Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Can a virus or malware rewrite an EFI partition?


  • This topic is locked This topic is locked
19 replies to this topic

#1 Xitixen

Xitixen

  • Members
  • 69 posts
  • OFFLINE
  •  
  • Local time:11:02 AM

Posted 24 July 2018 - 08:45 PM

My Windows 10 station won't boot up, and I've been working with folks in the relevant forum to repair a partition that now shows as RAW. In the process, using Testdisk from a USB drive via the recovery command prompt, I found that one partition conflict that simply refuses to be resolved. The tenacious doppelganger is shown in the attached image.

 

Dates of relevance: 20 Sept 2016 = build date (from scratch). 29 June 2018 = a potentially compromised Android phone is given access to the private network this station is on - no human interaction with this computer on that day.

 

In trying to debug an increasingly unreliable wireless adapter when the computer was still bootable, I did notice the event viewer had a run of strange (to a layman) events recorded on 29 June, a few hours after the aforementioned phone was allowed on the wireless network. These events looked (to a layman) like a new user being created, given admin access, generating and hiding system files - enough that I downloaded and ran a full Bitdefender scan of the entire system (7 drives, 2.6 million files, about 19 hours to complete). This after a top off from Windows Security Essentials and Malwarebytes, which are routinely run on a schedule. The only thing it found was an old Trojan in an archived pst on a supplemental drive that hasn't been accessed in years. Unable to disinfect the pst, I deleted it and the old mp4 on the same drive that had also been flagged (also ancient). Emptied the trash for that drive, subsequent scans were clean.

 

Somewhere during all this I hunted down and killed off an instance of ibtsiva, since I found a dll by that name in the system and was taking no chances. I used chkdsk /r on the system drive via Tweaking.com's system utility kit - but stopped it because I realized too late I was doing it to an SSD. Since then, partition troubles.

 

So, with that context, does this look shady to anyone else? The partition it overlaps and conflicts with has normal dates and names - human readable ones dated only since the machine was built.

Attached File  20180724_204653.jpg   181.06KB   0 downloads

 

 

 


Edited by Xitixen, 24 July 2018 - 08:49 PM.


BC AdBot (Login to Remove)

 


#2 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,752 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:06:02 AM

Posted 25 July 2018 - 10:36 AM

Welcome.

 

Can you boot to the Recovery environment's command prompt? If you do run the following:

 

Diskpart

Select Disk 0   (That is Select disk zero)

List vol

Exit

 

Can you post a screenshot of these results?


No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#3 Xitixen

Xitixen
  • Topic Starter

  • Members
  • 69 posts
  • OFFLINE
  •  
  • Local time:11:02 AM

Posted 25 July 2018 - 11:45 AM

This is what it looked like. I've made a lot of progress in putting things to right with much help from JohnC_21. Will be able to post Farbar info and event logs soon.

Attached Files



#4 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,752 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:06:02 AM

Posted 25 July 2018 - 02:53 PM

The volume 4 has become RAW. Meaning, it has lost its format. Being 237gb, it  may be the OS volume. You must format that partition and perform a Full Factory Recovery. There is no other way.


No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#5 Xitixen

Xitixen
  • Topic Starter

  • Members
  • 69 posts
  • OFFLINE
  •  
  • Local time:11:02 AM

Posted 25 July 2018 - 06:30 PM

That was the consensus. However, with the tenacity of a clueless noob and the knowledge of a bleepingcomputer expert, I'm back up and running! It took two days, but here I am. Watch the unlikely resurrection of a Win10 system volume on an SSD after a partial chkdsk /r and a DiskPart partition deletion: https://www.bleepingcomputer.com/forums/t/681142/help-recovering-system-from-partition-changed-to-raw

 

You guys really do rock.

 

I'll post the original Farbar results (from the days of RAW)  in my next reply, then current ones generated after the fix (10 minutes from now).

 

As far as the mystery invasion on 29 June - something did happen then. An automatic update for Windows 10 - version 1803 - that introduced Focus Assist and Nearby Sharing, one of which *might* have conflicted with my Intel Wireless AC-3160 (a lot of queries out there indicate that hardware may not play great with Win10). So, not knowing what Impersonation meant in the Event Viewer, which was apparently part of the Database Audit at time of update, I may have leapt to conclusions. After rescuing my system drive, I ran all the apps from this pinned Adware thread: https://www.bleepingcomputer.com/virus-removal/how-to-remove-adware-on-a-pc that could be run in Safe Mode. Caught a couple trojans that had eluded previous scans. Now to take a bat to the wireless adapter flakiness. 



#6 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,752 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:06:02 AM

Posted 25 July 2018 - 06:57 PM

I am glad you were able to recover.


No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#7 Xitixen

Xitixen
  • Topic Starter

  • Members
  • 69 posts
  • OFFLINE
  •  
  • Local time:11:02 AM

Posted 25 July 2018 - 07:45 PM

The RAW state Farbar FRST, as promised: 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21.07.2018
Ran by xian (administrator) on XILENCE (22-07-2018 23:08:02)
Running from H:\down
Loaded Profiles: xian (Available Profiles: xian)
Platform: Windows 10 Home Version 1803 17134.165 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
() C:\Windows\System32\nvwmi64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel Corporation) C:\Windows\System32\ibtsiva evil.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
(DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
() C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18061.12711.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Estmob Inc.) C:\Program Files (x86)\Send Anywhere\Send Anywhere.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Estmob Inc.) C:\Program Files (x86)\Send Anywhere\Send Anywhere.exe
(Estmob Inc.) C:\Program Files (x86)\Send Anywhere\Send Anywhere.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files (x86)\Tt eSPORTS\Challenger Prime\Monitor.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CoreSync.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe
(Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\libs\node.exe
(CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Creative Cloud Libraries\CCLibrary.exe
(Node.js) C:\Program Files (x86)\Common Files\Adobe\Creative Cloud Libraries\libs\node.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Tweaking.com) C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
() C:\Windows\System32\nvwmi64.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrotray.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Neuber Software) C:\Program Files (x86)\Security Task Manager\TaskMan.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Bitdefender) C:\Program Files\Bitdefender Antivirus Free\bdredline.exe
(Bitdefender) C:\Program Files\Bitdefender Antivirus Free\vsserv.exe
(Bitdefender) C:\Program Files\Bitdefender Antivirus Free\vsservppl.exe
(Bitdefender) C:\Program Files\Bitdefender Antivirus Free\updatesrv.exe
(Bitdefender) C:\Program Files\Bitdefender Antivirus Free\bdagent.exe
(Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-11] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16681728 2016-07-09] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-25] (Logitech, Inc.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [323056 2015-11-04] (Intel Corporation)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [316392 2018-05-11] (Adobe Systems, Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [298296 2018-07-06] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2409944 2018-06-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [1871344 2018-06-29] (Adobe Systems Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-12-09] (Apple Inc.)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3754168 2018-07-12] (Dropbox, Inc.)
HKLM-x32\...\Run: [Challenger Prime Gaming Keyboard Driver] => C:\Program Files (x86)\Tt eSPORTS\Challenger Prime\Monitor.exe [147456 2015-02-06] ()
HKLM-x32\...\Run: [WDDiscovery] => C:\Program Files (x86)\Western Digital\Discovery\Current\WD Discovery.exe [56894944 2017-12-09] (Western Digital Corporation)
HKLM-x32\...\Run: [DriveUtilitiesHelper] => C:\Program Files (x86)\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe [2309008 2017-09-19] (Western Digital Technologies, Inc.)
HKLM-x32\...\Run: [PMBVolumeWatcher] => C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe [3029480 2018-05-09] (Sony Corporation)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX2] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe [279240 2016-12-09] (CANON INC.)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1313408 2017-07-05] (CANON INC.)
HKLM-x32\...\Run: [] => [X]
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation)
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [886768 2018-06-29] (Adobe Systems Incorporated)
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\Bluestacks\HD-Agent.exe [171576 2017-12-17] (BlueStack Systems, Inc.)
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3042592 2017-06-08] (Valve Corporation)
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\Run: [Bomgar_Cleanup_ZD159297652639] => cmd.exe /C rd /S /Q "C:\ProgramData\apple-scc-0x595ad17f" & reg.exe delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD159297652639 /f <==== ATTENTION
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\Run: [Bomgar_Cleanup_ZD1605360925216] => cmd.exe /C rd /S /Q "C:\Users\xian\AppData\Local\Temp\nsfEFCD.tmpb" & reg.exe delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD1605360925216 /f <==== ATTENTION
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\Run: [Bomgar Support Reconnect [595AD346]] => C:\ProgramData\apple-scc-0x595ad346\apple-scc.exe [9329872 2017-02-24] (Apple)
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2018-06-26] (Apple Inc.)
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\Run: [SendAnywhere] => C:\Program Files (x86)\Send Anywhere\Send Anywhere.exe [49774880 2018-03-29] (Estmob Inc.)
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\RunOnce: [Application Restart #4] => C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe [2386392 2018-06-22] (Adobe Systems Incorporated)
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\RunOnce: [Uninstall 18.091.0506.0007] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\xian\AppData\Local\Microsoft\OneDrive\18.091.0506.0007"
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.62 209.18.47.63
Tcpip\..\Interfaces\{15172ade-1f2b-4da8-a3cf-3f038ee62d9f}: [DhcpNameServer] 209.18.47.61 209.18.47.62 209.18.47.63
Tcpip\..\Interfaces\{7417af0c-701a-491b-a98c-3538a361ce87}: [DhcpNameServer] 209.18.47.61 209.18.47.62
 
Internet Explorer:
==================
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-07-21] (Microsoft Corporation)
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (CANON INC.)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-06-30] (Adobe Systems Incorporated)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-06-30] (Adobe Systems Incorporated)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2018-04-30] (Microsoft Corporation)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (CANON INC.)
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-06-30] (Adobe Systems Incorporated)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-06-30] (Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-06-30] (Adobe Systems Incorporated)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (CANON INC.)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-06-30] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (CANON INC.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-07-03] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-07-03] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-07-03] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-07-03] (Microsoft Corporation)
 
FireFox:
========
FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2018-02-02]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2016-09-20] [Legacy] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2018-06-22] (Adobe Systems)
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2017-10-17] (CANON INC.)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2018-04-02] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-03-02] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-17] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2018-06-29] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2018-06-22] (Adobe Systems)
FF Plugin-x32: Sony Corporation/PMCADownloader -> C:\ProgramData\Sony Corporation\PMCADownloader\1.2.0.13221\npPMCADownloader.dll [2012-10-17] (Sony Network Entertainment International LLC)
FF Plugin-x32: Sony Corporation/PMCADownloaderHelper -> C:\ProgramData\Sony Corporation\PMCADownloader\1.2.0.13221\PMCADownloaderHelper.exe [2012-10-17] (Sony Network Entertainment International LLC)
FF Plugin-x32: Sony Corporation/PMCADownloaderLib -> C:\ProgramData\Sony Corporation\PMCADownloader\1.2.0.13221\PMCADownloaderLib.dll [2012-10-17] (Sony Network Entertainment International LLC)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxps://mail.google.com/mail/?shva=1#inbox/1281717902d4583d
CHR StartupUrls: Default -> "hxxp://mysearch.avg.com?cid={089DAE63-E800-49F7-AF37-01FDFE4BBB01}&mid=ec44c2ae1def47d39d27a5ac0571ec7b-c4d0b03ab77d4249be1b6773aef0eda7761a5f33&lang=en&ds=dl011&coid=avgtbdisdl&pr=sa&d=2013-10-02 21:37:41&v=17.0.0.12&pid=safeguard&sg=0&sap=hp"
CHR DefaultSearchKeyword: Default -> lp
CHR Profile: C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default [2018-07-22]
CHR Extension: (Slides) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-24]
CHR Extension: (Entanglement Web App) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd [2016-09-19]
CHR Extension: (Docs) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-24]
CHR Extension: (PriceBlink Coupons and Price Comparison) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aoiidodopnnhiflaflbfeblnojefhigh [2018-04-06]
CHR Extension: (Google Drive) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-09-19]
CHR Extension: (QR-Code Tag Extension) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcfddoencoiedfjgepnlhcpfikgaogdg [2016-09-19]
CHR Extension: (Brushed) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfjgbcjfpbbfepcccpaffkjofcmglifg [2016-09-19]
CHR Extension: (WOT Web of Trust, Website Reputation Ratings) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2018-06-29]
CHR Extension: (Audiotool) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkgoccjhfjgjedhkiefaclppgbmoobnk [2016-09-19]
CHR Extension: (Skype Calling) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blakpkgjpemejpbmfiglncklihnhjkij [2016-09-19]
CHR Extension: (YouTube) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-09-19]
CHR Extension: (Honey) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2018-07-10]
CHR Extension: (Ebates: The Free Cash Back Shopping Assistant) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\chhjbpecpncaggjpdakmflnfcopglcmi [2018-07-10]
CHR Extension: (Add to Amazon Wish List) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ciagpekplgpbepdgggflgmahnjgiaced [2016-09-19]
CHR Extension: (Google Search) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-09-19]
CHR Extension: (Logitech Smooth Scrolling) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkpejdfnpdkhifgbancbammdijojoffk [2016-09-20]
CHR Extension: (Google+) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlppkpafhbajpcmmoheippocdidnckmm [2016-09-19]
CHR Extension: (Chrome Connectivity Diagnostics) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\eemlkeanncmjljgehlbplemhmdmalhdc [2016-09-19]
CHR Extension: (Adobe Acrobat) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-04]
CHR Extension: (Bulk Media Downloader) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehfdcgbfcboceiclmjaofdannmjdeaoi [2017-11-07]
CHR Extension: (Box) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnkaeblpdcamcioiiabclakabcbjmbl [2016-09-19]
CHR Extension: (Pandora) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbangkleohkafngihneedemihgfeikcl [2016-09-19]
CHR Extension: (Sheets) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-24]
CHR Extension: (Stupeflix Video Maker) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkdmcfnoimoilncpjchamnenebopocem [2016-09-19]
CHR Extension: (iCloud Bookmarks) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkepacicchenbjecpbpbclokcabebhah [2017-10-11]
CHR Extension: (Full Screen Weather) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkkaebihfmbofclegkcfkkemepfehibg [2016-09-19]
CHR Extension: (Google Docs Offline) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-09-19]
CHR Extension: (AdBlock) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-07-20]
CHR Extension: (TinEye Reverse Image Search) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\haebnnbpedcbhciplfhjjkbafijpncjl [2017-08-04]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2018-07-20]
CHR Extension: (XPath Helper) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgimnogjllphhhkhlmebbmlgjoejdpjl [2016-09-19]
CHR Extension: (Mahjong Words) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmefkohhpkdnaieghlijadogfapogebe [2016-09-19]
CHR Extension: (Google Keep - notes and lists) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2018-07-10]
CHR Extension: (Bitly | Unleash the power of the link) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\iabeihobmhlgpkcgjiloemdbofjbdcic [2018-07-10]
CHR Extension: (Cisco Webex Extension) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlhmfgmfgeifomenelglieieghnjghma [2018-07-10]
CHR Extension: (Google Voice (by Google)) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcnhkahnjcbndmmehfkdnkjomaanaooo [2016-09-19]
CHR Extension: (EasyHome Homestyler) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdmmkfaghgcicheaimnpffeeekheafkb [2017-05-30]
CHR Extension: (Turbo Download Manager) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\kemfccojgjoilhfmcblgimbggikekjip [2017-03-01]
CHR Extension: (Google Play) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\komhbcfkdcgmcdoenjcjheifdiabikfi [2016-09-19]
CHR Extension: (Google Maps) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2016-09-19]
CHR Extension: (Take Webpage Screenshots Entirely - FireShot) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbpblocgmgfnpjjppndjkmgjaogfceg [2018-01-01]
CHR Extension: (Pocket) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk [2016-09-19]
CHR Extension: (Ghostery – Privacy Ad Blocker) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2018-07-20]
CHR Extension: (feedly) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndhinffkekpekljifjkkkkkhopnjodja [2016-09-19]
CHR Extension: (RSS Subscription Extension (by Google)) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlbjncdgjeocebhnmkbbbdekmmmcbfjd [2016-09-19]
CHR Extension: (Awesome Screenshot: Screen Video Recorder) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlipoenfbbikpbjkfpfillcgkoblgpmj [2018-06-17]
CHR Extension: (Chrome Web Store Payments) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-06]
CHR Extension: (PlayMemories Camera Apps Downloader) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohlghnkgcadghcdodlcjfhogekonhdei [2017-08-07]
CHR Extension: (Picasa) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb [2016-09-19]
CHR Extension: (QR Code Decoder) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pafahhgpmimhoiglnpehhjpnkkppfpek [2016-09-19]
CHR Extension: (Amazon Assistant for Chrome) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2018-06-29]
CHR Extension: (Gmail) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-09-19]
CHR Extension: (Google Similar Pages) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjnfggphgdjblhfjaphkjhfpiiekbbej [2016-09-19]
CHR Extension: (Chrome Media Router) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-06-18]
CHR Extension: (iReader) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ppelffpjgkifjfgnbaaldcehkpajlmbc [2016-09-19]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [818128 2018-06-22] (Adobe Systems Incorporated)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [2321384 2018-05-11] (Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2128872 2018-05-11] (Adobe Systems, Incorporated)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2018-07-05] (Apple Inc.)
R2 bdredline; C:\Program Files\Bitdefender Antivirus Free\bdredline.exe [2195280 2018-03-22] (Bitdefender)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8765104 2018-07-13] (Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-09-27] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-09-27] (Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [51392 2018-07-12] (Dropbox, Inc.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [19440 2015-11-04] (Intel Corporation)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [391744 2017-07-11] ()
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6541008 2018-05-09] (Malwarebytes)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268704 2016-04-04] ()
R2 NVWMI; C:\Windows\system32\nvwmi64.exe [3168824 2016-03-19] ()
R2 PMBDeviceInfoProvider; C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [498152 2018-05-09] (Sony Corporation)
R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [1275776 2018-05-16] (Bitdefender)
S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2017-01-16] (DEVGURU Co., LTD.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [11293936 2018-04-03] (TeamViewer GmbH)
R2 updatesrv; C:\Program Files\Bitdefender Antivirus Free\updatesrv.exe [239400 2018-05-14] (Bitdefender)
R2 vsserv; C:\Program Files\Bitdefender Antivirus Free\vsserv.exe [239400 2018-05-14] (Bitdefender)
R2 vsservppl; C:\Program Files\Bitdefender Antivirus Free\vsservppl.exe [239400 2018-05-14] (Bitdefender)
R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [355184 2017-09-19] (Western Digital Technologies, Inc.)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\NisSrv.exe [3925648 2018-06-26] (Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\MsMpEng.exe [100080 2018-06-26] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3833248 2016-04-04] (Intel® Corporation)
R2 ibtsiva; %SystemRoot%\system32\ibtsiva [X]
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 AsrDrv101; C:\Windows\SysWOW64\Drivers\AsrDrv101.sys [22280 2016-09-24] (ASRock Incorporation)
R0 atc; C:\WINDOWS\System32\DRIVERS\atc.sys [1283464 2018-04-27] (BitDefender S.R.L. Bucharest, ROMANIA)
R0 avc3; C:\WINDOWS\System32\DRIVERS\avc3.sys [1723552 2018-04-17] (BitDefender)
R0 BdDci; C:\WINDOWS\system32\DRIVERS\bddci.sys [152648 2018-04-19] (Bitdefender)
S0 bdelam; C:\WINDOWS\System32\drivers\bdelam.sys [23032 2018-04-19] (Bitdefender)
S3 BstkDrv; C:\Program Files (x86)\Bluestacks\BstkDrv.sys [269408 2017-12-16] (Bluestack System Inc. )
R3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2017-01-16] (Samsung Electronics Co., Ltd.)
R3 edrsensor; C:\WINDOWS\System32\DRIVERS\edrsensor.sys [246064 2018-04-19] (BitDefender S.R.L. Bucharest, ROMANIA)
R0 gzflt; C:\WINDOWS\System32\drivers\gzflt.sys [193184 2018-05-29] (BitDefender LLC)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [231168 2017-01-13] (Intel Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [253664 2018-07-20] (Malwarebytes)
R3 NETwNb64; C:\WINDOWS\system32\DRIVERS\Netwbw02.sys [3528976 2016-06-14] (Intel Corporation)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_b7e5dd1387001335\nvlddmkm.sys [16936560 2017-11-09] (NVIDIA Corporation)
R3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2017-01-16] (Samsung Electronics Co., Ltd.)
R2 trufos; C:\WINDOWS\System32\drivers\trufos.sys [607640 2018-04-25] (Bitdefender)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [46592 2018-06-26] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [340008 2018-06-26] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [59944 2018-06-26] (Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-07-22 23:07 - 2018-07-22 23:08 - 000000000 ____D C:\FRST
2018-07-22 22:43 - 2018-07-22 22:43 - 000029754 _____ C:\ProgramData\agent.update.1532317419.bdinstall.bin
2018-07-22 22:41 - 2018-07-22 22:41 - 000001194 _____ C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bitdefender Antivirus Free.lnk
2018-07-22 22:40 - 2018-07-22 22:40 - 000001209 _____ C:\Users\Public\Desktop\Bitdefender Antivirus Free.lnk
2018-07-22 22:40 - 2018-07-22 22:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender Antivirus Free
2018-07-22 22:40 - 2018-07-22 22:40 - 000000000 ____D C:\ProgramData\Bitdefender
2018-07-22 22:40 - 2018-05-29 05:04 - 000193184 _____ (BitDefender LLC) C:\WINDOWS\system32\Drivers\gzflt.sys
2018-07-22 22:40 - 2018-04-27 06:29 - 001283464 _____ (BitDefender S.R.L. Bucharest, ROMANIA) C:\WINDOWS\system32\Drivers\atc.sys
2018-07-22 22:40 - 2018-04-19 22:37 - 000023032 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\bdelam.sys
2018-07-22 22:40 - 2018-04-19 11:15 - 000246064 _____ (BitDefender S.R.L. Bucharest, ROMANIA) C:\WINDOWS\system32\Drivers\edrsensor.sys
2018-07-22 22:40 - 2018-04-19 05:11 - 000152648 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\bddci.sys
2018-07-22 22:40 - 2018-04-17 11:27 - 001723552 _____ (BitDefender) C:\WINDOWS\system32\Drivers\avc3.sys
2018-07-22 22:39 - 2018-07-22 22:39 - 000000000 ____D C:\Users\xian\AppData\Roaming\QuickScan
2018-07-22 22:39 - 2018-04-25 05:27 - 000607640 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\trufos.sys
2018-07-22 22:38 - 2018-07-22 23:08 - 000000000 ____D C:\Program Files\Bitdefender Antivirus Free
2018-07-22 22:37 - 2018-07-22 22:37 - 000003802 _____ C:\WINDOWS\System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864
2018-07-22 22:35 - 2018-07-22 22:43 - 000000000 ____D C:\Program Files\Bitdefender Agent
2018-07-22 22:35 - 2018-07-22 22:35 - 000042554 _____ C:\ProgramData\agent.1532316906.bdinstall.bin
2018-07-22 22:35 - 2018-07-22 22:35 - 000000000 ____D C:\ProgramData\Bitdefender Agent
2018-07-22 22:32 - 2018-07-22 22:32 - 009986176 _____ C:\Users\xian\Downloads\bitdefender_online.exe
2018-07-22 22:18 - 2018-07-22 22:24 - 000000000 ____D C:\ProgramData\SecTaskMan
2018-07-22 22:18 - 2018-07-22 22:18 - 000001229 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spy Protector.lnk
2018-07-22 22:18 - 2018-07-22 22:18 - 000001218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security Task Manager.lnk
2018-07-22 22:18 - 2018-07-22 22:18 - 000001206 _____ C:\Users\Public\Desktop\Security Task Manager.lnk
2018-07-22 22:18 - 2018-07-22 22:18 - 000000000 ____D C:\Program Files (x86)\Security Task Manager
2018-07-22 22:18 - 2018-07-22 22:16 - 003017632 _____ C:\Users\xian\Downloads\SecurityTaskManager_Setup.exe
2018-07-22 10:08 - 2018-07-22 10:08 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignec8b492d601a40b1
2018-07-22 09:47 - 2018-07-22 09:47 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign98c1dbba8fdb470d
2018-07-21 18:48 - 2018-07-21 18:48 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsigne63ad584d2c5de77
2018-07-21 18:45 - 2018-07-21 18:45 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign41e7078d6258ce1e
2018-07-21 14:50 - 2018-07-21 14:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2018-07-17 13:22 - 2018-07-17 13:22 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign3704237fd106cf36
2018-07-17 12:28 - 2018-07-17 12:28 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignd44dc54e4677596e
2018-07-17 12:13 - 2018-07-17 12:13 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign799888e304a81074
2018-07-17 12:13 - 2018-07-17 12:13 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign1cc08e469885b792
2018-07-15 19:33 - 2018-07-15 19:33 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign2930c85ae4bd9362
2018-07-15 19:30 - 2018-07-15 19:30 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign4909dc3eb204d02f
2018-07-15 19:21 - 2018-07-15 19:21 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignfaeaeca3bfbd73a2
2018-07-15 19:21 - 2018-07-15 19:21 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignb06f6c951c4e2722
2018-07-15 19:16 - 2018-07-15 19:16 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign9efe96ab01fcaa9f
2018-07-15 19:16 - 2018-07-15 19:16 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign610efe6f08ba5fcc
2018-07-15 11:26 - 2018-07-15 11:26 - 000000000 ____D C:\Program Files (x86)\Send Anywhere
2018-07-13 16:26 - 2018-07-13 16:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2018-07-13 11:40 - 2018-07-13 11:40 - 000001826 _____ C:\Users\Public\Desktop\iTunes.lnk
2018-07-13 11:40 - 2018-07-13 11:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2018-07-13 11:40 - 2018-07-13 11:40 - 000000000 ____D C:\Program Files\iTunes
2018-07-13 11:40 - 2018-07-13 11:40 - 000000000 ____D C:\Program Files\iPod
2018-07-13 11:36 - 2018-07-13 11:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2018-07-12 21:01 - 2018-07-12 21:01 - 000051392 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2018-07-12 21:01 - 2018-07-12 21:01 - 000050232 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2018-07-12 21:01 - 2018-07-12 21:01 - 000045672 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2018-07-12 21:01 - 2018-07-12 21:01 - 000045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2018-07-10 20:21 - 2018-07-06 09:20 - 002868640 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2018-07-10 20:21 - 2018-07-06 09:20 - 001610648 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2018-07-10 20:21 - 2018-07-06 09:20 - 000792472 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2018-07-10 20:21 - 2018-07-06 09:20 - 000689560 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2018-07-10 20:21 - 2018-07-06 09:20 - 000612248 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2018-07-10 20:21 - 2018-07-06 09:20 - 000451992 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2018-07-10 20:21 - 2018-07-06 09:20 - 000309664 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2018-07-10 20:21 - 2018-07-06 09:20 - 000144792 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2018-07-10 20:21 - 2018-07-06 09:17 - 003932672 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2018-07-10 20:21 - 2018-07-06 08:56 - 004708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2018-07-10 20:21 - 2018-07-06 08:53 - 000340992 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2018-07-10 20:21 - 2018-07-06 08:52 - 001787392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2018-07-10 20:21 - 2018-07-06 08:51 - 003652608 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-07-10 20:21 - 2018-07-06 08:51 - 002051584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2018-07-10 20:21 - 2018-07-06 08:51 - 001364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
2018-07-10 20:21 - 2018-07-06 07:06 - 003611368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2018-07-10 20:21 - 2018-07-06 06:52 - 002895360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-07-10 20:21 - 2018-07-06 06:51 - 002401280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2018-07-10 20:21 - 2018-07-06 06:26 - 019525120 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2018-07-10 20:21 - 2018-07-06 06:25 - 023863296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2018-07-10 20:21 - 2018-07-06 02:32 - 000480672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2018-07-10 20:21 - 2018-07-06 02:31 - 000462752 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2018-07-10 20:21 - 2018-07-06 02:27 - 001174432 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2018-07-10 20:21 - 2018-07-06 02:26 - 002712992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2018-07-10 20:21 - 2018-07-06 02:26 - 001148800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2018-07-10 20:21 - 2018-07-06 02:26 - 000930720 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2018-07-10 20:21 - 2018-07-06 02:25 - 009147808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-07-10 20:21 - 2018-07-06 02:25 - 002753040 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2018-07-10 20:21 - 2018-07-06 02:25 - 002571728 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2018-07-10 20:21 - 2018-07-06 02:25 - 002420632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2018-07-10 20:21 - 2018-07-06 02:25 - 001945784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2018-07-10 20:21 - 2018-07-06 02:25 - 001018616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2018-07-10 20:21 - 2018-07-06 02:25 - 000483048 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll
2018-07-10 20:21 - 2018-07-06 02:24 - 000380824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2018-07-10 20:21 - 2018-07-06 02:14 - 002242208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2018-07-10 20:21 - 2018-07-06 02:14 - 001981896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2018-07-10 20:21 - 2018-07-06 02:14 - 001175568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2018-07-10 20:21 - 2018-07-06 02:14 - 000988640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2018-07-10 20:21 - 2018-07-06 02:14 - 000829856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2018-07-10 20:21 - 2018-07-06 02:13 - 001620872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2018-07-10 20:21 - 2018-07-06 02:10 - 025845760 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-07-10 20:21 - 2018-07-06 02:07 - 022006272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2018-07-10 20:21 - 2018-07-06 02:04 - 022713856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-07-10 20:21 - 2018-07-06 02:03 - 004371456 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2018-07-10 20:21 - 2018-07-06 02:02 - 009084928 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2018-07-10 20:21 - 2018-07-06 02:01 - 007057408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2018-07-10 20:21 - 2018-07-06 02:01 - 005883904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2018-07-10 20:21 - 2018-07-06 02:00 - 019403264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-07-10 20:21 - 2018-07-06 01:59 - 006647296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2018-07-10 20:21 - 2018-07-06 01:59 - 003381248 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
2018-07-10 20:21 - 2018-07-06 01:59 - 001153536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2018-07-10 20:21 - 2018-07-06 01:58 - 004867584 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-07-10 20:21 - 2018-07-06 01:58 - 002825728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
2018-07-10 20:21 - 2018-07-06 01:58 - 001931776 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeangle.dll
2018-07-10 20:21 - 2018-07-06 01:58 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2018-07-10 20:21 - 2018-07-06 01:58 - 000670720 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2018-07-10 20:21 - 2018-07-06 01:57 - 007579648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2018-07-10 20:21 - 2018-07-06 01:57 - 005779456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2018-07-10 20:21 - 2018-07-06 01:57 - 003712512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-07-10 20:21 - 2018-07-06 01:57 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2018-07-10 20:21 - 2018-07-06 01:57 - 000813056 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2018-07-10 20:21 - 2018-07-06 01:57 - 000473088 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2018-07-10 20:21 - 2018-07-06 01:56 - 001986560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll
2018-07-10 20:21 - 2018-07-06 01:56 - 001817600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2018-07-10 20:21 - 2018-07-06 01:56 - 001567744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll
2018-07-10 20:21 - 2018-07-06 01:56 - 001225216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2018-07-10 20:21 - 2018-07-06 01:56 - 000784896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2018-07-10 20:21 - 2018-07-06 01:56 - 000327680 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioCredProv.dll
2018-07-10 20:21 - 2018-07-06 01:55 - 003440128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-07-10 20:21 - 2018-07-06 01:55 - 001804288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2018-07-10 20:21 - 2018-07-06 01:55 - 001627136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2018-07-10 20:21 - 2018-07-06 01:55 - 001395712 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2018-07-10 20:21 - 2018-07-06 01:55 - 001264640 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2018-07-10 20:21 - 2018-07-06 01:54 - 003015680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2018-07-10 20:21 - 2018-07-06 01:54 - 002449408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll
2018-07-10 20:21 - 2018-07-06 01:54 - 002236928 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2018-07-10 20:21 - 2018-07-06 01:54 - 001214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2018-07-10 20:21 - 2018-07-06 01:54 - 000999936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2018-07-10 20:21 - 2018-07-06 01:54 - 000943616 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll
2018-07-10 20:21 - 2018-07-06 01:54 - 000884736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2018-07-10 20:21 - 2018-07-06 01:54 - 000884224 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2018-07-10 20:21 - 2018-07-06 01:54 - 000542208 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2018-07-10 20:21 - 2018-07-06 01:54 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2018-07-10 20:21 - 2018-07-06 01:53 - 000713216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll
2018-07-10 20:21 - 2018-07-06 01:52 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2018-07-10 20:21 - 2018-06-15 12:50 - 001376576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2018-07-10 20:21 - 2018-06-15 12:49 - 021388856 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2018-07-10 20:21 - 2018-06-15 12:48 - 002395056 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
2018-07-10 20:21 - 2018-06-15 12:48 - 000338352 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSrvPolicyManager.dll
2018-07-10 20:21 - 2018-06-15 12:34 - 008623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2018-07-10 20:21 - 2018-06-15 12:33 - 012710400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2018-07-10 20:21 - 2018-06-15 12:30 - 001308672 _____ C:\WINDOWS\system32\FaceProcessor.dll
2018-07-10 20:21 - 2018-06-15 12:30 - 001254400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2018-07-10 20:21 - 2018-06-15 12:30 - 000878592 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2018-07-10 20:21 - 2018-06-15 12:29 - 000740864 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2018-07-10 20:21 - 2018-06-15 10:25 - 020383720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2018-07-10 20:21 - 2018-06-15 10:22 - 001026896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2018-07-10 20:21 - 2018-06-15 10:16 - 002206528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
2018-07-10 20:21 - 2018-06-15 10:07 - 011901952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2018-07-10 20:21 - 2018-06-15 10:06 - 007987712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2018-07-10 20:21 - 2018-06-15 10:02 - 000704000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2018-07-10 20:21 - 2018-06-15 08:23 - 000788992 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll
2018-07-10 20:21 - 2018-06-15 00:21 - 001213368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2018-07-10 20:21 - 2018-06-15 00:21 - 000761440 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2018-07-10 20:21 - 2018-06-15 00:19 - 001034632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2018-07-10 20:21 - 2018-06-15 00:15 - 002563960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2018-07-10 20:21 - 2018-06-15 00:15 - 000753152 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2018-07-10 20:21 - 2018-06-15 00:13 - 000510904 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2018-07-10 20:21 - 2018-06-15 00:12 - 007519992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-07-10 20:21 - 2018-06-15 00:12 - 000491304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2018-07-10 20:21 - 2018-06-15 00:11 - 006817872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2018-07-10 20:21 - 2018-06-15 00:10 - 001934400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2018-07-10 20:21 - 2018-06-15 00:10 - 001097640 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2018-07-10 20:21 - 2018-06-15 00:10 - 000717208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2018-07-10 20:21 - 2018-06-15 00:09 - 007436120 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-07-10 20:21 - 2018-06-15 00:09 - 002830240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2018-07-10 20:21 - 2018-06-15 00:09 - 002546592 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2018-07-10 20:21 - 2018-06-15 00:09 - 001798552 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2018-07-10 20:21 - 2018-06-15 00:09 - 001742272 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2018-07-10 20:21 - 2018-06-15 00:09 - 001659296 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2018-07-10 20:21 - 2018-06-15 00:09 - 001209800 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2018-07-10 20:21 - 2018-06-15 00:09 - 001112600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2018-07-10 20:21 - 2018-06-15 00:09 - 000594128 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2018-07-10 20:21 - 2018-06-15 00:08 - 004403304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2018-07-10 20:21 - 2018-06-15 00:08 - 002371392 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2018-07-10 20:21 - 2018-06-15 00:08 - 002062488 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2018-07-10 20:21 - 2018-06-15 00:08 - 001946752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2018-07-10 20:21 - 2018-06-15 00:08 - 001784584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2018-07-10 20:21 - 2018-06-15 00:08 - 001457128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-07-10 20:21 - 2018-06-15 00:08 - 001288840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2018-07-10 20:21 - 2018-06-15 00:08 - 001258280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-07-10 20:21 - 2018-06-15 00:08 - 001140568 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-07-10 20:21 - 2018-06-15 00:08 - 000898760 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2018-07-10 20:21 - 2018-06-15 00:07 - 001611584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2018-07-10 20:21 - 2018-06-15 00:07 - 001145696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2018-07-10 20:21 - 2018-06-15 00:05 - 000550608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2018-07-10 20:21 - 2018-06-15 00:04 - 002331576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2018-07-10 20:21 - 2018-06-15 00:04 - 001462824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2018-07-10 20:21 - 2018-06-15 00:04 - 001251736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll
2018-07-10 20:21 - 2018-06-15 00:04 - 000719552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 006572000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 006528600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 006043600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 004788504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 002535032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 002163184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 001805752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 001710240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 001559368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 001380192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 001144120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 001020160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 001011968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 000770152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2018-07-10 20:21 - 2018-06-14 23:49 - 002962944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2018-07-10 20:21 - 2018-06-14 23:48 - 002900992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2018-07-10 20:21 - 2018-06-14 23:46 - 004706816 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2018-07-10 20:21 - 2018-06-14 23:46 - 004333568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2018-07-10 20:21 - 2018-06-14 23:46 - 001356800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2018-07-10 20:21 - 2018-06-14 23:46 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2018-07-10 20:21 - 2018-06-14 23:45 - 002548736 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
2018-07-10 20:21 - 2018-06-14 23:45 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2018-07-10 20:21 - 2018-06-14 23:44 - 001632256 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2018-07-10 20:21 - 2018-06-14 23:44 - 001342976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2018-07-10 20:21 - 2018-06-14 23:43 - 001110528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2018-07-10 20:21 - 2018-06-14 23:43 - 000312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagnosticLogCSP.dll
2018-07-10 20:21 - 2018-06-14 23:42 - 003392512 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2018-07-10 20:21 - 2018-06-14 23:42 - 002367488 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2018-07-10 20:21 - 2018-06-14 23:42 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2018-07-10 20:21 - 2018-06-14 23:42 - 000102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2018-07-10 20:21 - 2018-06-14 23:41 - 004561920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2018-07-10 20:21 - 2018-06-14 23:41 - 003320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2018-07-10 20:21 - 2018-06-14 23:41 - 001768448 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2018-07-10 20:21 - 2018-06-14 23:41 - 001724928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2018-07-10 20:21 - 2018-06-14 23:41 - 000625152 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2018-07-10 20:21 - 2018-06-14 23:40 - 001550848 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2018-07-10 20:21 - 2018-06-14 23:40 - 001487360 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2018-07-10 20:21 - 2018-06-14 23:40 - 000827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2018-07-10 20:21 - 2018-06-14 23:39 - 002903040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2018-07-10 20:21 - 2018-06-14 23:39 - 002583552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2018-07-10 20:21 - 2018-06-14 23:39 - 002172416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2018-07-10 20:21 - 2018-06-14 23:39 - 001303040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2018-07-10 20:21 - 2018-06-14 23:39 - 000916992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2018-07-10 20:21 - 2018-06-14 23:39 - 000847360 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2018-07-10 20:21 - 2018-06-14 23:39 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2018-07-10 20:21 - 2018-06-14 23:38 - 001854976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2018-07-10 20:21 - 2018-06-14 23:38 - 001581568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2018-07-10 20:21 - 2018-06-14 23:38 - 001305088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2018-07-10 20:21 - 2018-06-14 23:38 - 001070080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2018-07-10 20:21 - 2018-06-14 23:38 - 001036288 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2018-07-10 20:21 - 2018-06-14 23:38 - 000949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2018-07-10 20:21 - 2018-06-14 23:38 - 000910848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2018-07-10 20:21 - 2018-06-14 23:38 - 000596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2018-07-10 20:21 - 2018-06-14 23:37 - 001374208 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2018-07-10 20:20 - 2018-07-06 09:20 - 000070040 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2018-07-10 20:20 - 2018-07-06 09:14 - 000541592 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2018-07-10 20:20 - 2018-07-06 08:53 - 000409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2018-07-10 20:20 - 2018-07-06 08:53 - 000386048 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2018-07-10 20:20 - 2018-07-06 08:52 - 000677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2018-07-10 20:20 - 2018-07-06 08:51 - 001004032 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2018-07-10 20:20 - 2018-07-06 08:51 - 000391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2018-07-10 20:20 - 2018-07-06 08:50 - 000615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2018-07-10 20:20 - 2018-07-06 08:49 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe
2018-07-10 20:20 - 2018-07-06 06:54 - 000485376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2018-07-10 20:20 - 2018-07-06 06:54 - 000343552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2018-07-10 20:20 - 2018-07-06 06:53 - 000775168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2018-07-10 20:20 - 2018-07-06 06:53 - 000347136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
2018-07-10 20:20 - 2018-07-06 06:52 - 001452544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2018-07-10 20:20 - 2018-07-06 06:52 - 001308160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2018-07-10 20:20 - 2018-07-06 06:51 - 000080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcbuilder.exe
2018-07-10 20:20 - 2018-07-06 06:01 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll
2018-07-10 20:20 - 2018-07-06 02:31 - 000035232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2018-07-10 20:20 - 2018-07-06 02:29 - 000272296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave.dll
2018-07-10 20:20 - 2018-07-06 02:29 - 000269224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2018-07-10 20:20 - 2018-07-06 02:27 - 001063320 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2018-07-10 20:20 - 2018-07-06 02:27 - 001012632 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2018-07-10 20:20 - 2018-07-06 02:27 - 000709824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2018-07-10 20:20 - 2018-07-06 02:27 - 000567176 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2018-07-10 20:20 - 2018-07-06 02:27 - 000134552 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2018-07-10 20:20 - 2018-07-06 02:27 - 000057440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.ShellCommon.Broker.dll
2018-07-10 20:20 - 2018-07-06 02:26 - 000766608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2018-07-10 20:20 - 2018-07-06 02:26 - 000170912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2018-07-10 20:20 - 2018-07-06 02:25 - 001026464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2018-07-10 20:20 - 2018-07-06 02:25 - 000885856 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2018-07-10 20:20 - 2018-07-06 02:25 - 000335776 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2018-07-10 20:20 - 2018-07-06 02:25 - 000267680 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2018-07-10 20:20 - 2018-07-06 02:25 - 000139672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
2018-07-10 20:20 - 2018-07-06 02:16 - 000567144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2018-07-10 20:20 - 2018-07-06 02:14 - 000573904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2018-07-10 20:20 - 2018-07-06 02:01 - 000104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2018-07-10 20:20 - 2018-07-06 02:01 - 000014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll
2018-07-10 20:20 - 2018-07-06 02:00 - 000151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2018-07-10 20:20 - 2018-07-06 02:00 - 000094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2018-07-10 20:20 - 2018-07-06 02:00 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
2018-07-10 20:20 - 2018-07-06 02:00 - 000053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll
2018-07-10 20:20 - 2018-07-06 02:00 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsTelemetry.dll
2018-07-10 20:20 - 2018-07-06 02:00 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll
2018-07-10 20:20 - 2018-07-06 01:59 - 000453632 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2018-07-10 20:20 - 2018-07-06 01:59 - 000334336 _____ (Microsoft Corporation) C:\WINDOWS\system32\NmaDirect.dll
2018-07-10 20:20 - 2018-07-06 01:59 - 000200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Geolocation.dll
2018-07-10 20:20 - 2018-07-06 01:59 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2018-07-10 20:20 - 2018-07-06 01:59 - 000048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\tokenbinding.dll
2018-07-10 20:20 - 2018-07-06 01:59 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2018-07-10 20:20 - 2018-07-06 01:58 - 001307648 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2018-07-10 20:20 - 2018-07-06 01:58 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2018-07-10 20:20 - 2018-07-06 01:58 - 000236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Core.dll
2018-07-10 20:20 - 2018-07-06 01:58 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Cortana.dll
2018-07-10 20:20 - 2018-07-06 01:58 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2018-07-10 20:20 - 2018-07-06 01:58 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProv2faHelper.dll
2018-07-10 20:20 - 2018-07-06 01:58 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2018-07-10 20:20 - 2018-07-06 01:58 - 000075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mpsdrv.sys
2018-07-10 20:20 - 2018-07-06 01:58 - 000035840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tokenbinding.dll
2018-07-10 20:20 - 2018-07-06 01:57 - 000839680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2018-07-10 20:20 - 2018-07-06 01:57 - 000676864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Devices.dll
2018-07-10 20:20 - 2018-07-06 01:57 - 000614912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2018-07-10 20:20 - 2018-07-06 01:57 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2018-07-10 20:20 - 2018-07-06 01:57 - 000262656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NmaDirect.dll
2018-07-10 20:20 - 2018-07-06 01:56 - 001708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSPhotography.dll
2018-07-10 20:20 - 2018-07-06 01:56 - 001535488 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-07-10 20:20 - 2018-07-06 01:56 - 000814592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2018-07-10 20:20 - 2018-07-06 01:56 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2018-07-10 20:20 - 2018-07-06 01:56 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuietHours.dll
2018-07-10 20:20 - 2018-07-06 01:56 - 000508416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2018-07-10 20:20 - 2018-07-06 01:56 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2018-07-10 20:20 - 2018-07-06 01:56 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2018-07-10 20:20 - 2018-07-06 01:56 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2018-07-10 20:20 - 2018-07-06 01:56 - 000181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Core.dll
2018-07-10 20:20 - 2018-07-06 01:56 - 000115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2018-07-10 20:20 - 2018-07-06 01:56 - 000081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProv2faHelper.dll
2018-07-10 20:20 - 2018-07-06 01:55 - 001361408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSPhotography.dll
2018-07-10 20:20 - 2018-07-06 01:55 - 000619520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2018-07-10 20:20 - 2018-07-06 01:55 - 000415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2018-07-10 20:20 - 2018-07-06 01:55 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2018-07-10 20:20 - 2018-07-06 01:54 - 000978944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2018-07-10 20:20 - 2018-07-06 01:54 - 000899072 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2018-07-10 20:20 - 2018-07-06 01:54 - 000275968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2018-07-10 20:20 - 2018-07-06 01:54 - 000254464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BioCredProv.dll
2018-07-10 20:20 - 2018-07-06 01:53 - 000778240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2018-07-10 20:20 - 2018-07-06 01:53 - 000729088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2018-07-10 20:20 - 2018-07-06 01:53 - 000705024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2018-07-10 20:20 - 2018-07-06 00:41 - 000001310 _____ C:\WINDOWS\system32\tcbres.wim
2018-07-10 20:20 - 2018-06-28 23:16 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll
2018-07-10 20:20 - 2018-06-15 12:55 - 000542888 _____ C:\WINDOWS\system32\FaceProcessorCore.dll
2018-07-10 20:20 - 2018-06-15 12:53 - 000348256 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2018-07-10 20:20 - 2018-06-15 12:53 - 000094104 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2018-07-10 20:20 - 2018-06-15 12:35 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2018-07-10 20:20 - 2018-06-15 12:34 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\DsmUserTask.exe
2018-07-10 20:20 - 2018-06-15 12:34 - 000025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfnet.dll
2018-07-10 20:20 - 2018-06-15 12:33 - 000182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpdr.sys
2018-07-10 20:20 - 2018-06-15 12:33 - 000156160 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupManagerAPI.dll
2018-07-10 20:20 - 2018-06-15 12:33 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2018-07-10 20:20 - 2018-06-15 12:32 - 000301568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcLayers.dll
2018-07-10 20:20 - 2018-06-15 12:32 - 000145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2018-07-10 20:20 - 2018-06-15 12:31 - 001605632 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2018-07-10 20:20 - 2018-06-15 12:31 - 000907776 _____ (Microsoft Corporation) C:\WINDOWS\system32\autofmt.exe
2018-07-10 20:20 - 2018-06-15 12:31 - 000220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2018-07-10 20:20 - 2018-06-15 12:30 - 001054720 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2018-07-10 20:20 - 2018-06-15 12:29 - 002084352 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2018-07-10 20:20 - 2018-06-15 12:29 - 000932352 _____ (Microsoft Corporation) C:\WINDOWS\system32\autoconv.exe
2018-07-10 20:20 - 2018-06-15 12:29 - 000757248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2018-07-10 20:20 - 2018-06-15 12:29 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\shdocvw.dll
2018-07-10 20:20 - 2018-06-15 12:29 - 000103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSoftwareInstallationClient.dll
2018-07-10 20:20 - 2018-06-15 12:28 - 000223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpd_ci.dll
2018-07-10 20:20 - 2018-06-15 12:28 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll
2018-07-10 20:20 - 2018-06-15 10:06 - 000022016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfnet.dll
2018-07-10 20:20 - 2018-06-15 10:04 - 000851968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autoconv.exe
2018-07-10 20:20 - 2018-06-15 10:04 - 000373248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcLayers.dll
2018-07-10 20:20 - 2018-06-15 10:03 - 000831488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autofmt.exe
2018-07-10 20:20 - 2018-06-15 10:03 - 000667648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2018-07-10 20:20 - 2018-06-15 10:01 - 002015744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2018-07-10 20:20 - 2018-06-15 10:01 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shdocvw.dll
2018-07-10 20:20 - 2018-06-15 02:11 - 000611232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2018-07-10 20:20 - 2018-06-15 02:10 - 000048544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storufs.sys
2018-07-10 20:20 - 2018-06-15 02:03 - 000083360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
2018-07-10 20:20 - 2018-06-15 00:19 - 000116632 _____ (Microsoft Corporation) C:\WINDOWS\system32\DTUHandler.exe
2018-07-10 20:20 - 2018-06-15 00:19 - 000093600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2018-07-10 20:20 - 2018-06-15 00:18 - 000228768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll
2018-07-10 20:20 - 2018-06-15 00:16 - 000562080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2018-07-10 20:20 - 2018-06-15 00:16 - 000433560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2018-07-10 20:20 - 2018-06-15 00:13 - 000324000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2018-07-10 20:20 - 2018-06-15 00:12 - 000661152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2018-07-10 20:20 - 2018-06-15 00:12 - 000260896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2018-07-10 20:20 - 2018-06-15 00:12 - 000118872 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll
2018-07-10 20:20 - 2018-06-15 00:10 - 000326024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExecModelClient.dll
2018-07-10 20:20 - 2018-06-15 00:09 - 000247984 _____ (Microsoft Corporation) C:\WINDOWS\system32\RESAMPLEDMO.DLL
2018-07-10 20:20 - 2018-06-15 00:08 - 001921944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys
2018-07-10 20:20 - 2018-06-15 00:08 - 001150408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVP9DEC.dll
2018-07-10 20:20 - 2018-06-15 00:08 - 000983008 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-07-10 20:20 - 2018-06-15 00:08 - 000945568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refsv1.sys
2018-07-10 20:20 - 2018-06-15 00:08 - 000642088 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp_win.dll
2018-07-10 20:20 - 2018-06-15 00:08 - 000604576 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2018-07-10 20:20 - 2018-06-15 00:08 - 000500552 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2018-07-10 20:20 - 2018-06-15 00:08 - 000413816 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2018-07-10 20:20 - 2018-06-15 00:08 - 000072768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WindowsTrustedRT.sys
2018-07-10 20:20 - 2018-06-15 00:05 - 000444240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2018-07-10 20:20 - 2018-06-15 00:04 - 001397192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVP9DEC.dll
2018-07-10 20:20 - 2018-06-15 00:04 - 000281080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExecModelClient.dll
2018-07-10 20:20 - 2018-06-15 00:04 - 000105376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll
2018-07-10 20:20 - 2018-06-15 00:03 - 001129640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2018-07-10 20:20 - 2018-06-15 00:03 - 000472136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2018-07-10 20:20 - 2018-06-15 00:03 - 000356960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2018-07-10 20:20 - 2018-06-15 00:03 - 000232488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RESAMPLEDMO.DLL
2018-07-10 20:20 - 2018-06-15 00:03 - 000129192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2018-07-10 20:20 - 2018-06-14 23:48 - 000311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Diagnostics.dll
2018-07-10 20:20 - 2018-06-14 23:47 - 000622080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsreg.dll
2018-07-10 20:20 - 2018-06-14 23:47 - 000515072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\untfs.dll
2018-07-10 20:20 - 2018-06-14 23:47 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2018-07-10 20:20 - 2018-06-14 23:46 - 000593408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2018-07-10 20:20 - 2018-06-14 23:46 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Input.dll
2018-07-10 20:20 - 2018-06-14 23:46 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
2018-07-10 20:20 - 2018-06-14 23:45 - 000992768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Vpn.dll
2018-07-10 20:20 - 2018-06-14 23:45 - 000871424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autochk.exe
2018-07-10 20:20 - 2018-06-14 23:45 - 000740352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2018-07-10 20:20 - 2018-06-14 23:45 - 000380416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2018-07-10 20:20 - 2018-06-14 23:45 - 000193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll
2018-07-10 20:20 - 2018-06-14 23:45 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\system32\DTUHandlerPS.dll
2018-07-10 20:20 - 2018-06-14 23:44 - 000873472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2018-07-10 20:20 - 2018-06-14 23:44 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
2018-07-10 20:20 - 2018-06-14 23:44 - 000185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2018-07-10 20:20 - 2018-06-14 23:44 - 000135680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smartscreenps.dll
2018-07-10 20:20 - 2018-06-14 23:44 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatecsp.dll
2018-07-10 20:20 - 2018-06-14 23:44 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcimage.dll
2018-07-10 20:20 - 2018-06-14 23:44 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\cellulardatacapabilityhandler.dll
2018-07-10 20:20 - 2018-06-14 23:43 - 001114112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.PointOfService.dll
2018-07-10 20:20 - 2018-06-14 23:43 - 000675840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2018-07-10 20:20 - 2018-06-14 23:43 - 000426496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2018-07-10 20:20 - 2018-06-14 23:43 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\RdpRelayTransport.dll
2018-07-10 20:20 - 2018-06-14 23:43 - 000209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2018-07-10 20:20 - 2018-06-14 23:43 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2018-07-10 20:20 - 2018-06-14 23:43 - 000191488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VideoHandlers.dll
2018-07-10 20:20 - 2018-06-14 23:43 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2018-07-10 20:20 - 2018-06-14 23:43 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2018-07-10 20:20 - 2018-06-14 23:42 - 000978432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2018-07-10 20:20 - 2018-06-14 23:42 - 000558592 _____ (Microsoft Corporation) C:\WINDOWS\system32\untfs.dll
2018-07-10 20:20 - 2018-06-14 23:42 - 000431104 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2018-07-10 20:20 - 2018-06-14 23:42 - 000386048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Diagnostics.dll
2018-07-10 20:20 - 2018-06-14 23:42 - 000319488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2018-07-10 20:20 - 2018-06-14 23:42 - 000273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2018-07-10 20:20 - 2018-06-14 23:42 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2018-07-10 20:20 - 2018-06-14 23:42 - 000216064 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2018-07-10 20:20 - 2018-06-14 23:42 - 000141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2018-07-10 20:20 - 2018-06-14 23:41 - 000953856 _____ (Microsoft Corporation) C:\WINDOWS\system32\autochk.exe
2018-07-10 20:20 - 2018-06-14 23:41 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2018-07-10 20:20 - 2018-06-14 23:41 - 000811520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Input.dll
2018-07-10 20:20 - 2018-06-14 23:41 - 000270336 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2018-07-10 20:20 - 2018-06-14 23:41 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManager.dll
2018-07-10 20:20 - 2018-06-14 23:41 - 000265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2018-07-10 20:20 - 2018-06-14 23:41 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupManager.dll
2018-07-10 20:20 - 2018-06-14 23:40 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
2018-07-10 20:20 - 2018-06-14 23:40 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreenps.dll
2018-07-10 20:20 - 2018-06-14 23:37 - 001069056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2018-07-10 20:20 - 2018-06-14 23:37 - 000883712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2018-07-10 20:20 - 2018-06-14 23:36 - 000159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cdrom.sys
2018-07-10 20:20 - 2018-06-01 00:18 - 000058524 _____ C:\WINDOWS\system32\srms.dat
2018-07-10 20:20 - 2018-05-20 06:53 - 000792984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2018-07-10 20:20 - 2018-05-20 06:52 - 000413080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2018-07-10 16:42 - 2018-07-10 16:42 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsigne9fca32f1ca75c38
2018-07-10 16:05 - 2018-07-10 16:05 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignf36a9148db4e1642
2018-07-09 19:26 - 2018-07-09 19:26 - 000001300 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2018-07-09 19:26 - 2018-07-09 19:26 - 000001288 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2018-07-09 15:45 - 2018-07-09 15:45 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsigne55609b247f1bc81
2018-07-09 15:44 - 2018-07-09 15:44 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignccb41b1ad08e129d
2018-07-09 15:38 - 2018-07-09 15:38 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign2ac9436c4901f6aa
2018-07-09 15:30 - 2018-07-09 15:30 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign9bbc425a737afc75
2018-07-09 15:30 - 2018-07-09 15:30 - 000000000 ____D C:\Users\xian\AppData\Local\NVIDIA
2018-06-29 22:42 - 2018-07-11 09:09 - 000000000 ____D C:\Windows.old
2018-06-29 22:39 - 2018-06-29 22:42 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2018-06-29 22:38 - 2018-06-29 22:39 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2018-06-29 22:38 - 2018-06-29 22:38 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2018-06-29 22:37 - 2018-06-29 22:37 - 016592384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 013873152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 013570560 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 012500992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 008188928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 007900984 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 006661120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 006032384 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 005951488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 005821544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 005307392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 004970360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 004929024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 004527680 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 004469832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 004392448 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 004070400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 003999232 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 003733320 _____ C:\WINDOWS\system32\Windows.Mirage.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 003640832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 003492864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 003444224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 003392512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 003348992 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 003296896 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 003293696 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 003283408 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 003180176 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 003086336 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002922496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002841312 _____ C:\WINDOWS\SysWOW64\Windows.Mirage.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002789376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002699776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002590400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVDECOD.DLL
2018-06-29 22:37 - 2018-06-29 22:37 - 002486992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002479272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002462272 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002417840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002364928 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002307336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVDECOD.DLL
2018-06-29 22:37 - 2018-06-29 22:37 - 002248192 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002178136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002061824 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002019840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001988072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001953280 _____ C:\WINDOWS\system32\rdpnano.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001855488 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001825792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001792808 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001719808 _____ (Microsoft Corporation) C:\WINDOWS\system32\dui70.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001676800 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShell.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001675264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001665920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001665024 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001659904 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001649760 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001634808 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001613200 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001586176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001585664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001584128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001565592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001560576 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdt.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 001543680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001508352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdt.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 001490144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001466368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001462784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dui70.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001456640 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001454024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001426328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001421312 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpbase.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001371136 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001364184 _____ (Microsoft Corporation) C:\WINDOWS\system32\webservices.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001363632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001348096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpcServices.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001318400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001299056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001295360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001292288 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 001285120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001271296 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloSI.PCShell.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001242112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001235968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpbase.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001210880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001192448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Maps.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001190152 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001180672 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001171968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001160192 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001128448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001121792 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001077504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webservices.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001046944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001034096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001032704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001017088 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001017080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2adec.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001012408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001005568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000983040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000976384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000960512 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000950272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmsys.cpl
2018-06-29 22:37 - 2018-06-29 22:37 - 000944640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000941056 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdlg.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000933376 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000932352 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000917408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000916480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000908800 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSMPEG2ENC.DLL
2018-06-29 22:37 - 2018-06-29 22:37 - 000908288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000906752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.PhoneNumberFormatting.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000899072 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000880152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000871424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000864768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmsys.cpl
2018-06-29 22:37 - 2018-06-29 22:37 - 000863232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000861616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2adec.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000861096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000860160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000858112 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000857088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSMPEG2ENC.DLL
2018-06-29 22:37 - 2018-06-29 22:37 - 000849408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000842240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000808960 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2018-06-29 22:37 - 2018-06-29 22:37 - 000804352 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVolSSO.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000788216 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000786176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000783360 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyHrtfEnc.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000781824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000778752 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2018-06-29 22:37 - 2018-06-29 22:37 - 000776880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000776192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000759192 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingWinRT.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000748512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SndVolSSO.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000735560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000729088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FlightSettings.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000723360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000722808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000713376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000705440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000695296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hhctrl.ocx
2018-06-29 22:37 - 2018-06-29 22:37 - 000678840 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000677888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\HeadTrackerStorage.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000669696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000667648 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000665320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000661160 _____ (Microsoft Corporation) C:\WINDOWS\system32\GenValObj.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000659096 _____ (Microsoft Corporation) C:\WINDOWS\system32\StateRepository.Core.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000658432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000653208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicensingWinRT.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000652800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000648192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000630784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.MediaPlayer.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000625152 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.rs4.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000613144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000607648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000606448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000593408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000585728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.rs3.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000581120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hhctrl.ocx
2018-06-29 22:37 - 2018-06-29 22:37 - 000577024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000568720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryPS.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000565152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2018-06-29 22:37 - 2018-06-29 22:37 - 000564736 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000561664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000560488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000553984 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationExtensions.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000553248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000528384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000527264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000506184 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000503296 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000494488 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000486912 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasplap.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTMediaFrame.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000474624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.rs2.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000466432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXP.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000461312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasplap.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000457152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAudDecMFT.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000444416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.rs1.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000434584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000416144 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000389632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000384000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Phoneutil.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000382872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000375808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTMediaFrame.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000375712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msrpc.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000356352 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWfdProvider.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000347704 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\system32\RasMediaManager.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserexport.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000329216 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000317440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Phoneutil.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000313592 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.th.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000286200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcredprov.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000264704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovs.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MixedReality.Broker.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000241664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.win81.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FSClient.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloShellRuntime.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtutil.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyMATEnc.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcredprov.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000226720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Ucx01000.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAC3ENC.DLL
2018-06-29 22:37 - 2018-06-29 22:37 - 000194456 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000184320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\HoloShellRuntime.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000182272 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000182272 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerCsp.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000177152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\itss.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000167936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtutil.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000164768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Analog.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\vertdll.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedPCCSP.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000150016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000150016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\itss.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSpkg.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000142848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000142336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.win8rtm.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000137568 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000131232 _____ (Microsoft Corporation) C:\WINDOWS\system32\rmclient.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000130456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvsocket.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000117760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSpkg.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppHostRegistrationVerifier.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApiSetHost.AppExecutionAlias.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000105368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000101288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rmclient.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManagerClient.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000098816 _____ (Microsoft Corporation) C:\WINDOWS\system32\TelephonyInteractiveUser.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000097176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000089984 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompPkgSup.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000088472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\crashdmp.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000084288 _____ (Microsoft Corporation) C:\WINDOWS\system32\LanguageOverlayUtil.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ApiSetHost.AppExecutionAlias.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000077040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CompPkgSup.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000064648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LanguageOverlayUtil.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\edpnotify.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000057960 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel.appcore.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000050208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel.appcore.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryCore.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSHEIF.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mskssrv.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000029600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\uefi.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000029184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSHEIF.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\credssp.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credssp.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000018716 _____ C:\WINDOWS\SysWOW64\srms-apr.dat
2018-06-29 22:37 - 2018-06-29 22:37 - 000018716 _____ C:\WINDOWS\system32\srms-apr.dat
2018-06-29 22:37 - 2018-06-29 22:37 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2018-06-29 22:35 - 2018-06-29 22:35 - 001166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2018-06-29 22:35 - 2018-06-29 22:35 - 000778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2018-06-29 22:35 - 2018-06-29 22:35 - 000124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2018-06-29 22:35 - 2018-06-29 22:35 - 000103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2018-06-29 22:35 - 2018-06-29 22:35 - 000035456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2018-06-29 22:35 - 2018-06-29 22:35 - 000035456 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2018-06-29 22:35 - 2018-06-29 22:35 - 000000000 ____D C:\Program Files\Reference Assemblies
2018-06-29 22:35 - 2018-06-29 22:35 - 000000000 ____D C:\Program Files\MSBuild
2018-06-29 22:35 - 2018-06-29 22:35 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2018-06-29 22:35 - 2018-06-29 22:35 - 000000000 ____D C:\Program Files (x86)\MSBuild
2018-06-29 22:34 - 2018-06-29 22:34 - 004492288 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2018-06-29 22:34 - 2018-06-29 22:34 - 003398144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2018-06-29 22:34 - 2018-06-29 22:34 - 000925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsFilt.dll
2018-06-29 22:34 - 2018-06-29 22:34 - 000575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsFilt.dll
2018-06-29 22:34 - 2018-06-29 22:34 - 000100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\XPSSHHDR.dll
2018-06-29 22:34 - 2018-06-29 22:34 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XPSSHHDR.dll
2018-06-29 22:34 - 2018-06-29 22:34 - 000076060 _____ C:\WINDOWS\SysWOW64\xpsrchvw.xml
2018-06-29 22:34 - 2018-06-29 22:34 - 000076060 _____ C:\WINDOWS\system32\xpsrchvw.xml
2018-06-29 21:13 - 2018-06-29 21:27 - 000000000 ___HD C:\ProgramData\CanonIJMIG
2018-06-29 21:12 - 2018-06-29 21:13 - 000000000 ___HD C:\ProgramData\CanonIJScan
2018-06-29 20:06 - 2018-07-14 16:09 - 000000000 ____D C:\ProgramData\Packages
2018-06-29 19:51 - 2018-07-22 22:38 - 000000000 ____D C:\Users\xian\AppData\Local\D3DSCache
2018-06-29 19:51 - 2018-06-29 19:51 - 000001417 _____ C:\Users\xian\Desktop\Microsoft Edge.lnk
2018-06-29 19:51 - 2018-06-29 19:51 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2018-06-29 19:50 - 2018-07-22 22:39 - 000840376 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-06-29 19:50 - 2018-07-21 09:36 - 000004212 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2018-06-29 19:50 - 2018-07-20 09:35 - 000003350 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-813518053-636032705-5302477-1001
2018-06-29 19:50 - 2018-07-20 09:31 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-06-29 19:50 - 2018-07-12 04:52 - 000004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2018-06-29 19:50 - 2018-06-29 19:50 - 000003434 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineUA
2018-06-29 19:50 - 2018-06-29 19:50 - 000003346 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2018-06-29 19:50 - 2018-06-29 19:50 - 000003210 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineCore
2018-06-29 19:50 - 2018-06-29 19:50 - 000003122 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2018-06-29 19:50 - 2018-06-29 19:50 - 000002998 _____ C:\WINDOWS\System32\Tasks\Tweaking.com - Windows Repair Tray Icon
2018-06-29 19:50 - 2018-06-29 19:50 - 000002762 _____ C:\WINDOWS\System32\Tasks\AdobeAAMUpdater-1.0-DESKTOP-08QK23U-xian
2018-06-29 19:50 - 2018-06-29 19:50 - 000002746 _____ C:\WINDOWS\System32\Tasks\AdobeAAMUpdater-1.0-XILENCE-xian
2018-06-29 19:50 - 2018-06-29 19:50 - 000002700 _____ C:\WINDOWS\System32\Tasks\AdobeGCInvoker-1.0-XILENCE-xian
2018-06-29 19:50 - 2018-06-29 19:50 - 000002580 _____ C:\WINDOWS\System32\Tasks\CreateExplorerShellUnelevatedTask
2018-06-29 19:50 - 2018-06-29 19:50 - 000002210 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2018-06-29 19:50 - 2018-06-29 19:50 - 000002172 _____ C:\WINDOWS\System32\Tasks\LaunchChromeTask111
2018-06-29 19:50 - 2018-06-29 19:50 - 000000020 ___SH C:\Users\xian\ntuser.ini
2018-06-29 19:50 - 2018-06-29 19:50 - 000000000 ____D C:\WINDOWS\System32\Tasks\Apple
2018-06-29 19:49 - 2018-06-29 19:50 - 000007623 _____ C:\WINDOWS\diagwrn.xml
2018-06-29 19:49 - 2018-06-29 19:50 - 000007623 _____ C:\WINDOWS\diagerr.xml
2018-06-29 19:46 - 2018-06-29 19:46 - 000001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2018-06-29 19:45 - 2018-06-29 19:45 - 000000000 ____D C:\ProgramData\USOShared
2018-06-29 19:45 - 2018-04-11 18:33 - 002752000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2018-06-29 19:44 - 2018-07-20 09:35 - 000002362 _____ C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-06-29 19:44 - 2018-06-29 19:50 - 000000000 ____D C:\Users\xian
2018-06-29 19:44 - 2018-06-29 19:44 - 000000000 ____D C:\Users\xian\AppData\Local\Google
2018-06-29 19:42 - 2018-07-22 21:56 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-06-29 19:42 - 2018-07-10 21:07 - 000550184 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-06-23 22:33 - 2018-06-29 19:50 - 000000000 ___DC C:\WINDOWS\Panther
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-07-22 22:55 - 2018-04-11 18:36 - 000000000 ____D C:\WINDOWS\INF
2018-07-22 22:54 - 2016-09-24 14:36 - 000007610 _____ C:\Users\xian\AppData\Local\resmon.resmoncfg
2018-07-22 22:51 - 2018-04-11 18:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-07-22 22:37 - 2016-09-21 14:23 - 000000000 ____D C:\Users\xian\AppData\Roaming\WhatsApp
2018-07-22 22:36 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\NDF
2018-07-22 18:48 - 2017-11-03 11:31 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2018-07-22 10:54 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-07-22 10:01 - 2016-09-20 15:48 - 000000000 ____D C:\Users\xian\AppData\Local\Adobe
2018-07-21 15:55 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2018-07-21 14:50 - 2016-09-19 23:03 - 000002495 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visio.lnk
2018-07-21 14:50 - 2016-09-19 22:53 - 000002513 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project.lnk
2018-07-21 14:50 - 2016-09-19 22:35 - 000002508 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business.lnk
2018-07-21 14:50 - 2016-09-19 22:35 - 000002503 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2018-07-21 14:50 - 2016-09-19 22:35 - 000002502 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2018-07-21 14:50 - 2016-09-19 22:35 - 000002466 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2018-07-21 14:50 - 2016-09-19 22:35 - 000002465 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2018-07-21 14:50 - 2016-09-19 22:35 - 000002459 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2018-07-21 14:50 - 2016-09-19 22:35 - 000002453 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2018-07-21 14:50 - 2016-09-19 22:35 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2018-07-21 14:50 - 2016-09-19 22:34 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-07-21 14:14 - 2016-09-20 16:03 - 000000033 _____ C:\Users\xian\AppData\Roaming\AdobeWLCMCache.dat
2018-07-20 21:40 - 2018-06-18 10:38 - 000253664 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2018-07-20 21:40 - 2017-09-22 16:50 - 000152688 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2018-07-20 09:35 - 2018-04-11 18:38 - 000000000 ___HD C:\Program Files\WindowsApps
2018-07-20 09:35 - 2016-09-19 21:21 - 000000000 ___RD C:\Users\xian\OneDrive
2018-07-20 09:32 - 2018-02-07 22:55 - 000000000 ____D C:\Users\xian\AppData\Roaming\Send Anywhere
2018-07-20 09:32 - 2017-12-09 13:08 - 000000000 ____D C:\Users\xian\AppData\Roaming\WD Discovery
2018-07-20 09:32 - 2016-09-20 15:54 - 000000000 ___RD C:\Users\xian\Creative Cloud Files
2018-07-20 09:31 - 2018-04-11 16:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-07-20 09:31 - 2017-05-18 11:29 - 000000000 ____D C:\ProgramData\NVIDIA
2018-07-17 12:58 - 2016-09-21 14:23 - 000000000 ____D C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WhatsApp
2018-07-17 12:58 - 2016-09-21 14:23 - 000000000 ____D C:\Users\xian\AppData\Local\WhatsApp
2018-07-17 12:57 - 2016-09-21 14:23 - 000000000 ____D C:\Users\xian\AppData\Local\SquirrelTemp
2018-07-16 19:02 - 2016-09-20 15:41 - 000563832 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2018-07-15 13:06 - 2016-09-23 08:25 - 000000000 ____D C:\Users\xian\AppData\Roaming\vlc
2018-07-15 11:26 - 2018-02-07 22:55 - 000002381 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Send Anywhere.lnk
2018-07-15 11:26 - 2017-12-06 12:08 - 000002369 _____ C:\Users\Public\Desktop\Send Anywhere.lnk
2018-07-13 16:26 - 2016-09-27 15:53 - 000000000 ____D C:\Program Files (x86)\Dropbox
2018-07-12 04:52 - 2016-09-20 16:13 - 000002469 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk
2018-07-12 04:52 - 2016-09-20 16:13 - 000002124 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk
2018-07-10 21:07 - 2017-11-23 10:14 - 000000000 ___RD C:\Users\xian\3D Objects
2018-07-10 21:07 - 2016-09-19 21:19 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-07-10 21:06 - 2018-06-07 14:10 - 000000000 ____D C:\ProgramData\CanonIJPLM
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\zu-ZA
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\yo-NG
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\xh-ZA
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\wo-SN
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\uz-Latn-UZ
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tn-ZA
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ti-ET
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tg-Cyrl-TJ
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-RS
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-BA
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sd-Arab-PK
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\rw-RW
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\quc-Latn-GT
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-Arab-PK
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\nso-ZA
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ku-Arab-IQ
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ig-NG
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ha-Latn-NG
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\chr-CHER-US
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES-valencia
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\bs-Latn-BA
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\az-Latn-AZ
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\zu-ZA
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\yo-NG
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\xh-ZA
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\wo-SN
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\uz-Latn-UZ
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\tn-ZA
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ti-ET
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\tg-Cyrl-TJ
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-RS
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-BA
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\sd-Arab-PK
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\rw-RW
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\quc-Latn-GT
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\pa-Arab-PK
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\nso-ZA
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ku-Arab-IQ
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ig-NG
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ha-Latn-NG
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\chr-CHER-US
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ca-ES-valencia
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\bs-Latn-BA
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\az-Latn-AZ
2018-07-10 21:06 - 2018-04-11 18:38 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2018-07-10 21:06 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2018-07-10 21:06 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-07-10 21:06 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\ShellExperiences
2018-07-10 21:06 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\bcastdvr
2018-07-10 20:25 - 2018-04-11 18:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-07-10 20:25 - 2016-09-20 19:39 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-07-10 20:23 - 2016-09-20 19:38 - 134675576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-07-09 19:26 - 2016-09-20 15:50 - 000000000 ____D C:\Program Files (x86)\Adobe
2018-07-09 17:12 - 2016-10-03 13:55 - 000000000 ____D C:\Users\xian\AppData\Roaming\Youtube Downloader HD
2018-07-07 19:51 - 2016-09-22 17:37 - 000000000 ____D C:\Users\xian\AppData\Roaming\Apple Computer
2018-06-30 03:10 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\appcompat
2018-06-29 22:42 - 2018-06-18 10:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-06-29 22:42 - 2018-06-07 14:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon TS9100 series On-screen Manual
2018-06-29 22:42 - 2018-04-11 18:41 - 000000000 ____D C:\WINDOWS\Setup
2018-06-29 22:42 - 2018-04-11 18:38 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2018-06-29 22:42 - 2018-04-11 18:38 - 000000000 __RHD C:\Users\Public\Libraries
2018-06-29 22:42 - 2018-04-11 18:38 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2018-06-29 22:42 - 2018-04-11 18:38 - 000000000 ___SD C:\WINDOWS\system32\F12
2018-06-29 22:42 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2018-06-29 22:42 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\spool
2018-06-29 22:42 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\oobe
2018-06-29 22:42 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\Help
2018-06-29 22:42 - 2018-04-11 18:38 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2018-06-29 22:42 - 2017-12-13 22:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\dupeGuru
2018-06-29 22:42 - 2017-12-09 13:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WD Discovery
2018-06-29 22:42 - 2017-11-20 13:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva
2018-06-29 22:42 - 2017-11-20 13:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2018-06-29 22:42 - 2017-11-13 10:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FontForge
2018-06-29 22:42 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2018-06-29 22:42 - 2017-09-19 11:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2018-06-29 22:42 - 2017-08-31 17:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remote Camera Control
2018-06-29 22:42 - 2017-08-07 12:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PlayMemories Home
2018-06-29 22:42 - 2017-07-06 17:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2018-06-29 22:42 - 2017-06-15 18:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2018-06-29 22:42 - 2017-05-18 11:29 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2018-06-29 22:42 - 2017-05-16 14:09 - 000000000 ____D C:\Program Files\UNP
2018-06-29 22:42 - 2017-05-15 17:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2018-06-29 22:42 - 2017-05-12 14:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2018-06-29 22:42 - 2017-04-12 20:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MicroDicom
2018-06-29 22:42 - 2016-12-12 01:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Screencast-O-Matic v2.0
2018-06-29 22:42 - 2016-12-12 01:05 - 000000000 ____D C:\WINDOWS\SysWOW64\MTSLog
2018-06-29 22:42 - 2016-12-12 00:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movavi Screen Capture Studio 8
2018-06-29 22:42 - 2016-12-09 14:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraEdit
2018-06-29 22:42 - 2016-12-09 14:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
2018-06-29 22:42 - 2016-11-30 17:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinHTTrack
2018-06-29 22:42 - 2016-10-03 13:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Youtube Downloader HD
2018-06-29 22:42 - 2016-09-24 14:36 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2018-06-29 22:42 - 2016-09-24 13:41 - 000000000 ___HD C:\WINDOWS\system32\WLANProfiles
2018-06-29 22:42 - 2016-09-23 08:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2018-06-29 22:42 - 2016-09-23 08:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2018-06-29 22:42 - 2016-09-22 17:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ReNamer
2018-06-29 22:42 - 2016-09-20 23:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PeaZip
2018-06-29 22:42 - 2016-09-20 16:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
2018-06-29 22:42 - 2016-09-20 15:58 - 000000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2018-06-29 22:42 - 2016-09-19 22:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
2018-06-29 22:42 - 2016-09-19 21:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2018-06-29 22:42 - 2016-09-19 21:52 - 000000000 ____D C:\Program Files\Intel
2018-06-29 22:39 - 2018-06-07 14:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2018-06-29 22:39 - 2018-04-11 16:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2018-06-29 22:39 - 2017-12-07 19:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seagate
2018-06-29 22:39 - 2017-09-22 17:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tt eSPORTS
2018-06-29 22:39 - 2017-07-14 16:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2018-06-29 22:39 - 2017-05-18 11:29 - 000000000 ____D C:\Program Files\Realtek
2018-06-29 22:39 - 2017-04-10 18:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iMobie
2018-06-29 22:39 - 2016-11-18 22:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Webgility
2018-06-29 22:39 - 2016-09-24 14:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASRock Utility
2018-06-29 22:39 - 2016-09-24 13:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2018-06-29 22:39 - 2016-09-20 23:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ur-PK
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ug-CN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tt-RU
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tk-TM
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\te-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ta-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sw-KE
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sq-AL
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\si-LK
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\quz-PE
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\prs-AF
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\or-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\nn-NO
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ne-NP
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mt-MT
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mr-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mn-MN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ml-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mk-MK
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mi-NZ
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\lo-LA
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\lb-LU
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ky-KG
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\kok-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\kn-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\km-KH
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\kk-KZ
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ka-GE
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\is-IS
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\hy-AM
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\gu-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\gd-GB
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ga-IE
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\fil-PH
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\fa-IR
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\cy-GB
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-BD
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\be-BY
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\as-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\am-ET
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\af-ZA
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\vi-VN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ur-PK
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ug-CN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\tt-RU
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\tk-TM
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\te-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\sw-KE
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\sq-AL
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\quz-PE
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\prs-AF
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\pa-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\or-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\nn-NO
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ne-NP
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\mt-MT
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\mr-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\mn-MN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ml-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\mk-MK
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\mi-NZ
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\lo-LA
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\lb-LU
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ky-KG
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\kok-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\kn-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\km-KH
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\kk-KZ
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ka-GE
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\is-IS
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\id-ID
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\hy-AM
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\gu-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\gd-GB
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ga-IE
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\fil-PH
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\fa-IR
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\cy-GB
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\bn-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\bn-BD
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\be-BY
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\as-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\af-ZA
2018-06-29 22:37 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\TextInput
2018-06-29 22:37 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2018-06-29 22:37 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2018-06-29 22:37 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2018-06-29 22:37 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\ta-in
2018-06-29 22:37 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2018-06-29 22:37 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\si-lk
2018-06-29 22:37 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\setup
2018-06-29 22:37 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\am-et
2018-06-29 22:37 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\Provisioning
2018-06-29 22:37 - 2018-04-11 18:38 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2018-06-29 22:37 - 2018-04-11 18:38 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2018-06-29 22:37 - 2018-04-11 16:04 - 000000000 ____D C:\WINDOWS\system32\Dism
2018-06-29 22:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2018-06-29 22:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2018-06-29 22:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2018-06-29 22:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2018-06-29 22:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\en-GB
2018-06-29 22:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2018-06-29 22:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2018-06-29 22:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\et-EE
2018-06-29 22:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\es-MX
2018-06-29 22:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\en-GB
2018-06-29 21:48 - 2017-08-08 00:17 - 000001141 _____ C:\Users\Public\Desktop\VLC media player.lnk
2018-06-29 21:13 - 2018-06-07 14:16 - 000000000 ____D C:\Users\xian\AppData\Roaming\Canon
2018-06-29 20:48 - 2016-09-29 06:52 - 000000000 ____D C:\Users\xian\AppData\Local\ConnectedDevicesPlatform
2018-06-29 20:06 - 2017-11-23 10:00 - 000000000 ____D C:\Users\xian\AppData\Local\Packages
2018-06-29 19:50 - 2018-04-11 18:38 - 000000000 ___RD C:\Program Files\Windows Defender
2018-06-29 19:50 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\Registration
2018-06-29 19:50 - 2018-04-11 16:04 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2018-06-29 19:49 - 2016-09-24 14:36 - 000838560 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2018-06-29 19:49 - 2016-09-19 21:56 - 000002311 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-06-29 19:48 - 2018-04-11 18:38 - 000000000 __RSD C:\WINDOWS\media
2018-06-29 19:48 - 2016-09-29 03:48 - 000022840 _____ C:\WINDOWS\system32\emptyregdb.dat
2018-06-29 19:46 - 2017-12-13 22:13 - 000000000 ____D C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Duplicate Files Finder
2018-06-29 19:46 - 2017-09-22 08:53 - 000000000 ____D C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\cloudLibrary
2018-06-29 19:46 - 2016-09-19 23:26 - 000000000 ____D C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2018-06-29 19:45 - 2017-07-20 07:25 - 000000000 ____D C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Syncios
2018-06-29 19:43 - 2017-05-18 11:30 - 000018960 _____ (Logitech, Inc.) C:\WINDOWS\system32\Drivers\LNonPnP.sys
2018-06-29 19:43 - 2017-05-18 11:29 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2018-06-29 19:43 - 2017-05-18 11:29 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2018-06-29 19:43 - 2017-04-10 23:48 - 000000000 ____D C:\temp
2018-06-28 20:13 - 2018-04-11 18:41 - 000835064 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2018-06-28 20:13 - 2018-04-11 18:41 - 000179704 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2018-06-26 21:16 - 2018-02-07 22:06 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-06-25 17:36 - 2017-03-22 12:15 - 000000000 ____D C:\Users\xian\Documents\Outlook Files
 
==================== Files in the root of some directories =======
 
2017-07-18 21:27 - 2017-07-18 21:27 - 000348680 _____ (Carifred) C:\Program Files\StopResettingMyApps.exe
2016-09-20 16:03 - 2018-07-21 14:14 - 000000033 _____ () C:\Users\xian\AppData\Roaming\AdobeWLCMCache.dat
2017-10-25 11:35 - 2017-10-25 11:35 - 000000028 _____ () C:\Users\xian\AppData\Roaming\kulerdata.json
2017-08-22 14:17 - 2018-01-17 14:13 - 000001456 _____ () C:\Users\xian\AppData\Local\Adobe Save for Web 13.0 Prefs
2016-09-24 14:36 - 2018-07-22 22:54 - 000007610 _____ () C:\Users\xian\AppData\Local\resmon.resmoncfg
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2018-06-29 19:42
 
==================== End of FRST.txt ============================

... and the Addition, also from RAW state:

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21.07.2018
Ran by xian (22-07-2018 23:09:27)
Running from H:\down
Windows 10 Home Version 1803 17134.165 (X64) (2018-06-30 00:50:13)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-813518053-636032705-5302477-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-813518053-636032705-5302477-503 - Limited - Disabled)
Guest (S-1-5-21-813518053-636032705-5302477-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-813518053-636032705-5302477-504 - Limited - Disabled)
xian (S-1-5-21-813518053-636032705-5302477-1001 - Administrator - Enabled) => C:\Users\xian
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Bitdefender Antivirus Free Antimalware (Enabled - Up to date) {EA21BCE8-A461-99C3-3A0D-4C964E75494E}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Bitdefender Antivirus Free Antimalware (Enabled - Up to date) {51405D0C-825B-964D-00BD-77E435F203F3}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 16.04 (x64) (HKLM\...\7-Zip) (Version: 16.04 - Igor Pavlov)
Adobe Acrobat DC (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-0C0F074E4100}) (Version: 18.011.20055 - Adobe Systems Incorporated)
Adobe After Effects CC 2017 (HKLM-x32\...\AEFT_14_2_1) (Version: 14.2.1 - Adobe Systems Incorporated)
Adobe Audition CC 2017 (HKLM-x32\...\AUDT_10_1_1) (Version: 10.1.1 - Adobe Systems Incorporated)
Adobe Bridge CC 2017 (HKLM-x32\...\KBRG_7_0) (Version: 7.0 - Adobe Systems Incorporated)
Adobe Character Animator CC (Beta) (HKLM-x32\...\ANMLBETA_1_0_6) (Version: 1.0.6 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 4.6.0.384 - Adobe Systems Incorporated)
Adobe Dreamweaver CC 2017 (HKLM-x32\...\DRWV_17_5_0) (Version: 17.5.0 - Adobe Systems Incorporated)
Adobe ExtendScript Toolkit CC (HKLM-x32\...\{6297487E-3778-4F72-B458-55690418DB98}) (Version: 4.0.0.0 - Adobe Systems Incorporated)
Adobe Extension Manager CC (HKLM-x32\...\{244FD30F-63F1-49B9-9D98-1150FF4FFCB1}) (Version: 7.3.2 - Adobe Systems Incorporated)
Adobe Illustrator CC 2017 (HKLM-x32\...\ILST_21_1_0) (Version: 21.1.0 - Adobe Systems Incorporated)
Adobe InDesign CC 2017 (HKLM-x32\...\IDSN_12_1_0) (Version: 12.1.0 - Adobe Systems Incorporated)
Adobe Lightroom (HKLM-x32\...\{8048A5DF-8A70-5BE1-954B-E0FDE1BD0D0D}) (Version: 6.12 - Adobe Systems Incorporated)
Adobe Media Encoder CC 2017 (HKLM-x32\...\AME_11_1_2) (Version: 11.1.2 - Adobe Systems Incorporated)
Adobe Muse CC 2017 (HKLM-x32\...\MUSE_2017_1_0) (Version: 2017.1.0.821 - Adobe Systems Incorporated)
Adobe Photoshop CC 2017 (HKLM-x32\...\PHSP_18_1_1) (Version: 18.1.1 - Adobe Systems Incorporated)
Adobe Premiere Pro CC 2017 (HKLM-x32\...\PPRO_11_1_2) (Version: 11.1.2 - Adobe Systems Incorporated)
APP Shop v1.0.24 (HKLM-x32\...\{90242E9B-BC60-46E3-8EE7-8E953F702280}_is1) (Version: 1.0.24 - ASRock Inc.)
Apple Application Support (32-bit) (HKLM-x32\...\{E5347310-C82F-4833-AA36-8D11E5A8A86A}) (Version: 6.6 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{D745E014-74DD-43A3-98DF-E7D38164B681}) (Version: 6.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{C29B636B-9015-4ED1-A12F-6375A337F23B}) (Version: 11.4.1.46 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{A30EA700-5515-48F0-88B0-9E99DC356B88}) (Version: 2.6.0.1 - Apple Inc.)
Asmedia USB Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.16.35.1 - Asmedia Technology)
ASRock App Charger v1.0.6 (HKLM\...\ASRock App Charger_is1) (Version: 1.0.6 - ASRock Inc.)
ASRock RapidSataSwitch v1.0.13 (HKLM\...\ASRock Rapid SATA Switch_is1) (Version:  - ASRock Inc.)
ASRock Restart to UEFI v1.0.5 (HKLM-x32\...\ASRock Restart to UEFI_is1) (Version: 1.0.5 - )
Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 1.0.1 - Bitdefender)
Bitdefender Antivirus Free (HKLM\...\{1FCCF41D-5F00-4FE2-9653-162D0486C8B4}) (Version: 1.0.12.41 - Bitdefender)
BlueStacks App Player (HKLM-x32\...\BlueStacks) (Version: 3.54.65.1755 - BlueStack Systems, Inc.)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.7.0.0 - Canon Inc.)
Canon IJ Network Scanner Selector EX2 (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX2) (Version: 2.0.5.3 - Canon Inc.)
Canon IJ Printer Assistant Tool (HKLM-x32\...\Canon IJ Printer Assistant Tool) (Version: 1.00.2.51 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: 1.4.0.16 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 5.5.0 - Canon Inc.)
Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 3.6.1 - Canon Inc.)
Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 3.6.0 - Canon Inc.)
Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.8.5 - Canon Inc.)
Canon TS9100 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_TS9100_series) (Version: 1.01 - Canon Inc.)
Canon TS9100 series On-screen Manual (HKLM-x32\...\Canon TS9100 series On-screen Manual) (Version: 1.1.0 - Canon Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.36 - Piriform)
Challenger Prime Gaming Keyboard Driver (HKLM-x32\...\{54C8FBB3-B992-43CB-8F0A-E26228013F88}) (Version: 1.0 - Tt eSPORTS)
cloudLibrary 2.3 (HKLM-x32\...\cloudLibrary) (Version: 2.3 - Bibliotheca)
Disk Health v3.0 (HKLM-x32\...\Disk Health_is1) (Version: 3.0 - ASRock Inc.)
Dropbox (HKLM-x32\...\Dropbox) (Version: 53.4.67 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.75.1 - Dropbox, Inc.) Hidden
dupeGuru 4.0.3 (HKLM\...\dupeGuru) (Version: 4.0.3 - Hardcoded Software)
Duplicate Files Finder (HKLM-x32\...\Duplicate Files Finder) (Version:  - )
FastBoot v3.0.2 (HKLM-x32\...\FastBoot_is1) (Version: 3.0.2 - ASRock Inc.)
FileZilla Client 3.27.1 (HKLM-x32\...\FileZilla Client) (Version: 3.27.1 - Tim Kosse)
FontForge version 31-07-2017 (HKLM-x32\...\{56748B9C-19AE-4689-B8C5-5A45AE0A993A}_is1) (Version: 31-07-2017 - FontForgeBuilds)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 67.0.3396.99 - Google Inc.)
Google Drive (HKLM-x32\...\{A8DC81F2-D365-4248-892A-FA3B5951F731}) (Version: 2.34.9392.7803 - Google, Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
iCloud (HKLM\...\{82FCC407-A0E5-4B80-9241-5ABA78B61090}) (Version: 7.6.0.15 - Apple Inc.)
Intel® C++ Redistributables on Intel® 64 (HKLM-x32\...\{F70BCE36-25F2-4475-A918-6209B3D85BF3}) (Version: 15.0.179 - Intel Corporation)
Intel® Chipset Device Software (HKLM-x32\...\{f2fa2583-cd6d-4da1-803c-2983cc6f7791}) (Version: 10.1.2.10 - Intel® Corporation) Hidden
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.4.1186 - Intel Corporation)
Intel® Network Connections 20.4.307.0 (HKLM\...\PROSetDX) (Version: 20.4.307.0 - Intel)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.8.0.1042 - Intel Corporation)
Intel® Wireless Bluetooth® (HKLM-x32\...\{5068B0F8-CE24-4B61-9C2F-301B411FFB9C}) (Version: 18.1.1611.3223 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{88540041-fd0c-4588-9b2f-251e29f7c5a1}) (Version: 18.40.4 - Intel Corporation)
iTunes (HKLM\...\{36F365B3-05C2-455D-9D96-B73829DE046D}) (Version: 12.8.0.150 - Apple Inc.)
join.me (HKU\S-1-5-21-813518053-636032705-5302477-1001\...\JoinMe) (Version: 3.3.0.5346 - LogMeIn, Inc.)
Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech)
M4VGear 5.3.1 (HKLM-x32\...\M4VGear) (Version: 5.3.1 - M4VGear)
Malwarebytes version 3.5.1.2522 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.5.1.2522 - Malwarebytes)
MergeModule_x64 (HKLM\...\{12DCC5A7-0100-4433-B4FF-217A3C5DC83B}) (Version: 9.3.00 - Sony Corporation) Hidden
MergeModule_x86 (HKLM-x32\...\{42251A8D-C4AE-4D3B-8A50-948CB98A0969}) (Version: 10.5.00 - Sony Corporation) Hidden
MicroDicom DICOM viewer 2.0.0 (HKLM-x32\...\MicroDicom) (Version: 2.0.0 - MicroDicom)
Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 16.0.10228.20134 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-813518053-636032705-5302477-1001\...\OneDriveSetup.exe) (Version: 18.111.0603.0006 - Microsoft Corporation)
Microsoft Project Professional 2016 - en-us (HKLM\...\ProjectProRetail - en-us) (Version: 16.0.10228.20134 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft Visio Professional 2016 - en-us (HKLM\...\VisioProRetail - en-us) (Version: 16.0.10228.20134 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810 (HKLM-x32\...\{e2ee15e2-a480-4bc5-bfb7-e9803d1d9823}) (Version: 14.12.25810.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.12.25810 (HKLM-x32\...\{56e11d69-7cc9-40a5-a4f9-8f6190c4d84d}) (Version: 14.12.25810.0 - Microsoft Corporation)
Movavi Screen Capture Studio 8 (HKLM-x32\...\Movavi Screen Capture Studio 8) (Version: 8.0.2 - Movavi)
Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.5.6 - Notepad++ Team)
NVIDIA 3D Vision Controller Driver 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
NVIDIA nView 147.00 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView) (Version: 147.00 - NVIDIA Corporation)
NVIDIA WMI 2.25.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVWMI) (Version: 2.25.0 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.10228.20134 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.10228.20134 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.10228.20134 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.10228.20134 - Microsoft Corporation) Hidden
PeaZip 6.1.1 (WIN64) (HKLM\...\{5A2BC38A-406C-4A5B-BF45-6991F9A05325}_is1) (Version: 6.1.1 - Giorgio Tani)
PeaZip configuration (WIN64) (HKLM\...\{4F8D60A8-C53D-47BD-AE5C-31AE6566D638}_is1) (Version:  - Giorgio Tani)
PhoneBrowse 3.2.0 (HKLM-x32\...\{6A4F3A46-FC4A-4B5C-917C-B9BAAB99FE01}}_is1) (Version: 3.2.0 - iMobie Inc.)
PlayMemories Camera Apps Downloader (HKLM-x32\...\{3333CE3B-CDF8-4F5E-A3BC-9ECD60FB7E66}) (Version: 1.2.0.13221 - Sony Corporation)
PlayMemories Home (HKLM-x32\...\{D3981248-DBE7-4050-B666-A7FE5AFFC62C}) (Version: 5.5.01.05091 - Sony Corporation)
PMB_ModeEditor (HKLM-x32\...\{E95982CA-945F-41F2-B156-A603897AB242}) (Version: 10.3.00 - Sony Corporation) Hidden
PMB_ServiceUploader (HKLM-x32\...\{7D3A0097-9E0E-4073-801C-295BBDAEAED8}) (Version: 10.5.01 - Sony Corporation) Hidden
PodTrans 4.9.0 (HKLM-x32\...\{A5B89AC2-2FE2-4AFD-8CB4-2613E0BB85FF}}_is1) (Version: 4.9.0 - iMobie Inc.)
Printer Registration (HKLM-x32\...\Canon EISRegistration) (Version: 1.1.0 - Canon Inc.)
QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7874 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform)
Remote Camera Control (HKLM-x32\...\{178CB313-9DB5-4634-8A2B-BB3BC31DF0B0}) (Version: 3.8.00000 - Sony Corporation)
ReNamer (HKLM-x32\...\ReNamer_is1) (Version: 6.6.0.0 - den4b Team)
Revo Uninstaller 2.0.4 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.4 - VS Revo Group, Ltd.)
Samsung SideSync (HKLM-x32\...\Samsung SideSync) (Version: 4.7.5.235 - Samsung Electronics Co., Ltd.)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.63.0 - Samsung Electronics Co., Ltd.)
Screencast-O-Matic v2.0 (HKLM-x32\...\Screencast-O-Matic v2.0) (Version: v2-1.8 - Screencast-O-Matic)
SeaTools for Windows 1.4.0.6 (HKLM-x32\...\SeaTools for Windows) (Version: 1.4.0.6 - Seagate Technology)
Security Task Manager 2.3 (HKLM-x32\...\Security Task Manager) (Version: 2.3 - Neuber Software)
Send Anywhere 8.3.291825 (HKLM-x32\...\20db1975-fda0-5740-b262-81be26ba22ab) (Version: 8.3.291825 - Estmob Inc.)
Speccy (HKLM\...\Speccy) (Version: 1.29 - Piriform)
Spotify (HKU\S-1-5-21-813518053-636032705-5302477-1001\...\Spotify) (Version: 1.0.82.447.g975ad224 - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TeamViewer 13 (HKLM-x32\...\TeamViewer) (Version: 13.1.3629 - TeamViewer)
Tweaking.com - Windows Repair (HKLM-x32\...\Tweaking.com - Windows Repair) (Version: 3.9.36 - Tweaking.com)
UltraEdit (HKLM\...\{AFFE5F64-3248-41E9-96AE-8B475F6EFAB3}) (Version: 23.20.0.43 - IDM Computer Solutions, Inc.)
Unify Enterprise (HKLM-x32\...\{2EAE48CE-DD4C-440A-8673-52536395CAEB}_is1) (Version: 5.6 - Webgility, Inc)
Unify Merge Module (HKLM-x32\...\{63EDF951-961A-48E2-B30D-C14516B8A74D}) (Version: 1.0 - Webgility)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.3 - VideoLAN)
WD Discovery (HKLM-x32\...\WDDiscovery) (Version: 1.3.482 - Western Digital Technologies, Inc.)
WD Drive Utilities (HKLM-x32\...\{27c7215d-df19-4095-8f6a-eba55cab35be}) (Version: 2.0.0.25 - Western Digital Technologies, Inc.)
WD Drive Utilities (HKLM-x32\...\{F413FB4C-7CFF-4737-BCC3-5EE43BFB3721}) (Version: 2.0.0.25 - Western Digital Technologies, Inc.) Hidden
WhatsApp (HKU\S-1-5-21-813518053-636032705-5302477-1001\...\WhatsApp) (Version: 0.3.33 - WhatsApp)
WinHTTrack Website Copier 3.48-22 (x64) (HKLM\...\WinHTTrack Website Copier_is1) (Version: 3.48.22 - HTTrack)
Youtube Downloader HD v. 2.9.9.31 (HKLM-x32\...\Youtube Downloader HD_is1) (Version:  - YoutubeDownloaderHD.com)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-813518053-636032705-5302477-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-8B3530E4204C}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File
CustomCLSID: HKU\S-1-5-21-813518053-636032705-5302477-1001_Classes\CLSID\{b5eedee0-c06e-11cf-8c56-444553540000}\InprocServer32 -> C:\Program Files\IDM Computer Solutions\UltraEdit\ue64ctmn.dll ()
CustomCLSID: HKU\S-1-5-21-813518053-636032705-5302477-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
ShellIconOverlayIdentifiers: [   AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-27] ()
ShellIconOverlayIdentifiers: [   AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-27] ()
ShellIconOverlayIdentifiers: [   AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-27] ()
ShellIconOverlayIdentifiers: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2018-04-23] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2018-04-23] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2018-04-23] (Google)
ShellIconOverlayIdentifiers-x32: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-27] ()
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2015-03-17] (Adobe Systems Inc.)
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files (x86)\Notepad++\NppShell_06.dll [2016-11-27] ()
ContextMenuHandlers1: [BB FlashBack 2] -> {A8065B9E-193F-4797-B62D-8F6321E7FCCB} =>  -> No File
ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2018-04-23] (Google)
ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll [2018-06-26] (Apple Inc.)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2018-04-23] (Google)
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers4: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd)
ContextMenuHandlers5: [00nView] -> {1E9B04FB-F9E5-4718-997B-B8DA88302A48} => C:\Program Files\NVIDIA Corporation\nview\nvshell.dll [2016-03-19] ()
ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-10-30] (NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-27] ()
ContextMenuHandlers6: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2015-03-17] (Adobe Systems Inc.)
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes)
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers6: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd)
ContextMenuHandlers1_S-1-5-21-813518053-636032705-5302477-1001: [UltraEdit] -> {b5eedee0-c06e-11cf-8c56-444553540000} => C:\Program Files\IDM Computer Solutions\UltraEdit\ue64ctmn.dll [2016-11-10] ()
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {1BB68826-A56E-478E-A841-34DD307FE051} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-09-27] (Dropbox, Inc.)
Task: {1C8B41E7-0402-497C-BA44-0BCE60CC6270} - System32\Tasks\Tweaking.com - Windows Repair Tray Icon => C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [2015-03-11] (Tweaking.com)
Task: {1CC3D1A9-E4D4-4D18-9CFE-C3BC3F2A94B4} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-07-21] (Microsoft Corporation)
Task: {3DE61A0A-7086-4D9E-A7EE-E4282F625A84} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-07-13] (Microsoft Corporation)
Task: {44814EE7-0DAE-4D0F-A04F-B66633BB015E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-09-19] (Google Inc.)
Task: {520D8283-7672-4772-AE19-20978D9FB4CB} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {52EDA6E4-1E89-4D56-B65E-0AD521C1CE37} - System32\Tasks\Microsoft\Office\OfficeOsfInstaller => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\osfinstaller.exe [2018-07-21] (Microsoft Corporation)
Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-11] ()
Task: {6C866DD5-F1B2-4F40-8184-A583CC8A1AD5} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2018-07-21] (Microsoft Corporation)
Task: {73B20228-B602-4FFB-BF38-7EF7C7C2A6AC} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [2018-05-16] (Bitdefender)
Task: {7B3BBDB2-AEDF-4756-B19D-0184D99B486C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2018-01-08] (Apple Inc.)
Task: {8A204C34-9F7D-4362-BC9A-1D6613A78BAD} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK
Task: {8A48C5FA-9EC3-4784-9AD2-73D7B5400B17} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-10-18] (Piriform Ltd)
Task: {92A22B6F-BAAE-4F50-B4C2-65B008F433F8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-09-19] (Google Inc.)
Task: {95FC6097-FBAD-4435-AA21-9C455255811D} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-09-27] (Dropbox, Inc.)
Task: {97A1B025-1359-4A1F-B13A-BD17FE1EA9DD} - System32\Tasks\AdobeAAMUpdater-1.0-DESKTOP-08QK23U-xian => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2018-04-11] (Adobe Systems Incorporated)
Task: {A2C5535A-8883-4213-A5D5-BC6342C9C0A4} - System32\Tasks\AdobeGCInvoker-1.0-XILENCE-xian => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2018-05-11] (Adobe Systems, Incorporated)
Task: {A5BAFDF8-81A8-4719-A3D6-857EA0937370} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-07-13] (Microsoft Corporation)
Task: {BC4FA66D-688F-4A52-8880-2A57658517CF} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2017-10-18] (Piriform Ltd)
Task: {CD47222C-5008-4CB5-BD12-9E39783B4810} - System32\Tasks\AdobeAAMUpdater-1.0-XILENCE-xian => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2018-04-11] (Adobe Systems Incorporated)
Task: {CDFF6A8B-9DCF-4C2C-8CD9-4A3A6405C378} - System32\Tasks\Microsoft\Windows\Setup\Notifier => C:\WINDOWS\system32\Notifier.exe
Task: {D8CB3130-99D3-4B6D-AE5B-7E5320808A0B} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-07-21] (Microsoft Corporation)
Task: {D9548503-F826-4FFF-8385-F2FFE8FB3DEC} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-03-21] (Adobe Systems Incorporated)
Task: {DE994CFB-D8F3-4D11-A2F6-AF1F9CB5E7A6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2018-07-21] (Microsoft Corporation)
Task: {F03E0DFE-5983-497F-B584-BE21073F4E1E} - System32\Tasks\LaunchChromeTask111 => C:\Program Files\FileZilla FTP Client\FileZilla.exe [2017-08-14] (FileZilla Project)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
Shortcut: C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\cloudLibrary\cloudLibrary Website.lnk -> hxxp://www.yourcloudlibrary.com/index.php/en-us
 
ShortcutWithArgument: C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome Connectivity Diagnostics.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=eemlkeanncmjljgehlbplemhmdmalhdc
ShortcutWithArgument: C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Keep - notes and lists.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=hmjkmjkepdijhoojdojkdfohbdgmmhki
ShortcutWithArgument: C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Pocket.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=mjcnijlhddpbdemagnpefmlkjdagkogk
ShortcutWithArgument: C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Turbo Download Manager.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=kemfccojgjoilhfmcblgimbggikekjip
 
==================== Loaded Modules (Whitelisted) ==============
 
2016-09-19 21:53 - 2016-03-19 00:39 - 003168824 _____ () C:\Windows\system32\nvwmi64.exe
2017-12-08 02:48 - 2017-12-08 02:48 - 000088888 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2018-06-23 06:56 - 2018-06-23 06:56 - 001356088 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2018-06-07 14:10 - 2017-07-11 10:36 - 000391744 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
2017-09-22 16:50 - 2018-07-20 21:40 - 002433744 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2018-04-11 18:34 - 2018-04-11 18:34 - 000491744 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2018-04-11 18:34 - 2018-04-11 18:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll
2018-04-11 18:34 - 2018-04-11 18:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2018-02-27 20:08 - 2018-02-27 20:08 - 000614856 _____ () C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll
2016-09-19 21:53 - 2016-03-19 00:39 - 000727488 ____R () C:\Program Files\NVIDIA Corporation\nview\nvshell.dll
2017-08-14 11:05 - 2017-08-14 11:05 - 000076456 _____ () C:\Program Files\FileZilla FTP Client\fzshellext_64.dll
2018-07-15 11:26 - 2018-03-29 20:36 - 000147968 _____ () C:\Program Files (x86)\Send Anywhere\context_handler\x64\snda_context_handler.dll
2016-11-10 10:52 - 2016-11-10 23:20 - 000147968 _____ () C:\Program Files\IDM Computer Solutions\UltraEdit\ue64ctmn.dll
2016-11-27 12:55 - 2016-11-27 12:55 - 000230064 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2018-07-10 20:21 - 2018-07-06 01:55 - 002185728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-07-16 23:08 - 2018-07-16 23:08 - 035195392 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18061.12711.0_x64__8wekyb3d8bbwe\Video.UI.exe
2018-07-16 23:08 - 2018-07-16 23:08 - 000290816 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18061.12711.0_x64__8wekyb3d8bbwe\SharedUI.dll
2018-07-16 23:08 - 2018-07-16 23:08 - 006373376 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18061.12711.0_x64__8wekyb3d8bbwe\EntCommon.dll
2017-09-25 22:00 - 2017-09-25 22:00 - 003553704 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18061.12711.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2018-07-16 23:08 - 2018-07-16 23:08 - 008903168 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18061.12711.0_x64__8wekyb3d8bbwe\EntPlat.dll
2018-07-06 02:00 - 2018-07-06 02:00 - 000088888 _____ () C:\Program Files\iTunes\zlib1.dll
2018-07-06 02:00 - 2018-07-06 02:00 - 001356088 _____ () C:\Program Files\iTunes\libxml2.dll
2018-06-26 15:46 - 2018-06-22 14:15 - 004608856 _____ () C:\Program Files (x86)\Google\Chrome\Application\67.0.3396.99\libglesv2.dll
2018-06-26 15:46 - 2018-06-22 14:15 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\67.0.3396.99\libegl.dll
2017-09-22 17:31 - 2015-02-06 17:24 - 000147456 _____ () C:\Program Files (x86)\Tt eSPORTS\Challenger Prime\Monitor.exe
2018-06-08 16:34 - 2018-06-08 16:34 - 035475912 _____ () C:\Program Files (x86)\Adobe\Adobe Sync\Coresync\Coresync.exe
2018-07-17 16:39 - 2018-07-17 16:39 - 000478720 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2018-07-17 16:39 - 2018-07-17 16:39 - 068153856 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2017-10-05 02:04 - 2017-10-05 02:05 - 002523136 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\UnityEngineDelegates.dll
2018-07-12 15:08 - 2018-07-12 15:08 - 000010752 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\RenderingPlugin.dll
2018-07-12 15:08 - 2018-07-12 15:08 - 004139008 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\MediaEngineCSWrapper.dll
2018-07-12 15:08 - 2018-07-12 15:08 - 000035840 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\WinMLWrapper.UWP.dll
2018-05-03 20:05 - 2018-05-03 20:06 - 000009216 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\ImagePipelineNative.dll
2018-04-05 08:04 - 2018-04-05 08:05 - 002283008 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\TrackingDLLUWP.dll
2018-07-17 16:39 - 2018-07-17 16:39 - 014919168 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll
2018-07-12 15:08 - 2018-07-12 15:08 - 003982848 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\MediaEngine.dll
2018-07-17 16:39 - 2018-07-17 16:39 - 002938880 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\AppCore.Windows.dll
2018-05-24 02:00 - 2018-05-24 02:00 - 000872448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\RuntimeConfiguration.dll
2018-07-12 15:08 - 2018-07-12 15:08 - 001396224 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll
2018-02-04 23:19 - 2018-02-04 23:20 - 004601048 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2018-07-17 16:39 - 2018-07-17 16:39 - 000162816 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18051.17710.0_x64__8wekyb3d8bbwe\SKU.dll
2018-07-22 22:40 - 2017-11-21 13:29 - 000278280 _____ () C:\Program Files\Bitdefender Antivirus Free\txmlutil.dll
2018-07-22 22:40 - 2018-06-18 19:15 - 000993728 _____ () C:\Program Files\Bitdefender Antivirus Free\Signatures\OTEngines\OTEngines_000_000\ashttpbr.mdl
2018-07-22 22:40 - 2018-06-18 19:15 - 000544880 _____ () C:\Program Files\Bitdefender Antivirus Free\Signatures\OTEngines\OTEngines_000_000\ashttpdsp.mdl
2018-07-22 22:40 - 2018-06-18 19:15 - 003232216 _____ () C:\Program Files\Bitdefender Antivirus Free\Signatures\OTEngines\OTEngines_000_000\ashttpph.mdl
2018-07-22 22:40 - 2018-06-18 19:15 - 001528320 _____ () C:\Program Files\Bitdefender Antivirus Free\Signatures\OTEngines\OTEngines_000_000\ashttprbl.mdl
2018-06-23 06:56 - 2018-06-23 06:56 - 001042232 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2018-06-23 06:56 - 2018-06-23 06:56 - 000189752 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll
2017-12-08 02:49 - 2017-12-08 02:49 - 000076088 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2018-07-15 11:26 - 2018-03-29 20:36 - 001694208 ____N () C:\Program Files (x86)\Send Anywhere\ffmpeg.dll
2018-07-15 11:26 - 2018-03-29 20:36 - 001251328 _____ () C:\Program Files (x86)\Send Anywhere\b70d5062edfef04020131b9431eb9034.node
2018-07-20 09:32 - 2018-07-20 09:32 - 001022464 _____ () \\?\C:\Users\xian\AppData\Local\Temp\d1f1e530-0b5d-4806-8057-fcc52784ccb8.tmp.node
2018-06-07 14:35 - 2018-06-07 14:35 - 081764304 _____ () C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\libcef.dll
2018-06-07 14:35 - 2018-06-07 14:35 - 002257360 _____ () C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\swiftshader\libglesv2.dll
2018-06-07 14:35 - 2018-06-07 14:35 - 000110544 _____ () C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\swiftshader\libegl.dll
2017-09-22 17:31 - 2014-12-10 14:50 - 000057344 _____ () C:\Program Files (x86)\Tt eSPORTS\Challenger Prime\lan.dll
2017-09-22 17:31 - 2013-03-30 23:53 - 000045056 _____ () C:\Program Files (x86)\Tt eSPORTS\Challenger Prime\hiddriver.dll
2017-08-14 11:05 - 2017-08-14 11:05 - 000073384 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll
2018-05-09 13:45 - 2018-05-09 13:45 - 000748008 _____ () C:\Program Files (x86)\Sony\PlayMemories Home\XMPFiles.dll
2018-05-09 13:45 - 2018-05-09 13:45 - 000696296 _____ () C:\Program Files (x86)\Sony\PlayMemories Home\XMPCore.dll
2018-06-11 15:57 - 2018-06-11 15:57 - 000142376 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\js\node_modules\fs-ext\build\Release\fs-ext.node
2018-06-11 15:57 - 2018-06-11 15:57 - 000271400 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\js\node_modules\node-vulcanjs\build\Release\VulcanJS.node
2018-06-11 15:57 - 2018-06-11 15:57 - 000141864 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\js\node_modules\ref\build\Release\binding.node
2018-06-11 15:57 - 2018-06-11 15:57 - 000150568 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\js\node_modules\ffi\build\Release\ffi_bindings.node
2018-06-11 15:57 - 2018-06-11 15:57 - 000097832 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\js\node_modules\node-ProxyResolver\build\Release\ProxyResolverWin.dll
2018-06-11 15:57 - 2018-06-11 15:57 - 000110120 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\js\node_modules\idle-gc\build\Release\idle-gc.node
2018-06-28 10:46 - 2018-06-28 10:46 - 000125976 _____ () \\?\C:\Program Files (x86)\Common Files\Adobe\Creative Cloud Libraries\js\node_modules\fs-ext\build\Release\fs-ext.node
2018-06-28 10:46 - 2018-06-28 10:46 - 000124952 _____ () \\?\C:\Program Files (x86)\Common Files\Adobe\Creative Cloud Libraries\js\node_modules\ref\build\Release\binding.node
2018-06-28 10:46 - 2018-06-28 10:46 - 000133144 _____ () \\?\C:\Program Files (x86)\Common Files\Adobe\Creative Cloud Libraries\js\node_modules\ffi\build\Release\ffi_bindings.node
2018-06-28 10:46 - 2018-06-28 10:46 - 000222232 _____ () \\?\C:\Program Files (x86)\Common Files\Adobe\Creative Cloud Libraries\js\node_modules\node-vulcanjs\build\Release\VulcanJS.node
2018-06-28 10:46 - 2018-06-28 10:46 - 000099864 _____ () C:\Program Files (x86)\Common Files\Adobe\Creative Cloud Libraries\js\node_modules\node-ProxyResolver\build\Release\ProxyResolverWin.dll
2018-06-28 10:46 - 2018-06-28 10:46 - 000106520 _____ () \\?\C:\Program Files (x86)\Common Files\Adobe\Creative Cloud Libraries\js\node_modules\bufferutil\build\Release\bufferutil.node
2018-06-28 10:46 - 2018-06-28 10:46 - 000094232 _____ () \\?\C:\Program Files (x86)\Common Files\Adobe\Creative Cloud Libraries\js\node_modules\idle-gc\build\Release\idle-gc.node
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2015-10-30 02:24 - 2017-07-14 18:24 - 000000855 _____ C:\WINDOWS\system32\Drivers\etc\hosts
 
127.0.0.1       localhost
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-813518053-636032705-5302477-1001\Control Panel\Desktop\\Wallpaper -> 
DNS Servers: 209.18.47.61 - 209.18.47.62
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Warn)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run: => "IAStorIcon"
HKLM\...\StartupApproved\Run32: => "Acrobat Assistant 8.0"
HKLM\...\StartupApproved\Run32: => "Dropbox"
HKLM\...\StartupApproved\Run32: => "QuickTime Task"
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer"
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\StartupApproved\Run: => "BlueStacks Agent"
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\StartupApproved\Run: => "Bomgar Support Reconnect [595AD346]"
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\StartupApproved\Run: => "Bomgar_Cleanup_ZD1605360925216"
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\StartupApproved\Run: => "Bomgar_Cleanup_ZD159297652639"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{FCBBB808-DD45-4442-A46E-0E62DDE555CA}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{678C9D20-D029-42B0-9183-50E5E2CFE8F3}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{C3D43F5C-2953-415A-8C80-FBB778DB29FC}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{F51298FB-8B60-49F9-AFF0-30323907B2AB}] => (Allow) C:\Program Files (x86)\Samsung\SideSync4\SideSync.exe
FirewallRules: [{6087F8F3-9911-46E7-A23B-65D523B0B531}] => (Allow) C:\Program Files (x86)\Samsung\SideSync4\SideSync.exe
FirewallRules: [{65EF7F39-A024-40B6-A960-2DB91DFFF1A6}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{7B8B1006-6776-4232-8265-E7A318539448}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{5FC01B65-45B5-47E3-9766-53BA12EC453D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{2299DADA-5200-408D-8DD9-4DD80694391C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [UDP Query User{F9226B54-EE2D-4D1A-A6AC-24E7F1EB1587}C:\users\xian\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\xian\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{D51176E6-9D46-4E6A-B276-A10F56F78FC6}C:\users\xian\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\xian\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{4B735292-96A7-4842-8130-EE312C1A819E}C:\users\xian\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\xian\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{3845C883-6A85-42AE-A3E0-7A0AB064023E}C:\users\xian\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\xian\appdata\roaming\spotify\spotify.exe
FirewallRules: [{9B32F551-E165-4679-BE37-27DAA0E7F198}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{64300E35-5DFC-4CA0-8AAA-68241C08061B}] => (Allow) C:\Program Files (x86)\Bluestacks\HD-Player.exe
FirewallRules: [{692CB1A1-B5CC-433E-B5BD-FBA92086C0EB}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
FirewallRules: [{4DAF3BA3-93AF-4FD8-B64C-918306632AA2}] => (Allow) X:\Steam\steamapps\common\Portal\hl2.exe
FirewallRules: [{F14A5B9C-676D-47A4-B4C6-A290A56843EB}] => (Allow) X:\Steam\steamapps\common\Portal\hl2.exe
FirewallRules: [{2395F1A6-BD80-4FDA-88CD-8AA566A8FCFB}] => (Allow) X:\Steam\steamapps\common\Portal 2\portal2.exe
FirewallRules: [{C0A4DAE4-C212-4785-B43A-934BB95D5B3C}] => (Allow) X:\Steam\steamapps\common\Portal 2\portal2.exe
FirewallRules: [{A256E5A1-B5C1-4EF9-9BE8-7DEB1EE82BBB}] => (Allow) X:\Steam\steamapps\common\Portal Stories Mel\portal2.exe
FirewallRules: [{86211C20-7E2A-496F-81C1-71E54F63B0CE}] => (Allow) X:\Steam\steamapps\common\Portal Stories Mel\portal2.exe
FirewallRules: [{E1A3B3D7-1B5C-4000-A69C-8815C698D60C}] => (Allow) X:\Steam\steamapps\common\SteamVRPerformanceTest\bin\win64\vr.exe
FirewallRules: [{172CC6F8-6B16-41EC-91A3-4DF5BCC6DEC3}] => (Allow) X:\Steam\steamapps\common\SteamVRPerformanceTest\bin\win64\vr.exe
FirewallRules: [{C294B62A-6BDE-46EF-85D0-2974D7E70B5B}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{F6072CFD-42FF-4838-AB2C-D51FED458C1C}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{937015D0-E2DD-4CC1-A927-2DC8C95E61AF}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{B79D273E-003D-43B9-9C5D-6606C42BDAFD}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{76AA7852-34F3-4776-990E-E3FDEE4B726E}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{D76AD06E-1C4B-4CF0-9078-CB227694B31B}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{DA358B1F-8983-4AEF-A596-7F19A10AA8EF}] => (Allow) LPort=8087
FirewallRules: [{AF1ACBA1-7E4C-455B-B102-FFBCF7E2A47A}] => (Allow) LPort=8086
FirewallRules: [{E14C9BFC-F1F6-4C1C-86F8-D7369E5AE956}] => (Allow) LPort=1434
FirewallRules: [{1042DEC0-2936-4EE3-944F-B8EFDC3AD1A9}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{430255D4-1673-452A-A3F7-0A024A78CBF6}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{99DA618B-810D-4D94-877E-4C2A19A0A195}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{986C682E-A132-4C33-A75C-A5D67DC2142B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{85D0AFE3-1164-4700-B6CF-A40B78585E31}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{F1B3A766-9DD2-467D-AEDF-D3950D8EB561}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{A50DBCF6-02A8-49FB-B8B4-063CD554D03A}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{71161327-8F9D-407A-9D4F-DC8EF7C78456}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{3376A7E6-1735-4F48-B90D-6350F92B71E8}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [TCP Query User{7CF03DAF-F27C-483C-B798-488161A09CE4}C:\program files (x86)\fontforgebuilds\bin\vcxsrv\vcxsrv.exe] => (Block) C:\program files (x86)\fontforgebuilds\bin\vcxsrv\vcxsrv.exe
FirewallRules: [UDP Query User{76877978-CF7E-418B-B70F-B18BD3FCD17C}C:\program files (x86)\fontforgebuilds\bin\vcxsrv\vcxsrv.exe] => (Block) C:\program files (x86)\fontforgebuilds\bin\vcxsrv\vcxsrv.exe
FirewallRules: [{3F17B4D9-B1FC-4765-A2C8-0DE28599A8E4}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{60E0AD8D-2323-4D00-B1B6-83E479A35B52}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{C8F403D2-3105-419E-B4B6-A3A2063FB807}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
FirewallRules: [TCP Query User{A165EBB2-03DF-4C64-8982-31255B668263}C:\program files (x86)\send anywhere\send anywhere.exe] => (Allow) C:\program files (x86)\send anywhere\send anywhere.exe
FirewallRules: [UDP Query User{EE43AD44-085C-44C5-977E-9F46A806E73F}C:\program files (x86)\send anywhere\send anywhere.exe] => (Allow) C:\program files (x86)\send anywhere\send anywhere.exe
 
==================== Restore Points =========================
 
18-07-2018 01:07:54 Scheduled Checkpoint
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (07/22/2018 10:41:18 PM) (Source: SecurityCenter) (EventID: 16) (User: )
Description: Error while updating  status to SECURITY_PRODUCT_STATE_ON.
 
Error: (07/22/2018 10:41:14 PM) (Source: SecurityCenter) (EventID: 16) (User: )
Description: Error while updating  status to SECURITY_PRODUCT_STATE_ON.
 
Error: (07/21/2018 10:06:45 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Samsung\SideSync4\SideSync.exe".Error in manifest or policy file "" on line .
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17134.165_none_fb429645306569ac.manifest.
Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17134.165_none_42efcd1c44e192b2.manifest.
 
Error: (07/21/2018 10:06:42 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ShellExperienceHost.exe, version: 10.0.17134.1, time stamp: 0x5ace103a
Faulting module name: Windows.UI.Xaml.dll, version: 10.0.17134.81, time stamp: 0x4f4899f8
Exception code: 0xc000027b
Fault offset: 0x00000000006a4e02
Faulting process id: 0x213c
Faulting application start time: 0x01d4203660d79a6b
Faulting application path: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
Faulting module path: C:\Windows\System32\Windows.UI.Xaml.dll
Report Id: 82eaac1d-5867-4d8a-9af6-794f926e5845
Faulting package full name: Microsoft.Windows.ShellExperienceHost_10.0.17134.112_neutral_neutral_cw5n1h2txyewy
Faulting package-relative application ID: App
 
Error: (07/20/2018 09:35:16 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Samsung\SideSync4\SideSync.exe".Error in manifest or policy file "" on line .
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17134.165_none_fb429645306569ac.manifest.
Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17134.165_none_42efcd1c44e192b2.manifest.
 
Error: (07/20/2018 09:35:11 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Please use sxstrace.exe for detailed diagnosis.
 
Error: (07/20/2018 09:32:07 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AppleOutlookDAVConfig.exe, version: 4.9.10.0, time stamp: 0x59e7127d
Faulting module name: KERNELBASE.dll, version: 10.0.17134.165, time stamp: 0xfa43f4b2
Exception code: 0xc06d007e
Fault offset: 0x0010ddc2
Faulting process id: 0x255c
Faulting application start time: 0x01d420366fb2fa46
Faulting application path: C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleOutlookDAVConfig.exe
Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
Report Id: 014649a0-b4d3-4618-988b-221e1c719d36
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (07/20/2018 09:32:06 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AppleOutlookDAVConfig.exe, version: 4.9.10.0, time stamp: 0x59e7127d
Faulting module name: KERNELBASE.dll, version: 10.0.17134.165, time stamp: 0xfa43f4b2
Exception code: 0xc06d007e
Fault offset: 0x0010ddc2
Faulting process id: 0x3aa0
Faulting application start time: 0x01d420366f444d4b
Faulting application path: C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleOutlookDAVConfig.exe
Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
Report Id: 66d05bdc-b2bd-44df-9c3e-489a40398a0c
Faulting package full name: 
Faulting package-relative application ID:
 
 
System errors:
=============
Error: (07/22/2018 09:58:13 PM) (Source: Microsoft-Windows-Diagnostics-Networking) (EventID: 5300) (User: NT AUTHORITY)
Description: An error occurred. The Network Diagnostics Framework failed to complete the repair phase of operation. A Windows Error Report was generated. [2147942487]
 
Error: (07/20/2018 09:33:43 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
Windows.SecurityCenter.WscDataProtection
 and APPID 
Unavailable
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/20/2018 09:33:43 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
Windows.SecurityCenter.WscBrokerManager
 and APPID 
Unavailable
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/20/2018 09:32:02 AM) (Source: DCOM) (EventID: 10016) (User: XILENCE)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user XILENCE\xian SID (S-1-5-21-813518053-636032705-5302477-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/20/2018 09:31:41 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/20/2018 09:31:41 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/20/2018 09:31:40 AM) (Source: NETLOGON) (EventID: 3095) (User: )
Description: This computer is configured as a member of a workgroup, not as
a member of a domain. The Netlogon service does not need to run in this
configuration.
 
Error: (07/20/2018 09:30:58 AM) (Source: DCOM) (EventID: 10010) (User: XILENCE)
Description: The server {F9717507-6651-4EDB-BFF7-AE615179BCCF} did not register with DCOM within the required timeout.
 
 
Windows Defender:
===================================
Date: 2018-07-22 09:42:07.662
Description: 
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version: 
Previous Signature Version: 1.273.129.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.15100.1
Error code: 0x80240438
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. 
 
Date: 2018-07-21 09:41:43.677
Description: 
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version: 
Previous Signature Version: 1.273.91.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.15100.1
Error code: 0x8024402c
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. 
 
Date: 2018-07-19 21:18:03.178
Description: 
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version: 
Previous Signature Version: 1.271.1198.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.15000.2
Error code: 0x800704cf
Error description: The network location cannot be reached. For information about network troubleshooting, see Windows Help. 
 
Date: 2018-07-14 21:17:36.606
Description: 
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version: 
Previous Signature Version: 1.271.971.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.15000.2
Error code: 0x8024402c
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. 
 
CodeIntegrity:
===================================
 
Date: 2018-07-22 22:43:34.489
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Bitdefender Antivirus Free\vsservppl.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender Antivirus Free\AgentCtrl.exe that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2018-07-22 22:41:32.559
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Bitdefender Antivirus Free\vsservppl.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender Antivirus Free\AgentCtrl.exe that did not meet the Custom 3 / Antimalware signing level requirements.
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i7-5820K CPU @ 3.30GHz
Percentage of memory in use: 32%
Total physical RAM: 32684.68 MB
Available physical RAM: 21938.88 MB
Total Virtual: 37548.68 MB
Available Virtual: 26167.08 MB
 
==================== Drives ================================
 
Drive c: (SystemDisk) (Fixed) (Total:237.48 GB) (Free:58.32 GB) NTFS
Drive e: (ScratchDisk) (Fixed) (Total:232.33 GB) (Free:231.74 GB) NTFS
Drive f: (easystore) (Fixed) (Total:7452.03 GB) (Free:4219.74 GB) NTFS
Drive h: (Fragile) (Fixed) (Total:931.51 GB) (Free:868.74 GB) NTFS
Drive i: (sKrubbed) (Fixed) (Total:19.69 GB) (Free:19.54 GB) NTFS
Drive k: (Kleen) (Fixed) (Total:909.91 GB) (Free:909.63 GB) NTFS
Drive x: (Six) (Fixed) (Total:1862.89 GB) (Free:436.75 GB) NTFS
 
\\?\Volume{72642e9b-ceb6-4947-bb7e-3ac7ae44c859}\ () (Fixed) (Total:0.44 GB) (Free:0.43 GB) NTFS
\\?\Volume{45f4dab9-ccf0-47b9-abd5-b0a0ec07f0e1}\ (Recovery) (Fixed) (Total:0.44 GB) (Free:0.15 GB) NTFS
\\?\Volume{107c55b2-ebbf-4d3b-b978-a95a7ecc161d}\ () (Fixed) (Total:0.44 GB) (Free:0.05 GB) NTFS
\\?\Volume{7c76a8e3-5bef-4ca4-9665-8aa5a57ba980}\ (Windows RE tools) (Fixed) (Total:1 GB) (Free:0.66 GB) NTFS
\\?\Volume{6920937e-f49a-4d05-835e-059acd18e5eb}\ () (Fixed) (Total:0.44 GB) (Free:0.12 GB) NTFS
\\?\Volume{674620eb-1c15-4b03-ba86-46004b29e308}\ () (Fixed) (Total:0.09 GB) (Free:0.09 GB) FAT32
\\?\Volume{8b69d665-f8d5-4482-9e58-5f09fd93cfa3}\ () (Fixed) (Total:0.09 GB) (Free:0.02 GB) FAT32
\\?\Volume{ae58cb97-fd4a-4550-8e6f-6d38d3b7a3a5}\ (SYSTEM) (Fixed) (Total:0.35 GB) (Free:0.31 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Protective MBR) (Size: 232.9 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
========================================================
Disk: 1 (Protective MBR) (Size: 238.5 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
========================================================
Disk: 2 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: BEC516A5)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)
 
========================================================
Disk: 3 (Protective MBR) (Size: 1863 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
========================================================
Disk: 4 (Size: 931.5 GB) (Disk ID: 7AFEF895)
 
Partition: GPT.
 
========================================================
Disk: 5 (Size: 7452 GB) (Disk ID: 16F2A91F)
 
Partition: GPT.
 
==================== End of Addition.txt ============================


#8 Xitixen

Xitixen
  • Topic Starter

  • Members
  • 69 posts
  • OFFLINE
  •  
  • Local time:11:02 AM

Posted 25 July 2018 - 07:50 PM

... and the after FRST:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21.07.2018
Ran by xian (administrator) on XILENCE (25-07-2018 19:46:00)
Running from H:\down
Loaded Profiles: xian (Available Profiles: xian)
Platform: Windows 10 Home Version 1803 17134.165 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
() C:\Windows\System32\nvwmi64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
(DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Bitdefender) C:\Program Files\Bitdefender Antivirus Free\updatesrv.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Bitdefender) C:\Program Files\Bitdefender Antivirus Free\bdredline.exe
(Bitdefender) C:\Program Files\Bitdefender Antivirus Free\vsserv.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Bitdefender) C:\Program Files\Bitdefender Antivirus Free\vsservppl.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
(Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectUI.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
() C:\Program Files (x86)\Tt eSPORTS\Challenger Prime\Monitor.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe
(CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
(Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectMonitor.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CoreSync.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe
(Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\libs\node.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(Bitdefender) C:\Program Files\Bitdefender Antivirus Free\bdagent.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
() C:\Windows\System32\nvwmi64.exe
(Microsoft Corporation) C:\Windows\System32\msdt.exe
(Microsoft Corporation) C:\Windows\System32\sdiagnhost.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-11] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16681728 2016-07-09] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-25] (Logitech, Inc.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [323056 2015-11-04] (Intel Corporation)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [316392 2018-05-11] (Adobe Systems, Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [298296 2018-07-06] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2409944 2018-06-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [1871344 2018-06-29] (Adobe Systems Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-12-09] (Apple Inc.)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3754168 2018-07-12] (Dropbox, Inc.)
HKLM-x32\...\Run: [Challenger Prime Gaming Keyboard Driver] => C:\Program Files (x86)\Tt eSPORTS\Challenger Prime\Monitor.exe [147456 2015-02-06] ()
HKLM-x32\...\Run: [WDDiscovery] => C:\Program Files (x86)\Western Digital\Discovery\Current\WD Discovery.exe [56894944 2017-12-09] (Western Digital Corporation)
HKLM-x32\...\Run: [DriveUtilitiesHelper] => C:\Program Files (x86)\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe [2309008 2017-09-19] (Western Digital Technologies, Inc.)
HKLM-x32\...\Run: [PMBVolumeWatcher] => C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe [3029480 2018-05-09] (Sony Corporation)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX2] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe [279240 2016-12-09] (CANON INC.)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1313408 2017-07-05] (CANON INC.)
HKLM-x32\...\Run: [] => [X]
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation)
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [886768 2018-06-29] (Adobe Systems Incorporated)
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\Bluestacks\HD-Agent.exe [171576 2017-12-17] (BlueStack Systems, Inc.)
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3042592 2017-06-08] (Valve Corporation)
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\Run: [Bomgar_Cleanup_ZD159297652639] => cmd.exe /C rd /S /Q "C:\ProgramData\apple-scc-0x595ad17f" & reg.exe delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD159297652639 /f <==== ATTENTION
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\Run: [Bomgar_Cleanup_ZD1605360925216] => cmd.exe /C rd /S /Q "C:\Users\xian\AppData\Local\Temp\nsfEFCD.tmpb" & reg.exe delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD1605360925216 /f <==== ATTENTION
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\Run: [Bomgar Support Reconnect [595AD346]] => C:\ProgramData\apple-scc-0x595ad346\apple-scc.exe [9329872 2017-02-24] (Apple)
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2018-06-26] (Apple Inc.)
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\Run: [Reflect UI] => C:\Program Files\Macrium\Common\ReflectUI.exe [3523848 2018-07-03] (Paramount Software UK Ltd)
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\RunOnce: [Application Restart #4] => C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe [2386392 2018-06-22] (Adobe Systems Incorporated)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.62 209.18.47.63
Tcpip\..\Interfaces\{15172ade-1f2b-4da8-a3cf-3f038ee62d9f}: [DhcpNameServer] 209.18.47.61 209.18.47.62 209.18.47.63
Tcpip\..\Interfaces\{7417af0c-701a-491b-a98c-3538a361ce87}: [DhcpNameServer] 209.18.47.61 209.18.47.62
Tcpip\..\Interfaces\{8f32a551-ab85-46ec-806e-34f1e60e30d7}: [DhcpNameServer] 209.18.47.61 209.18.47.62 209.18.47.63
 
Internet Explorer:
==================
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-07-21] (Microsoft Corporation)
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (CANON INC.)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-06-30] (Adobe Systems Incorporated)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-06-30] (Adobe Systems Incorporated)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2018-04-30] (Microsoft Corporation)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (CANON INC.)
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-06-30] (Adobe Systems Incorporated)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-06-30] (Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-06-30] (Adobe Systems Incorporated)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (CANON INC.)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-06-30] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (CANON INC.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-07-03] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-07-03] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-07-03] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-07-03] (Microsoft Corporation)
 
FireFox:
========
FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2018-02-02]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2016-09-20] [Legacy] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2018-06-22] (Adobe Systems)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2018-04-02] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-03-02] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-17] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2018-06-29] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2018-06-22] (Adobe Systems)
FF Plugin-x32: Sony Corporation/PMCADownloader -> C:\ProgramData\Sony Corporation\PMCADownloader\1.2.0.13221\npPMCADownloader.dll [2012-10-17] (Sony Network Entertainment International LLC)
FF Plugin-x32: Sony Corporation/PMCADownloaderHelper -> C:\ProgramData\Sony Corporation\PMCADownloader\1.2.0.13221\PMCADownloaderHelper.exe [2012-10-17] (Sony Network Entertainment International LLC)
FF Plugin-x32: Sony Corporation/PMCADownloaderLib -> C:\ProgramData\Sony Corporation\PMCADownloader\1.2.0.13221\PMCADownloaderLib.dll [2012-10-17] (Sony Network Entertainment International LLC)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxps://mail.google.com/mail/?shva=1#inbox/1281717902d4583d
CHR StartupUrls: Default -> "hxxps://www.google.com/"
CHR DefaultSearchKeyword: Default -> lp
CHR Profile: C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default [2018-07-25]
CHR Extension: (Slides) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-24]
CHR Extension: (Entanglement Web App) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd [2016-09-19]
CHR Extension: (Docs) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-24]
CHR Extension: (Google Drive) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-09-19]
CHR Extension: (QR-Code Tag Extension) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcfddoencoiedfjgepnlhcpfikgaogdg [2016-09-19]
CHR Extension: (Brushed) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfjgbcjfpbbfepcccpaffkjofcmglifg [2016-09-19]
CHR Extension: (WOT Web of Trust, Website Reputation Ratings) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2018-07-25]
CHR Extension: (Audiotool) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkgoccjhfjgjedhkiefaclppgbmoobnk [2016-09-19]
CHR Extension: (Skype Calling) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blakpkgjpemejpbmfiglncklihnhjkij [2016-09-19]
CHR Extension: (YouTube) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-09-19]
CHR Extension: (Honey) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2018-07-10]
CHR Extension: (Ebates: The Free Cash Back Shopping Assistant) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\chhjbpecpncaggjpdakmflnfcopglcmi [2018-07-25]
CHR Extension: (Add to Amazon Wish List) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ciagpekplgpbepdgggflgmahnjgiaced [2016-09-19]
CHR Extension: (Google Search) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-09-19]
CHR Extension: (Logitech Smooth Scrolling) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkpejdfnpdkhifgbancbammdijojoffk [2016-09-20]
CHR Extension: (Google+) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlppkpafhbajpcmmoheippocdidnckmm [2016-09-19]
CHR Extension: (Chrome Connectivity Diagnostics) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\eemlkeanncmjljgehlbplemhmdmalhdc [2016-09-19]
CHR Extension: (Adobe Acrobat) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-04]
CHR Extension: (Bulk Media Downloader) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehfdcgbfcboceiclmjaofdannmjdeaoi [2017-11-07]
CHR Extension: (Box) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejnkaeblpdcamcioiiabclakabcbjmbl [2016-09-19]
CHR Extension: (Pandora) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbangkleohkafngihneedemihgfeikcl [2016-09-19]
CHR Extension: (Sheets) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-24]
CHR Extension: (Stupeflix Video Maker) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkdmcfnoimoilncpjchamnenebopocem [2016-09-19]
CHR Extension: (iCloud Bookmarks) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkepacicchenbjecpbpbclokcabebhah [2017-10-11]
CHR Extension: (Full Screen Weather) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkkaebihfmbofclegkcfkkemepfehibg [2016-09-19]
CHR Extension: (Google Docs Offline) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-09-19]
CHR Extension: (AdBlock) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-07-25]
CHR Extension: (TinEye Reverse Image Search) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\haebnnbpedcbhciplfhjjkbafijpncjl [2017-08-04]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2018-07-20]
CHR Extension: (XPath Helper) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgimnogjllphhhkhlmebbmlgjoejdpjl [2016-09-19]
CHR Extension: (Mahjong Words) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmefkohhpkdnaieghlijadogfapogebe [2016-09-19]
CHR Extension: (Google Keep - notes and lists) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2018-07-10]
CHR Extension: (Cisco Webex Extension) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlhmfgmfgeifomenelglieieghnjghma [2018-07-10]
CHR Extension: (Google Voice (by Google)) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcnhkahnjcbndmmehfkdnkjomaanaooo [2016-09-19]
CHR Extension: (EasyHome Homestyler) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdmmkfaghgcicheaimnpffeeekheafkb [2017-05-30]
CHR Extension: (Turbo Download Manager) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\kemfccojgjoilhfmcblgimbggikekjip [2017-03-01]
CHR Extension: (Google Play) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\komhbcfkdcgmcdoenjcjheifdiabikfi [2016-09-19]
CHR Extension: (Google Maps) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2016-09-19]
CHR Extension: (Take Webpage Screenshots Entirely - FireShot) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbpblocgmgfnpjjppndjkmgjaogfceg [2018-01-01]
CHR Extension: (Pocket) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk [2016-09-19]
CHR Extension: (Ghostery – Privacy Ad Blocker) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2018-07-20]
CHR Extension: (feedly) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndhinffkekpekljifjkkkkkhopnjodja [2016-09-19]
CHR Extension: (RSS Subscription Extension (by Google)) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlbjncdgjeocebhnmkbbbdekmmmcbfjd [2016-09-19]
CHR Extension: (Awesome Screenshot: Screen Video Recorder) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlipoenfbbikpbjkfpfillcgkoblgpmj [2018-06-17]
CHR Extension: (Chrome Web Store Payments) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-06]
CHR Extension: (PlayMemories Camera Apps Downloader) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohlghnkgcadghcdodlcjfhogekonhdei [2017-08-07]
CHR Extension: (Picasa) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb [2016-09-19]
CHR Extension: (QR Code Decoder) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pafahhgpmimhoiglnpehhjpnkkppfpek [2016-09-19]
CHR Extension: (Gmail) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-09-19]
CHR Extension: (Google Similar Pages) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjnfggphgdjblhfjaphkjhfpiiekbbej [2016-09-19]
CHR Extension: (Chrome Media Router) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-06-18]
CHR Extension: (iReader) - C:\Users\xian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ppelffpjgkifjfgnbaaldcehkpajlmbc [2016-09-19]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [818128 2018-06-22] (Adobe Systems Incorporated)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [2321384 2018-05-11] (Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2128872 2018-05-11] (Adobe Systems, Incorporated)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2018-07-05] (Apple Inc.)
R2 bdredline; C:\Program Files\Bitdefender Antivirus Free\bdredline.exe [2195280 2018-03-22] (Bitdefender)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8765104 2018-07-13] (Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-09-27] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-09-27] (Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [51392 2018-07-12] (Dropbox, Inc.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [19440 2015-11-04] (Intel Corporation)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [391744 2017-07-11] ()
R2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [4091112 2017-11-09] (Paramount Software UK Ltd)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6541008 2018-05-03] (Malwarebytes)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [265824 2018-04-17] ()
R2 NVWMI; C:\Windows\system32\nvwmi64.exe [3168824 2016-03-19] ()
R2 PMBDeviceInfoProvider; C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [498152 2018-05-09] (Sony Corporation)
R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [1275776 2018-05-16] (Bitdefender)
S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2017-01-16] (DEVGURU Co., LTD.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [11293936 2018-04-03] (TeamViewer GmbH)
R2 updatesrv; C:\Program Files\Bitdefender Antivirus Free\updatesrv.exe [239400 2018-05-14] (Bitdefender)
R2 vsserv; C:\Program Files\Bitdefender Antivirus Free\vsserv.exe [239400 2018-05-14] (Bitdefender)
R2 vsservppl; C:\Program Files\Bitdefender Antivirus Free\vsservppl.exe [239400 2018-05-14] (Bitdefender)
R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [355184 2017-09-19] (Western Digital Technologies, Inc.)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\NisSrv.exe [3925648 2018-06-26] (Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\MsMpEng.exe [100080 2018-06-26] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3848288 2018-04-17] (Intel® Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 AsrDrv101; C:\Windows\SysWOW64\Drivers\AsrDrv101.sys [22280 2016-09-24] (ASRock Incorporation)
R0 atc; C:\WINDOWS\System32\DRIVERS\atc.sys [1283464 2018-04-27] (BitDefender S.R.L. Bucharest, ROMANIA)
R0 avc3; C:\WINDOWS\System32\DRIVERS\avc3.sys [1723552 2018-04-17] (BitDefender)
R0 BdDci; C:\WINDOWS\system32\DRIVERS\bddci.sys [152648 2018-04-19] (Bitdefender)
S0 bdelam; C:\WINDOWS\System32\drivers\bdelam.sys [23032 2018-04-19] (Bitdefender)
S3 BstkDrv; C:\Program Files (x86)\Bluestacks\BstkDrv.sys [269408 2017-12-16] (Bluestack System Inc. )
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2017-01-16] (Samsung Electronics Co., Ltd.)
R3 edrsensor; C:\WINDOWS\System32\DRIVERS\edrsensor.sys [246064 2018-04-19] (BitDefender S.R.L. Bucharest, ROMANIA)
S1 epp; O:\EmsiSoft\bin64\epp.sys [142952 2018-05-16] (Emsisoft Ltd)
R0 gzflt; C:\WINDOWS\System32\drivers\gzflt.sys [193184 2018-05-29] (BitDefender LLC)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [231168 2017-01-13] (Intel Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [253664 2018-07-25] (Malwarebytes)
R3 NETwNb64; C:\WINDOWS\system32\DRIVERS\Netwbw02.sys [3586072 2018-05-11] (Intel Corporation)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_b7e5dd1387001335\nvlddmkm.sys [16936560 2017-11-09] (NVIDIA Corporation)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2017-01-16] (Samsung Electronics Co., Ltd.)
R2 trufos; C:\WINDOWS\System32\drivers\trufos.sys [607640 2018-04-25] (Bitdefender)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [46592 2018-06-26] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [340008 2018-06-26] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [59944 2018-06-26] (Microsoft Corporation)
R1 ZAM; C:\WINDOWS\System32\drivers\zam64.sys [203680 2018-07-25] (Zemana Ltd.)
R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [203680 2018-07-25] (Zemana Ltd.)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-07-25 17:44 - 2018-07-25 17:44 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless
2018-07-25 17:44 - 2018-07-25 17:44 - 000000000 ____D C:\Program Files\Common Files\Intel
2018-07-25 17:44 - 2018-07-25 17:44 - 000000000 ____D C:\Program Files (x86)\Cisco
2018-07-25 17:38 - 2018-07-25 17:38 - 1241802535 _____ C:\WINDOWS\MEMORY.DMP
2018-07-25 17:38 - 2018-07-25 17:38 - 002096764 _____ C:\WINDOWS\Minidump\072518-8703-01.dmp
2018-07-25 14:53 - 2018-07-25 19:46 - 000122634 _____ C:\WINDOWS\ZAM.krnl.trace
2018-07-25 14:53 - 2018-07-25 19:46 - 000089107 _____ C:\WINDOWS\ZAM_Guard.krnl.trace
2018-07-25 14:53 - 2018-07-25 14:53 - 000203680 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zamguard64.sys
2018-07-25 14:53 - 2018-07-25 14:53 - 000203680 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zam64.sys
2018-07-25 14:22 - 2018-07-25 14:22 - 000000000 ____D C:\Users\xian\Documents\Reflect
2018-07-25 14:20 - 2018-07-25 14:20 - 000000000 ____D C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Macrium
2018-07-25 14:20 - 2018-07-25 14:20 - 000000000 ____D C:\Program Files\Macrium
2018-07-25 14:06 - 2018-07-25 14:20 - 000000000 ____D C:\ProgramData\Macrium
2018-07-25 13:46 - 2018-07-25 13:46 - 000000000 ____D C:\Users\xian\AppData\Local\Zemana
2018-07-25 13:40 - 2018-07-25 17:46 - 000253664 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2018-07-25 13:40 - 2018-07-25 13:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-07-25 13:40 - 2018-04-26 05:36 - 000152184 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2018-07-25 13:37 - 2018-07-25 13:37 - 000002410 _____ C:\Users\xian\Desktop\Rkill.txt
2018-07-25 13:37 - 2018-07-25 13:37 - 000000000 ____D C:\Users\xian\Desktop\rkill
2018-07-24 21:31 - 2018-07-24 21:31 - 000000080 ___SH C:\bootTel.dat
2018-07-23 19:36 - 2018-07-24 21:38 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2018-07-23 19:19 - 2018-07-25 17:38 - 000000000 ____D C:\WINDOWS\Minidump
2018-07-23 12:57 - 2018-07-23 12:57 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign086097b0d912ddc4
2018-07-23 10:33 - 2018-07-23 10:33 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsigna6baef72ad2da9c3
2018-07-23 10:33 - 2018-07-23 10:33 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign4620eb3e78bed101
2018-07-22 23:07 - 2018-07-25 19:46 - 000000000 ____D C:\FRST
2018-07-22 22:43 - 2018-07-22 22:43 - 000029754 _____ C:\ProgramData\agent.update.1532317419.bdinstall.bin
2018-07-22 22:41 - 2018-07-22 22:41 - 000001194 _____ C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bitdefender Antivirus Free.lnk
2018-07-22 22:40 - 2018-07-22 22:40 - 000001209 _____ C:\Users\Public\Desktop\Bitdefender Antivirus Free.lnk
2018-07-22 22:40 - 2018-07-22 22:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender Antivirus Free
2018-07-22 22:40 - 2018-07-22 22:40 - 000000000 ____D C:\ProgramData\Bitdefender
2018-07-22 22:40 - 2018-05-29 05:04 - 000193184 _____ (BitDefender LLC) C:\WINDOWS\system32\Drivers\gzflt.sys
2018-07-22 22:40 - 2018-04-27 06:29 - 001283464 _____ (BitDefender S.R.L. Bucharest, ROMANIA) C:\WINDOWS\system32\Drivers\atc.sys
2018-07-22 22:40 - 2018-04-19 22:37 - 000023032 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\bdelam.sys
2018-07-22 22:40 - 2018-04-19 11:15 - 000246064 _____ (BitDefender S.R.L. Bucharest, ROMANIA) C:\WINDOWS\system32\Drivers\edrsensor.sys
2018-07-22 22:40 - 2018-04-19 05:11 - 000152648 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\bddci.sys
2018-07-22 22:40 - 2018-04-17 11:27 - 001723552 _____ (BitDefender) C:\WINDOWS\system32\Drivers\avc3.sys
2018-07-22 22:39 - 2018-07-22 22:39 - 000000000 ____D C:\Users\xian\AppData\Roaming\QuickScan
2018-07-22 22:39 - 2018-04-25 05:27 - 000607640 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\trufos.sys
2018-07-22 22:38 - 2018-07-25 19:46 - 000000000 ____D C:\Program Files\Bitdefender Antivirus Free
2018-07-22 22:37 - 2018-07-22 22:37 - 000003802 _____ C:\WINDOWS\System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864
2018-07-22 22:35 - 2018-07-22 22:43 - 000000000 ____D C:\Program Files\Bitdefender Agent
2018-07-22 22:35 - 2018-07-22 22:35 - 000042554 _____ C:\ProgramData\agent.1532316906.bdinstall.bin
2018-07-22 22:35 - 2018-07-22 22:35 - 000000000 ____D C:\ProgramData\Bitdefender Agent
2018-07-22 22:32 - 2018-07-22 22:32 - 009986176 _____ C:\Users\xian\Downloads\bitdefender_online.exe
2018-07-22 22:18 - 2018-07-22 22:24 - 000000000 ____D C:\ProgramData\SecTaskMan
2018-07-22 22:18 - 2018-07-22 22:18 - 000001229 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spy Protector.lnk
2018-07-22 22:18 - 2018-07-22 22:18 - 000001218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security Task Manager.lnk
2018-07-22 22:18 - 2018-07-22 22:18 - 000001206 _____ C:\Users\Public\Desktop\Security Task Manager.lnk
2018-07-22 22:18 - 2018-07-22 22:18 - 000000000 ____D C:\Program Files (x86)\Security Task Manager
2018-07-22 22:18 - 2018-07-22 22:16 - 003017632 _____ C:\Users\xian\Downloads\SecurityTaskManager_Setup.exe
2018-07-22 10:08 - 2018-07-22 10:08 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignec8b492d601a40b1
2018-07-22 09:47 - 2018-07-22 09:47 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign98c1dbba8fdb470d
2018-07-21 18:48 - 2018-07-21 18:48 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsigne63ad584d2c5de77
2018-07-21 18:45 - 2018-07-21 18:45 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign41e7078d6258ce1e
2018-07-21 14:50 - 2018-07-21 14:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2018-07-17 13:22 - 2018-07-17 13:22 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign3704237fd106cf36
2018-07-17 12:28 - 2018-07-17 12:28 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignd44dc54e4677596e
2018-07-17 12:13 - 2018-07-17 12:13 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign799888e304a81074
2018-07-17 12:13 - 2018-07-17 12:13 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign1cc08e469885b792
2018-07-15 19:33 - 2018-07-15 19:33 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign2930c85ae4bd9362
2018-07-15 19:30 - 2018-07-15 19:30 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign4909dc3eb204d02f
2018-07-15 19:21 - 2018-07-15 19:21 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignfaeaeca3bfbd73a2
2018-07-15 19:21 - 2018-07-15 19:21 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignb06f6c951c4e2722
2018-07-15 19:16 - 2018-07-15 19:16 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign9efe96ab01fcaa9f
2018-07-15 19:16 - 2018-07-15 19:16 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign610efe6f08ba5fcc
2018-07-15 11:26 - 2018-07-25 15:24 - 000000000 ____D C:\Program Files (x86)\Send Anywhere
2018-07-13 16:26 - 2018-07-13 16:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2018-07-13 11:40 - 2018-07-13 11:40 - 000001826 _____ C:\Users\Public\Desktop\iTunes.lnk
2018-07-13 11:40 - 2018-07-13 11:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2018-07-13 11:40 - 2018-07-13 11:40 - 000000000 ____D C:\Program Files\iTunes
2018-07-13 11:40 - 2018-07-13 11:40 - 000000000 ____D C:\Program Files\iPod
2018-07-13 11:36 - 2018-07-13 11:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2018-07-12 21:01 - 2018-07-12 21:01 - 000051392 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2018-07-12 21:01 - 2018-07-12 21:01 - 000050232 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2018-07-12 21:01 - 2018-07-12 21:01 - 000045672 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2018-07-12 21:01 - 2018-07-12 21:01 - 000045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2018-07-10 20:21 - 2018-07-06 09:20 - 002868640 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2018-07-10 20:21 - 2018-07-06 09:20 - 001610648 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2018-07-10 20:21 - 2018-07-06 09:20 - 000792472 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2018-07-10 20:21 - 2018-07-06 09:20 - 000689560 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2018-07-10 20:21 - 2018-07-06 09:20 - 000612248 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2018-07-10 20:21 - 2018-07-06 09:20 - 000451992 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2018-07-10 20:21 - 2018-07-06 09:20 - 000309664 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2018-07-10 20:21 - 2018-07-06 09:20 - 000144792 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2018-07-10 20:21 - 2018-07-06 09:17 - 003932672 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2018-07-10 20:21 - 2018-07-06 08:56 - 004708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2018-07-10 20:21 - 2018-07-06 08:53 - 000340992 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2018-07-10 20:21 - 2018-07-06 08:52 - 001787392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2018-07-10 20:21 - 2018-07-06 08:51 - 003652608 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-07-10 20:21 - 2018-07-06 08:51 - 002051584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2018-07-10 20:21 - 2018-07-06 08:51 - 001364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
2018-07-10 20:21 - 2018-07-06 07:06 - 003611368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2018-07-10 20:21 - 2018-07-06 06:52 - 002895360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-07-10 20:21 - 2018-07-06 06:51 - 002401280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2018-07-10 20:21 - 2018-07-06 06:26 - 019525120 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2018-07-10 20:21 - 2018-07-06 06:25 - 023863296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2018-07-10 20:21 - 2018-07-06 02:32 - 000480672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2018-07-10 20:21 - 2018-07-06 02:31 - 000462752 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2018-07-10 20:21 - 2018-07-06 02:27 - 001174432 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2018-07-10 20:21 - 2018-07-06 02:26 - 002712992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2018-07-10 20:21 - 2018-07-06 02:26 - 001148800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2018-07-10 20:21 - 2018-07-06 02:26 - 000930720 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2018-07-10 20:21 - 2018-07-06 02:25 - 009147808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-07-10 20:21 - 2018-07-06 02:25 - 002753040 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2018-07-10 20:21 - 2018-07-06 02:25 - 002571728 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2018-07-10 20:21 - 2018-07-06 02:25 - 002420632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2018-07-10 20:21 - 2018-07-06 02:25 - 001945784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2018-07-10 20:21 - 2018-07-06 02:25 - 001018616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2018-07-10 20:21 - 2018-07-06 02:25 - 000483048 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll
2018-07-10 20:21 - 2018-07-06 02:24 - 000380824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2018-07-10 20:21 - 2018-07-06 02:14 - 002242208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2018-07-10 20:21 - 2018-07-06 02:14 - 001981896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2018-07-10 20:21 - 2018-07-06 02:14 - 001175568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2018-07-10 20:21 - 2018-07-06 02:14 - 000988640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2018-07-10 20:21 - 2018-07-06 02:14 - 000829856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2018-07-10 20:21 - 2018-07-06 02:13 - 001620872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2018-07-10 20:21 - 2018-07-06 02:10 - 025845760 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-07-10 20:21 - 2018-07-06 02:07 - 022006272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2018-07-10 20:21 - 2018-07-06 02:04 - 022713856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-07-10 20:21 - 2018-07-06 02:03 - 004371456 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2018-07-10 20:21 - 2018-07-06 02:02 - 009084928 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2018-07-10 20:21 - 2018-07-06 02:01 - 007057408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2018-07-10 20:21 - 2018-07-06 02:01 - 005883904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2018-07-10 20:21 - 2018-07-06 02:00 - 019403264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-07-10 20:21 - 2018-07-06 01:59 - 006647296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2018-07-10 20:21 - 2018-07-06 01:59 - 003381248 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
2018-07-10 20:21 - 2018-07-06 01:59 - 001153536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2018-07-10 20:21 - 2018-07-06 01:58 - 004867584 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-07-10 20:21 - 2018-07-06 01:58 - 002825728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
2018-07-10 20:21 - 2018-07-06 01:58 - 001931776 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeangle.dll
2018-07-10 20:21 - 2018-07-06 01:58 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2018-07-10 20:21 - 2018-07-06 01:58 - 000670720 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2018-07-10 20:21 - 2018-07-06 01:57 - 007579648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2018-07-10 20:21 - 2018-07-06 01:57 - 005779456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2018-07-10 20:21 - 2018-07-06 01:57 - 003712512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-07-10 20:21 - 2018-07-06 01:57 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2018-07-10 20:21 - 2018-07-06 01:57 - 000813056 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2018-07-10 20:21 - 2018-07-06 01:57 - 000473088 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2018-07-10 20:21 - 2018-07-06 01:56 - 001986560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll
2018-07-10 20:21 - 2018-07-06 01:56 - 001817600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2018-07-10 20:21 - 2018-07-06 01:56 - 001567744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll
2018-07-10 20:21 - 2018-07-06 01:56 - 001225216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2018-07-10 20:21 - 2018-07-06 01:56 - 000784896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2018-07-10 20:21 - 2018-07-06 01:56 - 000327680 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioCredProv.dll
2018-07-10 20:21 - 2018-07-06 01:55 - 003440128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-07-10 20:21 - 2018-07-06 01:55 - 001804288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2018-07-10 20:21 - 2018-07-06 01:55 - 001627136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2018-07-10 20:21 - 2018-07-06 01:55 - 001395712 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2018-07-10 20:21 - 2018-07-06 01:55 - 001264640 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2018-07-10 20:21 - 2018-07-06 01:54 - 003015680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2018-07-10 20:21 - 2018-07-06 01:54 - 002449408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll
2018-07-10 20:21 - 2018-07-06 01:54 - 002236928 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2018-07-10 20:21 - 2018-07-06 01:54 - 001214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2018-07-10 20:21 - 2018-07-06 01:54 - 000999936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2018-07-10 20:21 - 2018-07-06 01:54 - 000943616 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll
2018-07-10 20:21 - 2018-07-06 01:54 - 000884736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2018-07-10 20:21 - 2018-07-06 01:54 - 000884224 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2018-07-10 20:21 - 2018-07-06 01:54 - 000542208 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2018-07-10 20:21 - 2018-07-06 01:54 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2018-07-10 20:21 - 2018-07-06 01:53 - 000713216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll
2018-07-10 20:21 - 2018-07-06 01:52 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2018-07-10 20:21 - 2018-06-15 12:50 - 001376576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2018-07-10 20:21 - 2018-06-15 12:49 - 021388856 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2018-07-10 20:21 - 2018-06-15 12:48 - 002395056 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
2018-07-10 20:21 - 2018-06-15 12:48 - 000338352 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSrvPolicyManager.dll
2018-07-10 20:21 - 2018-06-15 12:34 - 008623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2018-07-10 20:21 - 2018-06-15 12:33 - 012710400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2018-07-10 20:21 - 2018-06-15 12:30 - 001308672 _____ C:\WINDOWS\system32\FaceProcessor.dll
2018-07-10 20:21 - 2018-06-15 12:30 - 001254400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2018-07-10 20:21 - 2018-06-15 12:30 - 000878592 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2018-07-10 20:21 - 2018-06-15 12:29 - 000740864 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2018-07-10 20:21 - 2018-06-15 10:25 - 020383720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2018-07-10 20:21 - 2018-06-15 10:22 - 001026896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2018-07-10 20:21 - 2018-06-15 10:16 - 002206528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
2018-07-10 20:21 - 2018-06-15 10:07 - 011901952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2018-07-10 20:21 - 2018-06-15 10:06 - 007987712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2018-07-10 20:21 - 2018-06-15 10:02 - 000704000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2018-07-10 20:21 - 2018-06-15 08:23 - 000788992 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll
2018-07-10 20:21 - 2018-06-15 00:21 - 001213368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2018-07-10 20:21 - 2018-06-15 00:21 - 000761440 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2018-07-10 20:21 - 2018-06-15 00:19 - 001034632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2018-07-10 20:21 - 2018-06-15 00:15 - 002563960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2018-07-10 20:21 - 2018-06-15 00:15 - 000753152 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2018-07-10 20:21 - 2018-06-15 00:13 - 000510904 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2018-07-10 20:21 - 2018-06-15 00:12 - 007519992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-07-10 20:21 - 2018-06-15 00:12 - 000491304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2018-07-10 20:21 - 2018-06-15 00:11 - 006817872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2018-07-10 20:21 - 2018-06-15 00:10 - 001934400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2018-07-10 20:21 - 2018-06-15 00:10 - 001097640 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2018-07-10 20:21 - 2018-06-15 00:10 - 000717208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2018-07-10 20:21 - 2018-06-15 00:09 - 007436120 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-07-10 20:21 - 2018-06-15 00:09 - 002830240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2018-07-10 20:21 - 2018-06-15 00:09 - 002546592 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2018-07-10 20:21 - 2018-06-15 00:09 - 001798552 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2018-07-10 20:21 - 2018-06-15 00:09 - 001742272 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2018-07-10 20:21 - 2018-06-15 00:09 - 001659296 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2018-07-10 20:21 - 2018-06-15 00:09 - 001209800 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2018-07-10 20:21 - 2018-06-15 00:09 - 001112600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2018-07-10 20:21 - 2018-06-15 00:09 - 000594128 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2018-07-10 20:21 - 2018-06-15 00:08 - 004403304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2018-07-10 20:21 - 2018-06-15 00:08 - 002371392 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2018-07-10 20:21 - 2018-06-15 00:08 - 002062488 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2018-07-10 20:21 - 2018-06-15 00:08 - 001946752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2018-07-10 20:21 - 2018-06-15 00:08 - 001784584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2018-07-10 20:21 - 2018-06-15 00:08 - 001457128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-07-10 20:21 - 2018-06-15 00:08 - 001288840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2018-07-10 20:21 - 2018-06-15 00:08 - 001258280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-07-10 20:21 - 2018-06-15 00:08 - 001140568 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-07-10 20:21 - 2018-06-15 00:08 - 000898760 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2018-07-10 20:21 - 2018-06-15 00:07 - 001611584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2018-07-10 20:21 - 2018-06-15 00:07 - 001145696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2018-07-10 20:21 - 2018-06-15 00:05 - 000550608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2018-07-10 20:21 - 2018-06-15 00:04 - 002331576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2018-07-10 20:21 - 2018-06-15 00:04 - 001462824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2018-07-10 20:21 - 2018-06-15 00:04 - 001251736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll
2018-07-10 20:21 - 2018-06-15 00:04 - 000719552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 006572000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 006528600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 006043600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 004788504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 002535032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 002163184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 001805752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 001710240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 001559368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 001380192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 001144120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 001020160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 001011968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2018-07-10 20:21 - 2018-06-15 00:03 - 000770152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2018-07-10 20:21 - 2018-06-14 23:49 - 002962944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2018-07-10 20:21 - 2018-06-14 23:48 - 002900992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2018-07-10 20:21 - 2018-06-14 23:46 - 004706816 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2018-07-10 20:21 - 2018-06-14 23:46 - 004333568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2018-07-10 20:21 - 2018-06-14 23:46 - 001356800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2018-07-10 20:21 - 2018-06-14 23:46 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2018-07-10 20:21 - 2018-06-14 23:45 - 002548736 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
2018-07-10 20:21 - 2018-06-14 23:45 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2018-07-10 20:21 - 2018-06-14 23:44 - 001632256 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2018-07-10 20:21 - 2018-06-14 23:44 - 001342976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2018-07-10 20:21 - 2018-06-14 23:43 - 001110528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2018-07-10 20:21 - 2018-06-14 23:43 - 000312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagnosticLogCSP.dll
2018-07-10 20:21 - 2018-06-14 23:42 - 003392512 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2018-07-10 20:21 - 2018-06-14 23:42 - 002367488 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2018-07-10 20:21 - 2018-06-14 23:42 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2018-07-10 20:21 - 2018-06-14 23:42 - 000102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2018-07-10 20:21 - 2018-06-14 23:41 - 004561920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2018-07-10 20:21 - 2018-06-14 23:41 - 003320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2018-07-10 20:21 - 2018-06-14 23:41 - 001768448 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2018-07-10 20:21 - 2018-06-14 23:41 - 001724928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2018-07-10 20:21 - 2018-06-14 23:41 - 000625152 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2018-07-10 20:21 - 2018-06-14 23:40 - 001550848 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2018-07-10 20:21 - 2018-06-14 23:40 - 001487360 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2018-07-10 20:21 - 2018-06-14 23:40 - 000827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2018-07-10 20:21 - 2018-06-14 23:39 - 002903040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2018-07-10 20:21 - 2018-06-14 23:39 - 002583552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2018-07-10 20:21 - 2018-06-14 23:39 - 002172416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2018-07-10 20:21 - 2018-06-14 23:39 - 001303040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2018-07-10 20:21 - 2018-06-14 23:39 - 000916992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2018-07-10 20:21 - 2018-06-14 23:39 - 000847360 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2018-07-10 20:21 - 2018-06-14 23:39 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2018-07-10 20:21 - 2018-06-14 23:38 - 001854976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2018-07-10 20:21 - 2018-06-14 23:38 - 001581568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2018-07-10 20:21 - 2018-06-14 23:38 - 001305088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2018-07-10 20:21 - 2018-06-14 23:38 - 001070080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2018-07-10 20:21 - 2018-06-14 23:38 - 001036288 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2018-07-10 20:21 - 2018-06-14 23:38 - 000949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2018-07-10 20:21 - 2018-06-14 23:38 - 000910848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2018-07-10 20:21 - 2018-06-14 23:38 - 000596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2018-07-10 20:21 - 2018-06-14 23:37 - 001374208 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2018-07-10 20:20 - 2018-07-06 09:20 - 000070040 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2018-07-10 20:20 - 2018-07-06 09:14 - 000541592 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2018-07-10 20:20 - 2018-07-06 08:53 - 000409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2018-07-10 20:20 - 2018-07-06 08:53 - 000386048 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2018-07-10 20:20 - 2018-07-06 08:52 - 000677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2018-07-10 20:20 - 2018-07-06 08:51 - 001004032 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2018-07-10 20:20 - 2018-07-06 08:51 - 000391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2018-07-10 20:20 - 2018-07-06 08:50 - 000615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2018-07-10 20:20 - 2018-07-06 08:49 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe
2018-07-10 20:20 - 2018-07-06 06:54 - 000485376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2018-07-10 20:20 - 2018-07-06 06:54 - 000343552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2018-07-10 20:20 - 2018-07-06 06:53 - 000775168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2018-07-10 20:20 - 2018-07-06 06:53 - 000347136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
2018-07-10 20:20 - 2018-07-06 06:52 - 001452544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2018-07-10 20:20 - 2018-07-06 06:52 - 001308160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2018-07-10 20:20 - 2018-07-06 06:51 - 000080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcbuilder.exe
2018-07-10 20:20 - 2018-07-06 06:01 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll
2018-07-10 20:20 - 2018-07-06 02:31 - 000035232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2018-07-10 20:20 - 2018-07-06 02:29 - 000272296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave.dll
2018-07-10 20:20 - 2018-07-06 02:29 - 000269224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2018-07-10 20:20 - 2018-07-06 02:27 - 001063320 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2018-07-10 20:20 - 2018-07-06 02:27 - 001012632 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2018-07-10 20:20 - 2018-07-06 02:27 - 000709824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2018-07-10 20:20 - 2018-07-06 02:27 - 000567176 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2018-07-10 20:20 - 2018-07-06 02:27 - 000134552 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2018-07-10 20:20 - 2018-07-06 02:27 - 000057440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.ShellCommon.Broker.dll
2018-07-10 20:20 - 2018-07-06 02:26 - 000766608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2018-07-10 20:20 - 2018-07-06 02:26 - 000170912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2018-07-10 20:20 - 2018-07-06 02:25 - 001026464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2018-07-10 20:20 - 2018-07-06 02:25 - 000885856 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2018-07-10 20:20 - 2018-07-06 02:25 - 000335776 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2018-07-10 20:20 - 2018-07-06 02:25 - 000267680 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2018-07-10 20:20 - 2018-07-06 02:25 - 000139672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
2018-07-10 20:20 - 2018-07-06 02:16 - 000567144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2018-07-10 20:20 - 2018-07-06 02:14 - 000573904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2018-07-10 20:20 - 2018-07-06 02:01 - 000104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2018-07-10 20:20 - 2018-07-06 02:01 - 000014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll
2018-07-10 20:20 - 2018-07-06 02:00 - 000151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2018-07-10 20:20 - 2018-07-06 02:00 - 000094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2018-07-10 20:20 - 2018-07-06 02:00 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
2018-07-10 20:20 - 2018-07-06 02:00 - 000053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll
2018-07-10 20:20 - 2018-07-06 02:00 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsTelemetry.dll
2018-07-10 20:20 - 2018-07-06 02:00 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll
2018-07-10 20:20 - 2018-07-06 01:59 - 000453632 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2018-07-10 20:20 - 2018-07-06 01:59 - 000334336 _____ (Microsoft Corporation) C:\WINDOWS\system32\NmaDirect.dll
2018-07-10 20:20 - 2018-07-06 01:59 - 000200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Geolocation.dll
2018-07-10 20:20 - 2018-07-06 01:59 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2018-07-10 20:20 - 2018-07-06 01:59 - 000048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\tokenbinding.dll
2018-07-10 20:20 - 2018-07-06 01:59 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2018-07-10 20:20 - 2018-07-06 01:58 - 001307648 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2018-07-10 20:20 - 2018-07-06 01:58 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2018-07-10 20:20 - 2018-07-06 01:58 - 000236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Core.dll
2018-07-10 20:20 - 2018-07-06 01:58 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Cortana.dll
2018-07-10 20:20 - 2018-07-06 01:58 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2018-07-10 20:20 - 2018-07-06 01:58 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProv2faHelper.dll
2018-07-10 20:20 - 2018-07-06 01:58 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2018-07-10 20:20 - 2018-07-06 01:58 - 000075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mpsdrv.sys
2018-07-10 20:20 - 2018-07-06 01:58 - 000035840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tokenbinding.dll
2018-07-10 20:20 - 2018-07-06 01:57 - 000839680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2018-07-10 20:20 - 2018-07-06 01:57 - 000676864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Devices.dll
2018-07-10 20:20 - 2018-07-06 01:57 - 000614912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2018-07-10 20:20 - 2018-07-06 01:57 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2018-07-10 20:20 - 2018-07-06 01:57 - 000262656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NmaDirect.dll
2018-07-10 20:20 - 2018-07-06 01:56 - 001708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSPhotography.dll
2018-07-10 20:20 - 2018-07-06 01:56 - 001535488 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-07-10 20:20 - 2018-07-06 01:56 - 000814592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2018-07-10 20:20 - 2018-07-06 01:56 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2018-07-10 20:20 - 2018-07-06 01:56 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuietHours.dll
2018-07-10 20:20 - 2018-07-06 01:56 - 000508416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2018-07-10 20:20 - 2018-07-06 01:56 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2018-07-10 20:20 - 2018-07-06 01:56 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2018-07-10 20:20 - 2018-07-06 01:56 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2018-07-10 20:20 - 2018-07-06 01:56 - 000181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Core.dll
2018-07-10 20:20 - 2018-07-06 01:56 - 000115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2018-07-10 20:20 - 2018-07-06 01:56 - 000081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProv2faHelper.dll
2018-07-10 20:20 - 2018-07-06 01:55 - 001361408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSPhotography.dll
2018-07-10 20:20 - 2018-07-06 01:55 - 000619520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2018-07-10 20:20 - 2018-07-06 01:55 - 000415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2018-07-10 20:20 - 2018-07-06 01:55 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2018-07-10 20:20 - 2018-07-06 01:54 - 000978944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2018-07-10 20:20 - 2018-07-06 01:54 - 000899072 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2018-07-10 20:20 - 2018-07-06 01:54 - 000275968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2018-07-10 20:20 - 2018-07-06 01:54 - 000254464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BioCredProv.dll
2018-07-10 20:20 - 2018-07-06 01:53 - 000778240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2018-07-10 20:20 - 2018-07-06 01:53 - 000729088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2018-07-10 20:20 - 2018-07-06 01:53 - 000705024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2018-07-10 20:20 - 2018-07-06 00:41 - 000001310 _____ C:\WINDOWS\system32\tcbres.wim
2018-07-10 20:20 - 2018-06-28 23:16 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll
2018-07-10 20:20 - 2018-06-15 12:55 - 000542888 _____ C:\WINDOWS\system32\FaceProcessorCore.dll
2018-07-10 20:20 - 2018-06-15 12:53 - 000348256 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2018-07-10 20:20 - 2018-06-15 12:53 - 000094104 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2018-07-10 20:20 - 2018-06-15 12:35 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2018-07-10 20:20 - 2018-06-15 12:34 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\DsmUserTask.exe
2018-07-10 20:20 - 2018-06-15 12:34 - 000025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfnet.dll
2018-07-10 20:20 - 2018-06-15 12:33 - 000182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpdr.sys
2018-07-10 20:20 - 2018-06-15 12:33 - 000156160 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupManagerAPI.dll
2018-07-10 20:20 - 2018-06-15 12:33 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2018-07-10 20:20 - 2018-06-15 12:32 - 000301568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcLayers.dll
2018-07-10 20:20 - 2018-06-15 12:32 - 000145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2018-07-10 20:20 - 2018-06-15 12:31 - 001605632 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2018-07-10 20:20 - 2018-06-15 12:31 - 000907776 _____ (Microsoft Corporation) C:\WINDOWS\system32\autofmt.exe
2018-07-10 20:20 - 2018-06-15 12:31 - 000220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2018-07-10 20:20 - 2018-06-15 12:30 - 001054720 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2018-07-10 20:20 - 2018-06-15 12:29 - 002084352 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2018-07-10 20:20 - 2018-06-15 12:29 - 000932352 _____ (Microsoft Corporation) C:\WINDOWS\system32\autoconv.exe
2018-07-10 20:20 - 2018-06-15 12:29 - 000757248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2018-07-10 20:20 - 2018-06-15 12:29 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\shdocvw.dll
2018-07-10 20:20 - 2018-06-15 12:29 - 000103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSoftwareInstallationClient.dll
2018-07-10 20:20 - 2018-06-15 12:28 - 000223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpd_ci.dll
2018-07-10 20:20 - 2018-06-15 12:28 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll
2018-07-10 20:20 - 2018-06-15 10:06 - 000022016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfnet.dll
2018-07-10 20:20 - 2018-06-15 10:04 - 000851968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autoconv.exe
2018-07-10 20:20 - 2018-06-15 10:04 - 000373248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcLayers.dll
2018-07-10 20:20 - 2018-06-15 10:03 - 000831488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autofmt.exe
2018-07-10 20:20 - 2018-06-15 10:03 - 000667648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2018-07-10 20:20 - 2018-06-15 10:01 - 002015744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2018-07-10 20:20 - 2018-06-15 10:01 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shdocvw.dll
2018-07-10 20:20 - 2018-06-15 02:11 - 000611232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2018-07-10 20:20 - 2018-06-15 02:10 - 000048544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storufs.sys
2018-07-10 20:20 - 2018-06-15 02:03 - 000083360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
2018-07-10 20:20 - 2018-06-15 00:19 - 000116632 _____ (Microsoft Corporation) C:\WINDOWS\system32\DTUHandler.exe
2018-07-10 20:20 - 2018-06-15 00:19 - 000093600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2018-07-10 20:20 - 2018-06-15 00:18 - 000228768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll
2018-07-10 20:20 - 2018-06-15 00:16 - 000562080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2018-07-10 20:20 - 2018-06-15 00:16 - 000433560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2018-07-10 20:20 - 2018-06-15 00:13 - 000324000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2018-07-10 20:20 - 2018-06-15 00:12 - 000661152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2018-07-10 20:20 - 2018-06-15 00:12 - 000260896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2018-07-10 20:20 - 2018-06-15 00:12 - 000118872 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll
2018-07-10 20:20 - 2018-06-15 00:10 - 000326024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExecModelClient.dll
2018-07-10 20:20 - 2018-06-15 00:09 - 000247984 _____ (Microsoft Corporation) C:\WINDOWS\system32\RESAMPLEDMO.DLL
2018-07-10 20:20 - 2018-06-15 00:08 - 001921944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys
2018-07-10 20:20 - 2018-06-15 00:08 - 001150408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVP9DEC.dll
2018-07-10 20:20 - 2018-06-15 00:08 - 000983008 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-07-10 20:20 - 2018-06-15 00:08 - 000945568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refsv1.sys
2018-07-10 20:20 - 2018-06-15 00:08 - 000642088 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp_win.dll
2018-07-10 20:20 - 2018-06-15 00:08 - 000604576 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2018-07-10 20:20 - 2018-06-15 00:08 - 000500552 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2018-07-10 20:20 - 2018-06-15 00:08 - 000413816 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2018-07-10 20:20 - 2018-06-15 00:08 - 000072768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WindowsTrustedRT.sys
2018-07-10 20:20 - 2018-06-15 00:05 - 000444240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2018-07-10 20:20 - 2018-06-15 00:04 - 001397192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVP9DEC.dll
2018-07-10 20:20 - 2018-06-15 00:04 - 000281080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExecModelClient.dll
2018-07-10 20:20 - 2018-06-15 00:04 - 000105376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll
2018-07-10 20:20 - 2018-06-15 00:03 - 001129640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2018-07-10 20:20 - 2018-06-15 00:03 - 000472136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2018-07-10 20:20 - 2018-06-15 00:03 - 000356960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2018-07-10 20:20 - 2018-06-15 00:03 - 000232488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RESAMPLEDMO.DLL
2018-07-10 20:20 - 2018-06-15 00:03 - 000129192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2018-07-10 20:20 - 2018-06-14 23:48 - 000311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Diagnostics.dll
2018-07-10 20:20 - 2018-06-14 23:47 - 000622080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsreg.dll
2018-07-10 20:20 - 2018-06-14 23:47 - 000515072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\untfs.dll
2018-07-10 20:20 - 2018-06-14 23:47 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2018-07-10 20:20 - 2018-06-14 23:46 - 000593408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2018-07-10 20:20 - 2018-06-14 23:46 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Input.dll
2018-07-10 20:20 - 2018-06-14 23:46 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
2018-07-10 20:20 - 2018-06-14 23:45 - 000992768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Vpn.dll
2018-07-10 20:20 - 2018-06-14 23:45 - 000871424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autochk.exe
2018-07-10 20:20 - 2018-06-14 23:45 - 000740352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2018-07-10 20:20 - 2018-06-14 23:45 - 000380416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2018-07-10 20:20 - 2018-06-14 23:45 - 000193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll
2018-07-10 20:20 - 2018-06-14 23:45 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\system32\DTUHandlerPS.dll
2018-07-10 20:20 - 2018-06-14 23:44 - 000873472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2018-07-10 20:20 - 2018-06-14 23:44 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
2018-07-10 20:20 - 2018-06-14 23:44 - 000185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2018-07-10 20:20 - 2018-06-14 23:44 - 000135680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smartscreenps.dll
2018-07-10 20:20 - 2018-06-14 23:44 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatecsp.dll
2018-07-10 20:20 - 2018-06-14 23:44 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcimage.dll
2018-07-10 20:20 - 2018-06-14 23:44 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\cellulardatacapabilityhandler.dll
2018-07-10 20:20 - 2018-06-14 23:43 - 001114112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.PointOfService.dll
2018-07-10 20:20 - 2018-06-14 23:43 - 000675840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2018-07-10 20:20 - 2018-06-14 23:43 - 000426496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2018-07-10 20:20 - 2018-06-14 23:43 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\RdpRelayTransport.dll
2018-07-10 20:20 - 2018-06-14 23:43 - 000209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2018-07-10 20:20 - 2018-06-14 23:43 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2018-07-10 20:20 - 2018-06-14 23:43 - 000191488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VideoHandlers.dll
2018-07-10 20:20 - 2018-06-14 23:43 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2018-07-10 20:20 - 2018-06-14 23:43 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2018-07-10 20:20 - 2018-06-14 23:42 - 000978432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2018-07-10 20:20 - 2018-06-14 23:42 - 000558592 _____ (Microsoft Corporation) C:\WINDOWS\system32\untfs.dll
2018-07-10 20:20 - 2018-06-14 23:42 - 000431104 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2018-07-10 20:20 - 2018-06-14 23:42 - 000386048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Diagnostics.dll
2018-07-10 20:20 - 2018-06-14 23:42 - 000319488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2018-07-10 20:20 - 2018-06-14 23:42 - 000273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2018-07-10 20:20 - 2018-06-14 23:42 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2018-07-10 20:20 - 2018-06-14 23:42 - 000216064 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2018-07-10 20:20 - 2018-06-14 23:42 - 000141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2018-07-10 20:20 - 2018-06-14 23:41 - 000953856 _____ (Microsoft Corporation) C:\WINDOWS\system32\autochk.exe
2018-07-10 20:20 - 2018-06-14 23:41 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2018-07-10 20:20 - 2018-06-14 23:41 - 000811520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Input.dll
2018-07-10 20:20 - 2018-06-14 23:41 - 000270336 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2018-07-10 20:20 - 2018-06-14 23:41 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManager.dll
2018-07-10 20:20 - 2018-06-14 23:41 - 000265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2018-07-10 20:20 - 2018-06-14 23:41 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupManager.dll
2018-07-10 20:20 - 2018-06-14 23:40 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
2018-07-10 20:20 - 2018-06-14 23:40 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreenps.dll
2018-07-10 20:20 - 2018-06-14 23:37 - 001069056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2018-07-10 20:20 - 2018-06-14 23:37 - 000883712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2018-07-10 20:20 - 2018-06-14 23:36 - 000159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cdrom.sys
2018-07-10 20:20 - 2018-06-01 00:18 - 000058524 _____ C:\WINDOWS\system32\srms.dat
2018-07-10 20:20 - 2018-05-20 06:53 - 000792984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2018-07-10 20:20 - 2018-05-20 06:52 - 000413080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2018-07-10 16:42 - 2018-07-10 16:42 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsigne9fca32f1ca75c38
2018-07-10 16:05 - 2018-07-10 16:05 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignf36a9148db4e1642
2018-07-09 19:26 - 2018-07-09 19:26 - 000001300 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2018-07-09 19:26 - 2018-07-09 19:26 - 000001288 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2018-07-09 15:45 - 2018-07-09 15:45 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsigne55609b247f1bc81
2018-07-09 15:44 - 2018-07-09 15:44 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignccb41b1ad08e129d
2018-07-09 15:38 - 2018-07-09 15:38 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign2ac9436c4901f6aa
2018-07-09 15:30 - 2018-07-09 15:30 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign9bbc425a737afc75
2018-07-09 15:30 - 2018-07-09 15:30 - 000000000 ____D C:\Users\xian\AppData\Local\NVIDIA
2018-06-29 22:42 - 2018-07-11 09:09 - 000000000 ____D C:\Windows.old
2018-06-29 22:39 - 2018-06-29 22:42 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2018-06-29 22:38 - 2018-06-29 22:39 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2018-06-29 22:38 - 2018-06-29 22:38 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2018-06-29 22:37 - 2018-06-29 22:37 - 016592384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 013873152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 013570560 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 012500992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 008188928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 007900984 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 006661120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 006032384 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 005951488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 005821544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 005307392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 004970360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 004929024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 004527680 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 004469832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 004392448 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 004070400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 003999232 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 003733320 _____ C:\WINDOWS\system32\Windows.Mirage.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 003640832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 003492864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 003444224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 003392512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 003348992 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 003296896 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 003293696 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 003283408 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 003180176 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 003086336 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002922496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002841312 _____ C:\WINDOWS\SysWOW64\Windows.Mirage.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002789376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002699776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002590400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVDECOD.DLL
2018-06-29 22:37 - 2018-06-29 22:37 - 002486992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002479272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002462272 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002417840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002364928 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002307336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVDECOD.DLL
2018-06-29 22:37 - 2018-06-29 22:37 - 002248192 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002178136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002061824 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 002019840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001988072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001953280 _____ C:\WINDOWS\system32\rdpnano.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001855488 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001825792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001792808 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001719808 _____ (Microsoft Corporation) C:\WINDOWS\system32\dui70.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001676800 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShell.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001675264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001665920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001665024 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001659904 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001649760 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001634808 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001613200 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001586176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001585664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001584128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001565592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001560576 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdt.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 001543680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001508352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdt.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 001490144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001466368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001462784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dui70.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001456640 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001454024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001426328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001421312 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpbase.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001371136 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001364184 _____ (Microsoft Corporation) C:\WINDOWS\system32\webservices.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001363632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001348096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpcServices.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001318400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001299056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001295360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001292288 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 001285120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001271296 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloSI.PCShell.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001242112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001235968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpbase.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001210880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001192448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Maps.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001190152 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001180672 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001171968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001160192 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001128448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001121792 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001077504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webservices.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001046944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001034096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001032704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001017088 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001017080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2adec.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001012408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 001005568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000983040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000976384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000960512 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000950272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmsys.cpl
2018-06-29 22:37 - 2018-06-29 22:37 - 000944640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000941056 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdlg.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000933376 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000932352 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000917408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000916480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000908800 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSMPEG2ENC.DLL
2018-06-29 22:37 - 2018-06-29 22:37 - 000908288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000906752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.PhoneNumberFormatting.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000899072 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000880152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000871424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000864768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmsys.cpl
2018-06-29 22:37 - 2018-06-29 22:37 - 000863232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000861616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2adec.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000861096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000860160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000858112 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000857088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSMPEG2ENC.DLL
2018-06-29 22:37 - 2018-06-29 22:37 - 000849408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000842240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000808960 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2018-06-29 22:37 - 2018-06-29 22:37 - 000804352 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVolSSO.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000788216 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000786176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000783360 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyHrtfEnc.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000781824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000778752 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2018-06-29 22:37 - 2018-06-29 22:37 - 000776880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000776192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000759192 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingWinRT.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000748512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SndVolSSO.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000735560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000729088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FlightSettings.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000723360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000722808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000713376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000705440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000695296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hhctrl.ocx
2018-06-29 22:37 - 2018-06-29 22:37 - 000678840 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000677888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\HeadTrackerStorage.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000669696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000667648 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000665320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000661160 _____ (Microsoft Corporation) C:\WINDOWS\system32\GenValObj.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000659096 _____ (Microsoft Corporation) C:\WINDOWS\system32\StateRepository.Core.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000658432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000653208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicensingWinRT.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000652800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000648192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000630784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.MediaPlayer.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000625152 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.rs4.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000613144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000607648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000606448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000593408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000585728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.rs3.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000581120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hhctrl.ocx
2018-06-29 22:37 - 2018-06-29 22:37 - 000577024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000568720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryPS.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000565152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2018-06-29 22:37 - 2018-06-29 22:37 - 000564736 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000561664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000560488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000553984 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationExtensions.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000553248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000528384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000527264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000506184 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000503296 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000494488 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000486912 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasplap.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTMediaFrame.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000474624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.rs2.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000466432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXP.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000461312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasplap.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000457152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAudDecMFT.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000444416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.rs1.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000434584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000416144 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000389632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000384000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Phoneutil.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000382872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000375808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTMediaFrame.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000375712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msrpc.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000356352 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWfdProvider.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000347704 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\system32\RasMediaManager.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserexport.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000329216 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000317440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Phoneutil.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000313592 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.th.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000286200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcredprov.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000264704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovs.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MixedReality.Broker.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000241664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.win81.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FSClient.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloShellRuntime.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtutil.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyMATEnc.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcredprov.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000226720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Ucx01000.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAC3ENC.DLL
2018-06-29 22:37 - 2018-06-29 22:37 - 000194456 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000184320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\HoloShellRuntime.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000182272 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000182272 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerCsp.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000177152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\itss.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000167936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtutil.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000164768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Analog.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\vertdll.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedPCCSP.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000150016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000150016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\itss.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSpkg.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000142848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000142336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.win8rtm.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000137568 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000131232 _____ (Microsoft Corporation) C:\WINDOWS\system32\rmclient.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000130456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvsocket.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000117760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSpkg.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppHostRegistrationVerifier.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApiSetHost.AppExecutionAlias.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000105368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000101288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rmclient.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManagerClient.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000098816 _____ (Microsoft Corporation) C:\WINDOWS\system32\TelephonyInteractiveUser.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000097176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000089984 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompPkgSup.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000088472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\crashdmp.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000084288 _____ (Microsoft Corporation) C:\WINDOWS\system32\LanguageOverlayUtil.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ApiSetHost.AppExecutionAlias.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000077040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CompPkgSup.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000064648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LanguageOverlayUtil.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\edpnotify.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000057960 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel.appcore.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000050208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel.appcore.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryCore.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSHEIF.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mskssrv.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000029600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\uefi.sys
2018-06-29 22:37 - 2018-06-29 22:37 - 000029184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
2018-06-29 22:37 - 2018-06-29 22:37 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSHEIF.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\credssp.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credssp.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000018716 _____ C:\WINDOWS\SysWOW64\srms-apr.dat
2018-06-29 22:37 - 2018-06-29 22:37 - 000018716 _____ C:\WINDOWS\system32\srms-apr.dat
2018-06-29 22:37 - 2018-06-29 22:37 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2018-06-29 22:37 - 2018-06-29 22:37 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2018-06-29 22:35 - 2018-06-29 22:35 - 001166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2018-06-29 22:35 - 2018-06-29 22:35 - 000778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2018-06-29 22:35 - 2018-06-29 22:35 - 000124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2018-06-29 22:35 - 2018-06-29 22:35 - 000103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2018-06-29 22:35 - 2018-06-29 22:35 - 000035456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2018-06-29 22:35 - 2018-06-29 22:35 - 000035456 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2018-06-29 22:35 - 2018-06-29 22:35 - 000000000 ____D C:\Program Files\Reference Assemblies
2018-06-29 22:35 - 2018-06-29 22:35 - 000000000 ____D C:\Program Files\MSBuild
2018-06-29 22:35 - 2018-06-29 22:35 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2018-06-29 22:35 - 2018-06-29 22:35 - 000000000 ____D C:\Program Files (x86)\MSBuild
2018-06-29 22:34 - 2018-06-29 22:34 - 004492288 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2018-06-29 22:34 - 2018-06-29 22:34 - 003398144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2018-06-29 22:34 - 2018-06-29 22:34 - 000925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsFilt.dll
2018-06-29 22:34 - 2018-06-29 22:34 - 000575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsFilt.dll
2018-06-29 22:34 - 2018-06-29 22:34 - 000100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\XPSSHHDR.dll
2018-06-29 22:34 - 2018-06-29 22:34 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XPSSHHDR.dll
2018-06-29 22:34 - 2018-06-29 22:34 - 000076060 _____ C:\WINDOWS\SysWOW64\xpsrchvw.xml
2018-06-29 22:34 - 2018-06-29 22:34 - 000076060 _____ C:\WINDOWS\system32\xpsrchvw.xml
2018-06-29 21:12 - 2018-06-29 21:13 - 000000000 ___HD C:\ProgramData\CanonIJScan
2018-06-29 20:06 - 2018-07-14 16:09 - 000000000 ____D C:\ProgramData\Packages
2018-06-29 19:51 - 2018-07-22 22:38 - 000000000 ____D C:\Users\xian\AppData\Local\D3DSCache
2018-06-29 19:51 - 2018-06-29 19:51 - 000001417 _____ C:\Users\xian\Desktop\Microsoft Edge.lnk
2018-06-29 19:51 - 2018-06-29 19:51 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2018-06-29 19:50 - 2018-07-25 17:55 - 000004212 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2018-06-29 19:50 - 2018-07-25 17:50 - 000840376 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-06-29 19:50 - 2018-07-25 17:46 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-06-29 19:50 - 2018-07-20 09:35 - 000003350 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-813518053-636032705-5302477-1001
2018-06-29 19:50 - 2018-07-12 04:52 - 000004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2018-06-29 19:50 - 2018-06-29 19:50 - 000003434 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineUA
2018-06-29 19:50 - 2018-06-29 19:50 - 000003346 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2018-06-29 19:50 - 2018-06-29 19:50 - 000003210 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineCore
2018-06-29 19:50 - 2018-06-29 19:50 - 000003122 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2018-06-29 19:50 - 2018-06-29 19:50 - 000002762 _____ C:\WINDOWS\System32\Tasks\AdobeAAMUpdater-1.0-DESKTOP-08QK23U-xian
2018-06-29 19:50 - 2018-06-29 19:50 - 000002746 _____ C:\WINDOWS\System32\Tasks\AdobeAAMUpdater-1.0-XILENCE-xian
2018-06-29 19:50 - 2018-06-29 19:50 - 000002700 _____ C:\WINDOWS\System32\Tasks\AdobeGCInvoker-1.0-XILENCE-xian
2018-06-29 19:50 - 2018-06-29 19:50 - 000002580 _____ C:\WINDOWS\System32\Tasks\CreateExplorerShellUnelevatedTask
2018-06-29 19:50 - 2018-06-29 19:50 - 000002210 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2018-06-29 19:50 - 2018-06-29 19:50 - 000002172 _____ C:\WINDOWS\System32\Tasks\LaunchChromeTask111
2018-06-29 19:50 - 2018-06-29 19:50 - 000000020 ___SH C:\Users\xian\ntuser.ini
2018-06-29 19:50 - 2018-06-29 19:50 - 000000000 ____D C:\WINDOWS\System32\Tasks\Apple
2018-06-29 19:49 - 2018-06-29 19:50 - 000007623 _____ C:\WINDOWS\diagwrn.xml
2018-06-29 19:49 - 2018-06-29 19:50 - 000007623 _____ C:\WINDOWS\diagerr.xml
2018-06-29 19:46 - 2018-06-29 19:46 - 000001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2018-06-29 19:45 - 2018-06-29 19:45 - 000000000 ____D C:\ProgramData\USOShared
2018-06-29 19:45 - 2018-04-11 18:33 - 002752000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2018-06-29 19:44 - 2018-07-20 09:35 - 000002362 _____ C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-06-29 19:44 - 2018-06-29 19:50 - 000000000 ____D C:\Users\xian
2018-06-29 19:44 - 2018-06-29 19:44 - 000000000 ____D C:\Users\xian\AppData\Local\Google
2018-06-29 19:42 - 2018-07-25 19:35 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-06-29 19:42 - 2018-07-10 21:07 - 000550184 _____ C:\WINDOWS\system32\FNTCACHE.DAT
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-07-25 19:41 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\NDF
2018-07-25 19:35 - 2016-09-29 06:52 - 000000000 ____D C:\Users\xian\AppData\Local\ConnectedDevicesPlatform
2018-07-25 18:51 - 2018-04-11 16:04 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2018-07-25 18:18 - 2018-04-11 18:38 - 000000000 ___HD C:\Program Files\WindowsApps
2018-07-25 18:18 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-07-25 18:18 - 2018-04-11 18:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-07-25 18:09 - 2017-03-04 17:08 - 000000000 ____D C:\Users\xian\AppData\Local\ElevatedDiagnostics
2018-07-25 17:50 - 2018-04-11 18:36 - 000000000 ____D C:\WINDOWS\INF
2018-07-25 17:46 - 2017-11-03 11:31 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2018-07-25 17:46 - 2017-05-18 11:29 - 000000000 ____D C:\ProgramData\NVIDIA
2018-07-25 17:45 - 2018-04-11 16:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-07-25 17:45 - 2016-09-19 21:51 - 000000000 ____D C:\ProgramData\Package Cache
2018-07-25 17:44 - 2016-09-19 21:55 - 000000000 ____D C:\ProgramData\Intel
2018-07-25 17:44 - 2016-09-19 21:55 - 000000000 ____D C:\Program Files (x86)\Intel
2018-07-25 17:43 - 2016-09-19 21:52 - 000000000 ____D C:\Program Files\Intel
2018-07-25 16:52 - 2017-04-10 23:31 - 000000000 ____D C:\Program Files (x86)\M4VGear
2018-07-25 16:51 - 2017-04-10 18:15 - 000000000 ____D C:\Users\xian\AppData\Roaming\iMobie
2018-07-25 16:43 - 2016-11-18 22:54 - 000000000 ____D C:\Webgility
2018-07-25 16:40 - 2018-06-07 14:16 - 000000000 ____D C:\Users\xian\AppData\Roaming\Canon
2018-07-25 16:40 - 2018-06-07 14:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2018-07-25 16:40 - 2018-06-07 14:10 - 000000000 ____D C:\Program Files (x86)\Canon
2018-07-25 13:46 - 2017-09-22 16:23 - 000000000 ____D C:\AdwCleaner
2018-07-25 13:39 - 2017-09-22 16:27 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-07-23 19:27 - 2017-12-09 13:08 - 000000000 ____D C:\Users\xian\AppData\Roaming\WD Discovery
2018-07-22 23:15 - 2016-09-20 15:54 - 000000000 ___RD C:\Users\xian\Creative Cloud Files
2018-07-22 23:15 - 2016-09-20 15:48 - 000000000 ____D C:\Users\xian\AppData\Local\Adobe
2018-07-22 22:54 - 2016-09-24 14:36 - 000007610 _____ C:\Users\xian\AppData\Local\resmon.resmoncfg
2018-07-22 22:37 - 2016-09-21 14:23 - 000000000 ____D C:\Users\xian\AppData\Roaming\WhatsApp
2018-07-21 15:55 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2018-07-21 14:50 - 2016-09-19 23:03 - 000002495 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visio.lnk
2018-07-21 14:50 - 2016-09-19 22:53 - 000002513 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project.lnk
2018-07-21 14:50 - 2016-09-19 22:35 - 000002508 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business.lnk
2018-07-21 14:50 - 2016-09-19 22:35 - 000002503 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2018-07-21 14:50 - 2016-09-19 22:35 - 000002502 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2018-07-21 14:50 - 2016-09-19 22:35 - 000002466 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2018-07-21 14:50 - 2016-09-19 22:35 - 000002465 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2018-07-21 14:50 - 2016-09-19 22:35 - 000002459 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2018-07-21 14:50 - 2016-09-19 22:35 - 000002453 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2018-07-21 14:50 - 2016-09-19 22:35 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2018-07-21 14:50 - 2016-09-19 22:34 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-07-21 14:14 - 2016-09-20 16:03 - 000000033 _____ C:\Users\xian\AppData\Roaming\AdobeWLCMCache.dat
2018-07-20 09:35 - 2016-09-19 21:21 - 000000000 ___RD C:\Users\xian\OneDrive
2018-07-17 12:58 - 2016-09-21 14:23 - 000000000 ____D C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WhatsApp
2018-07-17 12:58 - 2016-09-21 14:23 - 000000000 ____D C:\Users\xian\AppData\Local\WhatsApp
2018-07-17 12:57 - 2016-09-21 14:23 - 000000000 ____D C:\Users\xian\AppData\Local\SquirrelTemp
2018-07-16 19:02 - 2016-09-20 15:41 - 000563832 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2018-07-15 13:06 - 2016-09-23 08:25 - 000000000 ____D C:\Users\xian\AppData\Roaming\vlc
2018-07-13 16:26 - 2016-09-27 15:53 - 000000000 ____D C:\Program Files (x86)\Dropbox
2018-07-12 04:52 - 2016-09-20 16:13 - 000002469 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk
2018-07-12 04:52 - 2016-09-20 16:13 - 000002124 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk
2018-07-10 21:07 - 2017-11-23 10:14 - 000000000 ___RD C:\Users\xian\3D Objects
2018-07-10 21:07 - 2016-09-19 21:19 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-07-10 21:06 - 2018-06-07 14:10 - 000000000 ____D C:\ProgramData\CanonIJPLM
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\zu-ZA
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\yo-NG
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\xh-ZA
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\wo-SN
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\uz-Latn-UZ
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tn-ZA
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ti-ET
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tg-Cyrl-TJ
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-RS
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-BA
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sd-Arab-PK
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\rw-RW
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\quc-Latn-GT
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-Arab-PK
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\nso-ZA
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ku-Arab-IQ
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ig-NG
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ha-Latn-NG
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\chr-CHER-US
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES-valencia
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\bs-Latn-BA
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\az-Latn-AZ
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\zu-ZA
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\yo-NG
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\xh-ZA
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\wo-SN
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\uz-Latn-UZ
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\tn-ZA
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ti-ET
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\tg-Cyrl-TJ
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-RS
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-BA
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\sd-Arab-PK
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\rw-RW
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\quc-Latn-GT
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\pa-Arab-PK
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\nso-ZA
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ku-Arab-IQ
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ig-NG
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ha-Latn-NG
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\chr-CHER-US
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ca-ES-valencia
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\bs-Latn-BA
2018-07-10 21:06 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\az-Latn-AZ
2018-07-10 21:06 - 2018-04-11 18:38 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2018-07-10 21:06 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2018-07-10 21:06 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-07-10 21:06 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\ShellExperiences
2018-07-10 21:06 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\bcastdvr
2018-07-10 20:25 - 2018-04-11 18:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-07-10 20:25 - 2016-09-20 19:39 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-07-10 20:23 - 2016-09-20 19:38 - 134675576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-07-09 19:26 - 2016-09-20 15:50 - 000000000 ____D C:\Program Files (x86)\Adobe
2018-07-09 17:12 - 2016-10-03 13:55 - 000000000 ____D C:\Users\xian\AppData\Roaming\Youtube Downloader HD
2018-07-07 19:51 - 2016-09-22 17:37 - 000000000 ____D C:\Users\xian\AppData\Roaming\Apple Computer
2018-06-30 03:10 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\appcompat
2018-06-29 22:42 - 2018-06-07 14:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon TS9100 series On-screen Manual
2018-06-29 22:42 - 2018-04-11 18:41 - 000000000 ____D C:\WINDOWS\Setup
2018-06-29 22:42 - 2018-04-11 18:38 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2018-06-29 22:42 - 2018-04-11 18:38 - 000000000 __RHD C:\Users\Public\Libraries
2018-06-29 22:42 - 2018-04-11 18:38 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2018-06-29 22:42 - 2018-04-11 18:38 - 000000000 ___SD C:\WINDOWS\system32\F12
2018-06-29 22:42 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2018-06-29 22:42 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\spool
2018-06-29 22:42 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\oobe
2018-06-29 22:42 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\Help
2018-06-29 22:42 - 2018-04-11 18:38 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2018-06-29 22:42 - 2017-12-09 13:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WD Discovery
2018-06-29 22:42 - 2017-11-20 13:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva
2018-06-29 22:42 - 2017-11-20 13:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2018-06-29 22:42 - 2017-11-13 10:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FontForge
2018-06-29 22:42 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2018-06-29 22:42 - 2017-09-19 11:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2018-06-29 22:42 - 2017-08-31 17:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remote Camera Control
2018-06-29 22:42 - 2017-08-07 12:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PlayMemories Home
2018-06-29 22:42 - 2017-07-06 17:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2018-06-29 22:42 - 2017-06-15 18:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2018-06-29 22:42 - 2017-05-16 14:09 - 000000000 ____D C:\Program Files\UNP
2018-06-29 22:42 - 2017-05-15 17:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2018-06-29 22:42 - 2017-05-12 14:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2018-06-29 22:42 - 2017-04-12 20:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MicroDicom
2018-06-29 22:42 - 2016-12-12 01:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Screencast-O-Matic v2.0
2018-06-29 22:42 - 2016-12-12 01:05 - 000000000 ____D C:\WINDOWS\SysWOW64\MTSLog
2018-06-29 22:42 - 2016-12-09 14:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraEdit
2018-06-29 22:42 - 2016-12-09 14:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
2018-06-29 22:42 - 2016-10-03 13:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Youtube Downloader HD
2018-06-29 22:42 - 2016-09-24 14:36 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2018-06-29 22:42 - 2016-09-24 13:41 - 000000000 ___HD C:\WINDOWS\system32\WLANProfiles
2018-06-29 22:42 - 2016-09-23 08:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2018-06-29 22:42 - 2016-09-23 08:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2018-06-29 22:42 - 2016-09-22 17:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ReNamer
2018-06-29 22:42 - 2016-09-20 23:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PeaZip
2018-06-29 22:42 - 2016-09-20 16:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
2018-06-29 22:42 - 2016-09-20 15:58 - 000000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2018-06-29 22:42 - 2016-09-19 22:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
2018-06-29 22:42 - 2016-09-19 21:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2018-06-29 22:39 - 2018-04-11 16:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2018-06-29 22:39 - 2017-12-07 19:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seagate
2018-06-29 22:39 - 2017-09-22 17:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tt eSPORTS
2018-06-29 22:39 - 2017-07-14 16:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2018-06-29 22:39 - 2017-05-18 11:29 - 000000000 ____D C:\Program Files\Realtek
2018-06-29 22:39 - 2016-09-24 14:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASRock Utility
2018-06-29 22:39 - 2016-09-24 13:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2018-06-29 22:39 - 2016-09-20 23:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ur-PK
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ug-CN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tt-RU
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tk-TM
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\te-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ta-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sw-KE
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sq-AL
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\si-LK
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\quz-PE
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\prs-AF
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\or-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\nn-NO
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ne-NP
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mt-MT
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mr-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mn-MN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ml-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mk-MK
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mi-NZ
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\lo-LA
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\lb-LU
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ky-KG
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\kok-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\kn-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\km-KH
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\kk-KZ
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ka-GE
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\is-IS
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\hy-AM
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\gu-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\gd-GB
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ga-IE
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\fil-PH
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\fa-IR
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\cy-GB
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-BD
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\be-BY
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\as-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\am-ET
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\SysWOW64\af-ZA
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\vi-VN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ur-PK
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ug-CN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\tt-RU
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\tk-TM
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\te-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\sw-KE
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\sq-AL
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\quz-PE
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\prs-AF
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\pa-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\or-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\nn-NO
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ne-NP
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\mt-MT
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\mr-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\mn-MN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ml-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\mk-MK
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\mi-NZ
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\lo-LA
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\lb-LU
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ky-KG
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\kok-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\kn-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\km-KH
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\kk-KZ
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ka-GE
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\is-IS
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\id-ID
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\hy-AM
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\gu-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\gd-GB
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\ga-IE
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\fil-PH
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\fa-IR
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\cy-GB
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\bn-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\bn-BD
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\be-BY
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\as-IN
2018-06-29 22:37 - 2018-04-12 04:19 - 000000000 ____D C:\WINDOWS\system32\af-ZA
2018-06-29 22:37 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\TextInput
2018-06-29 22:37 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2018-06-29 22:37 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2018-06-29 22:37 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2018-06-29 22:37 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\ta-in
2018-06-29 22:37 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2018-06-29 22:37 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\si-lk
2018-06-29 22:37 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\setup
2018-06-29 22:37 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\am-et
2018-06-29 22:37 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\Provisioning
2018-06-29 22:37 - 2018-04-11 18:38 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2018-06-29 22:37 - 2018-04-11 18:38 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2018-06-29 22:37 - 2018-04-11 16:04 - 000000000 ____D C:\WINDOWS\system32\Dism
2018-06-29 22:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2018-06-29 22:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2018-06-29 22:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2018-06-29 22:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2018-06-29 22:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\SysWOW64\en-GB
2018-06-29 22:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2018-06-29 22:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2018-06-29 22:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\et-EE
2018-06-29 22:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\es-MX
2018-06-29 22:34 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\en-GB
2018-06-29 21:48 - 2017-08-08 00:17 - 000001141 _____ C:\Users\Public\Desktop\VLC media player.lnk
2018-06-29 20:06 - 2017-11-23 10:00 - 000000000 ____D C:\Users\xian\AppData\Local\Packages
2018-06-29 19:50 - 2018-06-23 22:33 - 000000000 ___DC C:\WINDOWS\Panther
2018-06-29 19:50 - 2018-04-11 18:38 - 000000000 ___RD C:\Program Files\Windows Defender
2018-06-29 19:50 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\Registration
2018-06-29 19:49 - 2016-09-24 14:36 - 000838560 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2018-06-29 19:49 - 2016-09-19 21:56 - 000002311 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-06-29 19:48 - 2018-04-11 18:38 - 000000000 __RSD C:\WINDOWS\media
2018-06-29 19:48 - 2016-09-29 03:48 - 000022840 _____ C:\WINDOWS\system32\emptyregdb.dat
2018-06-29 19:46 - 2017-12-13 22:13 - 000000000 ____D C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Duplicate Files Finder
2018-06-29 19:46 - 2017-09-22 08:53 - 000000000 ____D C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\cloudLibrary
2018-06-29 19:46 - 2016-09-19 23:26 - 000000000 ____D C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2018-06-29 19:45 - 2018-04-11 18:38 - 000000000 ____D C:\ProgramData\USOPrivate
2018-06-29 19:45 - 2017-07-20 07:25 - 000000000 ____D C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Syncios
2018-06-29 19:43 - 2017-05-18 11:30 - 000018960 _____ (Logitech, Inc.) C:\WINDOWS\system32\Drivers\LNonPnP.sys
2018-06-29 19:43 - 2017-05-18 11:29 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2018-06-29 19:43 - 2017-05-18 11:29 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2018-06-29 19:43 - 2017-05-18 11:29 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2018-06-29 19:43 - 2017-04-10 23:48 - 000000000 ____D C:\temp
2018-06-28 20:13 - 2018-04-11 18:41 - 000835064 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2018-06-28 20:13 - 2018-04-11 18:41 - 000179704 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2018-06-26 21:16 - 2018-02-07 22:06 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-06-25 17:36 - 2017-03-22 12:15 - 000000000 ____D C:\Users\xian\Documents\Outlook Files
 
==================== Files in the root of some directories =======
 
2017-07-18 21:27 - 2017-07-18 21:27 - 000348680 _____ (Carifred) C:\Program Files\StopResettingMyApps.exe
2016-09-20 16:03 - 2018-07-21 14:14 - 000000033 _____ () C:\Users\xian\AppData\Roaming\AdobeWLCMCache.dat
2017-10-25 11:35 - 2017-10-25 11:35 - 000000028 _____ () C:\Users\xian\AppData\Roaming\kulerdata.json
2017-08-22 14:17 - 2018-01-17 14:13 - 000001456 _____ () C:\Users\xian\AppData\Local\Adobe Save for Web 13.0 Prefs
2016-09-24 14:36 - 2018-07-22 22:54 - 000007610 _____ () C:\Users\xian\AppData\Local\resmon.resmoncfg
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2018-06-29 19:42
 
==================== End of FRST.txt ============================

and the Addition

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21.07.2018
Ran by xian (25-07-2018 19:47:34)
Running from H:\down
Windows 10 Home Version 1803 17134.165 (X64) (2018-06-30 00:50:13)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-813518053-636032705-5302477-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-813518053-636032705-5302477-503 - Limited - Disabled)
Guest (S-1-5-21-813518053-636032705-5302477-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-813518053-636032705-5302477-504 - Limited - Disabled)
xian (S-1-5-21-813518053-636032705-5302477-1001 - Administrator - Enabled) => C:\Users\xian
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Bitdefender Antivirus Free Antimalware (Enabled - Up to date) {EA21BCE8-A461-99C3-3A0D-4C964E75494E}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Bitdefender Antivirus Free Antimalware (Enabled - Up to date) {51405D0C-825B-964D-00BD-77E435F203F3}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 16.04 (x64) (HKLM\...\7-Zip) (Version: 16.04 - Igor Pavlov)
Adobe Acrobat DC (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-0C0F074E4100}) (Version: 18.011.20055 - Adobe Systems Incorporated)
Adobe After Effects CC 2017 (HKLM-x32\...\AEFT_14_2_1) (Version: 14.2.1 - Adobe Systems Incorporated)
Adobe Audition CC 2017 (HKLM-x32\...\AUDT_10_1_1) (Version: 10.1.1 - Adobe Systems Incorporated)
Adobe Bridge CC 2017 (HKLM-x32\...\KBRG_7_0) (Version: 7.0 - Adobe Systems Incorporated)
Adobe Character Animator CC (Beta) (HKLM-x32\...\ANMLBETA_1_0_6) (Version: 1.0.6 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 4.6.0.384 - Adobe Systems Incorporated)
Adobe Dreamweaver CC 2017 (HKLM-x32\...\DRWV_17_5_0) (Version: 17.5.0 - Adobe Systems Incorporated)
Adobe ExtendScript Toolkit CC (HKLM-x32\...\{6297487E-3778-4F72-B458-55690418DB98}) (Version: 4.0.0.0 - Adobe Systems Incorporated)
Adobe Extension Manager CC (HKLM-x32\...\{244FD30F-63F1-49B9-9D98-1150FF4FFCB1}) (Version: 7.3.2 - Adobe Systems Incorporated)
Adobe Illustrator CC 2017 (HKLM-x32\...\ILST_21_1_0) (Version: 21.1.0 - Adobe Systems Incorporated)
Adobe InDesign CC 2017 (HKLM-x32\...\IDSN_12_1_0) (Version: 12.1.0 - Adobe Systems Incorporated)
Adobe Lightroom (HKLM-x32\...\{8048A5DF-8A70-5BE1-954B-E0FDE1BD0D0D}) (Version: 6.12 - Adobe Systems Incorporated)
Adobe Media Encoder CC 2017 (HKLM-x32\...\AME_11_1_2) (Version: 11.1.2 - Adobe Systems Incorporated)
Adobe Muse CC 2017 (HKLM-x32\...\MUSE_2017_1_0) (Version: 2017.1.0.821 - Adobe Systems Incorporated)
Adobe Photoshop CC 2017 (HKLM-x32\...\PHSP_18_1_1) (Version: 18.1.1 - Adobe Systems Incorporated)
Adobe Premiere Pro CC 2017 (HKLM-x32\...\PPRO_11_1_2) (Version: 11.1.2 - Adobe Systems Incorporated)
APP Shop v1.0.24 (HKLM-x32\...\{90242E9B-BC60-46E3-8EE7-8E953F702280}_is1) (Version: 1.0.24 - ASRock Inc.)
Apple Application Support (32-bit) (HKLM-x32\...\{E5347310-C82F-4833-AA36-8D11E5A8A86A}) (Version: 6.6 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{D745E014-74DD-43A3-98DF-E7D38164B681}) (Version: 6.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{C29B636B-9015-4ED1-A12F-6375A337F23B}) (Version: 11.4.1.46 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{A30EA700-5515-48F0-88B0-9E99DC356B88}) (Version: 2.6.0.1 - Apple Inc.)
Asmedia USB Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.16.35.1 - Asmedia Technology)
ASRock App Charger v1.0.6 (HKLM\...\ASRock App Charger_is1) (Version: 1.0.6 - ASRock Inc.)
ASRock RapidSataSwitch v1.0.13 (HKLM\...\ASRock Rapid SATA Switch_is1) (Version:  - ASRock Inc.)
ASRock Restart to UEFI v1.0.5 (HKLM-x32\...\ASRock Restart to UEFI_is1) (Version: 1.0.5 - )
Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 1.0.1 - Bitdefender)
Bitdefender Antivirus Free (HKLM\...\{1FCCF41D-5F00-4FE2-9653-162D0486C8B4}) (Version: 1.0.12.41 - Bitdefender)
BlueStacks App Player (HKLM-x32\...\BlueStacks) (Version: 3.54.65.1755 - BlueStack Systems, Inc.)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.7.0.0 - Canon Inc.)
Canon IJ Network Scanner Selector EX2 (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX2) (Version: 2.0.5.3 - Canon Inc.)
Canon IJ Printer Assistant Tool (HKLM-x32\...\Canon IJ Printer Assistant Tool) (Version: 1.00.2.51 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: 1.4.0.16 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 5.5.0 - Canon Inc.)
Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.8.5 - Canon Inc.)
Canon TS9100 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_TS9100_series) (Version: 1.01 - Canon Inc.)
Canon TS9100 series On-screen Manual (HKLM-x32\...\Canon TS9100 series On-screen Manual) (Version: 1.1.0 - Canon Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.36 - Piriform)
Challenger Prime Gaming Keyboard Driver (HKLM-x32\...\{54C8FBB3-B992-43CB-8F0A-E26228013F88}) (Version: 1.0 - Tt eSPORTS)
cloudLibrary 2.3 (HKLM-x32\...\cloudLibrary) (Version: 2.3 - Bibliotheca)
Disk Health v3.0 (HKLM-x32\...\Disk Health_is1) (Version: 3.0 - ASRock Inc.)
Dropbox (HKLM-x32\...\Dropbox) (Version: 53.4.67 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.75.1 - Dropbox, Inc.) Hidden
Duplicate Files Finder (HKLM-x32\...\Duplicate Files Finder) (Version:  - )
FastBoot v3.0.2 (HKLM-x32\...\FastBoot_is1) (Version: 3.0.2 - ASRock Inc.)
FileZilla Client 3.27.1 (HKLM-x32\...\FileZilla Client) (Version: 3.27.1 - Tim Kosse)
FontForge version 31-07-2017 (HKLM-x32\...\{56748B9C-19AE-4689-B8C5-5A45AE0A993A}_is1) (Version: 31-07-2017 - FontForgeBuilds)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 67.0.3396.99 - Google Inc.)
Google Drive (HKLM-x32\...\{A8DC81F2-D365-4248-892A-FA3B5951F731}) (Version: 2.34.9392.7803 - Google, Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
iCloud (HKLM\...\{82FCC407-A0E5-4B80-9241-5ABA78B61090}) (Version: 7.6.0.15 - Apple Inc.)
Intel® C++ Redistributables on Intel® 64 (HKLM-x32\...\{F70BCE36-25F2-4475-A918-6209B3D85BF3}) (Version: 15.0.179 - Intel Corporation)
Intel® Chipset Device Software (HKLM-x32\...\{f2fa2583-cd6d-4da1-803c-2983cc6f7791}) (Version: 10.1.2.10 - Intel® Corporation) Hidden
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.4.1186 - Intel Corporation)
Intel® Network Connections 20.4.307.0 (HKLM\...\PROSetDX) (Version: 20.4.307.0 - Intel)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.8.0.1042 - Intel Corporation)
Intel® Wireless Bluetooth® (HKLM-x32\...\{5068B0F8-CE24-4B61-9C2F-301B411FFB9C}) (Version: 18.1.1611.3223 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{b67c644b-bbfa-45cf-a1fa-2e1ef2f99be6}) (Version: 20.60.0 - Intel Corporation)
iTunes (HKLM\...\{36F365B3-05C2-455D-9D96-B73829DE046D}) (Version: 12.8.0.150 - Apple Inc.)
Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech)
Macrium Reflect Free Edition (HKLM\...\{1A399324-9784-4384-927F-0FEA922BC516}) (Version: 7.1.3317 - Paramount Software (UK) Ltd.) Hidden
Macrium Reflect Free Edition (HKLM\...\MacriumReflect) (Version: 7.1 - Paramount Software (UK) Ltd.)
Malwarebytes version 3.5.1.2522 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.5.1.2522 - Malwarebytes)
MergeModule_x64 (HKLM\...\{12DCC5A7-0100-4433-B4FF-217A3C5DC83B}) (Version: 9.3.00 - Sony Corporation) Hidden
MergeModule_x86 (HKLM-x32\...\{42251A8D-C4AE-4D3B-8A50-948CB98A0969}) (Version: 10.5.00 - Sony Corporation) Hidden
MicroDicom DICOM viewer 2.0.0 (HKLM-x32\...\MicroDicom) (Version: 2.0.0 - MicroDicom)
Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 16.0.10228.20134 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-813518053-636032705-5302477-1001\...\OneDriveSetup.exe) (Version: 18.111.0603.0006 - Microsoft Corporation)
Microsoft Project Professional 2016 - en-us (HKLM\...\ProjectProRetail - en-us) (Version: 16.0.10228.20134 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft Visio Professional 2016 - en-us (HKLM\...\VisioProRetail - en-us) (Version: 16.0.10228.20134 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810 (HKLM-x32\...\{e2ee15e2-a480-4bc5-bfb7-e9803d1d9823}) (Version: 14.12.25810.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.12.25810 (HKLM-x32\...\{56e11d69-7cc9-40a5-a4f9-8f6190c4d84d}) (Version: 14.12.25810.0 - Microsoft Corporation)
Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.5.6 - Notepad++ Team)
NVIDIA 3D Vision Controller Driver 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
NVIDIA nView 147.00 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView) (Version: 147.00 - NVIDIA Corporation)
NVIDIA WMI 2.25.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVWMI) (Version: 2.25.0 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.10228.20134 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.10228.20134 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.10228.20134 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.10228.20134 - Microsoft Corporation) Hidden
PeaZip 6.1.1 (WIN64) (HKLM\...\{5A2BC38A-406C-4A5B-BF45-6991F9A05325}_is1) (Version: 6.1.1 - Giorgio Tani)
PeaZip configuration (WIN64) (HKLM\...\{4F8D60A8-C53D-47BD-AE5C-31AE6566D638}_is1) (Version:  - Giorgio Tani)
PlayMemories Camera Apps Downloader (HKLM-x32\...\{3333CE3B-CDF8-4F5E-A3BC-9ECD60FB7E66}) (Version: 1.2.0.13221 - Sony Corporation)
PlayMemories Home (HKLM-x32\...\{D3981248-DBE7-4050-B666-A7FE5AFFC62C}) (Version: 5.5.01.05091 - Sony Corporation)
PMB_ModeEditor (HKLM-x32\...\{E95982CA-945F-41F2-B156-A603897AB242}) (Version: 10.3.00 - Sony Corporation) Hidden
PMB_ServiceUploader (HKLM-x32\...\{7D3A0097-9E0E-4073-801C-295BBDAEAED8}) (Version: 10.5.01 - Sony Corporation) Hidden
Printer Registration (HKLM-x32\...\Canon EISRegistration) (Version: 1.1.0 - Canon Inc.)
QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7874 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform)
Remote Camera Control (HKLM-x32\...\{178CB313-9DB5-4634-8A2B-BB3BC31DF0B0}) (Version: 3.8.00000 - Sony Corporation)
ReNamer (HKLM-x32\...\ReNamer_is1) (Version: 6.6.0.0 - den4b Team)
Revo Uninstaller 2.0.4 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.4 - VS Revo Group, Ltd.)
Samsung SideSync (HKLM-x32\...\Samsung SideSync) (Version: 4.7.5.235 - Samsung Electronics Co., Ltd.)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.63.0 - Samsung Electronics Co., Ltd.)
Screencast-O-Matic v2.0 (HKLM-x32\...\Screencast-O-Matic v2.0) (Version: v2-1.8 - Screencast-O-Matic)
SeaTools for Windows 1.4.0.6 (HKLM-x32\...\SeaTools for Windows) (Version: 1.4.0.6 - Seagate Technology)
Security Task Manager 2.3 (HKLM-x32\...\Security Task Manager) (Version: 2.3 - Neuber Software)
Speccy (HKLM\...\Speccy) (Version: 1.29 - Piriform)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TeamViewer 13 (HKLM-x32\...\TeamViewer) (Version: 13.1.3629 - TeamViewer)
Tweaking.com - Windows Repair (HKLM-x32\...\Tweaking.com - Windows Repair) (Version: 3.9.36 - Tweaking.com)
UltraEdit (HKLM\...\{AFFE5F64-3248-41E9-96AE-8B475F6EFAB3}) (Version: 23.20.0.43 - IDM Computer Solutions, Inc.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.3 - VideoLAN)
WD Discovery (HKLM-x32\...\WDDiscovery) (Version: 1.3.482 - Western Digital Technologies, Inc.)
WD Drive Utilities (HKLM-x32\...\{27c7215d-df19-4095-8f6a-eba55cab35be}) (Version: 2.0.0.25 - Western Digital Technologies, Inc.)
WD Drive Utilities (HKLM-x32\...\{F413FB4C-7CFF-4737-BCC3-5EE43BFB3721}) (Version: 2.0.0.25 - Western Digital Technologies, Inc.) Hidden
WhatsApp (HKU\S-1-5-21-813518053-636032705-5302477-1001\...\WhatsApp) (Version: 0.3.33 - WhatsApp)
Youtube Downloader HD v. 2.9.9.31 (HKLM-x32\...\Youtube Downloader HD_is1) (Version:  - YoutubeDownloaderHD.com)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-813518053-636032705-5302477-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-8B3530E4204C}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File
CustomCLSID: HKU\S-1-5-21-813518053-636032705-5302477-1001_Classes\CLSID\{b5eedee0-c06e-11cf-8c56-444553540000}\InprocServer32 -> C:\Program Files\IDM Computer Solutions\UltraEdit\ue64ctmn.dll ()
CustomCLSID: HKU\S-1-5-21-813518053-636032705-5302477-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
ShellIconOverlayIdentifiers: [   AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-27] ()
ShellIconOverlayIdentifiers: [   AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-27] ()
ShellIconOverlayIdentifiers: [   AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-27] ()
ShellIconOverlayIdentifiers: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2018-04-23] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2018-04-23] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2018-04-23] (Google)
ShellIconOverlayIdentifiers-x32: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-27] ()
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2015-03-17] (Adobe Systems Inc.)
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files (x86)\Notepad++\NppShell_06.dll [2016-11-27] ()
ContextMenuHandlers1: [BB FlashBack 2] -> {A8065B9E-193F-4797-B62D-8F6321E7FCCB} =>  -> No File
ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2018-04-23] (Google)
ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll [2018-06-26] (Apple Inc.)
ContextMenuHandlers1: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2017-10-01] (Paramount Software UK Ltd)
ContextMenuHandlers2: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2017-10-01] (Paramount Software UK Ltd)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2018-04-23] (Google)
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers4: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd)
ContextMenuHandlers5: [00nView] -> {1E9B04FB-F9E5-4718-997B-B8DA88302A48} => C:\Program Files\NVIDIA Corporation\nview\nvshell.dll [2016-03-19] ()
ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-07-12] (Dropbox, Inc.)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-10-30] (NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-27] ()
ContextMenuHandlers6: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2015-03-17] (Adobe Systems Inc.)
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers6: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd)
ContextMenuHandlers1_S-1-5-21-813518053-636032705-5302477-1001: [UltraEdit] -> {b5eedee0-c06e-11cf-8c56-444553540000} => C:\Program Files\IDM Computer Solutions\UltraEdit\ue64ctmn.dll [2016-11-10] ()
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {1BB68826-A56E-478E-A841-34DD307FE051} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-09-27] (Dropbox, Inc.)
Task: {1CC3D1A9-E4D4-4D18-9CFE-C3BC3F2A94B4} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-07-21] (Microsoft Corporation)
Task: {3DE61A0A-7086-4D9E-A7EE-E4282F625A84} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-07-13] (Microsoft Corporation)
Task: {44814EE7-0DAE-4D0F-A04F-B66633BB015E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-09-19] (Google Inc.)
Task: {520D8283-7672-4772-AE19-20978D9FB4CB} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {52EDA6E4-1E89-4D56-B65E-0AD521C1CE37} - System32\Tasks\Microsoft\Office\OfficeOsfInstaller => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\osfinstaller.exe [2018-07-21] (Microsoft Corporation)
Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-11] ()
Task: {6C866DD5-F1B2-4F40-8184-A583CC8A1AD5} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2018-07-21] (Microsoft Corporation)
Task: {73B20228-B602-4FFB-BF38-7EF7C7C2A6AC} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [2018-05-16] (Bitdefender)
Task: {7B3BBDB2-AEDF-4756-B19D-0184D99B486C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2018-01-08] (Apple Inc.)
Task: {8A204C34-9F7D-4362-BC9A-1D6613A78BAD} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK
Task: {8A48C5FA-9EC3-4784-9AD2-73D7B5400B17} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-10-18] (Piriform Ltd)
Task: {92A22B6F-BAAE-4F50-B4C2-65B008F433F8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-09-19] (Google Inc.)
Task: {95FC6097-FBAD-4435-AA21-9C455255811D} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-09-27] (Dropbox, Inc.)
Task: {97A1B025-1359-4A1F-B13A-BD17FE1EA9DD} - System32\Tasks\AdobeAAMUpdater-1.0-DESKTOP-08QK23U-xian => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2018-04-11] (Adobe Systems Incorporated)
Task: {A2C5535A-8883-4213-A5D5-BC6342C9C0A4} - System32\Tasks\AdobeGCInvoker-1.0-XILENCE-xian => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2018-05-11] (Adobe Systems, Incorporated)
Task: {A5BAFDF8-81A8-4719-A3D6-857EA0937370} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-07-13] (Microsoft Corporation)
Task: {BC4FA66D-688F-4A52-8880-2A57658517CF} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2017-10-18] (Piriform Ltd)
Task: {CD47222C-5008-4CB5-BD12-9E39783B4810} - System32\Tasks\AdobeAAMUpdater-1.0-XILENCE-xian => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2018-04-11] (Adobe Systems Incorporated)
Task: {CDFF6A8B-9DCF-4C2C-8CD9-4A3A6405C378} - System32\Tasks\Microsoft\Windows\Setup\Notifier => C:\WINDOWS\system32\Notifier.exe
Task: {D8CB3130-99D3-4B6D-AE5B-7E5320808A0B} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-07-21] (Microsoft Corporation)
Task: {D9548503-F826-4FFF-8385-F2FFE8FB3DEC} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-03-21] (Adobe Systems Incorporated)
Task: {DE994CFB-D8F3-4D11-A2F6-AF1F9CB5E7A6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2018-07-21] (Microsoft Corporation)
Task: {F03E0DFE-5983-497F-B584-BE21073F4E1E} - System32\Tasks\LaunchChromeTask111 => C:\Program Files\FileZilla FTP Client\FileZilla.exe [2017-08-14] (FileZilla Project)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
Shortcut: C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\cloudLibrary\cloudLibrary Website.lnk -> hxxp://www.yourcloudlibrary.com/index.php/en-us
 
ShortcutWithArgument: C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome Connectivity Diagnostics.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=eemlkeanncmjljgehlbplemhmdmalhdc
ShortcutWithArgument: C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Keep - notes and lists.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=hmjkmjkepdijhoojdojkdfohbdgmmhki
ShortcutWithArgument: C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Pocket.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=mjcnijlhddpbdemagnpefmlkjdagkogk
ShortcutWithArgument: C:\Users\xian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Turbo Download Manager.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=kemfccojgjoilhfmcblgimbggikekjip
 
==================== Loaded Modules (Whitelisted) ==============
 
2016-09-19 21:53 - 2016-03-19 00:39 - 003168824 _____ () C:\Windows\system32\nvwmi64.exe
2017-12-08 02:48 - 2017-12-08 02:48 - 000088888 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2018-06-23 06:56 - 2018-06-23 06:56 - 001356088 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2018-06-07 14:10 - 2017-07-11 10:36 - 000391744 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
2018-07-22 22:40 - 2017-11-21 13:29 - 000278280 _____ () C:\Program Files\Bitdefender Antivirus Free\txmlutil.dll
2018-07-22 22:40 - 2018-06-18 19:15 - 000993728 _____ () C:\Program Files\Bitdefender Antivirus Free\Signatures\OTEngines\OTEngines_000_000\ashttpbr.mdl
2018-07-22 22:40 - 2018-06-18 19:15 - 000544880 _____ () C:\Program Files\Bitdefender Antivirus Free\Signatures\OTEngines\OTEngines_000_000\ashttpdsp.mdl
2018-07-22 22:40 - 2018-06-18 19:15 - 003232216 _____ () C:\Program Files\Bitdefender Antivirus Free\Signatures\OTEngines\OTEngines_000_000\ashttpph.mdl
2018-07-22 22:40 - 2018-06-18 19:15 - 001528320 _____ () C:\Program Files\Bitdefender Antivirus Free\Signatures\OTEngines\OTEngines_000_000\ashttprbl.mdl
2018-07-25 13:40 - 2018-04-25 13:16 - 002297040 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2018-04-11 18:34 - 2018-04-11 18:34 - 000491744 _____ () C:\Windows\System32\InputHost.dll
2018-04-11 18:34 - 2018-04-11 18:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll
2018-04-11 18:34 - 2018-04-11 18:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2016-11-10 10:52 - 2016-11-10 23:20 - 000147968 _____ () C:\Program Files\IDM Computer Solutions\UltraEdit\ue64ctmn.dll
2016-11-27 12:55 - 2016-11-27 12:55 - 000230064 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2018-02-27 20:08 - 2018-02-27 20:08 - 000614856 _____ () C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll
2018-07-10 20:21 - 2018-07-06 01:55 - 002185728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-09-22 17:31 - 2015-02-06 17:24 - 000147456 _____ () C:\Program Files (x86)\Tt eSPORTS\Challenger Prime\Monitor.exe
2018-06-08 16:34 - 2018-06-08 16:34 - 035475912 _____ () C:\Program Files (x86)\Adobe\Adobe Sync\Coresync\Coresync.exe
2018-06-26 15:46 - 2018-06-22 14:15 - 004608856 _____ () C:\Program Files (x86)\Google\Chrome\Application\67.0.3396.99\libglesv2.dll
2018-06-26 15:46 - 2018-06-22 14:15 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\67.0.3396.99\libegl.dll
2018-06-07 14:35 - 2018-06-07 14:35 - 081764304 _____ () C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\libcef.dll
2018-06-07 14:35 - 2018-06-07 14:35 - 002257360 _____ () C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\swiftshader\libglesv2.dll
2018-06-07 14:35 - 2018-06-07 14:35 - 000110544 _____ () C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\swiftshader\libegl.dll
2017-09-22 17:31 - 2014-12-10 14:50 - 000057344 _____ () C:\Program Files (x86)\Tt eSPORTS\Challenger Prime\lan.dll
2017-09-22 17:31 - 2013-03-30 23:53 - 000045056 _____ () C:\Program Files (x86)\Tt eSPORTS\Challenger Prime\hiddriver.dll
2018-06-11 15:57 - 2018-06-11 15:57 - 000142376 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\js\node_modules\fs-ext\build\Release\fs-ext.node
2018-06-11 15:57 - 2018-06-11 15:57 - 000271400 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\js\node_modules\node-vulcanjs\build\Release\VulcanJS.node
2018-06-11 15:57 - 2018-06-11 15:57 - 000141864 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\js\node_modules\ref\build\Release\binding.node
2018-06-11 15:57 - 2018-06-11 15:57 - 000150568 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\js\node_modules\ffi\build\Release\ffi_bindings.node
2018-06-11 15:57 - 2018-06-11 15:57 - 000097832 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\js\node_modules\node-ProxyResolver\build\Release\ProxyResolverWin.dll
2018-06-11 15:57 - 2018-06-11 15:57 - 000110120 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\js\node_modules\idle-gc\build\Release\idle-gc.node
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BFE => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MpsSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SharedAccess => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TweakingRemoveSafeBoot => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WSService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SamSs => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv2 => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srvnet => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TweakingRemoveSafeBoot => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WSService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2015-10-30 02:24 - 2017-07-14 18:24 - 000000855 _____ C:\WINDOWS\system32\Drivers\etc\hosts
 
127.0.0.1       localhost
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-813518053-636032705-5302477-1001\Control Panel\Desktop\\Wallpaper -> 
DNS Servers: 209.18.47.61 - 209.18.47.62
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Warn)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run: => "IAStorIcon"
HKLM\...\StartupApproved\Run: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "WDDiscovery"
HKLM\...\StartupApproved\Run32: => "CanonQuickMenu"
HKLM\...\StartupApproved\Run32: => "Acrobat Assistant 8.0"
HKLM\...\StartupApproved\Run32: => "Dropbox"
HKLM\...\StartupApproved\Run32: => "QuickTime Task"
HKLM\...\StartupApproved\Run32: => "PMBVolumeWatcher"
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer"
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\StartupApproved\Run: => "BlueStacks Agent"
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\StartupApproved\Run: => "Bomgar Support Reconnect [595AD346]"
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\StartupApproved\Run: => "Bomgar_Cleanup_ZD1605360925216"
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\StartupApproved\Run: => "Bomgar_Cleanup_ZD159297652639"
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\StartupApproved\Run: => "iCloudServices"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{FCBBB808-DD45-4442-A46E-0E62DDE555CA}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{678C9D20-D029-42B0-9183-50E5E2CFE8F3}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{C3D43F5C-2953-415A-8C80-FBB778DB29FC}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{F51298FB-8B60-49F9-AFF0-30323907B2AB}] => (Allow) C:\Program Files (x86)\Samsung\SideSync4\SideSync.exe
FirewallRules: [{6087F8F3-9911-46E7-A23B-65D523B0B531}] => (Allow) C:\Program Files (x86)\Samsung\SideSync4\SideSync.exe
FirewallRules: [{65EF7F39-A024-40B6-A960-2DB91DFFF1A6}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{7B8B1006-6776-4232-8265-E7A318539448}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{5FC01B65-45B5-47E3-9766-53BA12EC453D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{2299DADA-5200-408D-8DD9-4DD80694391C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{9B32F551-E165-4679-BE37-27DAA0E7F198}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{64300E35-5DFC-4CA0-8AAA-68241C08061B}] => (Allow) C:\Program Files (x86)\Bluestacks\HD-Player.exe
FirewallRules: [{692CB1A1-B5CC-433E-B5BD-FBA92086C0EB}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
FirewallRules: [{4DAF3BA3-93AF-4FD8-B64C-918306632AA2}] => (Allow) X:\Steam\steamapps\common\Portal\hl2.exe
FirewallRules: [{F14A5B9C-676D-47A4-B4C6-A290A56843EB}] => (Allow) X:\Steam\steamapps\common\Portal\hl2.exe
FirewallRules: [{2395F1A6-BD80-4FDA-88CD-8AA566A8FCFB}] => (Allow) X:\Steam\steamapps\common\Portal 2\portal2.exe
FirewallRules: [{C0A4DAE4-C212-4785-B43A-934BB95D5B3C}] => (Allow) X:\Steam\steamapps\common\Portal 2\portal2.exe
FirewallRules: [{A256E5A1-B5C1-4EF9-9BE8-7DEB1EE82BBB}] => (Allow) X:\Steam\steamapps\common\Portal Stories Mel\portal2.exe
FirewallRules: [{86211C20-7E2A-496F-81C1-71E54F63B0CE}] => (Allow) X:\Steam\steamapps\common\Portal Stories Mel\portal2.exe
FirewallRules: [{E1A3B3D7-1B5C-4000-A69C-8815C698D60C}] => (Allow) X:\Steam\steamapps\common\SteamVRPerformanceTest\bin\win64\vr.exe
FirewallRules: [{172CC6F8-6B16-41EC-91A3-4DF5BCC6DEC3}] => (Allow) X:\Steam\steamapps\common\SteamVRPerformanceTest\bin\win64\vr.exe
FirewallRules: [{C294B62A-6BDE-46EF-85D0-2974D7E70B5B}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{F6072CFD-42FF-4838-AB2C-D51FED458C1C}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{937015D0-E2DD-4CC1-A927-2DC8C95E61AF}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{B79D273E-003D-43B9-9C5D-6606C42BDAFD}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{76AA7852-34F3-4776-990E-E3FDEE4B726E}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{D76AD06E-1C4B-4CF0-9078-CB227694B31B}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{DA358B1F-8983-4AEF-A596-7F19A10AA8EF}] => (Allow) LPort=8087
FirewallRules: [{AF1ACBA1-7E4C-455B-B102-FFBCF7E2A47A}] => (Allow) LPort=8086
FirewallRules: [{E14C9BFC-F1F6-4C1C-86F8-D7369E5AE956}] => (Allow) LPort=1434
FirewallRules: [{1042DEC0-2936-4EE3-944F-B8EFDC3AD1A9}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{430255D4-1673-452A-A3F7-0A024A78CBF6}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{99DA618B-810D-4D94-877E-4C2A19A0A195}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{986C682E-A132-4C33-A75C-A5D67DC2142B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{F1B3A766-9DD2-467D-AEDF-D3950D8EB561}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{A50DBCF6-02A8-49FB-B8B4-063CD554D03A}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{71161327-8F9D-407A-9D4F-DC8EF7C78456}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{3376A7E6-1735-4F48-B90D-6350F92B71E8}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [TCP Query User{7CF03DAF-F27C-483C-B798-488161A09CE4}C:\program files (x86)\fontforgebuilds\bin\vcxsrv\vcxsrv.exe] => (Block) C:\program files (x86)\fontforgebuilds\bin\vcxsrv\vcxsrv.exe
FirewallRules: [UDP Query User{76877978-CF7E-418B-B70F-B18BD3FCD17C}C:\program files (x86)\fontforgebuilds\bin\vcxsrv\vcxsrv.exe] => (Block) C:\program files (x86)\fontforgebuilds\bin\vcxsrv\vcxsrv.exe
FirewallRules: [{60E0AD8D-2323-4D00-B1B6-83E479A35B52}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{C8F403D2-3105-419E-B4B6-A3A2063FB807}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
FirewallRules: [{8FDCC2D2-68E2-449F-9600-F5FBDAC78050}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
 
==================== Restore Points =========================
 
25-07-2018 14:20:19 Installed Macrium Reflect Free Edition
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (07/25/2018 05:46:25 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Samsung\SideSync4\SideSync.exe".Error in manifest or policy file "" on line .
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17134.165_none_fb429645306569ac.manifest.
Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17134.165_none_42efcd1c44e192b2.manifest.
 
Error: (07/25/2018 05:44:07 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT AUTHORITY)
Description: Event filter with query "//./ROOT/default" could not be reactivated in namespace "select * from CIntelWLANEvent" because of error 0x80041010. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (07/25/2018 05:38:15 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Samsung\SideSync4\SideSync.exe".Error in manifest or policy file "" on line .
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17134.165_none_fb429645306569ac.manifest.
Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17134.165_none_42efcd1c44e192b2.manifest.
 
Error: (07/25/2018 05:30:26 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program mmc.exe version 10.0.17134.1 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 10d0
 
Start Time: 01d424661123fa23
 
Termination Time: 18
 
Application Path: C:\Windows\System32\mmc.exe
 
Report Id: 38a53fcb-f6b3-4417-9c42-2fe118f91be2
 
Faulting package full name: 
 
Faulting package-relative application ID:
 
Error: (07/25/2018 04:40:38 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Spotify.exe, version: 1.0.82.447, time stamp: 0x5b101db7
Faulting module name: KERNELBASE.dll, version: 10.0.17134.165, time stamp: 0xfa43f4b2
Exception code: 0xc0000005
Fault offset: 0x000f2a40
Faulting process id: 0x3b0
Faulting application start time: 0x01d424601f46b4f7
Faulting application path: C:\Users\xian\AppData\Roaming\Spotify\Spotify.exe
Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
Report Id: e0479c66-f07a-4265-80c7-913e00f27ba8
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (07/25/2018 04:34:32 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program RevoUnin.exe version 2.0.4.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 1d10
 
Start Time: 01d4245efae62c09
 
Termination Time: 4294967295
 
Application Path: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe
 
Report Id: 8194a70c-edab-4661-bcfe-0af8e94334d6
 
Faulting package full name: 
 
Faulting package-relative application ID:
 
Error: (07/25/2018 04:31:58 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program RevoUnin.exe version 2.0.4.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 1f40
 
Start Time: 01d424557c39bf75
 
Termination Time: 4294967295
 
Application Path: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe
 
Report Id: 25aebb40-6368-48fb-aa96-01654194a3d9
 
Faulting package full name: 
 
Faulting package-relative application ID:
 
Error: (07/25/2018 02:12:22 PM) (Source: MsiInstaller) (EventID: 11920) (User: XILENCE)
Description: Product: Macrium Reflect Free Edition -- Error 1920. Service 'Macrium Service' (MacriumService) failed to start. Verify that you have sufficient privileges to start system services.
 
 
System errors:
=============
Error: (07/25/2018 07:05:11 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
 
Error: (07/25/2018 06:09:27 PM) (Source: DCOM) (EventID: 10016) (User: XILENCE)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user XILENCE\xian SID (S-1-5-21-813518053-636032705-5302477-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/25/2018 05:48:20 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
Windows.SecurityCenter.WscBrokerManager
 and APPID 
Unavailable
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/25/2018 05:46:23 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/25/2018 05:46:23 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (07/25/2018 05:46:18 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Windows Media Player Network Sharing Service service terminated with the following error: 
An attempt was made to reference a token that does not exist.
 
Error: (07/25/2018 05:46:14 PM) (Source: NETLOGON) (EventID: 3095) (User: )
Description: This computer is configured as a member of a workgroup, not as
a member of a domain. The Netlogon service does not need to run in this
configuration.
 
Error: (07/25/2018 05:40:06 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
Windows.SecurityCenter.WscBrokerManager
 and APPID 
Unavailable
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
 
Windows Defender:
===================================
Date: 2018-07-22 09:42:07.662
Description: 
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version: 
Previous Signature Version: 1.273.129.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.15100.1
Error code: 0x80240438
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. 
 
Date: 2018-07-21 09:41:43.677
Description: 
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version: 
Previous Signature Version: 1.273.91.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.15100.1
Error code: 0x8024402c
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. 
 
Date: 2018-07-19 21:18:03.178
Description: 
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version: 
Previous Signature Version: 1.271.1198.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.15000.2
Error code: 0x800704cf
Error description: The network location cannot be reached. For information about network troubleshooting, see Windows Help. 
 
Date: 2018-07-14 21:17:36.606
Description: 
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version: 
Previous Signature Version: 1.271.971.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.15000.2
Error code: 0x8024402c
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. 
 
CodeIntegrity:
===================================
 
Date: 2018-07-25 17:46:24.707
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Bitdefender Antivirus Free\vsservppl.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bitdefender Antivirus Free\AgentCtrl.exe that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2018-07-25 17:38:13.354
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Bitdefender Antivirus Free\vsservppl.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bitdefender Antivirus Free\AgentCtrl.exe that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2018-07-25 14:18:12.660
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Bitdefender Antivirus Free\vsservppl.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bitdefender Antivirus Free\AgentCtrl.exe that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2018-07-23 19:19:29.596
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Bitdefender Antivirus Free\vsservppl.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender Antivirus Free\AgentCtrl.exe that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2018-07-22 23:14:55.514
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Bitdefender Antivirus Free\vsservppl.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender Antivirus Free\AgentCtrl.exe that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2018-07-22 22:43:34.489
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Bitdefender Antivirus Free\vsservppl.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender Antivirus Free\AgentCtrl.exe that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2018-07-22 22:41:32.559
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Bitdefender Antivirus Free\vsservppl.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender Antivirus Free\AgentCtrl.exe that did not meet the Custom 3 / Antimalware signing level requirements.
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i7-5820K CPU @ 3.30GHz
Percentage of memory in use: 16%
Total physical RAM: 32684.68 MB
Available physical RAM: 27294.51 MB
Total Virtual: 34732.68 MB
Available Virtual: 28671.06 MB
 
==================== Drives ================================
 
Drive c: (SystemDisk) (Fixed) (Total:237.92 GB) (Free:72.29 GB) NTFS
Drive e: (ScratchDisk) (Fixed) (Total:232.33 GB) (Free:231.74 GB) NTFS
Drive f: (easystore) (Fixed) (Total:7452.03 GB) (Free:4139.67 GB) NTFS
Drive g: () (Fixed) (Total:0.44 GB) (Free:0.43 GB) NTFS
Drive h: (Fragile) (Fixed) (Total:931.51 GB) (Free:901.51 GB) NTFS
Drive i: (sKrubbed) (Fixed) (Total:19.69 GB) (Free:19.55 GB) NTFS
Drive j: () (Fixed) (Total:0.09 GB) (Free:0.09 GB) FAT32
Drive k: (Kleen) (Fixed) (Total:909.91 GB) (Free:80.05 GB) NTFS
Drive l: (Recovery) (Fixed) (Total:0.44 GB) (Free:0.15 GB) NTFS
Drive m: (Windows RE tools) (Fixed) (Total:1 GB) (Free:0.66 GB) NTFS
Drive n: () (Fixed) (Total:0.44 GB) (Free:0.12 GB) NTFS
Drive o: (USB DISK) (Removable) (Total:7.21 GB) (Free:4.97 GB) FAT32
Drive x: (Six) (Fixed) (Total:1862.89 GB) (Free:438.94 GB) NTFS
 
\\?\Volume{8b69d665-f8d5-4482-9e58-5f09fd93cfa3}\ () (Fixed) (Total:0.09 GB) (Free:0.02 GB) FAT32
\\?\Volume{ae58cb97-fd4a-4550-8e6f-6d38d3b7a3a5}\ (SYSTEM) (Fixed) (Total:0.35 GB) (Free:0.31 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Protective MBR) (Size: 232.9 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
========================================================
Disk: 1 (Protective MBR) (Size: 238.5 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
========================================================
Disk: 2 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: BEC516A5)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)
 
========================================================
Disk: 3 (Protective MBR) (Size: 1863 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
========================================================
Disk: 4 (Size: 931.5 GB) (Disk ID: 7AFEF895)
 
Partition: GPT.
 
========================================================
Disk: 5 (Size: 7452 GB) (Disk ID: 16F2A91F)
 
Partition: GPT.
 
========================================================
Disk: 6 (MBR Code: Windows XP) (Size: 7.2 GB) (Disk ID: 6B383CD4)
Partition 1: (Not Active) - (Size=7.2 GB) - (Type=0C)
 
==================== End of Addition.txt ============================


#9 Xitixen

Xitixen
  • Topic Starter

  • Members
  • 69 posts
  • OFFLINE
  •  
  • Local time:11:02 AM

Posted 25 July 2018 - 07:52 PM

If you don't care to parse all that, I totally understand. I think my main concern about an infection may turn out to be related to the 1803 Windows Update. I'll head over to the Win10 forum and see if we can get this intermittent wifi adapter connection to be more stable again...

 

Thanks for your time.



#10 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,752 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:06:02 AM

Posted 25 July 2018 - 09:45 PM

Lets check your current installation for malware.

  • Highlight the entire content of the quote box below.

Start::  
HKLM-x32\...\Run: [] => [X]
FirewallRules: [{DA358B1F-8983-4AEF-A596-7F19A10AA8EF}] => (Allow) LPort=8087
FirewallRules: [{AF1ACBA1-7E4C-455B-B102-FFBCF7E2A47A}] => (Allow) LPort=8086
FirewallRules: [{E14C9BFC-F1F6-4C1C-86F8-D7369E5AE956}] => (Allow) LPort=1434
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\Run: [Bomgar_Cleanup_ZD159297652639] => cmd.exe /C rd /S /Q "C:\ProgramData\apple-scc-0x595ad17f" & reg.exe delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD159297652639 /f <==== ATTENTION
Task: {520D8283-7672-4772-AE19-20978D9FB4CB} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
CustomCLSID: HKU\S-1-5-21-813518053-636032705-5302477-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-8B3530E4204C}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File
ContextMenuHandlers1: [BB FlashBack 2] -> {A8065B9E-193F-4797-B62D-8F6321E7FCCB} =>  -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
Task: {520D8283-7672-4772-AE19-20978D9FB4CB} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\Run: [Bomgar_Cleanup_ZD1605360925216] => cmd.exe /C rd /S /Q "C:\Users\xian\AppData\Local\Temp\nsfEFCD.tmpb" & reg.exe delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD1605360925216 /f <==== ATTENTION
2018-07-23 12:57 - 2018-07-23 12:57 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign086097b0d912ddc4
2018-07-23 10:33 - 2018-07-23 10:33 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsigna6baef72ad2da9c3
2018-07-23 10:33 - 2018-07-23 10:33 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign4620eb3e78bed101
2018-07-22 10:08 - 2018-07-22 10:08 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignec8b492d601a40b1
2018-07-22 09:47 - 2018-07-22 09:47 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign98c1dbba8fdb470d
2018-07-21 18:48 - 2018-07-21 18:48 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsigne63ad584d2c5de77
2018-07-21 18:45 - 2018-07-21 18:45 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign41e7078d6258ce1e
2018-07-17 13:22 - 2018-07-17 13:22 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign3704237fd106cf36
2018-07-17 12:28 - 2018-07-17 12:28 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignd44dc54e4677596e
2018-07-17 12:13 - 2018-07-17 12:13 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign799888e304a81074
2018-07-17 12:13 - 2018-07-17 12:13 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign1cc08e469885b792
2018-07-15 19:33 - 2018-07-15 19:33 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign2930c85ae4bd9362
2018-07-15 19:30 - 2018-07-15 19:30 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign4909dc3eb204d02f
2018-07-15 19:21 - 2018-07-15 19:21 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignfaeaeca3bfbd73a2
2018-07-15 19:21 - 2018-07-15 19:21 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignb06f6c951c4e2722
2018-07-15 19:16 - 2018-07-15 19:16 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign9efe96ab01fcaa9f
2018-07-15 19:16 - 2018-07-15 19:16 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign610efe6f08ba5fcc
2018-07-10 16:42 - 2018-07-10 16:42 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsigne9fca32f1ca75c38
2018-07-10 16:05 - 2018-07-10 16:05 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignf36a9148db4e1642
2018-07-09 15:45 - 2018-07-09 15:45 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsigne55609b247f1bc81
2018-07-09 15:44 - 2018-07-09 15:44 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignccb41b1ad08e129d
2018-07-09 15:38 - 2018-07-09 15:38 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign2ac9436c4901f6aa
2018-07-09 15:30 - 2018-07-09 15:30 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign9bbc425a737afc75
2018-07-23 12:57 - 2018-07-23 12:57 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign086097b0d912ddc4
2018-07-23 10:33 - 2018-07-23 10:33 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsigna6baef72ad2da9c3
2018-07-23 10:33 - 2018-07-23 10:33 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign4620eb3e78bed101
2018-07-22 10:08 - 2018-07-22 10:08 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignec8b492d601a40b1
2018-07-22 09:47 - 2018-07-22 09:47 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign98c1dbba8fdb470d
2018-07-21 18:48 - 2018-07-21 18:48 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsigne63ad584d2c5de77
2018-07-21 18:45 - 2018-07-21 18:45 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign41e7078d6258ce1e
2018-07-17 13:22 - 2018-07-17 13:22 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign3704237fd106cf36
2018-07-17 12:28 - 2018-07-17 12:28 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignd44dc54e4677596e
2018-07-17 12:13 - 2018-07-17 12:13 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign799888e304a81074
2018-07-17 12:13 - 2018-07-17 12:13 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign1cc08e469885b792
2018-07-15 19:33 - 2018-07-15 19:33 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign2930c85ae4bd9362
2018-07-15 19:30 - 2018-07-15 19:30 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign4909dc3eb204d02f
2018-07-15 19:21 - 2018-07-15 19:21 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignfaeaeca3bfbd73a2
2018-07-15 19:21 - 2018-07-15 19:21 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignb06f6c951c4e2722
2018-07-15 19:16 - 2018-07-15 19:16 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign9efe96ab01fcaa9f
2018-07-15 19:16 - 2018-07-15 19:16 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign610efe6f08ba5fcc
2018-07-10 16:42 - 2018-07-10 16:42 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsigne9fca32f1ca75c38
2018-07-10 16:05 - 2018-07-10 16:05 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignf36a9148db4e1642
2018-07-09 15:45 - 2018-07-09 15:45 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsigne55609b247f1bc81
2018-07-09 15:44 - 2018-07-09 15:44 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignccb41b1ad08e129d
2018-07-09 15:38 - 2018-07-09 15:38 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign2ac9436c4901f6aa
2018-07-09 15:30 - 2018-07-09 15:30 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign9bbc425a737afc75
HOSTS:
Removeproxy:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset C:\resettcpip.txt
CMD: FOR /F "usebackq delims==" %i IN (`wevtutil el`) DO wevtutil cl "%i"
CMD: Bitsadmin /Reset /Allusers
EMPTYTEMP:
Reboot:
End::

  • Right click on the highlighted text and select Copy.
  • Start FRST (FRST64) with Administrator privileges
  • Press the Fix button. FRST will process the lines copied above from the clipboard.
  • When finished, a log file (Fixlog.txt) will pop up and saved in the same location the tool was ran from.

Please copy and paste its contents in your next reply.

 

 

RQKuhw1.pngRogueKiller

  • Download the right version of RogueKiller for your Windows version (32 or 64-bit)
  • Once done, move the executable file to your Desktop, right-click on it and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Click on the Start Scan button in the right panel, which will bring you to another tab, and click on it again (this time it'll be in the bottom right corner)
  • Wait for the scan to complete
  • On completion, the results will be displayed
  • Check every single entry (threat found), and click on the Remove Selected button
  • On completion, the results will be displayed. Click on the Open Report button in the bottom left corner, followed by the Open TXT button (also in the bottom left corner)
  • This will open the report in Notepad. Copy/paste its content in your next reply

zcMPezJ.pngAdwCleaner - Fix Mode


  • Download AdwCleaner and move it to your Desktop
  • Right-click on AdwCleaner.exe and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Accept the EULA (I accept), then click on Scan
  • Let the scan complete. Once it's done, make sure that every item listed in the different tabs is checked and click on the Clean button. This will kill all active processes
    5ace519a6ff4a_Dashboard-firstrun.png.567
  • Once the cleaning process is complete, AdwCleaner will ask to restart your computer, do it
  • After the restart, a log will open when logging in. Please copy/paste the content of that log in your next reply

Your next reply(ies) should therefore contain:

  • Copy/pasted RogueKiller clean log
  • Copy/pasted AdwCleaner clean log
  • Copy/pasted Fixlog.txt log

 

 


No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#11 Xitixen

Xitixen
  • Topic Starter

  • Members
  • 69 posts
  • OFFLINE
  •  
  • Local time:11:02 AM

Posted 26 July 2018 - 10:26 AM

Fix result of Farbar Recovery Scan Tool (x64) Version: 21.07.2018
Ran by xian (26-07-2018 10:15:08) Run:2
Running from H:\down
Loaded Profiles: xian (Available Profiles: xian)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
  
HKLM-x32\...\Run: [] => [X]
FirewallRules: [{DA358B1F-8983-4AEF-A596-7F19A10AA8EF}] => (Allow) LPort=8087
FirewallRules: [{AF1ACBA1-7E4C-455B-B102-FFBCF7E2A47A}] => (Allow) LPort=8086
FirewallRules: [{E14C9BFC-F1F6-4C1C-86F8-D7369E5AE956}] => (Allow) LPort=1434
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\Run: [Bomgar_Cleanup_ZD159297652639] => cmd.exe /C rd /S /Q "C:\ProgramData\apple-scc-0x595ad17f" & reg.exe delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD159297652639 /f <==== ATTENTION
Task: {520D8283-7672-4772-AE19-20978D9FB4CB} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
CustomCLSID: HKU\S-1-5-21-813518053-636032705-5302477-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-8B3530E4204C}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File
ContextMenuHandlers1: [BB FlashBack 2] -> {A8065B9E-193F-4797-B62D-8F6321E7FCCB} =>  -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
Task: {520D8283-7672-4772-AE19-20978D9FB4CB} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
HKU\S-1-5-21-813518053-636032705-5302477-1001\...\Run: [Bomgar_Cleanup_ZD1605360925216] => cmd.exe /C rd /S /Q "C:\Users\xian\AppData\Local\Temp\nsfEFCD.tmpb" & reg.exe delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD1605360925216 /f <==== ATTENTION
2018-07-23 12:57 - 2018-07-23 12:57 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign086097b0d912ddc4
2018-07-23 10:33 - 2018-07-23 10:33 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsigna6baef72ad2da9c3
2018-07-23 10:33 - 2018-07-23 10:33 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign4620eb3e78bed101
2018-07-22 10:08 - 2018-07-22 10:08 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignec8b492d601a40b1
2018-07-22 09:47 - 2018-07-22 09:47 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign98c1dbba8fdb470d
2018-07-21 18:48 - 2018-07-21 18:48 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsigne63ad584d2c5de77
2018-07-21 18:45 - 2018-07-21 18:45 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign41e7078d6258ce1e
2018-07-17 13:22 - 2018-07-17 13:22 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign3704237fd106cf36
2018-07-17 12:28 - 2018-07-17 12:28 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignd44dc54e4677596e
2018-07-17 12:13 - 2018-07-17 12:13 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign799888e304a81074
2018-07-17 12:13 - 2018-07-17 12:13 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign1cc08e469885b792
2018-07-15 19:33 - 2018-07-15 19:33 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign2930c85ae4bd9362
2018-07-15 19:30 - 2018-07-15 19:30 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign4909dc3eb204d02f
2018-07-15 19:21 - 2018-07-15 19:21 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignfaeaeca3bfbd73a2
2018-07-15 19:21 - 2018-07-15 19:21 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignb06f6c951c4e2722
2018-07-15 19:16 - 2018-07-15 19:16 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign9efe96ab01fcaa9f
2018-07-15 19:16 - 2018-07-15 19:16 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign610efe6f08ba5fcc
2018-07-10 16:42 - 2018-07-10 16:42 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsigne9fca32f1ca75c38
2018-07-10 16:05 - 2018-07-10 16:05 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignf36a9148db4e1642
2018-07-09 15:45 - 2018-07-09 15:45 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsigne55609b247f1bc81
2018-07-09 15:44 - 2018-07-09 15:44 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignccb41b1ad08e129d
2018-07-09 15:38 - 2018-07-09 15:38 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign2ac9436c4901f6aa
2018-07-09 15:30 - 2018-07-09 15:30 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign9bbc425a737afc75
2018-07-23 12:57 - 2018-07-23 12:57 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign086097b0d912ddc4
2018-07-23 10:33 - 2018-07-23 10:33 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsigna6baef72ad2da9c3
2018-07-23 10:33 - 2018-07-23 10:33 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign4620eb3e78bed101
2018-07-22 10:08 - 2018-07-22 10:08 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignec8b492d601a40b1
2018-07-22 09:47 - 2018-07-22 09:47 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign98c1dbba8fdb470d
2018-07-21 18:48 - 2018-07-21 18:48 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsigne63ad584d2c5de77
2018-07-21 18:45 - 2018-07-21 18:45 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign41e7078d6258ce1e
2018-07-17 13:22 - 2018-07-17 13:22 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign3704237fd106cf36
2018-07-17 12:28 - 2018-07-17 12:28 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignd44dc54e4677596e
2018-07-17 12:13 - 2018-07-17 12:13 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign799888e304a81074
2018-07-17 12:13 - 2018-07-17 12:13 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign1cc08e469885b792
2018-07-15 19:33 - 2018-07-15 19:33 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign2930c85ae4bd9362
2018-07-15 19:30 - 2018-07-15 19:30 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign4909dc3eb204d02f
2018-07-15 19:21 - 2018-07-15 19:21 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignfaeaeca3bfbd73a2
2018-07-15 19:21 - 2018-07-15 19:21 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignb06f6c951c4e2722
2018-07-15 19:16 - 2018-07-15 19:16 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign9efe96ab01fcaa9f
2018-07-15 19:16 - 2018-07-15 19:16 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign610efe6f08ba5fcc
2018-07-10 16:42 - 2018-07-10 16:42 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsigne9fca32f1ca75c38
2018-07-10 16:05 - 2018-07-10 16:05 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignf36a9148db4e1642
2018-07-09 15:45 - 2018-07-09 15:45 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsigne55609b247f1bc81
2018-07-09 15:44 - 2018-07-09 15:44 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsignccb41b1ad08e129d
2018-07-09 15:38 - 2018-07-09 15:38 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign2ac9436c4901f6aa
2018-07-09 15:30 - 2018-07-09 15:30 - 000000000 ____D C:\Users\xian\AppData\Local\Tempzxpsign9bbc425a737afc75
HOSTS:
Removeproxy:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset C:\resettcpip.txt
CMD: FOR /F "usebackq delims==" %i IN (`wevtutil el`) DO wevtutil cl "%i"
CMD: Bitsadmin /Reset /Allusers
EMPTYTEMP:
Reboot:
 
*****************
 
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DA358B1F-8983-4AEF-A596-7F19A10AA8EF}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{AF1ACBA1-7E4C-455B-B102-FFBCF7E2A47A}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E14C9BFC-F1F6-4C1C-86F8-D7369E5AE956}" => removed successfully
"HKU\S-1-5-21-813518053-636032705-5302477-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Bomgar_Cleanup_ZD159297652639" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{520D8283-7672-4772-AE19-20978D9FB4CB}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{520D8283-7672-4772-AE19-20978D9FB4CB}" => removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager => not found
"HKU\S-1-5-21-813518053-636032705-5302477-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-8B3530E4204C}" => removed successfully
"HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\BB FlashBack 2" => removed successfully
HKLM\Software\Classes\CLSID\{A8065B9E-193F-4797-B62D-8F6321E7FCCB} => not found
"HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Offline Files" => removed successfully
HKLM\Software\Classes\CLSID\{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => not found
"HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\BriefcaseMenu" => removed successfully
"HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D}" => removed successfully
"HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Offline Files" => removed successfully
HKLM\Software\Classes\CLSID\{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{520D8283-7672-4772-AE19-20978D9FB4CB} => not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager => not found
"HKU\S-1-5-21-813518053-636032705-5302477-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Bomgar_Cleanup_ZD1605360925216" => removed successfully
C:\Users\xian\AppData\Local\Tempzxpsign086097b0d912ddc4 => moved successfully
C:\Users\xian\AppData\Local\Tempzxpsigna6baef72ad2da9c3 => moved successfully
C:\Users\xian\AppData\Local\Tempzxpsign4620eb3e78bed101 => moved successfully
C:\Users\xian\AppData\Local\Tempzxpsignec8b492d601a40b1 => moved successfully
C:\Users\xian\AppData\Local\Tempzxpsign98c1dbba8fdb470d => moved successfully
C:\Users\xian\AppData\Local\Tempzxpsigne63ad584d2c5de77 => moved successfully
C:\Users\xian\AppData\Local\Tempzxpsign41e7078d6258ce1e => moved successfully
C:\Users\xian\AppData\Local\Tempzxpsign3704237fd106cf36 => moved successfully
C:\Users\xian\AppData\Local\Tempzxpsignd44dc54e4677596e => moved successfully
C:\Users\xian\AppData\Local\Tempzxpsign799888e304a81074 => moved successfully
C:\Users\xian\AppData\Local\Tempzxpsign1cc08e469885b792 => moved successfully
C:\Users\xian\AppData\Local\Tempzxpsign2930c85ae4bd9362 => moved successfully
C:\Users\xian\AppData\Local\Tempzxpsign4909dc3eb204d02f => moved successfully
C:\Users\xian\AppData\Local\Tempzxpsignfaeaeca3bfbd73a2 => moved successfully
C:\Users\xian\AppData\Local\Tempzxpsignb06f6c951c4e2722 => moved successfully
C:\Users\xian\AppData\Local\Tempzxpsign9efe96ab01fcaa9f => moved successfully
C:\Users\xian\AppData\Local\Tempzxpsign610efe6f08ba5fcc => moved successfully
C:\Users\xian\AppData\Local\Tempzxpsigne9fca32f1ca75c38 => moved successfully
C:\Users\xian\AppData\Local\Tempzxpsignf36a9148db4e1642 => moved successfully
C:\Users\xian\AppData\Local\Tempzxpsigne55609b247f1bc81 => moved successfully
C:\Users\xian\AppData\Local\Tempzxpsignccb41b1ad08e129d => moved successfully
C:\Users\xian\AppData\Local\Tempzxpsign2ac9436c4901f6aa => moved successfully
C:\Users\xian\AppData\Local\Tempzxpsign9bbc425a737afc75 => moved successfully
"C:\Users\xian\AppData\Local\Tempzxpsign086097b0d912ddc4" => not found
"C:\Users\xian\AppData\Local\Tempzxpsigna6baef72ad2da9c3" => not found
"C:\Users\xian\AppData\Local\Tempzxpsign4620eb3e78bed101" => not found
"C:\Users\xian\AppData\Local\Tempzxpsignec8b492d601a40b1" => not found
"C:\Users\xian\AppData\Local\Tempzxpsign98c1dbba8fdb470d" => not found
"C:\Users\xian\AppData\Local\Tempzxpsigne63ad584d2c5de77" => not found
"C:\Users\xian\AppData\Local\Tempzxpsign41e7078d6258ce1e" => not found
"C:\Users\xian\AppData\Local\Tempzxpsign3704237fd106cf36" => not found
"C:\Users\xian\AppData\Local\Tempzxpsignd44dc54e4677596e" => not found
"C:\Users\xian\AppData\Local\Tempzxpsign799888e304a81074" => not found
"C:\Users\xian\AppData\Local\Tempzxpsign1cc08e469885b792" => not found
"C:\Users\xian\AppData\Local\Tempzxpsign2930c85ae4bd9362" => not found
"C:\Users\xian\AppData\Local\Tempzxpsign4909dc3eb204d02f" => not found
"C:\Users\xian\AppData\Local\Tempzxpsignfaeaeca3bfbd73a2" => not found
"C:\Users\xian\AppData\Local\Tempzxpsignb06f6c951c4e2722" => not found
"C:\Users\xian\AppData\Local\Tempzxpsign9efe96ab01fcaa9f" => not found
"C:\Users\xian\AppData\Local\Tempzxpsign610efe6f08ba5fcc" => not found
"C:\Users\xian\AppData\Local\Tempzxpsigne9fca32f1ca75c38" => not found
"C:\Users\xian\AppData\Local\Tempzxpsignf36a9148db4e1642" => not found
"C:\Users\xian\AppData\Local\Tempzxpsigne55609b247f1bc81" => not found
"C:\Users\xian\AppData\Local\Tempzxpsignccb41b1ad08e129d" => not found
"C:\Users\xian\AppData\Local\Tempzxpsign2ac9436c4901f6aa" => not found
"C:\Users\xian\AppData\Local\Tempzxpsign9bbc425a737afc75" => not found
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
 
========= RemoveProxy: =========
 
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => removed successfully
"HKU\S-1-5-21-813518053-636032705-5302477-1001\SOFTWARE\Policies\Microsoft\Internet Explorer" => removed successfully
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
"HKU\S-1-5-21-813518053-636032705-5302477-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-21-813518053-636032705-5302477-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
 
 
========= End of RemoveProxy: =========
 
 
========= netsh advfirewall reset =========
 
Ok.
 
 
========= End of CMD: =========
 
 
========= netsh advfirewall set allprofiles state ON =========
 
Ok.
 
 
========= End of CMD: =========
 
 
========= ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
 
========= netsh winsock reset catalog =========
 
 
Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.
 
 
========= End of CMD: =========
 
 
========= netsh int ip reset C:\resettcpip.txt =========
 
Resetting Compartment Forwarding, OK!
Resetting Compartment, OK!
Resetting Control Protocol, OK!
Resetting Echo Sequence Request, OK!
Resetting Global, OK!
Resetting Interface, OK!
Resetting Anycast Address, OK!
Resetting Multicast Address, OK!
Resetting Unicast Address, OK!
Resetting Neighbor, OK!
Resetting Path, OK!
Resetting Potential, OK!
Resetting Prefix Policy, OK!
Resetting Proxy Neighbor, OK!
Resetting Route, OK!
Resetting Site Prefix, OK!
Resetting Subinterface, OK!
Resetting Wakeup Pattern, OK!
Resetting Resolve Neighbor, OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , failed.
Access is denied.
 
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Restart the computer to complete this action.
 
 
========= End of CMD: =========
 
 
========= FOR /F "usebackq delims==" %i IN (`wevtutil el`) DO wevtutil cl "%i" =========
 
Failed to clear log Microsoft-Windows-LiveId/Analytic. Access is denied.
Failed to clear log Microsoft-Windows-LiveId/Operational. Access is denied.
 
========= End of CMD: =========
 
 
========= Bitsadmin /Reset /Allusers =========
 
 
BITSADMIN version 3.0
BITS administration utility.
© Copyright Microsoft Corp.
 
Unable to cancel {134C1E2F-C884-4EE6-BED4-9357294907FB}.
Unable to cancel {DF4C4D12-A6A4-4A20-BBDF-018C09CAC4DA}.
Unable to cancel {D438A550-8BBE-4831-A2CA-40B2FAD50E93}.
Unable to cancel {692E66DD-BD76-4356-88C3-83C825215FD5}.
0 out of 4 jobs canceled.
 
========= End of CMD: =========
 
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 10510336 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 121229581 B
Java, Flash, Steam htmlcache => 278519619 B
Windows/system/drivers => 13381181 B
Edge => 8129220 B
Chrome => 888367838 B
Firefox => 0 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 6656 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 43425144 B
LocalService => 0 B
NetworkService => 69230 B
NetworkService => 0 B
xian => 177308411 B
 
RecycleBin => 408260781 B
EmptyTemp: => 1.8 GB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 10:18:37 ====


#12 Xitixen

Xitixen
  • Topic Starter

  • Members
  • 69 posts
  • OFFLINE
  •  
  • Local time:11:02 AM

Posted 26 July 2018 - 03:13 PM

RogueKiller V12.12.28.0 (x64) [Jul 23 2018] (Free) by Adlice Software
 
Operating System : Windows 10 (10.0.17134) 64 bits version
Started in : Normal mode
User : xian [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Delete -- Date : 07/26/2018 10:30:35 (Duration : 02:06:33)
 
¤¤¤ Processes : 0 ¤¤¤
 
¤¤¤ Registry : 0 ¤¤¤
 
¤¤¤ Tasks : 0 ¤¤¤
 
¤¤¤ Files : 0 ¤¤¤
 
¤¤¤ WMI : 0 ¤¤¤
 
¤¤¤ Hosts File : 0 ¤¤¤
 
¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤
 
¤¤¤ Web browsers : 2 ¤¤¤
[PUP.Gen0][Chrome:Addon] Default : Honey [bmnlcjabgnpnenekpadlanbbkooimhnj] -> Deleted
[PUM.HomePage][Chrome:Config] Default [SecurePrefs] : homepage [https://mail.google.com/mail/?shva=1#inbox/1281717902d4583d] -> Deleted
 
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: Samsung SSD 750 EVO 250GB +++++
--- User ---
[MBR] b563c737ef84f53bb5a000af1ae1dc66
[BSP] 9e3b3c473b1db0daa516427cdae6e1cc : Windows Vista/7/8 MBR Code
Partition table:
0 -  | Offset (sectors): 2048 | Size: 450 MB
1 -  | Offset (sectors): 923648 | Size: 99 MB
2 -  | Offset (sectors): 1159168 | Size: 237909 MB
User = LL1 ... OK
User = LL2 ... OK
 
+++++ PhysicalDrive1: NVMe INTEL SSDPEKKW25 +++++
--- User ---
[MBR] a7f77c5835f565e26ea21a5433d4f97b
[BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code
Partition table:
0 -  | Offset (sectors): 2048 | Size: 450 MB
1 - EFI System Partition | Offset (sectors): 923648 | Size: 100 MB
2 -  | Offset (sectors): 1161216 | Size: 243631 MB
User = LL1 ... OK
Error reading LL2 MBR! ([1] Incorrect function. )
 
+++++ PhysicalDrive2: ST31000333AS +++++
--- User ---
[MBR] 9f5c6d7270ed9b5d2784f6452f8ebc63
[BSP] db492d6d8d8f2dfd77c36494c1b1624d : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 953867 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
 
+++++ PhysicalDrive3: TOSHIBA HDWD120 +++++
--- User ---
[MBR] 0086f36f0b7bc8b257f89fc226376c3d
[BSP] 9e3b3c473b1db0daa516427cdae6e1cc : Windows Vista/7/8 MBR Code
Partition table:
0 - Microsoft reserved partition | Offset (sectors): 34 | Size: 128 MB
1 - Basic data partition | Offset (sectors): 264192 | Size: 1907600 MB
User = LL1 ... OK
User = LL2 ... OK
 
+++++ PhysicalDrive4: Hitachi HDS721010CLA630 +++++
--- User ---
[MBR] 53ad2c97fcdbe1f389c511465b6f9a65
[BSP] f98612a450bb8fa044ffa3514c8e2d43 : Empty MBR Code
Partition table:
0 -  | Offset (sectors): 2048 | Size: 1023 MB
1 - EFI System Partition | Offset (sectors): 2097152 | Size: 360 MB
2 -  | Offset (sectors): 3096576 | Size: 931747 MB
3 -  | Offset (sectors): 1911316480 | Size: 450 MB
4 -  | Offset (sectors): 1912238080 | Size: 20159 MB
User = LL1 ... OK
User = LL2 ... OK
 
+++++ PhysicalDrive5: WD easystore 25FB USB Device +++++
--- User ---
[MBR] b749ca3279980e04af4acfc8f6e210f5
[BSP] 7fd284fb52c67c795cf1eb3c56d573d7 : Empty MBR Code
Partition table:
0 - easystore | Offset (sectors): 2048 | Size: 7630883 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] The request is not supported. )
 
+++++ PhysicalDrive6: USB DISK 2.0 USB Device +++++
--- User ---
[MBR] 489555f6a241223a0a80c66a1aa80c12
[BSP] 112835c366ed8cd9ec7660cc2e9749e9 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] FAT32-LBA (0xc) [VISIBLE] Offset (sectors): 8064 | Size: 7382 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] The request is not supported. )


#13 Xitixen

Xitixen
  • Topic Starter

  • Members
  • 69 posts
  • OFFLINE
  •  
  • Local time:11:02 AM

Posted 26 July 2018 - 03:24 PM

# -------------------------------
# Malwarebytes AdwCleaner 7.2.2.0
# -------------------------------
# Build:    07-17-2018
# Database: 2018-07-25.1
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start:    07-26-2018
# Duration: 00:00:21
# OS:       Windows 10 Home
# Scanned:  41737
# Detected: 0
 
 
***** [ Services ] *****
 
No malicious services found.
 
***** [ Folders ] *****
 
No malicious folders found.
 
***** [ Files ] *****
 
No malicious files found.
 
***** [ DLL ] *****
 
No malicious DLLs found.
 
***** [ WMI ] *****
 
No malicious WMI found.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts found.
 
***** [ Tasks ] *****
 
No malicious tasks found.
 
***** [ Registry ] *****
 
No malicious registry entries found.
 
***** [ Chromium (and derivatives) ] *****
 
No malicious Chromium entries found.
 
***** [ Chromium URLs ] *****
 
No malicious Chromium URLs found.
 
***** [ Firefox (and derivatives) ] *****
 
No malicious Firefox entries found.
 
***** [ Firefox URLs ] *****
 
No malicious Firefox URLs found.
 
 
AdwCleaner[S00].txt - [1755 octets] - [25/07/2018 13:46:30]
AdwCleaner[C00].txt - [1809 octets] - [25/07/2018 13:46:55]
 
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S01].txt ##########


#14 Xitixen

Xitixen
  • Topic Starter

  • Members
  • 69 posts
  • OFFLINE
  •  
  • Local time:11:02 AM

Posted 26 July 2018 - 03:25 PM

Took forever for the RogueKiller result, but here we are. All three logs. AdwCleaner found no threats and did not ask to reboot the system, so I didn't. I will if that helps.



#15 Xitixen

Xitixen
  • Topic Starter

  • Members
  • 69 posts
  • OFFLINE
  •  
  • Local time:11:02 AM

Posted 26 July 2018 - 03:30 PM

Actually, it did give the option to run basic repair and reboot anyway - something about resetting Winsock - so I did. We're back.






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users