was doing fine until maybe a week ago I had a previous problem show up again that had visited my old desktop. that was the odd Microsoft overtake of my browser that all I could do was end task in task manager of the browser. it's where suddenly your browser is taken over by a Microsoft rep (supposedly) informing of my computer is spreading virus at several websites and i'm to click a link for help. since it has slowed this normally fast LT down, noticed erratic browser behavior crashing frequently, scrolling issues so I thought i'd come say hello to you kind people. on installing the aswMBR, when i'd select yes on the virtualization twice it crashed my pc.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11.03.2019
Ran by ronny (administrator) on LAPTOP-7SS3QTOI (11-03-2019 22:47:49)
Running from C:\Users\ronny\Desktop
Loaded Profiles: ronny (Available Profiles: ronny)
Platform: Windows 10 Home Version 1809 17763.316 (X64) Language: English (United States)
Default browser: "C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe" "%1"
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\igfxCUIService.exe
(Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) C:\Windows\System32\drivers\AdminService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\IntelCpHDCPSvc.exe
(Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.) C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\jhi_service.exe
(Qualcomm Atheros -> Qualcomm Technologies Inc.) C:\Windows\System32\drivers\QcomWlanSrvx64.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnhService.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
(Logitech Inc -> Logitech) C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe
(Microsoft Corporation -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1902.2-0\MsMpEng.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\IntelCpHeciSvc.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Logitech Inc -> Logitech Europe S.A.) C:\Program Files\Logitech\Collaboration\Services\Video\RightSightAPI\RightSightService.exe
(Logitech Inc -> ) C:\Program Files\Logitech\Collaboration\Services\Video\RightSightAPI\crashpad_handler.exe
(Microsoft Corporation -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1902.2-0\NisSrv.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnh.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\igfxEM.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.YourPhone_1.0.20453.0_x64__8wekyb3d8bbwe\YourPhone.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.10314.31700.1000_x64__8wekyb3d8bbwe\Office16\OfficeHubTaskHost.exe
(Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19021.10411.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Logitech Inc -> Logitech, Inc.) C:\Program Files\Logitech\LogiOptions\LogiOptions.exe
(Logitech Inc -> Logitech, Inc.) C:\ProgramData\LogiShrd\LogiOptions\Software\Current\LogiOptionsMgr.exe
(Logitech Inc -> Logitech) C:\ProgramData\LogiShrd\LogiOptions\Software\Current\LogiOverlay.exe
(Logitech Inc -> Logitech, Inc.) C:\ProgramData\LogiShrd\LogiOptions\Software\Current\laclient\laclient.exe
(Lenovo -> Lenovo(beijing) Limited) C:\Program Files\WindowsApps\E0469640.LenovoUtility_3.0.50.0_x64__5grkq8ppsgwt4\VFS\ProgramFilesX64\Lenovo\LenovoUtility\utility.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Logitech, Inc. -> Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
(Logitech, Inc. -> ) C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(SweetLabs Inc. -> SweetLabs, Inc) C:\Users\ronny\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(Lenovo (Beijing) Limited -> Lenovo Group Limited) C:\Users\ronny\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSB.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.WindowsStore_11811.1001.18.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.18114.17710.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files (x86)\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.SettingsApp.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.CompanionApp.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files (x86)\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SndVol.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Maxthon Technology Co, Ltd. -> Maxthon International ltd.) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [LogiOptions] => C:\Program Files\Logitech\LogiOptions\LogiOptions.exe [2176648 2018-12-14] (Logitech Inc -> Logitech, Inc.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942864 2016-10-13] (Logitech -> Logitech, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-12-16] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech, Inc. -> Logitech Inc.)
HKU\S-1-5-21-2563344569-153408547-261685501-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\ronny\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"
HKU\S-1-5-21-2563344569-153408547-261685501-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\ronny\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"
HKU\S-1-5-21-2563344569-153408547-261685501-1001\...\RunOnce: [Uninstall 19.002.0107.0008\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ronny\AppData\Local\Microsoft\OneDrive\19.002.0107.0008\amd64"
HKU\S-1-5-21-2563344569-153408547-261685501-1001\...\RunOnce: [Uninstall 19.002.0107.0008] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ronny\AppData\Local\Microsoft\OneDrive\19.002.0107.0008"
Startup: C:\Users\ronny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Product Registration.lnk [2019-03-02]
ShortcutTarget: Logitech . Product Registration.lnk -> C:\Program Files (x86)\Logitech\Ereg\eReg.exe (Logitech -> Leader Technologies/Logitech)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{157c1c20-07a9-48f0-96eb-08b0ba15705c}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3c4437dd-9c7d-4241-a1ea-b136520b1063}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{b7a4ccd0-f88d-490b-949c-652a8e0776ce}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{f72efe12-e812-47ec-be3d-9570b755c139}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-2563344569-153408547-261685501-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo17win10.msn.com/?pc=LCTE
HKU\S-1-5-21-2563344569-153408547-261685501-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com/
SearchScopes: HKU\S-1-5-21-2563344569-153408547-261685501-1001 -> DefaultScope {2454177C-02A8-47B2-BB8B-5117BC9CF8E3} URL =
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\ssv.dll [2019-02-02] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\jp2ssv.dll [2019-02-02] (Oracle America, Inc. -> Oracle Corporation)

FireFox:
========
FF DefaultProfile: llfzwedj.default
FF ProfilePath: C:\Users\ronny\AppData\Roaming\Mozilla\Firefox\Profiles\llfzwedj.default [2019-03-11]
FF Homepage: Mozilla\Firefox\Profiles\llfzwedj.default -> hxxps://www.bing.com/?PC=JV01
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_142.dll [2019-02-20] (Adobe Systems Incorporated -> )
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_142.dll [2019-02-20] (Adobe Systems Incorporated -> )
FF Plugin-x32: @java.com/DTPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\dtplugin\npDeployJava1.dll [2019-02-02] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\plugin2\npjp2.dll [2019-02-02] (Oracle America, Inc. -> Oracle Corporation)

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AtherosSvc; C:\WINDOWS\System32\drivers\AdminService.exe [414696 2018-01-08] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
R2 Dolby DAX2 API Service; C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe [197120 2017-07-13] (Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.)
R2 ImControllerService; C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [71336 2019-01-07] (Lenovo -> Lenovo Group Ltd.)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\WINDOWS\System32\Intel\iCLS Client\lib\SocketHeciServer.exe [765112 2018-04-25] (Intel(R) Trust Services -> Intel(R) Corporation)
S2 Intel(R) TPM Provisioning Service; C:\WINDOWS\System32\Intel\iCLS Client\lib\TPMProvisioningService.exe [731832 2018-04-25] (Intel(R) Trust Services -> Intel(R) Corporation)
R2 jhi_service; C:\WINDOWS\System32\jhi_service.exe [576560 2018-05-23] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6562472 2019-02-01] (Malwarebytes Corporation -> Malwarebytes)
S2 MxService; C:\Program Files (x86)\Maxthon5\Bin\MxService.exe [176928 2019-02-01] (Maxthon Technology Co, Ltd. -> Maxthon International ltd.)
R2 nebula; C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe [4489352 2019-01-17] (Logitech Inc -> Logitech)
R2 QcomWlanSrv; C:\WINDOWS\System32\drivers\QcomWlanSrvx64.exe [191440 2018-09-26] (Qualcomm Atheros -> Qualcomm Technologies Inc.)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [266080 2018-07-13] (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor)
R2 SynTPEnhService; C:\WINDOWS\System32\SynTPEnhService.exe [352808 2018-04-12] (Synaptics Incorporated -> Synaptics Incorporated)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\NisSrv.exe [4098064 2019-02-22] (Microsoft Corporation -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MsMpEng.exe [113992 2019-02-22] (Microsoft Corporation -> Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 BtFilter; C:\WINDOWS\System32\drivers\btfilter.sys [65448 2018-01-08] (WDKTestCert aswbldsv,131431045756648395 -> Qualcomm)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153328 2019-01-08] (Malwarebytes Corporation -> Malwarebytes)
R3 IntcAzAudAddService; C:\WINDOWS\system32\drivers\RTKVHD64.sys [6314848 2018-07-13] (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corp.)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [198512 2019-02-26] (Malwarebytes Corporation -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2019-02-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [127136 2019-03-03] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [72864 2019-03-11] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [274416 2019-03-11] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [114040 2019-03-03] (Malwarebytes Corporation -> Malwarebytes)
R3 Qcamain10x64; C:\WINDOWS\System32\drivers\Qcamain10x64.sys [2358736 2018-09-26] (Qualcomm Atheros -> Qualcomm Atheros, Inc.)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1026896 2018-01-25] (Realtek Semiconductor Corp. -> Realtek )
S3 rtsuvc; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [3236320 2017-11-26] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.)
R3 SmbDrvI; C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [48168 2018-04-12] (Synaptics Incorporated -> Synaptics Incorporated)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 stdriver; C:\WINDOWS\system32\DRIVERS\stdriverx64.sys [53488 2019-02-10] (NCH Software Pty Ltd -> )
R3 SynRMIHID; C:\WINDOWS\System32\drivers\SynRMIHID.sys [61480 2018-04-12] (Synaptics Incorporated -> Synaptics Incorporated)
R3 usbrndis6; C:\WINDOWS\System32\drivers\usb80236.sys [24576 2018-09-15] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46472 2019-02-22] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [333792 2019-02-22] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [62432 2019-02-22] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-03-11 22:47 - 2019-03-11 22:50 - 000018986 _____ C:\Users\ronny\Desktop\FRST.txt
2019-03-11 22:47 - 2019-03-11 22:47 - 000000000 ____D C:\FRST
2019-03-11 22:35 - 2019-03-11 22:35 - 002434560 _____ (Farbar) C:\Users\ronny\Desktop\FRST64.exe
2019-03-11 22:34 - 2019-03-11 22:34 - 000002315 _____ C:\Users\Public\Desktop\Tweaking.com - Registry Backup.lnk
2019-03-11 22:34 - 2019-03-11 22:34 - 000000207 _____ C:\WINDOWS\tweaking.com-regbackup-LAPTOP-7SS3QTOI-Windows-10-Home-(64-bit).dat
2019-03-11 22:34 - 2019-03-11 22:34 - 000000000 ____D C:\RegBackup
2019-03-11 22:34 - 2019-03-11 22:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2019-03-11 22:34 - 2019-03-11 22:34 - 000000000 ____D C:\Program Files (x86)\Tweaking.com
2019-03-11 22:33 - 2019-03-11 22:34 - 000017985 _____ C:\WINDOWS\Tweaking.com - Registry Backup Setup Log.txt
2019-03-11 22:30 - 2019-03-11 22:30 - 005766144 _____ (Tweaking.com) C:\Users\ronny\Desktop\tweaking.com_registry_backup_setup.exe
2019-03-07 15:03 - 2019-03-07 15:08 - 000000000 ____D C:\Users\ronny\Desktop\trail cams
2019-03-07 07:00 - 2019-03-07 07:00 - 000004590 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2019-03-05 08:59 - 2019-03-05 08:59 - 000000738 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 10 Update Assistant.lnk
2019-03-05 08:59 - 2019-03-05 08:59 - 000000000 ____D C:\Windows10Upgrade
2019-03-04 18:33 - 2018-09-26 16:11 - 002358736 _____ (Qualcomm Atheros, Inc.) C:\WINDOWS\system32\Drivers\Qcamain10x64.sys
2019-03-04 18:33 - 2018-09-26 16:11 - 001136016 _____ C:\WINDOWS\system32\Drivers\qca9377_2_0.bin
2019-03-04 18:33 - 2018-09-26 16:11 - 000191440 _____ (Qualcomm Technologies Inc.) C:\WINDOWS\system32\Drivers\QcomWlanSrvx64.exe
2019-03-04 18:33 - 2018-09-26 16:11 - 000097201 _____ C:\WINDOWS\system32\Drivers\Data9377_2_0.msc
2019-03-04 18:33 - 2018-09-26 16:11 - 000008124 _____ C:\WINDOWS\system32\Drivers\eeprom_qca9377_1p1_NFA435_olpc_LE_15.bin
2019-03-04 18:33 - 2018-09-26 16:11 - 000008124 _____ C:\WINDOWS\system32\Drivers\eeprom_qca9377_1p1_NFA435_olpc_LE_14.bin
2019-03-04 18:33 - 2018-09-26 16:11 - 000008124 _____ C:\WINDOWS\system32\Drivers\eeprom_qca9377_1p1_NFA435_olpc_LE_13.bin
2019-03-04 18:33 - 2018-09-26 16:11 - 000008124 _____ C:\WINDOWS\system32\Drivers\eeprom_qca9377_1p1_NFA435_olpc_LE_12.bin
2019-03-04 18:33 - 2018-09-26 16:11 - 000008124 _____ C:\WINDOWS\system32\Drivers\eeprom_qca9377_1p1_NFA435_olpc_LE_11.bin
2019-03-03 05:14 - 2019-03-11 09:24 - 000072864 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2019-03-03 05:14 - 2019-03-03 05:14 - 000127136 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2019-03-03 05:13 - 2019-03-11 09:24 - 000274416 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2019-03-03 05:13 - 2019-03-03 05:13 - 000114040 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2019-03-02 07:13 - 2019-03-02 06:13 - 000000000 ____D C:\Windows.old
2019-03-02 07:05 - 2019-03-02 07:13 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2019-03-02 07:01 - 2019-03-02 07:04 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2019-03-02 07:01 - 2019-03-02 07:01 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2019-03-02 06:52 - 2019-03-02 06:52 - 024617472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 019284480 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 011724288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 009941504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 007724992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 005440008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 005112792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 004918784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 003566080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 003550384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 002986352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 002469648 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 002429752 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
2019-03-02 06:52 - 2019-03-02 06:52 - 002323696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 002278448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 002160160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
2019-03-02 06:52 - 2019-03-02 06:52 - 001294864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 001289192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 001282640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 001259024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2019-03-02 06:52 - 2019-03-02 06:52 - 001200920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 001166336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl
2019-03-02 06:52 - 2019-03-02 06:52 - 001073448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 001057976 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2adec.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 001024920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 001022464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 000870400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 000854784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2adec.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 000829440 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 000762272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 000662528 ____R (Microsoft Corporation) C:\WINDOWS\system32\MixedRealityCapture.Pipeline.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 000654848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 000577024 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicExtensions.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 000454144 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 000429056 _____ (Microsoft Corporation) C:\WINDOWS\system32\MixedReality.Broker.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 000427520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 000421904 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 000371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 000301096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpeffects.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 000263360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 000241680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpeffects.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 000218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpdxm.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 000167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpdxm.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 000166400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscinterop.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 000125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpshell.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 000098816 ____R (Microsoft Corporation) C:\WINDOWS\system32\MixedRealityCapture.Broker.dll
2019-03-02 06:52 - 2019-03-02 06:52 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpshell.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 026807296 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 023439360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 020812288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 019023872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 015224832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 012858368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 012151808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 008875520 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 007897088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 007883776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 006925824 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 006540424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 006306152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 006070272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 005764608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 005584864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 005205464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 005086208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 004885504 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 004688896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 004627456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 004526080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupapi.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 003952952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 003922944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 003743744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 003730352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2019-03-02 06:51 - 2019-03-02 06:51 - 003656192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 003504640 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 003427328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 003108864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 002942464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 002927120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2019-03-02 06:51 - 2019-03-02 06:51 - 002893312 _____ (Microsoft Corporation) C:\WINDOWS\system32\themeui.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 002832896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themeui.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 002776920 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 002765312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 002702528 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 002689024 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 002626592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2019-03-02 06:51 - 2019-03-02 06:51 - 002392576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 002346496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 002298880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 002275888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 002086400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsservices.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 002072728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001994768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001969680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys
2019-03-02 06:51 - 2019-03-02 06:51 - 001899160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001863168 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001783296 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001762816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001749504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001720936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001711104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001700864 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001696936 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2019-03-02 06:51 - 2019-03-02 06:51 - 001688576 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001675712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001674480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001671864 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001590288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001506304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001484800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001476096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001467560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001467384 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2019-03-02 06:51 - 2019-03-02 06:51 - 001456736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001446400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc42u.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001415680 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc42.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001395248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001391096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Taskmgr.exe
2019-03-02 06:51 - 2019-03-02 06:51 - 001387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001360696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2019-03-02 06:51 - 2019-03-02 06:51 - 001341584 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2019-03-02 06:51 - 2019-03-02 06:51 - 001311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001309696 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001309184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001294848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001279024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Taskmgr.exe
2019-03-02 06:51 - 2019-03-02 06:51 - 001271608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001254912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001224704 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001221528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2019-03-02 06:51 - 2019-03-02 06:51 - 001192448 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001182720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl
2019-03-02 06:51 - 2019-03-02 06:51 - 001180760 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001178344 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2019-03-02 06:51 - 2019-03-02 06:51 - 001168384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001162280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001110528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001098136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001064448 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001047552 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001026992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001018880 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 001010176 _____ (Microsoft Corporation) C:\WINDOWS\system32\refsutil.exe
2019-03-02 06:51 - 2019-03-02 06:51 - 000982032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refsv1.sys
2019-03-02 06:51 - 2019-03-02 06:51 - 000972288 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000964976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000953856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000949760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000947200 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000913920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000901632 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000883200 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000882688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2019-03-02 06:51 - 2019-03-02 06:51 - 000875008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000833536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000803328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000800256 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000794112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000787456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000782968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000769536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2019-03-02 06:51 - 2019-03-02 06:51 - 000762368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprddm.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000742912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceControl.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000729088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000726208 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000703488 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Language.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000690688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000684032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000681984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000663552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000663040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000652320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000649272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000624640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apphelp.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000622592 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000615936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000604248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.applicationmodel.datatransfer.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000588304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2019-03-02 06:51 - 2019-03-02 06:51 - 000585728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000570368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000553984 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000535048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2019-03-02 06:51 - 2019-03-02 06:51 - 000532480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000522312 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2019-03-02 06:51 - 2019-03-02 06:51 - 000514112 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000492032 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragsvc.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000481792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000475152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2019-03-02 06:51 - 2019-03-02 06:51 - 000454160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2019-03-02 06:51 - 2019-03-02 06:51 - 000451072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000449024 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000434176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000430904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
2019-03-02 06:51 - 2019-03-02 06:51 - 000429568 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000424960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000403968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoMetadataHandler.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000398848 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000383288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msrpc.sys
2019-03-02 06:51 - 2019-03-02 06:51 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000373768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\coml2.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000358400 _____ (Microsoft Corporation) C:\WINDOWS\regedit.exe
2019-03-02 06:51 - 2019-03-02 06:51 - 000352768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000349184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2019-03-02 06:51 - 2019-03-02 06:51 - 000349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000340480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\udfs.sys
2019-03-02 06:51 - 2019-03-02 06:51 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000329216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\regedit.exe
2019-03-02 06:51 - 2019-03-02 06:51 - 000316416 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000314368 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcLayers.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000313344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd2x40.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000312832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.Workflow.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000312832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000297984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Diagnostics.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000293376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2019-03-02 06:51 - 2019-03-02 06:51 - 000289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\discan.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wisp.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000284160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasppp.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000277536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000262672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2019-03-02 06:51 - 2019-03-02 06:51 - 000252536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngOnline.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000226816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wisp.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000222720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prnntfy.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscinterop.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000201216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincredui.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\spacebridge.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000176440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2019-03-02 06:51 - 2019-03-02 06:51 - 000173568 _____ (Microsoft Corporation) C:\WINDOWS\system32\WPTaskScheduler.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrrun.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\spopk.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000159744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincredui.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasman.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\CastingShellExt.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000146888 _____ (Microsoft Corporation) C:\WINDOWS\system32\smss.exe
2019-03-02 06:51 - 2019-03-02 06:51 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintWorkflowService.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceAgent.exe
2019-03-02 06:51 - 2019-03-02 06:51 - 000134144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CastingShellExt.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spopk.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000121872 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdnet.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000114344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rmclient.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\dab.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000104960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.NetworkOperators.HotspotAuthentication.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000104960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupcln.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cdfs.sys
2019-03-02 06:51 - 2019-03-02 06:51 - 000095744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000094224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fileinfo.sys
2019-03-02 06:51 - 2019-03-02 06:51 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlahc.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\PktMon.exe
2019-03-02 06:51 - 2019-03-02 06:51 - 000091424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CompPkgSup.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\nslookup.exe
2019-03-02 06:51 - 2019-03-02 06:51 - 000078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nslookup.exe
2019-03-02 06:51 - 2019-03-02 06:51 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsiwmi.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SMSRouter.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdBth.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdBth.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfts.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfts.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\msisip.dll
2019-03-02 06:51 - 2019-03-02 06:51 - 000024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msisip.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 022111856 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 017520640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 009683984 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 007685016 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 007645600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 006132736 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 005565952 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 005561856 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 005527552 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 005312512 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 005130752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 004991096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 004702704 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupapi.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 004588544 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 004298752 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 004245280 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 004019200 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 003982848 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 003662336 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 003556352 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 003386368 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 003379000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 003338328 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 003334144 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 003270144 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 003092480 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 002992640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 002929152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 002879488 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsservices.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 002843136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 002766136 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 002721280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 002654208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 002630656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 002618880 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 002594872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 002488320 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 002466304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 002437552 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 002187264 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 002185728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 002149368 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 002085376 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 002021584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001975296 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001903616 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001884672 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001842600 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001830912 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001824768 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001819136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001797128 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001715712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001700880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001671680 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001664904 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001641400 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001616384 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001604096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001533440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001520208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001496064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001462272 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001387496 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001331744 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001315840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001314304 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001287776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001267712 _____ (Microsoft Corporation) C:\WINDOWS\system32\APMon.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001258512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 001255736 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 001249792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001221120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 001212416 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001209360 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvstore.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001199104 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001057792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 001056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\pidgenx.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001054200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 001051960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 001050936 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 001050624 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 001005568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000998912 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000982576 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000970256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\drvstore.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000955392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000954368 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000925184 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000918304 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000897848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000890368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000889344 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000887808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprddm.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000865784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000864056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 000863752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000854016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000850968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000836096 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000822448 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000820736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000818832 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.applicationmodel.datatransfer.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000806560 _____ C:\WINDOWS\SysWOW64\locale.nls
2019-03-02 06:50 - 2019-03-02 06:50 - 000806560 _____ C:\WINDOWS\system32\locale.nls
2019-03-02 06:50 - 2019-03-02 06:50 - 000801792 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000799568 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000773120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000765960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000756640 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 000752136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000744960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000741888 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000681984 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000680184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000669184 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationFrame.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000663552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000660496 _____ (Microsoft Corporation) C:\WINDOWS\system32\computecore.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000651792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000651304 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 000648192 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32time.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000629576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000612368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000609792 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000604552 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 000593920 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000582240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000580024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2019-03-02 06:50 - 2019-03-02 06:50 - 000577536 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofmsvc.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000566584 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000556544 _____ (Microsoft Corporation) C:\WINDOWS\system32\BTAGService.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000547840 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000543744 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000531976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000527872 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 000519992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Vid.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000518656 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000516608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000515584 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000514048 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000506408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000500224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_PCDisplay.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000496872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 000494080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000494080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Activities.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000487424 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoMetadataHandler.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000478208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000473616 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000468992 _____ (Microsoft Corporation) C:\WINDOWS\system32\coml2.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000463672 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000461824 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000448000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.Workflow.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000439296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000421376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000419128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\eeprov.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000415744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 000408800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mswsock.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000407040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000402944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\exfat.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000402576 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000400384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000398848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000398416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000394752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcLayers.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000394240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000388096 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 000387384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000378368 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000375544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 000371200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Diagnostics.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000365056 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000353488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000346624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000326144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.OneCore.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000324408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswsock.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvcext.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000306704 _____ (Microsoft Corporation) C:\WINDOWS\system32\computestorage.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasppp.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000303616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000300024 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvc.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000298296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000294072 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000276488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MTF.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000275768 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000273920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000266240 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\prnntfy.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000246784 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000241664 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 000228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000217600 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000203280 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000202552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MTF.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\netiohlp.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthserv.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000195896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spacedump.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrrun.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000193032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasman.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000178696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\appsruprov.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\energyprov.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000175096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpioclx.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spacebridge.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompPkgSrv.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 000164344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000164288 _____ (Microsoft Corporation) C:\WINDOWS\system32\vertdll.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000157192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000155648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netiohlp.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000155648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000151872 _____ (Microsoft Corporation) C:\WINDOWS\system32\rmclient.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000148480 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 000146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000140808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.NetworkOperators.HotspotAuthentication.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000132104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupcln.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000114856 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompPkgSup.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000111104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000102392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000097592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000095544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storqosflt.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000090424 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcnfs.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000083472 _____ (Microsoft Corporation) C:\WINDOWS\system32\vid.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 000080400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vpci.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManMigrationPlugin.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000074424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WindowsTrustedRT.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iscsiwmi.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManMigrationPlugin.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000062464 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo-overrides.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000055608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\iorate.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mmcss.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000047136 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser_broker.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\hidparse.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys
2019-03-02 06:50 - 2019-03-02 06:50 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpkinstall.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 000039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\npmproxy.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000039304 _____ (Microsoft Corporation) C:\WINDOWS\system32\NtlmShared.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnsruprov.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 000033056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NtlmShared.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe
2019-03-02 06:50 - 2019-03-02 06:50 - 000021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\npmproxy.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2019-03-02 06:50 - 2019-03-02 06:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2019-03-02 06:50 - 2019-03-02 06:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2019-03-02 06:50 - 2019-03-02 06:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2019-03-02 06:50 - 2019-03-02 06:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2019-03-02 06:50 - 2019-03-02 06:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2019-03-02 06:50 - 2019-03-02 06:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2019-03-02 06:50 - 2019-03-02 06:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2019-03-02 06:50 - 2019-03-02 06:50 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
2019-03-02 06:50 - 2019-03-02 06:50 - 000000072 _____ C:\WINDOWS\system32\edgehtmlpluginpolicy.bin
2019-03-02 06:42 - 2019-03-02 06:42 - 000000000 ____D C:\Program Files\Reference Assemblies
2019-03-02 06:42 - 2019-03-02 06:42 - 000000000 ____D C:\Program Files\MSBuild
2019-03-02 06:42 - 2019-03-02 06:42 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2019-03-02 06:42 - 2019-03-02 06:42 - 000000000 ____D C:\Program Files (x86)\MSBuild
2019-03-02 06:41 - 2019-03-02 06:41 - 001167960 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2019-03-02 06:41 - 2019-03-02 06:41 - 000780376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2019-03-02 06:41 - 2019-03-02 06:41 - 000126064 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2019-03-02 06:41 - 2019-03-02 06:41 - 000104560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2019-03-02 06:41 - 2019-03-02 06:41 - 000036896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2019-03-02 06:41 - 2019-03-02 06:41 - 000035440 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2019-03-02 06:26 - 2019-03-02 06:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dolby
2019-03-02 06:26 - 2019-03-02 06:26 - 000000000 ____D C:\ProgramData\Dolby
2019-03-02 06:26 - 2019-03-02 06:26 - 000000000 ____D C:\Program Files\Dolby
2019-03-02 06:18 - 2019-03-02 06:18 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2019-03-02 06:13 - 2019-03-02 06:13 - 000000020 ___SH C:\Users\ronny\ntuser.ini
2019-03-02 06:10 - 2019-03-11 19:00 - 000004164 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{919E763D-944E-410C-BE5B-FE5211DD5A4F}
2019-03-02 06:10 - 2019-03-11 09:32 - 000003374 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2563344569-153408547-261685501-1001
2019-03-02 06:10 - 2019-03-11 09:23 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-03-02 06:10 - 2019-03-07 07:00 - 000004422 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2019-03-02 06:10 - 2019-03-02 06:26 - 000003266 _____ C:\WINDOWS\System32\Tasks\RtHDVBg_LENOVO_DOLBYDRAGON
2019-03-02 06:10 - 2019-03-02 06:26 - 000003220 _____ C:\WINDOWS\System32\Tasks\RtHDVBg_Dolby
2019-03-02 06:10 - 2019-03-02 06:25 - 000003216 _____ C:\WINDOWS\System32\Tasks\RTKCPL
2019-03-02 06:10 - 2019-03-02 06:11 - 000003748 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier
2019-03-02 06:10 - 2019-03-02 06:11 - 000003492 _____ C:\WINDOWS\System32\Tasks\LenovoUtility Task
2019-03-02 06:10 - 2019-03-02 06:11 - 000002766 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2019-03-02 06:10 - 2019-03-02 06:11 - 000002708 _____ C:\WINDOWS\System32\Tasks\Maxthon5 Update
2019-03-02 06:10 - 2019-03-02 06:11 - 000002650 _____ C:\WINDOWS\System32\Tasks\McAfee Remediation (Prepare)
2019-03-02 06:10 - 2019-03-02 06:10 - 000002408 _____ C:\WINDOWS\System32\Tasks\App Explorer
2019-03-02 06:10 - 2019-03-02 06:10 - 000000000 ____D C:\WINDOWS\System32\Tasks\NCH Software
2019-03-02 06:10 - 2019-03-02 06:10 - 000000000 ____D C:\WINDOWS\System32\Tasks\McAfee
2019-03-02 06:10 - 2019-03-02 06:10 - 000000000 ____D C:\WINDOWS\System32\Tasks\Lenovo
2019-03-02 06:09 - 2019-03-02 06:10 - 000007623 _____ C:\WINDOWS\diagwrn.xml
2019-03-02 06:09 - 2019-03-02 06:10 - 000007623 _____ C:\WINDOWS\diagerr.xml
2019-03-02 05:34 - 2019-03-11 09:30 - 000840848 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-03-02 05:25 - 2019-03-02 05:25 - 000001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2019-03-02 05:22 - 2019-03-11 09:30 - 000002370 _____ C:\Users\ronny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-03-02 05:22 - 2019-03-04 23:37 - 000000000 ____D C:\Users\ronny
2019-03-02 05:21 - 2018-05-06 13:15 - 000144808 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2019-03-02 05:21 - 2018-05-06 13:15 - 000119720 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL
2019-03-02 05:20 - 2019-03-02 05:20 - 000000000 ____D C:\ProgramData\USOShared
2019-03-02 05:20 - 2018-09-15 02:28 - 002864640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2019-03-02 05:15 - 2019-03-11 13:46 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-03-02 05:15 - 2019-03-02 05:28 - 000257824 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-03-01 01:27 - 2019-03-01 01:27 - 007474563 _____ C:\Users\ronny\Downloads\2011-silverado3500hd.pdf
2019-03-01 00:48 - 2019-03-01 00:48 - 000000000 ____D C:\Users\ronny\Desktop\NCH
2019-03-01 00:46 - 2019-03-01 00:46 - 000001061 _____ C:\Users\ronny\Desktop\My Documents - Shortcut.lnk
2019-02-26 09:48 - 2019-03-07 23:53 - 000000000 ____D C:\Users\ronny\Desktop\sound
2019-02-26 08:09 - 2019-02-26 08:09 - 000198512 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2019-02-26 08:09 - 2019-02-01 12:20 - 000020936 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2019-02-26 08:08 - 2019-03-02 07:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2019-02-26 08:08 - 2019-02-26 08:08 - 000001919 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2019-02-26 08:08 - 2019-01-08 16:32 - 000153328 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2019-02-20 07:21 - 2019-02-20 07:21 - 000000000 ___HD C:\OneDriveTemp
2019-02-20 07:10 - 2019-02-20 07:10 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2019-02-20 02:04 - 2019-03-07 07:00 - 000000000 ____D C:\Users\ronny\AppData\Local\Adobe
2019-02-19 06:11 - 2019-02-19 06:34 - 000000000 ____D C:\WINDOWS\Microsoft Antimalware
2019-02-19 00:02 - 2019-02-19 00:02 - 000001019 _____ C:\Program Files (x86)\unins000.dat
2019-02-19 00:02 - 2019-02-19 00:01 - 000715038 _____ C:\Program Files (x86)\unins000.exe
2019-02-19 00:02 - 2011-12-26 06:29 - 000001483 _____ C:\Program Files (x86)\LICENSE.txt
2019-02-19 00:02 - 2011-12-26 04:34 - 000475648 _____ C:\Program Files (x86)\lame.exe
2019-02-19 00:02 - 2011-12-26 04:34 - 000421888 _____ C:\Program Files (x86)\lame_enc.dll
2019-02-19 00:00 - 2019-02-19 00:00 - 000000000 ____D C:\Program Files (x86)\Lame For Audacity
2019-02-18 23:59 - 2019-02-18 23:59 - 000527423 _____ ( ) C:\Users\ronny\Downloads\Lame_v3.99.3_for_Windows.exe
2019-02-18 23:54 - 2019-02-19 04:08 - 000000000 ____D C:\Users\ronny\AppData\Roaming\audacity
2019-02-18 23:54 - 2019-02-18 23:54 - 000000000 ____D C:\Users\ronny\Documents\Audacity
2019-02-18 23:54 - 2019-02-18 23:54 - 000000000 ____D C:\Users\ronny\AppData\Local\Audacity
2019-02-18 23:53 - 2019-02-18 23:54 - 000000000 ____D C:\Program Files (x86)\Audacity
2019-02-18 23:53 - 2019-02-18 23:53 - 000001095 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2019-02-18 21:59 - 2019-03-02 07:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2019-02-18 21:59 - 2019-02-18 21:59 - 000001214 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Switch Sound File Converter.lnk
2019-02-18 10:16 - 2019-03-11 22:17 - 000000000 ____D C:\Users\ronny\AppData\LocalLow\Mozilla
2019-02-18 10:16 - 2019-03-01 07:48 - 000001012 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2019-02-18 10:16 - 2019-03-01 07:48 - 000000000 ____D C:\Program Files\Mozilla Firefox
2019-02-18 10:16 - 2019-03-01 07:48 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2019-02-18 10:16 - 2019-02-18 10:16 - 000000000 ____D C:\Users\ronny\AppData\Roaming\Mozilla
2019-02-18 10:16 - 2019-02-18 10:16 - 000000000 ____D C:\Users\ronny\AppData\Local\Mozilla
2019-02-18 10:16 - 2019-02-18 10:16 - 000000000 ____D C:\ProgramData\Mozilla
2019-02-16 07:32 - 2019-02-16 07:44 - 000000000 ____D C:\BIOS
2019-02-15 09:46 - 2019-03-02 06:14 - 000000000 ___DC C:\WINDOWS\Panther
2019-02-15 09:37 - 2019-03-02 07:06 - 000000000 ____D C:\WINDOWS\system32\Intel
2019-02-11 17:01 - 2018-09-11 07:09 - 004680168 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RsDMFT64.dll
2019-02-11 00:18 - 2019-02-11 00:18 - 000000719 _____ C:\Users\ronny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recordings.lnk
2019-02-10 22:19 - 2019-02-10 22:20 - 000001167 _____ C:\Users\ronny\AppData\Roaming\trace_FilterInstaller.txt
2019-02-10 22:19 - 2019-02-10 22:19 - 000053488 _____ C:\WINDOWS\system32\Drivers\stdriverx64.sys
2019-02-10 22:19 - 2019-02-10 22:19 - 000001250 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoundTap Streaming Audio Recorder.lnk
2019-02-10 22:19 - 2019-02-10 22:19 - 000000000 _____ C:\Users\ronny\AppData\Roaming\trace_FilterInstaller.txt-CRT.txt

==================== One month (modified) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-03-11 22:48 - 2018-09-15 02:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-03-11 09:30 - 2019-02-01 23:15 - 000000000 ___RD C:\Users\ronny\OneDrive
2019-03-11 09:30 - 2018-09-15 02:31 - 000000000 ____D C:\WINDOWS\INF
2019-03-11 09:28 - 2019-02-02 14:02 - 000000000 ____D C:\Users\ronny\AppData\Local\Host App Service
2019-03-11 09:26 - 2019-02-02 14:06 - 000000000 __SHD C:\Users\ronny\IntelGraphicsProfiles
2019-03-11 03:40 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2019-03-11 02:57 - 2019-02-03 22:17 - 000000000 ____D C:\Users\Public\Logi
2019-03-10 08:15 - 2018-09-15 02:33 - 000000000 ___HD C:\Program Files\WindowsApps
2019-03-10 08:15 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-03-09 13:13 - 2019-02-02 14:02 - 000000000 ____D C:\Users\ronny\AppData\Local\ElevatedDiagnostics
2019-03-09 12:55 - 2018-09-15 02:23 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-03-09 11:35 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\system32\NDF
2019-03-07 11:49 - 2019-02-02 13:42 - 000000000 ____D C:\Users\ronny\Documents\dad's
2019-03-07 06:59 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2019-03-07 06:59 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\system32\Macromed
2019-03-03 05:12 - 2018-09-15 01:09 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2019-03-03 04:39 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\appcompat
2019-03-02 12:57 - 2019-02-02 00:15 - 000000000 ____D C:\Users\ronny\AppData\Local\D3DSCache
2019-03-02 09:51 - 2019-02-03 22:01 - 000000000 ____D C:\Users\ronny\AppData\Local\PlaceholderTileLogoFolder
2019-03-02 09:49 - 2018-09-15 02:36 - 000835480 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2019-03-02 09:49 - 2018-09-15 02:36 - 000179600 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2019-03-02 07:13 - 2019-02-02 12:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2019-03-02 07:13 - 2019-02-02 00:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2019-03-02 07:13 - 2019-02-01 23:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MX5
2019-03-02 07:13 - 2019-02-01 23:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech Camera Settings
2019-03-02 07:13 - 2019-02-01 23:25 - 000000000 ____D C:\Program Files\Common Files\LogiShrd
2019-03-02 07:13 - 2018-10-09 09:55 - 000000000 ____D C:\Program Files\Realtek
2019-03-02 07:13 - 2018-10-09 09:54 - 000000000 ____D C:\Program Files\Intel
2019-03-02 07:13 - 2018-09-15 02:36 - 000000000 ____D C:\WINDOWS\Setup
2019-03-02 07:13 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2019-03-02 07:13 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\system32\spool
2019-03-02 07:13 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\system32\oobe
2019-03-02 07:13 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\Registration
2019-03-02 07:13 - 2018-09-15 02:31 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2019-03-02 07:13 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2019-03-02 07:07 - 2018-04-11 18:38 - 000000000 ____D C:\WINDOWS\InfusedApps
2019-03-02 07:06 - 2018-10-09 10:03 - 000000000 ____D C:\WINDOWS\system32\Drivers\Lenovo
2019-03-02 07:05 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\Resources
2019-03-02 06:54 - 2018-09-15 04:11 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2019-03-02 06:54 - 2018-09-15 04:11 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2019-03-02 06:54 - 2018-09-15 02:33 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2019-03-02 06:54 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\TextInput
2019-03-02 06:54 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2019-03-02 06:54 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2019-03-02 06:54 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\system32\migwiz
2019-03-02 06:54 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\system32\appraiser
2019-03-02 06:54 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\ShellExperiences
2019-03-02 06:54 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\ShellComponents
2019-03-02 06:54 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\bcastdvr
2019-03-02 06:54 - 2018-09-15 01:09 - 000000000 ____D C:\WINDOWS\system32\Dism
2019-03-02 06:41 - 2019-02-02 10:05 - 000000000 ____D C:\ProgramData\Packages
2019-03-02 06:36 - 2019-02-02 14:06 - 000000000 ____D C:\Users\ronny\AppData\Local\Packages
2019-03-02 06:26 - 2018-10-09 09:55 - 000000000 ____D C:\WINDOWS\system32\DAX2
2019-03-02 06:26 - 2018-10-09 09:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Realtek
2019-03-02 06:25 - 2018-10-09 09:55 - 000477243 _____ C:\WINDOWS\system32\Drivers\rtkhdasetting.zip
2019-03-02 06:25 - 2018-10-09 09:55 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2019-03-02 06:25 - 2018-10-09 09:55 - 000000000 ____D C:\WINDOWS\system32\DAX3
2019-03-02 06:15 - 2019-02-02 14:06 - 000000000 ___RD C:\Users\ronny\3D Objects
2019-03-02 06:15 - 2018-04-17 14:03 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-03-02 06:14 - 2019-02-02 14:06 - 000000000 ____D C:\Users\ronny\AppData\Local\ConnectedDevicesPlatform
2019-03-02 06:11 - 2018-09-15 01:09 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2019-03-02 06:10 - 2018-09-15 02:33 - 000000000 ___RD C:\Program Files\Windows Defender
2019-03-02 05:50 - 2018-09-15 02:33 - 000000000 ___RD C:\WINDOWS\PrintDialog
2019-03-02 05:33 - 2018-09-15 02:33 - 000000000 __RHD C:\Users\Public\Libraries
2019-03-02 05:26 - 2019-02-07 00:58 - 000000000 ____D C:\Users\ronny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dwyco CDC-X
2019-03-02 05:26 - 2019-02-02 12:16 - 000000000 ____D C:\Users\ronny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2019-03-02 05:20 - 2018-09-15 02:33 - 000000000 ____D C:\ProgramData\USOPrivate
2019-03-02 05:17 - 2018-09-15 02:33 - 000000000 ____D C:\WINDOWS\ServiceState
2019-03-01 11:40 - 2019-02-01 23:50 - 000000000 ____D C:\Program Files\rempl
2019-03-01 03:16 - 2019-02-07 01:08 - 002838528 _____ C:\Users\ronny\Documents\dwyco-backup-diff-f26998543478a9551774.sql
2019-03-01 00:47 - 2019-02-07 05:29 - 000000000 ____D C:\Users\ronny\Desktop\cloud
2019-03-01 00:47 - 2019-02-02 13:41 - 000000000 ____D C:\Users\ronny\Desktop\karaoke
2019-02-25 02:45 - 2019-02-07 01:08 - 002838528 _____ C:\Users\ronny\Documents\dwyco-backup-diff-f26998543478a9551774.old.sql
2019-02-22 16:31 - 2018-04-17 14:02 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2019-02-18 21:59 - 2019-02-07 10:57 - 000000000 ____D C:\ProgramData\NCH Software
2019-02-18 21:59 - 2019-02-07 10:56 - 000000000 ____D C:\Users\ronny\AppData\Roaming\NCH Software
2019-02-18 21:59 - 2019-02-07 10:56 - 000000000 ____D C:\Program Files (x86)\NCH Software
2019-02-18 00:05 - 2019-02-02 14:07 - 000000000 ____D C:\Users\ronny\AppData\Local\Publishers
2019-02-16 15:30 - 2019-02-02 12:50 - 000000000 _____ C:\WINDOWS\system32\Drivers\lvuvc.hs
2019-02-14 08:55 - 2019-02-02 14:06 - 000000000 ____D C:\Users\ronny\AppData\Local\Intel
2019-02-13 00:44 - 2019-02-01 23:41 - 000000000 ____D C:\WINDOWS\system32\MRT
2019-02-13 00:42 - 2019-02-01 23:40 - 129330784 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe

==================== Files in the root of some directories =======

2019-02-19 00:02 - 2011-12-26 04:34 - 000475648 _____ () C:\Program Files (x86)\lame.exe
2019-02-19 00:02 - 2011-12-26 04:34 - 000421888 _____ () C:\Program Files (x86)\lame_enc.dll
2019-02-19 00:02 - 2011-12-26 06:29 - 000001483 _____ () C:\Program Files (x86)\LICENSE.txt
2019-02-19 00:02 - 2019-02-19 00:02 - 000001019 _____ () C:\Program Files (x86)\unins000.dat
2019-02-19 00:02 - 2019-02-19 00:01 - 000715038 _____ () C:\Program Files (x86)\unins000.exe
2019-02-10 22:19 - 2019-02-10 22:20 - 000001167 _____ () C:\Users\ronny\AppData\Roaming\trace_FilterInstaller.txt
2019-02-10 22:19 - 2019-02-10 22:19 - 000000000 _____ () C:\Users\ronny\AppData\Roaming\trace_FilterInstaller.txt-CRT.txt

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\dllhost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\dllhost.exe => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End of FRST.txt ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11.03.2019
Ran by ronny (11-03-2019 22:51:12)
Running from C:\Users\ronny\Desktop
Windows 10 Home Version 1809 17763.316 (X64) (2019-03-02 11:13:44)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2563344569-153408547-261685501-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2563344569-153408547-261685501-503 - Limited - Disabled)
Guest (S-1-5-21-2563344569-153408547-261685501-501 - Limited - Disabled)
ronny (S-1-5-21-2563344569-153408547-261685501-1001 - Administrator - Enabled) => C:\Users\ronny
WDAGUtilityAccount (S-1-5-21-2563344569-153408547-261685501-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.142 - Adobe Systems Incorporated)
Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.142 - Adobe Systems Incorporated)
Audacity 2.3.0 (HKLM-x32\...\Audacity_is1) (Version: 2.3.0 - Audacity Team)
CameraHelperMsi (HKLM-x32\...\{15634701-BACE-4449-8B25-1567DA8C9FD3}) (Version: 13.51.815.0 - Logitech) Hidden
Dolby Audio X2 Windows API SDK (HKLM\...\{F994125B-7BF5-4A38-A569-82833CEB24DC}) (Version: 0.8.4.83 - Dolby Laboratories, Inc.)
Dolby Audio X2 Windows APP (HKLM\...\{4A02DCED-C2B0-4DD3-87BD-7D8E68D6AF3C}) (Version: 0.8.6.75 - Dolby Laboratories, Inc.)
Dwyco CDC-X version 2.17 (HKU\S-1-5-21-2563344569-153408547-261685501-1001\...\Dwyco CDC-X_is1) (Version: 2.17 - Dwyco, Inc.)
erLT (HKLM-x32\...\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}) (Version: 1.20.138.34 - Logitech, Inc.) Hidden
Intel(R) Chipset Device Software (HKLM-x32\...\{44ded3eb-1686-46a6-9770-fd79096c29f7}) (Version: 10.1.1.45 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1052 - Intel Corporation)
Intel(R) Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.47.715.0 - Intel Corporation) Hidden
Intel(R) Trusted Connect Services Client (HKLM-x32\...\{2b32b7d0-4f9f-47c8-adb7-807e6cb2fb75}) (Version: 1.47.715.0 - Intel Corporation) Hidden
Java 8 Update 201 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180201F0}) (Version: 8.0.2010.9 - Oracle Corporation)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - )
Lenovo App Explorer (HKU\S-1-5-21-2563344569-153408547-261685501-1001\...\Host App Service) (Version: 0.273.2.977 - SweetLabs for Lenovo) <==== ATTENTION
Lenovo Service Bridge (HKU\S-1-5-21-2563344569-153408547-261685501-1001\...\{2C74547D-EF88-47F4-85F5-BE46A31E26B7}_is1) (Version: 4.0.6.6 - Lenovo)
Logitech Camera Settings (HKLM-x32\...\LogiUCDPP) (Version: 2.8.24.0 - Logitech Europe S.A.)
Logitech Options (HKLM\...\LogiOptions) (Version: 7.10.3 - Logitech)
Logitech Unifying Software 2.50 (HKLM\...\Logitech Unifying) (Version: 2.50.25 - Logitech)
Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.80 - Logitech Inc.)
Malwarebytes version 3.7.1.2839 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.7.1.2839 - Malwarebytes)
Microsoft OneDrive (HKU\S-1-5-21-2563344569-153408547-261685501-1001\...\OneDriveSetup.exe) (Version: 19.012.0121.0011 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Mozilla Firefox 65.0.2 (x64 en-US) (HKLM\...\Mozilla Firefox 65.0.2 (x64 en-US)) (Version: 65.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 65.0.1 - Mozilla)
MX5 (HKLM-x32\...\Maxthon5) (Version: 5.2.6.1000 - Maxthon International Limited)
RecordPad Sound Recorder (HKLM-x32\...\Recordpad) (Version: 8.01 - NCH Software)
SoundTap Streaming Audio Recorder (HKLM-x32\...\SoundTap) (Version: 4.01 - NCH Software)
Switch Sound File Converter (HKLM-x32\...\Switch) (Version: 7.07 - NCH Software)
Tweaking.com - Registry Backup (HKLM-x32\...\Tweaking.com - Registry Backup) (Version: 3.5.3 - Tweaking.com)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{1FD817A6-63E1-4519-BFD4-228DABB7AB6B}) (Version: 2.55.0.0 - Microsoft Corporation)
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-2) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
WavePad Sound Editor (HKLM-x32\...\WavePad) (Version: 9.01 - NCH Software)
Windows 10 Update Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22589 - Microsoft Corporation)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2563344569-153408547-261685501-1001_Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6} -> [OneDrive] => {a52bba46-e9e1-435f-b3d9-28daa648c0f6}
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\igfxDTCM.dll [2018-05-06] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0303FC85-19E4-4A49-AFA4-CCFFF15FF8CC} - System32\Tasks\Lenovo\Lenovo Service Bridge\S-1-5-21-2563344569-153408547-261685501-1001 => C:\Users\ronny\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSBUpdater.exe (Lenovo (Beijing) Limited -> Lenovo Group Limited)
Task: {0ADF630D-EDBE-4DCC-A006-37EA17B9829E} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor)
Task: {0F014A73-EF28-462D-BD80-A18D3C8485B7} - System32\Tasks\Maxthon5 Update => C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe (Maxthon Technology Co, Ltd. -> Maxthon International ltd.)
Task: {19C50BE4-2339-4427-A530-669F122D488D} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\edb01cb6-ac56-424c-93cd-7bafaa0796ce => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe (Lenovo -> Lenovo Group Ltd.)
Task: {1C0AD44A-50C4-4548-957C-8229DA347CCD} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_142_pepper.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {207A4101-0AF7-4DAE-807E-686C20FE3279} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MpCmdRun.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {3108AFC8-0B77-4475-9EAF-09370455A19E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MpCmdRun.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {380BA743-88FF-441D-A82A-B652CC817F1C} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\4b8cf1e7-614e-47bd-ac35-262384fd72b4 => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe (Lenovo -> Lenovo Group Ltd.)
Task: {3A2C7E04-E660-4AC9-BA87-34F23463BDFE} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\16cd9a68-4315-46b0-a7ee-00f7573353c6 => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe (Lenovo -> Lenovo Group Ltd.)
Task: {3B99BBFC-A865-42D0-BD65-6C30871250B4} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_142_Plugin.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {3DA05F07-282C-4442-98E3-0F09C9650D65} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MpCmdRun.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {56459180-EFEE-41F5-A5DE-1AAC75A3848F} - System32\Tasks\App Explorer => C:\Users\ronny\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe (SweetLabs Inc. -> SweetLabs, Inc) <==== ATTENTION
Task: {5EA95F1C-CD90-4E33-909E-31BE54A712D4} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\fbfe6ea8-434b-478b-b245-2780780f9918 => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe (Lenovo -> Lenovo Group Ltd.)
Task: {716B90CE-A416-4784-BA18-242EC524DABE} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask => %windir%\System32\reg.exe add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler /v start /t reg_dword /d 1 /f /reg:32
Task: {8ED2C411-7510-43C9-A180-9D84045CF0DC} - System32\Tasks\RtHDVBg_LENOVO_DOLBYDRAGON => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor)
Task: {BE77526C-BEAF-4E49-86F6-D04BC84A3FF2} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => "%windir%\system32\sc.exe" START ImControllerService
Task: {C8CB119B-45DD-40AA-8460-12E0493DB950} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe (McAfee, Inc. -> McAfee, Inc.)
Task: {D63E305F-62FD-4616-AFF1-8D3480EA39F5} - System32\Tasks\NCH Software\SwitchSevenDays => C:\Program Files (x86)\NCH Software\Switch\Switch.exe (NCH Software Pty Ltd -> NCH Software)
Task: {D8BC2351-5AC2-49A7-BE4E-A17B21659A15} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {E7036E5E-8078-4B67-A5FD-A1F8A0CEE5D1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MpCmdRun.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {EBF36B46-CBDF-45A6-B321-60F118CB9CC3} - System32\Tasks\LenovoUtility Task => C:\Windows\explorer.exe lenovo-utility://
Task: {ED066DF5-E55B-4A40-B888-00144190843A} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Monitor => C:\WINDOWS\system32\ImController.InfInstaller.exe (Lenovo -> Lenovo Group Ltd.)
Task: {FA6D3E51-BDBD-490F-B0FD-8CECC50F7079} - System32\Tasks\RtHDVBg_Dolby => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2018-12-14 16:36 - 2018-12-14 16:36 - 000077824 _____ () [File not signed] C:\ProgramData\Logishrd\LogiOptions\Software\Current\laclient\zlib.dll
2018-12-14 16:36 - 2018-12-14 16:36 - 000355840 _____ (The cURL library, hxxp://curl.haxx.se/) [File not signed] C:\ProgramData\Logishrd\LogiOptions\Software\Current\laclient\LIBCURL.dll
2018-12-14 16:36 - 2018-12-14 16:36 - 000144896 _____ () [File not signed] C:\ProgramData\Logishrd\LogiOptions\Software\Current\laclient\libssh2.dll
2018-12-14 16:36 - 2018-12-14 16:36 - 002286747 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\ProgramData\Logishrd\LogiOptions\Software\Current\laclient\LIBEAY32.dll
2018-12-14 16:36 - 2018-12-14 16:36 - 000416627 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\ProgramData\Logishrd\LogiOptions\Software\Current\laclient\SSLEAY32.dll
2019-02-02 13:10 - 2019-02-01 10:56 - 000438272 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5WinExtras.dll
2019-02-02 13:09 - 2019-02-01 10:56 - 005139968 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Gui.dll
2019-02-02 13:09 - 2019-02-01 10:56 - 003084800 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Quick.dll
2019-02-02 13:10 - 2019-02-01 10:56 - 004571648 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Widgets.dll
2019-02-02 13:09 - 2019-02-01 10:55 - 005010944 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Core.dll
2019-02-02 13:09 - 2019-02-01 10:56 - 002950144 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Qml.dll
2019-02-02 13:09 - 2019-02-01 10:56 - 002234880 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Network.dll
2019-02-26 08:08 - 2019-02-01 10:56 - 001181184 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\platforms\qwindows.dll
2019-02-26 08:08 - 2019-02-01 10:56 - 000124928 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\styles\qwindowsvistastyle.dll
2019-02-26 08:08 - 2019-02-01 10:56 - 000026112 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qico.dll
2019-02-26 08:08 - 2019-02-01 10:56 - 000020992 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qsvg.dll
2019-02-02 13:10 - 2019-02-01 10:56 - 000259584 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Svg.dll
2019-02-26 08:08 - 2019-02-01 10:56 - 000014848 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick.2\qtquick2plugin.dll
2019-02-26 08:08 - 2019-02-01 10:56 - 000729088 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\qtquickcontrolsplugin.dll
2019-02-26 08:08 - 2019-02-01 10:56 - 000073216 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Layouts\qquicklayoutsplugin.dll
2019-02-26 08:08 - 2019-02-01 10:56 - 000179712 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\dialogplugin.dll
2019-02-26 08:08 - 2019-02-01 10:56 - 000014848 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Window.2\windowplugin.dll
2019-02-26 08:08 - 2019-02-01 10:56 - 000014848 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQml\Models.2\modelsplugin.dll
2019-02-26 08:08 - 2019-02-01 10:56 - 000101888 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\PrivateWidgets\widgetsplugin.dll
2019-02-26 08:08 - 2019-02-01 10:56 - 000035328 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\iconengines\qsvgicon.dll
2019-02-02 14:00 - 2018-08-13 00:29 - 001255424 _____ (Robert Simpson, et al.) [File not signed] C:\ProgramData\Lenovo\iMController\Plugins\GenericMessagingPlugin\x86\x86\SQLite.Interop.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2018-04-11 18:38 - 2018-04-11 18:36 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path: C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT
HKU\S-1-5-21-2563344569-153408547-261685501-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\ronny\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\20180626_061637.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{B6244532-8F31-485E-97AD-6131BC46AF7A}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{75E5CCD8-E30F-4E98-A71E-48F24F33F450}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{9AE87BEB-DDC6-42FF-AE2A-CA4C15DBA486}C:\users\ronny\documents\dwyco\cdc-x\cdcx.exe] => (Allow) C:\users\ronny\documents\dwyco\cdc-x\cdcx.exe (Dwyco, Inc. -> )
FirewallRules: [TCP Query User{5A17486F-38A5-4F75-A52C-D1418AC7BA32}C:\users\ronny\documents\dwyco\cdc-x\cdcx.exe] => (Allow) C:\users\ronny\documents\dwyco\cdc-x\cdcx.exe (Dwyco, Inc. -> )
FirewallRules: [{FD63A565-A786-446E-8ABA-057888C5DEC0}] => (Allow) C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOptionsMgr.EXE (Logitech Inc -> Logitech, Inc.)
FirewallRules: [UDP Query User{DFCB5FB7-1383-4289-964C-AB0E575FE84C}C:\users\ronny\onedrive\documents\dwyco\cdc-x\cdcx.exe] => (Allow) C:\users\ronny\onedrive\documents\dwyco\cdc-x\cdcx.exe (Dwyco, Inc. -> )
FirewallRules: [TCP Query User{DE83D8F0-4DC3-4615-BC7C-E1552D8B6BA3}C:\users\ronny\onedrive\documents\dwyco\cdc-x\cdcx.exe] => (Allow) C:\users\ronny\onedrive\documents\dwyco\cdc-x\cdcx.exe (Dwyco, Inc. -> )
FirewallRules: [{821AFEB3-FA53-4151-A52E-A5154C0CBEC4}] => (Allow) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe (Maxthon Technology Co, Ltd. -> Maxthon International ltd.)
FirewallRules: [{689283AB-5F2B-4CD5-AC28-0C4DBF972BC8}] => (Allow) C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe (Maxthon Technology Co, Ltd. -> Maxthon International ltd.)
FirewallRules: [{9ED2A87C-9EC4-413C-AF33-32D93891E375}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe No File
FirewallRules: [{5A6D8FE2-0692-4E73-B43F-F3BD38CCD56F}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe No File
FirewallRules: [{68A18C2B-DA57-474E-87B7-4F1B95611589}] => (Allow) C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16010.9126.2116.0_x86__8wekyb3d8bbwe\Office16\OUTLOOK.exe No File
FirewallRules: [{4ECADDAF-098F-4649-A707-4E8A95C63502}] => (Allow) C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.11328.20146.0_x86__8wekyb3d8bbwe\Office16\OUTLOOK.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{03D4CD9D-7BF7-40AA-9D32-BC48A28656BE}] => (Allow) C:\Users\ronny\Desktop\FRST64.exe (Farbar) [File not signed]
FirewallRules: [{A02964A7-951A-4798-B79B-FB98726C7662}] => (Allow) C:\Users\ronny\Desktop\FRST64.exe (Farbar) [File not signed]
FirewallRules: [{2B9E177A-CE36-4995-A70B-EE0737B681F5}] => (Allow) C:\Users\ronny\Desktop\FRST64.exe (Farbar) [File not signed]
FirewallRules: [{C7D10C69-1C1C-4697-A7B8-E1224E49764F}] => (Allow) C:\Users\ronny\Desktop\FRST64.exe (Farbar) [File not signed]

==================== Restore Points =========================

02-03-2019 06:21:17 Windows Update
09-03-2019 02:07:46 Windows Update

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (03/11/2019 10:13:52 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AUDIODG.EXE, version: 10.0.17763.292, time stamp: 0xa0a39b52
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0000000000000000
Faulting process id: 0x1bc8
Faulting application start time: 0x01d4d87a2bdeb8e9
Faulting application path: C:\WINDOWS\system32\AUDIODG.EXE
Faulting module path: unknown
Report Id: 2915a93f-3ef4-4da4-b152-43301311da82
Faulting package full name:
Faulting package-relative application ID:

Error: (03/11/2019 07:13:16 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AUDIODG.EXE, version: 10.0.17763.292, time stamp: 0xa0a39b52
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0000000000000000
Faulting process id: 0xe80
Faulting application start time: 0x01d4d8671d240a53
Faulting application path: C:\WINDOWS\system32\AUDIODG.EXE
Faulting module path: unknown
Report Id: 15b27ccf-9db9-46fc-97cf-601612c4110f
Faulting package full name:
Faulting package-relative application ID:

Error: (03/11/2019 09:24:35 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AUDIODG.EXE, version: 10.0.17763.292, time stamp: 0xa0a39b52
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0000000000000000
Faulting process id: 0x1158
Faulting application start time: 0x01d4d81626620566
Faulting application path: C:\WINDOWS\system32\AUDIODG.EXE
Faulting module path: unknown
Report Id: 07e28ccf-3514-472b-adfe-16f3fb1d8f5f
Faulting package full name:
Faulting package-relative application ID:

Error: (03/11/2019 12:03:16 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: dwm.exe, version: 10.0.17763.1, time stamp: 0xe52aabf3
Faulting module name: dwmcore.dll, version: 10.0.17763.168, time stamp: 0x23095d3f
Exception code: 0xc00001ad
Fault offset: 0x00000000001e8b4e
Faulting process id: 0x46c
Faulting application start time: 0x01d4d741edc71548
Faulting application path: C:\WINDOWS\system32\dwm.exe
Faulting module path: C:\WINDOWS\system32\dwmcore.dll
Report Id: dcbcfe20-6a97-4118-aaff-0f26caf8e817
Faulting package full name:
Faulting package-relative application ID:

Error: (03/10/2019 08:10:52 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program svchost.exe version 10.0.17763.1 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: a28

Start Time: 01d4d741ef40515e

Termination Time: 4294967295

Application Path: C:\Windows\System32\svchost.exe

Report Id: dc10856f-c91e-433f-9afe-160c2c6f880e

Faulting package full name:

Faulting package-relative application ID:

Hang type: Cross-process

Error: (03/10/2019 06:39:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AUDIODG.EXE, version: 10.0.17763.292, time stamp: 0xa0a39b52
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0000000000000000
Faulting process id: 0x36a8
Faulting application start time: 0x01d4d79a8747d984
Faulting application path: C:\WINDOWS\system32\AUDIODG.EXE
Faulting module path: unknown
Report Id: d429ce67-fe82-4c3a-8ee9-7a4054eabe07
Faulting package full name:
Faulting package-relative application ID:

Error: (03/10/2019 06:32:51 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AUDIODG.EXE, version: 10.0.17763.292, time stamp: 0xa0a39b52
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0000000000000000
Faulting process id: 0x21f8
Faulting application start time: 0x01d4d79992d5df90
Faulting application path: C:\WINDOWS\system32\AUDIODG.EXE
Faulting module path: unknown
Report Id: 30db91e9-8068-4983-8fff-6495b473524c
Faulting package full name:
Faulting package-relative application ID:

Error: (03/10/2019 09:07:56 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AUDIODG.EXE, version: 10.0.17763.292, time stamp: 0xa0a39b52
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0000000000000000
Faulting process id: 0x3a40
Faulting application start time: 0x01d4d7480b499eae
Faulting application path: C:\WINDOWS\system32\AUDIODG.EXE
Faulting module path: unknown
Report Id: 47e7c97d-f8f6-4b3c-bc9c-2507fad13cc3
Faulting package full name:
Faulting package-relative application ID:


System errors:
=============
Error: (03/11/2019 10:16:35 PM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-7SS3QTOI)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user LAPTOP-7SS3QTOI\ronny SID (S-1-5-21-2563344569-153408547-261685501-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (03/11/2019 10:16:34 PM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-7SS3QTOI)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user LAPTOP-7SS3QTOI\ronny SID (S-1-5-21-2563344569-153408547-261685501-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (03/11/2019 09:18:53 PM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-7SS3QTOI)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user LAPTOP-7SS3QTOI\ronny SID (S-1-5-21-2563344569-153408547-261685501-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (03/11/2019 09:18:53 PM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-7SS3QTOI)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user LAPTOP-7SS3QTOI\ronny SID (S-1-5-21-2563344569-153408547-261685501-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (03/11/2019 09:15:26 PM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-7SS3QTOI)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user LAPTOP-7SS3QTOI\ronny SID (S-1-5-21-2563344569-153408547-261685501-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (03/11/2019 09:15:25 PM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-7SS3QTOI)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user LAPTOP-7SS3QTOI\ronny SID (S-1-5-21-2563344569-153408547-261685501-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (03/11/2019 06:56:58 PM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: NT AUTHORITY)
Description: Miniport Remote NDIS based Internet Sharing Device #2, {f72efe12-e812-47ec-be3d-9570b755c139}, had event 74

Error: (03/11/2019 09:26:58 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID
Windows.SecurityCenter.WscBrokerManager
and APPID
Unavailable
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.


Windows Defender:
===================================
Date: 2019-03-11 20:02:31.013
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {D708F15C-2A38-42CC-86B2-5D0302136DA7}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2019-03-11 19:51:31.420
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {3CA53822-83E7-4276-B727-1B7FAD280936}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2019-03-11 19:46:32.050
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {771CD2B9-DB42-45BF-AC0C-105788534B9C}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2019-03-11 19:40:14.536
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {A0770082-0BDF-4DDC-BB60-B5A8A49DE3D8}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2019-03-10 09:50:49.422
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {A94538AE-CE7C-44A3-8C21-8395AA62C12F}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2019-03-09 08:28:53.840
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.289.679.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.15700.9
Error code: 0x80072f8f
Error description: A security error occurred

Date: 2019-03-09 00:40:22.341
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.289.679.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.15700.9
Error code: 0x800b010f
Error description: The certificate's CN name does not match the passed value.

Date: 2019-03-09 00:19:28.240
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.289.679.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.15700.9
Error code: 0x80240438
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

==================== Memory info ===========================

Processor: Intel(R) Core(TM) i3-8130U CPU @ 2.20GHz
Percentage of memory in use: 85%
Total physical RAM: 4005.22 MB
Available physical RAM: 575.72 MB
Total Virtual: 7333.22 MB
Available Virtual: 1039.36 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:930.27 GB) (Free:867.92 GB) NTFS

\\?\Volume{eae77724-da1d-47c7-8a1a-90516e452771}\ (WINRE_DRV) (Fixed) (Total:0.98 GB) (Free:0.57 GB) NTFS
\\?\Volume{58b722d2-9514-4e02-a23f-e06dd61b5c39}\ (SYSTEM_DRV) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 346005D8)

Partition: GPT.

==================== End of Addition.txt ============================