Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

winpatrol asks permission windows command processor on windows 10


  • This topic is locked This topic is locked
23 replies to this topic

#1 careful

careful

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:07:58 PM

Posted 26 July 2017 - 03:05 PM

I have 64 bit windows 10 and my winpatrol comes up every so often and asks permission to allow windows command processor to startup with windows, I was reading where this could be a virus or trojan. I downloaded the farbar and will post the results below.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-07-2017
Ran by Diane (administrator) on DESKTOP-4RSJHTG (26-07-2017 16:02:01)
Running from C:\Users\Diane\Desktop\farbar
Loaded Profiles: Diane (Available Profiles: defaultuser0 & Diane)
Platform: Windows 10 Pro Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(CobianSoft, Luis Cobian) C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Luis Cobian, CobianSoft) C:\Program Files (x86)\Cobian Backup 11\cbService.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(AOMEI Tech Co., Ltd.) C:\Program Files (x86)\AOMEI Backupper\ABService.exe
(Genie9) C:\Program Files\Genie9\Genie Timeline\GenieTimelineService.exe
(MSI) C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe
(Intel® Corporation) C:\Program Files\Intel\Intel® Online Connect Access\LegacyCsLoaderService.exe
(Intel® Corporation) C:\Program Files\Intel\Intel® Online Connect Access\IntelTechnologyAccessService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Siber Systems) C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
(Ulrich Krebs) C:\Program Files (x86)\Kalender\Kalender.exe
(Ruiware) C:\Program Files (x86)\Ruiware\WinPatrol\WinPatrol.exe
(MSI) C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Genie9) C:\Program Files\Genie9\Genie Timeline\GenieTimeLineAgent.exe
(Luis Cobian, CobianSoft) C:\Program Files (x86)\Cobian Backup 11\cbInterface.exe
() C:\Program Files (x86)\AOMEI Backupper\ABNotify.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Online Connect\ioc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8241.41275.0_x64__8wekyb3d8bbwe\HxOutlook.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8241.41275.0_x64__8wekyb3d8bbwe\HxTsr.exe
() C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1705.1301.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.820.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Program Files\Windows Mail\WinMail.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9198592 2017-02-10] (Realtek Semiconductor)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213832 2017-07-25] (AVAST Software)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [Super Charger] => C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe [1022928 2017-01-05] (MSI)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3486520 2017-07-12] (Dropbox, Inc.)
HKLM-x32\...\Run: [Cobian Backup 11 interface] => C:\Program Files (x86)\Cobian Backup 11\cbInterface.exe [4407808 2013-03-07] (Luis Cobian, CobianSoft)
HKLM-x32\...\Run: [ABNotify] => C:\Program Files (x86)\AOMEI Backupper\ABNotify.exe [89960 2017-03-25] ()
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKU\S-1-5-21-3119151931-944679501-478495044-1001\...\Run: [RoboForm] => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [110376 2017-05-31] (Siber Systems)
HKU\S-1-5-21-3119151931-944679501-478495044-1001\...\Run: [Kalender] => C:\Program Files (x86)\Kalender\Kalender.exe [1015808 2017-05-01] (Ulrich Krebs)
HKU\S-1-5-21-3119151931-944679501-478495044-1001\...\Run: [WinPatrol] => C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe [1223560 2017-05-07] (Ruiware)
HKU\S-1-5-21-3119151931-944679501-478495044-1001\...\MountPoints2: {0938790c-452e-11e7-840f-806e6f6e6963} - "D:\autorun.exe"

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{a6a053ae-0651-4d4b-9de8-e7c7d8f62cd8}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
BHO: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2017-05-31] (Siber Systems Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2017-05-31] (Siber Systems Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
Toolbar: HKLM - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2017-05-31] (Siber Systems Inc.)
Toolbar: HKLM-x32 - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2017-05-31] (Siber Systems Inc.)

Edge:
======
Edge Extension: (No Name) -> EdgeExtension_SiberSystemsIncRoboFormEdge_7kk3kr9e0p1np => C:\Program Files\WindowsApps\SiberSystemsInc.RoboFormEdge_8.3.6.0_neutral__7kk3kr9e0p1np [not found]

FireFox:
========
FF DefaultProfile: zcb721on.default
FF ProfilePath: C:\Users\Diane\AppData\Roaming\Mozilla\Firefox\Profiles\zcb721on.default [2017-07-26]
FF Homepage: Mozilla\Firefox\Profiles\zcb721on.default -> google.com
FF Session Restore: Mozilla\Firefox\Profiles\zcb721on.default -> is enabled.
FF Extension: (Keepa - Amazon Price Tracker) - C:\Users\Diane\AppData\Roaming\Mozilla\Firefox\Profiles\zcb721on.default\Extensions\amptra@keepa.com.xpi [2017-07-17]
FF Extension: (The Camelizer) - C:\Users\Diane\AppData\Roaming\Mozilla\Firefox\Profiles\zcb721on.default\Extensions\izer@camelcamelcamel.com.xpi [2017-07-03]
FF Extension: (Coupons at Checkout) - C:\Users\Diane\AppData\Roaming\Mozilla\Firefox\Profiles\zcb721on.default\Extensions\jid0-5R3LLpyrG0a1kPDXAA8ZKmM0bgM@jetpack.xpi [2017-05-30]
FF Extension: (YouTube ALL HTML5) - C:\Users\Diane\AppData\Roaming\Mozilla\Firefox\Profiles\zcb721on.default\Extensions\jid1-qj0w91o64N7Eeg@jetpack.xpi [2017-05-30]
FF Extension: (Open in IE) - C:\Users\Diane\AppData\Roaming\Mozilla\Firefox\Profiles\zcb721on.default\Extensions\openinie@wittersworld.com.xpi [2017-05-30]
FF Extension: (Print Edit) - C:\Users\Diane\AppData\Roaming\Mozilla\Firefox\Profiles\zcb721on.default\Extensions\printedit@DW-dev.xpi [2017-05-30]
FF Extension: (Print Without Ads) - C:\Users\Diane\AppData\Roaming\Mozilla\Firefox\Profiles\zcb721on.default\Extensions\printwithoutads@oleg.vaskevich.xpi [2017-05-30]
FF Extension: (Avast SafePrice) - C:\Users\Diane\AppData\Roaming\Mozilla\Firefox\Profiles\zcb721on.default\Extensions\sp@avast.com.xpi [2017-06-05]
FF Extension: (Avast Online Security) - C:\Users\Diane\AppData\Roaming\Mozilla\Firefox\Profiles\zcb721on.default\Extensions\wrc@avast.com.xpi [2017-06-04]
FF Extension: (NoSquint Plus) - C:\Users\Diane\AppData\Roaming\Mozilla\Firefox\Profiles\zcb721on.default\Extensions\zoomlevelplus@zoomlevelplus.net.xpi [2017-07-24]
FF Extension: (Garmin Communicator) - C:\Users\Diane\AppData\Roaming\Mozilla\Firefox\Profiles\zcb721on.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2017-05-30]
FF Extension: (BugMeNot Plugin) - C:\Users\Diane\AppData\Roaming\Mozilla\Firefox\Profiles\zcb721on.default\Extensions\{987311C6-B504-4aa2-90BF-60CC49808D42}.xpi [2017-05-30]
FF Extension: (No Color) - C:\Users\Diane\AppData\Roaming\Mozilla\Firefox\Profiles\zcb721on.default\Extensions\{ae443e4d-02db-4eef-bcc2-0f1b17edb941}.xpi [2017-05-30]
FF Extension: (Adblock Plus) - C:\Users\Diane\AppData\Roaming\Mozilla\Firefox\Profiles\zcb721on.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-06-07]
FF Extension: (IE View Lite) - C:\Users\Diane\AppData\Roaming\Mozilla\Firefox\Profiles\zcb721on.default\Extensions\{FDD8ECF0-451A-414D-8C8F-7B7F78B0ECD3}.xpi [2017-05-30]
FF HKLM-x32\...\Firefox\Extensions: [{22119944-ED35-4ab1-910B-E619EA06A115}] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox\roboform.xpi
FF Extension: (RoboForm Toolbar) - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox\roboform.xpi [2017-05-31]
FF HKU\S-1-5-21-3119151931-944679501-478495044-1001\...\Firefox\Extensions: [{22119944-ED35-4ab1-910B-E619EA06A115}] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox\roboform.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_26_0_0_137.dll [2017-07-12] ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-10] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_137.dll [2017-07-12] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2016-04-14] (CANON INC.)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-12-29] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-12-29] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-31] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-31] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-04] (Adobe Systems Inc.)

Chrome:
=======
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\Diane\AppData\Local\Google\Chrome\User Data\Default [2017-07-26]
CHR Extension: (Google Docs) - C:\Users\Diane\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-05-30]
CHR Extension: (Google Drive) - C:\Users\Diane\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-05-30]
CHR Extension: (YouTube) - C:\Users\Diane\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-05-30]
CHR Extension: (Adobe Acrobat) - C:\Users\Diane\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-06-12]
CHR Extension: (Avast SafePrice) - C:\Users\Diane\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-06-05]
CHR Extension: (Google Docs Offline) - C:\Users\Diane\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-05-30]
CHR Extension: (Avast Online Security) - C:\Users\Diane\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-06-05]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Diane\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-05-30]
CHR Extension: (Gmail) - C:\Users\Diane\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-05-30]
CHR Extension: (Chrome Media Router) - C:\Users\Diane\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-07-14]
CHR Extension: (RoboForm Password Manager) - C:\Users\Diane\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnlccmojcmeohlpggmfnbbiapkmbliob [2017-07-15]
CHR HKLM\...\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2017-05-31]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2017-05-31]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7430992 2017-07-25] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [263312 2017-07-25] (AVAST Software)
R2 Backupper Service; C:\Program Files (x86)\AOMEI Backupper\ABService.exe [122736 2017-03-25] (AOMEI Tech Co., Ltd.)
R2 cbVSCService11; C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe [67584 2013-03-07] (CobianSoft, Luis Cobian) [File not signed]
R2 CobianBackup11; C:\Program Files (x86)\Cobian Backup 11\cbService.exe [1131008 2013-03-07] (Luis Cobian, CobianSoft) [File not signed]
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-06-04] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-06-04] (Dropbox, Inc.)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [49992 2017-07-12] (Dropbox, Inc.)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2017-05-31] (Macrovision Europe Ltd.) [File not signed]
R2 GenieTimelineService; C:\Program Files\Genie9\Genie Timeline\GenieTimelineService.exe [678464 2013-12-08] (Genie9)
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [987432 2016-07-26] (Intel® Corporation)
R3 Intel® Online Connect; C:\Program Files\Intel\Intel® Online Connect\ioc.exe [25824 2016-10-04] (Intel Corporation)
S2 Intel® Online Connect Helper; C:\Program Files\Intel\Intel® Online Connect\iocHelperService.exe [22752 2016-10-04] (Intel Corporation)
S3 Intel® Online Connect Software Asset Manager; C:\Program Files (x86)\Intel\Intel® Online Connect Access\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [18152 2016-09-29] (Intel Corporation)
R2 Intel® TechnologyAccessLegacyCSLoader; C:\Program Files\Intel\Intel® Online Connect Access\LegacyCsLoaderService.exe [173288 2016-10-05] (Intel® Corporation)
R2 Intel® TechnologyAccessService; C:\Program Files\Intel\Intel® Online Connect Access\IntelTechnologyAccessService.exe [496872 2016-10-05] (Intel® Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [177440 2016-10-20] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe [164304 2017-01-05] (MSI)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [458176 2016-12-29] (NVIDIA Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-09-15] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-27] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103712 2017-04-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 ambakdrv; C:\Windows\System32\ambakdrv.sys [51120 2016-12-23] ()
R2 ammntdrv; C:\Windows\system32\ammntdrv.sys [171952 2016-12-23] ()
R2 amwrtdrv; C:\Windows\system32\amwrtdrv.sys [38320 2016-12-23] ()
R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [320008 2017-07-25] (AVAST Software s.r.o.)
R0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [198976 2017-07-25] (AVAST Software s.r.o.)
R0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [343288 2017-07-25] (AVAST Software s.r.o.)
R0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [57728 2017-07-25] (AVAST Software s.r.o.)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [46984 2017-07-07] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [41800 2017-07-07] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [146696 2017-07-25] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [110352 2017-07-07] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [84392 2017-07-07] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1015848 2017-07-07] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [585608 2017-07-07] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [198768 2017-07-07] (AVAST Software)
R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [361336 2017-07-07] (AVAST Software)
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.)
R3 e1dexpress; C:\Windows\system32\DRIVERS\e1d65x64.sys [543184 2016-07-25] (Intel Corporation)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77376 2017-07-17] ()
R2 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [188352 2017-07-17] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [101784 2017-07-26] (Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [45472 2017-07-26] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [253856 2017-07-26] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [93600 2017-07-26] (Malwarebytes)
R1 ndisrd; C:\Windows\system32\DRIVERS\ndisrfl.sys [59792 2016-09-13] (Intel Corporation)
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI)
R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nv_dispiwu.inf_amd64_b67dc924fff8de6d\nvlddmkm.sys [14199224 2017-01-04] (NVIDIA Corporation)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd.)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-07-26 16:01 - 2017-07-26 16:02 - 00000000 ____D C:\FRST
2017-07-26 16:00 - 2017-07-26 16:02 - 00000000 ____D C:\Users\Diane\Desktop\farbar
2017-07-26 15:56 - 2017-07-26 15:56 - 00000000 ____D C:\ProgramData\SWCUTemp
2017-07-26 07:17 - 2017-07-26 07:17 - 00003374 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3119151931-944679501-478495044-1001
2017-07-25 13:49 - 2017-07-25 13:49 - 00400464 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-07-23 07:22 - 2017-07-23 07:22 - 00000000 ____D C:\Users\Diane\AppData\Local\ElevatedDiagnostics
2017-07-21 06:11 - 2012-09-20 05:00 - 00393728 _____ (CANON INC.) C:\Windows\system32\CNMXLMBO.DLL
2017-07-21 06:10 - 2017-07-21 06:11 - 25955480 _____ C:\Users\Diane\Downloads\xp68-win-mx520-5_65-ea32_2.exe
2017-07-16 18:56 - 2017-07-16 18:56 - 00000000 ____D C:\Users\Default\AppData\Roaming\Genie9
2017-07-16 18:56 - 2017-07-16 18:56 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Genie9
2017-07-13 13:28 - 2017-07-13 13:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-07-13 07:11 - 2017-07-13 07:11 - 00000000 ____D C:\Users\Diane\AppData\Roaming\Genie9
2017-07-13 07:11 - 2017-07-13 07:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Genie9
2017-07-13 07:11 - 2017-07-13 07:11 - 00000000 ____D C:\Program Files\Genie9
2017-07-13 07:09 - 2017-07-13 07:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cobian Backup 11
2017-07-13 07:09 - 2017-07-13 07:09 - 00000000 ____D C:\Program Files (x86)\Cobian Backup 11
2017-07-13 06:59 - 2017-07-13 07:10 - 13497368 _____ (Genie9) C:\Users\Diane\Downloads\GenieTimeline5Free.exe
2017-07-13 06:59 - 2017-07-13 07:00 - 19709440 _____ (Luis Cobian, CobianSoft) C:\Users\Diane\Downloads\cbSetup.exe
2017-07-13 06:04 - 2017-07-13 06:04 - 40375216 _____ (Mozilla) C:\Users\Diane\Downloads\Thunderbird Setup 52.2.1.exe
2017-07-12 18:50 - 2017-07-12 18:50 - 00001466 _____ C:\Users\Diane\Desktop\WinMail - Shortcut.lnk
2017-07-12 16:43 - 2017-07-07 03:49 - 00340824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-07-12 16:43 - 2017-07-07 03:46 - 00781152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
2017-07-12 16:43 - 2017-07-07 03:45 - 02263832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-07-12 16:43 - 2017-07-07 03:40 - 20967840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2017-07-12 16:43 - 2017-07-07 03:29 - 05686272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2017-07-12 16:43 - 2017-07-07 03:13 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupShim.dll
2017-07-12 16:43 - 2017-07-07 03:13 - 00310272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll
2017-07-12 16:43 - 2017-07-07 03:10 - 00755200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-07-12 16:43 - 2017-07-07 03:09 - 00637952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2017-07-12 16:43 - 2017-07-07 03:09 - 00506368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-07-12 16:43 - 2017-07-07 03:06 - 07626752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2017-07-12 16:43 - 2017-07-07 03:03 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msinfo32.exe
2017-07-12 16:43 - 2017-07-07 03:02 - 01313280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdc.dll
2017-07-12 16:43 - 2017-07-07 02:55 - 04423680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2017-07-12 16:43 - 2017-07-07 02:55 - 01571840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2017-07-12 16:43 - 2017-07-07 02:54 - 02997248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
2017-07-12 16:43 - 2017-07-07 02:53 - 02483200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-07-12 16:43 - 2017-07-07 02:52 - 04561408 _____ (Microsoft) C:\Windows\SysWOW64\dbgeng.dll
2017-07-12 16:43 - 2017-07-07 02:52 - 01599488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-07-12 16:43 - 2017-07-07 02:52 - 01413632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OpcServices.dll
2017-07-12 16:43 - 2017-06-21 04:18 - 01470816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppVEntSubsystems32.dll
2017-07-12 16:43 - 2017-06-21 03:52 - 00088416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\scmbus.sys
2017-07-12 16:43 - 2017-06-21 03:52 - 00081760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stornvme.sys
2017-07-12 16:43 - 2017-06-21 03:42 - 01573280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-07-12 16:43 - 2017-06-21 03:42 - 00601712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2017-07-12 16:43 - 2017-06-21 03:39 - 02048496 _____ C:\Windows\SysWOW64\CoreUIComponents.dll
2017-07-12 16:43 - 2017-06-21 03:38 - 00790752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-07-12 16:43 - 2017-06-21 03:36 - 00557408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys
2017-07-12 16:43 - 2017-06-21 03:36 - 00129888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2017-07-12 16:43 - 2017-06-21 03:30 - 00869848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll
2017-07-12 16:43 - 2017-06-21 03:30 - 00196960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ifsutil.dll
2017-07-12 16:43 - 2017-06-21 03:29 - 05722320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2017-07-12 16:43 - 2017-06-21 03:28 - 02277288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2017-07-12 16:43 - 2017-06-21 03:28 - 01504056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2017-07-12 16:43 - 2017-06-21 03:28 - 00524776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2017-07-12 16:43 - 2017-06-21 03:28 - 00170960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-07-12 16:43 - 2017-06-21 03:27 - 01431232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2017-07-12 16:43 - 2017-06-21 03:27 - 01122344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dcomp.dll
2017-07-12 16:43 - 2017-06-21 03:27 - 00975744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.appcore.dll
2017-07-12 16:43 - 2017-06-21 03:27 - 00861024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LicenseManager.dll
2017-07-12 16:43 - 2017-06-21 03:27 - 00549088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2017-07-12 16:43 - 2017-06-21 03:27 - 00116576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudExperienceHostCommon.dll
2017-07-12 16:43 - 2017-06-21 03:25 - 02168288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
2017-07-12 16:43 - 2017-06-21 03:25 - 01980776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2017-07-12 16:43 - 2017-06-21 03:24 - 00846560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinTypes.dll
2017-07-12 16:43 - 2017-06-21 03:24 - 00154432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntmarta.dll
2017-07-12 16:43 - 2017-06-21 03:22 - 00361104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsmf.dll
2017-07-12 16:43 - 2017-06-21 03:21 - 06665440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-07-12 16:43 - 2017-06-21 03:21 - 04023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2017-07-12 16:43 - 2017-06-21 03:21 - 01845512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2017-07-12 16:43 - 2017-06-21 03:21 - 01557808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll
2017-07-12 16:43 - 2017-06-21 03:21 - 01277856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2017-07-12 16:43 - 2017-06-21 03:21 - 00952416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
2017-07-12 16:43 - 2017-06-21 03:21 - 00374448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFPlay.dll
2017-07-12 16:43 - 2017-06-21 03:20 - 01360464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetsrc.dll
2017-07-12 16:43 - 2017-06-21 03:20 - 00981888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetcore.dll
2017-07-12 16:43 - 2017-06-21 03:20 - 00962768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2017-07-12 16:43 - 2017-06-21 03:20 - 00312472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mftranscode.dll
2017-07-12 16:43 - 2017-06-21 03:19 - 04312248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2017-07-12 16:43 - 2017-06-21 03:04 - 01631232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Resources.dll
2017-07-12 16:43 - 2017-06-21 03:04 - 00026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcconf.dll
2017-07-12 16:43 - 2017-06-21 03:02 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\scmdisk0101.sys
2017-07-12 16:43 - 2017-06-21 03:01 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Radios.dll
2017-07-12 16:43 - 2017-06-21 03:00 - 00519168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ngccredprov.dll
2017-07-12 16:43 - 2017-06-21 03:00 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDeviceRegistration.dll
2017-07-12 16:43 - 2017-06-21 03:00 - 00143360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uudf.dll
2017-07-12 16:43 - 2017-06-21 03:00 - 00138240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DisplayManager.dll
2017-07-12 16:43 - 2017-06-21 02:59 - 00285184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.BlockedShutdown.dll
2017-07-12 16:43 - 2017-06-21 02:59 - 00255488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\unimdm.tsp
2017-07-12 16:43 - 2017-06-21 02:59 - 00177664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Web.Diagnostics.dll
2017-07-12 16:43 - 2017-06-21 02:59 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.HostName.dll
2017-07-12 16:43 - 2017-06-21 02:59 - 00097792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.System.SystemManagement.dll
2017-07-12 16:43 - 2017-06-21 02:58 - 00136192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinRtTracing.dll
2017-07-12 16:43 - 2017-06-21 02:58 - 00129024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.SerialCommunication.dll
2017-07-12 16:43 - 2017-06-21 02:58 - 00094208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepositoryClient.dll
2017-07-12 16:43 - 2017-06-21 02:58 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-07-12 16:43 - 2017-06-21 02:58 - 00059904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.System.UserDeviceAssociation.dll
2017-07-12 16:43 - 2017-06-21 02:57 - 00142336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.WiFi.dll
2017-07-12 16:43 - 2017-06-21 02:57 - 00122880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sendmail.dll
2017-07-12 16:43 - 2017-06-21 02:56 - 00392192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Gaming.Input.dll
2017-07-12 16:43 - 2017-06-21 02:56 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.LowLevel.dll
2017-07-12 16:43 - 2017-06-21 02:56 - 00315904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Gaming.XboxLive.Storage.dll
2017-07-12 16:43 - 2017-06-21 02:56 - 00299520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataAccountApis.dll
2017-07-12 16:43 - 2017-06-21 02:56 - 00237056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SyncSettings.dll
2017-07-12 16:43 - 2017-06-21 02:56 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2017-07-12 16:43 - 2017-06-21 02:56 - 00203776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credprovhost.dll
2017-07-12 16:43 - 2017-06-21 02:56 - 00184320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserMgrProxy.dll
2017-07-12 16:43 - 2017-06-21 02:56 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgent.exe
2017-07-12 16:43 - 2017-06-21 02:56 - 00113152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Lights.dll
2017-07-12 16:43 - 2017-06-21 02:55 - 00557568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StoreAgent.dll
2017-07-12 16:43 - 2017-06-21 02:55 - 00404992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dsreg.dll
2017-07-12 16:43 - 2017-06-21 02:55 - 00265728 _____ C:\Windows\SysWOW64\Windows.Perception.Stub.dll
2017-07-12 16:43 - 2017-06-21 02:55 - 00117760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AuthBroker.dll
2017-07-12 16:43 - 2017-06-21 02:55 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Core.dll
2017-07-12 16:43 - 2017-06-21 02:54 - 00609280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Import.dll
2017-07-12 16:43 - 2017-06-21 02:54 - 00483840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.AllJoyn.dll
2017-07-12 16:43 - 2017-06-21 02:54 - 00298496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Management.dll
2017-07-12 16:43 - 2017-06-21 02:54 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgentUserBroker.exe
2017-07-12 16:43 - 2017-06-21 02:53 - 00431616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\efswrt.dll
2017-07-12 16:43 - 2017-06-21 02:53 - 00390656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CredProvDataModel.dll
2017-07-12 16:43 - 2017-06-21 02:53 - 00386048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.WiFiDirect.dll
2017-07-12 16:43 - 2017-06-21 02:53 - 00332288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Bluetooth.dll
2017-07-12 16:43 - 2017-06-21 02:53 - 00325120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2017-07-12 16:43 - 2017-06-21 02:53 - 00284672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepsync.dll
2017-07-12 16:43 - 2017-06-21 02:53 - 00271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\deviceaccess.dll
2017-07-12 16:43 - 2017-06-21 02:53 - 00218624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WwaApi.dll
2017-07-12 16:43 - 2017-06-21 02:53 - 00202752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll
2017-07-12 16:43 - 2017-06-21 02:53 - 00201728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExecModelClient.dll
2017-07-12 16:43 - 2017-06-21 02:53 - 00185856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll
2017-07-12 16:43 - 2017-06-21 02:53 - 00175616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Scanners.dll
2017-07-12 16:43 - 2017-06-21 02:53 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepapi.dll
2017-07-12 16:43 - 2017-06-21 02:52 - 00262144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Picker.dll
2017-07-12 16:43 - 2017-06-21 02:52 - 00182784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BioCredProv.dll
2017-07-12 16:43 - 2017-06-21 02:51 - 00747520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Ocr.dll
2017-07-12 16:43 - 2017-06-21 02:51 - 00314368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Usb.dll
2017-07-12 16:43 - 2017-06-21 02:51 - 00284672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.dll
2017-07-12 16:43 - 2017-06-21 02:51 - 00258048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsDocumentTargetPrint.dll
2017-07-12 16:43 - 2017-06-21 02:50 - 01167360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2017-07-12 16:43 - 2017-06-21 02:50 - 00857600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EmailApis.dll
2017-07-12 16:43 - 2017-06-21 02:50 - 00529920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2017-07-12 16:43 - 2017-06-21 02:50 - 00297472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2017-07-12 16:43 - 2017-06-21 02:50 - 00238080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AboveLockAppHost.dll
2017-07-12 16:43 - 2017-06-21 02:49 - 00500224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.Printing.dll
2017-07-12 16:43 - 2017-06-21 02:49 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.dll
2017-07-12 16:43 - 2017-06-21 02:49 - 00288256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CryptoWinRT.dll
2017-07-12 16:43 - 2017-06-21 02:48 - 02333184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2017-07-12 16:43 - 2017-06-21 02:48 - 00395264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dmenrollengine.dll
2017-07-12 16:43 - 2017-06-21 02:48 - 00336384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\azroleui.dll
2017-07-12 16:43 - 2017-06-21 02:47 - 13873664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2017-07-12 16:43 - 2017-06-21 02:46 - 04615168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2017-07-12 16:43 - 2017-06-21 02:46 - 01323008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsp_fs.dll
2017-07-12 16:43 - 2017-06-21 02:46 - 01137152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsp_health.dll
2017-07-12 16:43 - 2017-06-21 02:46 - 01077760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Editing.dll
2017-07-12 16:43 - 2017-06-21 02:46 - 00355328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RTMediaFrame.dll
2017-07-12 16:43 - 2017-06-21 02:45 - 00891904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autochk.exe
2017-07-12 16:43 - 2017-06-21 02:45 - 00471552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll
2017-07-12 16:43 - 2017-06-21 02:45 - 00313856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2017-07-12 16:43 - 2017-06-21 02:45 - 00102400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uexfat.dll
2017-07-12 16:43 - 2017-06-21 02:44 - 00795648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MiracastReceiver.dll
2017-07-12 16:43 - 2017-06-21 02:44 - 00535040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\untfs.dll
2017-07-12 16:43 - 2017-06-21 02:44 - 00343040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToDevice.dll
2017-07-12 16:43 - 2017-06-21 02:44 - 00136704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ufat.dll
2017-07-12 16:43 - 2017-06-21 02:43 - 01534464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.Printing.3D.dll
2017-07-12 16:43 - 2017-06-21 02:43 - 00713216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpnapps.dll
2017-07-12 16:43 - 2017-06-21 02:43 - 00653312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.AccountsControl.dll
2017-07-12 16:43 - 2017-06-21 02:43 - 00468992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.InkControls.dll
2017-07-12 16:43 - 2017-06-21 02:43 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cnvfat.dll
2017-07-12 16:43 - 2017-06-21 02:42 - 03307008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2017-07-12 16:43 - 2017-06-21 02:42 - 02749440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mispace.dll
2017-07-12 16:43 - 2017-06-21 02:42 - 00853504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autofmt.exe
2017-07-12 16:43 - 2017-06-21 02:42 - 00525312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LogonController.dll
2017-07-12 16:43 - 2017-06-21 02:42 - 00470016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll
2017-07-12 16:43 - 2017-06-21 02:41 - 01255936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AzureSettingSyncProvider.dll
2017-07-12 16:43 - 2017-06-21 02:41 - 00459776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Playback.MediaPlayer.dll
2017-07-12 16:43 - 2017-06-21 02:40 - 02641920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2017-07-12 16:43 - 2017-06-21 02:40 - 02154496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\storagewmi.dll
2017-07-12 16:43 - 2017-06-21 02:40 - 00901120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Bluetooth.dll
2017-07-12 16:43 - 2017-06-21 02:40 - 00895488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Streaming.dll
2017-07-12 16:43 - 2017-06-21 02:40 - 00675840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll
2017-07-12 16:43 - 2017-06-21 02:40 - 00220672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToReceiver.dll
2017-07-12 16:43 - 2017-06-21 02:40 - 00090624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\olepro32.dll
2017-07-12 16:43 - 2017-06-21 02:39 - 00546304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uReFS.dll
2017-07-12 16:43 - 2017-06-21 02:39 - 00134144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ErrorDetails.dll
2017-07-12 16:43 - 2017-06-21 02:38 - 03733504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll
2017-07-12 16:43 - 2017-06-21 02:38 - 01221120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Audio.dll
2017-07-12 16:43 - 2017-06-21 02:38 - 00886272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aadtb.dll
2017-07-12 16:43 - 2017-06-21 02:38 - 00877056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autoconv.exe
2017-07-12 16:43 - 2017-06-21 02:38 - 00753152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imapi2fs.dll
2017-07-12 16:43 - 2017-06-21 02:38 - 00709120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2017-07-12 16:43 - 2017-06-21 02:37 - 07468544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2017-07-12 16:43 - 2017-06-21 02:37 - 06109696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mos.dll
2017-07-12 16:43 - 2017-06-21 02:37 - 00400384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToManager.dll
2017-07-12 16:43 - 2017-06-21 02:37 - 00357376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Geolocation.dll
2017-07-12 16:43 - 2017-06-21 02:37 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Devices.dll
2017-07-12 16:43 - 2017-06-21 02:36 - 02648576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertEnroll.dll
2017-07-12 16:43 - 2017-06-21 02:36 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2017-07-12 16:43 - 2017-06-21 02:36 - 01247232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Globalization.dll
2017-07-12 16:43 - 2017-06-21 02:35 - 02740224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2017-07-12 16:43 - 2017-06-21 02:35 - 02682880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netshell.dll
2017-07-12 16:43 - 2017-06-21 02:35 - 01656320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Perception.dll
2017-07-12 16:43 - 2017-06-21 02:35 - 01232384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Maps.dll
2017-07-12 16:43 - 2017-06-21 02:35 - 01170944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Speech.dll
2017-07-12 16:43 - 2017-06-21 02:35 - 00827904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.appcore.dll
2017-07-12 16:43 - 2017-06-21 02:35 - 00732160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsSpellCheckingFacility.dll
2017-07-12 16:43 - 2017-06-21 02:35 - 00598528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Web.dll
2017-07-12 16:43 - 2017-06-21 02:35 - 00589312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Sensors.dll
2017-07-12 16:43 - 2017-06-21 02:35 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Midi.dll
2017-07-12 16:43 - 2017-06-21 02:34 - 01886720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Logon.dll
2017-07-12 16:43 - 2017-06-21 02:34 - 00773120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2017-07-12 16:43 - 2017-06-21 02:34 - 00711168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll
2017-07-12 16:43 - 2017-06-21 02:34 - 00654336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApiPublic.dll
2017-07-12 16:43 - 2017-06-21 02:34 - 00621056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.dll
2017-07-12 16:43 - 2017-06-21 02:34 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ShareHost.dll
2017-07-12 16:43 - 2017-06-21 02:34 - 00542208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.Connectivity.dll
2017-07-12 16:43 - 2017-06-21 02:33 - 01170944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Phone.dll
2017-07-12 16:43 - 2017-06-21 02:33 - 01013248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Web.Http.dll
2017-07-12 16:43 - 2017-06-21 02:33 - 00751104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2017-07-12 16:43 - 2017-06-21 02:33 - 00691200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBroker.dll
2017-07-12 16:43 - 2017-06-21 02:32 - 01556992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll
2017-07-12 16:43 - 2017-06-21 02:32 - 00353280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TextInputFramework.dll
2017-07-12 16:43 - 2017-06-21 02:31 - 03106304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2017-07-12 16:43 - 2017-06-21 02:30 - 00038912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tlscsp.dll
2017-07-12 16:43 - 2017-06-21 02:10 - 00483840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreMessaging.dll
2017-07-12 16:43 - 2017-03-04 02:56 - 00263472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Storage.ApplicationData.dll
2017-07-12 16:43 - 2017-03-04 02:21 - 01243136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.FaceAnalysis.dll
2017-07-12 16:43 - 2017-03-04 02:21 - 00670208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.PointOfService.dll
2017-07-12 16:43 - 2017-03-04 02:20 - 00562176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.SmartCards.dll
2017-07-12 16:43 - 2017-03-04 02:20 - 00426496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Wallet.dll
2017-07-12 16:43 - 2017-03-04 02:20 - 00206336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vaultcli.dll
2017-07-12 16:43 - 2017-03-04 02:19 - 00498688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mbsmsapi.dll
2017-07-12 16:43 - 2017-03-04 02:18 - 00525824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintDialogs.dll
2017-07-12 16:43 - 2017-03-04 02:16 - 00584192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2017-07-12 16:43 - 2017-03-04 02:02 - 02138112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputService.dll
2017-07-12 16:43 - 2016-10-05 05:15 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dialclient.dll
2017-07-12 16:43 - 2016-09-15 12:58 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2017-07-12 16:43 - 2016-09-15 12:47 - 00134656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Energy.dll
2017-07-12 16:42 - 2017-07-07 03:44 - 00108896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pdc.sys
2017-07-12 16:42 - 2017-07-07 03:42 - 07781720 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-07-12 16:42 - 2017-07-07 03:40 - 00376672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\clfs.sys
2017-07-12 16:42 - 2017-07-07 03:37 - 00468320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2017-07-12 16:42 - 2017-07-07 03:37 - 00118112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2017-07-12 16:42 - 2017-07-07 03:32 - 00404824 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-07-12 16:42 - 2017-07-07 03:29 - 02759712 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-07-12 16:42 - 2017-07-07 03:29 - 00857440 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe
2017-07-12 16:42 - 2017-07-07 03:28 - 00223584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-07-12 16:42 - 2017-07-07 03:24 - 22220856 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2017-07-12 16:42 - 2017-07-07 03:23 - 01600624 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2017-07-12 16:42 - 2017-07-07 03:23 - 00241504 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHost.dll
2017-07-12 16:42 - 2017-07-07 03:20 - 00059904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\l2gpstore.dll
2017-07-12 16:42 - 2017-07-07 03:19 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-07-12 16:42 - 2017-07-07 03:19 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapprovp.dll
2017-07-12 16:42 - 2017-07-07 03:18 - 02532192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2017-07-12 16:42 - 2017-07-07 03:18 - 01100120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2017-07-12 16:42 - 2017-07-07 03:18 - 00450560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2017-07-12 16:42 - 2017-07-07 03:18 - 00210432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\onex.dll
2017-07-12 16:42 - 2017-07-07 03:18 - 00057400 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-07-12 16:42 - 2017-07-07 03:17 - 00118784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\raschap.dll
2017-07-12 16:42 - 2017-07-07 03:14 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-07-12 16:42 - 2017-07-07 03:14 - 00126464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2017-07-12 16:42 - 2017-07-07 03:11 - 00340480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-07-12 16:42 - 2017-07-07 03:06 - 18364928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2017-07-12 16:42 - 2017-07-07 03:05 - 19414528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-07-12 16:42 - 2017-07-07 03:00 - 12187136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-07-12 16:42 - 2017-07-07 03:00 - 00476160 _____ (Microsoft® Windows® Operating System) C:\Windows\SysWOW64\wvc.dll
2017-07-12 16:42 - 2017-07-07 02:58 - 07217152 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2017-07-12 16:42 - 2017-07-07 02:57 - 00691712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-07-12 16:42 - 2017-07-07 02:56 - 06035456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2017-07-12 16:42 - 2017-07-07 02:55 - 03664896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-07-12 16:42 - 2017-07-07 02:54 - 02027008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-07-12 16:42 - 2017-07-07 02:51 - 22569984 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2017-07-12 16:42 - 2017-07-07 02:49 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bridge.sys
2017-07-12 16:42 - 2017-07-07 02:48 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\l2gpstore.dll
2017-07-12 16:42 - 2017-07-07 02:48 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\eapprovp.dll
2017-07-12 16:42 - 2017-07-07 02:47 - 00201728 _____ (Microsoft Corporation) C:\Windows\system32\ScDeviceEnum.dll
2017-07-12 16:42 - 2017-07-07 02:46 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\shutdownux.dll
2017-07-12 16:42 - 2017-07-07 02:46 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2017-07-12 16:42 - 2017-07-07 02:45 - 00488960 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupShim.dll
2017-07-12 16:42 - 2017-07-07 02:45 - 00289792 _____ (Microsoft Corporation) C:\Windows\system32\DeveloperOptionsSettingsHandlers.dll
2017-07-12 16:42 - 2017-07-07 02:45 - 00276992 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-07-12 16:42 - 2017-07-07 02:45 - 00223744 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-07-12 16:42 - 2017-07-07 02:44 - 00502784 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2017-07-12 16:42 - 2017-07-07 02:44 - 00238592 _____ (Microsoft Corporation) C:\Windows\system32\onex.dll
2017-07-12 16:42 - 2017-07-07 02:44 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\certprop.dll
2017-07-12 16:42 - 2017-07-07 02:44 - 00147456 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-07-12 16:42 - 2017-07-07 02:44 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2017-07-12 16:42 - 2017-07-07 02:44 - 00137728 _____ (Microsoft Corporation) C:\Windows\system32\raschap.dll
2017-07-12 16:42 - 2017-07-07 02:43 - 01081856 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll
2017-07-12 16:42 - 2017-07-07 02:43 - 00431616 _____ (Microsoft Corporation) C:\Windows\system32\WpAXHolder.dll
2017-07-12 16:42 - 2017-07-07 02:43 - 00387584 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-07-12 16:42 - 2017-07-07 02:43 - 00088576 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-07-12 16:42 - 2017-07-07 02:42 - 00805888 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-07-12 16:42 - 2017-07-07 02:42 - 00352256 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2017-07-12 16:42 - 2017-07-07 02:39 - 00282624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-07-12 16:42 - 2017-07-07 02:36 - 00369664 _____ (Microsoft Corporation) C:\Windows\system32\msinfo32.exe
2017-07-12 16:42 - 2017-07-07 02:35 - 01397760 _____ (Microsoft Corporation) C:\Windows\system32\wdc.dll
2017-07-12 16:42 - 2017-07-07 02:34 - 09131008 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2017-07-12 16:42 - 2017-07-07 02:33 - 00576000 _____ (Microsoft® Windows® Operating System) C:\Windows\system32\wvc.dll
2017-07-12 16:42 - 2017-07-07 02:31 - 23676416 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-07-12 16:42 - 2017-07-07 02:30 - 13090816 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-07-12 16:42 - 2017-07-07 02:29 - 04749824 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
2017-07-12 16:42 - 2017-07-07 02:29 - 00932864 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-07-12 16:42 - 2017-07-07 02:28 - 02096640 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-07-12 16:42 - 2017-07-07 02:28 - 00927744 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2017-07-12 16:42 - 2017-07-07 02:28 - 00759296 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-07-12 16:42 - 2017-07-07 02:28 - 00589312 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-07-12 16:42 - 2017-07-07 02:27 - 08120832 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2017-07-12 16:42 - 2017-07-07 02:25 - 04708864 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2017-07-12 16:42 - 2017-07-07 02:24 - 05388800 _____ (Microsoft) C:\Windows\system32\dbgeng.dll
2017-07-12 16:42 - 2017-07-07 02:24 - 04744704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-07-12 16:42 - 2017-07-07 02:24 - 03615744 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2017-07-12 16:42 - 2017-07-07 02:24 - 02895872 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-07-12 16:42 - 2017-07-07 02:24 - 02217472 _____ (Microsoft Corporation) C:\Windows\system32\OpcServices.dll
2017-07-12 16:42 - 2017-07-07 02:24 - 01783296 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-07-12 16:42 - 2017-07-07 02:24 - 01513472 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2017-07-12 16:42 - 2017-07-07 02:22 - 01826816 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2017-07-12 16:42 - 2017-07-06 00:29 - 00690008 _____ (Microsoft Corporation) C:\Windows\system32\msvcp120_clr0400.dll
2017-07-12 16:42 - 2017-06-22 02:17 - 00987840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr120_clr0400.dll
2017-07-12 16:42 - 2017-06-22 02:17 - 00485576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp120_clr0400.dll
2017-07-12 16:42 - 2017-06-21 03:56 - 01405280 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntSubsystemController.dll
2017-07-12 16:42 - 2017-06-21 03:55 - 02170720 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntSubsystems64.dll
2017-07-12 16:42 - 2017-06-21 03:54 - 01669984 _____ (Microsoft Corporation) C:\Windows\system32\AppVIntegration.dll
2017-07-12 16:42 - 2017-06-21 03:54 - 00822624 _____ (Microsoft Corporation) C:\Windows\system32\AppVClient.exe
2017-07-12 16:42 - 2017-06-21 03:54 - 00813408 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntStreamingManager.dll
2017-07-12 16:42 - 2017-06-21 03:54 - 00758624 _____ (Microsoft Corporation) C:\Windows\system32\AppVOrchestration.dll
2017-07-12 16:42 - 2017-06-21 03:54 - 00704352 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntVirtualization.dll
2017-07-12 16:42 - 2017-06-21 03:54 - 00696160 _____ (Microsoft Corporation) C:\Windows\system32\AppVPublishing.dll
2017-07-12 16:42 - 2017-06-21 03:54 - 00603488 _____ (Microsoft Corporation) C:\Windows\system32\ContentDeliveryManager.Utilities.dll
2017-07-12 16:42 - 2017-06-21 03:54 - 00565088 _____ (Microsoft Corporation) C:\Windows\system32\AppVCatalog.dll
2017-07-12 16:42 - 2017-06-21 03:54 - 00406368 _____ (Microsoft Corporation) C:\Windows\system32\AppVScripting.dll
2017-07-12 16:42 - 2017-06-21 03:53 - 00794928 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Shell.Broker.dll
2017-07-12 16:42 - 2017-06-21 03:52 - 02213760 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-07-12 16:42 - 2017-06-21 03:52 - 01886344 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-07-12 16:42 - 2017-06-21 03:52 - 00774224 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2017-07-12 16:42 - 2017-06-21 03:51 - 02255712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2017-07-12 16:42 - 2017-06-21 03:51 - 00434528 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2017-07-12 16:42 - 2017-06-21 03:50 - 00126304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mup.sys
2017-07-12 16:42 - 2017-06-21 03:48 - 02681200 _____ C:\Windows\system32\CoreUIComponents.dll
2017-07-12 16:42 - 2017-06-21 03:47 - 00764392 _____ (Microsoft Corporation) C:\Windows\system32\CoreMessaging.dll
2017-07-12 16:42 - 2017-06-21 03:41 - 01706488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-07-12 16:42 - 2017-06-21 03:40 - 01069720 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
2017-07-12 16:42 - 2017-06-21 03:40 - 00328008 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Storage.ApplicationData.dll
2017-07-12 16:42 - 2017-06-21 03:40 - 00224096 _____ (Microsoft Corporation) C:\Windows\system32\ifsutil.dll
2017-07-12 16:42 - 2017-06-21 03:38 - 07220192 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
2017-07-12 16:42 - 2017-06-21 03:38 - 01860288 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2017-07-12 16:42 - 2017-06-21 03:38 - 01738560 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2017-07-12 16:42 - 2017-06-21 03:37 - 02446704 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2017-07-12 16:42 - 2017-06-21 03:37 - 01369240 _____ (Microsoft Corporation) C:\Windows\system32\dcomp.dll
2017-07-12 16:42 - 2017-06-21 03:37 - 01157008 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.appcore.dll
2017-07-12 16:42 - 2017-06-21 03:37 - 00146784 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHostCommon.dll
2017-07-12 16:42 - 2017-06-21 03:36 - 00624048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2017-07-12 16:42 - 2017-06-21 03:35 - 02915704 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll
2017-07-12 16:42 - 2017-06-21 03:35 - 01267512 _____ (Microsoft Corporation) C:\Windows\system32\WinTypes.dll
2017-07-12 16:42 - 2017-06-21 03:33 - 00408600 _____ (Microsoft Corporation) C:\Windows\system32\tsmf.dll
2017-07-12 16:42 - 2017-06-21 03:33 - 00092512 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2017-07-12 16:42 - 2017-06-21 03:32 - 08169024 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2017-07-12 16:42 - 2017-06-21 03:32 - 04260576 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2017-07-12 16:42 - 2017-06-21 03:32 - 01983408 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
2017-07-12 16:42 - 2017-06-21 03:32 - 01702392 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll
2017-07-12 16:42 - 2017-06-21 03:32 - 01072248 _____ (Microsoft Corporation) C:\Windows\system32\mfnetcore.dll
2017-07-12 16:42 - 2017-06-21 03:31 - 04674360 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2017-07-12 16:42 - 2017-06-21 03:31 - 01277824 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2017-07-12 16:42 - 2017-06-21 03:31 - 00160096 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHostBroker.dll
2017-07-12 16:42 - 2017-06-21 03:26 - 00387864 _____ (Microsoft Corporation) C:\Windows\system32\wmpps.dll
2017-07-12 16:42 - 2017-06-21 03:06 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\RDXTaskFactory.dll
2017-07-12 16:42 - 2017-06-21 03:04 - 01631232 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.dll
2017-07-12 16:42 - 2017-06-21 03:03 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\uudf.dll
2017-07-12 16:42 - 2017-06-21 03:03 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rootmdm.sys
2017-07-12 16:42 - 2017-06-21 03:02 - 00237568 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Web.Diagnostics.dll
2017-07-12 16:42 - 2017-06-21 03:02 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Windows.System.SystemManagement.dll
2017-07-12 16:42 - 2017-06-21 03:02 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2017-07-12 16:42 - 2017-06-21 03:02 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\odbcconf.dll
2017-07-12 16:42 - 2017-06-21 03:01 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\DisplayManager.dll
2017-07-12 16:42 - 2017-06-21 03:01 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\Family.Client.dll
2017-07-12 16:42 - 2017-06-21 03:01 - 00138752 _____ (Microsoft Corporation) C:\Windows\system32\VEDataLayerHelpers.dll
2017-07-12 16:42 - 2017-06-21 03:01 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\Family.Authentication.dll
2017-07-12 16:42 - 2017-06-21 03:01 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\snmptrap.exe
2017-07-12 16:42 - 2017-06-21 03:00 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\unimdm.tsp
2017-07-12 16:42 - 2017-06-21 03:00 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\Family.SyncEngine.dll
2017-07-12 16:42 - 2017-06-21 03:00 - 00233984 _____ (Microsoft Corporation) C:\Windows\system32\ProvisioningHandlers.dll
2017-07-12 16:42 - 2017-06-21 03:00 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_SignInOptions.dll
2017-07-12 16:42 - 2017-06-21 03:00 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\WinRtTracing.dll
2017-07-12 16:42 - 2017-06-21 03:00 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.WiFi.dll
2017-07-12 16:42 - 2017-06-21 03:00 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\Windows.System.Profile.RetailInfo.dll
2017-07-12 16:42 - 2017-06-21 03:00 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2017-07-12 16:42 - 2017-06-21 03:00 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-07-12 16:42 - 2017-06-21 03:00 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\Windows.System.UserDeviceAssociation.dll
2017-07-12 16:42 - 2017-06-21 03:00 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryBroker.dll
2017-07-12 16:42 - 2017-06-21 02:59 - 00467968 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Gaming.XboxLive.Storage.dll
2017-07-12 16:42 - 2017-06-21 02:59 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\UserDeviceRegistration.dll
2017-07-12 16:42 - 2017-06-21 02:59 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\DeviceDirectoryClient.dll
2017-07-12 16:42 - 2017-06-21 02:59 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Core.dll
2017-07-12 16:42 - 2017-06-21 02:59 - 00137216 _____ (Microsoft Corporation) C:\Windows\system32\tdlrecover.exe
2017-07-12 16:42 - 2017-06-21 02:59 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sendmail.dll
2017-07-12 16:42 - 2017-06-21 02:59 - 00122880 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryClient.dll
2017-07-12 16:42 - 2017-06-21 02:59 - 00101888 _____ (Microsoft Corporation) C:\Windows\system32\UserDeviceRegistration.Ngc.dll
2017-07-12 16:42 - 2017-06-21 02:59 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\KdsCli.dll
2017-07-12 16:42 - 2017-06-21 02:58 - 00547840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Gaming.Input.dll
2017-07-12 16:42 - 2017-06-21 02:58 - 00418304 _____ C:\Windows\system32\Windows.Perception.Stub.dll
2017-07-12 16:42 - 2017-06-21 02:58 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\CloudDomainJoinDataModelServer.dll
2017-07-12 16:42 - 2017-06-21 02:58 - 00224768 _____ (Microsoft Corporation) C:\Windows\system32\wpd_ci.dll
2017-07-12 16:42 - 2017-06-21 02:58 - 00211968 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgent.exe
2017-07-12 16:42 - 2017-06-21 02:58 - 00186368 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Radios.dll
2017-07-12 16:42 - 2017-06-21 02:58 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2017-07-12 16:42 - 2017-06-21 02:57 - 00651264 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.AllJoyn.dll
2017-07-12 16:42 - 2017-06-21 02:57 - 00505856 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.WiFiDirect.dll
2017-07-12 16:42 - 2017-06-21 02:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.BlockedShutdown.dll
2017-07-12 16:42 - 2017-06-21 02:57 - 00360448 _____ (Microsoft Corporation) C:\Windows\system32\rdpencom.dll
2017-07-12 16:42 - 2017-06-21 02:57 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\credprovhost.dll
2017-07-12 16:42 - 2017-06-21 02:57 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.SerialCommunication.dll
2017-07-12 16:42 - 2017-06-21 02:57 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\XamlTileRender.dll
2017-07-12 16:42 - 2017-06-21 02:57 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Lights.dll
2017-07-12 16:42 - 2017-06-21 02:57 - 00088576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDeviceRegistration.Ngc.dll
2017-07-12 16:42 - 2017-06-21 02:57 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\wpdbusenum.dll
2017-07-12 16:42 - 2017-06-21 02:56 - 01507840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.FaceAnalysis.dll
2017-07-12 16:42 - 2017-06-21 02:56 - 00912384 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.SmartCards.dll
2017-07-12 16:42 - 2017-06-21 02:56 - 00852480 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Import.dll
2017-07-12 16:42 - 2017-06-21 02:56 - 00748544 _____ (Microsoft Corporation) C:\Windows\system32\StoreAgent.dll
2017-07-12 16:42 - 2017-06-21 02:56 - 00719872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdiWiFi.sys
2017-07-12 16:42 - 2017-06-21 02:56 - 00590336 _____ (Microsoft Corporation) C:\Windows\system32\efswrt.dll
2017-07-12 16:42 - 2017-06-21 02:56 - 00568320 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.LowLevel.dll
2017-07-12 16:42 - 2017-06-21 02:56 - 00379904 _____ (Microsoft Corporation) C:\Windows\system32\apprepsync.dll
2017-07-12 16:42 - 2017-06-21 02:56 - 00324608 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.LockScreen.dll
2017-07-12 16:42 - 2017-06-21 02:56 - 00268800 _____ (Microsoft Corporation) C:\Windows\system32\UserMgrProxy.dll
2017-07-12 16:42 - 2017-06-21 02:56 - 00267264 _____ (Microsoft Corporation) C:\Windows\system32\vaultcli.dll
2017-07-12 16:42 - 2017-06-21 02:56 - 00260608 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgentUserBroker.exe
2017-07-12 16:42 - 2017-06-21 02:56 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Scanners.dll
2017-07-12 16:42 - 2017-06-21 02:55 - 00561664 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Wallet.dll
2017-07-12 16:42 - 2017-06-21 02:55 - 00533504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FXSCOMEX.dll
2017-07-12 16:42 - 2017-06-21 02:55 - 00456192 _____ (Microsoft Corporation) C:\Windows\system32\puiobj.dll
2017-07-12 16:42 - 2017-06-21 02:55 - 00407552 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Management.dll
2017-07-12 16:42 - 2017-06-21 02:55 - 00358912 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.dll
2017-07-12 16:42 - 2017-06-21 02:55 - 00349184 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2017-07-12 16:42 - 2017-06-21 02:55 - 00310784 _____ (Microsoft Corporation) C:\Windows\system32\SyncSettings.dll
2017-07-12 16:42 - 2017-06-21 02:55 - 00252416 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.Identity.Provider.dll
2017-07-12 16:42 - 2017-06-21 02:55 - 00176128 _____ (Microsoft Corporation) C:\Windows\system32\apprepapi.dll
2017-07-12 16:42 - 2017-06-21 02:55 - 00020480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\regsvr32.exe
2017-07-12 16:42 - 2017-06-21 02:54 - 01159680 _____ (Microsoft Corporation) C:\Windows\system32\XblGameSave.dll
2017-07-12 16:42 - 2017-06-21 02:54 - 00949248 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.PointOfService.dll
2017-07-12 16:42 - 2017-06-21 02:54 - 00671744 _____ (Microsoft Corporation) C:\Windows\system32\mbsmsapi.dll
2017-07-12 16:42 - 2017-06-21 02:54 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\tileobjserver.dll
2017-07-12 16:42 - 2017-06-21 02:54 - 00472064 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Bluetooth.dll
2017-07-12 16:42 - 2017-06-21 02:54 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Picker.dll
2017-07-12 16:42 - 2017-06-21 02:54 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\ExecModelClient.dll
2017-07-12 16:42 - 2017-06-21 02:54 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\WwaApi.dll
2017-07-12 16:42 - 2017-06-21 02:54 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\easwrt.dll
2017-07-12 16:42 - 2017-06-21 02:54 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\easwrt.dll
2017-07-12 16:42 - 2017-06-21 02:53 - 01010176 _____ (Microsoft Corporation) C:\Windows\system32\enterprisecsps.dll
2017-07-12 16:42 - 2017-06-21 02:53 - 00642048 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.InkControls.dll
2017-07-12 16:42 - 2017-06-21 02:53 - 00437248 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Usb.dll
2017-07-12 16:42 - 2017-06-21 02:53 - 00425984 _____ (Microsoft Corporation) C:\Windows\system32\aadcloudap.dll
2017-07-12 16:42 - 2017-06-21 02:53 - 00339968 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.dll
2017-07-12 16:42 - 2017-06-21 02:53 - 00329728 _____ (Microsoft Corporation) C:\Windows\system32\deviceaccess.dll
2017-07-12 16:42 - 2017-06-21 02:53 - 00284160 _____ (Microsoft Corporation) C:\Windows\system32\AboveLockAppHost.dll
2017-07-12 16:42 - 2017-06-21 02:52 - 17198592 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2017-07-12 16:42 - 2017-06-21 02:52 - 06288384 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2017-07-12 16:42 - 2017-06-21 02:52 - 00963584 _____ (Microsoft Corporation) C:\Windows\system32\WebcamUi.dll
2017-07-12 16:42 - 2017-06-21 02:52 - 00956416 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.desktop.dll
2017-07-12 16:42 - 2017-06-21 02:52 - 00896512 _____ (Microsoft Corporation) C:\Windows\system32\Windows.AccountsControl.dll
2017-07-12 16:42 - 2017-06-21 02:52 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\GamePanel.exe
2017-07-12 16:42 - 2017-06-21 02:52 - 00560128 _____ (Microsoft Corporation) C:\Windows\system32\AppReadiness.dll
2017-07-12 16:42 - 2017-06-21 02:52 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\DevicesFlowBroker.dll
2017-07-12 16:42 - 2017-06-21 02:52 - 00352256 _____ (Microsoft Corporation) C:\Windows\system32\XpsDocumentTargetPrint.dll
2017-07-12 16:42 - 2017-06-21 02:52 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\NgcCtnrSvc.dll
2017-07-12 16:42 - 2017-06-21 02:51 - 00846336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebcamUi.dll
2017-07-12 16:42 - 2017-06-21 02:51 - 00634368 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2017-07-12 16:42 - 2017-06-21 02:51 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
2017-07-12 16:42 - 2017-06-21 02:50 - 01054208 _____ (Microsoft Corporation) C:\Windows\system32\qmgr.dll
2017-07-12 16:42 - 2017-06-21 02:50 - 00661504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WpcWebFilter.dll
2017-07-12 16:42 - 2017-06-21 02:49 - 03778048 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2017-07-12 16:42 - 2017-06-21 02:49 - 02104320 _____ (Microsoft Corporation) C:\Windows\system32\wlidsvc.dll
2017-07-12 16:42 - 2017-06-21 02:49 - 01913856 _____ (Microsoft Corporation) C:\Windows\system32\wsp_fs.dll
2017-07-12 16:42 - 2017-06-21 02:49 - 01584128 _____ (Microsoft Corporation) C:\Windows\system32\wsp_health.dll
2017-07-12 16:42 - 2017-06-21 02:49 - 01403392 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Editing.dll
2017-07-12 16:42 - 2017-06-21 02:49 - 00458752 _____ (Microsoft Corporation) C:\Windows\system32\RTMediaFrame.dll
2017-07-12 16:42 - 2017-06-21 02:49 - 00175616 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettings.DeviceEncryptionHandlers.dll
2017-07-12 16:42 - 2017-06-21 02:49 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Energy.dll
2017-07-12 16:42 - 2017-06-21 02:48 - 00968192 _____ (Microsoft Corporation) C:\Windows\system32\autochk.exe
2017-07-12 16:42 - 2017-06-21 02:48 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\uexfat.dll
2017-07-12 16:42 - 2017-06-21 02:47 - 07655424 _____ (Microsoft Corporation) C:\Windows\system32\mos.dll
2017-07-12 16:42 - 2017-06-21 02:47 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\MiracastReceiver.dll
2017-07-12 16:42 - 2017-06-21 02:47 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\untfs.dll
2017-07-12 16:42 - 2017-06-21 02:47 - 00442368 _____ (Microsoft Corporation) C:\Windows\system32\PlayToDevice.dll
2017-07-12 16:42 - 2017-06-21 02:47 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\ufat.dll
2017-07-12 16:42 - 2017-06-21 02:47 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\fdProxy.dll
2017-07-12 16:42 - 2017-06-21 02:46 - 03290112 _____ (Microsoft Corporation) C:\Windows\system32\mispace.dll
2017-07-12 16:42 - 2017-06-21 02:46 - 01908224 _____ (Microsoft Corporation) C:\Windows\system32\AzureSettingSyncProvider.dll
2017-07-12 16:42 - 2017-06-21 02:46 - 00925184 _____ (Microsoft Corporation) C:\Windows\system32\autofmt.exe
2017-07-12 16:42 - 2017-06-21 02:46 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\SpaceControl.dll
2017-07-12 16:42 - 2017-06-21 02:46 - 00516608 _____ (Microsoft Corporation) C:\Windows\system32\uReFSv1.dll
2017-07-12 16:42 - 2017-06-21 02:46 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\dialclient.dll
2017-07-12 16:42 - 2017-06-21 02:46 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\cnvfat.dll
2017-07-12 16:42 - 2017-06-21 02:45 - 02861056 _____ (Microsoft Corporation) C:\Windows\system32\storagewmi.dll
2017-07-12 16:42 - 2017-06-21 02:44 - 00588288 _____ (Microsoft Corporation) C:\Windows\system32\wlidprov.dll
2017-07-12 16:42 - 2017-06-21 02:44 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\ErrorDetails.dll
2017-07-12 16:42 - 2017-06-21 02:44 - 00027136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fdProxy.dll
2017-07-12 16:42 - 2017-06-21 02:43 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Audio.dll
2017-07-12 16:42 - 2017-06-21 02:43 - 00961536 _____ (Microsoft Corporation) C:\Windows\system32\imapi2fs.dll
2017-07-12 16:42 - 2017-06-21 02:43 - 00953344 _____ (Microsoft Corporation) C:\Windows\system32\autoconv.exe
2017-07-12 16:42 - 2017-06-21 02:43 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\uReFS.dll
2017-07-12 16:42 - 2017-06-21 02:43 - 00130560 _____ (Microsoft Corporation) C:\Windows\system32\SpaceAgent.exe
2017-07-12 16:42 - 2017-06-21 02:42 - 00981504 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.OnlineId.dll
2017-07-12 16:42 - 2017-06-21 02:42 - 00779776 _____ (Microsoft Corporation) C:\Windows\system32\cscui.dll
2017-07-12 16:42 - 2017-06-21 02:42 - 00539136 _____ (Microsoft Corporation) C:\Windows\system32\PlayToManager.dll
2017-07-12 16:42 - 2017-06-21 02:42 - 00467968 _____ (Microsoft Corporation) C:\Windows\system32\Geolocation.dll
2017-07-12 16:42 - 2017-06-21 02:42 - 00380416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uReFSv1.dll
2017-07-12 16:42 - 2017-06-21 02:42 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Devices.dll
2017-07-12 16:42 - 2017-06-21 02:42 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\LocationFrameworkInternalPS.dll
2017-07-12 16:42 - 2017-06-21 02:41 - 03400704 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2017-07-12 16:42 - 2017-06-21 02:41 - 02279424 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2017-07-12 16:42 - 2017-06-21 02:41 - 01692160 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.onecore.dll
2017-07-12 16:42 - 2017-06-21 02:41 - 01359872 _____ (Microsoft Corporation) C:\Windows\system32\SharedStartModel.dll
2017-07-12 16:42 - 2017-06-21 02:41 - 01080320 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Ocr.dll
2017-07-12 16:42 - 2017-06-21 02:41 - 01021440 _____ (Microsoft Corporation) C:\Windows\system32\usermgr.dll
2017-07-12 16:42 - 2017-06-21 02:41 - 00983040 _____ (Microsoft Corporation) C:\Windows\system32\ngcsvc.dll
2017-07-12 16:42 - 2017-06-21 02:41 - 00945664 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebFilter.dll
2017-07-12 16:42 - 2017-06-21 02:41 - 00913920 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.dll
2017-07-12 16:42 - 2017-06-21 02:41 - 00460800 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Midi.dll
2017-07-12 16:42 - 2017-06-21 02:40 - 04474368 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll
2017-07-12 16:42 - 2017-06-21 02:40 - 01891328 _____ (Microsoft Corporation) C:\Windows\system32\pnidui.dll
2017-07-12 16:42 - 2017-06-21 02:40 - 01586176 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Globalization.dll
2017-07-12 16:42 - 2017-06-21 02:40 - 01421824 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2017-07-12 16:42 - 2017-06-21 02:40 - 00886784 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2017-07-12 16:42 - 2017-06-21 02:40 - 00611328 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.Printing.dll
2017-07-12 16:42 - 2017-06-21 02:40 - 00376832 _____ (Microsoft Corporation) C:\Windows\system32\CryptoWinRT.dll
2017-07-12 16:42 - 2017-06-21 02:39 - 08076288 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2017-07-12 16:42 - 2017-06-21 02:39 - 02916864 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll
2017-07-12 16:42 - 2017-06-21 02:39 - 02538496 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2017-07-12 16:42 - 2017-06-21 02:39 - 02208768 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.Printing.3D.dll
2017-07-12 16:42 - 2017-06-21 02:39 - 01643008 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Speech.dll
2017-07-12 16:42 - 2017-06-21 02:39 - 01490432 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-07-12 16:42 - 2017-06-21 02:39 - 00971264 _____ (Microsoft Corporation) C:\Windows\system32\twinui.appcore.dll
2017-07-12 16:42 - 2017-06-21 02:39 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.dll
2017-07-12 16:42 - 2017-06-21 02:39 - 00673792 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2017-07-12 16:42 - 2017-06-21 02:38 - 05611008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2017-07-12 16:42 - 2017-06-21 02:38 - 03520512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xpsrchvw.exe
2017-07-12 16:42 - 2017-06-21 02:38 - 02695680 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Logon.dll
2017-07-12 16:42 - 2017-06-21 02:38 - 02424320 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Perception.dll
2017-07-12 16:42 - 2017-06-21 02:38 - 01984000 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2017-07-12 16:42 - 2017-06-21 02:38 - 01275392 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Bluetooth.dll
2017-07-12 16:42 - 2017-06-21 02:38 - 00908800 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll
2017-07-12 16:42 - 2017-06-21 02:38 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApiPublic.dll
2017-07-12 16:42 - 2017-06-21 02:38 - 00765440 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Sensors.dll
2017-07-12 16:42 - 2017-06-21 02:37 - 00875520 _____ (Microsoft Corporation) C:\Windows\system32\TokenBroker.dll
2017-07-12 16:42 - 2017-06-21 02:37 - 00774656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Web.dll
2017-07-12 16:42 - 2017-06-21 02:37 - 00735744 _____ (Microsoft Corporation) C:\Windows\system32\LogonController.dll
2017-07-12 16:42 - 2017-06-21 02:37 - 00716800 _____ (Microsoft Corporation) C:\Windows\system32\ShareHost.dll
2017-07-12 16:42 - 2017-06-21 02:36 - 02318848 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-07-12 16:42 - 2017-06-21 02:36 - 01424896 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Maps.dll
2017-07-12 16:42 - 2017-06-21 02:36 - 00903680 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2017-07-12 16:42 - 2017-06-21 02:36 - 00881152 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.dll
2017-07-12 16:42 - 2017-06-21 02:36 - 00701952 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.Connectivity.dll
2017-07-12 16:42 - 2017-06-21 02:36 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\enrollmentapi.dll
2017-07-12 16:42 - 2017-06-21 02:35 - 04149248 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2017-07-12 16:42 - 2017-06-21 02:35 - 01726976 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll
2017-07-12 16:42 - 2017-06-21 02:35 - 01369088 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Phone.dll
2017-07-12 16:42 - 2017-06-21 02:35 - 01328640 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Web.Http.dll
2017-07-12 16:42 - 2017-06-21 02:35 - 00924672 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll
2017-07-12 16:42 - 2017-06-21 02:34 - 03299840 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2017-07-12 16:42 - 2017-06-21 02:34 - 01121280 _____ (Microsoft Corporation) C:\Windows\system32\aadtb.dll
2017-07-12 16:42 - 2017-06-21 02:34 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\tssrvlic.dll
2017-07-12 16:42 - 2017-06-21 02:34 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\spaceman.exe
2017-07-12 16:42 - 2017-06-21 02:33 - 00439296 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2017-07-12 16:42 - 2017-06-21 02:33 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\tlscsp.dll
2017-07-12 16:42 - 2017-06-19 22:42 - 00993632 _____ (Microsoft Corporation) C:\Windows\system32\msvcr120_clr0400.dll
2017-07-12 16:42 - 2017-05-23 00:58 - 00448576 _____ C:\Windows\system32\ApnDatabase.xml
2017-07-12 16:42 - 2017-03-04 03:10 - 00360040 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsAdminFlows.exe
2017-07-12 16:42 - 2017-03-04 02:28 - 00279552 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.HumanInterfaceDevice.dll
2017-07-12 16:42 - 2017-03-04 02:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2017-07-12 16:42 - 2017-03-04 02:26 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\PrintDialogs3D.dll
2017-07-12 16:42 - 2017-03-04 02:23 - 01145856 _____ (Microsoft Corporation) C:\Windows\system32\EmailApis.dll
2017-07-12 16:42 - 2017-03-04 02:23 - 00583680 _____ (Microsoft Corporation) C:\Windows\system32\PrintDialogs.dll
2017-07-12 16:42 - 2017-03-04 02:20 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.Web.Core.dll
2017-07-12 16:42 - 2017-03-04 02:19 - 01589760 _____ (Microsoft Corporation) C:\Windows\system32\msdtctm.dll
2017-07-12 16:42 - 2017-03-04 02:17 - 00864256 _____ (Microsoft Corporation) C:\Windows\system32\wpnapps.dll
2017-07-12 16:42 - 2017-03-04 02:15 - 01078784 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Streaming.dll
2017-07-12 16:42 - 2017-03-04 02:14 - 00279552 _____ (Microsoft Corporation) C:\Windows\system32\PlayToReceiver.dll
2017-07-12 16:42 - 2017-03-04 02:12 - 04596224 _____ (Microsoft Corporation) C:\Windows\system32\xpsrchvw.exe
2017-07-12 16:42 - 2016-10-14 23:45 - 01790464 _____ (Microsoft Corporation) C:\Windows\system32\LocationFramework.dll
2017-07-12 16:42 - 2016-10-05 05:32 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\AuthBroker.dll
2017-07-12 16:42 - 2016-08-27 01:12 - 00244816 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2017-07-12 15:58 - 2017-07-12 15:58 - 00049992 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
2017-07-12 15:58 - 2017-07-12 15:58 - 00045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys
2017-07-12 15:58 - 2017-07-12 15:58 - 00045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys
2017-07-12 15:58 - 2017-07-12 15:58 - 00045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-07-26 15:56 - 2016-07-16 07:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-07-26 15:56 - 2016-07-16 07:47 - 00000000 ____D C:\Windows\AppReadiness
2017-07-26 15:54 - 2017-05-30 06:49 - 00000000 ____D C:\Windows\system32\SleepStudy
2017-07-26 15:50 - 2017-05-30 21:33 - 00000000 ____D C:\Users\Diane\AppData\LocalLow\Mozilla
2017-07-26 15:49 - 2017-06-01 15:06 - 00093600 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2017-07-26 08:27 - 2017-05-30 06:55 - 01783250 _____ C:\Windows\system32\PerfStringBackup.INI
2017-07-26 08:21 - 2017-06-01 15:06 - 00253856 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-07-26 08:21 - 2017-06-01 15:06 - 00101784 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2017-07-26 08:21 - 2017-06-01 15:06 - 00045472 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-07-26 08:21 - 2017-05-30 23:18 - 00000082 _____ C:\Windows\SysWOW64\winsevr.dat
2017-07-26 08:21 - 2017-05-30 23:18 - 00000000 ____D C:\Program Files (x86)\AOMEI Backupper
2017-07-26 08:21 - 2017-05-30 07:08 - 00000000 ____D C:\ProgramData\NVIDIA
2017-07-26 08:21 - 2017-05-30 06:49 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-07-26 08:21 - 2016-07-16 02:04 - 00524288 _____ C:\Windows\system32\config\BBI
2017-07-26 07:57 - 2017-05-30 08:11 - 00000000 ____D C:\Users\Diane\AppData\Local\CrashDumps
2017-07-26 07:17 - 2017-05-30 06:53 - 00002363 _____ C:\Users\Diane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-07-26 07:17 - 2017-05-30 06:53 - 00000000 ___RD C:\Users\Diane\OneDrive
2017-07-26 07:04 - 2017-05-31 07:48 - 00000000 ____D C:\Users\Diane\Documents\amazon
2017-07-26 05:34 - 2017-05-31 07:49 - 00000000 ____D C:\Users\Diane\Documents\surveys
2017-07-25 20:41 - 2017-05-31 07:51 - 00000000 ____D C:\Users\Diane\Documents\studyhint
2017-07-25 13:49 - 2017-06-06 14:58 - 00061304 _____ () C:\Windows\system32\Drivers\lpsport.sys
2017-07-25 13:49 - 2017-06-04 07:37 - 00004022 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1496576224
2017-07-25 13:49 - 2017-06-04 07:37 - 00001088 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2017-07-25 13:49 - 2017-06-04 07:35 - 00343288 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys
2017-07-25 13:49 - 2017-06-04 07:35 - 00320008 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys
2017-07-25 13:49 - 2017-06-04 07:35 - 00198976 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys
2017-07-25 13:49 - 2017-06-04 07:35 - 00146696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys
2017-07-25 13:49 - 2017-06-04 07:35 - 00146664 _____ (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys.150100498965603
2017-07-25 13:49 - 2017-06-04 07:35 - 00057728 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys
2017-07-25 13:49 - 2017-06-04 07:35 - 00003994 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2017-07-25 13:48 - 2017-05-31 18:04 - 00000000 ____D C:\Users\Diane\AppData\Roaming\UK's Kalender
2017-07-25 06:28 - 2017-06-06 11:04 - 00000000 ____D C:\Users\Diane\Documents\community
2017-07-23 07:08 - 2016-07-16 07:47 - 00000000 ____D C:\Windows\system32\FxsTmp
2017-07-22 13:28 - 2017-05-31 07:49 - 00000000 ____D C:\Users\Diane\Documents\Quicken
2017-07-21 06:13 - 2016-07-16 07:45 - 00000000 ____D C:\Windows\INF
2017-07-18 12:50 - 2017-05-31 07:49 - 00000000 ____D C:\Users\Diane\Documents\recipe
2017-07-17 19:09 - 2017-06-01 15:07 - 00188352 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
2017-07-17 19:09 - 2017-06-01 15:06 - 00077376 _____ C:\Windows\system32\Drivers\mbae64.sys
2017-07-14 08:19 - 2016-07-16 07:47 - 00000000 ____D C:\Windows\rescache
2017-07-13 13:28 - 2017-06-04 09:42 - 00000000 ____D C:\Program Files (x86)\Dropbox
2017-07-13 12:24 - 2017-06-12 08:34 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-07-12 18:36 - 2017-05-30 23:21 - 00001024 ____H C:\SYSTAG.BIN
2017-07-12 17:13 - 2017-05-30 06:51 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-07-12 17:12 - 2017-05-30 06:49 - 00372584 _____ C:\Windows\system32\FNTCACHE.DAT
2017-07-12 17:11 - 2016-07-16 07:47 - 00000000 ___RD C:\Windows\ImmersiveControlPanel
2017-07-12 17:11 - 2016-07-16 07:47 - 00000000 ____D C:\Windows\system32\oobe
2017-07-12 17:11 - 2016-07-16 07:47 - 00000000 ____D C:\Windows\system32\appraiser
2017-07-12 17:11 - 2016-07-16 07:47 - 00000000 ____D C:\Windows\ShellExperiences
2017-07-12 17:11 - 2016-07-16 07:47 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2017-07-12 17:11 - 2016-07-16 07:47 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-07-12 16:48 - 2016-07-16 07:36 - 00000000 ____D C:\Windows\CbsTemp
2017-07-12 16:45 - 2017-05-30 10:56 - 00000000 ____D C:\Windows\system32\MRT
2017-07-12 16:44 - 2017-05-30 10:56 - 135225752 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-07-12 16:23 - 2016-07-16 07:43 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\enrollmentapi.dll
2017-07-12 05:54 - 2017-06-18 19:34 - 00004422 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-07-12 05:54 - 2016-07-16 07:47 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-07-12 05:54 - 2016-07-16 07:47 - 00000000 ____D C:\Windows\system32\Macromed
2017-07-07 09:02 - 2017-06-04 07:36 - 00041800 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2017-07-07 09:02 - 2017-06-04 07:35 - 01015848 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2017-07-07 09:02 - 2017-06-04 07:35 - 00585608 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-07-07 09:02 - 2017-06-04 07:35 - 00361336 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2017-07-07 09:02 - 2017-06-04 07:35 - 00360792 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys.149943254035906
2017-07-07 09:02 - 2017-06-04 07:35 - 00198768 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2017-07-07 09:02 - 2017-06-04 07:35 - 00110352 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-07-07 09:02 - 2017-06-04 07:35 - 00084392 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-07-07 09:02 - 2017-06-04 07:35 - 00046984 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-07-07 09:02 - 2017-06-04 07:33 - 00000000 ____D C:\ProgramData\AVAST Software
2017-07-05 06:12 - 2017-05-30 23:18 - 00000000 ____D C:\ProgramData\AomeiBR
2017-06-30 21:18 - 2016-07-16 07:47 - 00000000 ____D C:\Windows\system32\NDF
2017-06-30 18:53 - 2017-05-30 21:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-06-30 18:53 - 2017-05-30 21:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-06-30 10:46 - 2016-07-16 07:49 - 00835576 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-06-30 10:46 - 2016-07-16 07:49 - 00177656 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-06-29 18:49 - 2017-06-16 12:31 - 00000000 ____D C:\Users\Diane\Desktop\brandon
2017-06-28 05:08 - 2017-05-30 07:00 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk

==================== Files in the root of some directories =======

2017-06-09 07:12 - 2017-06-09 07:12 - 0000017 _____ () C:\Users\Diane\AppData\Local\resmon.resmoncfg
2017-05-30 06:58 - 2017-05-30 06:58 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-07-26 07:12

==================== End of FRST.txt ============================

 

ADDITION.txt

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-07-2017
Ran by Diane (26-07-2017 16:02:22)
Running from C:\Users\Diane\Desktop\farbar
Windows 10 Pro Version 1607 (X64) (2017-05-30 10:51:24)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3119151931-944679501-478495044-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3119151931-944679501-478495044-503 - Limited - Disabled)
defaultuser0 (S-1-5-21-3119151931-944679501-478495044-1000 - Limited - Disabled) => C:\Users\defaultuser0
Diane (S-1-5-21-3119151931-944679501-478495044-1001 - Administrator - Enabled) => C:\Users\Diane
Guest (S-1-5-21-3119151931-944679501-478495044-501 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.009.20058 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.1.0.5790 - Adobe Systems Inc.)
Adobe Flash Player 26 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 26.0.0.137 - Adobe Systems Incorporated)
Adobe Photoshop Elements 7.0 (HKLM-x32\...\Adobe Photoshop Elements 7) (Version: 7.0 - Adobe Systems Incorporated)
Adobe Photoshop.com Inspiration Browser (HKLM-x32\...\PhotoshopdotcomInspirationBrowser.4C35C4D325D350FE0114230CBADCA2DDD0AC8D25.1) (Version: 2.61 - Adobe Systems Incorporated)
Adobe Premiere Elements 7.0 (HKLM-x32\...\PremElem70) (Version: 7.0 - Adobe Systems Incorporated)
Adobe Premiere Elements 7.0 Templates (HKLM-x32\...\PremElem70Templates) (Version: 7.0.0 - Adobe Systems Incorporated)
Ansel (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel) (Version: 375.63 - NVIDIA Corporation) Hidden
AOMEI Backupper Standard (HKLM-x32\...\{A83692F5-3E9B-4E95-9E7E-B5DF5536CE9D}_is1) (Version:  - AOMEI Technology Co., Ltd.)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 17.5.2303 - AVAST Software)
Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: 4.7.0 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version:  - Canon Inc.)
Canon MX520 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX520_series) (Version: 1.01 - Canon Inc.)
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.3.0 - Canon Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.30 - Piriform)
Cobian Backup 11 Gravity (HKLM-x32\...\CobBackup11) (Version:  - )
Dropbox (HKLM-x32\...\Dropbox) (Version: 30.4.22 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.65.1 - Dropbox, Inc.) Hidden
Genie Timeline (HKLM-x32\...\Genie Timeline) (Version: 5.0 - Genie9)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 59.0.3071.115 - Google Inc.)
Google Drive (HKLM-x32\...\{A1238426-ECDF-4639-BE2F-8D12A97AE23C}) (Version: 2.34.5075.1619 - Google, Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
Image Resizer for Windows (64 bit) (HKLM\...\{617CA6E9-D5FB-4017-8130-82E68C56C34D}) (Version: 3.0.4802.35565 - Brice Lambson) Hidden
Image Resizer for Windows (HKLM-x32\...\{69d72156-6582-4556-8637-06f40aa7f85b}) (Version: 3.0.4802.35565 - Brice Lambson)
Intel® Chipset Device Software (HKLM-x32\...\{bb0592a7-5772-4736-9d55-2402740085db}) (Version: 10.1.1.38 - Intel® Corporation) Hidden
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.6.0.1036 - Intel Corporation)
Intel® Network Connections 21.1.30.0 (HKLM\...\PROSetDX) (Version: 21.1.30.0 - Intel)
Intel® Online Connect Software Asset Manager (HKLM-x32\...\{AE956AB9-CD98-4F1E-8B9E-C3C66E290D64}) (Version: 3.4.2072 - Intel Corporation) Hidden
Malwarebytes version 3.1.2.1733 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.1.2.1733 - Malwarebytes)
Microsoft Digital Image Suite 2006 (HKLM-x32\...\PictureItSuite_v11) (Version: 11.0.0422 - Microsoft Corporation)
Microsoft Office Professional 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3119151931-944679501-478495044-1001\...\OneDriveSetup.exe) (Version: 17.3.6943.0625 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 54.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 54.0.1 (x86 en-US)) (Version: 54.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 53.0.3 - Mozilla)
MSI Super Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.3.0.12 - MSI)
NVIDIA 3D Vision Controller Driver 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 376.53 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 376.53 - NVIDIA Corporation)
NVIDIA Graphics Driver 376.53 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.53 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.17 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
Opera Mail 1.0 (HKU\S-1-5-21-3119151931-944679501-478495044-1001\...\Opera 1.0.1044) (Version: 1.0.1044 - Opera Software ASA)
PhotoshopdotcomInspirationBrowser (HKLM-x32\...\{AFBBF30D-ADA9-4313-464E-14458B6BE034}) (Version: 0.0.0 - Adobe Systems Incorporated) Hidden
Quicken 2007 (HKLM-x32\...\{0D2E80C8-0875-43EB-9623-47118E2DFBCA}) (Version: 16.1.1.27 - Intuit)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8059 - Realtek Semiconductor Corp.)
RoboForm 7-9-28-8 (All Users) (HKLM-x32\...\AI RoboForm) (Version: 7-9-28-8 - Siber Systems)
SafeZone Stable 3.55.2393.609 (HKLM-x32\...\SafeZone 3.55.2393.609) (Version: 3.55.2393.609 - Avast Software) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
SmartSound Quicktracks for Premiere Elements (HKLM-x32\...\{F6234880-85BE-4DCB-8A45-1FF85A1A8552}) (Version: 3.11.3090 - SmartSound Software Inc) Hidden
SmartSound Quicktracks for Premiere Elements (HKLM-x32\...\InstallShield_{F6234880-85BE-4DCB-8A45-1FF85A1A8552}) (Version: 3.11.3090 - SmartSound Software Inc)
Speccy (HKLM\...\Speccy) (Version: 1.30 - Piriform)
UK's Kalender 2.5.2 (HKLM-x32\...\UK's Kalender_is1) (Version:  - Ulrich Krebs)
Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.)
Windows 10 Update and Privacy Settings (HKLM\...\{293F2009-0145-450B-B4AA-063D43FB368C}) (Version: 1.0.13.0 - Microsoft Corporation)
WinPatrol (HKLM-x32\...\{6A206A04-6BC1-411B-AA04-4E52EDEEADF2}) (Version: 35.5.2017.8 - Ruiware)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-03-21] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-03-21] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-03-21] (Google)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-25] (AVAST Software)
ShellIconOverlayIdentifiers-x32: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.17.0.dll [2017-07-12] (Dropbox, Inc.)
ContextMenuHandlers01: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-25] (AVAST Software)
ContextMenuHandlers01: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ContextMenuHandlers01: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-03-21] (Google)
ContextMenuHandlers01: [Image Resizer] -> {51B4D7E5-7568-4234-B4BB-47FB3C016A69} => C:\Program Files\Image Resizer for Windows\ShellExtensions.dll [2013-02-23] (Brice Lambson)
ContextMenuHandlers03: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-25] (AVAST Software)
ContextMenuHandlers03: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes)
ContextMenuHandlers04: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ContextMenuHandlers04: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-03-21] (Google)
ContextMenuHandlers05: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ContextMenuHandlers05: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2016-12-29] (NVIDIA Corporation)
ContextMenuHandlers06: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-25] (AVAST Software)
ContextMenuHandlers06: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {059EDA3A-E170-4D45-9BCB-18C424FFE77D} - System32\Tasks\Run RoboForm TaskBar Icon => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [2017-05-31] (Siber Systems)
Task: {15AA23DB-08D7-413B-8CD8-66E235B157B1} - System32\Tasks\IntelIOC-Upgrade-f1c8187b-2653-47cd-a9be-b554b98f68a7-Logon => C:\Program Files (x86)\Intel\Intel® Online Connect Access\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [2016-09-29] (Intel Corporation)
Task: {19B6EB3D-B0A5-44D8-8206-679F22E771D1} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [2016-07-26] (Intel® Corporation)
Task: {1FD8E559-558A-47D9-97A4-4FCB3291D55F} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated)
Task: {2291746A-0792-4965-9A60-54E68B6DB160} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-07-25] (AVAST Software)
Task: {2E50F98A-F57E-4F2B-B7A0-ABC6CA8278E1} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-07-12] (Adobe Systems Incorporated)
Task: {513E5FE4-0153-4FFB-BB6B-0BFD3656D982} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-06-04] (Dropbox, Inc.)
Task: {53BB5DFA-12FA-436B-A3AC-1663E62B33B0} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-05-19] (Piriform Ltd)
Task: {55F241AC-8BE7-4DFF-B49C-B49BAB4E3490} - System32\Tasks\IntelIOC-Upgrade-f1c8187b-2653-47cd-a9be-b554b98f68a7 => C:\Program Files (x86)\Intel\Intel® Online Connect Access\Intel® Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [2016-09-29] (Intel Corporation)
Task: {618303D3-3496-4A84-B69C-61B9081E9C76} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel® Update Manager\bin\iumsvc.exe
Task: {7C0ABB59-6FC4-48E9-8AD2-05DC952E172C} - System32\Tasks\SafeZone scheduled Autoupdate 1496576224 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2017-06-13] (Avast Software)
Task: {85B3D919-C642-4A59-A272-18EAA0B86B13} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-06-04] (Dropbox, Inc.)
Task: {9653355E-78CF-4AC8-8643-00C048EE7DE1} - System32\Tasks\Open URL by RoboForm => C:\Windows\system32\rundll32.exe url.dll,FileProtocolHandler "hxxps://www.roboform.com/test-pass.html?aaa=KICMLMNMPMIMMMMMMJGMCNHMKMKMNJCNLMNMOMMJCNOJLMKJLJCNMMHMMMHMKMMMMJNMHMMMMMMJJNJICMIMCNGMCNNMHMFMOMOMCNOMOMGMHMCNOMLMMMGMMMFMPMCNPMCNOMLMMMGMMMCNNMJNPICMPMFMEKMICNJJCKFMPMJNHICMEKMICNJJCKJNBJCMLLGJOJBJKJJNKJCMJNNICMJNDJCMKJBJJNM (the data entry has 48 more characters).
Task: {A38E33F9-7DA4-4D94-B3EB-0EFEFAFC8576} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-05-30] (Google Inc.)
Task: {B717DDE0-5B21-421D-847E-AE15456DAFA3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-05-30] (Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2016-07-16 07:42 - 2016-07-16 07:42 - 00231424 _____ () C:\Windows\SYSTEM32\ism32k.dll
2017-07-12 16:42 - 2017-06-21 03:48 - 02681200 _____ () C:\Windows\system32\CoreUIComponents.dll
2013-12-02 09:29 - 2013-12-02 09:29 - 00332800 _____ () C:\Program Files\Genie9\Genie Timeline\OnlineHandler.dll
2013-11-20 03:39 - 2013-11-20 03:39 - 00045568 _____ () C:\Program Files\Genie9\Genie Timeline\GSLogging.dll
2013-12-02 09:29 - 2013-12-02 09:29 - 00087040 _____ () C:\Program Files\Genie9\Genie Timeline\QueueManager.dll
2013-12-02 09:29 - 2013-12-02 09:29 - 00491008 _____ () C:\Program Files\Genie9\Genie Timeline\GSIndexDB.dll
2013-12-02 09:29 - 2013-12-02 09:29 - 00722944 _____ () C:\Program Files\Genie9\Genie Timeline\GSBackupManager.dll
2013-12-02 09:29 - 2013-12-02 09:29 - 00211456 _____ () C:\Program Files\Genie9\Genie Timeline\Settings.dll
2013-12-02 09:29 - 2013-12-02 09:29 - 00371200 _____ () C:\Program Files\Genie9\Genie Timeline\GSWatcher4.dll
2013-11-20 03:39 - 2013-11-20 03:39 - 00058368 _____ () C:\Program Files\Genie9\Genie Timeline\GSLibrariesManager.dll
2012-02-02 05:16 - 2012-02-02 05:16 - 00740864 _____ () C:\Program Files\Genie9\Genie Timeline\sqlite3.dll
2012-04-24 05:29 - 2012-04-24 05:29 - 00011264 _____ () C:\Program Files\Genie9\Genie Timeline\RWLock.dll
2013-12-02 09:29 - 2013-12-02 09:29 - 00054784 _____ () C:\Program Files\Genie9\Genie Timeline\GSLogManager.dll
2013-11-20 03:39 - 2013-11-20 03:39 - 00089600 _____ () C:\Program Files\Genie9\Genie Timeline\GSEncryption.dll
2012-02-02 05:16 - 2012-02-02 05:16 - 00010752 _____ () C:\Program Files\Genie9\Genie Timeline\VSSEngine_Proxy.dll
2013-02-11 07:34 - 2013-02-11 07:34 - 00045056 _____ () C:\Program Files\Genie9\Genie Timeline\pcre.dll
2013-02-11 07:34 - 2013-02-11 07:34 - 00097792 _____ () C:\Program Files\Genie9\Genie Timeline\pcrebase.dll
2016-10-05 15:15 - 2016-10-05 15:15 - 00107752 _____ () C:\Program Files\Intel\Intel® Online Connect Access\libglog.dll
2016-10-05 15:15 - 2016-10-05 15:15 - 00412904 _____ () C:\Program Files\Intel\Intel® Online Connect Access\JsonCpp.dll
2017-06-01 15:06 - 2017-07-17 19:09 - 02260432 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2017-05-30 07:08 - 2016-12-29 08:44 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2017-05-30 10:53 - 2016-09-07 00:56 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-05-30 10:53 - 2017-03-04 02:31 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2017-05-30 10:53 - 2017-03-04 02:12 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-05-30 10:53 - 2017-03-04 02:05 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-05-30 10:53 - 2017-03-04 02:05 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-07-12 16:42 - 2017-06-21 02:36 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2017-07-12 16:42 - 2017-06-21 02:35 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-07-12 16:42 - 2017-06-21 02:37 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2013-12-02 09:29 - 2013-12-02 09:29 - 00063488 _____ () C:\Program Files\Genie9\Genie Timeline\XBalloonMsgDll.dll
2013-11-20 03:39 - 2013-11-20 03:39 - 00093696 _____ () C:\Program Files\Genie9\Genie Timeline\GSCurl.dll
2017-05-30 23:18 - 2017-03-25 19:26 - 00089960 _____ () C:\Program Files (x86)\AOMEI Backupper\ABNotify.exe
2016-10-04 20:09 - 2016-10-04 20:09 - 00253664 _____ () C:\Program Files\Intel\Intel® Online Connect\CSLibWrapper.dll
2017-06-23 05:26 - 2017-06-23 05:29 - 13207232 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8241.41275.0_x64__8wekyb3d8bbwe\Office.UI.Xaml.Core.dll
2017-06-23 05:26 - 2017-06-23 05:29 - 01199816 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8241.41275.0_x64__8wekyb3d8bbwe\Office.UI.Xaml.Word.dll
2017-05-30 08:30 - 2017-05-30 08:30 - 03918848 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1705.1301.0_x64__8wekyb3d8bbwe\Calculator.exe
2017-07-17 04:34 - 2017-07-17 04:34 - 00074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.820.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2017-07-17 04:34 - 2017-07-17 04:34 - 00203264 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.820.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2017-07-17 04:34 - 2017-07-17 04:34 - 43573248 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.820.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2017-07-17 04:34 - 2017-07-17 04:34 - 02435584 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.820.0_x64__kzf8qxf38zg5c\skypert.dll
2017-05-30 23:18 - 2017-03-25 19:28 - 00954216 _____ () C:\Program Files (x86)\AOMEI Backupper\UiLogic.dll
2017-05-30 23:18 - 2017-03-25 19:27 - 00331632 _____ () C:\Program Files (x86)\AOMEI Backupper\Comn.dll
2017-05-30 23:18 - 2017-03-25 19:27 - 00253808 _____ () C:\Program Files (x86)\AOMEI Backupper\diskmgr.dll
2017-05-30 23:18 - 2017-03-25 19:27 - 00143208 _____ () C:\Program Files (x86)\AOMEI Backupper\FuncLogic.dll
2017-05-30 23:18 - 2017-03-25 19:27 - 00360296 _____ () C:\Program Files (x86)\AOMEI Backupper\ImgFile.dll
2017-05-30 23:18 - 2017-03-25 19:27 - 00040808 _____ () C:\Program Files (x86)\AOMEI Backupper\Encrypt.dll
2017-05-30 23:18 - 2017-03-25 19:27 - 00495472 _____ () C:\Program Files (x86)\AOMEI Backupper\EnumFolder.dll
2017-05-30 23:18 - 2017-03-25 19:27 - 00081776 _____ () C:\Program Files (x86)\AOMEI Backupper\Compress.dll
2017-05-30 23:18 - 2017-03-25 19:27 - 00114544 _____ () C:\Program Files (x86)\AOMEI Backupper\BrLog.dll
2017-05-30 23:18 - 2017-03-25 19:27 - 00339816 _____ () C:\Program Files (x86)\AOMEI Backupper\Clone.dll
2017-05-30 23:18 - 2017-03-25 19:27 - 00130920 _____ () C:\Program Files (x86)\AOMEI Backupper\Backup.dll
2017-05-30 23:18 - 2017-03-25 19:27 - 00171888 _____ () C:\Program Files (x86)\AOMEI Backupper\FlBackup.dll
2017-05-30 23:18 - 2017-03-25 19:28 - 00724848 _____ () C:\Program Files (x86)\AOMEI Backupper\Sync.dll
2017-05-30 23:18 - 2017-03-25 19:27 - 00089960 _____ () C:\Program Files (x86)\AOMEI Backupper\Ldm.dll
2017-05-30 23:18 - 2017-03-25 19:27 - 00073584 _____ () C:\Program Files (x86)\AOMEI Backupper\Device.dll
2017-05-30 23:18 - 2017-03-25 19:27 - 00298856 _____ () C:\Program Files (x86)\AOMEI Backupper\BrFat.dll
2017-05-30 23:18 - 2017-03-25 19:27 - 00978800 _____ () C:\Program Files (x86)\AOMEI Backupper\BrNtfs.dll
2017-05-30 23:18 - 2015-05-21 17:32 - 02403504 _____ () C:\Program Files (x86)\AOMEI Backupper\QtCore4.dll
2017-05-30 23:18 - 2017-03-25 19:27 - 00114536 _____ () C:\Program Files (x86)\AOMEI Backupper\BrVol.dll
2017-05-30 23:18 - 2017-03-25 19:27 - 00266088 _____ () C:\Program Files (x86)\AOMEI Backupper\GptBcd.dll
2017-05-30 23:18 - 2017-03-25 19:27 - 00188264 _____ () C:\Program Files (x86)\AOMEI Backupper\DeviceMgr.dll
2017-07-25 13:49 - 2017-07-25 13:49 - 00170224 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2017-07-25 13:49 - 2017-07-25 13:49 - 01065936 _____ () C:\Program Files\AVAST Software\Avast\AvChrome.dll
2017-07-07 09:02 - 2017-07-07 09:02 - 67109376 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2017-07-25 13:49 - 2017-07-25 13:49 - 00192664 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll
2017-07-25 13:49 - 2017-07-25 13:49 - 00224256 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll
2017-07-25 13:49 - 2017-07-25 13:49 - 00292920 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll
2017-07-25 13:49 - 2017-07-25 13:49 - 00689272 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2017-07-13 13:27 - 2017-07-12 15:58 - 00746816 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_watchdog.dll
2017-07-13 13:27 - 2017-07-12 15:58 - 01787200 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_crashpad.dll
2017-06-04 09:43 - 2017-07-12 15:58 - 00100296 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd
2017-06-04 09:43 - 2017-07-12 15:58 - 00018888 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd
2017-06-04 09:43 - 2017-07-12 16:01 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd
2017-06-04 09:43 - 2017-07-12 15:58 - 00035792 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd
2017-07-13 13:27 - 2017-07-12 15:59 - 00021848 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd
2017-06-04 09:43 - 2017-07-12 15:58 - 00125904 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd
2017-06-04 09:43 - 2017-07-12 15:58 - 00694224 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd
2017-07-13 13:27 - 2017-07-12 15:59 - 01862992 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd
2017-07-13 13:27 - 2017-07-12 15:59 - 00022864 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd
2017-07-13 13:27 - 2017-07-12 15:58 - 00145864 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd
2017-07-13 13:27 - 2017-07-12 15:58 - 00020432 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd
2017-07-13 13:27 - 2017-07-12 15:58 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll
2017-06-04 09:43 - 2017-07-12 15:58 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd
2017-06-04 09:43 - 2017-07-12 16:01 - 00022864 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.crt.compiled._winffi_crt.pyd
2017-07-13 13:27 - 2017-07-12 15:59 - 00062784 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd
2017-07-13 13:27 - 2017-07-12 15:59 - 00040248 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd
2017-06-04 09:43 - 2017-07-12 15:58 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd
2017-07-13 13:27 - 2017-07-12 15:58 - 00392656 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll
2017-07-13 13:27 - 2017-07-12 15:58 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd
2017-06-04 09:43 - 2017-07-12 15:58 - 00116176 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd
2017-06-04 09:43 - 2017-07-12 16:01 - 00392512 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd
2017-06-04 09:43 - 2017-07-12 15:58 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd
2017-06-04 09:43 - 2017-07-12 16:01 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.pyd
2017-06-04 09:43 - 2017-07-12 15:58 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd
2017-06-04 09:43 - 2017-07-12 15:58 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd
2017-06-04 09:43 - 2017-07-12 15:58 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd
2017-06-04 09:43 - 2017-07-12 15:58 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd
2017-06-04 09:43 - 2017-07-12 15:58 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd
2017-06-04 09:43 - 2017-07-12 15:58 - 00057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd
2017-06-04 09:43 - 2017-07-12 15:58 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd
2017-07-13 13:27 - 2017-07-12 15:59 - 00022336 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd
2017-06-04 09:43 - 2017-07-12 16:01 - 00082264 _____ () C:\Program Files (x86)\Dropbox\Client\winenumhandles.compiled._WinEnumHandles.pyd
2017-06-04 09:43 - 2017-07-12 16:01 - 00025432 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd
2017-07-13 13:27 - 2017-07-12 15:59 - 00027488 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd
2017-07-13 13:27 - 2017-07-12 16:00 - 03928896 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd
2017-06-04 09:43 - 2017-07-12 15:58 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd
2017-07-13 13:27 - 2017-07-12 15:59 - 01826104 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd
2017-07-13 13:27 - 2017-07-12 16:00 - 01972024 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd
2017-06-04 09:43 - 2017-07-12 15:58 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd
2017-07-13 13:27 - 2017-07-12 16:00 - 00171336 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd
2017-07-13 13:27 - 2017-07-12 16:00 - 00042816 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd
2017-07-13 13:27 - 2017-07-12 16:00 - 00531264 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd
2017-07-13 13:27 - 2017-07-12 16:00 - 00133432 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd
2017-07-13 13:27 - 2017-07-12 16:00 - 00224064 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd
2017-07-13 13:27 - 2017-07-12 16:00 - 00207680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd
2017-06-04 09:43 - 2017-07-12 15:58 - 00060880 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.pyd
2017-06-04 09:43 - 2017-07-12 16:01 - 00054608 _____ () C:\Program Files (x86)\Dropbox\Client\winrpcserver.compiled._RPCServer.pyd
2017-06-04 09:43 - 2017-07-12 16:01 - 00022864 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32.compiled._winffi_user32.pyd
2017-06-04 09:43 - 2017-07-12 16:01 - 00069968 _____ () C:\Program Files (x86)\Dropbox\Client\windisplaytoast.compiled._DisplayToast.pyd
2017-06-04 09:43 - 2017-07-12 16:01 - 00022872 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi.compiled._winffi_iphlpapi.pyd
2017-06-04 09:43 - 2017-07-12 16:01 - 00021848 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror.compiled._winffi_winerror.pyd
2017-06-04 09:43 - 2017-07-12 16:01 - 00022872 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet.compiled._winffi_wininet.pyd
2017-06-04 09:43 - 2017-07-12 15:58 - 00349128 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd
2017-07-13 13:27 - 2017-07-12 16:00 - 00103232 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWinExtras.pyd
2017-06-04 09:43 - 2017-07-12 16:01 - 00023896 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd
2017-07-13 13:27 - 2017-07-12 15:59 - 00025936 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd
2017-07-13 13:27 - 2017-07-12 15:58 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2017-07-13 13:27 - 2017-07-12 15:59 - 00033112 _____ () C:\Program Files (x86)\Dropbox\Client\enterprise_data.compiled._enterprise_data.pyd
2017-07-13 13:27 - 2017-07-12 15:58 - 00293392 _____ () C:\Program Files (x86)\Dropbox\Client\EnterpriseDataAdapter.dll
2017-07-13 13:27 - 2017-07-12 15:59 - 00181056 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
2017-06-04 09:43 - 2017-07-12 16:01 - 00030536 _____ () C:\Program Files (x86)\Dropbox\Client\wind3d11.compiled._wind3d11.pyd
2017-07-13 13:27 - 2017-07-12 15:59 - 00024368 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.dll
2017-07-13 13:27 - 2017-07-12 15:59 - 01637688 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
2017-06-04 09:43 - 2017-07-12 16:01 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.pyd
2017-06-04 09:43 - 2017-07-12 16:01 - 00023368 _____ () C:\Program Files (x86)\Dropbox\Client\wincrashpad.compiled._Crashpad.pyd
2017-07-13 13:27 - 2017-07-12 16:00 - 00546104 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd
2017-07-13 13:27 - 2017-07-12 16:00 - 00357688 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd
2016-10-20 04:28 - 2016-10-20 04:28 - 01243936 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\ACE.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2016-07-16 07:47 - 2016-07-16 07:45 - 00000824 _____ C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3119151931-944679501-478495044-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Diane\Pictures\11deskpic\Project1.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{1DBE90AE-3135-4430-9D98-3A35DC4CBD74}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{8A2FAF40-7D99-49E0-8CEE-67B3E126099A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{4D1F021A-01CE-434C-A4CF-E2CC57ADCA0B}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{DEF86B8D-8BF8-4B50-9599-EF8ECAC3498D}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.609\SZBrowser.exe
FirewallRules: [TCP Query User{E11DF654-C57B-4D8A-AD33-1C3603C710CB}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{DB9FBA90-46F9-479B-9AA0-BB94D4CDAF49}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{65209F42-E401-4D71-86B8-25716C57D285}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
FirewallRules: [{A93215EA-B11D-4ABB-9CB4-E939F70ED91F}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.609_0\SZBrowser.exe

==================== Restore Points =========================

23-07-2017 19:00:10 Windows Backup

==================== Faulty Device Manager Devices =============

Name: Standard PS/2 Keyboard
Description: Standard PS/2 Keyboard
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard keyboards)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Microsoft PS/2 Mouse
Description: Microsoft PS/2 Mouse
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (07/26/2017 09:07:29 AM) (Source: IntelDalJhi) (EventID: 4) (User: )
Description: Intel® Dynamic Application Loader Host Interface Service initialization failure - the spooler applet is invalid.

Error: (07/26/2017 09:07:29 AM) (Source: IntelDalJhi) (EventID: 4) (User: )
Description: Intel® Dynamic Application Loader Host Interface Service initialization failure - the spooler applet is invalid.

Error: (07/26/2017 07:57:19 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 54.0.1.6388, time stamp: 0x5953d640
Faulting module name: xul.dll, version: 54.0.1.6388, time stamp: 0x5953d62e
Exception code: 0x80000003
Fault offset: 0x008a6bcb
Faulting process id: 0x4e4
Faulting application start time: 0x01d306049376b14e
Faulting application path: C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
Faulting module path: C:\Program Files (x86)\Mozilla Firefox\xul.dll
Report Id: d02f9ec6-ba9b-4d92-b27a-c10001c18181
Faulting package full name:
Faulting package-relative application ID:

Error: (07/26/2017 04:46:15 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:
Access is denied.
.

Error: (07/26/2017 04:45:16 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "C:\Program Files\Genie9\Genie Timeline\x86\GenieTimeLineAgent.exe".Error in manifest or policy file "" on line .
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171.manifest.

Error: (07/26/2017 04:45:07 AM) (Source: SideBySide) (EventID: 63) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3.
The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid.

Error: (07/26/2017 04:42:35 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:
Access is denied.
.

Error: (07/25/2017 07:29:11 PM) (Source: IntelDalJhi) (EventID: 4) (User: )
Description: Intel® Dynamic Application Loader Host Interface Service initialization failure - the spooler applet is invalid.

Error: (07/25/2017 07:29:11 PM) (Source: IntelDalJhi) (EventID: 4) (User: )
Description: Intel® Dynamic Application Loader Host Interface Service initialization failure - the spooler applet is invalid.

Error: (07/25/2017 02:35:05 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.


Operation:
   Gathering Writer Data

Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {e424158b-5def-491a-989e-5bb573e60309}


System errors:
=============
Error: (07/26/2017 09:07:22 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (07/26/2017 08:31:50 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-4RSJHTG)
Description: The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Error: (07/26/2017 08:29:50 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Connected Devices Platform Service service terminated with the following error:
Unspecified error

Error: (07/26/2017 08:29:50 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-4RSJHTG)
Description: The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Error: (07/26/2017 08:27:50 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Connected Devices Platform Service service terminated with the following error:
Unspecified error

Error: (07/26/2017 08:23:54 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Connected Devices Platform Service service terminated with the following error:
Unspecified error

Error: (07/26/2017 08:22:48 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Intel® Online Connect Helper service.

Error: (07/26/2017 08:21:56 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (07/26/2017 08:21:20 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (07/26/2017 07:57:08 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.


==================== Memory info ===========================

Processor: Intel® Core™ i7-7700K CPU @ 4.20GHz
Percentage of memory in use: 9%
Total physical RAM: 32732.58 MB
Available physical RAM: 29459.68 MB
Total Virtual: 37596.58 MB
Available Virtual: 34113.43 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.27 GB) (Free:369.59 GB) NTFS
Drive e: (1TB1) (Fixed) (Total:931.51 GB) (Free:599.2 GB) NTFS
Drive f: (1TB2) (Fixed) (Total:443.23 GB) (Free:232.54 GB) NTFS
Drive g: (bkup) (Fixed) (Total:488.28 GB) (Free:447.85 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: AE8989DE)
Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.3 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 0240C1F9)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 0240C1F8)
Partition 1: (Not Active) - (Size=443.2 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=488.3 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================



BC AdBot (Login to Remove)

 


#2 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,209 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:04:58 PM

Posted 28 July 2017 - 09:49 PM

Greetings careful and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

If you would allow me to call you by your first name I would prefer to do that.

===================================================

Ground Rules:
  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met.
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far.

Please do this.

===================================================

Farbar's Recovery Scan Tool - Run Fix in Normal or Safe Mode

--------------------
  • Right click on the FRST icon and select Run as administrator
  • Highlight the below information then hit the Ctrl + C keys at the same time
Start::
CreateRestorePoint:
CloseProcesses:
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKU\S-1-5-21-3119151931-944679501-478495044-1001\...\MountPoints2: {0938790c-452e-11e7-840f-806e6f6e6963} - "D:\autorun.exe"
emptytemp:
End::
  • Click Fix
  • When completed he tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

RogueKiller

--------------------
  • Download RogueKiller and save it to your desktop
  • Close all running programs
  • Right click on the setup.exe icon and select Run as Administrator
  • For Windows XP simply double click on the icon
  • Click OK on English
  • Select Install 32 and 64 bits versions (Recommended for Technicians), then click Next 2 times
  • Click Install
  • Click Finish
  • Click Start Scan twice
  • When completed click Open Report
  • Click Export Text and save the file on your Desktop as RK.txt
  • Close all open RogueKiller windows
  • Copy and paste the contents of the report in your reply
===================================================

Malwarebytes AdwCleaner

-------------------
  • Please download AdwCleaner and save it on your desktop.
  • Close all open programs and browsers
  • Double click on AdwCleaner.exe, click Run, then select I agree if it appears
  • Click Scan
  • Once the scan has completed if there are threats found you will see Found 3 threats or something similar above the progress bar
  • Click each tab under Results and uncheck any items you want to keep
  • Click on Clean
  • Confirm the cleaning and rebooting of your computer by clicking OK
  • Click OK twice to finish the removal process by automatically rebooting your computer
  • Once completed an AdwCleaner document will open on your desktop
  • Copy and paste the contents in your reply
===================================================

SystemLook by jpshortstuff

--------------------
  • Please download SystemLook for 64 bit systems and save it to your Desktop.
  • Right-click SystemLook.exe and select Run as administrator...
  • Copy the content of the following codebox into the main textfield:
:filefind
cmd.exe
:regfind
cmd.exe
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please copy and paste the report contents in your reply.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Fixlog
  • RogueKiller log
  • AdwCleaner log
  • SystemLook report

Edited by Oh My!, 28 July 2017 - 10:02 PM.

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#3 careful

careful
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:07:58 PM

Posted 29 July 2017 - 04:55 AM

Hi Gary this is my farbar txt

Fix result of Farbar Recovery Scan Tool (x64) Version: 29-07-2017
Ran by Diane (29-07-2017 05:51:01) Run:1
Running from C:\Users\Diane\Desktop\farbar
Loaded Profiles: Diane (Available Profiles: defaultuser0 & Diane)
Boot Mode: Normal
==============================================

fixlist content:
*****************

CreateRestorePoint:
CloseProcesses:
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKU\S-1-5-21-3119151931-944679501-478495044-1001\...\MountPoints2: {0938790c-452e-11e7-840f-806e6f6e6963} - "D:\autorun.exe"
emptytemp:

*****************

Restore point was successfully created.
Processes closed successfully.
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION => restored successfully
HKU\S-1-5-21-3119151931-944679501-478495044-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0938790c-452e-11e7-840f-806e6f6e6963} => key removed successfully
HKLM\Software\Classes\CLSID\{0938790c-452e-11e7-840f-806e6f6e6963} => key not found.

=========== EmptyTemp: ==========

BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 14135286 B
Java, Flash, Steam htmlcache => 8438 B
Windows/system/drivers => 18124027 B
Edge => 5299563 B
Chrome => 887191478 B
Firefox => 387794038 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 0 B
LocalService => 50026 B
NetworkService => 11026 B
defaultuser0 => 7296 B
Diane => 26417377 B

RecycleBin => 1936740 B
EmptyTemp: => 1.2 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 05:51:45 ====



#4 careful

careful
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:07:58 PM

Posted 29 July 2017 - 05:15 AM

This is the roguekiller text

RogueKiller V12.11.8.0 (x64) [Jul 24 2017] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : https://forum.adlice.com
Website : http://www.adlice.com/download/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 10 (10.0.14393) 64 bits version
Started in : Normal mode
User : Diane [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Scan -- Date : 07/29/2017 06:01:55 (Duration : 00:11:50)
Switches : -refid

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 0 ¤¤¤

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ WMI : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: WDC WDS500G1B0A-00H9H0 +++++
--- User ---
[MBR] a107b4f40a21ef81a704a3b3843bc737
[BSP] b3c406628df99f450004bd0403f10ed0 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 500 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 1026048 | Size: 476438 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: WDC WD1003FZEX-00K3CA0 +++++
--- User ---
[MBR] 22518f823440ce05274bb595e8c584ff
[BSP] 79d170777fc7f2d5f346dc46cf7d679a : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 953867 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive2: WDC WD1003FZEX-00K3CA0 +++++
--- User ---
[MBR] 2d95ce567b7cbe4a7fc6437e9a5f880a
[BSP] 6f07e54fe1bbf070a32fbf50e3df3196 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 453867 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 929521664 | Size: 499999 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

 

This is the AdwCleaner report

# AdwCleaner 7.0.0.0 - Logfile created on Sat Jul 29 10:17:20 2017
# Updated on 2017/17/07 by Malwarebytes
# Running on Windows 10 Pro (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services deleted.

***** [ Folders ] *****

Deleted: C:/Program Files (x86)\SmartSound Software


***** [ Files ] *****

No malicious files deleted.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks deleted.

***** [ Registry ] *****

No malicious registry entries deleted.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries deleted.

***** [ Chromium (and derivatives) ] *****

SearchProvider deleted: AOL - aol.com
SearchProvider deleted: Ask - ask.com


*************************

::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0



*************************

C:/AdwCleaner/AdwCleaner[S0].txt - [1164 B] - [2017/7/29 10:17:8]


########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########

 

 

 

This is the systemlook (thanks so much for your help)

SystemLook 30.07.11 by jpshortstuff
Log created at 06:20 on 29/07/2017 by Diane
Administrator - Elevation successful

========== filefind ==========

Searching for "cmd.exe"
C:\Windows\System32\cmd.exe    --a---- 232960 bytes    [11:42 16/07/2016]    [11:42 16/07/2016] F4F684066175B77E0C3A000549D2922C
C:\Windows\SysWOW64\cmd.exe    --a---- 202752 bytes    [11:43 16/07/2016]    [11:43 16/07/2016] 0FEC5F30E705EADAEA5E9144F2FB12DC
C:\Windows\WinSxS\amd64_microsoft-windows-commandprompt_31bf3856ad364e35_10.0.14393.0_none_b8813238310f2dd6\cmd.exe    --a---- 232960 bytes    [11:42 16/07/2016]    [11:42 16/07/2016] F4F684066175B77E0C3A000549D2922C
C:\Windows\WinSxS\wow64_microsoft-windows-commandprompt_31bf3856ad364e35_10.0.14393.0_none_c2d5dc8a656fefd1\cmd.exe    --a---- 202752 bytes    [11:43 16/07/2016]    [11:43 16/07/2016] 0FEC5F30E705EADAEA5E9144F2FB12DC

========== regfind ==========

Searching for "cmd.exe"
[HKEY_CURRENT_USER\SOFTWARE\BillP Studios\Detected\Startup]
"C:\Windows\system32\cmd.exe /q /c rmdir /s /q C:\Users\Diane\AppData\Local\Microsoft\OneDrive\17.3.6799.0327\amd64"="06/20/2017 6:11 PM"
[HKEY_CURRENT_USER\SOFTWARE\BillP Studios\Detected\Startup]
"C:\Windows\system32\cmd.exe /q /c rmdir /s /q C:\Users\Diane\AppData\Local\Microsoft\OneDrive\17.3.6799.0327"="06/20/2017 6:13 PM"
[HKEY_CURRENT_USER\SOFTWARE\BillP Studios\Detected\Startup]
"C:\Windows\system32\cmd.exe /q /c rmdir /s /q C:\Users\Diane\AppData\Local\Microsoft\OneDrive\17.3.6917.0607\amd64"="07/26/2017 7:18 AM"
[HKEY_CURRENT_USER\SOFTWARE\BillP Studios\Detected\Startup]
"C:\Windows\system32\cmd.exe /q /c rmdir /s /q C:\Users\Diane\AppData\Local\Microsoft\OneDrive\17.3.6917.0607"="07/26/2017 7:20 AM"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dll\OpenWithList]
"a"="{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\cmd.exe"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\RecentApps\{D46E6A70-06CA-45CB-944D-B9C42775FE08}]
"AppId"="{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\cmd.exe"
[HKEY_CURRENT_USER\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Windows\system32\cmd.exe.FriendlyAppName"="Windows Command Processor"
[HKEY_CURRENT_USER\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Windows\system32\cmd.exe.ApplicationCompany"="Microsoft Corporation"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shell\runas\command]
@="cmd.exe /c takeown /f "%1" && icacls "%1" /grant *S-1-3-4:F /c /l"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shell\runas\command]
"IsolatedCommand"="cmd.exe /c takeown /f "%1" && icacls "%1" /grant *S-1-3-4:F /c /l"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\cmd.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\batfile\shell\runas\command]
@="%SystemRoot%\System32\cmd.exe /C "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00021400-0000-0000-C000-000000000046}\shell\cmd\command]
@="cmd.exe /s /k pushd "%V""
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\shell\cmd\command]
@="cmd.exe /s /k pushd "%V""
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\cmdfile\shell\runas\command]
@="%SystemRoot%\System32\cmd.exe /C "%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\background\shell\cmd\command]
@="cmd.exe /s /k pushd "%V""
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shell\cmd\command]
@="cmd.exe /s /k pushd "%V""
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shell\runas\command]
@="cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant *S-1-3-4:F /t /c /l /q"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shell\runas\command]
"IsolatedCommand"="cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant *S-1-3-4:F /t /c /l /q"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\dllfile\shell\runas\command]
@="cmd.exe /c takeown /f "%1" && icacls "%1" /grant *S-1-3-4:F /c /l"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\dllfile\shell\runas\command]
"IsolatedCommand"="cmd.exe /c takeown /f "%1" && icacls "%1" /grant *S-1-3-4:F /c /l"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shell\cmd\command]
@="cmd.exe /s /k pushd "%V""
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00021400-0000-0000-C000-000000000046}\shell\cmd\command]
@="cmd.exe /s /k pushd "%V""
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\shell\cmd\command]
@="cmd.exe /s /k pushd "%V""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{aff735eb-cdf9-4894-aa69-3e3131128618}]
"AppName"="cmd.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\IEDIAG.EXE]
@="C:\Program Files\Internet Explorer\IEDIAGCMD.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\IEDIAGCMD.EXE]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\IEDIAGCMD.EXE]
@="C:\Program Files\Internet Explorer\IEDIAGCMD.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RetailDemo\ServiceReadWrite\ProcessCloseExclusionList]
"cmd.exe"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AA9415D4-2A2D-43AA-99FA-0952FEE4AD70}]
"Description"="$(@%SystemRoot%\system32\dsregcmd.exe,-101)"
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{aff735eb-cdf9-4894-aa69-3e3131128618}]
"AppName"="cmd.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\IEDIAG.EXE]
@="C:\Program Files\Internet Explorer\IEDIAGCMD.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\IEDIAGCMD.EXE]
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\IEDIAGCMD.EXE]
@="C:\Program Files\Internet Explorer\IEDIAGCMD.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{00021400-0000-0000-C000-000000000046}\shell\cmd\command]
@="cmd.exe /s /k pushd "%V""
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\shell\cmd\command]
@="cmd.exe /s /k pushd "%V""
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot]
"AlternateShell"="cmd.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment]
"ComSpec"="%SystemRoot%\system32\cmd.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NVDisplay.ContainerLocalSystem]
"FailureCommand"="cmd.exe /C %windir%\NvContainerRecovery.bat NVDisplay.ContainerLocalSystem C:\ProgramData\NVIDIA\NvContainerRecoveryNVDisplay.ContainerLocalSystem.log"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
"AlternateShell"="cmd.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment]
"ComSpec"="%SystemRoot%\system32\cmd.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NVDisplay.ContainerLocalSystem]
"FailureCommand"="cmd.exe /C %windir%\NvContainerRecovery.bat NVDisplay.ContainerLocalSystem C:\ProgramData\NVIDIA\NvContainerRecoveryNVDisplay.ContainerLocalSystem.log"
[HKEY_USERS\S-1-5-21-3119151931-944679501-478495044-1001\SOFTWARE\BillP Studios\Detected\Startup]
"C:\Windows\system32\cmd.exe /q /c rmdir /s /q C:\Users\Diane\AppData\Local\Microsoft\OneDrive\17.3.6799.0327\amd64"="06/20/2017 6:11 PM"
[HKEY_USERS\S-1-5-21-3119151931-944679501-478495044-1001\SOFTWARE\BillP Studios\Detected\Startup]
"C:\Windows\system32\cmd.exe /q /c rmdir /s /q C:\Users\Diane\AppData\Local\Microsoft\OneDrive\17.3.6799.0327"="06/20/2017 6:13 PM"
[HKEY_USERS\S-1-5-21-3119151931-944679501-478495044-1001\SOFTWARE\BillP Studios\Detected\Startup]
"C:\Windows\system32\cmd.exe /q /c rmdir /s /q C:\Users\Diane\AppData\Local\Microsoft\OneDrive\17.3.6917.0607\amd64"="07/26/2017 7:18 AM"
[HKEY_USERS\S-1-5-21-3119151931-944679501-478495044-1001\SOFTWARE\BillP Studios\Detected\Startup]
"C:\Windows\system32\cmd.exe /q /c rmdir /s /q C:\Users\Diane\AppData\Local\Microsoft\OneDrive\17.3.6917.0607"="07/26/2017 7:20 AM"
[HKEY_USERS\S-1-5-21-3119151931-944679501-478495044-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dll\OpenWithList]
"a"="{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\cmd.exe"
[HKEY_USERS\S-1-5-21-3119151931-944679501-478495044-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\RecentApps\{D46E6A70-06CA-45CB-944D-B9C42775FE08}]
"AppId"="{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\cmd.exe"
[HKEY_USERS\S-1-5-21-3119151931-944679501-478495044-1001\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Windows\system32\cmd.exe.FriendlyAppName"="Windows Command Processor"
[HKEY_USERS\S-1-5-21-3119151931-944679501-478495044-1001\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Windows\system32\cmd.exe.ApplicationCompany"="Microsoft Corporation"
[HKEY_USERS\S-1-5-21-3119151931-944679501-478495044-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Windows\system32\cmd.exe.FriendlyAppName"="Windows Command Processor"
[HKEY_USERS\S-1-5-21-3119151931-944679501-478495044-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Windows\system32\cmd.exe.ApplicationCompany"="Microsoft Corporation"

-= EOF =-
 


Edited by careful, 29 July 2017 - 05:21 AM.


#5 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,209 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:04:58 PM

Posted 29 July 2017 - 02:27 PM

Thank you for the information.

When WinPatrol asks for permission does it provide any further information about the request?
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#6 careful

careful
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:07:58 PM

Posted 29 July 2017 - 03:35 PM

No, it doesn't provide any info, it just asks for permission to allow it to go into the start up. It hasn't happened again for several days, I wasn't sure what was causing it and some suggested a virus. I really hate windows 10 :) never had this problem with win7

It seems that the scans are all clear from what I can tell so maybe it is a glitch of some kind?

Thanks



#7 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,209 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:04:58 PM

Posted 29 July 2017 - 03:57 PM

Greetings,

I don't see anything abnormal.

Let's check one more thing. Please do this.

===================================================

Autoruns

--------------------
  • Please download AutoRuns and save it to your desktop
  • Double click the AutoRuns.zip folder (or if necessary right click and select Extract)
  • Double click autoruns.exe (not autorunsc.exe), select Run, then Run again and allow the information to populate
  • Hit the Ctrl + S key at the same time
  • Save the file to your Desktop as autoruns
  • Please zip and upload the file here
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Uploaded Autoruns file

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#8 careful

careful
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:07:58 PM

Posted 29 July 2017 - 05:02 PM

OK I uploaded the file as per the instructions to the site you linked to

Thanks



#9 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,209 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:04:58 PM

Posted 29 July 2017 - 05:05 PM

Got it, thanks. I will review it now.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#10 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,209 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:04:58 PM

Posted 29 July 2017 - 05:15 PM

There isn't anything suspicious in that report.

Do you recall when this started?
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#11 careful

careful
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:07:58 PM

Posted 29 July 2017 - 05:23 PM

about 2 weeks ago maybe? I did remove the microsoft cloud from startup after this last winpatrol popup so possibly the cloud thing had something to do with it?  I was looking for anything in the startup that might be a problem and I didn't use the cloud thing so I removed it.



#12 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,209 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:04:58 PM

Posted 29 July 2017 - 05:34 PM

It could be the Cloud program.

Let's monitor things for a day or so and in the meantime do this.

===================================================

ESET Online Scanner

--------------------

I'd like us to scan your machine with ESET OnlineScan This process may may take several hours, that is normal.
  • Download esetsmartinstaller_enu.exe and save it to your Desktop
  • Double click the icon
  • Check YES, I accept the Terms of Use
  • Click the Start button
  • Accept any security warnings from your browser
  • Click Advanced settings
  • Check the following items

Enable detection of potentially unwanted applications
Remove found threats
Scan archives
Scan for potentially unsafe applications
Enable Anti-Stealth technology

  • Click Start
  • ESET will then download updates and begin scanning your computer
  • If no threats are found simply click Uninstall application on close and hit Finish
  • If threats are found click List of found threats
  • Click Export to text file
  • Save the file on your Desktop as ESET.txt
  • Click Back
  • Review the list of entries and if there are any you want to keep stop and copy/paste the ESET.txt report in your reply for my review
  • If you do not wish to keep any of the entries check Uninstall application on close and Delete quarantined files
  • Click Finish
  • Close the ESET Online Scanner window
  • Copy and paste the contents of ESET.txt in your reply
===================================================

screen317's Security Check

--------------------
  • Please download screen317's Security Check to your desktop
  • Double-click icon to launch the program
  • Click OK
  • Select Run Note: If you receive an error message saying UNSUPPORTED OPERATING SYSTEM! ABORTED! reboot your computer and attempt to run it again
  • Allow the program to run
  • A Notepad document will open on your desktop. Please copy and paste the contents in your reply
===================================================

System Summary Information

--------------------
  • Press the Windows Key + R on your keyboard at the same time
  • Type msinfo32 and press Enter
  • Left click on System Summary
  • Click File, Save, and name the file Summary
  • Zip and attach the file to your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • ESET log
  • Security Check log
  • Attached System Summary file

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#13 careful

careful
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:07:58 PM

Posted 30 July 2017 - 08:55 AM

eset text

C:\Users\Diane\Downloads\ccsetup530.exe    Win32/Bundled.Toolbar.Google.D potentially unsafe application    cleaned by deleting
C:\Users\Diane\Downloads\spsetup130.exe    Win32/Bundled.Toolbar.Google.D potentially unsafe application    cleaned by deleting
E:\DESKTOP-4RSJHTG\Backup Set 2017-06-04 070401\Backup Files 2017-06-04 070401\Backup files 28.zip    Win32/Bundled.Toolbar.Google.D potentially unsafe application    deleted
E:\DESKTOP-4RSJHTG\Backup Set 2017-06-04 070401\Backup Files 2017-06-04 070401\Backup files 29.zip    Win32/Bundled.Toolbar.Google.D potentially unsafe application    deleted
E:\FileHistory\Diane\DESKTOP-4RSJHTG\Data\C\Users\Diane\Downloads\ccsetup530 (2017_06_04 10_56_21 UTC).exe    Win32/Bundled.Toolbar.Google.D potentially unsafe application    cleaned by deleting
E:\FileHistory\Diane\DESKTOP-4RSJHTG\Data\C\Users\Diane\Downloads\spsetup130 (2017_06_04 13_57_18 UTC).exe    Win32/Bundled.Toolbar.Google.D potentially unsafe application    cleaned by deleting
 

 

Security check--

 Results of screen317's Security Check version 1.014 --- 12/23/15  
   x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Enabled!  
Avast Antivirus    
Windows Defender   
Malwarebytes       
 Antivirus up to date!   
`````````Anti-malware/Other Utilities Check:`````````
 WinPatrol
 Adobe Flash Player     26.0.0.137  
 Mozilla Firefox (54.0.1)
 Google Chrome (60.0.3112.78)
 Google Chrome (SetupMetrics...)
 Google Chrome (SetupMetrics.pma..)
````````Process Check: objlist.exe by Laurent````````  
 WinPatrol winpatrol.exe
 Malwarebytes Anti-Malware mbamservice.exe  
 Malwarebytes Anti-Malware mbamtray.exe  
 Windows Defender MSASCuiL.exe   
 Intel Intel® Online Connect Access IntelTechnologyAccessService.exe  
 Intel Intel® Online Connect Access LegacyCsLoaderService.exe  
 Intel Intel® Online Connect ioc.exe  
 Intel iCLS Client AvastSvc.exe -?-  
 AVAST Software Avast AvastUI.exe  
 Ruiware WinPatrol WinPatrol.exe  
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C:  %
````````````````````End of Log``````````````````````
 


Edited by careful, 30 July 2017 - 09:00 AM.


#14 careful

careful
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:07:58 PM

Posted 30 July 2017 - 09:02 AM

here is the summary file attached

Attached Files


Edited by careful, 30 July 2017 - 11:52 AM.


#15 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,209 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:04:58 PM

Posted 30 July 2017 - 03:38 PM

Those reports look good.

I see Microsoft OneDrive was recently installed on your computer. Was that by choice?
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users