Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Win32/patched.Ap


  • This topic is locked This topic is locked
30 replies to this topic

#1 Craig Ingle

Craig Ingle

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cleveland, ohio
  • Local time:10:02 AM

Posted 01 October 2015 - 11:01 PM

What is this, and when I removed it I couldn't reinstall anything.

Win10,office365,Asus 64 bit

BC AdBot (Login to Remove)

 


#2 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,037 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:02 AM

Posted 02 October 2015 - 07:16 PM

Greetings Craig Ingle and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

===================================================

Ground Rules:
  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met.
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • When you post your reply, use the Replytopic.jpg button instead.
  • In the upper right hand corner of the topic you will see the Followtopic.jpg button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far.

Please do this.

===================================================

Farbar Recovery Scan Tool (FRST)

--------------------
  • Download Farbar Recover Scan Tool for either 32 bit or 64 bit systems and save it to your desktop <<< Important
  • If you are unsure if you have 32 bit or 64 bit simply download and try one. If that doesn't run properly the other one should
  • Double click the icon
  • Click Yes to the disclaimer
  • Make sure the Addition.txt box is checked
  • Click Scan and allow the program to run
  • Click OK on the Scan complete screen, then OK on the Addition.txt pop up screen
  • 2 Notepad documents should now be open on your desktop.
  • Please copy and paste the contents of both in your reply
===================================================

System Summary Information

--------------------
  • Press the windows key Windows_Logo_key.gif + r on your keyboard at the same time
  • Type msinfo32 and press Enter
  • Left click on System Summary
  • Click File, Save, and name the file Summary
  • Zip and attach the file to your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • FRST results
  • Addition log
  • System Summary Information

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#3 Craig Ingle

Craig Ingle
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cleveland, ohio
  • Local time:10:02 AM

Posted 02 October 2015 - 08:43 PM

Thank you Gary. I will Post tomorrow

#4 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,037 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:02 AM

Posted 02 October 2015 - 09:03 PM

:thumbsup2:
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#5 Craig Ingle

Craig Ingle
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cleveland, ohio
  • Local time:10:02 AM

Posted 03 October 2015 - 07:51 AM

It seems that I am having a problem trying to attach files, and reply to you on my comp. It seems that I will need to attempt to do this another way. I cannot email, attach files to my reply, it won't allow me to reply, it says that I must enter a post. I have tried several times. Any advise?

#6 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,037 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:02 AM

Posted 03 October 2015 - 07:58 AM

Try to do it in Safe Mode with Networking.


Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#7 Craig Ingle

Craig Ingle
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cleveland, ohio
  • Local time:10:02 AM

Posted 03 October 2015 - 08:43 AM

I will try later. I have to work till 9pm tonight if it doesnt work I am going to work through my other computer.

#8 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,037 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:02 AM

Posted 03 October 2015 - 02:38 PM

Great, thanks for letting me know.


Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#9 Craig Ingle

Craig Ingle
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cleveland, ohio
  • Local time:10:02 AM

Posted 03 October 2015 - 09:27 PM

Additional scan result of Farbar Recovery Scan Tool (x64) Version:03-10-2015
Ran by Pat (2015-10-03 08:19:05)
Running from C:\Users\Pat\Desktop
Windows 10 Pro (X64) (2015-09-11 02:09:12)
Boot Mode: Normal
==========================================================
 

==================== Accounts: =============================
 
Administrator (S-1-5-21-600590886-3396321983-1423553912-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-600590886-3396321983-1423553912-503 - Limited - Disabled)
Guest (S-1-5-21-600590886-3396321983-1423553912-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-600590886-3396321983-1423553912-1002 - Limited - Enabled)
Pat (S-1-5-21-600590886-3396321983-1423553912-1001 - Administrator - Enabled) => C:\Users\Pat
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD)
CCleaner (HKLM\...\CCleaner) (Version: 5.09 - Piriform)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Eassos PartitionGuru Free 3.7.0 (HKLM\...\{971F12D0-D834-4BAC-BD22-8769EBA08106}_is1) (Version:  - Eassos Co., Ltd.)
Free Easy Burner V 5.1 (HKLM-x32\...\Free Easy Burner_is1) (Version: 5.1.0.0 - Koyote soft)
globalupdate Helper (x32 Version: 1.3.25.0 - globalupdate Inc.) Hidden <==== ATTENTION
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 45.0.2454.101 - Google Inc.)
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft Money Plus (HKLM-x32\...\Money2008b) (Version: 17 - Microsoft)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
MiniTool Partition Wizard Free 9.1 (HKLM\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version:  - MiniTool Solution Ltd.)
MoneyLine (HKLM-x32\...\MoneyLine) (Version: 1.30 - NCH Software)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4753.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4753.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4753.1003 - Microsoft Corporation) Hidden
SeaTools for Windows 1.4.0.2 (HKLM-x32\...\SeaTools for Windows) (Version: 1.4.0.2 - Seagate Technology)
Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version:  - 2K Games, Inc.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Unity Web Player (HKU\S-1-5-21-600590886-3396321983-1423553912-1001\...\UnityWebPlayer) (Version: 4.6.1f1 - Unity Technologies ApS)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 

==================== Restore Points =========================
 
20-09-2015 09:24:25 avast! antivirus system restore point
24-09-2015 09:17:07 Windows Update
27-09-2015 11:08:11 Windows Update
30-09-2015 00:56:45 Installed QIF - CSV converter for MS Money 2001
01-10-2015 11:50:26 Installed DirectX
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 22:34 - 2015-09-16 21:49 - 00000768 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {005D3856-8599-4280-98FF-65E3C3E560F6} - \SPBIW_UpdateTask_Time_313831323534333439352d414a34413734452a786c5a5a -> No File <==== ATTENTION
Task: {0213099C-F9BC-47ED-B23D-E4FCB80057E5} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {1074471E-22AD-4750-BFF0-596D17457693} - \ShopperProJSUpd -> No File <==== ATTENTION
Task: {10CF9999-D29D-41F6-B740-C126EC62F36C} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {139EC17F-C21A-42CF-85C1-06ED5AFF8A89} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-10] (Google Inc.)
Task: {1AA797CE-735C-4A96-8B8A-859290F38316} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {1B567DF6-9FBA-4604-B2C7-B6548DD0AEBF} - \a02fd56e-2d4a-4e4a-8093-f8bd6f693298-1-7 -> No File <==== ATTENTION
Task: {25F5A4F0-E06D-4CA0-8228-E4300FF06CDA} - \a02fd56e-2d4a-4e4a-8093-f8bd6f693298-1-6 -> No File <==== ATTENTION
Task: {29185FA4-F933-4075-BDED-D2279DA2C1EF} - \a02fd56e-2d4a-4e4a-8093-f8bd6f693298-5 -> No File <==== ATTENTION
Task: {2D8226D7-F129-4D93-BE87-2F6CAE075759} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {2FB08624-24B8-4A41-8A00-C81642AF7E1F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-08-19] (Piriform Ltd)
Task: {3781A485-7109-40BF-8061-E3EF5E23D960} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {380623F4-033C-490B-B181-0B8DE53A1627} - System32\Tasks\AdobeoaUpdate Ver 2015916 => C:\Users\Pat\AppData\Roaming\wenguanjia\SurfAnonymous.exe
Task: {3997AF28-CF6B-415C-A302-9258D48B339A} - \a02fd56e-2d4a-4e4a-8093-f8bd6f693298-3 -> No File <==== ATTENTION
Task: {3C62ACD9-C1C2-4F64-B7F7-45B32CD72861} - \globalUpdateUpdateTaskMachineUA -> No File <==== ATTENTION
Task: {3CC0B8B3-928E-42DA-AF10-650A105EA88C} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe
Task: {3D093294-FE03-46CE-88CE-D898C8DF4E8E} - \Crossbrowse -> No File <==== ATTENTION
Task: {3F4FFA65-92DF-4B87-89E2-6193BFF97DF0} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {43892FA5-35FD-4A1D-9924-6EF6ED6E03B4} - \a02fd56e-2d4a-4e4a-8093-f8bd6f693298-10_user -> No File <==== ATTENTION
Task: {44DB775C-B3DF-465F-A615-15962FEBA31F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-09-10] (Adobe Systems Incorporated)
Task: {4A05BCEA-4C64-4B94-B4BE-3ABC345D37DA} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {4DD2C26F-A800-42D5-A31C-02AB8D205F64} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe
Task: {4E183A44-4121-44DA-B14B-C61D81C9BA59} - \CIMT_daily_S-1-5-21-600590886-3396321983-1423553912-1001 -> No File <==== ATTENTION
Task: {4F514E01-5C92-4F42-A3CE-699B8751FC79} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {54B4C875-9163-4510-AECF-D23916C82784} - \Smp -> No File <==== ATTENTION
Task: {59A104D7-AE42-46B2-9EAB-E6ACEBFD05C9} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {5A54B475-8470-408B-ACBD-29DBC79CEB39} - \bvxvdxvx -> No File <==== ATTENTION
Task: {60839DF6-8F16-4E34-82A0-C1E8499C84DE} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {6658BDD6-B5F4-419C-9326-3E58CF81238D} - \WordWizard Auto Updater 1.10.0.24 Core -> No File <==== ATTENTION
Task: {668840DB-4716-4143-AEAD-F0AAAB4D60B0} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {68A55A05-53D9-4AD5-BBE0-6CA28342163A} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {696E4CCD-2331-43B5-B5ED-86BE180012EE} - \1d0c7614-17dd-45d3-87db-fb5a0553396a-7 -> No File <==== ATTENTION
Task: {6F07B5AC-D531-4D71-8F76-48E8EFA50464} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {7060C6D1-A498-45FE-8212-9533A6EF2BB6} - \ConsumerInputUpdateTaskMachineCore -> No File <==== ATTENTION
Task: {75B4A485-9D3F-4677-BA77-67A5923CE9D3} - \a02fd56e-2d4a-4e4a-8093-f8bd6f693298-6 -> No File <==== ATTENTION
Task: {787D21E4-6706-443A-B13F-CC57C1B72755} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-10] (Google Inc.)
Task: {891CC45A-296D-448E-96C2-A5D4E3F750E2} - \a02fd56e-2d4a-4e4a-8093-f8bd6f693298-5_user -> No File <==== ATTENTION
Task: {8E3B5EA4-1F7D-4487-A3BD-4BD7AF97BDB6} - \1d0c7614-17dd-45d3-87db-fb5a0553396a-1-6 -> No File <==== ATTENTION
Task: {8F4C3A2F-D807-437E-BAA4-10DF9721ED47} - \Microsoft\Windows\File Classification Infrastructure\Property Definition Sync -> No File <==== ATTENTION
Task: {9A87FFFC-CBA1-45DA-A8FD-D500580D550D} - \Optimizer Pro Schedule -> No File <==== ATTENTION
Task: {9BCA65E4-73C4-4678-961B-99108E600362} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {9D0AFD14-5396-4425-988E-265EA74CC042} - \globalUpdateUpdateTaskMachineCore -> No File <==== ATTENTION
Task: {9DCD1274-C8E9-4AF6-95E0-98D5DE8745CF} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {9F365388-C017-4663-B6D8-CAA5FEEC84B7} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {A17F73EA-ED22-437B-8342-F3B292265913} - \1d0c7614-17dd-45d3-87db-fb5a0553396a-10_user -> No File <==== ATTENTION
Task: {B18ED546-21F0-489F-BDDF-99C07333FCB7} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {B906EA0C-23CA-4E9D-A469-9A1B27C27503} - \WordWizard Auto Updater 1.10.0.24 Pending Update -> No File <==== ATTENTION
Task: {BD45C90F-98E8-406B-9B78-9E034F79404E} - \1d0c7614-17dd-45d3-87db-fb5a0553396a-1-7 -> No File <==== ATTENTION
Task: {BE9890C9-C251-4D74-8560-718CB357E8DB} - \ConsumerInputUpdateTaskMachineUA -> No File <==== ATTENTION
Task: {C4AF0496-11C9-4D5A-B6BA-52DF94C10A38} - \SMW_UpdateTask_Time_313831323534333439352d414a34413734452a786c5a5a -> No File <==== ATTENTION
Task: {C7BEEE96-4E7B-4DFF-A43F-F8DBB5A76D35} - \1d0c7614-17dd-45d3-87db-fb5a0553396a-5 -> No File <==== ATTENTION
Task: {D0EA6EAE-3186-433A-BDFC-3A40C11455FC} - \1d0c7614-17dd-45d3-87db-fb5a0553396a-6 -> No File <==== ATTENTION
Task: {DBB8422F-5AE8-4C68-A854-03E3B522CAD2} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {DFF97CFA-E7C4-47B2-AF6F-37F774A2CC55} - \a02fd56e-2d4a-4e4a-8093-f8bd6f693298-7 -> No File <==== ATTENTION
Task: {E1B8F5B6-C4F3-486A-9DF6-D89445C03611} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {E7B896B2-91BB-4148-BFF9-392014A70F8B} - \AmiUpdXp -> No File <==== ATTENTION
Task: {EDD611C1-0ECD-4680-A1CB-A9A376726CA2} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {EF5C783B-F02C-4A74-B960-3C975D7DBFB4} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {F284DC08-E8F5-4A12-8DB4-B963A5E7B938} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {F29D6ED7-7D70-43D7-BE00-D1B716807D02} - \1d0c7614-17dd-45d3-87db-fb5a0553396a-5_user -> No File <==== ATTENTION
Task: {F46C268C-B0E1-425E-B8D6-0FDC482919EC} - \CIMT_S-1-5-21-600590886-3396321983-1423553912-1001 -> No File <==== ATTENTION
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\AdobeoaUpdate Ver 2015916.job => C:\Users\Pat\AppData\Roaming\wenguanjia\SurfAnonymous.exe/check_update C:\Users\Pat\AppData\Roaming\wenguanjia\mom\Pat(This task detect has update.Ver
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-09-11 01:47 - 2015-09-11 01:47 - 00032768 _____ () C:\WINDOWS\SYSTEM32\licensemanagerapi.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00404480 _____ () C:\WINDOWS\System32\diagtrack_wininternal.dll
2015-10-01 17:36 - 2015-09-17 02:48 - 02494712 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-10-01 17:36 - 2015-09-17 02:48 - 02494712 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-10-01 17:36 - 2015-09-17 01:48 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-10-01 17:36 - 2015-09-17 01:44 - 06569472 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2015-10-01 17:35 - 2015-09-17 01:42 - 00471040 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-10-01 17:35 - 2015-09-17 01:42 - 01808384 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2015-10-01 17:36 - 2015-09-17 01:43 - 02274816 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-08-03 15:59 - 2015-08-03 15:59 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2015-09-17 12:32 - 2015-07-03 12:12 - 00778240 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2015-09-17 12:32 - 2015-07-03 12:12 - 04962816 _____ () C:\Program Files (x86)\Steam\v8.dll
2015-09-17 12:32 - 2015-08-19 16:39 - 02413248 _____ () C:\Program Files (x86)\Steam\video.dll
2015-09-17 12:32 - 2014-12-01 17:31 - 02396672 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
2015-09-17 12:32 - 2014-12-01 17:31 - 00479744 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
2015-09-17 12:32 - 2014-12-01 17:31 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
2015-09-17 12:32 - 2014-12-01 17:31 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
2015-09-17 12:32 - 2014-12-01 17:31 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
2015-09-17 12:32 - 2015-07-03 12:12 - 01187840 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2015-09-17 12:32 - 2015-07-03 12:12 - 01556992 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2015-09-17 12:32 - 2015-08-19 16:39 - 00704192 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2015-09-17 12:32 - 2015-07-26 21:13 - 00171008 _____ () C:\Program Files (x86)\Steam\bin\openvr_api.dll
2015-09-17 12:32 - 2015-07-03 12:12 - 39553928 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 

==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 

==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 

==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 

==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-600590886-3396321983-1423553912-1001\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
DNS Servers: 64.233.214.34 - 64.233.214.41
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-600590886-3396321983-1423553912-1001\...\StartupApproved\Run: => "OneDrive"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{1FB4A916-3806-438A-B11D-6131540119A9}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{5C356976-CBFF-466D-8733-7885921EF2D7}] => (Allow) LPort=2869
FirewallRules: [{C192CA8C-2FC0-423C-8B81-4EF45CAC4621}] => (Allow) LPort=1900
FirewallRules: [{9E9AAB97-F147-4B09-97DC-81D3BD8BCBEB}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{7BD7C173-AD1E-473B-B822-52D0B7463509}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{E1B247DA-4773-4D65-8198-7093EE29F8FD}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [{07CD6B2B-FDAF-45E9-8665-0594DA234F71}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{8B35AF0D-AC2B-49C0-AC36-49F8371298F5}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{0FCB6A56-4F26-440E-BEA8-B9458F8D26C7}] => (Allow) D:\SteamLibrary\steamapps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{DF64CCE8-0541-44B3-B935-6FB9540C85F7}] => (Allow) D:\SteamLibrary\steamapps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{24F15377-5B7F-4571-8822-6830E138EA94}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Faulty Device Manager Devices =============
 

==================== Event log errors: =========================
 
Application errors:
==================
Error: (10/03/2015 08:13:48 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: DV.exe, version: 1.0.0.0, time stamp: 0x55e96721
Faulting module name: KERNELBASE.dll, version: 10.0.10240.16384, time stamp: 0x559f3b2a
Exception code: 0xe0434352
Fault offset: 0x000b3e28
Faulting process id: 0x13c8
Faulting application start time: 0xDV.exe0
Faulting application path: DV.exe1
Faulting module path: DV.exe2
Report Id: DV.exe3
Faulting package full name: DV.exe4
Faulting package-relative application ID: DV.exe5
 
Error: (10/03/2015 08:13:46 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: DV.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.Windows.Markup.XamlParseException
Stack:
   at System.Windows.Markup.WpfXamlLoader.Load(System.Xaml.XamlReader, System.Xaml.IXamlObjectWriterFactory, Boolean, System.Object, System.Xaml.XamlObjectWriterSettings, System.Uri)
   at System.Windows.Markup.WpfXamlLoader.LoadBaml(System.Xaml.XamlReader, Boolean, System.Object, System.Xaml.Permissions.XamlAccessLevel, System.Uri)
   at System.Windows.Markup.XamlReader.LoadBaml(System.IO.Stream, System.Windows.Markup.ParserContext, System.Object, Boolean)
   at System.Windows.Application.LoadBamlStreamWithSyncInfo(System.IO.Stream, System.Windows.Markup.ParserContext)
   at System.Windows.Application.LoadComponent(System.Uri, Boolean)
   at System.Windows.Application.DoStartup()
   at System.Windows.Application.<_ctor>b__0(System.Object)
   at System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
   at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
   at System.Windows.Threading.DispatcherOperation.InvokeImpl()
   at System.Windows.Threading.DispatcherOperation.InvokeInSecurityContext(System.Object)
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   at System.Windows.Threading.DispatcherOperation.Invoke()
   at System.Windows.Threading.Dispatcher.ProcessQueue()
   at System.Windows.Threading.Dispatcher.WndProcHook(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
   at MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
   at MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object)
   at System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
   at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
   at System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
   at MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
   at MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef)
   at System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame)
   at System.Windows.Threading.Dispatcher.PushFrame(System.Windows.Threading.DispatcherFrame)
   at System.Windows.Application.RunDispatcher(System.Object)
   at System.Windows.Application.RunInternal(System.Windows.Window)
   at System.Windows.Application.Run(System.Windows.Window)
   at System.Windows.Application.Run()
   at demoforupdaterwindow.App.Main()
 
Error: (10/03/2015 08:13:11 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: mom)
Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2147009284 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (10/03/2015 08:13:11 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: mom)
Description: Activation of app Microsoft.WindowsStore_8wekyb3d8bbwe!App failed with error: -2147009284 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (10/03/2015 08:13:10 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: mom)
Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2147009284 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (10/03/2015 03:24:36 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: mom)
Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (10/03/2015 03:02:49 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: mom)
Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2147009284 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (10/03/2015 03:00:43 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: mom)
Description: Activation of app Microsoft.WindowsStore_8wekyb3d8bbwe!App failed with error: -2147009284 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (10/03/2015 03:00:43 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: mom)
Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2147009284 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (10/03/2015 02:39:59 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: mom)
Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2147009284 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 

System errors:
=============
Error: (10/03/2015 03:24:36 AM) (Source: DCOM) (EventID: 10010) (User: mom)
Description: CortanaUI.AppXd4tad4d57t4wtdbnnmb8v2xtzym8c1n8.mca
 
Error: (10/03/2015 03:24:35 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Access_Session2 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (10/03/2015 03:24:35 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Storage_Session2 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (10/03/2015 03:24:35 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Contact Data_Session2 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (10/03/2015 03:24:35 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Sync Host_Session2 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (10/02/2015 07:09:45 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Access_Session1 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (10/02/2015 07:09:45 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Storage_Session1 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (10/02/2015 07:09:45 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Contact Data_Session1 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (10/02/2015 07:09:45 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Sync Host_Session1 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (10/02/2015 06:27:17 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The MBAMService service failed to start due to the following error:
%%1053
 

CodeIntegrity:
===================================
  Date: 2015-10-03 08:16:40.574
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\dnsapi.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-10-02 20:27:06.089
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.stdformat.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2015-10-02 20:27:06.043
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2015-10-02 20:27:05.995
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\msdatasrc.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2015-10-02 20:27:05.940
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.stdformat.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2015-10-02 20:27:05.911
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2015-10-02 20:27:05.856
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\msdatasrc.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2015-10-02 20:27:04.979
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2015-10-02 20:27:04.860
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2015-10-02 20:23:59.006
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.stdformat.dll that did not meet the Microsoft signing level requirements.
 

==================== Memory info ===========================
 
Processor: AMD Phenom™ II X6 1035T Processor
Percentage of memory in use: 24%
Total physical RAM: 7935.17 MB
Available physical RAM: 6003.51 MB
Total Virtual: 15871.17 MB
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:03-10-2015
Ran by Pat (administrator) on MOM (03-10-2015 08:17:23)
Running from C:\Users\Pat\Desktop
Loaded Profiles: Pat (Available Profiles: Pat & DefaultAppPool)
Platform: Windows 10 Pro (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AMD) C:\Windows\System32\atiesrxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16464_none_116100d161f6ab1d\TiWorker.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\ielowutil.exe
 

==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-03] (Advanced Micro Devices, Inc.)
HKU\S-1-5-21-600590886-3396321983-1423553912-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8455960 2015-08-19] (Piriform Ltd)
HKU\S-1-5-21-600590886-3396321983-1423553912-1001\...\Run: [DV] => C:\ProgramData\DataFile\Downloads\DV.exe [277504 2015-09-04] ()
HKU\S-1-5-21-600590886-3396321983-1423553912-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2899136 2015-08-19] (Valve Corporation)
HKU\S-1-5-21-600590886-3396321983-1423553912-1001\...\MountPoints2: {d88eb84c-5a5f-11e5-9bca-485b39d00a60} - "J:\VZW_Software_upgrade_assistant.exe"
ShellIconOverlayIdentifiers: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL No File
ShellIconOverlayIdentifiers: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL No File
ShellIconOverlayIdentifiers: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: 127.0.0.1 localhost
Tcpip\Parameters: [DhcpNameServer] 64.233.214.34 64.233.214.41
Tcpip\..\Interfaces\{47bf83c5-5a15-4b93-bdcb-dc834aa265d2}: [DhcpNameServer] 64.233.214.34 64.233.214.41
 
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-600590886-3396321983-1423553912-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-600590886-3396321983-1423553912-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-600590886-3396321983-1423553912-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
 
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [No File]
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-600590886-3396321983-1423553912-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Pat\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-12-05] (Unity Technologies ApS)
 
Chrome:
=======
CHR DefaultSearchURL: Default -> hxxp://www-searching.com/search.aspx?s=F9Gztutdk0004,9103000e-13fa-4f20-853b-5965f4688790,&q={searchTerms}
CHR DefaultSearchKeyword: Default -> www-searching.com
CHR DefaultSuggestURL: Default -> hxxp://api.searchpredict.com/api/?rqtype=ffplugin&siteID=8661&dbCode=1&command={searchTerms}
CHR Profile: C:\Users\Pat\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Pat\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-09-10]
CHR Extension: (Google Docs) - C:\Users\Pat\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-09-10]
CHR Extension: (Google Drive) - C:\Users\Pat\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-09-10]
CHR Extension: (YouTube) - C:\Users\Pat\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-10]
CHR Extension: (Google Search) - C:\Users\Pat\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-09-10]
CHR Extension: (Google Sheets) - C:\Users\Pat\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-09-10]
CHR Extension: (Google Docs Offline) - C:\Users\Pat\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-10]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Pat\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-09-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Pat\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-09-10]
CHR Extension: (Gmail) - C:\Users\Pat\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-09-10]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-03] (Advanced Micro Devices, Inc.) [File not signed]
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [26112 2015-09-11] (Microsoft Corporation)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [36504 2015-06-22] (VIA Technologies, Inc.)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [84480 2015-09-11] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [578560 2015-09-11] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [102912 2015-09-10] (Advanced Micro Devices)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [113880 2015-09-16] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [175104 2015-09-11] (Microsoft Corporation)
R3 MTsensor; C:\Windows\system32\DRIVERS\ASACPI.sys [17280 2013-05-17] ()
R0 pwdrvio; C:\Windows\System32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [587264 2015-07-10] (Realtek                                            )
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [35064 2015-09-16] ()
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
U3 idsvc; no ImagePath
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 

==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-10-03 08:17 - 2015-10-03 08:17 - 00011629 _____ C:\Users\Pat\Desktop\FRST.txt
2015-10-03 08:17 - 2015-10-03 08:17 - 00000000 ____D C:\FRST
2015-10-03 08:15 - 2015-10-03 08:16 - 02193408 _____ (Farbar) C:\Users\Pat\Desktop\FRST64.exe
2015-10-03 08:13 - 2015-10-03 08:13 - 00016148 _____ C:\WINDOWS\system32\MOM_Pat_HistoryPrediction.bin
2015-10-01 18:16 - 2015-10-01 18:21 - 02875456 _____ (Microsoft Corporation) C:\Users\Pat\Downloads\Setup.X86.en-US_O365HomePremRetail_d9153e04-460f-46a5-ac7d-0bdbbeab8ad1_TX_PR_ (3).exe
2015-10-01 18:15 - 2015-10-01 18:21 - 02875456 _____ (Microsoft Corporation) C:\Users\Pat\Downloads\Setup.X86.en-US_O365HomePremRetail_d9153e04-460f-46a5-ac7d-0bdbbeab8ad1_TX_PR_ (2).exe
2015-10-01 18:10 - 2015-10-01 18:10 - 00004392 _____ C:\WINDOWS\PFRO.log
2015-10-01 18:06 - 2015-10-01 18:06 - 00997927 _____ C:\Users\Pat\Downloads\O15CTRRemove (1).diagcab
2015-10-01 18:05 - 2015-10-01 18:06 - 02875456 _____ (Microsoft Corporation) C:\Users\Pat\Downloads\Setup.X86.en-US_O365HomePremRetail_d9153e04-460f-46a5-ac7d-0bdbbeab8ad1_TX_PR_ (1).exe
2015-10-01 17:39 - 2015-10-01 17:39 - 00997927 _____ C:\Users\Pat\Downloads\O15CTRRemove.diagcab
2015-10-01 17:38 - 2015-10-01 17:38 - 02875456 _____ (Microsoft Corporation) C:\Users\Pat\Downloads\Setup.X86.en-US_O365HomePremRetail_d9153e04-460f-46a5-ac7d-0bdbbeab8ad1_TX_PR_.exe
2015-10-01 17:36 - 2015-09-24 20:13 - 01276416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2015-10-01 17:36 - 2015-09-24 19:24 - 00796160 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2015-10-01 17:36 - 2015-09-24 19:24 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2015-10-01 17:36 - 2015-09-24 19:23 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-10-01 17:36 - 2015-09-24 19:17 - 02178560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-10-01 17:36 - 2015-09-24 19:08 - 03586560 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-10-01 17:36 - 2015-09-24 19:07 - 01382400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-10-01 17:36 - 2015-09-24 19:06 - 01423872 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2015-10-01 17:36 - 2015-09-24 19:01 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2015-10-01 17:36 - 2015-09-24 19:00 - 01205248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2015-10-01 17:36 - 2015-09-24 18:53 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2015-10-01 17:36 - 2015-09-24 18:43 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2015-10-01 17:36 - 2015-09-24 18:42 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-10-01 17:36 - 2015-09-24 18:25 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2015-10-01 17:36 - 2015-09-24 18:25 - 00625152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2015-10-01 17:36 - 2015-09-24 18:19 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2015-10-01 17:36 - 2015-09-17 02:50 - 02464216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-10-01 17:36 - 2015-09-17 02:50 - 01563392 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2015-10-01 17:36 - 2015-09-17 02:49 - 08020816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-10-01 17:36 - 2015-09-17 02:49 - 06487248 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2015-10-01 17:36 - 2015-09-17 02:49 - 01563472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2015-10-01 17:36 - 2015-09-17 02:49 - 00894256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Wdf01000.sys
2015-10-01 17:36 - 2015-09-17 02:49 - 00553808 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2015-10-01 17:36 - 2015-09-17 02:48 - 02824248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2015-10-01 17:36 - 2015-09-17 02:48 - 02494712 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2015-10-01 17:36 - 2015-09-17 02:48 - 02432336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2015-10-01 17:36 - 2015-09-17 02:48 - 02156400 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
2015-10-01 17:36 - 2015-09-17 02:48 - 01983824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2015-10-01 17:36 - 2015-09-17 02:48 - 00809352 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2015-10-01 17:36 - 2015-09-17 02:48 - 00784136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2015-10-01 17:36 - 2015-09-17 02:48 - 00584656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2015-10-01 17:36 - 2015-09-17 02:48 - 00555768 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll
2015-10-01 17:36 - 2015-09-17 02:48 - 00537080 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2015-10-01 17:36 - 2015-09-17 02:48 - 00516448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-10-01 17:36 - 2015-09-17 02:48 - 00505696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2015-10-01 17:36 - 2015-09-17 02:48 - 00476760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2015-10-01 17:36 - 2015-09-17 02:48 - 00395088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2015-10-01 17:36 - 2015-09-17 02:48 - 00332624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2015-10-01 17:36 - 2015-09-17 02:48 - 00243760 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-10-01 17:36 - 2015-09-17 02:47 - 01397088 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-10-01 17:36 - 2015-09-17 02:44 - 00781976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2015-10-01 17:36 - 2015-09-17 02:43 - 00966416 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2015-10-01 17:36 - 2015-09-17 02:37 - 01295712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2015-10-01 17:36 - 2015-09-17 02:28 - 05120056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2015-10-01 17:36 - 2015-09-17 02:28 - 02154808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-10-01 17:36 - 2015-09-17 02:28 - 01357888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2015-10-01 17:36 - 2015-09-17 02:28 - 00441168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2015-10-01 17:36 - 2015-09-17 02:27 - 01766952 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2015-10-01 17:36 - 2015-09-17 02:27 - 00454512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll
2015-10-01 17:36 - 2015-09-17 02:26 - 02446648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2015-10-01 17:36 - 2015-09-17 02:26 - 01895568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll
2015-10-01 17:36 - 2015-09-17 02:26 - 00646672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2015-10-01 17:36 - 2015-09-17 02:26 - 00508248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2015-10-01 17:36 - 2015-09-17 02:26 - 00434376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2015-10-01 17:36 - 2015-09-17 02:26 - 00428128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2015-10-01 17:36 - 2015-09-17 02:25 - 00962400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-10-01 17:36 - 2015-09-17 02:21 - 00658528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2015-10-01 17:36 - 2015-09-17 02:20 - 00764416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2015-10-01 17:36 - 2015-09-17 02:12 - 16708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-10-01 17:36 - 2015-09-17 02:09 - 00269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2015-10-01 17:36 - 2015-09-17 02:08 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2015-10-01 17:36 - 2015-09-17 02:07 - 21875712 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-10-01 17:36 - 2015-09-17 02:06 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
2015-10-01 17:36 - 2015-09-17 02:06 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2015-10-01 17:36 - 2015-09-17 02:06 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2015-10-01 17:36 - 2015-09-17 02:05 - 02226688 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-10-01 17:36 - 2015-09-17 02:05 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2015-10-01 17:36 - 2015-09-17 02:04 - 07569408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2015-10-01 17:36 - 2015-09-17 02:04 - 00910848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2015-10-01 17:36 - 2015-09-17 02:00 - 24595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-10-01 17:36 - 2015-09-17 02:00 - 03248640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-10-01 17:36 - 2015-09-17 02:00 - 02417664 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-10-01 17:36 - 2015-09-17 01:58 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2015-10-01 17:36 - 2015-09-17 01:57 - 02228736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2015-10-01 17:36 - 2015-09-17 01:57 - 00403456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2015-10-01 17:36 - 2015-09-17 01:57 - 00281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2015-10-01 17:36 - 2015-09-17 01:57 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2015-10-01 17:36 - 2015-09-17 01:56 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-10-01 17:36 - 2015-09-17 01:56 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2015-10-01 17:36 - 2015-09-17 01:55 - 02236416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-10-01 17:36 - 2015-09-17 01:55 - 01601536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2015-10-01 17:36 - 2015-09-17 01:55 - 00671232 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFx02000.dll
2015-10-01 17:36 - 2015-09-17 01:55 - 00366592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2015-10-01 17:36 - 2015-09-17 01:55 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2015-10-01 17:36 - 2015-09-17 01:54 - 03781120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-10-01 17:36 - 2015-09-17 01:54 - 00780288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2015-10-01 17:36 - 2015-09-17 01:53 - 07055872 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2015-10-01 17:36 - 2015-09-17 01:52 - 01181696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2015-10-01 17:36 - 2015-09-17 01:52 - 00591360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2015-10-01 17:36 - 2015-09-17 01:52 - 00570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2015-10-01 17:36 - 2015-09-17 01:52 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2015-10-01 17:36 - 2015-09-17 01:52 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2015-10-01 17:36 - 2015-09-17 01:52 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll
2015-10-01 17:36 - 2015-09-17 01:51 - 13027840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-10-01 17:36 - 2015-09-17 01:51 - 02660864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2015-10-01 17:36 - 2015-09-17 01:51 - 01812480 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2015-10-01 17:36 - 2015-09-17 01:51 - 01203712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2015-10-01 17:36 - 2015-09-17 01:51 - 01067520 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-10-01 17:36 - 2015-09-17 01:51 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-10-01 17:36 - 2015-09-17 01:50 - 00312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2015-10-01 17:36 - 2015-09-17 01:49 - 02740224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-10-01 17:36 - 2015-09-17 01:49 - 01290240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2015-10-01 17:36 - 2015-09-17 01:49 - 01010176 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-10-01 17:36 - 2015-09-17 01:48 - 02093056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2015-10-01 17:36 - 2015-09-17 01:48 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2015-10-01 17:36 - 2015-09-17 01:48 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2015-10-01 17:36 - 2015-09-17 01:48 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2015-10-01 17:36 - 2015-09-17 01:48 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2015-10-01 17:36 - 2015-09-17 01:48 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2015-10-01 17:36 - 2015-09-17 01:47 - 07523328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2015-10-01 17:36 - 2015-09-17 01:47 - 00513536 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2015-10-01 17:36 - 2015-09-17 01:47 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2015-10-01 17:36 - 2015-09-17 01:47 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2015-10-01 17:36 - 2015-09-17 01:46 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2015-10-01 17:36 - 2015-09-17 01:46 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2015-10-01 17:36 - 2015-09-17 01:46 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2015-10-01 17:36 - 2015-09-17 01:46 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2015-10-01 17:36 - 2015-09-17 01:45 - 19325440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-10-01 17:36 - 2015-09-17 01:45 - 04791296 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-10-01 17:36 - 2015-09-17 01:45 - 01331200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-10-01 17:36 - 2015-09-17 01:45 - 00869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2015-10-01 17:36 - 2015-09-17 01:45 - 00832512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2015-10-01 17:36 - 2015-09-17 01:45 - 00627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-10-01 17:36 - 2015-09-17 01:44 - 01844736 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2015-10-01 17:36 - 2015-09-17 01:44 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2015-10-01 17:36 - 2015-09-17 01:43 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2015-10-01 17:36 - 2015-09-17 01:43 - 00378368 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-10-01 17:36 - 2015-09-17 01:43 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2015-10-01 17:36 - 2015-09-17 01:42 - 02646528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-10-01 17:36 - 2015-09-17 01:41 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2015-10-01 17:36 - 2015-09-17 01:40 - 06101504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2015-10-01 17:36 - 2015-09-17 01:40 - 01918464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-10-01 17:36 - 2015-09-17 01:40 - 01162240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2015-10-01 17:36 - 2015-09-17 01:39 - 00587264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2015-10-01 17:36 - 2015-09-17 01:38 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2015-10-01 17:36 - 2015-09-17 01:37 - 18806272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-10-01 17:36 - 2015-09-17 01:37 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2015-10-01 17:36 - 2015-09-17 01:35 - 05079552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2015-10-01 17:36 - 2015-09-17 01:35 - 02207232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-10-01 17:36 - 2015-09-17 01:35 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2015-10-01 17:36 - 2015-09-17 01:35 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2015-10-01 17:36 - 2015-09-17 01:34 - 00253440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2015-10-01 17:36 - 2015-09-17 01:32 - 03579904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-10-01 17:36 - 2015-09-17 01:32 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2015-10-01 17:36 - 2015-09-17 01:32 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2015-10-01 17:36 - 2015-09-17 01:32 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2015-10-01 17:36 - 2015-09-17 01:31 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2015-10-01 17:36 - 2015-09-17 01:30 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2015-10-01 17:36 - 2015-09-17 01:29 - 01104384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-10-01 17:36 - 2015-09-17 01:29 - 00701952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2015-10-01 17:36 - 2015-09-17 01:29 - 00677888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2015-10-01 17:36 - 2015-09-17 01:29 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-10-01 17:36 - 2015-09-17 01:26 - 00899584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2015-10-01 17:36 - 2015-09-17 01:16 - 00512000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2015-10-01 17:36 - 2015-09-12 22:05 - 02987520 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2015-10-01 17:36 - 2015-09-12 21:41 - 02639872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2015-10-01 17:35 - 2015-09-24 20:35 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2015-10-01 17:35 - 2015-09-24 20:34 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2015-10-01 17:35 - 2015-09-24 19:34 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2015-10-01 17:35 - 2015-09-24 19:34 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
2015-10-01 17:35 - 2015-09-24 19:05 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2015-10-01 17:35 - 2015-09-24 19:01 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2015-10-01 17:35 - 2015-09-24 19:00 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2015-10-01 17:35 - 2015-09-24 19:00 - 00720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2015-10-01 17:35 - 2015-09-24 19:00 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll
2015-10-01 17:35 - 2015-09-24 18:43 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2015-10-01 17:35 - 2015-09-24 18:25 - 00579584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2015-10-01 17:35 - 2015-09-24 18:25 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2015-10-01 17:35 - 2015-09-24 18:25 - 00525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2015-10-01 17:35 - 2015-09-24 18:24 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll
2015-10-01 17:35 - 2015-09-19 01:14 - 00102304 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2015-10-01 17:35 - 2015-09-17 02:50 - 00099664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2015-10-01 17:35 - 2015-09-17 02:50 - 00088384 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2015-10-01 17:35 - 2015-09-17 02:49 - 00501008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-10-01 17:35 - 2015-09-17 02:48 - 00406864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2015-10-01 17:35 - 2015-09-17 02:48 - 00278352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2015-10-01 17:35 - 2015-09-17 02:39 - 00081488 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-10-01 17:35 - 2015-09-17 02:37 - 01168736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2015-10-01 17:35 - 2015-09-17 02:28 - 00407608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-10-01 17:35 - 2015-09-17 02:28 - 00074880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2015-10-01 17:35 - 2015-09-17 02:11 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2015-10-01 17:35 - 2015-09-17 02:10 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2015-10-01 17:35 - 2015-09-17 02:09 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2015-10-01 17:35 - 2015-09-17 02:08 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Speech.Pal.dll
2015-10-01 17:35 - 2015-09-17 02:08 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2015-10-01 17:35 - 2015-09-17 02:04 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2015-10-01 17:35 - 2015-09-17 02:03 - 00267776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2015-10-01 17:35 - 2015-09-17 02:03 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2015-10-01 17:35 - 2015-09-17 02:03 - 00154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2015-10-01 17:35 - 2015-09-17 02:03 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
2015-10-01 17:35 - 2015-09-17 02:03 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2015-10-01 17:35 - 2015-09-17 02:02 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2015-10-01 17:35 - 2015-09-17 02:02 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2015-10-01 17:35 - 2015-09-17 02:00 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2015-10-01 17:35 - 2015-09-17 02:00 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\KeywordDetectorMsftSidAdapter.dll
2015-10-01 17:35 - 2015-09-17 01:56 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2015-10-01 17:35 - 2015-09-17 01:55 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2015-10-01 17:35 - 2015-09-17 01:55 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2015-10-01 17:35 - 2015-09-17 01:55 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2015-10-01 17:35 - 2015-09-17 01:55 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwancfg.dll
2015-10-01 17:35 - 2015-09-17 01:54 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-10-01 17:35 - 2015-09-17 01:52 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2015-10-01 17:35 - 2015-09-17 01:52 - 01216512 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcenter.dll
2015-10-01 17:35 - 2015-09-17 01:52 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2015-10-01 17:35 - 2015-09-17 01:52 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2015-10-01 17:35 - 2015-09-17 01:51 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2015-10-01 17:35 - 2015-09-17 01:50 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-10-01 17:35 - 2015-09-17 01:50 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2015-10-01 17:35 - 2015-09-17 01:50 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeWiFi.dll
2015-10-01 17:35 - 2015-09-17 01:50 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeCell.dll
2015-10-01 17:35 - 2015-09-17 01:50 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\buttonconverter.sys
2015-10-01 17:35 - 2015-09-17 01:49 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2015-10-01 17:35 - 2015-09-17 01:49 - 00439296 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationWebproxy.dll
2015-10-01 17:35 - 2015-09-17 01:49 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationGeofences.dll
2015-10-01 17:35 - 2015-09-17 01:49 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2015-10-01 17:35 - 2015-09-17 01:49 - 00215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationCrowdsource.dll
2015-10-01 17:35 - 2015-09-17 01:49 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeIP.dll
2015-10-01 17:35 - 2015-09-17 01:49 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationWiFiAdapter.dll
2015-10-01 17:35 - 2015-09-17 01:49 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Speech.Pal.dll
2015-10-01 17:35 - 2015-09-17 01:46 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2015-10-01 17:35 - 2015-09-17 01:46 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2015-10-01 17:35 - 2015-09-17 01:46 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2015-10-01 17:35 - 2015-09-17 01:46 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncmlhook.dll
2015-10-01 17:35 - 2015-09-17 01:45 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2015-10-01 17:35 - 2015-09-17 01:44 - 00599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2015-10-01 17:35 - 2015-09-17 01:44 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncutil.dll
2015-10-01 17:35 - 2015-09-17 01:43 - 00328704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2015-10-01 17:35 - 2015-09-17 01:39 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-10-01 17:35 - 2015-09-17 01:36 - 01171456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcenter.dll
2015-10-01 17:35 - 2015-09-17 01:33 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2015-10-01 17:35 - 2015-09-17 01:31 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2015-10-01 17:35 - 2015-09-17 01:28 - 00473088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2015-10-01 17:22 - 2015-10-01 17:22 - 05693008 _____ (AVAST Software) C:\Users\Pat\Downloads\avast_free_antivirus_setup_online (2).exe
2015-10-01 17:20 - 2015-10-01 17:20 - 00000000 ____D C:\ProgramData\AVAST Software
2015-10-01 17:19 - 2015-10-01 17:21 - 05693008 _____ (AVAST Software) C:\Users\Pat\Downloads\avast_free_antivirus_setup_online (1).exe
2015-10-01 15:23 - 2015-10-01 15:23 - 00038563 _____ C:\Users\Pat\Downloads\cssemerg69697.diagcab
2015-10-01 15:10 - 2015-10-01 15:10 - 00302011 _____ C:\Users\Pat\Downloads\WindowsUpdateDiagnostic (2).diagcab
2015-10-01 15:09 - 2015-10-01 15:09 - 00302011 _____ C:\Users\Pat\Downloads\WindowsUpdateDiagnostic (1).diagcab
2015-10-01 15:07 - 2015-10-01 15:07 - 00302011 _____ C:\Users\Pat\Downloads\WindowsUpdateDiagnostic.diagcab
2015-10-01 14:50 - 2015-10-03 08:13 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-10-01 11:51 - 2015-10-01 11:51 - 00000000 ____D C:\Users\Pat\Documents\My Games
2015-10-01 11:51 - 2015-10-01 11:51 - 00000000 ____D C:\Users\Pat\AppData\Local\My Games
2015-10-01 11:44 - 2015-10-01 11:44 - 00000000 ____D C:\Users\Pat\AppData\Local\{3984668F-207C-44E9-AB32-C6E75E24D5BE}
2015-10-01 09:54 - 2015-10-01 20:37 - 00000000 ____D C:\Users\Pat\Desktop\New folder
2015-09-30 16:25 - 2015-09-30 17:11 - 00000000 ____D C:\Users\Pat\AppData\Roaming\MechCAD
2015-09-30 01:16 - 2015-09-30 01:17 - 00454714 ____R C:\Users\Pat\Documents\My Money Backup_2015-09-30_011659.mbf
2015-09-30 01:16 - 2015-09-30 01:16 - 00456038 ____R C:\Users\Pat\Documents\My Money Backup_2015-09-30_011619.mbf
2015-09-30 00:57 - 2015-09-30 00:57 - 00000000 ____D C:\Program Files (x86)\Softwareman4life
2015-09-30 00:56 - 2015-09-30 00:56 - 00363768 _____ C:\Users\Pat\Downloads\QIF-CSVconverterForMS_Money2001SetupProgramV3.zip
2015-09-30 00:39 - 2015-10-01 20:33 - 00000000 ____D C:\Users\Pat\AppData\Roaming\NCH Software
2015-09-30 00:39 - 2015-10-01 20:28 - 00000000 ____D C:\Program Files (x86)\NCH Software
2015-09-30 00:39 - 2015-09-30 00:50 - 00000000 ____D C:\WINDOWS\System32\Tasks\NCH Software
2015-09-30 00:39 - 2015-09-30 00:39 - 00001373 _____ C:\Users\Public\Desktop\NCH Suite.lnk
2015-09-30 00:39 - 2015-09-30 00:39 - 00001205 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MoneyLine.lnk
2015-09-30 00:39 - 2015-09-30 00:39 - 00001193 _____ C:\Users\Public\Desktop\MoneyLine.lnk
2015-09-30 00:36 - 2015-09-30 00:36 - 00000000 ____D C:\Users\Pat\AppData\Local\{59FDCEB7-55B7-462B-BD07-AA98FFC4EE7C}
2015-09-27 11:08 - 2015-09-27 11:08 - 00466736 _____ (Microsoft Corporation) C:\WINDOWS\system32\coin98itp.dll
2015-09-27 11:06 - 2015-09-27 11:06 - 00000000 ____D C:\Users\Pat\AppData\Local\{01A8D258-42A5-49BC-8CB7-9BD072120697}
2015-09-21 21:16 - 2015-09-21 21:16 - 00000000 ____D C:\Users\Pat\AppData\Local\{5B1083E0-9A9B-4910-8754-D944C1EDEC3C}
2015-09-19 22:14 - 2015-09-19 22:14 - 00000000 ____D C:\Users\Pat\AppData\Local\{0490E5A2-478A-4E0D-A336-E05AD7BAE676}
2015-09-17 21:04 - 2015-09-17 21:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Money Plus
2015-09-17 12:34 - 2015-09-17 12:34 - 00000000 ____D C:\Users\Pat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-09-17 12:31 - 2015-10-03 08:13 - 00000000 ____D C:\Program Files (x86)\Steam
2015-09-17 12:31 - 2015-09-17 12:31 - 00001032 _____ C:\Users\Public\Desktop\Steam.lnk
2015-09-17 12:31 - 2015-09-17 12:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2015-09-17 12:25 - 2015-09-17 12:25 - 00000000 ____D C:\Users\Pat\AppData\Local\{7B9A30AC-45CC-4647-A614-40A48E7E2F2D}
2015-09-16 22:58 - 2015-09-16 23:09 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2015-09-16 22:57 - 2015-09-16 22:57 - 00000000 ____D C:\WINDOWS\pss
2015-09-16 22:21 - 2015-09-16 22:22 - 05685704 _____ (AVAST Software) C:\Users\Pat\Downloads\avast_free_antivirus_setup_online.exe
2015-09-16 21:53 - 2015-09-16 21:54 - 00000000 ____D C:\Users\Pat\AppData\Roaming\FreeBurner
2015-09-16 21:53 - 2015-09-16 21:53 - 00001259 _____ C:\Users\Pat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free Easy CD DVD Burner.lnk
2015-09-16 21:53 - 2015-09-16 21:53 - 00001211 _____ C:\Users\Pat\Desktop\Free Easy Burner.lnk
2015-09-16 21:53 - 2015-09-16 21:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Easy Burner
2015-09-16 21:53 - 2015-09-16 21:53 - 00000000 ____D C:\Program Files (x86)\Free Easy CD DVD Burner
2015-09-16 21:53 - 2011-09-28 09:20 - 00484352 _____ C:\WINDOWS\SysWOW64\lame_enc.dll
2015-09-16 21:53 - 2011-09-28 09:20 - 00200704 _____ (vbAccelerator) C:\WINDOWS\SysWOW64\vbalExpBar6.ocx
2015-09-16 21:53 - 2011-09-28 09:20 - 00141312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSCMCFR.DLL
2015-09-16 21:53 - 2011-09-28 09:20 - 00119568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VB6FR.DLL
2015-09-16 21:53 - 2011-09-28 09:20 - 00115920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msinet.OCX
2015-09-16 21:53 - 2011-09-28 09:20 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VB6STKIT.DLL
2015-09-16 21:53 - 2011-09-28 09:20 - 00040960 _____ (vbAccelerator) C:\WINDOWS\SysWOW64\SSubTmr6.dll
2015-09-16 21:53 - 2011-09-28 09:20 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CMDLGFR.DLL
2015-09-16 21:53 - 2011-09-28 09:20 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetfr.DLL
2015-09-16 21:52 - 2015-10-03 08:14 - 00000000 ____D C:\Users\Pat\AppData\Local\CrashDumps
2015-09-16 21:37 - 2015-09-16 21:49 - 00000000 ____D C:\ProgramData\RogueKiller
2015-09-16 21:37 - 2015-09-16 21:37 - 00035064 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2015-09-16 21:11 - 2015-09-16 21:11 - 01660416 _____ C:\Users\Pat\Downloads\adwcleaner_5.007 (1).exe
2015-09-16 20:40 - 2015-09-16 22:36 - 00000000 ____D C:\AdwCleaner
2015-09-16 20:39 - 2015-09-16 20:39 - 01660416 _____ C:\Users\Pat\Downloads\adwcleaner_5.007.exe
2015-09-16 20:31 - 2015-10-01 20:39 - 00000000 ____D C:\Users\DefaultAppPool
2015-09-16 20:31 - 2015-09-16 20:31 - 00000020 ___SH C:\Users\DefaultAppPool\ntuser.ini
2015-09-16 20:31 - 2015-09-10 22:03 - 00000000 ___RD C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-16 20:31 - 2015-07-10 07:04 - 00000000 __RSD C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-09-16 20:31 - 2015-07-10 07:04 - 00000000 ___RD C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-09-16 20:31 - 2015-07-10 07:04 - 00000000 ___RD C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-09-16 20:31 - 2015-07-10 07:04 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-09-16 19:16 - 2015-09-16 20:12 - 00000000 ____D C:\ProgramData\DataFile
2015-09-16 19:07 - 2015-09-16 19:07 - 00000000 ____D C:\Users\Pat\AppData\Local\CrashRpt
2015-09-16 18:29 - 2015-09-16 18:29 - 00000048 _____ C:\InstallConfig.ini
2015-09-16 18:29 - 2015-09-16 18:29 - 00000000 ____D C:\ProgramData\LocalStorage
2015-09-16 18:28 - 2015-09-16 18:29 - 00000000 ____D C:\Users\Pat\AppData\Roaming\WB_CFG
2015-09-16 18:27 - 2009-06-10 17:00 - 00000824 _____ C:\WINDOWS\system32\Drivers\etc\hp.bak
2015-09-16 18:26 - 2015-09-16 19:31 - 00000004 _____ C:\WINDOWS\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-09-16 18:26 - 2015-09-16 18:26 - 00000000 ____D C:\Users\Pat\.android
2015-09-16 18:25 - 2015-10-03 03:00 - 00000464 _____ C:\WINDOWS\Tasks\AdobeoaUpdate Ver 2015916.job
2015-09-16 18:25 - 2015-09-16 18:26 - 00004648 _____ C:\WINDOWS\SysWOW64\Witihadik.ini
2015-09-16 18:25 - 2015-09-16 18:26 - 00002360 _____ C:\WINDOWS\SysWOW64\WitihadikOff.ini
2015-09-16 18:25 - 2015-09-16 18:26 - 00002360 _____ C:\WINDOWS\system32\WitihadikOff.ini
2015-09-16 18:25 - 2015-09-16 18:25 - 00003584 _____ C:\WINDOWS\System32\Tasks\AdobeoaUpdate Ver 2015916
2015-09-16 18:25 - 2015-09-16 18:25 - 00000000 ____D C:\WINDOWS\system32\koj
2015-09-16 18:25 - 2015-09-16 18:25 - 00000000 ____D C:\Users\Pat\AppData\Roaming\ppslog
2015-09-16 18:25 - 2015-09-16 18:25 - 00000000 ____D C:\Users\Pat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\文管家(916)
2015-09-16 18:25 - 2015-09-16 18:25 - 00000000 ____D C:\Users\Pat\AppData\LocalLow\VirtualStore
2015-09-16 18:25 - 2015-09-16 18:25 - 00000000 ____D C:\Users\Pat\AppData\LocalLow\Unity
2015-09-16 18:25 - 2015-09-16 18:25 - 00000000 ____D C:\Users\Pat\AppData\LocalLow\Company
2015-09-16 18:25 - 2015-09-16 18:25 - 00000000 ____D C:\Users\Pat\AppData\Local\Unity
2015-09-16 18:25 - 2015-09-16 18:25 - 00000000 ____D C:\Users\Pat\AppData\Local\Tempfolder
2015-09-16 18:25 - 2015-09-16 18:25 - 00000000 ____D C:\ProgramData\adb
2015-09-16 18:24 - 2015-09-16 18:24 - 00000000 ____D C:\Users\Public\QiYi
2015-09-16 18:24 - 2015-09-16 18:24 - 00000000 ____D C:\Users\Pat\AppData\Roaming\c
2015-09-16 18:24 - 2015-09-16 18:24 - 00000000 ____D C:\ProgramData\u4c
2015-09-16 18:24 - 2015-09-16 18:24 - 00000000 ____D C:\Program Files (x86)\taskvmx
2015-09-16 17:51 - 2015-10-01 20:37 - 00000000 __RHD C:\MSOCache
2015-09-16 17:24 - 2015-09-16 17:24 - 00000000 ____D C:\Users\Pat\AppData\Roaming\java
2015-09-16 17:24 - 2015-09-16 17:24 - 00000000 ____D C:\Users\Pat\AppData\Roaming\.minecraft
2015-09-16 17:09 - 2015-09-16 17:09 - 00000000 ____D C:\Users\Pat\AppData\Roaming\uTorrent
2015-09-16 17:02 - 2015-09-16 17:04 - 00000000 ____D C:\Users\Pat\Desktop\Kellys recipes
2015-09-16 17:02 - 2015-09-16 17:02 - 00000000 ____D C:\Users\Pat\AppData\LocalLow\Temp
2015-09-16 16:52 - 2015-09-16 16:55 - 00000000 ____D C:\Users\Pat\Desktop\Mom's Other Folder
2015-09-16 14:23 - 2015-09-16 14:23 - 00000000 ____D C:\Users\Pat\AppData\Local\{576ACE86-2AF6-40E2-B19F-F6FB8601A372}
2015-09-16 14:23 - 2015-09-16 14:23 - 00000000 ____D C:\Users\Pat\AppData\Local\{2C59100A-17E0-4515-9A42-E3CD3CD25A52}
2015-09-16 14:01 - 2015-10-01 17:31 - 00000000 ____D C:\Registry Backups
2015-09-16 13:41 - 2015-09-16 13:41 - 00000000 ____D C:\Users\Pat\Downloads\runtime
2015-09-16 13:41 - 2015-09-16 13:41 - 00000000 ____D C:\Users\Pat\Downloads\Pixles
2015-09-16 13:41 - 2015-09-16 13:41 - 00000000 ____D C:\Users\Pat\Downloads\game
2015-09-16 13:41 - 2015-09-16 13:41 - 00000000 ____D C:\Users\Pat\Desktop\JPEG IMAGES
2015-09-16 13:41 - 2015-09-16 13:41 - 00000000 ____D C:\Users\Pat\Desktop\Aidan-FB
2015-09-16 13:41 - 2015-09-07 14:02 - 00118571 _____ C:\Users\Pat\Downloads\[kat.cr]san.andreas.2015.hdrip.xvid.ac3.evo.torrent
2015-09-16 13:41 - 2015-09-03 11:10 - 00014998 _____ C:\Users\Pat\Downloads\[kat.cr]minions.2015.hc.hdrip.xvid.ac3.evo.avi.torrent
2015-09-16 13:41 - 2015-08-31 14:59 - 00111199 _____ C:\Users\Pat\Downloads\[kat.cr]lucifer.pilot.1080p.hdtv.x264.dimension.rartv.torrent
2015-09-16 13:41 - 2015-08-24 11:44 - 00088286 _____ C:\Users\Pat\Downloads\[kat.cr]avengers.age.of.ultron.2015.720p.web.dl.dd5.1.h264.rarbg.torrent
2015-09-16 13:41 - 2015-08-21 07:34 - 00019389 _____ C:\Users\Pat\Downloads\[kat.cr]windows.7.professional.x64.with.sp1.iso.danhuk (1).torrent
2015-09-16 13:41 - 2015-08-21 07:31 - 00019389 _____ C:\Users\Pat\Downloads\[kat.cr]windows.7.professional.x64.with.sp1.iso.danhuk.torrent
2015-09-16 13:41 - 2015-08-04 08:21 - 00020573 _____ C:\Users\Pat\Downloads\[kat.cr]halo.novels.torrent
2015-09-16 13:39 - 2015-09-16 11:26 - 01063390 _____ C:\Users\Pat\Downloads\NoMoneyFreeEasyCDDVDBurnerSetupstub.exe
2015-09-16 13:39 - 2015-09-08 17:59 - 3320903680 _____ C:\Users\Pat\Downloads\Windows_7_64-bit_Professional_x64.iso
2015-09-16 13:39 - 2015-07-12 11:52 - 00048159 _____ C:\Users\Pat\Downloads\productView.ehtml
2015-09-16 13:39 - 2015-07-09 16:09 - 00561248 _____ (Oracle Corporation) C:\Users\Pat\Downloads\jxpiinstall(1).exe
2015-09-16 13:39 - 2015-07-09 16:07 - 00561248 _____ (Oracle Corporation) C:\Users\Pat\Downloads\jxpiinstall.exe
2015-09-16 13:39 - 2015-06-22 14:39 - 01088664 _____ (Unity Technologies ApS) C:\Users\Pat\Downloads\UnityWebPlayer (1).exe
2015-09-16 13:39 - 2015-06-22 14:37 - 01088664 _____ (Unity Technologies ApS) C:\Users\Pat\Downloads\UnityWebPlayer.exe
2015-09-16 13:39 - 2015-03-15 11:32 - 51478672 _____ (HRB Technology, LLC.) C:\Users\Pat\Downloads\Promo_Partner_HRBlock_Deluxe+Efile+State.exe
2015-09-16 13:39 - 2014-11-08 12:42 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Pat\Downloads\mbam-setup-2.0.3.1025.exe
2015-09-16 13:39 - 2014-10-18 08:20 - 01054912 _____ (Adobe) C:\Users\Pat\Downloads\install_flashplayer15x32au_mssd_aaa_aih.exe
2015-09-16 13:39 - 2014-09-19 22:32 - 02021376 _____ (Klip'em) C:\Users\Pat\Downloads\klipem.exe
2015-09-16 13:39 - 2014-09-02 19:36 - 10222666 _____ (Hoo Technologies ) C:\Users\Pat\Downloads\totalamcvt.exe
2015-09-16 13:39 - 2014-06-24 08:05 - 01058200 _____ (Adobe) C:\Users\Pat\Downloads\install_flashplayer14x32au_mssd_aaa_aih.exe
2015-09-16 13:39 - 2014-01-29 18:45 - 10458976 _____ C:\Users\Pat\Downloads\TERA-Setup-HC.exe
2015-09-16 13:39 - 2013-01-19 22:45 - 124577880 _____ (Mad catz ) C:\Users\Pat\Downloads\SD7_0_23_0_64Bit_Software.exe
2015-09-16 13:39 - 2012-06-21 10:49 - 06953928 _____ (Microsoft Corporation) C:\Users\Pat\Downloads\Silverlight.exe
2015-09-16 13:39 - 2012-03-30 22:16 - 60267040 _____ (Saitek ) C:\Users\Pat\Downloads\Smart_Technology_7_0_2_7_64bit.exe
2015-09-16 13:35 - 2015-08-10 18:30 - 1207884520 _____ C:\Users\Pat\Downloads\files.zip
2015-09-16 13:35 - 2015-08-04 12:57 - 64798720 _____ C:\Users\Pat\Downloads\calibre-2.33.0.msi
2015-09-16 13:35 - 2015-05-23 22:07 - 06484352 _____ (Piriform Ltd) C:\Users\Pat\Downloads\ccsetup505.exe
2015-09-16 13:35 - 2015-05-21 19:12 - 04737144 _____ (Avira Operations GmbH & Co. KG) C:\Users\Pat\Downloads\avira_en_av_555e67221d81e__ws.exe
2015-09-16 13:35 - 2015-04-27 13:53 - 13488394 _____ C:\Users\Pat\Downloads\AUPSY202.13.1.mobi
2015-09-16 13:35 - 2015-04-05 09:04 - 05344528 _____ (Piriform Ltd) C:\Users\Pat\Downloads\ccsetup504.exe
2015-09-16 13:35 - 2015-03-07 11:51 - 03212008 _____ C:\Users\Pat\Downloads\2014_Ohio_Installer(1).exe
2015-09-16 13:35 - 2015-03-07 11:39 - 03212008 _____ C:\Users\Pat\Downloads\2014_Ohio_Installer.exe
2015-09-16 13:35 - 2014-08-30 21:54 - 06460992 _____ C:\Users\Pat\Downloads\Dell_V310-V510_Series_B082511_00_FWUpdate.exe
2015-09-16 13:35 - 2014-08-30 21:50 - 73340032 _____ C:\Users\Pat\Downloads\DELL_V313w_wcr_64_en.exe
2015-09-16 13:35 - 2014-05-03 14:29 - 00055536 _____ C:\Users\Pat\Downloads\bookmarks-2014-05-03.json
2015-09-16 13:35 - 2014-04-20 13:24 - 04470536 _____ (AVG Technologies) C:\Users\Pat\Downloads\avg_free_stb_all_2014_4355_cnet.exe
2015-09-16 13:35 - 2013-01-13 00:14 - 177652768 _____ (NVIDIA Corporation) C:\Users\Pat\Downloads\310.90-desktop-win8-win7-winvista-64bit-english-whql.exe
2015-09-16 13:35 - 2012-11-21 18:52 - 00001360 _____ C:\Users\Pat\Downloads\drumsui.jnlp
2015-09-16 13:35 - 2012-10-12 20:17 - 227947968 _____ (NVIDIA Corporation) C:\Users\Pat\Downloads\306.97-desktop-win8-win7-winvista-64bit-international-whql.exe
2015-09-16 13:35 - 2012-03-13 11:29 - 166448312 _____ (NVIDIA Corporation) C:\Users\Pat\Downloads\296.10-desktop-win7-winvista-64bit-english-whql.exe
2015-09-16 13:35 - 2011-12-04 16:39 - 155182440 _____ (NVIDIA Corporation) C:\Users\Pat\Downloads\285.62-desktop-win7-winvista-64bit-english-whql.exe
2015-09-16 13:26 - 2015-09-16 17:25 - 00000000 ____D C:\Users\Pat\Desktop\Mom's Recipes
2015-09-16 13:26 - 2015-09-16 13:26 - 00000000 ____D C:\Users\Pat\Desktop\Mom
2015-09-16 12:50 - 2015-09-16 12:50 - 00000000 ____D C:\Users\Pat\AppData\Roaming\TuneUp Software
2015-09-16 12:37 - 2015-09-16 12:37 - 00002842 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2015-09-16 12:37 - 2015-09-16 12:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-09-16 12:35 - 2015-09-16 12:37 - 00000000 ____D C:\Program Files\CCleaner
2015-09-16 12:32 - 2015-09-16 12:32 - 06667640 _____ (Piriform Ltd) C:\Users\Pat\Downloads\ccsetup509.exe
2015-09-16 12:25 - 2015-09-16 13:56 - 00000000 ____D C:\ProgramData\MFAData
2015-09-16 12:25 - 2015-09-16 12:25 - 00000000 ____D C:\Users\Pat\AppData\Local\MFAData
2015-09-16 12:19 - 2015-09-16 13:51 - 00000000 ____D C:\Users\Pat\AppData\Local\AvgSetupLog
2015-09-16 12:19 - 2015-09-16 12:19 - 00000000 ____D C:\Users\Pat\AppData\Local\Avg
2015-09-16 12:18 - 2015-09-16 21:21 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-09-16 12:18 - 2015-09-16 12:18 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-09-16 12:18 - 2015-09-16 12:18 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-09-16 12:18 - 2015-06-18 08:42 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-09-16 12:18 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-09-16 12:18 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-09-16 12:13 - 2015-09-17 18:14 - 00000000 ____D C:\Users\Pat\Desktop\down loads
2015-09-16 12:13 - 2015-09-16 17:26 - 00000000 ____D C:\Users\Pat\Desktop\Bob & Kelly
2015-09-16 12:13 - 2015-09-16 12:13 - 00000000 ____D C:\Users\Pat\Desktop\Craig Resumes & Cover Letters
2015-09-16 12:13 - 2015-09-16 12:13 - 00000000 ____D C:\Users\Pat\Desktop\Baby Shower
2015-09-16 11:27 - 2015-09-16 11:45 - 00000000 ____D C:\New folder
2015-09-16 11:19 - 2015-09-16 11:21 - 00000000 ____D C:\Program1
2015-09-15 20:49 - 2015-09-16 19:52 - 00000986 _____ C:\Users\Public\Desktop\PartitionGuru Free.lnk
2015-09-15 20:49 - 2015-09-15 20:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PartitionGuru Free
2015-09-15 20:49 - 2015-09-15 20:49 - 00000000 ____D C:\Program Files\PartitionGuru Free
2015-09-15 20:48 - 2015-09-15 20:48 - 07029664 _____ (Eassos Co., Ltd. ) C:\Users\Pat\Downloads\PGFreeSetup.exe
2015-09-13 16:06 - 2015-09-13 16:40 - 08867840 _____ C:\Users\Pat\Downloads\SeaToolsDOS223ALL.ISO
2015-09-13 11:05 - 2015-09-16 19:52 - 00001330 _____ C:\Users\Public\Desktop\SeaTools for Windows.lnk
2015-09-13 11:05 - 2015-09-13 11:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seagate
2015-09-13 11:05 - 2015-09-13 11:05 - 00000000 ____D C:\Program Files (x86)\Seagate
2015-09-13 11:04 - 2015-09-13 11:05 - 25527544 _____ C:\Users\Pat\Downloads\SeaToolsforWindowsSetup.exe
2015-09-13 10:44 - 2015-09-13 10:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-09-13 10:43 - 2015-09-13 10:43 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-09-13 10:43 - 2015-09-13 10:43 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-09-13 10:18 - 2015-09-13 10:18 - 00000000 ____D C:\Users\Pat\AppData\Local\{04E8D039-0257-4E53-998D-B8F9167204A9}
2015-09-13 10:04 - 2015-09-16 19:52 - 00001650 _____ C:\Users\Pat\Desktop\wlmail - Shortcut.lnk
2015-09-13 10:04 - 2015-09-13 10:04 - 00000000 ____D C:\Users\Pat\AppData\Roaming\Windows Live Writer
2015-09-13 10:04 - 2015-09-13 10:04 - 00000000 ____D C:\Users\Pat\AppData\Local\Windows Live Writer
2015-09-13 10:02 - 2015-09-16 14:00 - 00000000 ____D C:\Users\Pat\Tracing
2015-09-13 10:01 - 2015-09-13 10:01 - 00000000 ____D C:\WINDOWS\en
2015-09-13 10:00 - 2015-09-16 19:52 - 00001435 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
2015-09-13 10:00 - 2015-09-16 19:52 - 00001366 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
2015-09-13 10:00 - 2015-09-16 19:52 - 00001346 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
2015-09-13 10:00 - 2015-09-13 10:01 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
2015-09-13 10:00 - 2015-09-13 10:00 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2015-09-13 09:59 - 2015-09-16 19:52 - 00002342 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
2015-09-13 09:59 - 2015-09-13 10:01 - 00000000 ____D C:\Program Files (x86)\Windows Live
2015-09-13 09:59 - 2015-09-13 09:59 - 00000000 ____D C:\WINDOWS\PCHEALTH
2015-09-13 09:59 - 2015-09-13 09:59 - 00000000 ____D C:\Program Files\Windows Live
2015-09-13 09:58 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_5.dll
2015-09-13 09:58 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_3.dll
2015-09-13 09:58 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll
2015-09-13 09:58 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_42.dll
2015-09-13 09:58 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_32.dll
2015-09-13 09:58 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_32.dll
2015-09-13 09:57 - 2015-09-17 12:26 - 00000000 ____D C:\Users\Pat\AppData\Local\Windows Live
2015-09-13 09:57 - 2015-09-13 09:57 - 01287528 _____ (Microsoft Corporation) C:\Users\Pat\Downloads\wlsetup-web.exe
2015-09-11 23:18 - 2015-09-11 23:18 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2015-09-11 01:50 - 2015-09-16 13:59 - 00000000 ___DC C:\WINDOWS\Panther
2015-09-11 01:48 - 2015-09-11 01:48 - 00000000 ____D C:\Windows.old
2015-09-11 01:47 - 2015-09-11 01:47 - 22324656 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 20857848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 14241792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 12589056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 12503552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 11557888 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 11262464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 09889792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 08613200 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 06878256 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 06305792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 04760576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 04611584 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 04532304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 04398080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 04350464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 04169728 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 04048808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 03687936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 03620736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 03527168 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 03443200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 03362816 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 03248128 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 02880032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 02748416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 02606080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 02558976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 02446336 _____ C:\WINDOWS\system32\InputService.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 02415104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 02350592 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 02153472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 02147080 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 02125312 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 02116448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2015-09-11 01:47 - 2015-09-11 01:47 - 02112512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01985024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01888768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01867160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01823232 _____ C:\WINDOWS\SysWOW64\InputService.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01822280 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01774592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01714176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01679360 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01643872 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01612288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01602560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01593344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01591856 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01533496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01521664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01418240 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 01417216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01411072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01365072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01294352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2015-09-11 01:47 - 2015-09-11 01:47 - 01294336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcnwiz.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01234944 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 01226752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wcnwiz.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01201664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01200400 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01169408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01135312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 01123400 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 01106432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01101792 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01087296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01061888 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01043968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01043872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01031680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorDataService.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 01025840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 01018568 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2015-09-11 01:47 - 2015-09-11 01:47 - 01008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00993104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2015-09-11 01:47 - 2015-09-11 01:47 - 00934752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refsv1.sys
2015-09-11 01:47 - 2015-09-11 01:47 - 00918320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00902656 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00896144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00893440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00877016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00872448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00858408 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00850432 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00845664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00841728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00823336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00816576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfuimanager.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00801632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00799232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpccpl.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00798208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00783872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00754688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfuimanager.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00750592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00713312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00705520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00700256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00695136 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2015-09-11 01:47 - 2015-09-11 01:47 - 00680448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00679424 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00677888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00671232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00670208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00658568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00654848 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00642560 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00632168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00630160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00609592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00608936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00601344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2015-09-11 01:47 - 2015-09-11 01:47 - 00596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00594472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efscore.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00584544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00569344 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00565088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2015-09-11 01:47 - 2015-09-11 01:47 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00542720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00541248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00527952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00521568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00507696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00505344 _____ C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00498016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys
2015-09-11 01:47 - 2015-09-11 01:47 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMediaManager.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00487424 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00485888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00445240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00442208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2015-09-11 01:47 - 2015-09-11 01:47 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00437248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00430592 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcomapi.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00425824 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00420352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00416256 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00413184 _____ C:\WINDOWS\system32\diagtrack_win.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00404480 _____ C:\WINDOWS\system32\diagtrack_wininternal.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00373248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00373072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2015-09-11 01:47 - 2015-09-11 01:47 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00356352 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00343040 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00335248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00333168 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00325984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2015-09-11 01:47 - 2015-09-11 01:47 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenter.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00293376 _____ C:\WINDOWS\system32\TextInputFramework.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00292856 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00291840 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemcpl.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00290312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00285632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00280576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\systemcpl.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00265480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00263168 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActionCenter.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_UserAccount.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00252768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00247296 _____ C:\WINDOWS\system32\facecredentialprovider.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00243800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00242176 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00237392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdyboost.sys
2015-09-11 01:47 - 2015-09-11 01:47 - 00235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicesFlowBroker.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\notepad.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\notepad.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00208736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\srumsvc.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\OmaDmAgent.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00200704 _____ C:\WINDOWS\SysWOW64\TextInputFramework.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00200528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
2015-09-11 01:47 - 2015-09-11 01:47 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModelShim.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00191488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReInfo.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.PicturePassword.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00181088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SignInOptions.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\coredpus.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00179200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srumsvc.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Privacy.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReInfo.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tunnel.sys
2015-09-11 01:47 - 2015-09-11 01:47 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabSvc.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnApi.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPermissions.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkStatus.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWCN.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00116736 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeParserTask.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdWCN.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00102752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys
2015-09-11 01:47 - 2015-09-11 01:47 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WcnApi.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00097128 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcd.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdWCN.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\spbcd.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00082616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcd.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00080720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2015-09-11 01:47 - 2015-09-11 01:47 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthRadioMedia.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkInternalPS.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\setbcdlocale.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spbcd.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.ProxyStub.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys
2015-09-11 01:47 - 2015-09-11 01:47 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys
2015-09-11 01:47 - 2015-09-11 01:47 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\unenrollhook.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00061280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2015-09-11 01:47 - 2015-09-11 01:47 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.OneCore.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msiexec.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\hmkd.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.PAL.Desktop.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmprc.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00052264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wpcfltr.sys
2015-09-11 01:47 - 2015-09-11 01:47 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnNetsh.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00046432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpiowin32.sys
2015-09-11 01:47 - 2015-09-11 01:47 - 00046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmUcsi.sys
2015-09-11 01:47 - 2015-09-11 01:47 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hmkd.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tetheringclient.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\VoiceActivationManager.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VoiceActivationManager.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00032768 _____ C:\WINDOWS\system32\LicenseManagerApi.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\calc.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\calc.exe
2015-09-11 01:47 - 2015-09-11 01:47 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2015-09-11 01:47 - 2015-09-11 01:47 - 00008847 _____ C:\WINDOWS\system32\ResPriHMImageList
2015-09-11 01:44 - 2015-09-11 01:44 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2015-09-11 01:42 - 2015-09-11 01:42 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices
2015-09-11 01:42 - 2015-09-11 01:42 - 00000000 ____D C:\WINDOWS\system32\msmq
2015-09-11 01:42 - 2015-09-11 01:42 - 00000000 ____D C:\WINDOWS\system32\BestPractices
2015-09-11 01:42 - 2015-09-11 01:42 - 00000000 ____D C:\Program Files\Reference Assemblies
2015-09-11 01:42 - 2015-09-11 01:42 - 00000000 ____D C:\Program Files\MSBuild
2015-09-11 01:42 - 2015-09-11 01:42 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2015-09-11 01:42 - 2015-09-11 01:42 - 00000000 ____D C:\Program Files (x86)\MSBuild
2015-09-11 01:42 - 2015-09-11 01:42 - 00000000 ____D C:\inetpub
2015-09-11 01:42 - 2015-06-17 22:10 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2015-09-11 01:42 - 2015-06-17 22:10 - 00124112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2015-09-11 01:42 - 2015-06-17 22:10 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2015-09-11 01:42 - 2015-05-30 01:07 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2015-09-11 01:42 - 2015-05-30 01:07 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-09-11 01:42 - 2015-05-30 01:07 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2015-09-10 23:43 - 2015-09-10 23:43 - 00000000 ____D C:\Users\Pat\AppData\Local\PeerDistRepub
2015-09-10 23:26 - 2015-10-03 08:16 - 00004138 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{62C0C3E6-83A1-42E4-8D8A-28D853DE482A}
2015-09-10 22:59 - 2015-09-10 23:01 - 00000000 ____D C:\Users\Pat\AppData\Local\Comms
2015-09-10 22:55 - 2015-09-17 12:34 - 00000220 _____ C:\Users\Pat\Desktop\Sid Meier's Civilization V.url
2015-09-10 22:54 - 2015-09-10 22:54 - 00000000 ____D C:\Users\Pat\AppData\Local\Steam
2015-09-10 22:54 - 2015-09-10 22:54 - 00000000 ____D C:\Users\Pat\AppData\Local\CEF
2015-09-10 22:46 - 2015-10-03 08:13 - 00000910 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-10 22:46 - 2015-10-03 02:56 - 00000914 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-10 22:46 - 2015-09-27 20:57 - 00002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-09-10 22:46 - 2015-09-16 23:51 - 00003972 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-09-10 22:46 - 2015-09-16 23:51 - 00003740 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-09-10 22:46 - 2015-09-11 06:58 - 00000000 ____D C:\Users\Pat\AppData\Local\Google
2015-09-10 22:46 - 2015-09-10 22:46 - 00929360 _____ (Google Inc.) C:\Users\Pat\Downloads\ChromeSetup.exe
2015-09-10 22:46 - 2015-09-10 22:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-09-10 22:46 - 2015-09-10 22:46 - 00000000 ____D C:\Program Files (x86)\Google
2015-09-10 22:42 - 2015-09-16 21:02 - 00000000 ___RD C:\Users\Pat\Desktop\Security
2015-09-10 22:41 - 2015-09-16 16:05 - 00000000 ____D C:\Users\Pat\Desktop\Taxes 2013
2015-09-10 22:41 - 2015-09-10 22:43 - 00000000 ____D C:\Users\Pat\Desktop\Phone Pics-Mom
2015-09-10 22:41 - 2015-09-10 22:41 - 00000000 ____D C:\Users\Pat\Desktop\Taxes 2014
2015-09-10 22:41 - 2015-09-10 22:41 - 00000000 ____D C:\Users\Pat\Desktop\Photos
2015-09-10 22:40 - 2015-09-16 16:58 - 00000000 ____D C:\Users\Pat\Desktop\Bill Receipts
2015-09-10 22:26 - 2015-09-30 01:17 - 03407872 _____ C:\Users\Pat\Documents\My Money.mny
2015-09-10 22:23 - 2015-10-01 20:28 - 00000000 ____D C:\Program Files (x86)\Microsoft Money Plus
2015-09-10 22:23 - 2015-09-16 19:52 - 00001418 _____ C:\Users\Pat\Desktop\Money Plus.lnk
2015-09-10 22:22 - 2015-09-10 22:22 - 35677984 _____ (Microsoft Corporation) C:\Users\Pat\Downloads\USMoneyDlxSunset (1).exe
2015-09-10 22:21 - 2015-09-10 22:21 - 35677984 _____ (Microsoft Corporation) C:\Users\Pat\Downloads\USMoneyDlxSunset.exe
2015-09-10 22:18 - 2015-09-10 22:18 - 00000000 ____D C:\Users\Pat\AppData\Local\MicrosoftEdge
2015-09-10 22:12 - 2015-09-16 19:52 - 00002359 _____ C:\Users\Pat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-09-10 22:12 - 2015-09-15 15:05 - 00000000 ___RD C:\Users\Pat\OneDrive
2015-09-10 22:12 - 2015-09-10 22:12 - 00000000 ____D C:\Users\Pat\AppData\Roaming\ATI
2015-09-10 22:12 - 2015-09-10 22:12 - 00000000 ____D C:\Users\Pat\AppData\Local\ATI
2015-09-10 22:12 - 2015-09-10 22:12 - 00000000 ____D C:\Users\Pat\AppData\Local\AMD
2015-09-10 22:12 - 2015-09-10 22:12 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2015-09-10 22:12 - 2015-09-10 22:12 - 00000000 ____D C:\ProgramData\ATI
2015-09-10 22:11 - 2015-09-10 22:11 - 00232832 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\WDMBL_AP1NC_2_2_0.dll
2015-09-10 22:11 - 2015-09-10 22:11 - 00103424 _____ (Advanced Micro Devices) C:\WINDOWS\system32\DelayAPO.dll
2015-09-10 22:11 - 2015-09-10 22:11 - 00102912 _____ (Advanced Micro Devices) C:\WINDOWS\system32\Drivers\AtihdWT6.sys
2015-09-10 22:10 - 2015-09-10 22:10 - 00000000 ____D C:\Users\Pat\AppData\Local\Publishers
2015-09-10 22:09 - 2015-10-01 20:33 - 00000000 ____D C:\Users\Pat\AppData\Local\Packages
2015-09-10 22:09 - 2015-09-10 22:09 - 00000020 ___SH C:\Users\Pat\ntuser.ini
2015-09-10 22:09 - 2015-09-10 22:09 - 00000000 ____D C:\Users\Pat\AppData\Local\TileDataLayer
2015-09-10 22:08 - 2015-09-10 22:08 - 00000000 __SHD C:\Recovery
2015-09-10 22:07 - 2015-09-10 22:07 - 00022744 _____ C:\WINDOWS\system32\emptyregdb.dat
2015-09-10 22:03 - 2015-09-16 19:52 - 00001540 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-09-10 22:02 - 2015-09-10 22:02 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines
2015-09-10 22:01 - 2015-10-02 07:09 - 00000000 ____D C:\Users\Pat
2015-09-10 22:01 - 2015-09-16 19:31 - 00000000 ___RD C:\Users\Pat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-10 22:01 - 2015-09-16 14:03 - 00000000 ___RD C:\Users\Pat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-09-10 22:01 - 2015-07-10 07:04 - 00000000 __RSD C:\Users\Pat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-09-10 22:01 - 2015-07-10 07:04 - 00000000 ___RD C:\Users\Pat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-09-10 22:01 - 2015-07-10 07:04 - 00000000 ____D C:\Users\Pat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-09-10 22:00 - 2015-10-02 06:33 - 01005534 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-09-10 22:00 - 2015-09-10 22:00 - 00961296 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2015-09-10 21:59 - 2015-09-10 21:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2015-09-10 21:59 - 2015-09-10 21:59 - 00000000 ____D C:\ProgramData\AMD
2015-09-10 21:59 - 2015-09-10 21:59 - 00000000 ____D C:\Program Files\ATI Technologies
2015-09-10 21:59 - 2015-07-10 06:59 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2015-09-10 21:58 - 2015-09-13 11:05 - 00000000 ____D C:\ProgramData\Package Cache
2015-09-10 21:58 - 2015-09-10 21:59 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
2015-09-10 21:58 - 2015-09-10 21:58 - 00000000 ____D C:\WINDOWS\system32\SRSLabs
2015-09-10 21:58 - 2015-09-10 21:58 - 00000000 ____D C:\Program Files\VIA
2015-09-10 21:57 - 2015-10-01 14:15 - 00000000 ____D C:\WINDOWS\Minidump
2015-09-10 21:53 - 2015-09-10 21:58 - 00000000 ____D C:\AMD
2015-09-10 21:53 - 2015-09-10 21:53 - 00000000 _____ C:\WINDOWS\ativpsrm.bin
2015-09-10 21:52 - 2015-09-10 21:52 - 00020321 _____ C:\WINDOWS\system32\NetSetupMig.log
2015-09-10 21:52 - 2015-09-10 21:52 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2015-09-10 21:52 - 2015-09-10 21:52 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2015-09-10 21:52 - 2015-09-10 21:52 - 00000000 ____D C:\Program Files\AMD
2015-09-10 21:09 - 2015-09-10 22:08 - 00010449 _____ C:\WINDOWS\diagerr.xml
2015-09-10 21:09 - 2015-09-10 22:08 - 00009528 _____ C:\WINDOWS\diagwrn.xml
2015-09-10 21:09 - 2015-09-10 21:19 - 00000000 ___HD C:\$Windows.~BT
2015-09-10 21:08 - 2015-09-10 21:08 - 00000000 ____D C:\ESD
2015-09-10 21:00 - 2015-09-10 21:00 - 00000000 ___HD C:\$Windows.~WS
2015-09-10 20:46 - 2015-08-15 01:57 - 00968704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.exe
2015-09-10 20:46 - 2015-08-15 01:22 - 01359360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmlmedia.dll
2015-09-10 20:46 - 2015-08-15 01:01 - 01155072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmlmedia.dll
2015-09-10 20:45 - 2015-06-09 14:03 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\RdpGroupPolicyExtension.dll
2015-09-10 19:37 - 2013-10-01 22:11 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-09-10 19:30 - 2012-08-23 07:12 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpendp_winip.dll
2015-09-10 19:30 - 2012-08-23 06:51 - 00228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpendp_winip.dll
2015-09-10 18:37 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\WINDOWS\system32\IEUDINIT.EXE
2015-09-10 18:32 - 2015-09-10 18:32 - 00942592 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsIntl.dll
2015-09-10 18:32 - 2015-09-10 18:32 - 00645120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsIntl.dll
2015-09-10 18:24 - 2015-09-10 18:24 - 00010752 ____H (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2015-09-10 18:24 - 2015-09-10 18:24 - 00010752 ____H (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2015-09-10 18:24 - 2015-09-10 18:24 - 00009728 ____H (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-09-10 18:24 - 2015-09-10 18:24 - 00009728 ____H (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-09-10 18:24 - 2015-09-10 18:24 - 00005632 ____H (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2015-09-10 18:24 - 2015-09-10 18:24 - 00005632 ____H (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2015-09-10 18:24 - 2015-09-10 18:24 - 00005632 ____H (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2015-09-10 18:24 - 2015-09-10 18:24 - 00005632 ____H (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2015-09-10 18:24 - 2015-09-10 18:24 - 00004096 ____H (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2015-09-10 18:24 - 2015-09-10 18:24 - 00004096 ____H (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2015-09-10 18:24 - 2015-09-10 18:24 - 00003584 ____H (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2015-09-10 18:24 - 2015-09-10 18:24 - 00003584 ____H (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2015-09-10 18:24 - 2015-09-10 18:24 - 00003072 ____H (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2015-09-10 18:24 - 2015-09-10 18:24 - 00003072 ____H (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2015-09-10 18:24 - 2015-09-10 18:24 - 00003072 ____H (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-downlevel-version-l1-1-0.dll
2015-09-10 18:24 - 2015-09-10 18:24 - 00003072 ____H (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2015-09-10 18:24 - 2015-09-10 18:24 - 00002560 ____H (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2015-09-10 18:24 - 2015-09-10 18:24 - 00002560 ____H (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2015-09-10 18:04 - 2015-09-10 18:05 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-09-10 18:03 - 2015-08-26 18:37 - 134753440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-09-10 17:23 - 2015-09-10 17:23 - 00057560 _____ C:\Users\Pat\AppData\Local\GDIPFONTCACHEV1.DAT
2015-09-10 17:07 - 2015-10-03 02:43 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-09-10 17:07 - 2015-09-10 22:07 - 00003878 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-09-10 17:07 - 2015-09-10 17:07 - 00000000 ____D C:\Users\Pat\AppData\Roaming\Macromedia
2015-09-10 17:07 - 2015-09-10 17:07 - 00000000 ____D C:\Users\Pat\AppData\Roaming\Adobe
2015-09-10 15:45 - 2015-10-01 16:53 - 00000000 ____D C:\Users\Pat\AppData\Local\VirtualStore
2015-09-10 15:39 - 2015-09-10 15:39 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2015-09-10 15:11 - 2015-01-08 23:14 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\powertracker.dll
2015-09-10 15:10 - 2012-11-28 18:56 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wdfres.dll
2015-09-10 15:10 - 2012-11-28 18:56 - 00000003 _____ C:\WINDOWS\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2015-09-10 15:08 - 2015-07-22 12:48 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcResources.dll
2015-09-10 15:07 - 2012-08-21 17:01 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\OxpsConverter.exe
2015-09-10 15:06 - 2012-04-26 01:34 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdrmemptylst.exe
2015-09-10 14:52 - 2015-08-26 14:06 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wu.upgrade.ps.dll
2015-09-10 13:30 - 2015-09-16 19:52 - 00001022 _____ C:\Users\Public\Desktop\MiniTool Partition Wizard Free.lnk
2015-09-10 13:30 - 2015-09-10 22:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiniTool Partition Wizard Free 9.1
2015-09-10 13:30 - 2015-09-10 13:30 - 00000000 ____D C:\Program Files\MiniTool Partition Wizard Free 9.1
2015-09-10 13:30 - 2015-08-11 12:22 - 03067392 _____ C:\WINDOWS\system32\pwNative.exe
2015-09-10 13:30 - 2013-09-30 15:26 - 00019152 ____N C:\WINDOWS\system32\pwdrvio.sys
2015-09-10 13:30 - 2013-09-30 15:26 - 00012504 ____N C:\WINDOWS\system32\pwdspio.sys
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-10-03 08:13 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\sru
2015-10-02 20:22 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-10-02 07:02 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\rescache
2015-10-02 06:27 - 2015-07-10 08:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-10-01 20:39 - 2015-07-10 07:04 - 00000000 ___SD C:\WINDOWS\system32\Nui
2015-10-01 20:39 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2015-10-01 20:39 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system\Speech
2015-10-01 20:38 - 2015-07-10 07:04 - 00000000 __RSD C:\WINDOWS\Media
2015-10-01 20:38 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\oobe
2015-10-01 20:38 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\IME
2015-10-01 20:38 - 2015-07-10 05:05 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2015-10-01 20:35 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\registration
2015-10-01 20:34 - 2015-07-10 05:05 - 00000000 ____D C:\WINDOWS\servicing
2015-10-01 18:09 - 2015-07-10 05:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-10-01 18:08 - 2015-07-10 07:04 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2015-10-01 18:08 - 2015-07-10 07:04 - 00000000 ___SD C:\WINDOWS\system32\F12
2015-10-01 18:08 - 2015-07-10 07:04 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2015-10-01 18:08 - 2015-07-10 07:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-01 18:08 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2015-10-01 18:08 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2015-10-01 18:08 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-10-01 18:08 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\Provisioning
2015-10-01 18:08 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\L2Schemas
2015-10-01 17:47 - 2015-07-10 06:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-10-01 16:12 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-10-01 12:32 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2015-09-16 21:19 - 2015-07-10 08:20 - 00340032 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-09-16 20:26 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\Branding
2015-09-16 19:21 - 2015-07-10 07:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-09-16 18:25 - 2015-07-10 07:00 - 00680256 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2015-09-16 13:50 - 2015-07-10 07:04 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2015-09-16 12:56 - 2015-07-10 05:05 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2015-09-15 12:12 - 2015-07-10 07:06 - 00812008 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-09-15 12:12 - 2015-07-10 07:06 - 00178152 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-09-11 06:14 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\appcompat
2015-09-11 01:50 - 2015-07-10 07:04 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2015-09-11 01:48 - 2015-07-10 09:14 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-11 01:48 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
2015-09-11 01:48 - 2015-07-10 05:05 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2015-09-11 01:48 - 2015-07-10 05:05 - 00000000 ____D C:\WINDOWS\system32\Dism
2015-09-11 01:42 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2015-09-11 01:42 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2015-09-11 01:42 - 2015-07-10 07:01 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll
2015-09-11 01:42 - 2015-07-10 07:01 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqutil.dll
2015-09-11 01:42 - 2015-07-10 07:01 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.dll
2015-09-11 01:42 - 2015-07-10 07:01 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2015-09-11 01:42 - 2015-07-10 07:01 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqrt.dll
2015-09-11 01:42 - 2015-07-10 07:01 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.tlb
2015-09-11 01:42 - 2015-07-10 07:01 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa30.tlb
2015-09-11 01:42 - 2015-07-10 07:01 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa20.tlb
2015-09-11 01:42 - 2015-07-10 07:01 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2015-09-11 01:42 - 2015-07-10 07:01 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa10.tlb
2015-09-11 01:42 - 2015-07-10 07:01 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2015-09-11 01:42 - 2015-07-10 07:01 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2015-09-11 01:42 - 2015-07-10 07:01 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll
2015-09-11 01:42 - 2015-07-10 07:01 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2015-09-11 01:42 - 2015-07-10 07:01 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2015-09-11 01:42 - 2015-07-10 07:01 - 00009096 _____ C:\WINDOWS\SysWOW64\msmqtrc.mof
2015-09-11 01:42 - 2015-07-10 07:00 - 01417728 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqqm.dll
2015-09-11 01:42 - 2015-07-10 07:00 - 00813056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll
2015-09-11 01:42 - 2015-07-10 07:00 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqutil.dll
2015-09-11 01:42 - 2015-07-10 07:00 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.dll
2015-09-11 01:42 - 2015-07-10 07:00 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqrt.dll
2015-09-11 01:42 - 2015-07-10 07:00 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2015-09-11 01:42 - 2015-07-10 07:00 - 00175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mqac.sys
2015-09-11 01:42 - 2015-07-10 07:00 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqlogmgr.dll
2015-09-11 01:42 - 2015-07-10 07:00 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.tlb
2015-09-11 01:42 - 2015-07-10 07:00 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa30.tlb
2015-09-11 01:42 - 2015-07-10 07:00 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa20.tlb
2015-09-11 01:42 - 2015-07-10 07:00 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2015-09-11 01:42 - 2015-07-10 07:00 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2015-09-11 01:42 - 2015-07-10 07:00 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqbkup.exe
2015-09-11 01:42 - 2015-07-10 07:00 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa10.tlb
2015-09-11 01:42 - 2015-07-10 07:00 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe
2015-09-11 01:42 - 2015-07-10 07:00 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcertui.dll
2015-09-11 01:42 - 2015-07-10 07:00 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2015-09-11 01:42 - 2015-07-10 07:00 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2015-09-11 01:42 - 2015-07-10 07:00 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2015-09-11 01:42 - 2015-07-10 07:00 - 00009096 _____ C:\WINDOWS\system32\msmqtrc.mof
2015-09-10 22:22 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\restore
2015-09-10 22:10 - 2015-07-10 07:04 - 00000000 ___RD C:\WINDOWS\PrintDialog
2015-09-10 22:10 - 2015-07-10 07:04 - 00000000 ___RD C:\WINDOWS\MiracastView
2015-09-10 22:09 - 2015-07-10 07:04 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2015-09-10 22:07 - 2015-07-10 07:04 - 00000000 __RHD C:\Users\Public\Libraries
2015-09-10 22:07 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\spool
2015-09-10 22:03 - 2015-07-10 07:04 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-10 22:03 - 2015-07-10 07:04 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-10 22:03 - 2015-07-10 07:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-10 22:03 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2015-09-10 22:03 - 2009-07-13 23:20 - 00000000 ____D C:\Users\Default.migrated
2015-09-10 22:02 - 2015-07-10 07:04 - 00000000 __SHD C:\Program Files\Windows Sidebar
2015-09-10 22:02 - 2015-07-10 07:04 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2015-09-10 22:02 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\zh-HK
2015-09-10 22:02 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\tr-TR
2015-09-10 22:02 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2015-09-10 22:02 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2015-09-10 22:02 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\zh-HK
2015-09-10 22:02 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\tr-TR
2015-09-10 22:02 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\Recovery
2015-09-10 22:02 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\IME
2015-09-10 22:02 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\schemas
2015-09-10 22:02 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2015-09-10 22:02 - 2011-04-12 04:28 - 00000000 ___RD C:\Users\Public\Recorded TV
2015-09-10 22:02 - 2009-07-14 01:32 - 00000000 ____D C:\Program Files\DVD Maker
2015-09-10 21:51 - 2015-07-10 05:05 - 00000000 __RHD C:\Users\Default
2015-09-10 21:16 - 2009-07-14 00:45 - 00022368 ____H C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-09-10 21:16 - 2009-07-14 00:45 - 00022368 ____H C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-09-10 15:38 - 2011-04-12 04:28 - 00000000 ____D C:\WINDOWS\CSC
 
==================== Files in the root of some directories =======
 
2015-04-19 08:20 - 2015-04-19 08:20 - 0005872 _____ () C:\Users\Pat\AppData\Roaming\GKXs2Y86LxSuOYKUMsjSV
2015-04-19 08:20 - 2015-04-19 08:20 - 0005872 _____ () C:\Users\Pat\AppData\Roaming\pVDFgi6c5exU3Kxjgxa8k
 
Some files in TEMP:
====================
C:\Users\Pat\AppData\Local\Temp\dllnt_dump.dll
C:\Users\Pat\AppData\Local\Temp\IQIYIsetup_spl004@kb037.exe
C:\Users\Pat\AppData\Local\Temp\masauto_runxx.dl.dll
C:\Users\Pat\AppData\Local\Temp\masblog_runxx.dl.dll
C:\Users\Pat\AppData\Local\Temp\masflag_runxx.dl.dll
C:\Users\Pat\AppData\Local\Temp\ppstreamsetup_unfix.exe
C:\Users\Pat\AppData\Local\Temp\qqpcmgr_v10.11.16575.227_8881494_Silence.exe
C:\Users\Pat\AppData\Local\Temp\QYAgent_runxx.dl.dll
C:\Users\Pat\AppData\Local\Temp\setup3.exe
C:\Users\Pat\AppData\Local\Temp\SpOrder.dll
C:\Users\Pat\AppData\Local\Temp\sqlite3.dll
C:\Users\Pat\AppData\Local\Temp\UBp4C44.exe
C:\Users\Pat\AppData\Local\Temp\Uninstall.exe
C:\Users\Pat\AppData\Local\Temp\UninstallModule.exe
C:\Users\Pat\AppData\Local\Temp\wgjiklit_533_setup.exe
 

==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll
[2015-07-10 07:00] - [2015-09-16 18:25] - 0680256 ____A (Microsoft Corporation) CE60B3E653A919838B2D6BA2EAE502F1
 
C:\WINDOWS\SysWOW64\dnsapi.dll IS MISSING <==== ATTENTION
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 

LastRegBack: 2015-10-01 17:47
 
==================== End of FRST.txt ============================
 
Available Virtual: 13883.77 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:930.97 GB) (Free:661.09 GB) NTFS
Drive d: () (Fixed) (Total:931.51 GB) (Free:921.66 GB) NTFS
Drive e: (Sep 15 2015) (CDROM) (Total:1.69 GB) (Free:0 GB) UDF
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: B8A2F89A)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
 
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: CB5BD2B2)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=OF Extended)
 
==================== End of Addition.txt ============================

 

OS Name Microsoft Windows 10 Pro
Version 10.0.10240 Build 10240
Other OS Description  Not Available
OS Manufacturer Microsoft Corporation
System Name MOM
System Manufacturer ASUSTeK Computer INC.
System Model CG1330
System Type x64-based PC
System SKU To Be Filled By O.E.M.
Processor AMD Phenom™ II X6 1035T Processor, 2600 Mhz, 6 Core(s), 6 Logical Processor(s)
BIOS Version/Date American Megatrends Inc. 0307, 4/16/2010
SMBIOS Version 2.5
Embedded Controller Version 255.255
BIOS Mode Legacy
BaseBoard Manufacturer ASUSTeK Computer INC.
BaseBoard Model Not Available
BaseBoard Name Base Board
Platform Role Desktop
Secure Boot State Unsupported
PCR7 Configuration Binding Not Possible
Windows Directory C:\WINDOWS
System Directory C:\WINDOWS\system32
Boot Device \Device\HarddiskVolume1
Locale United States
Hardware Abstraction Layer Version = "10.0.10240.16392"
User Name mom\Pat
Time Zone Eastern Daylight Time
Installed Physical Memory (RAM) 8.00 GB
Total Physical Memory 7.75 GB
Available Physical Memory 5.86 GB
Total Virtual Memory 15.5 GB
Available Virtual Memory 13.5 GB
Page File Space 7.75 GB
Page File C:\pagefile.sys
Hyper-V - VM Monitor Mode Extensions Yes
Hyper-V - Second Level Address Translation Extensions Yes
Hyper-V - Virtualization Enabled in Firmware No
Hyper-V - Data Execution Protection Yes

 



#10 Craig Ingle

Craig Ingle
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cleveland, ohio
  • Local time:10:02 AM

Posted 03 October 2015 - 09:32 PM

the site will not allow me to upload/attach the summary file. It says that I don't have permission to upload this type of file. I've tried to do it several times, but to no avail. tell me what you want, and I'll get what you need.

 

P.S. Thanks for the help in advance



#11 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,037 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:02 AM

Posted 03 October 2015 - 10:06 PM

Welcome home and thank you.

Please consider and do this.

===================================================

P2P Warning

--------------------

Going over your logs I noticed that you have µTorrent installed. It is pretty much certain that if you continue to use P2P programs, you will get infected again.
  • Avoid gaming sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs.
  • They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites.
  • Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users.
  • The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications.
I would recommend that you uninstall µTorrent, however that choice is up to you. If you choose to remove the program, you can do so via Start > Control Panel > Add/Remove Programs.

If you are still leaning toward using this program, please take a look at this information about Ransomware which can be delivered via P2P file transfers. The newest variation of Ransomware can make it impossible to recover the files this malicious software encrypts. In other words, you will probably lose most if not all of your valuable information, including pictures. In addition it has recently been reported that P2P downloads may be tracked resulting in your IP address being monitored by copyright authorities. .

If you wish to keep it, please do not use it until we are completely done and your machine is determined to be clean and updated.

===================================================

Farbar's Recovery Scan Tool - Run Fix in Normal or Safe Mode

--------------------
  • Press the Windows key Windows_Logo_key.gif + r on your keyboard at the same time. Type in notepad and press Enter
  • Please copy and paste the contents of the below code box into the open notepad and save it to your desktop (<<<Important) as fixlist.txt
Task: {005D3856-8599-4280-98FF-65E3C3E560F6} - \SPBIW_UpdateTask_Time_313831323534333439352d414a34413734452a786c5a5a -> No File <==== ATTENTION
Task: {1074471E-22AD-4750-BFF0-596D17457693} - \ShopperProJSUpd -> No File <==== ATTENTION
Task: {1B567DF6-9FBA-4604-B2C7-B6548DD0AEBF} - \a02fd56e-2d4a-4e4a-8093-f8bd6f693298-1-7 -> No File <==== ATTENTION
Task: {25F5A4F0-E06D-4CA0-8228-E4300FF06CDA} - \a02fd56e-2d4a-4e4a-8093-f8bd6f693298-1-6 -> No File <==== ATTENTION
Task: {29185FA4-F933-4075-BDED-D2279DA2C1EF} - \a02fd56e-2d4a-4e4a-8093-f8bd6f693298-5 -> No File <==== ATTENTION
Task: {3997AF28-CF6B-415C-A302-9258D48B339A} - \a02fd56e-2d4a-4e4a-8093-f8bd6f693298-3 -> No File <==== ATTENTION
Task: {3C62ACD9-C1C2-4F64-B7F7-45B32CD72861} - \globalUpdateUpdateTaskMachineUA -> No File <==== ATTENTION
Task: {3D093294-FE03-46CE-88CE-D898C8DF4E8E} - \Crossbrowse -> No File <==== ATTENTION
Task: {43892FA5-35FD-4A1D-9924-6EF6ED6E03B4} - \a02fd56e-2d4a-4e4a-8093-f8bd6f693298-10_user -> No File <==== ATTENTION
Task: {4E183A44-4121-44DA-B14B-C61D81C9BA59} - \CIMT_daily_S-1-5-21-600590886-3396321983-1423553912-1001 -> No File <==== ATTENTION
Task: {54B4C875-9163-4510-AECF-D23916C82784} - \Smp -> No File <==== ATTENTION
Task: {5A54B475-8470-408B-ACBD-29DBC79CEB39} - \bvxvdxvx -> No File <==== ATTENTION
Task: {6658BDD6-B5F4-419C-9326-3E58CF81238D} - \WordWizard Auto Updater 1.10.0.24 Core -> No File <==== ATTENTION
Task: {696E4CCD-2331-43B5-B5ED-86BE180012EE} - \1d0c7614-17dd-45d3-87db-fb5a0553396a-7 -> No File <==== ATTENTION
Task: {7060C6D1-A498-45FE-8212-9533A6EF2BB6} - \ConsumerInputUpdateTaskMachineCore -> No File <==== ATTENTION
Task: {75B4A485-9D3F-4677-BA77-67A5923CE9D3} - \a02fd56e-2d4a-4e4a-8093-f8bd6f693298-6 -> No File <==== ATTENTION
Task: {891CC45A-296D-448E-96C2-A5D4E3F750E2} - \a02fd56e-2d4a-4e4a-8093-f8bd6f693298-5_user -> No File <==== ATTENTION
Task: {8E3B5EA4-1F7D-4487-A3BD-4BD7AF97BDB6} - \1d0c7614-17dd-45d3-87db-fb5a0553396a-1-6 -> No File <==== ATTENTION
Task: {8F4C3A2F-D807-437E-BAA4-10DF9721ED47} - \Microsoft\Windows\File Classification Infrastructure\Property Definition Sync -> No File <==== ATTENTION
Task: {9A87FFFC-CBA1-45DA-A8FD-D500580D550D} - \Optimizer Pro Schedule -> No File <==== ATTENTION
Task: {9D0AFD14-5396-4425-988E-265EA74CC042} - \globalUpdateUpdateTaskMachineCore -> No File <==== ATTENTION
Task: {A17F73EA-ED22-437B-8342-F3B292265913} - \1d0c7614-17dd-45d3-87db-fb5a0553396a-10_user -> No File <==== ATTENTION
Task: {B906EA0C-23CA-4E9D-A469-9A1B27C27503} - \WordWizard Auto Updater 1.10.0.24 Pending Update -> No File <==== ATTENTION
Task: {BD45C90F-98E8-406B-9B78-9E034F79404E} - \1d0c7614-17dd-45d3-87db-fb5a0553396a-1-7 -> No File <==== ATTENTION
Task: {BE9890C9-C251-4D74-8560-718CB357E8DB} - \ConsumerInputUpdateTaskMachineUA -> No File <==== ATTENTION
Task: {C4AF0496-11C9-4D5A-B6BA-52DF94C10A38} - \SMW_UpdateTask_Time_313831323534333439352d414a34413734452a786c5a5a -> No File <==== ATTENTION
Task: {C7BEEE96-4E7B-4DFF-A43F-F8DBB5A76D35} - \1d0c7614-17dd-45d3-87db-fb5a0553396a-5 -> No File <==== ATTENTION
Task: {D0EA6EAE-3186-433A-BDFC-3A40C11455FC} - \1d0c7614-17dd-45d3-87db-fb5a0553396a-6 -> No File <==== ATTENTION
Task: {DFF97CFA-E7C4-47B2-AF6F-37F774A2CC55} - \a02fd56e-2d4a-4e4a-8093-f8bd6f693298-7 -> No File <==== ATTENTION
Task: {E7B896B2-91BB-4148-BFF9-392014A70F8B} - \AmiUpdXp -> No File <==== ATTENTION
Task: {F29D6ED7-7D70-43D7-BE00-D1B716807D02} - \1d0c7614-17dd-45d3-87db-fb5a0553396a-5_user -> No File <==== ATTENTION
Task: {F46C268C-B0E1-425E-B8D6-0FDC482919EC} - \CIMT_S-1-5-21-600590886-3396321983-1423553912-1001 -> No File <==== ATTENTION
HKU\S-1-5-21-600590886-3396321983-1423553912-1001\...\Run: [DV] => C:\ProgramData\DataFile\Downloads\DV.exe [277504 2015-09-04] ()
C:\ProgramData\DataFile\Downloads\DV.exe
ShellIconOverlayIdentifiers: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL No File
ShellIconOverlayIdentifiers: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL No File
ShellIconOverlayIdentifiers: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-600590886-3396321983-1423553912-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-600590886-3396321983-1423553912-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [No File]
CHR DefaultSearchURL: Default -> hxxp://www-searching.com/search.aspx?s=F9Gztutdk0004,9103000e-13fa-4f20-853b-5965f4688790,&q={searchTerms}
CHR DefaultSearchKeyword: Default -> www-searching.com
CHR DefaultSuggestURL: Default -> hxxp://api.searchpredict.com/api/?rqtype=ffplugin&siteID=8661&dbCode=1&command={searchTerms}
U3 idsvc; no ImagePath
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath
2015-10-01 11:44 - 2015-10-01 11:44 - 00000000 ____D C:\Users\Pat\AppData\Local\{3984668F-207C-44E9-AB32-C6E75E24D5BE}
2015-09-30 00:36 - 2015-09-30 00:36 - 00000000 ____D C:\Users\Pat\AppData\Local\{59FDCEB7-55B7-462B-BD07-AA98FFC4EE7C}
2015-09-27 11:06 - 2015-09-27 11:06 - 00000000 ____D C:\Users\Pat\AppData\Local\{01A8D258-42A5-49BC-8CB7-9BD072120697}
2015-09-21 21:16 - 2015-09-21 21:16 - 00000000 ____D C:\Users\Pat\AppData\Local\{5B1083E0-9A9B-4910-8754-D944C1EDEC3C}
2015-09-19 22:14 - 2015-09-19 22:14 - 00000000 ____D C:\Users\Pat\AppData\Local\{0490E5A2-478A-4E0D-A336-E05AD7BAE676}
2015-09-17 12:25 - 2015-09-17 12:25 - 00000000 ____D C:\Users\Pat\AppData\Local\{7B9A30AC-45CC-4647-A614-40A48E7E2F2D}
2015-09-16 14:23 - 2015-09-16 14:23 - 00000000 ____D C:\Users\Pat\AppData\Local\{576ACE86-2AF6-40E2-B19F-F6FB8601A372}
2015-09-16 14:23 - 2015-09-16 14:23 - 00000000 ____D C:\Users\Pat\AppData\Local\{2C59100A-17E0-4515-9A42-E3CD3CD25A52}
2015-04-19 08:20 - 2015-04-19 08:20 - 0005872 _____ () C:\Users\Pat\AppData\Roaming\GKXs2Y86LxSuOYKUMsjSV
2015-04-19 08:20 - 2015-04-19 08:20 - 0005872 _____ () C:\Users\Pat\AppData\Roaming\pVDFgi6c5exU3Kxjgxa8k
C:\Users\Pat\AppData\Local\Temp\dllnt_dump.dll
C:\Users\Pat\AppData\Local\Temp\IQIYIsetup_spl004@kb037.exe
C:\Users\Pat\AppData\Local\Temp\masauto_runxx.dl.dll
C:\Users\Pat\AppData\Local\Temp\masblog_runxx.dl.dll
C:\Users\Pat\AppData\Local\Temp\masflag_runxx.dl.dll
C:\Users\Pat\AppData\Local\Temp\ppstreamsetup_unfix.exe
C:\Users\Pat\AppData\Local\Temp\qqpcmgr_v10.11.16575.227_8881494_Silence.exe
C:\Users\Pat\AppData\Local\Temp\QYAgent_runxx.dl.dll
C:\Users\Pat\AppData\Local\Temp\setup3.exe
C:\Users\Pat\AppData\Local\Temp\SpOrder.dll
C:\Users\Pat\AppData\Local\Temp\sqlite3.dll
C:\Users\Pat\AppData\Local\Temp\UBp4C44.exe
C:\Users\Pat\AppData\Local\Temp\Uninstall.exe
C:\Users\Pat\AppData\Local\Temp\UninstallModule.exe
C:\Users\Pat\AppData\Local\Temp\wgjiklit_533_setup.exe
  • Launch FRST and press the Fix button just once and wait, the program will automatically launch fixlist.txt.
  • The tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
  • Copy/paste the following in the Search Field
dnsapi.dll
  • Click Search File(s) button
  • When completed click OK and a Search.txt document will open on your desktop
  • Copy and paste the contents of that document your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Fixlog
  • Search log

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#12 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,037 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:02 AM

Posted 03 October 2015 - 10:10 PM

Greetings,

Don't worry about the System Summary file for now. If we need it we will deal with it then.

You are quite welcome. I appreciate you putting in a long day. :)
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#13 Craig Ingle

Craig Ingle
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cleveland, ohio
  • Local time:10:02 AM

Posted 04 October 2015 - 09:02 AM

Fix result of Farbar Recovery Scan Tool (x64) Version:03-10-2015
Ran by Pat (2015-10-04 09:35:40) Run:1
Running from C:\Users\Pat\Desktop
Loaded Profiles: Pat (Available Profiles: Pat & DefaultAppPool)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Task: {005D3856-8599-4280-98FF-65E3C3E560F6} - \SPBIW_UpdateTask_Time_313831323534333439352d414a34413734452a786c5a5a -> No File <==== ATTENTION
Task: {1074471E-22AD-4750-BFF0-596D17457693} - \ShopperProJSUpd -> No File <==== ATTENTION
Task: {1B567DF6-9FBA-4604-B2C7-B6548DD0AEBF} - \a02fd56e-2d4a-4e4a-8093-f8bd6f693298-1-7 -> No File <==== ATTENTION
Task: {25F5A4F0-E06D-4CA0-8228-E4300FF06CDA} - \a02fd56e-2d4a-4e4a-8093-f8bd6f693298-1-6 -> No File <==== ATTENTION
Task: {29185FA4-F933-4075-BDED-D2279DA2C1EF} - \a02fd56e-2d4a-4e4a-8093-f8bd6f693298-5 -> No File <==== ATTENTION
Task: {3997AF28-CF6B-415C-A302-9258D48B339A} - \a02fd56e-2d4a-4e4a-8093-f8bd6f693298-3 -> No File <==== ATTENTION
Task: {3C62ACD9-C1C2-4F64-B7F7-45B32CD72861} - \globalUpdateUpdateTaskMachineUA -> No File <==== ATTENTION
Task: {3D093294-FE03-46CE-88CE-D898C8DF4E8E} - \Crossbrowse -> No File <==== ATTENTION
Task: {43892FA5-35FD-4A1D-9924-6EF6ED6E03B4} - \a02fd56e-2d4a-4e4a-8093-f8bd6f693298-10_user -> No File <==== ATTENTION
Task: {4E183A44-4121-44DA-B14B-C61D81C9BA59} - \CIMT_daily_S-1-5-21-600590886-3396321983-1423553912-1001 -> No File <==== ATTENTION
Task: {54B4C875-9163-4510-AECF-D23916C82784} - \Smp -> No File <==== ATTENTION
Task: {5A54B475-8470-408B-ACBD-29DBC79CEB39} - \bvxvdxvx -> No File <==== ATTENTION
Task: {6658BDD6-B5F4-419C-9326-3E58CF81238D} - \WordWizard Auto Updater 1.10.0.24 Core -> No File <==== ATTENTION
Task: {696E4CCD-2331-43B5-B5ED-86BE180012EE} - \1d0c7614-17dd-45d3-87db-fb5a0553396a-7 -> No File <==== ATTENTION
Task: {7060C6D1-A498-45FE-8212-9533A6EF2BB6} - \ConsumerInputUpdateTaskMachineCore -> No File <==== ATTENTION
Task: {75B4A485-9D3F-4677-BA77-67A5923CE9D3} - \a02fd56e-2d4a-4e4a-8093-f8bd6f693298-6 -> No File <==== ATTENTION
Task: {891CC45A-296D-448E-96C2-A5D4E3F750E2} - \a02fd56e-2d4a-4e4a-8093-f8bd6f693298-5_user -> No File <==== ATTENTION
Task: {8E3B5EA4-1F7D-4487-A3BD-4BD7AF97BDB6} - \1d0c7614-17dd-45d3-87db-fb5a0553396a-1-6 -> No File <==== ATTENTION
Task: {8F4C3A2F-D807-437E-BAA4-10DF9721ED47} - \Microsoft\Windows\File Classification Infrastructure\Property Definition Sync -> No File <==== ATTENTION
Task: {9A87FFFC-CBA1-45DA-A8FD-D500580D550D} - \Optimizer Pro Schedule -> No File <==== ATTENTION
Task: {9D0AFD14-5396-4425-988E-265EA74CC042} - \globalUpdateUpdateTaskMachineCore -> No File <==== ATTENTION
Task: {A17F73EA-ED22-437B-8342-F3B292265913} - \1d0c7614-17dd-45d3-87db-fb5a0553396a-10_user -> No File <==== ATTENTION
Task: {B906EA0C-23CA-4E9D-A469-9A1B27C27503} - \WordWizard Auto Updater 1.10.0.24 Pending Update -> No File <==== ATTENTION
Task: {BD45C90F-98E8-406B-9B78-9E034F79404E} - \1d0c7614-17dd-45d3-87db-fb5a0553396a-1-7 -> No File <==== ATTENTION
Task: {BE9890C9-C251-4D74-8560-718CB357E8DB} - \ConsumerInputUpdateTaskMachineUA -> No File <==== ATTENTION
Task: {C4AF0496-11C9-4D5A-B6BA-52DF94C10A38} - \SMW_UpdateTask_Time_313831323534333439352d414a34413734452a786c5a5a -> No File <==== ATTENTION
Task: {C7BEEE96-4E7B-4DFF-A43F-F8DBB5A76D35} - \1d0c7614-17dd-45d3-87db-fb5a0553396a-5 -> No File <==== ATTENTION
Task: {D0EA6EAE-3186-433A-BDFC-3A40C11455FC} - \1d0c7614-17dd-45d3-87db-fb5a0553396a-6 -> No File <==== ATTENTION
Task: {DFF97CFA-E7C4-47B2-AF6F-37F774A2CC55} - \a02fd56e-2d4a-4e4a-8093-f8bd6f693298-7 -> No File <==== ATTENTION
Task: {E7B896B2-91BB-4148-BFF9-392014A70F8B} - \AmiUpdXp -> No File <==== ATTENTION
Task: {F29D6ED7-7D70-43D7-BE00-D1B716807D02} - \1d0c7614-17dd-45d3-87db-fb5a0553396a-5_user -> No File <==== ATTENTION
Task: {F46C268C-B0E1-425E-B8D6-0FDC482919EC} - \CIMT_S-1-5-21-600590886-3396321983-1423553912-1001 -> No File <==== ATTENTION
HKU\S-1-5-21-600590886-3396321983-1423553912-1001\...\Run: [DV] => C:\ProgramData\DataFile\Downloads\DV.exe [277504 2015-09-04] ()
C:\ProgramData\DataFile\Downloads\DV.exe
ShellIconOverlayIdentifiers: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL No File
ShellIconOverlayIdentifiers: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL No File
ShellIconOverlayIdentifiers: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-600590886-3396321983-1423553912-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-600590886-3396321983-1423553912-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [No File]
CHR DefaultSearchURL: Default -> hxxp://www-searching.com/search.aspx?s=F9Gztutdk0004,9103000e-13fa-4f20-853b-5965f4688790,&q={searchTerms}
CHR DefaultSearchKeyword: Default -> www-searching.com
CHR DefaultSuggestURL: Default -> hxxp://api.searchpredict.com/api/?rqtype=ffplugin&siteID=8661&dbCode=1&command={searchTerms}
U3 idsvc; no ImagePath
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath
2015-10-01 11:44 - 2015-10-01 11:44 - 00000000 ____D C:\Users\Pat\AppData\Local\{3984668F-207C-44E9-AB32-C6E75E24D5BE}
2015-09-30 00:36 - 2015-09-30 00:36 - 00000000 ____D C:\Users\Pat\AppData\Local\{59FDCEB7-55B7-462B-BD07-AA98FFC4EE7C}
2015-09-27 11:06 - 2015-09-27 11:06 - 00000000 ____D C:\Users\Pat\AppData\Local\{01A8D258-42A5-49BC-8CB7-9BD072120697}
2015-09-21 21:16 - 2015-09-21 21:16 - 00000000 ____D C:\Users\Pat\AppData\Local\{5B1083E0-9A9B-4910-8754-D944C1EDEC3C}
2015-09-19 22:14 - 2015-09-19 22:14 - 00000000 ____D C:\Users\Pat\AppData\Local\{0490E5A2-478A-4E0D-A336-E05AD7BAE676}
2015-09-17 12:25 - 2015-09-17 12:25 - 00000000 ____D C:\Users\Pat\AppData\Local\{7B9A30AC-45CC-4647-A614-40A48E7E2F2D}
2015-09-16 14:23 - 2015-09-16 14:23 - 00000000 ____D C:\Users\Pat\AppData\Local\{576ACE86-2AF6-40E2-B19F-F6FB8601A372}
2015-09-16 14:23 - 2015-09-16 14:23 - 00000000 ____D C:\Users\Pat\AppData\Local\{2C59100A-17E0-4515-9A42-E3CD3CD25A52}
2015-04-19 08:20 - 2015-04-19 08:20 - 0005872 _____ () C:\Users\Pat\AppData\Roaming\GKXs2Y86LxSuOYKUMsjSV
2015-04-19 08:20 - 2015-04-19 08:20 - 0005872 _____ () C:\Users\Pat\AppData\Roaming\pVDFgi6c5exU3Kxjgxa8k
C:\Users\Pat\AppData\Local\Temp\dllnt_dump.dll
C:\Users\Pat\AppData\Local\Temp\IQIYIsetup_spl004@kb037.exe
C:\Users\Pat\AppData\Local\Temp\masauto_runxx.dl.dll
C:\Users\Pat\AppData\Local\Temp\masblog_runxx.dl.dll
C:\Users\Pat\AppData\Local\Temp\masflag_runxx.dl.dll
C:\Users\Pat\AppData\Local\Temp\ppstreamsetup_unfix.exe
C:\Users\Pat\AppData\Local\Temp\qqpcmgr_v10.11.16575.227_8881494_Silence.exe
C:\Users\Pat\AppData\Local\Temp\QYAgent_runxx.dl.dll
C:\Users\Pat\AppData\Local\Temp\setup3.exe
C:\Users\Pat\AppData\Local\Temp\SpOrder.dll
C:\Users\Pat\AppData\Local\Temp\sqlite3.dll
C:\Users\Pat\AppData\Local\Temp\UBp4C44.exe
C:\Users\Pat\AppData\Local\Temp\Uninstall.exe
C:\Users\Pat\AppData\Local\Temp\UninstallModule.exe
C:\Users\Pat\AppData\Local\Temp\wgjiklit_533_setup.exe
*****************
 
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{005D3856-8599-4280-98FF-65E3C3E560F6}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{005D3856-8599-4280-98FF-65E3C3E560F6}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPBIW_UpdateTask_Time_313831323534333439352d414a34413734452a786c5a5a => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1074471E-22AD-4750-BFF0-596D17457693}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1074471E-22AD-4750-BFF0-596D17457693}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ShopperProJSUpd => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1B567DF6-9FBA-4604-B2C7-B6548DD0AEBF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1B567DF6-9FBA-4604-B2C7-B6548DD0AEBF}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a02fd56e-2d4a-4e4a-8093-f8bd6f693298-1-7 => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{25F5A4F0-E06D-4CA0-8228-E4300FF06CDA}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{25F5A4F0-E06D-4CA0-8228-E4300FF06CDA}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a02fd56e-2d4a-4e4a-8093-f8bd6f693298-1-6 => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{29185FA4-F933-4075-BDED-D2279DA2C1EF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{29185FA4-F933-4075-BDED-D2279DA2C1EF}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a02fd56e-2d4a-4e4a-8093-f8bd6f693298-5 => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3997AF28-CF6B-415C-A302-9258D48B339A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3997AF28-CF6B-415C-A302-9258D48B339A}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a02fd56e-2d4a-4e4a-8093-f8bd6f693298-3 => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3C62ACD9-C1C2-4F64-B7F7-45B32CD72861}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3C62ACD9-C1C2-4F64-B7F7-45B32CD72861}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineUA => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3D093294-FE03-46CE-88CE-D898C8DF4E8E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3D093294-FE03-46CE-88CE-D898C8DF4E8E}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Crossbrowse => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{43892FA5-35FD-4A1D-9924-6EF6ED6E03B4}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{43892FA5-35FD-4A1D-9924-6EF6ED6E03B4}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a02fd56e-2d4a-4e4a-8093-f8bd6f693298-10_user => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4E183A44-4121-44DA-B14B-C61D81C9BA59}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4E183A44-4121-44DA-B14B-C61D81C9BA59}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CIMT_daily_S-1-5-21-600590886-3396321983-1423553912-1001 => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{54B4C875-9163-4510-AECF-D23916C82784}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{54B4C875-9163-4510-AECF-D23916C82784}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Smp => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5A54B475-8470-408B-ACBD-29DBC79CEB39}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5A54B475-8470-408B-ACBD-29DBC79CEB39}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvdxvx => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6658BDD6-B5F4-419C-9326-3E58CF81238D}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6658BDD6-B5F4-419C-9326-3E58CF81238D}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WordWizard Auto Updater 1.10.0.24 Core => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{696E4CCD-2331-43B5-B5ED-86BE180012EE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{696E4CCD-2331-43B5-B5ED-86BE180012EE}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\1d0c7614-17dd-45d3-87db-fb5a0553396a-7 => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7060C6D1-A498-45FE-8212-9533A6EF2BB6}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7060C6D1-A498-45FE-8212-9533A6EF2BB6}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ConsumerInputUpdateTaskMachineCore => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{75B4A485-9D3F-4677-BA77-67A5923CE9D3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{75B4A485-9D3F-4677-BA77-67A5923CE9D3}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a02fd56e-2d4a-4e4a-8093-f8bd6f693298-6 => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{891CC45A-296D-448E-96C2-A5D4E3F750E2}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{891CC45A-296D-448E-96C2-A5D4E3F750E2}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a02fd56e-2d4a-4e4a-8093-f8bd6f693298-5_user => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8E3B5EA4-1F7D-4487-A3BD-4BD7AF97BDB6}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8E3B5EA4-1F7D-4487-A3BD-4BD7AF97BDB6}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\1d0c7614-17dd-45d3-87db-fb5a0553396a-1-6 => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8F4C3A2F-D807-437E-BAA4-10DF9721ED47}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8F4C3A2F-D807-437E-BAA4-10DF9721ED47}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\File Classification Infrastructure\Property Definition Sync" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9A87FFFC-CBA1-45DA-A8FD-D500580D550D}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9A87FFFC-CBA1-45DA-A8FD-D500580D550D}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Optimizer Pro Schedule => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9D0AFD14-5396-4425-988E-265EA74CC042}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9D0AFD14-5396-4425-988E-265EA74CC042}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A17F73EA-ED22-437B-8342-F3B292265913}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A17F73EA-ED22-437B-8342-F3B292265913}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\1d0c7614-17dd-45d3-87db-fb5a0553396a-10_user => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B906EA0C-23CA-4E9D-A469-9A1B27C27503}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B906EA0C-23CA-4E9D-A469-9A1B27C27503}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WordWizard Auto Updater 1.10.0.24 Pending Update => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{BD45C90F-98E8-406B-9B78-9E034F79404E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BD45C90F-98E8-406B-9B78-9E034F79404E}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\1d0c7614-17dd-45d3-87db-fb5a0553396a-1-7 => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BE9890C9-C251-4D74-8560-718CB357E8DB}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BE9890C9-C251-4D74-8560-718CB357E8DB}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ConsumerInputUpdateTaskMachineUA => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C4AF0496-11C9-4D5A-B6BA-52DF94C10A38}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C4AF0496-11C9-4D5A-B6BA-52DF94C10A38}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SMW_UpdateTask_Time_313831323534333439352d414a34413734452a786c5a5a => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C7BEEE96-4E7B-4DFF-A43F-F8DBB5A76D35}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C7BEEE96-4E7B-4DFF-A43F-F8DBB5A76D35}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\1d0c7614-17dd-45d3-87db-fb5a0553396a-5 => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D0EA6EAE-3186-433A-BDFC-3A40C11455FC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D0EA6EAE-3186-433A-BDFC-3A40C11455FC}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\1d0c7614-17dd-45d3-87db-fb5a0553396a-6 => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{DFF97CFA-E7C4-47B2-AF6F-37F774A2CC55}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DFF97CFA-E7C4-47B2-AF6F-37F774A2CC55}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a02fd56e-2d4a-4e4a-8093-f8bd6f693298-7 => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E7B896B2-91BB-4148-BFF9-392014A70F8B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E7B896B2-91BB-4148-BFF9-392014A70F8B}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AmiUpdXp => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F29D6ED7-7D70-43D7-BE00-D1B716807D02}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F29D6ED7-7D70-43D7-BE00-D1B716807D02}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\1d0c7614-17dd-45d3-87db-fb5a0553396a-5_user => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F46C268C-B0E1-425E-B8D6-0FDC482919EC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F46C268C-B0E1-425E-B8D6-0FDC482919EC}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CIMT_S-1-5-21-600590886-3396321983-1423553912-1001 => key not found.
HKU\S-1-5-21-600590886-3396321983-1423553912-1001\Software\Microsoft\Windows\CurrentVersion\Run\\DV => value removed successfully
C:\ProgramData\DataFile\Downloads\DV.exe => moved successfully
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrivePro1 (ErrorConflict)" => key removed successfully
"HKCR\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}" => key removed successfully
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrivePro2 (SyncInProgress)" => key removed successfully
"HKCR\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}" => key removed successfully
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrivePro3 (InSync)" => key removed successfully
"HKCR\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}" => key removed successfully
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key removed successfully
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
"HKU\S-1-5-21-600590886-3396321983-1423553912-1001\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKU\S-1-5-21-600590886-3396321983-1423553912-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0" => key removed successfully
Chrome DefaultSearchURL removed successfully
Chrome DefaultSearchKeyword removed successfully
Chrome DefaultSuggestURL removed successfully
idsvc => service removed successfully
wfpcapture => service removed successfully
wpcsvc => service removed successfully
C:\Users\Pat\AppData\Local\{3984668F-207C-44E9-AB32-C6E75E24D5BE} => moved successfully
C:\Users\Pat\AppData\Local\{59FDCEB7-55B7-462B-BD07-AA98FFC4EE7C} => moved successfully
C:\Users\Pat\AppData\Local\{01A8D258-42A5-49BC-8CB7-9BD072120697} => moved successfully
C:\Users\Pat\AppData\Local\{5B1083E0-9A9B-4910-8754-D944C1EDEC3C} => moved successfully
C:\Users\Pat\AppData\Local\{0490E5A2-478A-4E0D-A336-E05AD7BAE676} => moved successfully
C:\Users\Pat\AppData\Local\{7B9A30AC-45CC-4647-A614-40A48E7E2F2D} => moved successfully
C:\Users\Pat\AppData\Local\{576ACE86-2AF6-40E2-B19F-F6FB8601A372} => moved successfully
C:\Users\Pat\AppData\Local\{2C59100A-17E0-4515-9A42-E3CD3CD25A52} => moved successfully
C:\Users\Pat\AppData\Roaming\GKXs2Y86LxSuOYKUMsjSV => moved successfully
C:\Users\Pat\AppData\Roaming\pVDFgi6c5exU3Kxjgxa8k => moved successfully
C:\Users\Pat\AppData\Local\Temp\dllnt_dump.dll => moved successfully
C:\Users\Pat\AppData\Local\Temp\IQIYIsetup_spl004@kb037.exe => moved successfully
C:\Users\Pat\AppData\Local\Temp\masauto_runxx.dl.dll => moved successfully
C:\Users\Pat\AppData\Local\Temp\masblog_runxx.dl.dll => moved successfully
C:\Users\Pat\AppData\Local\Temp\masflag_runxx.dl.dll => moved successfully
C:\Users\Pat\AppData\Local\Temp\ppstreamsetup_unfix.exe => moved successfully
C:\Users\Pat\AppData\Local\Temp\qqpcmgr_v10.11.16575.227_8881494_Silence.exe => moved successfully
C:\Users\Pat\AppData\Local\Temp\QYAgent_runxx.dl.dll => moved successfully
C:\Users\Pat\AppData\Local\Temp\setup3.exe => moved successfully
C:\Users\Pat\AppData\Local\Temp\SpOrder.dll => moved successfully
C:\Users\Pat\AppData\Local\Temp\sqlite3.dll => moved successfully
C:\Users\Pat\AppData\Local\Temp\UBp4C44.exe => moved successfully
C:\Users\Pat\AppData\Local\Temp\Uninstall.exe => moved successfully
C:\Users\Pat\AppData\Local\Temp\UninstallModule.exe => moved successfully
C:\Users\Pat\AppData\Local\Temp\wgjiklit_533_setup.exe => moved successfully
 
==== End of Fixlog 09:35:47 ====
 
C:\Windows.old\Windows\winsxs\wow64_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7601.21673_none_4aa4e997e6a8ddc0\dnsapi.dll
[2015-09-10 15:07][2011-03-03 01:12] 0270336 ____A (Microsoft Corporation) 1F79F611109C2B97260B68FD6B4FC7DD [File not signed]
 
C:\Windows.old\Windows\winsxs\wow64_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7601.17570_none_4a184beecd8df1f1\dnsapi.dll
[2015-09-10 15:07][2011-03-03 01:38] 0270336 ____A (Microsoft Corporation) B40420876B9288E0A1C8CCA8A84E5DC9 [File not signed]
 
C:\Windows.old\Windows\winsxs\wow64_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7601.17514_none_4a5d2c9ecd59afa7\dnsapi.dll
[2010-11-20 23:24][2010-11-20 23:24] 0270336 ____A (Microsoft Corporation) 59DF156711A76BCB993253EC6C9BBF41 [File not signed]
 
C:\Windows.old\Windows\winsxs\amd64_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7601.21673_none_40503f45b2481bc5\dnsapi.dll
[2015-09-10 15:07][2011-03-03 02:12] 0357888 ____A (Microsoft Corporation) DCC0888655823103F19EF8FFD330080D [File not signed]
 
C:\Windows.old\Windows\winsxs\amd64_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7601.17570_none_3fc3a19c992d2ff6\dnsapi.dll
[2015-09-10 15:07][2011-03-03 02:24] 0357888 ____A (Microsoft Corporation) 492D07D79E7024CA310867B526D9636D [File not signed]
 
 
C:\Windows.old\Windows\winsxs\amd64_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7601.17514_none_4008824c98f8edac\dnsapi.dll
[2010-11-20 23:24][2010-11-20 23:24] 0357888 ____A (Microsoft Corporation) A52B6CC24063CC83C78C0E6F24DEEC01 [File not signed]
 
C:\Windows.old\Windows\SysWOW64\dnsapi.dll
[2015-09-10 15:07][2011-03-03 01:38] 0270336 ____A (Microsoft Corporation) B40420876B9288E0A1C8CCA8A84E5DC9 [File not signed]
 
C:\Windows.old\Windows\System32\dnsapi.dll
[2015-09-10 15:07][2011-03-03 02:24] 0357888 ____A (Microsoft Corporation) 492D07D79E7024CA310867B526D9636D [File not signed]
 
C:\Windows\WinSxS\wow64_microsoft-windows-dns-client-minwin_31bf3856ad364e35_10.0.10240.16384_none_a7e0cfc0f233a685\dnsapi.dll
[2015-07-10 07:00][2015-07-10 07:00] 0534064 ____A (Microsoft Corporation) BB5BBD0E4D04047585E4ED0F07AA51E7 [File is digitally signed]
 
C:\Windows\WinSxS\amd64_microsoft-windows-dns-client-minwin_31bf3856ad364e35_10.0.10240.16384_none_9d8c256ebdd2e48a\dnsapi.dll
[2015-07-10 07:00][2015-07-10 07:00] 0680256 ____A (Microsoft Corporation) C287D0E32771E3222A444DC527A29477 [File is digitally signed]
 
C:\Windows\System32\dnsapi.dll
[2015-07-10 07:00][2015-09-16 18:25] 0680256 ____A (Microsoft Corporation) CE60B3E653A919838B2D6BA2EAE502F1 [File not signed]
 
====== End of Search ======



#14 Craig Ingle

Craig Ingle
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cleveland, ohio
  • Local time:10:02 AM

Posted 04 October 2015 - 09:03 AM

again I will be working till 9 or so tonight, so I will look for any answers when I get home.

 

Thanks again



#15 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,037 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:02 AM

Posted 04 October 2015 - 04:00 PM

Thanks and welcome home again!

Please do this.

===================================================

Farbar's Recovery Scan Tool

--------------------

For this step you will need a USB flash drive.
  • Press the windows key Windows_Logo_key.gif + r on your keyboard at the same time. Type in notepad and press Enter
  • Please copy and paste the contents of the below code box into the open notepad and save it on the flashdrive as fixlist.txt
cmd: copy /y C:\Windows\WinSxS\amd64_microsoft-windows-dns-client-minwin_31bf3856ad364e35_10.0.10240.16384_none_9d8c256ebdd2e48a\dnsapi.dll C:\Windows\System32\dnsapi.dll
cmd: copy /y C:\Windows\WinSxS\wow64_microsoft-windows-dns-client-minwin_31bf3856ad364e35_10.0.10240.16384_none_a7e0cfc0f233a685\dnsapi.dll C:\WINDOWS\SysWOW64
  • Please download Farbar Recovery Scan Tool and save it to a flash drive. You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Plug the flashdrive into the infected PC and follow the 2 step process below. Step #1 is to boot into the System Recovery Options and Step #2 is running Farbar's Recover Scan Tool
----------

Step #1 - Entering System Recovery Options

Option #1 (Windows7/Vista)

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select English as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.
Option #2 (Windows 7/Vista)

To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select English as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next
----------

Step #2 - Running Farbar's Recovery Scan Tool in System Recovery
  • Once you are in the System Recovery Options menu you will get the following options:

Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

  • Select Command Prompt
  • In the command window type in Notepad and press Enter.
  • The notepad opens. Under File menu select Open.
  • Select Computer and find your flash drive letter and close the notepad.
  • In the command window type e:\frst (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
  • When the tool opens click Yes to disclaimer.
  • Press Fix button.
  • It will make a log (fixlog.txt) on the flash drive. Please copy and paste it to your reply.
  • Reboot your computer into Normal Mode and check the performance
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Fixlog
  • Update on computer performance

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users