Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

0xC0000005 renders computer unusable, isdel.exe missing, inconsistencies -repost


  • Please log in to reply
43 replies to this topic

#1 the2bachic

the2bachic

  • Members
  • 153 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Georgia, USA
  • Local time:07:57 PM

Posted 08 March 2017 - 07:50 PM

Edited: please disregard. Got an error message that the first didn't post, tried again, then the first post popped up. Please see https://www.bleepingcomputer.com/forums/t/641634/0xc0000005-renders-computer-unusable-isdelexe-missing-inconsistencies-repost/

 

(Looking for a way to delete this post, but haven't found it yet.)

Attached Files


Edited by the2bachic, 08 March 2017 - 07:56 PM.


BC AdBot (Login to Remove)

 


#2 Sintharius

Sintharius

    Bleepin' Sniper


  • Members
  • 5,639 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Netherlands
  • Local time:12:57 AM

Posted 09 March 2017 - 04:18 AM

Welcome to Bleeping Computer's Malware Removal Logs area. My name is Sintharius. I will assist you with your problem.

Below are some rules that you will need to follow while receiving my assistance:
  • I am currently in training, so my responses might be delayed. I will generally reply within 48 hours - if this is not possible, I will let you know.
  • Please do not seek assistance elsewhere without letting me know.
  • Please do not run any tools without being instructed to as this makes my job much harder in trying to figure out what you have done.
  • If you wish to do other interventions, please let me know. I will assist you if possible.
  • Make sure to read my instructions fully before attempting a step.
  • If you have problems or questions with any of the steps, feel free to ask me. I will be happy to answer any questions you have.
  • Please follow the topic by clicking on the Follow this topic button, and make sure a tick is in the receive notifications and is set to Instantly. Any replies should be made in this topic by clicking the Reply to this topic button.
  • Important information in my posts will often be in bold, make sure to take note of these.
  • I will bump a topic after 3 days of no activity, and then will give you another 2 days to reply before a topic is closed. Please inform me if you need more time.
  • Please stay with me until I have confirmed that you are clean. Absence of symptoms does not mean that the computer is clean.
  • If you do not agree with any of the above, please let me know so I can have this topic closed.
===

Can you repost the main log? Your other topic was deleted as a duplicate.

Also, can you clarify the problem? When does this start?

Edited by Sintharius, 09 March 2017 - 04:25 AM.


#3 the2bachic

the2bachic
  • Topic Starter

  • Members
  • 153 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Georgia, USA
  • Local time:07:57 PM

Posted 09 March 2017 - 10:59 AM

I guess the wrong one got deleted when I requested this one be deleted. Oh well. I posted everything I had done before turning here before (full text and link at the bottom here). On that original post, Boopme requested that I run FRST and repost. Here's the FRST log. The Addition.txt was still attached above.

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-03-2017
Ran by Amber (administrator) on AM (08-03-2017 19:31:50)
Running from C:\Users\Amber\Downloads
Loaded Profiles: Amber (Available Profiles: Amber & Administrator)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [snp2uvc] => C:\windows\vsnp2uvc.exe [662016 2009-08-13] (Sonix)
HKLM\...\Run: [ShadowPlay] => C:\windows\system32\rundll32.exe C:\windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11855976 2011-05-31] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2226280 2011-05-17] (Realtek Semiconductor)
HKLM\...\Run: [PSUTility] => C:\Program Files\Fujitsu\PSUtility\TrayManager.exe [200552 2011-01-11] (FUJITSU LIMITED)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2531472 2014-12-12] (NVIDIA Corporation)
HKLM\...\Run: [LoadFujitsuQuickTouch] => C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe [157512 2011-05-24] (FUJITSU LIMITED)
HKLM\...\Run: [LoadFUJ02E3] => C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe [45680 2010-06-08] (FUJITSU LIMITED)
HKLM\...\Run: [LoadBtnHnd] => C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe [23368 2011-05-24] (FUJITSU LIMITED)
HKLM\...\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel® Corporation)
HKLM\...\Run: [FJUPDNV_Chitose] => C:\Program Files\Fujitsu\fjdvrupd\updatenv.exe [157184 2010-01-12] (FUJITSU LIMITED)
HKLM\...\Run: [FDM7] => C:\Program Files\Fujitsu\FDM7\FdmDaemon.exe [164712 2009-11-25] (FUJITSU LIMITED)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [RoxWatchTray] => C:\Program Files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxWatchTray13.exe [293360 2011-07-13] (Rovi Corporation)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [87336 2010-02-02] (CyberLink Corp.)
HKLM-x32\...\Run: [QuickTime Task] => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
HKLM-x32\...\Run: [PPort12reminder] => "C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini"
HKLM-x32\...\Run: [PDFHook] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe [636192 2010-03-05] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PDF5 Registry Controller] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PaperPort PTD] => C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe [29984 2010-03-08] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2011-04-14] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM-x32\...\Run: [IndicatorUtility] => C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe [48752 2010-09-29] (FUJITSU LIMITED)
HKLM-x32\...\Run: [IndexSearch] => C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe [46368 2010-03-08] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
HKLM-x32\...\Run: [FUJ02B1_Apps] => C:\Program Files (x86)\Fujitsu\FUJ02B1\CheckBatteryPack.exe [367424 2016-05-11] (FUJITSU LIMITED)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1263512 2012-11-29] ()
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-09-10] (DivX, LLC)
HKLM-x32\...\Run: [Desktop Disc Tool] => C:\Program Files (x86)\Roxio 2012\Roxio Burn\RoxioBurnLauncher.exe [506352 2011-06-12] ()
HKLM-x32\...\Run: [CPMonitor] => C:\Program Files (x86)\Roxio 2012\5.0\CPMonitor.exe [84464 2011-07-08] ()
HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [143360 2012-09-06] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [3076096 2012-06-06] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BDRegion] => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [75048 2011-08-24] (cyberlink)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [205512 2017-03-03] (AVAST Software)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2524020813-2562236670-706791055-1001\...\Run: [pronto] => "C:\Program Files (x86)\Blackboard\Blackboard IM\blackboardim.exe"
HKU\S-1-5-21-2524020813-2562236670-706791055-1001\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [324976 2010-05-21] (Flexera Software, Inc.)
HKU\S-1-5-21-2524020813-2562236670-706791055-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23818360 2016-11-30] (Google)
HKU\S-1-5-21-2524020813-2562236670-706791055-1001\...\Run: [GoogleChromeAutoLaunch_B541A8D354ED80445B89E73989F98B03] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [945496 2017-02-01] (Google Inc.)
HKU\S-1-5-21-2524020813-2562236670-706791055-1001\...\Run: [Google Update] => C:\Users\Amber\AppData\Local\Google\Update\1.3.32.7\GoogleUpdateCore.exe [601752 2016-12-20] (Google Inc.)
HKU\S-1-5-21-2524020813-2562236670-706791055-1001\...\Run: [EasyTether] => C:\Program Files\Mobile Stream\EasyTether\easytthr.exe [73728 2015-05-04] (Mobile Stream)
HKU\S-1-5-21-2524020813-2562236670-706791055-1001\...\Run: [Dropbox Update] => C:\Users\Amber\AppData\Local\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-05] (Dropbox, Inc.)
HKU\S-1-5-21-2524020813-2562236670-706791055-1001\...\Run: [Amazon Music] => C:\Users\Amber\AppData\Local\Amazon Music\Amazon Music Helper.exe [5886784 2015-05-07] ()
HKU\S-1-5-21-2524020813-2562236670-706791055-1001\...\Run: [Akamai NetSession Interface] => "C:\Users\Amber\AppData\Local\Akamai\netsession_win.exe"
HKU\S-1-5-21-2524020813-2562236670-706791055-1001\...\Policies\Explorer: []
HKU\S-1-5-21-2524020813-2562236670-706791055-1001\...\MountPoints2: F - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-2524020813-2562236670-706791055-1001\...\MountPoints2: {2273f306-bd6b-11e1-b48e-0811960d411c} - F:\setup.exe -a
HKU\S-1-5-21-2524020813-2562236670-706791055-1001\...\MountPoints2: {29a4e16e-3029-11e2-854c-8c736eb67590} - F:\setup.exe -a
HKU\S-1-5-21-2524020813-2562236670-706791055-1001\...\MountPoints2: {57836606-752e-11e1-841e-9439e5d04d72} - F:\setup.exe -a
HKU\S-1-5-21-2524020813-2562236670-706791055-1001\...\MountPoints2: {6142685c-2fee-11e2-9c76-8c736eb67590} - F:\setup.exe -a
HKU\S-1-5-21-2524020813-2562236670-706791055-1001\...\MountPoints2: {7a6ef3a6-7912-11e2-ac99-9439e5d04d72} - F:\KODAK_Software_Downloader.exe
HKU\S-1-5-21-2524020813-2562236670-706791055-1001\...\MountPoints2: {95ddf884-cd53-11e5-8ff8-9439e5d04d72} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-2524020813-2562236670-706791055-1001\...\MountPoints2: {a18b0633-2997-11e4-bc17-9439e5d04d72} - F:\VerizonWirelessUpgradeAssistantSetup.exe -a
HKU\S-1-5-21-2524020813-2562236670-706791055-1001\...\MountPoints2: {a95790fb-fb4c-11e1-a813-8c736eb67590} - F:\setup.exe -a
HKU\S-1-5-21-2524020813-2562236670-706791055-1001\...\MountPoints2: {dc169823-bd5a-11e1-825a-8c736eb67590} - F:\setup.exe -a
AppInit_DLLs: C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [226920 2010-11-17] (NVIDIA Corporation)
AppInit_DLLs: , C:\windows\system32\nvinitx.dll => C:\windows\system32\nvinitx.dll [226920 2010-11-17] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [192616 2010-11-17] (NVIDIA Corporation)
AppInit_DLLs-x32: , C:\windows\SysWOW64\nvinit.dll => C:\windows\SysWOW64\nvinit.dll [192616 2010-11-17] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-03-03] (AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-03-03] (AVAST Software)
ShellIconOverlayIdentifiers: [1TortoiseNormal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [2TortoiseModified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [3TortoiseConflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [4TortoiseLocked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [5TortoiseReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [6TortoiseDeleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [7TortoiseAdded] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [8TortoiseIgnored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [9TortoiseUnversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Amber\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Amber\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Amber\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Amber\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Amber\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Amber\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Amber\AppData\Roaming\Dropbox\bin\DropboxExt.14.0.dll [2017-02-21] (Dropbox, Inc.)
BootExecute: autocheck autochk /k:C *

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{541C84A6-AAF3-4DA0-8977-1E40BF1C2020}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{71E99A61-16A5-4852-9AA3-C62C58B92C18}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{BAF4D7D9-A2FA-4BB3-8211-2A00368D4A0A}: [DhcpNameServer] 192.168.117.1

Internet Explorer:
==================
HKU\S-1-5-21-2524020813-2562236670-706791055-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://solutions.us.fujitsu.com/
HKU\S-1-5-21-2524020813-2562236670-706791055-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.keepvid.com/
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-03-03] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-27] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-22] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2016-11-15] (Microsoft Corporation)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21] (Hewlett-Packard Co.)
BHO-x32: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll [2009-02-06] (Zeon Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-02-24] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-03-03] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2015-01-29] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-27] (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-02-24] (Oracle Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21] (Hewlett-Packard Co.)
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-27] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-27] (Google Inc.)
Toolbar: HKU\S-1-5-21-2524020813-2562236670-706791055-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Toolbar: HKU\S-1-5-21-2524020813-2562236670-706791055-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-27] (Google Inc.)

FireFox:
========
FF ProfilePath: C:\Users\Amber\AppData\Roaming\Mozilla\Firefox\Profiles\j6852cbu.default [2017-03-08]
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\j6852cbu.default -> Google
FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\j6852cbu.default -> Google
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\j6852cbu.default -> Connect DLC Customized Web Search
FF Homepage: Mozilla\Firefox\Profiles\j6852cbu.default -> hxxps://calendar.google.com/calendar/b/1/render?tab=wc#main_7
FF Extension: (Ebates Cash Back) - C:\Users\Amber\AppData\Roaming\Mozilla\Firefox\Profiles\j6852cbu.default\Extensions\{35d6291e-1d4b-f9b4-c52f-77e6410d1326}.xpi [2017-03-02]
FF Extension: (NoScript) - C:\Users\Amber\AppData\Roaming\Mozilla\Firefox\Profiles\j6852cbu.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2017-03-04]
FF Extension: (FireFTP) - C:\Users\Amber\AppData\Roaming\Mozilla\Firefox\Profiles\j6852cbu.default\Extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f} [2017-01-29]
FF Extension: (Web Developer) - C:\Users\Amber\AppData\Roaming\Mozilla\Firefox\Profiles\j6852cbu.default\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2017-02-23]
FF Extension: (Adblock Plus) - C:\Users\Amber\AppData\Roaming\Mozilla\Firefox\Profiles\j6852cbu.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-23]
FF Extension: (SHA-1 deprecation staged rollout) - C:\Users\Amber\AppData\Roaming\Mozilla\Firefox\Profiles\j6852cbu.default\features\{b9390d48-bbb8-41b9-8e56-d2d5a3e41297}\disableSHA1rollout@mozilla.org.xpi [2017-03-03]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF48
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF48 [2017-03-03]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF48
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF48 [2017-03-03]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF48
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: (HP Smart Web Printing) - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-08-26] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF48
FF HKU\S-1-5-21-2524020813-2562236670-706791055-1001\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-02-24] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2013-09-16] (DivX, LLC.)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-24] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll [2012-10-04] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-20] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2013-09-16] (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2013-10-28] (DivX, LLC)
FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-02-24] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-02-24] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Reader 3\npnitromozilla.dll [2013-03-26] (Nitro PDF)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-20] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-20] (Google Inc.)
FF Plugin-x32: @ums.geocomply.com/GeoComply Update;version=3 -> C:\Program Files (x86)\GeoComply\Update\2.1.2.7\npGoogleUpdate3.dll [2016-01-09] (GeoComply Inc.)
FF Plugin-x32: @ums.geocomply.com/GeoComply Update;version=9 -> C:\Program Files (x86)\GeoComply\Update\2.1.2.7\npGoogleUpdate3.dll [2016-01-09] (GeoComply Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2524020813-2562236670-706791055-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\Amber\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-2524020813-2562236670-706791055-1001: @talk.google.com/O1DPlugin -> C:\Users\Amber\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-2524020813-2562236670-706791055-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Amber\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-20] (Google Inc.)
FF Plugin HKU\S-1-5-21-2524020813-2562236670-706791055-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Amber\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-20] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Amber\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Amber\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)

Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Amber\AppData\Local\Google\Chrome\User Data\Default [2017-03-06]
CHR Extension: (Google Slides) - C:\Users\Amber\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-04-05]
CHR Extension: (Google Docs) - C:\Users\Amber\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-04-05]
CHR Extension: (Google Drive) - C:\Users\Amber\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-04-05]
CHR Extension: (YouTube) - C:\Users\Amber\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-04-05]
CHR Extension: (Avast SafePrice) - C:\Users\Amber\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-01-02]
CHR Extension: (Google Sheets) - C:\Users\Amber\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-04-05]
CHR Extension: (Google Docs Offline) - C:\Users\Amber\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-20]
CHR Extension: (AdBlock) - C:\Users\Amber\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-03-01]
CHR Extension: (Avast Online Security) - C:\Users\Amber\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-12-20]
CHR Extension: (Motorola Connect) - C:\Users\Amber\AppData\Local\Google\Chrome\User Data\Default\Extensions\kigmoblgooahdmdibodmcnffgnejlndh [2016-01-12]
CHR Extension: (Google Hangouts) - C:\Users\Amber\AppData\Local\Google\Chrome\User Data\Default\Extensions\knipolnnllmklapflnccelgolnpehhpl [2017-02-13]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Amber\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2015-01-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Amber\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-19]
CHR Extension: (Adblock Pro) - C:\Users\Amber\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcklkibdehekfnmflempfgjhbedch [2016-05-17]
CHR Extension: (Gmail) - C:\Users\Amber\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-04-05]
CHR Extension: (Chrome Media Router) - C:\Users\Amber\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-24]
CHR HKU\S-1-5-21-2524020813-2562236670-706791055-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Amber\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2015-01-04]
CHR HKU\S-1-5-21-2524020813-2562236670-706791055-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx <not found>

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ATTENTION: => Could not perform signature verification. Cryptographic Service is not running.

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-02-23] (SUPERAntiSpyware.com)
S2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269; C:\Program Files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe [457200 2011-02-09] ()
S2 a2AntiMalware; C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [4920104 2014-12-31] (Emsisoft GmbH)
S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7147320 2017-03-03] (AVAST Software s.r.o.)
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [262736 2017-03-03] (AVAST Software)
S2 BOT4Service; C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe [21488 2011-07-15] ()
S4 BOTService; C:\Program Files (x86)\Roxio\BackOnTrack\Instant Restore\BOTService.exe [211440 2011-07-14] (Rovi Corporation)
S2 BRA_Scheduler; C:\Program Files (x86)\Brother\BRAdmin Professional 3\bratimer.exe [99328 2014-04-02] ()
S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [15768 2010-02-02] (Microsoft Corporation)
S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [248304 2011-06-07] (CyberLink)
S2 DTSAudioService; C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe [210024 2011-05-30] (DTS)
S2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148560 2014-12-12] (NVIDIA Corporation)
S2 HDRExpressService; C:\Program Files\UCT\HDR Express\HDRExpressService.exe [28432 2011-04-04] ()
S2 MotoHelper; C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe [214896 2011-12-06] ()
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] ()
S2 NitroReaderDriverReadSpool3; C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe [230416 2013-03-26] (Nitro PDF Software)
S2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1701520 2014-12-12] (NVIDIA Corporation)
S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19823248 2014-12-12] (NVIDIA Corporation)
S2 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-08] (Nuance Communications, Inc.)
S2 PowerSavingUtilityService; C:\Program Files\Fujitsu\PSUtility\PSUService.exe [63336 2010-06-17] (FUJITSU LIMITED)
S2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2011-05-13] ()
S3 RoxMediaDB13; C:\Program Files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxMediaDB13.exe [1095664 2011-07-13] (Rovi Corporation)
S2 RoxWatch12; C:\Program Files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxWatch13.exe [340976 2011-07-13] (Rovi Corporation)
S2 UpdateNaviInstallService; C:\Program Files\Fujitsu\fjdvrupd\updnvsrv.exe [14336 2009-09-30] (FUJITSU LIMITED)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 a2acc; C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys [71472 2014-05-12] (Emsisoft GmbH)
S1 A2DDA; C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys [26176 2013-03-28] (Emsisoft GmbH)
S1 a2injectiondriver; C:\Program Files (x86)\Emsisoft Anti-Malware\a2dix64.sys [45208 2013-09-30] (Emsisoft GmbH)
S1 a2util; C:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys [23088 2014-05-12] (Emsisoft GmbH)
S1 aswbidsdriver; C:\windows\system32\drivers\aswbidsdrivera.sys [309272 2017-03-03] (AVAST Software s.r.o.)
S0 aswbidsh; C:\windows\system32\drivers\aswbidsha.sys [189768 2017-03-03] (AVAST Software s.r.o.)
S0 aswblog; C:\windows\system32\drivers\aswbloga.sys [334600 2017-03-03] (AVAST Software s.r.o.)
S0 aswbuniv; C:\windows\system32\drivers\aswbuniva.sys [48528 2017-03-03] (AVAST Software s.r.o.)
S3 aswHwid; C:\windows\system32\drivers\aswHwid.sys [38296 2017-03-03] (AVAST Software)
R1 aswKbd; C:\windows\system32\drivers\aswKbd.sys [32088 2017-03-03] (AVAST Software)
S2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [126600 2017-03-03] (AVAST Software)
R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [100640 2017-03-03] (AVAST Software)
S0 aswRvrt; C:\windows\system32\drivers\aswRvrt.sys [75704 2017-03-03] (AVAST Software)
S1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [993608 2017-03-03] (AVAST Software)
S1 aswSP; C:\windows\system32\drivers\aswSP.sys [547904 2017-03-03] (AVAST Software)
S2 aswStm; C:\windows\system32\drivers\aswStm.sys [162528 2017-03-03] (AVAST Software)
S0 aswVmm; C:\windows\system32\drivers\aswVmm.sys [337592 2017-03-03] (AVAST Software)
S3 bcbtums; C:\windows\System32\drivers\bcbtums.sys [131112 2010-10-04] (Broadcom Corporation.)
S3 cleanhlp; C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [57024 2013-12-04] (Emsisoft GmbH)
R3 easytether; C:\windows\System32\DRIVERS\easytthr.sys [22728 2015-05-04] (Mobile Stream)
R0 FBIOSDRV; C:\windows\System32\Drivers\FBIOSDRV.sys [21104 2009-06-24] (FUJITSU LIMITED)
R3 FUJ02B1; C:\windows\System32\DRIVERS\FUJ02B1.sys [59152 2016-05-11] (FUJITSU LIMITED)
R3 FUJ02E3; C:\windows\system32\drivers\FUJ02E3.sys [7296 2006-11-01] (FUJITSU LIMITED)
S3 motport; C:\windows\System32\DRIVERS\motport.sys [30208 2011-03-31] (Motorola)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2014-12-12] (NVIDIA Corporation)
S3 nvvad_WaveExtensible; C:\windows\System32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
S1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 SNP2UVC; C:\windows\System32\DRIVERS\snp2uvc.sys [1803264 2011-03-10] ()
R0 SysCow; C:\windows\System32\drivers\syscowad64v.sys [164848 2010-05-23] (Sonic Solutions)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-03-08 19:27 - 2017-03-08 19:29 - 00074392 _____ C:\Users\Amber\Downloads\Addition.txt
2017-03-08 19:25 - 2017-03-08 19:31 - 00034587 _____ C:\Users\Amber\Downloads\FRST.txt
2017-03-08 19:24 - 2017-03-08 19:31 - 00000000 ____D C:\FRST
2017-03-08 19:22 - 2017-03-08 19:23 - 02423808 _____ (Farbar) C:\Users\Amber\Downloads\FRST64.exe
2017-03-05 15:16 - 2017-03-05 15:16 - 00680154 _____ C:\Users\Amber\Documents\FedLoan Servicing general forbearance application completed 2017.03.05.pdf
2017-03-05 15:15 - 2017-03-05 15:15 - 00680154 _____ C:\Users\Amber\Documents\FedLoan Servicing forbearance request 2017.03.05.pdf
2017-03-04 08:39 - 2017-03-04 08:39 - 00009876 _____ C:\Users\Amber\Documents\peanuts door sign.odt
2017-03-03 01:50 - 2017-03-03 01:50 - 00398408 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2017-03-03 01:42 - 2017-03-03 01:43 - 06654960 _____ (AVAST Software) C:\Users\Amber\Downloads\avast_free_antivirus_setup_online_cnet2.exe
2017-03-03 01:32 - 2017-03-03 01:32 - 00000000 ____D C:\Users\Amber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth Devices
2017-03-03 01:29 - 2017-02-02 11:36 - 00084712 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2017-03-03 01:29 - 2017-02-02 11:32 - 01285632 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2017-03-03 01:29 - 2017-02-02 09:06 - 00650752 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2017-03-03 01:29 - 2016-12-31 10:36 - 01609216 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2017-03-03 01:29 - 2016-12-31 10:36 - 00556544 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2017-03-03 01:29 - 2016-12-31 10:36 - 00335360 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2017-03-03 01:29 - 2016-12-31 10:36 - 00293376 _____ (Microsoft Corporation) C:\windows\system32\centel.dll
2017-03-03 01:29 - 2016-12-31 10:36 - 00233984 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2017-03-03 01:29 - 2016-12-31 10:36 - 00133632 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2017-03-03 01:29 - 2015-12-16 13:53 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\kbdgeoqw.dll
2017-03-03 01:29 - 2015-12-16 13:53 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDAZEL.DLL
2017-03-03 01:29 - 2015-12-16 13:53 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDAZE.DLL
2017-03-03 01:29 - 2015-12-16 13:48 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDAZE.DLL
2017-03-03 01:29 - 2015-12-16 13:48 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\kbdgeoqw.dll
2017-03-03 01:29 - 2015-12-16 13:48 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDAZEL.DLL
2017-03-03 01:29 - 2015-08-05 12:56 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\icaapi.dll
2017-03-03 01:29 - 2015-08-05 12:06 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2017-03-03 01:21 - 2016-07-22 09:58 - 00142336 _____ (Microsoft Corporation) C:\windows\system32\poqexec.exe
2017-03-03 01:21 - 2016-07-22 09:51 - 00123904 _____ (Microsoft Corporation) C:\windows\SysWOW64\poqexec.exe
2017-03-03 00:08 - 2016-11-14 18:27 - 00394448 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2017-03-03 00:08 - 2016-11-14 17:39 - 00346320 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2017-03-03 00:08 - 2016-11-12 14:48 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2017-03-03 00:08 - 2016-11-12 14:26 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2017-03-03 00:08 - 2016-11-12 14:21 - 02896384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2017-03-03 00:08 - 2016-11-12 14:14 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2017-03-03 00:08 - 2016-11-12 14:08 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2017-03-03 00:08 - 2016-11-12 13:41 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2017-03-03 00:08 - 2016-11-12 13:40 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2017-03-03 00:08 - 2016-11-12 13:30 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2017-03-03 00:08 - 2016-11-12 13:29 - 00498688 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2017-03-03 00:08 - 2016-11-12 13:28 - 00152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2017-03-03 00:08 - 2016-11-12 13:27 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2017-03-03 00:08 - 2016-11-12 13:20 - 02287616 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2017-03-03 00:08 - 2016-11-12 13:20 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2017-03-03 00:08 - 2016-11-12 13:19 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2017-03-03 00:08 - 2016-11-12 13:17 - 20302848 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2017-03-03 00:08 - 2016-11-12 13:14 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2017-03-03 00:08 - 2016-11-12 13:14 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2017-03-03 00:08 - 2016-11-12 13:14 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2017-03-03 00:08 - 2016-11-12 13:11 - 00725504 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2017-03-03 00:08 - 2016-11-12 12:57 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-03-03 00:08 - 2016-11-12 12:56 - 00091136 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
2017-03-03 00:08 - 2016-11-12 12:51 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2017-03-03 00:08 - 2016-11-12 12:49 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2017-03-03 00:08 - 2016-11-12 12:47 - 00130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2017-03-03 00:08 - 2016-11-12 12:38 - 00693248 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2017-03-03 00:08 - 2016-11-12 12:36 - 02055680 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2017-03-03 00:08 - 2016-11-12 12:20 - 01543680 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2017-03-03 00:08 - 2016-11-12 12:02 - 01312256 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2017-03-03 00:08 - 2016-11-12 12:02 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2017-03-03 00:08 - 2016-09-15 09:56 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\UtcResources.dll
2017-03-03 00:08 - 2016-08-22 11:19 - 01386496 _____ (Microsoft Corporation) C:\windows\system32\diagtrack.dll
2017-03-03 00:07 - 2017-01-05 13:55 - 00154856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2017-03-03 00:07 - 2017-01-05 13:55 - 00095464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2017-03-03 00:07 - 2017-01-05 13:52 - 01460736 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2017-03-03 00:07 - 2017-01-05 13:52 - 01212928 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2017-03-03 00:07 - 2017-01-05 13:52 - 00730624 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2017-03-03 00:07 - 2017-01-05 13:52 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2017-03-03 00:07 - 2017-01-05 13:52 - 00463872 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2017-03-03 00:07 - 2017-01-05 13:52 - 00345600 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2017-03-03 00:07 - 2017-01-05 13:52 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2017-03-03 00:07 - 2017-01-05 13:52 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2017-03-03 00:07 - 2017-01-05 13:52 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2017-03-03 00:07 - 2017-01-05 13:52 - 00190464 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll
2017-03-03 00:07 - 2017-01-05 13:52 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2017-03-03 00:07 - 2017-01-05 13:52 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2017-03-03 00:07 - 2017-01-05 13:52 - 00123904 _____ (Microsoft Corporation) C:\windows\system32\bcrypt.dll
2017-03-03 00:07 - 2017-01-05 13:52 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2017-03-03 00:07 - 2017-01-05 13:52 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2017-03-03 00:07 - 2017-01-05 13:52 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2017-03-03 00:07 - 2017-01-05 13:52 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2017-03-03 00:07 - 2017-01-05 13:52 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2017-03-03 00:07 - 2017-01-05 13:52 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2017-03-03 00:07 - 2017-01-05 12:43 - 00666112 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2017-03-03 00:07 - 2017-01-05 12:43 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2017-03-03 00:07 - 2017-01-05 12:43 - 00342528 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2017-03-03 00:07 - 2017-01-05 12:43 - 00261120 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2017-03-03 00:07 - 2017-01-05 12:43 - 00254464 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2017-03-03 00:07 - 2017-01-05 12:43 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2017-03-03 00:07 - 2017-01-05 12:43 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2017-03-03 00:07 - 2017-01-05 12:43 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2017-03-03 00:07 - 2017-01-05 12:43 - 00141312 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpchttp.dll
2017-03-03 00:07 - 2017-01-05 12:43 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2017-03-03 00:07 - 2017-01-05 12:43 - 00082944 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcrypt.dll
2017-03-03 00:07 - 2017-01-05 12:43 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2017-03-03 00:07 - 2017-01-05 12:43 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2017-03-03 00:07 - 2017-01-05 12:43 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2017-03-03 00:07 - 2017-01-05 12:43 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2017-03-03 00:07 - 2017-01-05 12:42 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2017-03-03 00:07 - 2017-01-05 12:32 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2017-03-03 00:07 - 2017-01-05 12:25 - 00159744 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2017-03-03 00:07 - 2017-01-05 12:24 - 00291328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2017-03-03 00:07 - 2017-01-05 12:24 - 00129536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2017-03-03 00:07 - 2017-01-05 12:24 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2017-03-03 00:07 - 2017-01-05 12:23 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2017-03-03 00:07 - 2017-01-05 12:19 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2017-03-03 00:07 - 2016-11-21 13:12 - 00109568 _____ (Microsoft Corporation) C:\windows\system32\hlink.dll
2017-03-03 00:07 - 2016-11-20 11:19 - 00084992 _____ (Microsoft Corporation) C:\windows\SysWOW64\hlink.dll
2017-03-03 00:07 - 2016-11-20 09:07 - 00467392 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2017-03-03 00:07 - 2016-11-17 11:41 - 00370920 _____ (Microsoft Corporation) C:\windows\system32\clfs.sys
2017-03-03 00:07 - 2016-11-12 14:48 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2017-03-03 00:07 - 2016-11-12 14:28 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2017-03-03 00:07 - 2016-11-12 14:26 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2017-03-03 00:07 - 2016-11-12 14:25 - 00576000 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2017-03-03 00:07 - 2016-11-12 14:25 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2017-03-03 00:07 - 2016-11-12 14:15 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2017-03-03 00:07 - 2016-11-12 14:09 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2017-03-03 00:07 - 2016-11-12 14:08 - 25759744 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2017-03-03 00:07 - 2016-11-12 14:08 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2017-03-03 00:07 - 2016-11-12 14:07 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2017-03-03 00:07 - 2016-11-12 14:07 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2017-03-03 00:07 - 2016-11-12 13:56 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2017-03-03 00:07 - 2016-11-12 13:53 - 06049280 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2017-03-03 00:07 - 2016-11-12 13:52 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2017-03-03 00:07 - 2016-11-12 13:47 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2017-03-03 00:07 - 2016-11-12 13:35 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2017-03-03 00:07 - 2016-11-12 13:34 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2017-03-03 00:07 - 2016-11-12 13:31 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2017-03-03 00:07 - 2016-11-12 13:29 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2017-03-03 00:07 - 2016-11-12 13:29 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2017-03-03 00:07 - 2016-11-12 13:15 - 00476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2017-03-03 00:07 - 2016-11-12 13:14 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2017-03-03 00:07 - 2016-11-12 13:10 - 00806912 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2017-03-03 00:07 - 2016-11-12 13:08 - 02131456 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2017-03-03 00:07 - 2016-11-12 13:08 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2017-03-03 00:07 - 2016-11-12 13:03 - 00416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2017-03-03 00:07 - 2016-11-12 12:52 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2017-03-03 00:07 - 2016-11-12 12:41 - 15257088 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2017-03-03 00:07 - 2016-11-12 12:40 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2017-03-03 00:07 - 2016-11-12 12:37 - 04608000 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2017-03-03 00:07 - 2016-11-12 12:36 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2017-03-03 00:07 - 2016-11-12 12:35 - 02920960 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2017-03-03 00:07 - 2016-11-12 12:21 - 13653504 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2017-03-03 00:07 - 2016-11-12 12:11 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2017-03-03 00:07 - 2016-11-12 12:05 - 02444800 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2017-03-03 00:07 - 2016-11-10 11:32 - 01009152 _____ (Microsoft Corporation) C:\windows\system32\user32.dll
2017-03-03 00:07 - 2016-11-10 11:19 - 00833024 _____ (Microsoft Corporation) C:\windows\SysWOW64\user32.dll
2017-03-03 00:07 - 2016-11-09 11:41 - 00114408 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2017-03-03 00:07 - 2016-11-09 11:33 - 03244032 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2017-03-03 00:07 - 2016-11-09 11:33 - 01941504 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2017-03-03 00:07 - 2016-11-09 11:33 - 00504320 _____ (Microsoft Corporation) C:\windows\system32\msihnd.dll
2017-03-03 00:07 - 2016-11-09 11:33 - 00070144 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2017-03-03 00:07 - 2016-11-09 11:33 - 00025088 _____ (Microsoft Corporation) C:\windows\system32\msimsg.dll
2017-03-03 00:07 - 2016-11-09 11:33 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2017-03-03 00:07 - 2016-11-09 11:17 - 02365440 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2017-03-03 00:07 - 2016-11-09 11:17 - 01806848 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2017-03-03 00:07 - 2016-11-09 11:17 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\msihnd.dll
2017-03-03 00:07 - 2016-11-09 11:17 - 00025088 _____ (Microsoft Corporation) C:\windows\SysWOW64\msimsg.dll
2017-03-03 00:07 - 2016-11-09 11:17 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2017-03-03 00:07 - 2016-11-09 11:02 - 00128512 _____ (Microsoft Corporation) C:\windows\system32\msiexec.exe
2017-03-03 00:07 - 2016-11-09 10:55 - 00073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\msiexec.exe
2017-03-03 00:07 - 2016-11-06 11:33 - 00404992 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2017-03-03 00:07 - 2016-11-06 11:16 - 00312832 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2017-03-03 00:07 - 2016-11-06 11:01 - 03219456 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2017-03-03 00:07 - 2016-11-02 10:36 - 00382696 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2017-03-03 00:07 - 2016-11-02 10:32 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2017-03-03 00:07 - 2016-11-02 10:32 - 00046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2017-03-03 00:07 - 2016-11-02 10:32 - 00041472 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2017-03-03 00:07 - 2016-11-02 10:32 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2017-03-03 00:07 - 2016-11-02 10:22 - 00308456 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2017-03-03 00:07 - 2016-11-02 10:16 - 00070656 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2017-03-03 00:07 - 2016-11-02 10:16 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
2017-03-03 00:07 - 2016-11-02 10:16 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
2017-03-03 00:07 - 2016-11-02 09:53 - 00034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2017-03-03 00:07 - 2016-10-27 10:33 - 00802304 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll
2017-03-03 00:07 - 2016-10-27 10:20 - 00627712 _____ (Microsoft Corporation) C:\windows\SysWOW64\usp10.dll
2017-03-03 00:07 - 2016-10-15 10:31 - 00976896 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2017-03-03 00:07 - 2016-10-15 10:31 - 00084480 _____ (Microsoft Corporation) C:\windows\system32\INETRES.dll
2017-03-03 00:07 - 2016-10-15 10:13 - 00741888 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
2017-03-03 00:07 - 2016-10-15 10:13 - 00084480 _____ (Microsoft Corporation) C:\windows\SysWOW64\INETRES.dll
2017-03-03 00:07 - 2016-10-11 10:40 - 00631176 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2017-03-03 00:07 - 2016-10-11 10:37 - 05547752 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2017-03-03 00:07 - 2016-10-11 10:37 - 00706792 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2017-03-03 00:07 - 2016-10-11 10:34 - 01732864 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2017-03-03 00:07 - 2016-10-11 10:32 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2017-03-03 00:07 - 2016-10-11 10:32 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2017-03-03 00:07 - 2016-10-11 10:32 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2017-03-03 00:07 - 2016-10-11 10:32 - 00215552 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2017-03-03 00:07 - 2016-10-11 10:32 - 00069120 _____ (Microsoft Corporation) C:\windows\system32\nlsbres.dll
2017-03-03 00:07 - 2016-10-11 10:32 - 00063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2017-03-03 00:07 - 2016-10-11 10:32 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2017-03-03 00:07 - 2016-10-11 10:32 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2017-03-03 00:07 - 2016-10-11 10:32 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 01148416 _____ (Microsoft Corporation) C:\windows\system32\IMJP10.IME
2017-03-03 00:07 - 2016-10-11 10:31 - 01068544 _____ (Microsoft Corporation) C:\windows\system32\msctf.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00880640 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00878080 _____ (Microsoft Corporation) C:\windows\system32\IMJP10K.DLL
2017-03-03 00:07 - 2016-10-11 10:31 - 00457216 _____ (Microsoft Corporation) C:\windows\system32\imkr80.ime
2017-03-03 00:07 - 2016-10-11 10:31 - 00419840 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00246784 _____ (Microsoft Corporation) C:\windows\system32\input.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00176128 _____ (Microsoft Corporation) C:\windows\system32\tintlgnt.ime
2017-03-03 00:07 - 2016-10-11 10:31 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\quick.ime
2017-03-03 00:07 - 2016-10-11 10:31 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\qintlgnt.ime
2017-03-03 00:07 - 2016-10-11 10:31 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\phon.ime
2017-03-03 00:07 - 2016-10-11 10:31 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\cintlgnt.ime
2017-03-03 00:07 - 2016-10-11 10:31 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\chajei.ime
2017-03-03 00:07 - 2016-10-11 10:31 - 00132608 _____ (Microsoft Corporation) C:\windows\system32\pintlgnt.ime
2017-03-03 00:07 - 2016-10-11 10:31 - 00059904 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00034816 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:31 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:24 - 04000488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2017-03-03 00:07 - 2016-10-11 10:24 - 03944680 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2017-03-03 00:07 - 2016-10-11 10:21 - 01314112 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 01027584 _____ (Microsoft Corporation) C:\windows\SysWOW64\IMJP10.IME
2017-03-03 00:07 - 2016-10-11 10:18 - 00829952 _____ (Microsoft Corporation) C:\windows\SysWOW64\msctf.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00701440 _____ (Microsoft Corporation) C:\windows\SysWOW64\IMJP10K.DLL
2017-03-03 00:07 - 2016-10-11 10:18 - 00644096 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00430080 _____ (Microsoft Corporation) C:\windows\SysWOW64\imkr80.ime
2017-03-03 00:07 - 2016-10-11 10:18 - 00275456 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00202240 _____ (Microsoft Corporation) C:\windows\SysWOW64\input.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00126976 _____ (Microsoft Corporation) C:\windows\SysWOW64\tintlgnt.ime
2017-03-03 00:07 - 2016-10-11 10:18 - 00125952 _____ (Microsoft Corporation) C:\windows\SysWOW64\quick.ime
2017-03-03 00:07 - 2016-10-11 10:18 - 00125952 _____ (Microsoft Corporation) C:\windows\SysWOW64\qintlgnt.ime
2017-03-03 00:07 - 2016-10-11 10:18 - 00125952 _____ (Microsoft Corporation) C:\windows\SysWOW64\phon.ime
2017-03-03 00:07 - 2016-10-11 10:18 - 00125952 _____ (Microsoft Corporation) C:\windows\SysWOW64\cintlgnt.ime
2017-03-03 00:07 - 2016-10-11 10:18 - 00125952 _____ (Microsoft Corporation) C:\windows\SysWOW64\chajei.ime
2017-03-03 00:07 - 2016-10-11 10:18 - 00090112 _____ (Microsoft Corporation) C:\windows\SysWOW64\pintlgnt.ime
2017-03-03 00:07 - 2016-10-11 10:18 - 00069120 _____ (Microsoft Corporation) C:\windows\SysWOW64\nlsbres.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:18 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 10:03 - 00148480 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2017-03-03 00:07 - 2016-10-11 10:03 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2017-03-03 00:07 - 2016-10-11 10:03 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2017-03-03 00:07 - 2016-10-11 09:59 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2017-03-03 00:07 - 2016-10-11 09:59 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2017-03-03 00:07 - 2016-10-11 09:55 - 00346112 _____ (Microsoft Corporation) C:\windows\system32\bcdedit.exe
2017-03-03 00:07 - 2016-10-11 09:55 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2017-03-03 00:07 - 2016-10-11 09:51 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2017-03-03 00:07 - 2016-10-11 09:51 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2017-03-03 00:07 - 2016-10-11 09:51 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2017-03-03 00:07 - 2016-10-11 09:51 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2017-03-03 00:07 - 2016-10-11 09:50 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 09:50 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 09:50 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 09:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-03-03 00:07 - 2016-10-11 08:33 - 00187392 _____ (Microsoft Corporation) C:\windows\SysWOW64\UIAnimation.dll
2017-03-03 00:07 - 2016-10-11 08:18 - 00419648 _____ C:\windows\SysWOW64\locale.nls
2017-03-03 00:07 - 2016-10-11 08:17 - 00419648 _____ C:\windows\system32\locale.nls
2017-03-03 00:07 - 2016-10-11 08:06 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\UIAnimation.dll
2017-03-03 00:07 - 2016-10-08 08:06 - 00633296 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2017-03-03 00:07 - 2016-10-07 10:32 - 03649536 _____ (Microsoft Corporation) C:\windows\system32\MSVidCtl.dll
2017-03-03 00:07 - 2016-10-07 10:32 - 00877056 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
2017-03-03 00:07 - 2016-10-07 10:32 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\asycfilt.dll
2017-03-03 00:07 - 2016-10-07 10:12 - 02291712 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSVidCtl.dll
2017-03-03 00:07 - 2016-10-07 10:12 - 00581632 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleaut32.dll
2017-03-03 00:07 - 2016-10-07 10:12 - 00067584 _____ (Microsoft Corporation) C:\windows\SysWOW64\asycfilt.dll
2017-03-03 00:07 - 2016-10-05 09:54 - 00090112 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bowser.sys
2017-03-03 00:07 - 2016-10-04 10:31 - 01483264 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2017-03-03 00:07 - 2016-10-04 10:31 - 00229376 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2017-03-03 00:07 - 2016-10-04 10:31 - 00190976 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2017-03-03 00:07 - 2016-10-04 10:31 - 00141824 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2017-03-03 00:07 - 2016-10-04 10:13 - 01176064 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2017-03-03 00:07 - 2016-10-04 10:13 - 00179200 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2017-03-03 00:07 - 2016-10-04 10:13 - 00145920 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2017-03-03 00:07 - 2016-10-04 10:13 - 00106496 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptnet.dll
2017-03-03 00:07 - 2016-09-12 16:08 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\adsmsext.dll
2017-03-03 00:07 - 2016-09-12 15:49 - 00076800 _____ (Microsoft Corporation) C:\windows\SysWOW64\adsmsext.dll
2017-03-03 00:07 - 2016-09-12 14:08 - 01251328 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWrite.dll
2017-03-03 00:07 - 2016-09-12 13:43 - 01648128 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
2017-03-03 00:07 - 2016-09-12 13:43 - 01180160 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll
2017-03-03 00:07 - 2016-09-09 13:20 - 00756736 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll
2017-03-03 00:07 - 2016-09-09 13:00 - 00497152 _____ (Microsoft Corporation) C:\windows\SysWOW64\win32spl.dll
2017-03-03 00:07 - 2016-09-08 15:34 - 00263680 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll
2017-03-03 00:07 - 2016-09-08 15:34 - 00208896 _____ (Microsoft Corporation) C:\windows\SysWOW64\WebClnt.dll
2017-03-03 00:07 - 2016-09-08 15:34 - 00108544 _____ (Microsoft Corporation) C:\windows\system32\davclnt.dll
2017-03-03 00:07 - 2016-09-08 15:34 - 00087040 _____ (Microsoft Corporation) C:\windows\SysWOW64\davclnt.dll
2017-03-03 00:07 - 2016-09-08 09:55 - 00142336 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxdav.sys
2017-03-03 00:07 - 2016-09-08 09:55 - 00106496 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dfsc.sys
2017-03-03 00:07 - 2016-08-12 12:02 - 14632960 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2017-03-03 00:07 - 2016-08-12 12:02 - 12574720 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2017-03-03 00:07 - 2016-08-12 12:02 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\spwmp.dll
2017-03-03 00:07 - 2016-08-12 12:02 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\msdxm.ocx
2017-03-03 00:07 - 2016-08-12 12:02 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\dxmasf.dll
2017-03-03 00:07 - 2016-08-12 11:47 - 12574208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
2017-03-03 00:07 - 2016-08-12 11:47 - 11410432 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2017-03-03 00:07 - 2016-08-12 11:31 - 00008192 _____ (Microsoft Corporation) C:\windows\SysWOW64\spwmp.dll
2017-03-03 00:07 - 2016-08-12 11:31 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\msdxm.ocx
2017-03-03 00:07 - 2016-08-12 11:31 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxmasf.dll
2017-03-03 00:07 - 2016-08-12 11:26 - 00461312 _____ (Microsoft Corporation) C:\windows\system32\scavengeui.dll
2017-03-03 00:07 - 2016-08-06 10:31 - 02023424 _____ (Microsoft Corporation) C:\windows\system32\WsmSvc.dll
2017-03-03 00:07 - 2016-08-06 10:31 - 00347136 _____ (Microsoft Corporation) C:\windows\system32\WSManMigrationPlugin.dll
2017-03-03 00:07 - 2016-08-06 10:31 - 00310784 _____ (Microsoft Corporation) C:\windows\system32\WsmWmiPl.dll
2017-03-03 00:07 - 2016-08-06 10:31 - 00182272 _____ (Microsoft Corporation) C:\windows\system32\WsmAuto.dll
2017-03-03 00:07 - 2016-08-06 10:31 - 00054272 _____ (Microsoft Corporation) C:\windows\system32\WsmRes.dll
2017-03-03 00:07 - 2016-08-06 10:31 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\wsmplpxy.dll
2017-03-03 00:07 - 2016-08-06 10:15 - 01178112 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmSvc.dll
2017-03-03 00:07 - 2016-08-06 10:15 - 00249344 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSManMigrationPlugin.dll
2017-03-03 00:07 - 2016-08-06 10:15 - 00214016 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmWmiPl.dll
2017-03-03 00:07 - 2016-08-06 10:15 - 00146944 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmAuto.dll
2017-03-03 00:07 - 2016-08-06 10:15 - 00054272 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmRes.dll
2017-03-03 00:07 - 2016-08-06 10:01 - 00266752 _____ (Microsoft Corporation) C:\windows\system32\WSManHTTPConfig.exe
2017-03-03 00:07 - 2016-08-06 10:01 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\wsmprovhost.exe
2017-03-03 00:07 - 2016-08-06 09:53 - 00199168 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSManHTTPConfig.exe
2017-03-03 00:07 - 2016-08-06 09:53 - 00012288 _____ (Microsoft Corporation) C:\windows\SysWOW64\wsmprovhost.exe
2017-03-03 00:07 - 2016-08-06 09:53 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\wsmplpxy.dll
2017-03-03 00:07 - 2016-06-14 12:21 - 00094440 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mountmgr.sys
2017-03-03 00:07 - 2016-06-14 12:16 - 04121600 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
2017-03-03 00:07 - 2016-06-14 12:16 - 01573888 _____ (Microsoft Corporation) C:\windows\system32\quartz.dll
2017-03-03 00:07 - 2016-06-14 12:16 - 01202176 _____ (Microsoft Corporation) C:\windows\system32\drmv2clt.dll
2017-03-03 00:07 - 2016-06-14 12:16 - 01068544 _____ (Microsoft Corporation) C:\windows\system32\cryptui.dll
2017-03-03 00:07 - 2016-06-14 12:16 - 00842240 _____ (Microsoft Corporation) C:\windows\system32\blackbox.dll
2017-03-03 00:07 - 2016-06-14 12:16 - 00782848 _____ (Microsoft Corporation) C:\windows\system32\wmdrmsdk.dll
2017-03-03 00:07 - 2016-06-14 12:16 - 00680448 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2017-03-03 00:07 - 2016-06-14 12:16 - 00641024 _____ (Microsoft Corporation) C:\windows\system32\msscp.dll
2017-03-03 00:07 - 2016-06-14 12:16 - 00632320 _____ (Microsoft Corporation) C:\windows\system32\evr.dll
2017-03-03 00:07 - 2016-06-14 12:16 - 00499712 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll
2017-03-03 00:07 - 2016-06-14 12:16 - 00497664 _____ (Microsoft Corporation) C:\windows\system32\drmmgrtn.dll
2017-03-03 00:07 - 2016-06-14 12:16 - 00440320 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll
2017-03-03 00:07 - 2016-06-14 12:16 - 00433152 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll
2017-03-03 00:07 - 2016-06-14 12:16 - 00371712 _____ (Microsoft Corporation) C:\windows\system32\qdvd.dll
2017-03-03 00:07 - 2016-06-14 12:16 - 00325632 _____ (Microsoft Corporation) C:\windows\system32\msnetobj.dll
2017-03-03 00:07 - 2016-06-14 12:16 - 00295936 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
2017-03-03 00:07 - 2016-06-14 12:16 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\EncDump.dll
2017-03-03 00:07 - 2016-06-14 12:16 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2017-03-03 00:07 - 2016-06-14 12:16 - 00187904 _____ (Microsoft Corporation) C:\windows\system32\pcasvc.dll
2017-03-03 00:07 - 2016-06-14 12:16 - 00081920 _____ (Microsoft Corporation) C:\windows\system32\cryptsp.dll
2017-03-03 00:07 - 2016-06-14 12:16 - 00037376 _____ (Microsoft Corporation) C:\windows\system32\pcadm.dll
2017-03-03 00:07 - 2016-06-14 12:16 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\msmmsp.dll
2017-03-03 00:07 - 2016-06-14 12:16 - 00008704 _____ (Microsoft Corporation) C:\windows\system32\pcaevts.dll
2017-03-03 00:07 - 2016-06-14 12:16 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
2017-03-03 00:07 - 2016-06-14 12:11 - 00663552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\PEAuth.sys
2017-03-03 00:07 - 2016-06-14 10:21 - 03209216 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll
2017-03-03 00:07 - 2016-06-14 10:21 - 01329664 _____ (Microsoft Corporation) C:\windows\SysWOW64\quartz.dll
2017-03-03 00:07 - 2016-06-14 10:21 - 01005056 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptui.dll
2017-03-03 00:07 - 2016-06-14 10:21 - 00988160 _____ (Microsoft Corporation) C:\windows\SysWOW64\drmv2clt.dll
2017-03-03 00:07 - 2016-06-14 10:21 - 00744960 _____ (Microsoft Corporation) C:\windows\SysWOW64\blackbox.dll
2017-03-03 00:07 - 2016-06-14 10:21 - 00617984 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmdrmsdk.dll
2017-03-03 00:07 - 2016-06-14 10:21 - 00519680 _____ (Microsoft Corporation) C:\windows\SysWOW64\qdvd.dll
2017-03-03 00:07 - 2016-06-14 10:21 - 00504320 _____ (Microsoft Corporation) C:\windows\SysWOW64\msscp.dll
2017-03-03 00:07 - 2016-06-14 10:21 - 00489984 _____ (Microsoft Corporation) C:\windows\SysWOW64\evr.dll
2017-03-03 00:07 - 2016-06-14 10:21 - 00442368 _____ (Microsoft Corporation) C:\windows\SysWOW64\AUDIOKSE.dll
2017-03-03 00:07 - 2016-06-14 10:21 - 00406016 _____ (Microsoft Corporation) C:\windows\SysWOW64\drmmgrtn.dll
2017-03-03 00:07 - 2016-06-14 10:21 - 00374784 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioEng.dll
2017-03-03 00:07 - 2016-06-14 10:21 - 00354816 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfplat.dll
2017-03-03 00:07 - 2016-06-14 10:21 - 00265216 _____ (Microsoft Corporation) C:\windows\SysWOW64\msnetobj.dll
2017-03-03 00:07 - 2016-06-14 10:21 - 00195072 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioSes.dll
2017-03-03 00:07 - 2016-06-14 10:21 - 00103424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfps.dll
2017-03-03 00:07 - 2016-06-14 10:21 - 00080896 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsp.dll
2017-03-03 00:07 - 2016-06-14 10:21 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mferror.dll
2017-03-03 00:07 - 2016-06-14 10:15 - 00125952 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe
2017-03-03 00:07 - 2016-06-14 10:15 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
2017-03-03 00:07 - 2016-06-14 10:15 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
2017-03-03 00:07 - 2016-06-14 10:05 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\rrinstaller.exe
2017-03-03 00:07 - 2016-06-14 10:05 - 00023040 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfpmp.exe
2017-03-03 00:07 - 2016-06-14 10:00 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\pcawrk.exe
2017-03-03 00:07 - 2016-06-14 10:00 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\pcalua.exe
2017-03-02 22:10 - 2017-03-02 22:10 - 00000000 ____D C:\74fe19fad07c70f478d649f342
2017-03-02 21:18 - 2016-05-13 17:09 - 03156480 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2017-03-02 21:18 - 2016-05-13 17:09 - 00192512 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2017-03-02 21:18 - 2016-05-13 17:09 - 00098816 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2017-03-02 21:18 - 2016-05-13 17:07 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2017-03-02 21:18 - 2016-05-13 16:55 - 02607104 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2017-03-02 21:18 - 2016-05-13 16:53 - 00709120 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2017-03-02 21:18 - 2016-05-13 16:53 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2017-03-02 21:18 - 2016-05-13 16:52 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2017-03-02 21:18 - 2016-05-13 16:52 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2017-03-02 21:18 - 2016-05-13 16:52 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2017-03-02 21:18 - 2016-05-13 16:52 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2017-03-02 21:18 - 2016-05-13 16:50 - 00174080 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2017-03-02 21:18 - 2016-05-13 16:38 - 00573440 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2017-03-02 21:18 - 2016-05-13 16:38 - 00093696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2017-03-02 21:18 - 2016-05-13 16:38 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2017-03-02 21:18 - 2016-05-13 16:38 - 00030208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2017-03-02 21:18 - 2016-05-12 10:18 - 00090624 _____ (Microsoft Corporation) C:\windows\SysWOW64\olepro32.dll
2017-03-02 21:11 - 2017-03-02 22:09 - 564744309 _____ C:\Users\Amber\Downloads\Windows6.1-KB947821-v34-x64.msu
2017-03-02 21:09 - 2016-08-29 10:31 - 14183424 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2017-03-02 21:09 - 2016-08-29 10:31 - 01867776 _____ (Microsoft Corporation) C:\windows\system32\ExplorerFrame.dll
2017-03-02 21:09 - 2016-08-29 10:12 - 12880384 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2017-03-02 21:09 - 2016-08-29 10:12 - 01499648 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExplorerFrame.dll
2017-03-02 21:09 - 2016-08-29 10:04 - 03229696 _____ (Microsoft Corporation) C:\windows\explorer.exe
2017-03-02 21:09 - 2016-08-29 09:55 - 02972672 _____ (Microsoft Corporation) C:\windows\SysWOW64\explorer.exe
2017-03-02 21:09 - 2016-08-16 15:40 - 00343552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys
2017-03-02 21:09 - 2016-08-16 15:40 - 00327168 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys
2017-03-02 21:09 - 2016-08-16 15:40 - 00099840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys
2017-03-02 21:09 - 2016-08-16 15:40 - 00056320 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys
2017-03-02 21:09 - 2016-08-16 15:40 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys
2017-03-02 21:09 - 2016-08-16 15:40 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbohci.sys
2017-03-02 21:09 - 2016-08-16 15:40 - 00007808 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys
2017-03-02 21:09 - 2016-08-12 11:26 - 00464896 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv.sys
2017-03-02 21:09 - 2016-08-12 11:26 - 00405504 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv2.sys
2017-03-02 21:09 - 2016-08-12 11:26 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srvnet.sys
2017-03-02 21:09 - 2016-07-07 10:36 - 01896168 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2017-03-02 21:09 - 2016-07-07 10:36 - 00377576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys
2017-03-02 21:09 - 2016-07-07 10:36 - 00287976 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2017-03-02 21:09 - 2016-07-07 10:08 - 00046080 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpipreg.sys
2017-03-02 19:01 - 2017-03-02 19:01 - 00000000 ____D C:\windows\CheckSur
2017-03-02 13:22 - 2017-03-02 13:25 - 145401112 _____ (Microsoft Corporation) C:\Users\Amber\Downloads\msert.exe
2017-03-02 13:20 - 2017-03-02 13:20 - 00000000 ____D C:\Users\Amber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-03-02 11:45 - 2017-03-02 11:45 - 00044204 _____ C:\Users\Amber\Downloads\fix-error-code-0xc0000005.php
2017-03-02 11:36 - 2012-06-05 00:35 - 02198581 _____ C:\Windows6.1-KB2718841-x64.msu
2017-03-02 11:35 - 2017-03-02 11:36 - 02324072 _____ C:\Users\Amber\Downloads\448993_intl_x64_zip.exe
2017-03-01 22:19 - 2017-02-12 10:12 - 00547904 _____ (AVAST Software) C:\windows\system32\Drivers\aswB336.tmp
2017-03-01 22:19 - 2017-02-12 10:12 - 00337080 _____ (AVAST Software) C:\windows\system32\Drivers\aswB347.tmp
2017-03-01 22:19 - 2017-02-12 10:12 - 00162528 _____ (AVAST Software) C:\windows\system32\Drivers\aswB348.tmp
2017-03-01 22:19 - 2017-02-12 10:12 - 00126088 _____ (AVAST Software) C:\windows\system32\Drivers\aswB315.tmp
2017-03-01 22:19 - 2017-02-12 10:12 - 00100640 _____ (AVAST Software) C:\windows\system32\Drivers\aswB304.tmp
2017-03-01 22:19 - 2017-02-12 10:12 - 00074680 _____ (AVAST Software) C:\windows\system32\Drivers\aswB326.tmp
2017-03-01 22:19 - 2017-02-12 10:12 - 00038296 _____ (AVAST Software) C:\windows\system32\Drivers\aswB305.tmp
2017-03-01 22:19 - 2017-02-12 10:11 - 00991496 _____ (AVAST Software) C:\windows\system32\Drivers\aswB2F3.tmp
2017-03-01 22:19 - 2017-02-12 10:11 - 00334600 _____ (AVAST Software s.r.o.) C:\windows\system32\Drivers\aswB2C1.tmp
2017-03-01 22:19 - 2017-02-12 10:11 - 00309784 _____ (AVAST Software s.r.o.) C:\windows\system32\Drivers\aswB2B0.tmp
2017-03-01 22:19 - 2017-02-12 10:11 - 00189768 _____ (AVAST Software s.r.o.) C:\windows\system32\Drivers\aswB2C0.tmp
2017-03-01 22:19 - 2017-02-12 10:11 - 00048528 _____ (AVAST Software s.r.o.) C:\windows\system32\Drivers\aswB2D2.tmp
2017-03-01 22:19 - 2017-02-12 10:11 - 00032088 _____ (AVAST Software) C:\windows\system32\Drivers\aswB2E2.tmp
2017-02-24 21:04 - 2017-02-24 21:11 - 00000000 ____D C:\windows\SysWOW64\NV
2017-02-24 21:04 - 2017-02-24 21:11 - 00000000 ____D C:\windows\system32\NV
2017-02-24 21:01 - 2010-11-17 15:54 - 20450408 _____ (NVIDIA Corporation) C:\windows\system32\nvoglv64.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 18580072 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcompiler.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 18580072 _____ (NVIDIA Corporation) C:\windows\system32\nvcompiler.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 15039080 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvoglv32.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 13006952 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvlddmkm.sys
2017-02-24 21:01 - 2010-11-17 15:54 - 12831336 _____ (NVIDIA Corporation) C:\windows\system32\nvd3dumx.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 10053224 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvd3dum.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 07706728 _____ (NVIDIA Corporation) C:\windows\system32\nvwgf2umx.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 06598248 _____ (NVIDIA Corporation) C:\windows\system32\nvcuda.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 05629032 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvwgf2um.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 04936808 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuda.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 03182184 _____ (NVIDIA Corporation) C:\windows\system32\nvcuvid.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 02954856 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuvid.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 02871400 _____ (NVIDIA Corporation) C:\windows\system32\nvcuvenc.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 02579560 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuvenc.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 02196072 _____ (NVIDIA Corporation) C:\windows\system32\nvapi64.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 01961064 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvapi.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 01612392 _____ (NVIDIA Corporation) C:\windows\system32\nvdispco642080.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 01359976 _____ (NVIDIA Corporation) C:\windows\system32\nvgenco642040.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 00762984 _____ (NVIDIA Corporation) C:\windows\system32\nvumdshimx.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 00643176 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvumdshim.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 00446056 _____ (NVIDIA Corporation) C:\windows\system32\nvoptimusmft.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 00391784 _____ (NVIDIA Corporation) C:\windows\system32\nvdecodemft.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 00380520 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvoptimusmft.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 00320104 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvdecodemft.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 00226920 _____ (NVIDIA Corporation) C:\windows\system32\nvinitx.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 00192616 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvinit.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 00067176 _____ (Khronos Group) C:\windows\system32\OpenCL.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 00057960 _____ (Khronos Group) C:\windows\SysWOW64\OpenCL.dll
2017-02-24 21:01 - 2010-11-17 15:54 - 00025576 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvpciflt.sys
2017-02-24 21:01 - 2010-11-17 15:54 - 00011240 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvBridge.kmd
2017-02-24 20:33 - 2017-02-24 20:57 - 138054762 _____ C:\Users\Amber\Downloads\DISPLAY_NVIDIA_V8.17.12.6577_WIN7-64_DAR_11SP_B1.EXE
2017-02-24 12:00 - 2017-02-24 12:06 - 155337989 _____ C:\Users\Amber\Downloads\DISPLAY_V8.17.12.6780_WIN7-64_FPC46-1732-01(1).EXE
2017-02-24 11:57 - 2017-02-24 11:59 - 78658464 _____ (NVIDIA Corporation) C:\Users\Amber\Downloads\GeForce_Experience_v3.3.0.100(1).exe
2017-02-24 11:39 - 2017-02-24 11:39 - 00738880 _____ (Oracle Corporation) C:\Users\Amber\Downloads\jxpiinstall.exe
2017-02-24 11:37 - 2017-02-24 11:39 - 78658464 _____ (NVIDIA Corporation) C:\Users\Amber\Downloads\GeForce_Experience_v3.3.0.100.exe
2017-02-24 09:11 - 2017-02-24 09:34 - 155337989 _____ C:\Users\Amber\Downloads\DISPLAY_V8.17.12.6780_WIN7-64_FPC46-1732-01.EXE
2017-02-23 23:13 - 2011-12-12 02:57 - 04378392 _____ (Intel Corporation) C:\windows\system32\GfxUI.exe
2017-02-23 23:13 - 2011-12-12 02:57 - 00510232 _____ (Intel Corporation) C:\windows\system32\igfxsrvc.exe
2017-02-23 23:13 - 2011-12-12 02:57 - 00416024 _____ (Intel Corporation) C:\windows\system32\igfxpers.exe
2017-02-23 23:13 - 2011-12-12 02:57 - 00392472 _____ (Intel Corporation) C:\windows\system32\hkcmd.exe
2017-02-23 23:13 - 2011-12-12 02:57 - 00239896 _____ (Intel Corporation) C:\windows\system32\igfxext.exe
2017-02-23 23:13 - 2011-12-12 02:57 - 00184600 _____ (Intel Corporation) C:\windows\system32\difx64.exe
2017-02-23 23:13 - 2011-12-12 02:57 - 00167704 _____ (Intel Corporation) C:\windows\system32\igfxtray.exe
2017-02-23 23:13 - 2011-10-21 13:20 - 00017496 _____ C:\windows\system32\iglhxs64.vp
2017-02-23 23:13 - 2011-10-21 12:36 - 00090112 _____ (Intel Corporation) C:\windows\system32\igfxCoIn_v2559.dll
2017-02-23 23:13 - 2011-10-21 12:30 - 12310112 _____ (Intel Corporation) C:\windows\system32\Drivers\igdkmd64.sys
2017-02-23 23:13 - 2011-10-21 12:30 - 08313856 _____ (Intel Corporation) C:\windows\system32\igdumd64.dll
2017-02-23 23:13 - 2011-10-21 12:27 - 00217536 _____ C:\windows\SysWOW64\igfcg600m.bin
2017-02-23 23:13 - 2011-10-21 12:27 - 00217536 _____ C:\windows\system32\igfcg600m.bin
2017-02-23 23:13 - 2011-10-21 12:27 - 00075776 _____ C:\windows\system32\igdde64.dll
2017-02-23 23:13 - 2011-10-21 12:25 - 06323712 _____ (Intel Corporation) C:\windows\SysWOW64\igdumd32.dll
2017-02-23 23:13 - 2011-10-21 12:22 - 00056832 _____ C:\windows\SysWOW64\igdde32.dll
2017-02-23 23:13 - 2011-10-21 12:21 - 00581120 _____ (Intel Corporation) C:\windows\SysWOW64\igdumdx32.dll
2017-02-23 23:13 - 2011-10-21 12:19 - 14592512 _____ (Intel Corporation) C:\windows\system32\igd10umd64.dll
2017-02-23 23:13 - 2011-10-21 12:13 - 12340224 _____ (Intel Corporation) C:\windows\SysWOW64\igd10umd32.dll
2017-02-23 23:13 - 2011-10-21 12:08 - 18651648 _____ (Intel Corporation) C:\windows\system32\ig4icd64.dll
2017-02-23 23:13 - 2011-10-21 12:03 - 13903872 _____ C:\windows\SysWOW64\ig4icd32.dll
2017-02-23 23:13 - 2011-10-21 11:59 - 00287232 _____ (Intel Corporation) C:\windows\system32\igfxresn.lrc
2017-02-23 23:13 - 2011-10-21 11:59 - 00287232 _____ (Intel Corporation) C:\windows\system32\igfxrell.lrc
2017-02-23 23:13 - 2011-10-21 11:59 - 00286720 _____ (Intel Corporation) C:\windows\system32\igfxrsky.lrc
2017-02-23 23:13 - 2011-10-21 11:59 - 00286720 _____ (Intel Corporation) C:\windows\system32\igfxrrus.lrc
2017-02-23 23:13 - 2011-10-21 11:59 - 00286720 _____ (Intel Corporation) C:\windows\system32\igfxrrom.lrc
2017-02-23 23:13 - 2011-10-21 11:59 - 00286720 _____ (Intel Corporation) C:\windows\system32\igfxrptg.lrc
2017-02-23 23:13 - 2011-10-21 11:59 - 00286720 _____ (Intel Corporation) C:\windows\system32\igfxrplk.lrc
2017-02-23 23:13 - 2011-10-21 11:59 - 00286720 _____ (Intel Corporation) C:\windows\system32\igfxrita.lrc
2017-02-23 23:13 - 2011-10-21 11:59 - 00286720 _____ (Intel Corporation) C:\windows\system32\igfxrhrv.lrc
2017-02-23 23:13 - 2011-10-21 11:59 - 00286208 _____ (Intel Corporation) C:\windows\system32\igfxrtrk.lrc
2017-02-23 23:13 - 2011-10-21 11:59 - 00286208 _____ (Intel Corporation) C:\windows\system32\igfxrsve.lrc
2017-02-23 23:13 - 2011-10-21 11:59 - 00286208 _____ (Intel Corporation) C:\windows\system32\igfxrslv.lrc
2017-02-23 23:13 - 2011-10-21 11:59 - 00286208 _____ (Intel Corporation) C:\windows\system32\igfxrptb.lrc
2017-02-23 23:13 - 2011-10-21 11:59 - 00286208 _____ (Intel Corporation) C:\windows\system32\igfxrnor.lrc
2017-02-23 23:13 - 2011-10-21 11:59 - 00286208 _____ (Intel Corporation) C:\windows\system32\igfxrhun.lrc
2017-02-23 23:13 - 2011-10-21 11:59 - 00285696 _____ (Intel Corporation) C:\windows\system32\igfxrtha.lrc
2017-02-23 23:13 - 2011-10-21 11:59 - 00285184 _____ (Intel Corporation) C:\windows\system32\igfxrheb.lrc
2017-02-23 23:13 - 2011-10-21 11:59 - 00283648 _____ (Intel Corporation) C:\windows\system32\igfxrjpn.lrc
2017-02-23 23:13 - 2011-10-21 11:59 - 00283136 _____ (Intel Corporation) C:\windows\system32\igfxrkor.lrc
2017-02-23 23:13 - 2011-10-21 11:59 - 00211303 _____ C:\windows\system32\Gfxres.th-TH.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00198139 _____ C:\windows\system32\Gfxres.el-GR.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00182706 _____ C:\windows\system32\Gfxres.ru-RU.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00156233 _____ C:\windows\system32\Gfxres.ar-SA.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00153167 _____ C:\windows\system32\Gfxres.ja-JP.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00149009 _____ C:\windows\system32\Gfxres.he-IL.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00140216 _____ C:\windows\system32\Gfxres.it-IT.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00138727 _____ C:\windows\system32\Gfxres.ko-KR.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00137846 _____ C:\windows\system32\Gfxres.de-DE.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00137668 _____ C:\windows\system32\Gfxres.es-ES.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00136603 _____ C:\windows\system32\Gfxres.ro-RO.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00135628 _____ C:\windows\system32\Gfxres.fr-FR.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00135370 _____ C:\windows\system32\Gfxres.tr-TR.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00134836 _____ C:\windows\system32\Gfxres.pt-BR.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00134412 _____ C:\windows\system32\Gfxres.nl-NL.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00134384 _____ C:\windows\system32\Gfxres.hu-HU.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00133846 _____ C:\windows\system32\Gfxres.sv-SE.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00133709 _____ C:\windows\system32\Gfxres.pt-PT.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00133404 _____ C:\windows\system32\Gfxres.cs-CZ.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00133178 _____ C:\windows\system32\Gfxres.pl-PL.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00132889 _____ C:\windows\system32\Gfxres.fi-FI.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00132788 _____ C:\windows\system32\Gfxres.sk-SK.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00131839 _____ C:\windows\system32\Gfxres.hr-HR.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00128996 _____ C:\windows\system32\Gfxres.sl-SI.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00128831 _____ C:\windows\system32\Gfxres.nb-NO.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00128535 _____ C:\windows\system32\Gfxres.da-DK.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00117636 _____ C:\windows\system32\Gfxres.zh-TW.resources
2017-02-23 23:13 - 2011-10-21 11:59 - 00116348 _____ C:\windows\system32\Gfxres.zh-CN.resources
2017-02-23 23:13 - 2011-10-21 11:58 - 00378368 _____ (Intel Corporation) C:\windows\system32\igfxTMM.dll
2017-02-23 23:13 - 2011-10-21 11:58 - 00375808 _____ (Intel Corporation) C:\windows\system32\igfxpph.dll
2017-02-23 23:13 - 2011-10-21 11:58 - 00287232 _____ (Intel Corporation) C:\windows\system32\igfxrfra.lrc
2017-02-23 23:13 - 2011-10-21 11:58 - 00286720 _____ (Intel Corporation) C:\windows\system32\igfxrnld.lrc
2017-02-23 23:13 - 2011-10-21 11:58 - 00286720 _____ (Intel Corporation) C:\windows\system32\igfxrdeu.lrc
2017-02-23 23:13 - 2011-10-21 11:58 - 00286720 _____ (Intel Corporation) C:\windows\system32\igfxrcsy.lrc
2017-02-23 23:13 - 2011-10-21 11:58 - 00286208 _____ (Intel Corporation) C:\windows\system32\igfxrfin.lrc
2017-02-23 23:13 - 2011-10-21 11:58 - 00285696 _____ (Intel Corporation) C:\windows\system32\igfxrdan.lrc
2017-02-23 23:13 - 2011-10-21 11:58 - 00285184 _____ (Intel Corporation) C:\windows\system32\igfxrara.lrc
2017-02-23 23:13 - 2011-10-21 11:58 - 00282624 _____ (Intel Corporation) C:\windows\system32\igfxrcht.lrc
2017-02-23 23:13 - 2011-10-21 11:58 - 00282624 _____ (Intel Corporation) C:\windows\system32\igfxrchs.lrc
2017-02-23 23:13 - 2011-10-21 11:58 - 00126976 _____ (Intel Corporation) C:\windows\system32\igfxcpl.cpl
2017-02-23 23:13 - 2011-10-21 11:58 - 00124056 _____ C:\windows\system32\Gfxres.en-US.resources
2017-02-23 23:13 - 2011-10-21 11:58 - 00028672 _____ (Intel Corporation) C:\windows\system32\igfxexps.dll
2017-02-23 23:13 - 2011-10-21 11:57 - 00390144 _____ (Intel Corporation) C:\windows\system32\igfxdev.dll
2017-02-23 23:13 - 2011-10-21 11:57 - 00146432 _____ (Intel Corporation) C:\windows\system32\gfxSrvc.dll
2017-02-23 23:13 - 2011-10-21 11:57 - 00110080 _____ (Intel Corporation) C:\windows\system32\hccutils.dll
2017-02-23 23:13 - 2011-10-21 11:57 - 00062464 _____ (Intel Corporation) C:\windows\system32\igfxsrvc.dll
2017-02-23 23:13 - 2011-10-21 11:57 - 00004096 _____ ( ) C:\windows\system32\IGFXDEVLib.dll
2017-02-23 23:13 - 2011-10-21 11:56 - 09014784 _____ (Intel Corporation) C:\windows\system32\igfxress.dll
2017-02-23 23:13 - 2011-10-21 11:56 - 00285696 _____ (Intel Corporation) C:\windows\system32\igfxrenu.lrc
2017-02-23 23:13 - 2011-10-21 11:56 - 00142336 _____ (Intel Corporation) C:\windows\system32\igfxdo.dll
2017-02-23 23:13 - 2011-10-21 11:52 - 00294400 _____ (Intel Corporation) C:\windows\SysWOW64\igfxdv32.dll
2017-02-23 23:13 - 2011-10-21 11:52 - 00024576 _____ (Intel Corporation) C:\windows\SysWOW64\igfxexps32.dll
2017-02-23 23:13 - 2011-10-21 11:49 - 02177536 _____ (Intel Corporation) C:\windows\system32\igfxcmjit64.dll
2017-02-23 23:13 - 2011-10-21 11:49 - 01663488 _____ (Intel Corporation) C:\windows\SysWOW64\igfxcmjit32.dll
2017-02-23 23:13 - 2011-10-21 11:49 - 00171520 _____ (Intel Corporation) C:\windows\SysWOW64\igfxcmrt32.dll
2017-02-23 23:13 - 2011-10-21 11:49 - 00148480 _____ (Intel Corporation) C:\windows\system32\igfxcmrt64.dll
2017-02-23 23:13 - 2011-08-23 08:12 - 00317440 _____ (Intel® Corporation) C:\windows\system32\Drivers\IntcDAud.sys
2017-02-23 23:13 - 2011-08-23 08:12 - 00014848 _____ (Intel® Corporation) C:\windows\system32\IntcDAuC.dll
2017-02-23 22:16 - 2017-02-23 22:35 - 67753330 _____ C:\Users\Amber\Downloads\DISPLAY_INTEL_V8.15.10.2559_WIN7-64_FPC46-1770-01.EXE
2017-02-23 22:14 - 2017-02-23 22:15 - 02612545 _____ C:\Users\Amber\Downloads\CHIPSET_V9.2.0.1021_WIN7-64_DAR_11WI_A1.EXE
2017-02-23 08:13 - 2017-02-23 08:13 - 02030536 _____ (Bleeping Computer, LLC) C:\Users\Amber\Downloads\rkill.com
2017-02-23 07:53 - 2017-02-23 07:53 - 00002144 _____ C:\Users\Public\Desktop\Google Earth.lnk
2017-02-23 07:53 - 2017-02-23 07:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
2017-02-12 11:48 - 2017-02-12 11:48 - 00451741 _____ C:\Users\Amber\Documents\BOZ DDA Account Statements - 1_18_2017 - 6833966 - ROBBIE W SOUTH.pdf
2017-02-12 10:12 - 2017-03-03 01:50 - 00003914 _____ C:\windows\System32\Tasks\Avast Emergency Update
2017-02-12 10:12 - 2017-03-03 01:49 - 00334600 _____ (AVAST Software s.r.o.) C:\windows\system32\Drivers\aswbloga.sys
2017-02-12 10:12 - 2017-03-03 01:49 - 00309272 _____ (AVAST Software s.r.o.) C:\windows\system32\Drivers\aswbidsdrivera.sys
2017-02-12 10:12 - 2017-03-03 01:49 - 00189768 _____ (AVAST Software s.r.o.) C:\windows\system32\Drivers\aswbidsha.sys
2017-02-12 10:12 - 2017-03-03 01:49 - 00048528 _____ (AVAST Software s.r.o.) C:\windows\system32\Drivers\aswbuniva.sys

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-03-08 18:49 - 2016-11-18 20:20 - 00000000 ____D C:\Users\Amber\AppData\LocalLow\Mozilla
2017-03-08 18:49 - 2012-04-02 17:48 - 10877568 _____ C:\windows\ntbtlog.txt
2017-03-07 10:51 - 2016-11-22 01:04 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2017-03-07 10:51 - 2012-05-03 08:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-03-05 17:22 - 2012-04-03 01:02 - 00000000 ____D C:\Users\Amber\AppData\Local\CrashDumps
2017-03-05 16:06 - 2013-08-04 23:34 - 00000000 ____D C:\ProgramData\Pyware 3D v7
2017-03-05 12:55 - 2015-01-08 01:34 - 00000000 ____D C:\Program Files (x86)\Emsisoft Anti-Malware
2017-03-05 12:53 - 2012-08-02 19:36 - 00000000 ____D C:\temp
2017-03-05 12:53 - 2012-04-01 20:38 - 00000830 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2017-03-05 12:51 - 2009-07-14 00:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2017-03-04 22:05 - 2012-03-30 09:23 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2017-03-04 18:29 - 2009-07-13 23:45 - 00018736 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-03-04 18:29 - 2009-07-13 23:45 - 00018736 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-03-04 08:40 - 2015-01-09 23:46 - 00000000 ____D C:\windows\pss
2017-03-03 02:22 - 2013-09-06 20:58 - 00000000 ___RD C:\Users\Amber\Dropbox
2017-03-03 02:20 - 2015-01-04 22:23 - 00000000 ___RD C:\Users\Amber\Google Drive
2017-03-03 02:19 - 2014-09-16 22:18 - 00000000 ____D C:\Users\Amber\AppData\Roaming\TortoiseHg
2017-03-03 01:56 - 2017-01-08 13:47 - 00003880 _____ C:\windows\System32\Tasks\SafeZone scheduled Autoupdate 1463750328
2017-03-03 01:53 - 2009-07-13 23:45 - 00481904 _____ C:\windows\system32\FNTCACHE.DAT
2017-03-03 01:51 - 2017-01-08 13:47 - 00001882 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2017-03-03 01:50 - 2014-10-16 14:51 - 00162528 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2017-03-03 01:50 - 2014-10-16 14:51 - 00038296 _____ (AVAST Software) C:\windows\system32\Drivers\aswHwid.sys
2017-03-03 01:50 - 2014-10-03 14:46 - 00337592 _____ (AVAST Software) C:\windows\system32\Drivers\aswVmm.sys
2017-03-03 01:50 - 2014-10-03 14:46 - 00075704 _____ (AVAST Software) C:\windows\system32\Drivers\aswRvrt.sys
2017-03-03 01:50 - 2012-03-23 17:47 - 00547904 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2017-03-03 01:50 - 2012-03-23 17:47 - 00126600 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2017-03-03 01:50 - 2012-03-23 17:47 - 00100640 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2017-03-03 01:49 - 2012-04-10 16:26 - 00032088 _____ (AVAST Software) C:\windows\system32\Drivers\aswKbd.sys
2017-03-03 01:49 - 2012-03-23 17:47 - 00993608 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2017-03-03 01:38 - 2015-06-20 23:07 - 00000918 _____ C:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-2524020813-2562236670-706791055-1001UA.job
2017-03-03 01:33 - 2014-12-10 03:23 - 00000000 ____D C:\windows\system32\appraiser
2017-03-03 01:33 - 2014-05-06 12:34 - 00000000 ___SD C:\windows\system32\CompatTel
2017-03-03 01:32 - 2009-07-13 22:20 - 00000000 ____D C:\windows\inf
2017-03-03 01:06 - 2014-12-19 18:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2017-03-03 01:03 - 2012-03-25 10:44 - 00776078 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2017-03-03 01:03 - 2009-07-14 00:13 - 00776078 _____ C:\windows\system32\PerfStringBackup.INI
2017-03-03 00:34 - 2013-07-15 14:51 - 00000000 ____D C:\windows\system32\MRT
2017-03-03 00:28 - 2012-03-24 09:26 - 138020592 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2017-03-03 00:12 - 2009-07-13 22:20 - 00000000 ____D C:\windows\SysWOW64\Dism
2017-03-03 00:12 - 2009-07-13 22:20 - 00000000 ____D C:\windows\system32\Dism
2017-03-02 23:47 - 2012-03-25 10:45 - 00000000 ____D C:\Users\Amber\AppData\Roaming\SoftGrid Client
2017-03-02 23:16 - 2009-07-14 02:45 - 00000000 ____D C:\windows\ShellNew
2017-03-02 21:57 - 2014-12-17 13:45 - 00000000 ____D C:\Program Files\SharePoint Client Components
2017-03-02 21:48 - 2012-05-15 17:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-03-02 21:47 - 2012-05-15 17:33 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-03-02 21:47 - 2012-05-15 17:33 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-03-02 20:06 - 2014-06-30 11:58 - 00192216 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2017-03-02 17:37 - 2015-06-20 23:07 - 00000866 _____ C:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-2524020813-2562236670-706791055-1001Core.job
2017-03-02 13:20 - 2013-09-06 18:47 - 00000000 ____D C:\Users\Amber\AppData\Roaming\Dropbox
2017-03-02 11:19 - 2012-11-01 11:28 - 00000000 ____D C:\Users\Amber\AppData\Local\ElevatedDiagnostics
2017-03-01 22:11 - 2012-03-23 09:15 - 00000000 ____D C:\Users\Amber
2017-03-01 22:10 - 2015-12-04 18:13 - 00000000 ____D C:\windows\System32\Tasks\AVAST Software
2017-03-01 22:10 - 2012-08-02 12:52 - 00000000 ____D C:\Users\Administrator
2017-03-01 22:10 - 2009-07-14 02:44 - 00000000 ___RD C:\Users\Public\Recorded TV
2017-03-01 22:10 - 2009-07-13 22:20 - 00000000 ____D C:\windows\registration
2017-02-24 21:24 - 2012-03-30 23:37 - 00000000 ____D C:\Users\Amber\AppData\Roaming\Nitro PDF
2017-02-24 21:04 - 2011-08-03 17:43 - 00000000 ____D C:\ProgramData\NVIDIA
2017-02-24 21:02 - 2011-08-03 17:43 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-02-24 21:02 - 2011-08-03 17:42 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-02-24 21:02 - 2009-07-13 22:20 - 00000000 ____D C:\windows\Help
2017-02-24 15:25 - 2009-07-13 23:45 - 00012288 _____ C:\windows\system32\umstartup.etl
2017-02-24 15:23 - 2014-12-20 12:15 - 00000000 ____D C:\Users\Administrator\AppData\Local\CrashDumps
2017-02-24 15:21 - 2014-12-20 12:12 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\TortoiseHg
2017-02-24 15:08 - 2016-01-09 13:38 - 00000000 ____D C:\Program Files (x86)\GeoComply
2017-02-24 12:27 - 2009-07-14 00:08 - 00032618 _____ C:\windows\Tasks\SCHEDLGU.TXT
2017-02-24 11:53 - 2012-04-01 20:38 - 00802904 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2017-02-24 11:53 - 2012-04-01 20:38 - 00003768 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2017-02-24 11:53 - 2012-03-24 09:08 - 00144472 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-02-24 11:53 - 2012-03-24 09:08 - 00000000 ____D C:\windows\SysWOW64\Macromed
2017-02-24 11:53 - 2012-03-24 09:08 - 00000000 ____D C:\windows\system32\Macromed
2017-02-24 11:45 - 2013-10-15 18:02 - 00000000 ____D C:\ProgramData\Oracle
2017-02-24 11:44 - 2014-09-06 17:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2017-02-24 11:44 - 2013-10-15 18:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-02-24 11:44 - 2012-04-03 00:10 - 00000000 ____D C:\Program Files (x86)\Java
2017-02-24 11:42 - 2014-08-28 18:28 - 00097856 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2017-02-24 11:32 - 2014-08-28 17:22 - 00000000 ____D C:\Users\Amber\AppData\LocalLow\HPAppData
2017-02-24 11:30 - 2016-11-02 20:03 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-02-24 11:14 - 2011-08-03 17:43 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-02-23 08:48 - 2015-08-28 15:29 - 00003030 _____ C:\Users\Amber\Desktop\Rkill.txt
2017-02-23 07:53 - 2011-08-03 18:13 - 00000000 ____D C:\Program Files (x86)\Google
2017-02-23 07:43 - 2012-03-23 17:46 - 00000000 ____D C:\ProgramData\AVAST Software
2017-02-15 23:28 - 2012-08-02 12:52 - 00130152 _____ C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2017-02-15 22:47 - 2014-12-20 12:12 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\ControlCenter4
2017-02-15 22:46 - 2014-12-20 12:12 - 00002255 _____ C:\Users\Administrator\Desktop\Google Chrome.lnk
2017-02-15 22:46 - 2012-08-02 12:52 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google
2017-02-15 22:46 - 2009-07-13 23:57 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2017-02-12 10:44 - 2017-01-18 09:43 - 00003680 _____ C:\windows\System32\Tasks\GeoComply Update Task
2017-02-12 10:13 - 2012-03-23 18:06 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-02-12 10:12 - 2014-10-03 14:46 - 00337080 _____ (AVAST Software) C:\windows\system32\Drivers\aswvmm.sys.148691237980004
2017-02-12 09:49 - 2012-04-06 16:45 - 00003902 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{0E626F3C-8A24-4FFB-84FD-07195C3D7244}
2017-02-12 09:13 - 2016-11-17 22:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox

==================== Files in the root of some directories =======

2015-01-10 20:01 - 2015-01-11 16:26 - 0030208 ___SH () C:\Users\Amber\AppData\Roaming\Thumbs.db
2013-11-12 09:17 - 2013-11-12 09:17 - 0026131 _____ () C:\Users\Amber\AppData\Roaming\UserTile.png
2012-03-23 09:23 - 2012-03-23 09:23 - 0015311 _____ () C:\Users\Amber\AppData\Local\IWDAudHelper.20120323.102327.txt
2012-03-23 09:23 - 2012-03-23 09:23 - 0000661 _____ () C:\Users\Amber\AppData\Local\PDLSetup.20120323.102313.txt
2012-03-23 09:23 - 2012-03-23 09:23 - 0001578 _____ () C:\Users\Amber\AppData\Local\PDLSetup.20120323.102315.txt
2012-03-23 09:23 - 2012-03-23 09:23 - 0001245 _____ () C:\Users\Amber\AppData\Local\PDLSetup.20120323.102318.txt
2014-12-07 13:00 - 2014-12-08 12:17 - 0000600 _____ () C:\Users\Amber\AppData\Local\PUTTY.RND
2012-06-23 13:00 - 2012-06-23 13:00 - 0000017 _____ () C:\Users\Amber\AppData\Local\resmon.resmoncfg
2012-08-26 16:03 - 2016-06-29 00:49 - 3725568 _____ () C:\Users\Amber\AppData\Local\rx_audio.Cache
2012-08-26 16:02 - 2016-06-29 00:49 - 10260656 _____ () C:\Users\Amber\AppData\Local\rx_image32.Cache
2014-08-26 01:12 - 2015-08-28 16:23 - 0001787 _____ () C:\ProgramData\hpzinstall.log
2014-12-14 22:14 - 2014-12-14 22:14 - 0000153 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc

Files to move or delete:
====================
C:\Users\Amber\WDMyCloud_win.exe


Some files in TEMP:
====================
2012-10-01 05:22 - 2012-10-01 05:22 - 0150648 ____R (Microsoft Corporation) C:\Users\Amber\AppData\Local\Temp\ose00000.exe
2006-05-24 12:10 - 2006-05-24 12:10 - 0455600 ____R (Macrovision Corporation) C:\Users\Amber\AppData\Local\Temp\_isDDEF.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\windows\system32\winlogon.exe => MD5 is legit
C:\windows\system32\wininit.exe => MD5 is legit
C:\windows\SysWOW64\wininit.exe => MD5 is legit
C:\windows\explorer.exe
[2017-03-02 21:09] - [2016-08-29 10:04] - 3229696 ____A (Microsoft Corporation) 38AE1B3C38FAEF56FE4907922F0385BA

C:\windows\SysWOW64\explorer.exe
[2017-03-02 21:09] - [2016-08-29 09:55] - 2972672 ____A (Microsoft Corporation) 6DDCA324434FFA506CF7DC4E51DB7935

C:\windows\system32\svchost.exe => MD5 is legit
C:\windows\SysWOW64\svchost.exe => MD5 is legit
C:\windows\system32\services.exe => MD5 is legit
C:\windows\system32\User32.dll
[2017-03-03 00:07] - [2016-11-10 11:32] - 1009152 ____A (Microsoft Corporation) 34BA256FBF83457F9D5E51A56DB54542

C:\windows\SysWOW64\User32.dll
[2017-03-03 00:07] - [2016-11-10 11:19] - 0833024 ____A (Microsoft Corporation) 3CB074875AC88A7C1010A2A7F9881A8C

C:\windows\system32\userinit.exe => MD5 is legit
C:\windows\SysWOW64\userinit.exe => MD5 is legit
C:\windows\system32\rpcss.dll => MD5 is legit
C:\windows\system32\dnsapi.dll => MD5 is legit
C:\windows\SysWOW64\dnsapi.dll => MD5 is legit
C:\windows\system32\Drivers\volsnap.sys => MD5 is legit

LastRegBack: 2017-02-25 02:08

==================== End of FRST.txt ============================

 

 

 

 

Original post: https://www.bleepingcomputer.com/forums/t/641367/0xc0000005-renders-computer-unusable-isdelexe-missing-inconsistencies/

 

Windows 7 Home Premium SP1 on a Fujitsu Lifebook NH751 that has given me problems from nearly day 1. The keyboard stopped working correctly pretty quickly, and I can no longer use it because it now registers as a stuck key even when nothing is pressed. I have to press escape to make it stop. Thus, I can no longer run check disk because it aborts immediately. That is the one thing I have not done while dealing with this problem... The last time I was able to run one (quite some time ago), it did show an error but I cannot find where I noted the information. That said, I do not think that it is a factor in this problem because of the long span of time between that error being caught and having any symptoms of any problem. I have included a list of what I have done over the past week. It may be out of order a bit, but it should be comprehensive.

 

The problem may have begun several weeks ago when Firefox began crashing repeatedly when more than 10 tabs were open in a window. All Avast, MBAM, and SAS scans were clean (except the normal tracking cookie stuff). I run AdBlocker Plus and NoScript, so that helps keep out some of the junk, and I had not allowed anything new so I didn't question the clean scans.

 

About a week ago, booting resulted in a constant barrage of application error 0xC0000005, and the application being unable to start. In short, the computer was rendered useless. Nothing would run.

 

I can boot in safe mode with networking, which is how I have done most of the repair attempts. Some programs will work at times, but then not work the next boot in safe mode. It's random enough that I can't figure it out.

 

A few times in this process, the computer would boot normally. Then with no changes whatsoever when I would shut down and reboot the next day the barrage of 0xC0000005 would begin again as if nothing had been repaired.

 

At times, the computer will fail to boot. Just freezes on the blank screen before the splash, or freezes on the first screen (Fujitsu). F-keys for booting, BIOS, and safe mode do nothing.

 

Also randomly, I will try to boot normally and after I choose the user, the screen goes black, but the arrow still moves for the mouse. It never progresses beyond this. Waited a few hours several times. Each time, I'm able to control + alt + delete to get to the task manager and restart in safe mode.

 

Sometimes a clean boot will run, sometimes the barrage of 0xC0000005 begins.

 

 

What I have done, some with the help of various websites:

  • Unplugged the USB keyboard and mouse. No change.
  • Ran SAS multiple times. Nothing but tracking cookies.
  • Ran MBAM multiple times. Nothing but tracking cookies.
  • Ran rkill, then SAS and MBAM again. Again, nothing.
  • Avast will not run, so I cannot scan with it anymore. I uninstalled and reinstalled, still will not run.
  • Updated all drivers in the Device Manager.
  • Used the Registry Editor to change LoadAppInit_DLLs and changed the value to 0 (it was 1). No change, and it later reset itself to 1 at some point in the process.
  • Still in Registry Editor, checked REG_SZ (was correctly set to 0) and _______ (can't remember, but it was correct as well)
  • Ran Windows Memory Diagnostic. No issues found.
  • Uninstalled the drivers for the Nvidia GeForce video card that has given me trouble in the past. After I did that, normal boot and everything worked, so I thought that was the answer. Installed the oldest version of the drivers I could find and restarted. 0xC0000005 was back. Uninstalled the old drivers. 0xC0000005 was back.
  • Immediately following the Nvidia drivers second uninstall and failure to resolve the problem, I used a restore point. (Side note: all previous restore points were gone, and this one just appeared even when I didn't specifically create one. Not sure what happened there.) It booted and ran just fine once. No changes made, but on the next boot 0xC0000005 was back.
  • Used an elevated command prompt to run sfc /scannow. The first run through, there were a lot of repairs made. Unfortunately, that log was gone as soon as I ran sfc /scannow again (my apologies for not remembering that it would overwrite). Each subsequent run, the only errors are these:
    • 2017-03-03 18:29:11, Info CSI    0000035c [SR] Repairing 1 components
    • 2017-03-03 18:29:11, Info CSI    0000035d [SR] Beginning Verify and Repair transaction
    • 2017-03-03 18:29:11, Info CSI    0000035e [SR] Cannot repair member file [l:20{10}]"_isdel.exe" of Microsoft-Windows-InstallShield-WOW64-Main, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing
    • 2017-03-03 18:29:11, Info CSI    0000035f [SR] Cannot repair member file [l:20{10}]"_isdel.exe" of Microsoft-Windows-InstallShield-WOW64-Main, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing
    • 2017-03-03 18:29:11, Info CSI    00000360 [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery"
    • 2017-03-03 18:29:11, Info CSI    00000361 [SR] Could not reproject corrupted file [ml:76{38},l:74{37}]"\??\C:\windows\SysWOW64\InstallShield"\[l:20{10}]"_isdel.exe"; source file in store is also corrupted
  • Checked Boot Configuration Data. The Windows boot loader path was correct.
  • Set msconfig to a clean boot (all disabled except Microsoft applications). It actually booted normally and worked.
  • During the clean boot, downloaded and ran Microsoft Safety Scanner.  Came back clean. Next boot, 0xC0000005 was back.
  • Somewhere in the middle of all of this, it booted normally a few times and I thought it was fixed, so I downloaded a bunch of updates that I had ignored for a couple of months. Still booted normally during the restarts for the updates. Got some work done. Then again, randomly, 0xC0000005 reappeared when I tried to boot normally.
  • Downloaded and used the System Update Readiness Tool.
    • Checking Component Store
    • (f)    CSI Payload File Missing    0x00000000    _isdel.exe    wow64_microsoft-windows-i..llshield-wow64-main_31bf3856ad364e35_6.1.7600.16385_none_ca61f601a4548b8e
    • (f)    CSI C Mark Deployment Missing    0x00000000    c!avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_0b20a8ff883c3a4a    x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c
    • (f)    CSI C Mark Deployment Missing    0x00000000    c!avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_c373722873c01144    amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396
    • (f)    CSI C Mark Deployment Missing    0x00000000    c!avast.vc140.mfc_fcc99ee6193ebbca_14.0.24210.0_49391d6d8244622b    x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.24210.0_none_a338d8ea2df29efb
    • (f)    CSI C Mark Deployment Missing    0x00000000    c!policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_ef17e13d91c55d96    amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_none_499a1b14d5902dfc
    • (f)    CSI C Mark Deployment Missing    0x00000000    c!policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_36c51814a641869c    x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_none_914751ebea0c5702
    • (f)    CSI C Mark Deployment Missing    0x00000000    c!avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_020285fe6d6e0580    amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_none_56aba0211ca246c2
    • (f)    CSI C Mark Deployment Missing    0x00000000    c!policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.24210.0_364e78aca69bba41    x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.24210.0_none_962753dde6e08635
    • (f)    CSI C Mark Deployment Missing    0x00000000    c!avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_49afbcd581ea2e86    x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.24210.0_none_9e58d6f8311e6fc8
    • Summary:
      Seconds executed: 175
       Found 9 errors
        CSI C Mark Deployment Missing Total count: 8
        CSI Payload File Missing Total count: 1
  • Used the DISM.
    • Ran Dism /Online /Cleanup-Image /CheckHealth
    • Ran DISM /Online /Cleanup-image /Scanhealth Got an error message. ~Deployment Image Servicing and Management tool Version: 6 . 1 . 7601 . 18489   Error:  87 The restorehealth option in not recognized in this context.~ I did not see anything in the log about  this, but maybe I was missing it.
    • Ran Dism /Online /Cleanup-Image /RestoreHealth
    • If I recall correctly, I also ran Dism.exe /Online /Cleanup-image /StartComponentCleanup.
    • The only problem (potential problem? Not sure.) was:
      • DISM   DISM Provider Store: PID=3060 Failed to get and initialize the PE Provider.  Continuing by assuming that it is not a WinPE image. - CDISMProviderStore::Final_OnConnect

 

I could fill up at least 50 pages with scan logs, so I'll hold those and give you what you specifically ask for. At this point, I have no clue whether or not it's infected. Nothing is adding up. I have seen some info that 0xC0000005 is related to an infection. I have also seen where there is a virus that used the name SysWOW64 basically to spoof, but at the same time InstallShield is a real thing. That said, I can't see how _isdel.exe missing would cause all of this since I wasn't using InstallShield to install or update or anything when this started...

 

I'm at the point that if it isn't infected, then the only thing I know to do is an update install (so I don't have to reinstall all the programs; all files are already on my home cloud). That said, I have a valid product key but I can't download the ISO files from Microsoft because they no longer support preinstalled versions. So I'll have to find another way to do that...



#4 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,612 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:01:57 AM

Posted 13 March 2017 - 11:29 AM

Hello,

My apologies for the delay in getting back to you. Sintharius is having some hardware trouble, so I'll work with you from here until she is back.

 

Can you first of all please uninstall SAS. It wouldn't be the first time this caused strange errors and I'd like to rule that out before continuing with anything else.


regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft

 

animinionsmalltext.gif


#5 the2bachic

the2bachic
  • Topic Starter

  • Members
  • 153 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Georgia, USA
  • Local time:07:57 PM

Posted 14 March 2017 - 11:40 AM

Thanks Elise. Seems Sintharius is in the same predicament as the people she usually helps. I feel for her.

 

I uninstalled SAS. Attempted to boot normally. First attempt resulted in the black screen (after selecting the user profile) where the cursor still moves. I used CTRL-ALT-DEL to restart. Second attempt resulted in the same black screen. I waited 10 minutes this time. I pressed escape a few times (occasionally that would help it progress before, but it was inconsistent). The "wait" circle at the cursor showed up after pressing escape, but I waited 10 more minutes and nothing else happened. CTL-ALT-DEL again, restarted in safe mode.



#6 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,612 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:01:57 AM

Posted 14 March 2017 - 03:21 PM

Can you please try the following. After pressing Alt-Ctrl-Del, select Task manager. If it opens click File > Run, type explorer and press enter. Does anything happen if you do this?


regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft

 

animinionsmalltext.gif


#7 the2bachic

the2bachic
  • Topic Starter

  • Members
  • 153 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Georgia, USA
  • Local time:07:57 PM

Posted 14 March 2017 - 08:25 PM

My computer is being cantankerous. I rebooted and instead of parking itself on the black screen, it fully booted. But of course, 0xC0000005 appeared. Rebooted almost a dozen times to see if the black screen reappeared, but it fully booted and went into the endless cycle of 0xC0000005 each time. Then it took me 4 times to reboot in safe mode, because each time I attempted it froze on the black screen between the opening Fujitsu screen and the splash. Each time, I had to press the power button to power down and try again. Randomly, it worked and booted in safe mode on the 4th try. These sort of inconsistencies are unnerving.

 

That said, if the situation arises again where it stays on the black screen after selecting the user, I will attempt to run explorer from the task manager. I will update you at that time.

 

Possibly of importance, possibly not: my USB mouse would not work at all today until the last reboot. It worked yesterday. Every reboot today (regardless of booting in safe mode or normal), it has not connected, no light on to indicate it was powered. I thought the mouse was damaged (my son did knock it off the desk last night). I tried switching USB ports between it and my USB keyboard, which was working, and the USB keyboard was powered in each USB port but the mouse was not. I had just left it plugged in where I could see the light, fully expecting it to not turn on again, when randomly it connected and worked after this last reboot in safe mode.

 

What next?



#8 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,612 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:01:57 AM

Posted 15 March 2017 - 03:12 AM

No problem, let's just try this instead (there are some Windows files that may need to be replaced because they don't have the right version at the moment).

 

Please rerun FRST and copy the following text into the Search box.

*user32*;*explorer*

Click on Search Files and wait for the scan to finish. Post the resulting log here.


regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft

 

animinionsmalltext.gif


#9 the2bachic

the2bachic
  • Topic Starter

  • Members
  • 153 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Georgia, USA
  • Local time:07:57 PM

Posted 15 March 2017 - 09:44 AM

Farbar Recovery Scan Tool (x64) Version: 15-03-2017
Ran by Amber (15-03-2017 10:15:29)
Running from C:\Users\Amber\Downloads
Boot Mode: Safe Mode (with Networking)

================== Search Files: "*user32*;*explorer*" =============

C:\Windows\explorer.exe
[2017-03-02 22:09][2016-08-29 11:04] 3229696 ____A (Microsoft Corporation) 38AE1B3C38FAEF56FE4907922F0385BA [File is digitally signed]

C:\Windows\winsxs\x86_microsoft-windows-networkexplorer_31bf3856ad364e35_6.1.7601.17514_none_4259cafda42274a4\networkexplorer.dll
[2011-07-08 11:30][2010-11-20 07:20] 1661440 ____A (Microsoft Corporation) 3D57FFBAD3ED16B63DE3879BAB0FB56F [File is digitally signed]

C:\Windows\winsxs\x86_microsoft-windows-n..kexplorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_87a958d2890f3511\NetworkExplorer.dll.mui
[2009-07-14 01:35][2009-07-13 22:04] 0006656 ____A (Microsoft Corporation) 9701FCD12B3528411048A0D23A27A403 [File is digitally signed]

C:\Windows\winsxs\x86_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7601.17514_none_fdfbc5f949b9a49e\Microsoft-Windows-IE-InternetExplorer-repl.man
[2009-07-13 16:44][2009-07-01 22:11] 0033037 ____A () BC453CA6B054CC5BD5CD3579B244945D [File is digitally signed]

C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_04801f69e1dbd8e6\explorer-DL.man
[2009-06-10 17:19][2009-06-10 17:19] 0002571 ____A () 87354E386F0C6B4D1FD4D9301A468C76 [File is digitally signed]

C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_04801f69e1dbd8e6\Microsoft-Windows-IE-InternetExplorer-DL.man
[2009-07-13 16:44][2009-07-01 22:11] 0012749 ____A () 4C0AF26AE7CB4A8231D81A3FF382FC05 [File is digitally signed]

C:\Windows\winsxs\x86_microsoft-windows-d..evelapisets-windows_31bf3856ad364e35_7.1.7601.16492_none_862b61bc350b5a4b\api-ms-win-downlevel-user32-l1-1-0.dll
[2013-02-27 17:44][2013-01-13 17:11] 0004096 ___AH (Microsoft Corporation) 589CBC4989F750E1DA35625AB481CF43 [File is digitally signed]

C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.23594_none_35e609f7d1bb80db\user32.dll
[2017-03-03 01:07][2016-11-10 12:19] 0833024 ____A (Microsoft Corporation) 3CB074875AC88A7C1010A2A7F9881A8C [File is digitally signed]

C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.23265_none_36077453d1a24eea\user32.dll
[2016-08-01 18:34][2015-11-10 14:35] 0833024 ____A (Microsoft Corporation) D0A3A0DBF77EE35CE97E55DE92014E05 [File is digitally signed]

C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.19061_none_3579d47ab8884c9d\user32.dll
[2016-08-01 18:34][2015-11-10 14:37] 0833024 ____A (Microsoft Corporation) 0A78439765E31510D75C9E2284F3A722 [File is digitally signed]

C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[2011-07-08 11:30][2010-11-20 07:08] 0833024 ____A (Microsoft Corporation) 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 [File is digitally signed]

C:\Windows\winsxs\wow64_microsoft-windows-user32.resources_31bf3856ad364e35_6.1.7601.17514_en-us_a678a78b761d8649\user32.dll.mui
[2011-07-08 11:40][2010-11-20 06:59] 0017920 ____A (Microsoft Corporation) 6B63EA7979F501C37FC55A26CA162ACD [File is digitally signed]

C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.23537_none_baa6252edde814c7\explorer.exe
[2017-03-02 22:09][2016-08-29 10:55] 2972672 ____A (Microsoft Corporation) 6DDCA324434FFA506CF7DC4E51DB7935 [File is digitally signed]

C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011-07-10 01:41][2011-07-10 01:41] 2616320 ____A (Microsoft Corporation) 0FB9C74046656D1579A64660AD67B746 [File is digitally signed]

C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2011-07-10 01:41][2011-07-10 01:41] 2616320 ____A (Microsoft Corporation) 8B88EBBB05A0E56B7DCC708498C02B3E [File is digitally signed]

C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011-07-08 11:30][2010-11-20 07:17] 2616320 ____A (Microsoft Corporation) 40D777B7A95E00593EB1568C68514493 [File is digitally signed]

C:\Windows\winsxs\wow64_microsoft-windows-explorerframe_31bf3856ad364e35_6.1.7601.23537_none_2b6e877fd7fc8ce2\ExplorerFrame.dll
[2017-03-02 22:09][2016-08-29 11:12] 1499648 ____A (Microsoft Corporation) 6DDBA73DD781D6CC3CC5A2E8A3E99092 [File is digitally signed]

C:\Windows\winsxs\wow64_microsoft-windows-explorerframe_31bf3856ad364e35_6.1.7601.23155_none_2b56df7bd80e9d7a\ExplorerFrame.dll
[2016-08-01 18:33][2015-08-06 13:37] 1499648 ____A (Microsoft Corporation) 5BDF3B6871BB584A218CD4CB1BD1609A [File is digitally signed]

C:\Windows\winsxs\wow64_microsoft-windows-explorerframe_31bf3856ad364e35_6.1.7601.18952_none_2aca69b0bef37e69\ExplorerFrame.dll
[2016-08-01 18:33][2015-08-06 13:44] 1498624 ____A (Microsoft Corporation) 5CB2886338C82E388F68557E2745200F [File is digitally signed]

C:\Windows\winsxs\wow64_microsoft-windows-explorerframe_31bf3856ad364e35_6.1.7601.17514_none_2af7b924bed13316\ExplorerFrame.dll
[2011-07-08 11:30][2010-11-20 07:19] 1493504 ____A (Microsoft Corporation) E2A17BCC08D92F42E08AF6BA2F93ABA7 [File is digitally signed]

C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui
[2009-07-14 01:35][2009-07-13 22:06] 0022016 ____A (Microsoft Corporation) B9F4B1CA23D60775736059D72BA48526 [File is digitally signed]

C:\Windows\winsxs\wow64_microsoft-windows-e..orerframe.resources_31bf3856ad364e35_6.1.7600.16385_en-us_b9c24c7c40b46d0f\explorerframe.dll.mui
[2009-07-14 01:35][2009-07-13 22:03] 0018432 ____A (Microsoft Corporation) BC486AFF277CD6AE2406FA1FE1B09D56 [File is digitally signed]

C:\Windows\winsxs\wow64_microsoft-windows-a..structure-manifests_31bf3856ad364e35_6.1.7601.17514_none_064614d3fe52ac8a\user32.amx
[2011-07-08 11:30][2010-11-20 04:07] 0367164 ____A () DE03DD1A689B53FB2B4A5E480AC7AA4F [File is digitally signed]

C:\Windows\winsxs\Temp\PendingRenames\389b58a37594d201de35000088073404.program_files_x86_internet_explorer_cafab575245eacb0.cdf-ms
[2017-03-03 19:26][2017-03-03 19:26] 0004428 ____A () 94FE77E584E9EE4041B062F6A3AD0648 [File not signed]

C:\Windows\winsxs\Temp\PendingRenames\5577548e7494d2010713000088073404.program_files_internet_explorer_en-us_2650c83f8a48b821.cdf-ms
[2017-03-03 19:19][2017-03-03 19:19] 0003156 ____A () 079D5CE321B4F51E1D208D0ACED55BCB [File not signed]

C:\Windows\winsxs\Temp\PendingRenames\98fc5aa37594d201df35000088073404.program_files_x86_internet_explorer_en-us_1a6a9dd9f26fbb24.cdf-ms
[2017-03-03 19:26][2017-03-03 19:26] 0002744 ____A () 3B5CEB36AA04251820ED38A16C88C10A [File not signed]

C:\Windows\winsxs\Temp\PendingRenames\fe3f718c7494d201b212000088073404.program_files_internet_explorer_a421d1bfaf856e2b.cdf-ms
[2017-03-03 19:19][2017-03-03 19:19] 0006632 ____A () 81E3D70B9E272C36EAAD20531F21DC04 [File not signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-e..orkexplorersettings_31bf3856ad364e35_6.1.7600.16385_none_0d29da7ff093e63c.manifest
[2009-07-13 22:15][2009-07-13 22:11] 0004278 ____A () 1B6BD7B1825EA431D5CE5963D887493D [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b.manifest
[2009-07-14 01:35][2009-07-13 22:43] 0002148 ____A () F0B319B966F9F0E401785F918C73A86F [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-explorerframe_31bf3856ad364e35_6.1.7601.17514_none_20a30ed28a70711b.manifest
[2011-07-08 11:29][2010-11-20 09:18] 0046854 ____N () 1D38657C0736D167266D0A7B0AAD1BDD [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-explorerframe_31bf3856ad364e35_6.1.7601.18952_none_2075bf5e8a92bc6e.manifest
[2016-08-01 18:15][2015-08-06 14:37] 0043720 ____N () A28AD108B7CF2AB57CC910B7B7537696 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-explorerframe_31bf3856ad364e35_6.1.7601.23155_none_21023529a3addb7f.manifest
[2016-08-01 18:15][2015-08-06 14:39] 0043720 ____N () 832A9F1FEDDB2EA29DE085A79F901886 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-explorerframe_31bf3856ad364e35_6.1.7601.23537_none_2119dd2da39bcae7.manifest
[2017-03-02 22:09][2016-08-29 11:57] 0043720 ____N () BF81DD3534911F7E36767CEA057DC529 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900.manifest
[2011-07-08 11:29][2010-11-20 09:40] 0098144 ____N () 19F417DD116EB786706B4E29A5FBF60F [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba.manifest
[2011-07-10 01:41][2011-07-10 01:41] 0098189 ____N () 340B290A68CE278EF1ADBF9D54E94261 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332.manifest
[2011-07-10 01:41][2011-07-10 01:41] 0098189 ____N () 51F2CBF614B9D2E25155DE2818F60D4B [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.23537_none_b0517adca98752cc.manifest
[2017-03-02 22:09][2016-08-29 11:55] 0088301 ____N () E7CE27172652A720BAA549580EF31E36 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gameexplorer-adm_31bf3856ad364e35_6.1.7600.16385_none_b2fa68403f0f1e47.manifest
[2009-07-13 22:18][2009-07-13 22:18] 0002773 ____A () 32509D1D115D9323A14818ED0FCAFCDB [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gameexplorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6a9a464388bbc56b.manifest
[2009-07-14 01:35][2009-07-13 22:43] 0002961 ____A () F59E14A2FCD38C85E4FA31D764617095 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gameexplorer_31bf3856ad364e35_6.1.7601.17514_none_a026547dd7dc8bbc.manifest
[2011-07-08 11:29][2010-11-20 09:40] 0041538 ____N () 651A8A1B316091B627CC1A3634898E46 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gameexplorer_31bf3856ad364e35_6.1.7601.18020_none_a0176323d7e86a2f.manifest
[2013-01-09 13:03][2012-12-10 14:13] 0043707 ____N () 007DFA3A914B9BF2781CD7AA8631749E [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gameexplorer_31bf3856ad364e35_6.1.7601.22183_none_a0632144f133fda4.manifest
[2013-01-09 13:03][2012-12-10 14:11] 0043707 ____N () 90F128F37424D2711FC029656550F1BA [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.16428_none_7b0d6f67c2d3f97a.manifest
[2013-12-10 07:33][2013-12-10 07:33] 0069043 ____N () 6CAB4AF10CB8474D9E36B74BBF3C3C8B [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.16518_none_7b019f31c2dcfc14.manifest
[2014-02-12 01:20][2014-02-06 19:10] 0069056 ____N () 215F74E19D0510C2F6A4E92B4A19A0F8 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.16521_none_7b033ef3c2db6204.manifest
[2014-03-12 12:00][2014-03-01 18:50] 0069056 ____N () 14484C623795E68F75BF375617290338 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17041_none_7b3b5109c2b10624.manifest
[2014-04-22 15:57][2014-03-26 21:11] 0069056 ____N () 791B0AF7A6992C1D9125321C36CC05D8 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17126_none_7b2e0ea1c2bb6f8c.manifest
[2014-06-11 11:39][2014-06-02 02:11] 0070140 ____N () CD1E6517711542D91856ACF30526C41A [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17207_none_7b212759c2c57270.manifest
[2014-07-09 21:48][2014-06-20 16:31] 0070140 ____N () AB9E8164D303DF64DF356741EB9F59AF [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17239_none_7b23faa7c2c2f1b7.manifest
[2014-08-15 11:32][2014-07-31 19:52] 0070140 ____N () 7BBBF2F9A14D1DC77C01E9DE214E0246 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17280_none_7b29c921c2bd89c1.manifest
[2014-09-12 12:27][2014-08-19 15:05] 0070140 ____N () 4DDC82B89A547D18610D56BC16AFAF7C [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17358_none_7b1b4217c2c926b5.manifest
[2014-10-15 14:41][2014-10-07 00:53] 0070140 ____N () 22A130AF3F18677FEA0B3CFD4F54955E [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17420_none_7b0e278dc2d32999.manifest
[2014-11-11 19:44][2014-11-07 16:04] 0070140 ____N () 5B8758AB519CB4EDE8DBC0D41A961CC3 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17501_none_7b014045c2dd2c7d.manifest
[2014-12-10 01:04][2014-11-26 21:53] 0070140 ____N () E3F01727689BE005B98092B07B0B43CE [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17633_none_7af943a7c2e2c7b5.manifest
[2015-02-12 23:23][2015-01-14 02:02] 0070140 ____N () 93D90FE47547A27565770B55160098E7 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17691_none_7aff72f3c2dd2c7d.manifest
[2015-03-17 18:10][2015-02-23 23:21] 0062532 ____N () 28B52EC0F0C641C1B744D42D31319FDB [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17843_none_7ae4a419c2f218ee.manifest
[2015-06-14 16:36][2015-06-01 16:45] 0062532 ____N () E359CE2D8EA2527BE0B880C83915A2B6 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17914_none_7ad6bc87c2fd027b.manifest
[2015-07-31 10:43][2015-06-25 14:35] 0062532 ____N () FAC2024B4FD67E80E77F514495594EF5 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.18376_none_7b1d7221c2c72348.manifest
[2016-08-01 18:21][2016-06-11 03:53] 0062629 ____N () 8253F5400FF5416D883BA7091CE50AC8 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.18426_none_7b0da0c3c2d3c086.manifest
[2016-08-28 11:31][2016-08-02 11:51] 0062629 ____N () 0A310A607E5564E711E5D0FF8D7EED86 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.18537_none_7b03ba59c2db0f6f.manifest
[2017-03-02 22:14][2016-11-14 20:29] 0062629 ____N () DF779CF6A40A04A122DBF62D7D37DEAE [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-i..explorer-deployment_31bf3856ad364e35_11.2.9600.16428_none_301e62752e193974.manifest
[2013-12-10 07:33][2013-12-10 07:33] 0023404 ____N () 8DCA5716BA048888A570587F04AC26DB [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-i..explorer-deployment_31bf3856ad364e35_8.0.7601.17514_none_c6a79c0da6ac8a8c.manifest
[2011-07-08 11:42][2011-07-08 11:42] 0019600 ____N () E52859666B5BB23BC3876ACB794904D3 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_11.2.9600.16428_en-us_1fe3862469d3980a.manifest
[2013-12-10 07:33][2013-12-10 07:33] 0002667 ____N () 571751290BF8CE253E78CCD8B2969C08 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.16428_none_11b913172f0cb26f.manifest
[2013-12-10 07:33][2013-12-10 07:33] 0081291 ____N () 9FAED81225F63431EAB7A3C37DDCDE9D [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.16476_none_11be42192f07fde0.manifest
[2013-12-11 19:06][2013-11-26 21:08] 0081291 ____N () 5C5633DE15B0F399BF6B0F2E05F714BB [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.16518_none_11ad42e12f15b509.manifest
[2014-02-12 01:20][2014-02-06 19:10] 0081291 ____N () 775C7DA473BF0204B6BA3F9FFA0934FC [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.16521_none_11aee2a32f141af9.manifest
[2014-03-12 12:00][2014-03-01 18:50] 0081291 ____N () 47C647EBBF01307C7C7509115833C264 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17041_none_11e6f4b92ee9bf19.manifest
[2014-04-22 15:57][2014-03-26 21:11] 0081291 ____N () 26C96D9F9AF8669E4B79AAE9B1CDD773 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17126_none_11d9b2512ef42881.manifest
[2014-06-11 11:39][2014-06-02 02:11] 0081291 ____N () 7F4A8923B9BF31453B68A0105F44A2FC [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17207_none_11cccb092efe2b65.manifest
[2014-07-09 21:48][2014-06-20 16:31] 0081291 ____N () C99DC9D969A41E2A93188B8B12DFB9E0 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17239_none_11cf9e572efbaaac.manifest
[2014-08-15 11:32][2014-07-31 19:52] 0081291 ____N () E2315364B25173F84B0D64E91916ADC2 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17280_none_11d56cd12ef642b6.manifest
[2014-09-12 12:27][2014-08-19 15:05] 0081291 ____N () FB5A8A229F66E7AEED2490E3EB60E7A9 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17358_none_11c6e5c72f01dfaa.manifest
[2014-10-15 14:41][2014-10-07 00:53] 0081291 ____N () 69FF81DAAD6A1BA1AFF509A6D32979A2 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17420_none_11b9cb3d2f0be28e.manifest
[2014-11-11 19:44][2014-11-07 16:04] 0081291 ____N () 92274C9328A6CCFEA72729D0F70CEE6B [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17501_none_11ace3f52f15e572.manifest
[2014-12-10 01:04][2014-11-26 21:53] 0081291 ____N () BBB726CB29AEE38147448C229188F0FC [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17509_none_11ac2db52f16b27a.manifest
[2014-12-17 18:49][2014-12-15 16:13] 0082018 ____N () 1FF3DBC1384A2E271FC452F2269B774C [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17633_none_11a4e7572f1b80aa.manifest
[2015-02-12 23:23][2015-01-14 02:02] 0081291 ____N () 8E3DAB60FFFB8060FE6149EDAE332FDF [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17691_none_11ab16a32f15e572.manifest
[2015-03-17 18:10][2015-02-23 23:21] 0080379 ____N () C110616377317746C35301751D551A38 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17843_none_119047c92f2ad1e3.manifest
[2015-06-14 16:36][2015-06-01 16:45] 0080379 ____N () 10C46D229CFFEB9773515AEA2B90C551 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17914_none_118260372f35bb70.manifest
[2015-07-31 10:43][2015-06-25 14:35] 0080379 ____N () FDB7827D3BBF0530E042E565238C9C60 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.18376_none_11c915d12effdc3d.manifest
[2016-08-01 18:21][2016-06-11 03:53] 0080766 ____N () 801539E72270DF65AABAE7F652562942 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.18426_none_11b944732f0c797b.manifest
[2016-08-28 11:31][2016-08-02 11:51] 0080766 ____N () EBF4FEB54D3E367EEE9A07730AE3E4F7 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.18537_none_11af5e092f13c864.manifest
[2017-03-02 22:14][2016-11-14 20:29] 0080766 ____N () 6C749AEB0D39B3AB9F160E7B62A8C6BC [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.7600.16385_none_a61138e7aab17fed.manifest
[2009-07-13 22:18][2009-07-13 22:18] 0077128 ____A () 45E3507082FD9FC0FFD537530EA3BD2D [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-interface-explorer_31bf3856ad364e35_6.1.7600.16385_none_f17f09d0a545aa4c.manifest
[2009-07-13 22:33][2009-07-13 22:12] 0000967 ____A () 0F1C83637A89C282DC2F091289DC9713 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-n..kexplorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_e3c7f456416ca647.manifest
[2009-07-14 01:35][2009-07-13 22:44] 0003766 ____A () 0DBEB3A4AC9257496A0F92DBC76FBECC [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-networkexplorer_31bf3856ad364e35_6.1.7601.17514_none_9e7866815c7fe5da.manifest
[2011-07-08 11:29][2010-11-20 09:40] 0014753 ____N () 0A7865921455E7FC1DBA740084029113 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-search-explorer_31bf3856ad364e35_6.1.7600.16385_none_ef7a36f86b2159cd.manifest
[2009-07-13 22:23][2009-07-13 22:12] 0005899 ____A () 981483174E4E74F4031877198BBC35E6 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-shell-internetexplorer_31bf3856ad364e35_6.1.7601.17514_none_e276f10f6877c8de.manifest
[2011-07-08 11:29][2010-11-20 13:42] 0001147 ____N () 628827A903BCB22A3AB9FA55D0E70F3D [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-user32.resources_31bf3856ad364e35_6.1.7601.17514_en-us_9c23fd3941bcc44e.manifest
[2011-07-08 11:39][2010-11-20 08:31] 0002380 ____N () FCF0C7FBF64A5B153F63B68A9D1587A2 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973.manifest
[2011-07-08 11:29][2010-11-20 09:22] 0002735 ____N () 15E19DF34278CE935EBA06DC1ACD2CC8 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.19061_none_2b252a2884278aa2.manifest
[2016-08-01 18:14][2015-11-10 15:30] 0002735 ____N () BB6E408F4F39C0C57BFF64B866B08C63 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.23265_none_2bb2ca019d418cef.manifest
[2016-08-01 18:14][2015-11-10 15:36] 0002735 ____N () 15607242FBCB6EDA7E26C5E810BCA101 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.23594_none_2b915fa59d5abee0.manifest
[2017-03-02 22:14][2016-11-10 13:00] 0002735 ____N () 98A13215D50F28871217D73E16C6E214 [File is digitally signed]

C:\Windows\winsxs\Manifests\amd64_microsoft-windows-windowsexplorer-adm_31bf3856ad364e35_6.1.7600.16385_none_4c5bc898cf89bb26.manifest
[2009-07-13 22:12][2009-07-13 22:12] 0002785 ____A () 3B580F4974C2F77CDD63A91136C1E492 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396.manifest
[2009-07-14 01:35][2009-07-13 22:28] 0002149 ____A () CE254FBC24EE699CB4ADA713B7FA47A4 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-explorerframe_31bf3856ad364e35_6.1.7601.17514_none_2af7b924bed13316.manifest
[2011-07-08 11:29][2010-11-20 07:58] 0046504 ____N () 7DB712D0A5AD32A8319999846BAE946E [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-explorerframe_31bf3856ad364e35_6.1.7601.18952_none_2aca69b0bef37e69.manifest
[2016-08-01 18:15][2015-08-06 14:03] 0043418 ____N () B5BA260ECDABA7A823AF352C7109A9D3 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-explorerframe_31bf3856ad364e35_6.1.7601.23155_none_2b56df7bd80e9d7a.manifest
[2016-08-01 18:15][2015-08-06 13:56] 0043418 ____N () 575D608007554E2B4EC5E1213F58EBAC [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-explorerframe_31bf3856ad364e35_6.1.7601.23537_none_2b6e877fd7fc8ce2.manifest
[2017-03-02 22:08][2016-08-29 11:24] 0043418 ____N () 7A111D5F0EC1E2E7E6DDEFBB0460EEBF [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb.manifest
[2011-07-08 11:29][2010-11-20 07:59] 0097119 ____N () CD1AD4891C8C2085083B5B69E34735FD [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5.manifest
[2011-07-10 01:41][2011-07-10 01:41] 0097119 ____N () 1170D7B27C7109B17E0519BE34DBB9CB [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d.manifest
[2011-07-10 01:41][2011-07-10 01:41] 0097119 ____N () 9A1075007E58D077AFC49C17CB873E37 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.23537_none_baa6252edde814c7.manifest
[2017-03-02 22:08][2016-08-29 11:24] 0087231 ____N () 07188EF0E4443F2A5E875C1072F98B81 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-gameexplorer_31bf3856ad364e35_6.1.7601.17514_none_aa7afed00c3d4db7.manifest
[2011-07-08 11:29][2010-11-20 08:27] 0039931 ____N () E35D8A1B0B7E9B06DD1EFB27F62927A3 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-gameexplorer_31bf3856ad364e35_6.1.7601.18020_none_aa6c0d760c492c2a.manifest
[2013-01-09 13:03][2012-12-10 14:12] 0042127 ____N () B4C7C5CBECA44193661EAC6A75C2B5AF [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-gameexplorer_31bf3856ad364e35_6.1.7601.22183_none_aab7cb972594bf9f.manifest
[2013-01-09 13:03][2012-12-10 14:13] 0042127 ____N () 36C66AD47ACA36A5C2144C58DD709842 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.16428_none_856219b9f734bb75.manifest
[2013-12-10 07:33][2013-12-10 07:33] 0050794 ____N () 5458462DDFB2D1D36BC39B0FA3E11772 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.16518_none_85564983f73dbe0f.manifest
[2014-02-12 01:20][2014-02-06 18:30] 0050807 ____N () F33BFDA0DAD2E0165881046ED2984633 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.16521_none_8557e945f73c23ff.manifest
[2014-03-12 12:00][2014-03-01 18:09] 0050807 ____N () 732A33A826618BC82B406DF36C1BCCE2 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17041_none_858ffb5bf711c81f.manifest
[2014-04-22 15:57][2014-03-26 20:23] 0050807 ____N () 59B00B2A168C876BCF06207C579C23DC [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17126_none_8582b8f3f71c3187.manifest
[2014-06-11 11:39][2014-06-02 00:51] 0050807 ____N () 400C6EFBC4C9DBB5EB6580E521CD7882 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17207_none_8575d1abf726346b.manifest
[2014-07-09 21:48][2014-06-20 15:49] 0050807 ____N () 52C4050AF10AE9CE516137F27B135F9A [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17239_none_8578a4f9f723b3b2.manifest
[2014-08-15 11:32][2014-07-31 19:30] 0050807 ____N () 2F7F304ACF0F1B6848731887D10D9FF3 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17280_none_857e7373f71e4bbc.manifest
[2014-09-12 12:27][2014-08-19 13:47] 0050807 ____N () AD6A892557314F35BE52FF248438CE92 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17358_none_856fec69f729e8b0.manifest
[2014-10-15 14:41][2014-10-06 22:18] 0050807 ____N () 1544636BBAF9BE558F31BEC308B11368 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17420_none_8562d1dff733eb94.manifest
[2014-11-11 19:44][2014-11-07 15:32] 0050807 ____N () 34326584232C13F5C72D271C3AA6A9C1 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17501_none_8555ea97f73dee78.manifest
[2014-12-10 01:04][2014-11-26 21:23] 0050807 ____N () CB8664B9CD1D994CADC8B622CB81EEFD [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17633_none_854dedf9f74389b0.manifest
[2015-02-12 23:23][2015-01-14 01:23] 0050807 ____N () 5F04DEB17413AFC578825EA23CBD922D [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17691_none_85541d45f73dee78.manifest
[2015-03-17 18:10][2015-02-23 22:40] 0045839 ____N () 15DBFA8B4C3602B2A59E6834DBC61761 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17843_none_85394e6bf752dae9.manifest
[2015-06-14 16:36][2015-06-01 14:51] 0045839 ____N () 8FC6D0061FE99C539FFB8428CBCE0685 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17914_none_852b66d9f75dc476.manifest
[2015-07-31 10:43][2015-06-25 14:06] 0045839 ____N () 9F20110ADB6792B35FC99DFCBA24A20A [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.18376_none_85721c73f727e543.manifest
[2016-08-01 18:21][2016-06-11 03:28] 0045936 ____N () 310BBA10CBBC79B3119CB44B486A1BC6 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.18426_none_85624b15f7348281.manifest
[2016-08-28 11:31][2016-08-02 11:24] 0045936 ____N () 361CD547871B18558EB5E6EBC1A30D4B [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.18537_none_855864abf73bd16a.manifest
[2017-03-02 22:14][2016-11-14 19:58] 0045936 ____N () BB2983C0204E5F26E50090EDC066F1CC [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-i..explorer-deployment_31bf3856ad364e35_11.2.9600.16428_none_3a730cc76279fb6f.manifest
[2013-12-10 07:33][2013-12-10 07:33] 0020039 ____N () E4924F1F125F0AFC0F8ED4851B20FADC [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-i..explorer-deployment_31bf3856ad364e35_8.0.7601.17514_none_d0fc465fdb0d4c87.manifest
[2011-07-08 11:29][2010-11-20 13:42] 0019167 ____N () 96C949F223C1BCD235F2E58301D12345 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_11.2.9600.16428_en-us_2a3830769e345a05.manifest
[2013-12-10 07:33][2013-12-10 07:33] 0002667 ____N () F45FC72062951B7B1E356C230492A16A [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.16428_none_1c0dbd69636d746a.manifest
[2013-12-10 07:33][2013-12-10 07:33] 0076209 ____N () F3D4EB764FEF59DED6F8F24BECCEA9BC [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.16518_none_1c01ed3363767704.manifest
[2014-02-12 01:20][2014-02-06 18:30] 0076209 ____N () 702B0FD58B35DFAF8AEFE696F4D1B6B9 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.16521_none_1c038cf56374dcf4.manifest
[2014-03-12 12:00][2014-03-01 18:09] 0076209 ____N () B601B6D8E4D19760D08F7D03CFDB0014 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17041_none_1c3b9f0b634a8114.manifest
[2014-04-22 15:56][2014-03-26 20:23] 0076209 ____N () 5E57817092B86DAC3CC532829922F15B [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17126_none_1c2e5ca36354ea7c.manifest
[2014-06-11 11:39][2014-06-02 00:51] 0076209 ____N () 0454267D544253FDA81D979F0CD7E96C [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17207_none_1c21755b635eed60.manifest
[2014-07-09 21:48][2014-06-20 15:49] 0076209 ____N () 99745C1AB523ACF46650BB6D1ACF59EA [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17239_none_1c2448a9635c6ca7.manifest
[2014-08-15 11:32][2014-07-31 19:30] 0076209 ____N () 093C5F1AE19B974A287776988DB3B226 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17280_none_1c2a1723635704b1.manifest
[2014-09-12 12:27][2014-08-19 13:47] 0076209 ____N () FFC3717D2650452F90C60F7FE2D3C241 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17358_none_1c1b90196362a1a5.manifest
[2014-10-15 14:41][2014-10-06 22:18] 0076209 ____N () C1CB357FDAD50F3967AA0076926E2F64 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17420_none_1c0e758f636ca489.manifest
[2014-11-11 19:44][2014-11-07 15:32] 0076209 ____N () 97E4EFC9CA57353D5159DE6FB5C2A64F [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17501_none_1c018e476376a76d.manifest
[2014-12-10 01:04][2014-11-26 21:23] 0076209 ____N () 4E3D92ED56E00537CFD37819FB609BA7 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17509_none_1c00d80763777475.manifest
[2014-12-17 18:49][2014-12-15 15:36] 0076936 ____N () 24CA91889CAC104C843D57030A1DBBA6 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17633_none_1bf991a9637c42a5.manifest
[2015-02-12 23:23][2015-01-14 01:23] 0076209 ____N () D43E9434CBF976804F416F2D39764062 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17691_none_1bffc0f56376a76d.manifest
[2015-03-17 18:10][2015-02-23 22:40] 0075297 ____N () 33C6F5B72EC92A3EE0C84197813D78F6 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17843_none_1be4f21b638b93de.manifest
[2015-06-14 16:36][2015-06-01 14:51] 0075297 ____N () CB9A4CC980E8F1086C047C97A25D7160 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17914_none_1bd70a8963967d6b.manifest
[2015-07-31 10:43][2015-06-25 14:06] 0075297 ____N () BF9E8FA3932FB6ED97A78165790DB7E2 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.18376_none_1c1dc02363609e38.manifest
[2016-08-01 18:21][2016-06-11 03:28] 0075684 ____N () 1CFB29C3DBC12CAAB0ED7F2CF8698CFC [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.18426_none_1c0deec5636d3b76.manifest
[2016-08-28 11:31][2016-08-02 11:24] 0075684 ____N () 6DECCF7C69CDED8F0195F18A81486A66 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.18537_none_1c04085b63748a5f.manifest
[2017-03-02 22:14][2016-11-14 19:58] 0075684 ____N () 0D2CFC183A64A1AD3B707DA88649ADCF [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.7601.17514_none_b296f701dc00c582.manifest
[2011-07-08 11:29][2010-11-20 07:59] 0071625 ____N () 578EFA1F3F60BE79E15A1FEC6DD017CB [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-user32.resources_31bf3856ad364e35_6.1.7601.17514_en-us_a678a78b761d8649.manifest
[2011-07-08 11:39][2010-11-20 07:27] 0002388 ____N () 1CECD60B9F87140B907C8A94695322E3 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e.manifest
[2011-07-08 11:29][2010-11-20 07:58] 0002743 ____N () 95DE794ABE239191A81508A617C359A1 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.19061_none_3579d47ab8884c9d.manifest
[2016-08-01 18:14][2015-11-10 15:01] 0002743 ____N () 3BBED4CF0A6EDC5AB188BEE466395CF8 [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.23265_none_36077453d1a24eea.manifest
[2016-08-01 18:14][2015-11-10 14:53] 0002743 ____N () 86A77EB6DDD71DB2371FBADE2B3E0EFF [File is digitally signed]

C:\Windows\winsxs\Manifests\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.23594_none_35e609f7d1bb80db.manifest
[2017-03-02 22:14][2016-11-10 12:32] 0002743 ____N () 5B934B4D4C81527D080F3901285B418A [File is digitally signed]

C:\Windows\winsxs\Manifests\x86_microsoft-windows-gameexplorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_0e7baabfd05e5435.manifest
[2009-07-14 01:35][2009-07-13 22:28] 0002959 ____A () 6806DF6BEBECA9FE94ACC9A25BA8D454 [File is digitally signed]

C:\Windows\winsxs\Manifests\x86_microsoft-windows-interface-explorer_31bf3856ad364e35_6.1.7600.16385_none_95606e4cece83916.manifest
[2009-07-13 22:33][2009-07-13 21:46] 0000963 ____A () BCF6AD0DD5FA473B709AC222F682B6AA [File is digitally signed]

C:\Windows\winsxs\Manifests\x86_microsoft-windows-n..kexplorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_87a958d2890f3511.manifest
[2009-07-14 01:35][2009-07-13 22:29] 0003764 ____A () AE0A19B88D4387BB778437DC48816DB3 [File is digitally signed]

C:\Windows\winsxs\Manifests\x86_microsoft-windows-networkexplorer_31bf3856ad364e35_6.1.7601.17514_none_4259cafda42274a4.manifest
[2011-07-08 11:29][2010-11-20 08:27] 0014749 ____N () 99011722D536DFAB1DD30ED784F57E13 [File is digitally signed]

C:\Windows\winsxs\Manifests\x86_microsoft-windows-search-explorer_31bf3856ad364e35_6.1.7600.16385_none_935b9b74b2c3e897.manifest
[2009-07-13 21:55][2009-07-13 21:46] 0005897 ____A () 92E83409F5961DD50ACB2CE7A7C1359A [File is digitally signed]

C:\Windows\winsxs\Manifests\x86_microsoft-windows-shell-internetexplorer_31bf3856ad364e35_6.1.7601.17514_none_8658558bb01a57a8.manifest
[2011-07-08 11:29][2010-11-20 13:42] 0001143 ____N () 137EA56D60EAF28A9FCBA7980AE48142 [File is digitally signed]

C:\Windows\winsxs\FileMaps\program_files_internet_explorer_a421d1bfaf856e2b.cdf-ms
[2009-07-13 22:59][2017-03-03 01:11] 0006632 ____A () B5E8887C2AD52BEB79E6A268F2B6580F [File not signed]

C:\Windows\winsxs\FileMaps\program_files_internet_explorer_en-us_2650c83f8a48b821.cdf-ms
[2009-07-14 01:37][2017-03-03 01:11] 0003156 ____A () FB27F1BCC16354D2CEC0ED76F5C90A6B [File not signed]

C:\Windows\winsxs\FileMaps\program_files_internet_explorer_images_970ee9acd2503f65.cdf-ms
[2013-04-05 12:14][2013-04-05 01:48] 0000608 ____A () D50F60E9D93FFDAE8BBCCBB8BE1913E9 [File not signed]

C:\Windows\winsxs\FileMaps\program_files_x86_internet_explorer_cafab575245eacb0.cdf-ms
[2009-07-13 22:59][2017-03-03 01:11] 0004428 ____A () F91D9AD40809B08052AAAF58195956F3 [File not signed]

C:\Windows\winsxs\FileMaps\program_files_x86_internet_explorer_en-us_1a6a9dd9f26fbb24.cdf-ms
[2009-07-14 01:37][2017-03-03 01:11] 0002744 ____A () C7AA5FE14B7B4012C061F8314CE2B4CE [File not signed]

C:\Windows\winsxs\Backup\amd64_microsoft-windows-e..orerframe.resources_31bf3856ad364e35_6.1.7600.16385_en-us_af6da22a0c53ab14_explorerframe.dll.mui_074caeb5
[2009-07-14 01:37][2009-07-14 01:37] 0018432 ____A (Microsoft Corporation) 86F52FD53B778CCE631F7C06B8D722AD [File is digitally signed]

C:\Windows\winsxs\Backup\amd64_microsoft-windows-explorerframe_31bf3856ad364e35_6.1.7601.23537_none_2119dd2da39bcae7.manifest
[2017-03-03 00:15][2017-03-02 22:45] 0043720 ____A () BF81DD3534911F7E36767CEA057DC529 [File is digitally signed]

C:\Windows\winsxs\Backup\amd64_microsoft-windows-explorerframe_31bf3856ad364e35_6.1.7601.23537_none_2119dd2da39bcae7_explorerframe.dll_f3ae0f78
[2017-03-03 00:15][2017-03-02 22:45] 1867776 ____A (Microsoft Corporation) BCFAF911FE43F80124C3A68BB07130A9 [File is digitally signed]

C:\Windows\winsxs\Backup\amd64_microsoft-windows-user32.resources_31bf3856ad364e35_6.1.7601.17514_en-us_9c23fd3941bcc44e.manifest
[2011-07-08 12:08][2011-07-08 11:57] 0002380 ____A () FCF0C7FBF64A5B153F63B68A9D1587A2 [File is digitally signed]

C:\Windows\winsxs\Backup\amd64_microsoft-windows-user32.resources_31bf3856ad364e35_6.1.7601.17514_en-us_9c23fd3941bcc44e_user32.dll.mui_14652dbb
[2011-07-08 12:08][2011-07-08 11:57] 0017920 ____A (Microsoft Corporation) EF9BC0D92F9AF6A446CA3179EFDA0CE0 [File is digitally signed]

C:\Windows\winsxs\Backup\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.23594_none_2b915fa59d5abee0.manifest
[2017-03-03 01:12][2017-03-03 01:11] 0002735 ____A () 98A13215D50F28871217D73E16C6E214 [File is digitally signed]

C:\Windows\winsxs\Backup\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.23594_none_2b915fa59d5abee0_user32.dll_55f4ed20
[2017-03-03 01:12][2017-03-03 01:11] 1009152 ____A (Microsoft Corporation) 34BA256FBF83457F9D5E51A56DB54542 [File is digitally signed]

C:\Windows\winsxs\Backup\wow64_microsoft-windows-e..orerframe.resources_31bf3856ad364e35_6.1.7600.16385_en-us_b9c24c7c40b46d0f_explorerframe.dll.mui_074caeb5
[2009-07-14 01:37][2009-07-14 01:37] 0018432 ____A (Microsoft Corporation) BC486AFF277CD6AE2406FA1FE1B09D56 [File is digitally signed]

C:\Windows\winsxs\Backup\wow64_microsoft-windows-explorerframe_31bf3856ad364e35_6.1.7601.23537_none_2b6e877fd7fc8ce2.manifest
[2017-03-03 00:15][2017-03-02 22:45] 0043418 ____A () 7A111D5F0EC1E2E7E6DDEFBB0460EEBF [File is digitally signed]

C:\Windows\winsxs\Backup\wow64_microsoft-windows-explorerframe_31bf3856ad364e35_6.1.7601.23537_none_2b6e877fd7fc8ce2_explorerframe.dll_f3ae0f78
[2017-03-03 00:15][2017-03-02 22:45] 1499648 ____A (Microsoft Corporation) 6DDBA73DD781D6CC3CC5A2E8A3E99092 [File is digitally signed]

C:\Windows\winsxs\Backup\wow64_microsoft-windows-user32.resources_31bf3856ad364e35_6.1.7601.17514_en-us_a678a78b761d8649.manifest
[2011-07-08 12:08][2011-07-08 11:57] 0002388 ____A () 1CECD60B9F87140B907C8A94695322E3 [File is digitally signed]

C:\Windows\winsxs\Backup\wow64_microsoft-windows-user32.resources_31bf3856ad364e35_6.1.7601.17514_en-us_a678a78b761d8649_user32.dll.mui_14652dbb
[2011-07-08 12:08][2011-07-08 11:57] 0017920 ____A (Microsoft Corporation) 6B63EA7979F501C37FC55A26CA162ACD [File is digitally signed]

C:\Windows\winsxs\Backup\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.23594_none_35e609f7d1bb80db.manifest
[2017-03-03 01:12][2017-03-03 01:11] 0002743 ____A () 5B934B4D4C81527D080F3901285B418A [File is digitally signed]

C:\Windows\winsxs\Backup\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.23594_none_35e609f7d1bb80db_user32.dll_55f4ed20
[2017-03-03 01:12][2017-03-03 01:11] 0833024 ____A (Microsoft Corporation) 3CB074875AC88A7C1010A2A7F9881A8C [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-windowsexplorer-adm_31bf3856ad364e35_6.1.7600.16385_none_4c5bc898cf89bb26\WindowsExplorer.admx
[2009-07-13 17:48][2009-06-10 16:53] 0035942 ____A () 6BBA1E311D9D0E64713CFD0C6C74CBF4 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-w..lorer-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_1f9279b1bc764ea5\WindowsExplorer.adml
[2009-07-14 01:35][2009-07-13 22:29] 0048102 ____A () 381BD4BC11B62CE13B187113D5C8B7F7 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.23594_none_2b915fa59d5abee0\user32.dll
[2017-03-03 01:07][2016-11-10 12:32] 1009152 ____A (Microsoft Corporation) 34BA256FBF83457F9D5E51A56DB54542 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.23265_none_2bb2ca019d418cef\user32.dll
[2016-08-01 18:34][2015-11-10 14:59] 1009152 ____A (Microsoft Corporation) E42CB2576D5C8456C60988B1C908F41A [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.19061_none_2b252a2884278aa2\user32.dll
[2016-08-01 18:34][2015-11-10 14:55] 1008640 ____A (Microsoft Corporation) 06BF84D26A05D400F6B3FB3D3DE0B03A [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[2011-07-08 11:29][2010-11-20 08:27] 1008128 ____A (Microsoft Corporation) FE70103391A64039A921DBFFF9C7AB1B [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-user32.resources_31bf3856ad364e35_6.1.7601.17514_en-us_9c23fd3941bcc44e\user32.dll.mui
[2011-07-08 11:40][2010-11-20 07:58] 0017920 ____A (Microsoft Corporation) EF9BC0D92F9AF6A446CA3179EFDA0CE0 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx
[2009-07-13 17:48][2009-06-10 16:53] 0003836 ____A () AD131A834808E6AFF4A3918DE05BFCF6 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml
[2009-07-14 01:35][2009-07-13 22:30] 0003695 ____A () 7A4C7F3CB156543113596988479CAFCE [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-networkexplorer_31bf3856ad364e35_6.1.7601.17514_none_9e7866815c7fe5da\networkexplorer.dll
[2011-07-08 11:29][2010-11-20 08:27] 1672704 ____A (Microsoft Corporation) 405F4D32D2185F1F1BD753D8EEAFFB3A [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-n..kexplorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_e3c7f456416ca647\NetworkExplorer.dll.mui
[2009-07-14 01:35][2009-07-13 22:29] 0006656 ____A (Microsoft Corporation) A61A51AAD80BCC75E1E60F1ADAB9CD9B [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-m..eplacementmanifests_31bf3856ad364e35_6.1.7601.17514_none_5a1a617d021715d4\Microsoft-Windows-IE-InternetExplorer-repl.man
[2009-07-13 16:35][2009-07-01 22:09] 0033037 ____A () BC453CA6B054CC5BD5CD3579B244945D [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_609ebaed9a394a1c\explorer-DL.man
[2009-06-10 16:36][2009-06-10 16:36] 0002571 ____A () 87354E386F0C6B4D1FD4D9301A468C76 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_609ebaed9a394a1c\Microsoft-Windows-IE-InternetExplorer-DL.man
[2009-07-13 16:35][2009-07-01 22:09] 0012749 ____A () 4C0AF26AE7CB4A8231D81A3FF382FC05 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.18537_none_11af5e092f13c864\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms
[2017-03-03 01:07][2016-11-14 20:28] 0002956 ____A () F09F9191AE563651EA41E376BAD264D7 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.18426_none_11b944732f0c797b\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms
[2016-08-28 11:33][2016-08-02 11:50] 0002956 ____A () AC83ABD25508152055231B8F496CA506 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.18376_none_11c915d12effdc3d\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms
[2016-08-01 18:40][2016-06-11 03:52] 0002956 ____A () 4FD3BEBF109087E29B393312CC9E8452 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17914_none_118260372f35bb70\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms
[2015-07-31 10:46][2015-06-25 14:34] 0002956 ____A () 4B2521630863085B66CA0749971C6B9F [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17843_none_119047c92f2ad1e3\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms
[2015-06-14 16:44][2015-06-01 16:43] 0002956 ____A () CF2A91B942BB7BE1D66E51156200C5AC [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17633_none_11a4e7572f1b80aa\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms
[2015-02-12 23:58][2015-01-14 02:00] 0002956 ____A () 152F9BC51C6A24528DD41510B22B0B33 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17509_none_11ac2db52f16b27a\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms
[2014-12-17 18:58][2014-12-15 16:12] 0002956 ____A () AEFA29890FE7C53465314B5A7A6279F9 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17501_none_11ace3f52f15e572\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms
[2014-12-10 02:18][2014-11-26 21:52] 0002956 ____A () EDF3BE6F7837A15B94B617BE14A9938A [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17420_none_11b9cb3d2f0be28e\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms
[2014-11-11 19:47][2014-11-07 16:04] 0002956 ____A () 2C17D5530D1E14BC5FE31366DF1F919E [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17358_none_11c6e5c72f01dfaa\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms
[2014-10-15 14:47][2014-10-07 00:52] 0002956 ____A () 31CA88008F442310AAC0A1701D7AE34F [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17280_none_11d56cd12ef642b6\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms
[2014-09-12 12:27][2014-08-19 15:04] 0002956 ____A () C75123C11BF08AA385FC5EDA9B211F49 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17239_none_11cf9e572efbaaac\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms
[2014-08-15 11:47][2014-07-31 19:51] 0002956 ____A () 6F4CC05C54A71A1CF494E4BDFFF58E27 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17207_none_11cccb092efe2b65\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms
[2014-07-09 21:55][2014-06-20 16:31] 0002956 ____A () F6D37E06C817C5013A83C5D0910D5A93 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17126_none_11d9b2512ef42881\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms
[2014-06-11 11:43][2014-06-02 02:11] 0002956 ____A () 636B800EFF804CEA96CF7FC8AF1C1A2E [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.17041_none_11e6f4b92ee9bf19\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms
[2014-04-22 15:57][2014-03-26 21:11] 0002956 ____A () 7F72D9F5F8608718C7C6963F977C871D [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.16521_none_11aee2a32f141af9\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms
[2014-03-12 12:06][2014-03-01 18:49] 0002956 ____A () 0F829ADCB177961451A8E2A0355892DC [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.16518_none_11ad42e12f15b509\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms
[2014-02-12 01:20][2014-02-06 19:10] 0002956 ____A () 69BFB2B7CB5A8322F52A283D2233A13E [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.16476_none_11be42192f07fde0\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms
[2013-12-11 19:06][2013-11-26 21:08] 0002956 ____A () 6F3FA8CA8C57DC6EC18432F96C1A129D [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.16428_none_11b913172f0cb26f\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms
[2013-12-10 07:33][2013-12-10 07:33] 0002956 ____A () 639DD22AA87C6AC9DE46CAA246A4C1FA [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-gameexplorer-adm_31bf3856ad364e35_6.1.7600.16385_none_b2fa68403f0f1e47\GameExplorer.admx
[2009-07-13 17:48][2009-06-10 16:38] 0002256 ____A () 7223A757158F86DD27EC7D0D43C682AD [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-g..lorer-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a98f8df3953bd666\GameExplorer.adml
[2009-07-14 01:35][2009-07-13 22:29] 0001897 ____A () 85EE206DDBF793929AC0467A02312D46 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.23537_none_b0517adca98752cc\explorer-ppdlic.xrm-ms
[2017-03-02 22:09][2016-08-29 11:45] 0003065 ____A () 8AA78A726F25414097939C99A45F28AA [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.23537_none_b0517adca98752cc\explorer.exe
[2017-03-02 22:09][2016-08-29 11:04] 3229696 ____A (Microsoft Corporation) 38AE1B3C38FAEF56FE4907922F0385BA [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer-ppdlic.xrm-ms
[2011-07-10 01:41][2011-07-10 01:41] 0003065 ____A () 29D941F5F1EA95FB471B4F5100EA15F5 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2011-07-10 01:41][2011-07-10 01:41] 2871808 ____A (Microsoft Corporation) 3B69712041F3D63605529BD66DC00C48 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer-ppdlic.xrm-ms
[2011-07-10 01:41][2011-07-10 01:41] 0003065 ____A () 26AC150971AA3364C3E233B8FBEA2770 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011-07-10 01:41][2011-07-10 01:41] 2871808 ____A (Microsoft Corporation) 332FEAB1435662FC6C672E25BEB37BE3 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer-ppdlic.xrm-ms
[2009-07-13 21:53][2009-07-13 21:53] 0003065 ____A () D653E5080F8F1B158F11A372C4AEE9A8 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2011-07-08 11:29][2010-11-20 08:24] 2872320 ____A (Microsoft Corporation) AC4C51EB24AA95B77F705AB159189E24 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-explorerframe_31bf3856ad364e35_6.1.7601.23537_none_2119dd2da39bcae7\ExplorerFrame.dll
[2017-03-02 22:09][2016-08-29 11:31] 1867776 ____A (Microsoft Corporation) BCFAF911FE43F80124C3A68BB07130A9 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-explorerframe_31bf3856ad364e35_6.1.7601.23155_none_21023529a3addb7f\ExplorerFrame.dll
[2016-08-01 18:33][2015-08-06 14:06] 1867776 ____A (Microsoft Corporation) ED6EAD7F48AEEB4AB8E5252DD4D90D7B [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-explorerframe_31bf3856ad364e35_6.1.7601.18952_none_2075bf5e8a92bc6e\ExplorerFrame.dll
[2016-08-01 18:33][2015-08-06 14:03] 1866752 ____A (Microsoft Corporation) 0F08BB62CD162883E9A3004BBE7914BD [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-explorerframe_31bf3856ad364e35_6.1.7601.17514_none_20a30ed28a70711b\ExplorerFrame.dll
[2011-07-08 11:30][2010-11-20 08:26] 1866240 ____A (Microsoft Corporation) EED05D42D91835064703E2318552ED25 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2009-07-14 01:35][2009-07-13 22:26] 0022016 ____A (Microsoft Corporation) 4B87EEFDC8E253F846A7DFB49A8E6C70 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-e..orerframe.resources_31bf3856ad364e35_6.1.7600.16385_en-us_af6da22a0c53ab14\explorerframe.dll.mui
[2009-07-14 01:35][2009-07-13 22:29] 0018432 ____A (Microsoft Corporation) 86F52FD53B778CCE631F7C06B8D722AD [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-d..evelapisets-windows_31bf3856ad364e35_7.1.7601.16492_none_e249fd3fed68cb81\api-ms-win-downlevel-user32-l1-1-0.dll
[2013-02-27 17:44][2013-01-13 16:31] 0004096 ___AH (Microsoft Corporation) 72723D3E4781BADC62C3180C137E7B23 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.23670_none_e8b423eefec8b519\Api-ms-win-downlevel-user32-l1-1-1.dll
[2017-03-03 02:29][2016-12-20 10:07] 0003584 ____A (Microsoft Corporation) CA0F55B487D767FB7E9BA51D115E9780 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.23488_none_e8b15286fec9a174\Api-ms-win-downlevel-user32-l1-1-1.dll
[2014-12-10 02:18][2014-12-03 00:01] 0003584 ____A (Microsoft Corporation) AEAE1082F6661CEC96CB60D5104DA716 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18942_none_e84d15dbe590cf25\Api-ms-win-downlevel-user32-l1-1-1.dll
[2014-12-10 02:18][2014-12-03 00:01] 0003584 ____A (Microsoft Corporation) AEAE1082F6661CEC96CB60D5104DA716 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18868_none_e83d75d9e59ba1ea\Api-ms-win-downlevel-user32-l1-1-1.dll
[2014-12-10 02:18][2014-12-03 00:01] 0003584 ____A (Microsoft Corporation) AEAE1082F6661CEC96CB60D5104DA716 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18742_none_e84d120fe590d4d7\Api-ms-win-downlevel-user32-l1-1-1.dll
[2014-12-10 02:18][2014-12-03 00:01] 0003584 ____A (Microsoft Corporation) AEAE1082F6661CEC96CB60D5104DA716 [File is digitally signed]

C:\Windows\winsxs\amd64_microsoft-windows-a..structure-manifests_31bf3856ad364e35_6.1.7601.17514_none_fbf16a81c9f1ea8f\user32.amx
[2011-07-08 11:30][2010-11-20 04:51] 0342524 ____A () 2FFFCC20E95D9DF2A4046328F6BB7AEC [File is digitally signed]

C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
[2013-02-27 17:44][2013-01-13 17:11] 0004096 ___AH (Microsoft Corporation) 589CBC4989F750E1DA35625AB481CF43 [File is digitally signed]

C:\Windows\SysWOW64\explorer.exe
[2017-03-02 22:09][2016-08-29 10:55] 2972672 ____A (Microsoft Corporation) 6DDCA324434FFA506CF7DC4E51DB7935 [File is digitally signed]

C:\Windows\SysWOW64\ExplorerFrame.dll
[2017-03-02 22:09][2016-08-29 11:12] 1499648 ____A (Microsoft Corporation) 6DDBA73DD781D6CC3CC5A2E8A3E99092 [File is digitally signed]

C:\Windows\SysWOW64\networkexplorer.dll
[2011-07-08 11:30][2010-11-20 07:20] 1661440 ____A (Microsoft Corporation) 3D57FFBAD3ED16B63DE3879BAB0FB56F [File is digitally signed]

C:\Windows\SysWOW64\user32.dll
[2017-03-03 01:07][2016-11-10 12:19] 0833024 ____A (Microsoft Corporation) 3CB074875AC88A7C1010A2A7F9881A8C [File is digitally signed]

C:\Windows\SysWOW64\migwiz\replacementmanifests\Microsoft-Windows-IE-InternetExplorer-repl.man
[2009-07-13 16:44][2009-07-01 22:11] 0033037 ____A () BC453CA6B054CC5BD5CD3579B244945D [File is digitally signed]

C:\Windows\SysWOW64\migwiz\dlmanifests\explorer-DL.man
[2009-06-10 17:19][2009-06-10 17:19] 0002571 ____A () 87354E386F0C6B4D1FD4D9301A468C76 [File is digitally signed]

C:\Windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-IE-InternetExplorer-DL.man
[2009-07-13 16:44][2009-07-01 22:11] 0012749 ____A () 4C0AF26AE7CB4A8231D81A3FF382FC05 [File is digitally signed]

C:\Windows\SysWOW64\manifeststore\user32.amx
[2011-07-08 11:30][2010-11-20 04:07] 0367164 ____A () DE03DD1A689B53FB2B4A5E480AC7AA4F [File is digitally signed]

C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2009-07-14 01:35][2009-07-13 22:06] 0022016 ____A (Microsoft Corporation) B9F4B1CA23D60775736059D72BA48526 [File is digitally signed]

C:\Windows\SysWOW64\en-US\explorerframe.dll.mui
[2009-07-14 01:35][2009-07-13 22:03] 0018432 ____A (Microsoft Corporation) BC486AFF277CD6AE2406FA1FE1B09D56 [File is digitally signed]

C:\Windows\SysWOW64\en-US\NetworkExplorer.dll.mui
[2009-07-14 01:35][2009-07-13 22:04] 0006656 ____A (Microsoft Corporation) 9701FCD12B3528411048A0D23A27A403 [File is digitally signed]

C:\Windows\SysWOW64\en-US\user32.dll.mui
[2011-07-08 11:40][2010-11-20 06:59] 0017920 ____A (Microsoft Corporation) 6B63EA7979F501C37FC55A26CA162ACD [File is digitally signed]

C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013-02-27 17:44][2013-01-13 16:31] 0004096 ___AH (Microsoft Corporation) 72723D3E4781BADC62C3180C137E7B23 [File is digitally signed]

C:\Windows\System32\ExplorerFrame.dll
[2017-03-02 22:09][2016-08-29 11:31] 1867776 ____A (Microsoft Corporation) BCFAF911FE43F80124C3A68BB07130A9 [File is digitally signed]

C:\Windows\System32\networkexplorer.dll
[2011-07-08 11:29][2010-11-20 08:27] 1672704 ____A (Microsoft Corporation) 405F4D32D2185F1F1BD753D8EEAFFB3A [File is digitally signed]

C:\Windows\System32\user32.dll
[2017-03-03 01:07][2016-11-10 12:32] 1009152 ____A (Microsoft Corporation) 34BA256FBF83457F9D5E51A56DB54542 [File is digitally signed]

C:\Windows\System32\winevt\Logs\Internet Explorer.evtx
[2012-03-23 09:05][2012-03-23 09:06] 0069632 ____A () DB8C6F83DDEB078E83CDAB35481E324F [File not signed]

C:\Windows\System32\spp\tokens\ppdlic\explorer-ppdlic.xrm-ms
[2017-03-02 22:09][2016-08-29 11:45] 0003065 ____A () 8AA78A726F25414097939C99A45F28AA [File is digitally signed]

C:\Windows\System32\spp\tokens\ppdlic\Microsoft-Windows-IE-InternetExplorer-ppdlic.xrm-ms
[2017-03-03 01:07][2016-11-14 20:28] 0002956 ____A () F09F9191AE563651EA41E376BAD264D7 [File is digitally signed]

C:\Windows\System32\migwiz\replacementmanifests\Microsoft-Windows-IE-InternetExplorer-repl.man
[2009-07-13 16:35][2009-07-01 22:09] 0033037 ____A () BC453CA6B054CC5BD5CD3579B244945D [File is digitally signed]

C:\Windows\System32\migwiz\dlmanifests\explorer-DL.man
[2009-06-10 16:36][2009-06-10 16:36] 0002571 ____A () 87354E386F0C6B4D1FD4D9301A468C76 [File is digitally signed]

C:\Windows\System32\migwiz\dlmanifests\Microsoft-Windows-IE-InternetExplorer-DL.man
[2009-07-13 16:35][2009-07-01 22:09] 0012749 ____A () 4C0AF26AE7CB4A8231D81A3FF382FC05 [File is digitally signed]

C:\Windows\System32\manifeststore\user32.amx
[2011-07-08 11:30][2010-11-20 04:51] 0342524 ____A () 2FFFCC20E95D9DF2A4046328F6BB7AEC [File is digitally signed]

C:\Windows\System32\en-US\explorerframe.dll.mui
[2009-07-14 01:35][2009-07-13 22:29] 0018432 ____A (Microsoft Corporation) 86F52FD53B778CCE631F7C06B8D722AD [File is digitally signed]

C:\Windows\System32\en-US\NetworkExplorer.dll.mui
[2009-07-14 01:35][2009-07-13 22:29] 0006656 ____A (Microsoft Corporation) A61A51AAD80BCC75E1E60F1ADAB9CD9B [File is digitally signed]

C:\Windows\System32\en-US\user32.dll.mui
[2011-07-08 11:40][2010-11-20 07:58] 0017920 ____A (Microsoft Corporation) EF9BC0D92F9AF6A446CA3179EFDA0CE0 [File is digitally signed]

C:\Windows\System32\CompatTel\Api-ms-win-downlevel-user32-l1-1-1.dll
[2017-03-03 02:29][2016-12-20 10:07] 0003584 ____A (Microsoft Corporation) CA0F55B487D767FB7E9BA51D115E9780 [File is digitally signed]

C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-Optional-Package-wrapper~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat
[2011-07-08 11:53][2010-11-20 16:26] 0007394 ____S () D6BECF7185D29D224EFC91030C2E5D98 [File is digitally signed]

C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-Optional-Package-wrapper~31bf3856ad364e35~amd64~~6.1.7601.17514.cat
[2011-07-08 11:52][2010-11-20 14:33] 0007394 ____S () 289AE1BDF6BB2D5CEDDD5D7B5432C5A6 [File is digitally signed]

C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-Optional-Package~31bf3856ad364e35~amd64~en-US~11.2.9600.16428.cat
[2013-12-10 07:33][2013-10-14 20:06] 0009085 ____S () E9CF10C30AC4D11E825546FC66EBBCDF [File is digitally signed]

C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-Optional-Package~31bf3856ad364e35~amd64~~11.2.9600.16428.cat
[2013-12-10 07:33][2013-10-14 20:06] 0013309 ____S () A9D3D4906737C83F906A4AB84AF12F72 [File is digitally signed]

C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-Package-MiniLP~31bf3856ad364e35~amd64~en-US~11.2.9600.16428.cat
[2013-12-10 07:33][2013-10-14 20:06] 0007497 ____S () 0494D9A1550B47F7AE0F93DBF9EB7F46 [File is digitally signed]

C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-Package-TopLevel~31bf3856ad364e35~amd64~~11.2.9600.16428.cat
[2013-12-10 07:33][2013-10-14 20:06] 0007497 ____S () 06C3E3278E12D84EF0DA2881456A4CCF [File is digitally signed]

C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-Package~31bf3856ad364e35~amd64~en-US~11.2.9600.16428.cat
[2013-12-10 07:33][2013-10-14 20:06] 0053177 ____S () 413820D08A7DA91B97C6D80331B5D330 [File is digitally signed]

C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-Package~31bf3856ad364e35~amd64~~11.2.9600.16428.cat
[2013-12-10 07:33][2013-10-14 20:06] 0007497 ____S () 7931F76B688097CBEDD5E23264498DB1 [File is digitally signed]

C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-Package~31bf3856ad364e35~amd64~~8.0.7601.17514.cat
[2011-07-08 11:52][2010-11-20 14:36] 0567471 ____S () F882D58D0B4E7F70A16C868EAA4E9609 [File is digitally signed]

C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-InternetExplorer-VistaPlus-Update~31bf3856ad364e35~amd64~~11.2.9600.16428.cat
[2013-12-10 07:33][2013-10-14 20:06] 0558629 ____S () CD7763D1A2FCEFA9EE33BF87113EC7E4 [File is digitally signed]

C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-Optional-Package-wrapper~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.cat
[2011-07-08 11:53][2010-11-20 16:26] 0007394 ____A () D6BECF7185D29D224EFC91030C2E5D98 [File is digitally signed]

C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-Optional-Package-wrapper~31bf3856ad364e35~amd64~en-US~6.1.7601.17514.mum
[2011-07-08 11:53][2010-11-20 15:37] 0001575 ____A () 4E9A4E050722844741F34E8196ECA534 [File is digitally signed]

C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-Optional-Package-wrapper~31bf3856ad364e35~amd64~~6.1.7601.17514.cat
[2011-07-08 11:52][2010-11-20 14:33] 0007394 ____A () 289AE1BDF6BB2D5CEDDD5D7B5432C5A6 [File is digitally signed]

C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-Optional-Package-wrapper~31bf3856ad364e35~amd64~~6.1.7601.17514.mum
[2011-07-08 11:52][2010-11-20 13:43] 0001614 ____A () 3DAA726B11866540589DA308196FDF57 [File is digitally signed]

C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-Optional-Package~31bf3856ad364e35~amd64~en-US~11.2.9600.16428.cat
[2013-12-10 07:33][2013-10-14 20:06] 0009085 ____A () E9CF10C30AC4D11E825546FC66EBBCDF [File is digitally signed]

C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-Optional-Package~31bf3856ad364e35~amd64~en-US~11.2.9600.16428.mum
[2013-12-10 07:33][2013-10-14 19:03] 0001449 ____A () BA35E980087E26D93B5F1F97245FA2B0 [File is digitally signed]

C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-Optional-Package~31bf3856ad364e35~amd64~~11.2.9600.16428.cat
[2013-12-10 07:33][2013-10-14 20:06] 0013309 ____A () A9D3D4906737C83F906A4AB84AF12F72 [File is digitally signed]

C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-Optional-Package~31bf3856ad364e35~amd64~~11.2.9600.16428.mum
[2013-12-10 07:33][2013-10-14 18:40] 0001646 ____A () 23F8BC98EB869DC949C426D8201921F1 [File is digitally signed]

C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-Package-MiniLP~31bf3856ad364e35~amd64~en-US~11.2.9600.16428.cat
[2013-12-10 07:33][2013-10-14 20:06] 0007497 ____A () 0494D9A1550B47F7AE0F93DBF9EB7F46 [File is digitally signed]

C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-Package-MiniLP~31bf3856ad364e35~amd64~en-US~11.2.9600.16428.mum
[2013-12-10 07:33][2013-10-14 20:05] 0001606 ____A () C6326946B3C0CC92DDD5DD15DE2FB286 [File is digitally signed]

C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-Package-TopLevel~31bf3856ad364e35~amd64~~11.2.9600.16428.cat
[2013-12-10 07:33][2013-10-14 20:06] 0007497 ____A () 06C3E3278E12D84EF0DA2881456A4CCF [File is digitally signed]

C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-Package-TopLevel~31bf3856ad364e35~amd64~~11.2.9600.16428.mum
[2013-12-10 07:33][2013-10-14 20:05] 0001769 ____A () 913003AEB931D2B8E2E95CD826324B05 [File is digitally signed]

C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-Package~31bf3856ad364e35~amd64~en-US~11.2.9600.16428.cat
[2013-12-10 07:33][2013-10-14 20:06] 0053177 ____A () 413820D08A7DA91B97C6D80331B5D330 [File is digitally signed]

C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-Package~31bf3856ad364e35~amd64~en-US~11.2.9600.16428.mum
[2013-12-10 07:33][2013-10-14 19:03] 0002765 ____A () 93846BE669FE1D09EB8F3F19A51FB751 [File is digitally signed]

C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-Package~31bf3856ad364e35~amd64~~11.2.9600.16428.cat
[2013-12-10 07:33][2013-10-14 20:06] 0007497 ____A () 7931F76B688097CBEDD5E23264498DB1 [File is digitally signed]

C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-Package~31bf3856ad364e35~amd64~~11.2.9600.16428.mum
[2013-12-10 07:33][2013-10-14 18:40] 0001274 ____A () D1956F04A2CC1EBEE98A8ECF273E9136 [File is digitally signed]

C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-Package~31bf3856ad364e35~amd64~~8.0.7601.17514.cat
[2011-07-08 11:52][2010-11-20 14:36] 0567471 ____A () F882D58D0B4E7F70A16C868EAA4E9609 [File is digitally signed]

C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-Package~31bf3856ad364e35~amd64~~8.0.7601.17514.mum
[2011-07-08 11:52][2010-11-20 13:42] 0001258 ____A () 54D7F3BA07CD158D6CE4B77983AFA473 [File is digitally signed]

C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-VistaPlus-Update~31bf3856ad364e35~amd64~~11.2.9600.16428.cat
[2013-12-10 07:33][2013-10-14 20:06] 0558629 ____A () CD7763D1A2FCEFA9EE33BF87113EC7E4 [File is digitally signed]

C:\Windows\servicing\Packages\Microsoft-Windows-InternetExplorer-VistaPlus-Update~31bf3856ad364e35~amd64~~11.2.9600.16428.mum
[2013-12-10 07:33][2013-10-14 18:40] 0002290 ____A () 043066955969F97390FAE03941CF8476 [File is digitally signed]

C:\Windows\en-US\explorer.exe.mui
[2009-07-14 01:35][2009-07-13 22:26] 0022016 ____A (Microsoft Corporation) 4B87EEFDC8E253F846A7DFB49A8E6C70 [File is digitally signed]

C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2012-03-23 09:05][2011-07-08 12:52] 0001409 ____A () 251DD9A9800A8692B9398B54540CF285 [File not signed]

C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012-03-23 09:05][2011-07-08 12:52] 0001443 ____A () DCA7FEE5BB278AFF52DB04AE53728D31 [File not signed]

C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk
[2009-07-14 00:49][2009-07-14 00:49] 0001228 ____A () 47B2E1C4DDD5FA161F4E7314222D7A29 [File not signed]

C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
[2012-03-23 09:05][2011-07-08 12:52] 0001493 ____A () F8E05A9E79D316EF67BBA2ADAE1A4F70 [File not signed]

C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer (2).lnk
[2012-03-23 09:05][2011-07-08 12:52] 0001443 ____A () DCA7FEE5BB278AFF52DB04AE53728D31 [File not signed]

C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer (3).lnk
[2012-03-23 09:05][2011-07-08 12:52] 0001443 ____A () DCA7FEE5BB278AFF52DB04AE53728D31 [File not signed]

C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
[2012-03-23 09:05][2009-07-14 01:09] 0001449 ____A () 53BE0C20BEF98BEE4968924E79A8384E [File not signed]

C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer (2).lnk
[2012-03-23 09:05][2009-07-14 00:49] 0001228 ____A () 47B2E1C4DDD5FA161F4E7314222D7A29 [File not signed]

C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer (3).lnk
[2012-03-23 09:05][2009-07-14 00:49] 0001228 ____A () 47B2E1C4DDD5FA161F4E7314222D7A29 [File not signed]

C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk
[2012-03-23 09:05][2009-07-14 00:49] 0001228 ____A () 47B2E1C4DDD5FA161F4E7314222D7A29 [File not signed]

C:\Users\Default\AppData\Local\Microsoft\Windows\Explorer\ExplorerStartupLog.etl
[2012-03-23 09:06][2011-08-03 18:30] 0008192 ____A () 2D45E1B97F1706308524B6508ED7C040 [File not signed]

C:\Users\Default\AppData\Local\Microsoft\Windows\Explorer\ExplorerStartupLog_RunOnce.etl
[2012-03-23 09:06][2011-08-26 12:48] 0016384 ____A () 9FB505BCA1B1265ED6B444998BA26215 [File not signed]

C:\Users\Amber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012-03-23 10:15][2013-12-10 11:09] 0001413 ____A () 18B6532553981651822374A004A8F127 [File not signed]

C:\Users\Amber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk
[2012-03-23 10:15][2009-07-14 00:49] 0001228 ____A () 47B2E1C4DDD5FA161F4E7314222D7A29 [File not signed]

C:\Users\Amber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
[2012-03-23 10:15][2013-12-10 11:09] 0001463 ____A () 60A44FACAA3790FA7785C6B7CDDA3E98 [File not signed]

C:\Users\Amber\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012-03-23 17:36][2012-03-23 17:36] 0001437 ____A () C86E7E9FADD267BD5CF397400C31105D [File not signed]

C:\Users\Amber\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer (2).lnk
[2012-03-23 10:15][2011-07-08 12:52] 0001443 ____A () DCA7FEE5BB278AFF52DB04AE53728D31 [File not signed]

C:\Users\Amber\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer (3).lnk
[2012-03-23 10:15][2011-07-08 12:52] 0001443 ____A () DCA7FEE5BB278AFF52DB04AE53728D31 [File not signed]

C:\Users\Amber\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
[2012-03-23 10:15][2013-12-10 11:09] 0001419 ____A () 43B8C8A2AAC46C449F3C86279B3476F4 [File not signed]

C:\Users\Amber\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer (2).lnk
[2012-03-23 10:15][2009-07-14 00:49] 0001228 ____A () 47B2E1C4DDD5FA161F4E7314222D7A29 [File not signed]

C:\Users\Amber\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer (3).lnk
[2012-03-23 10:15][2009-07-14 00:49] 0001228 ____A () 47B2E1C4DDD5FA161F4E7314222D7A29 [File not signed]

C:\Users\Amber\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer (4).lnk
[2015-05-16 20:05][2009-07-14 00:49] 0001228 ____A () 47B2E1C4DDD5FA161F4E7314222D7A29 [File not signed]

C:\Users\Amber\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk
[2012-03-23 10:15][2009-07-14 00:49] 0001228 ____A () 47B2E1C4DDD5FA161F4E7314222D7A29 [File not signed]

C:\Users\Amber\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer.lnk
[2015-08-06 12:35][2013-12-10 11:09] 0001419 ____A () 43B8C8A2AAC46C449F3C86279B3476F4 [File not signed]

C:\Users\Amber\AppData\Roaming\Dropbox\bin\winffi.user32.compiled._winffi_user32.pyd
[2017-02-12 11:06][2017-02-21 15:01] 0022864 ____A () 870A483F6E557C225043306F63D52EE4 [File is digitally signed]

C:\Users\Amber\AppData\Local\Microsoft\Windows\Explorer\ExplorerStartupLog.etl
[2012-03-23 10:15][2012-03-23 10:24] 0040960 ____A () FD9802ADEF831646C9B3683B679D6D8A [File not signed]

C:\Users\Amber\AppData\Local\Microsoft\Windows\Explorer\ExplorerStartupLog_RunOnce.etl
[2012-03-23 10:15][2017-03-14 20:11] 0024576 ____A () ED4F2F2F47F41E581423CC1F7D3FDEBC [File not signed]

C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012-08-02 13:52][2014-12-20 13:12] 0001373 ____A () C6E364AAEE296BD7F8AC0A6E0E65C25F [File not signed]

C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk
[2012-08-02 13:52][2009-07-14 00:49] 0001228 ____A () 47B2E1C4DDD5FA161F4E7314222D7A29 [File not signed]

C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
[2012-08-02 13:52][2014-12-20 13:12] 0001423 ____A () 8060D7DC882E4A526430AEDC0C05F80F [File not signed]

C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2014-12-20 13:23][2014-12-20 13:23] 0001367 ____A () 0E79C408DDEE5845D461EDE7CBC14BB2 [File not signed]

C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer (2).lnk
[2012-08-02 13:52][2011-07-08 12:52] 0001443 ____A () DCA7FEE5BB278AFF52DB04AE53728D31 [File not signed]

C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer (3).lnk
[2012-08-02 13:52][2011-07-08 12:52] 0001443 ____A () DCA7FEE5BB278AFF52DB04AE53728D31 [File not signed]

C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer (4).lnk
[2012-08-02 13:52][2012-08-02 13:52] 0001443 ____A () 925A6F9AF41328BEC64C7B4FAA566817 [File not signed]

C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
[2012-08-02 13:52][2014-12-20 13:12] 0001379 ____A () 4C6683FF8335AE227610908D97C38E09 [File not signed]

C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer (2).lnk
[2012-08-02 13:52][2009-07-14 00:49] 0001228 ____A () 47B2E1C4DDD5FA161F4E7314222D7A29 [File not signed]

C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer (3).lnk
[2012-08-02 13:52][2009-07-14 00:49] 0001228 ____A () 47B2E1C4DDD5FA161F4E7314222D7A29 [File not signed]

C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer (4).lnk
[2012-08-02 13:52][2009-07-14 00:49] 0001228 ____A () 47B2E1C4DDD5FA161F4E7314222D7A29 [File not signed]

C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk
[2012-08-02 13:52][2009-07-14 00:49] 0001228 ____A () 47B2E1C4DDD5FA161F4E7314222D7A29 [File not signed]

C:\Users\Administrator\AppData\Local\Microsoft\Windows\Explorer\ExplorerStartupLog.etl
[2012-08-02 13:52][2012-08-02 13:52] 0032768 ____A () 1917F40128CFC7AD488356BD34FA3743 [File not signed]

C:\Users\Administrator\AppData\Local\Microsoft\Windows\Explorer\ExplorerStartupLog_RunOnce.etl
[2012-08-02 13:52][2017-02-24 16:22] 0032768 ____A () AE0DEE3D0B70B03607FF6C3D4B1C105F [File not signed]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\GameExplorer.lnk
[2009-07-14 00:54][2009-07-14 00:54] 0000258 ____A () AE1153973EEE2A7F3661B03D33987AC7 [File not signed]

C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\WDExpressExtensions\Microsoft\SQLDB\Vsix\Microsoft.VisualStudio.Data.Tools.SqlObjectExplorer.pkgdef
[2013-09-19 03:04][2013-09-19 03:04] 0001035 ____A () 74999F3E24FFE3A395786FD9AAC21A6C [File not signed]

C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\VWDExpressExtensions\Microsoft\SQLDB\Vsix\Microsoft.VisualStudio.Data.Tools.SqlObjectExplorer.pkgdef
[2013-09-19 03:04][2013-09-19 03:04] 0001035 ____A () 74999F3E24FFE3A395786FD9AAC21A6C [File not signed]

C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\Extensions\Microsoft\SQLDB\Microsoft.VisualStudio.Data.Tools.SqlObjectExplorer.dll
[2013-09-19 03:14][2013-09-19 03:14] 0269984 ____A (Microsoft Corporation) 16899C09EFE0AAD10BD18374C1AD9781 [File is digitally signed]

C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\Extensions\Microsoft\SQLDB\Vsix\Microsoft.VisualStudio.Data.Tools.SqlObjectExplorer.pkgdef
[2013-09-19 03:04][2013-09-19 03:04] 0001035 ____A () 74999F3E24FFE3A395786FD9AAC21A6C [File not signed]

C:\Program Files (x86)\Finale 2009\Help Files\Content\Finale\Finale_and_Explorer.htm
[2008-06-24 19:24][2008-06-24 19:24] 0034715 ____A () C13D0A9A76EB9BC6C3257E34759EA775 [File not signed]

C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_explorer.exe
[2010-10-15 22:07][2010-10-15 22:07] 0273696 ____A (Broadcom Corporation.) 2705E3FACB88C8EDA1191091045BC3B4 [File is digitally signed]

C:\Program Files\Java\jdk1.8.0_20\lib\visualvm\platform\update_tracking\org-openide-explorer.xml
[2014-09-06 18:48][2014-09-06 18:48] 0000462 ____A () F46089CDF2D13891A90E7D9056BCEFD1 [File not signed]

C:\Program Files\Java\jdk1.8.0_20\lib\visualvm\platform\modules\org-openide-explorer.jar
[2014-09-06 18:48][2014-09-06 18:48] 1576036 ____A () E76023D1743F275BD4580BD938993C7F [File not signed]

C:\Program Files\Java\jdk1.8.0_20\lib\visualvm\platform\modules\locale\org-openide-explorer_ja.jar
[2014-09-06 18:48][2014-09-06 18:48] 0008254 ____A () 6923F78318A96E5E5FD7D8BF772CEB2F [File not signed]

C:\Program Files\Java\jdk1.8.0_20\lib\visualvm\platform\modules\locale\org-openide-explorer_zh_CN.jar
[2014-09-06 18:48][2014-09-06 18:48] 0007849 ____A () 12E22E01A9557F77CAC04EA40272FD3A [File not signed]

C:\Program Files\Java\jdk1.8.0_20\lib\visualvm\platform\config\Modules\org-openide-explorer.xml
[2014-09-06 18:48][2014-09-06 18:48] 0000413 ____A () 38A311A6621D4686B60150CF2194D283 [File not signed]

C:\Program Files\Java\jdk1.8.0_20\lib\visualvm\platform\config\ModuleAutoDeps\org-openide-explorer.xml
[2014-09-06 18:48][2014-09-06 18:48] 0000946 ____A () AE3BE854A11AC43835164C487D9DD751 [File not signed]

C:\Autodesk\WI\Autodesk AutoCAD Architecture 2015\x64\en-US\ACA\Acad\Program Files\Root\UserDataCache\en-us\Support\contentexplorer.cuix
[2010-12-22 14:41][2010-12-22 14:41] 0005565 ____A () B36658F1B3BCB6CF6DC0E4797221F90F [File not signed]

====== End of Search ======



#10 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,612 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:01:57 AM

Posted 15 March 2017 - 03:43 PM

Before continuing, did you (try to) replace either explorer.exe or user32.dll recently?


regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft

 

animinionsmalltext.gif


#11 the2bachic

the2bachic
  • Topic Starter

  • Members
  • 153 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Georgia, USA
  • Local time:07:57 PM

Posted 15 March 2017 - 07:37 PM

No, I had not tried to replace anything. I had not even run Windows Updates in several months when this began. Unless I am forgetting something (fairly certain I am not forgetting anything) the only thing altered in any way for months was updating the databases for MBAM, SAS, and Avast, and maybe a Java update and/or an Adobe Acrobat update.

#12 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,612 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:01:57 AM

Posted 16 March 2017 - 03:34 AM

Does Windows update not run at all, or did you simply disable it? If the latter, I'd strongly recommend you to enable it and do an online update first.


regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft

 

animinionsmalltext.gif


#13 the2bachic

the2bachic
  • Topic Starter

  • Members
  • 153 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Georgia, USA
  • Local time:07:57 PM

Posted 16 March 2017 - 05:17 AM

I disabled it during the time that Microsoft was attempting to force the upgrade to Windows 7. When that disappeared, I didn't think to set it back to update automatically.

After this problem began and during one of the times the computer appeared to be working correctly again, I did perform all updates. My apologies for not being more specific in that last reply. It was in the long list of things in the process of repairing that I posted about above, but I shouldn't have expected you to remember that!

Edited by the2bachic, 16 March 2017 - 05:18 AM.


#14 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,612 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:01:57 AM

Posted 16 March 2017 - 06:05 AM

Please do the following. Click Start, type cmd, right click Command Prompt (cmd.exe) and select Run as Administrator.

 

Copy/paste the following at the command prompt and press enter after each line (wait for the prompt to reappear):

sfc /scanfile="c:\windows\explorer.exe"

sfc /scanfile="c:\windows\system32\user32.dll"

 

Let me know what comes back after each command.


regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft

 

animinionsmalltext.gif


#15 the2bachic

the2bachic
  • Topic Starter

  • Members
  • 153 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Georgia, USA
  • Local time:07:57 PM

Posted 16 March 2017 - 11:42 AM

After both, the response was "Windows Resource Protection did not find any integrity violations."






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users