Results 1 to 10 of 15

Thread: Ransom Page Locked Browser - Windows Doing Strange Things - Is There a Virus?

Threaded View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Member
    Join Date
    Oct 2009
    Posts
    87

    Default Ransom Page Locked Browser - Windows Doing Strange Things - Is There a Virus?

    Hi,

    A couple of ransom pages have locked my Google Chrome browser tabs recently while browsing on totally legit websites, including a Microsoft site and SEO Chat.

    I ran Malwarebytes, Junkware Removal Tool and Adware cleaner after it happened which cleaned a Pokki threat and two others from the PC.

    Over the past few days I have been on lots of website template sites. Although, nothing with an obvious virus seems to have been downloaded, my PC has been doing some strange things, such as a window (not the commend prompt) keeps flashing open and shut really quickly before I have time to read the contents.

    I'm wondering whether something else has been picked up or left behind from the ransom page events.

    I thought it best to be on the safe side and get help, so any would be appreciated.

    Please fine logs attached,

    Thanks.


    aswMBR Log and FRST Below, Addition.txt attached.

    #######################

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 24-05-2017
    Ran by Daniel (administrator) on DANIELS-LAPTOP (27-05-2017 12:01:57)
    Running from C:\Users\Daniel\Desktop
    Loaded Profiles: Daniel (Available Profiles: Daniel & admin & Classic .NET AppPool & .NET v4.5 & DefaultAppPool & .NET v2.0 & .NET v4.5 Classic & .NET v2.0 Classic)
    Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: IE)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Intel Corporation) C:\Windows\System32\igfxCUIService.exe
    (Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe
    (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    () C:\Program Files\MySQL\MySQL Server 5.5\bin\mysqld.exe
    (Microsoft Corporation) C:\Program Files\IIS\Microsoft Web Deploy\MsDepSvc.exe
    (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
    (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
    (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe
    (Intel Corporation) C:\Windows\System32\igfxEM.exe
    (Intel Corporation) C:\Windows\System32\igfxHK.exe
    () C:\Windows\System32\igfxTray.exe
    (Realtek semiconductor) C:\Windows\RTFTrack.exe
    (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
    (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
    (Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (Lenovo) C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe
    (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Microsoft Corporation) C:\Windows\System32\cmd.exe
    (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\McChHost.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
    (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft WebMatrix\WebMatrix.exe
    (Microsoft Corporation) C:\Program Files (x86)\IIS Express\iisexpress.exe
    (Microsoft Corporation) C:\Program Files (x86)\IIS Express\iisexpresstray.exe
    () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1705.1301.0_x64__8wekyb3d8bbwe\Calculator.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.425.10010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft WebMatrix\WebMatrix.exe
    (Microsoft Corporation) C:\Program Files (x86)\IIS Express\iisexpress.exe
    (Intel Security, Inc.) C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
    (McAfee, Inc.) C:\Windows\System32\mfevtps.exe
    (McAfee, Inc.) C:\Windows\System32\mfevtps.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\VSCore_15_6\mcapexe.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\2.3.322.0\McCSPServiceHost.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
    (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (The PHP Group) C:\Program Files (x86)\IIS Express\PHP\v5.5\php-cgi.exe
    (Intel Security) C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Microsoft Corporation) C:\Windows\System32\smartscreen.exe
    (Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe

    ==================== Registry (Whitelisted) ====================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [935104 2014-11-25] (Conexant Systems, Inc.)
    HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc.)
    HKLM\...\Run: [RtsFT] => C:\windows\RTFTrack.exe [9308416 2015-06-02] (Realtek semiconductor)
    HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-31] (Intel Corporation)
    HKLM\...\Run: [IgfxTray] => C:\windows\system32\igfxtray.exe [401912 2017-04-23] ()
    HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [15813616 2013-11-29] (Lenovo(beijing) Limited)
    HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [80880 2013-11-29] (Lenovo(beijing) Limited)
    HKLM\...\Run: [IntelliPoint] => c:\Program Files\Microsoft IntelliPoint\ipoint.exe [2417032 2011-08-01] (Microsoft Corporation)
    HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3944136 2015-06-03] (Synaptics Incorporated)
    HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [303928 2017-05-09] (Apple Inc.)
    HKLM-x32\...\Run: [Lenovo App Shop] => C:\Program Files (x86)\Lenovo\LenovoAppShop\bin\ismagent.exe [156000 2013-07-18] (Intel Corporation)
    HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-07] (CyberLink Corp.)
    HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
    HKU\S-1-5-21-2228433086-130700982-1473003571-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27250144 2016-12-20] (Skype Technologies S.A.)
    HKU\S-1-5-21-2228433086-130700982-1473003571-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2017-05-09] (Apple Inc.)
    HKU\S-1-5-21-2228433086-130700982-1473003571-1001\...\MountPoints2: {0b79a272-a11a-11e6-82dc-201a063ade2a} - "F:\LaunchU3.exe" -a

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
    Tcpip\..\Interfaces\{d63c71ac-4514-4c5e-b7a6-8fa67a67086c}: [DhcpNameServer] 192.168.0.1

    Internet Explorer:
    ==================
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKU\S-1-5-21-2228433086-130700982-1473003571-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKU\S-1-5-21-2228433086-130700982-1473003571-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/
    HKU\S-1-5-21-2228433086-130700982-1473003571-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-05-26] (Microsoft Corporation)
    BHO: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-04-26] (McAfee, Inc.)
    BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-05-26] (Microsoft Corporation)
    BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2017-05-26] (Microsoft Corporation)
    BHO-x32: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-04-26] (McAfee, Inc.)
    BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-05-26] (Microsoft Corporation)
    IE Session Restore: HKU\S-1-5-21-2228433086-130700982-1473003571-1001 -> is enabled.
    Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-26] (Microsoft Corporation)
    Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-26] (Microsoft Corporation)
    Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-26] (Microsoft Corporation)
    Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-26] (Microsoft Corporation)
    Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-04-26] (McAfee, Inc.)
    Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-04-26] (McAfee, Inc.)
    Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll [2017-04-17] (McAfee, Inc.)
    Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2017-04-17] (McAfee, Inc.)

    FireFox:
    ========
    FF ProfilePath: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\egqb8cb4.default-1454922169867 [2017-05-27]
    FF Homepage: Mozilla\Firefox\Profiles\egqb8cb4.default-1454922169867 -> hxxps://www.google.com
    FF Session Restore: Mozilla\Firefox\Profiles\egqb8cb4.default-1454922169867 -> is enabled.
    FF Extension: (FireShot) - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\egqb8cb4.default-1454922169867\Extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba} [2016-09-04]
    FF Extension: (McAfee WebAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi [2017-04-18]
    FF SearchPlugin: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\egqb8cb4.default-1454922169867\searchplugins\McSiteAdvisor.xml [2016-03-11]
    FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
    FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
    FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
    FF Extension: (McAfee Anti-Spam Thunderbird Extension) - C:\Program Files\McAfee\MSK [2017-04-06] [not signed]
    FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_25_0_0_171.dll [2017-05-09] ()
    FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2017-04-17] ()
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_171.dll [2017-05-09] ()
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-08-08] (Intel Corporation)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-08-08] (Intel Corporation)
    FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2017-04-17] ()
    FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-05-26] (Microsoft Corporation)
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-05-26] (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.)
    FF Plugin HKU\S-1-5-21-2228433086-130700982-1473003571-1001: intel.com/AppUp -> C:\Program Files (x86)\Lenovo\LenovoAppShop\bin\npAppUp.dll [2013-07-18] (Intel)
    FF Plugin HKU\S-1-5-21-2228433086-130700982-1473003571-1001: intel.com/AppUpx64 -> C:\Program Files (x86)\Lenovo\LenovoAppShop\bin\npAppUp_x64.dll [2013-07-18] (Intel)

    Chrome:
    =======
    CHR DefaultProfile: Default
    CHR StartupUrls: Default -> "hxxps://www.google.com/"
    CHR Session Restore: Default -> is enabled.
    CHR Profile: C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default [2017-05-27]
    CHR Extension: (Google Slides) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-26]
    CHR Extension: (Google Docs) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-26]
    CHR Extension: (Google Drive) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-06]
    CHR Extension: (YouTube) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-01]
    CHR Extension: (Google Search) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-06]
    CHR Extension: (Google Sheets) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-26]
    CHR Extension: (McAfeeŽ WebAdvisor) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2017-05-26]
    CHR Extension: (Google Docs Offline) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-10-10]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-10]
    CHR Extension: (Gmail) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-09]
    CHR Extension: (Chrome Media Router) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-23]
    CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx

    ==================== Services (Whitelisted) ====================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S2 0202791495808287mcinstcleanup; C:\WINDOWS\TEMP\020279~1.EXE [1030904 2017-02-09] (McAfee, Inc.)
    R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-04-03] (Apple Inc.)
    R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3971264 2017-05-14] (Microsoft Corporation)
    R3 ClientAnalyticsService; C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe [1752992 2017-03-29] (Intel Security)
    R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.)
    S2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-31] (Intel Corporation)
    R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373752 2017-04-23] (Intel Corporation)
    R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-12] (Intel(R) Corporation) [File not signed]
    S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-12] (Intel(R) Corporation)
    R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-08-08] (Intel Corporation)
    S3 LSC.Services.SystemService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSC.Services.SystemService.exe [273232 2016-04-20] (Lenovo)
    R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [188256 2017-04-26] (McAfee, Inc.)
    R2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_15_6\McApExe.exe [994312 2017-04-04] (McAfee, Inc.)
    R2 McBootDelayStartSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.)
    R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\2.3.322.0\\McCSPServiceHost.exe [2054080 2017-02-28] (McAfee, Inc.)
    R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.)
    R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.)
    S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [1344472 2017-02-24] (McAfee, Inc.)
    R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.)
    R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.)
    R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [241040 2017-01-18] (McAfee, Inc.)
    R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [385112 2017-01-18] (McAfee, Inc.)
    R3 mfevtp; C:\WINDOWS\system32\mfevtps.exe [343792 2017-01-18] (McAfee, Inc.)
    R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1551512 2017-02-26] (McAfee, Inc.)
    R2 MsDepSvc; C:\Program Files\IIS\Microsoft Web Deploy\MsDepSvc.exe [88712 2014-09-26] (Microsoft Corporation)
    R3 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.)
    R2 MSSQL$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [62382256 2015-03-30] (Microsoft Corporation)
    R2 MySQL; C:\Program Files\MySQL\MySQL Server 5.5\my.ini [8915 2015-01-10] () [File not signed]
    R2 PEFService; C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe [1104304 2016-11-15] (Intel Security, Inc.)
    R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
    S4 SQLAgent$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [442536 2015-03-30] (Microsoft Corporation)
    R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [249032 2015-06-03] (Synaptics Incorporated)
    S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-28] (Microsoft Corporation)
    S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103712 2017-04-28] (Microsoft Corporation)
    R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-09-07] (Atheros) [File not signed]

    ===================== Drivers (Whitelisted) ======================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [88464 2017-01-20] (McAfee, Inc.)
    S3 HipShieldK; C:\WINDOWS\System32\drivers\HipShieldK.sys [225432 2017-04-01] (McAfee, Inc.)
    R3 MEIx64; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [99288 2013-08-08] (Intel Corporation)
    R3 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [487184 2017-01-20] (McAfee, Inc.)
    R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [366328 2017-01-20] (McAfee, Inc.)
    S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [85048 2017-04-03] (McAfee, Inc.)
    R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [518704 2017-01-20] (McAfee, Inc.)
    R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [923640 2017-01-20] (McAfee, Inc.)
    R3 mfencbdc; C:\WINDOWS\System32\DRIVERS\mfencbdc.sys [498648 2017-01-19] (McAfee, Inc.)
    S3 mfencrk; C:\WINDOWS\System32\DRIVERS\mfencrk.sys [109320 2017-01-19] (McAfee, Inc.)
    R3 mfeplk; C:\WINDOWS\System32\drivers\mfeplk.sys [110256 2017-01-20] (McAfee, Inc.)
    R3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [46240 2016-06-06] (McAfee, Inc.)
    R0 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [254800 2017-01-20] (McAfee, Inc.)
    S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
    S4 RsFx0153; C:\WINDOWS\System32\DRIVERS\RsFx0153.sys [322736 2015-03-30] (Microsoft Corporation)
    S3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [410880 2015-07-03] (Realsil Semiconductor Corporation)
    R3 rtsuvc; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [3057920 2015-06-02] (Realtek Semiconductor Corp.)
    R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-06-03] (Synaptics Incorporated)
    S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
    S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
    S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
    S3 wsvd; C:\WINDOWS\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2017-05-27 12:01 - 2017-05-27 12:04 - 00026422 _____ C:\Users\Daniel\Desktop\FRST.txt
    2017-05-27 12:01 - 2017-05-27 12:01 - 00000000 ____D C:\FRST
    2017-05-27 12:00 - 2017-05-27 12:01 - 02429952 _____ (Farbar) C:\Users\Daniel\Desktop\FRST64.exe
    2017-05-27 11:58 - 2017-05-27 11:58 - 00000000 ____D C:\RegBackup
    2017-05-27 11:57 - 2017-05-27 11:58 - 00018127 _____ C:\WINDOWS\Tweaking.com - Registry Backup Setup Log.txt
    2017-05-27 11:57 - 2017-05-27 11:57 - 00002319 _____ C:\Users\Daniel\Desktop\Tweaking.com - Registry Backup.lnk
    2017-05-27 11:57 - 2017-05-27 11:57 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tweaking.com
    2017-05-27 11:57 - 2017-05-27 11:57 - 00000000 ____D C:\Program Files (x86)\Tweaking.com
    2017-05-27 11:56 - 2017-05-27 11:57 - 05766144 _____ (Tweaking.com) C:\Users\Daniel\Desktop\tweaking.com_registry_backup_setup.exe
    2017-05-26 07:25 - 2017-05-26 07:25 - 00000356 _____ C:\Users\Daniel\Desktop\IntelŽ HD Graphics - Shortcut.lnk
    2017-05-26 07:08 - 2017-05-26 07:08 - 00000000 ____D C:\WINDOWS\LastGood
    2017-05-25 11:46 - 2017-05-25 11:46 - 00000000 _____ C:\WINDOWS\system32\GfxValDisplayLog.bin
    2017-05-25 11:44 - 2017-05-25 11:45 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
    2017-05-18 20:53 - 2017-05-18 20:53 - 00001833 _____ C:\Users\Public\Desktop\iTunes.lnk
    2017-05-18 20:53 - 2017-05-18 20:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
    2017-05-18 20:52 - 2017-05-18 20:53 - 00000000 ____D C:\Program Files\iTunes
    2017-05-18 20:52 - 2017-05-18 20:52 - 00000000 ____D C:\Program Files\iPod
    2017-05-18 20:45 - 2017-05-18 20:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
    2017-05-13 07:12 - 2017-05-13 07:13 - 00000022 _____ C:\Users\Daniel\Downloads\nesdb_2.zip
    2017-05-13 07:06 - 2017-05-13 07:06 - 07013752 _____ (Tim Kosse) C:\Users\Daniel\Downloads\FileZilla_3.25.2_win64-setup.exe
    2017-05-12 17:58 - 2017-05-26 17:50 - 00004222 _____ C:\WINDOWS\System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse
    2017-05-11 14:58 - 2017-04-28 02:28 - 00965472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
    2017-05-11 14:58 - 2017-04-28 01:59 - 00601712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
    2017-05-11 14:58 - 2017-04-28 01:56 - 02048488 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
    2017-05-11 14:58 - 2017-04-28 01:55 - 00088416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\scmbus.sys
    2017-05-11 14:58 - 2017-04-28 01:53 - 00616048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
    2017-05-11 14:58 - 2017-04-28 01:48 - 00263472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
    2017-05-11 14:58 - 2017-04-28 01:46 - 05722320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
    2017-05-11 14:58 - 2017-04-28 01:46 - 01504056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
    2017-05-11 14:58 - 2017-04-28 01:46 - 01431232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
    2017-05-11 14:58 - 2017-04-28 01:45 - 02263832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
    2017-05-11 14:58 - 2017-04-28 01:45 - 00975744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
    2017-05-11 14:58 - 2017-04-28 01:45 - 00861024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
    2017-05-11 14:58 - 2017-04-28 01:45 - 00781144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
    2017-05-11 14:58 - 2017-04-28 01:45 - 00493920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
    2017-05-11 14:58 - 2017-04-28 01:45 - 00116576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll
    2017-05-11 14:58 - 2017-04-28 01:43 - 02168288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
    2017-05-11 14:58 - 2017-04-28 01:43 - 01980768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
    2017-05-11 14:58 - 2017-04-28 01:43 - 01557224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
    2017-05-11 14:58 - 2017-04-28 01:43 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
    2017-05-11 14:58 - 2017-04-28 01:42 - 00601952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
    2017-05-11 14:58 - 2017-04-28 01:41 - 00361104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll
    2017-05-11 14:58 - 2017-04-28 01:40 - 06665952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
    2017-05-11 14:58 - 2017-04-28 01:40 - 04023008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
    2017-05-11 14:58 - 2017-04-28 01:40 - 01851696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
    2017-05-11 14:58 - 2017-04-28 01:40 - 01360456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
    2017-05-11 14:58 - 2017-04-28 01:40 - 01277856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
    2017-05-11 14:58 - 2017-04-28 01:40 - 01202936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
    2017-05-11 14:58 - 2017-04-28 01:40 - 00981888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
    2017-05-11 14:58 - 2017-04-28 01:40 - 00857440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
    2017-05-11 14:58 - 2017-04-28 01:40 - 00352760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MMDevAPI.dll
    2017-05-11 14:58 - 2017-04-28 01:39 - 20967840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
    2017-05-11 14:58 - 2017-04-28 01:39 - 04312248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
    2017-05-11 14:58 - 2017-04-28 01:39 - 00962760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
    2017-05-11 14:58 - 2017-04-28 01:39 - 00715104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
    2017-05-11 14:58 - 2017-04-28 01:38 - 00557408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
    2017-05-11 14:58 - 2017-04-28 01:35 - 01414208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
    2017-05-11 14:58 - 2017-04-28 01:35 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\input.dll
    2017-05-11 14:58 - 2017-04-28 01:29 - 05685760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
    2017-05-11 14:58 - 2017-04-28 01:23 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
    2017-05-11 14:58 - 2017-04-28 01:23 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
    2017-05-11 14:58 - 2017-04-28 01:22 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReInfo.dll
    2017-05-11 14:58 - 2017-04-28 01:22 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
    2017-05-11 14:58 - 2017-04-28 01:21 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll
    2017-05-11 14:58 - 2017-04-28 01:21 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BthTelemetry.dll
    2017-05-11 14:58 - 2017-04-28 01:20 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Radios.dll
    2017-05-11 14:58 - 2017-04-28 01:20 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\virtdisk.dll
    2017-05-11 14:58 - 2017-04-28 01:19 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDeviceRegistration.dll
    2017-05-11 14:58 - 2017-04-28 01:19 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
    2017-05-11 14:58 - 2017-04-28 01:18 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
    2017-05-11 14:58 - 2017-04-28 01:18 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll
    2017-05-11 14:58 - 2017-04-28 01:18 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unimdm.tsp
    2017-05-11 14:58 - 2017-04-28 01:17 - 00328192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
    2017-05-11 14:58 - 2017-04-28 01:17 - 00142336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.WiFi.dll
    2017-05-11 14:58 - 2017-04-28 01:17 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinRtTracing.dll
    2017-05-11 14:58 - 2017-04-28 01:17 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BluetoothApis.dll
    2017-05-11 14:58 - 2017-04-28 01:17 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll
    2017-05-11 14:58 - 2017-04-28 01:16 - 00392192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Input.dll
    2017-05-11 14:58 - 2017-04-28 01:16 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.LowLevel.dll
    2017-05-11 14:58 - 2017-04-28 01:16 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.XboxLive.Storage.dll
    2017-05-11 14:58 - 2017-04-28 01:16 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
    2017-05-11 14:58 - 2017-04-28 01:16 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
    2017-05-11 14:58 - 2017-04-28 01:16 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
    2017-05-11 14:58 - 2017-04-28 01:16 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
    2017-05-11 14:58 - 2017-04-28 01:16 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll
    2017-05-11 14:58 - 2017-04-28 01:16 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Lights.dll
    2017-05-11 14:58 - 2017-04-28 01:15 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
    2017-05-11 14:58 - 2017-04-28 01:15 - 00404992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsreg.dll
    2017-05-11 14:58 - 2017-04-28 01:15 - 00334848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastlsext.dll
    2017-05-11 14:58 - 2017-04-28 01:15 - 00237568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncSettings.dll
    2017-05-11 14:58 - 2017-04-28 01:15 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bthprops.cpl
    2017-05-11 14:58 - 2017-04-28 01:15 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthBroker.dll
    2017-05-11 14:58 - 2017-04-28 01:15 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Core.dll
    2017-05-11 14:58 - 2017-04-28 01:14 - 00670208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.PointOfService.dll
    2017-05-11 14:58 - 2017-04-28 01:14 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.AllJoyn.dll
    2017-05-11 14:58 - 2017-04-28 01:14 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe
    2017-05-11 14:58 - 2017-04-28 01:13 - 13873664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
    2017-05-11 14:58 - 2017-04-28 01:13 - 01755136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll
    2017-05-11 14:58 - 2017-04-28 01:13 - 01243136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.FaceAnalysis.dll
    2017-05-11 14:58 - 2017-04-28 01:13 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.SmartCards.dll
    2017-05-11 14:58 - 2017-04-28 01:13 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll
    2017-05-11 14:58 - 2017-04-28 01:13 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Wallet.dll
    2017-05-11 14:58 - 2017-04-28 01:13 - 00386048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.WiFiDirect.dll
    2017-05-11 14:58 - 2017-04-28 01:13 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
    2017-05-11 14:58 - 2017-04-28 01:13 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll
    2017-05-11 14:58 - 2017-04-28 01:13 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
    2017-05-11 14:58 - 2017-04-28 01:13 - 00271360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
    2017-05-11 14:58 - 2017-04-28 01:13 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WwaApi.dll
    2017-05-11 14:58 - 2017-04-28 01:13 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vaultcli.dll
    2017-05-11 14:58 - 2017-04-28 01:13 - 00202752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll
    2017-05-11 14:58 - 2017-04-28 01:13 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll
    2017-05-11 14:58 - 2017-04-28 01:13 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll
    2017-05-11 14:58 - 2017-04-28 01:13 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll
    2017-05-11 14:58 - 2017-04-28 01:13 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupugc.exe
    2017-05-11 14:58 - 2017-04-28 01:12 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mbsmsapi.dll
    2017-05-11 14:58 - 2017-04-28 01:12 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
    2017-05-11 14:58 - 2017-04-28 01:12 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll
    2017-05-11 14:58 - 2017-04-28 01:12 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Picker.dll
    2017-05-11 14:58 - 2017-04-28 01:11 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebcamUi.dll
    2017-05-11 14:58 - 2017-04-28 01:11 - 00747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Ocr.dll
    2017-05-11 14:58 - 2017-04-28 01:11 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
    2017-05-11 14:58 - 2017-04-28 01:10 - 00857600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
    2017-05-11 14:58 - 2017-04-28 01:10 - 00819200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll
    2017-05-11 14:58 - 2017-04-28 01:10 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NaturalLanguage6.dll
    2017-05-11 14:58 - 2017-04-28 01:10 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprddm.dll
    2017-05-11 14:58 - 2017-04-28 01:10 - 00314368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll
    2017-05-11 14:58 - 2017-04-28 01:10 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.dll
    2017-05-11 14:58 - 2017-04-28 01:10 - 00238080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
    2017-05-11 14:58 - 2017-04-28 01:09 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
    2017-05-11 14:58 - 2017-04-28 01:09 - 00525824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintDialogs.dll
    2017-05-11 14:58 - 2017-04-28 01:09 - 00509440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
    2017-05-11 14:58 - 2017-04-28 01:09 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
    2017-05-11 14:58 - 2017-04-28 01:09 - 00352256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Enumeration.dll
    2017-05-11 14:58 - 2017-04-28 01:08 - 07626752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
    2017-05-11 14:58 - 2017-04-28 01:08 - 01534464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.3D.dll
    2017-05-11 14:58 - 2017-04-28 01:08 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll
    2017-05-11 14:58 - 2017-04-28 01:08 - 00653312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
    2017-05-11 14:58 - 2017-04-28 01:08 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CryptoWinRT.dll
    2017-05-11 14:58 - 2017-04-28 01:07 - 03689984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
    2017-05-11 14:58 - 2017-04-28 01:07 - 00525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
    2017-05-11 14:58 - 2017-04-28 01:07 - 00256512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll
    2017-05-11 14:58 - 2017-04-28 01:06 - 04614656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
    2017-05-11 14:58 - 2017-04-28 01:06 - 02333184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
    2017-05-11 14:58 - 2017-04-28 01:06 - 00901120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
    2017-05-11 14:58 - 2017-04-28 01:06 - 00675840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
    2017-05-11 14:58 - 2017-04-28 01:05 - 03733504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
    2017-05-11 14:58 - 2017-04-28 01:05 - 00886272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
    2017-05-11 14:58 - 2017-04-28 01:05 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
    2017-05-11 14:58 - 2017-04-28 01:05 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
    2017-05-11 14:58 - 2017-04-28 01:04 - 01323008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
    2017-05-11 14:58 - 2017-04-28 01:03 - 01137152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
    2017-05-11 14:58 - 2017-04-28 01:03 - 01077760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll
    2017-05-11 14:58 - 2017-04-28 01:03 - 00355328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTMediaFrame.dll
    2017-05-11 14:58 - 2017-04-28 01:03 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LocationApi.dll
    2017-05-11 14:58 - 2017-04-28 01:03 - 00291328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adsnt.dll
    2017-05-11 14:58 - 2017-04-28 01:03 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Energy.dll
    2017-05-11 14:58 - 2017-04-28 01:02 - 03307008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
    2017-05-11 14:58 - 2017-04-28 01:02 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
    2017-05-11 14:58 - 2017-04-28 01:01 - 00795648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MiracastReceiver.dll
    2017-05-11 14:58 - 2017-04-28 01:01 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
    2017-05-11 14:58 - 2017-04-28 01:01 - 00343040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
    2017-05-11 14:58 - 2017-04-28 01:01 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\unimdm.tsp
    2017-05-11 14:58 - 2017-04-28 01:01 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dlnashext.dll
    2017-05-11 14:58 - 2017-04-28 01:01 - 00233472 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
    2017-05-11 14:58 - 2017-04-28 01:01 - 00141312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dialclient.dll
    2017-05-11 14:58 - 2017-04-28 01:00 - 02749440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
    2017-05-11 14:58 - 2017-04-28 01:00 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
    2017-05-11 14:58 - 2017-04-28 01:00 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinRtTracing.dll
    2017-05-11 14:58 - 2017-04-28 01:00 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Core.dll
    2017-05-11 14:58 - 2017-04-28 00:59 - 02154496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi.dll
    2017-05-11 14:58 - 2017-04-28 00:59 - 00895488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
    2017-05-11 14:58 - 2017-04-28 00:59 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.XboxLive.Storage.dll
    2017-05-11 14:58 - 2017-04-28 00:59 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToReceiver.dll
    2017-05-11 14:58 - 2017-04-28 00:58 - 07468544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
    2017-05-11 14:58 - 2017-04-28 00:58 - 00546304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
    2017-05-11 14:58 - 2017-04-28 00:58 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imapi2.dll
    2017-05-11 14:58 - 2017-04-28 00:58 - 00134144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ErrorDetails.dll
    2017-05-11 14:58 - 2017-04-28 00:58 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
    2017-05-11 14:58 - 2017-04-28 00:57 - 01507840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.FaceAnalysis.dll
    2017-05-11 14:58 - 2017-04-28 00:57 - 01247232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
    2017-05-11 14:58 - 2017-04-28 00:57 - 01221120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
    2017-05-11 14:58 - 2017-04-28 00:57 - 00719872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_sr.dll
    2017-05-11 14:58 - 2017-04-28 00:57 - 00641024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
    2017-05-11 14:58 - 2017-04-28 00:57 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CameraCaptureUI.dll
    2017-05-11 14:58 - 2017-04-28 00:56 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
    2017-05-11 14:58 - 2017-04-28 00:56 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.dll
    2017-05-11 14:58 - 2017-04-28 00:56 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Geolocation.dll
    2017-05-11 14:58 - 2017-04-28 00:56 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
    2017-05-11 14:58 - 2017-04-28 00:56 - 00293888 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
    2017-05-11 14:58 - 2017-04-28 00:56 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll
    2017-05-11 14:58 - 2017-04-28 00:55 - 01993216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
    2017-05-11 14:58 - 2017-04-28 00:55 - 01987584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
    2017-05-11 14:58 - 2017-04-28 00:55 - 01656320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Perception.dll
    2017-05-11 14:58 - 2017-04-28 00:55 - 01413632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpcServices.dll
    2017-05-11 14:58 - 2017-04-28 00:55 - 01232384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Maps.dll
    2017-05-11 14:58 - 2017-04-28 00:55 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
    2017-05-11 14:58 - 2017-04-28 00:55 - 01004544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
    2017-05-11 14:58 - 2017-04-28 00:55 - 00561664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll
    2017-05-11 14:58 - 2017-04-28 00:54 - 02747904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
    2017-05-11 14:58 - 2017-04-28 00:54 - 02646528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
    2017-05-11 14:58 - 2017-04-28 00:54 - 02483200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
    2017-05-11 14:58 - 2017-04-28 00:54 - 01883648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
    2017-05-11 14:58 - 2017-04-28 00:54 - 01013248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
    2017-05-11 14:58 - 2017-04-28 00:54 - 00967680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
    2017-05-11 14:58 - 2017-04-28 00:54 - 00654336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
    2017-05-11 14:58 - 2017-04-28 00:54 - 00598528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
    2017-05-11 14:58 - 2017-04-28 00:54 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
    2017-05-11 14:58 - 2017-04-28 00:54 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll
    2017-05-11 14:58 - 2017-04-28 00:53 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Phone.dll
    2017-05-11 14:58 - 2017-04-28 00:53 - 00798208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
    2017-05-11 14:58 - 2017-04-28 00:53 - 00751104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
    2017-05-11 14:58 - 2017-04-28 00:53 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
    2017-05-11 14:58 - 2017-04-28 00:53 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\WwaApi.dll
    2017-05-11 14:58 - 2017-04-28 00:52 - 03106304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
    2017-05-11 14:58 - 2017-04-28 00:52 - 02994176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
    2017-05-11 14:58 - 2017-04-28 00:52 - 02008576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
    2017-05-11 14:58 - 2017-04-28 00:52 - 01600000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
    2017-05-11 14:58 - 2017-04-28 00:50 - 00783360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
    2017-05-11 14:58 - 2017-04-28 00:44 - 00548864 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
    2017-05-11 14:58 - 2017-04-28 00:43 - 00963584 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebcamUi.dll
    2017-05-11 14:58 - 2017-04-28 00:41 - 01080320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Ocr.dll
    2017-05-11 14:58 - 2017-04-28 00:40 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
    2017-05-11 14:58 - 2017-04-28 00:39 - 04596224 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
    2017-05-11 14:58 - 2017-04-28 00:38 - 02424320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Perception.dll
    2017-05-11 14:58 - 2017-04-28 00:37 - 02538496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
    2017-05-11 14:58 - 2017-04-28 00:37 - 01424896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll
    2017-05-11 14:58 - 2017-04-28 00:37 - 01266176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
    2017-05-11 14:58 - 2017-04-28 00:37 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
    2017-05-11 14:58 - 2017-04-28 00:30 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
    2017-05-11 14:58 - 2017-03-04 08:57 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
    2017-05-11 14:58 - 2017-03-04 07:25 - 01388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
    2017-05-11 14:58 - 2017-03-04 07:23 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
    2017-05-11 14:58 - 2017-03-04 07:22 - 00265728 _____ C:\WINDOWS\SysWOW64\Windows.Perception.Stub.dll
    2017-05-11 14:58 - 2017-03-04 07:17 - 00529920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StructuredQuery.dll
    2017-05-11 14:58 - 2017-03-04 07:16 - 00500224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.dll
    2017-05-11 14:58 - 2017-03-04 07:06 - 01369088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
    2017-05-11 14:58 - 2017-03-04 07:05 - 03520512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
    2017-05-11 14:58 - 2017-03-04 07:01 - 00827904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
    2017-05-11 14:58 - 2017-03-04 07:00 - 00691200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
    2017-05-11 14:57 - 2017-04-28 01:58 - 01706488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
    2017-05-11 14:57 - 2017-04-28 01:57 - 00794928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
    2017-05-11 14:57 - 2017-04-28 01:57 - 00603488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
    2017-05-11 14:57 - 2017-04-28 01:53 - 07784288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
    2017-05-11 14:57 - 2017-04-28 01:53 - 02213760 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
    2017-05-11 14:57 - 2017-04-28 01:53 - 00774224 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
    2017-05-11 14:57 - 2017-04-28 01:49 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll
    2017-05-11 14:57 - 2017-04-28 01:42 - 00328008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
    2017-05-11 14:57 - 2017-04-28 01:40 - 07220184 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
    2017-05-11 14:57 - 2017-04-28 01:40 - 02759704 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
    2017-05-11 14:57 - 2017-04-28 01:40 - 02187104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
    2017-05-11 14:57 - 2017-04-28 01:40 - 01860288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
    2017-05-11 14:57 - 2017-04-28 01:40 - 01738560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
    2017-05-11 14:57 - 2017-04-28 01:40 - 01157000 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
    2017-05-11 14:57 - 2017-04-28 01:40 - 00402784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
    2017-05-11 14:57 - 2017-04-28 01:38 - 00847200 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
    2017-05-11 14:57 - 2017-04-28 01:36 - 00408600 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll
    2017-05-11 14:57 - 2017-04-28 01:36 - 00092512 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
    2017-05-11 14:57 - 2017-04-28 01:35 - 08170600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
    2017-05-11 14:57 - 2017-04-28 01:35 - 04260576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
    2017-05-11 14:57 - 2017-04-28 01:35 - 01988048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
    2017-05-11 14:57 - 2017-04-28 01:35 - 01702392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
    2017-05-11 14:57 - 2017-04-28 01:35 - 01302136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
    2017-05-11 14:57 - 2017-04-28 01:35 - 00596040 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
    2017-05-11 14:57 - 2017-04-28 01:34 - 22220856 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
    2017-05-11 14:57 - 2017-04-28 01:34 - 01277824 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
    2017-05-11 14:57 - 2017-04-28 01:34 - 01072248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
    2017-05-11 14:57 - 2017-04-28 01:34 - 00443232 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMDevAPI.dll
    2017-05-11 14:57 - 2017-04-28 01:34 - 00244824 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
    2017-05-11 14:57 - 2017-04-28 01:28 - 00453536 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
    2017-05-11 14:57 - 2017-04-28 01:28 - 00387864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
    2017-05-11 14:57 - 2017-04-28 01:19 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
    2017-05-11 14:57 - 2017-04-28 01:14 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
    2017-05-11 14:57 - 2017-04-28 01:14 - 00270336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
    2017-05-11 14:57 - 2017-04-28 01:11 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
    2017-05-11 14:57 - 2017-04-28 01:10 - 00661504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
    2017-05-11 14:57 - 2017-04-28 01:08 - 18365440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
    2017-05-11 14:57 - 2017-04-28 01:07 - 00372736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
    2017-05-11 14:57 - 2017-04-28 01:06 - 22569472 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
    2017-05-11 14:57 - 2017-04-28 01:06 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
    2017-05-11 14:57 - 2017-04-28 01:05 - 19414016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
    2017-05-11 14:57 - 2017-04-28 01:04 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
    2017-05-11 14:57 - 2017-04-28 01:03 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\raspppoe.sys
    2017-05-11 14:57 - 2017-04-28 01:03 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
    2017-05-11 14:57 - 2017-04-28 01:02 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bridge.sys
    2017-05-11 14:57 - 2017-04-28 01:02 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwifimp.sys
    2017-05-11 14:57 - 2017-04-28 01:01 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
    2017-05-11 14:57 - 2017-04-28 01:01 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Printers.dll
    2017-05-11 14:57 - 2017-04-28 01:00 - 12349440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
    2017-05-11 14:57 - 2017-04-28 01:00 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
    2017-05-11 14:57 - 2017-04-28 00:59 - 12187136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
    2017-05-11 14:57 - 2017-04-28 00:59 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll
    2017-05-11 14:57 - 2017-04-28 00:59 - 00375296 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastlsext.dll
    2017-05-11 14:57 - 2017-04-28 00:58 - 00418304 _____ C:\WINDOWS\system32\Windows.Perception.Stub.dll
    2017-05-11 14:57 - 2017-04-28 00:58 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
    2017-05-11 14:57 - 2017-04-28 00:58 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
    2017-05-11 14:57 - 2017-04-28 00:58 - 00276992 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
    2017-05-11 14:57 - 2017-04-28 00:58 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
    2017-05-11 14:57 - 2017-04-28 00:58 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Lights.dll
    2017-05-11 14:57 - 2017-04-28 00:57 - 00568320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.LowLevel.dll
    2017-05-11 14:57 - 2017-04-28 00:57 - 00505856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
    2017-05-11 14:57 - 2017-04-28 00:57 - 00502784 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
    2017-05-11 14:57 - 2017-04-28 00:57 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.HumanInterfaceDevice.dll
    2017-05-11 14:57 - 2017-04-28 00:57 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
    2017-05-11 14:57 - 2017-04-28 00:57 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll
    2017-05-11 14:57 - 2017-04-28 00:57 - 00132096 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintWSDAHost.dll
    2017-05-11 14:57 - 2017-04-28 00:56 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.dll
    2017-05-11 14:57 - 2017-04-28 00:56 - 00748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
    2017-05-11 14:57 - 2017-04-28 00:56 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
    2017-05-11 14:57 - 2017-04-28 00:56 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
    2017-05-11 14:57 - 2017-04-28 00:56 - 00311296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll
    2017-05-11 14:57 - 2017-04-28 00:56 - 00260608 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
    2017-05-11 14:57 - 2017-04-28 00:56 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
    2017-05-11 14:57 - 2017-04-28 00:55 - 06042624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
    2017-05-11 14:57 - 2017-04-28 00:55 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
    2017-05-11 14:57 - 2017-04-28 00:55 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Picker.dll
    2017-05-11 14:57 - 2017-04-28 00:55 - 00307200 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs3D.dll
    2017-05-11 14:57 - 2017-04-28 00:55 - 00252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
    2017-05-11 14:57 - 2017-04-28 00:54 - 03664384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
    2017-05-11 14:57 - 2017-04-28 00:54 - 02027008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
    2017-05-11 14:57 - 2017-04-28 00:54 - 01509376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
    2017-05-11 14:57 - 2017-04-28 00:54 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
    2017-05-11 14:57 - 2017-04-28 00:54 - 00472064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
    2017-05-11 14:57 - 2017-04-28 00:54 - 00425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
    2017-05-11 14:57 - 2017-04-28 00:54 - 00284160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
    2017-05-11 14:57 - 2017-04-28 00:53 - 06288384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
    2017-05-11 14:57 - 2017-04-28 00:53 - 03059200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
    2017-05-11 14:57 - 2017-04-28 00:53 - 00671744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mbsmsapi.dll
    2017-05-11 14:57 - 2017-04-28 00:53 - 00579584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll
    2017-05-11 14:57 - 2017-04-28 00:53 - 00437248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll
    2017-05-11 14:57 - 2017-04-28 00:51 - 02104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
    2017-05-11 14:57 - 2017-04-28 00:51 - 01589760 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
    2017-05-11 14:57 - 2017-04-28 00:51 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
    2017-05-11 14:57 - 2017-04-28 00:51 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTMediaFrame.dll
    2017-05-11 14:57 - 2017-04-28 00:51 - 00409600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
    2017-05-11 14:57 - 2017-04-28 00:50 - 03778048 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
    2017-05-11 14:57 - 2017-04-28 00:50 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
    2017-05-11 14:57 - 2017-04-28 00:49 - 17198592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
    2017-05-11 14:57 - 2017-04-28 00:49 - 01105408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MiracastReceiver.dll
    2017-05-11 14:57 - 2017-04-28 00:49 - 00864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
    2017-05-11 14:57 - 2017-04-28 00:49 - 00442368 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
    2017-05-11 14:57 - 2017-04-28 00:47 - 01908224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
    2017-05-11 14:57 - 2017-04-28 00:47 - 01078784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
    2017-05-11 14:57 - 2017-04-28 00:47 - 00796672 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
    2017-05-11 14:57 - 2017-04-28 00:47 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceControl.dll
    2017-05-11 14:57 - 2017-04-28 00:46 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToReceiver.dll
    2017-05-11 14:57 - 2017-04-28 00:45 - 23677440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
    2017-05-11 14:57 - 2017-04-28 00:45 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
    2017-05-11 14:57 - 2017-04-28 00:45 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
    2017-05-11 14:57 - 2017-04-28 00:44 - 13091328 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
    2017-05-11 14:57 - 2017-04-28 00:44 - 01366016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
    2017-05-11 14:57 - 2017-04-28 00:44 - 01145344 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
    2017-05-11 14:57 - 2017-04-28 00:44 - 00937984 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
    2017-05-11 14:57 - 2017-04-28 00:44 - 00583680 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs.dll
    2017-05-11 14:57 - 2017-04-28 00:43 - 01184256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
    2017-05-11 14:57 - 2017-04-28 00:43 - 00646656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiaservc.dll
    2017-05-11 14:57 - 2017-04-28 00:43 - 00539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
    2017-05-11 14:57 - 2017-04-28 00:43 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
    2017-05-11 14:57 - 2017-04-28 00:43 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Geolocation.dll
    2017-05-11 14:57 - 2017-04-28 00:43 - 00331264 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrSvc.dll
    2017-05-11 14:57 - 2017-04-28 00:42 - 13441536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
    2017-05-11 14:57 - 2017-04-28 00:42 - 08125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
    2017-05-11 14:57 - 2017-04-28 00:42 - 08076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
    2017-05-11 14:57 - 2017-04-28 00:42 - 02390016 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
    2017-05-11 14:57 - 2017-04-28 00:42 - 00945664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
    2017-05-11 14:57 - 2017-04-28 00:42 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
    2017-05-11 14:57 - 2017-04-28 00:41 - 00983040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
    2017-05-11 14:57 - 2017-04-28 00:41 - 00860160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprddm.dll
    2017-05-11 14:57 - 2017-04-28 00:41 - 00759296 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
    2017-05-11 14:57 - 2017-04-28 00:41 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
    2017-05-11 14:57 - 2017-04-28 00:41 - 00611328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.dll
    2017-05-11 14:57 - 2017-04-28 00:40 - 04474368 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
    2017-05-11 14:57 - 2017-04-28 00:40 - 02208768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll
    2017-05-11 14:57 - 2017-04-28 00:40 - 02096640 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
    2017-05-11 14:57 - 2017-04-28 00:40 - 01040896 _____ (Microsoft Corporation) C:\WINDOWS\system32\NaturalLanguage6.dll
    2017-05-11 14:57 - 2017-04-28 00:40 - 00913920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
    2017-05-11 14:57 - 2017-04-28 00:39 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
    2017-05-11 14:57 - 2017-04-28 00:38 - 05611008 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
    2017-05-11 14:57 - 2017-04-28 00:38 - 01359360 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
    2017-05-11 14:57 - 2017-04-28 00:38 - 01275392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
    2017-05-11 14:57 - 2017-04-28 00:38 - 00765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
    2017-05-11 14:57 - 2017-04-28 00:37 - 04744192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
    2017-05-11 14:57 - 2017-04-28 00:37 - 04149248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
    2017-05-11 14:57 - 2017-04-28 00:37 - 03134976 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
    2017-05-11 14:57 - 2017-04-28 00:37 - 02895872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
    2017-05-11 14:57 - 2017-04-28 00:37 - 02286592 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
    2017-05-11 14:57 - 2017-04-28 00:37 - 01984000 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
    2017-05-11 14:57 - 2017-04-28 00:37 - 01783296 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
    2017-05-11 14:57 - 2017-04-28 00:37 - 01637888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
    2017-05-11 14:57 - 2017-04-28 00:37 - 00875520 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
    2017-05-11 14:57 - 2017-04-28 00:36 - 02691072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
    2017-05-11 14:57 - 2017-04-28 00:36 - 02478080 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
    2017-05-11 14:57 - 2017-04-28 00:36 - 01844224 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
    2017-05-11 14:57 - 2017-04-28 00:36 - 01513472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
    2017-05-11 14:57 - 2017-04-28 00:36 - 01328640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
    2017-05-11 14:57 - 2017-04-28 00:36 - 01131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
    2017-05-11 14:57 - 2017-04-28 00:36 - 00774656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
    2017-05-11 14:57 - 2017-04-28 00:36 - 00735744 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
    2017-05-11 14:57 - 2017-04-28 00:35 - 03299840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
    2017-05-11 14:57 - 2017-04-28 00:35 - 01121280 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
    2017-05-11 14:57 - 2017-04-28 00:35 - 00924672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
    2017-05-11 14:57 - 2017-04-28 00:34 - 00999424 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
    2017-05-11 14:57 - 2017-04-28 00:34 - 00439296 _____ (Microsoft Corporation) C:\WINDOWS\system32\wksprt.exe
    2017-05-11 14:57 - 2017-04-28 00:34 - 00394240 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
    2017-05-11 14:57 - 2017-03-04 08:09 - 01293152 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
    2017-05-11 14:57 - 2017-03-04 07:27 - 00456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
    2017-05-11 14:57 - 2017-03-04 07:26 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll
    2017-05-11 14:57 - 2017-03-04 07:19 - 01403392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll
    2017-05-11 14:56 - 2017-04-28 01:40 - 00026976 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser_broker.exe
    2017-05-11 14:56 - 2017-04-28 01:38 - 02446704 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
    2017-05-11 14:56 - 2017-04-28 01:38 - 00431968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
    2017-05-11 14:56 - 2017-04-28 01:34 - 01600624 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
    2017-05-11 14:56 - 2017-04-28 01:34 - 00241504 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
    2017-05-11 14:56 - 2017-04-28 01:30 - 01569184 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
    2017-05-11 14:56 - 2017-04-28 01:21 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
    2017-05-11 14:56 - 2017-04-28 01:15 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
    2017-05-11 14:56 - 2017-04-28 01:15 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
    2017-05-11 14:56 - 2017-04-28 01:12 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
    2017-05-11 14:56 - 2017-04-28 01:12 - 00236544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
    2017-05-11 14:56 - 2017-04-28 01:10 - 07216640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
    2017-05-11 14:56 - 2017-04-28 01:05 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
    2017-05-11 14:56 - 2017-04-28 01:03 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
    2017-05-11 14:56 - 2017-04-28 01:01 - 00259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.SyncEngine.dll
    2017-05-11 14:56 - 2017-04-28 01:01 - 00156160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.Client.dll
    2017-05-11 14:56 - 2017-04-28 01:00 - 00196096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.dll
    2017-05-11 14:56 - 2017-04-28 01:00 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFi.dll
    2017-05-11 14:56 - 2017-04-28 01:00 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.Ngc.dll
    2017-05-11 14:56 - 2017-04-28 01:00 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
    2017-05-11 14:56 - 2017-04-28 00:59 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Radios.dll
    2017-05-11 14:56 - 2017-04-28 00:58 - 00547840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Input.dll
    2017-05-11 14:56 - 2017-04-28 00:58 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
    2017-05-11 14:56 - 2017-04-28 00:57 - 00651264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
    2017-05-11 14:56 - 2017-04-28 00:57 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
    2017-05-11 14:56 - 2017-04-28 00:57 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
    2017-05-11 14:56 - 2017-04-28 00:57 - 00139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
    2017-05-11 14:56 - 2017-04-28 00:56 - 00692224 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
    2017-05-11 14:56 - 2017-04-28 00:56 - 00691200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
    2017-05-11 14:56 - 2017-04-28 00:56 - 00379904 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
    2017-05-11 14:56 - 2017-04-28 00:56 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
    2017-05-11 14:56 - 2017-04-28 00:56 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll
    2017-05-11 14:56 - 2017-04-28 00:55 - 02084352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll
    2017-05-11 14:56 - 2017-04-28 00:55 - 00657920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
    2017-05-11 14:56 - 2017-04-28 00:55 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
    2017-05-11 14:56 - 2017-04-28 00:55 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll
    2017-05-11 14:56 - 2017-04-28 00:55 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
    2017-05-11 14:56 - 2017-04-28 00:54 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll
    2017-05-11 14:56 - 2017-04-28 00:54 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
    2017-05-11 14:56 - 2017-04-28 00:53 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Enumeration.dll
    2017-05-11 14:56 - 2017-04-28 00:51 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Energy.dll
    2017-05-11 14:56 - 2017-04-28 00:48 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll
    2017-05-11 14:56 - 2017-04-28 00:48 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialclient.dll
    2017-05-11 14:56 - 2017-04-28 00:47 - 09131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
    2017-05-11 14:56 - 2017-04-28 00:47 - 01790464 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
    2017-05-11 14:56 - 2017-04-28 00:46 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvps.dll
    2017-05-11 14:56 - 2017-04-28 00:45 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
    2017-05-11 14:56 - 2017-04-28 00:45 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ErrorDetails.dll
    2017-05-11 14:56 - 2017-04-28 00:45 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\CameraCaptureUI.dll
    2017-05-11 14:56 - 2017-04-28 00:44 - 04749824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
    2017-05-11 14:56 - 2017-04-28 00:44 - 01010176 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
    2017-05-11 14:56 - 2017-04-28 00:44 - 00896512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
    2017-05-11 14:56 - 2017-04-28 00:44 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
    2017-05-11 14:56 - 2017-04-28 00:44 - 00410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicesFlowBroker.dll
    2017-05-11 14:56 - 2017-04-28 00:44 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll
    2017-05-11 14:56 - 2017-04-28 00:43 - 00634368 _____ (Microsoft Corporation) C:\WINDOWS\system32\StructuredQuery.dll
    2017-05-11 14:56 - 2017-04-28 00:43 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll
    2017-05-11 14:56 - 2017-04-28 00:43 - 00320512 _____ (Microsoft Corporation) C:\WINDOWS\system32\thumbcache.dll
    2017-05-11 14:56 - 2017-04-28 00:42 - 01692160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
    2017-05-11 14:56 - 2017-04-28 00:41 - 01359872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
    2017-05-11 14:56 - 2017-04-28 00:41 - 00591360 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
    2017-05-11 14:56 - 2017-04-28 00:41 - 00376832 _____ (Microsoft Corporation) C:\WINDOWS\system32\CryptoWinRT.dll
    2017-05-11 14:56 - 2017-04-28 00:40 - 02914816 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
    2017-05-11 14:56 - 2017-04-28 00:40 - 01643008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
    2017-05-11 14:56 - 2017-04-28 00:40 - 01586176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
    2017-05-11 14:56 - 2017-04-28 00:40 - 00971264 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
    2017-05-11 14:56 - 2017-04-28 00:37 - 02316288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
    2017-05-11 14:56 - 2017-04-28 00:36 - 03613184 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
    2017-05-11 14:56 - 2017-04-28 00:36 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
    2017-05-11 14:56 - 2017-03-04 07:25 - 01060352 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll
    2017-05-11 14:55 - 2017-04-28 01:56 - 01117024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
    2017-05-11 14:55 - 2017-04-28 01:52 - 02255712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
    2017-05-11 14:55 - 2017-04-28 01:49 - 00764392 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
    2017-05-11 14:55 - 2017-04-28 01:49 - 00700936 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
    2017-05-11 14:55 - 2017-04-28 01:47 - 00699744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
    2017-05-11 14:55 - 2017-04-28 01:47 - 00501088 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizeng.dll
    2017-05-11 14:55 - 2017-04-28 01:46 - 00410464 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
    2017-05-11 14:55 - 2017-04-28 01:44 - 00062816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fsdepends.sys
    2017-05-11 14:55 - 2017-04-28 01:42 - 00526176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
    2017-05-11 14:55 - 2017-04-28 01:40 - 00578400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
    2017-05-11 14:55 - 2017-04-28 01:40 - 00146784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
    2017-05-11 14:55 - 2017-04-28 01:39 - 00624048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
    2017-05-11 14:55 - 2017-04-28 01:38 - 02915704 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
    2017-05-11 14:55 - 2017-04-28 01:38 - 01852200 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
    2017-05-11 14:55 - 2017-04-28 01:38 - 01267512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
    2017-05-11 14:55 - 2017-04-28 01:34 - 04674360 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
    2017-05-11 14:55 - 2017-04-28 01:30 - 00322912 _____ (Microsoft Corporation) C:\WINDOWS\system32\input.dll
    2017-05-11 14:55 - 2017-04-28 01:28 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
    2017-05-11 14:55 - 2017-04-28 01:19 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
    2017-05-11 14:55 - 2017-04-28 01:03 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
    2017-05-11 14:55 - 2017-04-28 01:03 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthTelemetry.dll
    2017-05-11 14:55 - 2017-04-28 01:02 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidcertstorecheck.exe
    2017-05-11 14:55 - 2017-04-28 01:01 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_ClosedCaptioning.dll
    2017-05-11 14:55 - 2017-04-28 01:01 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\virtdisk.dll
    2017-05-11 14:55 - 2017-04-28 01:00 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Profile.RetailInfo.dll
    2017-05-11 14:55 - 2017-04-28 01:00 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll
    2017-05-11 14:55 - 2017-04-28 01:00 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
    2017-05-11 14:55 - 2017-04-28 00:59 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
    2017-05-11 14:55 - 2017-04-28 00:59 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidsvc.dll
    2017-05-11 14:55 - 2017-04-28 00:59 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
    2017-05-11 14:55 - 2017-04-28 00:58 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
    2017-05-11 14:55 - 2017-04-28 00:58 - 00150016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
    2017-05-11 14:55 - 2017-04-28 00:58 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsentUX.dll
    2017-05-11 14:55 - 2017-04-28 00:57 - 00241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
    2017-05-11 14:55 - 2017-04-28 00:57 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthserv.dll
    2017-05-11 14:55 - 2017-04-28 00:56 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
    2017-05-11 14:55 - 2017-04-28 00:56 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultcli.dll
    2017-05-11 14:55 - 2017-04-28 00:56 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
    2017-05-11 14:55 - 2017-04-28 00:55 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthprops.cpl
    2017-05-11 14:55 - 2017-04-28 00:54 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
    2017-05-11 14:55 - 2017-04-28 00:51 - 01913856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
    2017-05-11 14:55 - 2017-04-28 00:51 - 01584128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
    2017-05-11 14:55 - 2017-04-28 00:50 - 01476608 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
    2017-05-11 14:55 - 2017-04-28 00:50 - 00380416 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationApi.dll
    2017-05-11 14:55 - 2017-04-28 00:50 - 00338944 _____ (Microsoft Corporation) C:\WINDOWS\system32\adsnt.dll
    2017-05-11 14:55 - 2017-04-28 00:48 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
    2017-05-11 14:55 - 2017-04-28 00:47 - 03290112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
    2017-05-11 14:55 - 2017-04-28 00:47 - 00942080 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
    2017-05-11 14:55 - 2017-04-28 00:47 - 00649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\vds.exe
    2017-05-11 14:55 - 2017-04-28 00:46 - 02861056 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll
    2017-05-11 14:55 - 2017-04-28 00:46 - 01547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe
    2017-05-11 14:55 - 2017-04-28 00:46 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe
    2017-05-11 14:55 - 2017-04-28 00:46 - 00501248 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi2.dll
    2017-05-11 14:55 - 2017-04-28 00:46 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
    2017-05-11 14:55 - 2017-04-28 00:45 - 00946688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_sr.dll
    2017-05-11 14:55 - 2017-04-28 00:45 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
    2017-05-11 14:55 - 2017-04-28 00:45 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceAgent.exe
    2017-05-11 14:55 - 2017-04-28 00:43 - 00600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll
    2017-05-11 14:55 - 2017-04-28 00:43 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
    2017-05-11 14:55 - 2017-04-28 00:42 - 01021440 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
    2017-05-11 14:55 - 2017-04-28 00:41 - 00890368 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
    2017-05-11 14:55 - 2017-04-28 00:41 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
    2017-05-11 14:55 - 2017-04-28 00:40 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
    2017-05-11 14:55 - 2017-04-28 00:40 - 00886784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
    2017-05-11 14:55 - 2017-04-28 00:40 - 00770560 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
    2017-05-11 14:55 - 2017-04-28 00:39 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
    2017-05-11 14:55 - 2017-04-28 00:38 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
    2017-05-11 14:55 - 2017-04-28 00:37 - 02216960 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll
    2017-05-11 14:55 - 2017-04-28 00:37 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
    2017-05-11 14:55 - 2017-04-28 00:34 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\spaceman.exe
    2017-05-11 14:55 - 2017-04-28 00:33 - 01817088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
    2017-05-11 14:55 - 2016-12-21 08:09 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneBackupHandler.dll
    2017-05-08 17:24 - 2017-05-10 15:18 - 00000000 ____D C:\Users\Daniel\Documents\My_Custom_Apps
    2017-05-08 17:11 - 2017-05-08 17:12 - 44347808 _____ C:\Users\Daniel\Downloads\Unconfirmed 109536.crdownload
    2017-05-05 12:51 - 2017-05-05 12:51 - 00251832 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\462F7680.sys
    2017-05-05 12:25 - 2017-05-05 12:26 - 60107896 _____ (Malwarebytes ) C:\Users\Daniel\Downloads\mb3-setup-consumer-3.0.6.1469-10103.exe

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2017-05-27 10:39 - 2017-03-30 08:24 - 00004034 _____ C:\WINDOWS\System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse
    2017-05-27 10:25 - 2016-12-14 17:55 - 00000000 ____D C:\Program Files\Common Files\McAfee
    2017-05-27 10:25 - 2016-07-16 12:47 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
    2017-05-27 10:23 - 2016-12-14 18:00 - 00003126 _____ C:\WINDOWS\System32\Tasks\McAfeeLogon
    2017-05-27 10:23 - 2016-12-14 18:00 - 00000000 ____D C:\WINDOWS\System32\Tasks\McAfee
    2017-05-27 10:23 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF
    2017-05-27 10:06 - 2016-09-27 21:01 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
    2017-05-27 08:43 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness
    2017-05-27 07:44 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps
    2017-05-26 07:41 - 2016-07-16 12:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2017-05-26 07:35 - 2013-11-29 16:47 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
    2017-05-26 07:15 - 2016-11-19 10:21 - 00000000 ____D C:\Users\Daniel\AppData\LocalLow\Mozilla
    2017-05-26 07:15 - 2016-11-18 09:19 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
    2017-05-26 07:15 - 2014-12-16 11:52 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2017-05-26 07:08 - 2016-09-27 21:05 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
    2017-05-26 07:08 - 2015-08-02 18:30 - 00000000 __SHD C:\Users\Daniel\IntelGraphicsProfiles
    2017-05-26 07:06 - 2016-09-27 22:12 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2017-05-26 07:05 - 2016-07-16 07:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
    2017-05-25 11:46 - 2016-09-27 21:05 - 00000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
    2017-05-24 11:29 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
    2017-05-24 11:29 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp
    2017-05-24 11:28 - 2015-01-10 16:27 - 00000000 ____D C:\Users\Daniel\Documents\My Web Sites
    2017-05-23 12:58 - 2014-12-16 11:32 - 00000000 ____D C:\WINDOWS\system32\MRT
    2017-05-23 12:53 - 2014-12-16 11:32 - 132223576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
    2017-05-23 07:22 - 2016-07-16 07:04 - 00008192 _____ C:\WINDOWS\system32\config\ELAM
    2017-05-21 12:02 - 2015-01-15 20:39 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\FileZilla
    2017-05-19 20:41 - 2015-06-30 09:44 - 00000000 ____D C:\Users\Daniel\Documents\House
    2017-05-19 06:41 - 2014-12-15 20:41 - 00000000 ____D C:\Users\Daniel\AppData\Local\Packages
    2017-05-16 18:25 - 2015-02-26 12:46 - 00002283 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
    2017-05-16 18:25 - 2015-02-26 12:46 - 00002271 _____ C:\Users\Public\Desktop\Google Chrome.lnk
    2017-05-13 12:37 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\rescache
    2017-05-13 07:07 - 2016-05-14 14:20 - 00002173 _____ C:\Users\Daniel\Desktop\FileZilla Client.lnk
    2017-05-13 07:07 - 2015-02-06 20:22 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
    2017-05-13 07:07 - 2015-02-06 20:22 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client
    2017-05-12 15:05 - 2014-12-16 04:03 - 00000000 __RHD C:\Users\Public\AccountPictures
    2017-05-12 15:04 - 2016-09-27 21:12 - 01234294 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2017-05-12 14:59 - 2016-09-27 21:01 - 00477192 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2017-05-12 08:59 - 2016-07-16 12:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
    2017-05-12 08:59 - 2016-07-16 12:47 - 00000000 ___SD C:\WINDOWS\system32\F12
    2017-05-12 08:59 - 2016-07-16 12:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
    2017-05-12 08:59 - 2016-07-16 12:47 - 00000000 ___RD C:\Program Files\Windows Defender
    2017-05-12 08:59 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
    2017-05-12 08:59 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
    2017-05-12 08:59 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\oobe
    2017-05-12 08:59 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\inetsrv
    2017-05-12 08:59 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
    2017-05-12 08:59 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\Provisioning
    2017-05-12 08:59 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
    2017-05-12 08:59 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files\Windows Photo Viewer
    2017-05-12 08:59 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
    2017-05-12 08:59 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files (x86)\Windows Defender
    2017-05-12 08:59 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
    2017-05-11 14:22 - 2016-07-16 12:42 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManMigrationPlugin.dll
    2017-05-11 07:10 - 2016-12-16 13:55 - 00004552 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
    2017-05-11 07:10 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
    2017-05-11 07:10 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
    2017-05-10 14:21 - 2015-01-10 16:27 - 00000000 ____D C:\Users\Daniel\Documents\IISExpress
    2017-05-10 12:22 - 2015-01-07 11:33 - 00000000 ____D C:\Users\Daniel\Documents\Bigint
    2017-05-06 06:37 - 2016-09-27 22:12 - 00004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
    2017-05-05 13:30 - 2015-07-15 14:30 - 00000000 ____D C:\ProgramData\Malwarebytes
    2017-05-05 13:29 - 2015-07-17 09:57 - 00000461 _____ C:\DelFix.txt
    2017-05-05 13:07 - 2015-09-15 22:56 - 00000000 ____D C:\Users\Daniel\Documents\Lenovo_PC
    2017-04-29 01:59 - 2016-07-16 12:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
    2017-04-29 01:59 - 2016-07-16 12:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
    2017-04-28 02:01 - 2016-09-27 21:04 - 02717184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
    2017-04-27 19:03 - 2016-09-27 22:12 - 00003416 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
    2017-04-27 19:03 - 2016-09-27 22:12 - 00003292 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore

    ==================== Files in the root of some directories =======

    2014-12-29 09:10 - 2014-12-29 09:10 - 0000036 _____ () C:\Program Files\smaple.txt
    2015-09-12 13:24 - 2016-01-01 17:15 - 0000600 _____ () C:\Users\Daniel\AppData\Local\PUTTY.RND
    2016-08-26 09:03 - 2016-08-26 09:03 - 0000000 _____ () C:\Users\Daniel\AppData\Local\{7A836782-D708-423D-A0A5-D54A2F04DEA5}
    2015-10-29 10:54 - 2015-10-29 10:54 - 0000000 _____ () C:\Users\Daniel\AppData\Local\{D2B08EFA-5186-40F3-B6D3-1B97F1EBFECC}
    2016-09-27 21:06 - 2016-09-27 21:06 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

    ==================== Bamital & volsnap ======================

    (There is no automatic fix for files that do not pass verification.)

    C:\WINDOWS\system32\winlogon.exe => File is digitally signed
    C:\WINDOWS\system32\wininit.exe => File is digitally signed
    C:\WINDOWS\explorer.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
    C:\WINDOWS\system32\svchost.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
    C:\WINDOWS\system32\services.exe => File is digitally signed
    C:\WINDOWS\system32\User32.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
    C:\WINDOWS\system32\userinit.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
    C:\WINDOWS\system32\rpcss.dll => File is digitally signed
    C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
    C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

    LastRegBack: 2017-05-23 08:19

    ==================== End of FRST.txt ============================

    aswMBR version 1.0.1.2252 Copyright(c) 2014 AVAST Software
    Run date: 2017-05-27 12:13:17
    -----------------------------
    12:13:17.001 OS Version: Windows x64 6.2.9200
    12:13:17.001 Number of processors: 8 586 0x3C03
    12:13:17.001 ComputerName: DANIELS-LAPTOP UserName: Daniel
    12:13:23.624 Initialize success
    12:13:23.852 VM: initialized successfully
    12:13:23.852 VM: Intel CPU BiosDisabled
    12:15:49.179 AVAST engine defs: 17030301
    12:16:06.538 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000031
    12:16:06.540 Disk 0 Vendor: ST1000LM024_HN-M101MBB 2BA30001 Size: 953869MB BusType: 11
    12:16:06.676 Disk 0 MBR read successfully
    12:16:06.682 Disk 0 MBR scan
    12:16:06.731 Disk 0 unknown MBR code
    12:16:06.735 Disk 0 Partition 1 00 EE GPT 2097151 MB offset 1
    12:16:06.756 Disk 0 scanning C:\WINDOWS\system32\drivers
    12:16:19.865 Service scanning
    12:16:48.017 Modules scanning
    12:16:48.034 Disk 0 trace - called modules:
    12:16:48.190 ntoskrnl.exe CLASSPNP.SYS disk.sys storport.sys hal.dll iaStorA.sys
    12:16:48.597 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffcc004c49b510]
    12:16:48.604 3 CLASSPNP.SYS[fffff803d2ff5efb] -> nt!IofCallDriver -> \Device\00000031[0xffffcc0049fac400]
    12:16:49.522 AVAST engine scan C:\WINDOWS
    12:16:52.185 AVAST engine scan C:\WINDOWS\system32
    12:19:42.604 AVAST engine scan C:\WINDOWS\system32\drivers
    12:20:00.721 AVAST engine scan C:\Users\Daniel
    12:37:57.567 Disk 0 MBR has been saved successfully to "C:\Users\Daniel\Desktop\MBR.dat"
    12:37:57.571 The log file has been saved successfully to "C:\Users\Daniel\Desktop\27-5-17-aswMBR.txt"
    Attached Files Attached Files

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •