Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

I think my computer is being controlled by a remote admin


  • This topic is locked This topic is locked
3 replies to this topic

#1 paigeorge

paigeorge

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:03:27 AM

Posted 05 February 2016 - 05:11 PM

Hello everyone. I hope I am posting this to the correct forum. I'm not sure if I have a trojan or some sort of malware, but I do believe that someone is gaining access to my computer remotely. If I should post this in a different forum, please let me know. I am a newbie when it comes to digging a little deeper into my computer, so if I have made mistakes, please go easy. I have a self built desktop computer running a fresh from USB dongle installation of Windows 10. Windows was installed on the 19th. I own this machine and I am wirelessly connected to an AT&T U-Verse modem/router. All of my system specs are listed in the attached "Speccy Summary-PAIGEDESKTOP.txt" file.  I noticed that within a few days of installing, my registry changed quite a bit, I was locked out of folders and files that I didn't think I should be, and I was uploading a lot of data without explanation, I experienced a number of memory crashes and certain apps and software that I installed would not run or freeze or was missing components. I also tried to run the following command: sfc /scannow - and I received a message that that function had been blocked by the administrator. So, I started looking around the system and I found some things that I'm not sure about, but maybe they are normal. There are other examples, but I thought I would provide these to begin with. I apologize if I'm completely wrong about all of this and these are all normal items. I have a neighbor who recently experienced someone controlling his system remotely and there is strong suspicion that it was a different neighbor who was responsible. So, I might be a little paranoid. Here are some of the things I found:

 

In Device Manager, I continuously uninstall the Microsoft Wi-Fi Direct Virtual Adapter, but it reappears. I did not install this. I also have a Microsoft Hosted Virtual Adapter, which I did not install. Both of these can be seen in the attached "Speccy Summary-PAIGEDESKTOP.txt". I have used Nirsoft Network software to monitor my adapters, and the Direct Virtual Adapter is uploading and downloading data sometimes, but then it is disabled without any action on my part.

 

I have a number of System Processes with Remote Connections, which can be seen near the bottom of the attached "Speccy Network Log.txt". Also located in this file is a section titled "WinInet Info" and it shows the following info: "LAN Connection - Local system uses a local area network to connect to the Internet - Local system has RAS to connect to the Internet."  The RAS, or Remote Access Service, I believe is used in a server environment, but I suppose it could be used for connecting to my ISP or some other website.

 


I found a number of suspicious Junctions, one of which led to this local directory: C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs.  In this folder I found a file named NGenTask.exe (attached). Opening this with notepad, I found references to WinRT, which I thought was primarily associated with Windows Server 2012, or other server software, but I could be wrong.

 

I looked through my Event Viewer logs and came across several SMB Client and SMB Server events. I should not be either of these, unless there is something I do not understand about SMB. I am not sharing my printer nor should I be sharing any files with anyone. But, again, I could be wrong about this. This is attached as "SMB Server Event". I also saw an event regarding file virtualization, which I don't think I should have either, but again, I may not understand it very well. This is attached as "File Virtualization Event".

 

I have pasted the FRST.txt below and I've attached the Addition.txt.

 

 

 

Thank you very much,

Paige

 

 Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:27-01-2016

Ran by georg (administrator) on PAIGEDESKTOP (05-02-2016 16:14:20)
Running from C:\Users\georg\Downloads
Loaded Profiles: georg (Available Profiles: Paige Perry & georg)
Platform: Windows 10 Home Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Ruiware LLC) C:\Program Files (x86)\Ruiware\WinPatrol\WinPatrol.exe
(PFU LIMITED) C:\Program Files (x86)\PFU\ScanSnap\CardMinder\CardLauncher.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(PFU LIMITED) C:\Program Files (x86)\PFU\ScanSnap\Update\SsUWatcher.exe
(PFU LIMITED) C:\Program Files (x86)\PFU\ScanSnap\Driver\PfuSsMon.exe
(PFU LIMITED) C:\Program Files (x86)\PFU\ScanSnap\SSFolder\SSFolderTray.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) C:\Windows\hh.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.201.11370.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_2015.25.24.0_x64__8wekyb3d8bbwe\WinStore.Mobile.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\georg\Downloads\FSS.exe
(Piriform Ltd) C:\Users\georg\Downloads\spsetup128\Speccy64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Tweaking.com) C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\Repair_Windows.exe
(Tweaking.com) C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation)
HKLM-x32\...\Run: [ScanSnap OnlineUpdate Watcher] => C:\Program Files (x86)\PFU\ScanSnap\Update\SsUWatcher.exe [77824 2015-11-17] (PFU LIMITED)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1311319171-3916018615-375967268-1003\...\Run: [WinPatrol] => C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe [1163264 2015-03-30] (Ruiware LLC)
HKU\S-1-5-21-1311319171-3916018615-375967268-1003\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8591272 2015-11-16] (Piriform Ltd)
HKU\S-1-5-21-1311319171-3916018615-375967268-1003\...\MountPoints2: {262b87ce-be7f-11e5-8ca3-806e6f6e6963} - "D:\HBCD\WINTOOLS\HBCDMENU.EXE"
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE ->
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CardMinder Viewer.lnk [2016-02-02]
ShortcutTarget: CardMinder Viewer.lnk -> C:\Program Files (x86)\PFU\ScanSnap\CardMinder\CardLauncher.exe (PFU LIMITED)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Conversion to PDF with ScanSnap Organizer.lnk [2016-02-05]
ShortcutTarget: Conversion to PDF with ScanSnap Organizer.lnk -> C:\Program Files (x86)\PFU\ScanSnap\Organizer\PfuSsOrgOcrChk.exe (PFU LIMITED)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ScanSnap Manager.lnk [2016-02-05]
ShortcutTarget: ScanSnap Manager.lnk -> C:\Program Files (x86)\PFU\ScanSnap\Driver\PfuSsMon.exe (PFU LIMITED)
Startup: C:\Users\Paige Perry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk [2016-01-20]
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{36067079-8cee-428a-937b-29a0c53652bc}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{36067079-8cee-428a-937b-29a0c53652bc}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{91b52ebe-f6ac-49f7-bb4a-8f4a83b2b97d}: [DhcpNameServer] 192.168.1.254

Internet Explorer:
==================
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2016-01-28] (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2016-01-28] (Oracle Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2016-01-19] (Oracle Corporation)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2015-12-01] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2016-01-19] (Oracle Corporation)

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.80.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2016-01-28] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.80.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2016-01-28] (Oracle Corporation)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2016-01-19] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2016-01-19] (Oracle Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-01-31] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-01-31] (Google Inc.)

Chrome:
=======
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-01-31]
CHR Extension: (Google Docs) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-31]
CHR Extension: (Google Drive) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-31]
CHR Extension: (YouTube) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-31]
CHR Extension: (Google Cast) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2016-02-02]
CHR Extension: (Adblock Plus) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-02-05]
CHR Extension: (Pushbullet) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\chlffgpmiacpedhhbkiomidkjlcfhogd [2016-01-31]
CHR Extension: (OneTab) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\chphlpgkkbolifaimnlloiipkdnihall [2016-01-31]
CHR Extension: (Google Search) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-31]
CHR Extension: (Chrome Connectivity Diagnostics) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\eemlkeanncmjljgehlbplemhmdmalhdc [2016-01-31]
CHR Extension: (Black Menu for Google™) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\eignhdfgaldabilaaegmdfbajngjmoke [2016-01-31]
CHR Extension: (Google Sheets) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-01-31]
CHR Extension: (Shield For Chrome ) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\gceighgadbamgchioaofojlblndjcggh [2016-01-31]
CHR Extension: (GQueues) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\gengnoncfjgkpbollpiejnelleeoiiei [2016-01-31]
CHR Extension: (Bookmark Manager) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2016-01-31]
CHR Extension: (Noisli) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\klejemegaoblahjdpcajmpcnjjmkmkkf [2016-02-05]
CHR Extension: (Google Hangouts) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\knipolnnllmklapflnccelgolnpehhpl [2016-01-31]
CHR Extension: (Evernote Web) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol [2016-01-31]
CHR Extension: (Google Dictionary (by Google)) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2016-01-31]
CHR Extension: (Google Drawings) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkaakpdehdafacodkgkpghoibnmamcme [2016-01-31]
CHR Extension: (Google Hangouts) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\nckgahadagoaajjgafhacjanaoiihapd [2016-01-31]
CHR Extension: (GQueues Chrome Extension) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfaboplgcinooacenccbofkaadcfbkkb [2016-01-31]
CHR Extension: (Chrome Web Store Payments) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-01-31]
CHR Extension: (Evernote Web Clipper) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2016-01-31]
CHR Extension: (Gmail) - C:\Users\georg\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-31]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-22] (SUPERAntiSpyware.com)
R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [127752 2016-01-31] (SurfRight B.V.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-02-28] (Riverbed Technology, Inc.)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S3 WiFiPasswordService; C:\Users\PAIGEP~1\AppData\Local\Temp\WiFiPasswordService.exe [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 cpuz138; C:\Users\georg\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [28392 2016-02-05] (CPUID)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-02-05] (Malwarebytes)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [193336 2015-07-10] (Intel Corporation)
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-02-28] (Riverbed Technology, Inc.)
S3 PORTMON; C:\Program Files (x86)\Sysinternals Suite\PORTMSYS.SYS [28656 2016-01-19] (Systems Internals) [File not signed]
U5 PROCMON23; C:\Windows\System32\Drivers\PROCMON23.sys [84360 2016-01-29] (Sysinternals - www.sysinternals.com) [File not signed]
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek )
R3 rtwlane_13; C:\Windows\System32\drivers\rtwlane_13.sys [3749888 2015-10-30] (Realtek Semiconductor Corporation )
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 SliceDisk5; C:\Program Files\A-FF Find and Mount\slicedisk-x64.sys [31824 2011-02-25] (Atola) [File not signed]
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-02-05 16:14 - 2016-02-05 16:14 - 00017884 _____ C:\Users\georg\Downloads\FRST.txt
2016-02-05 16:13 - 2016-02-05 16:14 - 00000000 ____D C:\FRST
2016-02-05 16:13 - 2016-02-05 16:13 - 02370560 _____ (Farbar) C:\Users\georg\Downloads\FRST64.exe
2016-02-05 15:38 - 2016-02-05 15:38 - 00005104 _____ C:\Users\georg\Downloads\Tweaking.com - Windows Repair - Pre-Scan.txt
2016-02-05 15:36 - 2016-02-05 15:36 - 00002176 _____ C:\Users\georg\Desktop\Tweaking.com - Hardware Identify.lnk
2016-02-05 15:31 - 2016-02-05 15:31 - 00002232 _____ C:\Users\georg\Desktop\Tweaking.com - Windows Repair.lnk
2016-02-05 15:31 - 2016-02-05 15:31 - 00000000 _____ C:\Users\georg\Desktop\New Text Document (3).txt
2016-02-05 15:12 - 2016-02-05 15:31 - 00000000 ____D C:\Users\georg\Downloads\spsetup128
2016-02-05 15:12 - 2016-02-05 15:12 - 00003776 _____ C:\Windows\System32\Tasks\Tweaking.com - Windows Repair Tray Icon
2016-02-05 15:11 - 2016-02-05 15:32 - 00183062 _____ C:\Windows\Tweaking.com - Windows Repair Setup Log.txt
2016-02-05 15:01 - 2016-02-05 15:12 - 01721856 _____ (Farbar) C:\Users\georg\Downloads\FRST.exe
2016-02-05 15:01 - 2016-02-05 15:12 - 00899584 _____ (Farbar) C:\Users\georg\Downloads\FSS.exe
2016-02-05 15:01 - 2016-02-05 15:11 - 21771608 _____ (Tweaking.com) C:\Users\georg\Downloads\tweaking.com_windows_repair_aio_setup (2).exe
2016-02-05 14:58 - 2016-02-05 15:36 - 06562608 _____ C:\Users\georg\Downloads\tweaking.com_hardware_identify_setup.exe
2016-02-05 14:58 - 2016-02-05 14:58 - 21771608 _____ (Tweaking.com) C:\Users\georg\Downloads\tweaking.com_windows_repair_aio_setup (1).exe
2016-02-05 14:58 - 2016-02-05 14:58 - 05381587 _____ C:\Users\georg\Downloads\spsetup128.zip
2016-02-05 13:34 - 2016-02-05 14:53 - 00000000 ____D C:\Program Files (x86)\DriverToolkit
2016-02-05 13:34 - 2016-02-05 13:34 - 00000000 ____D C:\Users\georg\AppData\Local\DriverToolkit
2016-02-05 13:23 - 2016-02-05 13:23 - 00002343 _____ C:\Users\georg\Desktop\ABBYY FineReader for ScanSnap ™ 5.0.lnk
2016-02-05 13:19 - 2016-02-05 13:19 - 00000000 ____D C:\Users\georg\Documents\ScanSnap
2016-02-05 13:12 - 2016-02-05 13:12 - 03224830 _____ C:\Users\georg\Downloads\P8H67-M-PRO-ASUS-3904.zip
2016-02-05 12:10 - 2016-02-05 12:10 - 00001141 _____ C:\Users\Public\Desktop\ScanSnap Receipt.lnk
2016-02-05 12:10 - 2016-02-05 12:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ScanSnap Receipt
2016-02-05 12:09 - 2016-02-05 12:09 - 00000000 ____D C:\Users\georg\AppData\Local\Nuance
2016-02-05 12:09 - 2016-02-05 12:09 - 00000000 ____D C:\ProgramData\Nuance
2016-02-05 12:08 - 2016-02-05 12:08 - 00000000 ____D C:\Windows\SSDriver
2016-02-05 12:08 - 2016-02-05 12:08 - 00000000 ____D C:\Users\georg\AppData\Local\PFU
2016-02-05 12:08 - 2016-02-05 12:08 - 00000000 ____D C:\ProgramData\PFU
2016-02-05 12:08 - 2016-02-05 12:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ScanSnap Manager
2016-02-05 12:06 - 2016-02-05 12:06 - 00002218 _____ C:\Users\Public\Desktop\ScanSnap Organizer.lnk
2016-02-05 12:05 - 2016-02-05 12:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ScanSnap Organizer
2016-02-05 12:05 - 2016-02-05 12:05 - 00000000 ____D C:\Users\georg\AppData\Local\Downloaded Installations
2016-02-05 10:03 - 2016-02-05 10:03 - 00000534 _____ C:\Windows\system32\.crusader
2016-02-04 17:02 - 2016-02-04 17:02 - 00000000 ____D C:\sgol
2016-02-04 13:12 - 2016-02-04 13:12 - 00000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2016-02-04 13:11 - 2016-02-05 12:13 - 00000000 ____D C:\Windows\pss
2016-02-04 13:09 - 2016-02-04 13:09 - 00000000 ____D C:\Users\Paige Perry\AppData\Roaming\PFU
2016-02-04 13:09 - 2016-02-04 13:09 - 00000000 ____D C:\Users\Paige Perry\AppData\Local\Dropbox
2016-02-03 14:10 - 2016-02-03 14:10 - 00000000 ____D C:\Users\georg\AppData\Roaming\Sun
2016-02-03 14:10 - 2016-02-03 14:10 - 00000000 ____D C:\Users\georg\AppData\LocalLow\Sun
2016-02-03 14:10 - 2016-02-03 14:10 - 00000000 ____D C:\Users\georg\.oracle_jre_usage
2016-02-03 13:22 - 2016-02-03 13:22 - 00002376 _____ C:\Users\georg\Desktop\Chrome App Launcher.lnk
2016-02-03 13:22 - 2016-02-03 13:22 - 00000000 ____D C:\Users\georg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2016-02-03 04:25 - 2016-02-03 04:25 - 00000531 _____ C:\Users\georg\Documents\netconnectchoose.csv
2016-02-03 04:21 - 2016-02-03 04:21 - 00036469 _____ C:\Users\georg\Documents\appcrash.csv
2016-02-03 04:18 - 2016-02-03 04:18 - 00000000 _____ C:\Users\georg\Desktop\New Text Document (2).txt
2016-02-03 04:11 - 2016-02-03 04:11 - 00006762 _____ C:\Users\georg\Documents\networkconnectlog.csv
2016-02-03 04:06 - 2016-02-03 04:06 - 00017606 _____ C:\Users\georg\Documents\currprocess.txt
2016-02-03 04:06 - 2016-02-03 04:06 - 00004678 _____ C:\Users\georg\Documents\wirelessconnectioninfo.csv
2016-02-03 04:04 - 2016-02-03 04:04 - 00001333 _____ C:\Users\georg\Documents\adapterwatch.csv
2016-02-03 04:03 - 2016-02-03 04:03 - 00000465 _____ C:\Users\georg\Documents\wirelessnetview.csv
2016-02-03 03:50 - 2016-02-03 03:50 - 00002864 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2016-02-03 03:50 - 2016-02-03 03:50 - 00000863 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-02-03 03:50 - 2016-02-03 03:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-02-03 03:50 - 2016-02-03 03:50 - 00000000 ____D C:\Program Files\CCleaner
2016-02-03 03:47 - 2016-02-03 04:37 - 00000000 ____D C:\Users\georg\Downloads\Nirsoft Data
2016-02-03 01:40 - 2016-02-05 15:36 - 00002323 _____ C:\Users\Public\Desktop\Tweaking.com - Technicians Toolbox.lnk
2016-02-03 01:40 - 2016-02-05 15:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2016-02-03 01:40 - 2016-02-05 15:36 - 00000000 ____D C:\Program Files (x86)\Tweaking.com
2016-02-03 01:39 - 2016-02-05 15:36 - 00030887 _____ C:\Windows\Tweaking.com - Technicians Toolbox Setup Log.txt
2016-02-03 01:38 - 2016-02-03 01:38 - 00000000 _____ C:\Windows\system32\getservice.txt
2016-02-03 01:32 - 2016-02-03 01:32 - 00041999 _____ C:\Users\georg\Desktop\dds.txt
2016-02-03 01:32 - 2016-02-03 01:32 - 00025616 _____ C:\Users\georg\Desktop\attach.txt
2016-02-03 01:24 - 2016-02-03 01:25 - 00000000 ____D C:\Users\georg\Documents\mes
2016-02-03 01:23 - 2016-02-03 03:50 - 00000000 ____D C:\Users\georg\AppData\Roaming\WinPatrol
2016-02-03 01:23 - 2016-02-03 01:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPatrol
2016-02-03 01:22 - 2016-02-03 01:22 - 00000000 ____D C:\ProgramData\InstallMate
2016-02-03 01:22 - 2016-02-03 01:22 - 00000000 ____D C:\Program Files (x86)\Ruiware
2016-02-03 01:02 - 2016-02-03 01:02 - 00010698 _____ C:\Users\georg\Desktop\CHROME PROCESS.txt
2016-02-03 00:59 - 2016-02-03 00:59 - 00000000 _____ C:\Users\georg\Desktop\New Text Document.txt
2016-02-03 00:47 - 2016-02-03 00:47 - 00000000 ____D C:\Users\georg\Downloads\Provisioning
2016-02-03 00:47 - 2016-02-03 00:47 - 00000000 ____D C:\Users\georg\Documents\Provisioning
2016-02-03 00:47 - 2016-02-03 00:47 - 00000000 ____D C:\Users\georg\Documents\PolicyDefinitions
2016-02-03 00:42 - 2016-02-03 00:42 - 00000000 ____D C:\Users\georg\Documents\Comms
2016-02-03 00:38 - 2015-12-07 13:04 - 08067784 _____ (Microsoft Corporation) C:\Users\georg\Documents\wct431E.tmp
2016-02-03 00:37 - 2016-02-03 00:27 - 00000985 _____ C:\Users\georg\Documents\tmpscx7ci1143205117.cert
2016-02-03 00:37 - 2016-02-02 22:44 - 00562072 _____ C:\Users\georg\Documents\sqlite3.dll
2016-02-03 00:37 - 2016-02-02 22:34 - 00016400 ___HT C:\Users\georg\Documents\etilqs_XjajQwZeB5j3u2G
2016-02-03 00:37 - 2016-02-02 22:34 - 00002052 ___HT C:\Users\georg\Documents\etilqs_fdUDtrY3jGMQelx
2016-02-03 00:34 - 2016-02-03 00:34 - 00000000 ____D C:\Users\georg\Documents\Panther
2016-02-03 00:33 - 2016-02-03 00:32 - 00006327 _____ C:\Users\georg\Documents\DLLHOST.EXE-824949B9.pf
2016-02-03 00:33 - 2016-02-03 00:31 - 00009481 _____ C:\Users\georg\Documents\NOTEPAD.EXE-D8414F97.pf
2016-02-03 00:33 - 2016-02-03 00:31 - 00008444 _____ C:\Users\georg\Documents\BACKGROUNDTASKHOST.EXE-8830FC91.pf
2016-02-03 00:33 - 2016-02-03 00:30 - 00022158 _____ C:\Users\georg\Documents\OPENWITH.EXE-5C93E816.pf
2016-02-03 00:33 - 2016-02-03 00:30 - 00019047 _____ C:\Users\georg\Documents\CONSENT.EXE-531BD9EA.pf
2016-02-03 00:33 - 2016-02-03 00:30 - 00018168 _____ C:\Users\georg\Documents\DLLHOST.EXE-6A473D35.pf
2016-02-03 00:33 - 2016-02-03 00:30 - 00013157 _____ C:\Users\georg\Documents\MPCMDRUN.EXE-F401FBB4.pf
2016-02-03 00:33 - 2016-02-03 00:30 - 00003291 _____ C:\Users\georg\Documents\DLLHOST.EXE-766398D2.pf
2016-02-03 00:33 - 2016-02-03 00:29 - 00006072 _____ C:\Users\georg\Documents\GOOGLEUPDATE.EXE-B95715F5.pf
2016-02-03 00:33 - 2016-02-03 00:28 - 00006123 _____ C:\Users\georg\Documents\DLLHOST.EXE-5E46FA0D.pf
2016-02-03 00:33 - 2016-02-03 00:28 - 00003400 _____ C:\Users\georg\Documents\SEARCHFILTERHOST.EXE-77482212.pf
2016-02-03 00:33 - 2016-02-03 00:28 - 00003254 _____ C:\Users\georg\Documents\SEARCHPROTOCOLHOST.EXE-0CB8CADE.pf
2016-02-03 00:33 - 2016-02-03 00:25 - 00041449 _____ C:\Users\georg\Documents\DROPBOX.EXE-BC41F124.pf
2016-02-03 00:33 - 2016-02-03 00:25 - 00009571 _____ C:\Users\georg\Documents\WMIPRVSE.EXE-1628051C.pf
2016-02-03 00:33 - 2016-02-03 00:25 - 00006324 _____ C:\Users\georg\Documents\CMD.EXE-AC113AA8.pf
2016-02-03 00:33 - 2016-02-03 00:25 - 00006051 _____ C:\Users\georg\Documents\CONHOST.EXE-1F3E9D7E.pf
2016-02-03 00:33 - 2016-02-03 00:24 - 00017062 _____ C:\Users\georg\Documents\DROPBOXUPDATE.EXE-48534C67.pf
2016-02-03 00:33 - 2016-02-03 00:24 - 00010038 _____ C:\Users\georg\Documents\CHROME.EXE-D999B1BA.pf
2016-02-03 00:33 - 2016-02-03 00:24 - 00005951 _____ C:\Users\georg\Documents\DROPBOXCRASHHANDLER.EXE-AD4C6470.pf
2016-02-03 00:33 - 2016-02-03 00:24 - 00003985 _____ C:\Users\georg\Documents\TASKENG.EXE-48D4E289.pf
2016-02-03 00:33 - 2016-02-03 00:24 - 00003723 _____ C:\Users\georg\Documents\RUNDLL32.EXE-5A6C2401.pf
2016-02-03 00:33 - 2016-02-03 00:23 - 00059410 _____ C:\Users\georg\Documents\EXPLORER.EXE-A80E4F97.pf
2016-02-03 00:33 - 2016-02-03 00:23 - 00047342 _____ C:\Users\georg\Documents\SEARCHUI.EXE-14F7ADB7.pf
2016-02-03 00:33 - 2016-02-03 00:23 - 00025107 _____ C:\Users\georg\Documents\SHELLEXPERIENCEHOST.EXE-DEE26F81.pf
2016-02-03 00:33 - 2016-02-03 00:23 - 00017789 _____ C:\Users\georg\Documents\WERFAULT.EXE-E69F695A.pf
2016-02-03 00:33 - 2016-02-03 00:23 - 00010553 _____ C:\Users\georg\Documents\BACKGROUNDTASKHOST.EXE-D53C639B.pf
2016-02-03 00:33 - 2016-02-03 00:23 - 00004077 _____ C:\Users\georg\Documents\IGFXSRVC.EXE-96A493A4.pf
2016-02-03 00:33 - 2016-02-03 00:23 - 00003731 _____ C:\Users\georg\Documents\RUNDLL32.EXE-CF0EC82C.pf
2016-02-03 00:33 - 2016-02-03 00:21 - 00014720 _____ C:\Users\georg\Documents\WMIPRVSE.EXE-6768A320.pf
2016-02-03 00:33 - 2016-02-03 00:21 - 00001826 _____ C:\Users\georg\Documents\FONTDRVHOST.EXE-31E45F6D.pf
2016-02-03 00:33 - 2016-02-03 00:20 - 00028418 _____ C:\Users\georg\Documents\DROPBOX.EXE-99FCFB67.pf
2016-02-03 00:33 - 2016-02-03 00:20 - 00015960 _____ C:\Users\georg\Documents\DROPBOXCLIENT_3.12.6.EXE-D4B256BF.pf
2016-02-03 00:33 - 2016-02-03 00:20 - 00008083 _____ C:\Users\georg\Documents\NETSH.EXE-CD959116.pf
2016-02-03 00:33 - 2016-02-03 00:20 - 00006200 _____ C:\Users\georg\Documents\RUNDLL32.EXE-C39362D4.pf
2016-02-03 00:33 - 2016-02-03 00:20 - 00005334 _____ C:\Users\georg\Documents\REGSVR32.EXE-D5170E12.pf
2016-02-03 00:33 - 2016-02-03 00:20 - 00005002 _____ C:\Users\georg\Documents\REGSVR32.EXE-8461DBEE.pf
2016-02-03 00:33 - 2016-02-03 00:20 - 00004885 _____ C:\Users\georg\Documents\DLLHOST.EXE-A2CE8BA8.pf
2016-02-03 00:33 - 2016-02-03 00:20 - 00003151 _____ C:\Users\georg\Documents\DROPBOXUPDATEONDEMAND.EXE-79C877CA.pf
2016-02-03 00:33 - 2016-02-03 00:19 - 00014815 _____ C:\Users\georg\Documents\DROPBOXUPDATE.EXE-8A01BECE.pf
2016-02-03 00:33 - 2016-02-03 00:19 - 00012183 _____ C:\Users\georg\Documents\MSIEXEC.EXE-A2D55CB6.pf
2016-02-03 00:33 - 2016-02-03 00:19 - 00006470 _____ C:\Users\georg\Documents\DROPBOXINSTALLER.EXE-A34F7F3C.pf
2016-02-03 00:33 - 2016-02-03 00:09 - 00005150 _____ C:\Users\georg\Documents\AUDIODG.EXE-BDFD3029.pf
2016-02-03 00:33 - 2016-02-03 00:03 - 00023913 _____ C:\Users\georg\Documents\DLLHOST.EXE-BF839084.pf
2016-02-03 00:33 - 2016-02-02 23:56 - 00004281 _____ C:\Users\georg\Documents\DLLHOST.EXE-905A63CB.pf
2016-02-03 00:33 - 2016-02-02 23:55 - 00008303 _____ C:\Users\georg\Documents\NETWORKUXBROKER.EXE-52124E6C.pf
2016-02-03 00:33 - 2016-02-02 23:55 - 00006148 _____ C:\Users\georg\Documents\SYSTEMSETTINGSBROKER.EXE-CBC37DFF.pf
2016-02-03 00:33 - 2016-02-02 23:52 - 00008338 _____ C:\Users\georg\Documents\BACKGROUNDTRANSFERHOST.EXE-903D7CE5.pf
2016-02-03 00:33 - 2016-02-02 23:48 - 00064230 _____ C:\Users\georg\Documents\MICROSOFTEDGECP.EXE-D13977B7.pf
2016-02-03 00:33 - 2016-02-02 23:48 - 00051801 _____ C:\Users\georg\Documents\MICROSOFTEDGE.EXE-F8C789BA.pf
2016-02-03 00:33 - 2016-02-02 23:48 - 00006672 _____ C:\Users\georg\Documents\BROWSER_BROKER.EXE-E6357BB0.pf
2016-02-03 00:33 - 2016-02-02 23:35 - 00003902 _____ C:\Users\georg\Documents\DLLHOST.EXE-76936ED5.pf
2016-02-03 00:33 - 2016-02-02 23:21 - 00027803 _____ C:\Users\georg\Documents\RECUVA64.EXE-C16E44D4.pf
2016-02-03 00:33 - 2016-02-02 23:16 - 00023050 _____ C:\Users\georg\Documents\TASKHOSTW.EXE-3E0B74C8.pf
2016-02-03 00:33 - 2016-02-02 23:01 - 00043159 _____ C:\Users\georg\Documents\MICROSOFT.PHOTOS.EXE-C8DAAC51.pf
2016-02-03 00:33 - 2016-02-02 23:01 - 00022976 _____ C:\Users\georg\Documents\WINSTORE.MOBILE.EXE-D2DA8599.pf
2016-02-03 00:33 - 2016-02-02 23:01 - 00010400 _____ C:\Users\georg\Documents\APPLICATIONFRAMEHOST.EXE-CCEEF759.pf
2016-02-03 00:33 - 2016-02-02 23:01 - 00003767 _____ C:\Users\georg\Documents\WUAPIHOST.EXE-8C63377C.pf
2016-02-03 00:33 - 2016-02-02 23:00 - 00024965 _____ C:\Users\georg\Documents\LOGONUI.EXE-09140401.pf
2016-02-03 00:33 - 2016-02-02 23:00 - 00019385 _____ C:\Users\georg\Documents\LOCKAPP.EXE-78D857CD.pf
2016-02-03 00:33 - 2016-02-02 23:00 - 00012871 _____ C:\Users\georg\Documents\LOCKAPPHOST.EXE-CAAE23A8.pf
2016-02-03 00:33 - 2016-02-02 23:00 - 00006581 _____ C:\Users\georg\Documents\WNETWATCHER.EXE-B4E3D053.pf
2016-02-03 00:33 - 2016-02-02 23:00 - 00006537 _____ C:\Users\georg\Documents\WUL.EXE-50C1D57F.pf
2016-02-03 00:33 - 2016-02-02 23:00 - 00006291 _____ C:\Users\georg\Documents\WINSOCKSERVICESVIEW.EXE-856C8808.pf
2016-02-03 00:33 - 2016-02-02 23:00 - 00005982 _____ C:\Users\georg\Documents\WINLOGONVIEW.EXE-C2FBCD0F.pf
2016-02-03 00:33 - 2016-02-02 23:00 - 00005920 _____ C:\Users\georg\Documents\WIRELESSCONNECTIONINFO.EXE-48D9EDD9.pf
2016-02-03 00:33 - 2016-02-02 23:00 - 00005897 _____ C:\Users\georg\Documents\WIRELESSNETVIEW.EXE-A0DAEC7F.pf
2016-02-03 00:33 - 2016-02-02 23:00 - 00004373 _____ C:\Users\georg\Documents\WIRELESSNETCONSOLE.EXE-94A97D7F.pf
2016-02-03 00:33 - 2016-02-02 22:59 - 00013864 _____ C:\Users\georg\Documents\TASKSCHEDULERVIEW.EXE-D06D3AFE.pf
2016-02-03 00:33 - 2016-02-02 22:59 - 00009639 _____ C:\Users\georg\Documents\WHATINSTARTUP.EXE-031CBE83.pf
2016-02-03 00:33 - 2016-02-02 22:59 - 00008606 _____ C:\Users\georg\Documents\WHATISHANG.EXE-D9CEF39B.pf
2016-02-03 00:33 - 2016-02-02 22:59 - 00007332 _____ C:\Users\georg\Documents\TCPLOGVIEW.EXE-0E207561.pf
2016-02-03 00:33 - 2016-02-02 22:59 - 00006792 _____ C:\Users\georg\Documents\SKYPELOGVIEW.EXE-8BFAAADC.pf
2016-02-03 00:33 - 2016-02-02 22:59 - 00006115 _____ C:\Users\georg\Documents\SMSNIFF.EXE-B6B6906B.pf
2016-02-03 00:33 - 2016-02-02 22:59 - 00005894 _____ C:\Users\georg\Documents\USERPROFILESVIEW.EXE-83316BAD.pf
2016-02-03 00:33 - 2016-02-02 22:59 - 00005722 _____ C:\Users\georg\Documents\USERASSISTVIEW.EXE-5AE032AC.pf
2016-02-03 00:33 - 2016-02-02 22:59 - 00005548 _____ C:\Users\georg\Documents\WIFICHANNELMONITOR.EXE-E47CDC2D.pf
2016-02-03 00:33 - 2016-02-02 22:58 - 00015338 _____ C:\Users\georg\Documents\SERVIWIN.EXE-2ACCAC58.pf
2016-02-03 00:33 - 2016-02-02 22:58 - 00015230 _____ C:\Users\georg\Documents\RECENTFILESVIEW.EXE-0F2E93E2.pf
2016-02-03 00:33 - 2016-02-02 22:58 - 00011877 _____ C:\Users\georg\Documents\PROCESSTHREADSVIEW.EXE-405AD70E.pf
2016-02-03 00:33 - 2016-02-02 22:58 - 00007872 _____ C:\Users\georg\Documents\SEARCHMYFILES.EXE-639EE850.pf
2016-02-03 00:33 - 2016-02-02 22:58 - 00006618 _____ C:\Users\georg\Documents\SIMPLEWMIVIEW.EXE-CE99BE69.pf
2016-02-03 00:33 - 2016-02-02 22:58 - 00005523 _____ C:\Users\georg\Documents\REGSCANNER.EXE-517DC61D.pf
2016-02-03 00:33 - 2016-02-02 22:57 - 00009369 _____ C:\Users\georg\Documents\NETWORKTRAFFICVIEW.EXE-470D3E11.pf
2016-02-03 00:33 - 2016-02-02 22:57 - 00009125 _____ C:\Users\georg\Documents\OPENSAVEFILESVIEW.EXE-950BB978.pf
2016-02-03 00:33 - 2016-02-02 22:57 - 00008207 _____ C:\Users\georg\Documents\OPENEDFILESVIEW.EXE-04EC8B3A.pf
2016-02-03 00:33 - 2016-02-02 22:57 - 00006407 _____ C:\Users\georg\Documents\NETWORKCONNECTLOG.EXE-9CFB0425.pf
2016-02-03 00:33 - 2016-02-02 22:57 - 00005751 _____ C:\Users\georg\Documents\NETWORKINTERFACESVIEW.EXE-ECC3AD72.pf
2016-02-03 00:33 - 2016-02-02 22:57 - 00005201 _____ C:\Users\georg\Documents\DLLHOST.EXE-F2DCEF0D.pf
2016-02-03 00:33 - 2016-02-02 22:56 - 00009708 _____ C:\Users\georg\Documents\RUNDLL32.EXE-F189B835.pf
2016-02-03 00:32 - 2016-02-02 23:06 - 00000000 ____D C:\Users\georg\Documents\MRT
2016-02-03 00:32 - 2016-02-02 20:29 - 00000000 _____ C:\Users\georg\Documents\FXSTIFFDebugLogFile.txt
2016-02-03 00:32 - 2016-02-02 20:29 - 00000000 _____ C:\Users\georg\Documents\FXSAPIDebugLogFile.txt
2016-02-03 00:32 - 2016-02-01 17:37 - 00000000 ____D C:\Users\georg\Documents\MPInstrumentation
2016-02-03 00:31 - 2016-01-29 17:26 - 00164220 _____ C:\Users\georg\Documents\012916-6312-01.dmp
2016-02-03 00:31 - 2016-01-19 15:19 - 00262028 _____ C:\Users\georg\Documents\011916-8031-01.dmp
2016-02-03 00:27 - 2016-02-04 13:06 - 00000000 ___RD C:\Users\georg\Dropbox
2016-02-03 00:24 - 2016-02-03 00:24 - 00000000 ____D C:\Users\georg\Documents\WIA
2016-02-03 00:23 - 2016-02-03 00:23 - 00000000 ____D C:\Panther
2016-02-03 00:22 - 2016-02-03 00:22 - 00000000 ____D C:\Users\Paige Perry\Documents\WindowsBackup
2016-02-03 00:22 - 2016-02-03 00:22 - 00000000 ____D C:\Users\Paige Perry\Documents\SystemRestore
2016-02-03 00:22 - 2016-02-03 00:22 - 00000000 ____D C:\Users\georg\Documents\WindowsBackup
2016-02-03 00:22 - 2016-02-03 00:22 - 00000000 ____D C:\Users\georg\Documents\SystemRestore
2016-02-03 00:22 - 2015-10-30 02:24 - 00000000 ____D C:\Users\Paige Perry\Documents\Telephony
2016-02-03 00:22 - 2015-10-30 02:24 - 00000000 ____D C:\Users\Paige Perry\Documents\HomeGroup
2016-02-03 00:22 - 2015-10-30 02:24 - 00000000 ____D C:\Users\georg\Documents\Telephony
2016-02-03 00:22 - 2015-10-30 02:24 - 00000000 ____D C:\Users\georg\Documents\HomeGroup
2016-02-03 00:21 - 2016-02-03 00:22 - 00000000 ____D C:\Users\Paige Perry\Documents\DPX
2016-02-03 00:21 - 2016-02-03 00:21 - 00000000 ____D C:\Users\Paige Perry\Documents\WindowsUpdate
2016-02-03 00:21 - 2016-02-03 00:21 - 00000000 ____D C:\Users\Paige Perry\Documents\SIH
2016-02-03 00:21 - 2016-02-03 00:21 - 00000000 ____D C:\Users\Paige Perry\Documents\SetupCleanupTask
2016-02-03 00:21 - 2016-02-03 00:21 - 00000000 ____D C:\Users\Paige Perry\Documents\NetSetup
2016-02-03 00:21 - 2016-02-03 00:21 - 00000000 ____D C:\Users\Paige Perry\Documents\MoSetup
2016-02-03 00:21 - 2016-02-03 00:21 - 00000000 ____D C:\Users\Paige Perry\Documents\dosvc
2016-02-03 00:21 - 2016-02-03 00:21 - 00000000 ____D C:\Users\Paige Perry\Documents\DISM
2016-02-03 00:21 - 2016-02-03 00:21 - 00000000 ____D C:\Users\Paige Perry\Documents\CBS
2016-02-03 00:21 - 2015-10-30 02:24 - 00000000 ___SD C:\Users\Paige Perry\Documents\MeasuredBoot
2016-02-03 00:21 - 2015-10-30 02:24 - 00000000 ____D C:\Users\Paige Perry\Documents\SettingSync
2016-02-03 00:20 - 2016-02-03 00:22 - 00000000 ____D C:\Users\georg\Documents\DPX
2016-02-03 00:20 - 2016-02-03 00:20 - 00000000 ____D C:\Users\georg\Documents\WindowsUpdate
2016-02-03 00:20 - 2016-02-03 00:20 - 00000000 ____D C:\Users\georg\Documents\SIH
2016-02-03 00:20 - 2016-02-03 00:20 - 00000000 ____D C:\Users\georg\Documents\SetupCleanupTask
2016-02-03 00:20 - 2016-02-03 00:20 - 00000000 ____D C:\Users\georg\Documents\NetSetup
2016-02-03 00:20 - 2016-02-03 00:20 - 00000000 ____D C:\Users\georg\Documents\MoSetup
2016-02-03 00:20 - 2016-02-03 00:20 - 00000000 ____D C:\Users\georg\Documents\dosvc
2016-02-03 00:20 - 2016-02-03 00:20 - 00000000 ____D C:\Users\georg\Documents\DISM
2016-02-03 00:20 - 2016-02-03 00:20 - 00000000 ____D C:\Users\georg\Documents\CBS
2016-02-03 00:20 - 2016-02-03 00:20 - 00000000 ____D C:\Users\georg\AppData\Roaming\Dropbox
2016-02-03 00:20 - 2015-10-30 02:24 - 00000000 ___SD C:\Users\georg\Documents\MeasuredBoot
2016-02-03 00:20 - 2015-10-30 02:24 - 00000000 ____D C:\Users\georg\Documents\SettingSync
2016-02-03 00:19 - 2016-02-05 12:25 - 00000000 ____D C:\Program Files (x86)\Dropbox
2016-02-03 00:19 - 2016-02-05 12:08 - 00000000 ____D C:\Users\georg\AppData\Local\Dropbox
2016-02-03 00:19 - 2016-02-03 00:19 - 00000000 ____D C:\ProgramData\Dropbox
2016-02-03 00:18 - 2016-02-03 00:19 - 00690072 _____ (Dropbox, Inc.) C:\Users\georg\Downloads\DropboxInstaller.exe
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\wsearchidxpi
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\WmiApRpl
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\Windows Workflow Foundation 4.0.0.0
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\Windows Workflow Foundation 3.0.0.0
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\usbhub
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\UGTHRSVC
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\UGatherer
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\TermService
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\TAPISRV
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\SMSvcHost 4.0.0.0
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\SMSvcHost 3.0.0.0
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\ServiceModelService 3.0.0.0
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\ServiceModelOperation 3.0.0.0
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\ServiceModelEndpoint 3.0.0.0
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\RemoteAccess
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\rdyboost
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\PNRPSvc
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\PERFLIB
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\MSDTC Bridge 4.0.0.0
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\MSDTC Bridge 3.0.0.0
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\MSDTC
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\ESENT
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\BITS
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\.NETFramework
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\.NET Data Provider for SqlServer
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\.NET Data Provider for Oracle
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\.NET CLR Networking 4.0.0.0
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\.NET CLR Networking
2016-02-03 00:17 - 2016-02-03 00:17 - 00000000 ____D C:\Users\georg\Documents\.NET CLR Data
2016-02-03 00:17 - 2016-01-29 00:23 - 00020812 _____ C:\Users\georg\Documents\wpdmtp.PNF
2016-02-03 00:17 - 2016-01-28 15:25 - 00008004 _____ C:\Users\georg\Documents\oem5.PNF
2016-02-03 00:17 - 2016-01-28 15:20 - 00010096 _____ C:\Users\georg\Documents\nulhprs8.PNF
2016-02-03 00:17 - 2016-01-28 15:19 - 00025548 _____ C:\Users\georg\Documents\wiahp008.PNF
2016-02-03 00:17 - 2016-01-28 09:07 - 00009696 _____ C:\Users\georg\Documents\usbser.PNF
2016-02-03 00:17 - 2016-01-28 09:07 - 00007404 _____ C:\Users\georg\Documents\netpacer.PNF
2016-02-03 00:17 - 2016-01-28 09:07 - 00006744 _____ C:\Users\georg\Documents\wnetvsc_vfpp.PNF
2016-02-03 00:17 - 2016-01-28 09:07 - 00006152 _____ C:\Users\georg\Documents\netvwififlt.PNF
2016-02-03 00:17 - 2016-01-28 09:07 - 00006092 _____ C:\Users\georg\Documents\ndiscap.PNF
2016-02-03 00:17 - 2016-01-28 09:07 - 00006088 _____ C:\Users\georg\Documents\netnwifi.PNF
2016-02-03 00:17 - 2016-01-28 09:07 - 00005464 _____ C:\Users\georg\Documents\netbrdg.PNF
2016-02-03 00:17 - 2016-01-28 09:07 - 00005300 _____ C:\Users\georg\Documents\Netserv.PNF
2016-02-03 00:17 - 2016-01-28 09:07 - 00005248 _____ C:\Users\georg\Documents\netnb.PNF
2016-02-03 00:17 - 2016-01-28 09:07 - 00005248 _____ C:\Users\georg\Documents\Netmscli.PNF
2016-02-03 00:17 - 2016-01-28 09:07 - 00005184 _____ C:\Users\georg\Documents\ndisuio.PNF
2016-02-03 00:17 - 2016-01-22 10:27 - 00010444 _____ C:\Users\georg\Documents\capimg.PNF
2016-02-03 00:17 - 2016-01-22 10:27 - 00009400 _____ C:\Users\georg\Documents\sdstor.PNF
2016-02-03 00:17 - 2016-01-22 09:21 - 00022312 _____ C:\Users\georg\Documents\netrasa.PNF
2016-02-03 00:17 - 2016-01-22 09:21 - 00006696 _____ C:\Users\georg\Documents\netsstpa.PNF
2016-02-03 00:17 - 2016-01-22 08:24 - 00014100 _____ C:\Users\georg\Documents\oem10.PNF
2016-02-03 00:17 - 2016-01-22 08:24 - 00008508 _____ C:\Users\georg\Documents\WpdFs.PNF
2016-02-03 00:17 - 2016-01-22 04:07 - 00020620 _____ C:\Users\georg\Documents\sti.PNF
2016-02-03 00:17 - 2016-01-20 13:10 - 00058716 _____ C:\Users\georg\Documents\prnhpcl1.PNF
2016-02-03 00:17 - 2016-01-20 12:38 - 00025864 _____ C:\Users\georg\Documents\wdmaudio.PNF
2016-02-03 00:17 - 2016-01-19 11:28 - 00019316 _____ C:\Users\georg\Documents\hidserv.PNF
2016-02-03 00:17 - 2016-01-19 11:28 - 00013724 _____ C:\Users\georg\Documents\miradisp.PNF
2016-02-03 00:17 - 2016-01-19 11:28 - 00012460 _____ C:\Users\georg\Documents\dc1-controller.PNF
2016-02-03 00:17 - 2016-01-19 11:28 - 00009640 _____ C:\Users\georg\Documents\ramdisk.PNF
2016-02-03 00:17 - 2016-01-19 11:28 - 00009384 _____ C:\Users\georg\Documents\xusb22.PNF
2016-02-03 00:17 - 2016-01-19 11:28 - 00008972 _____ C:\Users\georg\Documents\ts_generic.PNF
2016-02-03 00:17 - 2016-01-19 11:28 - 00008268 _____ C:\Users\georg\Documents\remoteposdrv.PNF
2016-02-03 00:17 - 2016-01-19 11:28 - 00008152 _____ C:\Users\georg\Documents\rawsilo.PNF
2016-02-03 00:17 - 2016-01-19 11:28 - 00008092 _____ C:\Users\georg\Documents\wsdprint.PNF
2016-02-03 00:17 - 2016-01-19 11:28 - 00007572 _____ C:\Users\georg\Documents\digitalmediadevice.PNF
2016-02-03 00:17 - 2016-01-19 11:28 - 00007532 _____ C:\Users\georg\Documents\c_firmware.PNF
2016-02-03 00:17 - 2016-01-19 11:28 - 00007184 _____ C:\Users\georg\Documents\basicrender.PNF
2016-02-03 00:17 - 2016-01-19 11:28 - 00006804 _____ C:\Users\georg\Documents\c_swdevice.PNF
2016-02-03 00:17 - 2016-01-19 11:28 - 00006804 _____ C:\Users\georg\Documents\c_monitor.PNF
2016-02-03 00:17 - 2016-01-19 11:28 - 00006228 _____ C:\Users\georg\Documents\ndisvirtualbus.PNF
2016-02-03 00:17 - 2016-01-19 11:28 - 00005308 _____ C:\Users\georg\Documents\c_processor.PNF
2016-02-03 00:17 - 2016-01-19 11:28 - 00005292 _____ C:\Users\georg\Documents\c_proximity.PNF
2016-02-03 00:17 - 2016-01-19 11:28 - 00005132 _____ C:\Users\georg\Documents\hal.PNF
2016-02-03 00:17 - 2016-01-19 11:28 - 00004428 _____ C:\Users\georg\Documents\c_extension.PNF
2016-02-03 00:17 - 2016-01-19 11:28 - 00004360 _____ C:\Users\georg\Documents\c_sslaccel.PNF
2016-02-03 00:17 - 2016-01-19 11:28 - 00003932 _____ C:\Users\georg\Documents\c_barcodescanner.PNF
2016-02-03 00:17 - 2016-01-19 11:28 - 00003924 _____ C:\Users\georg\Documents\c_cashdrawer.PNF
2016-02-03 00:17 - 2016-01-19 11:28 - 00003908 _____ C:\Users\georg\Documents\c_magneticstripereader.PNF
2016-02-03 00:17 - 2016-01-19 11:28 - 00003900 _____ C:\Users\georg\Documents\c_receiptprinter.PNF
2016-02-03 00:17 - 2016-01-19 10:47 - 00129276 _____ C:\Users\georg\Documents\ks.PNF
2016-02-03 00:17 - 2016-01-19 10:47 - 00097160 _____ C:\Users\georg\Documents\wdma_usb.PNF
2016-02-03 00:17 - 2016-01-19 04:49 - 00005112 _____ C:\Users\georg\Documents\volsnap.PNF
2016-02-03 00:17 - 2016-01-19 03:14 - 00013976 _____ C:\Users\georg\Documents\nettun.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00227808 _____ C:\Users\georg\Documents\netevbda.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00064456 _____ C:\Users\georg\Documents\mlx4_bus.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00063176 _____ C:\Users\georg\Documents\arcsas.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00062772 _____ C:\Users\georg\Documents\mdmbtmdm.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00060004 _____ C:\Users\georg\Documents\usbcir.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00057756 _____ C:\Users\georg\Documents\usbstor.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00034336 _____ C:\Users\georg\Documents\hidir.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00020660 _____ C:\Users\georg\Documents\circlass.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00018792 _____ C:\Users\georg\Documents\1394.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00017644 _____ C:\Users\georg\Documents\iaLPSS2i_I2C_SKL.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00016300 _____ C:\Users\georg\Documents\agp.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00016180 _____ C:\Users\georg\Documents\iastorv.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00015260 _____ C:\Users\georg\Documents\stornvme.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00014424 _____ C:\Users\georg\Documents\storufs.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00013212 _____ C:\Users\georg\Documents\tpm.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00013196 _____ C:\Users\georg\Documents\ialpssi_i2c.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00012596 _____ C:\Users\georg\Documents\netbvbda.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00012276 _____ C:\Users\georg\Documents\bthhfenum.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00012196 _____ C:\Users\georg\Documents\ialpssi_gpio.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00012068 _____ C:\Users\georg\Documents\iastorav.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00011708 _____ C:\Users\georg\Documents\msgpiowin32.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00011000 _____ C:\Users\georg\Documents\iscsi.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00010592 _____ C:\Users\georg\Documents\vstxraid.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00009952 _____ C:\Users\georg\Documents\hidbth.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00009880 _____ C:\Users\georg\Documents\bthaudhid.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00009660 _____ C:\Users\georg\Documents\flpydisk.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00009636 _____ C:\Users\georg\Documents\cmbatt.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00009496 _____ C:\Users\georg\Documents\hidinterrupt.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00009264 _____ C:\Users\georg\Documents\hidi2c.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00008996 _____ C:\Users\georg\Documents\winusb.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00008628 _____ C:\Users\georg\Documents\errdev.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00008548 _____ C:\Users\georg\Documents\xinputhid.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00008540 _____ C:\Users\georg\Documents\wvpci.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00008504 _____ C:\Users\georg\Documents\ufxsynopsys.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00008496 _____ C:\Users\georg\Documents\uefi.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00008416 _____ C:\Users\georg\Documents\hiddigi.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00008404 _____ C:\Users\georg\Documents\tsgenericusbdriver.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00008136 _____ C:\Users\georg\Documents\wvmbus.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00008116 _____ C:\Users\georg\Documents\uaspstor.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00008024 _____ C:\Users\georg\Documents\WindowsTrustedRTProxy.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00007964 _____ C:\Users\georg\Documents\ufxchipidea.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00007880 _____ C:\Users\georg\Documents\buttonconverter.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00007780 _____ C:\Users\georg\Documents\iai2c.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00007776 _____ C:\Users\georg\Documents\wstorflt.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00007760 _____ C:\Users\georg\Documents\ehstortcgdrv.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00007740 _____ C:\Users\georg\Documents\mtconfig.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00007688 _____ C:\Users\georg\Documents\npsvctrig.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00007572 _____ C:\Users\georg\Documents\sbp2.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00007568 _____ C:\Users\georg\Documents\genericusbfn.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00007436 _____ C:\Users\georg\Documents\acpitime.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00007344 _____ C:\Users\georg\Documents\hidbatt.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00007296 _____ C:\Users\georg\Documents\acpipmi.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00007280 _____ C:\Users\georg\Documents\termmou.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00007268 _____ C:\Users\georg\Documents\wgencounter.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00007208 _____ C:\Users\georg\Documents\usbprint.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00007152 _____ C:\Users\georg\Documents\intelpep.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00007108 _____ C:\Users\georg\Documents\bcmfn.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00006912 _____ C:\Users\georg\Documents\printqueue.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00006880 _____ C:\Users\georg\Documents\netavpna.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00006848 _____ C:\Users\georg\Documents\xboxgip.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00006812 _____ C:\Users\georg\Documents\acpipagr.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00006708 _____ C:\Users\georg\Documents\bcmfn2.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00006676 _____ C:\Users\georg\Documents\urssynopsys.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00006676 _____ C:\Users\georg\Documents\urschipidea.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00006244 _____ C:\Users\georg\Documents\umpass.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00006188 _____ C:\Users\georg\Documents\UcmUcsi.PNF
2016-02-03 00:17 - 2016-01-19 02:38 - 00006148 _____ C:\Users\georg\Documents\fdc.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 01148644 _____ C:\Users\georg\Documents\monitor.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00684388 _____ C:\Users\georg\Documents\rt640x64.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00165824 _____ C:\Users\georg\Documents\machine.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00140512 _____ C:\Users\georg\Documents\input.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00134156 _____ C:\Users\georg\Documents\usbport.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00111492 _____ C:\Users\georg\Documents\keyboard.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00096868 _____ C:\Users\georg\Documents\hdaudio.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00091632 _____ C:\Users\georg\Documents\msmouse.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00089208 _____ C:\Users\georg\Documents\netrtwlane_13.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00066452 _____ C:\Users\georg\Documents\usb.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00064560 _____ C:\Users\georg\Documents\mshdc.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00035880 _____ C:\Users\georg\Documents\msports.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00019056 _____ C:\Users\georg\Documents\cpu.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00018928 _____ C:\Users\georg\Documents\pci.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00018424 _____ C:\Users\georg\Documents\usbhub3.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00016576 _____ C:\Users\georg\Documents\disk.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00016208 _____ C:\Users\georg\Documents\ksfilter.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00011160 _____ C:\Users\georg\Documents\cdrom.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00010364 _____ C:\Users\georg\Documents\usbxhci.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00010284 _____ C:\Users\georg\Documents\acpi.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00009948 _____ C:\Users\georg\Documents\netvwifimp.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00009896 _____ C:\Users\georg\Documents\umbus.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00009784 _____ C:\Users\georg\Documents\hdaudbus.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00009152 _____ C:\Users\georg\Documents\kdnic.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00008620 _____ C:\Users\georg\Documents\wmiacpi.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00008396 _____ C:\Users\georg\Documents\volmgr.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00007760 _____ C:\Users\georg\Documents\mssmbios.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00007656 _____ C:\Users\georg\Documents\vdrvroot.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00007548 _____ C:\Users\georg\Documents\display.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00007544 _____ C:\Users\georg\Documents\swenum.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00007372 _____ C:\Users\georg\Documents\compositebus.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00007368 _____ C:\Users\georg\Documents\basicdisplay.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00007360 _____ C:\Users\georg\Documents\spaceport.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00006876 _____ C:\Users\georg\Documents\rdpbus.PNF
2016-02-03 00:17 - 2016-01-19 02:35 - 00006336 _____ C:\Users\georg\Documents\volume.PNF
2016-02-03 00:17 - 2016-01-19 00:20 - 00154812 _____ C:\Users\georg\Documents\oem4.PNF
2016-02-03 00:17 - 2016-01-19 00:18 - 00032420 _____ C:\Users\georg\Documents\oem3.PNF
2016-02-03 00:17 - 2016-01-19 00:18 - 00008816 _____ C:\Users\georg\Documents\oem2.PNF
2016-02-03 00:17 - 2016-01-19 00:14 - 00005960 _____ C:\Users\georg\Documents\audioendpoint.PNF
2016-02-03 00:05 - 2016-02-03 00:04 - 00004096 _____ C:\Users\Paige Perry\Documents\https_plus.google.com_0.localstorage
2016-02-03 00:05 - 2016-02-03 00:04 - 00004096 _____ C:\Users\georg\Documents\https_plus.google.com_0.localstorage
2016-02-03 00:05 - 2016-02-03 00:04 - 00000000 _____ C:\Users\Paige Perry\Documents\https_plus.google.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-03 00:04 - 00000000 _____ C:\Users\georg\Documents\https_plus.google.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-03 00:02 - 00110592 _____ C:\Users\Paige Perry\Documents\https_mail.google.com_0.localstorage
2016-02-03 00:05 - 2016-02-03 00:02 - 00110592 _____ C:\Users\georg\Documents\https_mail.google.com_0.localstorage
2016-02-03 00:05 - 2016-02-03 00:02 - 00000000 _____ C:\Users\Paige Perry\Documents\https_mail.google.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-03 00:02 - 00000000 _____ C:\Users\georg\Documents\https_mail.google.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 23:58 - 01332224 _____ C:\Users\Paige Perry\Documents\https_drive.google.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 23:58 - 01332224 _____ C:\Users\georg\Documents\https_drive.google.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 23:58 - 00016384 _____ C:\Users\Paige Perry\Documents\chrome-extension_chphlpgkkbolifaimnlloiipkdnihall_0.localstorage
2016-02-03 00:05 - 2016-02-02 23:58 - 00016384 _____ C:\Users\georg\Documents\chrome-extension_chphlpgkkbolifaimnlloiipkdnihall_0.localstorage
2016-02-03 00:05 - 2016-02-02 23:58 - 00008192 _____ C:\Users\Paige Perry\Documents\https_www.google.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 23:58 - 00008192 _____ C:\Users\georg\Documents\https_www.google.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 23:58 - 00007168 _____ C:\Users\Paige Perry\Documents\chrome-extension_pioclpoplcdbaefihamjohnefbikjilc_0.localstorage
2016-02-03 00:05 - 2016-02-02 23:58 - 00007168 _____ C:\Users\georg\Documents\chrome-extension_pioclpoplcdbaefihamjohnefbikjilc_0.localstorage
2016-02-03 00:05 - 2016-02-02 23:58 - 00000000 _____ C:\Users\Paige Perry\Documents\https_www.google.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 23:58 - 00000000 _____ C:\Users\Paige Perry\Documents\https_drive.google.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 23:58 - 00000000 _____ C:\Users\Paige Perry\Documents\chrome-extension_pioclpoplcdbaefihamjohnefbikjilc_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 23:58 - 00000000 _____ C:\Users\Paige Perry\Documents\chrome-extension_chphlpgkkbolifaimnlloiipkdnihall_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 23:58 - 00000000 _____ C:\Users\georg\Documents\https_www.google.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 23:58 - 00000000 _____ C:\Users\georg\Documents\https_drive.google.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 23:58 - 00000000 _____ C:\Users\georg\Documents\chrome-extension_pioclpoplcdbaefihamjohnefbikjilc_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 23:58 - 00000000 _____ C:\Users\georg\Documents\chrome-extension_chphlpgkkbolifaimnlloiipkdnihall_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 23:57 - 00003072 _____ C:\Users\Paige Perry\Documents\chrome-devtools_devtools_0.localstorage
2016-02-03 00:05 - 2016-02-02 23:57 - 00003072 _____ C:\Users\georg\Documents\chrome-devtools_devtools_0.localstorage
2016-02-03 00:05 - 2016-02-02 23:57 - 00000000 _____ C:\Users\Paige Perry\Documents\chrome-devtools_devtools_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 23:57 - 00000000 _____ C:\Users\georg\Documents\chrome-devtools_devtools_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:54 - 00003072 _____ C:\Users\Paige Perry\Documents\http_www.nirsoft.net_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:54 - 00003072 _____ C:\Users\georg\Documents\http_www.nirsoft.net_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:54 - 00000000 _____ C:\Users\Paige Perry\Documents\http_www.nirsoft.net_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:54 - 00000000 _____ C:\Users\georg\Documents\http_www.nirsoft.net_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:51 - 00003072 _____ C:\Users\Paige Perry\Documents\https_technet.microsoft.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:51 - 00003072 _____ C:\Users\Paige Perry\Documents\http_download.cnet.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:51 - 00003072 _____ C:\Users\georg\Documents\https_technet.microsoft.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:51 - 00003072 _____ C:\Users\georg\Documents\http_download.cnet.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:51 - 00000000 _____ C:\Users\Paige Perry\Documents\https_technet.microsoft.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:51 - 00000000 _____ C:\Users\Paige Perry\Documents\http_download.cnet.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:51 - 00000000 _____ C:\Users\georg\Documents\https_technet.microsoft.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:51 - 00000000 _____ C:\Users\georg\Documents\http_download.cnet.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:49 - 00005120 _____ C:\Users\Paige Perry\Documents\http_www.bleepingcomputer.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:49 - 00005120 _____ C:\Users\georg\Documents\http_www.bleepingcomputer.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:49 - 00000000 _____ C:\Users\Paige Perry\Documents\http_www.bleepingcomputer.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:49 - 00000000 _____ C:\Users\georg\Documents\http_www.bleepingcomputer.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:47 - 00003072 _____ C:\Users\Paige Perry\Documents\https_www.youtube.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:47 - 00003072 _____ C:\Users\georg\Documents\https_www.youtube.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:47 - 00000000 _____ C:\Users\Paige Perry\Documents\https_www.youtube.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:47 - 00000000 _____ C:\Users\georg\Documents\https_www.youtube.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:37 - 00003072 _____ C:\Users\Paige Perry\Documents\http_sourceforge.net_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:37 - 00003072 _____ C:\Users\georg\Documents\http_sourceforge.net_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:37 - 00000000 _____ C:\Users\Paige Perry\Documents\http_sourceforge.net_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:37 - 00000000 _____ C:\Users\georg\Documents\http_sourceforge.net_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:36 - 00007168 _____ C:\Users\Paige Perry\Documents\https_kb.acronis.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:36 - 00007168 _____ C:\Users\georg\Documents\https_kb.acronis.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:36 - 00004096 _____ C:\Users\Paige Perry\Documents\http_www.justanswer.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:36 - 00004096 _____ C:\Users\georg\Documents\http_www.justanswer.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:36 - 00000000 _____ C:\Users\Paige Perry\Documents\https_kb.acronis.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:36 - 00000000 _____ C:\Users\Paige Perry\Documents\http_www.justanswer.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:36 - 00000000 _____ C:\Users\georg\Documents\https_kb.acronis.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:36 - 00000000 _____ C:\Users\georg\Documents\http_www.justanswer.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:35 - 00036864 _____ C:\Users\Paige Perry\Documents\https_support.microsoft.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:35 - 00036864 _____ C:\Users\georg\Documents\https_support.microsoft.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:35 - 00005120 _____ C:\Users\Paige Perry\Documents\chrome-extension_boadgeojelhgndaghljhdicfkmllpafd_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:35 - 00005120 _____ C:\Users\georg\Documents\chrome-extension_boadgeojelhgndaghljhdicfkmllpafd_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:35 - 00004096 _____ C:\Users\Paige Perry\Documents\https_github.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:35 - 00004096 _____ C:\Users\georg\Documents\https_github.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:35 - 00003072 _____ C:\Users\Paige Perry\Documents\https_support.google.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:35 - 00003072 _____ C:\Users\Paige Perry\Documents\https_forums.techguy.org_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:35 - 00003072 _____ C:\Users\georg\Documents\https_support.google.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:35 - 00003072 _____ C:\Users\georg\Documents\https_forums.techguy.org_0.localstorage
2016-02-03 00:05 - 2016-02-02 22:35 - 00000000 _____ C:\Users\Paige Perry\Documents\https_support.microsoft.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:35 - 00000000 _____ C:\Users\Paige Perry\Documents\https_support.google.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:35 - 00000000 _____ C:\Users\Paige Perry\Documents\https_github.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:35 - 00000000 _____ C:\Users\Paige Perry\Documents\https_forums.techguy.org_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:35 - 00000000 _____ C:\Users\Paige Perry\Documents\chrome-extension_boadgeojelhgndaghljhdicfkmllpafd_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:35 - 00000000 _____ C:\Users\georg\Documents\https_support.microsoft.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:35 - 00000000 _____ C:\Users\georg\Documents\https_support.google.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:35 - 00000000 _____ C:\Users\georg\Documents\https_github.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:35 - 00000000 _____ C:\Users\georg\Documents\https_forums.techguy.org_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 22:35 - 00000000 _____ C:\Users\georg\Documents\chrome-extension_boadgeojelhgndaghljhdicfkmllpafd_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 20:59 - 00003072 _____ C:\Users\Paige Perry\Documents\http_stackoverflow.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 20:59 - 00003072 _____ C:\Users\georg\Documents\http_stackoverflow.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 20:59 - 00000000 _____ C:\Users\Paige Perry\Documents\http_stackoverflow.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 20:59 - 00000000 _____ C:\Users\georg\Documents\http_stackoverflow.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 20:33 - 00003072 _____ C:\Users\Paige Perry\Documents\https_docs.google.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 20:33 - 00003072 _____ C:\Users\georg\Documents\https_docs.google.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 20:33 - 00000000 _____ C:\Users\Paige Perry\Documents\https_docs.google.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 20:33 - 00000000 _____ C:\Users\georg\Documents\https_docs.google.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 20:24 - 00003072 _____ C:\Users\Paige Perry\Documents\http_launcher.nirsoft.net_0.localstorage
2016-02-03 00:05 - 2016-02-02 20:24 - 00003072 _____ C:\Users\georg\Documents\http_launcher.nirsoft.net_0.localstorage
2016-02-03 00:05 - 2016-02-02 20:24 - 00000000 _____ C:\Users\Paige Perry\Documents\http_launcher.nirsoft.net_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 20:24 - 00000000 _____ C:\Users\georg\Documents\http_launcher.nirsoft.net_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 20:00 - 00003072 _____ C:\Users\Paige Perry\Documents\https_superuser.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 20:00 - 00003072 _____ C:\Users\Paige Perry\Documents\http_superuser.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 20:00 - 00003072 _____ C:\Users\georg\Documents\https_superuser.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 20:00 - 00003072 _____ C:\Users\georg\Documents\http_superuser.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 20:00 - 00000000 _____ C:\Users\Paige Perry\Documents\https_superuser.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 20:00 - 00000000 _____ C:\Users\Paige Perry\Documents\http_superuser.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 20:00 - 00000000 _____ C:\Users\georg\Documents\https_superuser.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 20:00 - 00000000 _____ C:\Users\georg\Documents\http_superuser.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 19:35 - 00003072 _____ C:\Users\Paige Perry\Documents\https_play.google.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 19:35 - 00003072 _____ C:\Users\georg\Documents\https_play.google.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 19:35 - 00000000 _____ C:\Users\Paige Perry\Documents\https_play.google.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 19:35 - 00000000 _____ C:\Users\georg\Documents\https_play.google.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 19:13 - 00060416 _____ C:\Users\Paige Perry\Documents\http_listen.tidal.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 19:13 - 00060416 _____ C:\Users\georg\Documents\http_listen.tidal.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 19:13 - 00000000 _____ C:\Users\Paige Perry\Documents\http_listen.tidal.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 19:13 - 00000000 _____ C:\Users\georg\Documents\http_listen.tidal.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 19:11 - 01474560 _____ C:\Users\Paige Perry\Documents\https_en.wikipedia.org_0.localstorage
2016-02-03 00:05 - 2016-02-02 19:11 - 01474560 _____ C:\Users\georg\Documents\https_en.wikipedia.org_0.localstorage
2016-02-03 00:05 - 2016-02-02 19:11 - 00000000 _____ C:\Users\Paige Perry\Documents\https_en.wikipedia.org_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 19:11 - 00000000 _____ C:\Users\georg\Documents\https_en.wikipedia.org_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 19:01 - 00007168 _____ C:\Users\Paige Perry\Documents\https_soundcloud.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 19:01 - 00007168 _____ C:\Users\georg\Documents\https_soundcloud.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 19:01 - 00003072 _____ C:\Users\Paige Perry\Documents\https_www.reddit.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 19:01 - 00003072 _____ C:\Users\georg\Documents\https_www.reddit.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 19:01 - 00000000 _____ C:\Users\Paige Perry\Documents\https_www.reddit.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 19:01 - 00000000 _____ C:\Users\Paige Perry\Documents\https_soundcloud.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 19:01 - 00000000 _____ C:\Users\georg\Documents\https_www.reddit.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 19:01 - 00000000 _____ C:\Users\georg\Documents\https_soundcloud.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 18:58 - 00003072 _____ C:\Users\Paige Perry\Documents\https_w.soundcloud.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 18:58 - 00003072 _____ C:\Users\georg\Documents\https_w.soundcloud.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 18:58 - 00000000 _____ C:\Users\Paige Perry\Documents\https_w.soundcloud.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 18:58 - 00000000 _____ C:\Users\georg\Documents\https_w.soundcloud.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 17:48 - 00086016 _____ C:\Users\Paige Perry\Documents\chrome-extension_chlffgpmiacpedhhbkiomidkjlcfhogd_0.localstorage
2016-02-03 00:05 - 2016-02-02 17:48 - 00086016 _____ C:\Users\georg\Documents\chrome-extension_chlffgpmiacpedhhbkiomidkjlcfhogd_0.localstorage
2016-02-03 00:05 - 2016-02-02 17:48 - 00000000 _____ C:\Users\Paige Perry\Documents\chrome-extension_chlffgpmiacpedhhbkiomidkjlcfhogd_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 17:48 - 00000000 _____ C:\Users\georg\Documents\chrome-extension_chlffgpmiacpedhhbkiomidkjlcfhogd_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 17:02 - 00003072 _____ C:\Users\Paige Perry\Documents\https_www.psychologytoday.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 17:02 - 00003072 _____ C:\Users\georg\Documents\https_www.psychologytoday.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 17:02 - 00000000 _____ C:\Users\Paige Perry\Documents\https_www.psychologytoday.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 17:02 - 00000000 _____ C:\Users\georg\Documents\https_www.psychologytoday.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 16:26 - 00003072 _____ C:\Users\Paige Perry\Documents\http_answers.microsoft.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 16:26 - 00003072 _____ C:\Users\georg\Documents\http_answers.microsoft.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 16:26 - 00000000 _____ C:\Users\Paige Perry\Documents\http_answers.microsoft.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 16:26 - 00000000 _____ C:\Users\georg\Documents\http_answers.microsoft.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 15:54 - 00003072 _____ C:\Users\Paige Perry\Documents\https_chrome.google.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 15:54 - 00003072 _____ C:\Users\georg\Documents\https_chrome.google.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 15:54 - 00000000 _____ C:\Users\Paige Perry\Documents\https_chrome.google.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 15:54 - 00000000 _____ C:\Users\georg\Documents\https_chrome.google.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 15:40 - 00003072 _____ C:\Users\Paige Perry\Documents\http_www.cla5h.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 15:40 - 00003072 _____ C:\Users\georg\Documents\http_www.cla5h.com_0.localstorage
2016-02-03 00:05 - 2016-02-02 15:40 - 00000000 _____ C:\Users\Paige Perry\Documents\http_www.cla5h.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 15:40 - 00000000 _____ C:\Users\georg\Documents\http_www.cla5h.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 15:16 - 00004096 _____ C:\Users\Paige Perry\Documents\chrome-extension_nckgahadagoaajjgafhacjanaoiihapd_0.localstorage
2016-02-03 00:05 - 2016-02-02 15:16 - 00004096 _____ C:\Users\georg\Documents\chrome-extension_nckgahadagoaajjgafhacjanaoiihapd_0.localstorage
2016-02-03 00:05 - 2016-02-02 15:16 - 00000000 _____ C:\Users\Paige Perry\Documents\chrome-extension_nckgahadagoaajjgafhacjanaoiihapd_0.localstorage-journal
2016-02-03 00:05 - 2016-02-02 15:16 - 00000000 _____ C:\Users\georg\Documents\chrome-extension_nckgahadagoaajjgafhacjanaoiihapd_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 14:16 - 00012288 _____ C:\Users\Paige Perry\Documents\http_searchmobilecomputing.techtarget.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 14:16 - 00012288 _____ C:\Users\georg\Documents\http_searchmobilecomputing.techtarget.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 14:16 - 00003072 _____ C:\Users\Paige Perry\Documents\https_answers.microsoft.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 14:16 - 00003072 _____ C:\Users\georg\Documents\https_answers.microsoft.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 14:16 - 00000000 _____ C:\Users\Paige Perry\Documents\https_answers.microsoft.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 14:16 - 00000000 _____ C:\Users\Paige Perry\Documents\http_searchmobilecomputing.techtarget.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 14:16 - 00000000 _____ C:\Users\georg\Documents\https_answers.microsoft.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 14:16 - 00000000 _____ C:\Users\georg\Documents\http_searchmobilecomputing.techtarget.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 14:11 - 00065536 _____ C:\Users\Paige Perry\Documents\https_www.pushbullet.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 14:11 - 00065536 _____ C:\Users\georg\Documents\https_www.pushbullet.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 14:11 - 00009216 _____ C:\Users\Paige Perry\Documents\http_www.rapid7.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 14:11 - 00009216 _____ C:\Users\georg\Documents\http_www.rapid7.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 14:11 - 00000000 _____ C:\Users\Paige Perry\Documents\https_www.pushbullet.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 14:11 - 00000000 _____ C:\Users\Paige Perry\Documents\http_www.rapid7.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 14:11 - 00000000 _____ C:\Users\georg\Documents\https_www.pushbullet.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 14:11 - 00000000 _____ C:\Users\georg\Documents\http_www.rapid7.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 14:09 - 00003072 _____ C:\Users\Paige Perry\Documents\https_play.vidyard.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 14:09 - 00003072 _____ C:\Users\Paige Perry\Documents\https_information.rapid7.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 14:09 - 00003072 _____ C:\Users\Paige Perry\Documents\https_app-sjo.marketo.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 14:09 - 00003072 _____ C:\Users\Paige Perry\Documents\http_ct1.addthis.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 14:09 - 00003072 _____ C:\Users\georg\Documents\https_play.vidyard.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 14:09 - 00003072 _____ C:\Users\georg\Documents\https_information.rapid7.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 14:09 - 00003072 _____ C:\Users\georg\Documents\https_app-sjo.marketo.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 14:09 - 00003072 _____ C:\Users\georg\Documents\http_ct1.addthis.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 14:09 - 00000000 _____ C:\Users\Paige Perry\Documents\https_play.vidyard.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 14:09 - 00000000 _____ C:\Users\Paige Perry\Documents\https_information.rapid7.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 14:09 - 00000000 _____ C:\Users\Paige Perry\Documents\https_app-sjo.marketo.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 14:09 - 00000000 _____ C:\Users\Paige Perry\Documents\http_ct1.addthis.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 14:09 - 00000000 _____ C:\Users\georg\Documents\https_play.vidyard.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 14:09 - 00000000 _____ C:\Users\georg\Documents\https_information.rapid7.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 14:09 - 00000000 _____ C:\Users\georg\Documents\https_app-sjo.marketo.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 14:09 - 00000000 _____ C:\Users\georg\Documents\http_ct1.addthis.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 14:05 - 00003072 _____ C:\Users\Paige Perry\Documents\https_f.vimeocdn.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 14:05 - 00003072 _____ C:\Users\georg\Documents\https_f.vimeocdn.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 14:05 - 00000000 _____ C:\Users\Paige Perry\Documents\https_f.vimeocdn.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 14:05 - 00000000 _____ C:\Users\georg\Documents\https_f.vimeocdn.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 13:50 - 00003072 _____ C:\Users\Paige Perry\Documents\https_code.msdn.microsoft.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 13:50 - 00003072 _____ C:\Users\georg\Documents\https_code.msdn.microsoft.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 13:50 - 00000000 _____ C:\Users\Paige Perry\Documents\https_code.msdn.microsoft.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 13:50 - 00000000 _____ C:\Users\georg\Documents\https_code.msdn.microsoft.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 13:40 - 00013312 _____ C:\Users\Paige Perry\Documents\http_whatis.techtarget.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 13:40 - 00013312 _____ C:\Users\georg\Documents\http_whatis.techtarget.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 13:40 - 00000000 _____ C:\Users\Paige Perry\Documents\http_whatis.techtarget.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 13:40 - 00000000 _____ C:\Users\georg\Documents\http_whatis.techtarget.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 13:39 - 00003072 _____ C:\Users\Paige Perry\Documents\http_s7.addthis.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 13:39 - 00003072 _____ C:\Users\georg\Documents\http_s7.addthis.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 13:39 - 00000000 _____ C:\Users\Paige Perry\Documents\http_s7.addthis.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 13:39 - 00000000 _____ C:\Users\georg\Documents\http_s7.addthis.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 13:18 - 00003072 _____ C:\Users\Paige Perry\Documents\https_msdn.microsoft.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 13:18 - 00003072 _____ C:\Users\georg\Documents\https_msdn.microsoft.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 13:18 - 00000000 _____ C:\Users\Paige Perry\Documents\https_msdn.microsoft.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 13:18 - 00000000 _____ C:\Users\georg\Documents\https_msdn.microsoft.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 12:58 - 00003072 _____ C:\Users\Paige Perry\Documents\http_www.techsupportforum.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 12:58 - 00003072 _____ C:\Users\georg\Documents\http_www.techsupportforum.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 12:58 - 00000000 _____ C:\Users\Paige Perry\Documents\http_www.techsupportforum.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 12:58 - 00000000 _____ C:\Users\georg\Documents\http_www.techsupportforum.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 12:50 - 00003072 _____ C:\Users\Paige Perry\Documents\https_disqus.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 12:50 - 00003072 _____ C:\Users\Paige Perry\Documents\https_azure.microsoft.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 12:50 - 00003072 _____ C:\Users\georg\Documents\https_disqus.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 12:50 - 00003072 _____ C:\Users\georg\Documents\https_azure.microsoft.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 12:50 - 00000000 _____ C:\Users\Paige Perry\Documents\https_disqus.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 12:50 - 00000000 _____ C:\Users\Paige Perry\Documents\https_azure.microsoft.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 12:50 - 00000000 _____ C:\Users\georg\Documents\https_disqus.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 12:50 - 00000000 _____ C:\Users\georg\Documents\https_azure.microsoft.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 12:04 - 00003072 _____ C:\Users\Paige Perry\Documents\https_www.facebook.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 12:04 - 00003072 _____ C:\Users\georg\Documents\https_www.facebook.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 12:04 - 00000000 _____ C:\Users\Paige Perry\Documents\https_www.facebook.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 12:04 - 00000000 _____ C:\Users\georg\Documents\https_www.facebook.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 11:18 - 00003072 _____ C:\Users\Paige Perry\Documents\https_hangouts.google.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 11:18 - 00003072 _____ C:\Users\Paige Perry\Documents\chrome-extension_gceighgadbamgchioaofojlblndjcggh_0.localstorage
2016-02-03 00:05 - 2016-02-01 11:18 - 00003072 _____ C:\Users\Paige Perry\Documents\chrome-extension_eignhdfgaldabilaaegmdfbajngjmoke_0.localstorage
2016-02-03 00:05 - 2016-02-01 11:18 - 00003072 _____ C:\Users\georg\Documents\https_hangouts.google.com_0.localstorage
2016-02-03 00:05 - 2016-02-01 11:18 - 00003072 _____ C:\Users\georg\Documents\chrome-extension_gceighgadbamgchioaofojlblndjcggh_0.localstorage
2016-02-03 00:05 - 2016-02-01 11:18 - 00003072 _____ C:\Users\georg\Documents\chrome-extension_eignhdfgaldabilaaegmdfbajngjmoke_0.localstorage
2016-02-03 00:05 - 2016-02-01 11:18 - 00000000 _____ C:\Users\Paige Perry\Documents\https_hangouts.google.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 11:18 - 00000000 _____ C:\Users\Paige Perry\Documents\chrome-extension_gceighgadbamgchioaofojlblndjcggh_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 11:18 - 00000000 _____ C:\Users\Paige Perry\Documents\chrome-extension_eignhdfgaldabilaaegmdfbajngjmoke_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 11:18 - 00000000 _____ C:\Users\georg\Documents\https_hangouts.google.com_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 11:18 - 00000000 _____ C:\Users\georg\Documents\chrome-extension_gceighgadbamgchioaofojlblndjcggh_0.localstorage-journal
2016-02-03 00:05 - 2016-02-01 11:18 - 00000000 _____ C:\Users\georg\Documents\chrome-extension_eignhdfgaldabilaaegmdfbajngjmoke_0.localstorage-journal
2016-02-03 00:05 - 2016-01-31 14:32 - 00003072 _____ C:\Users\Paige Perry\Documents\https_help.evernote.com_0.localstorage
2016-02-03 00:05 - 2016-01-31 14:32 - 00003072 _____ C:\Users\Paige Perry\Documents\chrome-extension_mgijmajocgfcbeboacabfgobmjgjcoja_0.localstorage
2016-02-03 00:05 - 2016-01-31 14:32 - 00003072 _____ C:\Users\georg\Documents\https_help.evernote.com_0.localstorage
2016-02-03 00:05 - 2016-01-31 14:32 - 00003072 _____ C:\Users\georg\Documents\chrome-extension_mgijmajocgfcbeboacabfgobmjgjcoja_0.localstorage
2016-02-03 00:05 - 2016-01-31 14:32 - 00000000 _____ C:\Users\Paige Perry\Documents\https_help.evernote.com_0.localstorage-journal
2016-02-03 00:05 - 2016-01-31 14:32 - 00000000 _____ C:\Users\Paige Perry\Documents\chrome-extension_mgijmajocgfcbeboacabfgobmjgjcoja_0.localstorage-journal
2016-02-03 00:05 - 2016-01-31 14:32 - 00000000 _____ C:\Users\georg\Documents\https_help.evernote.com_0.localstorage-journal
2016-02-03 00:05 - 2016-01-31 14:32 - 00000000 _____ C:\Users\georg\Documents\chrome-extension_mgijmajocgfcbeboacabfgobmjgjcoja_0.localstorage-journal
2016-02-03 00:05 - 2016-01-31 14:27 - 00003072 _____ C:\Users\Paige Perry\Documents\http_www.windows10update.com_0.localstorage
2016-02-03 00:05 - 2016-01-31 14:27 - 00003072 _____ C:\Users\Paige Perry\Documents\http_disqus.com_0.localstorage
2016-02-03 00:05 - 2016-01-31 14:27 - 00003072 _____ C:\Users\georg\Documents\http_www.windows10update.com_0.localstorage
2016-02-03 00:05 - 2016-01-31 14:27 - 00003072 _____ C:\Users\georg\Documents\http_disqus.com_0.localstorage
2016-02-03 00:05 - 2016-01-31 14:27 - 00000000 _____ C:\Users\Paige Perry\Documents\http_www.windows10update.com_0.localstorage-journal
2016-02-03 00:05 - 2016-01-31 14:27 - 00000000 _____ C:\Users\Paige Perry\Documents\http_disqus.com_0.localstorage-journal
2016-02-03 00:05 - 2016-01-31 14:27 - 00000000 _____ C:\Users\georg\Documents\http_www.windows10update.com_0.localstorage-journal
2016-02-03 00:05 - 2016-01-31 14:27 - 00000000 _____ C:\Users\georg\Documents\http_disqus.com_0.localstorage-journal
2016-02-02 23:20 - 2016-02-02 23:20 - 00000002 _____ C:\Users\georg\Documents\whatishang.networktrafficview.txt
2016-02-02 22:51 - 2016-02-02 22:51 - 11895756 _____ (LopeSoft ) C:\Users\georg\Downloads\FileMenuTools-setup.exe
2016-02-02 22:50 - 2016-02-02 22:50 - 01250844 _____ C:\Users\georg\Downloads\ProcessExplorer.zip
2016-02-02 22:49 - 2016-02-02 22:49 - 00969845 _____ (ShadowExplorer.com ) C:\Users\georg\Downloads\ShadowExplorer-0.9-setup.exe
2016-02-02 22:49 - 2016-02-02 22:49 - 00969845 _____ (ShadowExplorer.com ) C:\Users\georg\Downloads\ShadowExplorer-0.9-setup (1).exe
2016-02-02 22:48 - 2016-02-03 01:22 - 01187840 _____ (Ruiware) C:\Users\georg\Downloads\wpsetup.exe
2016-02-02 22:48 - 2016-02-02 22:48 - 21771608 _____ (Tweaking.com) C:\Users\georg\Downloads\tweaking.com_windows_repair_aio_setup.exe
2016-02-02 22:48 - 2016-02-02 22:48 - 00688992 _____ (Swearware) C:\Users\georg\Downloads\dds (1).com
2016-02-02 22:44 - 2016-02-02 22:44 - 00001497 _____ C:\Users\georg\Desktop\SIWPortable - Shortcut.lnk
2016-02-02 22:43 - 2016-02-02 22:43 - 00000000 ____D C:\Program Files\SIWPortable
2016-02-02 22:40 - 2016-02-02 22:45 - 00000000 ____D C:\Users\georg\Downloads\nirsoft_package_1.19.71
2016-02-02 22:34 - 2016-02-05 13:29 - 00000000 ____D C:\Users\georg\AppData\Roaming\PFU
2016-02-02 20:48 - 2016-02-02 20:48 - 00000017 _____ C:\Users\georg\AppData\Local\resmon.resmoncfg
2016-02-02 20:24 - 2016-02-02 20:25 - 23049962 _____ C:\Users\georg\Downloads\nirsoft_package_1.19.71.zip
2016-02-02 19:22 - 2016-02-02 19:22 - 00000000 ____D C:\Users\georg\AppData\Local\NetworkTiles
2016-02-02 17:30 - 2016-02-05 12:17 - 00004160 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{A7E200CA-2543-42B9-9F97-FA9B7C68FCEF}
2016-02-02 17:28 - 2016-02-02 22:20 - 00000000 ____D C:\Users\georg\Desktop\recover
2016-02-02 17:24 - 2016-02-03 04:30 - 00000000 ____D C:\Users\georg\Downloads\security
2016-02-02 17:22 - 2016-02-03 01:32 - 00688992 ____R (Swearware) C:\Users\georg\Downloads\dds.com
2016-02-02 17:16 - 2016-02-02 17:16 - 00080156 _____ C:\Users\georg\Downloads\Extras.Txt
2016-02-02 16:05 - 2016-02-02 16:05 - 01665568 _____ ( ) C:\Users\georg\Downloads\cpu-z_1.75-en.exe
2016-02-02 16:05 - 2016-02-02 16:05 - 00000914 _____ C:\Users\Public\Desktop\CPUID CPU-Z.lnk
2016-02-02 16:05 - 2016-02-02 16:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
2016-02-02 16:05 - 2016-02-02 16:05 - 00000000 ____D C:\Program Files\CPUID
2016-02-02 15:28 - 2000-08-19 12:32 - 00032768 _____ (PFU) C:\Windows\SysWOW64\chksti.dll
2016-02-02 15:28 - 1999-09-18 13:22 - 00035328 _____ (PFU) C:\Windows\SysWOW64\pfdvmn.dll
2016-02-02 15:28 - 1999-07-07 17:40 - 00031232 _____ (PFU) C:\Windows\SysWOW64\pfusti.dll
2016-02-02 15:27 - 2016-02-02 15:27 - 00000942 _____ C:\Users\Public\Desktop\CardMinder.lnk
2016-02-02 15:27 - 2016-02-02 15:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CardMinder
2016-02-02 15:27 - 2003-12-16 19:16 - 00393216 _____ (PFU Limited.) C:\Windows\SysWOW64\PFUP60.dll
2016-02-02 15:27 - 2003-12-16 19:16 - 00249856 _____ (PFU Limited.) C:\Windows\SysWOW64\PFURT.dll
2016-02-02 15:27 - 2003-12-16 19:16 - 00069632 _____ (PFU Limited.) C:\Windows\SysWOW64\PFUIRT.dll
2016-02-02 15:26 - 2016-02-02 15:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ABBYY FineReader for ScanSnap ™ 5.0
2016-02-02 15:26 - 2016-02-02 15:26 - 00000000 ____D C:\ProgramData\ABBYY
2016-02-02 15:26 - 2016-02-02 15:26 - 00000000 ____D C:\Program Files (x86)\ABBYY FineReader for ScanSnap
2016-02-02 15:25 - 2016-02-02 15:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ScanSnap Online Update
2016-02-02 15:25 - 2016-02-02 15:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ScanSnap Manuals
2016-02-02 15:22 - 2016-02-02 15:22 - 00000000 ____D C:\Program Files (x86)\PFU
2016-02-02 15:22 - 2013-06-14 17:16 - 01453056 _____ (PFU LIMITED) C:\Windows\system32\SV600u-x64.dll
2016-02-02 15:22 - 2012-12-07 17:03 - 07983104 _____ (PFU LIMITED) C:\Windows\system32\ippiSV600-x64.dll
2016-02-02 15:22 - 2012-12-07 16:44 - 00901120 _____ (PFU LIMITED) C:\Windows\system32\ijlSV600-x64.dll
2016-02-02 15:22 - 2012-04-24 15:02 - 00031744 _____ (PFU) C:\Windows\system32\fj25usb-x64.dll
2016-02-02 15:22 - 2012-02-06 16:15 - 01065472 _____ (PFU LIMITED) C:\Windows\system32\s1300iu-x64.dll
2016-02-02 15:22 - 2010-08-03 18:55 - 00623104 _____ (PFU Limited) C:\Windows\system32\s1100u-x64.dll
2016-02-02 15:22 - 2010-07-23 12:50 - 03073024 _____ (PFU Limited) C:\Windows\system32\ijl5s1100-x64.dll
2016-02-02 15:22 - 2010-07-20 21:18 - 03073024 _____ (PFU Limited) C:\Windows\system32\ijl5s1300i-x64.dll
2016-02-02 15:22 - 2010-07-12 16:55 - 02467328 _____ (PFU Limited) C:\Windows\system32\ippi5s1100-x64.dll
2016-02-02 15:22 - 2010-02-04 02:44 - 02467328 _____ (PFU Limited) C:\Windows\system32\ippi5s1300i-x64.dll
2016-02-02 15:22 - 2009-09-18 22:01 - 00367616 _____ (PFU Limited) C:\Windows\system32\s1300u-x64.dll
2016-02-02 15:22 - 2009-04-23 20:29 - 02873856 _____ (PFU Limited) C:\Windows\system32\ijl5s1300-x64.dll
2016-02-02 15:22 - 2009-04-23 20:29 - 00695296 _____ (PFU Limited) C:\Windows\system32\ippi5s1300-x64.dll
2016-02-02 15:22 - 2008-04-03 08:08 - 00033280 _____ (PFU) C:\Windows\system32\fj52usb-x64.dll
2016-02-02 15:22 - 2007-08-17 16:33 - 00033280 _____ (PFU) C:\Windows\system32\fjmcusb-x64.dll
2016-02-02 15:22 - 2007-07-26 22:47 - 00351744 _____ (PFU Limited) C:\Windows\system32\s300u-x64.dll
2016-02-02 15:22 - 2007-05-23 19:57 - 02873856 _____ (PFU Limited) C:\Windows\system32\ijl5s300-x64.dll
2016-02-02 15:22 - 2007-05-23 19:57 - 00695296 _____ (PFU Limited) C:\Windows\system32\ippi5s300-x64.dll
2016-02-02 15:17 - 2016-02-05 12:08 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-02-02 13:14 - 2016-02-02 13:14 - 00196608 _____ C:\Users\Paige Perry\Documents\DITel-Merge.etl.converted.to..txt
2016-02-02 13:12 - 2016-02-02 13:12 - 00000000 _____ C:\Users\Paige Perry\Desktop\New Text Document (2).txt
2016-02-02 12:06 - 2016-02-05 12:08 - 00000000 ____D C:\Users\Paige Perry\Documents\ScanSnap IX500 Software
2016-02-01 19:21 - 2016-02-01 19:21 - 00008120 _____ C:\Users\Paige Perry\Desktop\microsoft tech support call.txt
2016-02-01 19:19 - 2016-02-01 19:19 - 00008120 _____ C:\Users\Paige Perry\Desktop\New Text Document.txt
2016-02-01 18:21 - 2016-02-01 18:21 - 00000000 ____D C:\copied documents
2016-02-01 17:20 - 2016-02-05 02:00 - 00000548 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 66596604-3010-4c22-8755-f4c8bbf2707f.job
2016-02-01 17:20 - 2016-02-05 01:20 - 00000548 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 9e2d0668-520e-4158-89e8-2ccd9f15a27b.job
2016-02-01 17:20 - 2016-02-01 17:20 - 00003794 _____ C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 66596604-3010-4c22-8755-f4c8bbf2707f
2016-02-01 17:20 - 2016-02-01 17:20 - 00003712 _____ C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 9e2d0668-520e-4158-89e8-2ccd9f15a27b
2016-02-01 17:20 - 2016-02-01 17:20 - 00001849 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2016-02-01 17:20 - 2016-02-01 17:20 - 00000000 ____D C:\Users\Paige Perry\AppData\Roaming\SUPERAntiSpyware.com
2016-02-01 17:20 - 2016-02-01 17:20 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2016-02-01 17:20 - 2016-02-01 17:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2016-02-01 17:20 - 2016-02-01 17:20 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2016-02-01 16:59 - 2016-02-05 15:43 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-02-01 16:59 - 2016-02-01 16:59 - 00001171 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-02-01 16:59 - 2016-02-01 16:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-02-01 16:59 - 2016-02-01 16:59 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-02-01 16:59 - 2016-02-01 16:59 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-02-01 16:59 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-02-01 16:59 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-02-01 16:59 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-02-01 16:39 - 2016-02-01 16:39 - 01593384 _____ (LogMeIn, Inc.) C:\Users\Paige Perry\Documents\Support-LogMeInRescue.exe
2016-02-01 16:39 - 2016-02-01 16:39 - 00002308 _____ C:\Users\Paige Perry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Support (2).lnk
2016-02-01 14:27 - 2016-02-01 14:27 - 00196608 _____ C:\Users\Paige Perry\DlTel-Merge sav3.etl
2016-02-01 14:17 - 2016-02-01 14:17 - 00000000 ___RD C:\Screenshots
2016-02-01 14:16 - 2016-02-01 14:16 - 00028260 _____ C:\Users\georg\MTB.txt
2016-02-01 13:46 - 2016-02-01 13:46 - 00000950 _____ C:\Users\georg\Desktop\Find and Mount.lnk
2016-02-01 13:46 - 2016-02-01 13:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Find and Mount
2016-02-01 13:46 - 2016-02-01 13:46 - 00000000 ____D C:\Program Files\A-FF Find and Mount
2016-02-01 13:32 - 2016-02-01 13:32 - 00028260 _____ C:\Users\georg\Downloads\MTB.txt
2016-02-01 13:06 - 2016-02-01 13:06 - 00069879 _____ C:\Users\georg\Downloads\ddwrt_drop_win_excerpt_ac.txt
2016-02-01 12:06 - 2016-02-01 12:08 - 00001908 _____ C:\Windows\diagwrn.xml
2016-02-01 12:06 - 2016-02-01 12:08 - 00001908 _____ C:\Windows\diagerr.xml
2016-02-01 12:06 - 2016-02-01 12:08 - 00000000 ___HD C:\$WINDOWS.~BT
2016-01-31 20:56 - 2016-02-05 16:01 - 00000958 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1311319171-3916018615-375967268-1001UA.job
2016-01-31 20:56 - 2016-02-04 21:01 - 00000906 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1311319171-3916018615-375967268-1001Core.job
2016-01-31 20:56 - 2016-01-31 20:56 - 00987728 _____ (Google Inc.) C:\Users\Paige Perry\Documents\chromecastinstaller.exe
2016-01-31 20:56 - 2016-01-31 20:56 - 00004086 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1311319171-3916018615-375967268-1001UA
2016-01-31 20:56 - 2016-01-31 20:56 - 00003710 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1311319171-3916018615-375967268-1001Core
2016-01-31 20:56 - 2016-01-31 20:56 - 00001301 _____ C:\Users\Paige Perry\Desktop\Chromecast.lnk
2016-01-31 20:56 - 2016-01-31 20:56 - 00000000 ____D C:\Users\Paige Perry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chromecast
2016-01-31 20:32 - 2016-01-31 20:32 - 00000000 ____D C:\Users\Paige Perry\Documents\sheryl stuff
2016-01-31 20:31 - 2016-01-31 20:33 - 00000000 ____D C:\Users\Paige Perry\Documents\memes
2016-01-31 19:41 - 2016-01-31 19:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
2016-01-31 19:41 - 2016-01-31 19:41 - 00000000 ____D C:\Program Files\HitmanPro
2016-01-31 19:40 - 2016-01-31 19:48 - 00000000 ____D C:\ProgramData\HitmanPro
2016-01-31 19:38 - 2016-01-31 19:40 - 11323704 _____ (SurfRight B.V.) C:\Users\Paige Perry\Documents\HitmanPro_x64.exe
2016-01-31 19:38 - 2016-01-31 19:39 - 11323704 _____ (SurfRight B.V.) C:\Users\Paige Perry\Downloads\ACCF.tmp
2016-01-31 19:26 - 2016-02-02 09:20 - 00000000 ____D C:\Users\Paige Perry\AppData\Local\LogMeIn Rescue Applet
2016-01-31 19:26 - 2016-01-31 19:26 - 01593384 _____ (LogMeIn, Inc.) C:\Users\Paige Perry\Downloads\Support-LogMeInRescue.exe
2016-01-31 19:26 - 2016-01-31 19:26 - 00002308 _____ C:\Users\Paige Perry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Support.lnk
2016-01-31 15:26 - 2016-02-04 14:59 - 00000000 ____D C:\Users\Paige Perry\Downloads\Installers
2016-01-31 15:25 - 2016-01-31 15:30 - 00000000 ____D C:\Users\Paige Perry\Downloads\Important
2016-01-31 15:24 - 2016-01-31 15:25 - 00000000 ____D C:\Users\Paige Perry\Downloads\Wilco
2016-01-31 15:12 - 2016-01-31 15:12 - 00000000 ____D C:\Temp
2016-01-31 15:11 - 2016-01-31 15:12 - 00000000 ____D C:\Users\Paige Perry\Documents\20080123115019703_SH-S203N_SB01
2016-01-31 15:11 - 2016-01-31 15:11 - 01032426 _____ C:\Users\Paige Perry\Documents\20080123115019703_SH-S203N_SB01.zip
2016-01-31 15:11 - 2016-01-31 15:11 - 01032426 _____ C:\Users\Paige Perry\Documents\20080123115019703_SH-S203N_SB01 (1).zip
2016-01-31 14:34 - 2016-01-31 14:36 - 96369872 _____ (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Users\georg\Downloads\Evernote_5.9.6.9494.exe
2016-01-31 14:32 - 2016-01-31 14:32 - 00000000 ____D C:\Users\georg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2016-01-31 14:23 - 2016-01-31 14:23 - 00987728 _____ (Google Inc.) C:\Users\georg\Downloads\ChromeSetup.exe
2016-01-31 14:23 - 2016-01-31 14:23 - 00000000 ____D C:\Users\georg\AppData\Local\MicrosoftEdge
2016-01-31 14:12 - 2016-01-31 14:12 - 00000000 ____D C:\Users\georg\AppData\Local\Comms
2016-01-31 14:12 - 2016-01-31 14:12 - 00000000 ____D C:\Users\georg\AppData\Local\ActiveSync
2016-01-31 14:11 - 2016-02-05 13:08 - 00000000 ____D C:\Users\georg
2016-01-31 14:11 - 2016-02-03 01:24 - 00000000 ___RD C:\Users\georg\OneDrive
2016-01-31 14:11 - 2016-02-01 11:59 - 00000000 ____D C:\Users\georg\AppData\Local\Google
2016-01-31 14:11 - 2016-01-31 14:28 - 00000000 ____D C:\Users\georg\AppData\Local\Packages
2016-01-31 14:11 - 2016-01-31 14:12 - 00002363 _____ C:\Users\georg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-01-31 14:11 - 2016-01-31 14:11 - 00000020 ___SH C:\Users\georg\ntuser.ini
2016-01-31 14:11 - 2016-01-31 14:11 - 00000000 _SHDL C:\Users\georg\My Documents
2016-01-31 14:11 - 2016-01-31 14:11 - 00000000 _SHDL C:\Users\georg\Documents\My Videos
2016-01-31 14:11 - 2016-01-31 14:11 - 00000000 _SHDL C:\Users\georg\Documents\My Pictures
2016-01-31 14:11 - 2016-01-31 14:11 - 00000000 _SHDL C:\Users\georg\Documents\My Music
2016-01-31 14:11 - 2016-01-31 14:11 - 00000000 ____D C:\Users\georg\AppData\Roaming\Adobe
2016-01-31 14:11 - 2016-01-31 14:11 - 00000000 ____D C:\Users\georg\AppData\Local\VirtualStore
2016-01-31 14:11 - 2016-01-31 14:11 - 00000000 ____D C:\Users\georg\AppData\Local\TileDataLayer
2016-01-31 14:11 - 2016-01-31 14:11 - 00000000 ____D C:\Users\georg\AppData\Local\Publishers
2016-01-30 17:01 - 2016-01-30 17:01 - 02242059 _____ C:\Users\Paige Perry\Documents\Drafts (34) - george.nicholson3@gmail.com - Gmail.html
2016-01-30 17:01 - 2016-01-30 17:01 - 00000000 ____D C:\Users\Paige Perry\Documents\Drafts (34) - george.nicholson3@gmail.com - Gmail_files
2016-01-30 14:26 - 2016-01-30 14:26 - 00000000 ____D C:\Users\Paige Perry\Documents\Wilco_Roadcase049_2015-08-06_SanFranciscoCA_FLAC
2016-01-29 22:55 - 2016-01-29 22:55 - 00003795 _____ C:\Users\Paige Perry\Desktop\one drive application settings.txt
2016-01-29 17:46 - 2005-01-28 01:40 - 00167936 _____ C:\Windows\SysWOW64\ErdHelp.exe
2016-01-29 17:46 - 2005-01-28 01:40 - 00040960 _____ C:\Windows\SysWOW64\PWDSERV.EXE
2016-01-29 17:46 - 2005-01-28 01:40 - 00003482 _____ C:\Windows\SysWOW64\ERDCMDR2005.CNT
2016-01-29 17:45 - 2016-01-29 17:45 - 00038400 _____ (Sysinternals) C:\Windows\SysWOW64\Drivers\REGSYS701.SYS
2016-01-29 17:26 - 2016-01-29 17:26 - 00164220 _____ C:\Windows\Minidump\012916-6312-01.dmp
2016-01-29 17:14 - 2016-01-29 17:14 - 00027016 _____ (Sysinternals - www.sysinternals.com) C:\Windows\system32\Drivers\PROCEXP141.SYS
2016-01-29 01:22 - 2016-01-29 01:37 - 1209163328 _____ (Google Inc.) C:\Users\Paige Perry\Documents\android-studio-bundle-141.2456560-windows.exe
2016-01-29 01:12 - 2016-01-29 01:12 - 08687314 _____ C:\Users\Paige Perry\Documents\usb_driver.zip
2016-01-29 00:23 - 2016-01-29 00:23 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2016-01-28 23:17 - 2016-01-28 23:17 - 00000000 ____D C:\Users\Paige Perry\AppData\Roaming\JetBrains
2016-01-28 23:16 - 2016-01-29 01:43 - 00000145 _____ C:\HaxLogs.txt
2016-01-28 23:16 - 2016-01-29 01:43 - 00000000 ____D C:\Users\Paige Perry\.android
2016-01-28 23:16 - 2016-01-28 23:16 - 00000000 ____D C:\Users\Paige Perry\.AndroidStudio1.5
2016-01-28 23:16 - 2016-01-28 23:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Android Studio
2016-01-28 23:12 - 2016-01-29 01:39 - 00000000 ____D C:\Android
2016-01-28 23:11 - 2016-01-29 01:38 - 00000000 ____D C:\Program Files\Android
2016-01-28 21:36 - 2016-01-28 21:36 - 00320424 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2016-01-28 21:36 - 2016-01-28 21:36 - 00189864 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2016-01-28 21:36 - 2016-01-28 21:36 - 00189864 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2016-01-28 21:36 - 2016-01-28 21:36 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2016-01-28 21:35 - 2016-01-28 21:36 - 00000000 ____D C:\Program Files\Java
2016-01-28 21:35 - 2016-01-28 21:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2016-01-28 21:33 - 2016-01-28 21:35 - 146893216 _____ (Oracle Corporation) C:\Users\Paige Perry\Documents\jdk-7u80-windows-x64.exe
2016-01-28 17:22 - 2016-01-28 17:22 - 00956446 _____ C:\Users\Paige Perry\Documents\Scan.pdf
2016-01-28 00:25 - 2016-01-28 00:25 - 00000000 ____D C:\Users\Paige Perry\Downloads\nirsoft_package_1.19.70 (1)
2016-01-27 13:43 - 2016-01-16 01:37 - 00202472 _____ (Microsoft Corporation) C:\Windows\system32\wscapi.dll
2016-01-27 13:43 - 2016-01-16 01:36 - 01173344 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-01-27 13:43 - 2016-01-16 01:36 - 00713568 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-01-27 13:43 - 2016-01-16 01:34 - 00513888 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-01-27 13:43 - 2016-01-16 01:24 - 00538632 _____ (Microsoft Corporation) C:\Windows\system32\WWanAPI.dll
2016-01-27 13:43 - 2016-01-16 01:23 - 08728920 _____ (Microsoft Corp.) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2016-01-27 13:43 - 2016-01-16 01:23 - 00848160 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll
2016-01-27 13:43 - 2016-01-16 01:23 - 00785088 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2016-01-27 13:43 - 2016-01-16 01:23 - 00536256 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2016-01-27 13:43 - 2016-01-16 01:23 - 00408120 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2016-01-27 13:43 - 2016-01-16 01:23 - 00369912 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2016-01-27 13:43 - 2016-01-16 01:21 - 22572624 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2016-01-27 13:43 - 2016-01-16 01:21 - 01750440 _____ (Microsoft Corporation) C:\Windows\system32\WpcMon.exe
2016-01-27 13:43 - 2016-01-16 01:20 - 06971752 _____ (Microsoft Corp.) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2016-01-27 13:43 - 2016-01-16 01:20 - 06600904 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
2016-01-27 13:43 - 2016-01-16 01:20 - 00652312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2016-01-27 13:43 - 2016-01-16 01:20 - 00431240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWanAPI.dll
2016-01-27 13:43 - 2016-01-16 01:20 - 00366224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2016-01-27 13:43 - 2016-01-16 01:19 - 00709688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
2016-01-27 13:43 - 2016-01-16 01:19 - 00405568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2016-01-27 13:43 - 2016-01-16 01:17 - 21125400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2016-01-27 13:43 - 2016-01-16 01:16 - 05238360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2016-01-27 13:43 - 2016-01-16 01:13 - 01998168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2016-01-27 13:43 - 2016-01-16 01:13 - 00576864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys
2016-01-27 13:43 - 2016-01-16 01:12 - 01415200 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2016-01-27 13:43 - 2016-01-16 01:09 - 01089880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2016-01-27 13:43 - 2016-01-16 01:08 - 01174008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2016-01-27 13:43 - 2016-01-16 01:08 - 00440152 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2016-01-27 13:43 - 2016-01-16 00:46 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbser.sys
2016-01-27 13:43 - 2016-01-16 00:45 - 16986112 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2016-01-27 13:43 - 2016-01-16 00:44 - 22394368 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2016-01-27 13:43 - 2016-01-16 00:44 - 00166400 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe
2016-01-27 13:43 - 2016-01-16 00:44 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\rasadhlp.dll
2016-01-27 13:43 - 2016-01-16 00:44 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\rastlsext.dll
2016-01-27 13:43 - 2016-01-16 00:43 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\winhttpcom.dll
2016-01-27 13:43 - 2016-01-16 00:42 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\MapsBtSvc.dll
2016-01-27 13:43 - 2016-01-16 00:42 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\sscoreext.dll
2016-01-27 13:43 - 2016-01-16 00:41 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\MusNotificationUx.exe
2016-01-27 13:43 - 2016-01-16 00:40 - 11545088 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2016-01-27 13:43 - 2016-01-16 00:40 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\rasauto.dll
2016-01-27 13:43 - 2016-01-16 00:40 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\pcaui.exe
2016-01-27 13:43 - 2016-01-16 00:40 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\rasautou.exe
2016-01-27 13:43 - 2016-01-16 00:39 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\FilterDS.dll
2016-01-27 13:43 - 2016-01-16 00:38 - 07979008 _____ (Microsoft Corporation) C:\Windows\system32\mos.dll
2016-01-27 13:43 - 2016-01-16 00:38 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll
2016-01-27 13:43 - 2016-01-16 00:38 - 00193024 _____ (Microsoft Corporation) C:\Windows\system32\SimCfg.dll
2016-01-27 13:43 - 2016-01-16 00:38 - 00130560 _____ (Microsoft Corporation) C:\Windows\system32\winbio.dll
2016-01-27 13:43 - 2016-01-16 00:37 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\StorSvc.dll
2016-01-27 13:43 - 2016-01-16 00:37 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\DisplayManager.dll
2016-01-27 13:43 - 2016-01-16 00:37 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\wscsvc.dll
2016-01-27 13:43 - 2016-01-16 00:37 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\SMSRouter.dll
2016-01-27 13:43 - 2016-01-16 00:36 - 00638464 _____ (Microsoft Corporation) C:\Windows\system32\enterprisecsps.dll
2016-01-27 13:43 - 2016-01-16 00:36 - 00475648 _____ (Microsoft Corporation) C:\Windows\system32\DDDS.dll
2016-01-27 13:43 - 2016-01-16 00:36 - 00221696 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-01-27 13:43 - 2016-01-16 00:36 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\SimAuth.dll
2016-01-27 13:43 - 2016-01-16 00:36 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastlsext.dll
2016-01-27 13:43 - 2016-01-16 00:35 - 13018624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2016-01-27 13:43 - 2016-01-16 00:35 - 00383488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-01-27 13:43 - 2016-01-16 00:35 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasadhlp.dll
2016-01-27 13:43 - 2016-01-16 00:34 - 00610816 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2016-01-27 13:43 - 2016-01-16 00:34 - 00590848 _____ (Microsoft Corporation) C:\Windows\system32\SmsRouterSvc.dll
2016-01-27 13:43 - 2016-01-16 00:34 - 00477696 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-01-27 13:43 - 2016-01-16 00:34 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2016-01-27 13:43 - 2016-01-16 00:34 - 00079360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttpcom.dll
2016-01-27 13:43 - 2016-01-16 00:33 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\wlidcli.dll
2016-01-27 13:43 - 2016-01-16 00:33 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.UX.EapRequestHandler.dll
2016-01-27 13:43 - 2016-01-16 00:33 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapsBtSvc.dll
2016-01-27 13:43 - 2016-01-16 00:32 - 24602624 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-01-27 13:43 - 2016-01-16 00:32 - 00621568 _____ (Microsoft Corporation) C:\Windows\system32\wbiosrvc.dll
2016-01-27 13:43 - 2016-01-16 00:32 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pcaui.exe
2016-01-27 13:43 - 2016-01-16 00:31 - 00851456 _____ (Microsoft Corporation) C:\Windows\system32\MapsStore.dll
2016-01-27 13:43 - 2016-01-16 00:31 - 00794112 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2016-01-27 13:43 - 2016-01-16 00:31 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\CredProvDataModel.dll
2016-01-27 13:43 - 2016-01-16 00:31 - 00343552 _____ (Microsoft Corporation) C:\Windows\system32\SensorsApi.dll
2016-01-27 13:43 - 2016-01-16 00:31 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasautou.exe
2016-01-27 13:43 - 2016-01-16 00:30 - 13382656 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-01-27 13:43 - 2016-01-16 00:30 - 02127360 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-01-27 13:43 - 2016-01-16 00:30 - 01053696 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2016-01-27 13:43 - 2016-01-16 00:30 - 00784384 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-01-27 13:43 - 2016-01-16 00:30 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SimCfg.dll
2016-01-27 13:43 - 2016-01-16 00:30 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winbio.dll
2016-01-27 13:43 - 2016-01-16 00:29 - 01500672 _____ (Microsoft Corporation) C:\Windows\system32\RecoveryDrive.exe
2016-01-27 13:43 - 2016-01-16 00:29 - 00200704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DisplayManager.dll
2016-01-27 13:43 - 2016-01-16 00:28 - 09918976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2016-01-27 13:43 - 2016-01-16 00:28 - 02624512 _____ (Microsoft Corporation) C:\Windows\system32\InputService.dll
2016-01-27 13:43 - 2016-01-16 00:28 - 01318912 _____ (Microsoft Corporation) C:\Windows\system32\wifinetworkmanager.dll
2016-01-27 13:43 - 2016-01-16 00:28 - 00884736 _____ (Microsoft Corporation) C:\Windows\system32\rasdlg.dll
2016-01-27 13:43 - 2016-01-16 00:28 - 00129024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SimAuth.dll
2016-01-27 13:43 - 2016-01-16 00:27 - 00335872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2016-01-27 13:43 - 2016-01-16 00:26 - 19338752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-01-27 13:43 - 2016-01-16 00:26 - 00535040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2016-01-27 13:43 - 2016-01-16 00:26 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\TextInputFramework.dll
2016-01-27 13:43 - 2016-01-16 00:26 - 00260608 _____ C:\Windows\system32\MTFServer.dll
2016-01-27 13:43 - 2016-01-16 00:26 - 00175616 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Core.TextInput.dll
2016-01-27 13:43 - 2016-01-16 00:25 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlidcli.dll
2016-01-27 13:43 - 2016-01-16 00:25 - 00457728 _____ (Microsoft Corporation) C:\Windows\system32\ipnathlp.dll
2016-01-27 13:43 - 2016-01-16 00:25 - 00235008 _____ C:\Windows\system32\MTF.dll
2016-01-27 13:43 - 2016-01-16 00:24 - 18678272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2016-01-27 13:43 - 2016-01-16 00:24 - 02057216 _____ (Microsoft Corporation) C:\Windows\system32\wlidsvc.dll
2016-01-27 13:43 - 2016-01-16 00:24 - 00613888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2016-01-27 13:43 - 2016-01-16 00:24 - 00350720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CredProvDataModel.dll
2016-01-27 13:43 - 2016-01-16 00:24 - 00273408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SensorsApi.dll
2016-01-27 13:43 - 2016-01-16 00:23 - 02050048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-01-27 13:43 - 2016-01-16 00:23 - 00687616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-01-27 13:43 - 2016-01-16 00:21 - 06297088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mos.dll
2016-01-27 13:43 - 2016-01-16 00:20 - 07199232 _____ (Microsoft Corporation) C:\Windows\system32\BingMaps.dll
2016-01-27 13:43 - 2016-01-16 00:20 - 02597888 _____ (Microsoft Corporation) C:\Windows\system32\NetworkMobileSettings.dll
2016-01-27 13:43 - 2016-01-16 00:20 - 01944576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputService.dll
2016-01-27 13:43 - 2016-01-16 00:20 - 00799744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasdlg.dll
2016-01-27 13:43 - 2016-01-16 00:19 - 12126208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-01-27 13:43 - 2016-01-16 00:19 - 00733184 _____ (Microsoft Corporation) C:\Windows\system32\rasapi32.dll
2016-01-27 13:43 - 2016-01-16 00:19 - 00245760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TextInputFramework.dll
2016-01-27 13:43 - 2016-01-16 00:19 - 00162816 _____ C:\Windows\SysWOW64\MTF.dll
2016-01-27 13:43 - 2016-01-16 00:19 - 00133632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Core.TextInput.dll
2016-01-27 13:43 - 2016-01-16 00:18 - 03593216 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2016-01-27 13:43 - 2016-01-16 00:18 - 01674240 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2016-01-27 13:43 - 2016-01-16 00:17 - 05503488 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2016-01-27 13:43 - 2016-01-16 00:16 - 05202944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BingMaps.dll
2016-01-27 13:43 - 2016-01-16 00:16 - 01542656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2016-01-27 13:43 - 2016-01-16 00:15 - 04759040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2016-01-27 13:43 - 2016-01-16 00:14 - 01946624 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2016-01-27 13:43 - 2016-01-16 00:14 - 01626624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2016-01-27 13:43 - 2016-01-16 00:11 - 00653312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasapi32.dll
2016-01-27 13:43 - 2016-01-16 00:09 - 01087488 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll
2016-01-26 12:25 - 2016-01-26 12:25 - 00345495 _____ C:\Users\Paige Perry\Downloads\Going_Paperless_Evernote_Webinar_Search.pdf
2016-01-26 11:06 - 2016-01-26 11:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3
2016-01-25 03:35 - 2016-02-02 23:38 - 00000000 ____D C:\Program Files\Recuva
2016-01-25 03:35 - 2016-01-25 03:35 - 00001699 _____ C:\Users\Public\Desktop\Recuva.lnk
2016-01-25 03:35 - 2016-01-25 03:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva
2016-01-23 16:22 - 2016-01-23 16:22 - 00059250 ____T C:\Users\Paige Perry\Documents\Steam Info and Receipt.pdf
2016-01-23 16:22 - 2016-01-23 16:22 - 00000000 ____D C:\Users\Paige Perry\AppData\LocalLow\Temp
2016-01-23 13:26 - 2016-01-23 16:10 - 00000000 ____D C:\Users\Paige Perry\AppData\Local\Ubisoft Game Launcher
2016-01-23 13:26 - 2016-01-23 13:26 - 00001274 _____ C:\Users\Paige Perry\Desktop\Uplay.lnk
2016-01-23 13:26 - 2016-01-23 13:26 - 00000000 ____D C:\Users\Paige Perry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2016-01-23 13:26 - 2016-01-23 13:26 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2016-01-23 13:25 - 2016-01-23 13:25 - 00000000 ____D C:\Users\Paige Perry\AppData\Local\Steam
2016-01-23 13:25 - 2016-01-23 13:25 - 00000000 ____D C:\Users\Paige Perry\AppData\Local\CEF
2016-01-23 13:22 - 2016-02-05 10:06 - 00000000 ____D C:\Program Files (x86)\Steam
2016-01-23 13:22 - 2016-01-23 13:22 - 00000986 _____ C:\Users\Public\Desktop\Steam.lnk
2016-01-23 13:22 - 2016-01-23 13:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2016-01-23 07:05 - 2016-01-23 07:05 - 00000000 ____D C:\Users\Paige Perry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2016-01-22 20:43 - 2016-01-22 20:43 - 00000000 ____D C:\Program Files\Reference Assemblies
2016-01-22 20:43 - 2016-01-22 20:43 - 00000000 ____D C:\Program Files\MSBuild
2016-01-22 20:43 - 2016-01-22 20:43 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2016-01-22 20:43 - 2016-01-22 20:43 - 00000000 ____D C:\Program Files (x86)\MSBuild
2016-01-22 20:43 - 2015-10-23 17:47 - 00778936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationNative_v0300.dll
2016-01-22 20:43 - 2015-10-23 17:47 - 00103120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2016-01-22 20:43 - 2015-10-23 17:47 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2016-01-22 20:43 - 2015-10-23 17:46 - 01166520 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll
2016-01-22 20:43 - 2015-10-23 17:46 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2016-01-22 20:43 - 2015-10-23 17:45 - 00124624 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2016-01-22 20:40 - 2016-01-22 20:40 - 00000000 ____D C:\Users\Paige Perry\AppData\Local\Mixesoft
2016-01-22 20:38 - 2016-02-02 12:15 - 00000000 ____D C:\Users\Paige Perry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2016-01-22 20:30 - 2016-02-04 19:30 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-01-22 20:28 - 2016-02-05 15:29 - 00000934 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-22 20:28 - 2016-02-05 13:08 - 00000930 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-01-22 20:28 - 2016-01-31 14:24 - 00003992 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-01-22 20:28 - 2016-01-31 14:24 - 00003760 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-01-22 19:37 - 2016-01-26 11:06 - 00000000 ____D C:\Program Files (x86)\Google
2016-01-22 19:32 - 2016-01-31 20:56 - 00000000 ____D C:\Users\Paige Perry\AppData\Local\Google
2016-01-22 08:24 - 2016-01-22 08:24 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2016-01-22 04:06 - 2016-01-30 01:35 - 00000000 ____D C:\ProgramData\HP
2016-01-22 04:06 - 2016-01-22 04:07 - 00000000 ____D C:\Users\Paige Perry\AppData\Local\HP
2016-01-22 04:06 - 2016-01-22 04:06 - 00000057 _____ C:\ProgramData\Ament.ini
2016-01-22 03:56 - 2016-01-22 03:56 - 00001058 _____ C:\ProgramData\Microsoft\Windows\Start Menu\VueScan x64.lnk
2016-01-22 03:56 - 2016-01-22 03:56 - 00000000 ____D C:\Program Files\VueScan
2016-01-21 17:29 - 2016-01-22 03:56 - 00000000 ____D C:\Windows\twain_64
2016-01-21 16:53 - 2016-01-21 16:53 - 05093276 _____ C:\Users\Paige Perry\Documents\Evernote Tools Document Snap.pdf
2016-01-21 16:16 - 2016-01-21 16:18 - 00000000 ____D C:\Users\Paige Perry\AppData\Local\QuickPar
2016-01-21 16:14 - 2016-01-21 16:14 - 00000000 ____D C:\Users\Paige Perry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\QuickPar
2016-01-21 16:14 - 2016-01-21 16:14 - 00000000 ____D C:\Program Files (x86)\QuickPar
2016-01-20 23:32 - 2016-01-20 23:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap
2016-01-20 23:32 - 2016-01-20 23:32 - 00000000 ____D C:\Program Files (x86)\WinPcap
2016-01-20 22:13 - 2016-01-20 22:13 - 00000000 ____D C:\Users\Paige Perry\AppData\Local\Apps\2.0
2016-01-20 21:19 - 2016-01-20 21:32 - 01297533 _____ C:\Users\Paige Perry\Downloads\documentsnap-evernote-resource-list.pdf
2016-01-20 20:14 - 2016-02-02 17:48 - 00000000 ____D C:\Users\Paige Perry\Desktop\Senior US Government
2016-01-20 03:04 - 2016-01-20 03:04 - 00000000 ____D C:\Windows\system32\SleepStudy
2016-01-20 02:33 - 2016-01-31 14:36 - 00002523 _____ C:\Users\Public\Desktop\Evernote.lnk
2016-01-20 02:33 - 2016-01-31 14:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
2016-01-20 02:33 - 2016-01-20 02:33 - 00000000 ____D C:\Users\Paige Perry\AppData\LocalLow\Evernote
2016-01-20 02:33 - 2016-01-20 02:33 - 00000000 ____D C:\Users\Paige Perry\AppData\Local\Evernote
2016-01-20 02:33 - 2016-01-20 02:33 - 00000000 ____D C:\Program Files (x86)\Evernote
2016-01-19 23:16 - 2016-01-19 23:16 - 00000000 ____D C:\Users\Paige Perry\Downloads\WindowsUserManager
2016-01-19 23:11 - 2016-01-31 20:20 - 00000000 ____D C:\Program Files (x86)\SecurityXploded
2016-01-19 23:07 - 2016-01-19 23:07 - 00000000 ____D C:\Users\Paige Perry\Downloads\RemoteDirDetector
2016-01-19 23:05 - 2016-02-05 10:06 - 00000000 ____D C:\Users\Paige Perry\Downloads\NetShareMonitor
2016-01-19 23:03 - 2016-01-19 23:03 - 00000000 ____D C:\Users\Paige Perry\Downloads\NetDatabaseScanner
2016-01-19 15:46 - 2016-01-19 15:46 - 00000000 ____D C:\Users\Paige Perry\AppData\Roaming\MiTeC
2016-01-19 15:19 - 2016-01-29 17:26 - 00000000 ____D C:\Windows\Minidump
2016-01-19 15:19 - 2016-01-19 15:19 - 00262028 _____ C:\Windows\Minidump\011916-8031-01.dmp
2016-01-19 15:18 - 2016-01-29 17:26 - 732556958 _____ C:\Windows\MEMORY.DMP
2016-01-19 14:21 - 2016-01-19 14:21 - 00000017 _____ C:\Users\Paige Perry\AppData\Local\resmon.resmoncfg
2016-01-19 13:32 - 2016-01-19 13:32 - 00034328 _____ (Sysinternals - www.sysinternals.com) C:\Windows\system32\Drivers\PROCEXP152.SYS
2016-01-19 13:31 - 2016-01-29 17:45 - 00084360 ____H (Sysinternals - www.sysinternals.com) C:\Windows\system32\Drivers\PROCMON23.SYS
2016-01-19 13:23 - 2016-02-05 10:02 - 00004178 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{B461D18C-F79B-444A-B04F-478497FC42B2}
2016-01-19 12:52 - 2016-02-02 22:57 - 00014600 _____ (NirSoft) C:\Windows\system32\Drivers\NirSoftOpenedFilesDriver.sys
2016-01-19 12:40 - 2016-01-21 17:49 - 00000000 ____D C:\Users\Paige Perry\AppData\Roaming\WSCC2
2016-01-19 12:39 - 2016-01-19 12:39 - 00001056 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WSCC.lnk
2016-01-19 12:34 - 2016-01-19 12:34 - 00000000 ____D C:\Program Files (x86)\nirsoft_package_1.19.69
2016-01-19 12:32 - 2016-02-02 22:55 - 00000000 ____D C:\Program Files (x86)\NirSoft Utilities
2016-01-19 12:29 - 2016-01-19 12:31 - 00000000 ____D C:\Program Files (x86)\MiTeC
2016-01-19 12:28 - 2016-01-19 12:28 - 00000000 ____D C:\Program Files (x86)\New folder
2016-01-19 12:26 - 2016-01-21 17:49 - 00000000 ____D C:\Program Files (x86)\WSCC
2016-01-19 12:24 - 2016-01-19 13:32 - 00000000 ____D C:\Program Files (x86)\Sysinternals Suite
2016-01-19 11:29 - 2016-01-19 11:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2016-01-19 11:29 - 2016-01-19 11:29 - 00000000 ____D C:\Program Files\7-Zip
2016-01-19 10:10 - 2016-01-19 10:10 - 00000000 ____D C:\Users\Paige Perry\Downloads\Mimo
2016-01-19 10:10 - 2016-01-19 10:10 - 00000000 ____D C:\Users\Paige Perry\AppData\Roaming\Mimo
2016-01-19 10:10 - 2016-01-19 10:10 - 00000000 ____D C:\Program Files (x86)\Mimo
2016-01-19 10:09 - 2016-01-28 21:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-01-19 10:09 - 2016-01-19 10:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mimo
2016-01-19 10:09 - 2016-01-19 10:09 - 00000000 ____D C:\Users\Paige Perry\AppData\Roaming\Sun
2016-01-19 10:09 - 2016-01-19 10:09 - 00000000 ____D C:\Users\Paige Perry\AppData\LocalLow\Sun
2016-01-19 10:09 - 2016-01-19 10:09 - 00000000 ____D C:\Users\Paige Perry\.oracle_jre_usage
2016-01-19 10:09 - 2016-01-19 10:08 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2016-01-19 10:08 - 2016-01-19 10:10 - 00000000 ____D C:\Program Files (x86)\Java
2016-01-19 10:08 - 2016-01-19 10:09 - 00000000 ____D C:\ProgramData\Oracle
2016-01-19 10:08 - 2016-01-19 10:08 - 00000000 ____D C:\Users\Paige Perry\AppData\LocalLow\Oracle
2016-01-19 09:06 - 2016-01-19 11:40 - 00000000 ____D C:\Users\Paige Perry\AppData\Roaming\NewsLeecher
2016-01-19 09:05 - 2016-01-19 09:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewsLeecher
2016-01-19 09:05 - 2016-01-19 09:05 - 00000000 ____D C:\Program Files (x86)\NewsLeecher
2016-01-19 05:45 - 2016-01-19 05:45 - 00000000 ____D C:\Users\Paige Perry\AppData\Local\NetworkTiles
2016-01-19 04:50 - 2015-12-08 22:39 - 00301728 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-01-19 04:49 - 2016-01-19 04:49 - 143671360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-01-19 04:49 - 2016-01-19 04:49 - 00000000 ____D C:\Windows\system32\MRT
2016-01-19 04:48 - 2016-01-04 21:51 - 07477600 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-01-19 04:48 - 2016-01-04 21:51 - 01317640 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2016-01-19 04:48 - 2016-01-04 21:51 - 01141496 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2016-01-19 04:48 - 2016-01-04 21:50 - 00671472 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-01-19 04:48 - 2016-01-04 21:48 - 00499432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2016-01-19 04:48 - 2016-01-04 21:45 - 02587696 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2016-01-19 04:48 - 2016-01-04 21:42 - 02026736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2016-01-19 04:48 - 2016-01-04 21:37 - 02544256 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2016-01-19 04:48 - 2016-01-04 21:37 - 01299504 _____ (Microsoft Corporation) C:\Windows\system32\mfnetsrc.dll
2016-01-19 04:48 - 2016-01-04 21:37 - 00858952 _____ (Microsoft Corporation) C:\Windows\system32\mfnetcore.dll
2016-01-19 04:48 - 2016-01-04 21:37 - 00245840 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2016-01-19 04:48 - 2016-01-04 21:37 - 00234504 _____ (Microsoft Corporation) C:\Windows\system32\mftranscode.dll
2016-01-19 04:48 - 2016-01-04 21:36 - 00808800 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe
2016-01-19 04:48 - 2016-01-04 21:33 - 02180128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2016-01-19 04:48 - 2016-01-04 21:33 - 01118208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetsrc.dll
2016-01-19 04:48 - 2016-01-04 21:33 - 00701384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetcore.dll
2016-01-19 04:48 - 2016-01-04 21:33 - 00208176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mftranscode.dll
2016-01-19 04:48 - 2016-01-04 21:33 - 00116728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2016-01-19 04:48 - 2016-01-04 21:31 - 00703840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
2016-01-19 04:48 - 2016-01-04 21:27 - 01594408 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2016-01-19 04:48 - 2016-01-04 21:24 - 00796352 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-01-19 04:48 - 2016-01-04 21:23 - 01804664 _____ (Microsoft Corporation) C:\Windows\system32\WMALFXGFXDSP.dll
2016-01-19 04:48 - 2016-01-04 21:23 - 01309376 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-01-19 04:48 - 2016-01-04 21:23 - 00786696 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL
2016-01-19 04:48 - 2016-01-04 21:23 - 00119320 _____ (Microsoft Corporation) C:\Windows\system32\MP3DMOD.DLL
2016-01-19 04:48 - 2016-01-04 21:21 - 01371792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2016-01-19 04:48 - 2016-01-04 21:17 - 00695752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOD.DLL
2016-01-19 04:48 - 2016-01-04 21:16 - 00100160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP3DMOD.DLL
2016-01-19 04:48 - 2016-01-04 20:57 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\usermgrcli.dll
2016-01-19 04:48 - 2016-01-04 20:56 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\omadmclient.exe
2016-01-19 04:48 - 2016-01-04 20:54 - 00162816 _____ (Microsoft Corporation) C:\Windows\system32\DeviceCensus.exe
2016-01-19 04:48 - 2016-01-04 20:53 - 00148992 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2016-01-19 04:48 - 2016-01-04 20:50 - 00644096 _____ (Microsoft Corporation) C:\Windows\system32\uReFS.dll
2016-01-19 04:48 - 2016-01-04 20:50 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2016-01-19 04:48 - 2016-01-04 20:49 - 01255936 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOE.DLL
2016-01-19 04:48 - 2016-01-04 20:49 - 00749056 _____ (Microsoft Corporation) C:\Windows\system32\PhoneService.dll
2016-01-19 04:48 - 2016-01-04 20:49 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\ProximityCommon.dll
2016-01-19 04:48 - 2016-01-04 20:48 - 01009152 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOD.DLL
2016-01-19 04:48 - 2016-01-04 20:48 - 00387072 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2016-01-19 04:48 - 2016-01-04 20:48 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usermgrcli.dll
2016-01-19 04:48 - 2016-01-04 20:47 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\MessagingDataModel2.dll
2016-01-19 04:48 - 2016-01-04 20:47 - 00479232 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-01-19 04:48 - 2016-01-04 20:47 - 00305664 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax
2016-01-19 04:48 - 2016-01-04 20:45 - 00678912 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2016-01-19 04:48 - 2016-01-04 20:45 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\facecredentialprovider.dll
2016-01-19 04:48 - 2016-01-04 20:43 - 00912384 _____ (Microsoft Corporation) C:\Windows\system32\usermgr.dll
2016-01-19 04:48 - 2016-01-04 20:43 - 00604672 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-01-19 04:48 - 2016-01-04 20:43 - 00584704 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2016-01-19 04:48 - 2016-01-04 20:41 - 00558592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uReFS.dll
2016-01-19 04:48 - 2016-01-04 20:40 - 00890880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOD.DLL
2016-01-19 04:48 - 2016-01-04 20:40 - 00123392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ProximityCommon.dll
2016-01-19 04:48 - 2016-01-04 20:39 - 03428864 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2016-01-19 04:48 - 2016-01-04 20:39 - 00569856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2016-01-19 04:48 - 2016-01-04 20:39 - 00498176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MessagingDataModel2.dll
2016-01-19 04:48 - 2016-01-04 20:38 - 00389120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-01-19 04:48 - 2016-01-04 20:36 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2016-01-19 04:48 - 2016-01-04 20:36 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-01-19 04:48 - 2016-01-04 20:30 - 02796032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2016-01-19 04:48 - 2016-01-04 20:30 - 02280448 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2016-01-19 04:48 - 2016-01-04 20:29 - 03667456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-01-19 04:48 - 2016-01-04 20:28 - 07826432 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2016-01-19 04:48 - 2016-01-04 20:28 - 04894720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-01-19 04:48 - 2016-01-04 20:25 - 05660160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2016-01-19 04:48 - 2015-12-06 23:57 - 00973664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LicenseManager.dll
2016-01-19 04:48 - 2015-12-06 23:55 - 01281376 _____ (Microsoft Corporation) C:\Windows\system32\LicenseManager.dll
2016-01-19 04:48 - 2015-12-06 23:49 - 00412512 _____ (Microsoft Corporation) C:\Windows\system32\wifitask.exe
2016-01-19 04:48 - 2015-12-06 23:48 - 01155944 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll
2016-01-19 04:48 - 2015-12-06 23:48 - 01092456 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2016-01-19 04:48 - 2015-12-06 23:48 - 01065080 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
2016-01-19 04:48 - 2015-12-06 23:48 - 01020096 _____ (Microsoft Corporation) C:\Windows\system32\mfsrcsnk.dll
2016-01-19 04:48 - 2015-12-06 23:48 - 00983464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2016-01-19 04:48 - 2015-12-06 23:48 - 00884256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2016-01-19 04:48 - 2015-12-06 23:48 - 00823264 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll
2016-01-19 04:48 - 2015-12-06 23:48 - 00794888 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll
2016-01-19 04:48 - 2015-12-06 23:48 - 00696160 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupEngine.dll
2016-01-19 04:48 - 2015-12-06 23:48 - 00670928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll
2016-01-19 04:48 - 2015-12-06 23:48 - 00526856 _____ (Microsoft Corporation) C:\Windows\system32\mfreadwrite.dll
2016-01-19 04:48 - 2015-12-06 23:48 - 00502112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupEngine.dll
2016-01-19 04:48 - 2015-12-06 23:48 - 00498448 _____ (Microsoft Corporation) C:\Windows\system32\MFCaptureEngine.dll
2016-01-19 04:48 - 2015-12-06 23:48 - 00462760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll
2016-01-19 04:48 - 2015-12-06 23:48 - 00450904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFCaptureEngine.dll
2016-01-19 04:48 - 2015-12-06 23:48 - 00337840 _____ (Microsoft Corporation) C:\Windows\system32\MFPlay.dll
2016-01-19 04:48 - 2015-12-06 23:48 - 00289248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFPlay.dll
2016-01-19 04:48 - 2015-12-06 23:48 - 00115040 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupApi.dll
2016-01-19 04:48 - 2015-12-06 23:48 - 00084832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupApi.dll
2016-01-19 04:48 - 2015-12-06 23:47 - 00925064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2016-01-19 04:48 - 2015-12-06 23:47 - 00898184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsrcsnk.dll
2016-01-19 04:48 - 2015-12-06 23:47 - 00716928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll
2016-01-19 04:48 - 2015-12-06 23:46 - 03671888 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-01-19 04:48 - 2015-12-06 23:46 - 02919320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-01-19 04:48 - 2015-12-06 23:45 - 00264544 _____ (Microsoft Corporation) C:\Windows\system32\ContentDeliveryManager.Utilities.dll
2016-01-19 04:48 - 2015-12-06 23:15 - 01035776 _____ (Microsoft Corporation) C:\Windows\system32\XboxNetApiSvc.dll
2016-01-19 04:48 - 2015-12-06 23:10 - 00824320 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebFilter.dll
2016-01-19 04:48 - 2015-12-06 23:09 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\flvprophandler.dll
2016-01-19 04:48 - 2015-12-06 23:06 - 00572928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WpcWebFilter.dll
2016-01-19 04:48 - 2015-12-06 23:06 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\KnobsCore.dll
2016-01-19 04:48 - 2015-12-06 23:06 - 00199168 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgent.exe
2016-01-19 04:48 - 2015-12-06 23:04 - 00056320 _____ (Microsoft Corporation) C:\Windows\system32\provtool.exe
2016-01-19 04:48 - 2015-12-06 23:02 - 00161280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgent.exe
2016-01-19 04:48 - 2015-12-06 23:01 - 00543232 _____ (Microsoft Corporation) C:\Windows\system32\StoreAgent.dll
2016-01-19 04:48 - 2015-12-06 23:00 - 00323072 _____ (Microsoft Corporation) C:\Windows\system32\MSFlacDecoder.dll
2016-01-19 04:48 - 2015-12-06 23:00 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wcmcsp.dll
2016-01-19 04:48 - 2015-12-06 22:59 - 00558080 _____ (Microsoft Corporation) C:\Windows\system32\MBMediaManager.dll
2016-01-19 04:48 - 2015-12-06 22:59 - 00292352 _____ (Microsoft Corporation) C:\Windows\system32\provengine.dll
2016-01-19 04:48 - 2015-12-06 22:59 - 00286208 _____ (Microsoft Corporation) C:\Windows\system32\provhandlers.dll
2016-01-19 04:48 - 2015-12-06 22:59 - 00165376 _____ (Microsoft Corporation) C:\Windows\system32\provdatastore.dll
2016-01-19 04:48 - 2015-12-06 22:58 - 00459776 _____ (Microsoft Corporation) C:\Windows\system32\MapConfiguration.dll
2016-01-19 04:48 - 2015-12-06 22:57 - 00409088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StoreAgent.dll
2016-01-19 04:48 - 2015-12-06 22:57 - 00270848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSFlacDecoder.dll
2016-01-19 04:48 - 2015-12-06 22:56 - 00607232 _____ (Microsoft Corporation) C:\Windows\system32\wcmsvc.dll
2016-01-19 04:48 - 2015-12-06 22:56 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\mfmkvsrcsnk.dll
2016-01-19 04:48 - 2015-12-06 22:53 - 00381952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmkvsrcsnk.dll
2016-01-19 04:48 - 2015-12-06 22:50 - 01131520 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Audio.dll
2016-01-19 04:48 - 2015-12-06 22:49 - 01105920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Audio.dll
2016-01-19 04:48 - 2015-12-06 22:45 - 02582016 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2016-01-19 04:48 - 2015-12-06 22:45 - 00900608 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll
2016-01-19 04:48 - 2015-12-06 22:45 - 00683008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2016-01-19 04:48 - 2015-12-06 22:43 - 00931328 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL
2016-01-19 04:48 - 2015-12-06 22:41 - 02061824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2016-01-19 04:48 - 2015-12-06 22:40 - 01995776 _____ (Microsoft Corporation) C:\Windows\system32\ActiveSyncProvider.dll
2016-01-19 04:48 - 2015-12-06 22:40 - 01706496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActiveSyncProvider.dll
2016-01-19 04:48 - 2015-12-06 22:39 - 00764928 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2016-01-19 04:48 - 2015-12-06 22:38 - 00871936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPEG2ENC.DLL
2016-01-19 04:48 - 2015-12-06 22:33 - 00375296 _____ (Microsoft Corporation) C:\Windows\system32\MDEServer.exe
2016-01-19 04:48 - 2015-12-06 22:32 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\dialserver.dll
2016-01-19 04:48 - 2015-12-01 02:12 - 02152800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2016-01-19 04:48 - 2015-11-24 07:07 - 01817160 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-01-19 04:48 - 2015-11-24 06:06 - 01540768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-01-19 04:48 - 2015-11-24 05:26 - 01399224 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2016-01-19 04:48 - 2015-11-24 04:37 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys
2016-01-19 04:48 - 2015-11-24 04:26 - 01337240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2016-01-19 04:48 - 2015-11-24 04:12 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll
2016-01-19 04:48 - 2015-11-24 03:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2016-01-19 04:48 - 2015-11-24 03:52 - 01717248 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2016-01-19 04:48 - 2015-11-24 03:49 - 01648640 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
2016-01-19 04:48 - 2015-11-24 03:14 - 00415744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\catsrvut.dll
2016-01-19 04:48 - 2015-11-24 02:59 - 01467392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2016-01-19 04:48 - 2015-11-24 02:57 - 01328128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comsvcs.dll
2016-01-19 04:48 - 2015-11-24 02:29 - 02352128 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2016-01-19 04:48 - 2015-11-24 02:04 - 02155008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2016-01-19 04:48 - 2015-11-22 05:47 - 02653816 _____ C:\Windows\system32\CoreUIComponents.dll
2016-01-19 04:48 - 2015-11-22 05:41 - 01859448 _____ C:\Windows\SysWOW64\CoreUIComponents.dll
2016-01-19 04:48 - 2015-11-22 05:41 - 00026408 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2016-01-19 04:48 - 2015-11-22 05:34 - 00080600 _____ (Microsoft Corporation) C:\Windows\system32\wwapi.dll
2016-01-19 04:48 - 2015-11-22 05:33 - 00095072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdstor.sys
2016-01-19 04:48 - 2015-11-22 05:33 - 00058408 _____ (Microsoft Corporation) C:\Windows\system32\SensorsNativeApi.dll
2016-01-19 04:48 - 2015-11-22 05:33 - 00051680 _____ (Microsoft Corporation) C:\Windows\system32\SensorsUtilsV2.dll
2016-01-19 04:48 - 2015-11-22 05:30 - 00604928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2016-01-19 04:48 - 2015-11-22 05:30 - 00161632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-01-19 04:48 - 2015-11-22 05:25 - 00063528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wwapi.dll
2016-01-19 04:48 - 2015-11-22 05:24 - 02772584 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2016-01-19 04:48 - 2015-11-22 05:14 - 02185840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2016-01-19 04:48 - 2015-11-22 04:55 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\XblAuthManagerProxy.dll
2016-01-19 04:48 - 2015-11-22 04:54 - 00138240 _____ (Microsoft Corporation) C:\Windows\system32\ETWCoreUIComponentsResources.dll
2016-01-19 04:48 - 2015-11-22 04:54 - 00117248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\capimg.sys
2016-01-19 04:48 - 2015-11-22 04:50 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\mssign32.dll
2016-01-19 04:48 - 2015-11-22 04:43 - 00704000 _____ (Microsoft Corporation) C:\Windows\system32\CellularAPI.dll
2016-01-19 04:48 - 2015-11-22 04:43 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\SensorService.dll
2016-01-19 04:48 - 2015-11-22 04:43 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XblAuthManagerProxy.dll
2016-01-19 04:48 - 2015-11-22 04:42 - 00589312 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApi.dll
2016-01-19 04:48 - 2015-11-22 04:42 - 00138240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ETWCoreUIComponentsResources.dll
2016-01-19 04:48 - 2015-11-22 04:41 - 00948224 _____ (Microsoft Corporation) C:\Windows\system32\XblAuthManager.dll
2016-01-19 04:48 - 2015-11-22 04:39 - 00957440 _____ (Microsoft Corporation) C:\Windows\system32\SRH.dll
2016-01-19 04:48 - 2015-11-22 04:39 - 00938496 _____ (Microsoft Corporation) C:\Windows\system32\MapControlCore.dll
2016-01-19 04:48 - 2015-11-22 04:39 - 00870400 _____ (Microsoft Corporation) C:\Windows\system32\modernexecserver.dll
2016-01-19 04:48 - 2015-11-22 04:38 - 01223168 _____ (Microsoft Corporation) C:\Windows\system32\Unistore.dll
2016-01-19 04:48 - 2015-11-22 04:38 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2016-01-19 04:48 - 2015-11-22 04:38 - 00320000 _____ (Microsoft Corporation) C:\Windows\system32\cryptngc.dll
2016-01-19 04:48 - 2015-11-22 04:38 - 00060928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssign32.dll
2016-01-19 04:48 - 2015-11-22 04:37 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll
2016-01-19 04:48 - 2015-11-22 04:37 - 00515584 _____ (Microsoft Corporation) C:\Windows\system32\LogonController.dll
2016-01-19 04:48 - 2015-11-22 04:36 - 01042432 _____ (Microsoft Corporation) C:\Windows\system32\BingOnlineServices.dll
2016-01-19 04:48 - 2015-11-22 04:34 - 02843136 _____ (Microsoft Corporation) C:\Windows\system32\cdp.dll
2016-01-19 04:48 - 2015-11-22 04:32 - 00340480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToDevice.dll
2016-01-19 04:48 - 2015-11-22 04:31 - 00470528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApi.dll
2016-01-19 04:48 - 2015-11-22 04:31 - 00416768 _____ (Microsoft Corporation) C:\Windows\system32\dmenrollengine.dll
2016-01-19 04:48 - 2015-11-22 04:28 - 01734656 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-01-19 04:48 - 2015-11-22 04:28 - 01387008 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-01-19 04:48 - 2015-11-22 04:28 - 00948224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Unistore.dll
2016-01-19 04:48 - 2015-11-22 04:28 - 00870400 _____ (Microsoft Corporation) C:\Windows\system32\wpncore.dll
2016-01-19 04:48 - 2015-11-22 04:28 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SRH.dll
2016-01-19 04:48 - 2015-11-22 04:27 - 03993600 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
2016-01-19 04:48 - 2015-11-22 04:27 - 00241664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptngc.dll
2016-01-19 04:48 - 2015-11-22 04:26 - 03355136 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2016-01-19 04:48 - 2015-11-22 04:26 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCore.dll
2016-01-19 04:48 - 2015-11-22 04:26 - 00709120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BingOnlineServices.dll
2016-01-19 04:48 - 2015-11-22 04:26 - 00421888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LogonController.dll
2016-01-19 04:48 - 2015-11-22 04:24 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-01-19 04:48 - 2015-11-22 04:20 - 01860096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdp.dll
2016-01-19 04:48 - 2015-11-22 04:18 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-01-19 04:48 - 2015-11-22 04:18 - 00697856 _____ (Microsoft Corporation) C:\Windows\system32\PlayToManager.dll
2016-01-19 04:48 - 2015-11-22 04:18 - 00458752 _____ (Microsoft Corporation) C:\Windows\system32\PlayToDevice.dll
2016-01-19 04:48 - 2015-11-22 04:17 - 02680320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2016-01-19 04:48 - 2015-11-22 04:17 - 02121216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-01-19 04:48 - 2015-11-22 04:11 - 00517632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToManager.dll
2016-01-19 04:48 - 2015-11-21 00:29 - 00286720 _____ (Microsoft Corporation) C:\Windows\system32\deviceaccess.dll
2016-01-19 04:48 - 2015-11-21 00:07 - 00227840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\deviceaccess.dll
2016-01-19 04:48 - 2015-11-13 01:55 - 00035680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wimmount.sys
2016-01-19 04:48 - 2015-11-13 01:51 - 00698208 _____ (Microsoft Corporation) C:\Windows\system32\wimgapi.dll
2016-01-19 04:48 - 2015-11-13 01:51 - 00523616 _____ (Microsoft Corporation) C:\Windows\system32\wimserv.exe
2016-01-19 04:48 - 2015-11-13 01:51 - 00334736 _____ (Microsoft Corporation) C:\Windows\system32\policymanager.dll
2016-01-19 04:48 - 2015-11-13 01:43 - 00586208 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2016-01-19 04:48 - 2015-11-13 01:43 - 00110032 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2016-01-19 04:48 - 2015-11-13 01:43 - 00035656 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2016-01-19 04:48 - 2015-11-13 01:42 - 00516544 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2016-01-19 04:48 - 2015-11-13 01:42 - 00088392 _____ (Microsoft Corporation) C:\Windows\system32\remoteaudioendpoint.dll
2016-01-19 04:48 - 2015-11-13 01:33 - 00911648 _____ (Microsoft Corporation) C:\Windows\system32\dcomp.dll
2016-01-19 04:48 - 2015-11-13 01:33 - 00586080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wimgapi.dll
2016-01-19 04:48 - 2015-11-13 01:33 - 00092352 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-01-19 04:48 - 2015-11-13 01:32 - 00296488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\policymanager.dll
2016-01-19 04:48 - 2015-11-13 01:21 - 00511320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2016-01-19 04:48 - 2015-11-13 01:21 - 00454056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2016-01-19 04:48 - 2015-11-13 01:21 - 00073360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\remoteaudioendpoint.dll
2016-01-19 04:48 - 2015-11-13 01:21 - 00032040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2016-01-19 04:48 - 2015-11-13 01:09 - 00675064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dcomp.dll
2016-01-19 04:48 - 2015-11-13 00:58 - 00162304 _____ (Microsoft Corporation) C:\Windows\system32\tetheringservice.dll
2016-01-19 04:48 - 2015-11-13 00:57 - 00623616 _____ (Microsoft Corporation) C:\Windows\system32\PhoneProviders.dll
2016-01-19 04:48 - 2015-11-13 00:55 - 00450560 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Bluetooth.dll
2016-01-19 04:48 - 2015-11-13 00:53 - 00517632 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv
2016-01-19 04:48 - 2015-11-13 00:49 - 00674816 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.dll
2016-01-19 04:48 - 2015-11-13 00:39 - 02444288 _____ (Microsoft Corporation) C:\Windows\system32\twinui.appcore.dll
2016-01-19 04:48 - 2015-11-13 00:27 - 00400896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winspool.drv
2016-01-19 04:48 - 2015-11-13 00:19 - 02001408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.appcore.dll
2016-01-19 04:48 - 2015-11-05 07:05 - 00118624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2016-01-19 04:48 - 2015-11-05 05:40 - 00630632 _____ (Microsoft Corporation) C:\Windows\system32\fontdrvhost.exe
2016-01-19 04:48 - 2015-11-05 05:25 - 00578912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2016-01-19 04:48 - 2015-11-05 04:41 - 00540752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontdrvhost.exe
2016-01-19 04:48 - 2015-11-05 04:13 - 00969728 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-01-19 04:48 - 2015-11-05 04:10 - 00803840 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-01-19 04:48 - 2015-11-05 03:18 - 00791552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-01-19 04:48 - 2015-11-05 03:15 - 00647168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-01-19 04:47 - 2016-01-04 20:57 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\RMSRoamingSecurity.dll
2016-01-19 04:47 - 2016-01-04 20:52 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2016-01-19 04:47 - 2016-01-04 20:51 - 00472576 _____ (Microsoft Corporation) C:\Windows\system32\DscCore.dll
2016-01-19 04:47 - 2016-01-04 20:51 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\UserMgrProxy.dll
2016-01-19 04:47 - 2016-01-04 20:49 - 01582080 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2016-01-19 04:47 - 2016-01-04 20:49 - 00764928 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll
2016-01-19 04:47 - 2016-01-04 20:44 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2016-01-19 04:47 - 2016-01-04 20:42 - 00166912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserMgrProxy.dll
2016-01-19 04:47 - 2016-01-04 20:41 - 01070080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOE.DLL
2016-01-19 04:47 - 2016-01-04 20:39 - 00235008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksproxy.ax
2016-01-19 04:47 - 2015-12-06 23:15 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.XboxLive.ProxyStub.dll
2016-01-19 04:47 - 2015-12-06 23:09 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\policymanagerprecheck.dll
2016-01-19 04:47 - 2015-12-06 23:09 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\StorageUsage.dll
2016-01-19 04:47 - 2015-12-06 23:07 - 00134656 _____ (Microsoft Corporation) C:\Windows\system32\wificonnapi.dll
2016-01-19 04:47 - 2015-12-06 23:07 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\ProvPluginEng.dll
2016-01-19 04:47 - 2015-12-06 23:05 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\provisioningcsp.dll
2016-01-19 04:47 - 2015-12-06 23:05 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\BackgroundTransferHost.exe
2016-01-19 04:47 - 2015-12-06 23:04 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\moshost.dll
2016-01-19 04:47 - 2015-12-06 23:02 - 00269824 _____ (Microsoft Corporation) C:\Windows\system32\moshostcore.dll
2016-01-19 04:47 - 2015-12-06 23:01 - 00034304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BackgroundTransferHost.exe
2016-01-19 04:47 - 2015-12-06 23:00 - 00203776 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupSvc.dll
2016-01-19 04:47 - 2015-12-06 22:55 - 00346112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapConfiguration.dll
2016-01-19 04:47 - 2015-12-06 22:51 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\fveapibase.dll
2016-01-19 04:47 - 2015-11-24 05:01 - 02756096 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-01-19 04:47 - 2015-11-24 04:54 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\readingviewresources.dll
2016-01-19 04:47 - 2015-11-24 04:53 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-01-19 04:47 - 2015-11-24 04:45 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wshrm.dll
2016-01-19 04:47 - 2015-11-24 04:19 - 00182784 _____ (Microsoft Corporation) C:\Windows\system32\shutdownux.dll
2016-01-19 04:47 - 2015-11-24 03:54 - 02756096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2016-01-19 04:47 - 2015-11-22 05:00 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\MapsCSP.dll
2016-01-19 04:47 - 2015-11-22 05:00 - 00058368 _____ (Microsoft Corporation) C:\Windows\system32\MosResource.dll
2016-01-19 04:47 - 2015-11-22 04:57 - 00110592 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft-Windows-MapControls.dll
2016-01-19 04:47 - 2015-11-22 04:57 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCoreRes.dll
2016-01-19 04:47 - 2015-11-22 04:57 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft-Windows-MosTrace.dll
2016-01-19 04:47 - 2015-11-22 04:57 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft-Windows-MosHost.dll
2016-01-19 04:47 - 2015-11-22 04:56 - 01268736 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.dll
2016-01-19 04:47 - 2015-11-22 04:56 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MosHostClient.dll
2016-01-19 04:47 - 2015-11-22 04:56 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\ihvrilproxy.dll
2016-01-19 04:47 - 2015-11-22 04:56 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rilproxy.dll
2016-01-19 04:47 - 2015-11-22 04:55 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\MapsBtSvcProxy.dll
2016-01-19 04:47 - 2015-11-22 04:54 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SensorsNativeApi.V2.dll
2016-01-19 04:47 - 2015-11-22 04:54 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2016-01-19 04:47 - 2015-11-22 04:54 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\wsplib.dll
2016-01-19 04:47 - 2015-11-22 04:54 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2016-01-19 04:47 - 2015-11-22 04:54 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\WordBreakers.dll
2016-01-19 04:47 - 2015-11-22 04:54 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\nativemap.dll
2016-01-19 04:47 - 2015-11-22 04:54 - 00003072 _____ (Microsoft Corporation) C:\Windows\system32\MapControlStringsRes.dll
2016-01-19 04:47 - 2015-11-22 04:52 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\wininetlui.dll
2016-01-19 04:47 - 2015-11-22 04:52 - 00060928 _____ (Microsoft Corporation) C:\Windows\system32\XblAuthTokenBrokerExt.dll
2016-01-19 04:47 - 2015-11-22 04:52 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-01-19 04:47 - 2015-11-22 04:52 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\mapsupdatetask.dll
2016-01-19 04:47 - 2015-11-22 04:51 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\dmcertinst.exe
2016-01-19 04:47 - 2015-11-22 04:51 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\MosStorage.dll
2016-01-19 04:47 - 2015-11-22 04:51 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\mapstoasttask.dll
2016-01-19 04:47 - 2015-11-22 04:51 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-01-19 04:47 - 2015-11-22 04:49 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-01-19 04:47 - 2015-11-22 04:49 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\Wwanpref.dll
2016-01-19 04:47 - 2015-11-22 04:48 - 00058368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MosResource.dll
2016-01-19 04:47 - 2015-11-22 04:45 - 06572032 _____ (Microsoft Corporation) C:\Windows\system32\wwanmm.dll
2016-01-19 04:47 - 2015-11-22 04:45 - 00264192 _____ (Nokia) C:\Windows\system32\NmaDirect.dll
2016-01-19 04:47 - 2015-11-22 04:45 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Microsoft-Windows-MapControls.dll
2016-01-19 04:47 - 2015-11-22 04:45 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\wwancfg.dll
2016-01-19 04:47 - 2015-11-22 04:45 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCoreRes.dll
2016-01-19 04:47 - 2015-11-22 04:45 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Microsoft-Windows-MosTrace.dll
2016-01-19 04:47 - 2015-11-22 04:45 - 00009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Microsoft-Windows-MosHost.dll
2016-01-19 04:47 - 2015-11-22 04:44 - 01268736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Resources.dll
2016-01-19 04:47 - 2015-11-22 04:44 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MosHostClient.dll
2016-01-19 04:47 - 2015-11-22 04:42 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\mdmmigrator.dll
2016-01-19 04:47 - 2015-11-22 04:42 - 00024064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WordBreakers.dll
2016-01-19 04:47 - 2015-11-22 04:42 - 00003072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapControlStringsRes.dll
2016-01-19 04:47 - 2015-11-22 04:41 - 01814528 _____ (Microsoft Corporation) C:\Windows\system32\pnidui.dll
2016-01-19 04:47 - 2015-11-22 04:40 - 01056256 _____ (Microsoft Corporation) C:\Windows\system32\JpMapControl.dll
2016-01-19 04:47 - 2015-11-22 04:40 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\wwanconn.dll
2016-01-19 04:47 - 2015-11-22 04:40 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininetlui.dll
2016-01-19 04:47 - 2015-11-22 04:40 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XblAuthTokenBrokerExt.dll
2016-01-19 04:47 - 2015-11-22 04:39 - 01713664 _____ (Microsoft Corporation) C:\Windows\system32\SRHInproc.dll
2016-01-19 04:47 - 2015-11-22 04:39 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\NMAA.dll
2016-01-19 04:47 - 2015-11-22 04:39 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\offlinelsa.dll
2016-01-19 04:47 - 2015-11-22 04:39 - 00058368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MosStorage.dll
2016-01-19 04:47 - 2015-11-22 04:39 - 00045568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2016-01-19 04:47 - 2015-11-22 04:34 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\InputLocaleManager.dll
2016-01-19 04:47 - 2015-11-22 04:34 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\EditBufferTestHook.dll
2016-01-19 04:47 - 2015-11-22 04:33 - 00205824 _____ (Nokia) C:\Windows\SysWOW64\NmaDirect.dll
2016-01-19 04:47 - 2015-11-22 04:29 - 00800768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JpMapControl.dll
2016-01-19 04:47 - 2015-11-22 04:28 - 01443328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SRHInproc.dll
2016-01-19 04:47 - 2015-11-22 04:28 - 00784896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NMAA.dll
2016-01-19 04:47 - 2015-11-22 04:28 - 00100864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\offlinelsa.dll
2016-01-19 04:47 - 2015-11-22 04:27 - 00711680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapControlCore.dll
2016-01-19 04:47 - 2015-11-22 04:27 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\enrollmentapi.dll
2016-01-19 04:47 - 2015-11-22 04:24 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputLocaleManager.dll
2016-01-19 04:47 - 2015-11-22 04:24 - 00059904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EditBufferTestHook.dll
2016-01-19 04:47 - 2015-11-21 00:44 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft-Windows-AppModelExecEvents.dll
2016-01-19 04:47 - 2015-11-13 01:07 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Management.Provisioning.ProxyStub.dll
2016-01-19 04:47 - 2015-11-13 01:06 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\RemovableMediaProvisioningPlugin.dll
2016-01-19 04:47 - 2015-11-13 01:05 - 00122368 _____ (Microsoft Corporation) C:\Windows\system32\KnobsCsp.dll
2016-01-19 04:47 - 2015-11-13 01:05 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\BarcodeProvisioningPlugin.dll
2016-01-19 04:47 - 2015-11-13 01:05 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\bcastdvr.proxy.dll
2016-01-19 04:47 - 2015-11-13 01:05 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\tetheringconfigsp.dll
2016-01-19 04:47 - 2015-11-13 01:04 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\NFCProvisioningPlugin.dll
2016-01-19 04:47 - 2015-11-13 01:04 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\LaunchWinApp.exe
2016-01-19 04:47 - 2015-11-13 01:04 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\IcsEntitlementHost.exe
2016-01-19 04:47 - 2015-11-13 01:03 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\tetheringclient.dll
2016-01-19 04:47 - 2015-11-13 01:00 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\tzautoupdate.dll
2016-01-19 04:47 - 2015-11-13 00:59 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\AppCapture.dll
2016-01-19 04:47 - 2015-11-13 00:56 - 00163328 _____ (Microsoft Corporation) C:\Windows\system32\provops.dll
2016-01-19 04:47 - 2015-11-13 00:40 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LaunchWinApp.exe
2016-01-19 04:47 - 2015-11-13 00:40 - 00027136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcastdvr.proxy.dll
2016-01-19 04:47 - 2015-11-13 00:34 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppCapture.dll
2016-01-19 04:47 - 2015-11-13 00:33 - 00414720 _____ (Microsoft Corporation) C:\Windows\system32\bcastdvr.exe
2016-01-19 04:47 - 2015-11-13 00:30 - 00334336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcastdvr.exe
2016-01-19 04:47 - 2015-11-13 00:30 - 00315904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Bluetooth.dll
2016-01-19 04:47 - 2015-11-13 00:23 - 00490496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.dll
2016-01-19 04:47 - 2015-11-05 05:08 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2016-01-19 04:47 - 2015-11-05 05:08 - 00003072 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2016-01-19 04:47 - 2015-11-05 05:04 - 00045568 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2016-01-19 04:47 - 2015-11-05 05:00 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2016-01-19 04:47 - 2015-11-05 04:44 - 00365568 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2016-01-19 04:47 - 2015-11-05 04:03 - 00003072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2016-01-19 04:47 - 2015-11-05 04:02 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2016-01-19 04:47 - 2015-11-05 03:59 - 00037376 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2016-01-19 04:47 - 2015-11-05 03:55 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2016-01-19 04:47 - 2015-11-05 03:42 - 00303104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2016-01-19 03:08 - 2016-01-19 00:14 - 00000000 ____D C:\Users\Paige Perry\AppData\Local\MicrosoftEdge
2016-01-19 02:59 - 2016-01-19 02:59 - 00000000 ____D C:\Users\Paige Perry\AppData\Local\Comms
2016-01-19 02:58 - 2016-01-19 03:08 - 00000000 ____D C:\Data
2016-01-19 02:45 - 2016-01-19 02:45 - 00000000 ____D C:\Users\Paige Perry\AppData\Local\ActiveSync
2016-01-19 02:44 - 2016-01-29 22:24 - 00002381 _____ C:\Users\Paige Perry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-01-19 02:44 - 2016-01-29 22:24 - 00000000 ___RD C:\Users\Paige Perry\OneDrive
2016-01-19 02:44 - 2016-01-19 02:44 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2016-01-19 02:43 - 2016-01-31 14:11 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-01-19 02:43 - 2016-01-20 13:56 - 00000000 ____D C:\Users\Paige Perry\AppData\Local\Packages
2016-01-19 02:43 - 2016-01-19 02:43 - 00000000 ____D C:\Users\Paige Perry\AppData\Roaming\Adobe
2016-01-19 02:43 - 2016-01-19 02:43 - 00000000 ____D C:\Users\Paige Perry\AppData\Local\VirtualStore
2016-01-19 02:43 - 2016-01-19 02:43 - 00000000 ____D C:\Users\Paige Perry\AppData\Local\TileDataLayer
2016-01-19 02:43 - 2016-01-19 02:43 - 00000000 ____D C:\Users\Paige Perry\AppData\Local\Publishers
2016-01-19 02:42 - 2016-02-04 14:14 - 00000000 ____D C:\Users\Paige Perry
2016-01-19 02:42 - 2016-01-19 02:42 - 00000020 ___SH C:\Users\Paige Perry\ntuser.ini
2016-01-19 02:42 - 2016-01-19 02:42 - 00000000 _SHDL C:\Users\Paige Perry\My Documents
2016-01-19 02:42 - 2016-01-19 02:42 - 00000000 _SHDL C:\Users\Paige Perry\Documents\My Videos
2016-01-19 02:42 - 2016-01-19 02:42 - 00000000 _SHDL C:\Users\Paige Perry\Documents\My Pictures
2016-01-19 02:42 - 2016-01-19 02:42 - 00000000 _SHDL C:\Users\Paige Perry\Documents\My Music
2016-01-19 02:40 - 2016-02-05 13:12 - 00879220 _____ C:\Windows\system32\PerfStringBackup.INI
2016-01-19 02:38 - 2015-10-30 02:17 - 02718208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2016-01-19 02:37 - 2016-01-19 02:37 - 00000000 ____D C:\ProgramData\USOShared
2016-01-19 02:36 - 2016-02-05 13:07 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-01-19 02:36 - 2016-01-19 02:36 - 00000000 _SHDL C:\Users\Public\Documents\My Videos
2016-01-19 02:36 - 2016-01-19 02:36 - 00000000 _SHDL C:\Users\Public\Documents\My Pictures
2016-01-19 02:36 - 2016-01-19 02:36 - 00000000 _SHDL C:\Users\Public\Documents\My Music
2016-01-19 02:36 - 2016-01-19 02:36 - 00000000 _SHDL C:\Users\Default\My Documents
2016-01-19 02:36 - 2016-01-19 02:36 - 00000000 _SHDL C:\Users\Default\Documents\My Videos
2016-01-19 02:36 - 2016-01-19 02:36 - 00000000 _SHDL C:\Users\Default\Documents\My Pictures
2016-01-19 02:36 - 2016-01-19 02:36 - 00000000 _SHDL C:\Users\Default\Documents\My Music
2016-01-19 02:36 - 2016-01-19 02:36 - 00000000 _SHDL C:\Users\Default User\Documents\My Videos
2016-01-19 02:36 - 2016-01-19 02:36 - 00000000 _SHDL C:\Users\Default User\Documents\My Pictures
2016-01-19 02:36 - 2016-01-19 02:36 - 00000000 _SHDL C:\Users\Default User\Documents\My Music
2016-01-19 02:36 - 2016-01-19 02:36 - 00000000 _SHDL C:\Documents and Settings
2016-01-19 02:35 - 2016-01-19 15:20 - 00189240 _____ C:\Windows\system32\FNTCACHE.DAT
2016-01-19 02:34 - 2016-02-01 12:08 - 00000000 ____D C:\Windows\Panther
2016-01-19 01:40 - 2016-01-19 01:40 - 00000000 ____D C:\Users\Paige Perry\AppData\Roaming\Macromedia
2016-01-19 00:20 - 2016-01-19 12:24 - 00000000 ____D C:\Intel
2016-01-19 00:20 - 2016-01-19 00:20 - 00000000 ____D C:\Program Files (x86)\Intel

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-02-05 14:53 - 2015-10-30 02:24 - 00000000 ____D C:\Windows\AppReadiness
2016-02-05 13:12 - 2015-10-30 02:21 - 00000000 ____D C:\Windows\INF
2016-02-05 12:13 - 2015-10-30 01:28 - 00524288 ___SH C:\Windows\system32\config\BBI
2016-02-05 12:11 - 2015-10-30 02:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-02-02 22:44 - 2015-10-30 02:24 - 00000000 ____D C:\Windows\LiveKernelReports
2016-02-01 17:27 - 2015-10-30 02:11 - 00000000 ____D C:\Windows\CbsTemp
2016-01-30 01:43 - 2015-10-30 02:24 - 00000000 ____D C:\Windows\Registration
2016-01-29 09:14 - 2015-10-30 02:24 - 00000000 ____D C:\Windows\rescache
2016-01-28 08:55 - 2015-10-30 02:24 - 00000000 ____D C:\Windows\appcompat
2016-01-28 08:51 - 2015-10-30 02:24 - 00000000 ___SD C:\Windows\system32\F12
2016-01-28 08:51 - 2015-10-30 02:24 - 00000000 ___RD C:\Windows\PurchaseDialog
2016-01-28 08:51 - 2015-10-30 02:24 - 00000000 ___RD C:\Windows\ImmersiveControlPanel
2016-01-28 08:51 - 2015-10-30 02:24 - 00000000 ____D C:\Windows\system32\WinBioPlugIns
2016-01-28 08:51 - 2015-10-30 02:24 - 00000000 ____D C:\Windows\system32\oobe
2016-01-28 08:51 - 2015-10-30 02:24 - 00000000 ____D C:\Windows\system32\appraiser
2016-01-28 08:51 - 2015-10-30 02:24 - 00000000 ____D C:\Windows\bcastdvr
2016-01-19 15:19 - 2015-10-30 02:24 - 00000000 ____D C:\Windows\system32\SystemResetPlatform
2016-01-19 15:19 - 2015-10-30 02:24 - 00000000 ____D C:\Windows\Provisioning
2016-01-19 15:19 - 2015-10-30 01:28 - 00000000 ____D C:\Windows\SysWOW64\Dism
2016-01-19 15:19 - 2015-10-30 01:28 - 00000000 ____D C:\Windows\system32\Dism
2016-01-19 02:59 - 2015-10-30 02:24 - 00000000 ___RD C:\Windows\DevicesFlow
2016-01-19 02:43 - 2015-10-30 02:24 - 00000000 ___RD C:\Windows\PrintDialog
2016-01-19 02:43 - 2015-10-30 02:24 - 00000000 ___RD C:\Windows\MiracastView
2016-01-19 02:42 - 2015-10-30 02:24 - 00000000 ____D C:\Windows\system32\WinBioDatabase
2016-01-19 02:38 - 2015-10-30 02:24 - 00000000 ____D C:\Windows\system32\spool
2016-01-19 02:38 - 2015-10-30 02:24 - 00000000 ____D C:\Windows\system32\FxsTmp
2016-01-19 02:37 - 2015-10-30 02:24 - 00000000 ____D C:\ProgramData\USOPrivate
2016-01-19 02:36 - 2015-10-30 01:28 - 00032768 ___SH C:\Windows\system32\config\ELAM
2016-01-19 02:35 - 2015-10-30 04:13 - 00000000 ____D C:\Windows\ServiceProfiles
2016-01-19 02:35 - 2015-10-30 01:28 - 00000000 ____D C:\Windows\system32\Sysprep
2016-01-19 02:34 - 2015-10-30 02:24 - 00028672 _____ C:\Windows\system32\config\BCD-Template

==================== Files in the root of some directories =======

2016-02-02 20:48 - 2016-02-02 20:48 - 0000017 _____ () C:\Users\georg\AppData\Local\resmon.resmoncfg
2016-01-22 04:06 - 2016-01-22 04:06 - 0000057 _____ () C:\ProgramData\Ament.ini

Some files in TEMP:
====================
C:\Users\georg\AppData\Local\Temp\speccycpuid.dll
C:\Users\georg\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-02-01 10:31

==================== End of FRST.txt ============================

Attached Files


Edited by paigeorge, 05 February 2016 - 05:25 PM.


BC AdBot (Login to Remove)

 


#2 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 38,200 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:27 AM

Posted 09 February 2016 - 10:34 AM

Greetings paigeorge and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

===================================================

Ground Rules:
  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met.
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • When you post your reply, use the Replytopic.jpg button instead.
  • In the upper right hand corner of the topic you will see the Followtopic.jpg button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far.

There is no evidence of malicious software on your computer. If you desire to have your internet traffic evaluated I would suggest you start a topic in the Networking Forum.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"For unto us a Child is born, Unto us a Son is given;"

#3 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 38,200 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:27 AM

Posted 11 February 2016 - 04:33 PM

I am going to close this Topic since it is not malware related. Feel free to send me a Personal Message if necessary.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"For unto us a Child is born, Unto us a Son is given;"

#4 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 38,200 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:27 AM

Posted 11 February 2016 - 04:33 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"For unto us a Child is born, Unto us a Son is given;"




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users