Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan TechSupport Scam found by Malwarebytes


  • This topic is locked This topic is locked
5 replies to this topic

#1 rmw388

rmw388

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:04:34 PM

Posted 18 June 2018 - 09:37 PM

1) Outlook quit working

2) A check on Windows Defender yields something about my IT Administrator has blocked access...

3) Ran MSERT found nothing

4) Ran Malwarbytes found so far 795 mostly PUP except for above title

5) Did have BItDefender running it found 51 items

6) Am installing Mcaffee

Plan to uninstall Bitdefender

 

any ideas? am attaching files from FRST64

Attached Files



BC AdBot (Login to Remove)

 


#2 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,635 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:05:34 PM

Posted 19 June 2018 - 08:01 PM

Hi

Welcome :)

I'll be helping you with your computer.

Please read this post completely before beginning. If there's anything that you do not understand, please don't hesitate to ask before proceeding.

Please take note of the guidelines for this fix:

  • Please note that I am a volunteer. I do have a family, a career, and other endeavors that may prevent immediate responses that meet your schedule. Do note that the differences in time zones could present a problem as well. Your patience and understanding will be greatly appreciated.
  • First of all, the procedures we are about to perform are specific to your problem and should only be used on this specific computer.
  • Do not make any changes to your computer that include installing/uninstalling programs, deleting files, modifying the registry, nor running scanners or tools of any kind unless specifically requested by me.
  • Please read ALL instructions carefully and perform the steps fully and in the order they are written.
  • If things appear to be better, let me know. Just because the symptoms no longer exist as before, does not mean that you are clean.
  • Continue to read and follow my instructions until I tell you that your machine is clean.
  • If you have any questions at all, please do not hesitate to ask before performing the task that I ask of you, and please wait for my reply before you proceed.
  • Scanning with programs and reading the logs do take a fair amount of time. Again, your patience will be necessary. :)

Let's begin... :)
 

  • Highlight the entire content of the quote box below.

Start::  
FirewallRules: [{D4D63686-328B-4D64-8401-B68C5BAA91CC}] => (Allow) LPort=9100
FirewallRules: [{3F31878F-35E1-4555-A09C-6943140CBA19}] => (Allow) LPort=427
FirewallRules: [{BEF42A82-6E1B-467D-8729-7A3B44416DB2}] => (Allow) LPort=161
FirewallRules: [{EB2B3CE2-718C-4323-B347-7F7972B63CE6}] => (Allow) LPort=427
GroupPolicy: Restriction ? <==== ATTENTION
Task: {5836168B-0445-4545-B5C6-24837B0ACE79} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {DCD269FF-A2C9-498D-8B7D-43C63ACD9A74} - \OneDrive Standalone Update Task-S-1-5-21-444302225-3719607882-3466423754-1003 -> No File <==== ATTENTION
Toolbar: HKU\S-1-5-21-444302225-3719607882-3466423754-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
ContextMenuHandlers4: [RecuvaShellExt] -> [CC]{435E5DF5-2510-463C-B223-BDA47006D002} =>  -> No File
Task: {5836168B-0445-4545-B5C6-24837B0ACE79} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {DCD269FF-A2C9-498D-8B7D-43C63ACD9A74} - \OneDrive Standalone Update Task-S-1-5-21-444302225-3719607882-3466423754-1003 -> No File <==== ATTENTION
2017-10-12 10:03 - 2017-10-12 10:03 - 000000706 _____ () C:\Program Files (x86)\LMIR0001.tmp.bat
2017-10-12 10:03 - 2017-10-12 10:03 - 000000514 _____ () C:\Program Files (x86)\LMIR0001.tmp_r.bat
2017-08-11 10:29 - 2017-08-11 10:29 - 000000706 _____ () C:\Program Files (x86)\LMIR0002.tmp.bat
2017-08-11 10:29 - 2017-08-11 10:29 - 000000514 _____ () C:\Program Files (x86)\LMIR0002.tmp_r.bat
2017-08-11 10:41 - 2017-08-11 10:41 - 000000706 _____ () C:\Program Files (x86)\LMIR0004.tmp.bat
2017-08-11 10:41 - 2017-08-11 10:41 - 000000514 _____ () C:\Program Files (x86)\LMIR0004.tmp_r.bat
2017-08-11 13:06 - 2017-08-11 13:06 - 000000706 _____ () C:\Program Files (x86)\LMIR0006.tmp.bat
2017-08-11 13:06 - 2017-08-11 13:06 - 000000514 _____ () C:\Program Files (x86)\LMIR0006.tmp_r.bat
2017-08-11 10:41 - 2017-08-11 10:41 - 000000512 _____ () C:\Users\ralph\AppData\Local\LMIR0003.tmp_r.bat
2017-10-12 10:09 - 2017-10-12 10:09 - 000000704 _____ () C:\Users\ralph\AppData\Local\LMIR0004.tmp.bat
2017-10-12 10:09 - 2017-10-12 10:09 - 000000512 _____ () C:\Users\ralph\AppData\Local\LMIR0004.tmp_r.bat
2017-08-11 13:07 - 2017-08-11 13:07 - 000000512 _____ () C:\Users\ralph\AppData\Local\LMIR0005.tmp_r.bat
EMPTYTEMP:
Reboot:
End::

  • Right click on the highlighted text and select Copy.
  • Start FRST (FRST64) with Administrator privileges
  • Press the Fix button. FRST will process the lines copied above from the clipboard.
  • When finished, a log file (Fixlog.txt) will pop up and saved in the same location the tool was ran from.

Please copy and paste its contents in your next reply.
 

  • Download AdwCleaner and move it to your Desktop
  • Right-click on AdwCleaner.exe and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Accept the EULA (I accept), then click on Scan
  • Let the scan complete. Once it's done, make sure that every item listed in the different tabs is checked and click on the Clean button. This will kill all active processes
    5ace519a6ff4a_Dashboard-firstrun.png.567
  • Once the cleaning process is complete, AdwCleaner will ask to restart your computer, do it
  • After the restart, a log will open when logging in. Please copy/paste the content of that log in your next reply

 


No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#3 rmw388

rmw388
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:04:34 PM

Posted 20 June 2018 - 11:04 AM

unfortunately Ive already done almost every thing you said not to do...

am including new files sorry for the trouble

and thanks for the quick response.

 

says msg too long. will insert FRSThere and another reply with Additional

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20.06.2018
Ran by ralph (administrator) on RWDESK (20-06-2018 10:34:52)
Running from C:\Users\ralph\Desktop
Loaded Profiles: ralph (Available Profiles: ralph & rw & Rward)
Platform: Windows 10 Home Version 1803 17134.112 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(HP) C:\Program Files\HP\HP LaserJet M1210 MFP Series\ReceiveFaxUtility.exe
(HP) C:\Windows\System32\HPSIsvc.exe
(Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.16.17656.18052-0\MsMpEng.exe
() C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(Acronis International GmbH) C:\Program Files (x86)\Common Files\Acronis\ActiveProtection\anti_ransomware_service.exe
() C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
(Acronis International GmbH) C:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
(McAfee, LLC) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\PEF\CORE\PEFService.exe
(McAfee, LLC) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHOST.exe
(McAfee, LLC) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\McAfee\MfeAV\MfeAVSvc.exe
(McAfee, LLC) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\VSCore_15_8\mcapexe.exe
(McAfee LLC.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\2.9.175.0\McCSPServiceHost.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
() C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
() C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\OpenWith.exe
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DW20.EXE
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
() C:\Windows\System32\Windows.WARP.JITService.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11804.1001.10.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(McAfee, Inc.) C:\Program Files\McAfee\VUL\McVulCtr.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(McAfee, Inc.) C:\Program Files\McAfee\VUL\McVulAlert.exe
(Microsoft Corporation) C:\Windows\System32\Speech_OneCore\common\SpeechRuntime.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-11] (Microsoft Corporation)
HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [585296 2017-11-22] ()
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [TrueImageMonitor.exe] => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [4630496 2018-04-03] ()
HKLM-x32\...\Run: [HPUsageTrackingLEDM] => "C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT LEDM\"
HKLM-x32\...\Run: [CMS] => C:\CMS\CMS.exe [109568 2016-06-23] (TODO: <公司名>)
HKLM-x32\...\Run: [AcronisTibMounterMonitor] => C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [425864 2017-02-14] (Acronis International GmbH)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [588704 2018-03-28] (Oracle Corporation)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2137744 2016-10-08] (Wondershare)
HKLM\...\RunOnce: [620_0176131549542] => C:\Program Files (x86)\LMIR0002.tmp_r.bat [514 2018-06-20] ()
HKLM\...\RunOnce: [620_745452260421] => C:\Program Files (x86)\LMIR0004.tmp_r.bat [514 2018-06-20] ()
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation)
HKU\S-1-5-21-444302225-3719607882-3466423754-1001\...\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2736128 2013-01-16] (Hewlett-Packard Company)
HKU\S-1-5-21-444302225-3719607882-3466423754-1001\...\Run: [ApplicationMonitor] => C:\Users\ralph\Downloads\appmonitor\ApplicationMonitor.exe [180224 2018-01-14] (JockerSoft)
HKU\S-1-5-21-444302225-3719607882-3466423754-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [18364648 2018-05-24] (Piriform Ltd)
HKU\S-1-5-21-444302225-3719607882-3466423754-1001\...\RunOnce: [620_0117321549542] => C:\Users\ralph\AppData\Local\LMIR0001.tmp_r.bat [512 2018-06-20] ()
HKU\S-1-5-21-444302225-3719607882-3466423754-1001\...\RunOnce: [620_7594472260421] => C:\Users\ralph\AppData\Local\LMIR0003.tmp_r.bat [512 2018-06-20] ()
BootExecute: autocheck autochk * 渀䘠汩獥
GroupPolicy: Restriction ? <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: 127.0.0.1    localhost
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{c26451a8-6f4e-4529-9d41-82d02fbaac25}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{fd7691e7-e31b-44b0-a38f-0cec9c0fb6a4}: [DhcpNameServer] 192.168.1.8

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-444302225-3719607882-3466423754-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\S-1-5-21-444302225-3719607882-3466423754-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE00
SearchScopes: HKU\S-1-5-21-444302225-3719607882-3466423754-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE00
SearchScopes: HKU\S-1-5-21-444302225-3719607882-3466423754-1001 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxps://nortonsafe.search.ask.com/web?q={searchTerms}&o=APN11913&l=dis&prt=NS&chn=1000&geo=US&ver=22.10.0.85&locale=en_US&guid=2296C450-1B55-4904-915F-5E438B5D401C&doi=2017-08-11&gct=kwd&qsrc=2869
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-06-19] (Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_171\bin\ssv.dll [2018-06-15] (Oracle Corporation)
BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2018-06-05] (McAfee, Inc.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_171\bin\jp2ssv.dll [2018-06-15] (Oracle Corporation)
BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2018-06-05] (McAfee, Inc.)
Toolbar: HKU\S-1-5-21-444302225-3719607882-3466423754-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Toolbar: HKU\S-1-5-21-444302225-3719607882-3466423754-1001 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -  No File
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-06-19] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-06-19] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-06-19] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-06-19] (Microsoft Corporation)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2018-06-05] (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2018-06-05] (McAfee, Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll [2018-05-08] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2018-05-08] (McAfee, Inc.)

FireFox:
========
FF DefaultProfile: upz7ca87.default
FF ProfilePath: C:\Users\ralph\AppData\Roaming\Mozilla\Firefox\Profiles\upz7ca87.default [2018-06-20]
FF Homepage: Mozilla\Firefox\Profiles\upz7ca87.default -> google.com
FF Extension: (Grammarly for Firefox) - C:\Users\ralph\AppData\Roaming\Mozilla\Firefox\Profiles\upz7ca87.default\Extensions\87677a2c52b84ad3a151a4a72f5bd3c4@jetpack.xpi [2018-06-08]
FF Extension: (Cisco WebEx Extension) - C:\Users\ralph\AppData\Roaming\Mozilla\Firefox\Profiles\upz7ca87.default\Extensions\ciscowebexstart1@cisco.com.xpi [2017-09-21]
FF Extension: (Privacy Badger) - C:\Users\ralph\AppData\Roaming\Mozilla\Firefox\Profiles\upz7ca87.default\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2018-06-08]
FF Extension: (TinEye Reverse Image Search) - C:\Users\ralph\AppData\Roaming\Mozilla\Firefox\Profiles\upz7ca87.default\Extensions\tineye@ideeinc.com.xpi [2017-09-27]
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi
FF Extension: (McAfee® WebAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi [2018-05-15]
FF HKLM-x32\...\Firefox\Extensions: [quickprint@hp.com] - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: (SmartPrintButton) - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension [2017-10-14] [Legacy] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_30_0_0_113.dll [2018-06-08] ()
FF Plugin: @java.com/DTPlugin,version=11.171.2 -> C:\Program Files\Java\jre1.8.0_171\bin\dtplugin\npDeployJava1.dll [2018-06-15] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.171.2 -> C:\Program Files\Java\jre1.8.0_171\bin\plugin2\npjp2.dll [2018-06-15] (Oracle Corporation)
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2018-05-08] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_30_0_0_113.dll [2018-06-08] ()
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2018-05-08] ()
FF Plugin-x32: @mcafee.com/MVT -> C:\Program Files (x86)\McAfee\Supportability\MVT\NPMVTPlugin.dll [2017-11-02] (McAfee LLC)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-06-19] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-10-27] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-10-27] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-06-08] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-06-08] (Google Inc.)

Chrome:
=======
CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?fr=mcafee&type=D211US1249G0&p={searchTerms}
CHR DefaultSearchKeyword: Default -> mcafee
CHR Profile: C:\Users\ralph\AppData\Local\Google\Chrome\User Data\Default [2018-06-20]
CHR Extension: (Slides) - C:\Users\ralph\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-13]
CHR Extension: (Docs) - C:\Users\ralph\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13]
CHR Extension: (Google Drive) - C:\Users\ralph\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-08-11]
CHR Extension: (YouTube) - C:\Users\ralph\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-08-11]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\ralph\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2018-06-19]
CHR Extension: (Cisco Webex Extension) - C:\Users\ralph\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlhmfgmfgeifomenelglieieghnjghma [2018-06-17]
CHR Extension: (Chrome Web Store Payments) - C:\Users\ralph\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-12]
CHR Extension: (Gmail) - C:\Users\ralph\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-08-11]
CHR Extension: (Chrome Media Router) - C:\Users\ralph\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-06-08]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AcronisActiveProtectionService; C:\Program Files (x86)\Common Files\Acronis\ActiveProtection\anti_ransomware_service.exe [2725920 2018-04-03] (Acronis International GmbH)
R2 AcrSch2Svc; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [1216760 2017-11-22] ()
S4 AdobeActiveFileMonitor14.0; C:\Program Files\Adobe\Elements 14 Organizer\PhotoshopElementsFileAgent.exe [226016 2015-12-07] (Adobe Systems Incorporated)
R2 afcdpsrv; C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [6096688 2018-04-10] ()
S4 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2257016 2017-08-23] (Adobe Systems, Incorporated)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8654504 2018-06-12] (Microsoft Corporation)
S3 ClientAnalyticsService; C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe [1508656 2018-05-03] (McAfee, Inc.)
S2 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [1194512 2018-06-06] (Garmin Ltd. or its subsidiaries)
S3 GSService; C:\WINDOWS\SysWOW64\GSService.exe [444640 2014-07-28] ()
R2 HPM1210RcvFaxSrvc; C:\Program Files\HP\HP LaserJet M1210 MFP Series\ReceiveFaxUtility.exe [361888 2012-07-25] (HP)
R2 ibtsiva; C:\WINDOWS\system32\ibtsiva.exe [183480 2017-02-27] (Intel Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
S4 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2013-01-16] (Hewlett-Packard Company) [File not signed]
R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [604824 2018-06-05] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_15_8\McApExe.exe [728808 2018-05-16] (McAfee, Inc.)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\2.9.175.0\\McCSPServiceHost.exe [2141912 2018-04-06] (McAfee, Inc.)
S3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [359888 2018-02-23] (McAfee, LLC)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [512976 2018-02-23] (McAfee, LLC)
R2 mfevtp; C:\WINDOWS\system32\mfevtps.exe [473040 2018-02-23] (McAfee, LLC)
R2 mmsminisrv; C:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe [4808088 2017-08-25] (Acronis International GmbH)
S3 mobile_backup_server; C:\Program Files (x86)\Common Files\Acronis\MobileBackupServer\mobile_backup_server.exe [3004128 2017-08-25] (Acronis International GmbH)
S3 mobile_backup_status_server; C:\Program Files (x86)\Acronis\TrueImageHome\mobile_backup_status_server.exe [1747304 2018-04-03] ()
R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1676024 2018-05-01] (McAfee, Inc.)
R2 PEFService; C:\Program Files\Common Files\McAfee\PEF\CORE\PEFService.exe [1047448 2018-05-07] (McAfee, Inc.)
S4 PowerAlert Agent; C:\Program Files (x86)\TrippLite\PowerAlert\engine\pal.exe [1655296 2014-09-09] (Tripp Lite) [File not signed]
S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
R2 syncagentsrv; C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [7003048 2017-09-26] ()
S4 Tib Mounter Service; C:\Program Files (x86)\Common Files\Acronis\TibMounter64\tib_mounter_service.exe [6774856 2017-07-19] (Acronis International GmbH)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.16.17656.18052-0\NisSrv.exe [4682552 2018-06-16] (Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.16.17656.18052-0\MsMpEng.exe [101096 2018-06-16] (Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [77224 2018-05-15] (McAfee, LLC)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.)
S3 epmntdrv; C:\WINDOWS\system32\epmntdrv.sys [33448 2016-12-07] ()
S3 epmntdrv; C:\WINDOWS\SysWOW64\epmntdrv.sys [21496 2016-01-14] ()
S3 EuGdiDrv; C:\WINDOWS\system32\EuGdiDrv.sys [10848 2016-07-11] () [File not signed]
S3 EuGdiDrv; C:\WINDOWS\SysWOW64\EuGdiDrv.sys [10208 2016-07-11] () [File not signed]
R2 file_protector; C:\WINDOWS\System32\DRIVERS\file_protector.sys [569392 2018-04-10] (Acronis International GmbH)
R0 file_tracker; C:\WINDOWS\System32\DRIVERS\file_tracker.sys [379664 2018-04-10] (Acronis International GmbH)
S3 HipShieldK; C:\WINDOWS\System32\drivers\HipShieldK.sys [226984 2018-05-02] (McAfee, Inc.)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [231944 2017-02-27] (Intel Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [253664 2018-06-19] (Malwarebytes)
R3 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [497568 2018-05-15] (McAfee, LLC)
R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [360352 2018-05-15] (McAfee, LLC)
U3 mfeavfk01; no ImagePath
U3 mfeavfk02; no ImagePath
S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [83952 2018-05-15] (McAfee, LLC)
R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [529312 2018-05-15] (McAfee, LLC)
R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [953248 2018-05-15] (McAfee, LLC)
R3 mfencbdc; C:\WINDOWS\system32\DRIVERS\mfencbdc.sys [543624 2018-04-30] (McAfee LLC.)
S3 mfencrk; C:\WINDOWS\system32\DRIVERS\mfencrk.sys [108432 2018-04-30] (McAfee LLC.)
R3 mfeplk; C:\WINDOWS\System32\drivers\mfeplk.sys [115616 2018-05-15] (McAfee, LLC)
R3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [111608 2017-02-14] (McAfee, Inc.)
R0 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [252832 2018-05-15] (McAfee, LLC)
R3 MusCAudio; C:\WINDOWS\system32\drivers\MusCAudio.sys [36064 2014-07-28] (Windows ® Win 7 DDK provider)
R3 NETwNb64; C:\WINDOWS\System32\drivers\Netwbw02.sys [3485696 2018-04-11] (Intel Corporation)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_2e7fa54192fe16d0\nvlddmkm.sys [16936048 2017-11-09] (NVIDIA Corporation)
R0 pwdrvio; C:\WINDOWS\System32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [12504 2013-09-30] ()
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd.)
R0 tib; C:\WINDOWS\System32\DRIVERS\tib.sys [1310552 2018-04-10] (Acronis International GmbH)
R2 tib_mounter; C:\WINDOWS\system32\DRIVERS\tib_mounter.sys [173328 2017-08-13] (Acronis International GmbH)
S3 tnd; C:\WINDOWS\system32\DRIVERS\tnd.sys [690520 2018-04-10] (Acronis International GmbH)
R2 virtual_file; C:\WINDOWS\System32\DRIVERS\virtual_file.sys [331976 2018-04-10] (Acronis International GmbH)
R0 volume_tracker; C:\WINDOWS\System32\DRIVERS\volume_tracker.sys [243472 2018-04-10] (Acronis International GmbH)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46072 2018-06-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [313384 2018-06-16] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [61992 2018-06-16] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-06-20 10:34 - 2018-06-20 10:36 - 000025166 _____ C:\Users\ralph\Desktop\FRST.txt
2018-06-20 10:34 - 2018-06-20 10:34 - 000000000 ____D C:\Users\ralph\Desktop\FRST-OlderVersion
2018-06-20 07:16 - 2018-06-20 07:16 - 000000016 _____ C:\Users\ralph\Documents\mcaffe3.txt
2018-06-20 07:15 - 2018-06-20 07:17 - 000005791 _____ C:\Users\ralph\Documents\mcaffe2.txt
2018-06-20 06:52 - 2018-06-20 06:52 - 002035240 _____ (LogMeIn, Inc.) C:\Users\ralph\Downloads\Support-LogMeInRescue(1).exe
2018-06-20 06:41 - 2018-06-20 10:21 - 000003606 _____ C:\WINDOWS\System32\Tasks\McAfee DAT Built in test
2018-06-20 06:41 - 2018-06-20 06:41 - 000000000 ____D C:\Users\ralph\AppData\Roaming\McAfee
2018-06-20 06:39 - 2018-06-20 06:39 - 000226136 _____ (McAfee LLC) C:\Users\ralph\Downloads\mvt.exe
2018-06-20 06:24 - 2018-06-20 06:24 - 002398688 _____ (McAfee, Inc.) C:\Users\ralph\Downloads\ProductDetection.exe
2018-06-20 00:26 - 2018-06-20 00:26 - 000045372 _____ C:\Users\ralph\Desktop\registry backup 620.reg
2018-06-20 00:18 - 2018-06-20 00:18 - 000000512 _____ C:\Users\ralph\AppData\Local\LMIR0001.tmp_r.bat
2018-06-20 00:13 - 2018-06-20 00:13 - 000000013 _____ C:\Users\ralph\Documents\june 20 case.txt
2018-06-20 00:09 - 2018-06-20 00:09 - 000000455 _____ C:\Users\ralph\Documents\rejoin link.txt
2018-06-19 23:53 - 2018-06-19 23:53 - 000000016 _____ C:\Users\ralph\Documents\google.txt
2018-06-19 23:37 - 2018-06-19 23:37 - 000002545 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2018-06-19 23:37 - 2018-06-19 23:37 - 000002544 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2018-06-19 23:37 - 2018-06-19 23:37 - 000002508 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2018-06-19 23:37 - 2018-06-19 23:37 - 000002507 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2018-06-19 23:37 - 2018-06-19 23:37 - 000002501 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2018-06-19 23:37 - 2018-06-19 23:37 - 000002495 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2018-06-19 23:37 - 2018-06-19 23:37 - 000002487 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2018-06-19 23:37 - 2018-06-19 23:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2018-06-19 23:35 - 2018-06-19 23:37 - 000000000 ____D C:\Program Files\Microsoft Office 15
2018-06-19 23:14 - 2018-06-19 23:14 - 004751648 _____ (Microsoft Corporation) C:\Users\ralph\Downloads\Setup.X86.en-US_O365HomePremRetail_01421663-f873-41c7-9246-2341c93454a4_TX_PR_.exe
2018-06-19 23:02 - 2018-06-19 23:02 - 000000000 ____D C:\Program Files\office.tmp
2018-06-19 21:34 - 2018-06-19 21:56 - 000000021 _____ C:\Users\ralph\Documents\1.txt
2018-06-19 21:32 - 2018-06-19 21:33 - 002205736 _____ (LogMeIn, Inc.) C:\Users\ralph\Downloads\Support-LogMeInRescue.exe
2018-06-19 19:54 - 2018-06-19 19:54 - 000309308 _____ C:\Users\ralph\Downloads\_Bexar County ARES Net Script160912(1).pdf
2018-06-19 19:51 - 2018-06-19 19:51 - 000000000 ____D C:\Users\ralph\AppData\LocalLow\Temp
2018-06-19 19:38 - 2018-06-19 19:38 - 001140177 _____ C:\Users\ralph\Documents\BEXAR ARES SCRIPT RAY AND ME AND DAVE.pdf
2018-06-19 19:28 - 2018-06-19 19:28 - 000253664 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2018-06-19 19:26 - 2018-06-19 19:26 - 000309308 _____ C:\Users\ralph\Downloads\_Bexar County ARES Net Script160912.pdf
2018-06-19 17:28 - 2018-06-19 17:28 - 000000292 _____ C:\Users\ralph\Documents\protected software.txt
2018-06-19 17:26 - 2018-06-19 17:26 - 000000698 _____ C:\Users\ralph\Documents\website blocked.txt
2018-06-19 17:02 - 2018-06-19 17:02 - 000172014 _____ C:\Users\ralph\Documents\m1run.txt
2018-06-19 13:53 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.850
2018-06-19 13:52 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.849
2018-06-19 13:52 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.848
2018-06-19 13:50 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.847
2018-06-19 13:48 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.846
2018-06-19 13:43 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.845
2018-06-19 13:41 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.844
2018-06-19 13:39 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.843
2018-06-19 13:37 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.842
2018-06-19 13:36 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.841
2018-06-19 13:36 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.840
2018-06-19 13:35 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.839
2018-06-19 13:35 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.838
2018-06-19 13:35 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.837
2018-06-19 13:34 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.836
2018-06-19 13:34 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.835
2018-06-19 13:34 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.834
2018-06-19 13:33 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.833
2018-06-19 13:33 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.832
2018-06-19 13:32 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.831
2018-06-19 13:32 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.830
2018-06-19 13:32 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.829
2018-06-19 13:32 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.828
2018-06-19 13:31 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.827
2018-06-19 13:31 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.826
2018-06-19 13:30 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.825
2018-06-19 13:30 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.824
2018-06-19 13:30 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.823
2018-06-19 13:29 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.822
2018-06-19 13:29 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.821
2018-06-19 13:29 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.820
2018-06-19 13:27 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.819
2018-06-19 13:18 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.818
2018-06-19 13:17 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.817
2018-06-19 13:17 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.816
2018-06-19 13:17 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.815
2018-06-19 13:17 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.814
2018-06-19 13:16 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.813
2018-06-19 13:16 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.812
2018-06-19 13:16 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.811
2018-06-19 13:15 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.810
2018-06-19 13:15 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.809
2018-06-19 13:15 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.808
2018-06-19 13:14 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.807
2018-06-19 13:14 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.806
2018-06-19 13:14 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.805
2018-06-19 13:14 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.804
2018-06-19 13:13 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.803
2018-06-19 13:13 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.802
2018-06-19 13:13 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.801
2018-06-19 13:12 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.800
2018-06-19 13:12 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.799
2018-06-19 13:12 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.798
2018-06-19 13:11 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.797
2018-06-19 13:11 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.796
2018-06-19 13:11 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.795
2018-06-19 13:10 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.794
2018-06-19 13:10 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.793
2018-06-19 13:10 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.792
2018-06-19 13:09 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.791
2018-06-19 13:09 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.790
2018-06-19 13:09 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.789
2018-06-19 13:08 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.788
2018-06-19 13:08 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.787
2018-06-19 13:08 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.786
2018-06-19 13:07 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.785
2018-06-19 13:07 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.784
2018-06-19 13:07 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.783
2018-06-19 13:06 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.782
2018-06-19 13:06 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.781
2018-06-19 13:06 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.780
2018-06-19 13:05 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.779
2018-06-19 13:05 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.778
2018-06-19 13:05 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.777
2018-06-19 13:04 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.776
2018-06-19 13:04 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.775
2018-06-19 13:04 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.774
2018-06-19 13:04 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.773
2018-06-19 13:03 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.772
2018-06-19 13:03 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.771
2018-06-19 13:02 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.770
2018-06-19 13:02 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.769
2018-06-19 13:02 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.768
2018-06-19 13:00 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.767
2018-06-19 12:58 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.766
2018-06-19 12:57 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.765
2018-06-19 12:56 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.764
2018-06-19 12:54 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.763
2018-06-19 12:53 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.762
2018-06-19 12:53 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.761
2018-06-19 12:52 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.760
2018-06-19 12:52 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.759
2018-06-19 12:48 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.758
2018-06-19 12:48 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.757
2018-06-19 12:48 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.756
2018-06-19 12:47 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.755
2018-06-19 12:47 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.754
2018-06-19 12:47 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.753
2018-06-19 12:46 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.752
2018-06-19 12:46 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.751
2018-06-19 12:46 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.750
2018-06-19 12:46 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.749
2018-06-19 12:45 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.748
2018-06-19 12:45 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.747
2018-06-19 12:45 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.746
2018-06-19 12:44 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.745
2018-06-19 12:44 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.744
2018-06-19 12:44 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.743
2018-06-19 12:43 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.742
2018-06-19 12:43 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.741
2018-06-19 12:42 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.740
2018-06-19 12:42 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.739
2018-06-19 12:42 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.738
2018-06-19 12:41 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.737
2018-06-19 12:41 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.736
2018-06-19 12:41 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.735
2018-06-19 12:40 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.734
2018-06-19 12:40 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.733
2018-06-19 12:40 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.732
2018-06-19 12:39 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.731
2018-06-19 12:39 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.730
2018-06-19 12:39 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.729
2018-06-19 12:38 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.728
2018-06-19 12:38 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.727
2018-06-19 12:38 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.726
2018-06-19 12:38 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.725
2018-06-19 12:37 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.724
2018-06-19 12:37 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.723
2018-06-19 12:37 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.722
2018-06-19 12:36 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.721
2018-06-19 12:36 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.720
2018-06-19 12:35 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.719
2018-06-19 12:35 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.718
2018-06-19 12:35 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.717
2018-06-19 12:34 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.716
2018-06-19 12:34 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.715
2018-06-19 12:34 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.714
2018-06-19 12:33 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.713
2018-06-19 12:33 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.712
2018-06-19 12:32 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.711
2018-06-19 12:32 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.710
2018-06-19 12:32 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.709
2018-06-19 12:31 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.708
2018-06-19 12:31 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.707
2018-06-19 12:31 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.706
2018-06-19 12:30 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.705
2018-06-19 12:30 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.704
2018-06-19 12:30 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.703
2018-06-19 12:29 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.702
2018-06-19 12:29 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.701
2018-06-19 12:29 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.700
2018-06-19 12:28 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.699
2018-06-19 12:28 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.698
2018-06-19 12:28 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.697
2018-06-19 12:27 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.696
2018-06-19 12:27 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.695
2018-06-19 12:27 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.694
2018-06-19 12:26 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.693
2018-06-19 12:26 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.692
2018-06-19 12:25 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.691
2018-06-19 12:25 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.690
2018-06-19 12:25 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.689
2018-06-19 12:24 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.688
2018-06-19 12:24 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.687
2018-06-19 12:24 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.686
2018-06-19 12:23 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.685
2018-06-19 12:23 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.684
2018-06-19 12:22 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.683
2018-06-19 12:22 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.682
2018-06-19 12:22 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.681
2018-06-19 12:21 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.680
2018-06-19 12:21 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.679
2018-06-19 12:21 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.678
2018-06-19 12:20 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.677
2018-06-19 12:20 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.676
2018-06-19 12:20 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.675
2018-06-19 12:19 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.674
2018-06-19 12:19 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.673
2018-06-19 12:19 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.672
2018-06-19 12:18 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.671
2018-06-19 12:15 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.670
2018-06-19 12:15 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.669
2018-06-19 12:15 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.668
2018-06-19 12:15 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.667
2018-06-19 12:14 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.666
2018-06-19 12:14 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.665
2018-06-19 12:14 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.664
2018-06-19 12:13 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.663
2018-06-19 12:13 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.662
2018-06-19 12:13 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.661
2018-06-19 12:12 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.660
2018-06-19 12:12 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.659
2018-06-19 12:12 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.658
2018-06-19 12:11 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.657
2018-06-19 12:11 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.656
2018-06-19 12:11 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.655
2018-06-19 12:10 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.654
2018-06-19 12:10 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.653
2018-06-19 12:10 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.652
2018-06-19 12:08 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.651
2018-06-19 12:08 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.650
2018-06-19 12:07 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.649
2018-06-19 12:07 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.648
2018-06-19 12:07 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.647
2018-06-19 12:06 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.646
2018-06-19 12:06 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.645
2018-06-19 12:05 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.644
2018-06-19 12:05 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.643
2018-06-19 12:05 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.642
2018-06-19 12:04 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.641
2018-06-19 12:04 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.640
2018-06-19 12:04 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.639
2018-06-19 12:03 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.638
2018-06-19 12:03 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.637
2018-06-19 12:03 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.636
2018-06-19 12:02 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.635
2018-06-19 12:02 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.634
2018-06-19 12:02 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.633
2018-06-19 12:01 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.632
2018-06-19 12:01 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.631
2018-06-19 12:01 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.630
2018-06-19 12:01 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.629
2018-06-19 12:00 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.628
2018-06-19 12:00 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.627
2018-06-19 12:00 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.626
2018-06-19 11:59 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.625
2018-06-19 11:59 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.624
2018-06-19 11:59 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.623
2018-06-19 11:58 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.622
2018-06-19 11:58 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.621
2018-06-19 11:58 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.620
2018-06-19 11:57 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.619
2018-06-19 11:57 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.618
2018-06-19 11:57 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.617
2018-06-19 11:56 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.616
2018-06-19 11:56 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.615
2018-06-19 11:56 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.614
2018-06-19 11:55 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.613
2018-06-19 11:55 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.612
2018-06-19 11:55 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.611
2018-06-19 11:54 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.610
2018-06-19 11:54 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.609
2018-06-19 11:54 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.608
2018-06-19 11:53 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.607
2018-06-19 11:53 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.606
2018-06-19 11:53 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.605
2018-06-19 11:52 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.604
2018-06-19 11:52 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.603
2018-06-19 11:52 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.602
2018-06-19 11:51 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.601
2018-06-19 11:51 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.600
2018-06-19 11:51 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.599
2018-06-19 11:50 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.598
2018-06-19 11:50 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.597
2018-06-19 11:50 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.596
2018-06-19 11:49 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.595
2018-06-19 11:49 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.594
2018-06-19 11:49 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.593
2018-06-19 11:48 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.592
2018-06-19 11:48 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.591
2018-06-19 11:48 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.590
2018-06-19 11:47 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.589
2018-06-19 11:47 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.588
2018-06-19 11:47 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.587
2018-06-19 11:46 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.586
2018-06-19 11:46 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.585
2018-06-19 11:45 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.584
2018-06-19 11:45 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.583
2018-06-19 11:45 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.582
2018-06-19 11:44 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.581
2018-06-19 11:44 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.580
2018-06-19 11:44 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.579
2018-06-19 11:43 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.578
2018-06-19 11:43 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.577
2018-06-19 11:43 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.576
2018-06-19 11:43 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.575
2018-06-19 11:42 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.574
2018-06-19 11:42 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.573
2018-06-19 11:42 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.572
2018-06-19 11:41 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.571
2018-06-19 11:41 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.570
2018-06-19 11:41 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.569
2018-06-19 11:40 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.568
2018-06-19 11:40 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.567
2018-06-19 11:40 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.566
2018-06-19 11:39 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.565
2018-06-19 11:39 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.564
2018-06-19 11:39 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.563
2018-06-19 11:38 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.562
2018-06-19 11:38 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.561
2018-06-19 11:38 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.560
2018-06-19 11:37 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.559
2018-06-19 11:37 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.558
2018-06-19 11:37 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.557
2018-06-19 11:36 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.556
2018-06-19 11:36 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.555
2018-06-19 11:36 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.554
2018-06-19 11:35 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.553
2018-06-19 11:35 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.552
2018-06-19 11:35 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.551
2018-06-19 11:34 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.550
2018-06-19 11:34 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.549
2018-06-19 11:34 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.548
2018-06-19 11:33 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.547
2018-06-19 11:33 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.546
2018-06-19 11:33 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.545
2018-06-19 11:32 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.544
2018-06-19 11:32 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.543
2018-06-19 11:32 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.542
2018-06-19 11:31 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.541
2018-06-19 11:31 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.540
2018-06-19 11:31 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.539
2018-06-19 11:30 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.538
2018-06-19 11:30 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.537
2018-06-19 11:30 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.536
2018-06-19 11:29 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.535
2018-06-19 11:29 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.534
2018-06-19 11:29 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.533
2018-06-19 11:28 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.532
2018-06-19 11:28 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.531
2018-06-19 11:28 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.530
2018-06-19 11:27 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.529
2018-06-19 11:27 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.528
2018-06-19 11:27 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.527
2018-06-19 11:26 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.526
2018-06-19 11:26 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.525
2018-06-19 11:26 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.524
2018-06-19 11:25 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.523
2018-06-19 11:25 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.522
2018-06-19 11:25 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.521
2018-06-19 11:25 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.520
2018-06-19 11:24 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.519
2018-06-19 11:24 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.518
2018-06-19 11:24 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.517
2018-06-19 11:23 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.516
2018-06-19 11:23 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.515
2018-06-19 11:23 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.514
2018-06-19 11:23 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.513
2018-06-19 11:22 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.512
2018-06-19 11:22 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.511
2018-06-19 11:22 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.510
2018-06-19 11:21 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.509
2018-06-19 11:21 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.508
2018-06-19 11:21 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.507
2018-06-19 11:21 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.506
2018-06-19 11:20 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.505
2018-06-19 11:20 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.504
2018-06-19 11:19 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.503
2018-06-19 11:19 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.502
2018-06-19 11:19 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.501
2018-06-19 11:18 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.500
2018-06-19 11:18 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.499
2018-06-19 11:18 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.498
2018-06-19 11:17 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.497
2018-06-19 11:17 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.496
2018-06-19 11:17 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.495
2018-06-19 11:16 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.494
2018-06-19 11:16 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.493
2018-06-19 11:16 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.492
2018-06-19 11:15 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.491
2018-06-19 11:15 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.490
2018-06-19 11:15 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.489
2018-06-19 11:14 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.488
2018-06-19 11:14 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.487
2018-06-19 11:14 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.486
2018-06-19 11:14 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.485
2018-06-19 11:13 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.484
2018-06-19 11:13 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.483
2018-06-19 11:13 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.482
2018-06-19 11:12 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.481
2018-06-19 11:12 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.480
2018-06-19 11:12 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.479
2018-06-19 11:11 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.478
2018-06-19 11:11 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.477
2018-06-19 11:11 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.476
2018-06-19 11:10 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.475
2018-06-19 11:06 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.474
2018-06-19 11:02 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.473
2018-06-19 11:01 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.472
2018-06-19 11:00 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.471
2018-06-19 10:59 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.470
2018-06-19 10:59 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.469
2018-06-19 10:58 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.468
2018-06-19 10:57 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.467
2018-06-19 10:56 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.466
2018-06-19 10:55 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.465
2018-06-19 10:54 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.464
2018-06-19 10:54 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.463
2018-06-19 10:49 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.462
2018-06-19 10:41 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.461
2018-06-19 10:39 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.460
2018-06-19 10:38 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.459
2018-06-19 10:38 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.458
2018-06-19 10:37 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.457
2018-06-19 10:37 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.456
2018-06-19 10:37 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.455
2018-06-19 10:37 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.454
2018-06-19 10:36 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.453
2018-06-19 10:36 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.452
2018-06-19 10:36 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.451
2018-06-19 10:36 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.450
2018-06-19 10:36 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.449
2018-06-19 10:35 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.448
2018-06-19 10:35 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.447
2018-06-19 10:35 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.446
2018-06-19 10:35 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.445
2018-06-19 10:35 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.444
2018-06-19 10:34 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.443
2018-06-19 10:34 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.442
2018-06-19 10:33 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.441
2018-06-19 10:33 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.440
2018-06-19 10:33 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.439
2018-06-19 10:33 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.438
2018-06-19 10:32 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.437
2018-06-19 10:32 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.436
2018-06-19 10:32 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.435
2018-06-19 10:32 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.434
2018-06-19 10:31 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.433
2018-06-19 10:31 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.432
2018-06-19 10:31 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.431
2018-06-19 10:31 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.430
2018-06-19 10:31 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.429
2018-06-19 10:30 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.428
2018-06-19 10:30 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.427
2018-06-19 10:30 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.426
2018-06-19 10:30 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.425
2018-06-19 10:29 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.424
2018-06-19 10:29 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.423
2018-06-19 10:28 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.422
2018-06-19 10:28 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.421
2018-06-19 10:28 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.420
2018-06-19 10:28 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.419
2018-06-19 10:28 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.418
2018-06-19 10:27 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.417
2018-06-19 10:27 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.416
2018-06-19 10:27 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.415
2018-06-19 10:25 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.414
2018-06-19 10:22 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.413
2018-06-19 10:18 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.412
2018-06-19 10:16 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.411
2018-06-19 10:15 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.410
2018-06-19 10:13 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.409
2018-06-19 10:12 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.408
2018-06-19 10:11 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.407
2018-06-19 10:10 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.406
2018-06-19 10:10 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.405
2018-06-19 10:08 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.404
2018-06-19 10:07 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.403
2018-06-19 10:05 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.402
2018-06-19 10:03 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.401
2018-06-19 10:02 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.400
2018-06-19 10:01 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.399
2018-06-19 10:01 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.398
2018-06-19 10:00 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.397
2018-06-19 09:58 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.396
2018-06-19 09:55 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.395
2018-06-19 09:53 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.394
2018-06-19 09:52 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.393
2018-06-19 09:50 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.392
2018-06-19 09:49 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.391
2018-06-19 09:48 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.390
2018-06-19 09:47 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.389
2018-06-19 09:46 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.388
2018-06-19 09:44 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.387
2018-06-19 09:43 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.386
2018-06-19 09:41 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.385
2018-06-19 09:38 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.384
2018-06-19 09:35 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.383
2018-06-19 09:32 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.382
2018-06-19 09:31 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.381
2018-06-19 09:30 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.380
2018-06-19 09:28 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.379
2018-06-19 09:26 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.378
2018-06-19 09:26 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.377
2018-06-19 09:24 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.376
2018-06-19 09:22 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.375
2018-06-19 09:20 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.374
2018-06-19 09:18 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.373
2018-06-19 09:16 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.372
2018-06-19 09:14 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.371
2018-06-19 09:11 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.370
2018-06-19 09:08 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.369
2018-06-19 09:05 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.368
2018-06-19 09:04 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.367
2018-06-19 09:03 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.366
2018-06-19 09:02 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.365
2018-06-19 08:59 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.364
2018-06-19 08:58 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.363
2018-06-19 08:58 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.362
2018-06-19 08:57 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.361
2018-06-19 08:55 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.360
2018-06-19 08:55 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.359
2018-06-19 08:54 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.358
2018-06-19 08:54 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.357
2018-06-19 08:53 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.356
2018-06-19 08:51 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.355
2018-06-19 08:48 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.354
2018-06-19 08:46 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.353
2018-06-19 08:42 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.352
2018-06-19 08:37 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.351
2018-06-19 08:36 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.350
2018-06-19 08:35 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.349
2018-06-19 08:35 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.348
2018-06-19 08:34 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.347
2018-06-19 08:34 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.346
2018-06-19 08:33 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.345
2018-06-19 08:32 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.344
2018-06-19 08:32 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.343
2018-06-19 08:31 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.342
2018-06-19 08:30 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.341
2018-06-19 08:30 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.340
2018-06-19 08:28 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.339
2018-06-19 08:22 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.338
2018-06-19 08:16 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.337
2018-06-19 08:14 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.336
2018-06-19 08:12 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.335
2018-06-19 08:11 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.334
2018-06-19 08:10 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.333
2018-06-19 08:09 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.332
2018-06-19 08:08 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.331
2018-06-19 08:07 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.330
2018-06-19 08:05 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.329
2018-06-19 08:01 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.328
2018-06-19 07:59 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.327
2018-06-19 07:55 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.326
2018-06-19 07:54 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.325
2018-06-19 07:53 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.324
2018-06-19 07:47 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.323
2018-06-19 07:43 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.322
2018-06-19 07:39 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.321
2018-06-19 07:36 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.320
2018-06-19 07:34 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.319
2018-06-19 07:33 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.318
2018-06-19 07:29 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.317
2018-06-19 07:28 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.316
2018-06-19 07:26 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.315
2018-06-19 07:24 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.314
2018-06-19 07:23 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.313
2018-06-19 07:20 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.312
2018-06-19 07:19 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.311
2018-06-19 07:19 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.310
2018-06-19 07:12 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.309
2018-06-19 07:11 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.308
2018-06-19 07:11 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.307
2018-06-19 07:11 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.306
2018-06-19 07:11 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.305
2018-06-19 07:08 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.304
2018-06-19 07:07 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.303
2018-06-19 07:05 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.302
2018-06-19 07:00 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.301
2018-06-19 06:47 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.300
2018-06-19 06:32 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.299
2018-06-19 06:23 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.298
2018-06-19 06:23 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.297
2018-06-19 06:23 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.296
2018-06-19 06:22 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.295
2018-06-19 06:22 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.294
2018-06-19 06:21 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.293
2018-06-19 06:21 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.292
2018-06-19 06:21 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.291
2018-06-19 06:20 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.290
2018-06-19 06:20 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.289
2018-06-19 06:18 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.288
2018-06-19 06:18 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.287
2018-06-19 06:16 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.286
2018-06-19 06:15 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.285
2018-06-19 06:15 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.284
2018-06-19 06:13 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.283
2018-06-19 06:13 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.282
2018-06-19 06:12 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.281
2018-06-19 06:11 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.280
2018-06-19 06:11 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.279
2018-06-19 06:10 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.278
2018-06-19 06:09 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.277
2018-06-19 06:08 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.276
2018-06-19 06:08 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.275
2018-06-19 06:07 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.274
2018-06-19 06:06 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.273
2018-06-19 06:05 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.272
2018-06-19 06:05 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.271
2018-06-19 06:04 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.270
2018-06-19 06:04 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.269
2018-06-19 06:03 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.268
2018-06-19 06:03 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.267
2018-06-19 06:02 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.266
2018-06-19 06:02 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.265
2018-06-19 06:01 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.264
2018-06-19 06:01 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.263
2018-06-19 06:00 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.262
2018-06-19 06:00 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.261
2018-06-19 05:59 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.260
2018-06-19 05:59 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.259
2018-06-19 05:58 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.258
2018-06-19 05:58 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.257
2018-06-19 05:57 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.256
2018-06-19 05:57 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.255
2018-06-19 05:56 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.254
2018-06-19 05:56 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.253
2018-06-19 00:45 - 2018-06-19 00:46 - 078101496 _____ (Malwarebytes ) C:\Users\ralph\Downloads\mb3-setup-consumer-3.5.1.2522-1.0.374-1.0.5526 (1).exe
2018-06-19 00:31 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.002
2018-06-19 00:30 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.001
2018-06-19 00:26 - 2018-06-19 20:17 - 688128000 _____ C:\Users\ralph\Documents\Drive_C.dat
2018-06-19 00:26 - 2018-06-19 20:17 - 004206592 _____ C:\Users\ralph\Documents\Drive_C.xml
2018-06-18 22:00 - 2018-06-18 22:00 - 000184550 _____ C:\ProgramData\cl.uninstall.1529376862.bdinstall.bin
2018-06-18 22:00 - 2018-06-18 22:00 - 000025578 _____ C:\ProgramData\agent.uninstall.1529377232.bdinstall.bin
2018-06-18 21:55 - 2018-06-18 21:55 - 000036639 _____ C:\ProgramData\dm.uninstall.1529376901.bdinstall.bin
2018-06-18 21:44 - 2018-06-20 06:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2018-06-18 21:44 - 2018-06-18 21:44 - 000002121 _____ C:\Users\Public\Desktop\McAfee® Total Protection.lnk
2018-06-18 21:41 - 2018-06-18 21:41 - 000001422 _____ C:\Users\ralph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\McAfee WebAdvisor.lnk
2018-06-18 21:41 - 2018-05-02 05:53 - 000226984 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\HipShieldK.sys
2018-06-18 21:27 - 2018-06-18 21:29 - 000003142 _____ C:\WINDOWS\System32\Tasks\McAfeeLogon
2018-06-18 21:20 - 2018-06-18 21:45 - 000000000 ____D C:\Program Files\McAfee
2018-06-18 21:20 - 2018-06-18 21:20 - 000000000 ____D C:\Program Files\McAfee.com
2018-06-18 21:12 - 2018-06-19 00:10 - 000000000 ____D C:\WINDOWS\System32\Tasks\McAfee
2018-06-18 21:06 - 2018-06-18 22:06 - 000003446 _____ C:\WINDOWS\System32\Tasks\McAfee Remediation (Prepare)
2018-06-18 21:05 - 2018-06-20 06:40 - 000000000 ____D C:\Program Files (x86)\McAfee
2018-06-18 20:57 - 2018-06-20 06:40 - 000000000 ____D C:\ProgramData\McAfee
2018-06-18 20:57 - 2018-06-18 21:42 - 000000000 ____D C:\Program Files\Common Files\McAfee
2018-06-18 20:57 - 2018-02-23 15:37 - 000473040 _____ (McAfee, LLC) C:\WINDOWS\system32\mfevtps.exe
2018-06-18 20:56 - 2018-06-18 20:56 - 037516464 _____ (McAfee, Inc.) C:\Users\ralph\Downloads\Setup_serial_ZmzTUSX5bRL3TaRXfMRwQQ2_key_affid_1249_akey.exe
2018-06-18 20:56 - 2018-06-18 20:56 - 000000046 _____ C:\Users\ralph\Documents\mcaffee.txt
2018-06-18 20:18 - 2018-06-18 20:21 - 000053570 _____ C:\Users\ralph\Desktop\1Addition (1).txt
2018-06-18 20:04 - 2018-06-18 20:21 - 000131285 _____ C:\Users\ralph\Desktop\1Addition (2).txt
2018-06-18 19:58 - 2018-06-20 10:34 - 002412544 _____ (Farbar) C:\Users\ralph\Desktop\FRST64.exe
2018-06-18 19:58 - 2018-06-20 10:34 - 000000000 ____D C:\FRST
2018-06-18 19:57 - 2018-06-18 19:57 - 002413056 _____ (Farbar) C:\Users\ralph\Downloads\FRST64.exe
2018-06-18 18:59 - 2018-06-19 00:03 - 000001232 _____ C:\Users\Public\Desktop\DriveImage XML.lnk
2018-06-18 18:59 - 2018-06-19 00:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Runtime Software
2018-06-18 18:59 - 2018-06-18 18:59 - 000000000 ____D C:\Program Files (x86)\Runtime Software
2018-06-18 18:57 - 2018-06-18 18:55 - 002023440 _____ C:\Users\ralph\Desktop\dixmlsetup.exe
2018-06-18 18:55 - 2018-06-18 18:55 - 002023440 _____ C:\Users\ralph\Downloads\dixmlsetup.exe
2018-06-18 18:21 - 2018-06-18 18:32 - 000001944 _____ C:\Users\ralph\Desktop\Rkill.txt
2018-06-18 18:19 - 2018-06-18 18:19 - 001802704 _____ (Bleeping Computer, LLC) C:\Users\ralph\Downloads\rkill.exe
2018-06-18 16:25 - 2018-06-18 16:25 - 078101496 _____ (Malwarebytes ) C:\Users\ralph\Downloads\mb3-setup-consumer-3.5.1.2522-1.0.374-1.0.5526.exe
2018-06-18 16:09 - 2018-06-18 15:05 - 000321116 _____ C:\Users\ralph\Desktop\1529295600_1_02.xml
2018-06-18 15:46 - 2018-06-18 15:46 - 000002333 _____ C:\Users\ralph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Suite.lnk
2018-06-18 15:46 - 2018-06-18 15:46 - 000002125 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Suite.lnk
2018-06-18 15:46 - 2018-06-18 15:46 - 000001361 _____ C:\Users\Public\Desktop\NCH Suite.lnk
2018-06-18 15:46 - 2018-06-18 15:46 - 000001243 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prism Video File Converter.lnk
2018-06-18 15:46 - 2018-06-18 15:46 - 000001231 _____ C:\Users\Public\Desktop\Prism Video File Converter.lnk
2018-06-18 15:46 - 2018-06-18 15:46 - 000000000 ____D C:\WINDOWS\System32\Tasks\NCH Software
2018-06-18 15:36 - 2018-06-18 15:39 - 000000000 ____D C:\Users\ralph\Desktop\music from b55
2018-06-18 15:02 - 2018-06-18 15:02 - 000009364 _____ C:\Users\ralph\AppData\Roaming\Comma Separated Values.EML
2018-06-18 14:12 - 2018-06-18 14:12 - 000458752 _____ C:\Users\ralph\Documents\14JUN2018  Bexar County CERT Team Meeting Autosaved1.ppt
2018-06-17 22:57 - 2018-06-18 19:36 - 000004142 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{31220534-A8BD-4D0D-A432-06B26A5088FB}
2018-06-17 20:21 - 2018-06-17 20:21 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2018-06-17 20:07 - 2018-06-17 20:07 - 000000000 ____D C:\ProgramData\HPSSUPPLY
2018-06-17 20:03 - 2012-09-29 13:26 - 001366528 _____ C:\WINDOWS\system32\HPM1210SM.exe
2018-06-17 20:03 - 2012-09-29 13:05 - 000350720 _____ C:\WINDOWS\system32\mvhlewsi.DLL
2018-06-17 19:58 - 2018-06-17 19:58 - 000000827 _____ C:\Users\ralph\Documents\bitdefender.txt
2018-06-17 19:52 - 2018-06-17 19:53 - 000248832 _____ C:\Users\ralph\Downloads\reset_password.exe
2018-06-17 19:48 - 2017-10-19 10:17 - 000271360 _____ (Wondershare Software) C:\WINDOWS\system32\WSPDFelementMonitor.dll
2018-06-17 19:40 - 2018-06-17 19:55 - 000000000 ____D C:\Users\ralph\AppData\Roaming\Wondershare
2018-06-17 19:40 - 2018-06-17 19:40 - 000001413 _____ C:\Users\Public\Desktop\PDFelement 6 Pro.lnk
2018-06-17 19:40 - 2018-06-17 19:40 - 000000000 ____D C:\ProgramData\PDFelement 6 Pro
2018-06-17 19:40 - 2018-06-17 19:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
2018-06-17 19:36 - 2018-06-17 19:36 - 000000149 _____ C:\Users\ralph\Documents\ms url.txt
2018-06-17 18:22 - 2018-06-17 18:22 - 000000000 ____D C:\ProgramData\Packages
2018-06-17 18:21 - 2018-06-17 18:21 - 000000000 ____D C:\Users\rw.DESKTOP-84BFGSO\AppData\Roaming\QuickScan
2018-06-17 18:19 - 2018-06-17 18:19 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2018-06-17 18:17 - 2018-06-17 18:20 - 000000000 ____D C:\Users\rw.DESKTOP-84BFGSO\AppData\Roaming\Bitdefender
2018-06-17 18:04 - 2018-06-17 18:04 - 000000000 ___RD C:\Users\rw.DESKTOP-84BFGSO\3D Objects
2018-06-17 18:03 - 2018-06-17 18:03 - 000000020 ___SH C:\Users\rw.DESKTOP-84BFGSO\ntuser.ini
2018-06-17 17:52 - 2018-06-17 17:52 - 000986728 _____ C:\Users\ralph\Downloads\pdfelement6-pro_setup_full2996.exe
2018-06-17 16:51 - 2018-06-17 16:51 - 000030225 _____ C:\Users\ralph\Downloads\g.csv
2018-06-16 16:33 - 2018-06-16 16:33 - 000013365 _____ C:\Users\ralph\Desktop\rw contacts2.CSV
2018-06-16 16:32 - 2018-06-16 16:32 - 000013365 _____ C:\Users\ralph\Documents\rw contacts2.CSV
2018-06-16 12:50 - 2018-06-16 12:50 - 000003624 _____ C:\WINDOWS\System32\Tasks\GarminUpdaterTask
2018-06-16 12:50 - 2018-06-16 12:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
2018-06-16 12:50 - 2018-06-16 12:50 - 000000000 ____D C:\ProgramData\Garmin
2018-06-16 12:47 - 2018-06-16 12:47 - 083792120 _____ (Garmin Ltd or its subsidiaries) C:\Users\ralph\Downloads\GarminExpress(1).exe
2018-06-16 09:46 - 2018-06-19 00:05 - 100925440 _____ C:\WINDOWS\system32\config\SOFTWARE
2018-06-16 06:26 - 2018-06-08 14:02 - 004527680 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2018-06-16 06:26 - 2018-06-08 14:01 - 002395056 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
2018-06-16 06:26 - 2018-06-08 13:45 - 012712448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2018-06-16 06:26 - 2018-06-08 13:45 - 004392448 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2018-06-16 06:26 - 2018-06-08 13:43 - 002922496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2018-06-16 06:26 - 2018-06-08 13:42 - 003653120 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-06-16 06:26 - 2018-06-08 11:51 - 011903488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2018-06-16 06:26 - 2018-06-08 05:37 - 002417840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2018-06-16 06:26 - 2018-06-08 05:31 - 007900984 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2018-06-16 06:26 - 2018-06-08 05:31 - 003180176 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2018-06-16 06:26 - 2018-06-08 04:33 - 001034632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2018-06-16 06:26 - 2018-06-08 04:30 - 009148320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-06-16 06:26 - 2018-06-08 04:30 - 003296896 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2018-06-16 06:26 - 2018-06-08 04:30 - 001798552 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2018-06-16 06:26 - 2018-06-08 04:30 - 001017080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2adec.dll
2018-06-16 06:26 - 2018-06-08 04:29 - 007520000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-06-16 06:26 - 2018-06-08 04:29 - 006817384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2018-06-16 06:26 - 2018-06-08 04:29 - 004970360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2018-06-16 06:26 - 2018-06-08 04:29 - 004403280 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2018-06-16 06:26 - 2018-06-08 04:29 - 003283408 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll
2018-06-16 06:26 - 2018-06-08 04:29 - 002753048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2018-06-16 06:26 - 2018-06-08 04:29 - 002570712 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2018-06-16 06:26 - 2018-06-08 04:29 - 002462272 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2018-06-16 06:26 - 2018-06-08 04:29 - 002371392 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2018-06-16 06:26 - 2018-06-08 04:29 - 001784584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2018-06-16 06:26 - 2018-06-08 04:29 - 001611592 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2018-06-16 06:26 - 2018-06-08 04:13 - 025846784 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-06-16 06:26 - 2018-06-08 04:12 - 000861616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2adec.dll
2018-06-16 06:26 - 2018-06-08 04:10 - 002479272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2018-06-16 06:26 - 2018-06-08 04:10 - 002331584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2018-06-16 06:26 - 2018-06-08 04:10 - 000457152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAudDecMFT.dll
2018-06-16 06:26 - 2018-06-08 04:09 - 006569960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-06-16 06:26 - 2018-06-08 04:09 - 006527064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2018-06-16 06:26 - 2018-06-08 04:09 - 004788512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2018-06-16 06:26 - 2018-06-08 04:09 - 004469832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2018-06-16 06:26 - 2018-06-08 04:09 - 001980872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2018-06-16 06:26 - 2018-06-08 04:09 - 001709720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2018-06-16 06:26 - 2018-06-08 04:09 - 001380200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2018-06-16 06:26 - 2018-06-08 04:09 - 001020168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2018-06-16 06:26 - 2018-06-08 04:04 - 004706816 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2018-06-16 06:26 - 2018-06-08 04:03 - 022005760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2018-06-16 06:26 - 2018-06-08 04:02 - 022713856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-06-16 06:26 - 2018-06-08 04:01 - 004563456 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2018-06-16 06:26 - 2018-06-08 04:00 - 019404288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-06-16 06:26 - 2018-06-08 04:00 - 004372992 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2018-06-16 06:26 - 2018-06-08 04:00 - 003320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2018-06-16 06:26 - 2018-06-08 03:59 - 006032384 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2018-06-16 06:26 - 2018-06-08 03:59 - 004867072 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-06-16 06:26 - 2018-06-08 03:59 - 003392512 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2018-06-16 06:26 - 2018-06-08 03:59 - 001767936 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2018-06-16 06:26 - 2018-06-08 03:58 - 007581696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2018-06-16 06:26 - 2018-06-08 03:58 - 003712512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-06-16 06:26 - 2018-06-08 03:58 - 001676800 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShell.dll
2018-06-16 06:26 - 2018-06-08 03:56 - 005780992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2018-06-16 06:26 - 2018-06-08 03:56 - 002900480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2018-06-16 06:26 - 2018-06-08 03:56 - 002364928 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll
2018-06-16 06:26 - 2018-06-08 03:55 - 003441152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-06-16 06:26 - 2018-06-08 03:55 - 002248192 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2018-06-16 06:26 - 2018-06-06 13:57 - 003733320 _____ C:\WINDOWS\system32\Windows.Mirage.dll
2018-06-16 06:26 - 2018-06-05 23:20 - 002841312 _____ C:\WINDOWS\SysWOW64\Windows.Mirage.dll
2018-06-16 06:25 - 2018-06-08 14:07 - 000506184 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2018-06-16 06:25 - 2018-06-08 14:05 - 000094112 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2018-06-16 06:25 - 2018-06-08 14:02 - 001634808 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2018-06-16 06:25 - 2018-06-08 14:02 - 000661160 _____ (Microsoft Corporation) C:\WINDOWS\system32\GenValObj.exe
2018-06-16 06:25 - 2018-06-08 14:01 - 001046944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2018-06-16 06:25 - 2018-06-08 13:48 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2018-06-16 06:25 - 2018-06-08 13:47 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2018-06-16 06:25 - 2018-06-08 13:46 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2018-06-16 06:25 - 2018-06-08 13:45 - 001560576 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdt.exe
2018-06-16 06:25 - 2018-06-08 13:45 - 000808960 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2018-06-16 06:25 - 2018-06-08 13:44 - 001121792 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2018-06-16 06:25 - 2018-06-08 13:44 - 000625152 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2018-06-16 06:25 - 2018-06-08 13:44 - 000340992 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2018-06-16 06:25 - 2018-06-08 13:44 - 000285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcredprov.dll
2018-06-16 06:25 - 2018-06-08 13:43 - 003640832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2018-06-16 06:25 - 2018-06-08 13:43 - 001719808 _____ (Microsoft Corporation) C:\WINDOWS\system32\dui70.dll
2018-06-16 06:25 - 2018-06-08 13:43 - 001659904 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2018-06-16 06:25 - 2018-06-08 13:43 - 001543680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
2018-06-16 06:25 - 2018-06-08 13:43 - 001364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
2018-06-16 06:25 - 2018-06-08 13:43 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2018-06-16 06:25 - 2018-06-08 13:42 - 003999232 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll
2018-06-16 06:25 - 2018-06-08 13:42 - 002084864 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2018-06-16 06:25 - 2018-06-08 13:42 - 001605632 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2018-06-16 06:25 - 2018-06-08 13:42 - 000503296 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2018-06-16 06:25 - 2018-06-08 13:41 - 002019840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2018-06-16 06:25 - 2018-06-08 13:41 - 001180672 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2018-06-16 06:25 - 2018-06-08 13:41 - 000878080 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2018-06-16 06:25 - 2018-06-08 13:41 - 000758272 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2018-06-16 06:25 - 2018-06-08 13:41 - 000577024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2018-06-16 06:25 - 2018-06-08 13:41 - 000182272 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
2018-06-16 06:25 - 2018-06-08 13:40 - 000465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXP.dll
2018-06-16 06:25 - 2018-06-08 12:04 - 001454024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2018-06-16 06:25 - 2018-06-08 11:58 - 002206544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
2018-06-16 06:25 - 2018-06-08 11:58 - 000917408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
2018-06-16 06:25 - 2018-06-08 11:50 - 001508352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdt.exe
2018-06-16 06:25 - 2018-06-08 11:48 - 000668672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2018-06-16 06:25 - 2018-06-08 11:48 - 000344064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2018-06-16 06:25 - 2018-06-08 11:47 - 003492864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll
2018-06-16 06:25 - 2018-06-08 11:47 - 002895872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-06-16 06:25 - 2018-06-08 11:47 - 001462784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dui70.dll
2018-06-16 06:25 - 2018-06-08 11:47 - 001032704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
2018-06-16 06:25 - 2018-06-08 11:47 - 000703488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2018-06-16 06:25 - 2018-06-08 11:47 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcredprov.dll
2018-06-16 06:25 - 2018-06-08 11:46 - 003444224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2018-06-16 06:25 - 2018-06-08 11:46 - 002016256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2018-06-16 06:25 - 2018-06-08 11:46 - 000908288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2018-06-16 06:25 - 2018-06-08 11:45 - 002401280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2018-06-16 06:25 - 2018-06-08 11:06 - 000976384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe
2018-06-16 06:25 - 2018-06-08 11:05 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll
2018-06-16 06:25 - 2018-06-08 11:05 - 000944640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
2018-06-16 06:25 - 2018-06-08 09:00 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll
2018-06-16 06:25 - 2018-06-08 09:00 - 000658432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2018-06-16 06:25 - 2018-06-08 05:38 - 005821544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2018-06-16 06:25 - 2018-06-08 05:35 - 001613200 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2018-06-16 06:25 - 2018-06-08 05:35 - 000613144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2018-06-16 06:25 - 2018-06-08 05:34 - 001299056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
2018-06-16 06:25 - 2018-06-08 05:34 - 000748512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2018-06-16 06:25 - 2018-06-08 05:31 - 000029600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\uefi.sys
2018-06-16 06:25 - 2018-06-08 05:30 - 000705440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2018-06-16 06:25 - 2018-06-08 04:34 - 001140576 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-06-16 06:25 - 2018-06-08 04:34 - 000983016 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-06-16 06:25 - 2018-06-08 04:33 - 001213368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2018-06-16 06:25 - 2018-06-08 04:33 - 000272296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave.dll
2018-06-16 06:25 - 2018-06-08 04:33 - 000269224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2018-06-16 06:25 - 2018-06-08 04:31 - 001174432 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2018-06-16 06:25 - 2018-06-08 04:31 - 001012640 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2018-06-16 06:25 - 2018-06-08 04:31 - 000226720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Ucx01000.sys
2018-06-16 06:25 - 2018-06-08 04:30 - 001363632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2018-06-16 06:25 - 2018-06-08 04:30 - 001063328 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2018-06-16 06:25 - 2018-06-08 04:30 - 000723360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2018-06-16 06:25 - 2018-06-08 04:30 - 000722808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2018-06-16 06:25 - 2018-06-08 04:30 - 000709824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2018-06-16 06:25 - 2018-06-08 04:30 - 000567184 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2018-06-16 06:25 - 2018-06-08 04:30 - 000565152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2018-06-16 06:25 - 2018-06-08 04:30 - 000527264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2018-06-16 06:25 - 2018-06-08 04:30 - 000491328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2018-06-16 06:25 - 2018-06-08 04:30 - 000194456 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2018-06-16 06:25 - 2018-06-08 04:30 - 000170912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2018-06-16 06:25 - 2018-06-08 04:30 - 000137568 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll
2018-06-16 06:25 - 2018-06-08 04:30 - 000134584 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2018-06-16 06:25 - 2018-06-08 04:29 - 002836384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2018-06-16 06:25 - 2018-06-08 04:29 - 002590400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVDECOD.DLL
2018-06-16 06:25 - 2018-06-08 04:29 - 002564984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2018-06-16 06:25 - 2018-06-08 04:29 - 002546592 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2018-06-16 06:25 - 2018-06-08 04:29 - 002422688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2018-06-16 06:25 - 2018-06-08 04:29 - 001946328 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2018-06-16 06:25 - 2018-06-08 04:29 - 001934400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2018-06-16 06:25 - 2018-06-08 04:29 - 001921952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys
2018-06-16 06:25 - 2018-06-08 04:29 - 001792808 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
2018-06-16 06:25 - 2018-06-08 04:29 - 001457136 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-06-16 06:25 - 2018-06-08 04:29 - 001364184 _____ (Microsoft Corporation) C:\WINDOWS\system32\webservices.dll
2018-06-16 06:25 - 2018-06-08 04:29 - 001288816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2018-06-16 06:25 - 2018-06-08 04:29 - 001258288 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-06-16 06:25 - 2018-06-08 04:29 - 001209800 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2018-06-16 06:25 - 2018-06-08 04:29 - 001190152 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2018-06-16 06:25 - 2018-06-08 04:29 - 001150416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVP9DEC.dll
2018-06-16 06:25 - 2018-06-08 04:29 - 001148808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2018-06-16 06:25 - 2018-06-08 04:29 - 001112608 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2018-06-16 06:25 - 2018-06-08 04:29 - 001097648 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2018-06-16 06:25 - 2018-06-08 04:29 - 001026976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2018-06-16 06:25 - 2018-06-08 04:29 - 000945568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refsv1.sys
2018-06-16 06:25 - 2018-06-08 04:29 - 000885880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2018-06-16 06:25 - 2018-06-08 04:29 - 000792992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2018-06-16 06:25 - 2018-06-08 04:29 - 000678840 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2018-06-16 06:25 - 2018-06-08 04:29 - 000659096 _____ (Microsoft Corporation) C:\WINDOWS\system32\StateRepository.Core.dll
2018-06-16 06:25 - 2018-06-08 04:29 - 000594128 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2018-06-16 06:25 - 2018-06-08 04:29 - 000416144 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
2018-06-16 06:25 - 2018-06-08 04:29 - 000413824 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2018-06-16 06:25 - 2018-06-08 04:29 - 000413088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2018-06-16 06:25 - 2018-06-08 04:29 - 000375712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msrpc.sys
2018-06-16 06:25 - 2018-06-08 04:29 - 000313592 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll
2018-06-16 06:25 - 2018-06-08 04:29 - 000266656 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2018-06-16 06:25 - 2018-06-08 04:29 - 000260896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2018-06-16 06:25 - 2018-06-08 04:29 - 000164768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2018-06-16 06:25 - 2018-06-08 04:29 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\vertdll.dll
2018-06-16 06:25 - 2018-06-08 04:29 - 000084288 _____ (Microsoft Corporation) C:\WINDOWS\system32\LanguageOverlayUtil.dll
2018-06-16 06:25 - 2018-06-08 04:29 - 000057960 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel.appcore.dll
2018-06-16 06:25 - 2018-06-08 04:12 - 000786176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2018-06-16 06:25 - 2018-06-08 04:11 - 001461744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2018-06-16 06:25 - 2018-06-08 04:11 - 000550616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2018-06-16 06:25 - 2018-06-08 04:10 - 002307336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVDECOD.DLL
2018-06-16 06:25 - 2018-06-08 04:10 - 001988072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2018-06-16 06:25 - 2018-06-08 04:10 - 001397200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVP9DEC.dll
2018-06-16 06:25 - 2018-06-08 04:10 - 001011992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2018-06-16 06:25 - 2018-06-08 04:10 - 000880152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2018-06-16 06:25 - 2018-06-08 04:10 - 000097176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll
2018-06-16 06:25 - 2018-06-08 04:09 - 002535552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2018-06-16 06:25 - 2018-06-08 04:09 - 002486992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2018-06-16 06:25 - 2018-06-08 04:09 - 002242216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2018-06-16 06:25 - 2018-06-08 04:09 - 001805776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2018-06-16 06:25 - 2018-06-08 04:09 - 001620880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2018-06-16 06:25 - 2018-06-08 04:09 - 001584128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll
2018-06-16 06:25 - 2018-06-08 04:09 - 001129648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2018-06-16 06:25 - 2018-06-08 04:09 - 001077504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webservices.dll
2018-06-16 06:25 - 2018-06-08 04:09 - 000988136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2018-06-16 06:25 - 2018-06-08 04:09 - 000770160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2018-06-16 06:25 - 2018-06-08 04:09 - 000607648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2018-06-16 06:25 - 2018-06-08 04:09 - 000568720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryPS.dll
2018-06-16 06:25 - 2018-06-08 04:09 - 000567144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2018-06-16 06:25 - 2018-06-08 04:09 - 000553248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2018-06-16 06:25 - 2018-06-08 04:09 - 000356960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2018-06-16 06:25 - 2018-06-08 04:09 - 000064648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LanguageOverlayUtil.dll
2018-06-16 06:25 - 2018-06-08 04:09 - 000050208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel.appcore.dll
2018-06-16 06:25 - 2018-06-08 04:03 - 000906752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.PhoneNumberFormatting.dll
2018-06-16 06:25 - 2018-06-08 04:03 - 000185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2018-06-16 06:25 - 2018-06-08 04:03 - 000038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryCore.dll
2018-06-16 06:25 - 2018-06-08 04:03 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mskssrv.sys
2018-06-16 06:25 - 2018-06-08 04:02 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll
2018-06-16 06:25 - 2018-06-08 04:02 - 000059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\edpnotify.exe
2018-06-16 06:25 - 2018-06-08 04:02 - 000035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
2018-06-16 06:25 - 2018-06-08 04:01 - 002961408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2018-06-16 06:25 - 2018-06-08 04:01 - 000342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserexport.exe
2018-06-16 06:25 - 2018-06-08 04:01 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2018-06-16 06:25 - 2018-06-08 04:01 - 000294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll
2018-06-16 06:25 - 2018-06-08 04:01 - 000209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2018-06-16 06:25 - 2018-06-08 04:01 - 000182272 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerCsp.dll
2018-06-16 06:25 - 2018-06-08 04:01 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2018-06-16 06:25 - 2018-06-08 04:01 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys
2018-06-16 06:25 - 2018-06-08 04:00 - 001285120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll
2018-06-16 06:25 - 2018-06-08 04:00 - 000329216 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll
2018-06-16 06:25 - 2018-06-08 04:00 - 000275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe
2018-06-16 06:25 - 2018-06-08 04:00 - 000149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2018-06-16 06:25 - 2018-06-08 04:00 - 000100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManagerClient.dll
2018-06-16 06:25 - 2018-06-08 04:00 - 000075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mpsdrv.sys
2018-06-16 06:25 - 2018-06-08 03:59 - 001318400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2018-06-16 06:25 - 2018-06-08 03:59 - 000983040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2018-06-16 06:25 - 2018-06-08 03:59 - 000673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2018-06-16 06:25 - 2018-06-08 03:59 - 000564736 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2018-06-16 06:25 - 2018-06-08 03:59 - 000456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
2018-06-16 06:25 - 2018-06-08 03:59 - 000177152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll
2018-06-16 06:25 - 2018-06-08 03:59 - 000174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2018-06-16 06:25 - 2018-06-08 03:58 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2018-06-16 06:25 - 2018-06-08 03:58 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2018-06-16 06:25 - 2018-06-08 03:58 - 000813568 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2018-06-16 06:25 - 2018-06-08 03:58 - 000781824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2018-06-16 06:25 - 2018-06-08 03:58 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManager.dll
2018-06-16 06:25 - 2018-06-08 03:58 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FSClient.dll
2018-06-16 06:25 - 2018-06-08 03:58 - 000029184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
2018-06-16 06:25 - 2018-06-08 03:57 - 003348992 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2018-06-16 06:25 - 2018-06-08 03:57 - 002172416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2018-06-16 06:25 - 2018-06-08 03:57 - 001708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSPhotography.dll
2018-06-16 06:25 - 2018-06-08 03:57 - 001485312 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2018-06-16 06:25 - 2018-06-08 03:57 - 000483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTMediaFrame.dll
2018-06-16 06:25 - 2018-06-08 03:57 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys
2018-06-16 06:25 - 2018-06-08 03:57 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2018-06-16 06:25 - 2018-06-08 03:57 - 000150016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll
2018-06-16 06:25 - 2018-06-08 03:57 - 000038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2018-06-16 06:25 - 2018-06-08 03:56 - 005307392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2018-06-16 06:25 - 2018-06-08 03:56 - 004336128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2018-06-16 06:25 - 2018-06-08 03:56 - 003293696 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2018-06-16 06:25 - 2018-06-08 03:56 - 002902016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2018-06-16 06:25 - 2018-06-08 03:56 - 001804288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2018-06-16 06:25 - 2018-06-08 03:56 - 001550848 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2018-06-16 06:25 - 2018-06-08 03:56 - 001395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2018-06-16 06:25 - 2018-06-08 03:56 - 001361408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSPhotography.dll
2018-06-16 06:25 - 2018-06-08 03:56 - 000916480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2018-06-16 06:25 - 2018-06-08 03:56 - 000908800 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSMPEG2ENC.DLL
2018-06-16 06:25 - 2018-06-08 03:56 - 000871424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll
2018-06-16 06:25 - 2018-06-08 03:56 - 000869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
2018-06-16 06:25 - 2018-06-08 03:56 - 000858112 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll
2018-06-16 06:25 - 2018-06-08 03:56 - 000715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2018-06-16 06:25 - 2018-06-08 03:56 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2018-06-16 06:25 - 2018-06-08 03:56 - 000615424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2018-06-16 06:25 - 2018-06-08 03:56 - 000466432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2018-06-16 06:25 - 2018-06-08 03:56 - 000389632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2018-06-16 06:25 - 2018-06-08 03:56 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2018-06-16 06:25 - 2018-06-08 03:56 - 000264704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovs.dll
2018-06-16 06:25 - 2018-06-08 03:55 - 002236928 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2018-06-16 06:25 - 2018-06-08 03:55 - 002061824 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2018-06-16 06:25 - 2018-06-08 03:55 - 001854976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2018-06-16 06:25 - 2018-06-08 03:55 - 001371648 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2018-06-16 06:25 - 2018-06-08 03:55 - 001242112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2018-06-16 06:25 - 2018-06-08 03:55 - 001192448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Maps.dll
2018-06-16 06:25 - 2018-06-08 03:55 - 001171968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2018-06-16 06:25 - 2018-06-08 03:55 - 001160192 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2018-06-16 06:25 - 2018-06-08 03:55 - 001070080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2018-06-16 06:25 - 2018-06-08 03:55 - 001033728 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2018-06-16 06:25 - 2018-06-08 03:55 - 000932352 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2018-06-16 06:25 - 2018-06-08 03:55 - 000849408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll
2018-06-16 06:25 - 2018-06-08 03:55 - 000778752 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2018-06-16 06:25 - 2018-06-08 03:55 - 000776192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2018-06-16 06:25 - 2018-06-08 03:55 - 000667648 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2018-06-16 06:25 - 2018-06-08 03:55 - 000652800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2018-06-16 06:25 - 2018-06-08 03:55 - 000630784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.MediaPlayer.dll
2018-06-16 06:25 - 2018-06-08 03:55 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2018-06-16 06:25 - 2018-06-08 03:55 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2018-06-16 06:25 - 2018-06-08 03:54 - 003016192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2018-06-16 06:25 - 2018-06-08 03:54 - 002789376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2018-06-16 06:25 - 2018-06-08 03:54 - 001627136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2018-06-16 06:25 - 2018-06-08 03:54 - 001586176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2018-06-16 06:25 - 2018-06-08 03:54 - 001348096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpcServices.dll
2018-06-16 06:25 - 2018-06-08 03:54 - 001128448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2018-06-16 06:25 - 2018-06-08 03:54 - 000999936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2018-06-16 06:25 - 2018-06-08 03:54 - 000950272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2018-06-16 06:25 - 2018-06-08 03:54 - 000857088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSMPEG2ENC.DLL
2018-06-16 06:25 - 2018-06-08 03:54 - 000842240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2018-06-16 06:25 - 2018-06-08 03:54 - 000729088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FlightSettings.dll
2018-06-16 06:25 - 2018-06-08 03:54 - 000646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll
2018-06-16 06:25 - 2018-06-08 03:54 - 000619520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2018-06-16 06:25 - 2018-06-08 03:54 - 000593408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2018-06-16 06:25 - 2018-06-08 03:54 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2018-06-16 06:25 - 2018-06-08 03:54 - 000375808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTMediaFrame.dll
2018-06-16 06:25 - 2018-06-08 03:54 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2018-06-16 06:25 - 2018-06-08 03:54 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAC3ENC.DLL
2018-06-16 06:25 - 2018-06-08 03:53 - 001675264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2018-06-16 06:25 - 2018-06-08 03:53 - 001466368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2018-06-16 06:25 - 2018-06-08 03:53 - 001108992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2018-06-16 06:25 - 2018-06-08 03:53 - 000873472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2018-06-16 06:25 - 2018-06-08 03:53 - 000677888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2018-06-16 06:25 - 2018-06-08 03:53 - 000669696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2018-06-16 06:25 - 2018-06-08 03:53 - 000648192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll
2018-06-16 06:25 - 2018-06-08 03:53 - 000528384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2018-06-16 06:25 - 2018-06-08 02:41 - 000001310 _____ C:\WINDOWS\system32\tcbres.wim
2018-06-16 06:25 - 2018-06-01 18:24 - 000713376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2018-06-16 06:25 - 2018-06-01 17:54 - 001825792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll
2018-06-16 06:25 - 2018-05-24 22:24 - 000340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2018-06-16 06:08 - 2018-06-16 06:08 - 000002832 _____ C:\WINDOWS\System32\Tasks\AdobeAAMUpdater-1.0-DESKTOP-84BFGSO-ralph
2018-06-16 06:05 - 2018-06-16 06:06 - 000004256 _____ C:\Users\ralph\Desktop\cc_20180616_060554.reg
2018-06-16 06:05 - 2018-06-16 06:05 - 000038398 _____ C:\Users\ralph\Desktop\cc_20180616_060455.reg
2018-06-16 06:02 - 2018-06-16 06:02 - 000003938 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2018-06-16 04:24 - 2018-06-16 04:24 - 000001887 _____ C:\Users\ralph\Documents\disk.txt
2018-06-16 04:03 - 2018-06-16 04:03 - 000000000 ____D C:\Users\ralph\AppData\Local\D3DSCache
2018-06-16 02:30 - 2018-06-19 19:26 - 000000000 ____D C:\Windows.old
2018-06-16 02:26 - 2018-06-16 02:30 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2018-06-16 02:26 - 2018-06-16 02:26 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2018-06-16 02:25 - 2018-06-16 02:25 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2018-06-16 02:23 - 2018-06-16 02:23 - 023862784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 021389360 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 020383712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 019525120 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 016592384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 013873152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 013570560 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 012500992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 008623104 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 008188928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 007987712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 007436632 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 006661120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 006044104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 005951488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 004929024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 004070400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 003392512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 003086336 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 002699776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 002366976 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 002178136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001953280 _____ C:\WINDOWS\system32\rdpnano.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001947808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001855488 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001665920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001665024 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001649760 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001585664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001565592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001559368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001534976 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001490144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001456640 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001426328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001421312 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpbase.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001371136 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001307648 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001303040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001295360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001292288 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2018-06-16 02:23 - 2018-06-16 02:23 - 001271296 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloSI.PCShell.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001235968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpbase.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001210880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001034096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001017088 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001012408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 001005568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000992768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Vpn.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000960512 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmsys.cpl
2018-06-16 02:23 - 2018-06-16 02:23 - 000941056 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdlg.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000933376 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000917504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000899072 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000864768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmsys.cpl
2018-06-16 02:23 - 2018-06-16 02:23 - 000863232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000861096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000860160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000847360 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000804352 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVolSSO.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000788480 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000788216 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000783360 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyHrtfEnc.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000776880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000759192 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingWinRT.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SndVolSSO.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000735560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000695296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hhctrl.ocx
2018-06-16 02:23 - 2018-06-16 02:23 - 000677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\HeadTrackerStorage.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000665320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000653208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicensingWinRT.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000625152 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.rs4.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000606448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000604568 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2018-06-16 02:23 - 2018-06-16 02:23 - 000596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000585728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.rs3.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000581120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hhctrl.ocx
2018-06-16 02:23 - 2018-06-16 02:23 - 000561664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000560488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000553984 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationExtensions.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000543744 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000524800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000494488 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2018-06-16 02:23 - 2018-06-16 02:23 - 000486912 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasplap.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000474624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.rs2.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000473496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000461312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasplap.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000444416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.rs1.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000434584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2018-06-16 02:23 - 2018-06-16 02:23 - 000384000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Phoneutil.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000382872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2018-06-16 02:23 - 2018-06-16 02:23 - 000356352 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWfdProvider.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000347704 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\system32\RasMediaManager.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000317440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Phoneutil.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000308408 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.th.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000286200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2018-06-16 02:23 - 2018-06-16 02:23 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MixedReality.Broker.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000241664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.win81.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloShellRuntime.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtutil.exe
2018-06-16 02:23 - 2018-06-16 02:23 - 000234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyMATEnc.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000184320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\HoloShellRuntime.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\itss.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000167936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtutil.exe
2018-06-16 02:23 - 2018-06-16 02:23 - 000159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Analog.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedPCCSP.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000150016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\itss.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSpkg.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000142848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000142336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.win8rtm.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000131232 _____ (Microsoft Corporation) C:\WINDOWS\system32\rmclient.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000130456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvsocket.sys
2018-06-16 02:23 - 2018-06-16 02:23 - 000119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000117760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSpkg.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppHostRegistrationVerifier.exe
2018-06-16 02:23 - 2018-06-16 02:23 - 000109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApiSetHost.AppExecutionAlias.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000105368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2018-06-16 02:23 - 2018-06-16 02:23 - 000101288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rmclient.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000098816 _____ (Microsoft Corporation) C:\WINDOWS\system32\TelephonyInteractiveUser.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000089984 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompPkgSup.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000088472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\crashdmp.sys
2018-06-16 02:23 - 2018-06-16 02:23 - 000081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ApiSetHost.AppExecutionAlias.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000077040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CompPkgSup.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcimage.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSHEIF.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSHEIF.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\credssp.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credssp.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000018716 _____ C:\WINDOWS\SysWOW64\srms-apr.dat
2018-06-16 02:23 - 2018-06-16 02:23 - 000018716 _____ C:\WINDOWS\system32\srms-apr.dat
2018-06-16 02:23 - 2018-06-16 02:23 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2018-06-16 02:23 - 2018-06-16 02:23 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2018-06-16 02:18 - 2018-06-16 02:18 - 001166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2018-06-16 02:18 - 2018-06-16 02:18 - 000778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2018-06-16 02:18 - 2018-06-16 02:18 - 000124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2018-06-16 02:18 - 2018-06-16 02:18 - 000103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2018-06-16 02:18 - 2018-06-16 02:18 - 000035456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2018-06-16 02:18 - 2018-06-16 02:18 - 000035456 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2018-06-16 02:18 - 2018-06-16 02:18 - 000000000 ____D C:\Program Files\Reference Assemblies
2018-06-16 02:18 - 2018-06-16 02:18 - 000000000 ____D C:\Program Files\MSBuild
2018-06-16 02:18 - 2018-06-16 02:18 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2018-06-16 02:18 - 2018-06-16 02:18 - 000000000 ____D C:\Program Files (x86)\MSBuild
2018-06-16 02:17 - 2018-06-16 02:17 - 004492288 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2018-06-16 02:17 - 2018-06-16 02:17 - 003398144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2018-06-16 02:17 - 2018-06-16 02:17 - 000925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsFilt.dll
2018-06-16 02:17 - 2018-06-16 02:17 - 000575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsFilt.dll
2018-06-16 02:17 - 2018-06-16 02:17 - 000100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\XPSSHHDR.dll
2018-06-16 02:17 - 2018-06-16 02:17 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XPSSHHDR.dll
2018-06-16 02:17 - 2018-06-16 02:17 - 000076060 _____ C:\WINDOWS\SysWOW64\xpsrchvw.xml
2018-06-16 02:17 - 2018-06-16 02:17 - 000076060 _____ C:\WINDOWS\system32\xpsrchvw.xml
2018-06-16 00:13 - 2018-06-16 00:13 - 000001417 _____ C:\Users\ralph\Desktop\Microsoft Edge.lnk
2018-06-16 00:10 - 2018-06-16 00:10 - 000000020 ___SH C:\Users\ralph\ntuser.ini
2018-06-16 00:07 - 2018-06-19 00:06 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-06-16 00:07 - 2018-06-18 17:37 - 000003352 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-444302225-3719607882-3466423754-1002
2018-06-16 00:07 - 2018-06-16 06:08 - 000003810 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier
2018-06-16 00:07 - 2018-06-16 06:08 - 000002916 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-444302225-3719607882-3466423754-1001
2018-06-16 00:07 - 2018-06-16 00:07 - 000003446 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2018-06-16 00:07 - 2018-06-16 00:07 - 000003346 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2018-06-16 00:07 - 2018-06-16 00:07 - 000003122 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2018-06-16 00:07 - 2018-06-16 00:07 - 000002814 _____ C:\WINDOWS\System32\Tasks\AdobeAAMUpdater-1.0-RWDESK-ralph
2018-06-16 00:07 - 2018-06-16 00:07 - 000002308 _____ C:\WINDOWS\System32\Tasks\Adobe Uninstaller
2018-06-16 00:07 - 2018-06-16 00:07 - 000002218 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2018-06-16 00:07 - 2018-06-16 00:07 - 000000000 ____D C:\WINDOWS\System32\Tasks\Remediation
2018-06-16 00:05 - 2018-06-16 00:07 - 000015243 _____ C:\WINDOWS\diagwrn.xml
2018-06-16 00:05 - 2018-06-16 00:07 - 000015243 _____ C:\WINDOWS\diagerr.xml
2018-06-15 23:52 - 2018-06-19 00:13 - 000838560 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-06-15 23:42 - 2018-06-15 23:42 - 000001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2018-06-15 23:38 - 2018-06-20 10:20 - 000000000 ____D C:\Users\Rward
2018-06-15 23:38 - 2018-06-18 20:06 - 000000000 ____D C:\Users\ralph
2018-06-15 23:38 - 2018-06-18 19:58 - 000000000 ____D C:\Users\rw.DESKTOP-84BFGSO
2018-06-15 23:38 - 2018-06-18 17:37 - 000002438 _____ C:\Users\rw.DESKTOP-84BFGSO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-06-15 23:38 - 2018-04-11 18:34 - 000001105 _____ C:\Users\Rward\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-06-15 23:38 - 2018-04-11 18:34 - 000001105 _____ C:\Users\ralph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-06-15 23:38 - 2016-11-11 12:47 - 000000000 ____D C:\Users\Rward\AppData\Roaming\Macromedia
2018-06-15 23:38 - 2016-11-11 12:47 - 000000000 ____D C:\Users\Rward\AppData\Local\Nuance
2018-06-15 23:38 - 2016-11-11 12:47 - 000000000 ____D C:\Users\rw.DESKTOP-84BFGSO\AppData\Roaming\Macromedia
2018-06-15 23:38 - 2016-11-11 12:47 - 000000000 ____D C:\Users\rw.DESKTOP-84BFGSO\AppData\Local\Nuance
2018-06-15 23:38 - 2016-11-11 12:47 - 000000000 ____D C:\Users\ralph\AppData\Roaming\Macromedia
2018-06-15 23:38 - 2016-11-11 12:47 - 000000000 ____D C:\Users\ralph\AppData\Local\Nuance
2018-06-15 23:37 - 2018-06-15 23:37 - 000002186 _____ C:\Users\Public\Desktop\3D Vision Photo Viewer.lnk
2018-06-15 23:37 - 2018-06-15 23:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2018-06-15 23:37 - 2018-06-15 23:37 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2018-06-15 23:37 - 2017-10-27 11:06 - 000136312 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2018-06-15 23:37 - 2017-09-13 18:20 - 000798008 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2018-06-15 23:37 - 2017-09-13 18:20 - 000490296 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2018-06-15 23:37 - 2017-09-13 18:19 - 000927544 _____ C:\WINDOWS\system32\vulkan-1.dll
2018-06-15 23:37 - 2017-09-13 18:19 - 000591160 _____ C:\WINDOWS\system32\vulkaninfo.exe
2018-06-15 23:36 - 2018-06-15 23:36 - 000000000 ____D C:\ProgramData\USOShared
2018-06-15 23:36 - 2018-04-11 18:33 - 002752000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2018-06-15 23:36 - 2017-11-09 05:43 - 000540784 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2018-06-15 23:36 - 2017-11-09 05:43 - 000446392 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2018-06-15 23:32 - 2018-06-20 10:17 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-06-15 23:32 - 2018-06-19 00:08 - 000513040 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-06-15 22:11 - 2018-06-15 22:13 - 000000000 ___HD C:\$GetCurrent
2018-06-15 22:09 - 2018-06-15 22:09 - 006266272 _____ (Microsoft Corporation) C:\Users\ralph\Downloads\Windows10Upgrade9252.exe
2018-06-15 22:06 - 2018-06-16 02:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2018-06-15 22:02 - 2018-06-15 22:02 - 071830472 _____ (Oracle Corporation) C:\Users\ralph\Downloads\jre-8u171-windows-x64(1).exe
2018-06-15 22:00 - 2018-06-15 22:00 - 001211216 _____ (Oracle Corporation) C:\Users\ralph\Downloads\JavaUninstallTool.exe
2018-06-15 21:59 - 2018-06-15 21:59 - 071830472 _____ (Oracle Corporation) C:\Users\ralph\Downloads\jre-8u171-windows-x64.exe
2018-06-15 21:59 - 2018-06-15 21:59 - 000000000 ____D C:\Users\ralph\AppData\Temp
2018-06-12 10:34 - 2018-06-12 10:34 - 000000000 ____D C:\Users\ralph\AppData\Local\Microsoft Help
2018-06-12 10:24 - 2018-06-12 10:24 - 000830341 _____ C:\Users\ralph\Documents\ALARM manual.pdf
2018-06-10 21:38 - 2018-06-10 21:38 - 016874288 _____ (Piriform Ltd) C:\Users\ralph\Downloads\CCleanerBundle-1116-Setup(2).exe
2018-06-09 02:08 - 2018-06-09 02:08 - 000021054 _____ C:\Users\ralph\Documents\startup.txt
2018-06-09 02:01 - 2018-06-09 02:02 - 000123400 _____ C:\Users\ralph\Documents\cc_20180609_020143.reg
2018-06-09 02:01 - 2018-06-09 02:01 - 016874288 _____ (Piriform Ltd) C:\Users\ralph\Downloads\CCleanerBundle-1116-Setup(1).exe
2018-06-09 01:54 - 2018-06-16 06:02 - 000000000 ____D C:\Program Files\CCleaner
2018-06-09 01:54 - 2018-06-16 02:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2018-06-09 01:54 - 2018-06-09 01:54 - 000000863 _____ C:\Users\Public\Desktop\CCleaner.lnk
2018-06-08 21:40 - 2018-06-08 21:40 - 000000000 ____D C:\ProgramData\Microsoft SkyDrive
2018-06-08 21:29 - 2018-06-08 21:29 - 000000018 _____ C:\Users\ralph\Documents\cc.txt
2018-06-08 19:31 - 2018-06-08 19:31 - 000000059 _____ C:\Users\ralph\Documents\win download.txt
2018-06-08 18:46 - 2018-06-15 22:13 - 000000000 ____D C:\Windows10Upgrade
2018-06-08 18:46 - 2018-06-15 22:10 - 000000731 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 10 Update Assistant.lnk
2018-06-08 18:46 - 2018-06-15 22:10 - 000000719 _____ C:\Users\ralph\Desktop\Windows 10 Update Assistant.lnk
2018-06-08 18:22 - 2018-06-08 18:22 - 000069213 _____ C:\ProgramData\cl.1528500153.bdinstall.bin
2018-06-08 17:40 - 2018-06-08 17:40 - 000000151 _____ C:\Users\ralph\Documents\office keys.txt
2018-06-08 17:39 - 2018-06-08 17:50 - 2201223168 _____ C:\Users\ralph\Downloads\AccessRetail(1).img
2018-06-08 17:38 - 2018-06-08 17:38 - 000016199 _____ C:\Users\ralph\Documents\rw contacts.CSV
2018-06-08 17:25 - 2018-06-08 17:35 - 2201223168 _____ C:\Users\ralph\Downloads\AccessRetail.img
2018-06-08 17:25 - 2018-06-08 17:31 - 2201997312 _____ C:\Users\ralph\Downloads\HomeBusinessRetail.img
2018-06-08 17:21 - 2018-06-08 17:23 - 2201997312 _____ C:\Users\ralph\Downloads\HomeBusinessRetail(1).img
2018-06-08 16:08 - 2018-06-08 16:08 - 000061343 _____ C:\ProgramData\dm.1528492055.bdinstall.bin
2018-06-08 16:07 - 2018-06-08 16:07 - 000381301 _____ C:\ProgramData\cl.1528491399.bdinstall.bin
2018-06-08 16:07 - 2018-06-08 16:07 - 000056750 _____ C:\ProgramData\cl.kit.1528491393.bdinstall.bin
2018-06-08 15:49 - 2018-06-08 15:49 - 000029897 _____ C:\ProgramData\agent.update.1528490929.bdinstall.bin
2018-06-08 15:43 - 2018-06-08 15:43 - 000000000 ____D C:\ProgramData\Bitdefender Device Management
2018-06-08 15:24 - 2018-06-08 15:24 - 018060728 _____ (MiniTool Software Limited ) C:\Users\ralph\Downloads\pdr8-free.exe
2018-06-08 15:03 - 2018-06-08 15:03 - 000000000 ____D C:\ProgramData\Atc
2018-06-08 14:56 - 2018-06-20 07:40 - 000000000 ____D C:\Program Files\MiniTool Partition Wizard 10
2018-06-08 14:56 - 2018-06-16 02:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiniTool Partition Wizard 10
2018-06-08 14:56 - 2018-06-08 14:56 - 000001028 _____ C:\Users\Public\Desktop\MiniTool Partition Wizard.lnk
2018-06-08 14:56 - 2017-03-23 09:04 - 003547136 _____ C:\WINDOWS\system32\pwNative.exe
2018-06-08 14:56 - 2013-09-30 15:26 - 000019152 _____ C:\WINDOWS\system32\pwdrvio.sys
2018-06-08 14:56 - 2013-09-30 15:26 - 000012504 _____ C:\WINDOWS\system32\pwdspio.sys
2018-06-08 14:55 - 2018-06-08 14:55 - 000000000 ____D C:\ProgramData\BDLogging
2018-06-08 14:52 - 2018-06-08 14:54 - 081265280 _____ (MiniTool Solution Ltd. ) C:\Users\ralph\Downloads\pw1023(1).exe
2018-06-08 14:52 - 2018-06-08 14:53 - 081265280 _____ (MiniTool Solution Ltd. ) C:\Users\ralph\Downloads\pw1023.exe
2018-06-08 14:50 - 2007-04-11 11:11 - 000511328 _____ (Microsoft Corporation) C:\WINDOWS\capicom.dll
2018-06-08 14:44 - 2018-06-08 14:44 - 000000000 ____D C:\Users\ralph\AppData\Roaming\QuickScan
2018-06-08 14:43 - 2018-06-18 21:58 - 000000000 ____D C:\ProgramData\Bitdefender
2018-06-08 14:42 - 2018-06-16 06:03 - 000000000 ___DC C:\WINDOWS\Panther
2018-06-08 14:32 - 2018-06-18 21:58 - 000000000 ____D C:\Program Files\Common Files\Bitdefender
2018-06-08 14:31 - 2018-06-08 14:31 - 000042768 _____ C:\ProgramData\agent.1528486298.bdinstall.bin
2018-06-08 14:31 - 2018-06-08 14:31 - 000000000 ____D C:\ProgramData\Bitdefender Agent
2018-06-08 14:30 - 2018-06-08 14:30 - 010933264 _____ C:\Users\ralph\Downloads\bitdefender_windows_bda7f450-2458-4e93-b51f-7273cb4c73a4.exe
2018-06-08 14:30 - 2018-06-08 14:30 - 010933264 _____ C:\Users\ralph\Downloads\bitdefender_windows_98765a7f-5371-49ad-aa99-a63b461f6150.exe
2018-05-29 19:33 - 2018-05-29 19:33 - 000440128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp140.dll
2018-05-29 19:33 - 2018-05-29 19:33 - 000263856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vccorlib140.dll
2018-05-29 19:33 - 2018-05-29 19:33 - 000242496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\concrt140.dll
2018-05-29 19:33 - 2018-05-29 19:33 - 000083792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vcruntime140.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-06-20 10:33 - 2017-08-11 10:30 - 000000000 ____D C:\Users\ralph\AppData\LocalLow\Mozilla
2018-06-20 10:30 - 2017-08-11 13:04 - 000000000 ____D C:\Users\ralph\Documents\Outlook Files
2018-06-20 08:19 - 2018-04-11 18:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-06-20 07:17 - 2017-08-11 10:41 - 000000706 _____ C:\Program Files (x86)\LMIR0004.tmp.bat
2018-06-20 07:17 - 2017-08-11 10:41 - 000000514 _____ C:\Program Files (x86)\LMIR0004.tmp_r.bat
2018-06-20 07:16 - 2017-08-11 10:41 - 000000512 _____ C:\Users\ralph\AppData\Local\LMIR0003.tmp_r.bat
2018-06-20 06:53 - 2017-08-11 09:50 - 000000000 ____D C:\Program Files (x86)\LogMeIn Rescue Applet
2018-06-20 00:22 - 2018-01-13 00:29 - 000027365 _____ C:\Users\ralph\Documents\pw3.ods
2018-06-20 00:18 - 2017-08-11 10:29 - 000000706 _____ C:\Program Files (x86)\LMIR0002.tmp.bat
2018-06-20 00:18 - 2017-08-11 10:29 - 000000514 _____ C:\Program Files (x86)\LMIR0002.tmp_r.bat
2018-06-19 23:36 - 2017-09-16 14:10 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-06-19 23:16 - 2018-04-11 18:38 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2018-06-19 23:06 - 2018-04-11 18:36 - 000000000 ____D C:\WINDOWS\INF
2018-06-19 22:50 - 2017-10-08 09:11 - 000000000 ____D C:\WeatherLink2
2018-06-19 22:30 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2018-06-19 19:57 - 2017-10-19 04:56 - 000000000 ____D C:\Users\ralph\AppData\Local\Packages
2018-06-19 18:35 - 2017-11-21 20:10 - 000000000 ____D C:\Users\ralph\AppData\Local\Amazon
2018-06-19 00:22 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-06-19 00:08 - 2017-10-12 10:26 - 000000000 ____D C:\ProgramData\NVIDIA
2018-06-19 00:05 - 2018-04-11 16:04 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2018-06-18 23:36 - 2017-08-13 18:11 - 000000000 ____D C:\ProgramData\Adobe
2018-06-18 23:29 - 2017-08-16 23:23 - 000000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2018-06-18 21:55 - 2013-08-07 04:24 - 000005700 _____ C:\bdlog.txt
2018-06-18 21:53 - 2018-04-11 16:04 - 000065536 _____ C:\WINDOWS\system32\config\ELAM
2018-06-18 21:05 - 2017-08-11 10:59 - 000000000 ____D C:\Program Files\Common Files\AV
2018-06-18 20:58 - 2018-04-11 18:38 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2018-06-18 18:02 - 2018-04-11 18:38 - 000000000 ___HD C:\Program Files\WindowsApps
2018-06-18 17:37 - 2017-08-13 23:25 - 000000000 ___RD C:\Users\rw.DESKTOP-84BFGSO\OneDrive
2018-06-18 15:46 - 2017-09-12 11:23 - 000000000 ____D C:\Users\ralph\AppData\Roaming\NCH Software
2018-06-18 15:46 - 2017-09-06 11:33 - 000000000 ____D C:\ProgramData\NCH Software
2018-06-18 15:46 - 2017-09-06 11:33 - 000000000 ____D C:\Program Files (x86)\NCH Software
2018-06-17 20:41 - 2017-10-19 04:55 - 000000000 ____D C:\Users\rw.DESKTOP-84BFGSO\AppData\Local\Packages
2018-06-17 20:40 - 2017-08-13 23:21 - 000000000 ____D C:\Users\rw.DESKTOP-84BFGSO\AppData\Local\ConnectedDevicesPlatform
2018-06-17 20:39 - 2017-08-13 23:22 - 000000000 ____D C:\Users\rw.DESKTOP-84BFGSO\AppData\Local\Publishers
2018-06-17 20:30 - 2017-08-15 20:51 - 000000000 ____D C:\Users\rw.DESKTOP-84BFGSO\AppData\Roaming\Mozilla
2018-06-17 20:30 - 2017-08-15 20:51 - 000000000 ____D C:\Users\rw.DESKTOP-84BFGSO\AppData\LocalLow\Mozilla
2018-06-17 20:07 - 2017-10-14 16:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2018-06-17 20:07 - 2015-03-10 11:45 - 000002224 _____ C:\Users\Public\Desktop\Shop for HP Supplies.lnk
2018-06-17 19:50 - 2017-10-15 07:49 - 000000000 ____D C:\Users\Public\Documents\Wondershare
2018-06-17 18:32 - 2017-08-13 18:11 - 000000000 ____D C:\Users\ralph\AppData\Local\Adobe
2018-06-17 18:20 - 2018-04-11 18:38 - 000000000 ___RD C:\WINDOWS\PrintDialog
2018-06-17 18:04 - 2015-08-02 06:33 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-06-17 17:57 - 2017-08-16 23:18 - 000000000 ____D C:\ProgramData\Package Cache
2018-06-17 17:54 - 2017-10-15 07:50 - 000000000 ____D C:\Program Files (x86)\Wondershare
2018-06-17 17:09 - 2017-08-23 08:49 - 000037715 _____ C:\Users\ralph\AppData\Roaming\Comma Separated Values.ADR
2018-06-16 17:58 - 2017-08-11 09:22 - 000000000 ____D C:\Users\ralph\AppData\Roaming\Adobe
2018-06-16 17:05 - 2017-09-16 11:54 - 000000000 ____D C:\Users\ralph\AppData\Local\ElevatedDiagnostics
2018-06-16 16:43 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\NDF
2018-06-16 12:50 - 2016-04-27 04:33 - 000002015 _____ C:\Users\Public\Desktop\Garmin Express.lnk
2018-06-16 12:03 - 2017-08-13 15:52 - 000000000 ____D C:\Users\ralph\Documents\AcuRite Weather Station
2018-06-16 09:46 - 2017-01-28 16:23 - 000000000 ____D C:\WINDOWS\Microsoft Antimalware
2018-06-16 07:00 - 2018-02-13 18:37 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\zu-ZA
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\yo-NG
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\xh-ZA
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\wo-SN
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\uz-Latn-UZ
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tn-ZA
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ti-ET
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tg-Cyrl-TJ
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-RS
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-BA
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sd-Arab-PK
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\rw-RW
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\quc-Latn-GT
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-Arab-PK
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\nso-ZA
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ku-Arab-IQ
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ig-NG
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ha-Latn-NG
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\chr-CHER-US
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES-valencia
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\bs-Latn-BA
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\az-Latn-AZ
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\zu-ZA
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\yo-NG
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\xh-ZA
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\wo-SN
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\uz-Latn-UZ
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\tn-ZA
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ti-ET
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\tg-Cyrl-TJ
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-RS
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-BA
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\sd-Arab-PK
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\rw-RW
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\quc-Latn-GT
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\pa-Arab-PK
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\nso-ZA
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ku-Arab-IQ
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ig-NG
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ha-Latn-NG
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\chr-CHER-US
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ca-ES-valencia
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\bs-Latn-BA
2018-06-16 06:34 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\az-Latn-AZ
2018-06-16 06:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\TextInput
2018-06-16 06:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2018-06-16 06:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2018-06-16 06:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2018-06-16 06:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2018-06-16 06:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\oobe
2018-06-16 06:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-06-16 06:34 - 2018-04-11 16:04 - 000000000 ____D C:\WINDOWS\system32\Dism
2018-06-16 06:33 - 2018-04-11 18:38 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2018-06-16 06:33 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\ShellExperiences
2018-06-16 06:33 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\bcastdvr
2018-06-16 06:33 - 2018-04-11 18:38 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2018-06-16 06:33 - 2018-04-11 18:38 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2018-06-16 06:33 - 2018-04-11 18:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-06-16 06:31 - 2018-04-11 18:38 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
2018-06-16 06:31 - 2018-04-11 18:38 - 000000000 ___RD C:\WINDOWS\Offline Web Pages
2018-06-16 03:14 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\appcompat
2018-06-16 02:30 - 2018-04-11 18:41 - 000000000 ____D C:\WINDOWS\Setup
2018-06-16 02:30 - 2018-04-11 18:38 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2018-06-16 02:30 - 2018-04-11 18:38 - 000000000 __RHD C:\Users\Public\Libraries
2018-06-16 02:30 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2018-06-16 02:30 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2018-06-16 02:30 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\spool
2018-06-16 02:30 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\Macromed
2018-06-16 02:30 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\InputMethod
2018-06-16 02:30 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\InputMethod
2018-06-16 02:30 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\Help
2018-06-16 02:30 - 2018-04-11 18:38 - 000000000 ____D C:\Program Files\Windows Portable Devices
2018-06-16 02:30 - 2018-04-11 18:38 - 000000000 ____D C:\Program Files\Windows Multimedia Platform
2018-06-16 02:30 - 2018-04-11 18:38 - 000000000 ____D C:\Program Files\Common Files\Services
2018-06-16 02:30 - 2018-04-11 18:38 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices
2018-06-16 02:30 - 2018-04-11 18:38 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2018-06-16 02:30 - 2018-01-13 20:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CMS
2018-06-16 02:30 - 2018-01-05 08:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 5.3
2018-06-16 02:30 - 2017-12-12 18:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2018-06-16 02:30 - 2017-12-12 18:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva
2018-06-16 02:30 - 2017-12-12 18:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Defraggler
2018-06-16 02:30 - 2017-10-22 10:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Quicken 2017
2018-06-16 02:30 - 2017-10-15 07:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AllMusicConverter
2018-06-16 02:30 - 2017-10-15 03:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AllMusicConverter Media Suite
2018-06-16 02:30 - 2017-10-15 02:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2018-06-16 02:30 - 2017-10-12 11:28 - 000000000 ____D C:\WINDOWS\SysWOW64\Silabs
2018-06-16 02:30 - 2017-10-12 11:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WeatherLink
2018-06-16 02:30 - 2017-10-12 10:26 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2018-06-16 02:30 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2018-06-16 02:30 - 2017-09-19 11:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TrustedQSL
2018-06-16 02:30 - 2017-08-23 09:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master 12.5
2018-06-16 02:30 - 2017-08-17 10:57 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LightScribe Direct Disc Labeling
2018-06-16 02:30 - 2017-08-11 14:00 - 000000000 ____D C:\Program Files\UNP
2018-06-16 02:30 - 2017-01-19 21:49 - 000000000 ____D C:\WINDOWS\SysWOW64\sda
2018-06-16 02:30 - 2016-11-11 12:33 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2018-06-16 02:30 - 2016-11-11 12:33 - 000000000 ____D C:\WINDOWS\system32\SRSLabs
2018-06-16 02:30 - 2016-11-11 11:46 - 000000000 ____D C:\WINDOWS\SysWOW64\BestPractices
2018-06-16 02:30 - 2015-03-10 11:37 - 000000000 ____D C:\Program Files\HP
2018-06-16 02:30 - 2015-03-08 13:37 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-06-16 02:30 - 2015-03-08 10:10 - 000000000 ____D C:\Program Files\Intel
2018-06-16 02:30 - 2013-08-22 10:36 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2018-06-16 02:30 - 2013-08-22 10:36 - 000000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Shared
2018-06-16 02:30 - 2013-08-22 10:36 - 000000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared
2018-06-16 02:27 - 2017-10-15 09:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoundTaxi Media Suite
2018-06-16 02:27 - 2017-09-21 19:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TrippLite
2018-06-16 02:27 - 2017-08-11 10:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis
2018-06-16 02:27 - 2016-11-11 11:46 - 000000000 ____D C:\WINDOWS\system32\BestPractices
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ur-PK
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ug-CN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tt-RU
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tk-TM
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\te-IN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ta-IN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sw-KE
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sq-AL
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\si-LK
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\quz-PE
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\prs-AF
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-IN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\or-IN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\nn-NO
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ne-NP
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mt-MT
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mr-IN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mn-MN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ml-IN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mk-MK
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mi-NZ
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\lo-LA
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\lb-LU
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ky-KG
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\kok-IN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\kn-IN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\km-KH
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\kk-KZ
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ka-GE
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\is-IS
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\hy-AM
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\gu-IN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\gd-GB
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ga-IE
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\fil-PH
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\fa-IR
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\cy-GB
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-IN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-BD
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\be-BY
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\as-IN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\am-ET
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\af-ZA
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\vi-VN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ur-PK
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ug-CN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\tt-RU
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\tk-TM
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\te-IN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\sw-KE
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\sq-AL
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\quz-PE
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\prs-AF
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\pa-IN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\or-IN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\nn-NO
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ne-NP
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\mt-MT
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\mr-IN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\mn-MN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ml-IN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\mk-MK
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\mi-NZ
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\lo-LA
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\lb-LU
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ky-KG
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\kok-IN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\kn-IN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\km-KH
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\kk-KZ
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ka-GE
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\is-IS
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\id-ID
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\hy-AM
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\gu-IN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\gd-GB
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ga-IE
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\fil-PH
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\fa-IR
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\cy-GB
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\bn-IN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\bn-BD
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\be-BY
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\as-IN
2018-06-16 02:24 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\af-ZA
2018-06-16 02:24 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2018-06-16 02:24 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\ta-in
2018-06-16 02:24 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\si-lk
2018-06-16 02:24 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\setup
2018-06-16 02:24 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\am-et
2018-06-16 02:24 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\Provisioning
2018-06-16 02:17 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2018-06-16 02:17 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2018-06-16 02:17 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2018-06-16 02:17 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2018-06-16 02:17 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\en-GB
2018-06-16 02:17 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2018-06-16 02:17 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2018-06-16 02:17 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\et-EE
2018-06-16 02:17 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\es-MX
2018-06-16 02:17 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\en-GB
2018-06-16 01:36 - 2017-08-13 13:23 - 000000258 __RSH C:\ProgramData\ntuser.pol
2018-06-16 00:11 - 2017-08-11 09:21 - 000000000 ____D C:\Users\ralph\AppData\Local\ConnectedDevicesPlatform
2018-06-16 00:10 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\Registration
2018-06-16 00:10 - 2017-10-19 05:26 - 000000000 ___RD C:\Users\ralph\3D Objects
2018-06-16 00:07 - 2018-04-11 18:38 - 000000000 ___RD C:\Program Files\Windows Defender
2018-06-15 23:57 - 2015-08-02 06:22 - 000022840 _____ C:\WINDOWS\system32\emptyregdb.dat
2018-06-15 23:50 - 2017-08-11 11:37 - 000002353 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-06-15 23:50 - 2017-08-11 11:37 - 000002312 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-06-15 23:44 - 2018-01-23 09:55 - 000000000 ____D C:\Users\ralph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EseeCloud
2018-06-15 23:44 - 2017-10-15 07:54 - 000000000 ____D C:\Users\ralph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HandBrake
2018-06-15 23:44 - 2017-09-30 06:07 - 000000000 ____D C:\Users\ralph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Radio Mobile
2018-06-15 23:44 - 2017-08-15 04:05 - 000000000 ____D C:\Users\ralph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Asunsoft Password Geeker Advanced
2018-06-15 23:44 - 2017-08-15 02:16 - 000000000 ____D C:\Users\ralph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Asunsoft Password Geeker Advanced Trial
2018-06-15 23:39 - 2017-10-19 04:54 - 000000000 ____D C:\Users\Rward\AppData\Local\Packages
2018-06-15 23:37 - 2017-10-12 10:26 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2018-06-15 23:37 - 2012-04-30 05:11 - 000000000 ____D C:\temp
2018-06-15 23:36 - 2018-04-11 18:38 - 000000000 ____D C:\ProgramData\USOPrivate
2018-06-15 23:36 - 2017-10-12 10:26 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2018-06-15 22:06 - 2016-04-27 15:43 - 000111048 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2018-06-15 22:05 - 2016-04-27 15:42 - 000000000 ____D C:\Program Files\Java
2018-06-15 22:02 - 2017-08-29 18:21 - 000000000 ____D C:\ProgramData\Oracle
2018-06-15 22:02 - 2015-03-14 05:25 - 000000000 ____D C:\Program Files (x86)\Java
2018-06-12 18:11 - 2017-10-12 12:15 - 133315992 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2018-06-12 18:11 - 2017-08-11 14:01 - 133315992 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-06-09 02:04 - 2018-04-14 21:48 - 000000000 ____D C:\Users\ralph\AppData\Roaming\Media Player Classic
2018-06-09 02:04 - 2017-08-11 09:37 - 000000000 ____D C:\Users\ralph\AppData\Local\CrashDumps
2018-06-08 19:40 - 2015-05-23 00:20 - 000000000 ____D C:\Program Files (x86)\Adobe
2018-06-08 18:32 - 2017-11-29 21:13 - 000000000 ____D C:\Program Files (x86)\D4
2018-06-08 18:20 - 2017-08-11 10:32 - 000000000 ____D C:\ProgramData\NortonInstaller
2018-06-08 17:49 - 2015-03-26 02:54 - 000000000 ____D C:\Program Files\Bonjour
2018-06-08 17:49 - 2015-03-26 02:54 - 000000000 ____D C:\Program Files (x86)\Bonjour
2018-06-08 15:57 - 2017-08-11 10:32 - 000000000 ____D C:\ProgramData\Norton
2018-06-08 15:32 - 2017-08-11 10:33 - 000000000 ____D C:\Program Files\Norton Security
2018-06-08 15:03 - 2017-08-11 10:30 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2018-06-08 15:03 - 2017-08-11 10:30 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-06-08 14:57 - 2015-03-07 10:34 - 000000000 ____D C:\Program Files\Common Files\Symantec Shared
2018-06-05 18:29 - 2018-04-11 18:41 - 000835056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2018-06-05 18:29 - 2018-04-11 18:41 - 000179704 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl

==================== Files in the root of some directories =======

2016-06-02 22:59 - 2016-06-02 22:57 - 424108520 _____ () C:\Users\Public\AcronisTrueImage2016_web (2).exe
2015-05-20 22:57 - 2016-07-26 23:59 - 000021368 _____ (Schneider Electric) C:\Users\rw\en_res.dll
2015-05-20 22:57 - 2016-07-26 23:59 - 000021368 _____ (Schneider Electric) C:\Users\rw\es_res.dll
2015-05-20 22:57 - 2016-07-26 23:59 - 000021880 _____ (Schneider Electric) C:\Users\rw\fr_res.dll
2015-05-20 22:57 - 2013-02-22 13:21 - 000113224 _____ () C:\Users\rw\g2ax_customer_downloadhelper_win32_x86.exe
2015-05-20 22:57 - 2016-07-26 23:59 - 000021880 _____ (Schneider Electric) C:\Users\rw\grm_res.dll
2015-05-20 22:57 - 2016-07-26 23:59 - 000021368 _____ (Schneider Electric) C:\Users\rw\it_res.dll
2015-05-20 22:57 - 2016-07-26 23:59 - 000020344 _____ (Schneider Electric) C:\Users\rw\jp_res.dll
2015-05-20 22:57 - 2016-07-26 23:59 - 001079808 _____ (Microsoft Corporation) C:\Users\rw\mfc80u.dll
2015-05-20 22:57 - 2016-07-26 23:59 - 000626688 _____ (Microsoft Corporation) C:\Users\rw\msvcr80.dll
2015-10-23 03:01 - 2015-10-23 03:16 - 095208448 _____ (Parallels Software International Inc                         ) C:\Users\rw\ParallelsAccess-3.0.1-30654-win.exe
2015-05-20 22:57 - 2016-07-26 23:59 - 013923704 _____ (Schneider Electric) C:\Users\rw\PCPE Setup.exe
2015-05-20 22:57 - 2013-01-29 23:59 - 010823568 _____ () C:\Users\rw\PPOfficeDropPatch.exe
2015-05-20 22:57 - 2016-07-26 23:59 - 000021368 _____ (Schneider Electric) C:\Users\rw\pt_res.dll
2015-05-20 22:57 - 2016-07-26 23:59 - 000018808 _____ () C:\Users\rw\ResourceReader.dll
2015-05-20 22:57 - 2016-07-26 23:59 - 000020856 _____ (Schneider Electric) C:\Users\rw\ru_res.dll
2015-05-20 22:57 - 2016-07-26 23:59 - 000019832 _____ (Schneider Electric) C:\Users\rw\zh_res.dll
2017-10-12 10:03 - 2017-10-12 10:03 - 000000706 _____ () C:\Program Files (x86)\LMIR0001.tmp.bat
2017-10-12 10:03 - 2017-10-12 10:03 - 000000514 _____ () C:\Program Files (x86)\LMIR0001.tmp_r.bat
2017-08-11 10:29 - 2018-06-20 00:18 - 000000706 _____ () C:\Program Files (x86)\LMIR0002.tmp.bat
2017-08-11 10:29 - 2018-06-20 00:18 - 000000514 _____ () C:\Program Files (x86)\LMIR0002.tmp_r.bat
2017-08-11 10:41 - 2018-06-20 07:17 - 000000706 _____ () C:\Program Files (x86)\LMIR0004.tmp.bat
2017-08-11 10:41 - 2018-06-20 07:17 - 000000514 _____ () C:\Program Files (x86)\LMIR0004.tmp_r.bat
2017-08-11 13:06 - 2017-08-11 13:06 - 000000706 _____ () C:\Program Files (x86)\LMIR0006.tmp.bat
2017-08-11 13:06 - 2017-08-11 13:06 - 000000514 _____ () C:\Program Files (x86)\LMIR0006.tmp_r.bat
2017-10-11 03:58 - 2017-10-23 16:00 - 000000033 _____ () C:\Users\ralph\AppData\Roaming\AdobeWLCMCache.dat
2017-08-23 08:49 - 2018-06-17 17:09 - 000037715 _____ () C:\Users\ralph\AppData\Roaming\Comma Separated Values.ADR
2018-06-18 15:02 - 2018-06-18 15:02 - 000009364 _____ () C:\Users\ralph\AppData\Roaming\Comma Separated Values.EML
2017-11-02 15:59 - 2017-11-02 15:59 - 000005632 _____ () C:\Users\ralph\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2018-06-20 00:18 - 2018-06-20 00:18 - 000000512 _____ () C:\Users\ralph\AppData\Local\LMIR0001.tmp_r.bat
2017-08-11 10:41 - 2018-06-20 07:16 - 000000512 _____ () C:\Users\ralph\AppData\Local\LMIR0003.tmp_r.bat
2017-10-12 10:09 - 2017-10-12 10:09 - 000000704 _____ () C:\Users\ralph\AppData\Local\LMIR0004.tmp.bat
2017-10-12 10:09 - 2017-10-12 10:09 - 000000512 _____ () C:\Users\ralph\AppData\Local\LMIR0004.tmp_r.bat
2017-08-11 13:07 - 2017-08-11 13:07 - 000000512 _____ () C:\Users\ralph\AppData\Local\LMIR0005.tmp_r.bat

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-06-15 23:32

==================== End of FRST.txt ============================

 

 

see next for Additional



#4 rmw388

rmw388
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:04:34 PM

Posted 20 June 2018 - 11:06 AM

additional.txt

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20.06.2018
Ran by ralph (20-06-2018 10:38:30)
Running from C:\Users\ralph\Desktop
Windows 10 Home Version 1803 17134.112 (X64) (2018-06-16 05:10:03)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-444302225-3719607882-3466423754-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-444302225-3719607882-3466423754-503 - Limited - Disabled)
Guest (S-1-5-21-444302225-3719607882-3466423754-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-444302225-3719607882-3466423754-1007 - Limited - Enabled)
ralph (S-1-5-21-444302225-3719607882-3466423754-1001 - Administrator - Enabled) => C:\Users\ralph
rw (S-1-5-21-444302225-3719607882-3466423754-1002 - Administrator - Enabled) => C:\Users\rw.DESKTOP-84BFGSO
Rward (S-1-5-21-444302225-3719607882-3466423754-1003 - Limited - Enabled) => C:\Users\Rward
WDAGUtilityAccount (S-1-5-21-444302225-3719607882-3466423754-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: McAfee VirusScan (Enabled - Up to date) {8BCDACFA-D264-3528-5EF8-E94FD0BC1FBC}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: McAfee VirusScan (Enabled - Up to date) {30AC4D1E-F45E-3AA6-6448-D23DAB3B5501}
FW: McAfee Firewall (Enabled) {B3F62DDF-980B-3470-75A7-407A2E6F58C7}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

1Step DVD Copy 4.5.4 (HKLM-x32\...\{1CB4ADE4-4B75-481A-BF77-EE69279DF30E}_is1) (Version: 4.5.4 - cyan soft ltd)
1Step Web-Video-Ripper Extras 4.5.4 (HKLM-x32\...\{4F7DCC3C-79E0-4d41-A85E-1F0B9DDABA02}_is1) (Version: 4.5.4 - 1i Soft)
Acronis True Image (HKLM-x32\...\{A9815535-66D1-4031-8845-0DF6DAB5B453}) (Version: 22.5.11530 - Acronis) Hidden
Acronis True Image (HKLM-x32\...\{A9815535-66D1-4031-8845-0DF6DAB5B453}Visible) (Version: 22.5.11530 - Acronis)
Adobe Flash Player 30 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 30.0.0.113 - Adobe Systems Incorporated)
Adobe Photoshop Elements 14 (HKLM-x32\...\{49F8D229-3E0E-4F43-8429-EB8F2583DB19}) (Version: 14.1 - Adobe Systems Incorporated)
AllMusicConverter 4.5.4 (HKLM-x32\...\{A1CDB5F3-4B89-404F-B6D8-879049265CE5}_is1) (Version: 4.5.4 - cyan soft ltd)
AllMusicConverter Endless Music Player 4.5.4 (HKLM-x32\...\{A1A2E29A-683B-BB20-BB0D-B97ECE1E2045}_is1) (Version: 4.5.4 - cyan soft ltd)
AllMusicConverter Media Suite 4.5.4 (HKLM-x32\...\{191A3E43-34AD-417C-BCA8-8D089AE59D25}_is1) (Version: 4.5.4 - cyan soft ltd)
ANT Drivers Installer x64 (HKLM\...\{20AB389B-8602-403C-B19B-F0A1D6C510A5}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
AnyMedia Player 4.5.4 (HKLM-x32\...\{1959CCD2-1227-4de4-97E7-04F29D526762}_is1) (Version: 4.5.4 - cyan soft ltd)
CCleaner (HKLM\...\CCleaner) (Version: 5.43 - Piriform)
CMS version 1.9.4.1 (HKLM-x32\...\{C300BB2E-1079-43BF-A820-97BB23065926}_is1) (Version: 1.9.4.1 - )
Debut Video Capture Software (HKLM-x32\...\Debut) (Version: 4.04 - NCH Software)
Defraggler (HKLM\...\Defraggler) (Version: 2.21 - Piriform)
Disk Burner 4.5.4 (HKLM-x32\...\{3B10760F-86A3-4376-A668-AC304015D5ED}_is1) (Version: 4.5.4 - cyan soft ltd)
DriveImage XML (Private Edition) (HKLM-x32\...\{F7E1CA14-B39D-452A-960B-39423DDDD933}) (Version: 2.60.000 - Runtime Software)
EaseUS Partition Master 12.5 Trial Edition (HKLM-x32\...\EaseUS Partition Master Trial Edition_is1) (Version:  - EaseUS)
Elevated Installer (HKLM-x32\...\{6E257EB0-5EFF-416D-82D4-592924566BB4}) (Version: 6.5.1.0 - Garmin Ltd or its subsidiaries) Hidden
EseeCloud 1.2.2 (HKLM-x32\...\EseeCloud) (Version: 1.2.2 - My company, Inc.)
Garmin Express (HKLM-x32\...\{3e534d41-dcc4-4f51-9858-70dd42beb3d5}) (Version: 6.5.1.0 - Garmin Ltd or its subsidiaries)
Garmin Express (HKLM-x32\...\{E1C18A5C-63D7-4DC5-977F-5B4BAB4169D9}) (Version: 6.5.1.0 - Garmin Ltd or its subsidiaries) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 67.0.3396.87 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
HandBrake 1.0.7 (HKLM-x32\...\HandBrake) (Version: 1.0.7 - )
HP LaserJet Professional M1130-M1210 MFP Series (HKLM\...\HP LaserJet Professional M1130-M1210 MFP Series) (Version:  - )
HP LaserJet Professional M1210 MFP Series Fax Installer (HKLM\...\{E94AE378-725A-41FF-BA24-397469D27FC8}) (Version: 1.3.0 - HP)
HP LaserJet Professional M1210 MFP Series Toolbox (HKLM\...\{F958F851-8DBE-420C-9D37-5ECBB6C61148}) (Version: 1.0.17 - Hewlett-Packard)
HP LaserJet Toolbox (HKLM\...\{2E8A793D-E275-46A2-BAB3-35FB95ACED57}) (Version: 3.0.0 - Hewlett-Packard)
hppLaserJetService (HKLM-x32\...\{D371F551-0DB9-4CEC-844B-4C90CE91EA0B}) (Version: 001.003.000145 - Hewlett-Packard) Hidden
hppM1130M1210SeriesLaserJetService (HKLM-x32\...\{0E448256-D515-4C3E-A5BE-0A7B76CED5D4}) (Version: 001.003.00073 - Hewlett-Packard) Hidden
hppusgM1130M1210Series (HKLM-x32\...\{DA6CC3A5-1F5B-4068-8BFF-C597BB6B8158}) (Version: 1.0.0.2 - Hewlett-Packard) Hidden
HPSSupply (HKLM-x32\...\{7902E313-FF0F-4493-ACB1-A8147B78DCD0}) (Version: 2.1.1.0000 - Hewlett Packard Development Company L.P.)
Intel® C++ Redistributables on Intel® 64 (HKLM-x32\...\{F70BCE36-25F2-4475-A918-6209B3D85BF3}) (Version: 15.0.179 - Intel Corporation)
Java 8 Update 171 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180171F0}) (Version: 8.0.1710.11 - Oracle Corporation)
KB4023057 (HKLM\...\{0339C035-CB0E-4AA1-8A94-6C306982BD86}) (Version: 2.1.0.0 - Microsoft Corporation)
K-Lite Mega Codec Pack 10.0.5 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.0.5 - )
LibreOffice 5.3.7.2 (HKLM\...\{117F3217-458C-4371-B222-00C69DE96CB2}) (Version: 5.3.7.2 - The Document Foundation)
LightScribe System Software (HKLM-x32\...\{F132000C-1CBA-458F-BF2F-FD43D59410F9}) (Version: 1.18.27.10 - LightScribe)
MarketResearch (HKLM-x32\...\{175F0111-2968-4935-8F70-33108C6A4DE3}) (Version: 130.0.374.000 - Hewlett-Packard) Hidden
McAfee Virtual Technician (HKLM-x32\...\McAfee Virtual Technician) (Version: 8.2.0.335 - McAfee, Inc.)
McAfee WebAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.0.7.203 - McAfee, Inc.)
McAfee® Total Protection (HKLM-x32\...\MSC) (Version: 16.0 R12 - McAfee, Inc.)
Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.9330.2124 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-444302225-3719607882-3466423754-1001\...\OneDriveSetup.exe) (Version: 18.065.0329.0002 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 (HKLM-x32\...\{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}) (Version: 9.0.21022.218 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
MiniTool Partition Wizard 10.2.2 (HKLM\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version:  - MiniTool Solution Ltd.)
Mozilla Firefox 60.0.2 (x64 en-US) (HKLM\...\Mozilla Firefox 60.0.2 (x64 en-US)) (Version: 60.0.2 - Mozilla)
NVIDIA 3D Vision Driver 388.13 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 388.13 - NVIDIA Corporation)
NVIDIA Graphics Driver 388.13 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 388.13 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.9330.2124 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.9330.2124 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.9330.2124 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.9330.2124 - Microsoft Corporation) Hidden
PowerAlert Local Software (HKLM-x32\...\{88E7FC62-7948-4262-93E2-1D0B1E992C84}) (Version: 12.04.55 - Tripp Lite)
Prism Video File Converter (HKLM-x32\...\Prism) (Version: 4.11 - NCH Software)
Quicken 2017 (HKLM-x32\...\{E5AE4F66-CDA1-432A-A69E-C685D454ABDA}) (Version: 26.1.15.2 - Quicken)
Radio Mobile (HKU\S-1-5-21-444302225-3719607882-3466423754-1001\...\Radio Mobile) (Version:  - )
RadioGet 4.5.4 (HKLM-x32\...\{F6C84ED7-9CAC-423b-9E00-C9BFAFBD0593}_is1) (Version: 4.5.4 - cyan soft ltd)
Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform)
RipTiger 4.5.4 (HKLM-x32\...\{AFD4597D-56CC-447F-AA68-C1BF1AEA448E}_is1) (Version: 4.5.4 - cyan soft ltd)
Scan To (HKLM\...\{E8A34AC8-0137-4515-A94B-0A0946DDC251}) (Version: 2.0.1 - HP)
Silicon Laboratories CP210x USB to UART Bridge (Driver Removal) (HKLM-x32\...\SLABCOMM&10C4&EA60) (Version:  - )
Silicon Laboratories USBXpress Device (Driver Removal) (HKLM-x32\...\SIUSBXP&10C4&EA61) (Version:  - )
SoundTaxi Media Suite 4.5.4 (HKLM-x32\...\{EF4C657F-632F-4CED-A220-F4C1C724241C}_is1) (Version: 4.5.4 - cyan soft ltd)
Speccy (HKLM\...\Speccy) (Version: 1.30 - Piriform)
TibMounter (HKLM-x32\...\{FC8CB6AE-D5DB-4F9E-BB64-BB5A0CE33B78}) (Version: 6.0.2754 - Acronis)
Trusted QSL v2.3.1 (HKLM-x32\...\{F9CE74C8-0C00-455F-A173-8983C8C5669D}) (Version: 2.3.1 - The TrustedQSL Developers)
TuneGet 4.5.4 (HKLM-x32\...\{050A0D31-6B33-4137-ADE5-C0896E5FA98D}_is1) (Version: 4.5.4 - cyan soft ltd)
Vulkan Run Time Libraries 1.0.61.0 (HKLM\...\VulkanRT1.0.61.0) (Version: 1.0.61.0 - LunarG, Inc.) Hidden
WeatherLink 6.0.3 (HKLM-x32\...\{E344C807-7DE0-4CC2-81BB-1F895CF8CBDF}) (Version: 6.0.3 - Davis Instruments Corp.)
Windows 10 Update Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22452 - Microsoft Corporation)
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Wondershare Helper Compact 2.5.2 (HKLM-x32\...\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.5.2 - Wondershare)
Wondershare PDFelement 6 Pro(Build 6.5.0) (HKLM-x32\...\{B026557A-EF19-4812-8A79-B30F94AA0A78}_is1) (Version: 6.5.0.3345 - Wondershare Software Co.,Ltd.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [     AcronisDrive] -> {5D74FD4B-4EFB-4586-8022-8637BBE40970} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2017-08-25] ()
ShellIconOverlayIdentifiers: [     AcronisSyncError] -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2017-08-25] ()
ShellIconOverlayIdentifiers: [     AcronisSyncInProgress] -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2017-08-25] ()
ShellIconOverlayIdentifiers: [     AcronisSyncOk] -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2017-08-25] ()
ContextMenuHandlers1: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2016-03-08] (Piriform Ltd)
ContextMenuHandlers1: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => c:\Program Files\McAfee\MSC\McCtxMenuFrmWrk.dll [2018-05-08] (McAfee, Inc.)
ContextMenuHandlers4: [RecuvaShellExt] -> [CC]{435E5DF5-2510-463C-B223-BDA47006D002} =>  -> No File
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-10-27] (NVIDIA Corporation)
ContextMenuHandlers6: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2016-03-08] (Piriform Ltd)
ContextMenuHandlers6: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => c:\Program Files\McAfee\MSC\McCtxMenuFrmWrk.dll [2018-05-08] (McAfee, Inc.)
ContextMenuHandlers6: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-01] (Piriform Ltd)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {08F8FA9A-C8DE-4F2E-A594-4801DD5E2515} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe [2018-02-28] (McAfee, Inc.)
Task: {13B1C226-8E40-46CF-8390-B4EBE986C77E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-25] (Google Inc.)
Task: {15E71076-A021-438C-8797-0B7869D0E02E} - System32\Tasks\Microsoft\Windows\Setup\Notifier => C:\WINDOWS\system32\Notifier.exe
Task: {1E65401F-B47A-4A60-B29E-E1D9CDC0A6FF} - System32\Tasks\NCH Software\PrismSevenDays => C:\Program Files (x86)\NCH Software\Prism\Prism.exe [2018-06-11] (NCH Software)
Task: {25B8789C-5692-4A10-BB42-E2B4A109329F} - System32\Tasks\AdobeAAMUpdater-1.0-RWDESK-ralph => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01] (Adobe Systems Incorporated)
Task: {2A531A1F-6491-45EB-9871-ADAD74859816} - System32\Tasks\Microsoft\Office\OfficeOsfInstaller => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\osfinstaller.exe [2018-06-19] (Microsoft Corporation)
Task: {2BE4DDA3-3DD9-4331-894F-693B4E7E8895} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.16.17656.18052-0\MpCmdRun.exe [2018-06-16] (Microsoft Corporation)
Task: {47C412F0-5B1B-4536-AEA4-D28D43DCB430} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-04-30] (AVAST Software)
Task: {4B2A8386-E478-49F7-9943-89406AE55D87} - System32\Tasks\AdobeAAMUpdater-1.0-DESKTOP-84BFGSO-ralph => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01] (Adobe Systems Incorporated)
Task: {4DF3880B-40D9-4236-8707-FCE0D25EFF04} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-06-19] (Microsoft Corporation)
Task: {51B98613-7A60-4F02-B5C4-A28EDB689FA5} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.16.17656.18052-0\MpCmdRun.exe [2018-06-16] (Microsoft Corporation)
Task: {577DB4A5-EA14-4C98-81BD-121EB79163B0} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2016-04-08] ()
Task: {5836168B-0445-4545-B5C6-24837B0ACE79} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {5994D7D2-1C51-4BEF-8551-5DEE5C18F7EE} - System32\Tasks\Adobe Uninstaller => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
Task: {63E27339-294E-468D-9D03-EF1BBE3B0937} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-25] (Google Inc.)
Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-11] ()
Task: {6B7E306C-53DD-49E3-B4DE-149220A68235} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-06-08] (Adobe Systems Incorporated)
Task: {6C39ACC3-7A97-4AA2-8E9D-C1320B3F8FE5} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-05-24] (Piriform Ltd)
Task: {6F053E93-C08B-40E1-9306-37072601E684} - System32\Tasks\McAfee\DAD.Execute.Updates => C:\Program Files\Common Files\McAfee\DynamicAppDownloader\1.1.178\DADUpdater.exe [2018-06-19] (McAfee, Inc.)
Task: {7AC2BCC3-A3A0-46A1-B70C-00B56123BE13} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2018-06-19] (Microsoft Corporation)
Task: {83C30CC4-1A21-4325-AF4C-21AFE167506E} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-06-12] (Microsoft Corporation)
Task: {89B44767-2B44-4D0B-839A-F798570F5859} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.16.17656.18052-0\MpCmdRun.exe [2018-06-16] (Microsoft Corporation)
Task: {99669831-D10B-4520-AD54-802D6A873B3B} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-06-12] (Microsoft Corporation)
Task: {9E9CCCD5-C933-4F50-A0C7-BAFA20F2259F} - System32\Tasks\McAfee\McAfee Idle Detection Task
Task: {B57F823E-F3DB-4307-B741-F6A605A5998C} - System32\Tasks\McAfee DAT Built in test => C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.0.5.243\mcdatrep.exe [2018-06-18] (McAfee, LLC.)
Task: {B811FC34-B661-4D8D-BE66-B93ECA8CFA8F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.16.17656.18052-0\MpCmdRun.exe [2018-06-16] (Microsoft Corporation)
Task: {BA757CF7-20EB-4720-BA55-57AEBF8E2B7E} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_30_0_0_113_Plugin.exe [2018-06-08] (Adobe Systems Incorporated)
Task: {C5B1CAF6-2D4B-46C9-971D-03EFB4C1F643} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent
Task: {D4C9542F-4BE3-4409-89F9-18773B3F3AC3} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-06-19] (Microsoft Corporation)
Task: {DCD269FF-A2C9-498D-8B7D-43C63ACD9A74} - \OneDrive Standalone Update Task-S-1-5-21-444302225-3719607882-3466423754-1003 -> No File <==== ATTENTION
Task: {FE2738ED-F380-4771-9246-BE6253F3490B} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe [2018-05-04] (McAfee, Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\HPCeeScheduleForrw.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2017-10-14 16:02 - 2012-09-29 13:25 - 000409088 ____N () C:\WINDOWS\System32\HPM1210LM.DLL
2017-10-14 16:03 - 2012-09-29 13:25 - 000074240 ____N () C:\WINDOWS\system32\spool\PRTPROCS\x64\HPM1210PP.dll
2017-11-22 12:20 - 2017-11-22 12:20 - 001216760 _____ () C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
2018-04-10 20:51 - 2018-04-10 20:51 - 006096688 _____ () C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
2018-04-06 06:05 - 2018-04-06 06:05 - 000896136 _____ () C:\Program Files\Common Files\McAfee\CSP\2.9.175.0\McCSPMsgBusDLL.dll
2018-04-11 18:34 - 2018-04-11 18:34 - 000491744 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2017-11-22 12:06 - 2017-11-22 12:06 - 000585296 _____ () C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
2018-04-03 10:01 - 2018-04-03 10:01 - 004630496 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
2018-04-30 06:20 - 2018-04-30 06:20 - 000061408 _____ () C:\Program Files\CCleaner\branding.dll
2017-09-26 13:41 - 2017-09-26 13:41 - 007003048 _____ () C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
2017-08-25 07:51 - 2017-08-25 07:51 - 005825576 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll
2018-04-11 18:34 - 2018-04-11 18:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll
2018-04-11 18:34 - 2018-04-11 18:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2018-06-16 06:25 - 2018-06-08 03:56 - 002185216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-06-16 06:26 - 2018-06-08 03:56 - 002060288 _____ () C:\Windows\System32\speech_onecore\engines\tts\MSTTSEngine_OneCore.dll
2018-04-11 18:34 - 2018-04-11 18:34 - 000031232 _____ () C:\WINDOWS\system32\Windows.WARP.JITService.exe
2018-06-08 14:28 - 2018-06-08 14:28 - 000084992 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11804.1001.10.0_x64__8wekyb3d8bbwe\WinStore.Preview.dll
2018-06-08 14:28 - 2018-06-08 14:28 - 001873120 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11804.1001.10.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2018-06-08 14:28 - 2018-06-08 14:28 - 007813120 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11804.1001.10.0_x64__8wekyb3d8bbwe\WinStore.Entertainment.Mobile.dll
2017-08-25 07:51 - 2017-08-25 07:51 - 000277538 _____ () C:\Program Files (x86)\Common Files\Acronis\ActiveProtection\LIBMAGIC.dll
2017-08-25 07:51 - 2017-08-25 07:51 - 002386352 _____ () C:\Program Files (x86)\Common Files\Acronis\ActiveProtection\xerces_c.dll
2017-08-25 07:51 - 2017-08-25 07:51 - 000160168 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\libevent.dll
2017-08-25 07:51 - 2017-08-25 07:51 - 000685488 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\sqlite3.dll
2018-04-03 10:00 - 2018-04-03 10:00 - 003489632 _____ () C:\Program Files (x86)\Common Files\Acronis\Infrastructure\atih_mms_addon.dll
2018-04-03 10:00 - 2018-04-03 10:00 - 001334496 _____ () C:\Program Files (x86)\Common Files\Acronis\Infrastructure\services_mms_addon.dll
2018-04-03 09:59 - 2018-04-03 09:59 - 022740976 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\ti_managers.dll
2018-04-03 08:55 - 2018-04-03 08:55 - 000414936 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\resource.dll
2017-11-22 11:51 - 2017-11-22 11:51 - 000136736 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\afcdpapi.dll
2017-09-26 13:41 - 2017-09-26 13:41 - 000255008 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\sync_agent_api.dll
2018-06-19 21:35 - 2018-06-19 21:33 - 000251872 _____ () C:\Program Files (x86)\LogMeIn Rescue Applet\LMIR0002.tmp\LMIRhook.000.dll
2018-04-03 08:53 - 2018-04-03 08:53 - 008988888 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\qt_resources.dll
2017-11-22 12:04 - 2017-11-22 12:04 - 000796192 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\qt_supp.dll
2018-04-03 08:53 - 2018-04-03 08:53 - 000057048 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\rpc_client.dll
2017-08-25 07:51 - 2017-08-25 07:51 - 000444336 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\ulxmlrpcpp.dll
2016-08-29 23:16 - 2016-08-29 23:16 - 000115632 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\expat.dll
2018-06-17 17:57 - 2016-07-21 10:54 - 000137728 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll
2018-06-17 17:57 - 2016-10-08 16:48 - 001506304 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\DAQExp.dll
2018-06-19 23:20 - 2018-06-19 23:20 - 000164528 _____ () C:\Program Files (x86)\Microsoft Office\root\Office16\JitV.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:AEC0AC81 [175]
AlternateDataStreams: C:\Users\ralph\Documents\aquachek truetest spa.jpeg:3or4kl4x13tuuug3Byamue2s4b [105]
AlternateDataStreams: C:\Users\ralph\Documents\aquachek truetest spa.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\ralph\Documents\NEIMA part 1.tiff:3or4kl4x13tuuug3Byamue2s4b [105]
AlternateDataStreams: C:\Users\ralph\Documents\NEIMA part 1.tiff:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\ralph\Documents\page 1 back.tiff:3or4kl4x13tuuug3Byamue2s4b [105]
AlternateDataStreams: C:\Users\ralph\Documents\page 1 back.tiff:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\ralph\Documents\page 1 front.tiff:3or4kl4x13tuuug3Byamue2s4b [105]
AlternateDataStreams: C:\Users\ralph\Documents\page 1 front.tiff:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\ralph\Documents\page 2 back.tiff:3or4kl4x13tuuug3Byamue2s4b [105]
AlternateDataStreams: C:\Users\ralph\Documents\page 2 back.tiff:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\ralph\Documents\page 2 front.tiff:3or4kl4x13tuuug3Byamue2s4b [105]
AlternateDataStreams: C:\Users\ralph\Documents\page 2 front.tiff:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\rw\Documents\ham license 2.jpeg:3or4kl4x13tuuug3Byamue2s4b [109]
AlternateDataStreams: C:\Users\rw\Documents\ham license 2.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\rw\Documents\races app scan.jpeg:3or4kl4x13tuuug3Byamue2s4b [109]
AlternateDataStreams: C:\Users\rw\Documents\races app scan.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ModuleCoreService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcapexe => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ModuleCoreService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2016-07-16 06:47 - 2018-06-18 20:10 - 000000768 _____ C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1    localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-444302225-3719607882-3466423754-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\ralph\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\Services: AcronisActiveProtectionService => 2
MSCONFIG\Services: AcrSch2Svc => 2
MSCONFIG\Services: AdobeActiveFileMonitor14.0 => 2
MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AdobeUpdateService => 2
MSCONFIG\Services: afcdpsrv => 2
MSCONFIG\Services: AGSService => 2
MSCONFIG\Services: DirMngr => 2
MSCONFIG\Services: GladFileMonSvc => 2
MSCONFIG\Services: GSService => 3
MSCONFIG\Services: ibtsiva => 2
MSCONFIG\Services: LightScribeService => 2
MSCONFIG\Services: MBAMService => 2
MSCONFIG\Services: mmsminisrv => 2
MSCONFIG\Services: mobile_backup_server => 3
MSCONFIG\Services: mobile_backup_status_server => 3
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: NS => 2
MSCONFIG\Services: NVDisplay.ContainerLocalSystem => 2
MSCONFIG\Services: PowerAlert Agent => 2
MSCONFIG\Services: syncagentsrv => 2
MSCONFIG\Services: Tib Mounter Service => 3
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run32: => "Wondershare Helper Compact.exe"
HKLM\...\StartupApproved\Run32: => "AcronisTibMounterMonitor"
HKLM\...\StartupApproved\Run32: => "Acrobat Assistant 8.0"
HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud"
HKLM\...\StartupApproved\Run32: => "Dimension4"
HKLM\...\StartupApproved\Run32: => "AdobeAAMUpdater-1.0"
HKU\S-1-5-21-444302225-3719607882-3466423754-1001\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer"
HKU\S-1-5-21-444302225-3719607882-3466423754-1001\...\StartupApproved\Run: => "LightScribe Control Panel"
HKU\S-1-5-21-444302225-3719607882-3466423754-1001\...\StartupApproved\Run: => "OneDriveSetup"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{8AF37841-3B8B-4614-85FB-4C11F3CB5904}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{B82CA0AF-56BF-4A32-A7FB-C01933A61FD1}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\ActiveProtection\anti_ransomware_service.exe
FirewallRules: [{C4D0DB4F-38C4-4A14-B98F-B797AF1034F4}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\ga_service.exe
FirewallRules: [{1862B239-46E8-4C47-95D5-82A6FE1C34D2}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\mobile_backup_status_server.exe
FirewallRules: [{4B7ED983-24EB-4955-B5DA-7B8D7662DA68}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\MobileBackupServer\mobile_backup_server.exe
FirewallRules: [{FF061000-F1B7-429C-9DCA-11530B0C8AEF}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\acronis_drive.exe
FirewallRules: [{B0D9906A-6922-468A-99A4-BDD0C0C86D1A}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\SystemReport.exe
FirewallRules: [{214A9A6F-8FDD-48FB-A3C6-61973DBD2720}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\MediaBuilder.exe
FirewallRules: [{8B166F4B-F619-47A9-9094-0948E13B156D}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\TrueImageHome\TrueImageHomeService.exe
FirewallRules: [{8F8ABF97-27A2-4D3D-A502-BC31A9353D78}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageTools.exe
FirewallRules: [{2F2E2A5E-754D-4CAE-B3A7-35F6F5715E2B}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
FirewallRules: [{78A21485-0CED-450F-A942-C8ED5A13C8C3}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImage.exe
FirewallRules: [{27090D60-0A5F-4178-8245-0FD6A03E7C5A}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe
FirewallRules: [{33F6C963-DE24-4BD4-A3A4-6FCD2D691F9D}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
FirewallRules: [UDP Query User{2F8794E2-3B57-4176-AF34-B1D80D18E01D}C:\cms\cms.exe] => (Allow) C:\cms\cms.exe
FirewallRules: [TCP Query User{CD5B3072-0784-42D5-8B2F-058E40BCDC95}C:\cms\cms.exe] => (Allow) C:\cms\cms.exe
FirewallRules: [{59ABE7FF-4EFE-474C-B88B-F1E32174B3A3}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{71CE777F-F30E-4CB0-BCD7-942C9D59944A}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [UDP Query User{EE1810D0-67F9-4D80-826A-70DF1219659B}C:\program files (x86)\acronis\trueimagehome\trueimage.exe] => (Allow) C:\program files (x86)\acronis\trueimagehome\trueimage.exe
FirewallRules: [TCP Query User{0B1D80C2-F1B9-4ADC-9F53-2001E5A4F310}C:\program files (x86)\acronis\trueimagehome\trueimage.exe] => (Allow) C:\program files (x86)\acronis\trueimagehome\trueimage.exe
FirewallRules: [{D4D63686-328B-4D64-8401-B68C5BAA91CC}] => (Allow) LPort=9100
FirewallRules: [{3F31878F-35E1-4555-A09C-6943140CBA19}] => (Allow) LPort=427
FirewallRules: [{BEF42A82-6E1B-467D-8729-7A3B44416DB2}] => (Allow) LPort=161
FirewallRules: [{EB2B3CE2-718C-4323-B347-7F7972B63CE6}] => (Allow) LPort=427
FirewallRules: [{065C7717-12BC-48F3-BEBC-B85856476348}] => (Allow) C:\Program Files (x86)\RipTiger\RipTiger.exe
FirewallRules: [{1FCDF789-35EA-4B4F-A269-D9B633721A3F}] => (Allow) C:\Program Files (x86)\RipTiger\RipTiger.exe
FirewallRules: [{3C9036A9-C819-4CCC-9700-AE6F4AA51E80}] => (Allow) C:\Program Files (x86)\RipTiger\HTTPDownloaderApp.exe
FirewallRules: [{7219AFEF-F5D0-4D3B-9DBE-0BE6AD8EF3A4}] => (Allow) C:\Program Files (x86)\RipTiger\HTTPDownloaderApp.exe
FirewallRules: [{11230D1D-4F4B-4F0C-A000-5391A34FC764}] => (Allow) C:\Program Files (x86)\RipTiger\RTMPDownloaderApp.exe
FirewallRules: [{A6BE8446-835E-4AAD-BC2F-2D4EE4649DAB}] => (Allow) C:\Program Files (x86)\RipTiger\RTMPDownloaderApp.exe
FirewallRules: [{B885B048-381C-4C63-9E7F-7732B4A92B6E}] => (Allow) C:\Program Files (x86)\RipTiger\VideoDownloadApp_RTMP.exe
FirewallRules: [{C785DBCA-7C3A-4713-81A6-6A28AE03F848}] => (Allow) C:\Program Files (x86)\RipTiger\VideoDownloadApp_RTMP.exe
FirewallRules: [{3613B526-63F6-4DE3-80DE-A2A5E57BA439}] => (Allow) C:\Program Files (x86)\RipTiger\MMSDownloaderApp.exe
FirewallRules: [{0CE85743-BB67-47F6-934D-F0AB8E1110B2}] => (Allow) C:\Program Files (x86)\RipTiger\MMSDownloaderApp.exe
FirewallRules: [{696F79F6-8872-499F-A03D-64E3CD02A76D}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe
FirewallRules: [{4C8D03DF-614C-4F2E-A7B6-B907E1C48994}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe
FirewallRules: [{E9385AAC-23E9-486A-9D5A-CAC1485C10C0}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{496FF627-3DE5-4116-A28E-0523B19F0E40}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{38109FF4-12D9-4297-971F-C8214D67222D}] => (Allow) C:\Users\ralph\Downloads\ProductDetection.exe
FirewallRules: [{18348BFB-C829-4E7E-8104-B39CD17DE6E9}] => (Allow) C:\Users\ralph\Downloads\ProductDetection.exe
FirewallRules: [{25B4531A-06ED-4009-BD4E-642F8A0A240F}] => (Allow) C:\Program Files (x86)\McAfee\Supportability\MVT\MvtApp.exe
FirewallRules: [{6C4769D4-E0CE-487D-8F90-1FD3852F8531}] => (Allow) C:\Program Files (x86)\McAfee\Supportability\MVT\MvtApp.exe

==================== Restore Points =========================

10-07-2017 21:57:10 Windows Update
05-06-2018 16:18:48 Windows Modules Installer
07-06-2018 01:29:50 Removed AcuRite PC Connect for Windows.
16-06-2018 06:23:05 Windows Update
16-06-2018 06:24:40 Windows Update
18-06-2018 23:06:45 McAfee Vulnerability Scanner
18-06-2018 23:17:13 Removed Adobe Acrobat DC.

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (06/20/2018 10:39:17 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: OUTLOOK.EXE, version: 16.0.9330.2124, time stamp: 0x5b20a322
Faulting module name: NPDFCG.cnv, version: 20.0.16316.100, time stamp: 0x5761c6a9
Exception code: 0xc00000fd
Fault offset: 0x0001b1a3
Faulting process id: 0x3a7c
Faulting application start time: 0x01d408ab8a09f2fc
Faulting application path: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
Faulting module path: C:\Program Files (x86)\Common Files\Microsoft Shared\TextConv\NPDFCG.cnv
Report Id: a0b91341-59b2-4d1b-9952-0682a6cab63c
Faulting package full name:
Faulting package-relative application ID:

Error: (06/20/2018 07:47:36 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: TrueImage.exe, version: 22.5.1.11530, time stamp: 0x5ac3365e
Faulting module name: ntdll.dll, version: 10.0.17134.112, time stamp: 0xcfe5bd82
Exception code: 0xc0000005
Fault offset: 0x00022e19
Faulting process id: 0x16e8
Faulting application start time: 0x01d408943d412976
Faulting application path: C:\Program Files (x86)\Acronis\TrueImageHome\TrueImage.exe
Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll
Report Id: af4bfb59-5b8a-408b-8912-19c9386cb302
Faulting package full name:
Faulting package-relative application ID:

Error: (06/20/2018 03:31:49 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: esu.exe, version: 1.0.0.0, time stamp: 0x5707c9f2
Faulting module name: KERNELBASE.dll, version: 10.0.17134.112, time stamp: 0xc863c6f9
Exception code: 0xe0434352
Fault offset: 0x0010db52
Faulting process id: 0x2e38
Faulting application start time: 0x01d4087119fbd35e
Faulting application path: C:\Program Files (x86)\Garmin\Express SelfUpdater\esu.exe
Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
Report Id: 0f666bbd-d7a8-480c-94d4-6b64bf8c82c6
Faulting package full name:
Faulting package-relative application ID:

Error: (06/20/2018 03:31:46 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: esu.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.TypeLoadException
   at Garmin.Omt.Express.SelfUpdater.Program.RealMain()
   at Garmin.Omt.Express.SelfUpdater.Program.Main(System.String[])

Error: (06/20/2018 12:24:00 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: OUTLOOK.EXE, version: 16.0.9330.2124, time stamp: 0x5b20a322
Faulting module name: NPDFCG.cnv, version: 20.0.16316.100, time stamp: 0x5761c6a9
Exception code: 0xc00000fd
Fault offset: 0x0001b1a3
Faulting process id: 0x6a4
Faulting application start time: 0x01d408530763ae15
Faulting application path: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
Faulting module path: C:\Program Files (x86)\Common Files\Microsoft Shared\TextConv\NPDFCG.cnv
Report Id: e29f4732-975e-4052-b7b2-db0a2a180703
Faulting package full name:
Faulting package-relative application ID:

Error: (06/20/2018 12:20:46 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: )
Description: Acquisition of End User License failed. hr=0x80072EFE
Sku Id=b58a5943-16ea-420f-a611-7b230acd762c

Error: (06/20/2018 12:20:46 AM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
Description: License acquisition failure details.
hr=0x80072EFE

Error: (06/20/2018 12:19:27 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: )
Description: Acquisition of End User License failed. hr=0x80072EFE
Sku Id=b58a5943-16ea-420f-a611-7b230acd762c


System errors:
=============
Error: (06/19/2018 11:42:54 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (06/19/2018 11:42:14 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (06/19/2018 11:39:27 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (06/19/2018 11:35:57 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (06/19/2018 11:25:51 PM) (Source: DCOM) (EventID: 10016) (User: RWDESK)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
 and APPID
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
 to the user RWDESK\ralph SID (S-1-5-21-444302225-3719607882-3466423754-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.ContentDeliveryManager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-350187224-1905355452-1037786396-3028148496-2624191407-3283318427-1255436723). This security permission can be modified using the Component Services administrative tool.

Error: (06/19/2018 11:19:23 PM) (Source: DCOM) (EventID: 10016) (User: RWDESK)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
 and APPID
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
 to the user RWDESK\ralph SID (S-1-5-21-444302225-3719607882-3466423754-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.ContentDeliveryManager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-350187224-1905355452-1037786396-3028148496-2624191407-3283318427-1255436723). This security permission can be modified using the Component Services administrative tool.

Error: (06/19/2018 11:13:13 PM) (Source: DCOM) (EventID: 10016) (User: RWDESK)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
 and APPID
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
 to the user RWDESK\ralph SID (S-1-5-21-444302225-3719607882-3466423754-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.ContentDeliveryManager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-350187224-1905355452-1037786396-3028148496-2624191407-3283318427-1255436723). This security permission can be modified using the Component Services administrative tool.

Error: (06/19/2018 11:12:16 PM) (Source: DCOM) (EventID: 10016) (User: RWDESK)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user RWDESK\ralph SID (S-1-5-21-444302225-3719607882-3466423754-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.


Windows Defender:
===================================
Date: 2018-06-18 18:09:08.929
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {EF7C9C7D-7064-4C2A-BC1E-090BBF874983}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2018-06-16 17:55:42.444
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {6C45A13B-2331-4EE4-99AA-60248437DB72}
Scan Type: Antimalware
Scan Parameters: Full Scan

Date: 2018-06-18 20:19:55.853
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.269.1427.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.14901.4
Error code: 0x80240016
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

Date: 2018-06-17 20:19:50.716
Description:
Windows Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: On Access
Error Code: 0x8007043c
Error description: This service cannot be started in Safe Mode
Reason: Antimalware protection has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.

Date: 2018-06-16 06:31:18.897
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.269.920.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.14901.4
Error code: 0x80240016
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

CodeIntegrity:
===================================

Date: 2018-06-20 07:10:00.962
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Users\rw\Documents\WinSxS\x86_microsoft-windows-cloudstoragewizard_31bf3856ad364e35_6.3.9600.17415_none_895a2497a8f7a9b7\CloudStorageWizard.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-06-20 07:10:00.960
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Users\rw\Documents\WinSxS\x86_microsoft-windows-cloudstoragewizard_31bf3856ad364e35_6.3.9600.17415_none_895a2497a8f7a9b7\CloudStorageWizard.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-06-20 07:10:00.958
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Users\rw\Documents\WinSxS\x86_microsoft-windows-cloudstoragewizard_31bf3856ad364e35_6.3.9600.17415_none_895a2497a8f7a9b7\CloudStorageWizard.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-06-20 07:07:17.501
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Users\rw\Documents\WinSxS\amd64_microsoft-windows-s..trics-sensoradapter_31bf3856ad364e35_6.3.9600.17415_none_04bcc3084936a7f6\winbiosensoradapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-06-20 07:07:17.498
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Users\rw\Documents\WinSxS\amd64_microsoft-windows-s..trics-sensoradapter_31bf3856ad364e35_6.3.9600.17415_none_04bcc3084936a7f6\winbiosensoradapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-06-20 07:07:17.488
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Users\rw\Documents\WinSxS\amd64_microsoft-windows-s..trics-sensoradapter_31bf3856ad364e35_6.3.9600.17415_none_04bcc3084936a7f6\winbiosensoradapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-06-20 07:07:16.365
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Users\rw\Documents\WinSxS\amd64_microsoft-windows-s..rics-storageadapter_31bf3856ad364e35_6.3.9600.17415_none_c7b14887291942c9\winbiostorageadapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-06-20 07:07:16.345
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Users\rw\Documents\WinSxS\amd64_microsoft-windows-s..rics-storageadapter_31bf3856ad364e35_6.3.9600.17415_none_c7b14887291942c9\winbiostorageadapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Memory info ===========================

Processor: Intel® Core™ i7-7700K CPU @ 4.20GHz
Percentage of memory in use: 33%
Total physical RAM: 16348.5 MB
Available physical RAM: 10849.28 MB
Total Virtual: 18780.5 MB
Available Virtual: 13071.13 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:1676.66 GB) (Free:290.34 GB) NTFS
Drive d: (OS) (Fixed) (Total:931.07 GB) (Free:285.12 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive e: (Recovery) (Fixed) (Total:0.44 GB) (Free:0.13 GB) NTFS
Drive f: (Disk 3 data) (Fixed) (Total:1847.92 GB) (Free:358.53 GB) NTFS
Drive g: (Elements) (Fixed) (Total:931.51 GB) (Free:605.95 GB) NTFS
Drive h: (Acronis Media) (CDROM) (Total:0.52 GB) (Free:0 GB) CDFS
Drive j: (rescues stuff) (CDROM) (Total:0.69 GB) (Free:0.66 GB) UDF
Drive k: (SAMSUNG) (Fixed) (Total:1863.01 GB) (Free:1785.69 GB) NTFS
Drive l: (SG 8) (Fixed) (Total:7451.91 GB) (Free:7117.54 GB) NTFS
Drive m: (My Passport) (Fixed) (Total:931.48 GB) (Free:105.34 GB) NTFS
Drive n: (disk2data) (Fixed) (Total:1870.8 GB) (Free:1870.49 GB) NTFS
Drive o: (disk3 data2) (Fixed) (Total:1876.68 GB) (Free:1398.97 GB) NTFS

\\?\Volume{49a434ed-7291-4f13-9eb1-35f2c1fc209e}\ (Recovery) (Fixed) (Total:0.44 GB) (Free:0.13 GB) NTFS
\\?\Volume{02a6457f-3ee2-47de-b3c9-d9a40a8b7180}\ () (Fixed) (Total:0.83 GB) (Free:0.44 GB) NTFS
\\?\Volume{54d26d14-5f81-4cb1-aebc-c576ad74b106}\ () (Fixed) (Total:0.82 GB) (Free:0.45 GB) NTFS
\\?\Volume{b8800640-0000-0000-0000-60c4e8000000}\ () (Fixed) (Total:0.44 GB) (Free:0.07 GB) NTFS
\\?\Volume{74d8aac6-60d8-4e18-81ab-cf0f6443fa81}\ () (Fixed) (Total:177.24 GB) (Free:177.21 GB) FAT32
\\?\Volume{69718b3f-8c69-46bb-8887-0484da776625}\ () (Fixed) (Total:0.04 GB) (Free:0.01 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: B8800640)
Partition 1: (Active) - (Size=931.1 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=455 MB) - (Type=27)

========================================================
Disk: 1 (Size: 3726 GB) (Disk ID: 898B6924)

Partition: GPT.

========================================================
Disk: 2 (MBR Code: Windows 7/8/10) (Size: 7452 GB) (Disk ID: 9AA0DBC3)

Partition: GPT.

========================================================
Disk: 3 (Size: 931.5 GB) (Disk ID: 16F2A91F)

Partition: GPT.

========================================================
Disk: 4 (Size: 3726 GB) (Disk ID: FAF21485)

Partition: GPT.

========================================================
Disk: 5 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: 60D85053)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

========================================================
Disk: 6 (Size: 1863 GB) (Disk ID: 36AC56DE)
Partition 1: (Active) - (Size=1863 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================



#5 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,635 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:05:34 PM

Posted 20 June 2018 - 11:37 AM

Anti-Virus programs take up an enormous amount of your computer's resources when they are actively scanning your computer. Having two anti-virus programs running at the same time can cause your computer to run very slow, become unstable and even, in rare cases, crash.

If you choose to install more than one Anti-Virus program on your computer, then only one of them should be active in memory at a time.

There are basically two types of these programs:
On-Access and On-Demand

On-Access Scanners
As the name implies, are scanners that run in the background all the time the PC is turned on and running.  The main function of an On-Access scanner is to monitor activity on your machine.

On-Demand Scanners
As the name implies, are scanners that only run when you ask them to.
Such as, online scans and scanners that run on your machine but are not actively scanning your machine.
 
In your position I would remove both, McAfee and BitDefender, and replace them with AVAST.

  • Highlight the entire content of the quote box below.

Start::
CMD: Type C:\Program Files (x86)\LMIR0002.tmp_r.bat
CMD: Type C:\Users\ralph\AppData\Local\LMIR0001.tmp_r.bat
BootExecute: autocheck autochk * 渀䘠汩獥
GroupPolicy: Restriction ? <==== ATTENTION
U3 mfeavfk01; no ImagePath
U3 mfeavfk02; no ImagePath
End::

  • Right click on the highlighted text and select Copy.
  • Start FRST (FRST64) with Administrator privileges
  • Press the Fix button. FRST will process the lines copied above from the clipboard.
  • When finished, a log file (Fixlog.txt) will pop up and saved in the same location the tool was ran from.

Please copy and paste its contents in your next reply.
 
RQKuhw1.pngRogueKiller

  • Download the right version of RogueKiller for your Windows version (32 or 64-bit)
  • Once done, move the executable file to your Desktop, right-click on it and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Click on the Start Scan button in the right panel, which will bring you to another tab, and click on it again (this time it'll be in the bottom right corner)
  • Wait for the scan to complete
  • On completion, the results will be displayed
  • Check every single entry (threat found), and click on the Remove Selected button
  • On completion, the results will be displayed. Click on the Open Report button in the bottom left corner, followed by the Open TXT button (also in the bottom left corner)
  • This will open the report in Notepad. Copy/paste its content in your next reply

favicon-32x32.png Please download Malwarebytes to your desktop.

  • Double-click mb3-setup-1878.1878-3.5.1.2522.exe and follow the prompts to install the program.
  • Once the program has fully updated, Proceed with the Scan options and select "Threat Scan".
  • The Scan Pane is the introduction to scan-related options in the program. When you click Scan in the Menu Pane, you will see the screen shown below.

02-malwarebytes-premium-scan-methods.jpg

  • After a scan has been executed, scan results are displayed.
  • Put a checkmark on all detected and click on "Quarantine Selected"
  • Selected reports may be viewed on screen, or exported to a text file for later viewing. Please note that only manual (on demand) scans are available for users of the free version of Malwarebytes.

You may export to your clipboard or to a text (TXT) file. Export to a .txt file and post its contents.


No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#6 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,635 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:05:34 PM

Posted 05 July 2018 - 05:33 PM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users