Page 1 of 2 12 LastLast
Results 1 to 10 of 15

Thread: new lenovo...

  1. #1
    Senior Member
    Join Date
    Feb 2008
    Location
    L.A. (Lower Arkansas)
    Posts
    381

    Default new lenovo...

    was doing fine until maybe a week ago I had a previous problem show up again that had visited my old desktop. that was the odd Microsoft overtake of my browser that all I could do was end task in task manager of the browser. it's where suddenly your browser is taken over by a Microsoft rep (supposedly) informing of my computer is spreading virus at several websites and i'm to click a link for help. since it has slowed this normally fast LT down, noticed erratic browser behavior crashing frequently, scrolling issues so I thought i'd come say hello to you kind people. on installing the aswMBR, when i'd select yes on the virtualization twice it crashed my pc.

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11.03.2019
    Ran by ronny (administrator) on LAPTOP-7SS3QTOI (11-03-2019 22:47:49)
    Running from C:\Users\ronny\Desktop
    Loaded Profiles: ronny (Available Profiles: ronny)
    Platform: Windows 10 Home Version 1809 17763.316 (X64) Language: English (United States)
    Default browser: "C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe" "%1"
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\igfxCUIService.exe
    (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
    (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) C:\Windows\System32\drivers\AdminService.exe
    (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\IntelCpHDCPSvc.exe
    (Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.) C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe
    (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\jhi_service.exe
    (Qualcomm Atheros -> Qualcomm Technologies Inc.) C:\Windows\System32\drivers\QcomWlanSrvx64.exe
    (Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnhService.exe
    (Lenovo -> Lenovo Group Ltd.) C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
    (Logitech Inc -> Logitech) C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe
    (Microsoft Corporation -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1902.2-0\MsMpEng.exe
    (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\IntelCpHeciSvc.exe
    (Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
    (Logitech Inc -> Logitech Europe S.A.) C:\Program Files\Logitech\Collaboration\Services\Video\RightSightAPI\RightSightService.exe
    (Logitech Inc -> ) C:\Program Files\Logitech\Collaboration\Services\Video\RightSightAPI\crashpad_handler.exe
    (Microsoft Corporation -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1902.2-0\NisSrv.exe
    (Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
    (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
    (Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnh.exe
    (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\igfxEM.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
    () [File not signed] C:\Program Files\WindowsApps\Microsoft.YourPhone_1.0.20453.0_x64__8wekyb3d8bbwe\YourPhone.exe
    (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.10314.31700.1000_x64__8wekyb3d8bbwe\Office16\OfficeHubTaskHost.exe
    (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    () [File not signed] C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19021.10411.0_x64__8wekyb3d8bbwe\Video.UI.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
    (Logitech Inc -> Logitech, Inc.) C:\Program Files\Logitech\LogiOptions\LogiOptions.exe
    (Logitech Inc -> Logitech, Inc.) C:\ProgramData\LogiShrd\LogiOptions\Software\Current\LogiOptionsMgr.exe
    (Logitech Inc -> Logitech) C:\ProgramData\LogiShrd\LogiOptions\Software\Current\LogiOverlay.exe
    (Logitech Inc -> Logitech, Inc.) C:\ProgramData\LogiShrd\LogiOptions\Software\Current\laclient\laclient.exe
    (Lenovo -> Lenovo(beijing) Limited) C:\Program Files\WindowsApps\E0469640.LenovoUtility_3.0.50.0_x64__5grkq8ppsgwt4\VFS\ProgramFilesX64\Lenovo\LenovoUtility\utility.exe
    (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    (Logitech, Inc. -> Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
    (Logitech, Inc. -> ) C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
    (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    (SweetLabs Inc. -> SweetLabs, Inc) C:\Users\ronny\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
    (Lenovo (Beijing) Limited -> Lenovo Group Limited) C:\Users\ronny\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSB.exe
    (Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.WindowsStore_11811.1001.18.0_x64__8wekyb3d8bbwe\WinStore.App.exe
    (Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
    () [File not signed] C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.18114.17710.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
    (Lenovo -> Lenovo Group Ltd.) C:\Program Files (x86)\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
    (Lenovo -> Lenovo Group Ltd.) C:\Program Files\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.SettingsApp.exe
    (Lenovo -> Lenovo Group Ltd.) C:\Program Files\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.CompanionApp.exe
    (Lenovo -> Lenovo Group Ltd.) C:\Program Files (x86)\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
    (Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
    (Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
    (Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
    (Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
    (Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
    (Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
    (Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SndVol.exe
    (Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
    (Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
    (Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
    (Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe

    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [LogiOptions] => C:\Program Files\Logitech\LogiOptions\LogiOptions.exe [2176648 2018-12-14] (Logitech Inc -> Logitech, Inc.)
    HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942864 2016-10-13] (Logitech -> Logitech, Inc.)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-12-16] (Oracle America, Inc. -> Oracle Corporation)
    HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech, Inc. -> Logitech Inc.)
    HKU\S-1-5-21-2563344569-153408547-261685501-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\ronny\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"
    HKU\S-1-5-21-2563344569-153408547-261685501-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\ronny\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"
    HKU\S-1-5-21-2563344569-153408547-261685501-1001\...\RunOnce: [Uninstall 19.002.0107.0008\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ronny\AppData\Local\Microsoft\OneDrive\19.002.0107.0008\amd64"
    HKU\S-1-5-21-2563344569-153408547-261685501-1001\...\RunOnce: [Uninstall 19.002.0107.0008] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ronny\AppData\Local\Microsoft\OneDrive\19.002.0107.0008"
    Startup: C:\Users\ronny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Product Registration.lnk [2019-03-02]
    ShortcutTarget: Logitech . Product Registration.lnk -> C:\Program Files (x86)\Logitech\Ereg\eReg.exe (Logitech -> Leader Technologies/Logitech)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
    Tcpip\..\Interfaces\{157c1c20-07a9-48f0-96eb-08b0ba15705c}: [DhcpNameServer] 192.168.1.1
    Tcpip\..\Interfaces\{3c4437dd-9c7d-4241-a1ea-b136520b1063}: [DhcpNameServer] 192.168.42.129
    Tcpip\..\Interfaces\{b7a4ccd0-f88d-490b-949c-652a8e0776ce}: [DhcpNameServer] 192.168.1.1
    Tcpip\..\Interfaces\{f72efe12-e812-47ec-be3d-9570b755c139}: [DhcpNameServer] 192.168.1.1

    Internet Explorer:
    ==================
    HKU\S-1-5-21-2563344569-153408547-261685501-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo17win10.msn.com/?pc=LCTE
    HKU\S-1-5-21-2563344569-153408547-261685501-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com/
    SearchScopes: HKU\S-1-5-21-2563344569-153408547-261685501-1001 -> DefaultScope {2454177C-02A8-47B2-BB8B-5117BC9CF8E3} URL =
    BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\ssv.dll [2019-02-02] (Oracle America, Inc. -> Oracle Corporation)
    BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\jp2ssv.dll [2019-02-02] (Oracle America, Inc. -> Oracle Corporation)

    FireFox:
    ========
    FF DefaultProfile: llfzwedj.default
    FF ProfilePath: C:\Users\ronny\AppData\Roaming\Mozilla\Firefox\Profiles\llfzwedj.default [2019-03-11]
    FF Homepage: Mozilla\Firefox\Profiles\llfzwedj.default -> hxxps://www.bing.com/?PC=JV01
    FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_142.dll [2019-02-20] (Adobe Systems Incorporated -> )
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_142.dll [2019-02-20] (Adobe Systems Incorporated -> )
    FF Plugin-x32: @java.com/DTPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\dtplugin\npDeployJava1.dll [2019-02-02] (Oracle America, Inc. -> Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\plugin2\npjp2.dll [2019-02-02] (Oracle America, Inc. -> Oracle Corporation)

    ==================== Services (Whitelisted) ====================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 AtherosSvc; C:\WINDOWS\System32\drivers\AdminService.exe [414696 2018-01-08] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
    R2 Dolby DAX2 API Service; C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe [197120 2017-07-13] (Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.)
    R2 ImControllerService; C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [71336 2019-01-07] (Lenovo -> Lenovo Group Ltd.)
    S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\WINDOWS\System32\Intel\iCLS Client\lib\SocketHeciServer.exe [765112 2018-04-25] (Intel(R) Trust Services -> Intel(R) Corporation)
    S2 Intel(R) TPM Provisioning Service; C:\WINDOWS\System32\Intel\iCLS Client\lib\TPMProvisioningService.exe [731832 2018-04-25] (Intel(R) Trust Services -> Intel(R) Corporation)
    R2 jhi_service; C:\WINDOWS\System32\jhi_service.exe [576560 2018-05-23] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation)
    R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6562472 2019-02-01] (Malwarebytes Corporation -> Malwarebytes)
    S2 MxService; C:\Program Files (x86)\Maxthon5\Bin\MxService.exe [176928 2019-02-01] (Maxthon Technology Co, Ltd. -> Maxthon International ltd.)
    R2 nebula; C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe [4489352 2019-01-17] (Logitech Inc -> Logitech)
    R2 QcomWlanSrv; C:\WINDOWS\System32\drivers\QcomWlanSrvx64.exe [191440 2018-09-26] (Qualcomm Atheros -> Qualcomm Technologies Inc.)
    R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [266080 2018-07-13] (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor)
    R2 SynTPEnhService; C:\WINDOWS\System32\SynTPEnhService.exe [352808 2018-04-12] (Synaptics Incorporated -> Synaptics Incorporated)
    R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\NisSrv.exe [4098064 2019-02-22] (Microsoft Corporation -> Microsoft Corporation)
    R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MsMpEng.exe [113992 2019-02-22] (Microsoft Corporation -> Microsoft Corporation)

    ===================== Drivers (Whitelisted) ======================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R3 BtFilter; C:\WINDOWS\System32\drivers\btfilter.sys [65448 2018-01-08] (WDKTestCert aswbldsv,131431045756648395 -> Qualcomm)
    S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
    R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153328 2019-01-08] (Malwarebytes Corporation -> Malwarebytes)
    R3 IntcAzAudAddService; C:\WINDOWS\system32\drivers\RTKVHD64.sys [6314848 2018-07-13] (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corp.)
    R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [198512 2019-02-26] (Malwarebytes Corporation -> Malwarebytes)
    S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2019-02-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
    R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [127136 2019-03-03] (Malwarebytes Corporation -> Malwarebytes)
    R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [72864 2019-03-11] (Malwarebytes Corporation -> Malwarebytes)
    R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [274416 2019-03-11] (Malwarebytes Corporation -> Malwarebytes)
    R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [114040 2019-03-03] (Malwarebytes Corporation -> Malwarebytes)
    R3 Qcamain10x64; C:\WINDOWS\System32\drivers\Qcamain10x64.sys [2358736 2018-09-26] (Qualcomm Atheros -> Qualcomm Atheros, Inc.)
    R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1026896 2018-01-25] (Realtek Semiconductor Corp. -> Realtek )
    S3 rtsuvc; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [3236320 2017-11-26] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.)
    R3 SmbDrvI; C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [48168 2018-04-12] (Synaptics Incorporated -> Synaptics Incorporated)
    S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
    R3 stdriver; C:\WINDOWS\system32\DRIVERS\stdriverx64.sys [53488 2019-02-10] (NCH Software Pty Ltd -> )
    R3 SynRMIHID; C:\WINDOWS\System32\drivers\SynRMIHID.sys [61480 2018-04-12] (Synaptics Incorporated -> Synaptics Incorporated)
    R3 usbrndis6; C:\WINDOWS\System32\drivers\usb80236.sys [24576 2018-09-15] (Microsoft Windows -> Microsoft Corporation)
    S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46472 2019-02-22] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
    R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [333792 2019-02-22] (Microsoft Windows -> Microsoft Corporation)
    R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [62432 2019-02-22] (Microsoft Windows -> Microsoft Corporation)

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One month (created) ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2019-03-11 22:47 - 2019-03-11 22:50 - 000018986 _____ C:\Users\ronny\Desktop\FRST.txt
    2019-03-11 22:47 - 2019-03-11 22:47 - 000000000 ____D C:\FRST
    2019-03-11 22:35 - 2019-03-11 22:35 - 002434560 _____ (Farbar) C:\Users\ronny\Desktop\FRST64.exe
    2019-03-11 22:34 - 2019-03-11 22:34 - 000002315 _____ C:\Users\Public\Desktop\Tweaking.com - Registry Backup.lnk
    2019-03-11 22:34 - 2019-03-11 22:34 - 000000207 _____ C:\WINDOWS\tweaking.com-regbackup-LAPTOP-7SS3QTOI-Windows-10-Home-(64-bit).dat
    2019-03-11 22:34 - 2019-03-11 22:34 - 000000000 ____D C:\RegBackup
    2019-03-11 22:34 - 2019-03-11 22:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
    2019-03-11 22:34 - 2019-03-11 22:34 - 000000000 ____D C:\Program Files (x86)\Tweaking.com
    2019-03-11 22:33 - 2019-03-11 22:34 - 000017985 _____ C:\WINDOWS\Tweaking.com - Registry Backup Setup Log.txt
    2019-03-11 22:30 - 2019-03-11 22:30 - 005766144 _____ (Tweaking.com) C:\Users\ronny\Desktop\tweaking.com_registry_backup_setup.exe
    2019-03-07 15:03 - 2019-03-07 15:08 - 000000000 ____D C:\Users\ronny\Desktop\trail cams
    2019-03-07 07:00 - 2019-03-07 07:00 - 000004590 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
    2019-03-05 08:59 - 2019-03-05 08:59 - 000000738 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 10 Update Assistant.lnk
    2019-03-05 08:59 - 2019-03-05 08:59 - 000000000 ____D C:\Windows10Upgrade
    2019-03-04 18:33 - 2018-09-26 16:11 - 002358736 _____ (Qualcomm Atheros, Inc.) C:\WINDOWS\system32\Drivers\Qcamain10x64.sys
    2019-03-04 18:33 - 2018-09-26 16:11 - 001136016 _____ C:\WINDOWS\system32\Drivers\qca9377_2_0.bin
    2019-03-04 18:33 - 2018-09-26 16:11 - 000191440 _____ (Qualcomm Technologies Inc.) C:\WINDOWS\system32\Drivers\QcomWlanSrvx64.exe
    2019-03-04 18:33 - 2018-09-26 16:11 - 000097201 _____ C:\WINDOWS\system32\Drivers\Data9377_2_0.msc
    2019-03-04 18:33 - 2018-09-26 16:11 - 000008124 _____ C:\WINDOWS\system32\Drivers\eeprom_qca9377_1p1_NFA435_olpc_LE_15.bin
    2019-03-04 18:33 - 2018-09-26 16:11 - 000008124 _____ C:\WINDOWS\system32\Drivers\eeprom_qca9377_1p1_NFA435_olpc_LE_14.bin
    2019-03-04 18:33 - 2018-09-26 16:11 - 000008124 _____ C:\WINDOWS\system32\Drivers\eeprom_qca9377_1p1_NFA435_olpc_LE_13.bin
    2019-03-04 18:33 - 2018-09-26 16:11 - 000008124 _____ C:\WINDOWS\system32\Drivers\eeprom_qca9377_1p1_NFA435_olpc_LE_12.bin
    2019-03-04 18:33 - 2018-09-26 16:11 - 000008124 _____ C:\WINDOWS\system32\Drivers\eeprom_qca9377_1p1_NFA435_olpc_LE_11.bin
    2019-03-03 05:14 - 2019-03-11 09:24 - 000072864 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
    2019-03-03 05:14 - 2019-03-03 05:14 - 000127136 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
    2019-03-03 05:13 - 2019-03-11 09:24 - 000274416 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
    2019-03-03 05:13 - 2019-03-03 05:13 - 000114040 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
    2019-03-02 07:13 - 2019-03-02 06:13 - 000000000 ____D C:\Windows.old
    2019-03-02 07:05 - 2019-03-02 07:13 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
    2019-03-02 07:01 - 2019-03-02 07:04 - 000000000 ____D C:\WINDOWS\ServiceProfiles
    2019-03-02 07:01 - 2019-03-02 07:01 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
    2019-03-02 06:52 - 2019-03-02 06:52 - 024617472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 019284480 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 011724288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 009941504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 007724992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 005440008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 005112792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 004918784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 003566080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 003550384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 002986352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 002469648 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 002429752 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
    2019-03-02 06:52 - 2019-03-02 06:52 - 002323696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 002278448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 002160160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
    2019-03-02 06:52 - 2019-03-02 06:52 - 001294864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 001289192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 001282640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 001259024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
    2019-03-02 06:52 - 2019-03-02 06:52 - 001200920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 001166336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl
    2019-03-02 06:52 - 2019-03-02 06:52 - 001073448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 001057976 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2adec.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 001024920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 001022464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 000870400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 000854784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2adec.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 000829440 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 000762272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 000662528 ____R (Microsoft Corporation) C:\WINDOWS\system32\MixedRealityCapture.Pipeline.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 000654848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 000577024 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicExtensions.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 000454144 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 000429056 _____ (Microsoft Corporation) C:\WINDOWS\system32\MixedReality.Broker.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 000427520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 000421904 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 000371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 000301096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpeffects.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 000263360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 000241680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpeffects.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 000218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpdxm.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 000167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpdxm.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 000166400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscinterop.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 000125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpshell.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 000098816 ____R (Microsoft Corporation) C:\WINDOWS\system32\MixedRealityCapture.Broker.dll
    2019-03-02 06:52 - 2019-03-02 06:52 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpshell.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 026807296 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 023439360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 020812288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 019023872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 015224832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 012858368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 012151808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 008875520 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 007897088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 007883776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 006925824 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 006540424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 006306152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 006070272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 005764608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 005584864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 005205464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 005086208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 004885504 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 004688896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 004627456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 004526080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupapi.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 003952952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 003922944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 003743744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 003730352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
    2019-03-02 06:51 - 2019-03-02 06:51 - 003656192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 003504640 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 003427328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 003108864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 002942464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 002927120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
    2019-03-02 06:51 - 2019-03-02 06:51 - 002893312 _____ (Microsoft Corporation) C:\WINDOWS\system32\themeui.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 002832896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themeui.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 002776920 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 002765312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 002702528 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 002689024 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 002626592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
    2019-03-02 06:51 - 2019-03-02 06:51 - 002392576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 002346496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 002298880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 002275888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 002086400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsservices.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 002072728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001994768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001969680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys
    2019-03-02 06:51 - 2019-03-02 06:51 - 001899160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001863168 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001783296 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001762816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001749504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001720936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001711104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001700864 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001696936 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
    2019-03-02 06:51 - 2019-03-02 06:51 - 001688576 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001675712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001674480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001671864 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001590288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001506304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001484800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001476096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001467560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001467384 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
    2019-03-02 06:51 - 2019-03-02 06:51 - 001456736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001446400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc42u.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001415680 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc42.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001395248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001391096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Taskmgr.exe
    2019-03-02 06:51 - 2019-03-02 06:51 - 001387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001360696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
    2019-03-02 06:51 - 2019-03-02 06:51 - 001341584 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
    2019-03-02 06:51 - 2019-03-02 06:51 - 001311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001309696 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001309184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001294848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001279024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Taskmgr.exe
    2019-03-02 06:51 - 2019-03-02 06:51 - 001271608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001254912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001224704 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001221528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
    2019-03-02 06:51 - 2019-03-02 06:51 - 001192448 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001182720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl
    2019-03-02 06:51 - 2019-03-02 06:51 - 001180760 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001178344 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
    2019-03-02 06:51 - 2019-03-02 06:51 - 001168384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001162280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001110528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001098136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001064448 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001047552 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001026992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001018880 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 001010176 _____ (Microsoft Corporation) C:\WINDOWS\system32\refsutil.exe
    2019-03-02 06:51 - 2019-03-02 06:51 - 000982032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refsv1.sys
    2019-03-02 06:51 - 2019-03-02 06:51 - 000972288 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000964976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000953856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000949760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000947200 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000913920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000901632 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000883200 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000882688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
    2019-03-02 06:51 - 2019-03-02 06:51 - 000875008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000833536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000803328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000800256 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000794112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000787456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000782968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000769536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
    2019-03-02 06:51 - 2019-03-02 06:51 - 000762368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprddm.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000742912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceControl.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000729088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000726208 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000703488 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Language.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000690688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000684032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000681984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000663552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000663040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000652320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000649272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000624640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apphelp.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000622592 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000615936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000604248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.applicationmodel.datatransfer.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000588304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
    2019-03-02 06:51 - 2019-03-02 06:51 - 000585728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000570368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000553984 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000535048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
    2019-03-02 06:51 - 2019-03-02 06:51 - 000532480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000522312 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
    2019-03-02 06:51 - 2019-03-02 06:51 - 000514112 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000492032 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragsvc.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000481792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000475152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
    2019-03-02 06:51 - 2019-03-02 06:51 - 000454160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
    2019-03-02 06:51 - 2019-03-02 06:51 - 000451072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000449024 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000434176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000430904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
    2019-03-02 06:51 - 2019-03-02 06:51 - 000429568 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000424960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000403968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoMetadataHandler.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000398848 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000383288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msrpc.sys
    2019-03-02 06:51 - 2019-03-02 06:51 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000373768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\coml2.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000358400 _____ (Microsoft Corporation) C:\WINDOWS\regedit.exe
    2019-03-02 06:51 - 2019-03-02 06:51 - 000352768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000349184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
    2019-03-02 06:51 - 2019-03-02 06:51 - 000349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000340480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\udfs.sys
    2019-03-02 06:51 - 2019-03-02 06:51 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000329216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\regedit.exe
    2019-03-02 06:51 - 2019-03-02 06:51 - 000316416 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000314368 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcLayers.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000313344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd2x40.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000312832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.Workflow.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000312832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000297984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Diagnostics.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000293376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
    2019-03-02 06:51 - 2019-03-02 06:51 - 000289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\discan.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wisp.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000284160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasppp.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000277536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000262672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
    2019-03-02 06:51 - 2019-03-02 06:51 - 000252536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngOnline.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000226816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wisp.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000222720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prnntfy.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscinterop.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000201216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincredui.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\spacebridge.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000176440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
    2019-03-02 06:51 - 2019-03-02 06:51 - 000173568 _____ (Microsoft Corporation) C:\WINDOWS\system32\WPTaskScheduler.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrrun.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\spopk.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000159744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincredui.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasman.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\CastingShellExt.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000146888 _____ (Microsoft Corporation) C:\WINDOWS\system32\smss.exe
    2019-03-02 06:51 - 2019-03-02 06:51 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintWorkflowService.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceAgent.exe
    2019-03-02 06:51 - 2019-03-02 06:51 - 000134144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CastingShellExt.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spopk.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000121872 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdnet.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000114344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rmclient.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\dab.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000104960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.NetworkOperators.HotspotAuthentication.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000104960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupcln.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cdfs.sys
    2019-03-02 06:51 - 2019-03-02 06:51 - 000095744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000094224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fileinfo.sys
    2019-03-02 06:51 - 2019-03-02 06:51 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlahc.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\PktMon.exe
    2019-03-02 06:51 - 2019-03-02 06:51 - 000091424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CompPkgSup.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\nslookup.exe
    2019-03-02 06:51 - 2019-03-02 06:51 - 000078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nslookup.exe
    2019-03-02 06:51 - 2019-03-02 06:51 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsiwmi.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SMSRouter.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdBth.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdBth.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfts.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfts.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\msisip.dll
    2019-03-02 06:51 - 2019-03-02 06:51 - 000024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msisip.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 022111856 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 017520640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 009683984 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 007685016 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 007645600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 006132736 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 005565952 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 005561856 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 005527552 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 005312512 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 005130752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 004991096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 004702704 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupapi.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 004588544 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 004298752 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 004245280 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 004019200 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 003982848 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 003662336 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 003556352 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 003386368 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 003379000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 003338328 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 003334144 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 003270144 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 003092480 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 002992640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 002929152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 002879488 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsservices.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 002843136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 002766136 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 002721280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 002654208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 002630656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 002618880 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 002594872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 002488320 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 002466304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 002437552 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 002187264 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 002185728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 002149368 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 002085376 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 002021584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001975296 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001903616 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001884672 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001842600 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001830912 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001824768 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001819136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001797128 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001715712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001700880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001671680 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001664904 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001641400 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001616384 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001604096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001533440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001520208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001496064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001462272 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001387496 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001331744 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001315840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001314304 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001287776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001267712 _____ (Microsoft Corporation) C:\WINDOWS\system32\APMon.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001258512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 001255736 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 001249792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001221120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 001212416 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001209360 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvstore.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001199104 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001057792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 001056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\pidgenx.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001054200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 001051960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 001050936 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 001050624 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 001005568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000998912 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000982576 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000970256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\drvstore.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000955392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000954368 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000925184 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000918304 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000897848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000890368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000889344 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000887808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprddm.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000865784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000864056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 000863752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000854016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000850968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000836096 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000822448 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000820736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000818832 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.applicationmodel.datatransfer.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000806560 _____ C:\WINDOWS\SysWOW64\locale.nls
    2019-03-02 06:50 - 2019-03-02 06:50 - 000806560 _____ C:\WINDOWS\system32\locale.nls
    2019-03-02 06:50 - 2019-03-02 06:50 - 000801792 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000799568 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000773120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000765960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000756640 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 000752136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000744960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000741888 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000681984 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000680184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000669184 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationFrame.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000663552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000660496 _____ (Microsoft Corporation) C:\WINDOWS\system32\computecore.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000651792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000651304 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 000648192 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32time.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000629576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000612368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000609792 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000604552 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 000593920 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000582240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000580024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 000577536 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofmsvc.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000566584 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000556544 _____ (Microsoft Corporation) C:\WINDOWS\system32\BTAGService.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000547840 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000543744 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000531976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000527872 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 000519992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Vid.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000518656 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000516608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000515584 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000514048 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000506408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000500224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_PCDisplay.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000496872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 000494080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000494080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Activities.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000487424 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoMetadataHandler.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000478208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000473616 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000468992 _____ (Microsoft Corporation) C:\WINDOWS\system32\coml2.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000463672 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000461824 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000448000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.Workflow.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000439296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000421376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000419128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\eeprov.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000415744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 000408800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mswsock.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000407040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000402944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\exfat.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000402576 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000400384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000398848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000398416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000394752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcLayers.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000394240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000388096 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 000387384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000378368 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000375544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 000371200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Diagnostics.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000365056 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000353488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000346624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000326144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.OneCore.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000324408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswsock.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvcext.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000306704 _____ (Microsoft Corporation) C:\WINDOWS\system32\computestorage.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasppp.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000303616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000300024 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvc.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000298296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000294072 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000276488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MTF.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000275768 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000273920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000266240 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\prnntfy.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000246784 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000241664 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 000228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000217600 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000203280 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000202552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MTF.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\netiohlp.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthserv.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000195896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spacedump.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrrun.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000193032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasman.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000178696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\appsruprov.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\energyprov.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000175096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpioclx.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spacebridge.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompPkgSrv.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 000164344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000164288 _____ (Microsoft Corporation) C:\WINDOWS\system32\vertdll.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000157192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000155648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netiohlp.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000155648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000151872 _____ (Microsoft Corporation) C:\WINDOWS\system32\rmclient.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000148480 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 000146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000140808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.NetworkOperators.HotspotAuthentication.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000132104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupcln.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000114856 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompPkgSup.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000111104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000102392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000097592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000095544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storqosflt.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000090424 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcnfs.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000083472 _____ (Microsoft Corporation) C:\WINDOWS\system32\vid.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 000080400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vpci.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManMigrationPlugin.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000074424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WindowsTrustedRT.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iscsiwmi.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManMigrationPlugin.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000062464 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo-overrides.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000055608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\iorate.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mmcss.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000047136 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser_broker.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\hidparse.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys
    2019-03-02 06:50 - 2019-03-02 06:50 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpkinstall.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 000039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\npmproxy.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000039304 _____ (Microsoft Corporation) C:\WINDOWS\system32\NtlmShared.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnsruprov.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 000033056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NtlmShared.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe
    2019-03-02 06:50 - 2019-03-02 06:50 - 000021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\npmproxy.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
    2019-03-02 06:50 - 2019-03-02 06:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
    2019-03-02 06:50 - 2019-03-02 06:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
    2019-03-02 06:50 - 2019-03-02 06:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
    2019-03-02 06:50 - 2019-03-02 06:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
    2019-03-02 06:50 - 2019-03-02 06:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
    2019-03-02 06:50 - 2019-03-02 06:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
    2019-03-02 06:50 - 2019-03-02 06:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
    2019-03-02 06:50 - 2019-03-02 06:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
    2019-03-02 06:50 - 2019-03-02 06:50 - 000000072 _____ C:\WINDOWS\system32\edgehtmlpluginpolicy.bin
    2019-03-02 06:42 - 2019-03-02 06:42 - 000000000 ____D C:\Program Files\Reference Assemblies
    2019-03-02 06:42 - 2019-03-02 06:42 - 000000000 ____D C:\Program Files\MSBuild
    2019-03-02 06:42 - 2019-03-02 06:42 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
    2019-03-02 06:42 - 2019-03-02 06:42 - 000000000 ____D C:\Program Files (x86)\MSBuild
    2019-03-02 06:41 - 2019-03-02 06:41 - 001167960 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
    2019-03-02 06:41 - 2019-03-02 06:41 - 000780376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
    2019-03-02 06:41 - 2019-03-02 06:41 - 000126064 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
    2019-03-02 06:41 - 2019-03-02 06:41 - 000104560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
    2019-03-02 06:41 - 2019-03-02 06:41 - 000036896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
    2019-03-02 06:41 - 2019-03-02 06:41 - 000035440 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
    2019-03-02 06:26 - 2019-03-02 06:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dolby
    2019-03-02 06:26 - 2019-03-02 06:26 - 000000000 ____D C:\ProgramData\Dolby
    2019-03-02 06:26 - 2019-03-02 06:26 - 000000000 ____D C:\Program Files\Dolby
    2019-03-02 06:18 - 2019-03-02 06:18 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
    2019-03-02 06:13 - 2019-03-02 06:13 - 000000020 ___SH C:\Users\ronny\ntuser.ini
    2019-03-02 06:10 - 2019-03-11 19:00 - 000004164 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{919E763D-944E-410C-BE5B-FE5211DD5A4F}
    2019-03-02 06:10 - 2019-03-11 09:32 - 000003374 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2563344569-153408547-261685501-1001
    2019-03-02 06:10 - 2019-03-11 09:23 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2019-03-02 06:10 - 2019-03-07 07:00 - 000004422 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
    2019-03-02 06:10 - 2019-03-02 06:26 - 000003266 _____ C:\WINDOWS\System32\Tasks\RtHDVBg_LENOVO_DOLBYDRAGON
    2019-03-02 06:10 - 2019-03-02 06:26 - 000003220 _____ C:\WINDOWS\System32\Tasks\RtHDVBg_Dolby
    2019-03-02 06:10 - 2019-03-02 06:25 - 000003216 _____ C:\WINDOWS\System32\Tasks\RTKCPL
    2019-03-02 06:10 - 2019-03-02 06:11 - 000003748 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier
    2019-03-02 06:10 - 2019-03-02 06:11 - 000003492 _____ C:\WINDOWS\System32\Tasks\LenovoUtility Task
    2019-03-02 06:10 - 2019-03-02 06:11 - 000002766 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
    2019-03-02 06:10 - 2019-03-02 06:11 - 000002708 _____ C:\WINDOWS\System32\Tasks\Maxthon5 Update
    2019-03-02 06:10 - 2019-03-02 06:11 - 000002650 _____ C:\WINDOWS\System32\Tasks\McAfee Remediation (Prepare)
    2019-03-02 06:10 - 2019-03-02 06:10 - 000002408 _____ C:\WINDOWS\System32\Tasks\App Explorer
    2019-03-02 06:10 - 2019-03-02 06:10 - 000000000 ____D C:\WINDOWS\System32\Tasks\NCH Software
    2019-03-02 06:10 - 2019-03-02 06:10 - 000000000 ____D C:\WINDOWS\System32\Tasks\McAfee
    2019-03-02 06:10 - 2019-03-02 06:10 - 000000000 ____D C:\WINDOWS\System32\Tasks\Lenovo
    2019-03-02 06:09 - 2019-03-02 06:10 - 000007623 _____ C:\WINDOWS\diagwrn.xml
    2019-03-02 06:09 - 2019-03-02 06:10 - 000007623 _____ C:\WINDOWS\diagerr.xml
    2019-03-02 05:34 - 2019-03-11 09:30 - 000840848 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2019-03-02 05:25 - 2019-03-02 05:25 - 000001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
    2019-03-02 05:22 - 2019-03-11 09:30 - 000002370 _____ C:\Users\ronny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
    2019-03-02 05:22 - 2019-03-04 23:37 - 000000000 ____D C:\Users\ronny
    2019-03-02 05:21 - 2018-05-06 13:15 - 000144808 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
    2019-03-02 05:21 - 2018-05-06 13:15 - 000119720 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL
    2019-03-02 05:20 - 2019-03-02 05:20 - 000000000 ____D C:\ProgramData\USOShared
    2019-03-02 05:20 - 2018-09-15 02:28 - 002864640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
    2019-03-02 05:15 - 2019-03-11 13:46 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
    2019-03-02 05:15 - 2019-03-02 05:28 - 000257824 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2019-03-01 01:27 - 2019-03-01 01:27 - 007474563 _____ C:\Users\ronny\Downloads\2011-silverado3500hd.pdf
    2019-03-01 00:48 - 2019-03-01 00:48 - 000000000 ____D C:\Users\ronny\Desktop\NCH
    2019-03-01 00:46 - 2019-03-01 00:46 - 000001061 _____ C:\Users\ronny\Desktop\My Documents - Shortcut.lnk
    2019-02-26 09:48 - 2019-03-07 23:53 - 000000000 ____D C:\Users\ronny\Desktop\sound
    2019-02-26 08:09 - 2019-02-26 08:09 - 000198512 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
    2019-02-26 08:09 - 2019-02-01 12:20 - 000020936 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
    2019-02-26 08:08 - 2019-03-02 07:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
    2019-02-26 08:08 - 2019-02-26 08:08 - 000001919 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
    2019-02-26 08:08 - 2019-01-08 16:32 - 000153328 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
    2019-02-20 07:21 - 2019-02-20 07:21 - 000000000 ___HD C:\OneDriveTemp
    2019-02-20 07:10 - 2019-02-20 07:10 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
    2019-02-20 02:04 - 2019-03-07 07:00 - 000000000 ____D C:\Users\ronny\AppData\Local\Adobe
    2019-02-19 06:11 - 2019-02-19 06:34 - 000000000 ____D C:\WINDOWS\Microsoft Antimalware
    2019-02-19 00:02 - 2019-02-19 00:02 - 000001019 _____ C:\Program Files (x86)\unins000.dat
    2019-02-19 00:02 - 2019-02-19 00:01 - 000715038 _____ C:\Program Files (x86)\unins000.exe
    2019-02-19 00:02 - 2011-12-26 06:29 - 000001483 _____ C:\Program Files (x86)\LICENSE.txt
    2019-02-19 00:02 - 2011-12-26 04:34 - 000475648 _____ C:\Program Files (x86)\lame.exe
    2019-02-19 00:02 - 2011-12-26 04:34 - 000421888 _____ C:\Program Files (x86)\lame_enc.dll
    2019-02-19 00:00 - 2019-02-19 00:00 - 000000000 ____D C:\Program Files (x86)\Lame For Audacity
    2019-02-18 23:59 - 2019-02-18 23:59 - 000527423 _____ ( ) C:\Users\ronny\Downloads\Lame_v3.99.3_for_Windows.exe
    2019-02-18 23:54 - 2019-02-19 04:08 - 000000000 ____D C:\Users\ronny\AppData\Roaming\audacity
    2019-02-18 23:54 - 2019-02-18 23:54 - 000000000 ____D C:\Users\ronny\Documents\Audacity
    2019-02-18 23:54 - 2019-02-18 23:54 - 000000000 ____D C:\Users\ronny\AppData\Local\Audacity
    2019-02-18 23:53 - 2019-02-18 23:54 - 000000000 ____D C:\Program Files (x86)\Audacity
    2019-02-18 23:53 - 2019-02-18 23:53 - 000001095 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
    2019-02-18 21:59 - 2019-03-02 07:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
    2019-02-18 21:59 - 2019-02-18 21:59 - 000001214 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Switch Sound File Converter.lnk
    2019-02-18 10:16 - 2019-03-11 22:17 - 000000000 ____D C:\Users\ronny\AppData\LocalLow\Mozilla
    2019-02-18 10:16 - 2019-03-01 07:48 - 000001012 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
    2019-02-18 10:16 - 2019-03-01 07:48 - 000000000 ____D C:\Program Files\Mozilla Firefox
    2019-02-18 10:16 - 2019-03-01 07:48 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2019-02-18 10:16 - 2019-02-18 10:16 - 000000000 ____D C:\Users\ronny\AppData\Roaming\Mozilla
    2019-02-18 10:16 - 2019-02-18 10:16 - 000000000 ____D C:\Users\ronny\AppData\Local\Mozilla
    2019-02-18 10:16 - 2019-02-18 10:16 - 000000000 ____D C:\ProgramData\Mozilla
    2019-02-16 07:32 - 2019-02-16 07:44 - 000000000 ____D C:\BIOS
    2019-02-15 09:46 - 2019-03-02 06:14 - 000000000 ___DC C:\WINDOWS\Panther
    2019-02-15 09:37 - 2019-03-02 07:06 - 000000000 ____D C:\WINDOWS\system32\Intel
    2019-02-11 17:01 - 2018-09-11 07:09 - 004680168 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RsDMFT64.dll
    2019-02-11 00:18 - 2019-02-11 00:18 - 000000719 _____ C:\Users\ronny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recordings.lnk
    2019-02-10 22:19 - 2019-02-10 22:20 - 000001167 _____ C:\Users\ronny\AppData\Roaming\trace_FilterInstaller.txt
    2019-02-10 22:19 - 2019-02-10 22:19 - 000053488 _____ C:\WINDOWS\system32\Drivers\stdriverx64.sys
    2019-02-10 22:19 - 2019-02-10 22:19 - 000001250 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoundTap Streaming Audio Recorder.lnk
    2019-02-10 22:19 - 2019-02-10 22:19 - 000000000 _____ C:\Users\ronny\AppData\Roaming\trace_FilterInstaller.txt-CRT.txt

    ==================== One month (modified) ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2019-03-11 22:48 - 2018-09-15 02:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2019-03-11 09:30 - 2019-02-01 23:15 - 000000000 ___RD C:\Users\ronny\OneDrive
    2019-03-11 09:30 - 2018-09-15 02:31 - 000000000 ____D C:\WINDOWS\INF
    2019-03-11 09:28 - 2019-02-02 14:02 - 000000000 ____D C:\Users\ronny\AppData\Local\Host App Service
    2019-03-11 09:26 - 2019-02-02 14:06 - 000000000 __SHD C:\Users\ronny\IntelGraphicsProfiles
    2019-03-11 03:40 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\LiveKernelReports
    2019-03-11 02:57 - 2019-02-03 22:17 - 000000000 ____D C:\Users\Public\Logi
    2019-03-10 08:15 - 2018-09-15 02:33 - 000000000 ___HD C:\Program Files\WindowsApps
    2019-03-10 08:15 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\AppReadiness
    2019-03-09 13:13 - 2019-02-02 14:02 - 000000000 ____D C:\Users\ronny\AppData\Local\ElevatedDiagnostics
    2019-03-09 12:55 - 2018-09-15 02:23 - 000000000 ____D C:\WINDOWS\CbsTemp
    2019-03-09 11:35 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\system32\NDF
    2019-03-07 11:49 - 2019-02-02 13:42 - 000000000 ____D C:\Users\ronny\Documents\dad's
    2019-03-07 06:59 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
    2019-03-07 06:59 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\system32\Macromed
    2019-03-03 05:12 - 2018-09-15 01:09 - 000786432 _____ C:\WINDOWS\system32\config\BBI
    2019-03-03 04:39 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\appcompat
    2019-03-02 12:57 - 2019-02-02 00:15 - 000000000 ____D C:\Users\ronny\AppData\Local\D3DSCache
    2019-03-02 09:51 - 2019-02-03 22:01 - 000000000 ____D C:\Users\ronny\AppData\Local\PlaceholderTileLogoFolder
    2019-03-02 09:49 - 2018-09-15 02:36 - 000835480 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
    2019-03-02 09:49 - 2018-09-15 02:36 - 000179600 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
    2019-03-02 07:13 - 2019-02-02 12:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
    2019-03-02 07:13 - 2019-02-02 00:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
    2019-03-02 07:13 - 2019-02-01 23:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MX5
    2019-03-02 07:13 - 2019-02-01 23:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech Camera Settings
    2019-03-02 07:13 - 2019-02-01 23:25 - 000000000 ____D C:\Program Files\Common Files\LogiShrd
    2019-03-02 07:13 - 2018-10-09 09:55 - 000000000 ____D C:\Program Files\Realtek
    2019-03-02 07:13 - 2018-10-09 09:54 - 000000000 ____D C:\Program Files\Intel
    2019-03-02 07:13 - 2018-09-15 02:36 - 000000000 ____D C:\WINDOWS\Setup
    2019-03-02 07:13 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
    2019-03-02 07:13 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\system32\spool
    2019-03-02 07:13 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\system32\oobe
    2019-03-02 07:13 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\Registration
    2019-03-02 07:13 - 2018-09-15 02:31 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
    2019-03-02 07:13 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
    2019-03-02 07:07 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\InfusedApps
    2019-03-02 07:06 - 2018-10-09 10:03 - 000000000 ____D C:\WINDOWS\system32\Drivers\Lenovo
    2019-03-02 07:05 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\Resources
    2019-03-02 06:54 - 2018-09-15 04:11 - 000000000 ____D C:\Program Files\Windows Photo Viewer
    2019-03-02 06:54 - 2018-09-15 04:11 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
    2019-03-02 06:54 - 2018-09-15 02:33 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
    2019-03-02 06:54 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\TextInput
    2019-03-02 06:54 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
    2019-03-02 06:54 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
    2019-03-02 06:54 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\system32\migwiz
    2019-03-02 06:54 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\system32\appraiser
    2019-03-02 06:54 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\ShellExperiences
    2019-03-02 06:54 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\ShellComponents
    2019-03-02 06:54 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\bcastdvr
    2019-03-02 06:54 - 2018-09-15 01:09 - 000000000 ____D C:\WINDOWS\system32\Dism
    2019-03-02 06:41 - 2019-02-02 10:05 - 000000000 ____D C:\ProgramData\Packages
    2019-03-02 06:36 - 2019-02-02 14:06 - 000000000 ____D C:\Users\ronny\AppData\Local\Packages
    2019-03-02 06:26 - 2018-10-09 09:55 - 000000000 ____D C:\WINDOWS\system32\DAX2
    2019-03-02 06:26 - 2018-10-09 09:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Realtek
    2019-03-02 06:25 - 2018-10-09 09:55 - 000477243 _____ C:\WINDOWS\system32\Drivers\rtkhdasetting.zip
    2019-03-02 06:25 - 2018-10-09 09:55 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
    2019-03-02 06:25 - 2018-10-09 09:55 - 000000000 ____D C:\WINDOWS\system32\DAX3
    2019-03-02 06:15 - 2019-02-02 14:06 - 000000000 ___RD C:\Users\ronny\3D Objects
    2019-03-02 06:15 - 2018-04-17 14:03 - 000000000 __RHD C:\Users\Public\AccountPictures
    2019-03-02 06:14 - 2019-02-02 14:06 - 000000000 ____D C:\Users\ronny\AppData\Local\ConnectedDevicesPlatform
    2019-03-02 06:11 - 2018-09-15 01:09 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
    2019-03-02 06:10 - 2018-09-15 02:33 - 000000000 ___RD C:\Program Files\Windows Defender
    2019-03-02 05:50 - 2018-09-15 02:33 - 000000000 ___RD C:\WINDOWS\PrintDialog
    2019-03-02 05:33 - 2018-09-15 02:33 - 000000000 __RHD C:\Users\Public\Libraries
    2019-03-02 05:26 - 2019-02-07 00:58 - 000000000 ____D C:\Users\ronny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dwyco CDC-X
    2019-03-02 05:26 - 2019-02-02 12:16 - 000000000 ____D C:\Users\ronny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
    2019-03-02 05:20 - 2018-09-15 02:33 - 000000000 ____D C:\ProgramData\USOPrivate
    2019-03-02 05:17 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\ServiceState
    2019-03-01 11:40 - 2019-02-01 23:50 - 000000000 ____D C:\Program Files\rempl
    2019-03-01 03:16 - 2019-02-07 01:08 - 002838528 _____ C:\Users\ronny\Documents\dwyco-backup-diff-f26998543478a9551774.sql
    2019-03-01 00:47 - 2019-02-07 05:29 - 000000000 ____D C:\Users\ronny\Desktop\cloud
    2019-03-01 00:47 - 2019-02-02 13:41 - 000000000 ____D C:\Users\ronny\Desktop\karaoke
    2019-02-25 02:45 - 2019-02-07 01:08 - 002838528 _____ C:\Users\ronny\Documents\dwyco-backup-diff-f26998543478a9551774.old.sql
    2019-02-22 16:31 - 2018-04-17 14:02 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
    2019-02-18 21:59 - 2019-02-07 10:57 - 000000000 ____D C:\ProgramData\NCH Software
    2019-02-18 21:59 - 2019-02-07 10:56 - 000000000 ____D C:\Users\ronny\AppData\Roaming\NCH Software
    2019-02-18 21:59 - 2019-02-07 10:56 - 000000000 ____D C:\Program Files (x86)\NCH Software
    2019-02-18 00:05 - 2019-02-02 14:07 - 000000000 ____D C:\Users\ronny\AppData\Local\Publishers
    2019-02-16 15:30 - 2019-02-02 12:50 - 000000000 _____ C:\WINDOWS\system32\Drivers\lvuvc.hs
    2019-02-14 08:55 - 2019-02-02 14:06 - 000000000 ____D C:\Users\ronny\AppData\Local\Intel
    2019-02-13 00:44 - 2019-02-01 23:41 - 000000000 ____D C:\WINDOWS\system32\MRT
    2019-02-13 00:42 - 2019-02-01 23:40 - 129330784 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe

    ==================== Files in the root of some directories =======

    2019-02-19 00:02 - 2011-12-26 04:34 - 000475648 _____ () C:\Program Files (x86)\lame.exe
    2019-02-19 00:02 - 2011-12-26 04:34 - 000421888 _____ () C:\Program Files (x86)\lame_enc.dll
    2019-02-19 00:02 - 2011-12-26 06:29 - 000001483 _____ () C:\Program Files (x86)\LICENSE.txt
    2019-02-19 00:02 - 2019-02-19 00:02 - 000001019 _____ () C:\Program Files (x86)\unins000.dat
    2019-02-19 00:02 - 2019-02-19 00:01 - 000715038 _____ () C:\Program Files (x86)\unins000.exe
    2019-02-10 22:19 - 2019-02-10 22:20 - 000001167 _____ () C:\Users\ronny\AppData\Roaming\trace_FilterInstaller.txt
    2019-02-10 22:19 - 2019-02-10 22:19 - 000000000 _____ () C:\Users\ronny\AppData\Roaming\trace_FilterInstaller.txt-CRT.txt

    ==================== Bamital & volsnap ======================

    (There is no automatic fix for files that do not pass verification.)

    C:\WINDOWS\system32\winlogon.exe => File is digitally signed
    C:\WINDOWS\system32\wininit.exe => File is digitally signed
    C:\WINDOWS\explorer.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
    C:\WINDOWS\system32\svchost.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
    C:\WINDOWS\system32\services.exe => File is digitally signed
    C:\WINDOWS\system32\User32.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
    C:\WINDOWS\system32\userinit.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
    C:\WINDOWS\system32\rpcss.dll => File is digitally signed
    C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
    C:\WINDOWS\system32\dllhost.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\dllhost.exe => File is digitally signed
    C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

    ==================== End of FRST.txt ============================

    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11.03.2019
    Ran by ronny (11-03-2019 22:51:12)
    Running from C:\Users\ronny\Desktop
    Windows 10 Home Version 1809 17763.316 (X64) (2019-03-02 11:13:44)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-2563344569-153408547-261685501-500 - Administrator - Disabled)
    DefaultAccount (S-1-5-21-2563344569-153408547-261685501-503 - Limited - Disabled)
    Guest (S-1-5-21-2563344569-153408547-261685501-501 - Limited - Disabled)
    ronny (S-1-5-21-2563344569-153408547-261685501-1001 - Administrator - Enabled) => C:\Users\ronny
    WDAGUtilityAccount (S-1-5-21-2563344569-153408547-261685501-504 - Limited - Disabled)

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.142 - Adobe Systems Incorporated)
    Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.142 - Adobe Systems Incorporated)
    Audacity 2.3.0 (HKLM-x32\...\Audacity_is1) (Version: 2.3.0 - Audacity Team)
    CameraHelperMsi (HKLM-x32\...\{15634701-BACE-4449-8B25-1567DA8C9FD3}) (Version: 13.51.815.0 - Logitech) Hidden
    Dolby Audio X2 Windows API SDK (HKLM\...\{F994125B-7BF5-4A38-A569-82833CEB24DC}) (Version: 0.8.4.83 - Dolby Laboratories, Inc.)
    Dolby Audio X2 Windows APP (HKLM\...\{4A02DCED-C2B0-4DD3-87BD-7D8E68D6AF3C}) (Version: 0.8.6.75 - Dolby Laboratories, Inc.)
    Dwyco CDC-X version 2.17 (HKU\S-1-5-21-2563344569-153408547-261685501-1001\...\Dwyco CDC-X_is1) (Version: 2.17 - Dwyco, Inc.)
    erLT (HKLM-x32\...\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}) (Version: 1.20.138.34 - Logitech, Inc.) Hidden
    Intel(R) Chipset Device Software (HKLM-x32\...\{44ded3eb-1686-46a6-9770-fd79096c29f7}) (Version: 10.1.1.45 - Intel(R) Corporation) Hidden
    Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1052 - Intel Corporation)
    Intel(R) Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.47.715.0 - Intel Corporation) Hidden
    Intel(R) Trusted Connect Services Client (HKLM-x32\...\{2b32b7d0-4f9f-47c8-adb7-807e6cb2fb75}) (Version: 1.47.715.0 - Intel Corporation) Hidden
    Java 8 Update 201 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180201F0}) (Version: 8.0.2010.9 - Oracle Corporation)
    LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - )
    Lenovo App Explorer (HKU\S-1-5-21-2563344569-153408547-261685501-1001\...\Host App Service) (Version: 0.273.2.977 - SweetLabs for Lenovo) <==== ATTENTION
    Lenovo Service Bridge (HKU\S-1-5-21-2563344569-153408547-261685501-1001\...\{2C74547D-EF88-47F4-85F5-BE46A31E26B7}_is1) (Version: 4.0.6.6 - Lenovo)
    Logitech Camera Settings (HKLM-x32\...\LogiUCDPP) (Version: 2.8.24.0 - Logitech Europe S.A.)
    Logitech Options (HKLM\...\LogiOptions) (Version: 7.10.3 - Logitech)
    Logitech Unifying Software 2.50 (HKLM\...\Logitech Unifying) (Version: 2.50.25 - Logitech)
    Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.80 - Logitech Inc.)
    Malwarebytes version 3.7.1.2839 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.7.1.2839 - Malwarebytes)
    Microsoft OneDrive (HKU\S-1-5-21-2563344569-153408547-261685501-1001\...\OneDriveSetup.exe) (Version: 19.012.0121.0011 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
    Mozilla Firefox 65.0.2 (x64 en-US) (HKLM\...\Mozilla Firefox 65.0.2 (x64 en-US)) (Version: 65.0.2 - Mozilla)
    Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 65.0.1 - Mozilla)
    MX5 (HKLM-x32\...\Maxthon5) (Version: 5.2.6.1000 - Maxthon International Limited)
    RecordPad Sound Recorder (HKLM-x32\...\Recordpad) (Version: 8.01 - NCH Software)
    SoundTap Streaming Audio Recorder (HKLM-x32\...\SoundTap) (Version: 4.01 - NCH Software)
    Switch Sound File Converter (HKLM-x32\...\Switch) (Version: 7.07 - NCH Software)
    Tweaking.com - Registry Backup (HKLM-x32\...\Tweaking.com - Registry Backup) (Version: 3.5.3 - Tweaking.com)
    Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{1FD817A6-63E1-4519-BFD4-228DABB7AB6B}) (Version: 2.55.0.0 - Microsoft Corporation)
    Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
    Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-2) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
    WavePad Sound Editor (HKLM-x32\...\WavePad) (Version: 9.01 - NCH Software)
    Windows 10 Update Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22589 - Microsoft Corporation)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-2563344569-153408547-261685501-1001_Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6} -> [OneDrive] => {a52bba46-e9e1-435f-b3d9-28daa648c0f6}
    ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
    ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\igfxDTCM.dll [2018-05-06] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)

    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {0303FC85-19E4-4A49-AFA4-CCFFF15FF8CC} - System32\Tasks\Lenovo\Lenovo Service Bridge\S-1-5-21-2563344569-153408547-261685501-1001 => C:\Users\ronny\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSBUpdater.exe (Lenovo (Beijing) Limited -> Lenovo Group Limited)
    Task: {0ADF630D-EDBE-4DCC-A006-37EA17B9829E} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor)
    Task: {0F014A73-EF28-462D-BD80-A18D3C8485B7} - System32\Tasks\Maxthon5 Update => C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe (Maxthon Technology Co, Ltd. -> Maxthon International ltd.)
    Task: {19C50BE4-2339-4427-A530-669F122D488D} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\edb01cb6-ac56-424c-93cd-7bafaa0796ce => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe (Lenovo -> Lenovo Group Ltd.)
    Task: {1C0AD44A-50C4-4548-957C-8229DA347CCD} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_142_pepper.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated)
    Task: {207A4101-0AF7-4DAE-807E-686C20FE3279} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MpCmdRun.exe (Microsoft Corporation -> Microsoft Corporation)
    Task: {3108AFC8-0B77-4475-9EAF-09370455A19E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MpCmdRun.exe (Microsoft Corporation -> Microsoft Corporation)
    Task: {380BA743-88FF-441D-A82A-B652CC817F1C} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\4b8cf1e7-614e-47bd-ac35-262384fd72b4 => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe (Lenovo -> Lenovo Group Ltd.)
    Task: {3A2C7E04-E660-4AC9-BA87-34F23463BDFE} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\16cd9a68-4315-46b0-a7ee-00f7573353c6 => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe (Lenovo -> Lenovo Group Ltd.)
    Task: {3B99BBFC-A865-42D0-BD65-6C30871250B4} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_142_Plugin.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated)
    Task: {3DA05F07-282C-4442-98E3-0F09C9650D65} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MpCmdRun.exe (Microsoft Corporation -> Microsoft Corporation)
    Task: {56459180-EFEE-41F5-A5DE-1AAC75A3848F} - System32\Tasks\App Explorer => C:\Users\ronny\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe (SweetLabs Inc. -> SweetLabs, Inc) <==== ATTENTION
    Task: {5EA95F1C-CD90-4E33-909E-31BE54A712D4} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\fbfe6ea8-434b-478b-b245-2780780f9918 => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe (Lenovo -> Lenovo Group Ltd.)
    Task: {716B90CE-A416-4784-BA18-242EC524DABE} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask => %windir%\System32\reg.exe add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler /v start /t reg_dword /d 1 /f /reg:32
    Task: {8ED2C411-7510-43C9-A180-9D84045CF0DC} - System32\Tasks\RtHDVBg_LENOVO_DOLBYDRAGON => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor)
    Task: {BE77526C-BEAF-4E49-86F6-D04BC84A3FF2} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => "%windir%\system32\sc.exe" START ImControllerService
    Task: {C8CB119B-45DD-40AA-8460-12E0493DB950} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe (McAfee, Inc. -> McAfee, Inc.)
    Task: {D63E305F-62FD-4616-AFF1-8D3480EA39F5} - System32\Tasks\NCH Software\SwitchSevenDays => C:\Program Files (x86)\NCH Software\Switch\Switch.exe (NCH Software Pty Ltd -> NCH Software)
    Task: {D8BC2351-5AC2-49A7-BE4E-A17B21659A15} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated)
    Task: {E7036E5E-8078-4B67-A5FD-A1F8A0CEE5D1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MpCmdRun.exe (Microsoft Corporation -> Microsoft Corporation)
    Task: {EBF36B46-CBDF-45A6-B321-60F118CB9CC3} - System32\Tasks\LenovoUtility Task => C:\Windows\explorer.exe lenovo-utility://
    Task: {ED066DF5-E55B-4A40-B888-00144190843A} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Monitor => C:\WINDOWS\system32\ImController.InfInstaller.exe (Lenovo -> Lenovo Group Ltd.)
    Task: {FA6D3E51-BDBD-490F-B0FD-8CECC50F7079} - System32\Tasks\RtHDVBg_Dolby => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor)

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


    ==================== Shortcuts & WMI ========================

    (The entries could be listed to be restored or removed.)


    ==================== Loaded Modules (Whitelisted) ==============

    2018-12-14 16:36 - 2018-12-14 16:36 - 000077824 _____ () [File not signed] C:\ProgramData\Logishrd\LogiOptions\Software\Current\laclient\zlib.dll
    2018-12-14 16:36 - 2018-12-14 16:36 - 000355840 _____ (The cURL library, hxxp://curl.haxx.se/) [File not signed] C:\ProgramData\Logishrd\LogiOptions\Software\Current\laclient\LIBCURL.dll
    2018-12-14 16:36 - 2018-12-14 16:36 - 000144896 _____ () [File not signed] C:\ProgramData\Logishrd\LogiOptions\Software\Current\laclient\libssh2.dll
    2018-12-14 16:36 - 2018-12-14 16:36 - 002286747 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\ProgramData\Logishrd\LogiOptions\Software\Current\laclient\LIBEAY32.dll
    2018-12-14 16:36 - 2018-12-14 16:36 - 000416627 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\ProgramData\Logishrd\LogiOptions\Software\Current\laclient\SSLEAY32.dll
    2019-02-02 13:10 - 2019-02-01 10:56 - 000438272 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5WinExtras.dll
    2019-02-02 13:09 - 2019-02-01 10:56 - 005139968 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Gui.dll
    2019-02-02 13:09 - 2019-02-01 10:56 - 003084800 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Quick.dll
    2019-02-02 13:10 - 2019-02-01 10:56 - 004571648 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Widgets.dll
    2019-02-02 13:09 - 2019-02-01 10:55 - 005010944 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Core.dll
    2019-02-02 13:09 - 2019-02-01 10:56 - 002950144 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Qml.dll
    2019-02-02 13:09 - 2019-02-01 10:56 - 002234880 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Network.dll
    2019-02-26 08:08 - 2019-02-01 10:56 - 001181184 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\platforms\qwindows.dll
    2019-02-26 08:08 - 2019-02-01 10:56 - 000124928 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\styles\qwindowsvistastyle.dll
    2019-02-26 08:08 - 2019-02-01 10:56 - 000026112 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qico.dll
    2019-02-26 08:08 - 2019-02-01 10:56 - 000020992 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qsvg.dll
    2019-02-02 13:10 - 2019-02-01 10:56 - 000259584 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Svg.dll
    2019-02-26 08:08 - 2019-02-01 10:56 - 000014848 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick.2\qtquick2plugin.dll
    2019-02-26 08:08 - 2019-02-01 10:56 - 000729088 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\qtquickcontrolsplugin.dll
    2019-02-26 08:08 - 2019-02-01 10:56 - 000073216 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Layouts\qquicklayoutsplugin.dll
    2019-02-26 08:08 - 2019-02-01 10:56 - 000179712 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\dialogplugin.dll
    2019-02-26 08:08 - 2019-02-01 10:56 - 000014848 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Window.2\windowplugin.dll
    2019-02-26 08:08 - 2019-02-01 10:56 - 000014848 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQml\Models.2\modelsplugin.dll
    2019-02-26 08:08 - 2019-02-01 10:56 - 000101888 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\PrivateWidgets\widgetsplugin.dll
    2019-02-26 08:08 - 2019-02-01 10:56 - 000035328 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\iconengines\qsvgicon.dll
    2019-02-02 14:00 - 2018-08-13 00:29 - 001255424 _____ (Robert Simpson, et al.) [File not signed] C:\ProgramData\Lenovo\iMController\Plugins\GenericMessagingPlugin\x86\x86\SQLite.Interop.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)


    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


    ==================== Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)


    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2018-04-11 18:38 - 2018-04-11 18:36 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path: C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT
    HKU\S-1-5-21-2563344569-153408547-261685501-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\ronny\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\20180626_061637.jpg
    DNS Servers: 192.168.1.1
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    If an entry is included in the fixlist, it will be removed.


    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [{B6244532-8F31-485E-97AD-6131BC46AF7A}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
    FirewallRules: [{75E5CCD8-E30F-4E98-A71E-48F24F33F450}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
    FirewallRules: [UDP Query User{9AE87BEB-DDC6-42FF-AE2A-CA4C15DBA486}C:\users\ronny\documents\dwyco\cdc-x\cdcx.exe] => (Allow) C:\users\ronny\documents\dwyco\cdc-x\cdcx.exe (Dwyco, Inc. -> )
    FirewallRules: [TCP Query User{5A17486F-38A5-4F75-A52C-D1418AC7BA32}C:\users\ronny\documents\dwyco\cdc-x\cdcx.exe] => (Allow) C:\users\ronny\documents\dwyco\cdc-x\cdcx.exe (Dwyco, Inc. -> )
    FirewallRules: [{FD63A565-A786-446E-8ABA-057888C5DEC0}] => (Allow) C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOptionsMgr.EXE (Logitech Inc -> Logitech, Inc.)
    FirewallRules: [UDP Query User{DFCB5FB7-1383-4289-964C-AB0E575FE84C}C:\users\ronny\onedrive\documents\dwyco\cdc-x\cdcx.exe] => (Allow) C:\users\ronny\onedrive\documents\dwyco\cdc-x\cdcx.exe (Dwyco, Inc. -> )
    FirewallRules: [TCP Query User{DE83D8F0-4DC3-4615-BC7C-E1552D8B6BA3}C:\users\ronny\onedrive\documents\dwyco\cdc-x\cdcx.exe] => (Allow) C:\users\ronny\onedrive\documents\dwyco\cdc-x\cdcx.exe (Dwyco, Inc. -> )
    FirewallRules: [{821AFEB3-FA53-4151-A52E-A5154C0CBEC4}] => (Allow) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe (Maxthon Technology Co, Ltd. -> Maxthon International ltd.)
    FirewallRules: [{689283AB-5F2B-4CD5-AC28-0C4DBF972BC8}] => (Allow) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe (Maxthon Technology Co, Ltd. -> Maxthon International ltd.)
    FirewallRules: [{9ED2A87C-9EC4-413C-AF33-32D93891E375}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe No File
    FirewallRules: [{5A6D8FE2-0692-4E73-B43F-F3BD38CCD56F}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe No File
    FirewallRules: [{68A18C2B-DA57-474E-87B7-4F1B95611589}] => (Allow) C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16010.9126.2116.0_x86__8wekyb3d8bbwe\Office16\OUTLOOK.exe No File
    FirewallRules: [{4ECADDAF-098F-4649-A707-4E8A95C63502}] => (Allow) C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.11328.20146.0_x86__8wekyb3d8bbwe\Office16\OUTLOOK.exe (Microsoft Corporation -> Microsoft Corporation)
    FirewallRules: [{03D4CD9D-7BF7-40AA-9D32-BC48A28656BE}] => (Allow) C:\Users\ronny\Desktop\FRST64.exe (Farbar) [File not signed]
    FirewallRules: [{A02964A7-951A-4798-B79B-FB98726C7662}] => (Allow) C:\Users\ronny\Desktop\FRST64.exe (Farbar) [File not signed]
    FirewallRules: [{2B9E177A-CE36-4995-A70B-EE0737B681F5}] => (Allow) C:\Users\ronny\Desktop\FRST64.exe (Farbar) [File not signed]
    FirewallRules: [{C7D10C69-1C1C-4697-A7B8-E1224E49764F}] => (Allow) C:\Users\ronny\Desktop\FRST64.exe (Farbar) [File not signed]

    ==================== Restore Points =========================

    02-03-2019 06:21:17 Windows Update
    09-03-2019 02:07:46 Windows Update

    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (03/11/2019 10:13:52 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: AUDIODG.EXE, version: 10.0.17763.292, time stamp: 0xa0a39b52
    Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
    Exception code: 0xc0000005
    Fault offset: 0x0000000000000000
    Faulting process id: 0x1bc8
    Faulting application start time: 0x01d4d87a2bdeb8e9
    Faulting application path: C:\WINDOWS\system32\AUDIODG.EXE
    Faulting module path: unknown
    Report Id: 2915a93f-3ef4-4da4-b152-43301311da82
    Faulting package full name:
    Faulting package-relative application ID:

    Error: (03/11/2019 07:13:16 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: AUDIODG.EXE, version: 10.0.17763.292, time stamp: 0xa0a39b52
    Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
    Exception code: 0xc0000005
    Fault offset: 0x0000000000000000
    Faulting process id: 0xe80
    Faulting application start time: 0x01d4d8671d240a53
    Faulting application path: C:\WINDOWS\system32\AUDIODG.EXE
    Faulting module path: unknown
    Report Id: 15b27ccf-9db9-46fc-97cf-601612c4110f
    Faulting package full name:
    Faulting package-relative application ID:

    Error: (03/11/2019 09:24:35 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: AUDIODG.EXE, version: 10.0.17763.292, time stamp: 0xa0a39b52
    Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
    Exception code: 0xc0000005
    Fault offset: 0x0000000000000000
    Faulting process id: 0x1158
    Faulting application start time: 0x01d4d81626620566
    Faulting application path: C:\WINDOWS\system32\AUDIODG.EXE
    Faulting module path: unknown
    Report Id: 07e28ccf-3514-472b-adfe-16f3fb1d8f5f
    Faulting package full name:
    Faulting package-relative application ID:

    Error: (03/11/2019 12:03:16 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: dwm.exe, version: 10.0.17763.1, time stamp: 0xe52aabf3
    Faulting module name: dwmcore.dll, version: 10.0.17763.168, time stamp: 0x23095d3f
    Exception code: 0xc00001ad
    Fault offset: 0x00000000001e8b4e
    Faulting process id: 0x46c
    Faulting application start time: 0x01d4d741edc71548
    Faulting application path: C:\WINDOWS\system32\dwm.exe
    Faulting module path: C:\WINDOWS\system32\dwmcore.dll
    Report Id: dcbcfe20-6a97-4118-aaff-0f26caf8e817
    Faulting package full name:
    Faulting package-relative application ID:

    Error: (03/10/2019 08:10:52 PM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program svchost.exe version 10.0.17763.1 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

    Process ID: a28

    Start Time: 01d4d741ef40515e

    Termination Time: 4294967295

    Application Path: C:\Windows\System32\svchost.exe

    Report Id: dc10856f-c91e-433f-9afe-160c2c6f880e

    Faulting package full name:

    Faulting package-relative application ID:

    Hang type: Cross-process

    Error: (03/10/2019 06:39:40 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: AUDIODG.EXE, version: 10.0.17763.292, time stamp: 0xa0a39b52
    Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
    Exception code: 0xc0000005
    Fault offset: 0x0000000000000000
    Faulting process id: 0x36a8
    Faulting application start time: 0x01d4d79a8747d984
    Faulting application path: C:\WINDOWS\system32\AUDIODG.EXE
    Faulting module path: unknown
    Report Id: d429ce67-fe82-4c3a-8ee9-7a4054eabe07
    Faulting package full name:
    Faulting package-relative application ID:

    Error: (03/10/2019 06:32:51 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: AUDIODG.EXE, version: 10.0.17763.292, time stamp: 0xa0a39b52
    Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
    Exception code: 0xc0000005
    Fault offset: 0x0000000000000000
    Faulting process id: 0x21f8
    Faulting application start time: 0x01d4d79992d5df90
    Faulting application path: C:\WINDOWS\system32\AUDIODG.EXE
    Faulting module path: unknown
    Report Id: 30db91e9-8068-4983-8fff-6495b473524c
    Faulting package full name:
    Faulting package-relative application ID:

    Error: (03/10/2019 09:07:56 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: AUDIODG.EXE, version: 10.0.17763.292, time stamp: 0xa0a39b52
    Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
    Exception code: 0xc0000005
    Fault offset: 0x0000000000000000
    Faulting process id: 0x3a40
    Faulting application start time: 0x01d4d7480b499eae
    Faulting application path: C:\WINDOWS\system32\AUDIODG.EXE
    Faulting module path: unknown
    Report Id: 47e7c97d-f8f6-4b3c-bc9c-2507fad13cc3
    Faulting package full name:
    Faulting package-relative application ID:


    System errors:
    =============
    Error: (03/11/2019 10:16:35 PM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-7SS3QTOI)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
    and APPID
    {15C20B67-12E7-4BB6-92BB-7AFF07997402}
    to the user LAPTOP-7SS3QTOI\ronny SID (S-1-5-21-2563344569-153408547-261685501-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

    Error: (03/11/2019 10:16:34 PM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-7SS3QTOI)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
    and APPID
    {15C20B67-12E7-4BB6-92BB-7AFF07997402}
    to the user LAPTOP-7SS3QTOI\ronny SID (S-1-5-21-2563344569-153408547-261685501-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

    Error: (03/11/2019 09:18:53 PM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-7SS3QTOI)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
    and APPID
    {15C20B67-12E7-4BB6-92BB-7AFF07997402}
    to the user LAPTOP-7SS3QTOI\ronny SID (S-1-5-21-2563344569-153408547-261685501-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

    Error: (03/11/2019 09:18:53 PM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-7SS3QTOI)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
    and APPID
    {15C20B67-12E7-4BB6-92BB-7AFF07997402}
    to the user LAPTOP-7SS3QTOI\ronny SID (S-1-5-21-2563344569-153408547-261685501-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

    Error: (03/11/2019 09:15:26 PM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-7SS3QTOI)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
    and APPID
    {15C20B67-12E7-4BB6-92BB-7AFF07997402}
    to the user LAPTOP-7SS3QTOI\ronny SID (S-1-5-21-2563344569-153408547-261685501-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

    Error: (03/11/2019 09:15:25 PM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-7SS3QTOI)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
    and APPID
    {15C20B67-12E7-4BB6-92BB-7AFF07997402}
    to the user LAPTOP-7SS3QTOI\ronny SID (S-1-5-21-2563344569-153408547-261685501-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

    Error: (03/11/2019 06:56:58 PM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: NT AUTHORITY)
    Description: Miniport Remote NDIS based Internet Sharing Device #2, {f72efe12-e812-47ec-be3d-9570b755c139}, had event 74

    Error: (03/11/2019 09:26:58 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID
    Windows.SecurityCenter.WscBrokerManager
    and APPID
    Unavailable
    to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.


    Windows Defender:
    ===================================
    Date: 2019-03-11 20:02:31.013
    Description:
    Windows Defender Antivirus scan has been stopped before completion.
    Scan ID: {D708F15C-2A38-42CC-86B2-5D0302136DA7}
    Scan Type: Antimalware
    Scan Parameters: Quick Scan

    Date: 2019-03-11 19:51:31.420
    Description:
    Windows Defender Antivirus scan has been stopped before completion.
    Scan ID: {3CA53822-83E7-4276-B727-1B7FAD280936}
    Scan Type: Antimalware
    Scan Parameters: Quick Scan

    Date: 2019-03-11 19:46:32.050
    Description:
    Windows Defender Antivirus scan has been stopped before completion.
    Scan ID: {771CD2B9-DB42-45BF-AC0C-105788534B9C}
    Scan Type: Antimalware
    Scan Parameters: Quick Scan

    Date: 2019-03-11 19:40:14.536
    Description:
    Windows Defender Antivirus scan has been stopped before completion.
    Scan ID: {A0770082-0BDF-4DDC-BB60-B5A8A49DE3D8}
    Scan Type: Antimalware
    Scan Parameters: Quick Scan

    Date: 2019-03-10 09:50:49.422
    Description:
    Windows Defender Antivirus scan has been stopped before completion.
    Scan ID: {A94538AE-CE7C-44A3-8C21-8395AA62C12F}
    Scan Type: Antimalware
    Scan Parameters: Quick Scan

    Date: 2019-03-09 08:28:53.840
    Description:
    Windows Defender Antivirus has encountered an error trying to update signatures.
    New Signature Version:
    Previous Signature Version: 1.289.679.0
    Update Source: Microsoft Update Server
    Signature Type: AntiVirus
    Update Type: Full
    Current Engine Version:
    Previous Engine Version: 1.1.15700.9
    Error code: 0x80072f8f
    Error description: A security error occurred

    Date: 2019-03-09 00:40:22.341
    Description:
    Windows Defender Antivirus has encountered an error trying to update signatures.
    New Signature Version:
    Previous Signature Version: 1.289.679.0
    Update Source: Microsoft Update Server
    Signature Type: AntiVirus
    Update Type: Full
    Current Engine Version:
    Previous Engine Version: 1.1.15700.9
    Error code: 0x800b010f
    Error description: The certificate's CN name does not match the passed value.

    Date: 2019-03-09 00:19:28.240
    Description:
    Windows Defender Antivirus has encountered an error trying to update signatures.
    New Signature Version:
    Previous Signature Version: 1.289.679.0
    Update Source: Microsoft Update Server
    Signature Type: AntiVirus
    Update Type: Full
    Current Engine Version:
    Previous Engine Version: 1.1.15700.9
    Error code: 0x80240438
    Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

    ==================== Memory info ===========================

    Processor: Intel(R) Core(TM) i3-8130U CPU @ 2.20GHz
    Percentage of memory in use: 85%
    Total physical RAM: 4005.22 MB
    Available physical RAM: 575.72 MB
    Total Virtual: 7333.22 MB
    Available Virtual: 1039.36 MB

    ==================== Drives ================================

    Drive c: (Windows) (Fixed) (Total:930.27 GB) (Free:867.92 GB) NTFS

    \\?\Volume{eae77724-da1d-47c7-8a1a-90516e452771}\ (WINRE_DRV) (Fixed) (Total:0.98 GB) (Free:0.57 GB) NTFS
    \\?\Volume{58b722d2-9514-4e02-a23f-e06dd61b5c39}\ (SYSTEM_DRV) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (Size: 931.5 GB) (Disk ID: 346005D8)

    Partition: GPT.

    ==================== End of Addition.txt ============================

  2. #2
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    Couple of items need to be uninstalled.
    Follow the below web site to remove from windows 10

    https://www.tenforums.com/tutorials/...dows-10-a.html

    Java 8 Update 201
    Lenovo App Explorer (HKU\S-1-5-21-2563344569-153408547-261685501-1001\...\Host App Service) (Version: 0.273.2.977 - SweetLabs for Lenovo) <==== ATTENTION

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


    Start Farbar Recovery Scan Tool with Administrator privileges
    (Right click on the FRST icon and select Run as administrator)

    highlight on the text below and select Copy.
    beginning with Start:: and finishing with End::
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Highlight the entire content of the quote box below and select Copy.


    Start::
    CloseProcesses:
    CreateRestorePoint:
    C:\Users\ronny\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe
    HKU\S-1-5-21-2563344569-153408547-261685501-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com/
    SearchScopes: HKU\S-1-5-21-2563344569-153408547-261685501-1001 -> DefaultScope {2454177C-02A8-47B2-BB8B-5117BC9CF8E3} URL =
    BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\ssv.dll [2019-02-02] (Oracle America, Inc. -> Oracle Corporation)
    BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\jp2ssv.dll [2019-02-02] (Oracle America, Inc. -> Oracle Corporation)
    FF Plugin-x32: @java.com/DTPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\dtplugin\npDeployJava1.dll [2019-02-02] (Oracle America, Inc. -> Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\plugin2\npjp2.dll [2019-02-02] (Oracle America, Inc. -> Oracle Corporation)
    Task: {56459180-EFEE-41F5-A5DE-1AAC75A3848F} - System32\Tasks\App Explorer => C:\Users\ronny\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe (SweetLabs Inc. -> SweetLabs, Inc) <==== ATTENTION
    C:\Windows\Temp\*.*
    Emptytemp:
    End::

    Start FRST (FRST64) with Administrator privileges
    Press the Fix button. FRST will process the lines copied above from the clipboard.
    When finished, a log file Fixlog.txt will pop up and saved in the same location the tool was ran from.

    Please copy and paste its contents in your next reply.
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    AdwCleaner - Fix Mode
    • Download AdwCleaner and move it to your Desktop
    • Right-click on AdwCleaner.exe and select Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
    • Accept the EULA (I accept), then click on Scan
    • Let the scan complete. Once it's done, make sure that every item listed in the different tabs is checked and click on the Clean & Repair button. This will kill all the active processes
    • Once the cleaning process is complete, AdwCleaner will ask to restart your computer, do it
    • After the restart, a log will open when logging in. Please copy/paste the content of that log in your next reply



    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    RogueKiller
    • Download the right version of RogueKiller for your Windows version (32 or 64-bit)
    • Once done, move the executable file to your Desktop, right-click on it and select Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
    • Click on the Start Scan button in the right panel, which will bring you to another tab, and click on it again (this time it'll be in the bottom right corner)
    • Wait for the scan to complete
    • On completion, the results will be displayed
    • Check every single entry (threat found), and click on the Remove Selected button
    • On completion, the results will be displayed. Click on the Open Report button in the bottom left corner, followed by the Open TXT button (also in the bottom left corner)
    • This will open the report in Notepad. Copy/paste its content in your next reply

    created by Aura

    Please post these 3 logs when finished.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  3. #3
    Senior Member
    Join Date
    Feb 2008
    Location
    L.A. (Lower Arkansas)
    Posts
    381

    Default

    hello hope you are doing well thanks for the help!

    Fix result of Farbar Recovery Scan Tool (x64) Version: 11.03.2019
    Ran by ronny (12-03-2019 23:45:38) Run:1
    Running from C:\Users\ronny\Desktop
    Loaded Profiles: ronny (Available Profiles: ronny)
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    CloseProcesses:
    CreateRestorePoint:
    C:\Users\ronny\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe
    HKU\S-1-5-21-2563344569-153408547-261685501-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com/
    SearchScopes: HKU\S-1-5-21-2563344569-153408547-261685501-1001 -> DefaultScope {2454177C-02A8-47B2-BB8B-5117BC9CF8E3} URL =
    BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\ssv.dll [2019-02-02] (Oracle America, Inc. -> Oracle Corporation)
    BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\jp2ssv.dll [2019-02-02] (Oracle America, Inc. -> Oracle Corporation)
    FF Plugin-x32: @java.com/DTPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\dtplugin\npDeployJava1.dll [2019-02-02] (Oracle America, Inc. -> Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\plugin2\npjp2.dll [2019-02-02] (Oracle America, Inc. -> Oracle Corporation)
    Task: {56459180-EFEE-41F5-A5DE-1AAC75A3848F} - System32\Tasks\App Explorer => C:\Users\ronny\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe (SweetLabs Inc. -> SweetLabs, Inc) <==== ATTENTION
    C:\Windows\Temp\*.*
    Emptytemp:

    *****************

    Processes closed successfully.
    Restore point was successfully created.
    "C:\Users\ronny\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe" => not found
    "HKU\S-1-5-21-2563344569-153408547-261685501-1001\Software\Microsoft\Internet Explorer\Main\\Secondary Start Pages" => removed successfully
    "HKU\S-1-5-21-2563344569-153408547-261685501-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => not found
    HKLM\Software\Wow6432Node\Classes\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => not found
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} => not found
    HKLM\Software\Wow6432Node\Classes\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} => not found
    "HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\dtplugin\npDeployJava1.dll [2019-02-02] (Oracle America, Inc." => not found
    "C:\Program Files (x86)\Java\jre1.8.0_201\bin\dtplugin\npDeployJava1.dll" => not found
    "HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\plugin2\npjp2.dll [2019-02-02] (Oracle America, Inc." => not found
    "C:\Program Files (x86)\Java\jre1.8.0_201\bin\plugin2\npjp2.dll" => not found
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{56459180-EFEE-41F5-A5DE-1AAC75A3848F}" => not found
    "C:\WINDOWS\System32\Tasks\App Explorer" => not found
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\App Explorer" => not found

    =========== "C:\Windows\Temp\*.*" ==========

    Could not move "C:\Windows\Temp\FXSAPIDebugLogFile.txt" => Scheduled to move on reboot.
    Could not move "C:\Windows\Temp\FXSTIFFDebugLogFile.txt" => Scheduled to move on reboot.
    C:\Windows\Temp\InfInstallerLog._19-03-11_10-21-04-388.log => moved successfully
    C:\Windows\Temp\InfInstallerLog._19-03-11_10-21-10-082.log => moved successfully
    C:\Windows\Temp\InfInstallerLog._19-03-11_10-21-15-216.log => moved successfully
    C:\Windows\Temp\InfInstallerLog._19-03-11_10-21-20-912.log => moved successfully
    C:\Windows\Temp\InfInstallerLog._19-03-11_10-21-26-018.log => moved successfully
    C:\Windows\Temp\InfInstallerLog._19-03-11_10-21-31-987.log => moved successfully
    C:\Windows\Temp\InfInstallerLog._19-03-11_10-21-37-205.log => moved successfully
    C:\Windows\Temp\InfInstallerLog._19-03-11_10-21-43-257.log => moved successfully
    C:\Windows\Temp\MpCmdRun.log => moved successfully
    C:\Windows\Temp\MpSigStub.log => moved successfully
    C:\Windows\Temp\MX_LOG_10.log => moved successfully
    C:\Windows\Temp\MX_LOG_11.log => moved successfully
    Could not move "C:\Windows\Temp\RightSight.log" => Scheduled to move on reboot.
    C:\Windows\Temp\WER11D9.tmp.WERDataCollectionStatus.txt => moved successfully

    ========= End -> "C:\Windows\Temp\*.*" ========


    =========== EmptyTemp: ==========

    BITS transfer queue => 7626752 B
    DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 24409520 B
    Java, Flash, Steam htmlcache => 4796 B
    Windows/system/drivers => 4201280 B
    Edge => 8143710 B
    Chrome => 0 B
    Firefox => 1086834172 B
    Opera => 0 B

    Temp, IE cache, history, cookies, recent:
    Default => 0 B
    Users => 0 B
    ProgramData => 0 B
    Public => 0 B
    systemprofile => 0 B
    systemprofile32 => 0 B
    LocalService => 0 B
    LocalService => 0 B
    NetworkService => 32110 B
    NetworkService => 0 B
    ronny => 634875683 B

    RecycleBin => 10021111 B
    EmptyTemp: => 1.7 GB temporary data Removed.

    ================================

    Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 12-03-2019 23:54:29)

    C:\Windows\Temp\FXSAPIDebugLogFile.txt => Is moved successfully
    C:\Windows\Temp\FXSTIFFDebugLogFile.txt => Is moved successfully
    C:\Windows\Temp\RightSight.log => Could not move

    ==== End of Fixlog 23:54:29 ====

    RogueKiller Anti-Malware V13.1.8.0 (x64) [Mar 12 2019] (Free) by Adlice Software
    mail : https://adlice.com/contact/
    Website : https://adlice.com/download/roguekiller/
    Operating System : Windows 10 (10.0.17763) 64 bits
    Started in : Normal mode
    User : ronny [Administrator]
    Started from : C:\Users\ronny\Desktop\RogueKiller\RogueKiller64.exe
    Signatures : 20190304_123840, Driver : Loaded
    Mode : Standard Scan, Scan -- Date : 2019/03/13 00:12:23 (Duration : 00:16:29)

    いいいいいいいいいいいい Processes いいいいいいいいいいいい

    いいいいいいいいいいいい Process Modules いいいいいいいいいいいい

    いいいいいいいいいいいい Services いいいいいいいいいいいい

    いいいいいいいいいいいい Tasks いいいいいいいいいいいい

    いいいいいいいいいいいい Registry いいいいいいいいいいいい

    いいいいいいいいいいいい WMI いいいいいいいいいいいい

    いいいいいいいいいいいい Hosts File いいいいいいいいいいいい

    いいいいいいいいいいいい Files いいいいいいいいいいいい

    いいいいいいいいいいいい Web browsers いいいいいいいいいいいい


    # -------------------------------
    # Malwarebytes AdwCleaner 7.2.7.0
    # -------------------------------
    # Build: 01-30-2019
    # Database: 2019-03-11.1 (Cloud)
    # Support: https://www.malwarebytes.com/support
    #
    # -------------------------------
    # Mode: Clean
    # -------------------------------
    # Start: 03-12-2019
    # Duration: 00:00:06
    # OS: Windows 10 Home
    # Cleaned: 7
    # Failed: 0


    ***** [ Services ] *****

    No malicious services cleaned.

    ***** [ Folders ] *****

    No malicious folders cleaned.

    ***** [ Files ] *****

    Deleted C:\Windows\System32\Tasks_Migrated\App Explorer

    ***** [ DLL ] *****

    No malicious DLLs cleaned.

    ***** [ WMI ] *****

    No malicious WMI cleaned.

    ***** [ Shortcuts ] *****

    No malicious shortcuts cleaned.

    ***** [ Tasks ] *****

    No malicious tasks cleaned.

    ***** [ Registry ] *****

    Deleted HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_CLIPCHILDREN_OPTIMIZATION|AppMaster.exe
    Deleted HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_GPU_RENDERING|AppMaster.exe
    Deleted HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_NINPUT_LEGACYMODE|AppMaster.exe
    Deleted HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_DOCUMENT_ZOOM|AppMaster.exe
    Deleted HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|AppMaster.exe
    Deleted HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_AJAX_CONNECTIONEVENTS|AppMaster.exe

    ***** [ Chromium (and derivatives) ] *****

    No malicious Chromium entries cleaned.

    ***** [ Chromium URLs ] *****

    No malicious Chromium URLs cleaned.

    ***** [ Firefox (and derivatives) ] *****

    No malicious Firefox entries cleaned.

    ***** [ Firefox URLs ] *****

    No malicious Firefox URLs cleaned.


    *************************

    [+] Delete Tracing Keys
    [+] Reset Winsock

    *************************

    AdwCleaner[S00].txt - [2093 octets] - [12/03/2019 23:58:33]

    ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

  4. #4
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    My opinion is your browser was hit with a malicious java script, probably embedded at a site you had visited.

    Hardening your web browser means to install extensions that will help it protect itself (and your system on the same occasion) against Exploit Kits, MiTM attacks, etc. but also you at the same time. Here are a few extensions that I recommend you to install.
    • uBlock Origin: Efficient multi-purpose blocker that is lightweight on RAM and CPU usage (Google Chrome, Mozilla Firefox, Microsoft Edge, Opera and most Chromium and Firefox-based browsers)
    • NoScript: NoScript is a script blocker (Java, Flash, JavaScript, etc.) for Mozilla Firefox and Firefox-based browsers (Mozilla Firefox and Firefox-based web browsers)

    I use NoScript, if it needs to be disabled just keep your addons window open to disable and refresh the page your on but remember to re-enable it afterwards.

    ~~~~~


    Let's check for remnants

    Open Malwarebytes Anti-Malware and click on Update


    • Under SETTINGS.....PROTECTION make sure AUTOMATIC QUARANTINE is on.
    • Then go to the Dashboard and click on SCAN NOW
    • If threats are detected, click the Apply Actions button. You will now be prompted to reboot. Click Yes.
      Upon completion of the scan (or after the reboot), click the Reports tab.
      Double-click the Scan Log.
      At the bottom click Export and choose Text file.

      Save the file to your desktop and include its content in your next reply.

      You can access the logs by going in the "Reports" tab, clicking on the latest "Scan" entry (the one with detections), then clicking on the "Export" button in the bottom-left corner and select "Copy to clipboard". After that, all you have to do is paste it here
    • Then click on POST
    • Exit Malwarebytes

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~`

    Emsisoft Emergency Kit - Fix Mode
    Follow the instructions below to run a scan using the Emsisoft Emergency Kit.
    • Download the Emsisoft Emergency Kit and execute it. From there, click on the Install button to extract the program in the EEK folder;
    • Once the extraction is complete, the EEK folder will open. Right-click on start emergency kit scanner.exe and select Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
    • EEK will suggest that you run an online update before using the program. Click on Yes to launch it.
    • After the update, click on Malware Scan under 2. Scan and accept to let EEK detect PUPs (click on Yes).
    • Once the scan is complete, make sure that every item in the list is checked, and click on the Quarantine selected button;
    • If it asks you for a reboot to delete some items, click on Ok to reboot automatically;
    • After the restart, open EEK again (in the C:\EEK folder);
    • This time, click on Logs;
    • From there, go under the Quarantine Log tab, and click on the Export button;
    • Save the log on your desktop, then open it, and copy/paste its content in your next reply;

    Please post these 2 logs when finished.

    Also, tell me how the computer is now.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  5. #5
    Senior Member
    Join Date
    Feb 2008
    Location
    L.A. (Lower Arkansas)
    Posts
    381

    Default

    ok the free version of mb wouldn't let me make those selections. the pc seems to run better and maybe it's me but still seems a bit sluggish.
    Malwarebytes
    www.malwarebytes.com

    -Log Details-
    Scan Date: 3/14/19
    Scan Time: 1:01 AM
    Log File: a1b3b3a2-461e-11e9-a989-00f48ddc7000.json

    -Software Information-
    Version: 3.7.1.2839
    Components Version: 1.0.538
    Update Package Version: 1.0.9678
    License: Expired

    -System Information-
    OS: Windows 10 (Build 17763.379)
    CPU: x64
    File System: NTFS
    User: LAPTOP-7SS3QTOI\ronny

    -Scan Summary-
    Scan Type: Threat Scan
    Scan Initiated By: Manual
    Result: Completed
    Objects Scanned: 271150
    Threats Detected: 0
    Threats Quarantined: 0
    Time Elapsed: 3 min, 57 sec

    -Scan Options-
    Memory: Enabled
    Startup: Enabled
    Filesystem: Enabled
    Archives: Enabled
    Rootkits: Disabled
    Heuristics: Enabled
    PUP: Detect
    PUM: Detect

    -Scan Details-
    Process: 0
    (No malicious items detected)

    Module: 0
    (No malicious items detected)

    Registry Key: 0
    (No malicious items detected)

    Registry Value: 0
    (No malicious items detected)

    Registry Data: 0
    (No malicious items detected)

    Data Stream: 0
    (No malicious items detected)

    Folder: 0
    (No malicious items detected)

    File: 0
    (No malicious items detected)

    Physical Sector: 0
    (No malicious items detected)

    WMI: 0
    (No malicious items detected)


    (end)

    Emsisoft Emergency Kit - Version 2018.6
    Last update: 3/14/2019 1:14:40 AM
    User account: LAPTOP-7SS3QTOI\ronny
    Computer name: LAPTOP-7SS3QTOI
    OS version: Windows 10x64

    Scan settings:

    Scan type: Malware Scan
    Objects: Rootkits, Memory, Traces, Files

    Detect PUPs: On
    Scan archives: Off
    Scan mail archives: Off
    ADS Scan: On
    File extension filter: Off
    Direct disk access: Off

    Scan start: 3/14/2019 1:16:35 AM

    Scanned 75423
    Found 0

    Scan end: 3/14/2019 1:24:25 AM
    Scan time: 0:07:50

  6. #6
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    Different reasons for it to be running slow, let's give it a day and see if that improves a bit.
    Just use it as you would normally, take note of any errors or things out of the ordinary.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  7. #7
    Senior Member
    Join Date
    Feb 2008
    Location
    L.A. (Lower Arkansas)
    Posts
    381

    Default

    ok i'll look around a bit and be back tomorrow. is java a complete nono now? i now it's being killed out but what will replace it?

  8. #8
    Senior Member
    Join Date
    Feb 2008
    Location
    L.A. (Lower Arkansas)
    Posts
    381

    Default

    well juliet, i have to say i see no significant problems and all there is to this pc seems to funtion normal or as was before. i play games that require flash and/or java, am i going to have to just give up on those or is there an alternative? buy a deck of cards?

  9. #9
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    I can help
    For I/E - some versions get 'Automatic' updates:
    - https://fpdownload.macromedia.com/pu..._player_ax.exe
    For Firefox and other Plugin-based browsers:
    - https://fpdownload.macromedia.com/pu...ash_player.exe
    For Chrome:
    - https://fpdownload.macromedia.com/pu...ayer_ppapi.exe

    Flash test site: https://www.adobe.com/software/flash/about/

    ~~~~~~~~~~~~~~~~~~

    For Java, beware, it is exploited.
    Check for updates often. https://www.java.com/en/download/
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  10. #10
    Senior Member
    Join Date
    Feb 2008
    Location
    L.A. (Lower Arkansas)
    Posts
    381

    Default

    ok thanks i''ll do that! now the only oddity i've noticed is last night my browser scrolled down all the way like it fell. it wouldn't scroll up it would just go back down. moving it manually from the side bars didn't work, also to click in my search or addy panes it would move the cursor one space at a time toi the far right side and when i'd type in one it atarted on the right side and went back left!

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •