I'm not sure if I am infected or not. My problems began to appear when Norton Security updated itself to the latest version via Norton's LiveUpdate feature. After that, the browser protection and exploit prevention settings of NS turned themselves off. Turning these features back on manually would cause them to turn off again after about 30 seconds.
At that point I ran Malwarebytes, which reported an infection with PUP.Optional.CrossRider. I followed the instructions for removal that I found here: https://malwaretips.com/blogs/pup-optional-crossrider-virus/. Malwarebytes no longer reports any infection. This partially changed the behavior of Norton Security, in that it now allows me to set browser protection on. However, if I turn on exploit prevention, it continues to turn both browser protection and exploit protection off. In short, I cannot leave exploit protection turned on without having both it and browser protection turned off after about 30 seconds.
I posted a question to the Norton Security forum and received a reply that my computer may continue to be infected; they are uncertain if the problem is with malware or a possible (as yet unreported) bug in the latest version of NS. They have asked me to ensure that I have no malware on my computer before I contact them again.
I have run FRST, and I paste the FRST.txt file below, as well as attach the Addition.txt file.
I greatly appreciate any support.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
Ran by Bill Pierce (administrator) on PORKY (13-03-2016 16:32:41)
Running from C:\Users\Bill Pierce\Desktop
Loaded Profiles: Bill Pierce (Available Profiles: Bill Pierce & DefaultAppPool)
Platform: Windows 10 Pro Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\Start10\Start10Srv.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\ModernMix\MMixSrv.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\Start10\Start10_64.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agr64svc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(MSI) C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(MSI) C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
(MSI) C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Symantec) C:\Program Files (x86)\Symantec\Norton Utilities 16\sMonitor\StartManSvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\mDNSResponder.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Security\Engine\22.6.0.142\ns.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(VMLite, Inc.) C:\Program Files\VMLite\VMLite Workstation\VMLiteService.exe
(Research In Motion Limited) C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\tunmgr.exe
(MSI) C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe
(Traysoft Inc.) C:\Program Files (x86)\PhoneTray\PhoneTrayService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(BlackBerry Limited) C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Security\Engine\22.6.0.142\ns.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\ModernMix\MMix_64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\ModernMix\MMix_32.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Abine Inc.) C:\Program Files (x86)\DoNotTrackMe\AbineAutoUpdate.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(NewSoft Technology Corporation) C:\Windows\System32\spool\drivers\x64\3\WrtMon.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe
(NewSoft Technology Corporation) C:\Windows\System32\spool\drivers\x64\3\WrtProc.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Traysoft Inc.) C:\Program Files (x86)\PhoneTray\PhoneTray.exe
(BlackBerry Limited) C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
(Research In Motion Limited) C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\PeerManager.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Utilities 16\sMonitor\SSDMonitor.exe
(MSI) C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe
(Micro-Star INT'L CO.,LTD.) C:\Program Files (x86)\MSI\Fast Boot\FastBoot.exe
(TP-LINK) C:\Program Files (x86)\TP-LINK\USB Printer Controller\USB Printer Controller.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Live Update\Live Update.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\CSISYNCCLIENT.EXE
() C:\Program Files (x86)\Common Files\Research In Motion\nginx\nginx.exe
() C:\Program Files (x86)\Common Files\Research In Motion\nginx\nginx.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSYNC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel® Corporation) C:\Program Files (x86)\Intel\Intel® Extreme Tuning Utility\XtuService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Abine Inc.) C:\Program Files (x86)\DoNotTrackMe\5.5.1930\AbineService.exe
(Eyeo GmbH) C:\Program Files\Adblock Plus for IE\AdblockPlusEngine.exe
(VMLite, Inc.) C:\Program Files\VMLite\VMLite Workstation\VBoxSVC.exe
(VMLite, Inc.) C:\Program Files\VMLite\VMLite Workstation\VMLite.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.302.8200.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Realtek Semiconductor) C:\Program Files (x86)\MSI\NetworkGenie\NetworkGenie.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8725248 2015-10-16] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2789248 2016-02-17] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [MBCfg64] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\MBCfg64.dll,RunDLLEntry MBCfg64
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-12-17] (Apple Inc.)
HKLM\...\Run: [WrtMon.exe] => C:\WINDOWS\system32\spool\drivers\x64\3\WrtMon.exe [26448 2008-05-24] (NewSoft Technology Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [NPSStartup] => [X]
HKLM-x32\...\Run: [RIMBBLaunchAgent.exe] => C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [443408 2014-02-07] (BlackBerry Limited)
HKLM-x32\...\Run: [RIM PeerManager] => C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\PeerManager.exe [4465152 2013-11-28] (Research In Motion Limited)
HKLM-x32\...\Run: [Sound Blaster Cinema] => C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe [711680 2013-08-16] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE
HKLM-x32\...\Run: [JMB36X IDE Setup] => C:\WINDOWS\RaidTool\xInsIDE.exe
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [25122080 2016-02-16] (Dropbox, Inc.)
HKLM-x32\...\Run: [SSDMonitor] => C:\Program Files (x86)\Symantec\Norton Utilities 16\sMonitor\SSDMonitor.exe [106112 2015-08-14] (Symantec Corporation)
HKLM-x32\...\Run: [Fast Boot] => C:\Program Files (x86)\MSI\Fast Boot\StartFastBoot.exe [759120 2015-04-22] ()
HKLM-x32\...\Run: [Super Charger] => C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe [1027024 2015-09-09] (MSI)
HKLM-x32\...\Run: [TP-LINK USB Printer Controller] => C:\Program Files (x86)\TP-LINK\USB Printer Controller\USB Printer Controller.exe [4265984 2014-06-19] (TP-LINK)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [594992 2016-01-29] (Oracle Corporation)
HKLM-x32\...\Run: [Live Update] => C:\Program Files (x86)\MSI\Live Update\Live Update.exe [11336656 2016-02-04] (Micro-Star INT'L CO., LTD.)
HKLM-x32\...\Run: [Command Center] => C:\Program Files (x86)\MSI\Command Center\StartCommandCenter.exe [830416 2016-02-16] (MSI)
HKLM-x32\...\RunOnce: [AbineAutoUpdate] => C:\Program Files (x86)\DoNotTrackMe\AbineAutoUpdate.exe [126704 2016-01-28] (Abine Inc.)
Winlogon\Notify\PCANotify-x32: PCANotify.dll [X]
HKLM\...\Policies\Explorer: [NoRecentDocsNetHood] 0
HKLM\...\Policies\Explorer: [NoChangeStartMenu] 0
HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore: [DisableSR/DisableConfig] <===== ATTENTION
HKU\S-1-5-21-2422629387-1192540806-1023300286-1001\...\Run: [TomTomHOME.exe] => C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe [248176 2015-07-13] (TomTom)
HKU\S-1-5-21-2422629387-1192540806-1023300286-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Bill Pierce\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-30] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2422629387-1192540806-1023300286-1001\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1403304 2016-01-28] (Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-2422629387-1192540806-1023300286-1001\...\RunOnce: [Uninstall C:\Users\Bill Pierce\AppData\Local\Microsoft\OneDrive\17.3.6301.0127_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Bill Pierce\AppData\Local\Microsoft\OneDrive\17.3.6301.0127_1\amd64"
HKU\S-1-5-21-2422629387-1192540806-1023300286-1001\...\RunOnce: [Uninstall C:\Users\Bill Pierce\AppData\Local\Microsoft\OneDrive\17.3.6301.0127_1] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Bill Pierce\AppData\Local\Microsoft\OneDrive\17.3.6301.0127_1"
HKU\S-1-5-21-2422629387-1192540806-1023300286-1001\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-2422629387-1192540806-1023300286-1001\...\Policies\Explorer: [NoPreviewPane] 0
HKU\S-1-5-21-2422629387-1192540806-1023300286-1001\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-2422629387-1192540806-1023300286-1001\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-2422629387-1192540806-1023300286-1001\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-2422629387-1192540806-1023300286-1001\...\Policies\Explorer: [TaskbarNoNotification] 0
HKU\S-1-5-21-2422629387-1192540806-1023300286-1001\...\Policies\Explorer: [NoWinkeys] 0
HKU\S-1-5-21-2422629387-1192540806-1023300286-1001\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-2422629387-1192540806-1023300286-1001\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-2422629387-1192540806-1023300286-1001\...\Policies\Explorer: [HideSCANetwork] 0
HKU\S-1-5-21-2422629387-1192540806-1023300286-1001\...\Policies\Explorer: [HideSCAVolume] 0
HKU\S-1-5-21-2422629387-1192540806-1023300286-1001\...\MountPoints2: {108509b9-de63-11e5-8297-448a5b5da8ba} - "V:\setup.exe"
HKU\S-1-5-21-2422629387-1192540806-1023300286-1001\...\MountPoints2: {bae2eff5-df38-11e5-8297-448a5b5da8ba} - "V:\setup.exe"
HKU\S-1-5-21-2422629387-1192540806-1023300286-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\Mystify.scr [150528 2015-10-30] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-02-24] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-02-24] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-02-24] (Google)
ShellIconOverlayIdentifiers: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton Security\Engine64\22.6.0.142\buShell.dll [2016-02-18] (Symantec Corporation)
ShellIconOverlayIdentifiers: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton Security\Engine64\22.6.0.142\buShell.dll [2016-02-18] (Symantec Corporation)
ShellIconOverlayIdentifiers: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton Security\Engine64\22.6.0.142\buShell.dll [2016-02-18] (Symantec Corporation)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Bill Pierce\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64\FileSyncShell64.dll [2016-03-11] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Bill Pierce\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64\FileSyncShell64.dll [2016-03-11] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Bill Pierce\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64\FileSyncShell64.dll [2016-03-11] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00HumyoPaired] -> {A203F945-39E9-4286-AFA2-F3ADFCD5FAAA} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll [2012-11-13] (Trend Micro Inc.)
ShellIconOverlayIdentifiers: [00HumyoPriority] -> {6F1BB626-1107-4b82-B322-54C5E64461B8} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll [2012-11-13] (Trend Micro Inc.)
ShellIconOverlayIdentifiers: [00HumyoProblem] -> {7479C9AF-DA81-4944-92E5-23E49390BB2B} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll [2012-11-13] (Trend Micro Inc.)
ShellIconOverlayIdentifiers: [00HumyoSynced] -> {7479C9AF-DA81-4944-92E5-23E49390BB2A} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll [2012-11-13] (Trend Micro Inc.)
ShellIconOverlayIdentifiers: [00HumyoSyncing] -> {7479C9AF-DA81-4944-92E5-23E49390BB29} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll [2012-11-13] (Trend Micro Inc.)
ShellIconOverlayIdentifiers: [00HumyoUnavailable] -> {66669544-5639-4922-99C8-CE7A86651364} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll [2012-11-13] (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Bill Pierce\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileSyncShell.dll [2016-03-11] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Bill Pierce\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileSyncShell.dll [2016-03-11] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Bill Pierce\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileSyncShell.dll [2016-03-11] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [00HumyoPaired] -> {A203F945-39E9-4286-AFA2-F3ADFCD5FAAA} => No File
ShellIconOverlayIdentifiers-x32: [00HumyoPriority] -> {6F1BB626-1107-4b82-B322-54C5E64461B8} => No File
ShellIconOverlayIdentifiers-x32: [00HumyoProblem] -> {7479C9AF-DA81-4944-92E5-23E49390BB2B} => No File
ShellIconOverlayIdentifiers-x32: [00HumyoSynced] -> {7479C9AF-DA81-4944-92E5-23E49390BB2A} => No File
ShellIconOverlayIdentifiers-x32: [00HumyoSyncing] -> {7479C9AF-DA81-4944-92E5-23E49390BB29} => No File
ShellIconOverlayIdentifiers-x32: [00HumyoUnavailable] -> {66669544-5639-4922-99C8-CE7A86651364} => No File
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PhoneTray.lnk [2015-02-22]
ShortcutTarget: PhoneTray.lnk -> C:\Program Files (x86)\PhoneTray\PhoneTray.exe (Traysoft Inc.)
Startup: C:\Users\Bill Pierce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2015-10-02]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation)
GroupPolicy: Restriction - Chrome <======= ATTENTION
GroupPolicyScripts: Restriction <======= ATTENTION
GroupPolicyScripts\User: Restriction <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\..\Interfaces\{2537fcef-de02-4814-9783-4d7073d82a07}: [NameServer] 199.85.126.10,199.85.127.10
Tcpip\..\Interfaces\{cbe2ab92-4022-4e70-a852-48bcfddcaf7c}: [NameServer] 24.226.1.93,24.226.1.94,24.226.10.193,24.226.10.194
Internet Explorer:
==================
HKU\S-1-5-21-2422629387-1192540806-1023300286-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
SearchScopes: HKU\S-1-5-21-2422629387-1192540806-1023300286-1001 -> DefaultScope {C545710C-2BD9-47F8-A661-8AA552047308} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}&rlz=
SearchScopes: HKU\S-1-5-21-2422629387-1192540806-1023300286-1001 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxps://nortonsafe.search.ask.com/web?q={searchTerms}&o=APN11913&l=dis&prt=NS&chn=1000&geo=US&ver=22&locale=en_US&gct=kwd&qsrc=2869
SearchScopes: HKU\S-1-5-21-2422629387-1192540806-1023300286-1001 -> {C545710C-2BD9-47F8-A661-8AA552047308} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}&rlz=
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-03-12] (Microsoft Corporation)
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Security\Engine64\22.6.0.142\coIEPlg.dll [2016-02-21] (Symantec Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-18] (Google Inc.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
BHO: Blur BHO -> {C584D6D2-EF22-4C61-BF5B-0C7E723D836C} -> C:\Program Files (x86)\DoNotTrackMe\5.5.1930\AbineBHO64.dll [2016-01-28] (Abine Inc.)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-03-12] (Microsoft Corporation)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-09-22] (Eyeo GmbH)
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Security\Engine\22.6.0.142\coIEPlg.dll [2016-02-21] (Symantec Corporation)
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\ssv.dll [2016-02-07] (Oracle Corporation)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-11-10] (Microsoft Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
BHO-x32: Blur BHO -> {C584D6D2-EF22-4C61-BF5B-0C7E723D836C} -> C:\Program Files (x86)\DoNotTrackMe\5.5.1930\AbineBHO.dll [2016-01-28] (Abine Inc.)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-07] (Oracle Corporation)
BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-09-22] (Eyeo GmbH)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-18] (Google Inc.)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security\Engine64\22.6.0.142\coIEPlg.dll [2016-02-21] (Symantec Corporation)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - No File
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security\Engine\22.6.0.142\coIEPlg.dll [2016-02-21] (Symantec Corporation)
DPF: HKLM-x32 {01025D1C-BB03-4369-8344-732CD0DCCCF0} hxxp://www.geforce.com/services_toolkit/ShimGen/1.1.28.1/GPU_Reader.cab
DPF: HKLM-x32 {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://qtinstall.apple.com/qtactivex/qtplugin.cab
DPF: HKLM-x32 {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} hxxp://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab
DPF: HKLM-x32 {0742B9EF-8C83-41CA-BFBA-830A59E23533} hxxps://oas.support.microsoft.com/ActiveX/MSDcode.cab
DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: HKLM-x32 {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: HKLM-x32 {22945A69-1191-4DCF-9E6F-409BDE94D101} hxxp://chil.solidworks.com/htdocs/pdownload/edrawings/e2011sp03/cab//eModelsStandard.cab
DPF: HKLM-x32 {44990B00-3C9D-426D-81DF-AAB636FA4345} hxxps://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlcm.cab
DPF: HKLM-x32 {4871A87A-BFDD-4106-8153-FFDE2BAC2967} hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.8.cab
DPF: HKLM-x32 {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1350216267514
DPF: HKLM-x32 {6C269571-C6D7-4818-BCA4-32A035E8C884} hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab
DPF: HKLM-x32 {74DBCB52-F298-4110-951D-AD2FF67BC8AB} hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: HKLM-x32 {82774781-8F4E-11D1-AB1C-0000F8773BF0} hxxps://transfers.ds.microsoft.com/FTM/TransferSource/grTransferCtrl.cab
DPF: HKLM-x32 {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: HKLM-x32 {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} hxxp://content.systemrequirementslab.com/bin/srldetect_intel_4.5.24.0.cab
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: HKLM-x32 {ED28050F-D713-43BA-A376-DCC5C35407D5} hxxp://entjs.msn.com/client/msnmusax9302.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab
DPF: HKLM-x32 {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} hxxp://www.trueswitch.com/TrueInstall.exe
Handler-x32: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\BelarcAdvisor\System\BAVoilaX.dll [2015-08-05] (Belarc, Inc.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-03-12] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-03-12] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-03-12] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-03-12] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
Edge:
======
Edge HomeButtonPage: HKU\S-1-5-21-2422629387-1192540806-1023300286-1001 -> hxxp://www.excite.com/
FireFox:
========
FF Plugin: @garmin.com/GpsControl -> C:\Program Files\Garmin GPS Plugin\npGarmin.dll [2014-03-31] (GARMIN Corp.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 -> C:\Program Files (x86)\Virtual Earth 3D\ [] ()
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-16] (VideoLAN)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-07-30] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2010-04-15] (CANON INC.)
FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll [2014-03-31] (GARMIN Corp.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-02-07] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-02-07] (Oracle Corporation)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll [2011-08-22] (Yahoo! Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-03-12] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/VirtualEarth3D,version=4.0 -> C:\Program Files (x86)\Virtual Earth 3D\ [] ()
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-10-13] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-10-13] (NVIDIA Corporation)
FF Plugin-x32: @real.com/nppl3260;version=6.0.12.448 -> C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nppl3260.dll [2010-02-04] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.448 -> C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nprpjplug.dll [2010-02-04] (RealNetworks, Inc.)
FF Plugin-x32: @rim.com/npappworld -> C:\Program Files (x86)\Research In Motion Limited\BlackBerry App World Browser Plugin\npappworld.dll [2013-04-11] ()
FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll [2014-04-30] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Extension: No Name - C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ff [not found]
FF Extension: No Name - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha5\ff [not found]
FF Extension: No Name - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta714\ff [not found]
FF Extension: No Name - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha569\ff [not found]
FF Extension: No Name - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1535\ff [not found]
FF Extension: No Name - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha975\ff [not found]
FF Extension: No Name - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha8533\ff [not found]
FF Extension: No Name - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home589\ff [not found]
FF Extension: No Name - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode2937\ff [not found]
FF HKLM\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NS_22.5.5.15\coFFAddon
FF Extension: Norton Identity Safe - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NS_22.5.5.15\coFFAddon [2016-03-02]
FF HKLM-x32\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NS_22.5.5.15\coFFAddon
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.ca/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\Bill Pierce\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Bill Pierce\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-09]
CHR Extension: (Google Drive) - C:\Users\Bill Pierce\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-25]
CHR Extension: (YouTube) - C:\Users\Bill Pierce\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-25]
CHR Extension: (Adblock Plus) - C:\Users\Bill Pierce\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-02-24]
CHR Extension: (Norton Security Toolbar) - C:\Users\Bill Pierce\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe [2016-02-04]
CHR Extension: (Google Search) - C:\Users\Bill Pierce\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-01]
CHR Extension: (Blur) - C:\Users\Bill Pierce\AppData\Local\Google\Chrome\User Data\Default\Extensions\epanfjkfahimkgomnigadpkobaefekcd [2016-02-04]
CHR Extension: (Google Docs Offline) - C:\Users\Bill Pierce\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-12-15]
CHR Extension: (Norton Identity Safe) - C:\Users\Bill Pierce\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif [2014-08-14]
CHR Extension: (Norton Safe) - C:\Users\Bill Pierce\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmgcfemagnogdodbambjhdcmfcpicngl [2014-09-12]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Bill Pierce\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-29]
CHR Extension: (pflmllfnnabikmfkkaddkoolinlfninn) - C:\Users\Bill Pierce\AppData\Local\Google\Chrome\User Data\Default\Extensions\pflmllfnnabikmfkkaddkoolinlfninn [2014-10-18]
CHR Extension: (Gmail) - C:\Users\Bill Pierce\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-04]
CHR HKLM\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Security\Engine\22.6.0.142\Exts\Chrome.crx [2016-03-02]
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ahmcccagmbagkpbdgpammblejlmiempb] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Security\Engine\22.6.0.142\Exts\Chrome.crx [2016-03-02]
CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 APC UPS Service; C:\Program Files (x86)\APC\APC PowerChute Personal Edition\mainserv.exe [689464 2009-01-06] (American Power Conversion Corporation)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.)
R3 BlackBerry Device Manager; C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [585728 2014-01-21] (BlackBerry Limited) [File not signed]
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2804976 2016-02-28] (Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [134512 2015-07-03] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [134512 2015-07-03] (Dropbox, Inc.)
S3 DiskDoctorService; C:\Program Files (x86)\Symantec\Norton Utilities 16\Tools\Disk Doctor\DiskDoctorSrv.exe [1147424 2012-09-29] (Symantec Corporation)
S2 ESRV_SVC_WILLAMETTE; C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe [414360 2015-09-14] ()
S4 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [626208 2009-08-10] ()
S2 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [803856 2016-01-28] (Garmin Ltd. or its subsidiaries)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1164672 2016-02-17] (NVIDIA Corporation)
S2 gupdate1c9e5f5de612b20; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc.)
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel® Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
R2 ModernMix; C:\Program Files (x86)\Stardock\ModernMix\MMixSrv.exe [74296 2014-06-12] (Stardock Software, Inc)
S3 MSIClock_CC; C:\Program Files (x86)\MSI\Command Center\ClockGen\MSIClockService.exe [4162512 2016-02-04] (MSI)
S3 MSICOMM_CC; C:\Program Files (x86)\MSI\Command Center\MSICommService.exe [2200872 2016-02-01] (MSI)
S3 MSICPU_CC; C:\Program Files (x86)\MSI\Command Center\CPU\MSICPUService.exe [4162512 2016-02-04] (MSI)
R2 MSICTL_CC; C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe [2013648 2016-02-16] (MSI)
R2 MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe [2312144 2016-02-22] (MSI)
S3 MSISMB_CC; C:\Program Files (x86)\MSI\Command Center\SMBus\MSISMBService.exe [2073040 2016-02-04] (MSI)
S3 MSISuperIO_CC; C:\Program Files (x86)\MSI\Command Center\SuperIO\MSISuperIOService.exe [596944 2016-02-01] (MSI)
R2 MSI_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe [105296 2015-06-04] (MSI)
R2 MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [1787344 2016-02-05] (Micro-Star INT'L CO., LTD.)
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe [163280 2015-05-18] (MSI)
S2 MSI_Trigger_Service; C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe [30240 2013-09-26] (MICRO-STAR INTERNATIONAL CO., LTD.)
S4 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [537896 2008-12-12] (Nero AG)
R2 NS; C:\Program Files (x86)\Norton Security\Engine\22.6.0.142\NS.exe [289080 2016-02-26] (Symantec Corporation)
S4 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [206880 2009-08-10] ()
S4 nTuneService; C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe [180224 2007-09-04] (NVIDIA) [File not signed]
R2 NU16StartManagerSvc; C:\Program Files (x86)\Symantec\Norton Utilities 16\sMonitor\StartManSvc.exe [792608 2012-09-29] (Symantec)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1880960 2016-02-17] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6474112 2016-02-17] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2609024 2016-02-17] (NVIDIA Corporation)
R2 PhoneTrayService; C:\Program Files (x86)\PhoneTray\PhoneTrayService.exe [14696 2015-02-21] (Traysoft Inc.)
R2 RIM MDNS; C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\mDNSResponder.exe [389632 2013-11-28] (Apple Inc.) [File not signed]
R2 RIM Tunnel Service; C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\tunmgr.exe [1304064 2013-11-28] (Research In Motion Limited) [File not signed]
S4 ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [620544 2008-11-11] (Nokia.) [File not signed]
S4 SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [79360 2011-05-22] (SolidWorks) [File not signed]
S3 SpeedDiskService; C:\Program Files (x86)\Symantec\Norton Utilities 16\Tools\SpeedDisk\SpeedDiskSrv.exe [1160224 2012-09-29] (Symantec Corporation)
R2 Start10; C:\Program Files (x86)\Stardock\Start10\Start10Srv.exe [219664 2015-02-03] (Stardock Software, Inc)
S2 SuperRAIDSvc; C:\MSI\Smart Utilities\SuperRAIDSvc.exe [29648 2015-02-09] (Micro-Star INT'L CO., LTD.)
S4 Symantec RemoteAssist; C:\Program Files (x86)\Common Files\Symantec Shared\Support Controls\ssrc.exe [394704 2008-01-29] (Symantec, Inc.)
S2 SystemUsageReportSvc_WILLAMETTE; C:\Program Files (x86)\Intel Driver Update Utility\SUR\SurSvc.exe [112792 2015-09-14] ()
S4 UpdateCenterService; C:\Program Files (x86)\NVIDIA Corporation\System Update\UpdateCenterService.exe [282728 2009-11-06] (NVIDIA)
S3 USER_ESRV_SVC_WILLAMETTE; C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe [414360 2015-09-14] ()
R2 VMLiteService; C:\Program Files\VMLite\VMLite Workstation\VMLiteService.exe [426600 2010-08-21] (VMLite, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
R2 XTU3SERVICE; C:\Program Files (x86)\Intel\Intel® Extreme Tuning Utility\XtuService.exe [19216 2015-07-07] (Intel® Corporation)
S2 NSL; "C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe" /s "NSL" /m "C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\diMaster.dll" /prefetch:1
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 Achernar; C:\Windows\System32\Drivers\Achernar.sys [34104 2016-02-04] (NewSoft Technology Corporation)
S3 AcpiCtlDrv; C:\Windows\System32\drivers\AcpiCtlDrv.sys [25880 2012-07-17] (Intel Corporation)
R1 BHDrvx64; C:\Program Files (x86)\Norton Security\NortonData\22.5.5.15\Definitions\BASHDefs\20160309.001_60c\BHDrvx64.sys [1766640 2016-03-09] (Symantec Corporation)
R1 ccSet_NS; C:\Windows\system32\drivers\NSx64\1606000.08E\ccSetx64.sys [173808 2015-11-11] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [498512 2016-02-04] (Symantec Corporation)
S3 ENTECH64; C:\Windows\system32\DRIVERS\ENTECH64.sys [12744 2008-04-22] (EnTech Taiwan)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [157520 2016-02-04] (Symantec Corporation)
S3 i8042HDR; C:\Windows\system32\DRIVERS\i8042HDR.sys [15920 2009-08-15] (Windows ® Codename Longhorn DDK provider)
R1 IDSVia64; C:\Program Files (x86)\Norton Security\NortonData\22.5.5.15\Definitions\IPSDefs\20160311.001\IDSvia64.sys [767224 2016-03-01] (Symantec Corporation)
R3 ikbevent; C:\Windows\system32\DRIVERS\ikbevent.sys [22216 2014-05-27] ()
R3 imsevent; C:\Windows\system32\DRIVERS\imsevent.sys [22728 2014-05-27] ()
R2 iocbios2; C:\Program Files (x86)\Intel\Intel® Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [30224 2015-05-28] (Intel Corporation)
R3 ISCT; C:\Windows\System32\drivers\ISCTD.sys [44744 2014-05-27] ()
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton Security\NortonData\22.5.5.15\Definitions\VirusDefs\20160313.003\ENG64.SYS [138488 2016-03-10] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton Security\NortonData\22.5.5.15\Definitions\VirusDefs\20160313.003\EX64.SYS [2148080 2016-03-10] (Symantec Corporation)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI)
S3 NTIOLib_1_0_6; C:\Program Files (x86)\Setup Files\Ms7850v170\NTIOLib_X64.sys [11888 2011-01-06] (MSI) [File not signed]
R3 NTIOLib_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\NTIOLib_X64.sys [13368 2012-10-26] (MSI)
R3 NTIOLib_MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\NTIOLib_X64.sys [13368 2012-11-26] (MSI)
S3 NTIOLib_MSI_RAID; C:\MSI\Smart Utilities\NTIOLib_X64.sys [13808 2014-03-17] (MSI)
S3 NVR0Dev; C:\Windows\nvoclk64.sys [39968 2007-09-04] (NVidia Corp.)
U5 nvstor64; C:\Windows\System32\Drivers\nvstor64.sys [244328 2010-04-09] (NVIDIA Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28032 2016-02-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation)
R2 OkiPar64; C:\Windows\System32\DRIVERS\OKIPAR64.SYS [46600 2007-11-14] (Oki Data Corporation)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [79872 2013-12-02] (BlackBerry Limited)
R3 rimvndis; C:\Windows\System32\Drivers\rimvndis6_AMD64.sys [17920 2013-09-12] (Research in Motion Limited)
R3 RimVSerPort; C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys [44544 2012-12-10] (Research in Motion Ltd)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [886528 2015-05-29] (Realtek )
S1 SBRE; C:\Windows\system32\drivers\SBREdrv.sys [55384 2011-06-28] (Sunbelt Software)
S3 semav6msr64; C:\WINDOWS\system32\drivers\semav6msr64.sys [21984 2015-06-04] ()
R3 SRTSP; C:\Windows\System32\Drivers\NSx64\1606000.08E\SRTSP64.SYS [928504 2016-02-23] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NSx64\1606000.08E\SRTSPX64.SYS [50936 2015-11-11] (Symantec Corporation)
R0 SymEFASI; C:\Windows\System32\drivers\NSx64\1606000.08E\SYMEFASI64.SYS [1621232 2016-02-23] (Symantec Corporation)
S0 SymELAM; C:\Windows\System32\drivers\NSx64\1606000.08E\SymELAM.sys [24192 2015-11-11] (Symantec Corporation)
R3 SymEvent; C:\WINDOWS\system32\Drivers\SYMEVENT64x86.SYS [111344 2016-03-02] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NSx64\1606000.08E\Ironx64.SYS [295664 2016-02-23] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\NSx64\1606000.08E\SYMNETS.SYS [577768 2016-02-23] (Symantec Corporation)
R3 tplinkUDSMBus; C:\Windows\system32\drivers\TplinkUDSMBus.sys [116936 2014-05-22] (Windows ® Codename Longhorn DDK provider)
R3 tplinkUDSTcpBus; C:\Windows\System32\Drivers\tplinkUDSTcpBus.sys [196296 2014-05-22] (Windows ® Codename Longhorn DDK provider)
R3 USBIPEnum; C:\Windows\System32\drivers\USBIPEnum.sys [52296 2015-12-01] (Windows ® Win 7 DDK provider)
R1 VBoxDrv; C:\Windows\System32\drivers\VBoxDrv.sys [204328 2010-08-11] (VMLite, Inc.)
R3 VBoxNetAdp; C:\Windows\System32\drivers\VBoxNetAdp.sys [146216 2010-08-11] (VMLite, Inc.)
S3 VBoxNetFlt; C:\Windows\system32\DRIVERS\VBoxNetFlt.sys [165800 2010-08-11] (VMLite, Inc.)
R1 vmlitedrv; C:\Windows\System32\drivers\vmlitedrv.sys [14952 2010-08-03] (VMLite, Inc.)
R3 vmlitestor; C:\Windows\System32\drivers\vmlitestor.sys [177768 2010-08-11] (VMLite, Inc.)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
R3 XtuAcpiDriver; C:\Windows\System32\drivers\XtuAcpiDriver.sys [63840 2015-07-10] (Intel Corporation)
U3 idsvc; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-13 16:32 - 2016-03-13 16:33 - 00052314 _____ C:\Users\Bill Pierce\Desktop\FRST.txt
2016-03-13 16:32 - 2016-03-13 16:32 - 00000000 ____D C:\FRST
2016-03-13 16:31 - 2016-03-13 16:32 - 02374144 _____ (Farbar) C:\Users\Bill Pierce\Desktop\FRST64.exe
2016-03-13 07:47 - 2016-03-13 07:48 - 00268884 _____ C:\WINDOWS\Minidump\031316-44625-01.dmp
2016-03-13 07:38 - 2016-03-13 07:38 - 00000306 _____ C:\WINDOWS\Tasks\NUSchedule.job
2016-03-13 03:05 - 2016-03-13 03:05 - 00297540 _____ C:\WINDOWS\Minidump\031316-58906-01.dmp
2016-03-13 03:04 - 2016-03-13 07:47 - 853357357 _____ C:\WINDOWS\MEMORY.DMP
2016-03-12 19:14 - 2016-03-12 19:14 - 00000000 ___HD C:\OneDriveTemp
2016-03-12 19:11 - 2016-03-12 19:11 - 00218764 _____ C:\WINDOWS\Minidump\031216-42890-01.dmp
2016-03-12 19:06 - 2015-08-18 10:51 - 01692840 _____ (MSI) C:\WINDOWS\SysWOW64\muachost.exe
2016-03-12 19:06 - 2013-02-08 12:04 - 00000000 _____ C:\RAMDiskImage.img
2016-03-12 11:51 - 2016-03-12 11:51 - 00002501 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
2016-03-12 11:51 - 2016-03-12 11:51 - 00002500 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
2016-03-12 11:51 - 2016-03-12 11:51 - 00002464 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk
2016-03-12 11:51 - 2016-03-12 11:51 - 00002463 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
2016-03-12 11:51 - 2016-03-12 11:51 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
2016-03-12 11:51 - 2016-03-12 11:51 - 00002451 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
2016-03-12 11:51 - 2016-03-12 11:51 - 00002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2016-03-12 11:51 - 2016-03-12 11:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
2016-03-12 11:41 - 2016-03-12 11:41 - 00000000 ____D C:\Program Files\Microsoft Office 15
2016-03-11 08:54 - 2016-03-11 08:55 - 119528976 _____ C:\Users\Bill Pierce\Desktop\710_b042_multilanguage.exe
2016-03-11 08:41 - 2016-03-08 03:12 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-03-11 08:41 - 2016-03-08 03:12 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-03-11 08:38 - 2016-03-11 08:38 - 00002579 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2016-03-11 08:38 - 2016-03-11 08:38 - 00000000 ____D C:\WINDOWS\System32\Tasks\Apple
2016-03-11 08:38 - 2016-03-11 08:38 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2016-03-11 08:30 - 2016-03-11 08:30 - 00002420 _____ C:\Users\Bill Pierce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-03-10 18:57 - 2016-03-11 08:24 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2016-03-10 18:57 - 2016-03-10 19:02 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2016-03-10 18:38 - 2016-03-13 00:27 - 00000000 ____D C:\Users\Bill Pierce\Desktop\HiJackThis
2016-03-08 14:46 - 2016-03-01 01:31 - 00848168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-03-08 14:46 - 2016-03-01 01:22 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2016-03-08 14:46 - 2016-02-24 05:52 - 01997328 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2016-03-08 14:46 - 2016-02-24 05:51 - 07474528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-03-08 14:46 - 2016-02-24 05:48 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-03-08 14:46 - 2016-02-24 05:47 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-03-08 14:46 - 2016-02-24 05:40 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-03-08 14:46 - 2016-02-24 05:34 - 01613664 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2016-03-08 14:46 - 2016-02-24 05:28 - 03449168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2016-03-08 14:46 - 2016-02-24 05:15 - 01557768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2016-03-08 14:46 - 2016-02-24 04:58 - 00794888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2016-03-08 14:46 - 2016-02-24 04:54 - 00127840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS
2016-03-08 14:46 - 2016-02-24 04:51 - 01322248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2016-03-08 14:46 - 2016-02-24 04:50 - 00808800 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2016-03-08 14:46 - 2016-02-24 04:46 - 06607080 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2016-03-08 14:46 - 2016-02-24 04:43 - 00625000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2016-03-08 14:46 - 2016-02-24 04:39 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-03-08 14:46 - 2016-02-24 04:39 - 00141560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthHost.exe
2016-03-08 14:46 - 2016-02-24 04:19 - 00670928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2016-03-08 14:46 - 2016-02-24 04:14 - 00216416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2016-03-08 14:46 - 2016-02-24 04:11 - 01997152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-03-08 14:46 - 2016-02-24 04:11 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2016-03-08 14:46 - 2016-02-24 04:11 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2016-03-08 14:46 - 2016-02-24 04:11 - 00652392 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2016-03-08 14:46 - 2016-02-24 04:11 - 00394080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2016-03-08 14:46 - 2016-02-24 04:11 - 00258280 _____ (Microsoft Corporation) C:\WINDOWS\system32\sqmapi.dll
2016-03-08 14:46 - 2016-02-24 04:10 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-03-08 14:46 - 2016-02-24 04:10 - 00576864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-03-08 14:46 - 2016-02-24 04:09 - 00640472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2016-03-08 14:46 - 2016-02-24 04:09 - 00147808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2016-03-08 14:46 - 2016-02-24 04:06 - 05242496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2016-03-08 14:46 - 2016-02-24 03:59 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-03-08 14:46 - 2016-02-24 03:39 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTypeHelperUtil.dll
2016-03-08 14:46 - 2016-02-24 03:39 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExtrasXmlParser.dll
2016-03-08 14:46 - 2016-02-24 03:38 - 00187744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2016-03-08 14:46 - 2016-02-24 03:38 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2016-03-08 14:46 - 2016-02-24 03:37 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataLanguageUtil.dll
2016-03-08 14:46 - 2016-02-24 03:36 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenanceClient.dll
2016-03-08 14:46 - 2016-02-24 03:35 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-03-08 14:46 - 2016-02-24 03:35 - 00523752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2016-03-08 14:46 - 2016-02-24 03:35 - 00220064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sqmapi.dll
2016-03-08 14:46 - 2016-02-24 03:35 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-03-08 14:46 - 2016-02-24 03:33 - 00538736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2016-03-08 14:46 - 2016-02-24 03:33 - 00141664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2016-03-08 14:46 - 2016-02-24 03:31 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2016-03-08 14:46 - 2016-02-24 03:30 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfapigp.dll
2016-03-08 14:46 - 2016-02-24 03:28 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\POSyncServices.dll
2016-03-08 14:46 - 2016-02-24 03:23 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2016-03-08 14:46 - 2016-02-24 03:23 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataPlatformHelperUtil.dll
2016-03-08 14:46 - 2016-02-24 03:22 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2016-03-08 14:46 - 2016-02-24 03:20 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll
2016-03-08 14:46 - 2016-02-24 03:20 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2016-03-08 14:46 - 2016-02-24 03:20 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2016-03-08 14:46 - 2016-02-24 03:19 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2016-03-08 14:46 - 2016-02-24 03:19 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\seclogon.dll
2016-03-08 14:46 - 2016-02-24 03:15 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-03-08 14:46 - 2016-02-24 03:14 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExSMime.dll
2016-03-08 14:46 - 2016-02-24 03:13 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll
2016-03-08 14:46 - 2016-02-24 03:12 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\cemapi.dll
2016-03-08 14:46 - 2016-02-24 03:12 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2016-03-08 14:46 - 2016-02-24 03:10 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
2016-03-08 14:46 - 2016-02-24 03:09 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2016-03-08 14:46 - 2016-02-24 03:09 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSip.dll
2016-03-08 14:46 - 2016-02-24 03:07 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2016-03-08 14:46 - 2016-02-24 03:05 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2016-03-08 14:46 - 2016-02-24 03:03 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2016-03-08 14:46 - 2016-02-24 03:02 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll
2016-03-08 14:46 - 2016-02-24 03:01 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-03-08 14:46 - 2016-02-24 03:01 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll
2016-03-08 14:46 - 2016-02-24 03:01 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll
2016-03-08 14:46 - 2016-02-24 03:00 - 00214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2016-03-08 14:46 - 2016-02-24 02:59 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2016-03-08 14:46 - 2016-02-24 02:59 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll
2016-03-08 14:46 - 2016-02-24 02:59 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2016-03-08 14:46 - 2016-02-24 02:58 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\scapi.dll
2016-03-08 14:46 - 2016-02-24 02:55 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2016-03-08 14:46 - 2016-02-24 02:55 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
2016-03-08 14:46 - 2016-02-24 02:55 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExtrasXmlParser.dll
2016-03-08 14:46 - 2016-02-24 02:54 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
2016-03-08 14:46 - 2016-02-24 02:54 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultcli.dll
2016-03-08 14:46 - 2016-02-24 02:54 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2016-03-08 14:46 - 2016-02-24 02:54 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTypeHelperUtil.dll
2016-03-08 14:46 - 2016-02-24 02:53 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2016-03-08 14:46 - 2016-02-24 02:53 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataLanguageUtil.dll
2016-03-08 14:46 - 2016-02-24 02:52 - 00451584 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2016-03-08 14:46 - 2016-02-24 02:52 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PimIndexMaintenanceClient.dll
2016-03-08 14:46 - 2016-02-24 02:51 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2016-03-08 14:46 - 2016-02-24 02:49 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2016-03-08 14:46 - 2016-02-24 02:47 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2016-03-08 14:46 - 2016-02-24 02:46 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfapigp.dll
2016-03-08 14:46 - 2016-02-24 02:44 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2016-03-08 14:46 - 2016-02-24 02:44 - 00915456 _____ (Microsoft Corporation) C:\WINDOWS\system32\configurationclient.dll
2016-03-08 14:46 - 2016-02-24 02:44 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2016-03-08 14:46 - 2016-02-24 02:44 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\POSyncServices.dll
2016-03-08 14:46 - 2016-02-24 02:43 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2016-03-08 14:46 - 2016-02-24 02:43 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2016-03-08 14:46 - 2016-02-24 02:41 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2016-03-08 14:46 - 2016-02-24 02:41 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2016-03-08 14:46 - 2016-02-24 02:40 - 01224704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2016-03-08 14:46 - 2016-02-24 02:40 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2016-03-08 14:46 - 2016-02-24 02:40 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataPlatformHelperUtil.dll
2016-03-08 14:46 - 2016-02-24 02:39 - 01390592 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-03-08 14:46 - 2016-02-24 02:39 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2016-03-08 14:46 - 2016-02-24 02:38 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VCardParser.dll
2016-03-08 14:46 - 2016-02-24 02:36 - 01847808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2016-03-08 14:46 - 2016-02-24 02:34 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2016-03-08 14:46 - 2016-02-24 02:34 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-03-08 14:46 - 2016-02-24 02:32 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll
2016-03-08 14:46 - 2016-02-24 02:32 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll
2016-03-08 14:46 - 2016-02-24 02:31 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cemapi.dll
2016-03-08 14:46 - 2016-02-24 02:31 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
2016-03-08 14:46 - 2016-02-24 02:28 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2016-03-08 14:46 - 2016-02-24 02:28 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2016-03-08 14:46 - 2016-02-24 02:28 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxSip.dll
2016-03-08 14:46 - 2016-02-24 02:25 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\sharemediacpl.dll
2016-03-08 14:46 - 2016-02-24 02:23 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll
2016-03-08 14:46 - 2016-02-24 02:22 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll
2016-03-08 14:46 - 2016-02-24 02:21 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2016-03-08 14:46 - 2016-02-24 02:21 - 00168448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll
2016-03-08 14:46 - 2016-02-24 02:18 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2016-03-08 14:46 - 2016-02-24 02:18 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2016-03-08 14:46 - 2016-02-24 02:18 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll
2016-03-08 14:46 - 2016-02-24 02:17 - 00369664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2016-03-08 14:46 - 2016-02-24 02:16 - 00394752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2016-03-08 14:46 - 2016-02-24 02:13 - 00540160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2016-03-08 14:46 - 2016-02-24 02:11 - 03593216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-03-08 14:46 - 2016-02-24 02:09 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2016-03-08 14:46 - 2016-02-24 02:09 - 00793600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2016-03-08 14:46 - 2016-02-24 02:09 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2016-03-08 14:46 - 2016-02-24 02:09 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
2016-03-08 14:46 - 2016-02-24 02:07 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2016-03-08 14:46 - 2016-02-24 02:07 - 00890368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2016-03-08 14:46 - 2016-02-24 02:07 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2016-03-08 14:46 - 2016-02-24 02:04 - 01497088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
2016-03-08 14:46 - 2016-02-24 02:03 - 00769536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2016-03-08 14:46 - 2016-02-24 02:01 - 01831936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-03-08 14:46 - 2016-02-24 02:00 - 02273792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-03-08 14:46 - 2016-02-24 02:00 - 01098752 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-03-08 14:46 - 2016-02-24 01:57 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-03-08 14:46 - 2016-02-24 01:55 - 01996288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2016-03-08 14:46 - 2016-02-24 01:43 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwbase.dll
2016-03-08 14:46 - 2016-02-24 01:34 - 01707520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
2016-03-08 14:46 - 2016-02-24 01:22 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwbase.dll
2016-03-08 14:46 - 2016-02-24 01:20 - 22376960 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-03-08 14:46 - 2016-02-24 01:18 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-03-08 14:46 - 2016-02-24 01:12 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-03-08 14:46 - 2016-02-24 01:12 - 05321728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2016-03-08 14:46 - 2016-02-24 01:10 - 24600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-03-08 14:46 - 2016-02-24 01:09 - 06972416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-03-08 14:46 - 2016-02-24 01:05 - 12586496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2016-03-08 14:46 - 2016-02-24 01:03 - 14252544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-03-08 14:46 - 2016-02-24 00:59 - 05661696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-03-08 14:46 - 2016-02-24 00:55 - 07835648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-03-08 10:31 - 2016-03-08 10:31 - 00012872 _____ (SurfRight B.V.) C:\WINDOWS\system32\bootdelete.exe
2016-03-08 09:45 - 2016-03-08 09:45 - 01524224 _____ C:\Users\Bill Pierce\Desktop\adwcleaner_5.101.exe
2016-03-07 01:06 - 2016-03-07 01:16 - 00000000 ____D C:\ProgramData\HitmanPro
2016-03-07 01:06 - 2016-03-07 01:06 - 00000000 ____D C:\Program Files\HitmanPro
2016-03-07 01:05 - 2016-03-07 01:06 - 11441744 _____ (SurfRight B.V.) C:\Users\Bill Pierce\Desktop\HitmanPro_x64.exe
2016-03-07 00:40 - 2016-03-12 23:55 - 00000749 _____ C:\Users\Bill Pierce\Desktop\JRT.txt
2016-03-07 00:36 - 2016-03-07 00:36 - 01609216 _____ (Malwarebytes) C:\Users\Bill Pierce\Desktop\JRT.exe
2016-03-07 00:23 - 2016-03-12 23:44 - 00000000 ____D C:\Program Files (x86)\AdwCleaner
2016-03-06 22:40 - 2016-03-06 22:41 - 00297804 _____ C:\WINDOWS\Minidump\030616-71812-01.dmp
2016-03-06 17:06 - 2016-03-13 07:47 - 00000000 ____D C:\WINDOWS\Minidump
2016-03-06 17:06 - 2016-03-06 17:06 - 00259708 _____ C:\WINDOWS\Minidump\030616-32984-01.dmp
2016-03-03 10:23 - 2016-03-13 13:00 - 00000354 _____ C:\WINDOWS\Tasks\SpeedDiskSchedule.job
2016-03-03 10:23 - 2016-03-03 10:23 - 00002942 _____ C:\WINDOWS\System32\Tasks\SpeedDiskSchedule
2016-03-03 10:14 - 2016-03-13 07:38 - 00002930 _____ C:\WINDOWS\System32\Tasks\NUSchedule
2016-03-03 10:13 - 2016-03-13 07:49 - 00000312 _____ C:\WINDOWS\Tasks\NUAutoUpdate.job
2016-03-03 10:13 - 2016-03-03 10:13 - 00002588 _____ C:\WINDOWS\System32\Tasks\NUAutoUpdate
2016-03-02 17:43 - 2016-03-13 13:07 - 00000000 ____D C:\WINDOWS\System32\Tasks\Norton Security
2016-03-02 17:41 - 2016-03-02 17:41 - 00003388 _____ C:\WINDOWS\System32\Tasks\Norton WSC Integration
2016-03-02 17:21 - 2016-03-02 17:21 - 00111344 _____ (Symantec Corporation) C:\WINDOWS\system32\Drivers\SYMEVENT64x86.SYS
2016-03-02 17:21 - 2016-03-02 17:21 - 00008214 _____ C:\WINDOWS\system32\Drivers\SYMEVENT64x86.CAT
2016-03-02 17:19 - 2016-03-02 17:41 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security
2016-03-02 17:19 - 2016-03-02 17:19 - 00000000 ____D C:\Program Files (x86)\Norton Security
2016-03-02 15:02 - 2016-03-02 15:02 - 00083123 _____ C:\Users\Bill Pierce\Documents\Megan - Catch-22.pdf
2016-03-01 15:26 - 2016-02-23 07:27 - 02654872 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2016-03-01 15:26 - 2016-02-23 07:27 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-03-01 15:26 - 2016-02-23 07:25 - 02152288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2016-03-01 15:26 - 2016-02-23 07:25 - 01818696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-03-01 15:26 - 2016-02-23 06:34 - 01859960 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2016-03-01 15:26 - 2016-02-23 06:34 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2016-03-01 15:26 - 2016-02-23 06:33 - 00696160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2016-03-01 15:26 - 2016-02-23 06:32 - 08705672 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2016-03-01 15:26 - 2016-02-23 06:32 - 02544264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2016-03-01 15:26 - 2016-02-23 06:32 - 01152328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2016-03-01 15:26 - 2016-02-23 06:32 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2016-03-01 15:26 - 2016-02-23 06:31 - 01017032 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2016-03-01 15:26 - 2016-02-23 06:31 - 00819648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2016-03-01 15:26 - 2016-02-23 06:31 - 00536256 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2016-03-01 15:26 - 2016-02-23 06:25 - 03671888 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-03-01 15:26 - 2016-02-23 06:21 - 22564328 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-03-01 15:26 - 2016-02-23 05:45 - 02773096 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2016-03-01 15:26 - 2016-02-23 05:39 - 00502112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2016-03-01 15:26 - 2016-02-23 05:38 - 06952088 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2016-03-01 15:26 - 2016-02-23 05:38 - 02180136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2016-03-01 15:26 - 2016-02-23 05:38 - 00980352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2016-03-01 15:26 - 2016-02-23 05:38 - 00895080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2016-03-01 15:26 - 2016-02-23 05:38 - 00882720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2016-03-01 15:26 - 2016-02-23 05:37 - 00713824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2016-03-01 15:26 - 2016-02-23 05:32 - 00791744 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-03-01 15:26 - 2016-02-23 05:30 - 02919320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-03-01 15:26 - 2016-02-23 05:27 - 21124344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-03-01 15:26 - 2016-02-23 05:27 - 00376536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2016-03-01 15:26 - 2016-02-23 05:20 - 01139712 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblGameSave.dll
2016-03-01 15:26 - 2016-02-23 05:17 - 00649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2016-03-01 15:26 - 2016-02-23 04:56 - 02186864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2016-03-01 15:26 - 2016-02-23 04:36 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuickActionsDataModel.dll
2016-03-01 15:26 - 2016-02-23 04:29 - 00591872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll
2016-03-01 15:26 - 2016-02-23 04:27 - 00307712 _____ (Microsoft Corporation) C:\WINDOWS\system32\usbmon.dll
2016-03-01 15:26 - 2016-02-23 04:20 - 00606720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2016-03-01 15:26 - 2016-02-23 04:20 - 00493568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2016-03-01 15:26 - 2016-02-23 04:19 - 00948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2016-03-01 15:26 - 2016-02-23 04:14 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2016-03-01 15:26 - 2016-02-23 04:12 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-03-01 15:26 - 2016-02-23 04:10 - 00997376 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2016-03-01 15:26 - 2016-02-23 04:10 - 00474624 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2016-03-01 15:26 - 2016-02-23 04:09 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-03-01 15:26 - 2016-02-23 04:09 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2016-03-01 15:26 - 2016-02-23 04:09 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2016-03-01 15:26 - 2016-02-23 04:06 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-03-01 15:26 - 2016-02-23 04:04 - 01131520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2016-03-01 15:26 - 2016-02-23 04:04 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2016-03-01 15:26 - 2016-02-23 04:02 - 01318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2016-03-01 15:26 - 2016-02-23 04:00 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-03-01 15:26 - 2016-02-23 03:58 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\TimeBrokerServer.dll
2016-03-01 15:26 - 2016-02-23 03:37 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2016-03-01 15:26 - 2016-02-23 03:31 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
2016-03-01 15:26 - 2016-02-23 03:30 - 01731584 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-03-01 15:26 - 2016-02-23 03:30 - 00646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2016-03-01 15:26 - 2016-02-23 03:24 - 04827136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2016-03-01 15:26 - 2016-02-23 03:24 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-03-01 15:26 - 2016-02-23 03:24 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2016-03-01 15:26 - 2016-02-23 03:22 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2016-03-01 15:26 - 2016-02-23 03:17 - 02635264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-03-01 15:26 - 2016-02-23 03:14 - 00990720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2016-03-01 15:26 - 2016-02-23 03:11 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-03-01 15:26 - 2016-02-23 02:59 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-03-01 15:26 - 2016-02-23 02:56 - 04412928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2016-03-01 15:26 - 2016-02-23 02:55 - 04894208 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-03-01 15:26 - 2016-02-23 02:55 - 02229760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-03-01 15:26 - 2016-02-23 02:53 - 01799168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-03-01 15:26 - 2016-02-23 02:52 - 11545600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-03-01 15:26 - 2016-02-23 02:50 - 09919488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-03-01 15:26 - 2016-02-23 02:42 - 03425792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-03-01 15:26 - 2016-02-23 02:41 - 02912256 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2016-03-01 15:26 - 2016-02-23 02:39 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-03-01 15:26 - 2016-02-23 02:39 - 02581504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2016-03-01 15:26 - 2016-02-23 02:36 - 12125696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-03-01 15:26 - 2016-02-23 02:36 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-03-01 15:26 - 2016-02-23 02:35 - 07533568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2016-03-01 15:26 - 2016-02-23 02:33 - 02604032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2016-03-01 15:26 - 2016-02-23 02:32 - 02793472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-03-01 15:26 - 2016-02-23 02:30 - 02061312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2016-03-01 15:26 - 2016-02-23 02:28 - 06740992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2016-03-01 15:26 - 2016-02-08 23:24 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-03-01 15:26 - 2016-02-08 23:07 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-03-01 15:26 - 2016-02-08 23:04 - 01946624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-03-01 15:25 - 2016-02-23 07:29 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-03-01 15:25 - 2016-02-23 07:29 - 00874968 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-03-01 15:25 - 2016-02-23 07:27 - 01141504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-03-01 15:25 - 2016-02-23 07:25 - 00563552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2016-03-01 15:25 - 2016-02-23 07:15 - 00779384 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll
2016-03-01 15:25 - 2016-02-23 07:08 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2016-03-01 15:25 - 2016-02-23 06:33 - 00389992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2016-03-01 15:25 - 2016-02-23 06:32 - 00498448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2016-03-01 15:25 - 2016-02-23 06:32 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2016-03-01 15:25 - 2016-02-23 06:31 - 00476728 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2016-03-01 15:25 - 2016-02-23 06:31 - 00408120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2016-03-01 15:25 - 2016-02-23 06:22 - 00572272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll
2016-03-01 15:25 - 2016-02-23 06:17 - 00146272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2016-03-01 15:25 - 2016-02-23 05:40 - 00430944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2016-03-01 15:25 - 2016-02-23 05:38 - 00450912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2016-03-01 15:25 - 2016-02-23 05:38 - 00420928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2016-03-01 15:25 - 2016-02-23 05:25 - 00534368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2016-03-01 15:25 - 2016-02-23 05:20 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
2016-03-01 15:25 - 2016-02-23 05:19 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
2016-03-01 15:25 - 2016-02-23 05:12 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\provpackageapidll.dll
2016-03-01 15:25 - 2016-02-23 05:10 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
2016-03-01 15:25 - 2016-02-23 05:07 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2016-03-01 15:25 - 2016-02-23 05:07 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2016-03-01 15:25 - 2016-02-23 05:06 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\flvprophandler.dll
2016-03-01 15:25 - 2016-02-23 05:01 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rasl2tp.sys
2016-03-01 15:25 - 2016-02-23 05:00 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2016-03-01 15:25 - 2016-02-23 05:00 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2016-03-01 15:25 - 2016-02-23 04:58 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2016-03-01 15:25 - 2016-02-23 04:58 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-03-01 15:25 - 2016-02-23 04:58 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\irmon.dll
2016-03-01 15:25 - 2016-02-23 04:57 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-03-01 15:25 - 2016-02-23 04:55 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bridge.sys
2016-03-01 15:25 - 2016-02-23 04:53 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\srpapi.dll
2016-03-01 15:25 - 2016-02-23 04:53 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
2016-03-01 15:25 - 2016-02-23 04:52 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2016-03-01 15:25 - 2016-02-23 04:50 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2016-03-01 15:25 - 2016-02-23 04:48 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2016-03-01 15:25 - 2016-02-23 04:48 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\TimeBrokerClient.dll
2016-03-01 15:25 - 2016-02-23 04:40 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SMSRouter.dll
2016-03-01 15:25 - 2016-02-23 04:39 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2016-03-01 15:25 - 2016-02-23 04:38 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
2016-03-01 15:25 - 2016-02-23 04:38 - 00287712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MediaControl.dll
2016-03-01 15:25 - 2016-02-23 04:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-03-01 15:25 - 2016-02-23 04:37 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2016-03-01 15:25 - 2016-02-23 04:37 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2016-03-01 15:25 - 2016-02-23 04:34 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifiprofilessettinghandler.dll
2016-03-01 15:25 - 2016-02-23 04:34 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2016-03-01 15:25 - 2016-02-23 04:33 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2016-03-01 15:25 - 2016-02-23 04:32 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-03-01 15:25 - 2016-02-23 04:31 - 00463360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2016-03-01 15:25 - 2016-02-23 04:28 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2016-03-01 15:25 - 2016-02-23 04:26 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
2016-03-01 15:25 - 2016-02-23 04:23 - 00412672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2016-03-01 15:25 - 2016-02-23 04:22 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2016-03-01 15:25 - 2016-02-23 04:20 - 00847360 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2016-03-01 15:25 - 2016-02-23 04:20 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-01 15:25 - 2016-02-23 04:19 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2016-03-01 15:25 - 2016-02-23 04:18 - 00557056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-03-01 15:25 - 2016-02-23 04:14 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2016-03-01 15:25 - 2016-02-23 04:11 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-03-01 15:25 - 2016-02-23 04:06 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2016-03-01 15:25 - 2016-02-23 04:06 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2016-03-01 15:25 - 2016-02-23 04:05 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2016-03-01 15:25 - 2016-02-23 04:04 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2016-03-01 15:25 - 2016-02-23 04:02 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2016-03-01 15:25 - 2016-02-23 04:02 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2016-03-01 15:25 - 2016-02-23 03:58 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2016-03-01 15:25 - 2016-02-23 03:58 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-03-01 15:25 - 2016-02-23 03:58 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2016-03-01 15:25 - 2016-02-23 03:57 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TimeBrokerClient.dll
2016-03-01 15:25 - 2016-02-23 03:52 - 00456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2016-03-01 15:25 - 2016-02-23 03:50 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
2016-03-01 15:25 - 2016-02-23 03:49 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2016-03-01 15:25 - 2016-02-23 03:48 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2016-03-01 15:25 - 2016-02-23 03:47 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WiFiDisplay.dll
2016-03-01 15:25 - 2016-02-23 03:38 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2016-03-01 15:25 - 2016-02-23 03:37 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2016-03-01 15:25 - 2016-02-23 03:36 - 00713728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2016-03-01 15:25 - 2016-02-23 03:36 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2016-03-01 15:25 - 2016-02-23 03:36 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-01 15:25 - 2016-02-23 03:35 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2016-03-01 15:25 - 2016-02-23 03:29 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2016-03-01 15:25 - 2016-02-23 03:28 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2016-03-01 15:25 - 2016-02-23 03:28 - 00256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2016-03-01 15:25 - 2016-02-23 03:24 - 01105920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2016-03-01 15:25 - 2016-02-23 03:21 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2016-03-01 15:25 - 2016-02-23 03:21 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2016-03-01 15:25 - 2016-02-23 03:20 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
2016-03-01 15:25 - 2016-02-23 03:05 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2016-03-01 15:25 - 2016-02-23 03:01 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2016-03-01 15:25 - 2016-02-23 02:58 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll
2016-03-01 15:25 - 2016-02-23 02:51 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2016-03-01 15:25 - 2016-02-09 00:28 - 00277856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2016-03-01 15:25 - 2016-02-09 00:13 - 00185184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2016-03-01 15:25 - 2016-02-08 23:18 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\system32\thumbcache.dll
2016-03-01 15:25 - 2016-02-08 23:18 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll
2016-03-01 15:25 - 2016-02-08 23:07 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2016-03-01 11:01 - 2016-03-02 17:23 - 00000000 ____D C:\WINDOWS\System32\Tasks\Norton Remove and Reinstall
2016-03-01 10:42 - 2008-04-13 20:12 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\winhlp32.exe
2016-03-01 00:44 - 2016-03-02 17:45 - 00000000 ____D C:\WINDOWS\System32\Tasks\Remediation
2016-03-01 00:44 - 2016-03-01 00:44 - 00000000 ____D C:\Program Files\Common Files\AV
2016-02-29 20:17 - 2016-02-29 20:17 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2016-02-29 18:29 - 2016-02-29 18:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinCDEmu
2016-02-29 18:29 - 2016-02-29 18:29 - 00000000 ____D C:\Program Files (x86)\WinCDEmu
2016-02-29 13:19 - 2016-02-29 13:19 - 00000020 ___SH C:\Users\DefaultAppPool\ntuser.ini
2016-02-28 19:05 - 2016-02-28 19:05 - 00003266 _____ C:\WINDOWS\System32\Tasks\SidebarExecute
2016-02-28 18:49 - 2016-02-28 19:00 - 00000000 ___DC C:\WINDOWS\Panther
2016-02-28 18:47 - 2016-02-28 18:47 - 00000000 ____D C:\Windows.old
2016-02-28 18:46 - 2016-02-28 18:46 - 16986112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 05503488 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 04759040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 04502352 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 04064320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 03993600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 03355136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 02843136 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2016-02-28 18:46 - 2016-02-28 18:46 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2016-02-28 18:46 - 2016-02-28 18:46 - 02680320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 02606824 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 02597888 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 02587696 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 02352128 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 02155008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 02127360 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2016-02-28 18:46 - 2016-02-28 18:46 - 02057216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 02050048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2016-02-28 18:46 - 2016-02-28 18:46 - 02026736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 02001408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01860096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01824264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01814528 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01804664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMALFXGFXDSP.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01750440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 01717248 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01674240 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01648640 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01594408 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01582080 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 01542656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 01467392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01415200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01399224 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01371792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01337240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01328128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01309376 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01299504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01281376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01270072 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOE.DLL
2016-02-28 18:46 - 2016-02-28 18:46 - 01174008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01092456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01089880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-02-28 18:46 - 2016-02-28 18:46 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01070080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOE.DLL
2016-02-28 18:46 - 2016-02-28 18:46 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01042432 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01035776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 01009152 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOD.DLL
2016-02-28 18:46 - 2016-02-28 18:46 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00973664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00931328 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSMPEG2ENC.DLL
2016-02-28 18:46 - 2016-02-28 18:46 - 00925064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00911648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00900608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00890880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOD.DLL
2016-02-28 18:46 - 2016-02-28 18:46 - 00884736 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdlg.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00871936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSMPEG2ENC.DLL
2016-02-28 18:46 - 2016-02-28 18:46 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00858952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00851456 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00824320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00820704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00803840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00786696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOD.DLL
2016-02-28 18:46 - 2016-02-28 18:46 - 00785088 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00784384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00749056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00733184 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00704000 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00701384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00698208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00697856 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00695752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOD.DLL
2016-02-28 18:46 - 2016-02-28 18:46 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00683008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00678912 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00675064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00671472 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00653312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00652312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00644096 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00621568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00613888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00610816 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-02-28 18:46 - 2016-02-28 18:46 - 00604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00586208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00586080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 00578912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2016-02-28 18:46 - 2016-02-28 18:46 - 00574976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00569856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00558592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00535040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00526856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00523776 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvut.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00523616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00515584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00511320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00499432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00477696 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\system32\DDDS.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00472576 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00470528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00462760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00454056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00440152 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 00431240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00415744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\catsrvut.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00412512 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00405568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00389120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00387072 _____ (Microsoft Corporation) C:\WINDOWS\system32\qdvd.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00383488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00366224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00337840 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ksproxy.ax
2016-02-28 18:46 - 2016-02-28 18:46 - 00304752 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 00299008 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00289248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00264544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00264192 _____ (Nokia) C:\WINDOWS\system32\NmaDirect.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00260608 _____ C:\WINDOWS\system32\MTFServer.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00258048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iassam.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00245840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00241664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00235008 _____ C:\WINDOWS\system32\MTF.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ksproxy.ax
2016-02-28 18:46 - 2016-02-28 18:46 - 00234504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mftranscode.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00208176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mftranscode.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00205824 _____ (Nokia) C:\WINDOWS\SysWOW64\NmaDirect.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iassam.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00202472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimCfg.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityCommon.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00161632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2016-02-28 18:46 - 2016-02-28 18:46 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimAuth.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimCfg.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\FilterDS.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshom.ocx
2016-02-28 18:46 - 2016-02-28 18:46 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rmcast.sys
2016-02-28 18:46 - 2016-02-28 18:46 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2016-02-28 18:46 - 2016-02-28 18:46 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ETWCoreUIComponentsResources.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ETWCoreUIComponentsResources.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbio.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimAuth.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshom.ocx
2016-02-28 18:46 - 2016-02-28 18:46 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ProximityCommon.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00119320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MP3DMOD.DLL
2016-02-28 18:46 - 2016-02-28 18:46 - 00118624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2016-02-28 18:46 - 2016-02-28 18:46 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\capimg.sys
2016-02-28 18:46 - 2016-02-28 18:46 - 00116728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2016-02-28 18:46 - 2016-02-28 18:46 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MapControls.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00110032 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\hlink.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasauto.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00100160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MP3DMOD.DLL
2016-02-28 18:46 - 2016-02-28 18:46 - 00099840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hlink.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttpcom.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00095072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdstor.sys
2016-02-28 18:46 - 2016-02-28 18:46 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winbio.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00088392 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00085320 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00081112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 00080600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwapi.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttpcom.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\cfgbkend.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMSRoamingSecurity.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.XboxLive.ProxyStub.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssign32.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwancfg.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00073360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManagerProxy.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys
2016-02-28 18:46 - 2016-02-28 18:46 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ihvrilproxy.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00063528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wwapi.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cfgbkend.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssign32.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00058408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosResource.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosResource.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\rilproxy.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wwanpref.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00051680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsUtilsV2.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthTokenBrokerExt.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaui.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsplib.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgrcli.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.proxy.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthManagerProxy.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcaui.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ztrace_maps.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\BackgroundTransferHost.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCoreRes.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCoreRes.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00035680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys
2016-02-28 18:46 - 2016-02-28 18:46 - 00035656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usermgrcli.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BackgroundTransferHost.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00032040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ztrace_maps.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringconfigsp.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.proxy.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasautou.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshrm.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasautou.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasadhlp.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\IcsEntitlementHost.exe
2016-02-28 18:46 - 2016-02-28 18:46 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\sscoreext.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastlsext.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasadhlp.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastlsext.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosTrace.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosHost.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\readingviewresources.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlStringsRes.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlStringsRes.dll
2016-02-28 18:46 - 2016-02-28 18:46 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2016-02-28 18:37 - 2016-02-28 18:37 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2016-02-28 18:35 - 2016-02-28 18:35 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices
2016-02-28 18:35 - 2016-02-28 18:35 - 00000000 ____D C:\WINDOWS\system32\msmq
2016-02-28 18:35 - 2016-02-28 18:35 - 00000000 ____D C:\WINDOWS\system32\BestPractices
2016-02-28 18:35 - 2016-02-28 18:35 - 00000000 ____D C:\Program Files\Reference Assemblies
2016-02-28 18:35 - 2016-02-28 18:35 - 00000000 ____D C:\Program Files\MSBuild
2016-02-28 18:35 - 2016-02-28 18:35 - 00000000 ____D C:\Program Files\Hyper-V
2016-02-28 18:35 - 2016-02-28 18:35 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2016-02-28 18:35 - 2016-02-28 18:35 - 00000000 ____D C:\Program Files (x86)\MSBuild
2016-02-28 18:35 - 2016-02-28 18:35 - 00000000 ____D C:\inetpub
2016-02-28 18:34 - 2015-10-23 21:47 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2016-02-28 18:34 - 2015-10-23 21:47 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2016-02-28 18:34 - 2015-10-23 21:47 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2016-02-28 18:34 - 2015-10-23 21:46 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2016-02-28 18:34 - 2015-10-23 21:46 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2016-02-28 18:34 - 2015-10-23 21:45 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2016-02-28 16:48 - 2016-02-28 16:48 - 00001844 __RSH C:\ProgramData\ntuser.pol
2016-02-28 16:34 - 2016-02-28 16:34 - 00000020 ___SH C:\Users\Bill Pierce\ntuser.ini
2016-02-28 16:34 - 2016-02-28 16:34 - 00000000 _SHDL C:\Users\Default\My Documents
2016-02-28 16:34 - 2016-02-28 16:34 - 00000000 _SHDL C:\Users\Default\Documents\My Videos
2016-02-28 16:34 - 2016-02-28 16:34 - 00000000 _SHDL C:\Users\Default\Documents\My Pictures
2016-02-28 16:34 - 2016-02-28 16:34 - 00000000 _SHDL C:\Users\Default\Documents\My Music
2016-02-28 16:34 - 2016-02-28 16:34 - 00000000 _SHDL C:\Users\Default User\Documents\My Videos
2016-02-28 16:34 - 2016-02-28 16:34 - 00000000 _SHDL C:\Users\Default User\Documents\My Pictures
2016-02-28 16:34 - 2016-02-28 16:34 - 00000000 _SHDL C:\Users\Default User\Documents\My Music
2016-02-28 16:28 - 2016-03-13 07:47 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-02-28 16:14 - 2016-02-28 16:14 - 00001519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-02-28 16:14 - 2016-02-28 16:14 - 00000000 ____D C:\Users\Default\AppData\Roaming\Trusteer
2016-02-28 16:14 - 2016-02-28 16:14 - 00000000 ____D C:\Users\Default\AppData\Roaming\Media Center Programs
2016-02-28 16:14 - 2016-02-28 16:14 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2016-02-28 16:14 - 2016-02-28 16:14 - 00000000 ____D C:\Users\Default\AppData\Roaming\Garmin
2016-02-28 16:14 - 2016-02-28 16:14 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2016-02-28 16:14 - 2016-02-28 16:14 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2016-02-28 16:14 - 2016-02-28 16:14 - 00000000 ____D C:\Users\Default\AppData\Local\Garmin_Ltd._or_its_subsid
2016-02-28 16:14 - 2016-02-28 16:14 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Trusteer
2016-02-28 16:14 - 2016-02-28 16:14 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Media Center Programs
2016-02-28 16:14 - 2016-02-28 16:14 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2016-02-28 16:14 - 2016-02-28 16:14 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Garmin
2016-02-28 16:14 - 2016-02-28 16:14 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2016-02-28 16:14 - 2016-02-28 16:14 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2016-02-28 16:14 - 2016-02-28 16:14 - 00000000 ____D C:\Users\Default User\AppData\Local\Garmin_Ltd._or_its_subsid
2016-02-28 16:08 - 2016-02-28 16:08 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines
2016-02-28 16:07 - 2016-02-28 16:07 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2016-02-28 16:05 - 2016-03-13 03:05 - 00000000 ____D C:\Users\Bill Pierce
2016-02-28 16:05 - 2016-02-28 16:05 - 00000000 _SHDL C:\Users\Bill Pierce\My Documents
2016-02-28 16:05 - 2016-02-28 16:05 - 00000000 _SHDL C:\Users\Bill Pierce\Documents\My Videos
2016-02-28 16:05 - 2016-02-28 16:05 - 00000000 _SHDL C:\Users\Bill Pierce\Documents\My Pictures
2016-02-28 16:05 - 2016-02-28 16:05 - 00000000 _SHDL C:\Users\Bill Pierce\Documents\My Music
2016-02-28 16:04 - 2016-03-13 07:54 - 00007248 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-02-28 16:04 - 2016-03-11 08:25 - 00000000 ____D C:\Users\DefaultAppPool
2016-02-28 16:04 - 2016-02-28 16:04 - 00965390 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2016-02-28 16:04 - 2016-02-28 16:04 - 00000000 _SHDL C:\Users\DefaultAppPool\My Documents
2016-02-28 16:04 - 2016-02-28 16:04 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\My Videos
2016-02-28 16:04 - 2016-02-28 16:04 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\My Pictures
2016-02-28 16:04 - 2016-02-28 16:04 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\My Music
2016-02-28 16:02 - 2016-03-13 07:47 - 00000000 ____D C:\ProgramData\NVIDIA
2016-02-28 16:02 - 2016-02-28 16:02 - 00000000 ____D C:\Program Files\LSI SoftModem
2016-02-28 16:02 - 2015-10-13 13:26 - 06783280 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2016-02-28 16:02 - 2015-10-13 13:26 - 03522168 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2016-02-28 16:02 - 2015-10-13 13:26 - 02557616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2016-02-28 16:02 - 2015-10-13 13:26 - 00933168 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2016-02-28 16:02 - 2015-10-13 13:26 - 00384176 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2016-02-28 16:02 - 2015-10-13 13:26 - 00062584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2016-02-28 16:02 - 2015-10-13 12:19 - 05972783 _____ C:\WINDOWS\system32\nvcoproc.bin
2016-02-28 16:01 - 2016-02-28 16:08 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-02-28 16:01 - 2016-02-28 16:08 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-02-28 16:01 - 2016-02-28 16:01 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2016-02-28 16:01 - 2016-02-28 16:01 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
2016-02-28 16:01 - 2016-02-28 16:01 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_RimSerial_AMD64_01007.Wdf
2016-02-28 16:01 - 2016-02-28 16:01 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2016-02-28 16:01 - 2016-02-28 16:01 - 00000000 ____D C:\Program Files\Realtek
2016-02-28 15:59 - 2015-10-30 03:17 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2016-02-28 15:56 - 2016-03-12 19:11 - 00413072 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-02-28 14:56 - 2016-02-28 15:19 - 00000000 ___HD C:\$WINDOWS.~BT
2016-02-17 18:23 - 2016-02-17 18:23 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2016-02-17 17:04 - 2016-02-28 16:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-02-17 16:48 - 2016-02-17 16:48 - 00000000 ___HD C:\$Windows.~WS
2016-02-17 10:58 - 2016-02-17 10:58 - 00000000 _____ C:\WINDOWS\exctrlst.INI
2016-02-17 10:53 - 2016-02-17 10:53 - 00000000 ____D C:\Program Files (x86)\Resource Kit
2016-02-13 08:13 - 2016-02-13 08:13 - 00000000 _____ C:\Users\Bill Pierce\s-1-5-21-2422629387-1192540806-1023300286-1001.rrr
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-13 16:27 - 2015-07-03 10:17 - 00000930 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2016-03-13 16:27 - 2015-07-03 10:17 - 00000926 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
2016-03-13 16:11 - 2012-11-20 16:43 - 00000000 ____D C:\Users\Bill Pierce\VMLites
2016-03-13 15:41 - 2016-02-02 06:36 - 00000924 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-03-13 12:59 - 2015-10-02 12:59 - 00000300 _____ C:\WINDOWS\Tasks\RtlNetworkGenieVistaStart.job
2016-03-13 11:16 - 2015-07-31 17:33 - 00004160 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{4F5BA495-7B5F-4090-8115-48E648263666}
2016-03-13 11:00 - 2015-09-23 15:42 - 00000000 ____D C:\Users\Bill Pierce\AppData\LocalLow\Adblock Plus for IE
2016-03-13 10:33 - 2013-06-19 14:18 - 00000000 ____D C:\Program Files (x86)\PhoneTray
2016-03-13 07:52 - 2015-07-03 10:23 - 00000000 ___RD C:\Users\Bill Pierce\Dropbox
2016-03-13 07:52 - 2015-07-03 10:17 - 00000000 ____D C:\Users\Bill Pierce\AppData\Local\Dropbox
2016-03-13 07:51 - 2015-07-31 13:06 - 00000000 ___RD C:\Users\Bill Pierce\OneDrive
2016-03-13 07:49 - 2016-02-02 06:36 - 00000920 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-03-13 07:49 - 2015-09-15 22:24 - 00000000 ____D C:\Program Files (x86)\DoNotTrackMe
2016-03-13 07:48 - 2013-10-17 10:14 - 00000000 ____D C:\Users\Public\Documents\PhoneTray
2016-03-13 07:38 - 2012-11-30 04:16 - 00000000 ____D C:\Users\Bill Pierce\AppData\Roaming\Norton Utilities 16
2016-03-13 07:38 - 2009-09-09 00:04 - 00000000 ____D C:\ProgramData\TEMP
2016-03-13 00:50 - 2009-07-26 22:48 - 00000000 ____D C:\Users\Bill Pierce\AppData\Local\CrashDumps
2016-03-13 00:33 - 2015-10-30 02:28 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2016-03-12 23:20 - 2015-01-15 14:19 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-03-12 19:06 - 2014-05-15 11:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
2016-03-12 19:06 - 2014-05-15 10:48 - 00000000 ____D C:\MSI
2016-03-12 18:50 - 2009-06-01 12:05 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2016-03-12 11:50 - 2015-10-30 03:24 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-03-12 11:41 - 2015-10-30 03:24 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-03-12 09:55 - 2009-10-26 16:34 - 00000000 ____D C:\Program Files (x86)\IrfanView
2016-03-12 09:54 - 2015-10-30 03:24 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files
2016-03-12 09:14 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-03-11 11:51 - 2010-01-15 12:25 - 00000000 ____D C:\Users\Bill Pierce\AppData\Roaming\uTorrent
2016-03-11 09:09 - 2015-10-30 03:21 - 00000000 ____D C:\WINDOWS\INF
2016-03-11 09:09 - 2013-06-03 14:20 - 00000000 ____D C:\ProgramData\Research In Motion
2016-03-11 09:09 - 2013-06-03 14:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlackBerry
2016-03-11 09:09 - 2013-06-03 14:20 - 00000000 ____D C:\Program Files (x86)\Research In Motion
2016-03-11 08:43 - 2015-10-30 03:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-03-11 08:41 - 2015-10-30 03:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-03-11 08:41 - 2015-06-11 09:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2016-03-11 08:25 - 2015-10-30 02:28 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2016-03-11 08:25 - 2011-10-18 21:11 - 00000000 ____D C:\Users\Bill Pierce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
2016-03-11 08:24 - 2009-05-26 11:40 - 00000000 ____D C:\ProgramData\Norton
2016-03-11 08:19 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\registration
2016-03-11 08:18 - 2012-11-19 14:39 - 00000000 ____D C:\Users\Bill Pierce\AppData\Local\Packages
2016-03-11 08:18 - 2011-10-18 21:11 - 00000000 ____D C:\Program Files (x86)\Trend Micro
2016-03-11 08:18 - 2010-06-15 13:09 - 00000000 ____D C:\Users\Bill Pierce\AppData\Local\Apple
2016-03-08 19:59 - 2009-08-12 07:41 - 00189440 ___SH C:\Users\Bill Pierce\Documents\Thumbs.db
2016-03-08 15:32 - 2015-10-30 03:24 - 00000000 ____D C:\Program Files\Windows Portable Devices
2016-03-08 15:32 - 2015-10-30 03:24 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2016-03-08 15:32 - 2015-10-30 03:24 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2016-03-08 15:32 - 2015-10-30 03:24 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2016-03-08 14:52 - 2013-07-09 15:58 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-03-08 14:47 - 2010-03-09 15:26 - 143659408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-03-06 17:26 - 2010-10-09 15:24 - 00000000 ____D C:\Users\Bill Pierce\AppData\Local\ElevatedDiagnostics
2016-03-06 17:11 - 2015-10-30 02:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2016-03-04 09:08 - 2012-07-28 22:54 - 00013312 _____ C:\Users\Bill Pierce\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-03-03 10:13 - 2009-05-26 17:41 - 00000000 ____D C:\ProgramData\Symantec
2016-03-02 22:55 - 2015-10-30 03:24 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2016-03-02 17:41 - 2015-08-10 00:19 - 00000000 ____D C:\WINDOWS\system32\Drivers\NSx64
2016-03-02 17:36 - 2009-09-16 22:24 - 00000000 ____D C:\Program Files (x86)\NortonInstaller
2016-03-02 17:21 - 2015-08-10 00:20 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2016-03-02 16:52 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\rescache
2016-03-01 15:48 - 2012-12-05 18:50 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-03-01 15:43 - 2015-10-30 05:07 - 00000000 ____D C:\Program Files\Windows Journal
2016-03-01 15:43 - 2015-10-30 03:24 - 00000000 __RSD C:\WINDOWS\Media
2016-03-01 15:43 - 2015-10-30 03:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2016-03-01 15:43 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-03-01 15:43 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2016-03-01 15:43 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-03-01 15:43 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-03-01 15:43 - 2015-10-30 02:28 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2016-03-01 15:43 - 2015-10-30 02:28 - 00000000 ____D C:\WINDOWS\system32\Dism
2016-03-01 10:48 - 2015-11-17 15:08 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-02-29 23:22 - 2016-02-06 00:56 - 00000000 ____D C:\Users\Bill Pierce\Documents\2015USTaxes
2016-02-29 04:16 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\appcompat
2016-02-28 19:11 - 2015-10-30 03:24 - 00000000 ____D C:\Program Files\Windows Sidebar
2016-02-28 19:11 - 2015-10-30 03:24 - 00000000 ____D C:\Program Files (x86)\Windows Sidebar
2016-02-28 18:49 - 2015-10-30 03:24 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2016-02-28 18:47 - 2015-10-30 03:24 - 00000000 ___SD C:\WINDOWS\system32\F12
2016-02-28 18:47 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\SysWOW64\en-GB
2016-02-28 18:47 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\en-GB
2016-02-28 18:47 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\Provisioning
2016-02-28 18:42 - 2015-10-30 05:03 - 00000000 ____D C:\WINDOWS\OCR
2016-02-28 18:41 - 2015-10-30 03:24 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2016-02-28 18:41 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
2016-02-28 18:41 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\migwiz
2016-02-28 18:41 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\IME
2016-02-28 18:41 - 2015-10-30 03:24 - 00000000 ____D C:\Program Files\Windows Defender
2016-02-28 18:41 - 2015-10-30 03:24 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2016-02-28 18:41 - 2015-10-30 02:28 - 00000000 ____D C:\WINDOWS\servicing
2016-02-28 18:35 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2016-02-28 18:35 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2016-02-28 18:35 - 2015-10-30 03:19 - 01140224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Windows.Smc.dll
2016-02-28 18:35 - 2015-10-30 03:19 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll
2016-02-28 18:35 - 2015-10-30 03:19 - 00266240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.dll
2016-02-28 18:35 - 2015-10-30 03:19 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2016-02-28 18:35 - 2015-10-30 03:19 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.tlb
2016-02-28 18:35 - 2015-10-30 03:19 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa30.tlb
2016-02-28 18:35 - 2015-10-30 03:19 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDRCWSProxy.DLL
2016-02-28 18:35 - 2015-10-30 03:19 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDEWSProxy.DLL
2016-02-28 18:35 - 2015-10-30 03:19 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa20.tlb
2016-02-28 18:35 - 2015-10-30 03:19 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2016-02-28 18:35 - 2015-10-30 03:19 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa10.tlb
2016-02-28 18:35 - 2015-10-30 03:19 - 00033614 _____ C:\WINDOWS\system32\ScanManagement.msc
2016-02-28 18:35 - 2015-10-30 03:19 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2016-02-28 18:35 - 2015-10-30 03:19 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2016-02-28 18:35 - 2015-10-30 03:19 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll
2016-02-28 18:35 - 2015-10-30 03:19 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2016-02-28 18:35 - 2015-10-30 03:19 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2016-02-28 18:35 - 2015-10-30 03:19 - 00009096 _____ C:\WINDOWS\SysWOW64\msmqtrc.mof
2016-02-28 18:35 - 2015-10-30 03:18 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqutil.dll
2016-02-28 18:35 - 2015-10-30 03:18 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmconnect.exe
2016-02-28 18:35 - 2015-10-30 03:18 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqrt.dll
2016-02-28 18:35 - 2015-10-30 03:18 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2016-02-28 18:35 - 2015-10-30 03:18 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mqac.sys
2016-02-28 18:35 - 2015-10-30 03:18 - 00144967 _____ C:\WINDOWS\system32\virtmgmt.msc
2016-02-28 18:35 - 2015-10-30 03:18 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqlogmgr.dll
2016-02-28 18:35 - 2015-10-30 03:18 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2016-02-28 18:35 - 2015-10-30 03:18 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2016-02-28 18:35 - 2015-10-30 03:18 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2016-02-28 18:35 - 2015-10-30 03:18 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2016-02-28 18:35 - 2015-10-30 03:18 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2016-02-28 18:34 - 2015-10-30 03:19 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqutil.dll
2016-02-28 18:34 - 2015-10-30 03:19 - 00496640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SMCNative.dll
2016-02-28 18:34 - 2015-10-30 03:19 - 00363520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SMCNative.dll
2016-02-28 18:34 - 2015-10-30 03:19 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqrt.dll
2016-02-28 18:34 - 2015-10-30 03:19 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDEWSProxy.DLL
2016-02-28 18:34 - 2015-10-30 03:19 - 00062464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDRCWSProxy.DLL
2016-02-28 18:34 - 2015-10-30 03:18 - 01417728 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqqm.dll
2016-02-28 18:34 - 2015-10-30 03:18 - 00813056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll
2016-02-28 18:34 - 2015-10-30 03:18 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.dll
2016-02-28 18:34 - 2015-10-30 03:18 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteFileBrowse.dll
2016-02-28 18:34 - 2015-10-30 03:18 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.tlb
2016-02-28 18:34 - 2015-10-30 03:18 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa30.tlb
2016-02-28 18:34 - 2015-10-30 03:18 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa20.tlb
2016-02-28 18:34 - 2015-10-30 03:18 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqbkup.exe
2016-02-28 18:34 - 2015-10-30 03:18 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa10.tlb
2016-02-28 18:34 - 2015-10-30 03:18 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe
2016-02-28 18:34 - 2015-10-30 03:18 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcertui.dll
2016-02-28 18:34 - 2015-10-30 03:18 - 00009096 _____ C:\WINDOWS\system32\msmqtrc.mof
2016-02-28 16:51 - 2015-10-30 03:24 - 00000000 ___RD C:\WINDOWS\DevicesFlow
2016-02-28 16:39 - 2015-10-30 03:24 - 00000000 __RHD C:\Users\Public\Libraries
2016-02-28 16:36 - 2015-10-30 03:24 - 00000000 ___RD C:\WINDOWS\PrintDialog
2016-02-28 16:36 - 2015-10-30 03:24 - 00000000 ___RD C:\WINDOWS\MiracastView
2016-02-28 16:36 - 2015-10-30 03:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-02-28 16:33 - 2013-10-17 09:58 - 00013338 _____ C:\WINDOWS\diagwrn.xml
2016-02-28 16:33 - 2013-10-17 09:58 - 00013338 _____ C:\WINDOWS\diagerr.xml
2016-02-28 16:29 - 2015-07-03 10:17 - 00003466 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineUA
2016-02-28 16:29 - 2012-11-26 23:52 - 00002230 _____ C:\WINDOWS\System32\Tasks\{B0244296-106F-4D0B-A9DC-1BDF2A003F1A}
2016-02-28 16:29 - 2012-03-07 23:56 - 00002306 _____ C:\WINDOWS\System32\Tasks\{92A20A3C-BB16-48F7-87B1-8C3AD640E668}
2016-02-28 16:29 - 2012-02-26 18:59 - 00002474 _____ C:\WINDOWS\System32\Tasks\{F9A6D05F-0CA8-4A70-A6C5-CEF5DCCC0517}
2016-02-28 16:29 - 2010-01-17 10:46 - 00022840 _____ C:\WINDOWS\system32\emptyregdb.dat
2016-02-28 16:29 - 2009-06-01 07:46 - 00002500 _____ C:\WINDOWS\System32\Tasks\{5161C6E5-8716-470C-A7BA-A53536A77D00}
2016-02-28 16:29 - 2009-05-31 07:28 - 00002474 _____ C:\WINDOWS\System32\Tasks\{11BD38B9-952A-4A3D-82E7-02177D8C6368}
2016-02-28 16:28 - 2016-02-02 05:13 - 00002702 _____ C:\WINDOWS\System32\Tasks\GarminUpdaterTask
2016-02-28 16:28 - 2016-01-14 18:24 - 00002954 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2016-02-28 16:28 - 2015-11-12 01:05 - 00002110 _____ C:\WINDOWS\System32\Tasks\USER_ESRV_SVC_WILLAMETTE
2016-02-28 16:28 - 2015-10-02 12:59 - 00002596 _____ C:\WINDOWS\System32\Tasks\RtlNetworkGenieVistaStart
2016-02-28 16:28 - 2015-07-03 10:17 - 00003238 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineCore
2016-02-28 16:28 - 2014-04-13 09:46 - 00002420 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe
2016-02-28 16:28 - 2014-04-13 09:46 - 00002394 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe
2016-02-28 16:28 - 2014-04-13 09:46 - 00002392 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_itype_exe
2016-02-28 16:28 - 2014-04-13 09:46 - 00002378 _____ C:\WINDOWS\System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe
2016-02-28 16:28 - 2014-04-13 09:46 - 00002376 _____ C:\WINDOWS\System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe
2016-02-28 16:28 - 2013-10-01 18:47 - 00002284 _____ C:\WINDOWS\System32\Tasks\{85D6C398-880E-46AA-8865-29AE6A9AAB12}
2016-02-28 16:28 - 2013-06-28 15:38 - 00002496 _____ C:\WINDOWS\System32\Tasks\{EC2449BD-1D10-44A2-BF0E-E6CA3F2E20D5}
2016-02-28 16:28 - 2012-11-26 23:52 - 00002230 _____ C:\WINDOWS\System32\Tasks\{99E02DFE-AB3C-433C-9A21-C5478CC9EA1B}
2016-02-28 16:28 - 2012-11-26 23:51 - 00002290 _____ C:\WINDOWS\System32\Tasks\{673FCEC9-C906-419C-A7FE-F917C5A54391}
2016-02-28 16:28 - 2012-11-26 23:49 - 00002230 _____ C:\WINDOWS\System32\Tasks\{A37C957F-2DA0-4674-93AC-042AC1011B5C}
2016-02-28 16:28 - 2012-11-26 23:49 - 00002230 _____ C:\WINDOWS\System32\Tasks\{2076E5D0-40B1-47E9-9BF0-92D993376E48}
2016-02-28 16:28 - 2012-11-19 14:46 - 00002940 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2422629387-1192540806-1023300286-1001
2016-02-28 16:28 - 2012-08-02 08:26 - 00002302 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_devicecenter_exe
2016-02-28 16:28 - 2012-04-10 20:24 - 00002290 _____ C:\WINDOWS\System32\Tasks\{8B819B5F-817A-43A4-BEE5-F32E5DDB3E1F}
2016-02-28 16:28 - 2012-03-08 11:39 - 00002444 _____ C:\WINDOWS\System32\Tasks\{925F4877-50AA-4C16-BB11-8FDEB1BC13D5}
2016-02-28 16:28 - 2012-03-08 00:15 - 00002454 _____ C:\WINDOWS\System32\Tasks\{06C4C5B1-E542-4491-9095-DA347EBE0E63}
2016-02-28 16:28 - 2012-03-08 00:14 - 00002306 _____ C:\WINDOWS\System32\Tasks\{B96F3914-91FB-45F5-80DA-CAD3B29B7B9A}
2016-02-28 16:28 - 2012-03-07 23:58 - 00002368 _____ C:\WINDOWS\System32\Tasks\{6BBC2489-F6BA-49F1-8589-9FE43DBE816F}
2016-02-28 16:28 - 2011-08-26 07:43 - 00002848 _____ C:\WINDOWS\System32\Tasks\Ad-Aware Update (Weekly)
2016-02-28 16:28 - 2011-05-02 14:38 - 00002446 _____ C:\WINDOWS\System32\Tasks\{55C5439E-22A8-43EE-98ED-608E90607E83}
2016-02-28 16:28 - 2011-04-13 17:51 - 00002282 _____ C:\WINDOWS\System32\Tasks\{CD9CC6C6-EECB-4B53-B03B-A88A9FE4D5C4}
2016-02-28 16:28 - 2011-04-13 14:58 - 00002284 _____ C:\WINDOWS\System32\Tasks\{AD25BAE5-5BF3-44F2-93F9-DD14EA5BA378}
2016-02-28 16:28 - 2011-04-01 15:47 - 00002460 _____ C:\WINDOWS\System32\Tasks\{52705735-45C3-465C-A9E9-838A335E36D5}
2016-02-28 16:28 - 2010-12-26 21:21 - 00002388 _____ C:\WINDOWS\System32\Tasks\{2C222F8B-8655-4596-BC43-9E00CA27605A}
2016-02-28 16:28 - 2010-12-26 21:16 - 00002328 _____ C:\WINDOWS\System32\Tasks\{9A1A3A8A-9C95-484A-BF10-D5DE70BEEDD0}
2016-02-28 16:28 - 2010-12-26 21:12 - 00002474 _____ C:\WINDOWS\System32\Tasks\{4D435EF2-D173-4941-9489-97612D7FA77E}
2016-02-28 16:28 - 2010-10-04 22:29 - 00002264 _____ C:\WINDOWS\System32\Tasks\{1522B97A-7AFB-4E52-BC3E-B2D53B1A058B}
2016-02-28 16:28 - 2010-10-04 21:01 - 00002324 _____ C:\WINDOWS\System32\Tasks\{3E99A261-2581-48C4-A590-F43E9B5E2E19}
2016-02-28 16:28 - 2010-10-04 15:54 - 00002326 _____ C:\WINDOWS\System32\Tasks\{559FBC8A-2500-4990-A579-D11EBDAFA1D6}
2016-02-28 16:28 - 2010-08-03 22:28 - 00002486 _____ C:\WINDOWS\System32\Tasks\{B8F41E86-FA35-4B20-8641-AD0113A7B6ED}
2016-02-28 16:28 - 2010-06-08 13:23 - 00002282 _____ C:\WINDOWS\System32\Tasks\{5064A034-C19B-470A-BF97-52F41E3EF2CD}
2016-02-28 16:28 - 2010-06-08 08:55 - 00002350 _____ C:\WINDOWS\System32\Tasks\{6357106F-E86E-4551-888E-D296629E7AD9}
2016-02-28 16:28 - 2010-06-01 08:50 - 00002336 _____ C:\WINDOWS\System32\Tasks\{F51332D8-0A84-4473-B9DA-294F0E951D8D}
2016-02-28 16:28 - 2010-06-01 08:10 - 00002310 _____ C:\WINDOWS\System32\Tasks\{1D0115F3-7EB5-4628-87F5-0FB1E32A8124}
2016-02-28 16:28 - 2010-04-20 08:36 - 00002376 _____ C:\WINDOWS\System32\Tasks\{601A886E-ED48-47AC-A953-0EE44CEFE50F}
2016-02-28 16:28 - 2010-03-13 11:33 - 00002380 _____ C:\WINDOWS\System32\Tasks\{22A0722E-C7B8-44D0-85C1-5B583665CFA3}
2016-02-28 16:28 - 2010-03-13 11:19 - 00002346 _____ C:\WINDOWS\System32\Tasks\{90D5C0A6-FCED-4E73-955A-83053C6860F5}
2016-02-28 16:28 - 2010-03-09 14:06 - 00002522 _____ C:\WINDOWS\System32\Tasks\{F6B21D2B-64F6-4C32-9274-CF99C90CF777}
2016-02-28 16:28 - 2010-03-09 12:15 - 00002522 _____ C:\WINDOWS\System32\Tasks\{DBAEC886-D4B6-4EE9-8173-208B808B650B}
2016-02-28 16:28 - 2010-02-19 16:09 - 00002500 _____ C:\WINDOWS\System32\Tasks\{B6819DEC-8F43-4204-8D2D-4004204CD20F}
2016-02-28 16:28 - 2010-01-13 13:43 - 00002434 _____ C:\WINDOWS\System32\Tasks\{7CCBAD76-A320-423C-9624-84B2594BADEA}
2016-02-28 16:28 - 2009-12-16 09:55 - 00002522 _____ C:\WINDOWS\System32\Tasks\{3F61827E-3E30-434E-9A5A-92E564B67977}
2016-02-28 16:28 - 2009-11-14 19:31 - 00002480 _____ C:\WINDOWS\System32\Tasks\{C190FB0B-DB3E-44F6-8649-56A5963C2B38}
2016-02-28 16:28 - 2009-10-14 14:57 - 00002146 _____ C:\WINDOWS\System32\Tasks\{8170DE13-857B-40D9-B95C-BA357B417F82}
2016-02-28 16:28 - 2009-10-14 08:58 - 00002240 _____ C:\WINDOWS\System32\Tasks\{E4E3C965-15E4-400A-9471-BD27BAD08D16}
2016-02-28 16:28 - 2009-08-11 16:11 - 00002522 _____ C:\WINDOWS\System32\Tasks\{B7061DD3-B48C-4EE0-B64A-45275BD38679}
2016-02-28 16:28 - 2009-07-05 11:31 - 00003436 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-02-28 16:28 - 2009-07-05 11:31 - 00003212 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-02-28 16:28 - 2009-06-16 16:25 - 00002512 _____ C:\WINDOWS\System32\Tasks\{2328726C-00B8-4AFB-95D9-B373F6BF2592}
2016-02-28 16:28 - 2009-06-12 09:46 - 00002476 _____ C:\WINDOWS\System32\Tasks\{ACA24D27-A509-4B6E-B4C8-F924B0E020CB}
2016-02-28 16:28 - 2009-06-02 15:43 - 00002322 _____ C:\WINDOWS\System32\Tasks\{4C40EB50-C540-4449-96F7-A1C0985134E2}
2016-02-28 16:28 - 2009-06-01 13:06 - 00002466 _____ C:\WINDOWS\System32\Tasks\{8E8C7A9B-28C2-469C-B99E-9D13992D3CE5}
2016-02-28 16:28 - 2009-06-01 11:58 - 00002260 _____ C:\WINDOWS\System32\Tasks\{722A8DCD-4F9A-436C-A38D-C60A7E21E715}
2016-02-28 16:28 - 2009-05-31 07:30 - 00002462 _____ C:\WINDOWS\System32\Tasks\{9AA7D089-7A1E-499B-8908-1554FB42BD78}
2016-02-28 16:28 - 2009-05-31 06:42 - 00002224 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_rundll32_exe
2016-02-28 16:28 - 2009-05-31 06:32 - 00002182 _____ C:\WINDOWS\System32\Tasks\{2D76B571-87D1-4189-8950-4A0DB9E8AE83}
2016-02-28 16:26 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2016-02-28 16:14 - 2015-10-30 02:28 - 00000000 ____D C:\Users\Default.migrated
2016-02-28 16:10 - 2015-10-30 05:02 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
2016-02-28 16:10 - 2015-10-30 05:02 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
2016-02-28 16:10 - 2015-10-30 05:02 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr
2016-02-28 16:10 - 2015-10-30 03:24 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2016-02-28 16:10 - 2015-10-30 03:24 - 00000000 ___SD C:\WINDOWS\SysWOW64\Configuration
2016-02-28 16:10 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\Web
2016-02-28 16:10 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI
2016-02-28 16:10 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2016-02-28 16:10 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2016-02-28 16:10 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2016-02-28 16:10 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2016-02-28 16:10 - 2015-10-07 16:00 - 00000000 ____D C:\WINDOWS\SysWOW64\5.1.1857
2016-02-28 16:10 - 2015-07-13 13:21 - 00000000 ____D C:\WINDOWS\SysWOW64\4.9.1762
2016-02-28 16:10 - 2015-06-18 15:19 - 00000000 ____D C:\WINDOWS\SysWOW64\4.8.1689
2016-02-28 16:10 - 2015-06-17 15:49 - 00000000 ____D C:\WINDOWS\SysWOW64\4.7.1574
2016-02-28 16:10 - 2015-03-24 14:40 - 00000000 ____D C:\WINDOWS\SysWOW64\LiveUpdate
2016-02-28 16:10 - 2012-05-08 14:00 - 00000000 __SHD C:\WINDOWS\SysWOW64\%APPDATA%
2016-02-28 16:10 - 2012-03-08 12:13 - 00000000 ____D C:\WINDOWS\SysWOW64\Samsung_USB_Drivers
2016-02-28 16:10 - 2010-10-05 14:48 - 00000000 ____D C:\WINDOWS\SysWOW64\PhotoImpression Slideshow
2016-02-28 16:10 - 2009-05-31 07:19 - 00000000 ____D C:\WINDOWS\SysWOW64\Futuremark
2016-02-28 16:09 - 2015-10-30 05:07 - 00000000 ____D C:\WINDOWS\ShellNew
2016-02-28 16:09 - 2015-10-30 05:02 - 00000000 ____D C:\WINDOWS\system32\WCN
2016-02-28 16:09 - 2015-10-30 05:02 - 00000000 ____D C:\WINDOWS\system32\slmgr
2016-02-28 16:09 - 2015-10-30 03:24 - 00000000 ___SD C:\WINDOWS\system32\Configuration
2016-02-28 16:09 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\spool
2016-02-28 16:09 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-02-28 16:09 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-02-28 16:09 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\MUI
2016-02-28 16:09 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\InputMethod
2016-02-28 16:09 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\IME
2016-02-28 16:09 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\schemas
2016-02-28 16:09 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\Resources
2016-02-28 16:09 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2016-02-28 16:09 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\ModemLogs
2016-02-28 16:09 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2016-02-28 16:09 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\InputMethod
2016-02-28 16:09 - 2013-08-22 11:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Shared
2016-02-28 16:09 - 2013-08-22 11:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared
2016-02-28 16:09 - 2012-05-08 15:15 - 00000000 __SHD C:\WINDOWS\system32\%APPDATA%
2016-02-28 16:09 - 2011-02-22 15:58 - 00000000 ____D C:\WINDOWS\system32\SPReview
2016-02-28 16:09 - 2011-02-22 15:57 - 00000000 ____D C:\WINDOWS\system32\EventProviders
2016-02-28 16:09 - 2009-06-09 19:36 - 00000000 ____D C:\WINDOWS\system32\appmgmt
2016-02-28 16:09 - 2009-05-26 15:51 - 00000000 ___HD C:\WINDOWS\system32\CanonIJ Uninstaller Information
2016-02-28 16:08 - 2016-02-05 11:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NAPS2
2016-02-28 16:08 - 2015-12-20 22:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-02-28 16:08 - 2015-12-19 18:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitvise SSH Client
2016-02-28 16:08 - 2015-12-18 10:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-LINK
2016-02-28 16:08 - 2015-11-12 20:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag
2016-02-28 16:08 - 2015-11-12 18:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
2016-02-28 16:08 - 2015-11-12 17:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre 64bit - E-book Management
2016-02-28 16:08 - 2015-11-12 01:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Driver Update Utility
2016-02-28 16:08 - 2015-10-30 05:02 - 00000000 ____D C:\WINDOWS\DigitalLocker
2016-02-28 16:08 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\Help
2016-02-28 16:08 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\Cursors
2016-02-28 16:08 - 2015-10-30 03:24 - 00000000 ____D C:\ProgramData\USOPrivate
2016-02-28 16:08 - 2015-10-30 03:24 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2016-02-28 16:08 - 2015-10-30 03:24 - 00000000 ____D C:\Program Files\Common Files\System
2016-02-28 16:08 - 2015-10-30 03:24 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2016-02-28 16:08 - 2015-08-14 23:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Utilities 16
2016-02-28 16:08 - 2015-08-12 09:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI® Intel® Extreme Tuning Utility
2016-02-28 16:08 - 2015-08-09 17:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xiph.Org
2016-02-28 16:08 - 2015-07-30 22:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2016-02-28 16:08 - 2015-06-02 20:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\dBpoweramp
2016-02-28 16:08 - 2015-06-01 17:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-02-28 16:08 - 2015-05-07 07:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TomTom
2016-02-28 16:08 - 2015-04-04 23:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel® Processor Identification Utility
2016-02-28 16:08 - 2015-03-01 00:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Handbrake
2016-02-28 16:08 - 2015-01-15 14:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-02-28 16:08 - 2014-10-16 17:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-02-28 16:08 - 2014-08-18 15:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Documents To Go Desktop for BlackBerry
2016-02-28 16:08 - 2014-08-02 21:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
2016-02-28 16:08 - 2014-05-29 13:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JMicron Technology Corp
2016-02-28 16:08 - 2014-05-15 11:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative
2016-02-28 16:08 - 2014-05-07 16:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
2016-02-28 16:08 - 2014-04-27 15:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMLite Workstation
2016-02-28 16:08 - 2014-04-13 09:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Mouse and Keyboard Center
2016-02-28 16:08 - 2013-12-10 18:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
2016-02-28 16:08 - 2013-12-02 15:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2016-02-28 16:08 - 2013-11-07 20:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Learn to Play Bridge
2016-02-28 16:08 - 2013-09-29 23:55 - 00000000 ___RD C:\Users\Public\Recorded TV
2016-02-28 16:08 - 2013-08-22 11:36 - 00000000 ____D C:\WINDOWS\ADFS
2016-02-28 16:08 - 2013-06-19 14:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhoneTray Pro
2016-02-28 16:08 - 2013-05-23 21:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2012
2016-02-28 16:08 - 2013-02-20 18:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Okidata
2016-02-28 16:08 - 2013-02-20 18:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-Link Network Print Server
2016-02-28 16:08 - 2013-02-03 22:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stardock
2016-02-28 16:08 - 2012-11-29 13:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NeoSmart Technologies
2016-02-28 16:08 - 2012-11-26 00:08 - 00000000 ____D C:\Program Files\Microsoft Games
2016-02-28 16:08 - 2012-11-19 20:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\8GadgetPack
2016-02-28 16:08 - 2012-05-08 15:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-02-28 16:08 - 2012-02-16 00:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\smartmontools
2016-02-28 16:08 - 2012-02-15 21:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seagate
2016-02-28 16:08 - 2011-11-15 10:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOL
2016-02-28 16:08 - 2011-10-14 12:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yahoo! Messenger
2016-02-28 16:08 - 2011-05-22 23:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SolidWorks 2011
2016-02-28 16:08 - 2011-04-13 17:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime Alternative
2016-02-28 16:08 - 2011-03-01 15:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vista Caller-ID
2016-02-28 16:08 - 2011-02-22 23:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Nvidia Demos
2016-02-28 16:08 - 2010-12-08 22:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Bootable Recovery Tool Wizard
2016-02-28 16:08 - 2010-10-19 22:42 - 00000000 ____D C:\WINDOWS\en
2016-02-28 16:08 - 2010-10-04 15:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon iP4200 Manual
2016-02-28 16:08 - 2010-10-04 14:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2016-02-28 16:08 - 2010-09-29 14:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Jodix
2016-02-28 16:08 - 2010-09-14 16:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Meeting 2007
2016-02-28 16:08 - 2010-09-07 10:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shark007 Codecs
2016-02-28 16:08 - 2010-05-26 05:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in
2016-02-28 16:08 - 2010-05-13 12:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Audio Pack
2016-02-28 16:08 - 2010-01-16 09:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2016-02-28 16:08 - 2010-01-06 21:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Longman iBT Prep 2.0
2016-02-28 16:08 - 2009-11-14 19:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DOSBox-0.73
2016-02-28 16:08 - 2009-10-26 18:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Karen's Power Tools
2016-02-28 16:08 - 2009-10-26 16:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IrfanView
2016-02-28 16:08 - 2009-10-14 14:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Presto! PageManager 6
2016-02-28 16:08 - 2009-08-20 22:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\APC
2016-02-28 16:08 - 2009-06-01 15:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2016-02-28 16:08 - 2009-06-01 11:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visioneer Pro OCR 100
2016-02-28 16:08 - 2009-06-01 07:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Futuremark
2016-02-28 16:08 - 2009-05-31 06:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetWaiting
2016-02-28 16:08 - 2009-05-31 06:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FaxTalk Communicator SE 4.7
2016-02-28 16:08 - 2009-05-30 20:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 8
2016-02-28 16:08 - 2009-05-27 15:19 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
2016-02-28 16:08 - 2009-05-26 15:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon iP4200
2016-02-28 16:07 - 2009-04-22 03:16 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2016-02-28 16:06 - 2016-02-04 12:11 - 00000000 ____D C:\Users\Bill Pierce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
2016-02-28 16:06 - 2015-12-07 23:33 - 00000000 ____D C:\Users\Bill Pierce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Holy Spirit, Southsea
2016-02-28 16:06 - 2015-10-02 23:15 - 00000000 ____D C:\Users\Bill Pierce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2007
2016-02-28 16:06 - 2015-08-28 00:08 - 00000000 ____D C:\Users\Bill Pierce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AIM for Windows
2016-02-28 16:06 - 2015-08-01 09:42 - 00000000 ____D C:\Users\Bill Pierce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kodi
2016-02-28 16:06 - 2015-01-08 15:57 - 00000000 ____D C:\Users\Bill Pierce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TomTomHeaven
2016-02-28 16:06 - 2014-09-25 19:22 - 00000000 ____D C:\Users\Bill Pierce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton
2016-02-28 16:06 - 2012-11-26 00:08 - 00000000 ____D C:\Users\Bill Pierce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2016-02-28 16:06 - 2012-11-26 00:08 - 00000000 ____D C:\Users\Bill Pierce\AppData\Roaming\Microsoft\Windows\Start Menu\Games
2016-02-28 16:06 - 2012-11-20 17:09 - 00000000 ____D C:\Users\Bill Pierce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VMLite Workstation
2016-02-28 16:06 - 2012-10-11 09:20 - 00000000 ____D C:\Users\Bill Pierce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Balabolka
2016-02-28 16:06 - 2011-12-05 11:14 - 00000000 ____D C:\Users\Bill Pierce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FirstClass
2016-02-28 16:06 - 2011-11-15 16:56 - 00000000 ____D C:\Users\Bill Pierce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CS2Outlook 1.0
2016-02-28 16:06 - 2011-10-01 14:51 - 00000000 ____D C:\Users\Bill Pierce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Network utilities - old
2016-02-28 16:06 - 2010-10-07 17:04 - 00000000 ____D C:\Users\Bill Pierce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2016-02-28 16:06 - 2010-09-17 17:43 - 00000000 ____D C:\Users\Bill Pierce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BootDisk2BootStick
2016-02-28 16:06 - 2009-06-23 18:27 - 00000000 ___RD C:\Users\Bill Pierce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Virtual PC
2016-02-28 16:06 - 2009-06-04 14:52 - 00000000 ____D C:\Users\Bill Pierce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Walmart
2016-02-28 16:06 - 2009-06-04 07:38 - 00000000 ____D C:\Users\Bill Pierce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ProMash
2016-02-28 16:06 - 2009-06-01 12:11 - 00000000 ____D C:\Users\Bill Pierce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016
2016-02-28 16:02 - 2012-09-13 21:39 - 00000000 ____D C:\temp
2016-02-28 15:57 - 2015-10-30 05:14 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2016-02-25 14:30 - 2013-05-27 19:31 - 00000000 ____D C:\Users\Bill Pierce\AppData\Local\NVIDIA
2016-02-25 14:30 - 2010-01-16 22:38 - 00000000 ____D C:\Users\Bill Pierce\AppData\Local\NVIDIA Corporation
2016-02-18 11:06 - 2010-08-14 20:27 - 00000000 ____D C:\Program Files (x86)\QuickTime
2016-02-17 17:04 - 2015-07-03 10:17 - 00000000 ____D C:\Program Files (x86)\Dropbox
2016-02-17 02:40 - 2016-01-31 23:52 - 00112216 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll
2016-02-17 02:40 - 2014-08-16 14:39 - 01903344 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2016-02-17 02:40 - 2014-08-16 14:39 - 01756424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2016-02-17 02:40 - 2014-08-16 14:39 - 01571624 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2016-02-17 02:40 - 2014-08-16 14:39 - 01316184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
==================== Files in the root of some directories =======
2013-04-18 13:06 - 2013-04-18 13:06 - 0023294 _____ () C:\Users\Bill Pierce\AppData\Roaming\Comma Separated Values (DOS).ADR
2014-10-11 17:16 - 2014-10-11 17:16 - 0024769 _____ () C:\Users\Bill Pierce\AppData\Roaming\Comma Separated Values (Windows).ADR
2013-06-03 19:05 - 2013-06-20 23:33 - 0007444 _____ () C:\Users\Bill Pierce\AppData\Roaming\Comma Separated Values (Windows).EML
2009-05-31 22:38 - 2009-06-04 16:02 - 0000042 _____ () C:\Users\Bill Pierce\AppData\Roaming\default.pls
2013-04-16 22:43 - 2016-03-13 00:51 - 0037319 _____ () C:\Users\Bill Pierce\AppData\Roaming\Rim.Desktop.Exception.log
2013-04-16 22:42 - 2016-03-11 09:09 - 0017168 _____ () C:\Users\Bill Pierce\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2013-04-16 22:43 - 2016-03-13 00:51 - 0031570 _____ () C:\Users\Bill Pierce\AppData\Roaming\Rim.DesktopHelper.Exception.log
2013-05-31 19:08 - 2016-03-13 00:51 - 0026334 _____ () C:\Users\Bill Pierce\AppData\Roaming\Rim.Transcoder.Exception.log
2012-04-20 21:30 - 2012-05-10 10:18 - 0000156 _____ () C:\Users\Bill Pierce\AppData\Roaming\Safer-Networking.log
2009-12-20 23:43 - 2009-12-20 23:43 - 0000008 _____ () C:\Users\Bill Pierce\AppData\Roaming\usb.dat.bin
2012-07-28 22:54 - 2016-03-04 09:08 - 0013312 _____ () C:\Users\Bill Pierce\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-10-10 11:35 - 2013-10-10 11:35 - 0000218 _____ () C:\Users\Bill Pierce\AppData\Local\recently-used.xbel
2011-09-10 22:45 - 2016-02-11 17:44 - 0007607 _____ () C:\Users\Bill Pierce\AppData\Local\resmon.resmoncfg
2015-06-15 13:20 - 2015-06-15 13:20 - 0019535 _____ () C:\ProgramData\empty.ico
Some files in TEMP:
====================
C:\Users\Bill Pierce\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-03-11 09:30
==================== End of FRST.txt ============================