I keep getting advertisements even after running programs: rkill, malwarebytes, adwcleaner, malware junk removal tool, hitmanpro. Here is the FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-08-2016
Ran by lukew (administrator) on DESKTOP-BFMU3EB (29-08-2016 00:00:58)
Running from C:\Users\lukew\Downloads
Loaded Profiles: lukew (Available Profiles: lukew)
Platform: Windows 10 Pro Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Bitdefender) C:\Program Files\Bitdefender Antivirus Free\vsserv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Bitdefender) C:\Program Files\Bitdefender Antivirus Free\updatesrv.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Bitdefender) C:\Program Files\Bitdefender Antivirus Free\bdagent.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe
(Microsoft Corporation) C:\Windows\System32\Speech_OneCore\Common\SpeechRuntime.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.7.102.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Spotify Ltd) C:\Users\lukew\AppData\Roaming\Spotify\SpotifyWebHelper.exe
() C:\Users\lukew\AppData\Roaming\AppsolutelyApps\TouchMe\TouchMe.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Microsoft Corporation) C:\Windows\System32\SurfaceService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSYNC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\CSISYNCCLIENT.EXE
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176952 2016-07-26] (Apple Inc.)
HKLM\...\Run: [SurfaceService.exe] => C:\Windows\System32\SurfaceService.exe [710408 2016-07-26] (Microsoft Corporation)
HKU\S-1-5-21-583132838-3792314683-1425707835-1001\...\Run: [Spotify Web Helper] => C:\Users\lukew\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1523312 2016-08-23] (Spotify Ltd)
HKU\S-1-5-21-583132838-3792314683-1425707835-1001\...\Run: [Spotify] => C:\Users\lukew\AppData\Roaming\Spotify\Spotify.exe [6930544 2016-08-23] (Spotify Ltd)
HKU\S-1-5-21-583132838-3792314683-1425707835-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8894680 2016-08-05] (Piriform Ltd)
HKU\S-1-5-21-583132838-3792314683-1425707835-1001\...\RunOnce: [Uninstall C:\Users\lukew\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_2\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\lukew\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_2\amd64"
HKU\S-1-5-21-583132838-3792314683-1425707835-1001\...\RunOnce: [Uninstall C:\Users\lukew\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_2] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\lukew\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_2"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2016-08-28]
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\lukew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2016-08-28]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\lukew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Slack.lnk [2016-08-28]
ShortcutTarget: Slack.lnk -> C:\Users\lukew\AppData\Local\slack\Update.exe ()
Startup: C:\Users\lukew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TouchMe Engine.lnk [2016-08-28]
ShortcutTarget: TouchMe Engine.lnk -> C:\Users\lukew\AppData\Roaming\AppsolutelyApps\TouchMe\TouchMe.exe ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{2bd25aa6-d50d-4cb0-8a62-120a7f046e9e}: [NameServer] 188.120.239.115,8.8.8.8
Tcpip\..\Interfaces\{2bd25aa6-d50d-4cb0-8a62-120a7f046e9e}: [DhcpNameServer] 75.75.75.75 75.75.76.76
ManualProxies:
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-583132838-3792314683-1425707835-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-08-16] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-08-16] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-08-16] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-08-16] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-08-16] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-08-16] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-08-16] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-08-16] (Microsoft Corporation)
FireFox:
========
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-12-18] ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-08-16] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-08-16] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-28] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-06-30] (Adobe Systems Inc.)
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR HomePage: Default -> hxxp://google.com/
CHR StartupUrls: Default -> "hxxp://google.com/"
CHR DefaultSearchURL: Default -> hxxp://www-searching.com/search.aspx?site=shdefault1&prd=smw&pid=s&shr=d&q={searchTerms}&s=g8szftpbl0cshmobu,5bf8b142-b597-491a-bc07-b1bd1d2fed9b,
CHR DefaultSearchKeyword: Default -> www-searching.com
CHR DefaultSuggestURL: Default -> hxxp://api.searchpredict.com/api/?rqtype=ffplugin&siteID=8661&dbCode=1&command={searchTerms}
CHR Profile: C:\Users\lukew\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\lukew\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-08-15]
CHR Extension: (Google Docs) - C:\Users\lukew\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-08-15]
CHR Extension: (Google Drive) - C:\Users\lukew\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-08-15]
CHR Extension: (YouTube) - C:\Users\lukew\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-08-15]
CHR Extension: (Google Cast) - C:\Users\lukew\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2016-08-27]
CHR Extension: (Adblock Plus) - C:\Users\lukew\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-08-23]
CHR Extension: (Google Sheets) - C:\Users\lukew\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-08-15]
CHR Extension: (Word Online) - C:\Users\lukew\AppData\Local\Google\Chrome\User Data\Default\Extensions\fiombgjlkfpdpkbhfioofeeinbehmajg [2016-08-15]
CHR Extension: (Google Docs Offline) - C:\Users\lukew\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-08-16]
CHR Extension: (Pomodoro Timer) - C:\Users\lukew\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfgjlgjnpkpmnpojkkpfkogapiclopop [2016-08-18]
CHR Extension: (Kindle Cloud Reader) - C:\Users\lukew\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2016-08-15]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\lukew\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2016-08-15]
CHR Extension: (The Great Suspender) - C:\Users\lukew\AppData\Local\Google\Chrome\User Data\Default\Extensions\klbibkeccnjlkjkiokjodocebajanakg [2016-08-28]
CHR Extension: (Google Dictionary (by Google)) - C:\Users\lukew\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2016-08-15]
CHR Extension: (ChemReference: Periodic Table) - C:\Users\lukew\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjpnebljmdbglkmlnijcaplhfhkhdnib [2016-08-15]
CHR Extension: (Google Play Books) - C:\Users\lukew\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb [2016-08-15]
CHR Extension: (Video Speed Controller) - C:\Users\lukew\AppData\Local\Google\Chrome\User Data\Default\Extensions\nffaoalbilbmmfgbnbgppjihopabppdk [2016-08-21]
CHR Extension: (Chrome Web Store Payments) - C:\Users\lukew\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-08-15]
CHR Extension: (Gmail) - C:\Users\lukew\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-08-15]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2981056 2016-08-11] (Microsoft Corporation)
S3 cplspcon; C:\Windows\system32\IntelCpHDCPSvc.exe [465912 2016-07-14] (Intel Corporation)
S2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [391168 2016-07-14] (Intel Corporation)
R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [991248 2016-06-22] (Bitdefender)
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1570520 2016-02-02] (Secunia)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-07-16] (Microsoft Corporation)
R2 SurfaceService; C:\Windows\system32\SurfaceService.exe [710408 2016-07-26] (Microsoft Corporation)
R2 updatesrv; C:\Program Files\Bitdefender Antivirus Free\updatesrv.exe [100392 2016-07-08] (Bitdefender)
R2 vsserv; C:\Program Files\Bitdefender Antivirus Free\vsserv.exe [100392 2016-07-08] (Bitdefender)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1603264 2016-06-29] (BitDefender)
R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [850464 2016-06-03] (BitDefender)
R1 bdfwfpf; C:\Program Files\Bitdefender Antivirus Free\bdfwfpf.sys [127312 2016-02-22] (BitDefender LLC)
R3 CSI2HostControllerDriver; C:\Windows\System32\drivers\CSI2HostControllerDriver.sys [125456 2016-07-16] (Intel® Corporation)
R0 gzflt; C:\Windows\System32\drivers\gzflt.sys [182936 2015-12-16] (BitDefender LLC)
R3 iacamera64; C:\Windows\system32\DRIVERS\iacamera64.sys [2133520 2016-07-16] (Intel® Corporation)
S3 iaLPSS2_GPIO2; C:\Windows\System32\drivers\iaLPSS2_GPIO2.sys [83768 2016-02-01] (Windows ® Win 7 DDK provider)
S3 iaLPSS2_I2C; C:\Windows\System32\drivers\iaLPSS2_I2C.sys [185144 2016-02-01] (Intel Corporation)
S3 iaLPSS2_SPI; C:\Windows\System32\drivers\iaLPSS2_SPI.sys [152376 2016-02-01] (Intel Corporation)
S3 iaLPSS2_UART2; C:\Windows\System32\drivers\iaLPSS2_UART2.sys [281400 2016-02-01] (Intel Corporation)
R3 IntcAudioBus; C:\Windows\System32\drivers\IntcAudioBus.sys [217672 2016-06-28] (Intel® Corporation)
R3 IntcOED; C:\Windows\System32\drivers\IntcOED.sys [648264 2016-06-28] (Intel® Corporation)
R3 IntTouch; C:\Windows\System32\drivers\iaPreciseTouch.sys [272392 2016-07-21] (Intel Corporation)
R3 mrvlpcie8897; C:\Windows\System32\drivers\mrvlpcie8897.sys [1050112 2016-02-24] (Marvell Semiconductors Inc.)
R3 msux64w10; C:\Windows\System32\drivers\msux64w10.sys [334848 2016-07-16] (Microsoft )
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 ov5693; C:\Windows\System32\drivers\ov5693.sys [164880 2016-07-16] (Intel® Corporation)
R3 ov7251; C:\Windows\System32\drivers\ov7251.sys [156176 2016-07-16] (Intel Corporation)
R3 ov8865; C:\Windows\System32\drivers\ov8865.sys [162320 2016-07-16] (Intel Corporation)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2016-02-02] (Secunia)
R3 SkcController; C:\Windows\System32\drivers\SkcController.sys [170496 2016-07-16] (Intel® Corporation)
R3 supportdriver; C:\Windows\System32\drivers\iaisp64.sys [52752 2016-07-16] (Intel® Corporation)
R3 SurfaceAccessoryDevice; C:\Windows\System32\drivers\SurfaceAccessoryDevice.sys [70264 2015-09-24] (Microsoft Corporation)
R3 SurfaceButton; C:\Windows\System32\drivers\SurfaceButton.sys [128144 2016-06-28] (Microsoft Corporation)
R3 SurfaceCoSAR; C:\Windows\System32\drivers\SurfaceCoSAR.sys [55960 2016-02-01] (Microsoft Corporation)
R3 SurfaceDigitizerIntegration; C:\Windows\System32\drivers\SurfaceDigitizerIntegration.sys [58504 2015-09-24] (Microsoft Corporation)
R3 SurfaceDisplayCalibration; C:\Windows\System32\drivers\SurfaceDisplayCalibration.sys [51344 2016-02-01] (Microsoft Corporation)
R3 SurfaceDockIntegration; C:\Windows\System32\drivers\SurfaceDockIntegration.sys [41232 2016-04-10] (Microsoft Corporation)
R3 SurfaceIntegrationDriver; C:\Windows\System32\drivers\SurfaceIntegrationDriver.sys [110872 2016-07-22] (Microsoft Corporation)
S3 SurfacePenClickFilter; C:\Windows\System32\drivers\SurfacePenClickFilter.sys [56984 2015-09-24] (Microsoft Corporation)
R3 SurfacePenDriver; C:\Windows\System32\drivers\SurfacePenDriver.sys [115592 2016-07-14] (Microsoft Corporation)
S3 SurfacePenIntegration; C:\Windows\System32\drivers\SurfacePenIntegration.sys [61464 2015-09-24] (Microsoft Corporation)
S3 SurfacePro4TypeCoverIntegration; C:\Windows\System32\drivers\SurfacePro4TypeCoverIntegration.sys [59448 2015-09-24] (Microsoft Corporation)
R3 SurfaceStorageFwUpdate; C:\Windows\System32\drivers\SurfaceStorageFwUpdate.sys [2813592 2015-10-21] (Microsoft Corporation)
R3 SurfaceSystemTelemetryDriver; C:\Windows\System32\drivers\SurfaceSystemTelemetryDriver.sys [64000 2015-09-24] (Microsoft Corporation)
R3 SurfaceTouchServicingML; C:\Windows\System32\drivers\SurfaceTouchServicingML.sys [77584 2016-06-28] (Microsoft Corporation)
S3 SurfaceTypeCover; C:\Windows\System32\drivers\SurfaceTypeCover.sys [58896 2015-09-24] (Microsoft Corporation)
R2 trufos; C:\Windows\System32\drivers\trufos.sys [520032 2016-06-22] (BitDefender S.R.L.)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-08-29 00:00 - 2016-08-29 00:01 - 00018606 _____ C:\Users\lukew\Downloads\FRST.txt
2016-08-29 00:00 - 2016-08-29 00:00 - 02396672 _____ (Farbar) C:\Users\lukew\Downloads\FRST64.exe
2016-08-29 00:00 - 2016-08-29 00:00 - 00000000 ____D C:\FRST
2016-08-28 23:51 - 2016-08-28 23:51 - 00003342 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task
2016-08-28 23:50 - 2016-08-28 23:50 - 00000000 ___HD C:\OneDriveTemp
2016-08-28 23:50 - 2016-08-28 23:50 - 00000000 ____D C:\Users\lukew\AppData\Roaming\Skype
2016-08-28 23:48 - 2016-08-28 23:49 - 00003996 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-08-28 23:48 - 2016-08-28 23:49 - 00003764 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-08-28 23:48 - 2016-08-28 23:49 - 00000938 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-08-28 23:48 - 2016-08-28 23:49 - 00000934 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-08-28 23:48 - 2016-08-28 23:48 - 00000000 ____D C:\Program Files (x86)\GUM6E89.tmp
2016-08-28 23:40 - 2016-08-28 23:41 - 00055532 _____ C:\TDSSKiller.3.1.0.11_28.08.2016_23.40.51_log.txt
2016-08-28 23:35 - 2016-08-28 23:35 - 00001152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
2016-08-28 23:35 - 2016-08-28 23:35 - 00000000 ____D C:\Program Files (x86)\Secunia
2016-08-28 22:46 - 2016-08-28 22:46 - 00055456 _____ C:\TDSSKiller.3.1.0.11_28.08.2016_22.46.11_log.txt
2016-08-28 22:44 - 2016-08-28 22:44 - 00005748 _____ C:\TDSSKiller.3.1.0.11_28.08.2016_22.44.51_log.txt
2016-08-28 22:23 - 2016-08-28 23:23 - 00001178 _____ C:\Users\lukew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bitdefender Antivirus Free.lnk
2016-08-28 22:23 - 2016-08-28 22:23 - 00000000 ____D C:\Users\lukew\AppData\Local\Bitdefender Antivirus Free
2016-08-28 22:22 - 2016-08-28 23:23 - 00001211 _____ C:\Users\Public\Desktop\Bitdefender Antivirus Free.lnk
2016-08-28 22:22 - 2016-08-28 22:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender Antivirus Free
2016-08-28 22:22 - 2016-08-28 22:22 - 00000000 ____D C:\ProgramData\Bitdefender
2016-08-28 22:22 - 2015-12-16 04:53 - 00182936 _____ (BitDefender LLC) C:\WINDOWS\system32\Drivers\gzflt.sys
2016-08-28 22:21 - 2016-06-29 18:07 - 01603264 _____ (BitDefender) C:\WINDOWS\system32\Drivers\avc3.sys
2016-08-28 22:21 - 2016-06-22 15:40 - 00520032 _____ (BitDefender S.R.L.) C:\WINDOWS\system32\Drivers\trufos.sys
2016-08-28 22:21 - 2016-06-03 17:05 - 00850464 _____ (BitDefender) C:\WINDOWS\system32\Drivers\avckf.sys
2016-08-28 22:20 - 2016-08-29 00:00 - 00000000 ____D C:\Program Files\Bitdefender Antivirus Free
2016-08-28 22:20 - 2016-08-28 22:20 - 00000000 ____D C:\Users\lukew\AppData\Roaming\QuickScan
2016-08-28 22:18 - 2016-08-28 22:18 - 00003794 _____ C:\WINDOWS\System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864
2016-08-28 22:17 - 2016-08-28 22:17 - 03826240 _____ C:\Users\lukew\Downloads\adwcleaner_6.010.exe
2016-08-28 22:16 - 2016-08-28 23:35 - 00000000 ____D C:\Program Files\Bitdefender Agent
2016-08-28 22:16 - 2016-08-28 22:16 - 00000000 ____D C:\ProgramData\Bitdefender Agent
2016-08-28 22:16 - 2016-08-28 22:16 - 00000000 ____D C:\ProgramData\BDLogging
2016-08-28 22:15 - 2016-08-28 22:15 - 08118408 _____ C:\Users\lukew\Downloads\bitdefender_online.exe
2016-08-28 22:12 - 2016-08-28 22:13 - 48750920 _____ C:\Users\lukew\Downloads\BDPUARLauncher.exe
2016-08-28 20:31 - 2016-08-28 20:31 - 00002870 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2016-08-28 20:31 - 2016-08-28 20:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-08-28 20:31 - 2016-08-28 20:31 - 00000000 ____D C:\Program Files\CCleaner
2016-08-28 20:30 - 2016-08-28 20:30 - 08227032 _____ (Piriform Ltd) C:\Users\lukew\Downloads\ccsetup521.exe
2016-08-28 20:21 - 2016-08-28 20:21 - 00000000 ____D C:\Program Files\HitmanPro
2016-08-28 20:20 - 2016-08-28 23:29 - 00000841 _____ C:\Users\lukew\Desktop\JRT.txt
2016-08-28 19:59 - 2016-08-28 23:45 - 00003940 _____ C:\Users\lukew\Desktop\Rkill.txt
2016-08-27 22:03 - 2016-08-28 20:23 - 00002368 _____ C:\WINDOWS\system32\.crusader
2016-08-27 21:57 - 2016-08-27 22:46 - 00000000 ____D C:\ProgramData\HitmanPro
2016-08-27 21:53 - 2016-08-27 21:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-08-27 21:00 - 2016-08-28 23:46 - 00000000 ____D C:\AdwCleaner
2016-08-27 20:50 - 2016-08-27 20:50 - 00000000 ____D C:\Users\lukew\AppData\Roaming\Macromedia
2016-08-27 20:43 - 2016-08-28 23:19 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-08-27 20:27 - 2016-08-28 21:38 - 00004166 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{10ED8D70-7E45-479F-991B-AA87687699DB}
2016-08-27 20:27 - 2016-08-27 20:27 - 00003849 _____ C:\WINDOWS\system32\hst.pcm
2016-08-27 20:27 - 2016-08-27 20:27 - 00000000 ____D C:\WINDOWS\system32\appmgmt
2016-08-27 20:22 - 2016-08-27 20:22 - 00000000 ____D C:\WINDOWS\SysWOW64\CpuHeatMapping2200
2016-08-27 20:22 - 2016-08-27 20:22 - 00000000 _____ C:\WINDOWS\SysWOW64\Number of results
2016-08-27 20:07 - 2016-08-27 20:30 - 00000000 _____ C:\Users\lukew\AppData\Local\icka17777572.txt
2016-08-27 19:54 - 2016-08-28 19:08 - 00187904 _____ C:\WINDOWS\rsrcs.dll
2016-08-27 19:54 - 2016-08-27 21:07 - 00000000 ____D C:\Users\lukew\AppData\Local\Apps\2.0
2016-08-27 19:54 - 2016-08-27 19:54 - 00138240 _____ C:\Users\lukew\AppData\Roaming\Installer.dat
2016-08-27 19:52 - 2016-08-27 19:50 - 00001006 _____ C:\WINDOWS\system32\Drivers\etc\hp.bak
2016-08-27 19:48 - 2016-08-27 20:34 - 00000000 ____D C:\WINDOWS\system32\SSL
2016-08-27 19:48 - 2016-08-27 19:48 - 00000000 ____D C:\Users\lukew\AppData\Roaming\c
2016-08-25 15:33 - 2016-08-25 15:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPUB File Reader
2016-08-25 15:33 - 2016-08-25 15:33 - 00000000 ____D C:\Program Files (x86)\EPUB File Reader
2016-08-23 17:53 - 2016-08-05 23:08 - 02251432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-08-23 17:53 - 2016-08-05 23:04 - 00361096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll
2016-08-23 17:53 - 2016-08-05 22:42 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ClipboardServer.dll
2016-08-23 17:53 - 2016-08-05 22:41 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncPolicy.dll
2016-08-23 17:53 - 2016-08-05 22:37 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2016-08-23 17:53 - 2016-08-05 22:31 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2016-08-23 17:53 - 2016-08-05 22:30 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2016-08-23 17:53 - 2016-08-05 22:29 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2016-08-23 17:53 - 2016-08-05 22:25 - 01595904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-08-23 17:53 - 2016-08-05 22:24 - 02026496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2016-08-23 17:53 - 2016-08-05 04:10 - 00939872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pidgenx.dll
2016-08-23 17:53 - 2016-08-05 03:29 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.UXRes.dll
2016-08-23 17:53 - 2016-08-05 03:23 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppc.dll
2016-08-23 17:53 - 2016-08-05 03:18 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slc.dll
2016-08-23 17:53 - 2016-08-05 03:07 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2016-08-23 17:52 - 2016-08-05 23:24 - 01570680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2016-08-23 17:52 - 2016-08-05 23:17 - 00790760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2016-08-23 17:52 - 2016-08-05 23:08 - 01430208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2016-08-23 17:52 - 2016-08-05 23:08 - 00843104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2016-08-23 17:52 - 2016-08-05 23:08 - 00509784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2016-08-23 17:52 - 2016-08-05 23:08 - 00313560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2016-08-23 17:52 - 2016-08-05 23:03 - 20965240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-08-23 17:52 - 2016-08-05 23:03 - 01557296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2016-08-23 17:52 - 2016-08-05 23:03 - 01360456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2016-08-23 17:52 - 2016-08-05 23:03 - 01343928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2016-08-23 17:52 - 2016-08-05 23:03 - 00980824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2016-08-23 17:52 - 2016-08-05 23:03 - 00955008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2016-08-23 17:52 - 2016-08-05 23:03 - 00529928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2016-08-23 17:52 - 2016-08-05 23:03 - 00036168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
2016-08-23 17:52 - 2016-08-05 23:02 - 00321280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2016-08-23 17:52 - 2016-08-05 22:50 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2016-08-23 17:52 - 2016-08-05 22:48 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2016-08-23 17:52 - 2016-08-05 22:48 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2016-08-23 17:52 - 2016-08-05 22:48 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanhlp.dll
2016-08-23 17:52 - 2016-08-05 22:48 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spwmp.dll
2016-08-23 17:52 - 2016-08-05 22:48 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdxm.ocx
2016-08-23 17:52 - 2016-08-05 22:48 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxmasf.dll
2016-08-23 17:52 - 2016-08-05 22:46 - 09260032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmploc.DLL
2016-08-23 17:52 - 2016-08-05 22:45 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll
2016-08-23 17:52 - 2016-08-05 22:45 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll
2016-08-23 17:52 - 2016-08-05 22:45 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2016-08-23 17:52 - 2016-08-05 22:45 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netiougc.exe
2016-08-23 17:52 - 2016-08-05 22:44 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2016-08-23 17:52 - 2016-08-05 22:44 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceassociation.dll
2016-08-23 17:52 - 2016-08-05 22:42 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2016-08-23 17:52 - 2016-08-05 22:41 - 13867520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-08-23 17:52 - 2016-08-05 22:41 - 00554496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2016-08-23 17:52 - 2016-08-05 22:41 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudBackupSettings.dll
2016-08-23 17:52 - 2016-08-05 22:40 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2016-08-23 17:52 - 2016-08-05 22:40 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe
2016-08-23 17:52 - 2016-08-05 22:39 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tcpipcfg.dll
2016-08-23 17:52 - 2016-08-05 22:37 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-08-23 17:52 - 2016-08-05 22:37 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll
2016-08-23 17:52 - 2016-08-05 22:36 - 19422720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-08-23 17:52 - 2016-08-05 22:35 - 07624192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-08-23 17:52 - 2016-08-05 22:34 - 19418624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-08-23 17:52 - 2016-08-05 22:33 - 01304576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2016-08-23 17:52 - 2016-08-05 22:33 - 01106432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2016-08-23 17:52 - 2016-08-05 22:33 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smphost.dll
2016-08-23 17:52 - 2016-08-05 22:31 - 12174336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-08-23 17:52 - 2016-08-05 22:31 - 02710528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2016-08-23 17:52 - 2016-08-05 22:30 - 12345344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2016-08-23 17:52 - 2016-08-05 22:28 - 00544768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
2016-08-23 17:52 - 2016-08-05 22:28 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinesam.dll
2016-08-23 17:52 - 2016-08-05 22:28 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2016-08-23 17:52 - 2016-08-05 22:27 - 00640000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2016-08-23 17:52 - 2016-08-05 22:26 - 02422784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAJApi.dll
2016-08-23 17:52 - 2016-08-05 22:26 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-08-23 17:52 - 2016-08-05 22:24 - 01875456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-08-23 17:52 - 2016-08-05 22:23 - 00860672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2016-08-23 17:52 - 2016-08-05 22:21 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll
2016-08-23 17:52 - 2016-08-05 03:29 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slcext.dll
2016-08-23 17:52 - 2016-08-05 03:20 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll
2016-08-23 17:51 - 2016-08-05 23:33 - 00354264 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2016-08-23 17:51 - 2016-08-05 23:32 - 01046976 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-08-23 17:51 - 2016-08-05 23:32 - 00885832 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-08-23 17:51 - 2016-08-05 23:31 - 00077664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2016-08-23 17:51 - 2016-08-05 23:31 - 00041824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe
2016-08-23 17:51 - 2016-08-05 23:30 - 07814496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-08-23 17:51 - 2016-08-05 23:30 - 01883784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-08-23 17:51 - 2016-08-05 23:30 - 01349128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-08-23 17:51 - 2016-08-05 23:30 - 01163696 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-08-23 17:51 - 2016-08-05 23:29 - 00199008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
2016-08-23 17:51 - 2016-08-05 23:29 - 00128352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2016-08-23 17:51 - 2016-08-05 23:26 - 01176664 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2016-08-23 17:51 - 2016-08-05 23:26 - 00409944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2016-08-23 17:51 - 2016-08-05 23:23 - 00168800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2016-08-23 17:51 - 2016-08-05 23:18 - 02745224 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-08-23 17:51 - 2016-08-05 23:18 - 01859264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-08-23 17:51 - 2016-08-05 23:18 - 01260384 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-08-23 17:51 - 2016-08-05 23:18 - 00584032 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2016-08-23 17:51 - 2016-08-05 23:18 - 00396168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2016-08-23 17:51 - 2016-08-05 23:17 - 00619368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-08-23 17:51 - 2016-08-05 23:17 - 00450400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2016-08-23 17:51 - 2016-08-05 23:17 - 00224096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2016-08-23 17:51 - 2016-08-05 23:16 - 00435040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2016-08-23 17:51 - 2016-08-05 23:16 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2016-08-23 17:51 - 2016-08-05 23:15 - 00408600 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll
2016-08-23 17:51 - 2016-08-05 23:13 - 22218808 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-08-23 17:51 - 2016-08-05 23:13 - 01847048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2016-08-23 17:51 - 2016-08-05 23:13 - 01694200 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2016-08-23 17:51 - 2016-08-05 23:13 - 01453992 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2016-08-23 17:51 - 2016-08-05 23:13 - 01071728 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2016-08-23 17:51 - 2016-08-05 23:13 - 01066096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-08-23 17:51 - 2016-08-05 23:13 - 00595488 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2016-08-23 17:51 - 2016-08-05 23:13 - 00381760 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2016-08-23 17:51 - 2016-08-05 23:13 - 00044472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
2016-08-23 17:51 - 2016-08-05 23:09 - 00151224 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-08-23 17:51 - 2016-08-05 23:08 - 02537816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2016-08-23 17:51 - 2016-08-05 23:08 - 01469120 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-08-23 17:51 - 2016-08-05 23:08 - 00587968 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-08-23 17:51 - 2016-08-05 23:08 - 00050880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2016-08-23 17:51 - 2016-08-05 22:49 - 22570496 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-08-23 17:51 - 2016-08-05 22:48 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2016-08-23 17:51 - 2016-08-05 22:48 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2016-08-23 17:51 - 2016-08-05 22:48 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2016-08-23 17:51 - 2016-08-05 22:48 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
2016-08-23 17:51 - 2016-08-05 22:48 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.exe
2016-08-23 17:51 - 2016-08-05 22:48 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwmp.dll
2016-08-23 17:51 - 2016-08-05 22:47 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2016-08-23 17:51 - 2016-08-05 22:47 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2016-08-23 17:51 - 2016-08-05 22:47 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
2016-08-23 17:51 - 2016-08-05 22:47 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdxm.ocx
2016-08-23 17:51 - 2016-08-05 22:47 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxmasf.dll
2016-08-23 17:51 - 2016-08-05 22:46 - 09260032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmploc.DLL
2016-08-23 17:51 - 2016-08-05 22:46 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\dasHost.exe
2016-08-23 17:51 - 2016-08-05 22:46 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModelOOBE.exe
2016-08-23 17:51 - 2016-08-05 22:46 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2016-08-23 17:51 - 2016-08-05 22:45 - 00327680 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
2016-08-23 17:51 - 2016-08-05 22:45 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2016-08-23 17:51 - 2016-08-05 22:45 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2016-08-23 17:51 - 2016-08-05 22:45 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\netiougc.exe
2016-08-23 17:51 - 2016-08-05 22:44 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceassociation.dll
2016-08-23 17:51 - 2016-08-05 22:43 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_WorkAccess.dll
2016-08-23 17:51 - 2016-08-05 22:43 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2016-08-23 17:51 - 2016-08-05 22:43 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipboardServer.dll
2016-08-23 17:51 - 2016-08-05 22:43 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2016-08-23 17:51 - 2016-08-05 22:42 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2016-08-23 17:51 - 2016-08-05 22:42 - 00211456 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-08-23 17:51 - 2016-08-05 22:41 - 00743424 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-08-23 17:51 - 2016-08-05 22:41 - 00462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2016-08-23 17:51 - 2016-08-05 22:41 - 00412160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2016-08-23 17:51 - 2016-08-05 22:41 - 00323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2016-08-23 17:51 - 2016-08-05 22:41 - 00266240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
2016-08-23 17:51 - 2016-08-05 22:41 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2016-08-23 17:51 - 2016-08-05 22:40 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2016-08-23 17:51 - 2016-08-05 22:40 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
2016-08-23 17:51 - 2016-08-05 22:40 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafpos.dll
2016-08-23 17:51 - 2016-08-05 22:40 - 00234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcpipcfg.dll
2016-08-23 17:51 - 2016-08-05 22:40 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncPolicy.dll
2016-08-23 17:51 - 2016-08-05 22:39 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2016-08-23 17:51 - 2016-08-05 22:39 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifiprofilessettinghandler.dll
2016-08-23 17:51 - 2016-08-05 22:39 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll
2016-08-23 17:51 - 2016-08-05 22:39 - 00261120 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll
2016-08-23 17:51 - 2016-08-05 22:38 - 17187328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-08-23 17:51 - 2016-08-05 22:38 - 00526848 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2016-08-23 17:51 - 2016-08-05 22:38 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-08-23 17:51 - 2016-08-05 22:38 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-08-23 17:51 - 2016-08-05 22:36 - 00447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\das.dll
2016-08-23 17:51 - 2016-08-05 22:35 - 09127936 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-08-23 17:51 - 2016-08-05 22:35 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll
2016-08-23 17:51 - 2016-08-05 22:34 - 01883648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2016-08-23 17:51 - 2016-08-05 22:34 - 01545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2016-08-23 17:51 - 2016-08-05 22:34 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CastLaunch.dll
2016-08-23 17:51 - 2016-08-05 22:34 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\smphost.dll
2016-08-23 17:51 - 2016-08-05 22:33 - 23682560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-08-23 17:51 - 2016-08-05 22:33 - 01082368 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2016-08-23 17:51 - 2016-08-05 22:33 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-08-23 17:51 - 2016-08-05 22:32 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2016-08-23 17:51 - 2016-08-05 22:31 - 03244032 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2016-08-23 17:51 - 2016-08-05 22:31 - 01908224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2016-08-23 17:51 - 2016-08-05 22:31 - 01052672 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
2016-08-23 17:51 - 2016-08-05 22:31 - 00884224 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2016-08-23 17:51 - 2016-08-05 22:31 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
2016-08-23 17:51 - 2016-08-05 22:30 - 13080576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-08-23 17:51 - 2016-08-05 22:30 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2016-08-23 17:51 - 2016-08-05 22:29 - 13433856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-08-23 17:51 - 2016-08-05 22:29 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-08-23 17:51 - 2016-08-05 22:29 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2016-08-23 17:51 - 2016-08-05 22:29 - 00237568 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
2016-08-23 17:51 - 2016-08-05 22:29 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2016-08-23 17:51 - 2016-08-05 22:28 - 00936960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2016-08-23 17:51 - 2016-08-05 22:27 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-08-23 17:51 - 2016-08-05 22:26 - 00758784 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-08-23 17:51 - 2016-08-05 22:25 - 03116032 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAJApi.dll
2016-08-23 17:51 - 2016-08-05 22:24 - 02680832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-08-23 17:51 - 2016-08-05 22:24 - 02314752 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-08-23 17:51 - 2016-08-05 22:24 - 02095616 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2016-08-23 17:51 - 2016-08-05 22:23 - 02370048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2016-08-23 17:51 - 2016-08-05 22:23 - 01780736 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-08-23 17:51 - 2016-08-05 22:23 - 01508864 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-08-23 17:51 - 2016-08-05 22:23 - 01491456 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-08-23 17:51 - 2016-08-05 22:23 - 01231872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-08-23 17:51 - 2016-08-05 22:23 - 01062400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2016-08-23 17:51 - 2016-08-05 22:23 - 00520192 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32time.dll
2016-08-23 17:51 - 2016-08-05 22:23 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2016-08-23 17:51 - 2016-08-05 22:19 - 01812480 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2016-08-23 17:51 - 2016-08-05 22:19 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2016-08-23 17:51 - 2016-08-05 04:14 - 01066328 _____ (Microsoft Corporation) C:\WINDOWS\system32\pidgenx.dll
2016-08-23 17:51 - 2016-08-05 04:12 - 05622600 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2016-08-23 17:51 - 2016-08-05 04:05 - 00665768 _____ (Microsoft Corporation) C:\WINDOWS\system32\GenValObj.exe
2016-08-23 17:51 - 2016-08-05 03:29 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.UXRes.dll
2016-08-23 17:51 - 2016-08-05 03:28 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\slcext.dll
2016-08-23 17:51 - 2016-08-05 03:22 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppc.dll
2016-08-23 17:51 - 2016-08-05 03:20 - 00538112 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2016-08-23 17:51 - 2016-08-05 03:08 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\slc.dll
2016-08-23 17:51 - 2016-08-05 03:07 - 01643008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-08-23 17:50 - 2016-08-05 23:16 - 01099104 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2016-08-23 17:50 - 2016-08-05 23:16 - 00987488 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2016-08-23 17:50 - 2016-08-05 23:16 - 00942432 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi
2016-08-23 17:50 - 2016-08-05 23:16 - 00807776 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe
2016-08-23 17:50 - 2016-08-05 23:16 - 00073568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2016-08-23 17:50 - 2016-08-05 23:16 - 00020320 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2016-08-23 17:50 - 2016-08-05 22:47 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidusb.sys
2016-08-23 17:50 - 2016-08-05 22:46 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys
2016-08-23 17:50 - 2016-08-05 22:43 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys
2016-08-23 08:03 - 2016-08-23 08:03 - 02369536 _____ (BitTorrent Inc.) C:\Program Files\uTorrent.exe
2016-08-22 07:15 - 2016-08-22 07:15 - 00000000 ____D C:\ProgramData\Brother
2016-08-21 01:05 - 2016-08-21 01:21 - 00000000 ____D C:\Users\lukew\AppData\Roaming\vlc
2016-08-21 01:04 - 2016-08-21 01:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-08-21 01:03 - 2016-08-21 01:03 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2016-08-20 21:52 - 2016-08-28 20:32 - 00000000 ___DC C:\WINDOWS\Panther
2016-08-20 21:51 - 2016-08-20 21:51 - 08124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 06664192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2016-08-20 21:51 - 2016-08-20 21:51 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2016-08-20 21:51 - 2016-08-20 21:51 - 06044672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 05511168 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 05398016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aclui.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 03617280 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-08-20 21:51 - 2016-08-20 21:51 - 02999296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2016-08-20 21:51 - 2016-08-20 21:51 - 02190688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-08-20 21:51 - 2016-08-20 21:51 - 01708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 01656320 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 01461200 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 01456640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 01435896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 01418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 01265424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 01081856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 00770048 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 00658784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-08-20 21:51 - 2016-08-20 21:51 - 00509952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2016-08-20 21:51 - 2016-08-20 21:51 - 00389000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtapi.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 00297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtapi.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 00241496 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2016-08-20 21:51 - 2016-08-20 21:51 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2016-08-20 21:51 - 2016-08-20 21:51 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 00114192 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 00079536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 00062816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2016-08-20 21:51 - 2016-08-20 21:51 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll
2016-08-20 21:51 - 2016-08-20 21:51 - 00000000 ____D C:\Windows.old
2016-08-20 21:51 - 2016-08-20 21:51 - 00000000 ____D C:\Program Files\CMAK
2016-08-20 21:51 - 2016-08-20 21:51 - 00000000 ____D C:\Program Files (x86)\CMAK
2016-08-20 21:50 - 2016-08-20 21:50 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2016-08-20 21:49 - 2016-02-01 06:49 - 00185384 ____R (Intel Corporation) C:\WINDOWS\system32\Drivers\TeeDriverW8x64.sys
2016-08-20 21:49 - 2016-02-01 06:49 - 00185144 ____R (Intel Corporation) C:\WINDOWS\system32\Drivers\iaLPSS2_I2C.sys
2016-08-20 21:49 - 2016-02-01 06:49 - 00083768 ____R (Windows ® Win 7 DDK provider) C:\WINDOWS\system32\Drivers\iaLPSS2_GPIO2.sys
2016-08-20 19:31 - 2016-08-28 23:23 - 00001033 _____ C:\Users\lukew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optional Features.lnk
2016-08-20 19:02 - 2016-08-20 19:02 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2016-08-20 19:01 - 2016-08-21 01:09 - 00000000 ____D C:\Users\lukew\AppData\Local\ConnectedDevicesPlatform
2016-08-20 19:01 - 2016-08-20 19:01 - 00000020 ___SH C:\Users\lukew\ntuser.ini
2016-08-20 19:00 - 2016-08-20 19:00 - 00000000 _SHDL C:\Users\Default\My Documents
2016-08-20 19:00 - 2016-08-20 19:00 - 00000000 _SHDL C:\Users\Default\Documents\My Videos
2016-08-20 19:00 - 2016-08-20 19:00 - 00000000 _SHDL C:\Users\Default\Documents\My Pictures
2016-08-20 19:00 - 2016-08-20 19:00 - 00000000 _SHDL C:\Users\Default\Documents\My Music
2016-08-20 19:00 - 2016-08-20 19:00 - 00000000 _SHDL C:\Users\Default User\Documents\My Videos
2016-08-20 19:00 - 2016-08-20 19:00 - 00000000 _SHDL C:\Users\Default User\Documents\My Pictures
2016-08-20 19:00 - 2016-08-20 19:00 - 00000000 _SHDL C:\Users\Default User\Documents\My Music
2016-08-20 19:00 - 2016-08-20 19:00 - 00000000 ____D C:\ProgramData\USOShared
2016-08-20 18:59 - 2016-08-20 18:59 - 00007623 _____ C:\WINDOWS\diagwrn.xml
2016-08-20 18:59 - 2016-08-20 18:59 - 00007623 _____ C:\WINDOWS\diagerr.xml
2016-08-20 18:58 - 2016-08-28 23:34 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-08-20 18:58 - 2016-08-20 18:58 - 00022744 _____ C:\WINDOWS\system32\emptyregdb.dat
2016-08-20 18:57 - 2016-08-28 23:23 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-08-20 18:55 - 2016-08-20 18:57 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2016-08-20 18:54 - 2016-08-27 19:31 - 00000000 ____D C:\Users\lukew
2016-08-20 18:54 - 2016-08-20 18:54 - 00000000 _SHDL C:\Users\lukew\My Documents
2016-08-20 18:54 - 2016-08-20 18:54 - 00000000 _SHDL C:\Users\lukew\Documents\My Videos
2016-08-20 18:54 - 2016-08-20 18:54 - 00000000 _SHDL C:\Users\lukew\Documents\My Pictures
2016-08-20 18:54 - 2016-08-20 18:54 - 00000000 _SHDL C:\Users\lukew\Documents\My Music
2016-08-20 18:54 - 2016-07-16 06:41 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2016-08-20 18:53 - 2016-08-28 23:34 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-08-20 18:53 - 2016-08-27 22:52 - 00000000 ____D C:\WINDOWS\Firmware
2016-08-20 18:53 - 2016-08-20 18:53 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_SurfacePenDriver_01011.Wdf
2016-08-20 18:53 - 2016-08-20 18:53 - 00000000 ____D C:\WINDOWS\system32\Intel
2016-08-20 18:53 - 2016-08-20 18:53 - 00000000 ____D C:\Program Files\Intel
2016-08-20 18:53 - 2016-08-20 18:53 - 00000000 _____ C:\WINDOWS\system32\GfxValDisplayLog.bin
2016-08-20 18:53 - 2016-07-14 19:32 - 00117272 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2016-08-20 18:53 - 2016-02-24 06:09 - 01050112 ____R (Marvell Semiconductors Inc.) C:\WINDOWS\system32\Drivers\mrvlpcie8897.sys
2016-08-20 18:53 - 2016-02-08 17:51 - 04792088 ____R (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys
2016-08-20 18:53 - 2016-02-08 17:51 - 03320696 ____R (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll
2016-08-20 18:53 - 2016-02-08 17:51 - 03195960 ____R (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll
2016-08-20 18:53 - 2016-02-08 17:51 - 03108640 ____R (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll
2016-08-20 18:53 - 2016-02-08 17:51 - 02467240 ____R (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv201.dll
2016-08-20 18:53 - 2016-02-08 17:51 - 01377104 ____R (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll
2016-08-20 18:53 - 2016-02-08 17:51 - 00961712 ____R (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOProp.dll
2016-08-20 18:53 - 2016-02-08 17:51 - 00378032 ____R (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2API.dll
2016-08-20 18:53 - 2016-02-08 17:51 - 00203472 ____R (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll
2016-08-20 18:53 - 2016-02-08 17:51 - 00002300 ____R C:\WINDOWS\system32\Drivers\RTAIODAT.DAT
2016-08-20 18:52 - 2016-08-28 23:02 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2016-08-20 18:52 - 2016-08-21 01:56 - 00338288 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-08-20 18:52 - 2016-08-20 18:52 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2016-08-18 21:48 - 2016-08-28 23:33 - 00040190 _____ C:\WINDOWS\system32\OV7251_FRONT.aiqd
2016-08-18 21:48 - 2016-08-28 23:33 - 00040190 _____ C:\WINDOWS\system32\OV5693_FRONT.aiqd
2016-08-18 18:31 - 2016-08-28 23:23 - 00001159 _____ C:\Users\lukew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TouchMe Engine.lnk
2016-08-18 18:31 - 2016-08-21 01:26 - 00000000 ____D C:\Users\lukew\AppData\Roaming\AppsolutelyApps
2016-08-17 21:15 - 2016-08-17 21:15 - 00000000 ____D C:\Users\lukew\AppData\LocalLow\Adobe
2016-08-17 21:14 - 2016-08-28 23:23 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-08-17 21:14 - 2016-08-17 21:15 - 00000000 ____D C:\ProgramData\Adobe
2016-08-17 21:14 - 2016-08-17 21:14 - 00000000 ____D C:\Program Files (x86)\Adobe
2016-08-17 21:12 - 2016-08-17 21:15 - 00000000 ____D C:\Users\lukew\AppData\Local\Adobe
2016-08-17 16:11 - 2016-08-17 16:13 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-08-17 16:11 - 2016-08-17 16:11 - 147640136 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-08-17 10:27 - 2016-08-20 18:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2016-08-17 10:27 - 2016-08-18 21:05 - 00000000 ____D C:\Users\lukew\AppData\Roaming\Apple Computer
2016-08-17 10:27 - 2016-08-17 10:27 - 00000000 ____D C:\Users\lukew\AppData\Local\Apple Computer
2016-08-17 10:26 - 2016-08-28 23:23 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2016-08-17 10:26 - 2016-08-17 10:27 - 00000000 ____D C:\Program Files\iTunes
2016-08-17 10:26 - 2016-08-17 10:26 - 00000000 ____D C:\Users\lukew\AppData\Local\Apple
2016-08-17 10:26 - 2016-08-17 10:26 - 00000000 ____D C:\ProgramData\Apple Computer
2016-08-17 10:26 - 2016-08-17 10:26 - 00000000 ____D C:\ProgramData\Apple
2016-08-17 10:26 - 2016-08-17 10:26 - 00000000 ____D C:\Program Files\iPod
2016-08-17 10:26 - 2016-08-17 10:26 - 00000000 ____D C:\Program Files\Common Files\Apple
2016-08-17 10:26 - 2016-08-17 10:26 - 00000000 ____D C:\Program Files\Bonjour
2016-08-17 10:26 - 2016-08-17 10:26 - 00000000 ____D C:\Program Files (x86)\iTunes
2016-08-17 10:26 - 2016-08-17 10:26 - 00000000 ____D C:\Program Files (x86)\Bonjour
2016-08-17 10:26 - 2016-08-17 10:26 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2016-08-17 10:23 - 2016-08-28 23:23 - 00001866 _____ C:\Users\lukew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2016-08-17 10:23 - 2016-08-28 22:56 - 00000000 ____D C:\Users\lukew\AppData\Local\Spotify
2016-08-17 10:23 - 2016-08-28 22:22 - 00000000 ____D C:\Users\lukew\AppData\Roaming\Spotify
2016-08-17 10:23 - 2016-08-17 10:23 - 00000000 ____D C:\Users\lukew\AppData\Local\CEF
2016-08-17 09:04 - 2016-08-27 22:14 - 00000000 ____D C:\Users\lukew\AppData\Roaming\Slack
2016-08-17 09:04 - 2016-08-22 19:22 - 00000000 ____D C:\Users\lukew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Slack Technologies
2016-08-17 09:04 - 2016-08-22 19:22 - 00000000 ____D C:\Users\lukew\AppData\Local\slack
2016-08-17 09:04 - 2016-08-22 19:21 - 00000000 ____D C:\Users\lukew\AppData\Local\SquirrelTemp
2016-08-17 08:34 - 2016-07-27 14:25 - 00504488 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-08-17 00:32 - 2016-06-30 22:40 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Speech.Pal.dll
2016-08-17 00:31 - 2016-06-30 22:57 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpreference.exe
2016-08-16 23:37 - 2016-08-16 23:37 - 00000000 ____D C:\Users\lukew\AppData\Local\PeerDistRepub
2016-08-16 18:09 - 2016-08-28 23:23 - 00000760 _____ C:\Users\lukew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Anki.lnk
2016-08-16 18:09 - 2016-08-16 18:09 - 00000000 ____D C:\Program Files (x86)\Anki
2016-08-16 15:44 - 2016-08-16 15:44 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2016-08-16 15:42 - 2016-08-28 23:23 - 00002248 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2016-08-16 15:42 - 2016-08-28 23:23 - 00002214 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business 2016.lnk
2016-08-15 22:31 - 2016-08-21 15:13 - 00000000 ____D C:\Users\lukew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2016-08-15 22:28 - 2016-08-27 21:53 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-08-15 22:28 - 2016-08-15 22:28 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-08-15 22:28 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2016-08-15 22:28 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-08-15 22:28 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2016-08-15 22:25 - 2016-08-28 23:23 - 00002354 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-08-15 22:24 - 2016-08-16 17:30 - 00000000 ____D C:\Users\lukew\AppData\Local\Google
2016-08-15 22:24 - 2016-08-15 22:25 - 00000000 ____D C:\Program Files (x86)\Google
2016-08-15 22:23 - 2016-08-15 22:23 - 00000000 ____D C:\Users\lukew\AppData\Local\MicrosoftEdge
2016-08-15 22:07 - 2016-08-15 22:07 - 00000000 ____D C:\Users\lukew\AppData\Local\NetworkTiles
2016-08-15 18:42 - 2016-08-15 18:42 - 00000000 ____D C:\Program Files (x86)\Intel
2016-08-15 18:39 - 2016-08-28 23:56 - 00000000 ___RD C:\Users\lukew\OneDrive
2016-08-15 18:39 - 2016-08-28 23:51 - 00002373 _____ C:\Users\lukew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-08-15 18:38 - 2016-08-16 17:16 - 00000000 ____D C:\Users\lukew\AppData\Local\Comms
2016-08-15 18:38 - 2016-08-15 18:38 - 00000000 ____D C:\Users\lukew\AppData\Local\ActiveSync
2016-08-15 18:37 - 2016-08-16 15:56 - 00000000 ____D C:\Users\lukew\AppData\Local\PackageStaging
2016-08-15 18:37 - 2016-08-15 18:37 - 00000000 ____D C:\Users\lukew\AppData\Local\Publishers
2016-08-15 18:36 - 2016-08-21 01:03 - 00000000 ____D C:\Users\lukew\AppData\Local\Packages
2016-08-15 18:36 - 2016-08-17 21:15 - 00000000 ____D C:\Users\lukew\AppData\Roaming\Adobe
2016-08-15 18:36 - 2016-08-15 18:36 - 00000000 ____D C:\Users\lukew\AppData\Local\VirtualStore
2016-08-15 18:36 - 2016-08-15 18:36 - 00000000 ____D C:\Users\lukew\AppData\Local\TileDataLayer
2016-08-15 18:33 - 2016-08-15 18:33 - 00000000 ____D C:\WINDOWS\CSC
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-08-28 23:51 - 2016-04-29 15:23 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2016-08-28 23:39 - 2016-04-29 15:08 - 01479448 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-08-28 23:37 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2016-08-28 23:33 - 2016-07-16 01:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2016-08-28 23:23 - 2016-04-29 15:24 - 00002503 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
2016-08-28 23:23 - 2016-04-29 15:24 - 00002502 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
2016-08-28 23:23 - 2016-04-29 15:24 - 00002466 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk
2016-08-28 23:23 - 2016-04-29 15:24 - 00002465 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
2016-08-28 23:23 - 2016-04-29 15:24 - 00002459 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
2016-08-28 23:23 - 2016-04-29 15:24 - 00002453 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
2016-08-28 23:23 - 2016-04-29 15:24 - 00002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2016-08-28 20:41 - 2016-07-16 06:45 - 00000000 ____D C:\WINDOWS\INF
2016-08-28 20:17 - 2016-07-16 06:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-08-28 10:23 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-08-27 21:40 - 2016-07-16 06:47 - 00000000 ___RD C:\WINDOWS\MiracastView
2016-08-27 11:49 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2016-08-27 07:52 - 2016-07-16 06:47 - 00000000 ___HD C:\Program Files\WindowsApps
2016-08-26 00:26 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\rescache
2016-08-25 11:09 - 2016-04-29 15:36 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-08-25 11:04 - 2016-07-16 06:47 - 00000000 ___SD C:\WINDOWS\system32\dsc
2016-08-25 11:04 - 2016-07-16 06:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-08-25 11:04 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-08-25 11:04 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
2016-08-21 09:54 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\appcompat
2016-08-20 21:52 - 2016-07-16 06:47 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2016-08-20 21:51 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\system32\lv-LV
2016-08-20 21:51 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\system32\lt-LT
2016-08-20 21:51 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\system32\et-EE
2016-08-20 21:51 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\system32\es-MX
2016-08-20 21:51 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\system32\en-GB
2016-08-20 19:00 - 2016-07-16 06:47 - 00000000 ____D C:\ProgramData\USOPrivate
2016-08-20 19:00 - 2016-07-16 01:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2016-08-20 18:59 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\Registration
2016-08-20 18:59 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2016-08-20 18:58 - 2016-07-16 06:47 - 00000000 __RHD C:\Users\Public\Libraries
2016-08-20 18:57 - 2016-07-16 06:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-08-20 18:57 - 2016-04-29 15:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
2016-08-20 18:57 - 2015-10-30 01:28 - 00000000 ____D C:\Users\Default.migrated
2016-08-20 18:55 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\system32\spool
2016-08-20 18:55 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-08-20 18:55 - 2016-07-16 06:47 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-08-20 18:54 - 2016-07-16 01:04 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2016-08-20 18:53 - 2016-07-16 06:47 - 00000000 ___RD C:\WINDOWS\PrintDialog
2016-08-20 18:43 - 2016-07-16 10:17 - 00000000 ___HD C:\$WINDOWS.~BT
==================== Files in the root of some directories =======
2016-08-23 08:03 - 2016-08-23 08:03 - 2369536 _____ (BitTorrent Inc.) C:\Program Files\uTorrent.exe
2016-08-27 19:54 - 2016-08-27 19:54 - 0138240 _____ () C:\Users\lukew\AppData\Roaming\Installer.dat
2016-08-27 20:07 - 2016-08-27 20:30 - 0000000 _____ () C:\Users\lukew\AppData\Local\icka17777572.txt
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-08-20 18:52
==================== End of FRST.txt ============================