Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Adware - ps4ux.com - cannot remove


  • This topic is locked This topic is locked
17 replies to this topic

#1 jecwells

jecwells

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:19 AM

Posted 26 October 2016 - 04:25 AM

My computer has become infected with seemingly various kinds of adware which, despite searching and trying numerous different methods, I cannot remove.

 

The problems manifest themselves when browsing on chrome (strangely both on laptop and phone). Most of the time when I open a new webpage, a separate popup tries to open up to display some mindless advert. When it first started happening, the initial URL displayed was

 

'onclickads.net' before opening the actual advert. This has now changed more frequently to 'ps4ux.com'

 

Also, on various webpages, I get specific words on that page appearing as coloured links in capital letters. If I hover over these links it appears to be controlled by something called 'Ads by Not Set' or 'Advertise'.

 

I have tried the following to rectify this:

- Run Malwarebytes

- Run AdwareCleaner

- Run Hitman Pro

- Run Zemana

- Run Webroot Anti-virus

- Checked and unistalled any unwanted programs

- Removed all extensions within Chrome

- Reset settings within Chrome

- Deleted user within Chrome

 

What else can I do!? Any advice would be greatly appreciated!

 

Thanks

 

James

 



BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 38,594 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:11:19 PM

Posted 26 October 2016 - 10:39 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Download the version of this tool for your operating system.
Farbar Recovery Scan Tool (64 bit)
Farbar Recovery Scan Tool (32 bit)
and save it to a folder on your computer's Desktop.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

How to attach a file to your reply:
In the Reply section in the bottom of the topic Click the "more reply Options" button.
attachlogs.png

Attach the file.
Select the "Choose a File" navigate to the location of the File.
Click the file you wish to Attach.

Click the Add reply button.
===

Please post the logs.

Wait for further instructions.

#3 jecwells

jecwells
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:19 AM

Posted 26 October 2016 - 11:01 AM

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-10-2016
Ran by James (USG) (26-10-2016 16:54:09)
Running from C:\Users\james.WELLSIE\Desktop\Farbar
Windows 10 Home Version 1607 (X64) (2016-09-27 09:27:53)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3658493019-1111599900-2463904087-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3658493019-1111599900-2463904087-503 - Limited - Disabled)
Guest (S-1-5-21-3658493019-1111599900-2463904087-501 - Limited - Disabled)
James (Home) (S-1-5-21-3658493019-1111599900-2463904087-1003 - Administrator - Enabled) => C:\Users\James (Home)
James (Propia) (S-1-5-21-3658493019-1111599900-2463904087-1004 - Administrator - Enabled) => C:\Users\James (Propia)
James (USG) (S-1-5-21-3658493019-1111599900-2463904087-1006 - Administrator - Enabled) => C:\Users\james.WELLSIE
Priscilla (S-1-5-21-3658493019-1111599900-2463904087-1005 - Administrator - Enabled) => C:\Users\Priscilla
UpdatusUser (S-1-5-21-3658493019-1111599900-2463904087-1002 - Limited - Enabled) => C:\Users\UpdatusUser
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Webroot SecureAnywhere (Enabled - Up to date) {4646A877-74EB-CD3B-8FDB-210DB94FA61A}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Webroot SecureAnywhere (Enabled - Up to date) {FD274993-52D1-C2B5-B56B-1A7FC2C8ECA7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
64 Bit HP CIO Components Installer (Version: 15.2.1 - Hewlett-Packard) Hidden
Adobe Acrobat X Pro - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7760-000000000005}) (Version: 10.1.2 - Adobe Systems)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 14.0.0.110 - Adobe Systems Incorporated)
Adobe Flash Player 23 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 23.0.0.185 - Adobe Systems Incorporated)
Adobe Reader X (10.1.10) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.10 - Adobe Systems Incorporated)
AirParrot 2 (HKLM\...\{D35A3EFE-C605-4496-9D6F-26E033E2F9AE}) (Version: 2.6.2.0 - Squirrels)
Allshare Play Link (HKLM-x32\...\{91786428-D4AA-476D-8AF9-A63FFAC2901F}) (Version: 1.0.0 - Samsung)
ARGUS Developer (x32 Version: 7.50.1.145 - ARGUS Software) Hidden
ARGUS Developer 7 (HKLM-x32\...\{11cfa395-6270-4e83-90e0-684c83ad9505}) (Version: 7.50.1.145 - ARGUS Software)
BBC iPlayer Downloads (HKLM-x32\...\{D8753E3F-B86E-4BA6-A44A-6D92BFB38519}) (Version: 1.11.0 - BBC)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dropbox (HKLM-x32\...\Dropbox) (Version: 12.4.22 - Dropbox, Inc.)
Dropbox Update Helper (x32 Version: 1.3.27.37 - Dropbox, Inc.) Hidden
eM Client (HKLM-x32\...\{7B35918E-43E4-45AF-8F1B-C15D86CA919D}) (Version: 6.0.24928.0 - eM Client Inc.)
Epson Customer Participation (HKLM\...\{814FA673-A085-403C-9545-747FC1495069}) (Version: 1.4.0.0 - SEIKO EPSON CORPORATION)
Epson Event Manager (HKLM-x32\...\{44F72193-F59C-4303-BAE8-E3E4BC1C122C}) (Version: 3.01.0003 - Seiko Epson Corporation)
Epson FAX Utility (HKLM-x32\...\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 1.46.00 - SEIKO EPSON CORPORATION)
EpsonNet Print (HKLM-x32\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.5.00 - SEIKO EPSON CORPORATION)
Evernote v. 6.1.2 (HKLM-x32\...\{A46ABD1E-2837-11E6-9E7C-005056951CAD}) (Version: 6.1.2.2292 - Evernote Corp.)
Free Audio Converter version 5.0.54.1215 (HKLM-x32\...\Free Audio Converter_is1) (Version: 5.0.54.1215 - DVDVideoSoft Ltd.)
Free DVD Video Burner version 3.2.13.1215 (HKLM-x32\...\Free DVD Video Burner_is1) (Version: 3.2.13.1215 - DVDVideoSoft Ltd.)
Free Video to DVD Converter version 5.0.54.1215 (HKLM-x32\...\Free Video to DVD Converter_is1) (Version: 5.0.54.1215 - DVDVideoSoft Ltd.)
Free Video to MP3 Converter version 5.0.54.1215 (HKLM-x32\...\Free Video to MP3 Converter_is1) (Version: 5.0.54.1215 - DVDVideoSoft Ltd.)
Free YouTube Download version 3.2.41.623 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.41.623 - DVDVideoSoft Ltd.)
Free YouTube to MP3 Converter version 3.12.49.1022 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.49.1022 - DVDVideoSoft Ltd.)
Galerie de photos (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 54.0.2840.71 - Google Inc.)
Google Drive (HKLM-x32\...\{459CE109-4E46-4340-92BC-054642BC3BC2}) (Version: 1.31.2873.2758 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
Help Desk (HKLM\...\{AEC9D273-E162-4614-83F1-722B8C74B185}) (Version: 1.0.96 - Samsung Electronics CO., LTD.)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4276 - Intel Corporation)
Intel® PROSet/Wireless Software for Bluetooth® Technology (HKLM\...\{302600C1-6BDF-4FD1-1309-148929CC1385}) (Version: 3.1.1309.0390 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation)
Intel® SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel® WiDi (HKLM\...\{6097158B-0184-4140-BEC3-7885794D2571}) (Version: 3.5.40.0 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{c9967fbd-e3c3-4ed0-992a-5b33260f2944}) (Version: 16.1.5 - Intel Corporation)
MediaMonkey 4.1 (HKLM-x32\...\MediaMonkey_is1) (Version: 4.1 - Ventis Media Inc.)
Microsoft Office 365 Business - en-us (HKLM\...\O365BusinessRetail - en-us) (Version: 15.0.4867.1003 - Microsoft Corporation)
Microsoft Office 365 Small Business Premium - en-us (HKLM\...\O365SmallBusPremRetail - en-us) (Version: 15.0.4867.1003 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\...\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 47.0.1 (x86 en-GB) (HKLM-x32\...\Mozilla Firefox 47.0.1 (x86 en-GB)) (Version: 47.0.1 - Mozilla)
NVIDIA Graphics Driver 305.46 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 305.46 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.12.0613 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0613 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4867.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4867.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4867.1003 - Microsoft Corporation) Hidden
Online Support(S Service) (HKLM-x32\...\{C8996970-A56E-4659-B01B-CCB7097C4E59}) (Version: 1.1 - Samsung Electronics Co., Ltd.)
Raccolta foto (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.1.505.2015 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7543 - Realtek Semiconductor Corp.)
Recovery (HKLM-x32\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 6.1.0.3 - Samsung Electronics CO., LTD.)
Revo Uninstaller Pro 3.1.7 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.7 - VS Revo Group, Ltd.)
S Agent (Version: 1.1.58 - Samsung Electronics Co., Ltd.) Hidden
Samsung Settings (HKLM-x32\...\{3BB58176-B3A7-47FD-9F18-C3576431D193}) (Version: 2.2.0 - Samsung Electronics CO., LTD.)
Samsung Update (HKLM-x32\...\{0FFDCE96-00EF-4037-A241-634060A5517B}) (Version: 2.2.40 - Samsung Electronics Co., Ltd.)
SketchUp 2016 (HKLM\...\{D87EE6DC-32BA-4219-AC75-0A6FD54ED058}) (Version: 16.0.19912 - Trimble Navigation Limited)
Skype™ 7.26 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.26.101 - Skype Technologies S.A.)
Software Updater (HKLM-x32\...\{8DBC5A0A-31C4-46C7-B252-6B593EA11A87}) (Version: 4.3.7 - SEIKO EPSON CORPORATION)
Spotify (HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Spotify) (Version: 0.9.11.27.g2b1a638c - Spotify AB)
Spotify (HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Spotify) (Version: 1.0.33.106.g60b5d1f0 - Spotify AB)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.2.1.8 - Synaptics Incorporated)
Synology Assistant (remove only) (HKLM-x32\...\Synology Assistant) (Version:  - )
Synology Cloud Station Drive (remove only) (HKLM\...\Synology Cloud Station Drive) (Version: 4.1.4224 - Synology, Inc.)
User Guide (HKLM-x32\...\{039EA659-E421-45C6-8913-BED5D69B5536}) (Version: 1.1.00 - Samsung Electronics CO., LTD.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Webroot SecureAnywhere (HKLM-x32\...\WRUNINST) (Version: 9.0.13.50 - Webroot)
Windows Driver Package - Samsung Electronics Co. Ltd. (RadioHIDMini) HIDClass  (08/23/2013 6.2.8400.4218) (HKLM\...\26BFE384C802803107F583AE1A739E4FEB56134B) (Version: 08/23/2013 6.2.8400.4218 - Samsung Electronics Co. Ltd.)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3658493019-1111599900-2463904087-1006_Classes\CLSID\{2C4A5D61-009C-4561-9A33-6AFD542FD237}\InprocServer32 -> C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\icon-overlay\16\x64\ContextMenu.dll ()
CustomCLSID: HKU\S-1-5-21-3658493019-1111599900-2463904087-1006_Classes\CLSID\{472CE1AD-5D53-4BCF-A1FB-3982A5F55138}\InprocServer32 -> C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\icon-overlay\16\x64\iconOverlay.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-3658493019-1111599900-2463904087-1006_Classes\CLSID\{48AB5ADA-36B1-4137-99C9-2BD97F8788AB}\InprocServer32 -> C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\icon-overlay\16\x64\iconOverlay.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-3658493019-1111599900-2463904087-1006_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\james.WELLSIE\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3658493019-1111599900-2463904087-1006_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)
CustomCLSID: HKU\S-1-5-21-3658493019-1111599900-2463904087-1006_Classes\CLSID\{A433C3E0-8B24-40EB-93C3-4B10D9959F58}\InprocServer32 -> C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\icon-overlay\16\x64\iconOverlay.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-3658493019-1111599900-2463904087-1006_Classes\CLSID\{AEB16659-2125-4ADA-A4AB-45EE21E86469}\InprocServer32 -> C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\icon-overlay\16\x64\iconOverlay.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-3658493019-1111599900-2463904087-1006_Classes\CLSID\{C701AD67-3DF0-47C9-89CB-DFA6207BE229}\InprocServer32 -> C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\icon-overlay\16\x64\iconOverlay.dll (TODO: <Company name>)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {028A0DD4-7718-4B9A-ADE2-BCE55ECAE8A9} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-10-12] (Microsoft Corporation)
Task: {08D58F16-1CA9-4AB5-9BF2-A3B1BF4EE441} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {0AA2455D-20FC-4157-AE0D-1A4BDD24517E} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-06-18] (Realtek Semiconductor)
Task: {0E917DD8-586F-4283-BB70-DD320B8F4FFC} - System32\Tasks\{6B23812D-9410-4E6B-82C3-62D219429324} => Chrome.exe hxxp://ui.skype.com/ui/0/7.6.64.105/en/go/help.faq.installer?LastError=1618
Task: {15D72819-F5AA-4F1F-B906-C0C218544B47} - System32\Tasks\LaunchSettings => C:\Program Files (x86)\Samsung\Settings\Settings.exe [2015-06-24] ()
Task: {174D5BC1-25F7-4D6F-99BA-7722580B8F09} - System32\Tasks\Settings => C:\Program Files (x86)\Samsung\Settings\sSettings.exe
Task: {208B45ED-8293-481B-958A-A6BF02DFD76F} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2016-02-01] (Synaptics Incorporated)
Task: {27E9873C-DE6E-44CF-87F1-68C24205F0E9} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-10-04] (Microsoft Corporation)
Task: {2C217A69-67FF-479D-8252-7E918D2FC8E4} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\WINDOWS\System32\AutoWorkplace.exe
Task: {36D6F89A-B6A7-42F9-845A-6C24E753B877} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {4EF33CD9-3815-4805-BCD2-662444AA16B3} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {53C85EE8-17FC-4AF3-B481-6A0E688EF54D} - System32\Tasks\SettingsHibernateMonitor => C:\Program Files (x86)\Samsung\Settings\SettingsHibernateMonitor.exe [2015-06-24] (Samsung Electronics CO., LTD.)
Task: {5444BC8C-7B29-4CA4-9184-7CF54777EEE4} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3658493019-1111599900-2463904087-1004Core => C:\Users\James (Propia)\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-17] (Dropbox, Inc.)
Task: {5D5D4576-7E34-4726-B424-7FDF5D1E27A0} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\Priscilla\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe [2016-09-12] (Microsoft Corporation)
Task: {6D4BD490-7057-4931-9167-06D3E7E0F5EE} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2016-07-26] (Microsoft Corporation)
Task: {6D889F06-BBEA-4BC1-B1B3-F17FAF80A94E} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {7C956990-2F68-415A-AD35-10AF624816D2} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-10-17] (Dropbox, Inc.)
Task: {7CEAE3F7-E3ED-4EB0-8A94-034297B60AE0} - System32\Tasks\SettingsEventHandlerMonitor => C:\Program Files (x86)\Samsung\Settings\CmdServer\RSSettingEventHandler.exe [2015-06-24] (Samsung Electronics CO., LTD.)
Task: {81946D50-4BCE-449E-A8C7-C6B63704D14F} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {85D83D1F-B5CD-461B-B1BA-674FA4F95511} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {8BDEACFB-71D5-4B37-AE44-EE73DA54889C} - System32\Tasks\advRecovery => C:\Program Files\Samsung\Recovery\WCScheduler.exe [2016-07-05] (SEC)
Task: {A34818B6-40E9-4A46-B4C1-3781F19BFDF9} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {A6CE73F9-1DE1-4F4C-8C61-B3C1515BBDE9} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-10-15] (Adobe Systems Incorporated)
Task: {ACD48289-DE50-487C-8893-DFC82D9C97CA} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [2016-02-24] (Samsung Electronics Co., Ltd.)
Task: {B6B6B7E3-3B67-41C7-A27D-0FC0A4884503} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-10-17] (Dropbox, Inc.)
Task: {B9B9A508-8109-41CD-8979-8DCE3980CE6B} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-10-04] (Microsoft Corporation)
Task: {C3016E4B-2D0E-4858-AA4C-79CF36433240} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {CD8DB9A0-BB87-4823-9ADA-5980165BBC2F} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {D9D567F7-9903-4DA4-BD71-5FC3781C38CA} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {DA83F46A-C5B2-47E8-BF87-E214F60723F0} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {EAC219B3-7A7B-4C58-A10F-BB84637A7F12} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3658493019-1111599900-2463904087-1004UA => C:\Users\James (Propia)\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-17] (Dropbox, Inc.)
Task: {EF62FE45-970E-44B0-93D9-CB775B35C328} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3658493019-1111599900-2463904087-1004Core.job => C:\Users\James (Propia)\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3658493019-1111599900-2463904087-1004UA.job => C:\Users\James (Propia)\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2016-07-16 12:42 - 2016-07-16 12:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-10-03 09:08 - 2016-09-15 18:25 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-07-04 03:16 - 2016-07-04 03:16 - 00287256 _____ () C:\Program Files (x86)\Synology\CloudStation\bin\vss-service-x64.exe
2015-11-13 09:53 - 2016-05-24 09:51 - 00116416 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2015-05-11 08:12 - 2015-05-11 08:12 - 00248736 _____ () C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe
2016-10-03 09:08 - 2016-09-15 18:25 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll
2016-07-16 12:42 - 2016-07-16 12:42 - 00130048 _____ () C:\WINDOWS\SYSTEM32\CHARTV.dll
2016-09-27 11:19 - 2016-09-27 11:19 - 00959168 _____ () C:\Users\james.WELLSIE\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2016-10-12 13:28 - 2016-10-05 10:35 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2016-10-20 07:28 - 2016-10-20 07:29 - 00072192 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.8.197.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2016-10-20 07:28 - 2016-10-20 07:29 - 00178176 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.8.197.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2016-10-20 07:28 - 2016-10-20 07:29 - 35253760 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.8.197.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2015-06-23 18:08 - 2015-10-20 09:32 - 00692736 _____ () C:\WINDOWS\system32\spool\DRIVERS\x64\3\KOAYTJ_O.DLL
2016-10-12 13:29 - 2016-10-05 10:21 - 09760256 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-10-12 13:29 - 2016-10-05 10:13 - 01401344 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-10-12 13:29 - 2016-10-05 10:13 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2016-10-12 13:29 - 2016-10-05 10:13 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2016-10-12 13:29 - 2016-10-05 10:13 - 02424832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-10-12 13:29 - 2016-10-05 10:14 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-06-19 14:55 - 2015-06-19 14:55 - 00211064 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\WinCRT.dll
2016-06-01 14:39 - 2016-06-01 14:39 - 00439480 _____ () C:\Program Files (x86)\Evernote\Evernote\libxml2.dll
2016-06-01 14:39 - 2016-06-01 14:39 - 00321208 _____ () C:\Program Files (x86)\Evernote\Evernote\libtidy.dll
2016-10-14 09:19 - 2016-09-22 02:44 - 00035792 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd
2016-10-14 09:19 - 2016-09-22 02:44 - 00145864 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd
2016-10-14 09:19 - 2016-09-22 02:45 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd
2016-10-14 09:19 - 2016-09-22 02:44 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll
2016-10-14 09:19 - 2016-09-22 02:44 - 00100296 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd
2016-10-14 09:19 - 2016-09-22 02:44 - 00018888 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00019760 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd
2016-10-14 09:19 - 2016-09-22 02:44 - 00694224 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00020816 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd
2016-10-14 09:19 - 2016-09-22 02:45 - 00123856 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 01682760 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00020808 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd
2016-10-14 09:19 - 2016-09-22 02:46 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00021312 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.crt.compiled._winffi_crt.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00052024 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00038696 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd
2016-10-14 09:19 - 2016-09-22 02:44 - 00392144 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll
2016-10-14 09:19 - 2016-09-22 02:46 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd
2016-10-14 09:19 - 2016-09-22 02:46 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd
2016-10-14 09:19 - 2016-09-22 02:46 - 00116176 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00381752 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd
2016-10-14 09:19 - 2016-09-22 02:46 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00025424 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.pyd
2016-10-14 09:19 - 2016-09-22 02:46 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd
2016-10-14 09:19 - 2016-09-22 02:46 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd
2016-10-14 09:19 - 2016-09-22 02:46 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd
2016-10-14 09:19 - 2016-09-22 02:46 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd
2016-10-14 09:19 - 2016-09-22 02:46 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd
2016-10-14 09:19 - 2016-09-22 02:46 - 00057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd
2016-10-14 09:19 - 2016-09-22 02:46 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00246592 _____ () C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handler.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd
2016-10-14 09:19 - 2016-09-22 02:45 - 00241104 _____ () C:\Program Files (x86)\Dropbox\Client\_jpegtran.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00020280 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd
2016-10-14 09:19 - 2016-09-22 02:46 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00023376 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi._winffi_iphlpapi.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00019776 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror._winffi_winerror.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet._winffi_wininet.pyd
2016-10-14 09:19 - 2016-09-22 02:46 - 00350152 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00022352 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00024392 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd
2016-10-14 09:19 - 2016-09-22 02:42 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2016-10-14 09:19 - 2016-10-10 19:35 - 00031568 _____ () C:\Program Files (x86)\Dropbox\Client\enterprise_data.compiled._enterprise_data.pyd
2016-10-14 09:19 - 2016-10-10 19:30 - 00293392 _____ () C:\Program Files (x86)\Dropbox\Client\EnterpriseDataAdapter.dll
2016-10-14 09:19 - 2016-10-10 19:35 - 00084280 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
2016-10-14 09:19 - 2016-10-10 19:35 - 01826096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd
2016-10-14 09:19 - 2016-09-22 02:45 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00531248 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 03928880 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 01972528 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00133424 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00224056 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00207672 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00020288 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32._winffi_user32.pyd
2016-10-14 09:19 - 2016-09-22 02:49 - 00017864 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.dll
2016-10-14 09:19 - 2016-09-22 02:49 - 01631184 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
2016-10-14 09:19 - 2016-09-22 02:46 - 00060880 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00037192 _____ () C:\Program Files (x86)\Dropbox\Client\windisplaytoast.compiled._DisplayToast.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00024904 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00546096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00357680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00042808 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd
2016-10-14 09:19 - 2016-10-10 19:35 - 00168760 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd
2016-10-14 09:19 - 2016-09-22 02:51 - 00697304 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Controls\qtquickcontrolsplugin.dll
2016-08-02 14:31 - 2016-08-02 14:31 - 00123918 _____ () C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\bin\libgcc_s_dw2-1.dll
2016-08-02 14:31 - 2016-08-02 14:31 - 01026062 _____ () C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\bin\libstdc++-6.dll
2016-08-02 14:31 - 2016-08-02 14:31 - 00524460 _____ () C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\bin\libcurl-4.dll
2016-08-02 14:31 - 2016-08-02 14:31 - 03036430 _____ () C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\bin\libsqlite3-0.dll
2016-08-02 14:31 - 2016-08-02 14:31 - 01798570 _____ () C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\bin\icuuc53.dll
2016-08-02 14:31 - 2016-08-02 14:31 - 00115214 _____ () C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\bin\zlib1.dll
2016-08-02 14:31 - 2016-08-02 14:31 - 03095505 _____ () C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\bin\icuin53.dll
2016-08-02 14:31 - 2016-08-02 14:31 - 21565192 _____ () C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\bin\icudt53.dll
2016-08-02 14:31 - 2016-08-02 14:31 - 00712704 _____ () C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\bin\platforms\qwindows.dll
2016-08-02 14:31 - 2016-08-02 14:31 - 00031744 _____ () C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\bin\imageformats\qgif.dll
2016-08-02 14:31 - 2016-08-02 14:31 - 00046080 _____ () C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\bin\imageformats\qicns.dll
2016-08-02 14:31 - 2016-08-02 14:31 - 00032768 _____ () C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\bin\imageformats\qico.dll
2016-08-02 14:31 - 2016-08-02 14:31 - 00516608 _____ () C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\bin\imageformats\qjp2.dll
2016-08-02 14:31 - 2016-08-02 14:31 - 00243200 _____ () C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\bin\imageformats\qjpeg.dll
2016-08-02 14:31 - 2016-08-02 14:31 - 00431616 _____ () C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\bin\imageformats\qtiff.dll
2016-10-26 08:59 - 2016-10-26 08:59 - 00098816 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\win32api.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00110080 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\pywintypes27.dll
2016-10-26 08:59 - 2016-10-26 08:59 - 00364544 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\pythoncom27.dll
2016-10-26 08:59 - 2016-10-26 08:59 - 00320512 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\win32com.shell.shell.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00776704 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\_hashlib.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 01176576 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\wx._core_.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00806400 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\wx._gdi_.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00816128 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\wx._windows_.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 01067008 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\wx._controls_.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00733184 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\wx._misc_.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00682496 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\pysqlite2._sqlite.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00088064 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\_ctypes.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00119808 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\win32file.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00108544 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\win32security.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00007168 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\hashobjs_ext.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00017920 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\thumbnails_ext.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00088064 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\usb_ext.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00012800 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\common.time34.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00018432 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\win32event.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00167936 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\win32gui.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00046080 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\_socket.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 01208320 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\_ssl.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00128512 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\_elementtree.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00127488 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\pyexpat.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00038912 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\win32inet.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00036864 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\_psutil_windows.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00525208 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\windows._lib_cacheinvalidation.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00011264 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\win32crypt.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00077312 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\wx._html2.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00027136 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\_multiprocessing.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00020480 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\_yappi.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00035840 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\win32process.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00686080 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\unicodedata.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00078848 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\wx._animate.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00123392 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\wx._wizard.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00024064 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\win32pipe.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00010240 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\select.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00025600 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\win32pdh.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00017408 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\win32profile.pyd
2016-10-26 08:59 - 2016-10-26 08:59 - 00022528 ____R () C:\Users\JAMES~1.WEL\AppData\Local\Temp\_MEI52402\win32ts.pyd
2015-11-13 09:54 - 2016-05-24 16:21 - 08909504 _____ () C:\Program Files\Microsoft Office 15\root\Office15\1033\GrooveIntlResource.dll
2016-09-27 11:19 - 2016-09-27 11:19 - 00679624 _____ () C:\Users\james.WELLSIE\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\ClientTelemetry.dll
2016-10-25 08:03 - 2016-10-20 09:47 - 01819240 _____ () C:\Program Files (x86)\Google\Chrome\Application\54.0.2840.71\libglesv2.dll
2016-10-25 08:03 - 2016-10-20 09:47 - 00093288 _____ () C:\Program Files (x86)\Google\Chrome\Application\54.0.2840.71\libegl.dll
2014-07-09 09:19 - 2013-09-16 12:20 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\ACE.dll

==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm [0]
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm [0]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\microsoftonline.com -> hxxps://login.microsoftonline.com
IE trusted site: HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\microsoftonline.com -> hxxp://login.microsoftonline.com
IE trusted site: HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\sharepoint.com -> hxxp://urbanstudent.sharepoint.com
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 14:25 - 2014-08-01 18:50 - 00001805 ___RA C:\WINDOWS\system32\Drivers\etc\hosts
 
127.0.0.1 3dns.adobe.com 3dns-1.adobe.com 3dns-2.adobe.com 3dns-3.adobe.com 3dns-4.adobe.com activate.adobe.com activate-sea.adobe.com activate-sjc0.adobe.com activate.wip.adobe.com
127.0.0.1 activate.wip1.adobe.com activate.wip2.adobe.com activate.wip3.adobe.com activate.wip4.adobe.com adobe-dns.adobe.com adobe-dns-1.adobe.com adobe-dns-2.adobe.com adobe-dns-3.adobe.com adobe-dns-4.adobe.com
127.0.0.1 adobeereg.com practivate.adobe practivate.adobe.com practivate.adobe.newoa practivate.adobe.ntp practivate.adobe.ipp ereg.adobe.com ereg.wip.adobe.com ereg.wip1.adobe.com
127.0.0.1 ereg.wip2.adobe.com ereg.wip3.adobe.com ereg.wip4.adobe.com hl2rcv.adobe.com wip.adobe.com wip1.adobe.com wip2.adobe.com wip3.adobe.com wip4.adobe.com
127.0.0.1 www.adobeereg.com wwis-dubc1-vip60.adobe.com www.wip.adobe.com www.wip1.adobe.com
127.0.0.1 www.wip2.adobe.com www.wip3.adobe.com www.wip4.adobe.com wwis-dubc1-vip60.adobe.com crl.verisign.net CRL.VERISIGN.NET ood.opsource.net
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\Control Panel\Desktop\\Wallpaper -> 
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\windows\img0.jpg
DNS Servers: 8.8.8.8 - 135.196.0.14
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\Services: Apple Mobile Device => 2
MSCONFIG\Services: Bluetooth Device Monitor => 2
MSCONFIG\Services: Bluetooth OBEX Service => 2
MSCONFIG\Services: Bonjour Service => 2
MSCONFIG\Services: EaseUS Agent => 2
MSCONFIG\Services: Easy Launcher => 2
MSCONFIG\Services: iPod Service => 3
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\Services: ss_conn_service => 2
MSCONFIG\Services: TeamViewer9 => 2
MSCONFIG\Services: vToolbarUpdater18.2.0 => 2
HKLM\...\StartupApproved\Run: => "HotKeysCmds"
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "Adobe Reader Speed Launcher"
HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKLM\...\StartupApproved\Run32: => "GrooveMonitor"
HKLM\...\StartupApproved\Run32: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "KiesTrayAgent"
HKLM\...\StartupApproved\Run32: => "EaseUS TB Tray Agent"
HKLM\...\StartupApproved\Run32: => "FUFAXSTM"
HKLM\...\StartupApproved\Run32: => "FUFAXRCV"
HKLM\...\StartupApproved\Run32: => "EEventManager"
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\StartupApproved\StartupFolder: => "EvernoteClipper.lnk"
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\StartupApproved\StartupFolder: => "OneDrive for Business.lnk"
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\StartupApproved\StartupFolder: => "Send to OneNote.lnk"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [UDP Query User{DB6A803C-9047-4AFD-ADC5-5E0342DDAC73}C:\users\james.wellsie\appdata\local\cloudstation\cloudstation.app\bin\cloud-drive-ui.exe] => (Allow) C:\users\james.wellsie\appdata\local\cloudstation\cloudstation.app\bin\cloud-drive-ui.exe
FirewallRules: [TCP Query User{39B999A5-9F0C-455A-AE45-CD5D63B9B352}C:\users\james.wellsie\appdata\local\cloudstation\cloudstation.app\bin\cloud-drive-ui.exe] => (Allow) C:\users\james.wellsie\appdata\local\cloudstation\cloudstation.app\bin\cloud-drive-ui.exe
FirewallRules: [UDP Query User{93320375-4278-4328-91AC-4B647452ACDC}C:\users\james.wellsie\appdata\local\cloudstation\cloudstation.app\bin\cloud-drive-connect.exe] => (Allow) C:\users\james.wellsie\appdata\local\cloudstation\cloudstation.app\bin\cloud-drive-connect.exe
FirewallRules: [TCP Query User{F2ED56CC-661C-45C2-8049-B1A20EE6481D}C:\users\james.wellsie\appdata\local\cloudstation\cloudstation.app\bin\cloud-drive-connect.exe] => (Allow) C:\users\james.wellsie\appdata\local\cloudstation\cloudstation.app\bin\cloud-drive-connect.exe
FirewallRules: [UDP Query User{84F7A330-99FD-4191-870B-4ED2C32DD1A3}C:\program files (x86)\synology\assistant\dsassistant.exe] => (Allow) C:\program files (x86)\synology\assistant\dsassistant.exe
FirewallRules: [TCP Query User{DFF37AE9-D0E1-451E-8842-A60CADEF6E0A}C:\program files (x86)\synology\assistant\dsassistant.exe] => (Allow) C:\program files (x86)\synology\assistant\dsassistant.exe
FirewallRules: [{A347730F-9516-4AA0-B212-16B4915EDE9B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{376182B3-E310-4402-8B27-416831C0F26B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{B77164DF-D44E-4CFA-8970-6DCD42B5C8FA}] => (Allow) C:\Users\James (Propia)\AppData\Local\Microsoft\OneDrive\OneDrive.exe
FirewallRules: [{B39C93F0-415C-4B54-BCAE-FDDA4CB4A8E4}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{43B2ED67-C2A9-4147-BB0F-5CF0A024008D}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [UDP Query User{E6756929-4463-44E7-A7AF-0B3B7ADBF981}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe
FirewallRules: [TCP Query User{0FB854A0-C796-4F08-A6EC-5CBF9A2EDEF0}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe
FirewallRules: [{0C77B6A9-51ED-4AF5-881C-9FEF391C539D}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
FirewallRules: [{9698676A-C011-4A68-9D8F-99B82EAB9A29}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
FirewallRules: [{A9297C0D-85C0-4D15-8475-83D6FB77EBB4}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{43EF2792-FE00-46C4-9C7E-FA523BE2F1F0}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{3D7639BE-0A93-4060-B0EB-81635E063221}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{17F95182-EA6E-45FC-8546-AC71407FC21F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [UDP Query User{455F8889-02BC-43C8-8AB2-91D760A8D7D5}C:\program files (x86)\mediamonkey\mediamonkey.exe] => (Allow) C:\program files (x86)\mediamonkey\mediamonkey.exe
FirewallRules: [TCP Query User{26A425CB-6311-47E2-8E40-8C97722888BF}C:\program files (x86)\mediamonkey\mediamonkey.exe] => (Allow) C:\program files (x86)\mediamonkey\mediamonkey.exe
FirewallRules: [UDP Query User{2075A2E8-2CB8-4EE7-B11F-513CDA9624B9}C:\users\priscilla\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\priscilla\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{5070A262-E9D6-42D6-A4EC-0CF42853E471}C:\users\priscilla\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\priscilla\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{5D7F2EEF-C76A-4B22-A42E-C4F6F8128B6A}C:\users\priscilla\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\priscilla\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{D3D17429-1AC8-4707-8BC6-9D8D438B1035}C:\users\priscilla\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\priscilla\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{9CE93D0D-BFFB-469F-8B56-B0221BE44328}C:\program files (x86)\mediamonkey\mediamonkey.exe] => (Allow) C:\program files (x86)\mediamonkey\mediamonkey.exe
FirewallRules: [TCP Query User{D131B370-9A8F-4429-B5DC-49CFD0DDED87}C:\program files (x86)\mediamonkey\mediamonkey.exe] => (Allow) C:\program files (x86)\mediamonkey\mediamonkey.exe
FirewallRules: [{220BCA14-F9EA-492B-B728-B40E042B25EB}] => (Allow) LPort=1900
FirewallRules: [{268B8288-72AF-4173-85C3-6FB3B3AC73D9}] => (Allow) LPort=2869
FirewallRules: [{FD2E7B8F-4F37-40AD-B321-3726E09C21D9}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [UDP Query User{2ACCDC66-AB4E-4DE9-B766-ED0CF61D7FAD}C:\users\james (propia)\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\james (propia)\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [TCP Query User{4A345F4C-60CE-4D32-905A-0634ACC832E1}C:\users\james (propia)\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\james (propia)\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{A131BB38-5133-4732-840E-5501181981AB}C:\users\james (propia)\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\james (propia)\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{53207088-1307-4232-81A8-0026249D3FCC}C:\users\james (propia)\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\james (propia)\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{E0C2634D-F20B-4F17-ADDB-DCFF61B0D0D4}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{8CC7D3B2-A340-4277-8C84-736B6727AC00}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{DD394573-E68F-439A-B137-4F3DF29E9442}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{65088122-23ED-401A-89FE-4B783392205E}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{7EAB640E-E842-4C21-A81F-6B3F0A0E38ED}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{50668171-5B47-47CB-881F-D698A829A11A}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [UDP Query User{B33DF569-47C1-4CC9-BE78-DDE632E07DB2}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{C0461BCA-6B47-40D3-80A5-A2CF3D95D59B}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{78E9BEB3-1398-4404-96E6-137ACAFBC405}C:\users\james (propia)\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\james (propia)\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{5E93F2B7-2827-4037-8F44-4CB734A9D7AA}C:\users\james (propia)\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\james (propia)\appdata\roaming\spotify\spotify.exe
FirewallRules: [{446FFFFD-EF97-43D6-9283-1469B1F6D4E4}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{776E44D0-898E-459F-85B7-8951E9B2CD19}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{B31543C3-496A-4918-A881-5402E1ACD538}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [{B4D04BA8-9EF5-48C5-AE9C-D37E807ED4DB}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
FirewallRules: [{7678B131-98E9-4AEE-A8D2-2BA15FE1E123}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
FirewallRules: [{95111B37-63CF-4ED9-901E-416C59FE7895}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
FirewallRules: [{94078351-5BE7-4859-9708-77548FDD49D5}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
FirewallRules: [{996B4B23-0192-4819-B3B8-477432AA7FF9}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
FirewallRules: [TCP Query User{3E291613-C0E3-464E-B727-7B138B71D584}C:\program files\airparrot 2\airparrot2.exe] => (Allow) C:\program files\airparrot 2\airparrot2.exe
FirewallRules: [UDP Query User{71D5D6D7-B9A8-46F7-900B-D31AD35FC23D}C:\program files\airparrot 2\airparrot2.exe] => (Allow) C:\program files\airparrot 2\airparrot2.exe
FirewallRules: [{CED8B1A3-7D47-4839-BE47-056E94A81184}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Restore Points =========================
 
10-10-2016 09:28:02 JRT Pre-Junkware Removal
18-10-2016 09:46:15 Windows Update
25-10-2016 12:53:11 JRT Pre-Junkware Removal
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (10/26/2016 11:27:31 AM) (Source: Perflib) (EventID: 1008) (User: )
Description: The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.
 
Error: (10/26/2016 09:10:02 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW.  hr = 0x8007001f, A device attached to the system is not functioning.
.
 
 
Operation:
   Executing Asynchronous Operation
 
Context:
   Current State: DoSnapshotSet
 
Error: (10/26/2016 09:07:08 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
 
System Error:
Access is denied.
.
 
Error: (10/26/2016 09:04:57 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {9ab57a53-f052-4493-9434-a47deb276554}
 
Error: (10/26/2016 08:57:12 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files\Microsoft Office 15\root\office15\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files\Microsoft Office 15\root\office15\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0".
Please use sxstrace.exe for detailed diagnosis.
 
Error: (10/26/2016 08:15:37 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Au_.exe version 5.20.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 39ec
 
Start Time: 01d22f57454633dd
 
Termination Time: 4294967295
 
Application Path: C:\Users\JAMES~1.WEL\AppData\Local\Temp\~nsu.tmp\Au_.exe
 
Report Id: fd4e325a-9b4b-11e6-bf57-c8f7330e5ec4
 
Faulting package full name: 
 
Faulting package-relative application ID:
 
Error: (10/26/2016 07:46:53 AM) (Source: Microsoft Office 15) (EventID: 2001) (User: )
Description: Microsoft Outlook: Rejected Safe Mode action : Outlook couldn't start last time. Safe mode could help you troubleshoot the problem, but some features might not be available in this mode.
 
Do you want to start in safe mode?.
Rejected Safe Mode action : Microsoft Outlook.
 
Error: (10/25/2016 06:01:19 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15125
 
Error: (10/25/2016 06:01:19 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15125
 
Error: (10/25/2016 06:01:19 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
 
System errors:
=============
Error: (10/26/2016 04:52:32 PM) (Source: DCOM) (EventID: 10010) (User: Wellsie)
Description: The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.
 
Error: (10/26/2016 04:50:32 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Connected Devices Platform Service service terminated with the following error: 
Unspecified error
 
Error: (10/26/2016 03:36:59 PM) (Source: DCOM) (EventID: 10010) (User: Wellsie)
Description: The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.
 
Error: (10/26/2016 03:34:59 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Connected Devices Platform Service service terminated with the following error: 
Unspecified error
 
Error: (10/26/2016 03:14:14 PM) (Source: DCOM) (EventID: 10010) (User: Wellsie)
Description: The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.
 
Error: (10/26/2016 03:12:14 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Connected Devices Platform Service service terminated with the following error: 
Unspecified error
 
Error: (10/26/2016 01:46:19 PM) (Source: DCOM) (EventID: 10010) (User: Wellsie)
Description: The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.
 
Error: (10/26/2016 01:44:19 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Connected Devices Platform Service service terminated with the following error: 
Unspecified error
 
Error: (10/26/2016 01:42:56 PM) (Source: DCOM) (EventID: 10010) (User: Wellsie)
Description: The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.
 
Error: (10/26/2016 01:40:56 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Connected Devices Platform Service service terminated with the following error: 
Unspecified error
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i5-3210M CPU @ 2.50GHz
Percentage of memory in use: 41%
Total physical RAM: 6031.56 MB
Available physical RAM: 3517.01 MB
Total Virtual: 11151.56 MB
Available Virtual: 7934.75 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:908.82 GB) (Free:591.24 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: BD53F73D)
 
Partition: GPT.
 
==================== End of Addition.txt ============================

See attached

Attached Files



#4 nasdaq

nasdaq

  • Malware Response Team
  • 38,594 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:11:19 PM

Posted 26 October 2016 - 12:49 PM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Unfortunately you have posted the Addition.txt file and attached them same.

Please post the FRST log and I will review both logs.

#5 jecwells

jecwells
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:19 AM

Posted 27 October 2016 - 02:44 AM

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-10-2016
Ran by James (USG) (administrator) on WELLSIE (26-10-2016 16:52:07)
Running from C:\Users\james.WELLSIE\Desktop\Farbar
Loaded Profiles: UpdatusUser & James (USG) (Available Profiles: UpdatusUser & James (Home) & James (Propia) & Priscilla & James (USG))
Platform: Windows 10 Home Version 1607 (X64) Language: English (United Kingdom)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Webroot) C:\Program Files\Webroot\WRSA.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
() C:\Program Files (x86)\Synology\CloudStation\bin\vss-service-x64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\SettingsLauncher.exe
() C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe
(Samsung Electronics Co., Ltd.) C:\ProgramData\SAMSUNG\SW Update Service\SWMAgent.exe
(Webroot) C:\Program Files\Webroot\WRSA.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\SettingsCmdServer.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\SettingsEventHandler.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler64.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Synology Inc.) C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\bin\cloud-drive-ui.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Synology Inc.) C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\bin\cloud-drive-connect.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Synology Inc.) C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\bin\cloud-drive-daemon.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.8.197.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
 
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [14021336 2015-06-18] (Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40312 2014-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [36760 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [815512 2012-01-03] (Adobe Systems Inc.)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1058400 2012-01-26] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [FUFAXRCV] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe [642664 2013-12-24] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [FUFAXSTM] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [863848 2013-12-24] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [25366584 2016-10-10] (Dropbox, Inc.)
HKLM-x32\...\Run: [WRSVC] => C:\Program Files\Webroot\WRSA.exe [990464 2016-10-20] (Webroot)
HKLM\...\Policies\Explorer: [NoViewOnDrive] 0
HKLM\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKLM\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKLM\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKLM\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKLM\...\Policies\Explorer: [NoViewContextMenu] 0
HKLM\...\Policies\Explorer: [NoShellSearchButton] 0
HKLM\...\Policies\Explorer: [NoFind] 0
HKLM\...\Policies\Explorer: [NoFile] 0
HKLM\...\Policies\Explorer: [HideClock] 0
HKLM\...\Policies\Explorer: [NoTrayContextMenu] 0
HKLM\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKLM\...\Policies\Explorer: [NoSetFolders] 0
HKLM\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKLM\...\Policies\Explorer: [NoSetTaskbar] 0
HKLM\...\Policies\Explorer: [NoDeletePrinter] 0
HKLM\...\Policies\Explorer: [NoDFSTab] 0
HKLM\...\Policies\Explorer: [NoChangeStartMenu] 0
HKLM\...\Policies\Explorer: [NoLogoff] 0
HKLM\...\Policies\Explorer: [NoWindowsUpdate] 0
HKLM\...\Policies\Explorer: [NoEncryptOnMove] 0
HKLM\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKLM\...\Policies\Explorer: [NoResolveSearch] 0
HKLM\...\Policies\Explorer: [NoSaveSettings] 0
HKLM\...\Policies\Explorer: [NoHardwareTab] 0
HKLM\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKLM\...\Policies\Explorer: [NoDesktop] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23375200 2016-07-29] (Google)
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [516608 2016-07-16] (Microsoft Corporation)
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23375200 2016-07-29] (Google)
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\RunOnce: [Uninstall C:\Users\james.WELLSIE\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\james.WELLSIE\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64"
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\RunOnce: [Uninstall C:\Users\james.WELLSIE\AppData\Local\Microsoft\OneDrive\17.3.6281.1202] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\james.WELLSIE\AppData\Local\Microsoft\OneDrive\17.3.6281.1202"
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\RunOnce: [Uninstall C:\Users\james.WELLSIE\AppData\Local\Microsoft\OneDrive\17.3.6381.0405\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\james.WELLSIE\AppData\Local\Microsoft\OneDrive\17.3.6381.0405\amd64"
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\RunOnce: [Uninstall C:\Users\james.WELLSIE\AppData\Local\Microsoft\OneDrive\17.3.6381.0405] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\james.WELLSIE\AppData\Local\Microsoft\OneDrive\17.3.6381.0405"
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\...\Policies\Explorer: [NoStartMenuSubFolders] 0
AppInit_DLLs: C:\windows\system32\nvinitx.dll => No File
SSODL: EldosMountNotificator-cbfs5 - {F3482BEA-25ED-4D93-A276-09B5FECC8FA6} - C:\WINDOWS\system32\cbfsMntNtf5.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator-cbfs5 - {F3482BEA-25ED-4D93-A276-09B5FECC8FA6} - C:\WINDOWS\SysWOW64\cbfsMntNtf5.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: [   01UnsuppModule] -> {AEB16659-2125-4ADA-A4AB-45EE21E86469} => C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\icon-overlay\16\x64\iconOverlay.dll [2016-08-02] (TODO: <Company name>)
ShellIconOverlayIdentifiers: [   02SyncingModule] -> {48AB5ADA-36B1-4137-99C9-2BD97F8788AB} => C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\icon-overlay\16\x64\iconOverlay.dll [2016-08-02] (TODO: <Company name>)
ShellIconOverlayIdentifiers: [   03SyncedModule] -> {472CE1AD-5D53-4BCF-A1FB-3982A5F55138} => C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\icon-overlay\16\x64\iconOverlay.dll [2016-08-02] (TODO: <Company name>)
ShellIconOverlayIdentifiers: [   04ReadOnlyModule] -> {A433C3E0-8B24-40EB-93C3-4B10D9959F58} => C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\icon-overlay\16\x64\iconOverlay.dll [2016-08-02] (TODO: <Company name>)
ShellIconOverlayIdentifiers: [   05NoPermModule] -> {C701AD67-3DF0-47C9-89CB-DFA6207BE229} => C:\Users\james.WELLSIE\AppData\Local\CloudStation\CloudStation.app\icon-overlay\16\x64\iconOverlay.dll [2016-08-02] (TODO: <Company name>)
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-07-29] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-07-29] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-07-29] (Google)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [EldosIconOverlay-cbfs5] -> {7008505C-E87D-4C92-9D19-37ED79C11589} => C:\WINDOWS\system32\cbfsMntNtf5.dll [2014-09-18] (EldoS Corporation)
ShellIconOverlayIdentifiers-x32: [  SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-09-06] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [  SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-09-06] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [  SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-09-06] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-09-06] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-09-06] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-09-06] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [EldosIconOverlay-cbfs5] -> {7008505C-E87D-4C92-9D19-37ED79C11589} => C:\WINDOWS\SysWOW64\cbfsMntNtf5.dll [2014-09-18] (EldoS Corporation)
Startup: C:\Users\James (Home)\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk [2014-06-20]
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
Startup: C:\Users\James (Propia)\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk [2014-06-20]
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
Startup: C:\Users\james.WELLSIE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk [2015-11-24]
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
Startup: C:\Users\james.WELLSIE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneDrive for Business.lnk [2015-08-24]
ShortcutTarget: OneDrive for Business.lnk -> C:\Program Files\Microsoft Office 15\root\office15\groove.exe (Microsoft Corporation)
Startup: C:\Users\james.WELLSIE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2015-10-16]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe (Microsoft Corporation)
Startup: C:\Users\james.WELLSIE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Synology Cloud Station Drive.lnk [2016-10-26]
ShortcutTarget: Synology Cloud Station Drive.lnk -> C:\Program Files (x86)\Synology\CloudStation\bin\launcher.exe (Synology Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 135.196.0.14
Tcpip\..\Interfaces\{a1c4d5fa-c1ba-4fc0-ba43-7ca893636566}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{c1373ace-7d17-460e-98de-31cebf2dcf1e}: [DhcpNameServer] 8.8.8.8 135.196.0.14
 
Internet Explorer:
==================
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.co.uk/
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung13.msn.com
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung13.msn.com/
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung13.msn.com
SearchScopes: HKU\S-1-5-21-3658493019-1111599900-2463904087-1002 -> DefaultScope {F7E9B3D9-56D2-4C05-9AE7-BEAB4E8B30CE} URL = 
SearchScopes: HKU\S-1-5-21-3658493019-1111599900-2463904087-1002 -> {F7E9B3D9-56D2-4C05-9AE7-BEAB4E8B30CE} URL = 
SearchScopes: HKU\S-1-5-21-3658493019-1111599900-2463904087-1006 -> DefaultScope {F7E9B3D9-56D2-4C05-9AE7-BEAB4E8B30CE} URL = 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-08-16] (Microsoft Corporation)
BHO: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG Web TuneUp\4.3.6.255\AVG Web TuneUp.dll => No File
BHO: Webroot Filtering Extension -> {C9C42510-9B41-42c1-9DCD-7282A2D07C61} -> C:\Program Files\Common Files\Webroot\WebFiltering\wrflt.dll [2016-10-20] (Webroot)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-09-06] (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2016-07-26] (Microsoft Corporation)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2016-06-01] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2012-01-03] (Adobe Systems Incorporated)
BHO-x32: Webroot Filtering Extension -> {C9C42510-9B41-42c1-9DCD-7282A2D07C61} -> C:\Program Files (x86)\Common Files\Webroot\WebFiltering\wrflt.dll [2016-10-20] (Webroot)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-09-06] (Microsoft Corporation)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2012-01-03] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2012-01-03] (Adobe Systems Incorporated)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2016-04-20] (Microsoft Corporation)
 
FireFox:
========
FF DefaultProfile: lcj75pi6.default
FF ProfilePath: C:\Users\james.WELLSIE\AppData\Roaming\Mozilla\Firefox\Profiles\lcj75pi6.default [2016-10-17]
FF Extension: (Firefox Hotfix) - C:\Users\james.WELLSIE\AppData\Roaming\Mozilla\Firefox\Profiles\lcj75pi6.default\Extensions\firefox-hotfix@mozilla.org.xpi [2016-09-07]
FF HKLM\...\Firefox\Extensions: [webrootsecure@webroot.com] - C:\ProgramData\WRData\PKG\FIREFOX\WebrootSecure_SocketServer
FF Extension: (Webroot Filtering Extension) - C:\ProgramData\WRData\PKG\FIREFOX\WebrootSecure_SocketServer [2016-10-20]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: (Adobe Acrobat - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2014-08-01] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [webrootsecure@webroot.com] - C:\ProgramData\WRData\PKG\FIREFOX\WebrootSecure_SocketServer
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_23_0_0_185.dll [2016-10-15] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [No File]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_23_0_0_185.dll [2016-10-15] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-12] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-11-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2012-01-03] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3658493019-1111599900-2463904087-1006: intel.com/AppUp -> C:\Program Files (x86)\Intel\IntelAppStore\bin\npAppUp.dll [No File]
 
Chrome: 
=======
CHR DefaultProfile: Profile 2
CHR HomePage: Profile 2 -> hxxp://www.google.co.uk/
CHR StartupUrls: Profile 2 -> "hxxps://www.google.co.uk/"
CHR Profile: C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Default [2016-10-18]
CHR Profile: C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1 [2016-10-25]
CHR Extension: (Google Slides) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-10-17]
CHR Extension: (Google Docs) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-10-17]
CHR Extension: (Google Drive) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-10-17]
CHR Extension: (YouTube) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-10-17]
CHR Extension: (Google Sheets) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-10-17]
CHR Extension: (Google Docs Offline) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-10-18]
CHR Extension: (Cisco WebEx Extension) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jlhmfgmfgeifomenelglieieghnjghma [2016-10-17]
CHR Extension: (Webroot Filtering Extension) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kjeghcllfecehndceplomkocgfbklffd [2016-10-20]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2016-10-17]
CHR Extension: (Chrome Web Store Payments) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-10-17]
CHR Extension: (TunnelBear VPN) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\omdakjcmkglenbhjadbccaookpfjihpa [2016-10-17]
CHR Extension: (Gmail) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-10-17]
CHR Extension: (Chrome Media Router) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-17]
CHR Profile: C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 2 [2016-10-26]
CHR Extension: (Google Slides) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-10-25]
CHR Extension: (Google Docs) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2016-10-25]
CHR Extension: (Google Drive) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-10-25]
CHR Extension: (YouTube) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-10-25]
CHR Extension: (Google Sheets) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-10-25]
CHR Extension: (Google Docs Offline) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-10-25]
CHR Extension: (Webroot Filtering Extension) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\kjeghcllfecehndceplomkocgfbklffd [2016-10-25]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2016-10-25]
CHR Extension: (Chrome Web Store Payments) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-10-25]
CHR Extension: (Gmail) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-10-25]
CHR Extension: (Chrome Media Router) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-25]
CHR HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\JAMES~1.WEL\AppData\Local\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx [2016-10-20]
CHR HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [kjeghcllfecehndceplomkocgfbklffd] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3037424 2016-10-04] (Microsoft Corporation)
R2 Cloud Station Drive VSS Service x64; C:\Program Files (x86)\Synology\CloudStation\bin\vss-service-x64.exe [287256 2016-07-04] ()
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-10-17] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-10-17] (Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [38000 2016-10-10] (Dropbox, Inc.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [337888 2016-05-03] (Intel Corporation)
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel® Corporation)
R2 Intel® Wireless Bluetooth® 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-18] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [50688 2013-05-16] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [66048 2013-05-16] (Hewlett-Packard) [File not signed]
R2 Settings Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\SettingsLauncher.exe [1594176 2015-06-24] (Samsung Electronics CO., LTD.)
R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3292520 2016-08-25] (Samsung Electronics Co., Ltd.)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [256120 2016-02-01] (Synaptics Incorporated)
R2 UsbClientService; C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe [248736 2015-05-11] () [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
R2 WRSVC; C:\Program Files\Webroot\WRSA.exe [990464 2016-10-20] (Webroot)
S2 ZAMSvc; "C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe" /service [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 cbfs5; C:\WINDOWS\system32\drivers\cbfs5.sys [419520 2014-09-18] (EldoS Corporation)
S0 megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys [64352 2016-10-05] (Avago Technologies)
R3 MEIx64; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 NETwNe64; C:\WINDOWS\system32\DRIVERS\Netwew01.sys [3363112 2015-07-28] (Intel Corporation)
R3 RadioHIDMini; C:\WINDOWS\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows ® Win 7 DDK provider)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [895256 2015-06-23] (Realtek                                            )
R3 usb3Hub; C:\WINDOWS\System32\drivers\usb3Hub.sys [47072 2012-10-09] (Windows ® Win 7 DDK provider)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
R0 WRkrn; C:\WINDOWS\System32\drivers\WRkrn.sys [138576 2016-10-26] (Webroot)
R3 wrUrlFlt; C:\WINDOWS\system32\DRIVERS\wrUrlFlt.sys [66328 2016-09-30] (Webroot)
R3 XHCIPort; C:\WINDOWS\System32\drivers\XHCIPort.sys [188896 2012-10-09] (Windows ® Win 7 DDK provider)
R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [203680 2016-10-17] (Zemana Ltd.)
S3 dbx; system32\DRIVERS\dbx.sys [X]
S1 ZAM; \??\C:\WINDOWS\System32\drivers\zam64.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-10-26 16:52 - 2016-10-26 16:52 - 00000000 ____D C:\FRST
2016-10-26 16:51 - 2016-10-26 16:52 - 00000000 ____D C:\Users\james.WELLSIE\Desktop\Farbar
2016-10-26 16:50 - 2016-10-26 16:50 - 02407424 _____ (Farbar) C:\Users\james.WELLSIE\Downloads\FRST64.exe
2016-10-26 13:22 - 2016-10-26 13:22 - 00008216 _____ C:\Users\james.WELLSIE\Downloads\RegisterSX42609.pdf
2016-10-26 08:56 - 2016-10-26 08:56 - 00000000 ____D C:\Users\james.WELLSIE\AppData\Local\VS Revo Group
2016-10-26 08:56 - 2016-10-26 08:56 - 00000000 ____D C:\ProgramData\VS Revo Group
2016-10-26 08:56 - 2016-10-26 08:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2016-10-26 08:56 - 2016-10-26 08:56 - 00000000 ____D C:\Program Files\VS Revo Group
2016-10-26 08:56 - 2009-12-30 11:21 - 00031800 _____ (VS Revo Group) C:\WINDOWS\system32\Drivers\revoflt.sys
2016-10-26 08:55 - 2016-10-26 08:55 - 11432112 _____ (VS Revo Group ) C:\Users\james.WELLSIE\Downloads\RevoUninProSetup.exe
2016-10-25 12:56 - 2016-10-25 12:56 - 00000553 _____ C:\Users\james.WELLSIE\Desktop\JRT.txt
2016-10-25 12:53 - 2016-10-25 12:53 - 01631928 _____ (Malwarebytes) C:\Users\james.WELLSIE\Downloads\JRT.exe
2016-10-25 12:49 - 2016-10-25 12:49 - 03516080 _____ (Enigma Software Group USA, LLC.) C:\Users\james.WELLSIE\Downloads\SpyHunter-Installer.exe
2016-10-25 12:41 - 2016-10-25 12:42 - 00002374 _____ C:\Users\james.WELLSIE\Desktop\Google Chrome.lnk
2016-10-25 08:53 - 2016-10-25 08:53 - 00018565 _____ C:\Users\james.WELLSIE\Downloads\GW Dissertation Intro (1).pdf
2016-10-24 21:24 - 2016-10-24 21:24 - 00018565 _____ C:\Users\james.WELLSIE\Downloads\GW Dissertation Intro.pdf
2016-10-21 11:41 - 2016-10-21 11:41 - 03550924 _____ C:\Users\james.WELLSIE\Downloads\2043080_36q0k1ejpl07ydd5.pdf
2016-10-20 11:29 - 2016-10-20 11:29 - 00099292 _____ C:\Users\james.WELLSIE\Downloads\pm2302.pdf
2016-10-18 13:59 - 2016-10-18 14:00 - 00014772 _____ C:\Users\james.WELLSIE\Desktop\161018 - Studious Comps Master Sheet.xlsx
2016-10-18 07:52 - 2016-10-18 07:54 - 182611714 _____ C:\Users\james.WELLSIE\Downloads\1 Olympic Way, Wembley.zip
2016-10-17 12:08 - 2016-10-17 12:08 - 00948220 _____ C:\Users\james.WELLSIE\Downloads\Hackney-CIL-Charging-Schedule.pdf
2016-10-17 11:10 - 2016-10-26 16:52 - 00138866 _____ C:\WINDOWS\ZAM_Guard.krnl.trace
2016-10-17 11:10 - 2016-10-26 08:02 - 09136065 _____ C:\WINDOWS\ZAM.krnl.trace
2016-10-17 11:09 - 2016-10-17 11:09 - 05363600 _____ ( ) C:\Users\james.WELLSIE\Downloads\Zemana.AntiMalware.Setup (1).exe
2016-10-17 10:31 - 2016-10-17 10:31 - 00001955 _____ C:\Users\Public\Desktop\AirParrot 2.lnk
2016-10-17 10:31 - 2016-10-17 10:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AirParrot 2
2016-10-17 09:57 - 2016-10-17 09:58 - 05363600 _____ ( ) C:\Users\james.WELLSIE\Downloads\Zemana.AntiMalware.Setup.exe
2016-10-17 09:51 - 2016-10-26 08:19 - 00000000 ____D C:\Program Files (x86)\Zemana AntiMalware
2016-10-17 09:51 - 2016-10-17 11:10 - 00203680 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zamguard64.sys
2016-10-17 09:51 - 2016-10-17 09:51 - 00000000 ____D C:\Users\james.WELLSIE\AppData\Local\Zemana
2016-10-17 09:42 - 2016-10-17 09:42 - 00012872 _____ (SurfRight B.V.) C:\WINDOWS\system32\bootdelete.exe
2016-10-17 09:11 - 2016-10-17 09:42 - 00000000 ____D C:\ProgramData\HitmanPro
2016-10-14 09:20 - 2016-10-14 09:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-10-12 13:29 - 2016-10-05 11:34 - 01051104 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-10-12 13:29 - 2016-10-05 11:34 - 00894088 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-10-12 13:29 - 2016-10-05 11:33 - 00128864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2016-10-12 13:29 - 2016-10-05 11:31 - 02213248 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2016-10-12 13:29 - 2016-10-05 11:31 - 01353768 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-10-12 13:29 - 2016-10-05 11:31 - 01172472 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-10-12 13:29 - 2016-10-05 11:30 - 07812448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-10-12 13:29 - 2016-10-05 11:22 - 01181536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2016-10-12 13:29 - 2016-10-05 11:17 - 01322848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2016-10-12 13:29 - 2016-10-05 11:13 - 02750384 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-10-12 13:29 - 2016-10-05 11:13 - 01859264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-10-12 13:29 - 2016-10-05 11:13 - 00146784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2016-10-12 13:29 - 2016-10-05 11:12 - 02446696 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2016-10-12 13:29 - 2016-10-05 11:12 - 01112928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2016-10-12 13:29 - 2016-10-05 11:12 - 00619368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-10-12 13:29 - 2016-10-05 11:09 - 22219328 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-10-12 13:29 - 2016-10-05 11:09 - 00064352 _____ (Avago Technologies) C:\WINDOWS\system32\Drivers\MegaSas2i.sys
2016-10-12 13:29 - 2016-10-05 11:08 - 00241504 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2016-10-12 13:29 - 2016-10-05 11:03 - 01705976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2016-10-12 13:29 - 2016-10-05 10:51 - 01430720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2016-10-12 13:29 - 2016-10-05 10:50 - 02256592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-10-12 13:29 - 2016-10-05 10:50 - 00116576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll
2016-10-12 13:29 - 2016-10-05 10:48 - 01022304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2016-10-12 13:29 - 2016-10-05 10:46 - 03892352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2016-10-12 13:29 - 2016-10-05 10:46 - 01360456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2016-10-12 13:29 - 2016-10-05 10:46 - 00980824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2016-10-12 13:29 - 2016-10-05 10:45 - 20965240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-10-12 13:29 - 2016-10-05 10:44 - 22568960 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-10-12 13:29 - 2016-10-05 10:41 - 00545944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-10-12 13:29 - 2016-10-05 10:38 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2016-10-12 13:29 - 2016-10-05 10:38 - 00237568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Diagnostics.dll
2016-10-12 13:29 - 2016-10-05 10:36 - 00113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2016-10-12 13:29 - 2016-10-05 10:35 - 00327680 _____ C:\WINDOWS\system32\wc_storage.dll
2016-10-12 13:29 - 2016-10-05 10:35 - 00196096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.dll
2016-10-12 13:29 - 2016-10-05 10:35 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.Ngc.dll
2016-10-12 13:29 - 2016-10-05 10:34 - 00463360 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2016-10-12 13:29 - 2016-10-05 10:34 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2016-10-12 13:29 - 2016-10-05 10:33 - 00651264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
2016-10-12 13:29 - 2016-10-05 10:33 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll
2016-10-12 13:29 - 2016-10-05 10:33 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2016-10-12 13:29 - 2016-10-05 10:33 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll
2016-10-12 13:29 - 2016-10-05 10:32 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2016-10-12 13:29 - 2016-10-05 10:32 - 00379904 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
2016-10-12 13:29 - 2016-10-05 10:32 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.HostName.dll
2016-10-12 13:29 - 2016-10-05 10:32 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll
2016-10-12 13:29 - 2016-10-05 10:31 - 00837632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2016-10-12 13:29 - 2016-10-05 10:31 - 00748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2016-10-12 13:29 - 2016-10-05 10:31 - 00561664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll
2016-10-12 13:29 - 2016-10-05 10:31 - 00480768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
2016-10-12 13:29 - 2016-10-05 10:31 - 00425472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2016-10-12 13:29 - 2016-10-05 10:31 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
2016-10-12 13:29 - 2016-10-05 10:31 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ConfigureExpandedStorage.dll
2016-10-12 13:29 - 2016-10-05 10:30 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2016-10-12 13:29 - 2016-10-05 10:29 - 01145856 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2016-10-12 13:29 - 2016-10-05 10:29 - 00956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2016-10-12 13:29 - 2016-10-05 10:29 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2016-10-12 13:29 - 2016-10-05 10:28 - 03059200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2016-10-12 13:29 - 2016-10-05 10:28 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2016-10-12 13:29 - 2016-10-05 10:28 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2016-10-12 13:29 - 2016-10-05 10:28 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDeviceRegistration.dll
2016-10-12 13:29 - 2016-10-05 10:28 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.HostName.dll
2016-10-12 13:29 - 2016-10-05 10:27 - 00945664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2016-10-12 13:29 - 2016-10-05 10:27 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll
2016-10-12 13:29 - 2016-10-05 10:27 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2016-10-12 13:29 - 2016-10-05 10:26 - 23680512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-10-12 13:29 - 2016-10-05 10:26 - 00590848 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-10-12 13:29 - 2016-10-05 10:26 - 00327680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2016-10-12 13:29 - 2016-10-05 10:26 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
2016-10-12 13:29 - 2016-10-05 10:26 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovs.dll
2016-10-12 13:29 - 2016-10-05 10:26 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDeviceRegistration.Ngc.dll
2016-10-12 13:29 - 2016-10-05 10:25 - 01589248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
2016-10-12 13:29 - 2016-10-05 10:25 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2016-10-12 13:29 - 2016-10-05 10:25 - 00404992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsreg.dll
2016-10-12 13:29 - 2016-10-05 10:25 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2016-10-12 13:29 - 2016-10-05 10:25 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthBroker.dll
2016-10-12 13:29 - 2016-10-05 10:24 - 13434368 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-10-12 13:29 - 2016-10-05 10:24 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.AllJoyn.dll
2016-10-12 13:29 - 2016-10-05 10:24 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\adsmsext.dll
2016-10-12 13:29 - 2016-10-05 10:23 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
2016-10-12 13:29 - 2016-10-05 10:23 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Wallet.dll
2016-10-12 13:29 - 2016-10-05 10:23 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll
2016-10-12 13:29 - 2016-10-05 10:23 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialclient.dll
2016-10-12 13:29 - 2016-10-05 10:23 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll
2016-10-12 13:29 - 2016-10-05 10:22 - 13081088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-10-12 13:29 - 2016-10-05 10:22 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2016-10-12 13:29 - 2016-10-05 10:21 - 08075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2016-10-12 13:29 - 2016-10-05 10:21 - 03689984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2016-10-12 13:29 - 2016-10-05 10:21 - 01364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2016-10-12 13:29 - 2016-10-05 10:21 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2016-10-12 13:29 - 2016-10-05 10:21 - 00310272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2016-10-12 13:29 - 2016-10-05 10:20 - 00804864 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2016-10-12 13:29 - 2016-10-05 10:20 - 00661504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2016-10-12 13:29 - 2016-10-05 10:20 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2016-10-12 13:29 - 2016-10-05 10:19 - 02390016 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
2016-10-12 13:29 - 2016-10-05 10:19 - 02265088 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-10-12 13:29 - 2016-10-05 10:19 - 01690112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2016-10-12 13:29 - 2016-10-05 10:19 - 00982528 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2016-10-12 13:29 - 2016-10-05 10:18 - 04612608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-10-12 13:29 - 2016-10-05 10:18 - 00983040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2016-10-12 13:29 - 2016-10-05 10:18 - 00911872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2016-10-12 13:29 - 2016-10-05 10:18 - 00858112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2016-10-12 13:29 - 2016-10-05 10:18 - 00759296 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-10-12 13:29 - 2016-10-05 10:17 - 08126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-10-12 13:29 - 2016-10-05 10:17 - 02914304 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2016-10-12 13:29 - 2016-10-05 10:17 - 01493504 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-10-12 13:29 - 2016-10-05 10:16 - 19418624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-10-12 13:29 - 2016-10-05 10:16 - 04747776 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-10-12 13:29 - 2016-10-05 10:16 - 00765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2016-10-12 13:29 - 2016-10-05 10:16 - 00508416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2016-10-12 13:29 - 2016-10-05 10:15 - 07625728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-10-12 13:29 - 2016-10-05 10:15 - 03617792 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-10-12 13:29 - 2016-10-05 10:15 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll
2016-10-12 13:29 - 2016-10-05 10:15 - 01980416 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2016-10-12 13:29 - 2016-10-05 10:15 - 01509376 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-10-12 13:29 - 2016-10-05 10:15 - 00774656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2016-10-12 13:29 - 2016-10-05 10:15 - 00141312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dialclient.dll
2016-10-12 13:29 - 2016-10-05 10:14 - 19416576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-10-12 13:29 - 2016-10-05 10:14 - 02688512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-10-12 13:29 - 2016-10-05 10:14 - 02667520 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-10-12 13:29 - 2016-10-05 10:14 - 02476544 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2016-10-12 13:29 - 2016-10-05 10:14 - 01778176 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-10-12 13:29 - 2016-10-05 10:14 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2016-10-12 13:29 - 2016-10-05 10:14 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2016-10-12 13:29 - 2016-10-05 10:14 - 00701952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2016-10-12 13:29 - 2016-10-05 10:13 - 12345856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2016-10-12 13:29 - 2016-10-05 10:13 - 01328128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2016-10-12 13:29 - 2016-10-05 10:13 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2016-10-12 13:29 - 2016-10-05 10:12 - 01107456 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2016-10-12 13:29 - 2016-10-05 10:12 - 00998912 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2016-10-12 13:29 - 2016-10-05 10:12 - 00924672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2016-10-12 13:29 - 2016-10-05 10:11 - 12174848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-10-12 13:29 - 2016-10-05 10:11 - 06108672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-10-12 13:29 - 2016-10-05 10:11 - 06043136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-10-12 13:29 - 2016-10-05 10:11 - 03496960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll
2016-10-12 13:29 - 2016-10-05 10:11 - 00640000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2016-10-12 13:29 - 2016-10-05 10:10 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2016-10-12 13:29 - 2016-10-05 10:09 - 07467520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2016-10-12 13:29 - 2016-10-05 10:09 - 03369984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2016-10-12 13:29 - 2016-10-05 10:09 - 00884224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2016-10-12 13:29 - 2016-10-05 10:09 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2016-10-12 13:29 - 2016-10-05 10:09 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-10-12 13:29 - 2016-10-05 10:09 - 00674304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2016-10-12 13:29 - 2016-10-05 10:08 - 02356736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVidCtl.dll
2016-10-12 13:29 - 2016-10-05 10:08 - 00873472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2016-10-12 13:29 - 2016-10-05 10:08 - 00598528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2016-10-12 13:29 - 2016-10-05 10:07 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-10-12 13:29 - 2016-10-05 10:07 - 02682880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll
2016-10-12 13:29 - 2016-10-05 10:07 - 02646016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2016-10-12 13:29 - 2016-10-05 10:07 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
2016-10-12 13:29 - 2016-10-05 10:07 - 00542208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2016-10-12 13:29 - 2016-10-05 10:06 - 02999296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2016-10-12 13:29 - 2016-10-05 10:06 - 02254336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-10-12 13:29 - 2016-10-05 10:06 - 02005504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2016-10-12 13:29 - 2016-10-05 10:06 - 01880576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-10-12 13:29 - 2016-10-05 10:06 - 01594368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-10-12 13:29 - 2016-10-05 10:06 - 01013248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2016-10-12 13:29 - 2016-10-05 10:06 - 00850944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2016-10-12 13:29 - 2016-10-05 10:06 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2016-10-12 13:29 - 2016-10-05 10:05 - 03105792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2016-10-12 13:29 - 2016-10-05 10:05 - 00751104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2016-10-12 13:29 - 2016-10-05 01:01 - 00446124 _____ C:\WINDOWS\system32\ApnDatabase.xml
2016-10-12 13:29 - 2016-09-07 06:34 - 00360040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-10-12 13:28 - 2016-10-05 11:35 - 00279904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2016-10-12 13:28 - 2016-10-05 11:16 - 00187232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2016-10-12 13:28 - 2016-10-05 11:09 - 04129928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2016-10-12 13:28 - 2016-10-05 11:09 - 01071728 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2016-10-12 13:28 - 2016-10-05 11:09 - 00244816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2016-10-12 13:28 - 2016-10-05 11:04 - 02537824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2016-10-12 13:28 - 2016-10-05 11:04 - 00628032 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-10-12 13:28 - 2016-10-05 10:49 - 01980768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2016-10-12 13:28 - 2016-10-05 10:36 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthpan.sys
2016-10-12 13:28 - 2016-10-05 10:36 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2016-10-12 13:28 - 2016-10-05 10:35 - 00352768 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2016-10-12 13:28 - 2016-10-05 10:35 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2016-10-12 13:28 - 2016-10-05 10:29 - 09129984 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-10-12 13:28 - 2016-10-05 10:29 - 06285312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-10-12 13:28 - 2016-10-05 10:28 - 00406016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2016-10-12 13:28 - 2016-10-05 10:26 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsensorgroup.dll
2016-10-12 13:28 - 2016-10-05 10:23 - 01908224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2016-10-12 13:28 - 2016-10-05 10:22 - 07654912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-10-12 13:28 - 2016-10-05 10:22 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-10-12 13:28 - 2016-10-05 10:21 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ErrorDetails.dll
2016-10-12 13:28 - 2016-10-05 10:20 - 00936960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2016-10-12 13:28 - 2016-10-05 10:18 - 01656832 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2016-10-12 13:28 - 2016-10-05 10:17 - 04136960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2016-10-12 13:28 - 2016-10-05 10:17 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adsmsext.dll
2016-10-12 13:28 - 2016-10-05 10:16 - 06664192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2016-10-12 13:28 - 2016-10-05 10:16 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2016-10-12 13:28 - 2016-10-05 10:15 - 01840640 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2016-10-12 13:28 - 2016-10-05 10:15 - 00833024 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2016-10-12 13:28 - 2016-10-05 10:15 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2016-10-12 13:28 - 2016-10-05 10:14 - 01456640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2016-10-12 13:28 - 2016-10-05 10:14 - 01013760 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2016-10-12 13:28 - 2016-10-05 10:07 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2016-10-11 12:34 - 2016-10-11 12:34 - 04214617 _____ C:\Users\james.WELLSIE\Desktop\accommodation-guide.pdf
2016-10-10 19:30 - 2016-10-10 19:30 - 00074352 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2016-10-10 19:30 - 2016-10-10 19:30 - 00074352 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2016-10-10 19:30 - 2016-10-10 19:30 - 00074352 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2016-10-10 19:30 - 2016-10-10 19:30 - 00038000 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2016-10-10 09:05 - 2016-10-17 08:12 - 00000000 ____D C:\AdwCleaner
2016-10-04 13:08 - 2016-10-04 13:08 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-10-03 09:16 - 2016-09-15 18:40 - 00965472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
2016-10-03 09:16 - 2016-09-15 18:19 - 00361104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll
2016-10-03 09:16 - 2016-09-15 18:13 - 01264912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2016-10-03 09:16 - 2016-09-15 18:00 - 00554496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2016-10-03 09:16 - 2016-09-15 17:59 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unimdm.tsp
2016-10-03 09:16 - 2016-09-15 17:58 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlancfg.dll
2016-10-03 09:16 - 2016-09-15 17:57 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncSettings.dll
2016-10-03 09:15 - 2016-09-15 18:37 - 00496872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2016-10-03 09:15 - 2016-09-15 18:37 - 00402352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ws2_32.dll
2016-10-03 09:15 - 2016-09-15 18:35 - 01570680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2016-10-03 09:15 - 2016-09-15 18:35 - 00455040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll
2016-10-03 09:15 - 2016-09-15 18:33 - 00083120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devenum.dll
2016-10-03 09:15 - 2016-09-15 18:32 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2016-10-03 09:15 - 2016-09-15 18:25 - 00340320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-10-03 09:15 - 2016-09-15 18:25 - 00262960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2016-10-03 09:15 - 2016-09-15 18:23 - 01503032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2016-10-03 09:15 - 2016-09-15 18:23 - 00170960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2016-10-03 09:15 - 2016-09-15 18:22 - 05722320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2016-10-03 09:15 - 2016-09-15 18:22 - 00975744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2016-10-03 09:15 - 2016-09-15 18:22 - 00860512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2016-10-03 09:15 - 2016-09-15 18:22 - 00433832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2016-10-03 09:15 - 2016-09-15 18:21 - 00272720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2016-10-03 09:15 - 2016-09-15 18:20 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2016-10-03 09:15 - 2016-09-15 18:18 - 06654616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2016-10-03 09:15 - 2016-09-15 18:18 - 01201872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2016-10-03 09:15 - 2016-09-15 18:18 - 01123368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2016-10-03 09:15 - 2016-09-15 18:18 - 00955528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2016-10-03 09:15 - 2016-09-15 18:18 - 00856872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
2016-10-03 09:15 - 2016-09-15 18:17 - 04311736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2016-10-03 09:15 - 2016-09-15 18:14 - 01415752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2016-10-03 09:15 - 2016-09-15 18:13 - 00113504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll
2016-10-03 09:15 - 2016-09-15 18:08 - 05683712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2016-10-03 09:15 - 2016-09-15 18:03 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2016-10-03 09:15 - 2016-09-15 18:03 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TempSignedLicenseExchangeTask.dll
2016-10-03 09:15 - 2016-09-15 18:03 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
2016-10-03 09:15 - 2016-09-15 18:02 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfksproxy.dll
2016-10-03 09:15 - 2016-09-15 18:01 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Radios.dll
2016-10-03 09:15 - 2016-09-15 18:01 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\findnetprinters.dll
2016-10-03 09:15 - 2016-09-15 18:00 - 00518656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll
2016-10-03 09:15 - 2016-09-15 18:00 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2016-10-03 09:15 - 2016-09-15 17:59 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinRtTracing.dll
2016-10-03 09:15 - 2016-09-15 17:58 - 00291840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2016-10-03 09:15 - 2016-09-15 17:58 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
2016-10-03 09:15 - 2016-09-15 17:58 - 00142336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.WiFi.dll
2016-10-03 09:15 - 2016-09-15 17:58 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.SerialCommunication.dll
2016-10-03 09:15 - 2016-09-15 17:58 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2016-10-03 09:15 - 2016-09-15 17:58 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.UserDeviceAssociation.dll
2016-10-03 09:15 - 2016-09-15 17:57 - 00392192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Input.dll
2016-10-03 09:15 - 2016-09-15 17:57 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.LowLevel.dll
2016-10-03 09:15 - 2016-09-15 17:57 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.XboxLive.Storage.dll
2016-10-03 09:15 - 2016-09-15 17:57 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2016-10-03 09:15 - 2016-09-15 17:57 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ClipboardServer.dll
2016-10-03 09:15 - 2016-09-15 17:56 - 01300480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll
2016-10-03 09:15 - 2016-09-15 17:56 - 00670208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.PointOfService.dll
2016-10-03 09:15 - 2016-09-15 17:56 - 00609280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll
2016-10-03 09:15 - 2016-09-15 17:56 - 00554496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2016-10-03 09:15 - 2016-09-15 17:56 - 00413184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SndVolSSO.dll
2016-10-03 09:15 - 2016-09-15 17:56 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2016-10-03 09:15 - 2016-09-15 17:56 - 00265728 _____ C:\WINDOWS\SysWOW64\Windows.Perception.Stub.dll
2016-10-03 09:15 - 2016-09-15 17:56 - 00262656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pdh.dll
2016-10-03 09:15 - 2016-09-15 17:56 - 00257536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DataExchange.dll
2016-10-03 09:15 - 2016-09-15 17:56 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Core.dll
2016-10-03 09:15 - 2016-09-15 17:56 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManagerApi.dll
2016-10-03 09:15 - 2016-09-15 17:55 - 01243136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.FaceAnalysis.dll
2016-10-03 09:15 - 2016-09-15 17:55 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
2016-10-03 09:15 - 2016-09-15 17:55 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.SmartCards.dll
2016-10-03 09:15 - 2016-09-15 17:55 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetworkCollectionAgent.dll
2016-10-03 09:15 - 2016-09-15 17:55 - 00386048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.WiFiDirect.dll
2016-10-03 09:15 - 2016-09-15 17:55 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2016-10-03 09:15 - 2016-09-15 17:55 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll
2016-10-03 09:15 - 2016-09-15 17:55 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2016-10-03 09:15 - 2016-09-15 17:55 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe
2016-10-03 09:15 - 2016-09-15 17:55 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WwaApi.dll
2016-10-03 09:15 - 2016-09-15 17:55 - 00213504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.CredDialogController.dll
2016-10-03 09:15 - 2016-09-15 17:55 - 00202752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll
2016-10-03 09:15 - 2016-09-15 17:55 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll
2016-10-03 09:15 - 2016-09-15 17:55 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll
2016-10-03 09:15 - 2016-09-15 17:55 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupugc.exe
2016-10-03 09:15 - 2016-09-15 17:54 - 00747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Ocr.dll
2016-10-03 09:15 - 2016-09-15 17:54 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mbsmsapi.dll
2016-10-03 09:15 - 2016-09-15 17:54 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll
2016-10-03 09:15 - 2016-09-15 17:54 - 00431104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprdim.dll
2016-10-03 09:15 - 2016-09-15 17:54 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Picker.dll
2016-10-03 09:15 - 2016-09-15 17:53 - 00819200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll
2016-10-03 09:15 - 2016-09-15 17:53 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll
2016-10-03 09:15 - 2016-09-15 17:53 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2016-10-03 09:15 - 2016-09-15 17:53 - 00314368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll
2016-10-03 09:15 - 2016-09-15 17:53 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.dll
2016-10-03 09:15 - 2016-09-15 17:52 - 01358336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2016-10-03 09:15 - 2016-09-15 17:52 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NaturalLanguage6.dll
2016-10-03 09:15 - 2016-09-15 17:52 - 00525824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintDialogs.dll
2016-10-03 09:15 - 2016-09-15 17:52 - 00500224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.dll
2016-10-03 09:15 - 2016-09-15 17:52 - 00445952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprapi.dll
2016-10-03 09:15 - 2016-09-15 17:52 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2016-10-03 09:15 - 2016-09-15 17:52 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2016-10-03 09:15 - 2016-09-15 17:52 - 00238080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2016-10-03 09:15 - 2016-09-15 17:51 - 02333184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2016-10-03 09:15 - 2016-09-15 17:51 - 00762368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprddm.dll
2016-10-03 09:15 - 2016-09-15 17:51 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CryptoWinRT.dll
2016-10-03 09:15 - 2016-09-15 17:50 - 01534464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.3D.dll
2016-10-03 09:15 - 2016-09-15 17:50 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pwrshplugin.dll
2016-10-03 09:15 - 2016-09-15 17:50 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe
2016-10-03 09:15 - 2016-09-15 17:49 - 00901120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2016-10-03 09:15 - 2016-09-15 17:49 - 00499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2016-10-03 09:15 - 2016-09-15 17:49 - 00468992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.InkControls.dll
2016-10-03 09:15 - 2016-09-15 17:48 - 01321472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2016-10-03 09:15 - 2016-09-15 17:48 - 01320448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
2016-10-03 09:15 - 2016-09-15 17:48 - 01112576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2016-10-03 09:15 - 2016-09-15 17:47 - 01077760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll
2016-10-03 09:15 - 2016-09-15 17:47 - 00355328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTMediaFrame.dll
2016-10-03 09:15 - 2016-09-15 17:47 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Energy.dll
2016-10-03 09:15 - 2016-09-15 17:46 - 03305984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2016-10-03 09:15 - 2016-09-15 17:46 - 00795648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MiracastReceiver.dll
2016-10-03 09:15 - 2016-09-15 17:46 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2016-10-03 09:15 - 2016-09-15 17:46 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2016-10-03 09:15 - 2016-09-15 17:46 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll
2016-10-03 09:15 - 2016-09-15 17:46 - 00343040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
2016-10-03 09:15 - 2016-09-15 17:45 - 02749440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2016-10-03 09:15 - 2016-09-15 17:45 - 02642944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2016-10-03 09:15 - 2016-09-15 17:45 - 00470016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll
2016-10-03 09:15 - 2016-09-15 17:44 - 02153984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi.dll
2016-10-03 09:15 - 2016-09-15 17:44 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.MediaPlayer.dll
2016-10-03 09:15 - 2016-09-15 17:44 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAC3ENC.DLL
2016-10-03 09:15 - 2016-09-15 17:43 - 03520512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2016-10-03 09:15 - 2016-09-15 17:43 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imapi2.dll
2016-10-03 09:15 - 2016-09-15 17:43 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToReceiver.dll
2016-10-03 09:15 - 2016-09-15 17:43 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinesam.dll
2016-10-03 09:15 - 2016-09-15 17:43 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll


#6 jecwells

jecwells
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:19 AM

Posted 27 October 2016 - 02:45 AM

2016-10-03 09:15 - 2016-09-15 17:42 - 01220608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2016-10-03 09:15 - 2016-09-15 17:42 - 00719872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_sr.dll
2016-10-03 09:15 - 2016-09-15 17:42 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
2016-10-03 09:15 - 2016-09-15 17:42 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BackgroundMediaPolicy.dll
2016-10-03 09:15 - 2016-09-15 17:41 - 03733504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2016-10-03 09:15 - 2016-09-15 17:41 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2016-10-03 09:15 - 2016-09-15 17:41 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Geolocation.dll
2016-10-03 09:15 - 2016-09-15 17:40 - 05061120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2016-10-03 09:15 - 2016-09-15 17:40 - 02138112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2016-10-03 09:15 - 2016-09-15 17:40 - 02026496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2016-10-03 09:15 - 2016-09-15 17:40 - 01988096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2016-10-03 09:15 - 2016-09-15 17:40 - 01656320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Perception.dll
2016-10-03 09:15 - 2016-09-15 17:40 - 01247232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
2016-10-03 09:15 - 2016-09-15 17:40 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2016-10-03 09:15 - 2016-09-15 17:40 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2016-10-03 09:15 - 2016-09-15 17:40 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll
2016-10-03 09:15 - 2016-09-15 17:39 - 02740224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2016-10-03 09:15 - 2016-09-15 17:39 - 01232384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Maps.dll
2016-10-03 09:15 - 2016-09-15 17:39 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Phone.dll
2016-10-03 09:15 - 2016-09-15 17:39 - 01004544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2016-10-03 09:15 - 2016-09-15 17:39 - 00827904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2016-10-03 09:15 - 2016-09-15 17:38 - 00773120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2016-10-03 09:15 - 2016-09-15 17:38 - 00691200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2016-10-03 09:15 - 2016-09-15 17:38 - 00654336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
2016-10-03 09:15 - 2016-09-15 17:38 - 00620544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2016-10-03 09:15 - 2016-09-15 17:36 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2016-10-03 09:15 - 2016-09-15 17:36 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2016-10-03 09:15 - 2016-09-15 17:35 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SessEnv.dll
2016-10-03 09:15 - 2016-08-06 04:33 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smphost.dll
2016-10-03 09:15 - 2016-08-05 09:29 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.UXRes.dll
2016-10-03 09:14 - 2016-09-15 19:14 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2016-10-03 09:14 - 2016-09-15 18:00 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BcastDVRHelper.dll
2016-10-03 09:14 - 2016-09-15 17:59 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovslegacy.dll
2016-10-03 09:14 - 2016-09-15 17:58 - 00491008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2016-10-03 09:14 - 2016-09-15 17:57 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2016-10-03 09:14 - 2016-09-15 17:55 - 00152064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\biwinrt.dll
2016-10-03 09:14 - 2016-09-15 17:54 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-10-03 09:14 - 2016-09-15 17:49 - 00653312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
2016-10-03 09:14 - 2016-09-15 17:45 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dlnashext.dll
2016-10-03 09:14 - 2016-09-15 17:43 - 03196416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2016-10-03 09:14 - 2016-09-15 17:16 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2016-10-03 09:10 - 2016-09-15 18:30 - 00354264 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2016-10-03 09:10 - 2016-09-15 18:29 - 01117024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2016-10-03 09:10 - 2016-09-15 18:29 - 00424640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ws2_32.dll
2016-10-03 09:10 - 2016-09-15 18:29 - 00218008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
2016-10-03 09:10 - 2016-09-15 18:29 - 00081760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2016-10-03 09:10 - 2016-09-15 18:29 - 00074080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vpci.sys
2016-10-03 09:10 - 2016-09-15 18:27 - 05622088 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2016-10-03 09:10 - 2016-09-15 18:25 - 00280472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdeunlock.exe
2016-10-03 09:10 - 2016-09-15 18:21 - 01000288 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2016-10-03 09:10 - 2016-09-15 18:18 - 00404832 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-10-03 09:10 - 2016-09-15 18:18 - 00328008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2016-10-03 09:10 - 2016-09-15 18:16 - 01738040 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2016-10-03 09:10 - 2016-09-15 18:16 - 01292640 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-10-03 09:10 - 2016-09-15 18:16 - 01157000 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2016-10-03 09:10 - 2016-09-15 18:16 - 00527808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2016-10-03 09:10 - 2016-09-15 18:15 - 00649568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2016-10-03 09:10 - 2016-09-15 18:15 - 00341936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2016-10-03 09:10 - 2016-09-15 18:15 - 00223584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2016-10-03 09:10 - 2016-09-15 18:15 - 00130912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys
2016-10-03 09:10 - 2016-09-15 18:12 - 08158672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2016-10-03 09:10 - 2016-09-15 18:10 - 01600632 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2016-10-03 09:10 - 2016-09-15 18:10 - 00918848 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2016-10-03 09:10 - 2016-09-15 18:07 - 01418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2016-10-03 09:10 - 2016-09-15 17:46 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ffbroker.dll
2016-10-03 09:10 - 2016-09-15 17:44 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2016-10-03 09:10 - 2016-09-15 17:43 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmintegrator.dll
2016-10-03 09:10 - 2016-09-15 17:42 - 00492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2016-10-03 09:10 - 2016-09-15 17:42 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2016-10-03 09:10 - 2016-09-15 17:41 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\unimdm.tsp
2016-10-03 09:10 - 2016-09-15 17:41 - 00259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.SyncEngine.dll
2016-10-03 09:10 - 2016-09-15 17:41 - 00156160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.Client.dll
2016-10-03 09:10 - 2016-09-15 17:41 - 00108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.Authentication.dll
2016-10-03 09:10 - 2016-09-15 17:40 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.XboxLive.Storage.dll
2016-10-03 09:10 - 2016-09-15 17:40 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2016-10-03 09:10 - 2016-09-15 17:40 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2016-10-03 09:10 - 2016-09-15 17:40 - 00082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.UserDeviceAssociation.dll
2016-10-03 09:10 - 2016-09-15 17:39 - 00547840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Input.dll
2016-10-03 09:10 - 2016-09-15 17:39 - 00408576 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll
2016-10-03 09:10 - 2016-09-15 17:39 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneBackupHandler.dll
2016-10-03 09:10 - 2016-09-15 17:39 - 00234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Flights.dll
2016-10-03 09:10 - 2016-09-15 17:38 - 00730112 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2016-10-03 09:10 - 2016-09-15 17:38 - 00573952 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrGidsHandler.dll
2016-10-03 09:10 - 2016-09-15 17:38 - 00211456 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-10-03 09:10 - 2016-09-15 17:38 - 00205824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2016-10-03 09:10 - 2016-09-15 17:38 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2016-10-03 09:10 - 2016-09-15 17:37 - 01507840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.FaceAnalysis.dll
2016-10-03 09:10 - 2016-09-15 17:37 - 00743424 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-10-03 09:10 - 2016-09-15 17:37 - 00680448 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2016-10-03 09:10 - 2016-09-15 17:37 - 00390144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2016-10-03 09:10 - 2016-09-15 17:37 - 00296448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlancfg.dll
2016-10-03 09:10 - 2016-09-15 17:37 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2016-10-03 09:10 - 2016-09-15 17:37 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2016-10-03 09:10 - 2016-09-15 17:36 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsregcmd.exe
2016-10-03 09:10 - 2016-09-15 17:36 - 00640000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2016-10-03 09:10 - 2016-09-15 17:36 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.dll
2016-10-03 09:10 - 2016-09-15 17:36 - 00349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2016-10-03 09:10 - 2016-09-15 17:36 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll
2016-10-03 09:10 - 2016-09-15 17:36 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-10-03 09:10 - 2016-09-15 17:35 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2016-10-03 09:10 - 2016-09-15 17:35 - 01060352 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll
2016-10-03 09:10 - 2016-09-15 17:35 - 01013248 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2016-10-03 09:10 - 2016-09-15 17:35 - 00538112 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2016-10-03 09:10 - 2016-09-15 17:35 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2016-10-03 09:10 - 2016-09-15 17:35 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
2016-10-03 09:10 - 2016-09-15 17:34 - 00642048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.InkControls.dll
2016-10-03 09:10 - 2016-09-15 17:34 - 00560640 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll
2016-10-03 09:10 - 2016-09-15 17:34 - 00424960 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2016-10-03 09:10 - 2016-09-15 17:33 - 00966144 _____ (Microsoft Corporation) C:\WINDOWS\system32\sbe.dll
2016-10-03 09:10 - 2016-09-15 17:33 - 00963584 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebcamUi.dll
2016-10-03 09:10 - 2016-09-15 17:32 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2016-10-03 09:10 - 2016-09-15 17:32 - 00634368 _____ (Microsoft Corporation) C:\WINDOWS\system32\StructuredQuery.dll
2016-10-03 09:10 - 2016-09-15 17:32 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2016-10-03 09:10 - 2016-09-15 17:31 - 01912320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2016-10-03 09:10 - 2016-09-15 17:31 - 01553408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2016-10-03 09:10 - 2016-09-15 17:31 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe
2016-10-03 09:10 - 2016-09-15 17:30 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2016-10-03 09:10 - 2016-09-15 17:30 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2016-10-03 09:10 - 2016-09-15 17:29 - 01082368 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2016-10-03 09:10 - 2016-09-15 17:29 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
2016-10-03 09:10 - 2016-09-15 17:28 - 03288064 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2016-10-03 09:10 - 2016-09-15 17:27 - 02860032 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll
2016-10-03 09:10 - 2016-09-15 17:27 - 00796672 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2016-10-03 09:10 - 2016-09-15 17:27 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceControl.dll
2016-10-03 09:10 - 2016-09-15 17:27 - 00279040 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
2016-10-03 09:10 - 2016-09-15 17:27 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\manage-bde.exe
2016-10-03 09:10 - 2016-09-15 17:27 - 00171008 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvenotify.exe
2016-10-03 09:10 - 2016-09-15 17:27 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Sens.dll
2016-10-03 09:10 - 2016-09-15 17:26 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2016-10-03 09:10 - 2016-09-15 17:26 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdeui.dll
2016-10-03 09:10 - 2016-09-15 17:25 - 00947200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_sr.dll
2016-10-03 09:10 - 2016-09-15 17:25 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceAgent.exe
2016-10-03 09:10 - 2016-09-15 17:24 - 04596224 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2016-10-03 09:10 - 2016-09-15 17:24 - 01080320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Ocr.dll
2016-10-03 09:10 - 2016-09-15 17:24 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2016-10-03 09:10 - 2016-09-15 17:23 - 03405824 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2016-10-03 09:10 - 2016-09-15 17:23 - 01361408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2016-10-03 09:10 - 2016-09-15 17:22 - 01643008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-10-03 09:10 - 2016-09-15 17:21 - 02538496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2016-10-03 09:10 - 2016-09-15 17:21 - 00971264 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2016-10-03 09:10 - 2016-09-15 17:21 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2016-10-03 09:10 - 2016-09-15 17:21 - 00674304 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2016-10-03 09:10 - 2016-09-15 17:20 - 02424320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Perception.dll
2016-10-03 09:10 - 2016-09-15 17:20 - 01710080 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2016-10-03 09:10 - 2016-09-15 17:20 - 01535488 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll
2016-10-03 09:10 - 2016-09-15 17:20 - 01266176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2016-10-03 09:10 - 2016-09-15 17:20 - 00875520 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2016-10-03 09:10 - 2016-09-15 17:20 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll
2016-10-03 09:10 - 2016-09-15 17:20 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll
2016-10-03 09:10 - 2016-09-15 17:19 - 01424896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll
2016-10-03 09:10 - 2016-09-15 17:19 - 00903680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2016-10-03 09:10 - 2016-09-15 17:19 - 00730112 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-10-03 09:10 - 2016-09-15 17:18 - 01369088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
2016-10-03 09:10 - 2016-09-15 17:16 - 01817088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2016-10-03 09:10 - 2016-09-15 17:16 - 00531456 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2016-10-03 09:10 - 2016-09-15 17:16 - 00387072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SessEnv.dll
2016-10-03 09:10 - 2016-09-15 17:16 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\spaceman.exe
2016-10-03 09:10 - 2016-08-06 04:34 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\smphost.dll
2016-10-03 09:10 - 2016-08-05 09:29 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.UXRes.dll
2016-10-03 09:09 - 2016-09-15 18:30 - 00646136 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2016-10-03 09:09 - 2016-09-15 18:29 - 00512416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
2016-10-03 09:09 - 2016-09-15 18:28 - 00498960 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2016-10-03 09:09 - 2016-09-15 18:27 - 01883784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-10-03 09:09 - 2016-09-15 18:27 - 00434528 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2016-10-03 09:09 - 2016-09-15 18:27 - 00128352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2016-10-03 09:09 - 2016-09-15 18:26 - 00090400 _____ (Microsoft Corporation) C:\WINDOWS\system32\devenum.dll
2016-10-03 09:09 - 2016-09-15 18:16 - 07219672 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2016-10-03 09:09 - 2016-09-15 18:16 - 02190176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-10-03 09:09 - 2016-09-15 18:16 - 00657760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-10-03 09:09 - 2016-09-15 18:16 - 00401760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2016-10-03 09:09 - 2016-09-15 18:16 - 00206096 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2016-10-03 09:09 - 2016-09-15 18:14 - 00435040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2016-10-03 09:09 - 2016-09-15 18:12 - 01472536 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2016-10-03 09:09 - 2016-09-15 18:12 - 00092512 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2016-10-03 09:09 - 2016-09-15 18:11 - 04673296 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2016-10-03 09:09 - 2016-09-15 18:11 - 01990640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2016-10-03 09:09 - 2016-09-15 18:11 - 01300600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2016-10-03 09:09 - 2016-09-15 18:11 - 01066104 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-10-03 09:09 - 2016-09-15 18:11 - 00862064 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2016-10-03 09:09 - 2016-09-15 18:11 - 00773168 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2016-10-03 09:09 - 2016-09-15 18:11 - 00725664 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2016-10-03 09:09 - 2016-09-15 18:07 - 01572768 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2016-10-03 09:09 - 2016-09-15 18:07 - 00128864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
2016-10-03 09:09 - 2016-09-15 18:06 - 01046880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-10-03 09:09 - 2016-09-15 18:06 - 00387872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
2016-10-03 09:09 - 2016-09-15 17:50 - 07219200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-10-03 09:09 - 2016-09-15 17:47 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2016-10-03 09:09 - 2016-09-15 17:43 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfksproxy.dll
2016-10-03 09:09 - 2016-09-15 17:43 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2016-10-03 09:09 - 2016-09-15 17:43 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2016-10-03 09:09 - 2016-09-15 17:41 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2016-10-03 09:09 - 2016-09-15 17:41 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Printers.dll
2016-10-03 09:09 - 2016-09-15 17:41 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\NfcRadioMedia.dll
2016-10-03 09:09 - 2016-09-15 17:40 - 00194048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFi.dll
2016-10-03 09:09 - 2016-09-15 17:40 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMapi.dll
2016-10-03 09:09 - 2016-09-15 17:39 - 00418304 _____ C:\WINDOWS\system32\Windows.Perception.Stub.dll
2016-10-03 09:09 - 2016-09-15 17:39 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-10-03 09:09 - 2016-09-15 17:39 - 00295936 _____ (Microsoft Corporation) C:\WINDOWS\system32\pdh.dll
2016-10-03 09:09 - 2016-09-15 17:39 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2016-10-03 09:09 - 2016-09-15 17:39 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Radios.dll
2016-10-03 09:09 - 2016-09-15 17:38 - 01291264 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2016-10-03 09:09 - 2016-09-15 17:38 - 00671232 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkCollectionAgent.dll
2016-10-03 09:09 - 2016-09-15 17:38 - 00505856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
2016-10-03 09:09 - 2016-09-15 17:38 - 00343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.Phone.dll
2016-10-03 09:09 - 2016-09-15 17:38 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2016-10-03 09:09 - 2016-09-15 17:38 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2016-10-03 09:09 - 2016-09-15 17:38 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SerialCommunication.dll
2016-10-03 09:09 - 2016-09-15 17:38 - 00132096 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintWSDAHost.dll
2016-10-03 09:09 - 2016-09-15 17:38 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2016-10-03 09:09 - 2016-09-15 17:37 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.dll
2016-10-03 09:09 - 2016-09-15 17:37 - 00690176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2016-10-03 09:09 - 2016-09-15 17:37 - 00568320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.LowLevel.dll
2016-10-03 09:09 - 2016-09-15 17:37 - 00321024 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkUXBroker.dll
2016-10-03 09:09 - 2016-09-15 17:37 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.HumanInterfaceDevice.dll
2016-10-03 09:09 - 2016-09-15 17:36 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll
2016-10-03 09:09 - 2016-09-15 17:36 - 00719360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2016-10-03 09:09 - 2016-09-15 17:36 - 00648192 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2016-10-03 09:09 - 2016-09-15 17:36 - 00456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2016-10-03 09:09 - 2016-09-15 17:36 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2016-10-03 09:09 - 2016-09-15 17:36 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2016-10-03 09:09 - 2016-09-15 17:36 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2016-10-03 09:09 - 2016-09-15 17:36 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\usbmon.dll
2016-10-03 09:09 - 2016-09-15 17:36 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.CredDialogController.dll
2016-10-03 09:09 - 2016-09-15 17:36 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupugc.exe
2016-10-03 09:09 - 2016-09-15 17:35 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2016-10-03 09:09 - 2016-09-15 17:35 - 00645120 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2016-10-03 09:09 - 2016-09-15 17:35 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprdim.dll
2016-10-03 09:09 - 2016-09-15 17:35 - 00472064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2016-10-03 09:09 - 2016-09-15 17:35 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2016-10-03 09:09 - 2016-09-15 17:35 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Picker.dll
2016-10-03 09:09 - 2016-09-15 17:35 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataExchange.dll
2016-10-03 09:09 - 2016-09-15 17:35 - 00252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2016-10-03 09:09 - 2016-09-15 17:34 - 00671744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mbsmsapi.dll
2016-10-03 09:09 - 2016-09-15 17:34 - 00441856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AccountsRt.dll
2016-10-03 09:09 - 2016-09-15 17:34 - 00437248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll
2016-10-03 09:09 - 2016-09-15 17:34 - 00284160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2016-10-03 09:09 - 2016-09-15 17:33 - 01004032 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-10-03 09:09 - 2016-09-15 17:33 - 00512000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprapi.dll
2016-10-03 09:09 - 2016-09-15 17:32 - 01037312 _____ (Microsoft Corporation) C:\WINDOWS\system32\nettrace.dll
2016-10-03 09:09 - 2016-09-15 17:31 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\pwrshplugin.dll
2016-10-03 09:09 - 2016-09-15 17:30 - 03776512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2016-10-03 09:09 - 2016-09-15 17:30 - 01403392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll
2016-10-03 09:09 - 2016-09-15 17:30 - 01227264 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll
2016-10-03 09:09 - 2016-09-15 17:30 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTMediaFrame.dll
2016-10-03 09:09 - 2016-09-15 17:30 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Energy.dll
2016-10-03 09:09 - 2016-09-15 17:29 - 01105408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MiracastReceiver.dll
2016-10-03 09:09 - 2016-09-15 17:29 - 00720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll
2016-10-03 09:09 - 2016-09-15 17:29 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2016-10-03 09:09 - 2016-09-15 17:29 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\RelPost.exe
2016-10-03 09:09 - 2016-09-15 17:28 - 00864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2016-10-03 09:09 - 2016-09-15 17:28 - 00718848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
2016-10-03 09:09 - 2016-09-15 17:28 - 00442368 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
2016-10-03 09:09 - 2016-09-15 17:28 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcfg.dll
2016-10-03 09:09 - 2016-09-15 17:27 - 01078784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2016-10-03 09:09 - 2016-09-15 17:27 - 00883712 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2016-10-03 09:09 - 2016-09-15 17:27 - 00702976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll
2016-10-03 09:09 - 2016-09-15 17:27 - 00250368 _____ (Microsoft Corporation) C:\WINDOWS\system32\discan.dll
2016-10-03 09:09 - 2016-09-15 17:27 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAC3ENC.DLL
2016-10-03 09:09 - 2016-09-15 17:26 - 00501248 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi2.dll
2016-10-03 09:09 - 2016-09-15 17:26 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2016-10-03 09:09 - 2016-09-15 17:26 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToReceiver.dll
2016-10-03 09:09 - 2016-09-15 17:25 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2016-10-03 09:09 - 2016-09-15 17:25 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2016-10-03 09:09 - 2016-09-15 17:25 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2016-10-03 09:09 - 2016-09-15 17:25 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
2016-10-03 09:09 - 2016-09-15 17:25 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\BackgroundMediaPolicy.dll
2016-10-03 09:09 - 2016-09-15 17:24 - 00538624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2016-10-03 09:09 - 2016-09-15 17:24 - 00467456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Geolocation.dll
2016-10-03 09:09 - 2016-09-15 17:24 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll
2016-10-03 09:09 - 2016-09-15 17:23 - 04474368 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2016-10-03 09:09 - 2016-09-15 17:23 - 01040896 _____ (Microsoft Corporation) C:\WINDOWS\system32\NaturalLanguage6.dll
2016-10-03 09:09 - 2016-09-15 17:23 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2016-10-03 09:09 - 2016-09-15 17:23 - 00611328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2016-10-03 09:09 - 2016-09-15 17:23 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll
2016-10-03 09:09 - 2016-09-15 17:23 - 00347648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2016-10-03 09:09 - 2016-09-15 17:22 - 05611008 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2016-10-03 09:09 - 2016-09-15 17:22 - 01709056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2016-10-03 09:09 - 2016-09-15 17:22 - 01586176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2016-10-03 09:09 - 2016-09-15 17:22 - 00960000 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2016-10-03 09:09 - 2016-09-15 17:22 - 00857600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprddm.dll
2016-10-03 09:09 - 2016-09-15 17:22 - 00376832 _____ (Microsoft Corporation) C:\WINDOWS\system32\CryptoWinRT.dll
2016-10-03 09:09 - 2016-09-15 17:21 - 02208768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll
2016-10-03 09:09 - 2016-09-15 17:20 - 02095616 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2016-10-03 09:09 - 2016-09-15 17:20 - 01275392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2016-10-03 09:09 - 2016-09-15 17:20 - 00845824 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2016-10-03 09:09 - 2016-09-15 17:19 - 03202048 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2016-10-03 09:09 - 2016-09-15 17:19 - 01130496 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2016-10-03 09:09 - 2016-09-15 17:19 - 00788992 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2016-10-03 09:09 - 2016-09-15 17:19 - 00717824 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2016-10-03 09:09 - 2016-09-15 17:18 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2016-10-03 09:09 - 2016-09-15 17:17 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2016-10-03 09:09 - 2016-09-15 17:17 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\FontProvider.dll
2016-10-03 09:09 - 2016-09-15 17:16 - 00886784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2016-10-03 09:08 - 2016-09-15 18:37 - 00590960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2016-10-03 09:08 - 2016-09-15 18:29 - 01377016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2016-10-03 09:08 - 2016-09-15 18:29 - 00603488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2016-10-03 09:08 - 2016-09-15 18:29 - 00169056 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2016-10-03 09:08 - 2016-09-15 18:29 - 00023392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cmimcext.sys
2016-10-03 09:08 - 2016-09-15 18:27 - 00553312 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-10-03 09:08 - 2016-09-15 18:25 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2016-10-03 09:08 - 2016-09-15 18:24 - 00764936 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2016-10-03 09:08 - 2016-09-15 18:21 - 01218912 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-10-03 09:08 - 2016-09-15 18:20 - 00634944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2016-10-03 09:08 - 2016-09-15 18:15 - 00557408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2016-10-03 09:08 - 2016-09-15 18:15 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2016-10-03 09:08 - 2016-09-15 18:15 - 00218976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2016-10-03 09:08 - 2016-09-15 18:14 - 01267512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2016-10-03 09:08 - 2016-09-15 18:14 - 01100128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2016-10-03 09:08 - 2016-09-15 18:14 - 00988512 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2016-10-03 09:08 - 2016-09-15 18:14 - 00947552 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi
2016-10-03 09:08 - 2016-09-15 18:14 - 00811872 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe
2016-10-03 09:08 - 2016-09-15 18:14 - 00119648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
2016-10-03 09:08 - 2016-09-15 18:11 - 00160096 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostBroker.dll
2016-10-03 09:08 - 2016-09-15 18:06 - 01469120 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-10-03 09:08 - 2016-09-15 18:06 - 00587968 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-10-03 09:08 - 2016-09-15 18:06 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2016-10-03 09:08 - 2016-09-15 18:06 - 00372440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2016-10-03 09:08 - 2016-09-15 18:06 - 00050880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2016-10-03 09:08 - 2016-09-15 17:43 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdhid.sys
2016-10-03 09:08 - 2016-09-15 17:42 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winhvr.sys
2016-10-03 09:08 - 2016-09-15 17:40 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthLEEnum.sys
2016-10-03 09:08 - 2016-09-15 17:40 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2016-10-03 09:08 - 2016-09-15 17:40 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2016-10-03 09:08 - 2016-09-15 17:40 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthRadioMedia.dll
2016-10-03 09:08 - 2016-09-15 17:38 - 00427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmrdvcore.dll
2016-10-03 09:08 - 2016-09-15 17:38 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvcext.dll
2016-10-03 09:08 - 2016-09-15 17:37 - 00266240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
2016-10-03 09:08 - 2016-09-15 17:37 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\biwinrt.dll
2016-10-03 09:08 - 2016-09-15 17:36 - 00410624 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2016-10-03 09:08 - 2016-09-15 17:36 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2016-10-03 09:08 - 2016-09-15 17:36 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2016-10-03 09:08 - 2016-09-15 17:36 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovslegacy.dll
2016-10-03 09:08 - 2016-09-15 17:35 - 00432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVolSSO.dll
2016-10-03 09:08 - 2016-09-15 17:35 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2016-10-03 09:08 - 2016-09-15 17:35 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2016-10-03 09:08 - 2016-09-15 17:35 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvc.dll
2016-10-03 09:08 - 2016-09-15 17:35 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\rshx32.dll
2016-10-03 09:08 - 2016-09-15 17:33 - 03753984 _____ (Microsoft Corporation) C:\WINDOWS\system32\bootux.dll
2016-10-03 09:08 - 2016-09-15 17:33 - 00896512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2016-10-03 09:08 - 2016-09-15 17:33 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2016-10-03 09:08 - 2016-09-15 17:31 - 01053184 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
2016-10-03 09:08 - 2016-09-15 17:30 - 01639424 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2016-10-03 09:08 - 2016-09-15 17:30 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CastLaunch.dll
2016-10-03 09:08 - 2016-09-15 17:27 - 05111296 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2016-10-03 09:08 - 2016-09-15 17:27 - 00942080 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-10-03 09:08 - 2016-09-15 17:27 - 00582656 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2016-10-03 09:08 - 2016-09-15 17:23 - 01020928 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2016-10-03 09:08 - 2016-09-15 17:23 - 00631296 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2016-10-03 09:08 - 2016-09-15 17:22 - 00770560 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-09-29 09:06 - 2016-09-29 09:06 - 00000000 ____D C:\Users\james.WELLSIE\AppData\Roaming\ARGUS Software
2016-09-29 09:05 - 2016-09-29 09:05 - 00000173 _____ C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
2016-09-29 09:04 - 2016-09-29 09:04 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services
2016-09-29 09:04 - 2016-09-29 09:04 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2016-09-29 09:04 - 2016-09-29 09:04 - 00000000 ____D C:\Program Files (x86)\Microsoft Synchronization Services
2016-09-29 08:59 - 2016-09-29 09:07 - 00000000 ____D C:\Users\james.WELLSIE\Documents\ARGUS Developer
2016-09-29 08:59 - 2016-09-29 08:59 - 00002202 _____ C:\Users\Public\Desktop\ARGUS Developer.lnk
2016-09-29 08:59 - 2016-09-29 08:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ARGUS Software
2016-09-29 08:58 - 2016-09-29 09:07 - 00000000 ____D C:\ProgramData\ARGUS Software
2016-09-29 08:58 - 2016-09-29 08:58 - 00000000 ____D C:\Program Files (x86)\ARGUS Software
2016-09-28 09:53 - 2016-09-28 11:39 - 00013972 _____ C:\Users\james.WELLSIE\Desktop\Sevi Bingo.xlsx
2016-09-27 11:01 - 2016-09-27 11:01 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2016-09-27 10:57 - 2016-09-28 07:44 - 00000000 ____D C:\Users\james.WELLSIE\AppData\Local\ConnectedDevicesPlatform
2016-09-27 10:57 - 2016-09-27 10:57 - 00000020 ___SH C:\Users\james.WELLSIE\ntuser.ini
2016-09-27 10:57 - 2016-09-27 10:57 - 00000000 ____D C:\ProgramData\USOShared
2016-09-27 10:21 - 2016-09-27 10:26 - 00022863 _____ C:\WINDOWS\diagwrn.xml
2016-09-27 10:21 - 2016-09-27 10:26 - 00022863 _____ C:\WINDOWS\diagerr.xml
2016-09-27 10:20 - 2016-10-26 08:58 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-09-27 10:20 - 2016-09-27 10:20 - 00003312 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{CEBFF8E2-1106-4C8F-B890-6B78D2FE4709}
2016-09-27 10:20 - 2016-09-27 10:20 - 00003294 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{012E388D-EFE7-45FB-9143-FB6CBDDB355E}
2016-09-27 10:20 - 2016-09-27 10:20 - 00002978 _____ C:\WINDOWS\System32\Tasks\SettingsEventHandlerMonitor
2016-09-27 10:20 - 2016-09-27 10:20 - 00002966 _____ C:\WINDOWS\System32\Tasks\SettingsHibernateMonitor
2016-09-27 10:20 - 2016-09-27 10:20 - 00002940 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3658493019-1111599900-2463904087-1005
2016-09-27 10:20 - 2016-09-27 10:20 - 00002880 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3658493019-1111599900-2463904087-1004
2016-09-27 10:20 - 2016-09-27 10:20 - 00002880 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3658493019-1111599900-2463904087-1003
2016-09-27 10:20 - 2016-09-27 10:20 - 00002832 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task
2016-09-27 10:20 - 2016-09-27 10:20 - 00002776 _____ C:\WINDOWS\System32\Tasks\Settings
2016-09-27 10:20 - 2016-09-27 10:20 - 00002380 _____ C:\WINDOWS\System32\Tasks\SAgent
2016-09-27 10:20 - 2016-09-27 10:20 - 00002280 _____ C:\WINDOWS\System32\Tasks\RTKCPL
2016-09-27 10:20 - 2016-09-27 10:20 - 00002260 _____ C:\WINDOWS\System32\Tasks\{6B23812D-9410-4E6B-82C3-62D219429324}
2016-09-27 10:20 - 2016-09-27 10:20 - 00002254 _____ C:\WINDOWS\System32\Tasks\Synaptics TouchPad Enhancements
2016-09-27 10:19 - 2016-10-15 00:06 - 00003804 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-09-27 10:19 - 2016-09-27 10:20 - 00003586 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3658493019-1111599900-2463904087-1004UA
2016-09-27 10:19 - 2016-09-27 10:20 - 00003448 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineUA
2016-09-27 10:19 - 2016-09-27 10:20 - 00003434 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-09-27 10:19 - 2016-09-27 10:20 - 00003314 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3658493019-1111599900-2463904087-1004Core
2016-09-27 10:19 - 2016-09-27 10:20 - 00003224 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineCore
2016-09-27 10:19 - 2016-09-27 10:20 - 00003210 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-09-27 10:19 - 2016-09-27 10:20 - 00002758 _____ C:\WINDOWS\System32\Tasks\LaunchSettings
2016-09-27 10:19 - 2016-09-27 10:20 - 00002462 _____ C:\WINDOWS\System32\Tasks\advRecovery
2016-09-27 10:06 - 2016-10-04 14:36 - 00000000 ___DC C:\WINDOWS\Panther
2016-09-27 09:59 - 2016-09-27 09:59 - 09260032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmploc.DLL
2016-09-27 09:59 - 2016-09-27 09:59 - 09260032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmploc.DLL
2016-09-27 09:59 - 2016-09-27 09:59 - 06574592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 05511680 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 05398016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aclui.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 05384192 _____ (Microsoft) C:\WINDOWS\system32\dbgeng.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 04148224 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 03299328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 02852864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2016-09-27 09:59 - 2016-09-27 09:59 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2016-09-27 09:59 - 2016-09-27 09:59 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 02481768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 02370048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 02360832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 02315264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 02256224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2016-09-27 09:59 - 2016-09-27 09:59 - 02206496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 02183792 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 02049480 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 01966288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 01891328 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 01853232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 01847048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 01726976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 01694712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 01637888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 01557296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 01556992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 01555456 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 01509376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 01453992 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 01388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 01362504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpmde.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 01359360 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 01349120 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 01343928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 01312768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorDataService.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 01293312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 01282048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 01274712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 01232384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 01176664 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 01081856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 01066328 _____ (Microsoft Corporation) C:\WINDOWS\system32\pidgenx.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00959104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00939872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pidgenx.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00895488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00866816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00857440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebcamUi.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00811416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00798208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00790760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00782176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00781824 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00755656 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00678912 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00665768 _____ (Microsoft Corporation) C:\WINDOWS\system32\GenValObj.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00650240 _____ (Microsoft) C:\WINDOWS\system32\DbgModel.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00640976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00595488 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00540160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00529928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00523712 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMRServer.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00520192 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32time.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00509952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00468992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00450392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2016-09-27 09:59 - 2016-09-27 09:59 - 00447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\das.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00444416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00438784 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDec.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00423776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00412160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00409944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2016-09-27 09:59 - 2016-09-27 09:59 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2016-09-27 09:59 - 2016-09-27 09:59 - 00408600 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00396168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00382272 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00379744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
2016-09-27 09:59 - 2016-09-27 09:59 - 00363520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00321792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Phoneutil.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00313560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00303968 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifiprofilessettinghandler.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00289280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NmaDirect.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2016-09-27 09:59 - 2016-09-27 09:59 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_WorkAccess.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00263680 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExSMime.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00261120 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00260096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Phoneutil.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00248320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2016-09-27 09:59 - 2016-09-27 09:59 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapp3hst.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafpos.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapphost.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcpipcfg.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudBackupSettings.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_G18030.DLL
2016-09-27 09:59 - 2016-09-27 09:59 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.UI.Logon.ProxyStub.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00204288 _____ (Windows ® Win 7 DDK provider) C:\WINDOWS\system32\DscCoreConfProv.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FSClient.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappcfg.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tcpipcfg.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00172528 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00162850 _____ C:\WINDOWS\system32\C_932.NLS
2016-09-27 09:59 - 2016-09-27 09:59 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\system32\XamlTileRender.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00151224 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VCardParser.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00141824 _____ (Windows ® Win 7 DDK provider) C:\WINDOWS\SysWOW64\DscCoreConfProv.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppc.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\slc.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\MediaFoundation.DefaultPerceptionProvider.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00133472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
2016-09-27 09:59 - 2016-09-27 09:59 - 00121368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slc.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00117240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00108384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2016-09-27 09:59 - 2016-09-27 09:59 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppc.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.UI.Logon.ProxyStub.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\dasHost.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappgnui.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncPolicy.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncPolicy.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AddressParser.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\POSyncServices.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataPlatformHelperUtil.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00062816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2016-09-27 09:59 - 2016-09-27 09:59 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\csrsrv.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00057400 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsass.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\POSyncServices.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappprxy.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModelOOBE.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataPlatformHelperUtil.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AddressParser.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactActivation.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactActivation.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceassociation.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTypeHelperUtil.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00044472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataLanguageUtil.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00041824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTypeHelperUtil.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataLanguageUtil.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00036168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\netiougc.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\encapi.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerSvc.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netiougc.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExtrasXmlParser.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\slcext.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slcext.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExtrasXmlParser.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_IS2022.DLL
2016-09-27 09:59 - 2016-09-27 09:59 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanhlp.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\c_GSM7.DLL
2016-09-27 09:59 - 2016-09-27 09:59 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.exe
2016-09-27 09:59 - 2016-09-27 09:59 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwmp.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spwmp.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccessRes.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccessRes.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdxm.ocx
2016-09-27 09:59 - 2016-09-27 09:59 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxmasf.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdxm.ocx
2016-09-27 09:59 - 2016-09-27 09:59 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxmasf.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneutilRes.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneutilRes.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneServiceRes.dll
2016-09-27 09:59 - 2016-09-27 09:59 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6r.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 17187840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 13867520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 07792640 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 05376000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 04557824 _____ (Microsoft) C:\WINDOWS\SysWOW64\dbgeng.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 03435008 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 03116544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAJApi.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 02947072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 02913104 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 02820096 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 02423296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAJApi.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 02289664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 02166232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 02107392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 02083840 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 01993216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 01755136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 01461200 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 01435896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 01062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 01060352 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 01029632 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 01006080 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00965120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2016-09-27 09:58 - 2016-09-27 09:58 - 00936448 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00932864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00905216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00860672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00820736 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00806912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00773200 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00761344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00755200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00681304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys
2016-09-27 09:58 - 2016-09-27 09:58 - 00601200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00584544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2016-09-27 09:58 - 2016-09-27 09:58 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00536576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00526848 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00509792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2016-09-27 09:58 - 2016-09-27 09:58 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00461312 _____ (Microsoft) C:\WINDOWS\SysWOW64\DbgModel.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00446464 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00410624 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosResource.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosResource.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00389000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtapi.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00366592 _____ (Microsoft Corporation) C:\WINDOWS\system32\NmaDirect.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00327680 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00302592 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtapi.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00243200 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbvideo.sys
2016-09-27 09:58 - 2016-09-27 09:58 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_G18030.DLL
2016-09-27 09:58 - 2016-09-27 09:58 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2016-09-27 09:58 - 2016-09-27 09:58 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipboardServer.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00178528 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostUser.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00168800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2016-09-27 09:58 - 2016-09-27 09:58 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys
2016-09-27 09:58 - 2016-09-27 09:58 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2016-09-27 09:58 - 2016-09-27 09:58 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00136032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostUser.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00118112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\EhStorTcgDrv.sys
2016-09-27 09:58 - 2016-09-27 09:58 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00114192 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
2016-09-27 09:58 - 2016-09-27 09:58 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MapControls.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2016-09-27 09:58 - 2016-09-27 09:58 - 00079536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00073568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2016-09-27 09:58 - 2016-09-27 09:58 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappprxy.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
2016-09-27 09:58 - 2016-09-27 09:58 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys
2016-09-27 09:58 - 2016-09-27 09:58 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidusb.sys
2016-09-27 09:58 - 2016-09-27 09:58 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceassociation.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\delegatorprovider.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi_passthru.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\encapi.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\delegatorprovider.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi_passthru.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00020320 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_IS2022.DLL
2016-09-27 09:58 - 2016-09-27 09:58 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\c_GSM7.DLL
2016-09-27 09:58 - 2016-09-27 09:58 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosTrace.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosHost.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6r.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlStringsRes.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2016-09-27 09:58 - 2016-09-27 09:58 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlStringsRes.dll
2016-09-27 09:52 - 2016-07-15 20:29 - 09893376 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons000a.dll
2016-09-27 09:52 - 2016-07-15 20:19 - 09681920 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData000a.dll
2016-09-27 09:52 - 2016-07-15 19:45 - 09893376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons000a.dll
2016-09-27 09:52 - 2016-07-15 19:39 - 09565696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData000a.dll
2016-09-27 09:51 - 2016-09-27 09:51 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2016-09-27 09:51 - 2016-09-27 09:51 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini
2016-09-27 09:51 - 2016-09-27 09:08 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2016-09-27 09:46 - 2016-09-27 09:46 - 00000000 ____D C:\Program Files\Reference Assemblies
2016-09-27 09:46 - 2016-09-27 09:46 - 00000000 ____D C:\Program Files\MSBuild
2016-09-27 09:46 - 2016-09-27 09:46 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2016-09-27 09:46 - 2016-09-27 09:46 - 00000000 ____D C:\Program Files (x86)\MSBuild
2016-09-27 09:45 - 2016-05-25 15:31 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2016-09-27 09:45 - 2016-05-25 15:31 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2016-09-27 09:45 - 2016-05-25 15:31 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2016-09-27 09:45 - 2016-05-25 12:03 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2016-09-27 09:45 - 2016-05-25 12:03 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2016-09-27 09:45 - 2016-05-25 12:03 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2016-09-27 09:44 - 2016-09-27 09:44 - 00199008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
2016-09-27 09:42 - 2016-09-27 09:42 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-09-27 09:42 - 2016-09-27 09:42 - 00000000 ____D C:\Users\Default\AppData\Roaming\TuneUp Software
2016-09-27 09:42 - 2016-09-27 09:42 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2016-09-27 09:42 - 2016-09-27 09:42 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2016-09-27 09:42 - 2016-09-27 09:42 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2016-09-27 09:42 - 2016-09-27 09:42 - 00000000 ____D C:\Users\Default User\AppData\Roaming\TuneUp Software
2016-09-27 09:42 - 2016-09-27 09:42 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2016-09-27 09:42 - 2016-09-27 09:42 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2016-09-27 09:42 - 2016-09-27 09:42 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2016-09-27 09:32 - 2016-09-27 09:44 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2016-09-27 09:19 - 2016-10-26 09:00 - 00000000 ____D C:\Users\james.WELLSIE
2016-09-27 09:19 - 2016-09-27 10:20 - 00000000 ____D C:\Users\James (Propia)
2016-09-27 09:19 - 2016-09-27 10:03 - 00000000 ____D C:\Users\Priscilla
2016-09-27 09:19 - 2016-09-27 09:55 - 00000000 ____D C:\Users\UpdatusUser
2016-09-27 09:19 - 2016-09-27 09:55 - 00000000 ____D C:\Users\James (Home)
2016-09-27 09:13 - 2016-09-27 09:13 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2016-09-27 09:13 - 2016-09-27 09:13 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2016-09-27 09:13 - 2016-09-27 09:13 - 00000000 ____D C:\WINDOWS\system32\SRSLabs
2016-09-27 09:13 - 2016-09-27 09:13 - 00000000 ____D C:\Program Files\Realtek
2016-09-27 09:12 - 2016-09-27 09:33 - 00000000 ____D C:\Program Files\Intel
2016-09-27 09:12 - 2016-09-27 09:12 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf
2016-09-27 09:12 - 2016-05-03 23:30 - 00081416 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2016-09-27 09:12 - 2016-05-03 23:30 - 00077832 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL
2016-09-27 09:11 - 2016-09-27 09:11 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
2016-09-27 09:11 - 2016-09-27 09:11 - 00000000 ____D C:\Program Files\Synaptics
2016-09-27 09:10 - 2016-07-16 12:41 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2016-09-27 09:08 - 2016-10-26 13:13 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2016-09-27 09:08 - 2016-10-26 08:20 - 00346328 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-09-26 11:02 - 2016-09-26 11:02 - 00000000 ____D C:\Users\james.WELLSIE\AppData\Local\MFAData
2016-09-26 11:02 - 2016-09-26 11:02 - 00000000 ____D C:\Users\james.WELLSIE\AppData\Local\Avg2015
2016-09-26 10:53 - 2016-09-30 07:18 - 00066328 ____T (Webroot) C:\WINDOWS\system32\Drivers\wrUrlFlt.sys
2016-09-26 10:53 - 2016-09-26 10:53 - 00000000 ____D C:\Program Files\Common Files\Webroot
2016-09-26 10:51 - 2016-10-26 08:58 - 00138576 _____ (Webroot) C:\WINDOWS\system32\Drivers\WRkrn.sys
2016-09-26 10:51 - 2016-10-24 21:16 - 00000000 ____D C:\ProgramData\WRData
2016-09-26 10:51 - 2016-10-20 07:35 - 00184760 _____ (Webroot) C:\WINDOWS\SysWOW64\WRusr.dll
2016-09-26 10:51 - 2016-10-20 07:35 - 00118384 _____ (Webroot) C:\WINDOWS\system32\WRusr.dll
2016-09-26 10:51 - 2016-09-27 09:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Webroot SecureAnywhere
2016-09-26 10:51 - 2016-09-26 10:51 - 00117728 _____ (Webroot) C:\WINDOWS\system32\Drivers\QxJLFdlz.sys
2016-09-26 10:51 - 2016-09-26 10:51 - 00000000 ____D C:\Program Files\Webroot
2016-09-26 09:30 - 2016-09-26 09:30 - 00000000 ____D C:\Users\james.WELLSIE\AppData\Roaming\webex
2016-09-26 09:30 - 2016-09-26 09:30 - 00000000 ____D C:\Users\james.WELLSIE\AppData\Local\WebEx
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-10-26 16:51 - 2015-08-25 07:58 - 00000000 ____D C:\Users\james.WELLSIE\Documents\Outlook Files
2016-10-26 16:44 - 2015-08-21 13:47 - 00000000 ____D C:\Users\james.WELLSIE\AppData\Local\Packages
2016-10-26 09:10 - 2012-08-24 02:35 - 00000000 ____D C:\ProgramData\WinClon
2016-10-26 09:05 - 2016-01-18 16:54 - 00000000 ___RD C:\Users\james.WELLSIE\StudioUS (CLOUD)
2016-10-26 09:04 - 2016-08-02 14:30 - 00000000 ____D C:\Users\james.WELLSIE\AppData\Local\CloudStation
2016-10-26 09:03 - 2015-10-26 18:16 - 00000000 ___RD C:\Users\james.WELLSIE\Dropbox
2016-10-26 09:01 - 2015-09-28 12:19 - 00000000 ___RD C:\Users\james.WELLSIE\Google Drive
2016-10-26 08:57 - 2016-07-16 07:04 - 00786432 _____ C:\WINDOWS\system32\config\BBI
2016-10-26 08:41 - 2015-10-12 21:57 - 00000000 ____D C:\Users\james.WELLSIE\AppData\Roaming\ObviousIdea
2016-10-26 08:40 - 2014-07-07 16:18 - 00000000 ____D C:\ProgramData\Apple
2016-10-26 08:39 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF
2016-10-26 08:37 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-10-26 08:32 - 2014-06-23 16:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
2016-10-26 08:31 - 2014-06-23 16:19 - 00000000 ____D C:\Program Files (x86)\Intel
2016-10-26 08:31 - 2012-08-24 02:15 - 00000000 ____D C:\ProgramData\Intel
2016-10-26 08:19 - 2014-06-25 11:48 - 00000000 ____D C:\Program Files (x86)\epson
2016-10-26 08:07 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps
2016-10-26 08:02 - 2014-10-31 10:48 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2016-10-25 08:03 - 2014-06-20 19:23 - 00002274 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-10-21 14:22 - 2015-10-03 08:40 - 00000000 ____D C:\Users\james.WELLSIE\AppData\Roaming\eM Client
2016-10-21 08:40 - 2016-07-16 12:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-10-21 08:37 - 2015-11-13 09:53 - 00000000 ____D C:\Program Files\Microsoft Office 15
2016-10-18 09:48 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-10-17 10:32 - 2015-11-19 10:40 - 00000000 ____D C:\Users\james.WELLSIE\AppData\Local\AirParrot 2
2016-10-17 10:31 - 2015-11-19 10:39 - 00000000 ____D C:\Program Files\AirParrot 2
2016-10-17 08:20 - 2015-08-06 23:03 - 00955098 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-10-17 08:13 - 2014-06-25 11:22 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-10-15 00:06 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2016-10-15 00:06 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
2016-10-14 09:20 - 2015-08-24 12:25 - 00000000 ____D C:\Program Files (x86)\Dropbox
2016-10-13 13:55 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\rescache
2016-10-13 07:28 - 2014-06-20 09:52 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-10-13 07:20 - 2014-07-28 12:35 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2016-10-13 07:20 - 2014-07-28 12:35 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2016-10-12 17:19 - 2016-07-16 12:47 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
2016-10-12 17:19 - 2016-07-16 12:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-10-12 17:19 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\en-GB
2016-10-12 17:19 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-10-12 17:19 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\migwiz
2016-10-12 17:19 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\en-GB
2016-10-12 17:19 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
2016-10-12 17:19 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2016-10-12 17:19 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2016-10-12 15:50 - 2014-06-20 22:46 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-10-12 15:31 - 2014-06-20 22:46 - 143495576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-10-12 15:30 - 2014-07-28 12:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-10-12 12:03 - 2016-07-16 12:43 - 00783360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2016-10-12 12:03 - 2016-07-16 12:42 - 00177664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Diagnostics.dll
2016-10-04 14:38 - 2015-10-26 15:22 - 00000000 ____D C:\Users\james.WELLSIE\AppData\Roaming\TeamViewer
2016-10-03 21:09 - 2016-07-16 12:49 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-10-03 21:09 - 2016-07-16 12:49 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-10-03 17:12 - 2016-07-16 12:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2016-10-03 17:12 - 2016-07-16 12:47 - 00000000 ___SD C:\WINDOWS\system32\F12
2016-10-03 17:12 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\setup
2016-10-03 17:12 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\setup
2016-10-03 17:12 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-10-03 17:12 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-10-03 17:12 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\Provisioning
2016-10-03 17:12 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-10-03 17:12 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2016-10-03 17:12 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2016-10-03 17:12 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\Dism
2016-09-29 09:48 - 2012-08-24 02:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2016-09-29 09:04 - 2012-08-24 02:39 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2016-09-29 08:57 - 2014-06-20 10:23 - 00000000 ____D C:\ProgramData\Package Cache
2016-09-28 07:46 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\appcompat
2016-09-27 11:19 - 2015-08-21 13:51 - 00002428 _____ C:\Users\james.WELLSIE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-09-27 11:19 - 2015-08-21 13:51 - 00000000 ___RD C:\Users\james.WELLSIE\OneDrive
2016-09-27 11:05 - 2016-01-21 09:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2016-09-27 10:58 - 2014-06-23 16:45 - 00000451 _____ C:\WINDOWS\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2016-09-27 10:57 - 2016-07-16 12:47 - 00000000 ____D C:\ProgramData\USOPrivate
2016-09-27 10:28 - 2016-07-16 07:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2016-09-27 10:20 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2016-09-27 10:20 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\Registration
2016-09-27 10:20 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2016-09-27 10:06 - 2016-07-16 12:47 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2016-09-27 10:06 - 2014-06-23 16:40 - 00022840 _____ C:\WINDOWS\system32\emptyregdb.dat
2016-09-27 10:04 - 2016-07-16 12:47 - 00000000 __RHD C:\Users\Public\Libraries
2016-09-27 10:00 - 2016-07-16 12:47 - 00000000 ___SD C:\WINDOWS\system32\dsc
2016-09-27 10:00 - 2016-07-16 12:47 - 00000000 ___RD C:\Program Files\Windows Defender
2016-09-27 10:00 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\es-MX
2016-09-27 10:00 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2016-09-27 09:53 - 2016-07-16 23:50 - 00000000 ____D C:\WINDOWS\OCR
2016-09-27 09:51 - 2014-07-09 09:20 - 00882678 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2016-09-27 09:44 - 2016-07-16 23:49 - 00000000 ____D C:\WINDOWS\en-GB
2016-09-27 09:44 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-09-27 09:44 - 2016-01-18 16:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Synology
2016-09-27 09:44 - 2015-12-26 11:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SketchUp 2016
2016-09-27 09:44 - 2015-10-10 08:45 - 00000000 ____D C:\Users\James (Propia)\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-09-27 09:44 - 2015-04-16 10:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Software
2016-09-27 09:44 - 2014-12-30 16:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MediaMonkey
2016-09-27 09:44 - 2014-12-17 16:13 - 00000000 ____D C:\Users\James (Propia)\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BBC iPlayer
2016-09-27 09:44 - 2014-11-02 20:05 - 00000000 ____D C:\WINDOWS\it
2016-09-27 09:44 - 2014-11-02 20:05 - 00000000 ____D C:\WINDOWS\fr
2016-09-27 09:44 - 2014-08-24 17:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bluetooth Devices
2016-09-27 09:44 - 2014-08-01 18:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe LiveCycle ES2
2016-09-27 09:44 - 2014-07-05 09:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-09-27 09:44 - 2014-06-24 11:38 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2016-09-27 09:44 - 2014-06-20 20:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2016-09-27 09:44 - 2012-08-24 02:28 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2016-09-27 09:44 - 2012-08-24 02:16 - 00000000 ___HD C:\WINDOWS\system32\WLANProfiles
2016-09-27 09:42 - 2015-10-30 07:28 - 00000000 ____D C:\Users\Default.migrated
2016-09-27 09:36 - 2016-07-16 23:49 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr
2016-09-27 09:36 - 2016-07-16 23:49 - 00000000 ____D C:\WINDOWS\system32\slmgr
2016-09-27 09:36 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2016-09-27 09:36 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2016-09-27 09:36 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2016-09-27 09:36 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\et-EE
2016-09-27 09:36 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\spool
2016-09-27 09:36 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\MUI
2016-09-27 09:36 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\lv-LV
2016-09-27 09:36 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\lt-LT
2016-09-27 09:36 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\InputMethod
2016-09-27 09:36 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\IME
2016-09-27 09:36 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\et-EE
2016-09-27 09:36 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Shared
2016-09-27 09:36 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared
2016-09-27 09:36 - 2012-08-24 18:06 - 00000000 ____D C:\WINDOWS\SysWOW64\NV
2016-09-27 09:36 - 2012-08-24 18:06 - 00000000 ____D C:\WINDOWS\system32\NV
2016-09-27 09:34 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2016-09-27 09:34 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2016-09-27 09:34 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\InputMethod
2016-09-27 09:34 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\IME
2016-09-27 09:34 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\Help
2016-09-27 09:33 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files\Common Files\System
2016-09-27 09:33 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-09-27 09:33 - 2016-06-24 16:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
2016-09-27 09:33 - 2015-12-26 19:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-09-27 09:32 - 2014-06-25 18:35 - 00000000 ____D C:\Users\Priscilla\AppData\Local\Packages
2016-09-27 09:23 - 2014-06-20 09:59 - 00000000 ____D C:\Users\James (Home)\AppData\Local\Packages
2016-09-27 09:21 - 2014-06-20 21:30 - 00000000 ____D C:\Users\James (Propia)\AppData\Local\Packages
2016-09-27 09:14 - 2016-07-16 12:47 - 00000000 ___RD C:\WINDOWS\PrintDialog
2016-09-27 09:14 - 2016-07-16 12:47 - 00000000 ___RD C:\WINDOWS\MiracastView
2016-09-27 09:11 - 2012-08-24 02:28 - 00000000 ____D C:\Intel
2016-09-26 15:09 - 2014-06-20 19:20 - 00000922 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-09-26 14:58 - 2015-06-17 12:47 - 00000970 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3658493019-1111599900-2463904087-1004UA.job
2016-09-26 14:55 - 2015-10-17 10:50 - 00000934 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2016-09-26 13:58 - 2015-06-17 12:47 - 00000918 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3658493019-1111599900-2463904087-1004Core.job
2016-09-26 11:12 - 2015-10-17 10:50 - 00000930 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
2016-09-26 11:12 - 2014-06-20 19:20 - 00000918 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-09-26 11:08 - 2015-06-23 11:04 - 00000000 ____D C:\Program Files\Common Files\AV
2016-09-26 11:08 - 2014-06-20 21:53 - 00000000 ____D C:\ProgramData\MFAData
2016-09-26 11:07 - 2014-10-23 08:53 - 00000000 ____D C:\ProgramData\AVG2015
2016-09-26 11:07 - 2014-06-20 21:56 - 00000000 ___HD C:\$AVG
2016-09-26 09:30 - 2016-01-20 16:37 - 00000000 ____D C:\Users\james.WELLSIE\AppData\LocalLow\Temp
2016-09-26 09:30 - 2015-08-30 14:55 - 00000000 ____D C:\Users\james.WELLSIE\AppData\Roaming\Mozilla
 
==================== Files in the root of some directories =======
 
2016-09-27 09:13 - 2016-09-27 09:13 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2016-09-29 09:05 - 2016-09-29 09:05 - 0000173 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
 
Some files in TEMP:
====================
C:\Users\james.WELLSIE\AppData\Local\Temp\HitmanPro.exe
C:\Users\james.WELLSIE\AppData\Local\Temp\libeay32.dll
C:\Users\james.WELLSIE\AppData\Local\Temp\msvcr120.dll
C:\Users\james.WELLSIE\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-10-26 10:40
 
==================== End of FRST.txt ============================


#7 nasdaq

nasdaq

  • Malware Response Team
  • 38,594 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:11:19 PM

Posted 27 October 2016 - 10:07 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Press the windows key Windows_Logo_key.gif+ r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.
Please copy the entire contents of the code box below to the a new file.
 
start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:

AppInit_DLLs: C:\windows\system32\nvinitx.dll => No File
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
BHO: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG Web TuneUp\4.3.6.255\AVG Web TuneUp.dll => No File
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [No File]
FF Plugin HKU\S-1-5-21-3658493019-1111599900-2463904087-1006: intel.com/AppUp -> C:\Program Files (x86)\Intel\IntelAppStore\bin\npAppUp.dll [No File]
CHR Extension: (Chrome Web Store Payments) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-10-17]
CHR Extension: (Chrome Media Router) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-17]
CHR Extension: (Chrome Web Store Payments) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-10-25]
CHR Extension: (Chrome Media Router) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-25]
S3 dbx; system32\DRIVERS\dbx.sys [X]
S1 ZAM; \??\C:\WINDOWS\System32\drivers\zam64.sys [X]
C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm
C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm
Task: {0E917DD8-586F-4283-BB70-DD320B8F4FFC} - System32\Tasks\{6B23812D-9410-4E6B-82C3-62D219429324} => Chrome.exe hxxp://ui.skype.com/ui/0/7.6.64.105/en/go/help.faq.installer?LastError=1618
Task: {2C217A69-67FF-479D-8252-7E918D2FC8E4} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {36D6F89A-B6A7-42F9-845A-6C24E753B877} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {4EF33CD9-3815-4805-BCD2-662444AA16B3} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {6D889F06-BBEA-4BC1-B1B3-F17FAF80A94E} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {81946D50-4BCE-449E-A8C7-C6B63704D14F} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {A34818B6-40E9-4A46-B4C1-3781F19BFDF9} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {C3016E4B-2D0E-4858-AA4C-79CF36433240} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {CD8DB9A0-BB87-4823-9ADA-5980165BBC2F} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {D9D567F7-9903-4DA4-BD71-5FC3781C38CA} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {DA83F46A-C5B2-47E8-BF87-E214F60723F0} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {EF62FE45-970E-44B0-93D9-CB775B35C328} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm [0]
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm [0]
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION

End
Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

Restart the computer normally to reset the registry.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

Reset Chrome...
Open Google Chrome, click on menu icon google-chrome-setting-icon.png which is located right side top of the google chrome.
 
Click "Settings" then "Show advanced settings" at the bottom of the screen.
 
Click "Reset browser settings" button.
 
Clear your cache and cookies
https://support.google.com/chromebook/answer/183083?hl=en

Restart Chrome.
<<<>>>

Your version of Adobe AIR is out-or-date and vulnerable.

https://get.adobe.com/air/

Go to Start > Control Panel > Programs and Features and uninstall the old version(s) if present.
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 14.0.0.110 - Adobe Systems Incorporated)
<<<>>>

Get the latest version of the Adobe Reader.
http://get.adobe.com/reader/
Before your download I suggest you unckeck the box on the top right "Yes, install McAfee Security Scan Plus - optional" this is not required if you are not a McAfee subscriber. While the installation is in progress you can also deny the installation of any other programs that may be suggested.

When installed remove your old version of the Reader Via the Control Panel > Programs > Programs and Features.
Adobe Reader X (10.1.10) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.10 - Adobe Systems Incorporated)
<<<>>>

Please post the Fixlog.txt and let me know if the problem persists.

#8 jecwells

jecwells
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:19 AM

Posted 27 October 2016 - 10:52 AM

Fix result of Farbar Recovery Scan Tool (x64) Version: 26-10-2016
Ran by James (USG) (27-10-2016 16:13:02) Run:1
Running from C:\Users\james.WELLSIE\Desktop\Farbar
Loaded Profiles: UpdatusUser & James (USG) (Available Profiles: UpdatusUser & James (Home) & James (Propia) & Priscilla & James (USG))
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
start
 
CreateRestorePoint:
EmptyTemp:
CloseProcesses:
 
AppInit_DLLs: C:\windows\system32\nvinitx.dll => No File
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
BHO: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG Web TuneUp\4.3.6.255\AVG Web TuneUp.dll => No File
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [No File]
FF Plugin HKU\S-1-5-21-3658493019-1111599900-2463904087-1006: intel.com/AppUp -> C:\Program Files (x86)\Intel\IntelAppStore\bin\npAppUp.dll [No File]
CHR Extension: (Chrome Web Store Payments) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-10-17]
CHR Extension: (Chrome Media Router) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-17]
CHR Extension: (Chrome Web Store Payments) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-10-25]
CHR Extension: (Chrome Media Router) - C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-25]
S3 dbx; system32\DRIVERS\dbx.sys [X]
S1 ZAM; \??\C:\WINDOWS\System32\drivers\zam64.sys [X]
C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm
C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm
Task: {0E917DD8-586F-4283-BB70-DD320B8F4FFC} - System32\Tasks\{6B23812D-9410-4E6B-82C3-62D219429324} => Chrome.exe hxxp://ui.skype.com/ui/0/7.6.64.105/en/go/help.faq.installer?LastError=1618
Task: {2C217A69-67FF-479D-8252-7E918D2FC8E4} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {36D6F89A-B6A7-42F9-845A-6C24E753B877} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {4EF33CD9-3815-4805-BCD2-662444AA16B3} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {6D889F06-BBEA-4BC1-B1B3-F17FAF80A94E} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {81946D50-4BCE-449E-A8C7-C6B63704D14F} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {A34818B6-40E9-4A46-B4C1-3781F19BFDF9} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {C3016E4B-2D0E-4858-AA4C-79CF36433240} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {CD8DB9A0-BB87-4823-9ADA-5980165BBC2F} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {D9D567F7-9903-4DA4-BD71-5FC3781C38CA} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {DA83F46A-C5B2-47E8-BF87-E214F60723F0} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {EF62FE45-970E-44B0-93D9-CB775B35C328} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm [0]
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm [0]
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
 
End
*****************
 
Restore point was successfully created.
Processes closed successfully.
"C:\windows\system32\nvinitx.dll" => Value data removed successfully.
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}" => key removed successfully
"HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}" => key removed successfully
"HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect" => key removed successfully
"HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\Software\MozillaPlugins\intel.com/AppUp" => key removed successfully
C:\Program Files (x86)\Intel\IntelAppStore\bin\npAppUp.dll => not found.
C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda => moved successfully
C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm => moved successfully
C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda => moved successfully
C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm => moved successfully
dbx => service removed successfully
ZAM => service removed successfully
"C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda" => not found.
"C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda" => not found.
"C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm" => not found.
"C:\Users\james.WELLSIE\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm" => not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0E917DD8-586F-4283-BB70-DD320B8F4FFC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0E917DD8-586F-4283-BB70-DD320B8F4FFC}" => key removed successfully
C:\WINDOWS\System32\Tasks\{6B23812D-9410-4E6B-82C3-62D219429324} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6B23812D-9410-4E6B-82C3-62D219429324}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2C217A69-67FF-479D-8252-7E918D2FC8E4}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2C217A69-67FF-479D-8252-7E918D2FC8E4}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{36D6F89A-B6A7-42F9-845A-6C24E753B877}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{36D6F89A-B6A7-42F9-845A-6C24E753B877}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4EF33CD9-3815-4805-BCD2-662444AA16B3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4EF33CD9-3815-4805-BCD2-662444AA16B3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6D889F06-BBEA-4BC1-B1B3-F17FAF80A94E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6D889F06-BBEA-4BC1-B1B3-F17FAF80A94E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{81946D50-4BCE-449E-A8C7-C6B63704D14F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{81946D50-4BCE-449E-A8C7-C6B63704D14F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A34818B6-40E9-4A46-B4C1-3781F19BFDF9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A34818B6-40E9-4A46-B4C1-3781F19BFDF9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C3016E4B-2D0E-4858-AA4C-79CF36433240}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C3016E4B-2D0E-4858-AA4C-79CF36433240}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CD8DB9A0-BB87-4823-9ADA-5980165BBC2F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CD8DB9A0-BB87-4823-9ADA-5980165BBC2F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D9D567F7-9903-4DA4-BD71-5FC3781C38CA}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D9D567F7-9903-4DA4-BD71-5FC3781C38CA}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DA83F46A-C5B2-47E8-BF87-E214F60723F0}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DA83F46A-C5B2-47E8-BF87-E214F60723F0}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EF62FE45-970E-44B0-93D9-CB775B35C328}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EF62FE45-970E-44B0-93D9-CB775B35C328}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => key removed successfully
C:\ProgramData\Reprise => ":wupeogjxldtlfudivq`qsp`26hfm" ADS removed successfully.
C:\ProgramData\Reprise => ":wupeogjxldtlfudivq`qsp`27hfm" ADS removed successfully.
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\Software\Classes\exefile => key not found. 
HKU\S-1-5-21-3658493019-1111599900-2463904087-1002\Software\Classes\.exe => key not found. 
"HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\Software\Classes\exefile" => key removed successfully
"HKU\S-1-5-21-3658493019-1111599900-2463904087-1006\Software\Classes\.exe" => key removed successfully
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 36868200 B
Java, Flash, Steam htmlcache => 506 B
Windows/system/drivers => 24627800 B
Edge => 3657 B
Chrome => 705308712 B
Firefox => 10987841 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 7382 B
NetworkService => 13051664 B
UpdatusUser => 0 B
James (Home) => 110650 B
James (Propia) => 5336528 B
Priscilla => 325276 B
james.WELLSIE => 1103622276 B
 
RecycleBin => 210674848 B
EmptyTemp: => 2 GB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 16:16:30 ====


#9 jecwells

jecwells
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:19 AM

Posted 27 October 2016 - 10:53 AM

Thank you so much for your help, but sadly it does not seem to have worked. I still have both the pop-ups appearing and the random words on every page I visit which are turned into links. What else can we try!?



#10 nasdaq

nasdaq

  • Malware Response Team
  • 38,594 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:11:19 PM

Posted 27 October 2016 - 01:30 PM

Temporarily disable your AV program so it does not interfere.
Info on how to disable your security applications How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs - Security Mini-Guides.

Download Zoek tool from here

When the download appears, save to the Desktop.
On the Desktop, right-click the Zoek.exe file and select: Run as Administrator
(Give it a few seconds to appear.)

Next, copy/paste the entire script inside the code box below to the input field of Zoek:
createsrpoint;
autoclean;
emptyclsid;
emptyffcache;
FFdefaults;
emptyiecache;
iedefaults;
emptychrcache;
CHRdefaults;
emptyalltemp;
emptyfolderscheck;delete
ipconfig /flushdns;b
Now...
Close any open Browsers.
Click the Run script button, and wait. It takes a few minutes to run all the script.

When the tool finishes, the zoek-results.log is opened in Notepad.
The log is also found on the systemdrive, normally C:\
If a reboot is needed, the log is opened after the reboot.

Please attach the zoek-results.log in your reply.
===

Also, please provide an update on how the computer is behaving after running the above script.

#11 jecwells

jecwells
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:19 AM

Posted 31 October 2016 - 02:50 AM

See attached. Will need to use computer for a bit to establish if problem is still persisting.

 

Thanks so much for your help so far...!

Attached Files



#12 nasdaq

nasdaq

  • Malware Response Team
  • 38,594 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:11:19 PM

Posted 31 October 2016 - 08:40 AM

Keep me posted.

If all is well.

To learn more about how to protect yourself while on the internet read this little guide best security practices keep safe.
http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/

#13 jecwells

jecwells
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:19 AM

Posted 31 October 2016 - 08:48 AM

I'm afraid I am still getting pop ups. Seems to start with ps4ux.com and then recently links to hlpnowp-c.com

 

Is there anything else we can do!?



#14 nasdaq

nasdaq

  • Malware Response Team
  • 38,594 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:11:19 PM

Posted 31 October 2016 - 08:58 AM

--RogueKiller--
  • Download & SAVE to your Desktop Download RogueKiller
  • Quit all programs that you may have started.
  • Please disconnect any USB or external drives from the computer before you run this scan!
  • For Vista or above, right-click the program file and select "Run as Administrator"
  • Accept the user agreements.
  • Execute the scan and wait until it has finished.
  • If a Windows opens to explain what [PUM's] are, read about it.
  • Click the RoguKiller icon on your taksbar to return to the report.
  • Click open the Report
  • Click Export TXT button
  • Save the file as ReportRogue.txt
  • Click the Remove button to delete the items in RED
  • Click Finish and close the program.
  • Locate the ReportRogue.txt file on your Desktop and copy/paste the contents in your next.
=======


Let check the BIOS.

We will check your BIOS and Master boot record.

Read carefully and follow these steps.
TDSS
  • Download TDSSKiller and save it to your Desktop.
  • Doubleclick on TDSSKiller.exe to run the application.
  • Then click on Start Scan.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.

    TDSSKillerSuspicious-1.png
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • Important: Do NOT change the default action on your own unless instructed by a malware Helper! Doing so may render your computer unbootable.
    TDSSKillerMal-1.png
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.

    TDSSKillerCompleted.png
  • If no reboot is required, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
===

Download http://public.avast.com/~gmerek/aswMBR.exe (aswMBR.exe) to your desktop. Double click the aswMBR.exe to run it.
aswMBRScan.gif
  • Click the "Scan" button to start scan.
  • Upon completion of the scan, click Save log, and save it to your desktop. (Note - do not select any Fix at this time) <- IMPORTANT
  • Please paste the contents of that log in your next reply.
  • There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.
    ===

    Wait for further instructions.


#15 jecwells

jecwells
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:03:19 AM

Posted 31 October 2016 - 10:33 AM

RogueKiller V12.7.5.0 (x64) [Oct 31 2016] (Free) by Adlice Software
 
Operating System : Windows 10 (10.0.14393) 64 bits version
Started in : Normal mode
User : James (USG) [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Scan -- Date : 10/31/2016 14:35:10 (Duration : 00:48:07)
 
¤¤¤ Processes : 0 ¤¤¤
 
¤¤¤ Registry : 13 ¤¤¤
[PUP] (X64) HKEY_CLASSES_ROOT\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468} -> Found
[PUP] (X64) HKEY_CLASSES_ROOT\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-3658493019-1111599900-2463904087-1006\Software\Microsoft\Internet Explorer\Main | Start Page : http://samsung13.msn.com/  -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-3658493019-1111599900-2463904087-1006\Software\Microsoft\Internet Explorer\Main | Start Page : http://samsung13.msn.com/  -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-3658493019-1111599900-2463904087-1002\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://samsung13.msn.com  -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-3658493019-1111599900-2463904087-1002\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://samsung13.msn.com  -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-3658493019-1111599900-2463904087-1006\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://samsung13.msn.com  -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-3658493019-1111599900-2463904087-1006\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://samsung13.msn.com  -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 8.8.8.8 135.196.0.14 ([-][United Kingdom])  -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{a1c4d5fa-c1ba-4fc0-ba43-7ca893636566} | DhcpNameServer : 8.8.8.8 135.196.0.14 ([-][United Kingdom])  -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{c1373ace-7d17-460e-98de-31cebf2dcf1e} | DhcpNameServer : 8.8.8.8 135.196.0.14 ([-][United Kingdom])  -> Found
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | TCP Query User{5CDE6D69-F0AE-46C6-8237-A09E51717941}C:\users\james.wellsie\appdata\local\temp\ign446e.tmp\lmiignition.exe : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\users\james.wellsie\appdata\local\temp\ign446e.tmp\lmiignition.exe|Name=lmiignition.exe|Desc=lmiignition.exe|Defer=User| [x] -> Found
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | UDP Query User{CF7A0C51-C783-4809-8390-0411CBA886E9}C:\users\james.wellsie\appdata\local\temp\ign446e.tmp\lmiignition.exe : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\users\james.wellsie\appdata\local\temp\ign446e.tmp\lmiignition.exe|Name=lmiignition.exe|Desc=lmiignition.exe|Defer=User| [x] -> Found
 
¤¤¤ Tasks : 0 ¤¤¤
 
¤¤¤ Files : 0 ¤¤¤
 
¤¤¤ WMI : 0 ¤¤¤
 
¤¤¤ Hosts File : 0 ¤¤¤
 
¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤
 
¤¤¤ Web browsers : 1 ¤¤¤
[PUM.NewTab][FIREFX:Config] lcj75pi6.default : user_pref("browser.newtab.url", "about:newtab"); -> Found
 
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: ST1000LM024 HN-M101MBB +++++
--- User ---
[MBR] d8fc90e42c86690af0b610fcf10deca4
[BSP] 7d003dcc7ad27807c0b7d80e9271f4d8 : Empty|VT.Unknown MBR Code
Partition table:
0 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2048 | Size: 500 MB
1 - [MAN-MOUNT] EFI system partition | Offset (sectors): 1026048 | Size: 300 MB
2 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 1640448 | Size: 128 MB
3 - Basic data partition | Offset (sectors): 1902592 | Size: 930631 MB
4 - [SYSTEM][MAN-MOUNT]  | Offset (sectors): 1907834880 | Size: 450 MB
5 - [SYSTEM][MAN-MOUNT]  | Offset (sectors): 1908756480 | Size: 350 MB
6 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 1909473280 | Size: 20480 MB
7 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 1951416320 | Size: 1029 MB
User = LL1 ... OK
User = LL2 ... OK

15:30:34.0400 0x1a78  TDSS rootkit removing tool 3.1.0.11 Aug  5 2016 12:13:31
15:30:34.0400 0x1a78  UEFI system
15:30:37.0969 0x1a78  ============================================================
15:30:37.0969 0x1a78  Current date / time: 2016/10/31 15:30:37.0969
15:30:37.0971 0x1a78  SystemInfo:
15:30:37.0971 0x1a78  
15:30:37.0971 0x1a78  OS Version: 10.0.14393 ServicePack: 0.0
15:30:37.0971 0x1a78  Product type: Workstation
15:30:37.0971 0x1a78  ComputerName: WELLSIE
15:30:37.0971 0x1a78  UserName: James (USG)
15:30:37.0971 0x1a78  Windows directory: C:\WINDOWS
15:30:37.0971 0x1a78  System windows directory: C:\WINDOWS
15:30:37.0971 0x1a78  Running under WOW64
15:30:37.0971 0x1a78  Processor architecture: Intel x64
15:30:37.0971 0x1a78  Number of processors: 4
15:30:37.0971 0x1a78  Page size: 0x1000
15:30:37.0971 0x1a78  Boot type: Normal boot
15:30:37.0971 0x1a78  CodeIntegrityOptions = 0x00000001
15:30:37.0971 0x1a78  ============================================================
15:30:38.0563 0x1a78  KLMD registered as C:\WINDOWS\system32\drivers\15553216.sys
15:30:38.0563 0x1a78  KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.351, osProperties = 0x19
15:30:38.0942 0x1a78  System UUID: {5DEC3991-12E1-6AFB-C4DF-7D663177C118}
15:30:39.0457 0x1a78  Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
15:30:39.0461 0x1a78  ============================================================
15:30:39.0461 0x1a78  \Device\Harddisk0\DR0:
15:30:39.0461 0x1a78  GPT partitions:
15:30:39.0462 0x1a78  \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {7344EC5C-60E4-407C-8365-E83F8520D29C}, Name: Basic data partition, StartLBA 0x800, BlocksNum 0xFA000
15:30:39.0462 0x1a78  \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {F936330F-0237-41F5-8E8D-A53CAF36BBE9}, Name: EFI system partition, StartLBA 0xFA800, BlocksNum 0x96000
15:30:39.0462 0x1a78  \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {010B1CF6-0B22-48B2-AAF3-0BD4C9DB7353}, Name: Microsoft reserved partition, StartLBA 0x190800, BlocksNum 0x40000
15:30:39.0462 0x1a78  \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {FBBA6A10-796C-4CB5-ABBC-8EBA838CED26}, Name: Basic data partition, StartLBA 0x1D0800, BlocksNum 0x719A3800
15:30:39.0462 0x1a78  \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {628BAE76-FC75-4DB3-A074-EE15EBF46B24}, Name: , StartLBA 0x71B74000, BlocksNum 0xE1000
15:30:39.0462 0x1a78  \Device\Harddisk0\DR0\Partition6: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {DAAC840C-2A57-4F99-B20D-8C240C303B35}, Name: , StartLBA 0x71C55000, BlocksNum 0xAF000
15:30:39.0462 0x1a78  \Device\Harddisk0\DR0\Partition7: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {6C5AB633-B7FF-4C7B-AEBC-099BBA4D2F84}, Name: Basic data partition, StartLBA 0x71D04000, BlocksNum 0x2800000
15:30:39.0462 0x1a78  \Device\Harddisk0\DR0\Partition8: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {56861E6C-BAB9-482C-4173-636C65706975}, Name: Basic data partition, StartLBA 0x74504000, BlocksNum 0x202800
15:30:39.0462 0x1a78  MBR partitions:
15:30:39.0462 0x1a78  ============================================================
15:30:39.0486 0x1a78  C: <-> \Device\Harddisk0\DR0\Partition4
15:30:39.0486 0x1a78  ============================================================
15:30:39.0486 0x1a78  Initialize success
15:30:39.0486 0x1a78  ============================================================
15:30:43.0973 0x0490  ============================================================
15:30:43.0973 0x0490  Scan started
15:30:43.0973 0x0490  Mode: Manual; 
15:30:43.0973 0x0490  ============================================================
15:30:43.0973 0x0490  KSN ping started
15:30:44.0192 0x0490  KSN ping finished: true
15:30:52.0367 0x0490  ================ Scan system memory ========================
15:30:52.0368 0x0490  System memory - ok
15:30:52.0368 0x0490  ================ Scan services =============================
15:30:52.0654 0x0490  1394ohci - ok
15:30:52.0661 0x0490  3ware - ok
15:30:52.0691 0x0490  ACPI - ok
15:30:52.0698 0x0490  AcpiDev - ok
15:30:52.0706 0x0490  acpiex - ok
15:30:52.0714 0x0490  acpipagr - ok
15:30:52.0755 0x0490  AcpiPmi - ok
15:30:52.0762 0x0490  acpitime - ok
15:30:52.0955 0x0490  [ 16D11D2CA3F2078F553E0C3A70A4F050, 51EEA7EFBE122D3FEB2F8487F5A45166A0C4963314B28840C3C404479B4E1849 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
15:30:52.0985 0x0490  AdobeFlashPlayerUpdateSvc - ok
15:30:53.0043 0x0490  ADP80XX - ok
15:30:53.0062 0x0490  AFD - ok
15:30:53.0084 0x0490  ahcache - ok
15:30:53.0104 0x0490  AJRouter - ok
15:30:53.0124 0x0490  ALG - ok
15:30:53.0131 0x0490  AmdK8 - ok
15:30:53.0138 0x0490  AmdPPM - ok
15:30:53.0146 0x0490  amdsata - ok
15:30:53.0150 0x0490  amdsbs - ok
15:30:53.0154 0x0490  amdxata - ok
15:30:53.0211 0x0490  [ 0C3D62CB6B8F2B3CC42369BAC0F58AD5, F0121EACB6060DF1F6C5F79C15D5B483F301EF85B3C79F67806520BE9CEE398E ] AMPPAL          C:\WINDOWS\System32\drivers\AMPPAL.sys
15:30:53.0220 0x0490  AMPPAL - ok
15:30:53.0226 0x0490  AppID - ok
15:30:53.0230 0x0490  AppIDSvc - ok
15:30:53.0256 0x0490  Appinfo - ok
15:30:53.0287 0x0490  applockerfltr - ok
15:30:53.0301 0x0490  AppReadiness - ok
15:30:53.0339 0x0490  AppXSvc - ok
15:30:53.0342 0x0490  arcsas - ok
15:30:53.0346 0x0490  AsyncMac - ok
15:30:53.0351 0x0490  atapi - ok
15:30:53.0368 0x0490  AudioEndpointBuilder - ok
15:30:53.0395 0x0490  Audiosrv - ok
15:30:53.0416 0x0490  AxInstSV - ok
15:30:53.0429 0x0490  b06bdrv - ok
15:30:53.0442 0x0490  BasicDisplay - ok
15:30:53.0446 0x0490  BasicRender - ok
15:30:53.0452 0x0490  bcmfn - ok
15:30:53.0456 0x0490  bcmfn2 - ok
15:30:53.0473 0x0490  BDESVC - ok
15:30:53.0476 0x0490  Beep - ok
15:30:53.0486 0x0490  BFE - ok
15:30:53.0501 0x0490  BITS - ok
15:30:53.0504 0x0490  bowser - ok
15:30:53.0523 0x0490  BrokerInfrastructure - ok
15:30:53.0526 0x0490  Browser - ok
15:30:53.0542 0x0490  BthAvrcpTg - ok
15:30:53.0591 0x0490  BthEnum - ok
15:30:53.0598 0x0490  BthHFEnum - ok
15:30:53.0629 0x0490  bthhfhid - ok
15:30:53.0641 0x0490  BthHFSrv - ok
15:30:53.0667 0x0490  BthLEEnum - ok
15:30:53.0673 0x0490  BTHMODEM - ok
15:30:53.0700 0x0490  BthPan - ok
15:30:53.0707 0x0490  BTHPORT - ok
15:30:53.0727 0x0490  bthserv - ok
15:30:53.0769 0x0490  BTHUSB - ok
15:30:53.0848 0x0490  [ 5A458422B4312BAEEFA3E64D321596E6, 1213D86B9B6FBB1414D1D3E5F4B0ED0C68D05EB98C902395AB0F0FC3D8A29AD5 ] busenum         C:\WINDOWS\System32\drivers\busenum.sys
15:30:53.0867 0x0490  busenum - ok
15:30:53.0887 0x0490  buttonconverter - ok
15:30:53.0913 0x0490  CapImg - ok
15:30:53.0950 0x0490  [ 9161ACE4F6274E71DB8BBDDC843EC5E8, 1DF6987310322EEE7EDED96722E9EECA328E2CA0353C78AB8E261B00F192553A ] cbfs5           C:\WINDOWS\system32\drivers\cbfs5.sys
15:30:53.0962 0x0490  cbfs5 - ok
15:30:53.0967 0x0490  cdfs - ok
15:30:53.0990 0x0490  CDPSvc - ok
15:30:54.0017 0x0490  CDPUserSvc - ok
15:30:54.0096 0x0490  cdrom - ok
15:30:54.0105 0x0490  CertPropSvc - ok
15:30:54.0120 0x0490  cht4iscsi - ok
15:30:54.0123 0x0490  cht4vbd - ok
15:30:54.0152 0x0490  circlass - ok
15:30:54.0156 0x0490  CLFS - ok
15:30:54.0367 0x0490  [ 99D4DBD01BC8384B8A395778D9F45D2C, 1F21E9E19FAF48CA7DDFB2A1ED39DBBB38AFCBEB86BED0A42A673D565D0C77FC ] ClickToRunSvc   C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe
15:30:54.0420 0x0490  ClickToRunSvc - ok
15:30:54.0450 0x0490  ClipSVC - ok
15:30:54.0552 0x0490  [ 45D908483D6BDE0B618E0351EBB29973, 2B8F884663C8AB07F0CAE606C8BC3DEC9D961AC1EE1B78E7832CCF6164C431EF ] Cloud Station Drive VSS Service x64 C:\Program Files (x86)\Synology\CloudStation\bin\vss-service-x64.exe
15:30:54.0562 0x0490  Cloud Station Drive VSS Service x64 - ok
15:30:54.0595 0x0490  clreg - ok
15:30:54.0663 0x0490  CmBatt - ok
15:30:54.0701 0x0490  CNG - ok
15:30:54.0707 0x0490  cnghwassist - ok
15:30:54.0818 0x0490  CompositeBus - ok
15:30:54.0825 0x0490  COMSysApp - ok
15:30:54.0833 0x0490  condrv - ok
15:30:54.0854 0x0490  CoreMessagingRegistrar - ok
15:30:54.0966 0x0490  [ A28D6FA203CE094BDE7ED8CEC6079E42, 5DCA8BA21F5FD0D9F00620E7592949ABCF3BA202CF7AF3D84F93DF7C13E2D4C9 ] cphs            C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
15:30:56.0309 0x0490  cphs - ok
15:30:56.0349 0x0490  CryptSvc - ok
15:30:56.0398 0x0490  dam - ok
15:30:56.0512 0x0490  dbupdate - ok
15:30:56.0517 0x0490  dbupdatem - ok
15:30:56.0575 0x0490  dbx - ok
15:30:56.0610 0x0490  [ 566BD6ED419F7FBC88EDD579044AD5C9, EC66C10DAC23ED149545305EA25F60888C5D3675BD850C7C12275B8666D18FEF ] DbxSvc          C:\WINDOWS\system32\DbxSvc.exe
15:30:57.0276 0x0490  DbxSvc - ok
15:30:57.0302 0x0490  DcomLaunch - ok
15:30:57.0317 0x0490  DcpSvc - ok
15:30:57.0334 0x0490  defragsvc - ok
15:30:57.0345 0x0490  DeviceAssociationService - ok
15:30:57.0349 0x0490  DeviceInstall - ok
15:30:57.0389 0x0490  DevQueryBroker - ok
15:30:57.0407 0x0490  Dfsc - ok
15:30:57.0430 0x0490  [ 85137571AEC8AC757D497B9DD30D544D, 6E15C9FB4010B26A8E5AFD4E85F7362B2616EB8503ACCE28EC31AC1E7D18566F ] dg_ssudbus      C:\WINDOWS\system32\DRIVERS\ssudbus.sys
15:30:57.0654 0x0490  dg_ssudbus - ok
15:30:57.0674 0x0490  Dhcp - ok
15:30:57.0781 0x0490  diagnosticshub.standardcollector.service - ok
15:30:57.0822 0x0490  DiagTrack - ok
15:30:57.0847 0x0490  disk - ok
15:30:57.0874 0x0490  DmEnrollmentSvc - ok
15:30:57.0881 0x0490  dmvsc - ok
15:30:57.0900 0x0490  dmwappushservice - ok
15:30:57.0920 0x0490  Dnscache - ok
15:30:57.0930 0x0490  dot3svc - ok
15:30:57.0951 0x0490  DPS - ok
15:30:57.0967 0x0490  drmkaud - ok
15:30:57.0987 0x0490  DsmSvc - ok
15:30:57.0993 0x0490  DsSvc - ok
15:30:58.0009 0x0490  DXGKrnl - ok
15:30:58.0014 0x0490  EapHost - ok
15:30:58.0023 0x0490  ebdrv - ok
15:30:58.0043 0x0490  EFS - ok
15:30:58.0046 0x0490  EhStorClass - ok
15:30:58.0073 0x0490  EhStorTcgDrv - ok
15:30:58.0077 0x0490  embeddedmode - ok
15:30:58.0081 0x0490  EntAppSvc - ok
15:30:58.0209 0x0490  [ 1E0764A8A8F39BAAEB271DA597422584, 0FEC21BF69925496E11DCDBB3409F63C0F7970FF2B68391CD6E3EF6F566FD2A3 ] EpsonCustomerParticipation C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe
15:30:58.0227 0x0490  EpsonCustomerParticipation - ok
15:30:58.0232 0x0490  ErrDev - ok
15:30:58.0287 0x0490  EventSystem - ok
15:30:58.0293 0x0490  exfat - ok
15:30:58.0300 0x0490  fastfat - ok
15:30:58.0320 0x0490  Fax - ok
15:30:58.0327 0x0490  fdc - ok
15:30:58.0333 0x0490  fdPHost - ok
15:30:58.0342 0x0490  FDResPub - ok
15:30:58.0360 0x0490  fhsvc - ok
15:30:58.0390 0x0490  FileCrypt - ok
15:30:58.0393 0x0490  FileInfo - ok
15:30:58.0398 0x0490  Filetrace - ok
15:30:58.0420 0x0490  flpydisk - ok
15:30:58.0426 0x0490  FltMgr - ok
15:30:58.0460 0x0490  FontCache - ok
15:30:58.0568 0x0490  FontCache3.0.0.0 - ok
15:30:58.0589 0x0490  FrameServer - ok
15:30:58.0594 0x0490  FsDepends - ok
15:30:58.0597 0x0490  Fs_Rec - ok
15:30:58.0621 0x0490  fvevol - ok
15:30:58.0662 0x0490  [ 8E98D21EE06192492A5671A6144D092F, B8F656B34D361EA5AFB47F3A67AB2221580DADA59C8CD0CB83181E4AD8B562B4 ] GEARAspiWDM     C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
15:30:58.0663 0x0490  GEARAspiWDM - ok
15:30:58.0711 0x0490  gencounter - ok
15:30:58.0750 0x0490  genericusbfn - ok
15:30:58.0800 0x0490  GPIOClx0101 - ok
15:30:58.0811 0x0490  gpsvc - ok
15:30:58.0817 0x0490  GpuEnergyDrv - ok
15:30:58.0902 0x0490  [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdate         C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
15:30:58.0908 0x0490  gupdate - ok
15:30:58.0920 0x0490  [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
15:30:58.0927 0x0490  gupdatem - ok
15:30:58.0956 0x0490  HDAudBus - ok
15:30:58.0972 0x0490  HidBatt - ok
15:30:59.0000 0x0490  HidBth - ok
15:30:59.0004 0x0490  hidi2c - ok
15:30:59.0008 0x0490  hidinterrupt - ok
15:30:59.0012 0x0490  HidIr - ok
15:30:59.0025 0x0490  hidserv - ok
15:30:59.0071 0x0490  HidUsb - ok
15:30:59.0096 0x0490  HomeGroupListener - ok
15:30:59.0114 0x0490  HomeGroupProvider - ok
15:30:59.0118 0x0490  HpSAMD - ok
15:30:59.0130 0x0490  HTTP - ok
15:30:59.0152 0x0490  HvHost - ok
15:30:59.0220 0x0490  hvservice - ok
15:30:59.0225 0x0490  hwpolicy - ok
15:30:59.0229 0x0490  hyperkbd - ok
15:30:59.0255 0x0490  i8042prt - ok
15:30:59.0258 0x0490  iagpio - ok
15:30:59.0261 0x0490  iai2c - ok
15:30:59.0266 0x0490  iaLPSS2i_GPIO2 - ok
15:30:59.0270 0x0490  iaLPSS2i_I2C - ok
15:30:59.0273 0x0490  iaLPSSi_GPIO - ok
15:30:59.0303 0x0490  iaLPSSi_I2C - ok
15:30:59.0369 0x0490  [ 57CD95DEB3529181BCC931DD2DFB2341, 03ACF906E4C3CF954F503900F42C7A60FCD5624772B90A956F032484146E42B7 ] iaStorA         C:\WINDOWS\system32\drivers\iaStorA.sys
15:30:59.0379 0x0490  iaStorA - ok
15:30:59.0383 0x0490  iaStorAV - ok
15:30:59.0463 0x0490  [ 20E83F4632E15A5E9E716FF2E8AC7FAE, 7CA1A4924F432AD30ED7FA6247C6513DA173EE31132AE115E85C0ED7E5971029 ] IAStorDataMgrSvc C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
15:30:59.0464 0x0490  IAStorDataMgrSvc - ok
15:30:59.0467 0x0490  iaStorV - ok
15:30:59.0472 0x0490  ibbus - ok
15:30:59.0516 0x0490  [ 62F0CB0A54EAF37E15EC385300957BB8, 55FCF7068D84D5AEEAF3149A5349BF13F1D18E34956217916ED7C1950885E63C ] ibtfltcoex      C:\WINDOWS\system32\DRIVERS\ibtfltcoex.sys
15:30:59.0518 0x0490  ibtfltcoex - ok
15:30:59.0549 0x0490  icssvc - ok
15:30:59.0730 0x0490  [ 9CE4D3A79D3180AC5A141E2F7E7137F4, 1D717D2156B78632895281779D2646AB066619EA1DB293A9505BF7C174F53271 ] igfx            C:\WINDOWS\system32\DRIVERS\igdkmd64.sys
15:30:59.0824 0x0490  igfx - ok
15:30:59.0898 0x0490  [ 6A9C613D0F5F9676D128F39B63ACE45B, 027B9568C740E336C7CBBE952309E2719E8FFA14E7DFC2B85B49E0C0CE7D2149 ] igfxCUIService1.0.0.0 C:\WINDOWS\system32\igfxCUIService.exe
15:31:00.0631 0x0490  igfxCUIService1.0.0.0 - ok
15:31:00.0638 0x0490  IKEEXT - ok
15:31:00.0665 0x0490  IndirectKmd - ok
15:31:00.0698 0x0490  [ B1F193AB8FB72E9FC34B3A39314ED872, 408E98D9C8ABB928090DD9E5D1BB227EFBC997BF168437BAEF0461EB0D1DAE3D ] intaud_WaveExtensible C:\WINDOWS\system32\drivers\intelaud.sys
15:31:00.0700 0x0490  intaud_WaveExtensible - ok
15:31:00.0907 0x0490  [ 5911E1BD8E8E5912092BB922EFA68E91, 2DA61E6C6A9F2467784EF7050EB586574F60CADDD236C8F732233AFC4BEA085B ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
15:31:01.0037 0x0490  IntcAzAudAddService - ok
15:31:01.0074 0x0490  [ 87871AB7AC797F922A6F3D4C874CED96, 2BCD89911E42827CD294DD7D1486A7845D1F98019E51958E0F488384401B2944 ] IntcDAud        C:\WINDOWS\system32\DRIVERS\IntcDAud.sys
15:31:01.0084 0x0490  IntcDAud - ok
15:31:01.0152 0x0490  [ DAE6C3099D291EED8922A65C29ABCF52, AD0A932345382824122F84AF97A8609BAE1B916A3B9FD608779A1411E37D3643 ] Intel® Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
15:31:01.0168 0x0490  Intel® Capability Licensing Service Interface - ok
15:31:01.0209 0x0490  [ D45226E3E7A25F1E7CE8DF8FD0A2A098, 7BD74E9E3CB0A83D26BA3FD8177C6B9BA46A8695B6569CF7887FDC87947DA2D6 ] Intel® Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
15:31:01.0225 0x0490  Intel® Capability Licensing Service TCP IP Interface - ok
15:31:01.0319 0x0490  [ 441D5FAF24CC2EC115B654A55C52F0AF, 5BF5299DAD9A7076C43D68C70E02AEC8DBFD89C1AFDF7CD6AB95550EE25EEB36 ] Intel® Wireless Bluetooth® 4.0 Radio Management C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
15:31:01.0326 0x0490  Intel® Wireless Bluetooth® 4.0 Radio Management - ok
15:31:01.0346 0x0490  intelide - ok
15:31:01.0374 0x0490  intelpep - ok
15:31:01.0398 0x0490  intelppm - ok
15:31:01.0405 0x0490  iorate - ok
15:31:01.0428 0x0490  IpFilterDriver - ok
15:31:01.0478 0x0490  iphlpsvc - ok
15:31:01.0485 0x0490  IPMIDRV - ok
15:31:01.0494 0x0490  IPNAT - ok
15:31:01.0503 0x0490  irda - ok
15:31:01.0515 0x0490  IRENUM - ok
15:31:01.0548 0x0490  irmon - ok
15:31:01.0553 0x0490  isapnp - ok
15:31:01.0584 0x0490  iScsiPrt - ok
15:31:01.0611 0x0490  [ 48B904D31F2369D7B0122617038D3F5B, 8A43CB37667929CCCC37B6E79E82509BBCA6C8884B44059DC87BCA7C21BE7FE1 ] iwdbus          C:\WINDOWS\System32\drivers\iwdbus.sys
15:31:01.0613 0x0490  iwdbus - ok
15:31:01.0656 0x0490  [ 52069AEB42D3D0F97CBCA1085EBF55E6, ADB2EFFF563B3FE113FCD156FD1E469BC24FC1D68AFEDCA21306F76592C9FF88 ] jhi_service     C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
15:31:01.0660 0x0490  jhi_service - ok
15:31:01.0677 0x0490  kbdclass - ok
15:31:01.0700 0x0490  kbdhid - ok
15:31:01.0710 0x0490  kdnic - ok
15:31:01.0717 0x0490  KeyIso - ok
15:31:01.0737 0x0490  KSecDD - ok
15:31:01.0757 0x0490  KSecPkg - ok
15:31:01.0764 0x0490  ksthunk - ok
15:31:01.0775 0x0490  KtmRm - ok
15:31:01.0795 0x0490  LanmanServer - ok
15:31:01.0810 0x0490  LanmanWorkstation - ok
15:31:01.0861 0x0490  lfsvc - ok
15:31:01.0866 0x0490  LicenseManager - ok
15:31:01.0882 0x0490  lltdio - ok
15:31:01.0887 0x0490  lltdsvc - ok
15:31:01.0900 0x0490  lmhosts - ok
15:31:02.0019 0x0490  [ 3DE66F47365AA8CEB18B1EE272F4FEBA, 8DDD6AB4AEDE3B2FEA0D3B63DD24E3F3422D6ADE067756A3919FCED53C349167 ] LMS             C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
15:31:02.0027 0x0490  LMS - ok
15:31:02.0052 0x0490  LSI_SAS - ok
15:31:02.0069 0x0490  LSI_SAS2i - ok
15:31:02.0073 0x0490  LSI_SAS3i - ok
15:31:02.0090 0x0490  LSI_SSS - ok
15:31:02.0105 0x0490  LSM - ok
15:31:02.0110 0x0490  luafv - ok
15:31:02.0145 0x0490  MapsBroker - ok
15:31:02.0185 0x0490  megasas - ok
15:31:02.0243 0x0490  megasas2i - ok
15:31:02.0265 0x0490  megasr - ok
15:31:02.0311 0x0490  [ E0EF6C1399A9B1AAA0B28590411BED04, 10C193D1ED434A6DC2AD8C450012B9AF1C848A0A0B3B775F13495648FB77E009 ] MEIx64          C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys
15:31:02.0414 0x0490  MEIx64 - ok
15:31:02.0479 0x0490  MessagingService - ok
15:31:02.0517 0x0490  mlx4_bus - ok
15:31:02.0548 0x0490  MMCSS - ok
15:31:02.0567 0x0490  Modem - ok
15:31:02.0595 0x0490  monitor - ok
15:31:02.0641 0x0490  mouclass - ok
15:31:02.0660 0x0490  mouhid - ok
15:31:02.0669 0x0490  mountmgr - ok
15:31:02.0678 0x0490  mpsdrv - ok
15:31:02.0767 0x0490  MpsSvc - ok
15:31:02.0896 0x0490  MRxDAV - ok
15:31:02.0922 0x0490  mrxsmb - ok
15:31:02.0927 0x0490  mrxsmb10 - ok
15:31:02.0937 0x0490  mrxsmb20 - ok
15:31:02.0947 0x0490  MsBridge - ok
15:31:02.0960 0x0490  MSDTC - ok
15:31:02.0970 0x0490  Msfs - ok
15:31:03.0005 0x0490  msgpiowin32 - ok
15:31:03.0041 0x0490  mshidkmdf - ok
15:31:03.0052 0x0490  mshidumdf - ok
15:31:03.0056 0x0490  msisadrv - ok
15:31:03.0110 0x0490  MSiSCSI - ok
15:31:03.0115 0x0490  msiserver - ok
15:31:03.0119 0x0490  MSKSSRV - ok
15:31:03.0125 0x0490  MsLldp - ok
15:31:03.0159 0x0490  MSPCLOCK - ok
15:31:03.0163 0x0490  MSPQM - ok
15:31:03.0167 0x0490  MsRPC - ok
15:31:03.0196 0x0490  mssmbios - ok
15:31:03.0219 0x0490  MSTEE - ok
15:31:03.0224 0x0490  MTConfig - ok
15:31:03.0229 0x0490  Mup - ok
15:31:03.0235 0x0490  mvumis - ok
15:31:03.0271 0x0490  NativeWifiP - ok
15:31:03.0311 0x0490  NcaSvc - ok
15:31:03.0349 0x0490  NcbService - ok
15:31:03.0355 0x0490  NcdAutoSetup - ok
15:31:03.0396 0x0490  ndfltr - ok
15:31:03.0430 0x0490  NDIS - ok
15:31:03.0434 0x0490  NdisCap - ok
15:31:03.0439 0x0490  NdisImPlatform - ok
15:31:03.0459 0x0490  NdisTapi - ok
15:31:03.0463 0x0490  Ndisuio - ok
15:31:03.0468 0x0490  NdisVirtualBus - ok
15:31:03.0487 0x0490  NdisWan - ok
15:31:03.0492 0x0490  ndiswanlegacy - ok
15:31:03.0507 0x0490  ndproxy - ok
15:31:03.0511 0x0490  Ndu - ok
15:31:03.0540 0x0490  [ C3A9A4EDB8842884F888BE669834F3D1, D0F3C8500A9AD82149E82258258F55894662E70BFE7C73CA623DDF9BD059E2C4 ] Net Driver HPZ12 C:\Windows\System32\HPZinw12.dll
15:31:03.0547 0x0490  Net Driver HPZ12 - ok
15:31:03.0588 0x0490  [ EE00C544C025958AF50C7B199F3C8595, D774DB020D9C46D1AA0B2DB9FA2C36C4A9C38D904CC6929695321D32ACA0D4D1 ] Netaapl         C:\WINDOWS\System32\drivers\netaapl64.sys
15:31:03.0590 0x0490  Netaapl - ok
15:31:03.0594 0x0490  NetAdapterCx - ok
15:31:03.0598 0x0490  NetBIOS - ok
15:31:03.0604 0x0490  NetBT - ok
15:31:03.0609 0x0490  Netlogon - ok
15:31:03.0632 0x0490  Netman - ok
15:31:03.0644 0x0490  netprofm - ok
15:31:03.0678 0x0490  NetSetupSvc - ok
15:31:03.0745 0x0490  NetTcpPortSharing - ok
15:31:03.0928 0x0490  [ AA274535FD2CB470E671C7AF369C47EF, 37FF6CD81FFEE7E7ED7A424A625E1448A7B6403A960E092E76F5ED1EFEC07E0C ] NETwNe64        C:\WINDOWS\system32\DRIVERS\Netwew01.sys
15:31:03.0998 0x0490  NETwNe64 - ok
15:31:04.0038 0x0490  NgcCtnrSvc - ok
15:31:04.0071 0x0490  NgcSvc - ok
15:31:04.0097 0x0490  NlaSvc - ok
15:31:04.0124 0x0490  Npfs - ok
15:31:04.0171 0x0490  npsvctrig - ok
15:31:04.0187 0x0490  nsi - ok
15:31:04.0192 0x0490  nsiproxy - ok
15:31:04.0244 0x0490  NTFS - ok
15:31:04.0248 0x0490  Null - ok
15:31:04.0283 0x0490  nvraid - ok
15:31:04.0304 0x0490  nvstor - ok
15:31:04.0361 0x0490  [ EDEF3B2D77698F9FF8BD9A56D297638B, 5946EBF73187458C5C355A6ABDFF1E006C46E9DB120D52EF4E9D873E1197706E ] nvsvc           C:\windows\system32\nvvsvc.exe
15:31:05.0708 0x0490  nvsvc - ok
15:31:05.0839 0x0490  [ 249357999355A998AA94A3673C3367EB, D33A231EB1B09A838446CE7C4A057CF0DE7C1C62639703EB920BA554EB8A4E0B ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
15:31:05.0857 0x0490  nvUpdatusService - ok
15:31:06.0130 0x0490  OneSyncSvc - ok
15:31:06.0385 0x0490  [ 30B5F9FB0C35AE6B4A0851D24CE2EE8B, 0340E77E8EC2ADC21B8DDD9C9CC95B3F4BCAFD54618A333C72D7D9587D593B83 ] ose             C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
15:31:06.0387 0x0490  ose - ok
15:31:06.0456 0x0490  p2pimsvc - ok
15:31:06.0521 0x0490  p2psvc - ok
15:31:06.0557 0x0490  Parport - ok
15:31:06.0581 0x0490  partmgr - ok
15:31:06.0641 0x0490  PcaSvc - ok
15:31:06.0662 0x0490  pci - ok
15:31:06.0684 0x0490  pciide - ok
15:31:06.0695 0x0490  pcmcia - ok
15:31:06.0699 0x0490  pcw - ok
15:31:06.0730 0x0490  pdc - ok
15:31:06.0774 0x0490  PEAUTH - ok
15:31:06.0799 0x0490  percsas2i - ok
15:31:06.0803 0x0490  percsas3i - ok
15:31:07.0664 0x0490  PerfHost - ok
15:31:07.0712 0x0490  PhoneSvc - ok
15:31:07.0757 0x0490  PimIndexMaintenanceSvc - ok
15:31:07.0798 0x0490  pla - ok
15:31:07.0830 0x0490  PlugPlay - ok
15:31:07.0878 0x0490  [ C203F2064F6AEA4C902C86B1E40F3D1B, DA6846CC64299BFC8056A791394A0BE1F077E72429C78980FF035DD2F78ABF4E ] Pml Driver HPZ12 C:\Windows\System32\HPZipm12.dll
15:31:07.0888 0x0490  Pml Driver HPZ12 - ok
15:31:07.0910 0x0490  PNRPAutoReg - ok
15:31:07.0914 0x0490  PNRPsvc - ok
15:31:07.0944 0x0490  PolicyAgent - ok
15:31:07.0951 0x0490  Power - ok
15:31:08.0029 0x0490  PptpMiniport - ok
15:31:08.0593 0x0490  [ 7196D3C2E2E3129814C8DAB91F9A7D1E, 6763E4BF8E846B597E78778E520F5BADC95608BAA4EA0AC84971384B5D976DD7 ] PrintNotify     C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
15:31:08.0828 0x0490  PrintNotify - ok
15:31:08.0909 0x0490  Processor - ok
15:31:08.0956 0x0490  ProfSvc - ok
15:31:09.0005 0x0490  Psched - ok
15:31:09.0043 0x0490  QWAVE - ok
15:31:09.0065 0x0490  QWAVEdrv - ok
15:31:09.0122 0x0490  [ 194ED3C117525613E701FF257882303E, F9D771B573078C6335F352812E24918CB79529BAE2262117E8E0DD4C57AA64C1 ] RadioHIDMini    C:\WINDOWS\System32\drivers\RadioHIDMini.sys
15:31:09.0132 0x0490  RadioHIDMini - ok
15:31:09.0138 0x0490  RasAcd - ok
15:31:09.0170 0x0490  RasAgileVpn - ok
15:31:09.0214 0x0490  RasAuto - ok
15:31:09.0245 0x0490  Rasl2tp - ok
15:31:09.0279 0x0490  RasMan - ok
15:31:09.0298 0x0490  RasPppoe - ok
15:31:09.0336 0x0490  RasSstp - ok
15:31:09.0364 0x0490  rdbss - ok
15:31:09.0400 0x0490  rdpbus - ok
15:31:09.0404 0x0490  RDPDR - ok
15:31:09.0484 0x0490  RdpVideoMiniport - ok
15:31:09.0488 0x0490  rdyboost - ok
15:31:09.0493 0x0490  ReFSv1 - ok
15:31:09.0500 0x0490  RemoteAccess - ok
15:31:09.0532 0x0490  RemoteRegistry - ok
15:31:09.0581 0x0490  RetailDemo - ok
15:31:09.0690 0x0490  [ 9C3AC71A9934B884FAC567A8807E9C4D, 0B6B2970098E3C21E1E54A25785544903E8CD415B527FCEF86ABC7B33BEC83E7 ] Revoflt         C:\WINDOWS\system32\DRIVERS\revoflt.sys
15:31:09.0703 0x0490  Revoflt - ok
15:31:09.0736 0x0490  RFCOMM - ok
15:31:09.0778 0x0490  RmSvc - ok
15:31:09.0826 0x0490  RpcEptMapper - ok
15:31:09.0881 0x0490  RpcLocator - ok
15:31:09.0898 0x0490  RpcSs - ok
15:31:09.0926 0x0490  rspndr - ok
15:31:10.0517 0x0490  [ FA00B16D06217288AFD700223DA131BA, 90688C3A8403FEF2A90550781CBA932A522125B47D71F3F0AF73E21E43BC5564 ] rt640x64        C:\WINDOWS\System32\drivers\rt640x64.sys
15:31:10.0575 0x0490  rt640x64 - ok
15:31:10.0660 0x0490  s3cap - ok
15:31:10.0700 0x0490  SamSs - ok
15:31:10.0773 0x0490  sbp2port - ok
15:31:10.0810 0x0490  SCardSvr - ok
15:31:10.0851 0x0490  ScDeviceEnum - ok
15:31:10.0870 0x0490  scfilter - ok
15:31:10.0900 0x0490  Schedule - ok
15:31:10.0906 0x0490  scmbus - ok
15:31:10.0929 0x0490  scmdisk0101 - ok
15:31:10.0956 0x0490  SCPolicySvc - ok
15:31:10.0985 0x0490  sdbus - ok
15:31:11.0022 0x0490  SDRSVC - ok
15:31:11.0049 0x0490  sdstor - ok
15:31:11.0068 0x0490  seclogon - ok
15:31:11.0101 0x0490  SENS - ok
15:31:11.0107 0x0490  SensorDataService - ok
15:31:11.0141 0x0490  SensorService - ok
15:31:11.0164 0x0490  SensrSvc - ok
15:31:11.0173 0x0490  SerCx - ok
15:31:11.0180 0x0490  SerCx2 - ok
15:31:11.0200 0x0490  Serenum - ok
15:31:11.0228 0x0490  Serial - ok
15:31:11.0233 0x0490  sermouse - ok
15:31:11.0269 0x0490  SessionEnv - ok
15:31:11.0933 0x0490  [ E62DACE1C081A463B90BF8B76FA19514, 68C73A579B872988A75FFB42662C5D40D4BC343B34DE8178AA1EC5E0AB696217 ] Settings Launcher C:\Program Files (x86)\Samsung\Settings\CmdServer\SettingsLauncher.exe
15:31:11.0963 0x0490  Settings Launcher - ok
15:31:12.0005 0x0490  sfloppy - ok
15:31:12.0097 0x0490  SharedAccess - ok
15:31:12.0133 0x0490  ShellHWDetection - ok
15:31:12.0239 0x0490  shpamsvc - ok
15:31:12.0278 0x0490  SiSRaid2 - ok
15:31:12.0300 0x0490  SiSRaid4 - ok
15:31:12.0465 0x0490  [ 6749AD471D1D44CBD1F30257C861F77B, D5A554F35E380948F13BFE0673B49F8FD8AE5A438BF3645857522E2560A58685 ] SkypeUpdate     C:\Program Files (x86)\Skype\Updater\Updater.exe
15:31:12.0479 0x0490  SkypeUpdate - ok
15:31:12.0571 0x0490  smphost - ok
15:31:12.0605 0x0490  SmsRouter - ok
15:31:12.0647 0x0490  SNMPTRAP - ok
15:31:12.0706 0x0490  spaceport - ok
15:31:12.0744 0x0490  SpbCx - ok
15:31:12.0780 0x0490  Spooler - ok
15:31:12.0848 0x0490  sppsvc - ok
15:31:12.0876 0x0490  srv - ok
15:31:12.0921 0x0490  srv2 - ok
15:31:12.0961 0x0490  srvnet - ok
15:31:13.0023 0x0490  SSDPSRV - ok
15:31:13.0099 0x0490  SstpSvc - ok
15:31:13.0189 0x0490  [ 9B74226E10CD57E965F87014841016F9, 95C76049DBBF3B31A9B01CFD0EDAAC47DE9A1F096B61D05C47FB85E1AFC07288 ] ssudmdm         C:\WINDOWS\system32\DRIVERS\ssudmdm.sys
15:31:13.0209 0x0490  ssudmdm - ok
15:31:13.0283 0x0490  StateRepository - ok
15:31:13.0347 0x0490  stexstor - ok
15:31:13.0447 0x0490  stisvc - ok
15:31:13.0472 0x0490  storahci - ok
15:31:13.0499 0x0490  storflt - ok
15:31:13.0529 0x0490  stornvme - ok
15:31:13.0536 0x0490  storqosflt - ok
15:31:13.0613 0x0490  StorSvc - ok
15:31:13.0616 0x0490  storufs - ok
15:31:13.0621 0x0490  storvsc - ok
15:31:13.0665 0x0490  svsvc - ok
15:31:13.0690 0x0490  swenum - ok
15:31:13.0732 0x0490  swprv - ok
15:31:13.0911 0x0490  SWUpdateService - ok
15:31:13.0977 0x0490  Synth3dVsc - ok
15:31:14.0089 0x0490  [ 55CCD15CA1BFC41A07A58DAD29341720, B675C6C8B4DD5856B1D6996A6605834433F3B5C0B6C0EB1D91BA29CA2D75946B ] SynTP           C:\WINDOWS\system32\DRIVERS\SynTP.sys
15:31:14.0109 0x0490  SynTP - ok
15:31:14.0245 0x0490  [ 1046691BF93D89342190DA54DF437238, A1C0EDF4F6CAAEE304960813005AF3F06ADBE0C85C9447669D8FCE7B0F049CA0 ] SynTPEnhService C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
15:31:14.0302 0x0490  SynTPEnhService - ok
15:31:14.0422 0x0490  SysMain - ok
15:31:14.0518 0x0490  SystemEventsBroker - ok
15:31:14.0571 0x0490  TabletInputService - ok
15:31:14.0615 0x0490  TapiSrv - ok
15:31:14.0657 0x0490  Tcpip - ok
15:31:14.0663 0x0490  Tcpip6 - ok
15:31:14.0695 0x0490  tcpipreg - ok
15:31:14.0741 0x0490  tdx - ok
15:31:14.0746 0x0490  terminpt - ok
15:31:14.0793 0x0490  TermService - ok
15:31:14.0880 0x0490  Themes - ok
15:31:14.0995 0x0490  TieringEngineService - ok
15:31:15.0080 0x0490  tiledatamodelsvc - ok
15:31:15.0159 0x0490  TimeBrokerSvc - ok
15:31:15.0201 0x0490  TPM - ok
15:31:15.0238 0x0490  TrkWks - ok
15:31:15.0348 0x0490  TrustedInstaller - ok
15:31:15.0355 0x0490  tsusbflt - ok
15:31:15.0531 0x0490  TsUsbGD - ok
15:31:15.0538 0x0490  tunnel - ok
15:31:15.0600 0x0490  tzautoupdate - ok
15:31:15.0699 0x0490  UASPStor - ok
15:31:15.0704 0x0490  UcmCx0101 - ok
15:31:15.0720 0x0490  UcmTcpciCx0101 - ok
15:31:15.0742 0x0490  UcmUcsi - ok
15:31:15.0746 0x0490  Ucx01000 - ok
15:31:15.0761 0x0490  UdeCx - ok
15:31:15.0766 0x0490  udfs - ok
15:31:15.0790 0x0490  UEFI - ok
15:31:15.0794 0x0490  Ufx01000 - ok
15:31:15.0799 0x0490  UfxChipidea - ok
15:31:15.0808 0x0490  ufxsynopsys - ok
15:31:15.0905 0x0490  UI0Detect - ok
15:31:15.0944 0x0490  umbus - ok
15:31:15.0952 0x0490  UmPass - ok
15:31:15.0984 0x0490  UmRdpService - ok
15:31:16.0016 0x0490  UnistoreSvc - ok
15:31:16.0106 0x0490  upnphost - ok
15:31:16.0145 0x0490  UrsChipidea - ok
15:31:16.0197 0x0490  UrsCx01000 - ok
15:31:16.0212 0x0490  UrsSynopsys - ok
15:31:16.0292 0x0490  [ 8047D8AFA070A4C3B9FCBDBF77A84C45, D8B47716EE57391E3B9CBE3B35FF1F933F08E40B1C8C12EB5BE2438D9E409FF0 ] usb3Hub         C:\WINDOWS\System32\drivers\usb3Hub.sys
15:31:16.0325 0x0490  usb3Hub - ok
15:31:16.0365 0x0490  [ F957092C63CD71D85903CA0D8370F473, 4DEC2FC20329F248135DA24CB6694FD972DCCE8B1BBEA8D872FDE41939E96AAF ] USBAAPL64       C:\WINDOWS\System32\Drivers\usbaapl64.sys
15:31:16.0397 0x0490  USBAAPL64 - ok
15:31:16.0421 0x0490  usbccgp - ok
15:31:16.0488 0x0490  usbcir - ok
15:31:16.0674 0x0490  [ 635686E528F2C9CB916EC1BB04EE6AD1, 080A0F209773232860F510F17005EF92650BA831F69BB0006AEF11A2BB0A4906 ] UsbClientService C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe
15:31:16.0678 0x0490  UsbClientService - ok
15:31:16.0774 0x0490  usbehci - ok
15:31:16.0781 0x0490  usbhub - ok
15:31:16.0793 0x0490  USBHUB3 - ok
15:31:16.0807 0x0490  usbohci - ok
15:31:16.0846 0x0490  usbprint - ok
15:31:16.0886 0x0490  usbser - ok
15:31:16.0943 0x0490  USBSTOR - ok
15:31:16.0950 0x0490  usbuhci - ok
15:31:16.0998 0x0490  usbvideo - ok
15:31:17.0023 0x0490  USBXHCI - ok
15:31:17.0102 0x0490  UserDataSvc - ok
15:31:17.0204 0x0490  UserManager - ok
15:31:17.0256 0x0490  UsoSvc - ok
15:31:17.0261 0x0490  VaultSvc - ok
15:31:17.0266 0x0490  vdrvroot - ok
15:31:17.0300 0x0490  vds - ok
15:31:17.0352 0x0490  VerifierExt - ok
15:31:17.0460 0x0490  vhdmp - ok
15:31:17.0466 0x0490  vhf - ok
15:31:17.0487 0x0490  vmbus - ok
15:31:17.0491 0x0490  VMBusHID - ok
15:31:17.0528 0x0490  vmgid - ok
15:31:17.0568 0x0490  vmicguestinterface - ok
15:31:17.0572 0x0490  vmicheartbeat - ok
15:31:17.0577 0x0490  vmickvpexchange - ok
15:31:17.0634 0x0490  vmicrdv - ok
15:31:17.0638 0x0490  vmicshutdown - ok
15:31:17.0643 0x0490  vmictimesync - ok
15:31:17.0647 0x0490  vmicvmsession - ok
15:31:17.0651 0x0490  vmicvss - ok
15:31:17.0655 0x0490  volmgr - ok
15:31:17.0660 0x0490  volmgrx - ok
15:31:17.0665 0x0490  volsnap - ok
15:31:17.0677 0x0490  volume - ok
15:31:17.0711 0x0490  vpci - ok
15:31:17.0733 0x0490  vsmraid - ok
15:31:17.0751 0x0490  VSS - ok
15:31:17.0756 0x0490  VSTXRAID - ok
15:31:17.0792 0x0490  vwifibus - ok
15:31:17.0795 0x0490  vwififlt - ok
15:31:17.0828 0x0490  vwifimp - ok
15:31:17.0873 0x0490  W32Time - ok
15:31:17.0880 0x0490  WacomPen - ok
15:31:17.0969 0x0490  WalletService - ok
15:31:18.0036 0x0490  wanarp - ok
15:31:18.0045 0x0490  wanarpv6 - ok
15:31:18.0088 0x0490  wbengine - ok
15:31:18.0147 0x0490  WbioSrvc - ok
15:31:18.0184 0x0490  wcifs - ok
15:31:18.0228 0x0490  Wcmsvc - ok
15:31:18.0252 0x0490  wcncsvc - ok
15:31:18.0257 0x0490  wcnfs - ok
15:31:18.0265 0x0490  WdBoot - ok
15:31:18.0308 0x0490  [ D0335A55E5C3F812548E18300C2ACB62, 7EF7C3A21E97197E1A6D2956D0F5A7C23F2D590C9709708394426031634990A5 ] WDC_SAM         C:\WINDOWS\System32\drivers\wdcsam64.sys
15:31:18.0399 0x0490  WDC_SAM - ok
15:31:18.0404 0x0490  Wdf01000 - ok
15:31:18.0435 0x0490  WdFilter - ok
15:31:18.0472 0x0490  WdiServiceHost - ok
15:31:18.0477 0x0490  WdiSystemHost - ok
15:31:18.0529 0x0490  wdiwifi - ok
15:31:18.0535 0x0490  WdNisDrv - ok
15:31:18.0625 0x0490  WdNisSvc - ok
15:31:18.0659 0x0490  WebClient - ok
15:31:18.0671 0x0490  Wecsvc - ok
15:31:18.0701 0x0490  WEPHOSTSVC - ok
15:31:18.0722 0x0490  wercplsupport - ok
15:31:18.0731 0x0490  WerSvc - ok
15:31:18.0761 0x0490  WFPLWFS - ok
15:31:18.0772 0x0490  WiaRpc - ok
15:31:18.0814 0x0490  WIMMount - ok
15:31:18.0819 0x0490  WinDefend - ok
15:31:18.0870 0x0490  WindowsTrustedRT - ok
15:31:18.0875 0x0490  WindowsTrustedRTProxy - ok
15:31:18.0928 0x0490  WinHttpAutoProxySvc - ok
15:31:18.0972 0x0490  WinMad - ok
15:31:19.0203 0x0490  Winmgmt - ok
15:31:19.0248 0x0490  WinRM - ok
15:31:19.0305 0x0490  WINUSB - ok
15:31:19.0349 0x0490  WinVerbs - ok
15:31:19.0445 0x0490  wisvc - ok
15:31:19.0498 0x0490  WlanSvc - ok
15:31:19.0556 0x0490  wlidsvc - ok
15:31:19.0560 0x0490  WmiAcpi - ok
15:31:19.0685 0x0490  wmiApSrv - ok
15:31:19.0784 0x0490  WMPNetworkSvc - ok
15:31:19.0825 0x0490  Wof - ok
15:31:19.0921 0x0490  workfolderssvc - ok
15:31:20.0055 0x0490  WPDBusEnum - ok
15:31:20.0202 0x0490  WpdUpFltr - ok
15:31:20.0296 0x0490  WpnService - ok
15:31:20.0409 0x0490  WpnUserService - ok
15:31:20.0626 0x0490  [ 0FD43A503F1CA97E649391672BAA6FDB, 29762613DB3DB97007F39F99DDDAEE1C8CED14EE98732B16A676768B7D309DBE ] WRkrn           C:\WINDOWS\system32\drivers\WRkrn.sys
15:31:20.0809 0x0490  WRkrn - ok
15:31:20.0978 0x0490  [ 787A87114ADBD06B619525C21CAA3BB1, 65B6CFC0161EE18B6E51C78E5751401D5EDA15AF618DECA9022858B76191C77A ] WRSVC           C:\Program Files\Webroot\WRSA.exe
15:31:21.0020 0x0490  WRSVC - ok
15:31:21.0074 0x0490  [ F5BB6459A1289527434772FE74227BD0, 2A299FA91537ADCA475E2DC4DDD204B55FC00AE996A921C637CB7297E91F58C9 ] wrUrlFlt        C:\WINDOWS\system32\DRIVERS\wrUrlFlt.sys
15:31:21.0078 0x0490  wrUrlFlt - ok
15:31:21.0120 0x0490  ws2ifsl - ok
15:31:21.0168 0x0490  wscsvc - ok
15:31:21.0245 0x0490  WSDPrintDevice - ok
15:31:21.0291 0x0490  WSDScan - ok
15:31:21.0298 0x0490  WSearch - ok
15:31:21.0332 0x0490  wuauserv - ok
15:31:21.0335 0x0490  WudfPf - ok
15:31:21.0339 0x0490  WUDFRd - ok
15:31:21.0343 0x0490  wudfsvc - ok
15:31:21.0381 0x0490  WUDFWpdFs - ok
15:31:21.0429 0x0490  WwanSvc - ok
15:31:21.0525 0x0490  XblAuthManager - ok
15:31:21.0608 0x0490  XblGameSave - ok
15:31:21.0626 0x0490  xboxgip - ok
15:31:21.0664 0x0490  XboxNetApiSvc - ok
15:31:21.0724 0x0490  [ 24E57041608ED6A9D7FDAD0D9EC214E2, 895A16072F5EFFF57A7DCA21917540726BF816A2746EC47A066AAD363F69E5D7 ] XHCIPort        C:\WINDOWS\System32\drivers\XHCIPort.sys
15:31:21.0736 0x0490  XHCIPort - ok
15:31:21.0812 0x0490  xinputhid - ok
15:31:21.0822 0x0490  ZAMSvc - ok
15:31:21.0911 0x0490  [ 21E13F2CB269DEFEAE5E1D09887D47BB, 543991CA8D1C65113DFF039B85AE3F9A87F503DAEC30F46929FD454BC57E5A91 ] ZAM_Guard       C:\WINDOWS\System32\drivers\zamguard64.sys
15:31:21.0934 0x0490  ZAM_Guard - ok
15:31:21.0935 0x0490  ================ Scan global ===============================
15:31:22.0225 0x0490  [ Global ] - ok
15:31:22.0226 0x0490  ================ Scan MBR ==================================
15:31:22.0256 0x0490  [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
15:31:22.0287 0x0490  \Device\Harddisk0\DR0 - ok
15:31:22.0287 0x0490  ================ Scan VBR ==================================
15:31:22.0307 0x0490  [ 10C77173AD3157B86DE5509B2FFE6118 ] \Device\Harddisk0\DR0\Partition1
15:31:22.0343 0x0490  \Device\Harddisk0\DR0\Partition1 - ok
15:31:22.0358 0x0490  [ 653CB82D405165A45EB09EBEB6A70C24 ] \Device\Harddisk0\DR0\Partition2
15:31:22.0359 0x0490  \Device\Harddisk0\DR0\Partition2 - ok
15:31:22.0378 0x0490  [ 0F9952CE9A925B23FE6CF0ECC6CF5FBB ] \Device\Harddisk0\DR0\Partition3
15:31:22.0379 0x0490  \Device\Harddisk0\DR0\Partition3 - ok
15:31:22.0404 0x0490  [ 8ED77E370E2522F717966DBBF1E8DAC0 ] \Device\Harddisk0\DR0\Partition4
15:31:22.0414 0x0490  \Device\Harddisk0\DR0\Partition4 - ok
15:31:22.0457 0x0490  [ E80FAFC1614AE868E07070DB04172605 ] \Device\Harddisk0\DR0\Partition5
15:31:22.0481 0x0490  \Device\Harddisk0\DR0\Partition5 - ok
15:31:22.0538 0x0490  [ 347AE7E6D56AD689AFBEBF29AAFFA4A2 ] \Device\Harddisk0\DR0\Partition6
15:31:22.0590 0x0490  \Device\Harddisk0\DR0\Partition6 - ok
15:31:22.0675 0x0490  [ DB4DC5C433B767112032724B8E16605F ] \Device\Harddisk0\DR0\Partition7
15:31:22.0794 0x0490  \Device\Harddisk0\DR0\Partition7 - ok
15:31:22.0857 0x0490  [ 8A610D5E108F0334F431F37F107209AB ] \Device\Harddisk0\DR0\Partition8
15:31:22.0859 0x0490  \Device\Harddisk0\DR0\Partition8 - ok
15:31:22.0860 0x0490  ================ Scan generic autorun ======================
15:31:25.0953 0x0490  [ D0E9E2E198C8BA95297EF8C9D04865F1, 1889A66AEEEE1E9D80FB99E23AFBB23AF37044BAA8AE00070667D3B2E32AB804 ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
15:31:26.0347 0x0490  RtHDVCpl - ok
15:31:26.0479 0x0490  [ 4A0477ADCD07EC9D21257A2E456B16C5, CEF9C81730C12283A7600C3D921D89A62B14D1C46544B493F3AF7520DD2D1F79 ] C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe
15:31:26.0483 0x0490  IAStorIcon - ok
15:31:26.0564 0x0490  Adobe Reader Speed Launcher - ok
15:31:27.0207 0x0490  [ 048EA4B978851788E9F5E8E4F081DF7A, EB62719AC0DCC18FF056F2CD84438BF14B61E38F0619617C81961C6257BDFCEC ] C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
15:31:27.0246 0x0490  Adobe ARM - ok
15:31:27.0497 0x0490  [ 675768F27997468394AEF7A785ACD28C, A8549CAD3BA56D95612BA1087AB1A7E3805E774B3CF8EB605884CDC71195CA82 ] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe
15:31:27.0498 0x0490  Adobe Acrobat Speed Launcher - ok
15:31:27.0857 0x0490  [ 16AEDBEBD92D1ECBA79BCEB09ED90F32, EE63C6D772FFE1F6428EA49268B07D0DA1CE0733C2B20C141E4BA7BFD6AB56CC ] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe
15:31:27.0874 0x0490  Acrobat Assistant 8.0 - ok
15:31:28.0620 0x0490  [ 86F33213C450FED3C7E32F9473415E7E, 75F3B3739DD12D8B7F93BEA912B864BF8BAEFA061720A87CF1F55030334C2558 ] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
15:31:28.0640 0x0490  EEventManager - ok
15:31:29.0079 0x0490  [ 256912AE51F711E74603C79D3EC668E2, DB133AA902F77C9728C997BABE7BD994459449B6114D2410B61D329C09C67411 ] C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe
15:31:29.0094 0x0490  FUFAXRCV - ok
15:31:29.0510 0x0490  [ A96A03B2F861024EACC1BC25664FFFC9, 00CF3B8AD668DB305EF93A89381AAC7252779B380F8CD00F82BEEED65469590A ] C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe
15:31:29.0522 0x0490  FUFAXSTM - ok
15:31:29.0928 0x0490  Dropbox - ok
15:31:30.0462 0x0490  [ 787A87114ADBD06B619525C21CAA3BB1, 65B6CFC0161EE18B6E51C78E5751401D5EDA15AF618DECA9022858B76191C77A ] C:\Program Files\Webroot\WRSA.exe
15:31:30.0478 0x0490  WRSVC - ok
15:31:33.0670 0x0490  OneDriveSetup - ok
15:31:33.0672 0x0490  OneDriveSetup - ok
15:31:33.0675 0x0490  OneDriveSetup - ok
15:31:33.0939 0x0490  GoogleDriveSync - ok
15:31:34.0038 0x0490  WAB Migrate - ok
15:31:34.0042 0x0490  OneDriveSetup - ok
15:31:34.0043 0x0490  WAB Migrate - ok
15:31:34.0048 0x0490  OneDriveSetup - ok
15:31:34.0053 0x0490  GoogleDriveSync - ok
15:31:34.0403 0x0490  EPLTarget\P0000000000000001 - ok
15:31:34.0860 0x0490  [ 7C6D524C78A1722AD987B9E47AC1FEE2, FFDC6C92ABB547D0DCD2621EC423C755A78079B061A41FA1751A56799D1A79A5 ] C:\Users\James (Propia)\AppData\Local\Dropbox\Update\DropboxUpdate.exe
15:31:34.0938 0x0490  Dropbox Update - ok
15:31:35.0828 0x0490  [ 005B2B63719E6B3E8E2E1446A9278F8E, 0A34046B0205A2FEEE5E2867765D171D7BA420A1527E49472A35B484219BD377 ] C:\Users\James (Propia)\AppData\Roaming\Spotify\SpotifyWebHelper.exe
15:31:36.0122 0x0490  Spotify Web Helper - ok
15:31:36.0125 0x0490  WAB Migrate - ok
15:31:36.0128 0x0490  OneDriveSetup - ok
15:31:36.0132 0x0490  GoogleDriveSync - ok
15:31:37.0234 0x0490  [ 08DFA176E4FC0E63ACD8EC854449D2B0, B8CA204C3F318CD9D12F61CDDA5C66184A48D6206F019AD11DB2605FDBEB288D ] C:\Users\Priscilla\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
15:31:37.0469 0x0490  Spotify Web Helper - ok
15:31:37.0815 0x0490  [ 1D7DD340E13DF9585EABB849CFC3E11B, 31CCD9753402DC030C641214B4ECB48A757BCD9F427A143A88745C62EFF87766 ] C:\Users\Priscilla\AppData\Local\Microsoft\OneDrive\OneDrive.exe
15:31:37.0906 0x0490  OneDrive - ok
15:31:37.0908 0x0490  WAB Migrate - ok
15:31:37.0912 0x0490  GoogleDriveSync - ok
15:31:37.0953 0x0490  Uninstall C:\Users\james.WELLSIE\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64 - ok
15:31:37.0961 0x0490  Uninstall C:\Users\james.WELLSIE\AppData\Local\Microsoft\OneDrive\17.3.6281.1202 - ok
15:31:37.0969 0x0490  Uninstall C:\Users\james.WELLSIE\AppData\Local\Microsoft\OneDrive\17.3.6381.0405\amd64 - ok
15:31:37.0978 0x0490  Uninstall C:\Users\james.WELLSIE\AppData\Local\Microsoft\OneDrive\17.3.6381.0405 - ok
15:31:37.0979 0x0490  Waiting for KSN requests completion. In queue: 4
15:31:39.0453 0x0490  AV detected via SS2: Webroot SecureAnywhere, C:\Program Files\Webroot\WRSA.exe ( 9.0.13.50 ), 0x41000 ( enabled : updated )
15:31:39.0454 0x0490  AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x60100 ( disabled : updated )
15:31:39.0466 0x0490  Win FW state via NFP2: enabled ( trusted )
15:31:39.0611 0x0490  ============================================================
15:31:39.0611 0x0490  Scan finished
15:31:39.0611 0x0490  ============================================================
15:31:39.0633 0x2640  Detected object count: 0
15:31:39.0633 0x2640  Actual detected object count: 0





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users