Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

I have Trojan trojan.kotver gm2 .. It keeps coming back (in Chrome)


  • This topic is locked This topic is locked
3 replies to this topic

#1 MarcStephens

MarcStephens

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:12:33 PM

Posted 17 October 2016 - 05:53 PM

 
I get popup adds and my Norton 360 is constantly quarantining files and asking for a restart.
 
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-10-2016
Ran by jabbe_000 (administrator) on STEPHENS (17-10-2016 18:42:36)
Running from C:\Users\jabbe_000\Downloads
Loaded Profiles: jabbe_000 (Available Profiles: jabbe_000)
Platform: Microsoft Windows 10 Home Version 1607 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files\Backblaze\bzserv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(NTI Corporation) C:\Program Files\NTI\NTI Backup Now EZ\BackupNowEZSvr.exe
(Symantec Corporation) C:\Program Files\Norton 360\Engine\22.7.1.32\N360.exe
(Symantec Corporation) C:\Program Files\Norton 360\Engine\22.7.1.32\N360.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.8.190.0_x86__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(NTI Corporation) C:\Program Files\NTI\NTI Backup Now EZ\BackupNowEZtray.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
() C:\Program Files\Backblaze\bzbui.exe
(Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP Officejet 5740 series\Bin\ScanToPCActivationApp.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP Officejet 5740 series\Bin\HPNetworkCommunicatorCom.exe
(Microsoft Corporation) C:\Program Files\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x86__8wekyb3d8bbwe\Microsoft.Photos.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Apple Inc.) C:\Program Files\iTunes\iTunes.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [BackupNowEZtray] => C:\Program Files\NTI\NTI Backup Now EZ\BackupNowEZtray.exe [1239032 2014-01-28] (NTI Corporation)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157456 2015-09-23] (Apple Inc.)
HKLM\...\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKU\S-1-5-21-3409270631-3081192051-993886705-1001\...\Run: [Backblaze] => C:\Program Files\Backblaze\bzbui.exe [593576 2016-09-28] ()
HKU\S-1-5-21-3409270631-3081192051-993886705-1001\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [26424960 2016-06-29] (Skype Technologies S.A.)
HKU\S-1-5-21-3409270631-3081192051-993886705-1001\...\Run: [HP Officejet 5740 series (NET)] => C:\Program Files\HP\HP Officejet 5740 series\Bin\ScanToPCActivationApp.exe [2424840 2014-08-22] (Hewlett-Packard Development Company, LP)
HKU\S-1-5-21-3409270631-3081192051-993886705-1001\...\Run: [Google Update] => C:\Users\jabbe_000\AppData\Local\Google\Update\GoogleUpdate.exe [154440 2016-02-02] (Google Inc.)
HKU\S-1-5-21-3409270631-3081192051-993886705-1001\...\Run: [**xdgt<*>] => "C:\Users\jabbe_000\AppData\Local\bcefaa26\89f9bed5.lnk" <===== ATTENTION (Value Name with invalid characters)
HKU\S-1-5-18\...\Run: [Backblaze] => C:\Program Files\Backblaze\bzbui.exe [593576 2016-09-28] ()
ShellIconOverlayIdentifiers: [  OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files\Norton 360\Engine\22.7.1.32\buShell.dll [2016-08-15] (Symantec Corporation)
ShellIconOverlayIdentifiers: [  OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files\Norton 360\Engine\22.7.1.32\buShell.dll [2016-08-15] (Symantec Corporation)
ShellIconOverlayIdentifiers: [  OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files\Norton 360\Engine\22.7.1.32\buShell.dll [2016-08-15] (Symantec Corporation)
Startup: C:\Users\jabbe_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ba0723f5.lnk [2016-10-17]
ShortcutTarget: ba0723f5.lnk -> C:\Windows\System32\mshta.exe (Microsoft Corporation)
Startup: C:\Users\jabbe_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\d7eba04f.lnk [2016-10-07]
ShortcutTarget: d7eba04f.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{076ec967-10b4-4867-8371-20a85af4cb67}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{910d0c35-4c78-4db2-8c14-0a448c689485}: [DhcpNameServer] 192.168.1.254
 
Internet Explorer:
==================
HKU\S-1-5-21-3409270631-3081192051-993886705-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.yahoo.com/?fr=befhp&type=iehp-3.19-1510
HKU\S-1-5-21-3409270631-3081192051-993886705-1001\Software\Microsoft\Internet Explorer\Main,Old Start Page = hxxp://www.yahoo.com/
SearchScopes: HKU\S-1-5-21-3409270631-3081192051-993886705-1001 -> DefaultScope {6F943D1A-B06A-45D6-AA49-E179115FFFDE} URL = hxxps://search.yahoo.com/search?ei=utf-8&fr=befds&p={searchTerms}&type=ieds-3.19-1510
SearchScopes: HKU\S-1-5-21-3409270631-3081192051-993886705-1001 -> {6F943D1A-B06A-45D6-AA49-E179115FFFDE} URL = hxxps://search.yahoo.com/search?ei=utf-8&fr=befds&p={searchTerms}&type=ieds-3.19-1510
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Norton 360\Engine\22.7.1.32\coIEPlg.dll [2016-08-05] (Symantec Corporation)
BHO: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files\Norton 360\Engine\21.7.0.11\IPS\IPSBHO.DLL => No File
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\22.7.1.32\coIEPlg.dll [2016-08-05] (Symantec Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
 
FireFox:
========
FF HKLM\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_22.7.1.32\coFFAddon
FF Extension: (Norton Identity Safe) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_22.7.1.32\coFFAddon [2016-10-08]
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll [2013-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-25] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-10] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-10] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-12-17] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3409270631-3081192051-993886705-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\jabbe_000\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-3409270631-3081192051-993886705-1001: @talk.google.com/O1DPlugin -> C:\Users\jabbe_000\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-3409270631-3081192051-993886705-1001: @tools.google.com/Google Update;version=3 -> C:\Users\jabbe_000\AppData\Local\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-10] (Google Inc.)
FF Plugin HKU\S-1-5-21-3409270631-3081192051-993886705-1001: @tools.google.com/Google Update;version=9 -> C:\Users\jabbe_000\AppData\Local\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-10] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\jabbe_000\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\jabbe_000\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxps://www.google.com/"
CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=orcl_default
CHR DefaultSearchKeyword: Default -> Yahoo
CHR DefaultSuggestURL: Default -> hxxps://search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10
CHR Profile: C:\Users\jabbe_000\AppData\Local\Google\Chrome\User Data\Default [2016-10-17]
CHR Extension: (Google Slides) - C:\Users\jabbe_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-04]
CHR Extension: (Duolingo on the Web) - C:\Users\jabbe_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiahmijlpehemcpleichkcokhegllfjl [2015-03-10]
CHR Extension: (Google Docs) - C:\Users\jabbe_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-04]
CHR Extension: (Google Drive) - C:\Users\jabbe_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\jabbe_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-27]
CHR Extension: (Norton Security Toolbar) - C:\Users\jabbe_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe [2016-10-08]
CHR Extension: (Google Search) - C:\Users\jabbe_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Google Sheets) - C:\Users\jabbe_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-04]
CHR Extension: (Google Docs Offline) - C:\Users\jabbe_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-16]
CHR Extension: (Norton Identity Safe) - C:\Users\jabbe_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif [2014-11-22]
CHR Extension: (Chrome Web Store Payments) - C:\Users\jabbe_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Gmail) - C:\Users\jabbe_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-07]
CHR Extension: (Chrome Media Router) - C:\Users\jabbe_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-09-22]
CHR HKLM\...\Chrome\Extension: [aaffhmecfaelkngcbnfdkcckmillnoki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files\Norton 360\Engine\22.7.1.32\Exts\Chrome.crx [2016-08-05]
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-05-25]
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 bzserv; C:\Program Files\Backblaze\bzserv.exe [354984 2016-09-28] ()
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1364096 2016-05-25] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1687680 2016-05-25] (Microsoft Corporation)
S3 fussvc; C:\Program Files\Windows Kits\8.1\App Certification Kit\fussvc.exe [140800 2014-02-20] (Microsoft Corporation) [File not signed]
R2 N360; C:\Program Files\Norton 360\Engine\22.8.0.50\N360.exe [289080 2016-09-23] (Symantec Corporation)
R2 NTI BackupNowEZSvr; C:\Program Files\NTI\NTI Backup Now EZ\BackupNowEZSvr.exe [45048 2014-01-28] (NTI Corporation)
S3 Te.Service; C:\Program Files\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [91136 2013-08-21] (Microsoft Corporation) [File not signed]
R3 VSStandardCollectorService140; C:\Program Files\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [48872 2015-11-19] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [271496 2016-07-16] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [84928 2016-07-16] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 BHDrvx86; C:\Program Files\Norton 360\NortonData\22.7.1.32\Definitions\BASHDefs\20161005.001\BHDrvx86.sys [1334008 2016-10-05] (Symantec Corporation)
R1 ccSet_N360; C:\WINDOWS\system32\drivers\N360\1608000.032\ccSetx86.sys [137456 2016-08-09] (Symantec Corporation)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [388824 2016-09-22] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [124632 2016-09-22] (Symantec Corporation)
R1 IDSVix86; C:\Program Files\Norton 360\NortonData\22.7.1.32\Definitions\IPSDefs\20161014.003\IDSvix86.sys [768728 2016-10-07] (Symantec Corporation)
S0 megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys [56672 2016-10-05] (Avago Technologies)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [62976 2016-07-16] ()
R3 SensorsSimulatorDriver; C:\WINDOWS\System32\drivers\WUDFRd.sys [161280 2016-07-16] (Microsoft Corporation)
R3 SRTSP; C:\WINDOWS\system32\drivers\N360\1607010.020\SRTSP.SYS [626416 2016-08-09] (Symantec Corporation)
R1 SRTSPX; C:\WINDOWS\system32\drivers\N360\1608000.032\SRTSPX.SYS [43248 2016-09-23] (Symantec Corporation)
R0 SymEFASI; C:\WINDOWS\System32\drivers\N360\1608000.032\SYMEFASI.SYS [1291992 2016-09-23] (Symantec Corporation)
S0 SymELAM; C:\WINDOWS\System32\drivers\N360\1608000.032\SYMELAM.SYS [22144 2016-08-09] (Symantec Corporation)
R3 SymEvent; C:\WINDOWS\system32\Drivers\SYMEVENT.SYS [88312 2016-10-07] (Symantec Corporation)
R1 SymIRON; C:\WINDOWS\system32\drivers\N360\1608000.032\Ironx86.SYS [229616 2016-09-23] (Symantec Corporation)
R3 SymNetS; C:\WINDOWS\system32\drivers\N360\1607010.020\SYMNETS.SYS [423152 2016-08-09] (Symantec Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [37912 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [244576 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [100192 2016-07-16] (Microsoft Corporation)
S3 NAVENG; \??\C:\Program Files\Norton 360\NortonData\22.7.1.32\Definitions\SDSDefs\20161008.001\NAVENG.SYS [X]
S3 NAVEX15; \??\C:\Program Files\Norton 360\NortonData\22.7.1.32\Definitions\SDSDefs\20161008.001\NAVEX15.SYS [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-10-17 18:42 - 2016-10-17 18:43 - 00017806 _____ C:\Users\jabbe_000\Downloads\FRST.txt
2016-10-17 18:42 - 2016-10-17 18:42 - 00000000 ____D C:\FRST
2016-10-17 18:41 - 2016-10-17 18:41 - 01756672 _____ (Farbar) C:\Users\jabbe_000\Downloads\FRST.exe
2016-10-17 16:17 - 2016-10-17 16:17 - 00087792 _____ (Symantec Corporation) C:\WINDOWS\system32\Drivers\SYMEVENT.SY1
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00032464.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00030710.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00029494.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00028853.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00023815.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00021685.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00021327.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00020775.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00020515.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00020436.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00017019.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00016857.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00015569.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00015240.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00014704.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00013941.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00010103.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00009886.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00009775.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00009560.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00009346.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00008500.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00008045.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00007753.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00007025.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00006787.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00006771.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00004628.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00004101.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00001415.tmp
2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00000060.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00032504.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00031547.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00031252.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00030311.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00030188.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00030083.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00029796.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00028149.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00027759.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00025672.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00025608.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00024470.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00024444.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00023953.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00022150.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00020482.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00019685.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00019116.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00018665.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00017864.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00017824.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00016534.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00015584.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00014631.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00014202.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00014095.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00009843.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00009454.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00009417.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00009061.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00007614.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00007507.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00006869.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00006523.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00006269.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00003639.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00003243.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00002758.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00001533.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00001444.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00001405.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00001344.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00000824.tmp
2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00000359.tmp
2016-10-13 17:48 - 2016-10-13 17:48 - 00000000 ___HD C:\OneDriveTemp
2016-10-12 22:43 - 2016-10-05 06:10 - 00231776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2016-10-12 22:43 - 2016-10-05 06:05 - 00892008 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-10-12 22:43 - 2016-10-05 06:05 - 00784576 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-10-12 22:43 - 2016-10-05 06:05 - 00099680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2016-10-12 22:43 - 2016-10-05 06:03 - 06015840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-10-12 22:43 - 2016-10-05 06:03 - 01724584 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2016-10-12 22:43 - 2016-10-05 06:03 - 01072280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-10-12 22:43 - 2016-10-05 06:03 - 00946272 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-10-12 22:43 - 2016-10-05 05:59 - 00949600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2016-10-12 22:43 - 2016-10-05 05:54 - 01097568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2016-10-12 22:43 - 2016-10-05 05:53 - 00154976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2016-10-12 22:43 - 2016-10-05 05:51 - 01430720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-10-12 22:43 - 2016-10-05 05:50 - 02256592 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-10-12 22:43 - 2016-10-05 05:50 - 00116576 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2016-10-12 22:43 - 2016-10-05 05:49 - 01980768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2016-10-12 22:43 - 2016-10-05 05:48 - 01022304 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2016-10-12 22:43 - 2016-10-05 05:46 - 03892352 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2016-10-12 22:43 - 2016-10-05 05:46 - 01360456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2016-10-12 22:43 - 2016-10-05 05:46 - 00980824 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2016-10-12 22:43 - 2016-10-05 05:46 - 00056672 _____ (Avago Technologies) C:\WINDOWS\system32\Drivers\MegaSas2i.sys
2016-10-12 22:43 - 2016-10-05 05:45 - 00198496 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2016-10-12 22:43 - 2016-10-05 05:41 - 00545944 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-10-12 22:43 - 2016-10-05 05:40 - 01968480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2016-10-12 22:43 - 2016-10-05 05:31 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConfigureExpandedStorage.dll
2016-10-12 22:43 - 2016-10-05 05:28 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2016-10-12 22:43 - 2016-10-05 05:28 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.dll
2016-10-12 22:43 - 2016-10-05 05:28 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.HostName.dll
2016-10-12 22:43 - 2016-10-05 05:27 - 00229888 _____ C:\WINDOWS\system32\wc_storage.dll
2016-10-12 22:43 - 2016-10-05 05:27 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2016-10-12 22:43 - 2016-10-05 05:27 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2016-10-12 22:43 - 2016-10-05 05:26 - 00327680 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2016-10-12 22:43 - 2016-10-05 05:26 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2016-10-12 22:43 - 2016-10-05 05:26 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll
2016-10-12 22:43 - 2016-10-05 05:26 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll
2016-10-12 22:43 - 2016-10-05 05:26 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.Ngc.dll
2016-10-12 22:43 - 2016-10-05 05:25 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-10-12 22:43 - 2016-10-05 05:25 - 00404992 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
2016-10-12 22:43 - 2016-10-05 05:25 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2016-10-12 22:43 - 2016-10-05 05:25 - 00267776 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2016-10-12 22:43 - 2016-10-05 05:25 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2016-10-12 22:43 - 2016-10-05 05:25 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll
2016-10-12 22:43 - 2016-10-05 05:24 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
2016-10-12 22:43 - 2016-10-05 05:24 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2016-10-12 22:43 - 2016-10-05 05:23 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2016-10-12 22:43 - 2016-10-05 05:23 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll
2016-10-12 22:43 - 2016-10-05 05:23 - 00373760 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2016-10-12 22:43 - 2016-10-05 05:23 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
2016-10-12 22:43 - 2016-10-05 05:23 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs3D.dll
2016-10-12 22:43 - 2016-10-05 05:23 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
2016-10-12 22:43 - 2016-10-05 05:22 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2016-10-12 22:43 - 2016-10-05 05:22 - 00325632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2016-10-12 22:43 - 2016-10-05 05:21 - 03689984 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2016-10-12 22:43 - 2016-10-05 05:21 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2016-10-12 22:43 - 2016-10-05 05:21 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2016-10-12 22:43 - 2016-10-05 05:21 - 00310272 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2016-10-12 22:43 - 2016-10-05 05:20 - 00661504 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2016-10-12 22:43 - 2016-10-05 05:20 - 00303104 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2016-10-12 22:43 - 2016-10-05 05:18 - 04612608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-10-12 22:43 - 2016-10-05 05:18 - 01283584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
2016-10-12 22:43 - 2016-10-05 05:18 - 00858112 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2016-10-12 22:43 - 2016-10-05 05:17 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\adsmsext.dll
2016-10-12 22:43 - 2016-10-05 05:16 - 19418624 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-10-12 22:43 - 2016-10-05 05:16 - 00508416 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-10-12 22:43 - 2016-10-05 05:15 - 01375232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2016-10-12 22:43 - 2016-10-05 05:15 - 00141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialclient.dll
2016-10-12 22:43 - 2016-10-05 05:14 - 19416576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-10-12 22:43 - 2016-10-05 05:14 - 01456640 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2016-10-12 22:43 - 2016-10-05 05:14 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2016-10-12 22:43 - 2016-10-05 05:13 - 12345856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-10-12 22:43 - 2016-10-05 05:13 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2016-10-12 22:43 - 2016-10-05 05:11 - 12174848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-10-12 22:43 - 2016-10-05 05:11 - 06108672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-10-12 22:43 - 2016-10-05 05:11 - 06043136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-10-12 22:43 - 2016-10-05 05:11 - 03776000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-10-12 22:43 - 2016-10-05 05:11 - 01938944 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-10-12 22:43 - 2016-10-05 05:11 - 01135616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2016-10-12 22:43 - 2016-10-05 05:11 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2016-10-12 22:43 - 2016-10-05 05:11 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2016-10-12 22:43 - 2016-10-05 05:10 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2016-10-12 22:43 - 2016-10-05 05:10 - 00754688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2016-10-12 22:43 - 2016-10-05 05:09 - 07467520 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2016-10-12 22:43 - 2016-10-05 05:09 - 03369984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2016-10-12 22:43 - 2016-10-05 05:09 - 01700864 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
2016-10-12 22:43 - 2016-10-05 05:09 - 00884224 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2016-10-12 22:43 - 2016-10-05 05:09 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2016-10-12 22:43 - 2016-10-05 05:09 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-10-12 22:43 - 2016-10-05 05:09 - 00674304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2016-10-12 22:43 - 2016-10-05 05:09 - 00608256 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2016-10-12 22:43 - 2016-10-05 05:08 - 02356736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll
2016-10-12 22:43 - 2016-10-05 05:08 - 01524224 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2016-10-12 22:43 - 2016-10-05 05:08 - 01485312 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2016-10-12 22:43 - 2016-10-05 05:08 - 00873472 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2016-10-12 22:43 - 2016-10-05 05:08 - 00598528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2016-10-12 22:43 - 2016-10-05 05:07 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-10-12 22:43 - 2016-10-05 05:07 - 02682880 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll
2016-10-12 22:43 - 2016-10-05 05:07 - 02646016 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2016-10-12 22:43 - 2016-10-05 05:07 - 01232384 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-10-12 22:43 - 2016-10-05 05:07 - 01123328 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-10-12 22:43 - 2016-10-05 05:07 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2016-10-12 22:43 - 2016-10-05 05:07 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2016-10-12 22:43 - 2016-10-05 05:06 - 02999296 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-10-12 22:43 - 2016-10-05 05:06 - 02254336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-10-12 22:43 - 2016-10-05 05:06 - 02005504 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2016-10-12 22:43 - 2016-10-05 05:06 - 01880576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-10-12 22:43 - 2016-10-05 05:06 - 01594368 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-10-12 22:43 - 2016-10-05 05:06 - 01013248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2016-10-12 22:43 - 2016-10-05 05:06 - 00850944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2016-10-12 22:43 - 2016-10-05 05:06 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2016-10-12 22:43 - 2016-10-05 05:05 - 03105792 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2016-10-12 22:43 - 2016-10-05 05:05 - 00751104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2016-10-12 22:43 - 2016-09-22 23:59 - 00446124 _____ C:\WINDOWS\system32\ApnDatabase.xml
2016-10-12 22:43 - 2016-09-07 01:18 - 00290264 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-10-08 20:02 - 2016-10-08 20:02 - 00872863 _____ C:\Users\jabbe_000\Downloads\SpartanJ-soil2-0c3ee32de3ba (1).zip
2016-10-08 17:35 - 2016-10-17 13:32 - 00000000 ____D C:\Users\jabbe_000\AppData\Local\NPE
2016-10-07 23:20 - 2016-10-17 16:17 - 00008234 _____ C:\WINDOWS\system32\Drivers\SYMEVENT.CAT
2016-10-07 23:20 - 2016-10-07 23:20 - 00088312 _____ (Symantec Corporation) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
2016-10-07 23:19 - 2016-10-16 22:14 - 00000000 ____D C:\WINDOWS\system32\Drivers\N360
2016-10-07 23:19 - 2016-10-07 23:20 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360
2016-10-07 23:19 - 2016-10-07 23:19 - 00000000 ____D C:\Program Files\Norton 360
2016-10-07 23:05 - 2016-10-07 23:05 - 00000000 ____D C:\ProgramData\PCSettings
2016-10-07 22:28 - 2016-10-15 16:03 - 00000000 ____D C:\Users\jabbe_000\AppData\Local\bcefaa26
2016-10-07 22:28 - 2016-10-07 22:28 - 00000000 ____D C:\Users\jabbe_000\AppData\Roaming\bec53dd7
2016-10-01 22:04 - 2016-10-07 22:29 - 00000000 ____H C:\Users\jabbe_000\AppData\Local\IconCache.db.backup
2016-09-29 21:39 - 2016-09-15 14:14 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2016-09-29 21:39 - 2016-09-15 13:42 - 01144600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2016-09-29 21:39 - 2016-09-15 13:40 - 00965472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2016-09-29 21:39 - 2016-09-15 13:37 - 00496872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2016-09-29 21:39 - 2016-09-15 13:37 - 00320152 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2016-09-29 21:39 - 2016-09-15 13:35 - 00470368 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-09-29 21:39 - 2016-09-15 13:35 - 00455040 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2016-09-29 21:39 - 2016-09-15 13:35 - 00356704 _____ (Microsoft Corporation) C:\WINDOWS\system32\halmacpi.dll
2016-09-29 21:39 - 2016-09-15 13:35 - 00356704 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2016-09-29 21:39 - 2016-09-15 13:32 - 02048496 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2016-09-29 21:39 - 2016-09-15 13:32 - 00279416 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdeunlock.exe
2016-09-29 21:39 - 2016-09-15 13:31 - 00583648 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2016-09-29 21:39 - 2016-09-15 13:28 - 01015648 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-09-29 21:39 - 2016-09-15 13:27 - 00868704 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2016-09-29 21:39 - 2016-09-15 13:23 - 01897824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-09-29 21:39 - 2016-09-15 13:23 - 01503032 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2016-09-29 21:39 - 2016-09-15 13:23 - 00550240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-09-29 21:39 - 2016-09-15 13:23 - 00342368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2016-09-29 21:39 - 2016-09-15 13:23 - 00170448 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2016-09-29 21:39 - 2016-09-15 13:22 - 00433832 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2016-09-29 21:39 - 2016-09-15 13:22 - 00111968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys
2016-09-29 21:39 - 2016-09-15 13:21 - 00557920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2016-09-29 21:39 - 2016-09-15 13:21 - 00272720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2016-09-29 21:39 - 2016-09-15 13:19 - 00361104 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll
2016-09-29 21:39 - 2016-09-15 13:18 - 06654616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2016-09-29 21:39 - 2016-09-15 13:18 - 01201872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2016-09-29 21:39 - 2016-09-15 13:18 - 01123368 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2016-09-29 21:39 - 2016-09-15 13:18 - 00955528 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-09-29 21:39 - 2016-09-15 13:18 - 00856872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2016-09-29 21:39 - 2016-09-15 13:17 - 20965248 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-09-29 21:39 - 2016-09-15 13:14 - 01413664 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2016-09-29 21:39 - 2016-09-15 13:13 - 01276608 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-09-29 21:39 - 2016-09-15 13:13 - 01264912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2016-09-29 21:39 - 2016-09-15 13:13 - 00484544 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-09-29 21:39 - 2016-09-15 13:13 - 00113504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
2016-09-29 21:39 - 2016-09-15 13:12 - 00046784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2016-09-29 21:39 - 2016-09-15 13:03 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2016-09-29 21:39 - 2016-09-15 13:00 - 00518656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2016-09-29 21:39 - 2016-09-15 13:00 - 00399360 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2016-09-29 21:39 - 2016-09-15 13:00 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\BcastDVRHelper.dll
2016-09-29 21:39 - 2016-09-15 13:00 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\NfcRadioMedia.dll
2016-09-29 21:39 - 2016-09-15 12:59 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\unimdm.tsp
2016-09-29 21:39 - 2016-09-15 12:59 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovslegacy.dll
2016-09-29 21:39 - 2016-09-15 12:58 - 00491008 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-09-29 21:39 - 2016-09-15 12:58 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2016-09-29 21:39 - 2016-09-15 12:58 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2016-09-29 21:39 - 2016-09-15 12:58 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2016-09-29 21:39 - 2016-09-15 12:58 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2016-09-29 21:39 - 2016-09-15 12:58 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2016-09-29 21:39 - 2016-09-15 12:57 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.LowLevel.dll
2016-09-29 21:39 - 2016-09-15 12:57 - 00272896 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-09-29 21:39 - 2016-09-15 12:57 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.Phone.dll
2016-09-29 21:39 - 2016-09-15 12:57 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll
2016-09-29 21:39 - 2016-09-15 12:57 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Flights.dll
2016-09-29 21:39 - 2016-09-15 12:57 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthRadioMedia.dll
2016-09-29 21:39 - 2016-09-15 12:56 - 01300480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2016-09-29 21:39 - 2016-09-15 12:56 - 00823808 _____ (Microsoft Corporation) C:\WINDOWS\system32\nettrace.dll
2016-09-29 21:39 - 2016-09-15 12:56 - 00413184 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVolSSO.dll
2016-09-29 21:39 - 2016-09-15 12:56 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2016-09-29 21:39 - 2016-09-15 12:56 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMapi.dll
2016-09-29 21:39 - 2016-09-15 12:55 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.dll
2016-09-29 21:39 - 2016-09-15 12:55 - 00386048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
2016-09-29 21:39 - 2016-09-15 12:55 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2016-09-29 21:39 - 2016-09-15 12:55 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll
2016-09-29 21:39 - 2016-09-15 12:55 - 00202752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.HumanInterfaceDevice.dll
2016-09-29 21:39 - 2016-09-15 12:55 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2016-09-29 21:39 - 2016-09-15 12:55 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupugc.exe
2016-09-29 21:39 - 2016-09-15 12:54 - 00747520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Ocr.dll
2016-09-29 21:39 - 2016-09-15 12:54 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-09-29 21:39 - 2016-09-15 12:54 - 00323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicesFlowBroker.dll
2016-09-29 21:39 - 2016-09-15 12:54 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvc.dll
2016-09-29 21:39 - 2016-09-15 12:54 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
2016-09-29 21:39 - 2016-09-15 12:54 - 00132096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2016-09-29 21:39 - 2016-09-15 12:53 - 01344000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2016-09-29 21:39 - 2016-09-15 12:53 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-09-29 21:39 - 2016-09-15 12:52 - 00822272 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2016-09-29 21:39 - 2016-09-15 12:52 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\NaturalLanguage6.dll
2016-09-29 21:39 - 2016-09-15 12:52 - 00500224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2016-09-29 21:39 - 2016-09-15 12:52 - 00445952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprapi.dll
2016-09-29 21:39 - 2016-09-15 12:52 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2016-09-29 21:39 - 2016-09-15 12:52 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2016-09-29 21:39 - 2016-09-15 12:52 - 00238080 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2016-09-29 21:39 - 2016-09-15 12:51 - 02333184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2016-09-29 21:39 - 2016-09-15 12:51 - 00551936 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2016-09-29 21:39 - 2016-09-15 12:51 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\CryptoWinRT.dll
2016-09-29 21:39 - 2016-09-15 12:50 - 01534464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll
2016-09-29 21:39 - 2016-09-15 12:50 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe
2016-09-29 21:39 - 2016-09-15 12:49 - 00901120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2016-09-29 21:39 - 2016-09-15 12:49 - 00653312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2016-09-29 21:39 - 2016-09-15 12:49 - 00499200 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2016-09-29 21:39 - 2016-09-15 12:48 - 00626688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2016-09-29 21:39 - 2016-09-15 12:48 - 00310272 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2016-09-29 21:39 - 2016-09-15 12:48 - 00153088 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2016-09-29 21:39 - 2016-09-15 12:47 - 01077760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll
2016-09-29 21:39 - 2016-09-15 12:47 - 00355328 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTMediaFrame.dll
2016-09-29 21:39 - 2016-09-15 12:47 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\RelPost.exe
2016-09-29 21:39 - 2016-09-15 12:47 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Energy.dll
2016-09-29 21:39 - 2016-09-15 12:46 - 03305984 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2016-09-29 21:39 - 2016-09-15 12:46 - 00945664 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2016-09-29 21:39 - 2016-09-15 12:46 - 00795648 _____ (Microsoft Corporation) C:\WINDOWS\system32\MiracastReceiver.dll
2016-09-29 21:39 - 2016-09-15 12:46 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2016-09-29 21:39 - 2016-09-15 12:46 - 00343040 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
2016-09-29 21:39 - 2016-09-15 12:46 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcfg.dll
2016-09-29 21:39 - 2016-09-15 12:45 - 02749440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2016-09-29 21:39 - 2016-09-15 12:45 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\manage-bde.exe
2016-09-29 21:39 - 2016-09-15 12:44 - 02153984 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll
2016-09-29 21:39 - 2016-09-15 12:44 - 00786432 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-09-29 21:39 - 2016-09-15 12:44 - 00582656 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceControl.dll
2016-09-29 21:39 - 2016-09-15 12:44 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2016-09-29 21:39 - 2016-09-15 12:44 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
2016-09-29 21:39 - 2016-09-15 12:44 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\discan.dll
2016-09-29 21:39 - 2016-09-15 12:44 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvenotify.exe
2016-09-29 21:39 - 2016-09-15 12:44 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Sens.dll
2016-09-29 21:39 - 2016-09-15 12:43 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi2.dll
2016-09-29 21:39 - 2016-09-15 12:43 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdeui.dll
2016-09-29 21:39 - 2016-09-15 12:42 - 01220608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2016-09-29 21:39 - 2016-09-15 12:42 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceAgent.exe
2016-09-29 21:39 - 2016-09-15 12:42 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2016-09-29 21:39 - 2016-09-15 12:41 - 03733504 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2016-09-29 21:39 - 2016-09-15 12:41 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2016-09-29 21:39 - 2016-09-15 12:41 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Geolocation.dll
2016-09-29 21:39 - 2016-09-15 12:40 - 02138112 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-09-29 21:39 - 2016-09-15 12:40 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-09-29 21:39 - 2016-09-15 12:40 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll
2016-09-29 21:39 - 2016-09-15 12:39 - 02740224 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2016-09-29 21:39 - 2016-09-15 12:38 - 00691200 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2016-09-29 21:39 - 2016-09-15 12:38 - 00620544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2016-09-29 21:39 - 2016-09-15 12:38 - 00585728 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-09-29 21:39 - 2016-09-15 12:36 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2016-09-29 21:39 - 2016-09-15 12:36 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\FontProvider.dll
2016-09-29 21:39 - 2016-09-15 12:35 - 01438720 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2016-09-29 21:39 - 2016-09-15 12:35 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SessEnv.dll
2016-09-29 21:39 - 2016-09-15 12:35 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\spaceman.exe
2016-09-29 21:39 - 2016-08-05 23:33 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\smphost.dll
2016-09-29 21:38 - 2016-09-15 13:33 - 00083120 _____ (Microsoft Corporation) C:\WINDOWS\system32\devenum.dll
2016-09-29 21:38 - 2016-09-15 13:25 - 00262960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2016-09-29 21:38 - 2016-09-15 13:22 - 05722320 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2016-09-29 21:38 - 2016-09-15 13:22 - 00975744 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2016-09-29 21:38 - 2016-09-15 13:22 - 00860512 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-09-29 21:38 - 2016-09-15 13:21 - 00357216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2016-09-29 21:38 - 2016-09-15 13:21 - 00186720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2016-09-29 21:38 - 2016-09-15 13:21 - 00175968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2016-09-29 21:38 - 2016-09-15 13:20 - 00095072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
2016-09-29 21:38 - 2016-09-15 13:08 - 05683712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-09-29 21:38 - 2016-09-15 13:02 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfksproxy.dll
2016-09-29 21:38 - 2016-09-15 13:00 - 00554496 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2016-09-29 21:38 - 2016-09-15 12:58 - 00254976 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2016-09-29 21:38 - 2016-09-15 12:56 - 00576512 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2016-09-29 21:38 - 2016-09-15 12:56 - 00262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\pdh.dll
2016-09-29 21:38 - 2016-09-15 12:55 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2016-09-29 21:38 - 2016-09-15 12:55 - 00293888 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2016-09-29 21:38 - 2016-09-15 12:55 - 00152064 _____ (Microsoft Corporation) C:\WINDOWS\system32\biwinrt.dll
2016-09-29 21:38 - 2016-09-15 12:53 - 00819200 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll
2016-09-29 21:38 - 2016-09-15 12:52 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-09-29 21:38 - 2016-09-15 12:52 - 00500736 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2016-09-29 21:38 - 2016-09-15 12:49 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2016-09-29 21:38 - 2016-09-15 12:46 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll
2016-09-29 21:38 - 2016-09-15 12:45 - 00470016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
2016-09-29 21:38 - 2016-09-15 12:44 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll
2016-09-29 21:38 - 2016-09-15 12:43 - 03196416 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2016-09-29 21:38 - 2016-09-15 12:39 - 00827904 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2016-09-29 21:38 - 2016-09-15 12:36 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2016-09-29 21:37 - 2016-09-15 13:19 - 00080224 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2016-09-29 21:37 - 2016-09-15 13:12 - 00781664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-09-29 21:37 - 2016-09-15 12:58 - 00132608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2016-09-29 21:37 - 2016-09-15 12:56 - 00257536 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataExchange.dll
2016-09-29 21:37 - 2016-09-15 12:40 - 01247232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2016-09-29 21:36 - 2016-09-15 13:03 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2016-09-29 21:36 - 2016-09-15 12:42 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\BackgroundMediaPolicy.dll
2016-09-29 21:35 - 2016-09-15 13:42 - 00448864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2016-09-29 21:35 - 2016-09-15 13:38 - 04970224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2016-09-29 21:35 - 2016-09-15 13:37 - 00402352 _____ (Microsoft Corporation) C:\WINDOWS\system32\ws2_32.dll
2016-09-29 21:35 - 2016-09-15 13:36 - 00021344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cmimcext.sys
2016-09-29 21:35 - 2016-09-15 13:35 - 01583112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-09-29 21:35 - 2016-09-15 13:34 - 00106336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2016-09-29 21:35 - 2016-09-15 13:26 - 00581672 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2016-09-29 21:35 - 2016-09-15 13:25 - 00340320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-09-29 21:35 - 2016-09-15 13:21 - 00458592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2016-09-29 21:35 - 2016-09-15 13:21 - 00261984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2016-09-29 21:35 - 2016-09-15 13:20 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2016-09-29 21:35 - 2016-09-15 13:17 - 04311736 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2016-09-29 21:35 - 2016-09-15 13:17 - 01384704 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2016-09-29 21:35 - 2016-09-15 13:17 - 00834128 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2016-09-29 21:35 - 2016-09-15 13:17 - 00702416 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2016-09-29 21:35 - 2016-09-15 13:17 - 00125792 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostBroker.dll
2016-09-29 21:35 - 2016-09-15 13:16 - 00093984 _____ (Microsoft Corporation) C:\WINDOWS\system32\phoneactivate.exe
2016-09-29 21:35 - 2016-09-15 13:06 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2016-09-29 21:35 - 2016-09-15 13:06 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ffbroker.dll
2016-09-29 21:35 - 2016-09-15 13:02 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2016-09-29 21:35 - 2016-09-15 13:01 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Radios.dll
2016-09-29 21:35 - 2016-09-15 13:01 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2016-09-29 21:35 - 2016-09-15 13:01 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\findnetprinters.dll
2016-09-29 21:35 - 2016-09-15 13:01 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmintegrator.dll
2016-09-29 21:35 - 2016-09-15 13:00 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2016-09-29 21:35 - 2016-09-15 13:00 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.Client.dll
2016-09-29 21:35 - 2016-09-15 13:00 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdhid.sys
2016-09-29 21:35 - 2016-09-15 12:59 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinRtTracing.dll
2016-09-29 21:35 - 2016-09-15 12:58 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmrdvcore.dll
2016-09-29 21:35 - 2016-09-15 12:58 - 00291840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2016-09-29 21:35 - 2016-09-15 12:58 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlancfg.dll
2016-09-29 21:35 - 2016-09-15 12:58 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.SyncEngine.dll
2016-09-29 21:35 - 2016-09-15 12:58 - 00142336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFi.dll
2016-09-29 21:35 - 2016-09-15 12:58 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.UserDeviceAssociation.dll
2016-09-29 21:35 - 2016-09-15 12:57 - 03716096 _____ (Microsoft Corporation) C:\WINDOWS\system32\bootux.dll
2016-09-29 21:35 - 2016-09-15 12:57 - 00392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Input.dll
2016-09-29 21:35 - 2016-09-15 12:57 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.XboxLive.Storage.dll
2016-09-29 21:35 - 2016-09-15 12:57 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2016-09-29 21:35 - 2016-09-15 12:57 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2016-09-29 21:35 - 2016-09-15 12:57 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-09-29 21:35 - 2016-09-15 12:57 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipboardServer.dll
2016-09-29 21:35 - 2016-09-15 12:57 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2016-09-29 21:35 - 2016-09-15 12:56 - 00670208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2016-09-29 21:35 - 2016-09-15 12:56 - 00609280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll
2016-09-29 21:35 - 2016-09-15 12:56 - 00554496 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-09-29 21:35 - 2016-09-15 12:56 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2016-09-29 21:35 - 2016-09-15 12:56 - 00265728 _____ C:\WINDOWS\system32\Windows.Perception.Stub.dll
2016-09-29 21:35 - 2016-09-15 12:55 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2016-09-29 21:35 - 2016-09-15 12:55 - 00518144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2016-09-29 21:35 - 2016-09-15 12:55 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkCollectionAgent.dll
2016-09-29 21:35 - 2016-09-15 12:55 - 00378368 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrGidsHandler.dll
2016-09-29 21:35 - 2016-09-15 12:55 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2016-09-29 21:35 - 2016-09-15 12:55 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2016-09-29 21:35 - 2016-09-15 12:55 - 00277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvcext.dll
2016-09-29 21:35 - 2016-09-15 12:55 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\usbmon.dll
2016-09-29 21:35 - 2016-09-15 12:55 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
2016-09-29 21:35 - 2016-09-15 12:55 - 00213504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.CredDialogController.dll
2016-09-29 21:35 - 2016-09-15 12:55 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2016-09-29 21:35 - 2016-09-15 12:54 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mbsmsapi.dll
2016-09-29 21:35 - 2016-09-15 12:54 - 00493568 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsregcmd.exe
2016-09-29 21:35 - 2016-09-15 12:54 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll
2016-09-29 21:35 - 2016-09-15 12:54 - 00431104 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprdim.dll
2016-09-29 21:35 - 2016-09-15 12:54 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Picker.dll
2016-09-29 21:35 - 2016-09-15 12:53 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2016-09-29 21:35 - 2016-09-15 12:53 - 00314368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll
2016-09-29 21:35 - 2016-09-15 12:53 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.dll
2016-09-29 21:35 - 2016-09-15 12:52 - 01110016 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2016-09-29 21:35 - 2016-09-15 12:52 - 00834560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2016-09-29 21:35 - 2016-09-15 12:52 - 00525824 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs.dll
2016-09-29 21:35 - 2016-09-15 12:52 - 00441856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2016-09-29 21:35 - 2016-09-15 12:52 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2016-09-29 21:35 - 2016-09-15 12:51 - 00762368 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprddm.dll
2016-09-29 21:35 - 2016-09-15 12:50 - 07625728 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-09-29 21:35 - 2016-09-15 12:50 - 00796672 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
2016-09-29 21:35 - 2016-09-15 12:50 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\pwrshplugin.dll
2016-09-29 21:35 - 2016-09-15 12:49 - 00468992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.InkControls.dll
2016-09-29 21:35 - 2016-09-15 12:48 - 01321472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2016-09-29 21:35 - 2016-09-15 12:48 - 01112576 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2016-09-29 21:35 - 2016-09-15 12:47 - 01098752 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll
2016-09-29 21:35 - 2016-09-15 12:46 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2016-09-29 21:35 - 2016-09-15 12:45 - 02642944 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2016-09-29 21:35 - 2016-09-15 12:45 - 00302592 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
2016-09-29 21:35 - 2016-09-15 12:45 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll
2016-09-29 21:35 - 2016-09-15 12:44 - 00734208 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2016-09-29 21:35 - 2016-09-15 12:44 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAC3ENC.DLL
2016-09-29 21:35 - 2016-09-15 12:43 - 04596224 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsDesktopEngine.exe
2016-09-29 21:35 - 2016-09-15 12:43 - 03520512 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2016-09-29 21:35 - 2016-09-15 12:43 - 00758784 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2016-09-29 21:35 - 2016-09-15 12:43 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToReceiver.dll
2016-09-29 21:35 - 2016-09-15 12:43 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
2016-09-29 21:35 - 2016-09-15 12:43 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\olepro32.dll
2016-09-29 21:35 - 2016-09-15 12:42 - 00719872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_sr.dll
2016-09-29 21:35 - 2016-09-15 12:40 - 02026496 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2016-09-29 21:35 - 2016-09-15 12:40 - 01988096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2016-09-29 21:35 - 2016-09-15 12:40 - 01656320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Perception.dll
2016-09-29 21:35 - 2016-09-15 12:40 - 00580096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2016-09-29 21:35 - 2016-09-15 12:39 - 01232384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll
2016-09-29 21:35 - 2016-09-15 12:39 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
2016-09-29 21:35 - 2016-09-15 12:39 - 01004544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2016-09-29 21:35 - 2016-09-15 12:39 - 00941568 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2016-09-29 21:35 - 2016-09-15 12:39 - 00240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll
2016-09-29 21:35 - 2016-09-15 12:38 - 00773120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2016-09-29 21:35 - 2016-09-15 12:38 - 00654336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2016-09-29 21:35 - 2016-09-15 12:38 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2016-09-29 21:35 - 2016-09-15 12:35 - 00783360 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2016-09-22 22:11 - 2016-09-22 22:11 - 00000000 ____D C:\Users\jabbe_000\.vs
2016-09-21 22:39 - 2016-09-21 19:26 - 00000000 ___DC C:\WINDOWS\Panther
2016-09-21 22:35 - 2016-09-21 22:35 - 13867520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 09260032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmploc.DLL
2016-09-21 22:35 - 2016-09-21 22:35 - 06534656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 05398016 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 05376000 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 04557824 _____ (Microsoft) C:\WINDOWS\system32\dbgeng.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 03595264 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2016-09-21 22:35 - 2016-09-21 22:35 - 02423296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAJApi.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 02360832 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 02318336 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 02206496 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 02166232 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 02107392 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 01997824 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 01993216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 01966288 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 01957216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2016-09-21 22:35 - 2016-09-21 22:35 - 01935360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d12SDKLayers.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 01885696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 01853232 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 01842688 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 01774080 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 01755136 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 01557296 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 01556992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 01509376 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 01362504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 01344992 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 01343928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 01293312 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2016-09-21 22:35 - 2016-09-21 22:35 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 01056768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 01013248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00959104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00939872 _____ (Microsoft Corporation) C:\WINDOWS\system32\pidgenx.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00920576 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00895488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00894976 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorDataService.exe
2016-09-21 22:35 - 2016-09-21 22:35 - 00866816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00860672 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebcamUi.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00806912 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00798504 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00798208 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00782176 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2016-09-21 22:35 - 2016-09-21 22:35 - 00761344 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00755200 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00705536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00640000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00636928 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00601200 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2016-09-21 22:35 - 2016-09-21 22:35 - 00589144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys
2016-09-21 22:35 - 2016-09-21 22:35 - 00582144 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\system32\qdvd.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00570720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2016-09-21 22:35 - 2016-09-21 22:35 - 00564488 _____ (Microsoft Corporation) C:\WINDOWS\system32\GenValObj.exe
2016-09-21 22:35 - 2016-09-21 22:35 - 00536576 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00529928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00520192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-09-21 22:35 - 2016-09-21 22:35 - 00509792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2016-09-21 22:35 - 2016-09-21 22:35 - 00461312 _____ (Microsoft) C:\WINDOWS\system32\DbgModel.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32time.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00444416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00432328 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMRServer.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00416256 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosResource.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00399712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2016-09-21 22:35 - 2016-09-21 22:35 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00392704 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00392704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00366592 _____ (Microsoft Corporation) C:\WINDOWS\system32\das.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00353792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2016-09-21 22:35 - 2016-09-21 22:35 - 00341344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
2016-09-21 22:35 - 2016-09-21 22:35 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00331264 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00321792 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2016-09-21 22:35 - 2016-09-21 22:35 - 00315736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
2016-09-21 22:35 - 2016-09-21 22:35 - 00313560 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00309760 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00300544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00297552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtapi.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00292184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2016-09-21 22:35 - 2016-09-21 22:35 - 00289280 _____ (Microsoft Corporation) C:\WINDOWS\system32\NmaDirect.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00270848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifiprofilessettinghandler.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00260448 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00260096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Phoneutil.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00246784 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00244224 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2016-09-21 22:35 - 2016-09-21 22:35 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_G18030.DLL
2016-09-21 22:35 - 2016-09-21 22:35 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExSMime.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_WorkAccess.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00211456 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2016-09-21 22:35 - 2016-09-21 22:35 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2016-09-21 22:35 - 2016-09-21 22:35 - 00192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2016-09-21 22:35 - 2016-09-21 22:35 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcpipcfg.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafpos.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00162850 _____ C:\WINDOWS\system32\C_932.NLS
2016-09-21 22:35 - 2016-09-21 22:35 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2016-09-21 22:35 - 2016-09-21 22:35 - 00158208 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2016-09-21 22:35 - 2016-09-21 22:35 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00145248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2016-09-21 22:35 - 2016-09-21 22:35 - 00141824 _____ (Windows ® Win 7 DDK provider) C:\WINDOWS\system32\DscCoreConfProv.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00133296 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00127168 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00121368 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\slc.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys
2016-09-21 22:35 - 2016-09-21 22:35 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppc.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.UI.Logon.ProxyStub.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00102752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
2016-09-21 22:35 - 2016-09-21 22:35 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00101216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\EhStorTcgDrv.sys
2016-09-21 22:35 - 2016-09-21 22:35 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MediaFoundation.DefaultPerceptionProvider.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00094528 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00092000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2016-09-21 22:35 - 2016-09-21 22:35 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\CastLaunch.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\dasHost.exe
2016-09-21 22:35 - 2016-09-21 22:35 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\POSyncServices.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataPlatformHelperUtil.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AddressParser.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00054624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2016-09-21 22:35 - 2016-09-21 22:35 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2016-09-21 22:35 - 2016-09-21 22:35 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\csrsrv.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactActivation.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModelOOBE.exe
2016-09-21 22:35 - 2016-09-21 22:35 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00043944 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsass.exe
2016-09-21 22:35 - 2016-09-21 22:35 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTypeHelperUtil.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataLanguageUtil.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00036704 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe
2016-09-21 22:35 - 2016-09-21 22:35 - 00036168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
2016-09-21 22:35 - 2016-09-21 22:35 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceassociation.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2016-09-21 22:35 - 2016-09-21 22:35 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
2016-09-21 22:35 - 2016-09-21 22:35 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys
2016-09-21 22:35 - 2016-09-21 22:35 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidusb.sys
2016-09-21 22:35 - 2016-09-21 22:35 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\netiougc.exe
2016-09-21 22:35 - 2016-09-21 22:35 - 00023776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2016-09-21 22:35 - 2016-09-21 22:35 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\encapi.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerSvc.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\delegatorprovider.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi_passthru.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\system32\slcext.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExtrasXmlParser.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_IS2022.DLL
2016-09-21 22:35 - 2016-09-21 22:35 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\c_GSM7.DLL
2016-09-21 22:35 - 2016-09-21 22:35 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.exe
2016-09-21 22:35 - 2016-09-21 22:35 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwmp.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccessRes.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdxm.ocx
2016-09-21 22:35 - 2016-09-21 22:35 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxmasf.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneutilRes.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneServiceRes.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6r.dll
2016-09-21 22:35 - 2016-09-21 22:35 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlStringsRes.dll
2016-09-21 22:31 - 2016-09-21 22:31 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2016-09-21 22:31 - 2016-07-15 22:58 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\DxToolsReportGenerator.dll
2016-09-21 22:31 - 2016-07-15 22:44 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsProxyStub.dll
2016-09-21 22:31 - 2016-07-15 22:43 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSD3DWARP12Debug.dll
2016-09-21 22:31 - 2016-07-15 22:42 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSD3DWARPDebug.dll
2016-09-21 22:31 - 2016-07-15 22:41 - 00355840 _____ (Windows ® Win 7 DDK provider) C:\WINDOWS\system32\DXCpl.exe
2016-09-21 22:31 - 2016-07-15 22:41 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXGIDebug.dll
2016-09-21 22:31 - 2016-07-15 22:39 - 11670528 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXCaptureReplay.dll
2016-09-21 22:31 - 2016-07-15 22:38 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1debug3.dll
2016-09-21 22:31 - 2016-07-15 22:37 - 01074176 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11_3SDKLayers.dll
2016-09-21 22:31 - 2016-07-15 22:35 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\system32\perf_gputiming.dll
2016-09-21 22:31 - 2016-07-15 22:32 - 03701248 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsRemoteEngine.exe
2016-09-21 22:31 - 2016-07-15 22:31 - 04977664 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d12warp.dll
2016-09-21 22:31 - 2016-07-15 22:29 - 00953344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXCap.exe
2016-09-21 22:31 - 2016-07-15 22:29 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsExperiment.dll
2016-09-21 22:31 - 2016-07-15 22:29 - 00134144 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsCapture.dll
2016-09-21 22:31 - 2016-07-15 22:28 - 01509888 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsOfflineAnalysis.dll
2016-09-21 22:31 - 2016-07-15 22:28 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsMonitor.dll
2016-09-21 22:31 - 2016-07-15 22:28 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsReporting.dll
2016-09-21 22:29 - 2016-09-21 22:29 - 00173408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
2016-09-21 22:29 - 2016-09-21 22:29 - 00000000 ____D C:\Program Files\Reference Assemblies
2016-09-21 22:29 - 2016-09-21 19:09 - 00000000 ____D C:\Program Files\MSBuild
2016-09-21 22:29 - 2016-05-25 15:03 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2016-09-21 22:29 - 2016-05-25 15:03 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2016-09-21 22:29 - 2016-05-25 15:03 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2016-09-21 21:27 - 2016-09-21 21:27 - 00000000 ____D C:\ProgramData\USOShared
2016-09-21 19:30 - 2016-09-21 19:30 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2016-09-21 19:27 - 2016-10-02 13:58 - 00000000 ____D C:\Users\jabbe_000\AppData\Local\ConnectedDevicesPlatform
2016-09-21 19:27 - 2016-10-02 13:57 - 00000000 ____D C:\Users\jabbe_000\AppData\Local\PackageStaging
2016-09-21 19:26 - 2016-09-21 19:26 - 00000020 ___SH C:\Users\jabbe_000\ntuser.ini
2016-09-21 19:26 - 2016-09-21 19:26 - 00000000 _SHDL C:\Users\Default\My Documents
2016-09-21 19:26 - 2016-09-21 19:26 - 00000000 _SHDL C:\Users\Default\Documents\My Videos
2016-09-21 19:26 - 2016-09-21 19:26 - 00000000 _SHDL C:\Users\Default\Documents\My Pictures
2016-09-21 19:26 - 2016-09-21 19:26 - 00000000 _SHDL C:\Users\Default\Documents\My Music
2016-09-21 19:26 - 2016-09-21 19:26 - 00000000 _SHDL C:\Users\Default User\Documents\My Videos
2016-09-21 19:26 - 2016-09-21 19:26 - 00000000 _SHDL C:\Users\Default User\Documents\My Pictures
2016-09-21 19:26 - 2016-09-21 19:26 - 00000000 _SHDL C:\Users\Default User\Documents\My Music
2016-09-21 19:23 - 2016-09-21 19:25 - 00007623 _____ C:\WINDOWS\diagwrn.xml
2016-09-21 19:23 - 2016-09-21 19:25 - 00007623 _____ C:\WINDOWS\diagerr.xml
2016-09-21 19:12 - 2016-10-17 13:42 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-09-21 19:08 - 2016-09-21 19:08 - 00001544 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-09-21 18:48 - 2016-09-21 19:09 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2016-09-21 18:45 - 2016-10-17 13:48 - 01149868 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-09-21 18:45 - 2016-10-17 13:44 - 00000000 ____D C:\Users\jabbe_000
2016-09-21 18:45 - 2016-09-21 18:45 - 00000000 _SHDL C:\Users\jabbe_000\My Documents
2016-09-21 18:45 - 2016-09-21 18:45 - 00000000 _SHDL C:\Users\jabbe_000\Documents\My Videos
2016-09-21 18:45 - 2016-09-21 18:45 - 00000000 _SHDL C:\Users\jabbe_000\Documents\My Pictures
2016-09-21 18:45 - 2016-09-21 18:45 - 00000000 _SHDL C:\Users\jabbe_000\Documents\My Music
2016-09-21 18:41 - 2016-09-21 18:41 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2016-09-21 18:41 - 2016-09-21 18:41 - 00000000 _____ C:\WINDOWS\ativpsrm.bin
2016-09-21 18:40 - 2016-10-16 18:35 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2016-09-21 18:40 - 2016-10-13 01:04 - 00337888 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-09-21 18:40 - 2016-09-21 18:40 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2016-09-18 15:44 - 2016-10-08 20:10 - 00000000 ____D C:\OpenGL
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-10-17 16:17 - 2014-11-24 21:01 - 00000000 ____D C:\Program Files\Backblaze
2016-10-17 13:45 - 2015-02-03 00:37 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
2016-10-17 13:44 - 2014-11-29 23:01 - 00000000 ____D C:\Users\jabbe_000\AppData\Roaming\Skype
2016-10-17 13:43 - 2014-11-22 03:02 - 00000000 __RDO C:\Users\jabbe_000\OneDrive
2016-10-17 13:42 - 2016-07-15 22:22 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2016-10-17 13:41 - 2016-07-15 22:22 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2016-10-17 13:30 - 2016-07-16 04:28 - 00000000 ____D C:\WINDOWS\INF
2016-10-16 21:57 - 2014-11-22 03:06 - 00000000 ____D C:\ProgramData\Norton
2016-10-15 14:38 - 2015-12-31 00:31 - 00000000 ____D C:\Users\jabbe_000\Documents\Visual Studio 2015
2016-10-15 12:59 - 2016-07-16 04:29 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-10-14 21:11 - 2016-07-16 04:29 - 00000000 ____D C:\WINDOWS\rescache
2016-10-14 12:21 - 2016-07-16 04:29 - 00000000 ___HD C:\Program Files\WindowsApps
2016-10-13 18:17 - 2014-12-21 11:58 - 00000000 ____D C:\Users\jabbe_000\AppData\Local\CrashDumps
2016-10-13 01:02 - 2016-07-16 04:29 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
2016-10-13 01:02 - 2016-07-16 04:29 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-10-13 01:02 - 2016-07-16 04:29 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-10-13 01:02 - 2016-07-16 04:29 - 00000000 ____D C:\WINDOWS\system32\migwiz
2016-10-13 01:02 - 2016-07-16 04:29 - 00000000 ____D C:\WINDOWS\ShellExperiences
2016-10-13 01:02 - 2016-07-16 04:29 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2016-10-13 00:07 - 2016-07-16 04:19 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-10-13 00:03 - 2014-11-24 08:21 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-10-12 23:54 - 2014-11-24 08:21 - 141042968 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-10-12 22:07 - 2016-07-16 04:25 - 00177664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Diagnostics.dll
2016-10-08 17:25 - 2016-07-16 04:29 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2016-10-07 23:20 - 2016-07-16 04:29 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2016-10-07 23:20 - 2014-11-22 14:59 - 00002350 _____ C:\Users\jabbe_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton 360.lnk
2016-10-07 23:20 - 2014-11-22 05:10 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2016-10-07 23:13 - 2014-11-22 03:06 - 00000000 ____D C:\Users\Public\Downloads\Norton
2016-10-07 23:05 - 2014-11-22 05:09 - 00000000 ____D C:\ProgramData\NortonInstaller
2016-10-07 22:49 - 2014-11-22 05:09 - 00000000 ____D C:\Program Files\NortonInstaller
2016-10-07 22:48 - 2015-02-26 22:34 - 00000000 ____D C:\Program Files\Common Files\Steam
2016-10-07 22:42 - 2015-07-03 11:57 - 00000000 ____D C:\Users\jabbe_000\AppData\Local\Dropbox
2016-10-07 22:39 - 2016-01-21 22:36 - 00000000 ____D C:\Users\jabbe_000\AppData\Local\TSVNCache
2016-10-07 22:39 - 2014-11-22 03:00 - 00000000 ____D C:\Users\jabbe_000\AppData\Local\Packages
2016-10-07 22:37 - 2014-11-22 14:49 - 00002218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-10-07 22:35 - 2014-11-22 14:48 - 00000000 ___RD C:\Users\jabbe_000\Dropbox
2016-10-03 16:09 - 2016-07-16 04:31 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2016-10-03 16:09 - 2016-07-16 04:31 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2016-10-02 13:57 - 2016-02-13 08:21 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-10-02 00:13 - 2016-07-16 04:29 - 00000000 ___SD C:\WINDOWS\system32\F12
2016-10-02 00:13 - 2016-07-16 04:29 - 00000000 ____D C:\WINDOWS\system32\setup
2016-10-02 00:13 - 2016-07-16 04:29 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-10-02 00:13 - 2016-07-16 04:29 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-10-02 00:13 - 2016-07-16 04:29 - 00000000 ____D C:\WINDOWS\Provisioning
2016-10-02 00:13 - 2016-07-16 04:29 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-10-02 00:13 - 2016-07-15 22:22 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2016-10-02 00:13 - 2016-07-15 22:22 - 00000000 ____D C:\WINDOWS\system32\Dism
2016-09-22 04:57 - 2016-07-16 04:29 - 00000000 ____D C:\WINDOWS\appcompat
2016-09-21 22:39 - 2016-07-16 04:30 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2016-09-21 22:36 - 2016-07-16 04:29 - 00000000 ___SD C:\WINDOWS\system32\dsc
2016-09-21 22:36 - 2016-07-16 04:29 - 00000000 ___RD C:\Program Files\Windows Defender
2016-09-21 22:36 - 2016-07-16 04:29 - 00000000 ____D C:\WINDOWS\system32\es-MX
2016-09-21 22:29 - 2016-07-16 04:26 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnet.dll
2016-09-21 22:29 - 2016-07-16 04:26 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dplayx.dll
2016-09-21 22:29 - 2016-07-16 04:26 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnathlp.dll
2016-09-21 22:29 - 2016-07-16 04:26 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpwsockx.dll
2016-09-21 22:29 - 2016-07-16 04:26 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpmodemx.dll
2016-09-21 22:29 - 2016-07-16 04:26 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnsvr.exe
2016-09-21 22:29 - 2016-07-16 04:26 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\dplaysvr.exe
2016-09-21 22:29 - 2016-07-16 04:26 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhupnp.dll
2016-09-21 22:29 - 2016-07-16 04:26 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhpast.dll
2016-09-21 22:29 - 2016-07-16 04:26 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnlobby.dll
2016-09-21 22:29 - 2016-07-16 04:26 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnaddr.dll
2016-09-21 21:27 - 2016-07-16 04:29 - 00000000 ____D C:\ProgramData\USOPrivate
2016-09-21 19:34 - 2016-05-20 18:03 - 00002375 _____ C:\Users\jabbe_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-09-21 19:27 - 2015-12-31 00:06 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 12.0
2016-09-21 19:27 - 2015-12-30 23:58 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 14.0
2016-09-21 19:22 - 2016-07-16 04:29 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2016-09-21 19:22 - 2016-07-16 04:29 - 00000000 ____D C:\WINDOWS\Registration
2016-09-21 19:22 - 2015-10-30 01:48 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2016-09-21 19:16 - 2016-05-20 00:00 - 00021412 _____ C:\WINDOWS\system32\emptyregdb.dat
2016-09-21 19:15 - 2016-07-16 04:29 - 00000000 __RHD C:\Users\Public\Libraries
2016-09-21 19:10 - 2016-07-16 04:29 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2016-09-21 19:09 - 2016-08-13 13:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2016-09-21 19:09 - 2016-02-28 14:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2016-09-21 19:09 - 2016-02-13 08:05 - 00000000 ____D C:\WINDOWS\ShellNew
2016-09-21 19:09 - 2016-02-08 20:53 - 00000000 ____D C:\Users\jabbe_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Qt
2016-09-21 19:09 - 2015-12-31 00:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-09-21 19:09 - 2015-12-30 23:59 - 00000000 ____D C:\WINDOWS\system32\1033
2016-09-21 19:09 - 2015-10-11 19:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2016-09-21 19:09 - 2014-11-24 21:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backblaze
2016-09-21 19:09 - 2014-11-22 14:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Quicken 2014
2016-09-21 19:09 - 2014-11-22 13:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
2016-09-21 19:09 - 2014-11-22 13:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2016-09-21 19:09 - 2014-11-22 13:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NTI Backup Now EZ
2016-09-21 19:08 - 2016-07-16 04:29 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-09-21 19:08 - 2015-10-30 01:13 - 00000000 ____D C:\Users\Default.migrated
2016-09-21 18:53 - 2016-07-16 04:29 - 00000000 ____D C:\WINDOWS\system32\spool
2016-09-21 18:53 - 2016-07-16 04:29 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-09-21 18:53 - 2016-07-16 04:29 - 00000000 ____D C:\WINDOWS\system32\lv-LV
2016-09-21 18:53 - 2016-07-16 04:29 - 00000000 ____D C:\WINDOWS\system32\lt-LT
2016-09-21 18:53 - 2016-07-16 04:29 - 00000000 ____D C:\WINDOWS\system32\InputMethod
2016-09-21 18:53 - 2016-07-16 04:29 - 00000000 ____D C:\WINDOWS\system32\et-EE
2016-09-21 18:53 - 2016-07-16 04:29 - 00000000 ____D C:\WINDOWS\system32\en-GB
2016-09-21 18:53 - 2013-08-22 04:17 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Shared
2016-09-21 18:53 - 2013-08-22 04:17 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared
2016-09-21 18:52 - 2016-07-16 04:29 - 00000000 ____D C:\WINDOWS\InputMethod
2016-09-21 18:52 - 2016-07-16 04:29 - 00000000 ____D C:\Program Files\Common Files\System
2016-09-21 18:52 - 2016-07-16 04:29 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-09-21 18:52 - 2016-01-01 21:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-09-21 18:52 - 2015-12-31 13:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
2016-09-21 18:52 - 2015-12-31 00:08 - 00000000 ____D C:\Program Files\IIS
2016-09-21 18:52 - 2015-12-31 00:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Expression
2016-09-21 18:52 - 2015-12-31 00:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2015
2016-09-21 18:47 - 2016-04-11 21:37 - 00000000 ____D C:\Users\jabbe_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\realtech VR
2016-09-21 18:42 - 2016-07-16 04:29 - 00000000 ___RD C:\WINDOWS\PrintDialog
2016-09-21 18:42 - 2016-07-16 04:29 - 00000000 ___RD C:\WINDOWS\MiracastView
2016-09-21 15:03 - 2016-08-10 17:58 - 00000942 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3409270631-3081192051-993886705-1001UA1d1f35250a59e84.job
2016-09-21 14:41 - 2016-08-10 03:36 - 00000912 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d1f2d9eea6953f.job
2016-09-20 18:03 - 2016-08-10 17:58 - 00000890 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3409270631-3081192051-993886705-1001Core1d1f3524f375103.job
 
==================== Files in the root of some directories =======
 
2016-02-28 14:57 - 2016-02-28 14:57 - 0000057 _____ () C:\ProgramData\Ament.ini
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-10-14 13:22
 
==================== End of FRST.txt ============================

Attached Files



BC AdBot (Login to Remove)

 


#2 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,680 posts
  • ONLINE
  •  
  • Gender:Male
  • Local time:12:33 PM

Posted 18 October 2016 - 11:33 AM

Hi MarcStephens :)

My name is Aura and I'll be assisting you with your malware issue. Since we'll be working together, you can call me Aura or Yoan, which is my real name, it's up to you! Now that we've broke the ice, I'll just ask you a few things during the time we'll be working together to clean your system and get it back to an operational state.
  • As you'll notice, the logs we are asking for here are quite lenghty, so it's normal for me to not reply exactly after you post them. This is because I need some time to analyse them and then act accordingly. However, I'll always reply within 24 hours, 48 hours at most if something unexpected happens;
  • As long as I'm assisting you on BleepingComputer, in this thread, I'll ask you to not seek assistance anywhere else for any issue related to the system we are working on. If you have an issue, question, etc. about your computer, please ask it in this thread and I'll assist you;
  • The same principle applies to any modifications you make to your system, I would like you to ask me before you do any manipulations that aren't in the instructions I posted. This is to ensure that we are operating in sync and I know exactly what's happening on your system;
  • If you aren't sure about an instruction I'm giving you, ask me about it. This is to ensure that the clean-up process goes without any issue. I'll answer you and even give you more precise instructions/explanations if you need. There's no shame in asking questions here, better be safe than sorry!;
  • If you don't reply to your thread within 3 days, I'll bump this thread to let you know that I'm waiting for you. If you don't reply after 5 days, it'll be closed. If you return after that period, you can send me a PM to get it unlocked and we'll continue where we left off;
  • Since malware can work quickly, we want to get rid of them as fast as we can, before they make unknown changes to the system. This being said, I would appreciate if you could reply to this thread within 24 hours of me posting. This way, we'll have a good clean-up rhythm and the chances of complications will be reduced;
  • I'm against any form of pirated, illegal and counterfeit software and material. So if you have any installed on your system, I'll ask you to uninstall them right now. You don't have to tell me if you indeed had some or not, I'll give you the benefit of the doubt. Plus, this would be against BleepingComputer's rules;
  • In the end, you are the one asking for assistance here. So if you wish to go a different way during the clean-up, like format and reinstall Windows, you are free to do so. I would appreciate you to let me know about it first, and if you need, I can also assist you in the process;
  • I would appreciate if you were to stay with me until the end, which means, until I declare your system clean. Just because your system isn't behaving weirdly anymore, or is running better than before, it doesn't mean that the infection is completely gone;
    This being said, I have a full time job so sometimes it'll take longer for me to reply to you. Don't worry, you'll be my first priority as soon as I get home and have time to look at your thread;
This being said, it's time to clean-up some malware, so let's get started, shall we? :)

Looks like you're indeed infected by Kovter. We'll clean it up using FRST and ESET Poweliks Cleaner.

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Fix mode
Follow the instructions below to execute a fix on your system using FRST, and provide the log in your next reply.
  • Right-click on your Desktop, select New and click on Text Document. Name it fixlist (make sure it's a .txt file) and press on Enter;
  • Open the file you just created and copy/paste the content below in it, then save it (Ctrl + S);
    CloseProcesses:
    CreateRestorePoint:
    
    Zip: C:\Users\jabbe_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ba0723f5.lnk;C:\Users\jabbe_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\d7eba04f.lnk;C:\Users\jabbe_000\AppData\Local\bcefaa26\89f9bed5.lnk;C:\Users\jabbe_000\AppData\Local\bcefaa26\9594f4ad.bat
    
    HKU\S-1-5-21-3409270631-3081192051-993886705-1001\...\Run: [**xdgt<*>] => "C:\Users\jabbe_000\AppData\Local\bcefaa26\89f9bed5.lnk" <===== ATTENTION (Value Name with invalid characters)
    Startup: C:\Users\jabbe_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ba0723f5.lnk [2016-10-17]
    Startup: C:\Users\jabbe_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\d7eba04f.lnk [2016-10-07]
    
    HKU\S-1-5-21-3409270631-3081192051-993886705-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.yahoo.com/?fr=befhp&type=iehp-3.19-1510
    HKU\S-1-5-21-3409270631-3081192051-993886705-1001\Software\Microsoft\Internet Explorer\Main,Old Start Page = hxxp://www.yahoo.com/
    SearchScopes: HKU\S-1-5-21-3409270631-3081192051-993886705-1001 -> DefaultScope {6F943D1A-B06A-45D6-AA49-E179115FFFDE} URL = hxxps://search.yahoo.com/search?ei=utf-8&fr=befds&p={searchTerms}&type=ieds-3.19-1510
    SearchScopes: HKU\S-1-5-21-3409270631-3081192051-993886705-1001 -> {6F943D1A-B06A-45D6-AA49-E179115FFFDE} URL = hxxps://search.yahoo.com/search?ei=utf-8&fr=befds&p={searchTerms}&type=ieds-3.19-1510
    BHO: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files\Norton 360\Engine\21.7.0.11\IPS\IPSBHO.DLL => No File
    
    CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=orcl_default
    CHR DefaultSearchKeyword: Default -> Yahoo
    CHR DefaultSuggestURL: Default -> hxxps://search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10
    CHR HKLM\...\Chrome\Extension: [aaffhmecfaelkngcbnfdkcckmillnoki] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
    
    S3 NAVENG; \??\C:\Program Files\Norton 360\NortonData\22.7.1.32\Definitions\SDSDefs\20161008.001\NAVENG.SYS [X]
    S3 NAVEX15; \??\C:\Program Files\Norton 360\NortonData\22.7.1.32\Definitions\SDSDefs\20161008.001\NAVEX15.SYS [X]
    
    CustomCLSID: HKU\S-1-5-21-3409270631-3081192051-993886705-1001_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\jabbe_000\AppData\Local\Google\Update\1.3.30.3\psuser.dll => No File
    CustomCLSID: HKU\S-1-5-21-3409270631-3081192051-993886705-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\jabbe_000\AppData\Local\Google\Update\1.3.29.5\psuser.dll => No File
    CustomCLSID: HKU\S-1-5-21-3409270631-3081192051-993886705-1001_Classes\CLSID\{D166BD15-03AF-413A-BEFD-0679FF410B49}\InprocServer32 -> C:\Users\jabbe_000\AppData\Local\Dropbox\Update\1.3.27.29\psuser.dll => No File
    CustomCLSID: HKU\S-1-5-21-3409270631-3081192051-993886705-1001_Classes\CLSID\{E7A37920-253C-4FF1-B169-298A7CE6CAA9}\localserver32 -> C:\Users\jabbe_000\AppData\Roaming\Dropbox\bin\Dropbox.exe => No File
    
    Task: {02C42F93-89DC-48BB-AC91-D037CCC052D1} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION
    Task: {03F63FDB-3A1E-4C8B-9B67-5BE977EB7A4C} - \GoogleUpdateTaskUserS-1-5-21-3409270631-3081192051-993886705-1001Core -> No File <==== ATTENTION
    Task: {07A0C94D-9C9C-44E9-BF01-B46629F1DF2C} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
    Task: {0CB3EFDA-C692-4263-9580-F85339F16A8A} - \Adobe Acrobat Update Task -> No File <==== ATTENTION
    Task: {134E1E90-301D-4724-BC29-B1AE30270C3A} - \Microsoft\Windows\UpdateOrchestrator\Policy Install -> No File <==== ATTENTION
    Task: {16D4418B-3DD8-4D3B-8A06-4BA4A8EB17C0} - \Microsoft\Windows\Customer Experience Improvement Program\BthSQM -> No File <==== ATTENTION
    Task: {1A751807-1D6D-46E5-9F18-F56B002C503D} - \Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor -> No File <==== ATTENTION
    Task: {1B898619-2F14-4A77-92A0-07B883AE83D0} - \Microsoft\Windows\WindowsUpdate\AUFirmwareInstall -> No File <==== ATTENTION
    Task: {1BA30CD2-D0D5-4420-AFA5-DB862AE95D51} - \Norton 360\Norton Error Processor -> No File <==== ATTENTION
    Task: {20137DB3-3FF7-47D0-8979-2B1F5EE5C7B9} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
    Task: {247BD142-0549-4E91-84B0-172C25563718} - \Microsoft\Windows\Workplace Join\Automatic-Workplace-Join -> No File <==== ATTENTION
    Task: {25D3B9E9-74CF-4969-86A6-E3E079A243FE} - \Microsoft\Windows\IME\SQM data sender -> No File <==== ATTENTION
    Task: {26BB7C1C-A376-45CB-BB5E-AABD582C9627} - \GoogleUpdateTaskMachineUA1d1f2d9eea6953f -> No File <==== ATTENTION
    Task: {28F319C1-2374-4EC1-A02D-10896E5BF647} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
    Task: {2BE65564-89D1-4396-A5CC-D7D9283FC4A1} - \Microsoft\Windows\SkyDrive\Routine Maintenance Task -> No File <==== ATTENTION
    Task: {2D0AF274-E27F-41C6-8A3F-F155E88152B7} - \DropboxUpdateTaskUserS-1-5-21-3409270631-3081192051-993886705-1001Core -> No File <==== ATTENTION
    Task: {36AAE632-071E-494E-B669-7B0CD0A7B83E} - \Microsoft\Windows\WindowsUpdate\AUScheduledInstall -> No File <==== ATTENTION
    Task: {40C56877-7817-49EE-8E83-9A4F90252B83} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
    Task: {4DEDDB1F-543A-43D4-9FE1-EDFB184C5959} - \Microsoft\Windows\WindowsUpdate\AUSessionConnect -> No File <==== ATTENTION
    Task: {5D700823-2DD6-4655-AA67-5182D0B92F3A} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
    Task: {5DCFF5E9-4E07-4080-AE8D-7A1DF56CEF80} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
    Task: {5DEAB72E-8400-467A-873F-5C6A7B9314C3} - \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot -> No File <==== ATTENTION
    Task: {6ACB16E9-4243-45D7-B717-041390318D19} - \Microsoft\Windows\Customer Experience Improvement Program\Uploader -> No File <==== ATTENTION
    Task: {713581C3-41FF-4528-BB9A-1BC1067F4EA7} - \Optimize Start Menu Cache Files-S-1-5-21-3409270631-3081192051-993886705-1001 -> No File <==== ATTENTION
    Task: {72E55520-011B-4948-9B2B-B4C02374A54C} - \WPD\SqmUpload_S-1-5-21-3409270631-3081192051-993886705-1001 -> No File <==== ATTENTION
    Task: {7B289C27-5045-4CF9-94C6-B302F436F5D6} - \GoogleUpdateTaskUserS-1-5-21-3409270631-3081192051-993886705-1001UA -> No File <==== ATTENTION
    Task: {7BB7C2C8-5E76-4886-9244-E42CB1B6A8CA} - \Microsoft\Windows\Setup\gwx\rundetector -> No File <==== ATTENTION
    Task: {7F159F2B-C3D2-4618-9080-F3AE798478E5} - \Apple\AppleSoftwareUpdate -> No File <==== ATTENTION
    Task: {857C1532-D919-44E0-8BD8-9FA485544588} - \Remediation\AntimalwareMigrationTask -> No File <==== ATTENTION
    Task: {88DF8337-9AFF-4AC1-B0A7-B2996C2CD0B3} - \Microsoft\Windows\RemovalTools\MRT_HB -> No File <==== ATTENTION
    Task: {9B278FB7-5DFA-41F4-9CE4-E477C4088C82} - \DropboxUpdateTaskUserS-1-5-21-3409270631-3081192051-993886705-1001UA -> No File <==== ATTENTION
    Task: {9B9BCA7A-6B33-477A-B27C-D4B299BA597A} - \GoogleUpdateTaskUserS-1-5-21-3409270631-3081192051-993886705-1001Core1d1f3524f375103 -> No File <==== ATTENTION
    Task: {9F047551-A09D-42A4-8552-554202CA7457} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
    Task: {B9C010D8-0528-4C51-B732-59D737B187C3} - \Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler -> No File <==== ATTENTION
    Task: {BAE64E0C-54D9-4239-9D42-9F6DAC095100} - \Microsoft\Windows\RAC\RacTask -> No File <==== ATTENTION
    Task: {BC402302-3985-4305-88D7-528FFFF56D21} - \{2A3AD23F-B9DE-41A3-B87B-A05A4712214F} -> No File <==== ATTENTION
    Task: {BF192DB8-05B5-4087-9965-803B1C494DD0} - \Norton WSC Integration -> No File <==== ATTENTION
    Task: {C532F84C-2E31-40A9-9FFC-6CB44752A023} - \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display -> No File <==== ATTENTION
    Task: {CBBB0A6D-A9BD-4BE6-A502-9E1B133C14D6} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
    Task: {D7B5E720-2487-4861-BB1D-E812DCE47E51} - \User_Feed_Synchronization-{A347D0AE-8B26-4F00-BDB3-F0DEEAFC3A7C} -> No File <==== ATTENTION
    Task: {E035FAC8-09CF-4F07-BD94-AC08FFDE13B9} - \GoogleUpdateTaskMachineUA -> No File <==== ATTENTION
    Task: {E4C8774A-2818-45A4-8A6D-11DDF6348886} - \Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task -> No File <==== ATTENTION
    Task: {E5136838-F250-4161-B727-AF332EF71A0E} - \GoogleUpdateTaskMachineCore -> No File <==== ATTENTION
    Task: {E70C697E-7BB7-44C8-819E-12C866927FC6} - \Microsoft\Windows\WindowsUpdate\Scheduled Start With Network -> No File <==== ATTENTION
    Task: {EA399839-9F00-45D5-AE32-B31B15968456} - \GoogleUpdateTaskUserS-1-5-21-3409270631-3081192051-993886705-1001UA1d1f35250a59e84 -> No File <==== ATTENTION
    Task: {F040CC13-020C-4A76-A766-BA460C0772C6} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
    Task: {F58C52E7-E5B0-462E-A738-4833C9306043} - \Norton 360\Norton Error Analyzer -> No File <==== ATTENTION
    Task: {F5EE5ABD-D0A5-401A-B9F5-3CBDE788A0E9} - \GoogleUpdateTaskMachineCore1d1f2d9ee878d56 -> No File <==== ATTENTION
    Task: {F6C1EF3F-E1DA-4F12-8537-72BE68805758} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
    Task: {FABAA95E-55EF-4C45-A158-CCFFC99AF3AB} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
    Task: {FBDF9FC2-569C-4AA0-9FD5-66C7F00DCAF0} - \Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval -> No File <==== ATTENTION
    Task: {FD6F5738-ECAC-4FF6-B346-EB2F4C967BDC} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
    Task: {FE500C1A-AF83-49E1-820A-259DDC2C6C68} - \Microsoft\Windows\Shell\FamilySafetyUpload -> No File <==== ATTENTION
    Task: {FED6B60D-D06B-44F4-B80B-9B423196A3A7} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
    
    HKU\S-1-5-21-3409270631-3081192051-993886705-1001\Software\Classes\6c17867a: "C:\WINDOWS\system32\mshta.exe" "javascript:kCzE7f="K6PS";Xa14=new ActiveXObject("WScript.Shell");AeB29DI="Wup";H9m5oy=Xa14.RegRead("HKCU\\software\\pdza\\wdboiyr");Hg8To="RTiOch";eval(H9m5oy);M3KfJyAk="V";" <===== ATTENTION
    
    C:\Users\jabbe_000\AppData\Local\bcefaa26
    C:\Users\jabbe_000\AppData\Roaming\bec53dd7
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00032464.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00030710.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00029494.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00028853.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00023815.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00021685.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00021327.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00020775.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00020515.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00020436.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00017019.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00016857.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00015569.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00015240.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00014704.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00013941.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00010103.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00009886.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00009775.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00009560.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00009346.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00008500.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00008045.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00007753.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00007025.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00006787.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00006771.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00004628.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00004101.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00001415.tmp
    2016-10-14 22:18 - 2016-10-14 22:18 - 01340008 ____T C:\WINDOWS\00000060.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00032504.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00031547.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00031252.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00030311.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00030188.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00030083.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00029796.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00028149.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00027759.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00025672.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00025608.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00024470.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00024444.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00023953.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00022150.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00020482.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00019685.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00019116.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00018665.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00017864.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00017824.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00016534.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00015584.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00014631.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00014202.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00014095.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00009843.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00009454.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00009417.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00009061.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00007614.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00007507.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00006869.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00006523.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00006269.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00003639.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00003243.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00002758.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00001533.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00001444.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00001405.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00001344.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00000824.tmp
    2016-10-14 22:17 - 2016-10-14 22:17 - 01340008 ____T C:\WINDOWS\00000359.tmp
    
    EmptyTemp:
    
  • Right-click on the FRST executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
  • Click on the Fix button;
    NYA5Cbr.png
  • On completion, a message will come up saying that the fix has been completed and it'll open a log in Notepad;
  • Copy and paste its content in your next reply;
Follow the Steps 6 to 10 in the guide below to scan your computer with ESET Poweliks Cleaner, and copy/paste the content of the output log in your next reply after.

http://www.bleepingcomputer.com/virus-removal/remove-poweliks-trojan

After running the FRST fix, a file called Upload.zip will be created on your desktop. Upload it to the link below please.

http://www.bleepingcomputer.com/submit-malware.php?channel=194

After running FRST, ESET and restarting, do you still get warnings about Kovter?

Your next reply(ies) should include:
  • Copy/pasted content of FRST's fixlog.txt;
  • Copy/pasted content of the ESET Poweliks Cleaner log;
  • Confirmation that you uploaded the Upload.zip file to the link provided above;
  • Answer to my question about Kovter-related alerts on your system;

Edited by Aura, 18 October 2016 - 11:34 AM.

unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#3 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,680 posts
  • ONLINE
  •  
  • Gender:Male
  • Local time:12:33 PM

Posted 21 October 2016 - 01:06 PM

Hi MarcStephens,

Are you still with me? Can you follow the instructions in my previous post?

unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#4 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,680 posts
  • ONLINE
  •  
  • Gender:Male
  • Local time:12:33 PM

Posted 24 October 2016 - 07:19 AM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.

unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users