64\BRLMW03A.DLL
2015-08-20 09:53 - 2015-08-20 09:53 - 00045056 _____ C:\WINDOWS\SysWOW64\BRTCPCON.DLL
2015-08-20 09:53 - 2015-08-20 09:53 - 00025299 _____ (Brother Industries, Ltd) C:\WINDOWS\SysWOW64\BRLM03A.DLL
2015-08-20 09:53 - 2015-08-20 09:53 - 00000114 _____ C:\WINDOWS\SysWOW64\BRLMW03A.INI
2015-08-20 09:53 - 2015-08-20 09:53 - 00000050 _____ C:\WINDOWS\system32\BRADC12A.DAT
2015-08-19 14:15 - 2015-08-19 14:16 - 00000000 ____D C:\Program Files\IDT
2015-08-19 14:15 - 2015-08-19 14:15 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-08-19 14:15 - 2011-01-25 02:57 - 11941376 _____ (IDT, Inc.) C:\WINDOWS\system32\idtsg64.cpl
2015-08-19 14:15 - 2011-01-25 02:57 - 04637184 _____ (IDT, Inc.) C:\WINDOWS\system32\stlang64.dll
2015-08-19 14:15 - 2011-01-25 02:57 - 01499136 _____ (IDT, Inc.) C:\WINDOWS\system32\stapo64.dll
2015-08-19 14:15 - 2011-01-25 02:57 - 00651776 ____N (IDT, Inc.) C:\WINDOWS\system32\stapi64.dll
2015-08-19 14:15 - 2011-01-25 02:57 - 00520192 _____ (IDT, Inc.) C:\WINDOWS\system32\Drivers\stwrt64.sys
2015-08-19 14:15 - 2011-01-25 02:57 - 00431616 _____ (IDT, Inc.) C:\WINDOWS\system32\stcplx64.dll
2015-08-19 14:15 - 2011-01-25 02:57 - 00220160 _____ (IDT, Inc.) C:\WINDOWS\system32\st646324.dll
2015-08-19 14:15 - 2010-01-27 03:30 - 00162816 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AESTAC64.dll
2015-08-19 14:15 - 2009-10-10 00:45 - 00442368 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AESTEC64.dll
2015-08-19 14:15 - 2009-03-03 02:58 - 00068608 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AESTAR64.dll
2015-08-19 14:14 - 2015-08-19 14:14 - 28859960 _____ (Dell Inc.) C:\Users\User\Downloads\DRVR_WIN_R297613 (1).EXE
2015-08-19 14:14 - 2015-08-19 14:14 - 03081720 _____ C:\Users\User\Downloads\E5520A14.exe
2015-08-19 14:13 - 2015-08-19 14:13 - 28859960 _____ (Dell Inc.) C:\Users\User\Downloads\DRVR_WIN_R297613.EXE
2015-08-19 14:13 - 2015-08-19 14:13 - 00000000 ____D C:\Users\User\AppData\Local\Dell
2015-08-19 14:11 - 2015-08-24 17:09 - 00000000 ____D C:\Users\User\AppData\Local\Deployment
2015-08-19 14:11 - 2015-08-19 14:11 - 00417064 _____ () C:\Users\User\Downloads\DellSystemDetectLauncher.exe
2015-08-19 14:11 - 2015-08-19 14:11 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell
2015-08-19 13:58 - 2015-08-13 05:33 - 24593408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-08-19 13:58 - 2015-08-13 05:23 - 02178560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-08-19 13:58 - 2015-08-13 05:22 - 02093056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2015-08-19 13:58 - 2015-08-13 05:20 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2015-08-19 13:58 - 2015-08-13 05:17 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-08-19 13:58 - 2015-08-13 05:07 - 19323392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-08-19 13:58 - 2015-08-13 04:53 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2015-08-19 13:58 - 2015-08-11 11:04 - 04532304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2015-08-19 13:58 - 2015-08-11 11:04 - 02462648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-08-19 13:58 - 2015-08-11 11:04 - 01087296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2015-08-19 13:58 - 2015-08-11 11:03 - 08021840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-08-19 13:58 - 2015-08-11 11:03 - 00442208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2015-08-19 13:58 - 2015-08-11 11:02 - 00554744 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll
2015-08-19 13:58 - 2015-08-11 11:02 - 00292856 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2015-08-19 13:58 - 2015-08-11 11:02 - 00080720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2015-08-19 13:58 - 2015-08-11 10:57 - 03622256 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-08-19 13:58 - 2015-08-11 10:52 - 00993104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2015-08-19 13:58 - 2015-08-11 10:50 - 01643872 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2015-08-19 13:58 - 2015-08-11 10:40 - 04048808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2015-08-19 13:58 - 2015-08-11 10:40 - 02151208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-08-19 13:58 - 2015-08-11 10:40 - 00918320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2015-08-19 13:58 - 2015-08-11 10:38 - 00454000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll
2015-08-19 13:58 - 2015-08-11 10:37 - 00243800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2015-08-19 13:58 - 2015-08-11 10:31 - 02880032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-08-19 13:58 - 2015-08-11 10:26 - 00845664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
2015-08-19 13:58 - 2015-08-11 10:23 - 16706560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-08-19 13:58 - 2015-08-11 10:22 - 21875200 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-08-19 13:58 - 2015-08-11 10:21 - 00148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2015-08-19 13:58 - 2015-08-11 10:21 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
2015-08-19 13:58 - 2015-08-11 10:20 - 02224640 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-08-19 13:58 - 2015-08-11 10:20 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2015-08-19 13:58 - 2015-08-11 10:19 - 00235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2015-08-19 13:58 - 2015-08-11 10:18 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2015-08-19 13:58 - 2015-08-11 10:16 - 02416640 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-08-19 13:58 - 2015-08-11 10:14 - 00404480 _____ C:\WINDOWS\system32\diagtrack_wininternal.dll
2015-08-19 13:58 - 2015-08-11 10:13 - 00413184 _____ C:\WINDOWS\system32\diagtrack_win.dll
2015-08-19 13:58 - 2015-08-11 10:11 - 02446336 _____ C:\WINDOWS\system32\InputService.dll
2015-08-19 13:58 - 2015-08-11 10:11 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2015-08-19 13:58 - 2015-08-11 10:10 - 00778752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2015-08-19 13:58 - 2015-08-11 10:10 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-19 13:58 - 2015-08-11 10:10 - 00293376 _____ C:\WINDOWS\system32\TextInputFramework.dll
2015-08-19 13:58 - 2015-08-11 10:09 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll
2015-08-19 13:58 - 2015-08-11 10:08 - 00893440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2015-08-19 13:58 - 2015-08-11 10:08 - 00563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2015-08-19 13:58 - 2015-08-11 10:07 - 01178112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2015-08-19 13:58 - 2015-08-11 10:07 - 00593920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2015-08-19 13:58 - 2015-08-11 10:07 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeParserTask.exe
2015-08-19 13:58 - 2015-08-11 10:06 - 07523328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2015-08-19 13:58 - 2015-08-11 10:06 - 02662400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2015-08-19 13:58 - 2015-08-11 10:05 - 03527168 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2015-08-19 13:58 - 2015-08-11 10:05 - 00996352 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-08-19 13:58 - 2015-08-11 10:05 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationGeofences.dll
2015-08-19 13:58 - 2015-08-11 10:05 - 00269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2015-08-19 13:58 - 2015-08-11 10:05 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPermissions.dll
2015-08-19 13:58 - 2015-08-11 10:05 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkInternalPS.dll
2015-08-19 13:58 - 2015-08-11 10:03 - 02558976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2015-08-19 13:58 - 2015-08-11 10:02 - 03588096 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-08-19 13:58 - 2015-08-11 10:02 - 01890304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2015-08-19 13:58 - 2015-08-11 10:02 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2015-08-19 13:58 - 2015-08-11 10:02 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2015-08-19 13:58 - 2015-08-11 10:01 - 01334784 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-08-19 13:58 - 2015-08-11 10:00 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2015-08-19 13:58 - 2015-08-11 10:00 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncutil.dll
2015-08-19 13:58 - 2015-08-11 09:59 - 01106432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2015-08-19 13:58 - 2015-08-11 09:59 - 00642560 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll
2015-08-19 13:58 - 2015-08-11 09:59 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2015-08-19 13:58 - 2015-08-11 09:59 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tetheringclient.dll
2015-08-19 13:58 - 2015-08-11 09:58 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2015-08-19 13:58 - 2015-08-11 09:57 - 13024768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-08-19 13:58 - 2015-08-11 09:57 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
2015-08-19 13:58 - 2015-08-11 09:51 - 01916928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-08-19 13:58 - 2015-08-11 09:51 - 01823232 _____ C:\WINDOWS\SysWOW64\InputService.dll
2015-08-19 13:58 - 2015-08-11 09:50 - 00420352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
2015-08-19 13:58 - 2015-08-11 09:50 - 00200704 _____ C:\WINDOWS\SysWOW64\TextInputFramework.dll
2015-08-19 13:58 - 2015-08-11 09:50 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2015-08-19 13:58 - 2015-08-11 09:49 - 00586752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2015-08-19 13:58 - 2015-08-11 09:49 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-19 13:58 - 2015-08-11 09:48 - 00671232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
2015-08-19 13:58 - 2015-08-11 09:47 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2015-08-19 13:58 - 2015-08-11 09:45 - 18805760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-08-19 13:58 - 2015-08-11 09:45 - 01820672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2015-08-19 13:58 - 2015-08-11 09:43 - 02748416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2015-08-19 13:58 - 2015-08-11 09:42 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2015-08-19 13:58 - 2015-08-11 09:40 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2015-08-19 13:58 - 2015-08-11 09:40 - 01593856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2015-08-19 13:58 - 2015-08-11 09:40 - 01112064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-08-19 13:58 - 2015-08-11 09:39 - 00280576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2015-08-19 13:58 - 2015-08-11 09:38 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReInfo.dll
2015-08-16 15:13 - 2015-08-16 15:13 - 00000000 ____D C:\Users\User\Desktop\sa visit
2015-08-16 14:55 - 2015-08-16 14:55 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2015-08-14 12:07 - 2015-08-14 12:07 - 00000000 ____D C:\Users\User\AppData\Roaming\Macromedia
2015-08-14 11:36 - 2015-08-14 11:36 - 00000000 ____D C:\Users\User\AppData\Local\NetworkTiles
2015-08-12 15:16 - 2015-08-12 15:22 - 00000000 ____D C:\Users\User\AppData\Roaming\Apple Computer
2015-08-12 15:16 - 2015-08-12 15:16 - 00001822 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-08-12 15:16 - 2015-08-12 15:16 - 00000000 ____D C:\Users\User\AppData\Local\Apple Computer
2015-08-12 15:16 - 2015-08-12 15:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-08-12 15:13 - 2015-08-12 15:16 - 00000000 ____D C:\Program Files\iTunes
2015-08-12 15:13 - 2015-08-12 15:13 - 00000000 ____D C:\ProgramData\Apple Computer
2015-08-12 15:13 - 2015-08-12 15:13 - 00000000 ____D C:\Program Files\iPod
2015-08-12 15:13 - 2015-08-12 15:13 - 00000000 ____D C:\Program Files (x86)\iTunes
2015-08-12 15:12 - 2015-08-12 15:12 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-08-12 15:12 - 2015-08-12 15:12 - 00000000 ____D C:\WINDOWS\System32\Tasks\Apple
2015-08-12 15:12 - 2015-08-12 15:12 - 00000000 ____D C:\Users\User\AppData\Local\Apple
2015-08-12 15:12 - 2015-08-12 15:12 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2015-08-12 15:11 - 2015-08-26 23:42 - 00000000 ____D C:\Program Files (x86)\Bonjour
2015-08-12 15:11 - 2015-08-12 15:11 - 00000000 ____D C:\Program Files\Bonjour
2015-08-12 15:10 - 2015-08-12 15:13 - 00000000 ____D C:\Program Files\Common Files\Apple
2015-08-12 15:09 - 2015-08-12 15:12 - 00000000 ____D C:\ProgramData\Apple
2015-08-12 15:04 - 2015-08-12 15:07 - 155875632 _____ (Apple Inc.) C:\Users\User\Downloads\iTunes6464Setup.exe
2015-08-12 14:53 - 2015-08-12 14:55 - 46141524 _____ C:\Users\User\Downloads\rise_up_a_warrior.zip
2015-08-12 13:26 - 2015-08-12 13:26 - 00000000 ____D C:\Users\Default\AppData\Local\Trusteer
2015-08-12 13:26 - 2015-08-12 13:26 - 00000000 ____D C:\Users\Default User\AppData\Local\Trusteer
2015-08-12 13:15 - 2015-08-12 13:15 - 00000000 ____D C:\Users\User\Tracing
2015-08-12 13:11 - 2015-08-12 13:11 - 00000000 ____D C:\WINDOWS\PCHEALTH
2015-08-12 10:50 - 2015-08-03 03:18 - 08613200 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2015-08-12 10:50 - 2015-08-03 02:56 - 06878256 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2015-08-12 10:49 - 2015-08-08 08:19 - 00608936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-08-12 10:49 - 2015-08-08 07:40 - 00365056 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-08-12 10:49 - 2015-08-08 07:24 - 02415104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2015-08-12 10:49 - 2015-08-08 07:24 - 01679360 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2015-08-12 10:49 - 2015-08-08 07:15 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-08-12 10:49 - 2015-08-08 07:00 - 01985024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2015-08-12 10:49 - 2015-08-05 05:49 - 00783112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2015-08-12 10:49 - 2015-08-05 05:29 - 00644128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2015-08-12 10:49 - 2015-08-05 05:00 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenter.dll
2015-08-12 10:49 - 2015-08-05 04:47 - 01383424 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-08-12 10:49 - 2015-08-04 05:06 - 00583128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2015-08-12 10:49 - 2015-08-04 03:59 - 01212416 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2015-08-12 10:49 - 2015-08-04 03:47 - 00898560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2015-08-12 10:49 - 2015-08-03 03:19 - 00505696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2015-08-12 10:49 - 2015-08-03 03:18 - 01983840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2015-08-12 10:49 - 2015-08-03 03:13 - 22322624 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-08-12 10:49 - 2015-08-03 03:12 - 00801632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2015-08-12 10:49 - 2015-08-03 02:50 - 20857848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-08-12 10:49 - 2015-08-03 02:49 - 00700256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2015-08-12 10:49 - 2015-08-03 02:22 - 01601536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2015-08-12 10:49 - 2015-08-03 02:22 - 01008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2015-08-12 10:49 - 2015-08-03 02:18 - 12503552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-08-12 10:49 - 2015-08-03 02:18 - 03780096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-08-12 10:49 - 2015-08-03 02:18 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll
2015-08-12 10:49 - 2015-08-03 02:18 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkStatus.dll
2015-08-12 10:49 - 2015-08-03 02:15 - 00595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2015-08-12 10:49 - 2015-08-03 02:14 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2015-08-12 10:49 - 2015-08-03 02:14 - 00247808 _____ C:\WINDOWS\system32\facecredentialprovider.dll
2015-08-12 10:49 - 2015-08-03 02:10 - 01162240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2015-08-12 10:49 - 2015-08-03 02:03 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2015-08-12 10:49 - 2015-08-03 02:02 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2015-08-12 10:49 - 2015-08-03 02:01 - 11262464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-08-12 10:48 - 2015-08-08 08:29 - 01822280 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-08-12 10:48 - 2015-08-08 08:01 - 01533496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-08-12 10:48 - 2015-08-08 07:48 - 00539728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-08-12 10:48 - 2015-08-06 04:17 - 00237392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdyboost.sys
2015-08-12 10:48 - 2015-08-06 04:17 - 00200528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
2015-08-12 10:48 - 2015-08-06 03:22 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2015-08-12 10:48 - 2015-08-05 04:54 - 01274880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2015-08-12 10:48 - 2015-08-05 04:39 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActionCenter.dll
2015-08-12 10:48 - 2015-08-04 05:07 - 00102752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys
2015-08-12 10:48 - 2015-08-04 05:06 - 00243248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-08-12 10:48 - 2015-08-04 04:23 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2015-08-12 10:48 - 2015-08-03 03:32 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2015-08-12 10:48 - 2015-08-03 03:28 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll
2015-08-12 10:48 - 2015-08-03 03:19 - 00393568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2015-08-12 10:48 - 2015-08-03 03:18 - 00594472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2015-08-12 10:48 - 2015-08-03 03:18 - 00046432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpiowin32.sys
2015-08-12 10:48 - 2015-08-03 03:17 - 00516960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-08-12 10:48 - 2015-08-03 03:17 - 00052264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wpcfltr.sys
2015-08-12 10:48 - 2015-08-03 02:31 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2015-08-12 10:48 - 2015-08-03 02:30 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_UserAccount.dll
2015-08-12 10:48 - 2015-08-03 02:24 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2015-08-12 10:48 - 2015-08-03 02:24 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2015-08-12 10:48 - 2015-08-03 02:24 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModelShim.dll
2015-08-12 10:48 - 2015-08-03 02:23 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
2015-08-12 10:48 - 2015-08-03 02:22 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2015-08-12 10:48 - 2015-08-03 02:21 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\coredpus.dll
2015-08-12 10:48 - 2015-08-03 02:19 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\notepad.exe
2015-08-12 10:48 - 2015-08-03 02:19 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\notepad.exe
2015-08-12 10:48 - 2015-08-03 02:15 - 01290752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2015-08-12 10:48 - 2015-08-03 02:15 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2015-08-12 10:48 - 2015-08-03 02:15 - 00384000 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2015-08-12 10:48 - 2015-08-03 02:15 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2015-08-12 10:48 - 2015-08-03 02:12 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2015-08-12 10:48 - 2015-08-03 02:12 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll
2015-08-12 10:48 - 2015-08-03 02:11 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfuimanager.dll
2015-08-12 10:48 - 2015-08-03 02:06 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe
2015-08-12 10:48 - 2015-08-03 02:02 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2015-08-12 10:48 - 2015-08-03 01:59 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfuimanager.dll
2015-08-10 20:34 - 2015-08-10 20:34 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2015-08-10 19:44 - 2015-07-30 07:24 - 01561872 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2015-08-10 19:44 - 2015-07-30 07:23 - 00527952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2015-08-10 19:44 - 2015-07-30 07:21 - 00816576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2015-08-10 19:44 - 2015-07-30 07:17 - 01200400 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2015-08-10 19:44 - 2015-07-30 07:17 - 01025840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2015-08-10 19:44 - 2015-07-30 07:16 - 02147080 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2015-08-10 19:44 - 2015-07-30 07:14 - 00333168 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
2015-08-10 19:44 - 2015-07-30 07:09 - 01562968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2015-08-10 19:44 - 2015-07-30 07:06 - 01043872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2015-08-10 19:44 - 2015-07-30 07:05 - 02498808 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2015-08-10 19:44 - 2015-07-30 07:05 - 00501008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-08-10 19:44 - 2015-07-30 07:04 - 01396064 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-08-10 19:44 - 2015-07-30 07:03 - 02116448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2015-08-10 19:44 - 2015-07-30 06:24 - 00252768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2015-08-10 19:44 - 2015-07-30 05:29 - 00705520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2015-08-10 19:44 - 2015-07-30 05:26 - 01867160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2015-08-10 19:44 - 2015-07-30 05:26 - 00877016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2015-08-10 19:44 - 2015-07-30 05:25 - 01356368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2015-08-10 19:44 - 2015-07-30 05:25 - 00713312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2015-08-10 19:44 - 2015-07-30 05:24 - 01769056 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2015-08-10 19:44 - 2015-07-30 05:24 - 00445240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2015-08-10 19:44 - 2015-07-30 05:24 - 00285632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
2015-08-10 19:44 - 2015-07-30 05:21 - 00962400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-08-10 19:44 - 2015-07-30 05:12 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2015-08-10 19:44 - 2015-07-30 05:12 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2015-08-10 19:44 - 2015-07-30 05:08 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2015-08-10 19:44 - 2015-07-30 04:52 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-08-10 19:44 - 2015-07-30 04:52 - 00521216 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2015-08-10 19:44 - 2015-07-30 04:52 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2015-08-10 19:44 - 2015-07-30 04:49 - 11557888 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2015-08-10 19:44 - 2015-07-30 04:46 - 02125312 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2015-08-10 19:44 - 2015-07-30 04:44 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-08-10 19:44 - 2015-07-30 04:44 - 00229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2015-08-10 19:44 - 2015-07-30 04:42 - 00518144 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2015-08-10 19:44 - 2015-07-30 04:41 - 00407040 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2015-08-10 19:44 - 2015-07-30 04:40 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2015-08-10 19:44 - 2015-07-30 04:38 - 01420288 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2015-08-10 19:44 - 2015-07-30 04:34 - 00599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2015-08-10 19:44 - 2015-07-30 04:29 - 00654848 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2015-08-10 19:44 - 2015-07-30 04:15 - 09889792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2015-08-10 19:44 - 2015-07-30 04:04 - 01714176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2015-08-10 19:44 - 2015-07-30 04:04 - 00335360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2015-08-10 19:44 - 2015-07-30 03:58 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2015-08-10 19:43 - 2015-07-30 07:15 - 00632168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2015-08-10 19:43 - 2015-07-30 05:24 - 00407616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-08-10 19:43 - 2015-07-30 05:22 - 00896144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2015-08-10 19:43 - 2015-07-30 05:22 - 00507696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2015-08-10 19:43 - 2015-07-30 05:09 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2015-08-10 19:43 - 2015-07-30 05:08 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2015-08-10 19:43 - 2015-07-30 05:08 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2015-08-10 19:43 - 2015-07-30 04:59 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2015-08-10 19:43 - 2015-07-30 04:46 - 00487424 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2015-08-10 19:43 - 2015-07-30 04:46 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2015-08-10 19:43 - 2015-07-30 04:45 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2015-08-10 19:43 - 2015-07-30 04:45 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tunnel.sys
2015-08-10 19:43 - 2015-07-30 04:44 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2015-08-10 19:43 - 2015-07-30 04:44 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys
2015-08-10 19:43 - 2015-07-30 04:44 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\VoiceActivationManager.dll
2015-08-10 19:43 - 2015-07-30 04:41 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2015-08-10 19:43 - 2015-07-30 04:38 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2015-08-10 19:43 - 2015-07-30 04:07 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2015-08-10 19:43 - 2015-07-30 04:06 - 00373248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2015-08-10 19:43 - 2015-07-30 04:06 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll
2015-08-10 19:43 - 2015-07-30 04:06 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VoiceActivationManager.dll
2015-08-10 19:43 - 2015-07-30 03:59 - 00473088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2015-08-10 01:45 - 2015-08-25 17:01 - 00000000 ___DC C:\WINDOWS\Panther
2015-08-10 01:42 - 2015-08-10 01:42 - 14241792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 12589056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 04791296 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 04760576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 04398080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 04350464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 04169728 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 03687936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 03579904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 03443200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 03248640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 02646528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 01611264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 01411072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 01201664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 01168736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2015-08-10 01:42 - 2015-08-10 01:42 - 01067520 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 01043968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 01031680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorDataService.exe
2015-08-10 01:42 - 2015-08-10 01:42 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2015-08-10 01:42 - 2015-08-10 01:42 - 00872448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00799232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpccpl.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00798208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00754688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00750592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00670208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efscore.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00584544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00569344 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00485888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00437248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00356352 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00291840 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemcpl.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\systemcpl.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2015-08-10 01:42 - 2015-08-10 01:42 - 00251392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00181088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SignInOptions.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00179200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srumsvc.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00116736 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00097128 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcd.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00082616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcd.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spbcd.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msiexec.exe
2015-08-10 01:42 - 2015-08-10 01:42 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.PAL.Desktop.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\calc.exe
2015-08-10 01:42 - 2015-08-10 01:42 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\calc.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 07569408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 07051264 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 06488312 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 06305792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 06101504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 05118024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 05076480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 04611584 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 03362816 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 03248128 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 02741760 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 02606080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 02235904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 02207744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 02112512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01773056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01602560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01591856 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01521664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01418240 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 01417216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01365072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01294352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2015-08-10 01:41 - 2015-08-10 01:41 - 01203200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01203200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01169408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01135312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 01123400 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 01101792 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01061888 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01018568 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2015-08-10 01:41 - 2015-08-10 01:41 - 00966424 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00934752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refsv1.sys
2015-08-10 01:41 - 2015-08-10 01:41 - 00925696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00902656 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00858408 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00856064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00850432 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00841728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00832512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00823336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00808856 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00783872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00762896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00695136 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00680448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00679424 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00677888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00658568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00630160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00601344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2015-08-10 01:41 - 2015-08-10 01:41 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00578048 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00565088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2015-08-10 01:41 - 2015-08-10 01:41 - 00542720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00521568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00505344 _____ C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00498016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys
2015-08-10 01:41 - 2015-08-10 01:41 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00430592 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcomapi.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00425824 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00416256 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00366592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00343040 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00335248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00328704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00325984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2015-08-10 01:41 - 2015-08-10 01:41 - 00303616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00290312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00265480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00263168 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00242176 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicesFlowBroker.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00208736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\srumsvc.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\OmaDmAgent.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00191488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReInfo.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Privacy.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabSvc.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\spbcd.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\setbcdlocale.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.ProxyStub.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys
2015-08-10 01:41 - 2015-08-10 01:41 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\unenrollhook.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00061280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2015-08-10 01:41 - 2015-08-10 01:41 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.OneCore.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\hmkd.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmprc.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmUcsi.sys
2015-08-10 01:41 - 2015-08-10 01:41 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hmkd.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00032768 _____ C:\WINDOWS\system32\LicenseManagerApi.dll
2015-08-10 01:39 - 2015-08-10 01:39 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2015-08-10 01:37 - 2015-08-10 01:37 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices
2015-08-10 01:37 - 2015-08-10 01:37 - 00000000 ____D C:\WINDOWS\system32\msmq
2015-08-10 01:37 - 2015-08-10 01:37 - 00000000 ____D C:\WINDOWS\system32\BestPractices
2015-08-10 01:37 - 2015-08-10 01:37 - 00000000 ____D C:\Program Files\Reference Assemblies
2015-08-10 01:37 - 2015-08-10 01:37 - 00000000 ____D C:\Program Files\MSBuild
2015-08-10 01:37 - 2015-08-10 01:37 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2015-08-10 01:37 - 2015-08-10 01:37 - 00000000 ____D C:\Program Files (x86)\MSBuild
2015-08-10 01:37 - 2015-08-10 01:37 - 00000000 ____D C:\inetpub
2015-08-10 01:37 - 2015-05-30 06:07 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2015-08-10 01:37 - 2015-05-30 06:07 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-10 01:37 - 2015-05-30 06:07 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2015-08-10 01:36 - 2015-06-18 03:10 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2015-08-10 01:36 - 2015-06-18 03:10 - 00124112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-10 01:36 - 2015-06-18 03:10 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2015-08-09 18:11 - 2015-08-09 18:11 - 00000000 ____D C:\Users\User\AppData\Local\PeerDistRepub
2015-08-09 17:13 - 2015-08-29 20:55 - 00000000 ____D C:\Users\User\OneDrive
2015-08-09 17:13 - 2015-08-24 07:45 - 00002335 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-08-09 17:12 - 2015-08-14 11:10 - 00000000 ____D C:\Users\User\AppData\Local\MicrosoftEdge
2015-08-09 17:12 - 2015-08-09 17:15 - 00000000 ____D C:\Users\User\AppData\Local\Comms
2015-08-09 17:12 - 2015-08-09 17:12 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2015-08-09 17:11 - 2015-08-09 17:11 - 00001051 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optional Features.lnk
2015-08-09 17:09 - 2015-08-09 17:09 - 00000000 ____D C:\Users\User\AppData\Local\Publishers
2015-08-09 17:08 - 2015-08-25 08:53 - 00000000 ____D C:\Users\User\AppData\Local\Packages
2015-08-09 17:08 - 2015-08-09 17:08 - 00000020 ___SH C:\Users\User\ntuser.ini
2015-08-09 17:08 - 2015-08-09 17:08 - 00000000 ____D C:\Users\User\AppData\Local\TileDataLayer
2015-08-09 17:03 - 2015-08-09 17:03 - 00022744 _____ C:\WINDOWS\system32\emptyregdb.dat
2015-08-09 16:56 - 2015-08-09 16:56 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-08-09 16:56 - 2015-08-09 16:56 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2015-08-09 16:56 - 2015-08-09 16:56 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2015-08-09 16:54 - 2015-08-09 16:54 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines
2015-08-09 16:53 - 2015-08-09 17:08 - 00000000 ___RD C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-09 16:53 - 2015-07-10 12:04 - 00000000 __RSD C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-08-09 16:53 - 2015-07-10 12:04 - 00000000 ___RD C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-09 16:53 - 2015-07-10 12:04 - 00000000 ___RD C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-09 16:53 - 2015-07-10 12:04 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-09 16:51 - 2015-08-29 20:58 - 01005534 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-08-09 16:51 - 2015-08-09 16:52 - 00021209 _____ C:\WINDOWS\iis.log
2015-08-09 16:51 - 2015-08-09 16:51 - 00961296 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2015-08-09 16:50 - 2015-07-10 11:59 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2015-08-09 16:49 - 2015-08-09 16:49 - 00006352 _____ C:\WINDOWS\DPINST.LOG
2015-08-09 16:49 - 2015-08-09 16:49 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_ST_Accel_01009.Wdf
2015-08-09 16:49 - 2015-08-09 16:49 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
2015-08-09 16:49 - 2015-08-09 16:49 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_Apfiltr_01009.Wdf
2015-08-09 16:49 - 2015-08-09 16:49 - 00000000 ____D C:\Program Files\Synaptics
2015-08-09 16:49 - 2015-08-09 16:49 - 00000000 ____D C:\Program Files\STMicroelectronics
2015-08-09 16:49 - 2015-08-09 16:49 - 00000000 ____D C:\Program Files\DIFX
2015-08-09 16:49 - 2015-08-09 16:49 - 00000000 ____D C:\Program Files\DellTPad
2015-08-09 16:49 - 2015-08-09 16:49 - 00000000 ____D C:\Intel
2015-08-09 16:49 - 2011-07-15 21:31 - 00022128 _____ (ST Microelectronics) C:\WINDOWS\system32\Drivers\stdcfltn.sys
2015-08-09 16:47 - 2015-08-09 16:48 - 00024923 _____ C:\WINDOWS\system32\NetSetupMig.log
2015-08-09 16:46 - 2015-08-25 00:08 - 00010134 _____ C:\WINDOWS\PFRO.log
2015-08-09 16:21 - 2015-08-09 17:04 - 00006506 _____ C:\WINDOWS\comsetup.log
2015-08-09 16:19 - 2015-08-09 17:05 - 00010447 _____ C:\WINDOWS\diagerr.xml
2015-08-09 16:19 - 2015-08-09 17:05 - 00009528 _____ C:\WINDOWS\diagwrn.xml
2015-07-31 12:30 - 2015-07-31 12:30 - 00091648 _____ C:\Users\User\Documents\YCS 2015 enquiries.xls
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-30 10:55 - 2015-07-29 16:45 - 00000000 ____D C:\Users\User\AppData\Roaming\Skype
2015-08-30 10:54 - 2015-07-29 16:41 - 00152220 _____ C:\lm.log
2015-08-30 10:54 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\sru
2015-08-30 03:29 - 2015-07-10 13:22 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-08-29 21:32 - 2015-07-23 14:14 - 00000922 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-29 20:56 - 2015-07-23 14:14 - 00000918 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-29 20:53 - 2015-07-10 13:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-08-29 20:14 - 2015-07-10 10:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-08-29 16:40 - 2015-07-10 11:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-08-29 15:08 - 2015-07-10 13:20 - 00014260 _____ C:\WINDOWS\setupact.log
2015-08-29 14:53 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-08-28 17:26 - 2015-07-23 14:14 - 00003980 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-08-28 17:26 - 2015-07-23 14:14 - 00003748 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-08-28 17:17 - 2013-04-29 19:45 - 00000000 ____D C:\Users\User\Documents\invoices ycs
2015-08-27 08:00 - 2015-07-29 16:45 - 00002640 _____ C:\Users\Public\Desktop\Skype.lnk
2015-08-27 08:00 - 2015-07-29 16:45 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-08-27 08:00 - 2015-07-29 16:45 - 00000000 ____D C:\ProgramData\Skype
2015-08-27 03:31 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\rescache
2015-08-26 22:15 - 2015-06-04 12:35 - 00000000 ____D C:\Users\User\AppData\Local\VirtualStore
2015-08-24 21:33 - 2015-07-22 23:02 - 00002259 _____ C:\WINDOWS\epplauncher.mif
2015-08-24 21:26 - 2009-07-14 04:20 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2015-08-24 16:57 - 2015-07-23 14:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-08-20 11:56 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2015-08-20 11:54 - 2012-10-24 12:25 - 00000000 ____D C:\Users\User\Documents\Your counselling S client notes
2015-08-19 16:01 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2015-08-19 16:01 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-08-17 22:29 - 2013-10-07 13:13 - 00000000 ____D C:\Users\User\Documents\YCS Admin
2015-08-16 14:52 - 2015-07-10 13:20 - 00334968 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-08-12 13:21 - 2015-07-23 19:19 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-08-12 13:20 - 2015-07-23 19:15 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-12 13:19 - 2015-07-10 12:04 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-12 13:19 - 2015-07-10 12:04 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-12 13:19 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\oobe
2015-08-12 13:14 - 2015-06-02 14:07 - 00000000 ____D C:\Users\User\Documents\C3 counselling admin docs
2015-08-12 13:14 - 2012-11-07 11:53 - 00000000 ____D C:\Users\User\Documents\counselling docs
2015-08-12 13:10 - 2009-07-14 03:34 - 00000478 _____ C:\WINDOWS\win.ini
2015-08-11 03:30 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\Provisioning
2015-08-10 21:25 - 2015-07-23 19:15 - 00000000 ____D C:\Users\User\AppData\Local\Microsoft Help
2015-08-10 08:19 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\appcompat
2015-08-10 01:45 - 2015-07-10 12:04 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2015-08-10 01:42 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
2015-08-10 01:42 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2015-08-10 01:42 - 2015-07-10 10:05 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2015-08-10 01:42 - 2015-07-10 10:05 - 00000000 ____D C:\WINDOWS\system32\Dism
2015-08-10 01:37 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2015-08-10 01:37 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2015-08-10 01:37 - 2015-07-10 12:01 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll
2015-08-10 01:37 - 2015-07-10 12:01 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqutil.dll
2015-08-10 01:37 - 2015-07-10 12:01 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.dll
2015-08-10 01:37 - 2015-07-10 12:01 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2015-08-10 01:37 - 2015-07-10 12:01 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqrt.dll
2015-08-10 01:37 - 2015-07-10 12:01 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.tlb
2015-08-10 01:37 - 2015-07-10 12:01 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa30.tlb
2015-08-10 01:37 - 2015-07-10 12:01 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa20.tlb
2015-08-10 01:37 - 2015-07-10 12:01 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2015-08-10 01:37 - 2015-07-10 12:01 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa10.tlb
2015-08-10 01:37 - 2015-07-10 12:01 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2015-08-10 01:37 - 2015-07-10 12:01 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2015-08-10 01:37 - 2015-07-10 12:01 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll
2015-08-10 01:37 - 2015-07-10 12:01 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2015-08-10 01:37 - 2015-07-10 12:01 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2015-08-10 01:37 - 2015-07-10 12:01 - 00009096 _____ C:\WINDOWS\SysWOW64\msmqtrc.mof
2015-08-10 01:37 - 2015-07-10 12:00 - 01417728 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqqm.dll
2015-08-10 01:37 - 2015-07-10 12:00 - 00813056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll
2015-08-10 01:37 - 2015-07-10 12:00 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqutil.dll
2015-08-10 01:37 - 2015-07-10 12:00 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.dll
2015-08-10 01:37 - 2015-07-10 12:00 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqrt.dll
2015-08-10 01:37 - 2015-07-10 12:00 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2015-08-10 01:37 - 2015-07-10 12:00 - 00175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mqac.sys
2015-08-10 01:37 - 2015-07-10 12:00 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqlogmgr.dll
2015-08-10 01:37 - 2015-07-10 12:00 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.tlb
2015-08-10 01:37 - 2015-07-10 12:00 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa30.tlb
2015-08-10 01:37 - 2015-07-10 12:00 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa20.tlb
2015-08-10 01:37 - 2015-07-10 12:00 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2015-08-10 01:37 - 2015-07-10 12:00 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2015-08-10 01:37 - 2015-07-10 12:00 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqbkup.exe
2015-08-10 01:37 - 2015-07-10 12:00 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa10.tlb
2015-08-10 01:37 - 2015-07-10 12:00 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe
2015-08-10 01:37 - 2015-07-10 12:00 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcertui.dll
2015-08-10 01:37 - 2015-07-10 12:00 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2015-08-10 01:37 - 2015-07-10 12:00 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2015-08-10 01:37 - 2015-07-10 12:00 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2015-08-10 01:37 - 2015-07-10 12:00 - 00009096 _____ C:\WINDOWS\system32\msmqtrc.mof
2015-08-09 17:54 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\restore
2015-08-09 17:11 - 2015-07-10 14:12 - 00000000 ____D C:\WINDOWS\OCR
2015-08-09 17:09 - 2015-07-10 12:04 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2015-08-09 17:09 - 2015-07-10 12:04 - 00000000 ___RD C:\WINDOWS\PrintDialog
2015-08-09 17:09 - 2015-07-10 12:04 - 00000000 ___RD C:\WINDOWS\MiracastView
2015-08-09 17:09 - 2015-07-10 12:04 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2015-08-09 17:05 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\Registration
2015-08-09 17:03 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\spool
2015-08-09 17:01 - 2015-07-10 12:04 - 00000000 __RSD C:\WINDOWS\Media
2015-08-09 17:01 - 2015-07-10 12:04 - 00000000 __RHD C:\Users\Public\Libraries
2015-08-09 16:56 - 2015-07-10 14:14 - 00000000 ____D C:\WINDOWS\ShellNew
2015-08-09 16:56 - 2015-07-10 12:05 - 00004362 _____ C:\WINDOWS\DtcInstall.log
2015-08-09 16:56 - 2015-07-10 12:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-09 16:56 - 2015-07-10 10:05 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2015-08-09 16:56 - 2009-07-14 04:20 - 00000000 ____D C:\Users\Default.migrated
2015-08-09 16:55 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\SysWOW64\zh-HK
2015-08-09 16:55 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\SysWOW64\tr-TR
2015-08-09 16:55 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2015-08-09 16:55 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2015-08-09 16:55 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\zh-HK
2015-08-09 16:55 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\tr-TR
2015-08-09 16:55 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\IME
2015-08-09 16:54 - 2015-07-10 12:04 - 00000000 __SHD C:\Program Files\Windows Sidebar
2015-08-09 16:54 - 2015-07-10 12:04 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2015-08-09 16:54 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\schemas
2015-08-09 16:54 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2015-08-09 16:54 - 2015-07-10 12:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-08-09 16:54 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\DVD Maker
2015-08-09 16:53 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\Recovery
2015-08-09 16:51 - 2015-07-10 10:05 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2015-08-09 16:46 - 2015-07-10 10:05 - 00000000 __RHD C:\Users\Default
2015-08-09 16:27 - 2015-06-04 12:32 - 01618734 _____ C:\WINDOWS\WindowsUpdate (1).log
2015-08-09 16:23 - 2009-07-14 05:45 - 00022096 ____H C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-09 16:23 - 2009-07-14 05:45 - 00022096 ____H C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-08 16:38 - 2015-07-10 12:06 - 00794088 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-08-08 16:38 - 2015-07-10 12:06 - 00179688 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
 
==================== Files in the root of some directories =======
 
2015-08-25 08:16 - 2015-08-26 22:35 - 0180062 _____ () C:\Users\User\AppData\Local\ars.cache
2015-08-25 08:16 - 2015-08-26 22:36 - 0498461 _____ () C:\Users\User\AppData\Local\census.cache
2015-08-25 08:07 - 2015-08-25 08:07 - 0000036 _____ () C:\Users\User\AppData\Local\housecall.guid.cache
2015-08-25 08:12 - 2015-08-26 22:27 - 0000010 _____ () C:\Users\User\AppData\Local\sponge.last.runtime.cache
 
Some files in TEMP:
====================
C:\Users\User\AppData\Local\Temp\adobe_reader.exe
C:\Users\User\AppData\Local\Temp\SkypeSetup.exe
C:\Users\User\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-08-27 02:28
 
==================== End of FRST.txt ============================

Attached Files

  • Attached File  FRST.txt   93.22KB   1 downloads

Edited by xXToffeeXx, 03 September 2015 - 03:57 AM.


#8 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,078 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:12:38 AM

Posted 03 September 2015 - 04:36 AM

Hi Henniee,
 
We need to run a fix with FRST:

  • Press the windows key Windows_Logo_key.gif + r on your keyboard at the same time. Type in notepad and press Enter.
  • Copy and paste the script below in the notepad document:​
Task: {0999BC8D-B743-47F4-8D23-6B37BE489C70} - \8573a892-e4b5-4e4d-b10a-9b0136cad0b0-10_user -> No File <==== ATTENTION
Task: {131FD00E-EDDD-460B-AB0C-C026327559DF} - \8573a892-e4b5-4e4d-b10a-9b0136cad0b0-3 -> No File <==== ATTENTION
Task: {29E29F8E-92F7-4617-BC75-06792E01D24D} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {2A10BE05-1194-4188-BE08-8F9D864B486C} - System32\Tasks\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-5_user => C:\Program Files (x86)\SmartSaver+ 3\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-5.exe <==== ATTENTION
Task: {3BBFEB67-09C8-4073-BF20-C06BA089DA32} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {3CC601CC-FB93-49E9-991C-AF88942231DD} - System32\Tasks\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-1-7 => C:\Program Files (x86)\SmartSaver+ 3\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-1-7.exe <==== ATTENTION
Task: {3CE3C244-5E40-4323-8628-677F1F11BB13} - \globalUpdateUpdateTaskMachineCore -> No File <==== ATTENTION
Task: {449D2131-DE4A-42BD-A6E6-D204EBC8EA6F} - \8573a892-e4b5-4e4d-b10a-9b0136cad0b0-7 -> No File <==== ATTENTION
Task: {46FDF814-7F36-4646-BD97-502B6113012B} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {50F8E166-2837-4374-958E-7E64A3392B1B} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {530CF08D-6183-4685-932F-CAB80FA8A7D0} - System32\Tasks\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-5 => C:\Program Files (x86)\SmartSaver+ 3\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-5.exe <==== ATTENTION
Task: {537F5EE0-51A9-4DBB-8FBA-B900C980D424} - \AmiUpdXp -> No File <==== ATTENTION
Task: {5A78753B-6494-44B3-B452-9D078C90B02A} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {70D68711-DA7C-4D88-AC29-69922F38D309} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {79BD7177-339D-4506-B34A-DA17C972840D} - \8573a892-e4b5-4e4d-b10a-9b0136cad0b0-1-6 -> No File <==== ATTENTION
Task: {89B7BB24-0CEA-44E8-ACE3-4F75B41FAB34} - \globalUpdateUpdateTaskMachineUA -> No File <==== ATTENTION
Task: {8F338595-77E4-4BCC-9844-E815BB03F10C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {8F4C3A2F-D807-437E-BAA4-10DF9721ED47} - \Microsoft\Windows\File Classification Infrastructure\Property Definition Sync -> No File <==== ATTENTION
Task: {931FF5AD-3039-4233-B34F-0B4EE99BF52C} - \8573a892-e4b5-4e4d-b10a-9b0136cad0b0-6 -> No File <==== ATTENTION
Task: {A2570BF4-BDF0-4CAB-AA16-2054CE4CBAF4} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {AB6D0376-4D7F-43B8-82C6-E4BF5F65CF46} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {CF8BA5B0-73E4-4385-A8A0-2B2218F2E581} - System32\Tasks\LaunchPreSignup => C:\Program Files (x86)\OLBPre\OLBPre.exe <==== ATTENTION
Task: {DACFF8DE-A100-49F3-BFE8-E0A65C68B7DF} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {EBEC0615-2C1C-4683-8E46-699874520E11} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: C:\WINDOWS\Tasks\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-1-7.job => C:\Program Files (x86)\SmartSaver+ 3\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-1-7.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-5.job => C:\Program Files (x86)\SmartSaver+ 3\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-5.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-5_user.job => C:\Program Files (x86)\SmartSaver+ 3\8573a892-e4b5-4e4d-b10a-9b0136cad0b0-5.exe <==== ATTENTION
GroupPolicyScripts: Group Policy detected <======= ATTENTION
GroupPolicyScripts\User: Group Policy detected <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1394956801-2065374029-3886242179-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings: [ProxySettingsPerUser] 1 <======= ATTENTION (Policy restriction on ProxySettings)
ProxyEnable: [HKLM] => Proxy is enabled.
ProxyEnable: [HKLM-x32] => Proxy is enabled.
ProxyServer: [HKLM] => http=127.0.0.1:8877;https=127.0.0.1:8877
ProxyServer: [HKLM-x32] => http=127.0.0.1:8877;https=127.0.0.1:8877
2015-08-26 23:42 - 2015-08-26 23:42 - 00000000 ____D C:\Program Files (x86)\e315fa42-f04d-4036-8ae9-d3eb41dc5bf9
C:\Program Files (x86)\OLBPre
  • Save the file to your desktop and name it as fixlist.txt

Note: It's important that both files, FRST.exe/FRST64.exe and fixlist.txt are in the same location or the fix will not work
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

  • Run FRST.exe/FRST64.exe and press the Fix button just once and wait
  • If for some reason the tool needs a restart, please make sure you let the system restart normally, then let the tool complete its run
  • When finished, FRST will generate a log (Fixlog.txt) in the same location the tool was run.
  • Please copy and paste the log in your next reply.

--------------
 
How is the system running now?
 
xXToffeeXx~


~If I am helping you and you have not had a reply from me in two days, please send me a PM~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


#9 Henniee

Henniee
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:11:38 PM

Posted 03 September 2015 - 04:46 PM

It is running a lot smoother than before

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:31-08-2015
Ran by User (administrator) on USER-PC (03-09-2015 22:40:44)
Running from C:\Users\User\Desktop
Loaded Profiles: User (Available Profiles: User & DefaultAppPool)
Platform: Windows 10 Pro (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Broadcom Corporation.) C:\WINDOWS\System32\BtwRSupportService.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidMonitorSvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\WINDOWS\System32\mqsvc.exe
(O2Micro International) C:\WINDOWS\System32\drivers\o2flash.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(Microsoft Corporation) C:\WINDOWS\System32\SppExtComObj.Exe
(Microsoft Corporation) C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
(Microsoft Corporation) C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
(Intel Corporation) C:\WINDOWS\System32\igfxtray.exe
(Intel Corporation) C:\WINDOWS\System32\hkcmd.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXE
(Intel Corporation) C:\WINDOWS\System32\igfxpers.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Microsoft Corporation) C:\Users\User\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE
(Microsoft Corporation) C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\WINDOWS\System32\browser_broker.exe
(Microsoft Corporation) C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.827.16340.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
(Microsoft Corporation) C:\WINDOWS\System32\msfeedssync.exe
 

==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [727896 2014-03-13] (Alps Electric Co., Ltd.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170280 2015-07-11] (Apple Inc.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-25] (IDT, Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1394956801-2065374029-3886242179-1000\...\Run: [OneDrive] => C:\Users\User\AppData\Local\Microsoft\OneDrive\OneDrive.exe [404064 2015-08-24] (Microsoft Corporation)
HKU\S-1-5-21-1394956801-2065374029-3886242179-1000\...\Run: [Lync] => C:\Program Files (x86)\Microsoft Office\Office15\lync.exe [24107176 2015-07-14] (Microsoft Corporation)
GroupPolicyScripts: Group Policy detected <======= ATTENTION
GroupPolicyScripts\User: Group Policy detected <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings: [ProxySettingsPerUser] 1 <======= ATTENTION (Policy restriction on ProxySettings)
ProxyEnable: [HKLM] => Proxy is enabled.
ProxyEnable: [HKLM-x32] => Proxy is enabled.
ProxyServer: [HKLM] => http=127.0.0.1:8877;https=127.0.0.1:8877
ProxyServer: [HKLM-x32] => http=127.0.0.1:8877;https=127.0.0.1:8877
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{bcce3918-b299-42e3-b3b1-7417ac10c904}: [DhcpNameServer] 192.168.0.1
 
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1394956801-2065374029-3886242179-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
HKU\S-1-5-21-1394956801-2065374029-3886242179-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
HKU\S-1-5-21-1394956801-2065374029-3886242179-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/en-gb/?ocid=iehp
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-07-14] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-07-14] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-07-14] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-07-14] (Microsoft Corporation)
 
FireFox:
========
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-04-22] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-28] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-04-22] (Microsoft Corporation)
 
Chrome:
=======
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-07-23]
CHR Extension: (Google Docs) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-07-23]
CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-07-23]
CHR Extension: (Rapport) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjllphbppobebmjpjcijfbakobcheof [2015-08-08]
CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-07-23]
CHR Extension: (Google Search) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-07-23]
CHR Extension: (Google Play Music) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2015-07-23]
CHR Extension: (Google Sheets) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-07-23]
CHR Extension: (Google Docs Offline) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-02]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-08-08]
CHR Extension: (Chrome Web Store Payments) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-28]
CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-23]
CHR HKU\S-1-5-21-1394956801-2065374029-3886242179-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bbjllphbppobebmjpjcijfbakobcheof] - https://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 ApHidMonitorService; C:\Program Files\DellTPad\HidMonitorSvc.exe [87384 2014-03-27] (Alps Electric Co., Ltd.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2255064 2013-10-28] (Broadcom Corporation.)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [26112 2015-08-10] (Microsoft Corporation)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [84480 2015-08-10] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [578560 2015-08-10] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-10-28] (Broadcom Corporation.)
S0 LSI_SAS3i; C:\Windows\System32\drivers\lsi_sas3i.sys [99168 2015-07-10] (Avago Technologies)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [175104 2015-08-10] (Microsoft Corporation)
R3 NETwNe64; C:\Windows\System32\drivers\NETwew01.sys [3354384 2015-07-10] (Intel Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33448 2015-03-20] (Synaptics Incorporated)
R3 ST_Accel; C:\Windows\system32\DRIVERS\ST_Accel.sys [73928 2013-11-21] (STMicroelectronics)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
U3 idsvc; no ImagePath
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 

==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-03 22:40 - 2015-09-03 22:40 - 00004552 _____ C:\Users\User\Desktop\fixlist.txt
2015-09-03 22:40 - 2015-09-03 22:40 - 00000000 ____D C:\Users\User\Desktop\FRST-OlderVersion
2015-09-03 22:37 - 2015-09-03 22:37 - 00016148 _____ C:\WINDOWS\system32\USER-PC_User_HistoryPrediction.bin
2015-09-01 08:20 - 2015-09-01 08:20 - 00000000 ___HD C:\OneDriveTemp
2015-08-30 10:57 - 2015-08-30 10:58 - 00038372 _____ C:\Users\User\Desktop\Addition.txt
2015-08-30 10:55 - 2015-09-03 22:40 - 00011865 _____ C:\Users\User\Desktop\FRST.txt
2015-08-29 20:06 - 2015-08-29 20:14 - 00000000 ____D C:\AdwCleaner
2015-08-29 20:06 - 2015-08-29 20:06 - 01618432 _____ C:\Users\User\Desktop\adwcleaner_5.004.exe
2015-08-29 20:01 - 2015-09-03 22:40 - 02188800 _____ (Farbar) C:\Users\User\Desktop\FRST64.exe
2015-08-29 16:49 - 2015-08-20 07:07 - 08019296 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-08-29 16:49 - 2015-08-20 07:06 - 00609592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2015-08-29 16:49 - 2015-08-20 07:02 - 22324656 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-08-29 16:49 - 2015-08-20 06:57 - 00077400 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-08-29 16:49 - 2015-08-20 06:26 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2015-08-29 16:49 - 2015-08-20 06:21 - 21875200 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-08-29 16:49 - 2015-08-20 06:21 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
2015-08-29 16:49 - 2015-08-20 06:16 - 20857848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-08-29 16:49 - 2015-08-20 06:13 - 02235904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-08-29 16:49 - 2015-08-20 06:09 - 00929280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2015-08-29 16:49 - 2015-08-20 05:31 - 18806272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-08-29 16:49 - 2015-08-18 08:56 - 02498808 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2015-08-29 16:49 - 2015-08-18 08:55 - 00373072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2015-08-29 16:49 - 2015-08-18 08:54 - 01396064 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-08-29 16:49 - 2015-08-18 08:27 - 01771592 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2015-08-29 16:49 - 2015-08-18 08:24 - 00963920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-08-29 16:49 - 2015-08-18 08:13 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMediaManager.dll
2015-08-29 16:49 - 2015-08-18 08:13 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2015-08-29 16:49 - 2015-08-18 08:12 - 02225664 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-08-29 16:49 - 2015-08-18 08:07 - 02226688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2015-08-29 16:49 - 2015-08-18 08:04 - 01234944 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2015-08-29 16:49 - 2015-08-18 08:04 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-08-29 16:49 - 2015-08-18 07:59 - 01294336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcnwiz.dll
2015-08-29 16:49 - 2015-08-18 07:59 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnApi.dll
2015-08-29 16:49 - 2015-08-18 07:58 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2015-08-29 16:49 - 2015-08-18 07:58 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWCN.dll
2015-08-29 16:49 - 2015-08-18 07:58 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdWCN.dll
2015-08-29 16:49 - 2015-08-18 07:58 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnNetsh.dll
2015-08-29 16:49 - 2015-08-18 07:57 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2015-08-29 16:49 - 2015-08-18 07:56 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthRadioMedia.dll
2015-08-29 16:49 - 2015-08-18 07:55 - 02178560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-08-29 16:49 - 2015-08-18 07:54 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll
2015-08-29 16:49 - 2015-08-18 07:54 - 00247296 _____ C:\WINDOWS\system32\facecredentialprovider.dll
2015-08-29 16:49 - 2015-08-18 07:52 - 01888768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2015-08-29 16:49 - 2015-08-18 07:50 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-08-29 16:49 - 2015-08-18 07:49 - 01061888 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2015-08-29 16:49 - 2015-08-18 07:49 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2015-08-29 16:49 - 2015-08-18 07:49 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
2015-08-29 16:49 - 2015-08-18 07:36 - 01226752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wcnwiz.dll
2015-08-29 16:49 - 2015-08-18 07:35 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WcnApi.dll
2015-08-29 16:49 - 2015-08-18 07:35 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdWCN.dll
2015-08-29 16:49 - 2015-08-18 07:34 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll
2015-08-29 16:49 - 2015-08-18 07:29 - 01593344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2015-08-29 16:49 - 2015-08-18 07:26 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll
2015-08-29 16:49 - 2015-08-18 05:44 - 00008847 _____ C:\WINDOWS\system32\ResPriHMImageList
2015-08-27 22:09 - 2015-09-03 22:40 - 00000000 ____D C:\FRST
2015-08-27 22:09 - 2015-08-27 22:11 - 00000000 ____D C:\Security
2015-08-27 22:08 - 2015-08-27 22:08 - 02186752 _____ (Farbar) C:\Users\User\Downloads\FRST64.exe
2015-08-27 08:00 - 2015-08-27 08:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-08-26 23:42 - 2015-08-26 23:56 - 00000004 _____ C:\WINDOWS\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-08-26 23:42 - 2015-08-26 23:42 - 00000000 ____D C:\Program Files (x86)\e315fa42-f04d-4036-8ae9-d3eb41dc5bf9
2015-08-26 23:14 - 2015-09-03 22:41 - 00004150 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{35D4F0C9-276E-43E9-9B33-72962D950766}
2015-08-26 22:51 - 2015-08-27 02:18 - 00000000 ____D C:\NPE
2015-08-26 22:42 - 2015-09-03 15:34 - 00000000 ____D C:\Users\User\AppData\Local\CrashDumps
2015-08-26 22:35 - 2015-08-26 22:37 - 00000000 ____D C:\Users\User\Desktop\backups
2015-08-26 22:29 - 2015-08-26 22:30 - 02494560 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HousecallLauncher64 (3).exe
2015-08-26 22:18 - 2015-08-26 22:18 - 02494560 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HousecallLauncher64 (2).exe
2015-08-26 22:18 - 2015-08-26 22:18 - 02494560 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HousecallLauncher64 (1).exe
2015-08-26 22:17 - 2015-08-26 22:17 - 00388608 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HijackThis (1).exe
2015-08-26 22:17 - 2015-08-26 22:15 - 00388608 _____ (Trend Micro Inc.) C:\Users\User\Desktop\HijackThis.exe
2015-08-26 22:15 - 2015-08-26 22:15 - 00388608 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HijackThis.exe
2015-08-26 22:11 - 2015-08-26 22:11 - 01618432 _____ C:\Users\User\Downloads\adwcleaner_5.004.exe
2015-08-26 22:06 - 2015-08-27 07:57 - 00000000 ____D C:\Users\User\AppData\Local\NPE
2015-08-26 22:06 - 2015-08-26 22:06 - 03088296 _____ (Symantec Corporation) C:\Users\User\Downloads\NPE.exe
2015-08-26 22:06 - 2015-08-26 22:06 - 00000000 ____D C:\ProgramData\Norton
2015-08-25 20:43 - 2015-08-25 20:43 - 02073112 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HousecallLauncher.exe
2015-08-25 20:43 - 2015-08-25 20:43 - 02073112 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HousecallLauncher (1).exe
2015-08-25 17:01 - 2015-08-25 17:01 - 00000000 _____ C:\Recovery.txt
2015-08-25 09:46 - 2015-08-25 09:46 - 00000000 ____D C:\Recovery
2015-08-25 09:21 - 2015-08-25 09:43 - 00000000 ___HD C:\$Windows.~BT
2015-08-25 08:16 - 2015-08-26 22:36 - 00498461 _____ C:\Users\User\AppData\Local\census.cache
2015-08-25 08:16 - 2015-08-26 22:35 - 00180062 _____ C:\Users\User\AppData\Local\ars.cache
2015-08-25 08:12 - 2015-08-26 22:27 - 00000010 _____ C:\Users\User\AppData\Local\sponge.last.runtime.cache
2015-08-25 08:07 - 2015-08-25 08:07 - 00000036 _____ C:\Users\User\AppData\Local\housecall.guid.cache
2015-08-25 08:06 - 2015-08-25 08:07 - 02494560 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HousecallLauncher64.exe
2015-08-25 00:18 - 2015-08-25 00:18 - 00000000 ____D C:\WINDOWS\system32\appmgmt
2015-08-24 21:32 - 2015-08-26 23:09 - 00000008 __RSH C:\ProgramData\ntuser.pol
2015-08-24 21:16 - 2015-08-24 21:17 - 14243008 _____ (Microsoft Corporation) C:\Users\User\Downloads\mseinstall (1).exe
2015-08-24 21:11 - 2015-08-24 21:11 - 14243008 _____ (Microsoft Corporation) C:\Users\User\Downloads\mseinstall.exe
2015-08-24 21:11 - 2015-08-24 21:11 - 00000000 ____D C:\c8fdacbef381ec7fe3
2015-08-24 17:54 - 2015-08-24 17:54 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2015-08-24 17:02 - 2015-08-24 17:02 - 00003302 _____ C:\WINDOWS\System32\Tasks\{72B56432-498F-4EFA-BF3D-DAE4E9CCAA92}
2015-08-24 17:00 - 2015-08-24 17:00 - 00000020 ___SH C:\Users\DefaultAppPool\ntuser.ini
2015-08-24 17:00 - 2015-08-24 17:00 - 00000000 ____D C:\Users\DefaultAppPool
2015-08-24 17:00 - 2015-08-12 13:26 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Local\Trusteer
2015-08-24 17:00 - 2015-08-12 13:19 - 00000000 ___RD C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-24 17:00 - 2015-08-09 16:56 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Local\Microsoft Help
2015-08-24 17:00 - 2015-07-10 12:04 - 00000000 __RSD C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-08-24 17:00 - 2015-07-10 12:04 - 00000000 ___RD C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-24 17:00 - 2015-07-10 12:04 - 00000000 ___RD C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-24 17:00 - 2015-07-10 12:04 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-24 16:52 - 2015-08-26 23:21 - 00002226 _____ C:\Users\User\Desktop\Google Chrome.lnk
2015-08-24 07:55 - 2015-08-26 23:02 - 00000000 ___HD C:\a
2015-08-24 07:55 - 2015-08-24 17:02 - 00000000 ____D C:\Program Files (x86)\FastInternet
2015-08-24 07:45 - 2015-08-24 07:45 - 00000019 _____ C:\WINDOWS\SysWOW64\19262648.bat
2015-08-20 12:01 - 2015-08-20 12:01 - 00000918 _____ C:\WINDOWS\SysWOW64\${LOGFILE}
2015-08-20 11:53 - 2015-08-24 07:48 - 00000000 ____D C:\ProgramData\Cegeespe
2015-08-20 11:43 - 2015-08-20 11:43 - 00000000 ____D C:\Users\User\AppData\Local\Adobe
2015-08-20 09:54 - 2015-08-20 09:55 - 00000348 _____ C:\WINDOWS\BRRBCOM.INI
2015-08-20 09:54 - 2015-08-20 09:54 - 00000000 ____D C:\ProgramData\Brother
2015-08-20 09:53 - 2015-08-20 09:53 - 00224256 _____ (Brother Industries, Ltd.) C:\WINDOWS\system32\BRCOC12A.DLL
2015-08-20 09:53 - 2015-08-20 09:53 - 00180224 _____ (Brother Industries, Ltd.) C:\WINDOWS\SysWOW64\BROSNMP.DLL
2015-08-20 09:53 - 2015-08-20 09:53 - 00136456 _____ (Brother Industries Ltd) C:\WINDOWS\SysWOW64\BRRBTOOL.EXE
2015-08-20 09:53 - 2015-08-20 09:53 - 00077824 _____ (Brother Industries, Ltd.) C:\WINDOWS\SysWOW64\BRLMW03A.DLL
2015-08-20 09:53 - 2015-08-20 09:53 - 00045056 _____ C:\WINDOWS\SysWOW64\BRTCPCON.DLL
2015-08-20 09:53 - 2015-08-20 09:53 - 00025299 _____ (Brother Industries, Ltd) C:\WINDOWS\SysWOW64\BRLM03A.DLL
2015-08-20 09:53 - 2015-08-20 09:53 - 00000114 _____ C:\WINDOWS\SysWOW64\BRLMW03A.INI
2015-08-20 09:53 - 2015-08-20 09:53 - 00000050 _____ C:\WINDOWS\system32\BRADC12A.DAT
2015-08-19 14:15 - 2015-08-19 14:16 - 00000000 ____D C:\Program Files\IDT
2015-08-19 14:15 - 2015-08-19 14:15 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-08-19 14:15 - 2011-01-25 02:57 - 11941376 _____ (IDT, Inc.) C:\WINDOWS\system32\idtsg64.cpl
2015-08-19 14:15 - 2011-01-25 02:57 - 04637184 _____ (IDT, Inc.) C:\WINDOWS\system32\stlang64.dll
2015-08-19 14:15 - 2011-01-25 02:57 - 01499136 _____ (IDT, Inc.) C:\WINDOWS\system32\stapo64.dll
2015-08-19 14:15 - 2011-01-25 02:57 - 00651776 ____N (IDT, Inc.) C:\WINDOWS\system32\stapi64.dll
2015-08-19 14:15 - 2011-01-25 02:57 - 00520192 _____ (IDT, Inc.) C:\WINDOWS\system32\Drivers\stwrt64.sys
2015-08-19 14:15 - 2011-01-25 02:57 - 00431616 _____ (IDT, Inc.) C:\WINDOWS\system32\stcplx64.dll
2015-08-19 14:15 - 2011-01-25 02:57 - 00220160 _____ (IDT, Inc.) C:\WINDOWS\system32\st646324.dll
2015-08-19 14:15 - 2010-01-27 03:30 - 00162816 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AESTAC64.dll
2015-08-19 14:15 - 2009-10-10 00:45 - 00442368 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AESTEC64.dll
2015-08-19 14:15 - 2009-03-03 02:58 - 00068608 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AESTAR64.dll
2015-08-19 14:14 - 2015-08-19 14:14 - 28859960 _____ (Dell Inc.) C:\Users\User\Downloads\DRVR_WIN_R297613 (1).EXE
2015-08-19 14:14 - 2015-08-19 14:14 - 03081720 _____ C:\Users\User\Downloads\E5520A14.exe
2015-08-19 14:13 - 2015-08-19 14:13 - 28859960 _____ (Dell Inc.) C:\Users\User\Downloads\DRVR_WIN_R297613.EXE
2015-08-19 14:13 - 2015-08-19 14:13 - 00000000 ____D C:\Users\User\AppData\Local\Dell
2015-08-19 14:11 - 2015-08-24 17:09 - 00000000 ____D C:\Users\User\AppData\Local\Deployment
2015-08-19 14:11 - 2015-08-19 14:11 - 00417064 _____ () C:\Users\User\Downloads\DellSystemDetectLauncher.exe
2015-08-19 14:11 - 2015-08-19 14:11 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell
2015-08-19 13:58 - 2015-08-13 05:33 - 24593408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-08-19 13:58 - 2015-08-13 05:22 - 02093056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2015-08-19 13:58 - 2015-08-13 05:20 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2015-08-19 13:58 - 2015-08-13 05:07 - 19323392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-08-19 13:58 - 2015-08-13 04:53 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2015-08-19 13:58 - 2015-08-11 11:04 - 04532304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2015-08-19 13:58 - 2015-08-11 11:04 - 02462648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-08-19 13:58 - 2015-08-11 11:04 - 01087296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2015-08-19 13:58 - 2015-08-11 11:03 - 00442208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2015-08-19 13:58 - 2015-08-11 11:02 - 00554744 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll
2015-08-19 13:58 - 2015-08-11 11:02 - 00292856 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2015-08-19 13:58 - 2015-08-11 11:02 - 00080720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2015-08-19 13:58 - 2015-08-11 10:57 - 03622256 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-08-19 13:58 - 2015-08-11 10:52 - 00993104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2015-08-19 13:58 - 2015-08-11 10:50 - 01643872 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2015-08-19 13:58 - 2015-08-11 10:40 - 04048808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2015-08-19 13:58 - 2015-08-11 10:40 - 02151208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-08-19 13:58 - 2015-08-11 10:40 - 00918320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2015-08-19 13:58 - 2015-08-11 10:38 - 00454000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll
2015-08-19 13:58 - 2015-08-11 10:37 - 00243800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2015-08-19 13:58 - 2015-08-11 10:31 - 02880032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-08-19 13:58 - 2015-08-11 10:26 - 00845664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
2015-08-19 13:58 - 2015-08-11 10:23 - 16706560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-08-19 13:58 - 2015-08-11 10:21 - 00148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2015-08-19 13:58 - 2015-08-11 10:21 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
2015-08-19 13:58 - 2015-08-11 10:20 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2015-08-19 13:58 - 2015-08-11 10:19 - 00235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2015-08-19 13:58 - 2015-08-11 10:18 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2015-08-19 13:58 - 2015-08-11 10:16 - 02416640 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-08-19 13:58 - 2015-08-11 10:14 - 00404480 _____ C:\WINDOWS\system32\diagtrack_wininternal.dll
2015-08-19 13:58 - 2015-08-11 10:13 - 00413184 _____ C:\WINDOWS\system32\diagtrack_win.dll
2015-08-19 13:58 - 2015-08-11 10:11 - 02446336 _____ C:\WINDOWS\system32\InputService.dll
2015-08-19 13:58 - 2015-08-11 10:11 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2015-08-19 13:58 - 2015-08-11 10:10 - 00778752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2015-08-19 13:58 - 2015-08-11 10:10 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-19 13:58 - 2015-08-11 10:10 - 00293376 _____ C:\WINDOWS\system32\TextInputFramework.dll
2015-08-19 13:58 - 2015-08-11 10:09 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll
2015-08-19 13:58 - 2015-08-11 10:08 - 00893440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2015-08-19 13:58 - 2015-08-11 10:08 - 00563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2015-08-19 13:58 - 2015-08-11 10:07 - 01178112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2015-08-19 13:58 - 2015-08-11 10:07 - 00593920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2015-08-19 13:58 - 2015-08-11 10:07 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeParserTask.exe
2015-08-19 13:58 - 2015-08-11 10:06 - 07523328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2015-08-19 13:58 - 2015-08-11 10:06 - 02662400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2015-08-19 13:58 - 2015-08-11 10:05 - 03527168 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2015-08-19 13:58 - 2015-08-11 10:05 - 00996352 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-08-19 13:58 - 2015-08-11 10:05 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationGeofences.dll
2015-08-19 13:58 - 2015-08-11 10:05 - 00269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2015-08-19 13:58 - 2015-08-11 10:05 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPermissions.dll
2015-08-19 13:58 - 2015-08-11 10:05 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkInternalPS.dll
2015-08-19 13:58 - 2015-08-11 10:03 - 02558976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2015-08-19 13:58 - 2015-08-11 10:02 - 03588096 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-08-19 13:58 - 2015-08-11 10:02 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2015-08-19 13:58 - 2015-08-11 10:02 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2015-08-19 13:58 - 2015-08-11 10:01 - 01334784 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-08-19 13:58 - 2015-08-11 10:00 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2015-08-19 13:58 - 2015-08-11 10:00 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncutil.dll
2015-08-19 13:58 - 2015-08-11 09:59 - 01106432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2015-08-19 13:58 - 2015-08-11 09:59 - 00642560 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll
2015-08-19 13:58 - 2015-08-11 09:59 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2015-08-19 13:58 - 2015-08-11 09:59 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tetheringclient.dll
2015-08-19 13:58 - 2015-08-11 09:58 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2015-08-19 13:58 - 2015-08-11 09:57 - 13024768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-08-19 13:58 - 2015-08-11 09:57 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
2015-08-19 13:58 - 2015-08-11 09:51 - 01916928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-08-19 13:58 - 2015-08-11 09:51 - 01823232 _____ C:\WINDOWS\SysWOW64\InputService.dll
2015-08-19 13:58 - 2015-08-11 09:50 - 00420352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
2015-08-19 13:58 - 2015-08-11 09:50 - 00200704 _____ C:\WINDOWS\SysWOW64\TextInputFramework.dll
2015-08-19 13:58 - 2015-08-11 09:50 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2015-08-19 13:58 - 2015-08-11 09:49 - 00586752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2015-08-19 13:58 - 2015-08-11 09:49 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-19 13:58 - 2015-08-11 09:48 - 00671232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
2015-08-19 13:58 - 2015-08-11 09:47 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2015-08-19 13:58 - 2015-08-11 09:45 - 01820672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2015-08-19 13:58 - 2015-08-11 09:43 - 02748416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2015-08-19 13:58 - 2015-08-11 09:42 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2015-08-19 13:58 - 2015-08-11 09:40 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2015-08-19 13:58 - 2015-08-11 09:40 - 01112064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-08-19 13:58 - 2015-08-11 09:39 - 00280576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2015-08-19 13:58 - 2015-08-11 09:38 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReInfo.dll
2015-08-16 15:13 - 2015-08-16 15:13 - 00000000 ____D C:\Users\User\Desktop\sa visit
2015-08-16 14:55 - 2015-08-16 14:55 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2015-08-14 12:07 - 2015-08-14 12:07 - 00000000 ____D C:\Users\User\AppData\Roaming\Macromedia
2015-08-14 11:36 - 2015-08-14 11:36 - 00000000 ____D C:\Users\User\AppData\Local\NetworkTiles
2015-08-12 15:16 - 2015-08-12 15:22 - 00000000 ____D C:\Users\User\AppData\Roaming\Apple Computer
2015-08-12 15:16 - 2015-08-12 15:16 - 00001822 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-08-12 15:16 - 2015-08-12 15:16 - 00000000 ____D C:\Users\User\AppData\Local\Apple Computer
2015-08-12 15:16 - 2015-08-12 15:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-08-12 15:13 - 2015-08-12 15:16 - 00000000 ____D C:\Program Files\iTunes
2015-08-12 15:13 - 2015-08-12 15:13 - 00000000 ____D C:\ProgramData\Apple Computer
2015-08-12 15:13 - 2015-08-12 15:13 - 00000000 ____D C:\Program Files\iPod
2015-08-12 15:13 - 2015-08-12 15:13 - 00000000 ____D C:\Program Files (x86)\iTunes
2015-08-12 15:12 - 2015-08-12 15:12 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-08-12 15:12 - 2015-08-12 15:12 - 00000000 ____D C:\WINDOWS\System32\Tasks\Apple
2015-08-12 15:12 - 2015-08-12 15:12 - 00000000 ____D C:\Users\User\AppData\Local\Apple
2015-08-12 15:12 - 2015-08-12 15:12 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2015-08-12 15:11 - 2015-08-26 23:42 - 00000000 ____D C:\Program Files (x86)\Bonjour
2015-08-12 15:11 - 2015-08-12 15:11 - 00000000 ____D C:\Program Files\Bonjour
2015-08-12 15:10 - 2015-08-12 15:13 - 00000000 ____D C:\Program Files\Common Files\Apple
2015-08-12 15:09 - 2015-08-12 15:12 - 00000000 ____D C:\ProgramData\Apple
2015-08-12 15:04 - 2015-08-12 15:07 - 155875632 _____ (Apple Inc.) C:\Users\User\Downloads\iTunes6464Setup.exe
2015-08-12 14:53 - 2015-08-12 14:55 - 46141524 _____ C:\Users\User\Downloads\rise_up_a_warrior.zip
2015-08-12 13:26 - 2015-08-12 13:26 - 00000000 ____D C:\Users\Default\AppData\Local\Trusteer
2015-08-12 13:26 - 2015-08-12 13:26 - 00000000 ____D C:\Users\Default User\AppData\Local\Trusteer
2015-08-12 13:15 - 2015-08-12 13:15 - 00000000 ____D C:\Users\User\Tracing
2015-08-12 13:11 - 2015-08-12 13:11 - 00000000 ____D C:\WINDOWS\PCHEALTH
2015-08-12 10:50 - 2015-08-03 03:18 - 08613200 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2015-08-12 10:50 - 2015-08-03 02:56 - 06878256 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2015-08-12 10:49 - 2015-08-08 08:19 - 00608936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-08-12 10:49 - 2015-08-08 07:40 - 00365056 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-08-12 10:49 - 2015-08-08 07:24 - 02415104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2015-08-12 10:49 - 2015-08-08 07:24 - 01679360 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2015-08-12 10:49 - 2015-08-08 07:15 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-08-12 10:49 - 2015-08-08 07:00 - 01985024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2015-08-12 10:49 - 2015-08-05 05:49 - 00783112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2015-08-12 10:49 - 2015-08-05 05:29 - 00644128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2015-08-12 10:49 - 2015-08-05 05:00 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenter.dll
2015-08-12 10:49 - 2015-08-05 04:47 - 01383424 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-08-12 10:49 - 2015-08-04 05:06 - 00583128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2015-08-12 10:49 - 2015-08-04 03:59 - 01212416 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2015-08-12 10:49 - 2015-08-04 03:47 - 00898560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2015-08-12 10:49 - 2015-08-03 03:19 - 00505696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2015-08-12 10:49 - 2015-08-03 03:18 - 01983840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2015-08-12 10:49 - 2015-08-03 03:12 - 00801632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2015-08-12 10:49 - 2015-08-03 02:49 - 00700256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2015-08-12 10:49 - 2015-08-03 02:22 - 01601536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2015-08-12 10:49 - 2015-08-03 02:22 - 01008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2015-08-12 10:49 - 2015-08-03 02:18 - 12503552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-08-12 10:49 - 2015-08-03 02:18 - 03780096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-08-12 10:49 - 2015-08-03 02:18 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll
2015-08-12 10:49 - 2015-08-03 02:18 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkStatus.dll
2015-08-12 10:49 - 2015-08-03 02:15 - 00595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2015-08-12 10:49 - 2015-08-03 02:14 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2015-08-12 10:49 - 2015-08-03 02:10 - 01162240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2015-08-12 10:49 - 2015-08-03 02:03 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2015-08-12 10:49 - 2015-08-03 02:02 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2015-08-12 10:49 - 2015-08-03 02:01 - 11262464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-08-12 10:48 - 2015-08-08 08:29 - 01822280 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-08-12 10:48 - 2015-08-08 08:01 - 01533496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-08-12 10:48 - 2015-08-08 07:48 - 00539728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-08-12 10:48 - 2015-08-06 04:17 - 00237392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdyboost.sys
2015-08-12 10:48 - 2015-08-06 04:17 - 00200528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
2015-08-12 10:48 - 2015-08-06 03:22 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2015-08-12 10:48 - 2015-08-05 04:54 - 01274880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2015-08-12 10:48 - 2015-08-05 04:39 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActionCenter.dll
2015-08-12 10:48 - 2015-08-04 05:07 - 00102752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys
2015-08-12 10:48 - 2015-08-04 05:06 - 00243248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-08-12 10:48 - 2015-08-04 04:23 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2015-08-12 10:48 - 2015-08-03 03:32 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2015-08-12 10:48 - 2015-08-03 03:28 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll
2015-08-12 10:48 - 2015-08-03 03:19 - 00393568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2015-08-12 10:48 - 2015-08-03 03:18 - 00594472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2015-08-12 10:48 - 2015-08-03 03:18 - 00046432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpiowin32.sys
2015-08-12 10:48 - 2015-08-03 03:17 - 00516960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-08-12 10:48 - 2015-08-03 03:17 - 00052264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wpcfltr.sys
2015-08-12 10:48 - 2015-08-03 02:31 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2015-08-12 10:48 - 2015-08-03 02:30 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_UserAccount.dll
2015-08-12 10:48 - 2015-08-03 02:24 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2015-08-12 10:48 - 2015-08-03 02:24 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2015-08-12 10:48 - 2015-08-03 02:24 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModelShim.dll
2015-08-12 10:48 - 2015-08-03 02:23 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
2015-08-12 10:48 - 2015-08-03 02:22 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2015-08-12 10:48 - 2015-08-03 02:21 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\coredpus.dll
2015-08-12 10:48 - 2015-08-03 02:19 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\notepad.exe
2015-08-12 10:48 - 2015-08-03 02:19 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\notepad.exe
2015-08-12 10:48 - 2015-08-03 02:15 - 01290752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2015-08-12 10:48 - 2015-08-03 02:15 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2015-08-12 10:48 - 2015-08-03 02:15 - 00384000 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2015-08-12 10:48 - 2015-08-03 02:15 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2015-08-12 10:48 - 2015-08-03 02:12 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2015-08-12 10:48 - 2015-08-03 02:12 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll
2015-08-12 10:48 - 2015-08-03 02:11 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfuimanager.dll
2015-08-12 10:48 - 2015-08-03 02:06 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe
2015-08-12 10:48 - 2015-08-03 02:02 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2015-08-12 10:48 - 2015-08-03 01:59 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfuimanager.dll
2015-08-10 20:34 - 2015-08-10 20:34 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2015-08-10 19:44 - 2015-07-30 07:24 - 01561872 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2015-08-10 19:44 - 2015-07-30 07:23 - 00527952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2015-08-10 19:44 - 2015-07-30 07:21 - 00816576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2015-08-10 19:44 - 2015-07-30 07:17 - 01200400 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2015-08-10 19:44 - 2015-07-30 07:17 - 01025840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2015-08-10 19:44 - 2015-07-30 07:16 - 02147080 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2015-08-10 19:44 - 2015-07-30 07:14 - 00333168 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
2015-08-10 19:44 - 2015-07-30 07:09 - 01562968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2015-08-10 19:44 - 2015-07-30 07:06 - 01043872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2015-08-10 19:44 - 2015-07-30 07:05 - 00501008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-08-10 19:44 - 2015-07-30 07:03 - 02116448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2015-08-10 19:44 - 2015-07-30 06:24 - 00252768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2015-08-10 19:44 - 2015-07-30 05:29 - 00705520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2015-08-10 19:44 - 2015-07-30 05:26 - 01867160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2015-08-10 19:44 - 2015-07-30 05:26 - 00877016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2015-08-10 19:44 - 2015-07-30 05:25 - 01356368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2015-08-10 19:44 - 2015-07-30 05:25 - 00713312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2015-08-10 19:44 - 2015-07-30 05:24 - 00445240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2015-08-10 19:44 - 2015-07-30 05:24 - 00285632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
2015-08-10 19:44 - 2015-07-30 05:12 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2015-08-10 19:44 - 2015-07-30 05:12 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2015-08-10 19:44 - 2015-07-30 05:08 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2015-08-10 19:44 - 2015-07-30 04:52 - 00521216 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2015-08-10 19:44 - 2015-07-30 04:52 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2015-08-10 19:44 - 2015-07-30 04:49 - 11557888 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2015-08-10 19:44 - 2015-07-30 04:46 - 02125312 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2015-08-10 19:44 - 2015-07-30 04:44 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-08-10 19:44 - 2015-07-30 04:44 - 00229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2015-08-10 19:44 - 2015-07-30 04:42 - 00518144 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2015-08-10 19:44 - 2015-07-30 04:41 - 00407040 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2015-08-10 19:44 - 2015-07-30 04:40 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2015-08-10 19:44 - 2015-07-30 04:38 - 01420288 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2015-08-10 19:44 - 2015-07-30 04:34 - 00599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2015-08-10 19:44 - 2015-07-30 04:29 - 00654848 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2015-08-10 19:44 - 2015-07-30 04:15 - 09889792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2015-08-10 19:44 - 2015-07-30 04:04 - 01714176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2015-08-10 19:44 - 2015-07-30 04:04 - 00335360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2015-08-10 19:44 - 2015-07-30 03:58 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2015-08-10 19:43 - 2015-07-30 07:15 - 00632168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2015-08-10 19:43 - 2015-07-30 05:24 - 00407616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-08-10 19:43 - 2015-07-30 05:22 - 00896144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2015-08-10 19:43 - 2015-07-30 05:22 - 00507696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2015-08-10 19:43 - 2015-07-30 05:09 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2015-08-10 19:43 - 2015-07-30 05:08 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2015-08-10 19:43 - 2015-07-30 04:59 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2015-08-10 19:43 - 2015-07-30 04:46 - 00487424 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2015-08-10 19:43 - 2015-07-30 04:46 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2015-08-10 19:43 - 2015-07-30 04:45 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2015-08-10 19:43 - 2015-07-30 04:45 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tunnel.sys
2015-08-10 19:43 - 2015-07-30 04:44 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2015-08-10 19:43 - 2015-07-30 04:44 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys
2015-08-10 19:43 - 2015-07-30 04:44 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\VoiceActivationManager.dll
2015-08-10 19:43 - 2015-07-30 04:41 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2015-08-10 19:43 - 2015-07-30 04:38 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2015-08-10 19:43 - 2015-07-30 04:07 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2015-08-10 19:43 - 2015-07-30 04:06 - 00373248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2015-08-10 19:43 - 2015-07-30 04:06 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll
2015-08-10 19:43 - 2015-07-30 04:06 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VoiceActivationManager.dll
2015-08-10 19:43 - 2015-07-30 03:59 - 00473088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2015-08-10 01:45 - 2015-08-25 17:01 - 00000000 ___DC C:\WINDOWS\Panther
2015-08-10 01:42 - 2015-08-10 01:42 - 14241792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 12589056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 04791296 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 04760576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 04398080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 04350464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 04169728 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 03687936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 03579904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 03443200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 03248640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 02646528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 01611264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 01411072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 01201664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 01168736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2015-08-10 01:42 - 2015-08-10 01:42 - 01067520 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 01043968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 01031680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorDataService.exe
2015-08-10 01:42 - 2015-08-10 01:42 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2015-08-10 01:42 - 2015-08-10 01:42 - 00872448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00799232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpccpl.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00798208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00754688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00750592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00670208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efscore.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00584544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00569344 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00485888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00437248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00356352 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00291840 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemcpl.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\systemcpl.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2015-08-10 01:42 - 2015-08-10 01:42 - 00251392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00181088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SignInOptions.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00179200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srumsvc.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00116736 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00097128 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcd.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00082616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcd.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spbcd.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msiexec.exe
2015-08-10 01:42 - 2015-08-10 01:42 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.PAL.Desktop.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-08-10 01:42 - 2015-08-10 01:42 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\calc.exe
2015-08-10 01:42 - 2015-08-10 01:42 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\calc.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 07569408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 07051264 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 06488312 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 06305792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 06101504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 05118024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 05076480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 04611584 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 03362816 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 03248128 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 02741760 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 02606080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 02207744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 02112512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01773056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01602560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01591856 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01521664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01418240 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 01417216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01365072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01294352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2015-08-10 01:41 - 2015-08-10 01:41 - 01203200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01203200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01169408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01135312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 01123400 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 01101792 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 01018568 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2015-08-10 01:41 - 2015-08-10 01:41 - 00966424 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00934752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refsv1.sys
2015-08-10 01:41 - 2015-08-10 01:41 - 00925696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00902656 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00858408 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00856064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00850432 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00841728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00832512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00823336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00808856 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00783872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00762896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00695136 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00680448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00679424 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00677888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00658568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00630160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00601344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2015-08-10 01:41 - 2015-08-10 01:41 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00578048 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00565088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2015-08-10 01:41 - 2015-08-10 01:41 - 00542720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00521568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00505344 _____ C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00498016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys
2015-08-10 01:41 - 2015-08-10 01:41 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00430592 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcomapi.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00425824 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00416256 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00366592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00343040 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00335248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00328704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00325984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2015-08-10 01:41 - 2015-08-10 01:41 - 00303616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00290312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00265480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00263168 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00242176 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicesFlowBroker.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00208736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\srumsvc.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\OmaDmAgent.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00191488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReInfo.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Privacy.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabSvc.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\spbcd.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\setbcdlocale.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.ProxyStub.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys
2015-08-10 01:41 - 2015-08-10 01:41 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\unenrollhook.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00061280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2015-08-10 01:41 - 2015-08-10 01:41 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.OneCore.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\hmkd.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmprc.exe
2015-08-10 01:41 - 2015-08-10 01:41 - 00046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmUcsi.sys
2015-08-10 01:41 - 2015-08-10 01:41 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hmkd.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-08-10 01:41 - 2015-08-10 01:41 - 00032768 _____ C:\WINDOWS\system32\LicenseManagerApi.dll
2015-08-10 01:39 - 2015-08-10 01:39 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2015-08-10 01:37 - 2015-08-10 01:37 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices
2015-08-10 01:37 - 2015-08-10 01:37 - 00000000 ____D C:\WINDOWS\system32\msmq
2015-08-10 01:37 - 2015-08-10 01:37 - 00000000 ____D C:\WINDOWS\system32\BestPractices
2015-08-10 01:37 - 2015-08-10 01:37 - 00000000 ____D C:\Program Files\Reference Assemblies
2015-08-10 01:37 - 2015-08-10 01:37 - 00000000 ____D C:\Program Files\MSBuild
2015-08-10 01:37 - 2015-08-10 01:37 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2015-08-10 01:37 - 2015-08-10 01:37 - 00000000 ____D C:\Program Files (x86)\MSBuild
2015-08-10 01:37 - 2015-08-10 01:37 - 00000000 ____D C:\inetpub
2015-08-10 01:37 - 2015-05-30 06:07 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2015-08-10 01:37 - 2015-05-30 06:07 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-10 01:37 - 2015-05-30 06:07 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2015-08-10 01:36 - 2015-06-18 03:10 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2015-08-10 01:36 - 2015-06-18 03:10 - 00124112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-10 01:36 - 2015-06-18 03:10 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2015-08-09 18:11 - 2015-08-09 18:11 - 00000000 ____D C:\Users\User\AppData\Local\PeerDistRepub
2015-08-09 17:13 - 2015-09-03 15:33 - 00000000 ____D C:\Users\User\OneDrive
2015-08-09 17:13 - 2015-08-24 07:45 - 00002335 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-08-09 17:12 - 2015-08-14 11:10 - 00000000 ____D C:\Users\User\AppData\Local\MicrosoftEdge
2015-08-09 17:12 - 2015-08-09 17:15 - 00000000 ____D C:\Users\User\AppData\Local\Comms
2015-08-09 17:12 - 2015-08-09 17:12 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2015-08-09 17:11 - 2015-08-09 17:11 - 00001051 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optional Features.lnk
2015-08-09 17:09 - 2015-08-09 17:09 - 00000000 ____D C:\Users\User\AppData\Local\Publishers
2015-08-09 17:08 - 2015-08-25 08:53 - 00000000 ____D C:\Users\User\AppData\Local\Packages
2015-08-09 17:08 - 2015-08-09 17:08 - 00000020 ___SH C:\Users\User\ntuser.ini
2015-08-09 17:08 - 2015-08-09 17:08 - 00000000 ____D C:\Users\User\AppData\Local\TileDataLayer
2015-08-09 17:03 - 2015-08-09 17:03 - 00022744 _____ C:\WINDOWS\system32\emptyregdb.dat
2015-08-09 16:56 - 2015-08-09 16:56 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-08-09 16:56 - 2015-08-09 16:56 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2015-08-09 16:56 - 2015-08-09 16:56 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2015-08-09 16:54 - 2015-08-09 16:54 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines
2015-08-09 16:53 - 2015-08-09 17:08 - 00000000 ___RD C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-09 16:53 - 2015-07-10 12:04 - 00000000 __RSD C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-08-09 16:53 - 2015-07-10 12:04 - 00000000 ___RD C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-09 16:53 - 2015-07-10 12:04 - 00000000 ___RD C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-09 16:53 - 2015-07-10 12:04 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-09 16:51 - 2015-09-03 17:20 - 01005534 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-08-09 16:51 - 2015-08-09 16:52 - 00021209 _____ C:\WINDOWS\iis.log
2015-08-09 16:51 - 2015-08-09 16:51 - 00961296 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2015-08-09 16:50 - 2015-07-10 11:59 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2015-08-09 16:49 - 2015-08-09 16:49 - 00006352 _____ C:\WINDOWS\DPINST.LOG
2015-08-09 16:49 - 2015-08-09 16:49 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_ST_Accel_01009.Wdf
2015-08-09 16:49 - 2015-08-09 16:49 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
2015-08-09 16:49 - 2015-08-09 16:49 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_Apfiltr_01009.Wdf
2015-08-09 16:49 - 2015-08-09 16:49 - 00000000 ____D C:\Program Files\Synaptics
2015-08-09 16:49 - 2015-08-09 16:49 - 00000000 ____D C:\Program Files\STMicroelectronics
2015-08-09 16:49 - 2015-08-09 16:49 - 00000000 ____D C:\Program Files\DIFX
2015-08-09 16:49 - 2015-08-09 16:49 - 00000000 ____D C:\Program Files\DellTPad
2015-08-09 16:49 - 2015-08-09 16:49 - 00000000 ____D C:\Intel
2015-08-09 16:49 - 2011-07-15 21:31 - 00022128 _____ (ST Microelectronics) C:\WINDOWS\system32\Drivers\stdcfltn.sys
2015-08-09 16:47 - 2015-08-09 16:48 - 00024923 _____ C:\WINDOWS\system32\NetSetupMig.log
2015-08-09 16:46 - 2015-08-25 00:08 - 00010134 _____ C:\WINDOWS\PFRO.log
2015-08-09 16:21 - 2015-08-09 17:04 - 00006506 _____ C:\WINDOWS\comsetup.log
2015-08-09 16:19 - 2015-08-09 17:05 - 00010447 _____ C:\WINDOWS\diagerr.xml
2015-08-09 16:19 - 2015-08-09 17:05 - 00009528 _____ C:\WINDOWS\diagwrn.xml
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-03 22:41 - 2015-07-29 16:45 - 00000000 ____D C:\Users\User\AppData\Roaming\Skype
2015-09-03 22:41 - 2015-07-10 13:22 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-09-03 22:39 - 2015-07-29 16:41 - 00169179 _____ C:\lm.log
2015-09-03 22:38 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\sru
2015-09-03 18:31 - 2015-07-23 14:14 - 00000922 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-03 17:47 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-09-03 17:32 - 2015-07-23 14:14 - 00000918 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-03 15:31 - 2015-07-10 13:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-09-02 19:10 - 2012-10-24 12:25 - 00000000 ____D C:\Users\User\Documents\Your counselling S client notes
2015-09-01 04:32 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\rescache
2015-09-01 04:18 - 2015-07-10 10:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-09-01 04:17 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\oobe
2015-09-01 04:17 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-08-31 20:17 - 2013-03-13 15:43 - 00000000 ____D C:\Users\User\Documents\crochet patrone
2015-08-30 15:53 - 2015-07-10 11:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-08-29 15:08 - 2015-07-10 13:20 - 00014260 _____ C:\WINDOWS\setupact.log
2015-08-28 17:26 - 2015-07-23 14:14 - 00003980 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-08-28 17:26 - 2015-07-23 14:14 - 00003748 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-08-28 17:17 - 2013-04-29 19:45 - 00000000 ____D C:\Users\User\Documents\invoices ycs
2015-08-27 08:00 - 2015-07-29 16:45 - 00002640 _____ C:\Users\Public\Desktop\Skype.lnk
2015-08-27 08:00 - 2015-07-29 16:45 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-08-27 08:00 - 2015-07-29 16:45 - 00000000 ____D C:\ProgramData\Skype
2015-08-26 22:15 - 2015-06-04 12:35 - 00000000 ____D C:\Users\User\AppData\Local\VirtualStore
2015-08-24 21:33 - 2015-07-22 23:02 - 00002259 _____ C:\WINDOWS\epplauncher.mif
2015-08-24 21:26 - 2009-07-14 04:20 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2015-08-24 16:57 - 2015-07-23 14:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-08-20 11:56 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2015-08-19 16:01 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2015-08-17 22:29 - 2013-10-07 13:13 - 00000000 ____D C:\Users\User\Documents\YCS Admin
2015-08-16 14:52 - 2015-07-10 13:20 - 00334968 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-08-12 13:21 - 2015-07-23 19:19 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-08-12 13:20 - 2015-07-23 19:15 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-12 13:19 - 2015-07-10 12:04 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-12 13:19 - 2015-07-10 12:04 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-12 13:14 - 2015-06-02 14:07 - 00000000 ____D C:\Users\User\Documents\C3 counselling admin docs
2015-08-12 13:14 - 2012-11-07 11:53 - 00000000 ____D C:\Users\User\Documents\counselling docs
2015-08-12 13:10 - 2009-07-14 03:34 - 00000478 _____ C:\WINDOWS\win.ini
2015-08-11 03:30 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\Provisioning
2015-08-10 21:25 - 2015-07-23 19:15 - 00000000 ____D C:\Users\User\AppData\Local\Microsoft Help
2015-08-10 08:19 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\appcompat
2015-08-10 01:45 - 2015-07-10 12:04 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2015-08-10 01:42 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
2015-08-10 01:42 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2015-08-10 01:42 - 2015-07-10 10:05 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2015-08-10 01:42 - 2015-07-10 10:05 - 00000000 ____D C:\WINDOWS\system32\Dism
2015-08-10 01:37 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2015-08-10 01:37 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2015-08-10 01:37 - 2015-07-10 12:01 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll
2015-08-10 01:37 - 2015-07-10 12:01 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqutil.dll
2015-08-10 01:37 - 2015-07-10 12:01 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.dll
2015-08-10 01:37 - 2015-07-10 12:01 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2015-08-10 01:37 - 2015-07-10 12:01 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqrt.dll
2015-08-10 01:37 - 2015-07-10 12:01 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.tlb
2015-08-10 01:37 - 2015-07-10 12:01 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa30.tlb
2015-08-10 01:37 - 2015-07-10 12:01 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa20.tlb
2015-08-10 01:37 - 2015-07-10 12:01 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2015-08-10 01:37 - 2015-07-10 12:01 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa10.tlb
2015-08-10 01:37 - 2015-07-10 12:01 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2015-08-10 01:37 - 2015-07-10 12:01 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2015-08-10 01:37 - 2015-07-10 12:01 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll
2015-08-10 01:37 - 2015-07-10 12:01 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2015-08-10 01:37 - 2015-07-10 12:01 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2015-08-10 01:37 - 2015-07-10 12:01 - 00009096 _____ C:\WINDOWS\SysWOW64\msmqtrc.mof
2015-08-10 01:37 - 2015-07-10 12:00 - 01417728 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqqm.dll
2015-08-10 01:37 - 2015-07-10 12:00 - 00813056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll
2015-08-10 01:37 - 2015-07-10 12:00 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqutil.dll
2015-08-10 01:37 - 2015-07-10 12:00 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.dll
2015-08-10 01:37 - 2015-07-10 12:00 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqrt.dll
2015-08-10 01:37 - 2015-07-10 12:00 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2015-08-10 01:37 - 2015-07-10 12:00 - 00175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mqac.sys
2015-08-10 01:37 - 2015-07-10 12:00 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqlogmgr.dll
2015-08-10 01:37 - 2015-07-10 12:00 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.tlb
2015-08-10 01:37 - 2015-07-10 12:00 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa30.tlb
2015-08-10 01:37 - 2015-07-10 12:00 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa20.tlb
2015-08-10 01:37 - 2015-07-10 12:00 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2015-08-10 01:37 - 2015-07-10 12:00 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2015-08-10 01:37 - 2015-07-10 12:00 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqbkup.exe
2015-08-10 01:37 - 2015-07-10 12:00 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa10.tlb
2015-08-10 01:37 - 2015-07-10 12:00 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe
2015-08-10 01:37 - 2015-07-10 12:00 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcertui.dll
2015-08-10 01:37 - 2015-07-10 12:00 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2015-08-10 01:37 - 2015-07-10 12:00 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2015-08-10 01:37 - 2015-07-10 12:00 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2015-08-10 01:37 - 2015-07-10 12:00 - 00009096 _____ C:\WINDOWS\system32\msmqtrc.mof
2015-08-09 17:54 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\restore
2015-08-09 17:11 - 2015-07-10 14:12 - 00000000 ____D C:\WINDOWS\OCR
2015-08-09 17:09 - 2015-07-10 12:04 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2015-08-09 17:09 - 2015-07-10 12:04 - 00000000 ___RD C:\WINDOWS\PrintDialog
2015-08-09 17:09 - 2015-07-10 12:04 - 00000000 ___RD C:\WINDOWS\MiracastView
2015-08-09 17:09 - 2015-07-10 12:04 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2015-08-09 17:05 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\Registration
2015-08-09 17:03 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\spool
2015-08-09 17:01 - 2015-07-10 12:04 - 00000000 __RSD C:\WINDOWS\Media
2015-08-09 17:01 - 2015-07-10 12:04 - 00000000 __RHD C:\Users\Public\Libraries
2015-08-09 16:56 - 2015-07-10 14:14 - 00000000 ____D C:\WINDOWS\ShellNew
2015-08-09 16:56 - 2015-07-10 12:05 - 00004362 _____ C:\WINDOWS\DtcInstall.log
2015-08-09 16:56 - 2015-07-10 12:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-09 16:56 - 2015-07-10 10:05 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2015-08-09 16:56 - 2009-07-14 04:20 - 00000000 ____D C:\Users\Default.migrated
2015-08-09 16:55 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\SysWOW64\zh-HK
2015-08-09 16:55 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\SysWOW64\tr-TR
2015-08-09 16:55 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2015-08-09 16:55 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2015-08-09 16:55 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\zh-HK
2015-08-09 16:55 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\tr-TR
2015-08-09 16:55 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\IME
2015-08-09 16:54 - 2015-07-10 12:04 - 00000000 __SHD C:\Program Files\Windows Sidebar
2015-08-09 16:54 - 2015-07-10 12:04 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2015-08-09 16:54 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\schemas
2015-08-09 16:54 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2015-08-09 16:54 - 2015-07-10 12:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-08-09 16:54 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\DVD Maker
2015-08-09 16:53 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\Recovery
2015-08-09 16:51 - 2015-07-10 10:05 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2015-08-09 16:46 - 2015-07-10 10:05 - 00000000 __RHD C:\Users\Default
2015-08-09 16:27 - 2015-06-04 12:32 - 01618734 _____ C:\WINDOWS\WindowsUpdate (1).log
2015-08-09 16:23 - 2009-07-14 05:45 - 00022096 ____H C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-09 16:23 - 2009-07-14 05:45 - 00022096 ____H C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-08 16:38 - 2015-07-10 12:06 - 00794088 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-08-08 16:38 - 2015-07-10 12:06 - 00179688 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
 
==================== Files in the root of some directories =======
 
2015-08-25 08:16 - 2015-08-26 22:35 - 0180062 _____ () C:\Users\User\AppData\Local\ars.cache
2015-08-25 08:16 - 2015-08-26 22:36 - 0498461 _____ () C:\Users\User\AppData\Local\census.cache
2015-08-25 08:07 - 2015-08-25 08:07 - 0000036 _____ () C:\Users\User\AppData\Local\housecall.guid.cache
2015-08-25 08:12 - 2015-08-26 22:27 - 0000010 _____ () C:\Users\User\AppData\Local\sponge.last.runtime.cache
 
Some files in TEMP:
====================
C:\Users\User\AppData\Local\Temp\adobe_reader.exe
C:\Users\User\AppData\Local\Temp\SkypeSetup.exe
C:\Users\User\AppData\Local\Temp\sqlite3.dll
 

==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 

LastRegBack: 2015-08-27 02:28
 
==================== End of FRST.txt ============================


#10 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,078 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:12:38 AM

Posted 04 September 2015 - 04:05 AM

Hi Henniee,
 
Download Emsisoft Emergency Kit and save it to your desktop. Double click on EmsisoftEmergencyKit.exe to extract its contents and create a shortcut on the desktop. Leave all settings as they are and click  Accept & Extract. A folder named EEK will be created in the root of the drive (usually c:\). .

  • After extraction an Emsisoft Emergency Kit window will open. Under "Run Directly:" click Emergency Kit Scanner.
  • When asked to run an online update, click Yes.
  • When the update is finished, click the Back to Security Status link in the left corner. On the main screen click the Scan Now button.
  • Select the Full Scan option and click the SCAN button.
  • When the scan is finished click the Quarantine selected objects button. Note, this option is only available if malicious objects were detected during the scan.
  • Click the View Report button and in the Reports window double-click on the most recent log. Note, logs are named as follows: a2scan_<date>-<time>.txt.
  • Copy/paste the report contents in your next reply.

--------------
 
This scan can take a long time, so it is best done overnight or when you do not need the computer
 
I'd like us to scan your machine with ESET OnlineScan

  • Hold down Control and click on this link to open ESET OnlineScan in a new window.
  • Click the esetonlinebtn.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the esetsmartinstaller_enu.png icon on your desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.

--------------
 
To recap, in your next reply I would like to see the following. Make sure to copy & paste them unless I ask otherwise:

  • Emsisoft log
  • ESET log

xXToffeeXx~


~If I am helping you and you have not had a reply from me in two days, please send me a PM~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


#11 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,078 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:12:38 AM

Posted 08 September 2015 - 12:00 PM

Hi Henniee,
 
This is a 3 day bump:
 
It has been more than 3 days since my last post.

  • Do you still need help with this?
  • If after 48hrs you have not replied to this thread then it will have to be closed.

xXToffeeXx~


~If I am helping you and you have not had a reply from me in two days, please send me a PM~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


#12 Henniee

Henniee
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:11:38 PM

Posted 08 September 2015 - 06:47 PM

I will do this tonight. Sorry we were away for a few days. 



#13 Henniee

Henniee
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:11:38 PM

Posted 10 September 2015 - 01:54 AM

EMI Log

Attached Files



#14 Henniee

Henniee
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:11:38 PM

Posted 10 September 2015 - 05:11 PM

Results from the ESET scan. It has put some files in Quatrinteen

Attached Files

  • Attached File  ESET.PNG   97.12KB   0 downloads


#15 Henniee

Henniee
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:11:38 PM

Posted 10 September 2015 - 05:25 PM

Emsisoft Emergency Kit - Version 10.0
Last update: 2015-09-09 10:40:53 PM
User account: User-PC\User
 
Scan settings:
 
Scan type: Malware Scan
Objects: Rootkits, Memory, Traces, Files
 
Detect PUPs: On
Scan archives: Off
ADS Scan: On
File extension filter: Off
Advanced caching: On
Direct disk access: Off
 
Scan start: 2015-09-10 11:12:19 PM
 
Scanned 98971
Found 0
 
Scan end: 2015-09-10 11:23:48 PM
Scan time: 0:11:29





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users