Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Help | C0000135 The program can't start (frst log inside)


  • This topic is locked This topic is locked
4 replies to this topic

#1 nessbru23

nessbru23

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:10:38 PM

Posted 21 February 2017 - 10:43 AM

C0000135 The program can't start because %hs is missing. Try resintalling the program

Hello

i am trying to help a friend fix his computer And I am having problem described above.

i sew an old guide, I realized I needed to add the file frst log, so here it is:

 

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-02-2017
Ran by SYSTEM on MININT-1IFIE09 (21-02-2017 16:26:30)
Running from G:\
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11
Boot Mode: Recovery
Default: ControlSet001
ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16407296 2015-12-14] (Realtek Semiconductor)
HKLM\...\Run: [StartCN] => C:\Program Files\AMD\CNext\CNext\cnext.exe [4859592 2015-11-17] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2014-02-20] (Intel Corporation)
HKLM-x32\...\Run: [IObit Malware Fighter] => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [5893920 2015-11-12] (IObit)
Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 0003691486761231mcinstcleanup; C:\Windows\TEMP\000369~1.EXE [922152 2016-03-02] (McAfee, Inc.)
S2 AdvancedSystemCareService9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [827680 2015-11-04] (IObit)
S2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [355232 2015-08-08] (Intel Corporation)
S2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [882464 2015-11-04] (IObit)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2934048 2015-11-10] (IObit)
S2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [965776 2014-10-25] (@ByELDI)
S2 TrueKey; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [995800 2017-01-05] (McAfee, Inc.)
S2 TrueKeyScheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [16248 2017-01-05] (McAfee, Inc.)
S3 TrueKeyServiceHelper; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [86864 2017-01-05] (McAfee, Inc.)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 FileMonitor; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [23048 2015-03-25] (IObit)
S1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-12-14] (REALiX™)
S0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [31144 2015-12-14] (Intel Corporation)
S3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [179456 2015-12-14] (Intel Corporation)
S3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34848 2015-03-25] (IObit.com)
S3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [32936 2015-12-14] (Synaptics Incorporated)
S3 UrlFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [23016 2015-03-25] (IObit.com)
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-02-21 16:26 - 2017-02-21 16:26 - 00000000 ____D C:\FRST
2017-02-21 05:06 - 2017-02-21 05:07 - 00318110 _____ C:\Windows\ntbtlog.txt
2017-01-30 06:35 - 2017-01-30 06:36 - 00000000 ____D C:\Users\Sahar\Desktop\מבחנים
2017-01-25 17:10 - 2017-01-25 17:10 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2017-01-25 05:53 - 2017-01-05 10:55 - 00154856 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2017-01-25 05:53 - 2017-01-05 10:55 - 00095464 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2017-01-25 05:53 - 2017-01-05 10:52 - 01460736 _____ (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2017-01-25 05:53 - 2017-01-05 10:52 - 01212928 _____ (Microsoft Corporation) C:\Windows\System32\rpcrt4.dll
2017-01-25 05:53 - 2017-01-05 10:52 - 00730624 _____ (Microsoft Corporation) C:\Windows\System32\kerberos.dll
2017-01-25 05:53 - 2017-01-05 10:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\System32\adtschema.dll
2017-01-25 05:53 - 2017-01-05 10:52 - 00463872 _____ (Microsoft Corporation) C:\Windows\System32\certcli.dll
2017-01-25 05:53 - 2017-01-05 10:52 - 00345600 _____ (Microsoft Corporation) C:\Windows\System32\schannel.dll
2017-01-25 05:53 - 2017-01-05 10:52 - 00316928 _____ (Microsoft Corporation) C:\Windows\System32\msv1_0.dll
2017-01-25 05:53 - 2017-01-05 10:52 - 00312320 _____ (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2017-01-25 05:53 - 2017-01-05 10:52 - 00210432 _____ (Microsoft Corporation) C:\Windows\System32\wdigest.dll
2017-01-25 05:53 - 2017-01-05 10:52 - 00190464 _____ (Microsoft Corporation) C:\Windows\System32\rpchttp.dll
2017-01-25 05:53 - 2017-01-05 10:52 - 00146432 _____ (Microsoft Corporation) C:\Windows\System32\msaudite.dll
2017-01-25 05:53 - 2017-01-05 10:52 - 00135680 _____ (Microsoft Corporation) C:\Windows\System32\sspicli.dll
2017-01-25 05:53 - 2017-01-05 10:52 - 00123904 _____ (Microsoft Corporation) C:\Windows\System32\bcrypt.dll
2017-01-25 05:53 - 2017-01-05 10:52 - 00086528 _____ (Microsoft Corporation) C:\Windows\System32\TSpkg.dll
2017-01-25 05:53 - 2017-01-05 10:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\System32\msobjs.dll
2017-01-25 05:53 - 2017-01-05 10:52 - 00043520 _____ (Microsoft Corporation) C:\Windows\System32\cryptbase.dll
2017-01-25 05:53 - 2017-01-05 10:52 - 00028672 _____ (Microsoft Corporation) C:\Windows\System32\sspisrv.dll
2017-01-25 05:53 - 2017-01-05 10:52 - 00028160 _____ (Microsoft Corporation) C:\Windows\System32\secur32.dll
2017-01-25 05:53 - 2017-01-05 10:52 - 00022016 _____ (Microsoft Corporation) C:\Windows\System32\credssp.dll
2017-01-25 05:53 - 2017-01-05 09:43 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-01-25 05:53 - 2017-01-05 09:43 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-01-25 05:53 - 2017-01-05 09:43 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-01-25 05:53 - 2017-01-05 09:43 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-01-25 05:53 - 2017-01-05 09:43 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-01-25 05:53 - 2017-01-05 09:43 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-01-25 05:53 - 2017-01-05 09:43 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-01-25 05:53 - 2017-01-05 09:43 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-01-25 05:53 - 2017-01-05 09:43 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-01-25 05:53 - 2017-01-05 09:43 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-01-25 05:53 - 2017-01-05 09:43 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-01-25 05:53 - 2017-01-05 09:43 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-01-25 05:53 - 2017-01-05 09:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-01-25 05:53 - 2017-01-05 09:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-01-25 05:53 - 2017-01-05 09:43 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-01-25 05:53 - 2017-01-05 09:42 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-01-25 05:53 - 2017-01-05 09:32 - 00064000 _____ (Microsoft Corporation) C:\Windows\System32\auditpol.exe
2017-01-25 05:53 - 2017-01-05 09:25 - 00159744 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb.sys
2017-01-25 05:53 - 2017-01-05 09:24 - 00291328 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb10.sys
2017-01-25 05:53 - 2017-01-05 09:24 - 00129536 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb20.sys
2017-01-25 05:53 - 2017-01-05 09:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\System32\lsass.exe
2017-01-25 05:53 - 2017-01-05 09:23 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-01-25 05:53 - 2017-01-05 09:19 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-01-25 05:53 - 2016-11-21 10:12 - 00109568 _____ (Microsoft Corporation) C:\Windows\System32\hlink.dll
2017-01-25 05:53 - 2016-11-20 08:19 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hlink.dll
2017-01-25 05:53 - 2016-11-20 06:07 - 00467392 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2017-01-25 05:53 - 2016-11-17 08:41 - 00370920 _____ (Microsoft Corporation) C:\Windows\System32\clfs.sys
2017-01-25 05:53 - 2016-11-14 15:27 - 00394448 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2017-01-25 05:53 - 2016-11-14 14:39 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-01-25 05:53 - 2016-11-12 11:48 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2017-01-25 05:53 - 2016-11-12 11:48 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll
2017-01-25 05:53 - 2016-11-12 11:28 - 00066560 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2017-01-25 05:53 - 2016-11-12 11:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\System32\html.iec
2017-01-25 05:53 - 2016-11-12 11:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll
2017-01-25 05:53 - 2016-11-12 11:25 - 00576000 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2017-01-25 05:53 - 2016-11-12 11:25 - 00088064 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll
2017-01-25 05:53 - 2016-11-12 11:21 - 02896384 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2017-01-25 05:53 - 2016-11-12 11:15 - 00054784 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2017-01-25 05:53 - 2016-11-12 11:14 - 00034304 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2017-01-25 05:53 - 2016-11-12 11:09 - 00615936 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2017-01-25 05:53 - 2016-11-12 11:08 - 25759744 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2017-01-25 05:53 - 2016-11-12 11:08 - 00144384 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2017-01-25 05:53 - 2016-11-12 11:08 - 00114688 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe
2017-01-25 05:53 - 2016-11-12 11:07 - 00817664 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
2017-01-25 05:53 - 2016-11-12 11:07 - 00814080 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll
2017-01-25 05:53 - 2016-11-12 10:56 - 00968704 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
2017-01-25 05:53 - 2016-11-12 10:53 - 06049280 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2017-01-25 05:53 - 2016-11-12 10:52 - 00489984 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2017-01-25 05:53 - 2016-11-12 10:47 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-01-25 05:53 - 2016-11-12 10:41 - 00077824 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll
2017-01-25 05:53 - 2016-11-12 10:40 - 00107520 _____ (Microsoft Corporation) C:\Windows\System32\inseng.dll
2017-01-25 05:53 - 2016-11-12 10:35 - 00199680 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll
2017-01-25 05:53 - 2016-11-12 10:34 - 00092160 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2017-01-25 05:53 - 2016-11-12 10:31 - 00315392 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2017-01-25 05:53 - 2016-11-12 10:30 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-01-25 05:53 - 2016-11-12 10:29 - 00498688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-01-25 05:53 - 2016-11-12 10:29 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-01-25 05:53 - 2016-11-12 10:29 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-01-25 05:53 - 2016-11-12 10:28 - 00152064 _____ (Microsoft Corporation) C:\Windows\System32\occache.dll
2017-01-25 05:53 - 2016-11-12 10:27 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-01-25 05:53 - 2016-11-12 10:20 - 02287616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-01-25 05:53 - 2016-11-12 10:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-01-25 05:53 - 2016-11-12 10:19 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-01-25 05:53 - 2016-11-12 10:17 - 20302848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-01-25 05:53 - 2016-11-12 10:15 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-01-25 05:53 - 2016-11-12 10:14 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-01-25 05:53 - 2016-11-12 10:14 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-01-25 05:53 - 2016-11-12 10:14 - 00262144 _____ (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2017-01-25 05:53 - 2016-11-12 10:14 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-01-25 05:53 - 2016-11-12 10:11 - 00725504 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2017-01-25 05:53 - 2016-11-12 10:10 - 00806912 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2017-01-25 05:53 - 2016-11-12 10:08 - 02131456 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2017-01-25 05:53 - 2016-11-12 10:08 - 01359360 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
2017-01-25 05:53 - 2016-11-12 10:03 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-01-25 05:53 - 2016-11-12 09:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-01-25 05:53 - 2016-11-12 09:56 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-01-25 05:53 - 2016-11-12 09:52 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-01-25 05:53 - 2016-11-12 09:51 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-01-25 05:53 - 2016-11-12 09:49 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-01-25 05:53 - 2016-11-12 09:47 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-01-25 05:53 - 2016-11-12 09:41 - 15257088 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2017-01-25 05:53 - 2016-11-12 09:40 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-01-25 05:53 - 2016-11-12 09:38 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-01-25 05:53 - 2016-11-12 09:37 - 04608000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-01-25 05:53 - 2016-11-12 09:36 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-01-25 05:53 - 2016-11-12 09:36 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-01-25 05:53 - 2016-11-12 09:35 - 02920960 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2017-01-25 05:53 - 2016-11-12 09:21 - 13653504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-01-25 05:53 - 2016-11-12 09:20 - 01543680 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2017-01-25 05:53 - 2016-11-12 09:11 - 00800768 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2017-01-25 05:53 - 2016-11-12 09:05 - 02444800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-01-25 05:53 - 2016-11-12 09:02 - 01312256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-01-25 05:53 - 2016-11-12 09:02 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-01-25 05:53 - 2016-11-10 08:32 - 01009152 _____ (Microsoft Corporation) C:\Windows\System32\user32.dll
2017-01-25 05:53 - 2016-11-10 08:19 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2017-01-25 05:53 - 2016-11-09 08:41 - 00114408 _____ (Microsoft Corporation) C:\Windows\System32\consent.exe
2017-01-25 05:53 - 2016-11-09 08:33 - 03244032 _____ (Microsoft Corporation) C:\Windows\System32\msi.dll
2017-01-25 05:53 - 2016-11-09 08:33 - 01941504 _____ (Microsoft Corporation) C:\Windows\System32\authui.dll
2017-01-25 05:53 - 2016-11-09 08:33 - 00504320 _____ (Microsoft Corporation) C:\Windows\System32\msihnd.dll
2017-01-25 05:53 - 2016-11-09 08:33 - 00070144 _____ (Microsoft Corporation) C:\Windows\System32\appinfo.dll
2017-01-25 05:53 - 2016-11-09 08:33 - 00025088 _____ (Microsoft Corporation) C:\Windows\System32\msimsg.dll
2017-01-25 05:53 - 2016-11-09 08:33 - 00002048 _____ (Microsoft Corporation) C:\Windows\System32\tzres.dll
2017-01-25 05:53 - 2016-11-09 08:17 - 02365440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2017-01-25 05:53 - 2016-11-09 08:17 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2017-01-25 05:53 - 2016-11-09 08:17 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2017-01-25 05:53 - 2016-11-09 08:17 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2017-01-25 05:53 - 2016-11-09 08:17 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2017-01-25 05:53 - 2016-11-09 08:02 - 00128512 _____ (Microsoft Corporation) C:\Windows\System32\msiexec.exe
2017-01-25 05:53 - 2016-11-09 07:55 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2017-01-25 05:53 - 2016-11-06 08:33 - 00404992 _____ (Microsoft Corporation) C:\Windows\System32\gdi32.dll
2017-01-25 05:53 - 2016-11-06 08:16 - 00312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-01-25 05:53 - 2016-11-06 08:01 - 03219456 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys
2017-01-25 05:53 - 2016-11-02 07:36 - 00382696 _____ (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
2017-01-25 05:53 - 2016-11-02 07:32 - 00100864 _____ (Microsoft Corporation) C:\Windows\System32\fontsub.dll
2017-01-25 05:53 - 2016-11-02 07:32 - 00046080 _____ (Adobe Systems) C:\Windows\System32\atmlib.dll
2017-01-25 05:53 - 2016-11-02 07:32 - 00041472 _____ (Microsoft Corporation) C:\Windows\System32\lpk.dll
2017-01-25 05:53 - 2016-11-02 07:32 - 00014336 _____ (Microsoft Corporation) C:\Windows\System32\dciman32.dll
2017-01-25 05:53 - 2016-11-02 07:22 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2017-01-25 05:53 - 2016-11-02 07:16 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2017-01-25 05:53 - 2016-11-02 07:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2017-01-25 05:53 - 2016-11-02 07:16 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2017-01-25 05:53 - 2016-11-02 06:53 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2017-01-25 05:53 - 2016-10-27 07:20 - 00627712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2017-01-25 05:53 - 2016-10-15 07:31 - 00976896 _____ (Microsoft Corporation) C:\Windows\System32\inetcomm.dll
2017-01-25 05:53 - 2016-10-15 07:31 - 00084480 _____ (Microsoft Corporation) C:\Windows\System32\INETRES.dll
2017-01-25 05:53 - 2016-10-15 07:13 - 00741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2017-01-25 05:53 - 2016-10-15 07:13 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll
2017-01-25 05:53 - 2016-10-11 07:40 - 00631176 _____ (Microsoft Corporation) C:\Windows\System32\winresume.efi
2017-01-25 05:53 - 2016-10-11 07:37 - 05547752 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2017-01-25 05:53 - 2016-10-11 07:37 - 00706792 _____ (Microsoft Corporation) C:\Windows\System32\winload.efi
2017-01-25 05:53 - 2016-10-11 07:34 - 01732864 _____ (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2017-01-25 05:53 - 2016-10-11 07:32 - 00503808 _____ (Microsoft Corporation) C:\Windows\System32\srcore.dll
2017-01-25 05:53 - 2016-10-11 07:32 - 00362496 _____ (Microsoft Corporation) C:\Windows\System32\wow64win.dll
2017-01-25 05:53 - 2016-10-11 07:32 - 00243712 _____ (Microsoft Corporation) C:\Windows\System32\wow64.dll
2017-01-25 05:53 - 2016-10-11 07:32 - 00215552 _____ (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2017-01-25 05:53 - 2016-10-11 07:32 - 00069120 _____ (Microsoft Corporation) C:\Windows\System32\nlsbres.dll
2017-01-25 05:53 - 2016-10-11 07:32 - 00063488 _____ (Microsoft Corporation) C:\Windows\System32\setbcdlocale.dll
2017-01-25 05:53 - 2016-10-11 07:32 - 00050176 _____ (Microsoft Corporation) C:\Windows\System32\srclient.dll
2017-01-25 05:53 - 2016-10-11 07:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll
2017-01-25 05:53 - 2016-10-11 07:32 - 00013312 _____ (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 01163264 _____ (Microsoft Corporation) C:\Windows\System32\kernel32.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 01148416 _____ (Microsoft Corporation) C:\Windows\System32\IMJP10.IME
2017-01-25 05:53 - 2016-10-11 07:31 - 01068544 _____ (Microsoft Corporation) C:\Windows\System32\msctf.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00880640 _____ (Microsoft Corporation) C:\Windows\System32\advapi32.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00878080 _____ (Microsoft Corporation) C:\Windows\System32\IMJP10K.DLL
2017-01-25 05:53 - 2016-10-11 07:31 - 00457216 _____ (Microsoft Corporation) C:\Windows\System32\imkr80.ime
2017-01-25 05:53 - 2016-10-11 07:31 - 00419840 _____ (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00246784 _____ (Microsoft Corporation) C:\Windows\System32\input.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00176128 _____ (Microsoft Corporation) C:\Windows\System32\tintlgnt.ime
2017-01-25 05:53 - 2016-10-11 07:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\System32\quick.ime
2017-01-25 05:53 - 2016-10-11 07:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\System32\qintlgnt.ime
2017-01-25 05:53 - 2016-10-11 07:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\System32\phon.ime
2017-01-25 05:53 - 2016-10-11 07:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\System32\cintlgnt.ime
2017-01-25 05:53 - 2016-10-11 07:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\System32\chajei.ime
2017-01-25 05:53 - 2016-10-11 07:31 - 00132608 _____ (Microsoft Corporation) C:\Windows\System32\pintlgnt.ime
2017-01-25 05:53 - 2016-10-11 07:31 - 00059904 _____ (Microsoft Corporation) C:\Windows\System32\appidapi.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00044032 _____ (Microsoft Corporation) C:\Windows\System32\csrsrv.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00034816 _____ (Microsoft Corporation) C:\Windows\System32\appidsvc.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\System32\apisetschema.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00006144 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00005120 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:24 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-01-25 05:53 - 2016-10-11 07:24 - 03944680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-01-25 05:53 - 2016-10-11 07:21 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 01027584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10.IME
2017-01-25 05:53 - 2016-10-11 07:18 - 00829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
2017-01-25 05:53 - 2016-10-11 07:18 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00430080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imkr80.ime
2017-01-25 05:53 - 2016-10-11 07:18 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00202240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\input.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tintlgnt.ime
2017-01-25 05:53 - 2016-10-11 07:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quick.ime
2017-01-25 05:53 - 2016-10-11 07:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qintlgnt.ime
2017-01-25 05:53 - 2016-10-11 07:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\phon.ime
2017-01-25 05:53 - 2016-10-11 07:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cintlgnt.ime
2017-01-25 05:53 - 2016-10-11 07:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\chajei.ime
2017-01-25 05:53 - 2016-10-11 07:18 - 00090112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pintlgnt.ime
2017-01-25 05:53 - 2016-10-11 07:18 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlsbres.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 07:03 - 00148480 _____ (Microsoft Corporation) C:\Windows\System32\appidpolicyconverter.exe
2017-01-25 05:53 - 2016-10-11 07:03 - 00062464 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\appid.sys
2017-01-25 05:53 - 2016-10-11 07:03 - 00017920 _____ (Microsoft Corporation) C:\Windows\System32\appidcertstorecheck.exe
2017-01-25 05:53 - 2016-10-11 06:59 - 00338432 _____ (Microsoft Corporation) C:\Windows\System32\conhost.exe
2017-01-25 05:53 - 2016-10-11 06:59 - 00296960 _____ (Microsoft Corporation) C:\Windows\System32\rstrui.exe
2017-01-25 05:53 - 2016-10-11 06:55 - 00346112 _____ (Microsoft Corporation) C:\Windows\System32\bcdedit.exe
2017-01-25 05:53 - 2016-10-11 06:55 - 00112640 _____ (Microsoft Corporation) C:\Windows\System32\smss.exe
2017-01-25 05:53 - 2016-10-11 06:51 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-01-25 05:53 - 2016-10-11 06:51 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-01-25 05:53 - 2016-10-11 06:51 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-01-25 05:53 - 2016-10-11 06:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-01-25 05:53 - 2016-10-11 06:50 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 06:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-01-25 05:53 - 2016-10-11 05:33 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2017-01-25 05:53 - 2016-10-11 05:18 - 00419648 _____ C:\Windows\SysWOW64\locale.nls
2017-01-25 05:53 - 2016-10-11 05:17 - 00419648 _____ C:\Windows\System32\locale.nls
2017-01-25 05:53 - 2016-10-11 05:06 - 00221184 _____ (Microsoft Corporation) C:\Windows\System32\UIAnimation.dll
2017-01-25 05:53 - 2016-10-08 05:06 - 00633296 _____ (Microsoft Corporation) C:\Windows\System32\winload.exe
2017-01-25 05:53 - 2016-10-07 07:32 - 03649536 _____ (Microsoft Corporation) C:\Windows\System32\MSVidCtl.dll
2017-01-25 05:53 - 2016-10-07 07:32 - 00877056 _____ (Microsoft Corporation) C:\Windows\System32\oleaut32.dll
2017-01-25 05:53 - 2016-10-07 07:32 - 00084992 _____ (Microsoft Corporation) C:\Windows\System32\asycfilt.dll
2017-01-25 05:53 - 2016-10-07 07:12 - 02291712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll
2017-01-25 05:53 - 2016-10-07 07:12 - 00581632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2017-01-25 05:53 - 2016-10-07 07:12 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2017-01-25 05:53 - 2016-10-05 06:54 - 00090112 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\bowser.sys
2017-01-25 05:53 - 2016-10-04 07:31 - 01483264 _____ (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2017-01-25 05:53 - 2016-10-04 07:31 - 00229376 _____ (Microsoft Corporation) C:\Windows\System32\wintrust.dll
2017-01-25 05:53 - 2016-10-04 07:31 - 00190976 _____ (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2017-01-25 05:53 - 2016-10-04 07:31 - 00141824 _____ (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2017-01-25 05:53 - 2016-10-04 07:13 - 01176064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2017-01-25 05:53 - 2016-10-04 07:13 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2017-01-25 05:53 - 2016-10-04 07:13 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2017-01-25 05:53 - 2016-10-04 07:13 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2017-01-25 05:53 - 2016-09-15 06:56 - 00041984 _____ (Microsoft Corporation) C:\Windows\System32\UtcResources.dll
2017-01-25 05:53 - 2016-09-12 13:08 - 00107520 _____ (Microsoft Corporation) C:\Windows\System32\adsmsext.dll
2017-01-25 05:53 - 2016-09-12 12:49 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adsmsext.dll
2017-01-25 05:53 - 2016-09-12 11:08 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2017-01-25 05:53 - 2016-09-12 10:43 - 01648128 _____ (Microsoft Corporation) C:\Windows\System32\DWrite.dll
2017-01-25 05:53 - 2016-09-12 10:43 - 01180160 _____ (Microsoft Corporation) C:\Windows\System32\FntCache.dll
2017-01-25 05:53 - 2016-09-09 10:20 - 00756736 _____ (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2017-01-25 05:53 - 2016-09-09 10:00 - 00497152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2017-01-25 05:53 - 2016-09-08 12:34 - 00263680 _____ (Microsoft Corporation) C:\Windows\System32\WebClnt.dll
2017-01-25 05:53 - 2016-09-08 12:34 - 00208896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2017-01-25 05:53 - 2016-09-08 12:34 - 00108544 _____ (Microsoft Corporation) C:\Windows\System32\davclnt.dll
2017-01-25 05:53 - 2016-09-08 12:34 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2017-01-25 05:53 - 2016-09-08 06:55 - 00142336 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxdav.sys
2017-01-25 05:53 - 2016-09-08 06:55 - 00106496 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\dfsc.sys
2017-01-25 05:53 - 2016-08-22 08:19 - 01386496 _____ (Microsoft Corporation) C:\Windows\System32\diagtrack.dll
2017-01-25 05:53 - 2016-08-12 09:02 - 14632960 _____ (Microsoft Corporation) C:\Windows\System32\wmp.dll
2017-01-25 05:53 - 2016-08-12 09:02 - 12574720 _____ (Microsoft Corporation) C:\Windows\System32\wmploc.DLL
2017-01-25 05:53 - 2016-08-12 09:02 - 00009728 _____ (Microsoft Corporation) C:\Windows\System32\spwmp.dll
2017-01-25 05:53 - 2016-08-12 09:02 - 00005120 _____ (Microsoft Corporation) C:\Windows\System32\msdxm.ocx
2017-01-25 05:53 - 2016-08-12 09:02 - 00005120 _____ (Microsoft Corporation) C:\Windows\System32\dxmasf.dll
2017-01-25 05:53 - 2016-08-12 08:47 - 12574208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2017-01-25 05:53 - 2016-08-12 08:47 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2017-01-25 05:53 - 2016-08-12 08:31 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2017-01-25 05:53 - 2016-08-12 08:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2017-01-25 05:53 - 2016-08-12 08:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2017-01-25 05:53 - 2016-08-12 08:26 - 00461312 _____ (Microsoft Corporation) C:\Windows\System32\scavengeui.dll
2017-01-25 05:53 - 2016-08-06 07:31 - 02023424 _____ (Microsoft Corporation) C:\Windows\System32\WsmSvc.dll
2017-01-25 05:53 - 2016-08-06 07:31 - 00347136 _____ (Microsoft Corporation) C:\Windows\System32\WSManMigrationPlugin.dll
2017-01-25 05:53 - 2016-08-06 07:31 - 00310784 _____ (Microsoft Corporation) C:\Windows\System32\WsmWmiPl.dll
2017-01-25 05:53 - 2016-08-06 07:31 - 00182272 _____ (Microsoft Corporation) C:\Windows\System32\WsmAuto.dll
2017-01-25 05:53 - 2016-08-06 07:31 - 00054272 _____ (Microsoft Corporation) C:\Windows\System32\WsmRes.dll
2017-01-25 05:53 - 2016-08-06 07:31 - 00012800 _____ (Microsoft Corporation) C:\Windows\System32\wsmplpxy.dll
2017-01-25 05:53 - 2016-08-06 07:15 - 01178112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2017-01-25 05:53 - 2016-08-06 07:15 - 00249344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2017-01-25 05:53 - 2016-08-06 07:15 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2017-01-25 05:53 - 2016-08-06 07:15 - 00146944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2017-01-25 05:53 - 2016-08-06 07:15 - 00054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmRes.dll
2017-01-25 05:53 - 2016-08-06 07:01 - 00266752 _____ (Microsoft Corporation) C:\Windows\System32\WSManHTTPConfig.exe
2017-01-25 05:53 - 2016-08-06 07:01 - 00013824 _____ (Microsoft Corporation) C:\Windows\System32\wsmprovhost.exe
2017-01-25 05:53 - 2016-08-06 06:53 - 00199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2017-01-25 05:53 - 2016-08-06 06:53 - 00012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmprovhost.exe
2017-01-25 05:53 - 2016-08-06 06:53 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmplpxy.dll
2017-01-25 05:53 - 2016-06-14 09:21 - 00094440 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mountmgr.sys
2017-01-25 05:53 - 2016-06-14 09:16 - 04121600 _____ (Microsoft Corporation) C:\Windows\System32\mf.dll
2017-01-25 05:53 - 2016-06-14 09:16 - 01573888 _____ (Microsoft Corporation) C:\Windows\System32\quartz.dll
2017-01-25 05:53 - 2016-06-14 09:16 - 01202176 _____ (Microsoft Corporation) C:\Windows\System32\drmv2clt.dll
2017-01-25 05:53 - 2016-06-14 09:16 - 01068544 _____ (Microsoft Corporation) C:\Windows\System32\cryptui.dll
2017-01-25 05:53 - 2016-06-14 09:16 - 00842240 _____ (Microsoft Corporation) C:\Windows\System32\blackbox.dll
2017-01-25 05:53 - 2016-06-14 09:16 - 00782848 _____ (Microsoft Corporation) C:\Windows\System32\wmdrmsdk.dll
2017-01-25 05:53 - 2016-06-14 09:16 - 00680448 _____ (Microsoft Corporation) C:\Windows\System32\audiosrv.dll
2017-01-25 05:53 - 2016-06-14 09:16 - 00641024 _____ (Microsoft Corporation) C:\Windows\System32\msscp.dll
2017-01-25 05:53 - 2016-06-14 09:16 - 00632320 _____ (Microsoft Corporation) C:\Windows\System32\evr.dll
2017-01-25 05:53 - 2016-06-14 09:16 - 00499712 _____ (Microsoft Corporation) C:\Windows\System32\AUDIOKSE.dll
2017-01-25 05:53 - 2016-06-14 09:16 - 00497664 _____ (Microsoft Corporation) C:\Windows\System32\drmmgrtn.dll
2017-01-25 05:53 - 2016-06-14 09:16 - 00440320 _____ (Microsoft Corporation) C:\Windows\System32\AudioEng.dll
2017-01-25 05:53 - 2016-06-14 09:16 - 00433152 _____ (Microsoft Corporation) C:\Windows\System32\mfplat.dll
2017-01-25 05:53 - 2016-06-14 09:16 - 00371712 _____ (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2017-01-25 05:53 - 2016-06-14 09:16 - 00325632 _____ (Microsoft Corporation) C:\Windows\System32\msnetobj.dll
2017-01-25 05:53 - 2016-06-14 09:16 - 00295936 _____ (Microsoft Corporation) C:\Windows\System32\AudioSes.dll
2017-01-25 05:53 - 2016-06-14 09:16 - 00284672 _____ (Microsoft Corporation) C:\Windows\System32\EncDump.dll
2017-01-25 05:53 - 2016-06-14 09:16 - 00206848 _____ (Microsoft Corporation) C:\Windows\System32\mfps.dll
2017-01-25 05:53 - 2016-06-14 09:16 - 00187904 _____ (Microsoft Corporation) C:\Windows\System32\pcasvc.dll
2017-01-25 05:53 - 2016-06-14 09:16 - 00081920 _____ (Microsoft Corporation) C:\Windows\System32\cryptsp.dll
2017-01-25 05:53 - 2016-06-14 09:16 - 00037376 _____ (Microsoft Corporation) C:\Windows\System32\pcadm.dll
2017-01-25 05:53 - 2016-06-14 09:16 - 00011264 _____ (Microsoft Corporation) C:\Windows\System32\msmmsp.dll
2017-01-25 05:53 - 2016-06-14 09:16 - 00008704 _____ (Microsoft Corporation) C:\Windows\System32\pcaevts.dll
2017-01-25 05:53 - 2016-06-14 09:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\System32\mferror.dll
2017-01-25 05:53 - 2016-06-14 09:11 - 00663552 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\PEAuth.sys
2017-01-25 05:53 - 2016-06-14 07:21 - 03209216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2017-01-25 05:53 - 2016-06-14 07:21 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2017-01-25 05:53 - 2016-06-14 07:21 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2017-01-25 05:53 - 2016-06-14 07:21 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2017-01-25 05:53 - 2016-06-14 07:21 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2017-01-25 05:53 - 2016-06-14 07:21 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2017-01-25 05:53 - 2016-06-14 07:21 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2017-01-25 05:53 - 2016-06-14 07:21 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2017-01-25 05:53 - 2016-06-14 07:21 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2017-01-25 05:53 - 2016-06-14 07:21 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2017-01-25 05:53 - 2016-06-14 07:21 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2017-01-25 05:53 - 2016-06-14 07:21 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2017-01-25 05:53 - 2016-06-14 07:21 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2017-01-25 05:53 - 2016-06-14 07:21 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2017-01-25 05:53 - 2016-06-14 07:21 - 00195072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2017-01-25 05:53 - 2016-06-14 07:21 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2017-01-25 05:53 - 2016-06-14 07:21 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2017-01-25 05:53 - 2016-06-14 07:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2017-01-25 05:53 - 2016-06-14 07:15 - 00125952 _____ (Microsoft Corporation) C:\Windows\System32\audiodg.exe
2017-01-25 05:53 - 2016-06-14 07:15 - 00055808 _____ (Microsoft Corporation) C:\Windows\System32\rrinstaller.exe
2017-01-25 05:53 - 2016-06-14 07:15 - 00024576 _____ (Microsoft Corporation) C:\Windows\System32\mfpmp.exe
2017-01-25 05:53 - 2016-06-14 07:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2017-01-25 05:53 - 2016-06-14 07:05 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2017-01-25 05:53 - 2016-06-14 07:00 - 00011264 _____ (Microsoft Corporation) C:\Windows\System32\pcawrk.exe
2017-01-25 05:53 - 2016-06-14 07:00 - 00009728 _____ (Microsoft Corporation) C:\Windows\System32\pcalua.exe
2017-01-25 05:47 - 2016-09-12 13:17 - 00077032 _____ (Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
2017-01-25 05:47 - 2016-09-12 13:08 - 01226752 _____ (Microsoft Corporation) C:\Windows\System32\aeinv.dll
2017-01-25 05:47 - 2016-09-09 07:54 - 01629184 _____ (Microsoft Corporation) C:\Windows\System32\appraiser.dll
2017-01-25 05:47 - 2016-09-09 07:54 - 00586752 _____ (Microsoft Corporation) C:\Windows\System32\generaltel.dll
2017-01-25 05:47 - 2016-09-09 07:54 - 00575488 _____ (Microsoft Corporation) C:\Windows\System32\devinv.dll
2017-01-25 05:47 - 2016-09-09 07:54 - 00314368 _____ (Microsoft Corporation) C:\Windows\System32\invagent.dll
2017-01-25 05:47 - 2016-09-09 07:54 - 00273408 _____ (Microsoft Corporation) C:\Windows\System32\centel.dll
2017-01-25 05:47 - 2016-09-09 07:54 - 00224256 _____ (Microsoft Corporation) C:\Windows\System32\aepic.dll
2017-01-25 05:47 - 2016-09-09 07:54 - 00129024 _____ (Microsoft Corporation) C:\Windows\System32\acmigration.dll
2017-01-25 03:30 - 2016-08-16 12:40 - 00343552 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbhub.sys
2017-01-25 03:30 - 2016-08-16 12:40 - 00327168 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbport.sys
2017-01-25 03:30 - 2016-08-16 12:40 - 00099840 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbccgp.sys
2017-01-25 03:30 - 2016-08-16 12:40 - 00056320 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbehci.sys
2017-01-25 03:30 - 2016-08-16 12:40 - 00030720 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbuhci.sys
2017-01-25 03:30 - 2016-08-16 12:40 - 00025600 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbohci.sys
2017-01-25 03:30 - 2016-08-16 12:40 - 00007808 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbd.sys
2017-01-25 03:19 - 2016-07-22 06:58 - 00142336 _____ (Microsoft Corporation) C:\Windows\System32\poqexec.exe
2017-01-25 03:19 - 2016-07-22 06:51 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2017-01-24 17:18 - 2017-01-24 17:18 - 00282032 _____ C:\Windows\Minidump\012517-56784-01.dmp
2017-01-24 17:17 - 2017-01-24 17:17 - 1004448219 ____N C:\Windows\MEMORY.DMP

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-02-20 16:56 - 2016-10-15 23:15 - 00000000 ____D C:\Program Files\TrueKey
2017-02-20 16:54 - 2015-12-14 16:29 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2017-02-20 16:35 - 2015-12-15 15:00 - 00000000 ____D C:\Program Files (x86)\Steam
2017-02-20 14:04 - 2009-07-13 20:45 - 00021472 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-02-20 14:04 - 2009-07-13 20:45 - 00021472 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-02-13 02:48 - 2015-12-22 10:30 - 00408372 _____ C:\Windows\System32\perfh011.dat
2017-02-13 02:48 - 2015-12-22 10:30 - 00121758 _____ C:\Windows\System32\perfc011.dat
2017-02-13 02:48 - 2015-12-22 10:25 - 00501008 _____ C:\Windows\System32\perfh006.dat
2017-02-13 02:48 - 2015-12-22 10:25 - 00098316 _____ C:\Windows\System32\perfc006.dat
2017-02-13 02:48 - 2015-12-22 09:59 - 00389936 _____ C:\Windows\System32\prfh0404.dat
2017-02-13 02:48 - 2015-12-22 09:59 - 00114748 _____ C:\Windows\System32\prfc0404.dat
2017-02-13 02:48 - 2015-12-22 09:46 - 00705474 _____ C:\Windows\System32\prfh0416.dat
2017-02-13 02:48 - 2015-12-22 09:46 - 00147314 _____ C:\Windows\System32\prfc0416.dat
2017-02-13 02:48 - 2015-12-22 09:37 - 00720612 _____ C:\Windows\System32\prfh0816.dat
2017-02-13 02:48 - 2015-12-22 09:37 - 00152564 _____ C:\Windows\System32\prfc0816.dat
2017-02-13 02:48 - 2015-12-22 09:33 - 00731952 _____ C:\Windows\System32\perfh015.dat
2017-02-13 02:48 - 2015-12-22 09:33 - 00155530 _____ C:\Windows\System32\perfc015.dat
2017-02-13 02:48 - 2015-12-22 09:29 - 00648276 _____ C:\Windows\System32\perfh01F.dat
2017-02-13 02:48 - 2015-12-22 09:29 - 00139658 _____ C:\Windows\System32\perfc01F.dat
2017-02-13 02:48 - 2015-12-22 09:14 - 00372764 _____ C:\Windows\System32\prfh0804.dat
2017-02-13 02:48 - 2015-12-22 09:14 - 00119250 _____ C:\Windows\System32\prfc0804.dat
2017-02-13 02:48 - 2015-12-22 08:53 - 00715782 _____ C:\Windows\System32\perfh019.dat
2017-02-13 02:48 - 2015-12-22 08:53 - 00150444 _____ C:\Windows\System32\perfc019.dat
2017-02-13 02:48 - 2015-12-22 08:49 - 00486108 _____ C:\Windows\System32\perfh014.dat
2017-02-13 02:48 - 2015-12-22 08:49 - 00095062 _____ C:\Windows\System32\perfc014.dat
2017-02-13 02:48 - 2015-12-22 08:42 - 00598582 _____ C:\Windows\System32\perfh008.dat
2017-02-13 02:48 - 2015-12-22 08:42 - 00110786 _____ C:\Windows\System32\perfc008.dat
2017-02-13 02:48 - 2015-12-22 08:36 - 00655314 _____ C:\Windows\System32\perfh01D.dat
2017-02-13 02:48 - 2015-12-22 08:36 - 00142132 _____ C:\Windows\System32\perfc01D.dat
2017-02-13 02:48 - 2015-12-22 08:32 - 00420018 _____ C:\Windows\System32\perfh012.dat
2017-02-13 02:48 - 2015-12-22 08:32 - 00120042 _____ C:\Windows\System32\perfc012.dat
2017-02-13 02:48 - 2015-12-22 08:28 - 00660434 _____ C:\Windows\System32\perfh005.dat
2017-02-13 02:48 - 2015-12-22 08:28 - 00141084 _____ C:\Windows\System32\perfc005.dat
2017-02-13 02:48 - 2015-12-22 08:12 - 00735092 _____ C:\Windows\System32\perfh013.dat
2017-02-13 02:48 - 2015-12-22 08:12 - 00152760 _____ C:\Windows\System32\perfc013.dat
2017-02-13 02:48 - 2015-12-22 03:00 - 00473096 _____ C:\Windows\System32\perfh00B.dat
2017-02-13 02:48 - 2015-12-22 03:00 - 00101178 _____ C:\Windows\System32\perfc00B.dat
2017-02-13 02:48 - 2015-12-22 02:57 - 00675348 _____ C:\Windows\System32\perfh00E.dat
2017-02-13 02:48 - 2015-12-22 02:57 - 00170932 _____ C:\Windows\System32\perfc00E.dat
2017-02-13 02:48 - 2015-12-22 02:52 - 00737050 _____ C:\Windows\System32\perfh00A.dat
2017-02-13 02:48 - 2015-12-22 02:52 - 00158132 _____ C:\Windows\System32\perfc00A.dat
2017-02-13 02:48 - 2015-12-22 02:47 - 00731640 _____ C:\Windows\System32\perfh010.dat
2017-02-13 02:48 - 2015-12-22 02:47 - 00146504 _____ C:\Windows\System32\perfc010.dat
2017-02-13 02:48 - 2015-12-22 02:45 - 00737310 _____ C:\Windows\System32\perfh00C.dat
2017-02-13 02:48 - 2015-12-22 02:45 - 00470608 _____ C:\Windows\System32\perfh001.dat
2017-02-13 02:48 - 2015-12-22 02:45 - 00149238 _____ C:\Windows\System32\perfc00C.dat
2017-02-13 02:48 - 2015-12-22 02:45 - 00094430 _____ C:\Windows\System32\perfc001.dat
2017-02-13 02:48 - 2015-12-22 02:40 - 00688802 _____ C:\Windows\System32\perfh007.dat
2017-02-13 02:48 - 2015-12-22 02:40 - 00148774 _____ C:\Windows\System32\perfc007.dat
2017-02-13 02:48 - 2015-12-14 19:30 - 00392068 _____ C:\Windows\System32\perfh00D.dat
2017-02-13 02:48 - 2015-12-14 19:30 - 00084542 _____ C:\Windows\System32\perfc00D.dat
2017-02-13 02:48 - 2009-07-13 21:13 - 17428728 _____ C:\Windows\System32\PerfStringBackup.INI
2017-02-13 02:48 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\inf
2017-02-13 02:45 - 2015-12-14 17:50 - 00002904 _____ C:\Windows\System32\Tasks\Uninstaller_SkipUac_Sahar
2017-02-10 13:13 - 2016-10-15 23:23 - 00000000 ____D C:\Program Files (x86)\McAfee
2017-02-08 17:01 - 2009-07-13 18:34 - 00000478 _____ C:\Windows\win.ini
2017-02-08 02:01 - 2015-12-14 19:38 - 00000000 __SHD C:\Users\Sahar\IntelGraphicsProfiles
2017-02-08 02:01 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-02-07 03:53 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
2017-02-06 14:07 - 2015-12-14 16:29 - 00002177 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-02-05 02:39 - 2015-12-29 02:51 - 00001343 _____ C:\Users\Sahar\Desktop\מסמכים חשובים.txt
2017-01-25 18:59 - 2016-10-14 13:08 - 00000000 ____D C:\Windows\rescache
2017-01-25 17:50 - 2009-07-13 20:45 - 00467864 _____ C:\Windows\System32\FNTCACHE.DAT
2017-01-25 17:28 - 2015-12-22 09:03 - 00000000 ____D C:\Windows\et-EE
2017-01-25 17:28 - 2015-12-22 08:56 - 00000000 ____D C:\Windows\lt-LT
2017-01-25 17:28 - 2015-12-22 08:08 - 00000000 ____D C:\Windows\lv-LV
2017-01-25 17:28 - 2015-12-15 09:00 - 00000000 ___SD C:\Windows\System32\CompatTel
2017-01-25 17:28 - 2015-12-15 09:00 - 00000000 ____D C:\Windows\System32\appraiser
2017-01-25 17:28 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\lv-LV
2017-01-25 17:28 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\lt-LT
2017-01-25 17:28 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\et-EE
2017-01-25 17:28 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
2017-01-25 17:28 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\lv-LV
2017-01-25 17:28 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\lt-LT
2017-01-25 17:28 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\et-EE
2017-01-25 17:28 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\Dism
2017-01-25 17:08 - 2015-12-14 17:54 - 17037236 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2017-01-24 17:18 - 2016-06-16 02:33 - 00000000 ____D C:\Windows\Minidump

==================== Known DLLs (Whitelisted) =========================

C:\Windows\System32\USP10.dll IS MISSING <==== ATTENTION

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe
[2016-10-17 22:14] - [2016-08-29 07:04] - 3229696 ____A (Microsoft Corporation) 38AE1B3C38FAEF56FE4907922F0385BA

C:\Windows\SysWOW64\explorer.exe
[2016-10-17 22:14] - [2016-08-29 06:55] - 2972672 ____A (Microsoft Corporation) 6DDCA324434FFA506CF7DC4E51DB7935

C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll
[2017-01-25 05:53] - [2016-11-10 08:32] - 1009152 ____A (Microsoft Corporation) 34BA256FBF83457F9D5E51A56DB54542

C:\Windows\SysWOW64\User32.dll
[2017-01-25 05:53] - [2016-11-10 08:19] - 0833024 ____A (Microsoft Corporation) 3CB074875AC88A7C1010A2A7F9881A8C

C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\dnsapi.dll => MD5 is legit
C:\Windows\SysWOW64\dnsapi.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== Association (Whitelisted) =============


==================== Restore Points =========================

Restore point date: 2017-02-21 02:53

==================== Memory info ===========================

Percentage of memory in use: 12%
Total physical RAM: 8091.95 MB
Available physical RAM: 7065.29 MB
Total Virtual: 8090.15 MB
Available Virtual: 7106.9 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:111.69 GB) (Free:20.03 GB) NTFS
Drive d: () (Fixed) (Total:931.51 GB) (Free:838.97 GB) NTFS
Drive g: () (Removable) (Total:31.23 GB) (Free:31.23 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[system with boot components (obtained from drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: 70B7528B)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=111.7 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 754E95E1)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (Size: 31.3 GB) (Disk ID: 6F20736B)
No partition Table on disk 2.
Disk 2 is a removable device.

LastRegBack: 2017-02-11 14:52

==================== End of FRST.txt ============================

Attached Files

  • Attached File  FRST.txt   58.99KB   0 downloads

Edited by hamluis, 21 February 2017 - 11:42 AM.
Merged topics - Hamluis.


BC AdBot (Login to Remove)

 


#2 nessbru23

nessbru23
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:10:38 PM

Posted 21 February 2017 - 11:08 AM

i sew an old , i realized i needed to add the file frst log so here it is

Attached Files


Edited by hamluis, 21 February 2017 - 11:43 AM.


#3 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,640 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:01:38 PM

Posted 21 February 2017 - 06:31 PM

Greetings nessbru23 and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

If you would allow me to call you by your first name I would prefer to do that.

===================================================

Ground Rules:
  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met.
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • When you post your reply, use the Replytopic.jpg button instead.
  • In the upper right hand corner of the topic you will see the Followtopic.jpg button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far.

Please run this program for me.

===================================================

Farbar's Recovery Scan Tool Search

--------------------
  • Boot to the System Recovery Options again and run FRST
  • Type the following in the Search Field
USP10.dll
  • Click Search File(s) button
  • A Search.txt document will be saved to your USB device
  • Copy and paste the contents of that document your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Search.txt

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#4 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,640 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:01:38 PM

Posted 27 February 2017 - 10:20 PM

Greetings,

===================================================

Do You Still Need Help?

It has been 3 days since my last post.
  • Do you still need help with this?
  • If you have not replied within 48 hours I will assume you have abandoned the Topic and it will be closed.

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#5 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,640 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:01:38 PM

Posted 02 March 2017 - 10:13 PM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users