Results 1 to 5 of 5

Thread: Ransomware changed extensions of files ~ Please help. Thank you

  1. #1
    Member
    Join Date
    Sep 2009
    Posts
    34

    Default Ransomware changed extensions of files ~ Please help. Thank you

    Ransomware has changed all files extensions to .id[244EA16D-2275].[helprecover@foxmail.com].help
    Id there a way to reverse this?
    Thank you for any help you may be able to provide.

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 09-08-2020
    Ran by jseym (administrator) on DESKTOP-V4HLLCM (LENOVO 3302F1U) (09-08-2020 19:05:01)
    Running from C:\Users\jseym\Downloads
    Loaded Profiles: jseym
    Platform: Windows 10 Pro Version 1909 18363.959 (X64) Language: English (United States)
    Default browser: Edge
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Adobe Inc. -> Adobe Inc) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe
    (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe
    (Apple Inc. -> Apple Inc.) C:\Program Files (x86)\QuickTime\QuickTimePlayer.exe
    (IDSA Production signing key -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe
    (IDSA Production signing key -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe
    (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
    (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
    (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
    (Intel(R) Software Development Products -> ) C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe
    (Intel(R) Software Development Products -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe
    (Microsoft Corporation -> Microsoft Corporation) C:\Users\jseym\AppData\Local\Temp\InstallUtil.exe
    (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
    (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2005.23.0_x64__8wekyb3d8bbwe\Calculator.exe
    (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12007.1001.2.0_x64__8wekyb3d8bbwe\WinStore.App.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
    (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2007.8-0\MsMpEng.exe
    (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2007.8-0\NisSrv.exe
    (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <10>
    (Node.js Foundation -> Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\libs\node.exe
    (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    (Red Giant LLC -> Red Giant LLC) C:\Program Files\Red Giant\Services\Red Giant Service.exe

    ==================== Registry (Whitelisted) ===================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [Unattend0000000001{15A3A1EB-3696-4573-ACE7-3A352B79D405}] => C:\Windows\system32\devmgmt.msc [145622 2019-03-18] (Microsoft Windows -> )
    HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc. -> Apple Inc.)
    HKLM-x32\...\Run: [Intel Driver & Support Assistant] => C:\Program Files (x86)\Intel\Driver and Support Assistant\DSATray.exe [236392 2020-07-09] (IDSA Production signing key -> Intel)
    HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\Run: [CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [144008 2019-10-22] (Adobe Inc. -> Adobe Systems Incorporated)
    HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\Run: [BingWallpaperApp] => C:\Users\jseym\AppData\Local\Microsoft\BingWallpaperApp\BingWallpaperApp.exe [2759032 2020-06-05] (Microsoft Corporation -> Microsoft Corporation)
    HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\Run: [LBRY] => C:\Program Files\LBRY\LBRY.exe [94038840 2020-07-23] (LBRY, Inc -> LBRY Inc.)
    HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\Run: [Llscs] => C:\Users\jseym\AppData\Roaming\dllsha.exe [200192 2020-08-02] (H$a8qZ9|6&NbzD4*) [File not signed]
    BootExecute: autocheck autochk * sdnclean64.exe

    ==================== Scheduled Tasks (Whitelisted) ============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {12A02D8D-0063-41A7-848D-0C344F6D7A22} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.8-0\MpCmdRun.exe [516776 2020-08-04] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {346C02FC-3387-4911-8518-2BA0410A6C58} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe
    Task: {34E6AADE-F756-41C3-A8E3-86B93E764E7F} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [3087184 2020-03-10] (Intel(R) Software Development Products -> Intel Corporation)
    Task: {3F326A1B-ECAD-4843-824F-3BE4B7BF8A39} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16408320 2015-12-18] (Realtek Semiconductor Corp -> Realtek Semiconductor)
    Task: {59AE585F-069F-4531-836E-E4730D211956} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [563000 2015-08-27] (Apple Inc. -> Apple Inc.)
    Task: {657AB868-8072-4FC8-8B84-A4A1B73F5203} - System32\Tasks\RtHDVBg_LENOVO_MICPKEY => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2015-12-18] (Realtek Semiconductor Corp -> Realtek Semiconductor)
    Task: {66FC4DF8-75BA-4D33-84C3-7CB64D9A5161} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.8-0\MpCmdRun.exe [516776 2020-08-04] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {8934F1CB-1858-4F8B-82AC-FAA7E2660794} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.8-0\MpCmdRun.exe [516776 2020-08-04] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {B661171E-78E9-45C9-B2DF-471024657433} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [123600 2020-07-29] (Mozilla Corporation -> Mozilla Foundation)
    Task: {BD3F409C-D89E-41FA-97B4-9C89662F7FE4} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.8-0\MpCmdRun.exe [516776 2020-08-04] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {CFF297AE-1D3D-4160-9B81-4057F48A8782} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => "C:\Windows\System32\Wscript.exe" //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"
    Task: {F2004AA5-EBD0-42BB-99B7-3C14E14ECF5B} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [3087184 2020-03-10] (Intel(R) Software Development Products -> Intel Corporation)
    Task: {F85CA6E8-62FE-45E2-9157-0DFAA6EA2898} - System32\Tasks\Red Giant Link => C:\Program [Argument = Files (x86)\Red Giant Link\Red Giant Link.exe]
    Task: {FE78B23E-54CA-4DD0-984F-D692E228522D} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
    Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
    Tcpip\..\Interfaces\{16ea75fc-585d-492a-aab4-e91f59e2c07d}: [DhcpNameServer] 192.168.2.1
    Tcpip\..\Interfaces\{ed2b5ddf-5cce-4285-a77f-ace87df4d112}: [DhcpNameServer] 8.8.8.8 8.8.4.4

    Internet Explorer:
    ==================
    HKU\S-1-5-21-871970874-3256418639-2447214560-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/?pc=COS2&ptag=D051220-A915F698E57&form=CONMHP&conlogo=CT3335818
    SearchScopes: HKU\S-1-5-21-871970874-3256418639-2447214560-1004 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?pc=COS2&ptag=D051220-N0700A915F698E57&form=CONBDF&conlogo=CT3335818&q={searchTerms}
    BHO: IEToEdge BHO -> {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} -> C:\Program Files (x86)\Microsoft\Edge\Application\84.0.522.52\BHO\ie_to_edge_bho_64.dll [2020-08-01] (Microsoft Corporation -> Microsoft Corporation)
    BHO-x32: IEToEdge BHO -> {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} -> C:\Program Files (x86)\Microsoft\Edge\Application\84.0.522.52\BHO\ie_to_edge_bho.dll [2020-08-01] (Microsoft Corporation -> Microsoft Corporation)

    Edge:
    ======
    Edge Profile: C:\Users\jseym\AppData\Local\Microsoft\Edge\User Data\Default [2020-08-09]

    FireFox:
    ========
    FF DefaultProfile: ezc0qb7c.default
    FF ProfilePath: C:\Users\jseym\AppData\Roaming\Mozilla\Firefox\Profiles\ezc0qb7c.default [2020-08-09]
    FF NewTab: Mozilla\Firefox\Profiles\ezc0qb7c.default -> hxxps://defaultsearch.co/homepage?hp=1&pId=BT170603&iDate=2020-05-12 08:24:24&bName=&bitmask=0600
    FF ProfilePath: C:\Users\jseym\AppData\Roaming\Mozilla\Firefox\Profiles\6x38r1q0.default-release [2020-08-09]
    FF Homepage: Mozilla\Firefox\Profiles\6x38r1q0.default-release -> www.google.com
    FF NewTab: Mozilla\Firefox\Profiles\6x38r1q0.default-release -> hxxps://defaultsearch.co/homepage?hp=1&pId=BT170603&iDate=2020-05-12 08:24:24&bName=&bitmask=0600
    FF Extension: (No Name) - C:\Users\jseym\AppData\Roaming\Mozilla\Firefox\Profiles\6x38r1q0.default-release\Extensions\@hoxx-vpn.xpi.id[244EA16D-2275].[helprecover@foxmail.com].help [2020-08-09] [not signed]
    FF Extension: (No Name) - C:\Users\jseym\AppData\Roaming\Mozilla\Firefox\Profiles\6x38r1q0.default-release\Extensions\ffext_basicvideoext@startpage24.xpi.id[244EA16D-2275].[helprecover@foxmail.com].help [2020-08-09] [not signed]
    FF Extension: (No Name) - C:\Users\jseym\AppData\Roaming\Mozilla\Firefox\Profiles\6x38r1q0.default-release\Extensions\{667ef836-c20c-4a01-bfa4-af9b3e17299b}.xpi.id[244EA16D-2275].[helprecover@foxmail.com].help [2020-08-09] [not signed]
    FF Extension: (No Name) - C:\Users\jseym\AppData\Roaming\Mozilla\Firefox\Profiles\6x38r1q0.default-release\Extensions\{adeadebb-fedc-4180-a7f4-cfdd87496551}.xpi.id[244EA16D-2275].[helprecover@foxmail.com].help [2020-08-09] [not signed]
    FF Extension: (No Name) - C:\Users\jseym\AppData\Roaming\Mozilla\Firefox\Profiles\6x38r1q0.default-release\Extensions\{f73df109-8fb4-453e-8373-f59e61ca4da3}.xpi.id[244EA16D-2275].[helprecover@foxmail.com].help [2020-08-09] [not signed]
    FF Plugin-x32: @videolan.org/vlc,version=3.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)

    ==================== Services (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 Red Giant Service; C:\Program Files\Red Giant\Services\Red Giant Service.exe [5950024 2020-05-13] (Red Giant LLC -> Red Giant LLC)
    S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5930136 2020-05-12] (Microsoft Windows Publisher -> Microsoft Corporation)
    R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.8-0\NisSrv.exe [2169568 2020-08-04] (Microsoft Windows Publisher -> Microsoft Corporation)
    R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.8-0\MsMpEng.exe [128376 2020-08-04] (Microsoft Windows Publisher -> Microsoft Corporation)
    S2 AGMService; "C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe" [X]
    S2 AGSService; "C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe" [X]

    ===================== Drivers (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S3 AgereSoftModem; C:\Windows\system32\DRIVERS\agrsm64.sys [1146880 2019-03-18] (Microsoft Windows -> LSI Corp)
    R3 atmeltpm; C:\Windows\System32\drivers\atmeltpm64.sys [19456 2011-08-05] (Microsoft Windows Hardware Compatibility Publisher -> Atmel, Inc.)
    S3 bcmsmbsp; C:\Windows\System32\drivers\bcmsmbsp.sys [53024 2015-07-10] (Broadcom Corporation -> Broadcom Corporation.)
    S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [231936 2019-10-06] (Microsoft Corporation) [File not signed]
    S3 ETDSMBus; C:\Windows\System32\drivers\ETDSMBus.sys [30808 2015-12-17] (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronic Corp.)
    R3 int0800; C:\Windows\System32\drivers\flashud.sys [51712 2009-09-09] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
    R3 LBAI; C:\Windows\System32\Drivers\LBAI.sys [30432 2017-04-29] (Lenovo -> Lenovo)
    R3 netr28ux; C:\Windows\System32\drivers\netr28ux.sys [2224128 2019-03-18] (Microsoft Windows -> MediaTek Inc.)
    S3 NETwNe64; C:\Windows\System32\drivers\NETwew01.sys [3343872 2019-03-18] (Microsoft Windows -> Intel Corporation)
    R3 tap0901; C:\Windows\System32\drivers\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
    S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [78216 2020-08-04] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
    R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [430320 2020-08-04] (Microsoft Windows -> Microsoft Corporation)
    R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [98520 2020-08-04] (Microsoft Windows -> Microsoft Corporation)

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One month (created) ===================

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2020-08-09 19:01 - 2020-08-09 19:04 - 005198336 _____ (AVAST Software) C:\Users\jseym\Downloads\aswMBR.exe
    2020-08-09 18:56 - 2020-08-09 18:57 - 000051328 _____ C:\Users\jseym\Desktop\Addition.txt
    2020-08-09 18:55 - 2020-08-09 19:05 - 000014830 _____ C:\Users\jseym\Downloads\FRST.txt
    2020-08-09 18:55 - 2020-08-09 18:57 - 000111594 _____ C:\Users\jseym\Desktop\FRST.txt
    2020-08-09 18:52 - 2020-08-09 19:05 - 000000000 ____D C:\FRST
    2020-08-09 18:50 - 2020-08-09 18:50 - 002296320 _____ (Farbar) C:\Users\jseym\Downloads\FRST64.exe
    2020-08-09 16:41 - 2020-08-09 16:41 - 000000000 ____D C:\Users\jseym\AppData\Local\mbam
    2020-08-09 16:40 - 2020-08-09 16:40 - 000000000 ____D C:\ProgramData\Malwarebytes
    2020-08-09 16:39 - 2020-08-09 16:39 - 000000000 ____D C:\Program Files\Malwarebytes
    2020-08-09 14:52 - 2020-08-09 14:52 - 000000000 ___HD C:\$SysReset
    2020-08-09 14:45 - 2020-08-09 17:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
    2020-08-09 14:45 - 2020-08-09 16:46 - 000000000 ____D C:\Safer-Networking Ltd
    2020-08-09 14:45 - 2020-08-09 15:17 - 000000000 ____D C:\Users\jseym\AppData\Roaming\Waterfox
    2020-08-09 14:45 - 2020-08-09 14:45 - 000000000 ____D C:\Users\jseym\AppData\Local\Waterfox
    2020-08-09 14:45 - 2020-08-09 14:45 - 000000000 ____D C:\ProgramData\Waterfox
    2020-08-09 14:34 - 2020-08-09 14:34 - 000001478 _____ C:\Users\jseym\Desktop\info.txt
    2020-08-09 14:22 - 2020-08-09 14:22 - 000823538 _____ C:\Users\Public\xdg.exe.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:22 - 2020-08-09 14:22 - 000823538 _____ C:\Users\Public\uwa.exe.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:22 - 2020-08-09 14:22 - 000823538 _____ C:\Users\Public\rdn.exe.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:22 - 2020-08-09 14:22 - 000823538 _____ C:\Users\Public\mlx.exe.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:22 - 2020-08-09 14:22 - 000823538 _____ C:\Users\Public\ldz.exe.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:22 - 2020-08-09 14:22 - 000823538 _____ C:\Users\Public\fxc.exe.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:22 - 2020-08-09 14:22 - 000000418 ___SH C:\Users\Public\Downloads\desktop.ini.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:17 - 2020-08-09 14:17 - 000000530 ___SH C:\Users\Public\Documents\desktop.ini.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:17 - 2020-08-09 14:17 - 000000530 ___SH C:\ProgramData\Documents\desktop.ini.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:17 - 2020-08-09 14:17 - 000000418 ___SH C:\Users\Public\desktop.ini.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:17 - 2020-08-09 14:17 - 000000274 ___SH C:\Users\jseym\ntuser.ini.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 001099090 _____ C:\Users\jseym\Downloads\Hd Drops Dripping Down The Glass Stock Video - Download Video Clip Now - iStock.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 001007154 _____ C:\Users\jseym\Downloads\jungle-601542_1920.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000606626 _____ C:\Users\jseym\Downloads\loading screen free download - DASH_V.webm.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000491538 _____ C:\Users\jseym\Downloads\Haywood County Schools - Framework and Protocol for Re-Opening - 2020-2021-2-1.pdf.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000487522 _____ C:\Users\jseym\Downloads\kisspng-smartphone-feature-phone-mobile-phone-vector-blue-overlooking-smartphone-5a83d097ba45a6.773556601518588055763.png.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000464658 _____ C:\Users\jseym\Downloads\kisspng-sony-xperia-z3-sony-xperia-t-sony-xperia-m-sony-xp-phone-prototype-5a9d81c6960475.8869652515202718146145.png.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000354898 _____ C:\Users\jseym\Downloads\kisspng-smartphone-mobile-phones-telephone-5af29a9e6fb496.5137883115258487344576.png.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000219362 _____ C:\Users\jseym\Downloads\tech-rings.png.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000217874 _____ C:\Users\jseym\Downloads\puerto_madero_at_night_20___wet_street_by_maxi_exequiel-d5lmge0.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000192706 _____ C:\Users\jseym\Downloads\Blank Links.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000174690 _____ C:\Users\jseym\Downloads\France_Night_City_Roads_HDR_wet_rain_lights_sky_clouds_roads-2560X1600-915x515.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000116866 _____ C:\Users\jseym\Downloads\wet_leaf_by_wuestenbrand-d6ivd2a.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000080914 _____ C:\Users\jseym\Downloads\circle002png.png.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000075954 _____ C:\Users\jseym\Downloads\EeDUz5QXkAsgV-2.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000074946 _____ C:\Users\jseym\Downloads\kisspng-nexus-6p-google-nexus-smartphone-oncallers-cell-phone-repair-computer-services-5b52a047ae03b6.4705107915321416397128.png.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000071250 _____ C:\Users\jseym\Downloads\Product fufillment email.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000051090 _____ C:\Users\jseym\Downloads\landscape-1454360218-barndo.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000042098 _____ C:\Users\jseym\Downloads\kisspng-smartphone-feature-phone-sony-xperia-tipo-iphone-mobile-phone-vector-5a80e6827f88e5.1130330015183970585224.png.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000041218 _____ C:\Users\jseym\Downloads\kisspng-iphone-7-plus-ipad-3-car-audi-a3-phone-template-5aae63debc3189.6586718815213782707709.png.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000016706 _____ C:\Users\jseym\Downloads\Donate_Button.png.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000011378 _____ C:\Users\jseym\Downloads\circle003 black.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000007602 _____ C:\Users\jseym\Downloads\loading screen free download - DASH_A.webm.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000001010 _____ C:\Users\jseym\Downloads\Desktop - Shortcut.lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000000530 ___SH C:\Users\jseym\Downloads\desktop.ini.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000000354 _____ C:\Users\jseym\Downloads\credit.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000287666 _____ C:\Users\jseym\Downloads\8c38ce171e6f98a184153e8f8a6c9b30.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000023330 _____ C:\Users\jseym\Downloads\744px-Black-android-phone.svg.png.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000007602 _____ C:\Users\jseym\Downloads\3-2-paypal-donate-button-png-image-thumb.png.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000004354 _____ C:\Users\jseym\Documents\Tutorial Script.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000003106 _____ C:\Users\jseym\Documents\new script.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000000738 _____ C:\Users\jseym\Documents\Liberty line-up Aug 8th 2020.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000000706 _____ C:\Users\jseym\Documents\Tutorial Script new order for command.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000000658 ___SH C:\Users\jseym\Documents\desktop.ini.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000000626 _____ C:\Users\jseym\Documents\LBRY 02 & 03 logo giphy.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000000498 _____ C:\Users\jseym\Documents\Possible warnings for Adult SFX.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000000498 _____ C:\Users\jseym\Documents\Media Browser Provider Exception.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000000466 _____ C:\Users\jseym\Documents\delete temp w instruction.txt
    2020-08-09 14:15 - 2020-08-09 14:15 - 000000434 _____ C:\Users\jseym\Documents\SharedView Column Settings.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000000434 _____ C:\Users\jseym\Documents\Recent Directories.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000000322 _____ C:\Users\jseym\Documents\liberty changes.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000000274 _____ C:\Users\jseym\Documents\FileZilla.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000000274 _____ C:\Users\jseym\Documents\delete temp.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000005506 _____ C:\Users\jseym\Desktop\long story.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000002274 _____ C:\Users\jseym\Desktop\DAZ Install Manager (64-bit).lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000002258 _____ C:\Users\jseym\Desktop\DazCentral (64-bit).lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000002194 _____ C:\Users\jseym\Desktop\FileZilla Client.lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000002034 _____ C:\Users\jseym\Desktop\Audacity - Audio Editor and Recorder.lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000001442 _____ C:\Users\jseym\Desktop\DAZ Studio 4.12 (64-bit).lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000001426 _____ C:\Users\jseym\Desktop\Hexagon 2.5.lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000001426 _____ C:\Users\jseym\Desktop\Adobe Media Encoder 2020.lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000001378 _____ C:\Users\jseym\Documents\Benefit show.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000001346 _____ C:\Users\jseym\Desktop\Adobe Photoshop 2020.lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000001122 _____ C:\Users\jseym\Desktop\HandBrake.lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000001042 _____ C:\Users\jseym\Desktop\Documents - Shortcut.lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000000706 _____ C:\Users\jseym\Desktop\New Volume (D).lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000000530 ___SH C:\Users\jseym\Desktop\desktop.ini.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000000482 _____ C:\Users\jseym\Desktop\Call Landon.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000000386 _____ C:\Users\jseym\Desktop\Website important stats.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000000338 _____ C:\Users\jseym\Desktop\wrong length lower thirds redo.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000000306 _____ C:\Users\jseym\Documents\att account number.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:04 - 2020-08-09 14:04 - 000200450 _____ C:\Users\jseym\AppData\Roaming\dllsha.exe.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:04 - 2020-08-09 14:04 - 000002626 _____ C:\Users\jseym\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:04 - 2020-08-09 14:04 - 000001138 _____ C:\Users\jseym\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:04 - 2020-08-09 14:04 - 000000706 _____ C:\Users\jseym\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\New Volume (D).lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:04 - 2020-08-09 14:04 - 000000514 ___SH C:\Users\jseym\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:04 - 2020-08-09 14:04 - 000000418 ___SH C:\Users\jseym\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:03 - 2020-08-09 14:03 - 000352402 _____ C:\Users\jseym\AppData\Roaming\CodecsLE_Install.log.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 04:52 - 2020-08-09 04:52 - 000000658 _____ C:\Users\jseym\AppData\Local\oobelibMkey.log.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 04:49 - 2020-08-09 04:49 - 001035058 _____ C:\Users\jseym\AppData\Local\Ikslsec.exe.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 04:49 - 2020-08-09 04:49 - 000000402 _____ C:\Users\jseym\AppData\Local\Iksl.url.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 04:44 - 2020-08-09 04:44 - 000260802 ____H C:\Users\jseym\AppData\Local\IconCache.db.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-07 23:17 - 2020-08-09 14:05 - 126215202 _____ C:\Users\jseym\Desktop\FireExplosion01.mov
    2020-08-07 23:17 - 2020-08-09 14:05 - 044930191 _____ C:\Users\jseym\Desktop\FireExplosion02.mov.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-07 01:26 - 2020-08-09 14:16 - 023330707 _____ C:\Users\jseym\Downloads\Trapcode Particular 2.zip.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-05 21:04 - 2020-08-09 14:05 - 039059569 _____ C:\Users\jseym\Desktop\Lava Flow GS 1080.m4v
    2020-08-03 16:16 - 2020-08-09 14:05 - 021630573 _____ C:\Users\jseym\Desktop\Blood Drip Run on Glass original.wmv
    2020-08-03 15:20 - 2020-08-03 15:20 - 000000085 _____ C:\Windows\wininit.ini
    2020-08-03 05:29 - 2020-08-09 14:16 - 1127828789 _____ C:\Users\jseym\Downloads\ALIVE 2020 HDRip 720p H264 Mkvking.mkv.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-02 05:43 - 2019-03-18 23:49 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts.20200802-054355.backup
    2020-08-02 05:16 - 2020-08-02 05:16 - 000000000 ____D C:\Users\jseym\AppData\Local\Safer-Networking Ltd
    2020-08-02 05:11 - 2020-08-09 17:37 - 000000000 ____D C:\ProgramData\Spybot - Search & Destroy
    2020-08-02 05:11 - 2020-08-09 17:37 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
    2020-08-02 04:30 - 2020-08-02 04:53 - 069300040 _____ (Safer-Networking Ltd. ) C:\Users\jseym\Downloads\spybotsd-2.8.68.0.exe
    2020-08-02 04:23 - 2020-08-02 04:23 - 000823296 _____ C:\Users\Public\rdn.exe
    2020-08-02 04:23 - 2020-08-02 04:23 - 000823296 _____ C:\Users\Public\mlx.exe
    2020-08-02 04:22 - 2020-08-02 04:22 - 000823296 _____ C:\Users\Public\uwa.exe
    2020-08-02 04:18 - 2020-08-02 04:18 - 000823296 _____ C:\Users\Public\ldz.exe
    2020-08-02 04:13 - 2020-08-02 04:13 - 000000000 ____D C:\Windows\Finex
    2020-08-02 04:13 - 2020-08-02 04:12 - 000200192 _____ (H$a8qZ9/6&NbzD4*) C:\Users\jseym\AppData\Roaming\dllsha.exe
    2020-08-02 04:12 - 2020-08-02 04:12 - 001034806 _____ C:\Users\jseym\AppData\Local\Ikslsec.exe
    2020-08-02 04:12 - 2020-08-02 04:12 - 000823296 _____ C:\Users\Public\fxc.exe
    2020-08-02 04:11 - 2020-08-09 17:37 - 000000000 ____D C:\Users\jseym\AppData\LocalLow\3098htrhpen8ifg0
    2020-08-02 04:11 - 2020-08-02 04:11 - 000823296 _____ C:\Users\Public\xdg.exe
    2020-08-02 04:08 - 2020-08-02 04:20 - 000403768 _____ (Intel Corporation) C:\Windows\system32\tbb.dll
    2020-08-02 04:08 - 2020-08-02 04:20 - 000234808 _____ (Intel Corporation) C:\Windows\system32\tbbmalloc.dll
    2020-08-01 03:41 - 2020-08-09 14:16 - 000000000 ____D C:\Users\jseym\Downloads\oiwa
    2020-07-30 15:01 - 2020-08-09 17:45 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
    2020-07-29 16:43 - 2020-08-09 17:37 - 000000000 ____D C:\Program Files\Mozilla Firefox
    2020-07-29 01:31 - 2020-08-09 14:16 - 005396816 _____ C:\Users\jseym\Downloads\Rollin.mp3.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-29 01:29 - 2020-08-09 14:16 - 005124130 _____ C:\Users\jseym\Downloads\Mint_Chocolate_2a.mp3.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-29 01:28 - 2020-08-09 14:16 - 005381143 _____ C:\Users\jseym\Downloads\Flexxx.mp3.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-29 01:27 - 2020-08-09 14:16 - 004700946 _____ C:\Users\jseym\Downloads\Yellow_Rose_of_Berkeley.mp3.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-28 17:23 - 2020-07-28 17:23 - 000000000 ____D C:\Program Files\LBRY
    2020-07-28 05:06 - 2020-08-09 14:16 - 004192169 _____ C:\Users\jseym\Downloads\Wageningen's_Hoogstraat_after_spring_rain.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-28 05:02 - 2020-08-09 14:15 - 005159223 _____ C:\Users\jseym\Downloads\5417452809_e4ddfa3507_o.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-27 01:10 - 2020-08-09 14:16 - 002419899 _____ C:\Users\jseym\Downloads\city-1595830222804-339.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 23:37 - 2020-08-09 14:16 - 043254829 _____ C:\Users\jseym\Downloads\Waterfall Relaxing_Guru pixabay.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 23:35 - 2020-08-09 14:16 - 051815945 _____ C:\Users\jseym\Downloads\Videvo02.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 23:33 - 2020-08-09 14:16 - 309294980 _____ C:\Users\jseym\Downloads\videzzy2.mov.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 23:32 - 2020-08-09 14:16 - 290431860 _____ C:\Users\jseym\Downloads\Videzzy.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 23:25 - 2020-08-09 14:16 - 054892548 _____ C:\Users\jseym\Downloads\Videvo 1.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 23:15 - 2020-08-09 14:16 - 009994835 _____ C:\Users\jseym\Downloads\Videvo.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 21:22 - 2020-08-09 14:16 - 041281178 _____ C:\Users\jseym\Downloads\Rain - 44791.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 19:57 - 2020-08-09 14:16 - 021456843 _____ C:\Users\jseym\Downloads\Rainy Day - 5275.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 19:49 - 2020-08-09 14:16 - 067627255 _____ C:\Users\jseym\Downloads\mixkit-times-square-during-a-rainy-night-4332.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 19:45 - 2020-08-09 14:16 - 006989111 _____ C:\Users\jseym\Downloads\mixkit-thunderstorm-in-the-city-night-7239-medium.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 14:58 - 2020-08-09 14:15 - 000000000 ____D C:\Users\jseym\Downloads\AEdownload
    2020-07-24 06:00 - 2020-08-09 14:16 - 015110400 _____ C:\Users\jseym\Downloads\AEdownload.com-19242729-rain2.rar.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 05:42 - 2020-08-09 14:16 - 015110400 _____ C:\Users\jseym\Downloads\AEdownload.com-19242729-rain.rar.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 04:56 - 2020-08-09 14:16 - 006462955 _____ C:\Users\jseym\Downloads\Water Drop Heavy Rain On Window Stock Video - Download Video Clip Now - iStock.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 04:47 - 2020-07-24 04:47 - 000000747 _____ C:\Users\jseym\Downloads\Desktop - Shortcut.lnk
    2020-07-23 21:46 - 2020-08-09 14:16 - 022161852 _____ C:\Users\jseym\Downloads\London - 27028.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-23 21:42 - 2020-08-09 14:16 - 032393493 _____ C:\Users\jseym\Downloads\Water - 19799.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-23 21:06 - 2020-08-09 14:16 - 029882358 _____ C:\Users\jseym\Downloads\mixkit-busy-avenue-in-las-vegas-4251.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-23 20:41 - 2020-08-09 14:16 - 1037927686 _____ C:\Users\jseym\Downloads\Techno_0003.mov.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-23 20:31 - 2020-08-09 14:16 - 002989116 _____ C:\Users\jseym\Downloads\Hud Element Futuristic Loading Pending Screen Loopable Parts Alpha Mask Included Stock Video - Download Video Clip Now - iStock.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-23 19:25 - 2020-08-09 14:16 - 002502824 _____ C:\Users\jseym\Downloads\Loading Circle Icon On White Background Animation With Optional Luma Matte Alpha Luma Matte Included 4k Video Stock Video - Download Video Clip Now - iStock.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-23 19:23 - 2020-08-09 14:16 - 003433457 _____ C:\Users\jseym\Downloads\downloading_bar.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-23 17:37 - 2020-08-09 14:16 - 000000000 ____D C:\Users\jseym\Downloads\New folder
    2020-07-23 17:33 - 2020-08-09 14:15 - 048903784 _____ C:\Users\jseym\Downloads\200207_London Streets_1_4k_033.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-23 17:33 - 2020-08-09 14:15 - 029295016 _____ C:\Users\jseym\Downloads\200207_London Streets_1_4k_049.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-23 17:32 - 2020-08-09 14:15 - 039696900 _____ C:\Users\jseym\Downloads\200207_London Streets_1_4k_037.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-23 17:08 - 2020-08-09 14:16 - 008598929 _____ C:\Users\jseym\Downloads\radar_02.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-23 05:42 - 2020-07-23 05:42 - 000000000 ____D C:\Users\jseym\AppData\Roaming\Maxon
    2020-07-23 01:27 - 2020-08-02 01:41 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
    2020-07-23 01:27 - 2020-08-02 01:41 - 000002283 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
    2020-07-23 01:27 - 2020-08-02 01:41 - 000002283 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk
    2020-07-23 01:27 - 2020-07-23 14:48 - 000003478 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
    2020-07-23 01:27 - 2020-07-23 14:48 - 000003354 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
    2020-07-22 23:45 - 2020-07-22 23:45 - 025902592 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 025444352 _____ (Microsoft Corporation) C:\Windows\system32\Hydrogen.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 022641664 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 019851776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 019812864 _____ (Microsoft Corporation) C:\Windows\system32\HologramWorld.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 018031104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 017792512 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 014820352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 009931576 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 008015872 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 007917408 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 007850288 _____ (Microsoft Corporation) C:\Windows\system32\OneCoreUAPCommonProxyStub.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 007823912 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 007604584 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 007297536 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 007269376 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 007268640 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 007012864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 006523856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 006437376 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 006292992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 006233080 _____ (Microsoft Corporation) C:\Windows\system32\StartTileData.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 006169088 _____ (Microsoft Corporation) C:\Windows\system32\twinui.pcshell.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 006089512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 005946368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 005765648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 005111808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 005099384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 004625192 _____ (Microsoft Corporation) C:\Windows\explorer.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 004565264 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 004129424 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 004014592 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Bluetooth.Service.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 003980800 _____ (Microsoft Corporation) C:\Windows\system32\tellib.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 003974368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 003800576 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 003748352 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 003743048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OneCoreUAPCommonProxyStub.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 003727360 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
    2020-07-22 23:45 - 2020-07-22 23:45 - 003712000 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 003084800 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002799104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
    2020-07-22 23:45 - 2020-07-22 23:45 - 002768984 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002737664 _____ (Microsoft Corporation) C:\Windows\system32\WebRuntimeManager.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002716672 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
    2020-07-22 23:45 - 2020-07-22 23:45 - 002576896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002552120 _____ (Microsoft Corporation) C:\Windows\system32\UpdateAgent.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002505496 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.appcore.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002494744 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002467840 _____ (Microsoft Corporation) C:\Windows\system32\InstallService.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002448712 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002357248 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Perception.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002285056 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.Printing.3D.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002264064 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Bluetooth.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002237096 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002161664 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.PointOfService.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002087168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002074112 _____ (Microsoft Corporation) C:\Windows\system32\ISM.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002060288 _____ (Microsoft Corporation) C:\Windows\system32\cdprt.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001991592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.appcore.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001952880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001946144 _____ (Microsoft Corporation) C:\Windows\system32\dcomp.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001918464 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001885184 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001877504 _____ (Microsoft Corporation) C:\Windows\system32\LocationFramework.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001827328 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Speech.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001821696 _____ (Microsoft Corporation) C:\Windows\system32\CoreShell.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001787392 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Globalization.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001764336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001745728 _____ (Microsoft Corporation) C:\Windows\system32\ContentDeliveryManager.Utilities.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001743680 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001737728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallService.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001723392 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001697792 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001665728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001658368 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001656904 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001655472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001654304 _____ (Microsoft Corporation) C:\Windows\system32\gdi32full.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001640448 _____ (Microsoft Corporation) C:\Windows\system32\TaskFlowDataEngine.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001612800 _____ (Microsoft Corporation) C:\Windows\system32\wpncore.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001610240 _____ (Microsoft Corporation) C:\Windows\system32\HologramCompositor.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001604608 _____ (Microsoft Corporation) C:\Windows\system32\dosvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001581568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Perception.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001550336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.Printing.3D.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001540608 _____ (Microsoft Corporation) C:\Windows\system32\WindowManagement.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001512960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdprt.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001500160 _____ (Microsoft Corporation) C:\Windows\system32\TokenBroker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001495040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Bluetooth.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001486848 _____ (Microsoft Corporation) C:\Windows\system32\usocoreworker.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 001484384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001477632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dcomp.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001463808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.PointOfService.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001458688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001420328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32full.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001397568 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 001392128 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.FaceAnalysis.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001385696 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001374208 _____ (Microsoft Corporation) C:\Windows\system32\NotificationController.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001371136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001357824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Globalization.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001346048 _____ (Microsoft Corporation) C:\Windows\system32\HoloSI.PCShell.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001344512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Audio.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001337856 _____ (Microsoft Corporation) C:\Windows\system32\wpnapps.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001335296 _____ (Microsoft Corporation) C:\Windows\system32\MiracastReceiver.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001312256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001307136 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Audio.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001306944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ContentDeliveryManager.Utilities.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001290192 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Sensors.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001284608 _____ (Microsoft Corporation) C:\Windows\system32\werconcpl.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001284608 _____ (Microsoft Corporation) C:\Windows\system32\usermgr.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001271296 _____ (Microsoft Corporation) C:\Windows\system32\SEMgrSvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001265152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Speech.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001247232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBroker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001223168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.FaceAnalysis.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001195008 _____ (Microsoft Corporation) C:\Windows\system32\sdengin2.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001183744 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.Web.Core.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001159168 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApiPublic.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001151816 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001151304 _____ (Microsoft Corporation) C:\Windows\system32\InputHost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001149712 _____ (Microsoft Corporation) C:\Windows\system32\ApplyTrustOffline.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 001125376 _____ (Microsoft Corporation) C:\Windows\system32\CBDHSvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001121792 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001100800 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001086776 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Services.TargetedContent.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001081344 _____ (Microsoft Corporation) C:\Windows\system32\ShareHost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001077048 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 001068544 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001059840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001055232 _____ (Microsoft Corporation) C:\Windows\system32\Windows.AccountsControl.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001048992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001028336 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Perception.Stub.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001014784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpnapps.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001009152 _____ (Microsoft Corporation) C:\Windows\system32\StorSvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001008960 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHostCommon.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001007616 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000995840 _____ (Microsoft Corporation) C:\Windows\system32\EdgeManager.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000967680 _____ (Microsoft Corporation) C:\Windows\system32\WebcamUi.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000958608 _____ (Microsoft Corporation) C:\Windows\system32\AppContracts.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000950272 _____ (Microsoft Corporation) C:\Windows\system32\rasapi32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000949760 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Ocr.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000945176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Sensors.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000931840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Management.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000922624 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Management.Service.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000919880 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000917504 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.OnlineId.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000913408 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000912896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MiracastReceiver.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000904192 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.SmartCards.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000899584 _____ (Microsoft Corporation) C:\Windows\system32\MdmDiagnostics.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000898048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000895600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000892928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApiPublic.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000891392 _____ (Microsoft Corporation) C:\Windows\system32\HolographicExtensions.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000889416 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Shell.Broker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000882184 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000882176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ShareHost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000875008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasapi32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000867840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000865280 _____ (Microsoft Corporation) C:\Windows\system32\efswrt.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000848384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000844096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudExperienceHostCommon.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000827904 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Import.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000822200 _____ (Microsoft Corporation) C:\Windows\system32\fontdrvhost.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000821232 _____ (Microsoft Corporation) C:\Windows\system32\windows.applicationmodel.datatransfer.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000815616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebcamUi.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000814080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000809984 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Gaming.Input.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000797448 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000793320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputHost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000783488 _____ (Microsoft Corporation) C:\Windows\system32\tcblaunch.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000782848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000779080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Services.TargetedContent.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000778872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppContracts.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000750592 _____ (Microsoft Corporation) C:\Windows\system32\ActivationManager.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000750080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.OnlineId.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000742712 _____ (Microsoft Corporation) C:\Windows\system32\LicensingWinRT.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000737792 _____ (Microsoft Corporation) C:\Windows\system32\Windows.System.Launcher.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000733184 _____ (Microsoft Corporation) C:\Windows\system32\windows.immersiveshell.serviceprovider.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000727040 _____ (Microsoft Corporation) C:\Windows\system32\agentactivationruntime.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000722072 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.AccountsControl.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000716288 _____ (Microsoft Corporation) C:\Windows\system32\agentactivationruntimewindows.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Mirage.Internal.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000695208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000694784 _____ (Microsoft Corporation) C:\Windows\system32\gpprefcl.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000692224 _____ (Microsoft Corporation) C:\Windows\system32\LockController.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000689664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Ocr.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000685384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000684864 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000678720 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000673448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontdrvhost.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000669184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EdgeManager.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000653824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Management.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000651264 _____ (Microsoft Corporation) C:\Windows\system32\DevicesFlowBroker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000639488 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000638464 _____ (Microsoft Corporation) C:\Windows\system32\twinui.appcore.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000630784 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.AllJoyn.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000628416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000628024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LicensingWinRT.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000624640 _____ (Microsoft Corporation) C:\Windows\system32\TileDataRepository.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000616960 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.LowLevel.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000614912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\efswrt.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000614912 _____ (Microsoft Corporation) C:\Windows\system32\netprofmsvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000608256 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.SmartCards.Phone.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000605896 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000602112 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Payments.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000600064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActivationManager.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000596992 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000594992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Perception.Stub.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000593408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000584704 _____ (Microsoft Corporation) C:\Windows\system32\PlayToManager.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000582056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.applicationmodel.datatransfer.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000570368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Import.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000565248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Gaming.Input.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000564736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpprefcl.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000550400 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2020-07-22 23:45 - 2020-07-22 23:45 - 000549048 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.MediaControl.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000544256 _____ (Microsoft Corporation) C:\Windows\system32\usosvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000542288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000540672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.SmartCards.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000538664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000534016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000533504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000526848 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000524784 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Enumeration.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000522240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.System.Launcher.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000521728 _____ (Microsoft Corporation) C:\Windows\system32\WinBioDataModel.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000518656 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000518464 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000513024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000513024 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Activities.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000512000 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Cortana.Desktop.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000502784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.appcore.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000502784 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.WiFiDirect.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000501760 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.LockScreen.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000497664 _____ (Microsoft Corporation) C:\Windows\system32\werui.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000495616 _____ (Microsoft Corporation) C:\Windows\system32\RTMediaFrame.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000490496 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000484352 _____ (Microsoft Corporation) C:\Windows\system32\MixedReality.Broker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000478296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000477184 _____ (Microsoft Corporation) C:\Windows\system32\CloudDomainJoinDataModelServer.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000476160 _____ (Microsoft Corporation) C:\Windows\system32\MicrosoftAccountWAMExtension.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000475136 _____ (Microsoft Corporation) C:\Windows\system32\Geolocation.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000467960 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000467456 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Picker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000467456 _____ (Microsoft Corporation) C:\Windows\system32\modernexecserver.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000466432 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.Printing.Workflow.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000462848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000461112 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000458240 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.ConversationalAgent.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000456704 _____ (Microsoft Corporation) C:\Windows\system32\upnphost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000453944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000452096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TileDataRepository.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000444416 _____ (Microsoft Corporation) C:\Windows\system32\fhsettingsprovider.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000444416 _____ (Microsoft Corporation) C:\Windows\system32\edgeIso.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.AllJoyn.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000442096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.MediaControl.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000434176 _____ (Microsoft Corporation) C:\Windows\system32\MicrosoftAccountExtension.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000432128 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Midi.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000432128 _____ (Microsoft Corporation) C:\Windows\system32\WalletService.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000430592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werui.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000419328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000419328 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.NetworkOperators.ESim.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000416768 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Usb.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000416768 _____ (Microsoft Corporation) C:\Windows\system32\RDXTaskFactory.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000412672 _____ (Microsoft Corporation) C:\Windows\system32\AboveLockAppHost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000411640 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Devices.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000411136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToManager.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000410112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.SmartCards.Phone.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000406992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Enumeration.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000406992 _____ (Microsoft Corporation) C:\Windows\system32\tsmf.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000405944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Faultrep.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000403968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Payments.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000399672 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettings.DataModel.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000397824 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Lights.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000395264 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Gaming.Preview.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000392504 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000388096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.LowLevel.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000387584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.LockScreen.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000382976 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000381152 _____ (Microsoft Corporation) C:\Windows\system32\CredentialEnrollmentManager.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000380224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000375296 _____ (Microsoft Corporation) C:\Windows\system32\Windows.System.Diagnostics.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000374272 _____ (Microsoft Corporation) C:\Windows\system32\PickerPlatform.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000371712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Geolocation.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000361472 _____ (Microsoft Corporation) C:\Windows\system32\vaultsvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000361472 _____ (Microsoft Corporation) C:\Windows\system32\QuickActionsDataModel.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.WiFiDirect.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000355840 _____ (Microsoft Corporation) C:\Windows\system32\wpnclient.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000355840 _____ (Microsoft Corporation) C:\Windows\system32\WaaSMedicSvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000355328 _____ (Microsoft Corporation) C:\Windows\system32\ConsoleLogon.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RTMediaFrame.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000352256 _____ (Microsoft Corporation) C:\Windows\system32\APHostService.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000345560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsmf.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AboveLockAppHost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000340328 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Storage.ApplicationData.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000338944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Picker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000335360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MicrosoftAccountWAMExtension.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000334336 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_Cortana.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000329728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\upnphost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000328192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgeIso.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.Printing.Workflow.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\windows.internal.shellcommon.shareexperience.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32k.sys
    2020-07-22 23:45 - 2020-07-22 23:45 - 000317440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Midi.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\SyncSettings.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000311608 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHostBroker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000311440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Devices.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000306688 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.CredDialogController.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000295936 _____ (Microsoft Corporation) C:\Windows\system32\TDLMigration.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000293888 _____ (Microsoft Corporation) C:\Windows\system32\CXHProvisioningServer.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpnclient.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000292864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.System.Diagnostics.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000290304 _____ (Microsoft Corporation) C:\Windows\system32\vaultcli.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000287744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Gaming.Preview.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000285184 _____ (Microsoft Corporation) C:\Windows\system32\WaaSMedicCapsule.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000283648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.NetworkOperators.ESim.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000283136 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.AppDefaults.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000281600 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.HumanInterfaceDevice.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000280576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Usb.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000275968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Lights.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000274432 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.Identity.Provider.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000272384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PickerPlatform.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000268552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Storage.ApplicationData.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000266552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SystemSettings.DataModel.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000265728 _____ (Microsoft Corporation) C:\Windows\system32\netman.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000261632 _____ (Microsoft Corporation) C:\Windows\system32\bthprops.cpl
    2020-07-22 23:45 - 2020-07-22 23:45 - 000260288 _____ (Microsoft Corporation) C:\Windows\system32\logoncli.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000256000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ConsoleLogon.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000248832 _____ (Microsoft Corporation) C:\Windows\system32\PasswordEnrollmentManager.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000247864 _____ (Microsoft Corporation) C:\Windows\system32\weretw.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000243200 _____ (Microsoft Corporation) C:\Windows\system32\SystemEventsBrokerServer.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000242688 _____ (Microsoft Corporation) C:\Windows\system32\CapabilityAccessManagerClient.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.CredDialogController.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000240640 _____ (Microsoft Corporation) C:\Windows\system32\dialclient.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000239928 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Management.Workplace.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000237056 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.CapturePicker.Desktop.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000237056 _____ (Microsoft Corporation) C:\Windows\system32\psmsrv.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000237056 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000231424 _____ (Microsoft Corporation) C:\Windows\system32\HoloShellRuntime.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000228864 _____ (Microsoft Corporation) C:\Windows\system32\wersvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000228864 _____ (Microsoft Corporation) C:\Windows\system32\netprofm.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000227840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SyncSettings.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000224768 _____ (Microsoft Corporation) C:\Windows\system32\DWWIN.EXE
    2020-07-22 23:45 - 2020-07-22 23:45 - 000220992 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000220672 _____ (Microsoft Corporation) C:\Windows\system32\MtcModel.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000219136 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000217600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bthprops.cpl
    2020-07-22 23:45 - 2020-07-22 23:45 - 000217600 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Core.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\UserDeviceRegistration.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000215040 _____ (Microsoft Corporation) C:\Windows\system32\PeopleBand.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000215040 _____ (Microsoft Corporation) C:\Windows\system32\DiagSvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000211256 _____ (Microsoft Corporation) C:\Windows\system32\tcbloader.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000210944 _____ (Microsoft Corporation) C:\Windows\system32\ErrorDetails.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000206336 _____ (Microsoft Corporation) C:\Windows\system32\useractivitybroker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000200704 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Internal.Input.ExpressiveInput.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000199496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000196096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000195584 _____ (Microsoft Corporation) C:\Windows\system32\AarSvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000193600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\weretw.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000190056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logoncli.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000188928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000188928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWWIN.EXE
    2020-07-22 23:45 - 2020-07-22 23:45 - 000186368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000183808 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Energy.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000180224 _____ (Microsoft Corporation) C:\Windows\system32\dialserver.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000179712 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_Clipboard.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000179512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
    2020-07-22 23:45 - 2020-07-22 23:45 - 000179200 _____ (Microsoft Corporation) C:\Windows\system32\PrintWorkflowService.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000179200 _____ (Microsoft Corporation) C:\Windows\system32\easwrt.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000179200 _____ (Microsoft Corporation) C:\Windows\system32\AppExtension.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000178688 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Graphics.Display.DisplayEnhancementManagement.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000176952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Management.Workplace.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\HoloShellRuntime.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dialclient.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000172032 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.CapturePicker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000165840 _____ (Microsoft Corporation) C:\Windows\system32\WerFaultSecure.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000165376 _____ (Microsoft Corporation) C:\Windows\splwow64.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000162816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ErrorDetails.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDeviceRegistration.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000160768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CapabilityAccessManagerClient.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000159744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Core.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000157184 _____ (Microsoft Corporation) C:\Windows\system32\PrintWSDAHost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000152064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\useractivitybroker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000151552 _____ (Microsoft Corporation) C:\Windows\system32\fdWSD.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000151040 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.SerialCommunication.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000150336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFaultSecure.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000147968 _____ (Microsoft Corporation) C:\Windows\system32\Family.Client.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000146232 _____ (Microsoft Corporation) C:\Windows\system32\ResourcePolicyServer.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\AppointmentActivation.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000143360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\easwrt.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintWorkflowService.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000140800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Energy.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000133632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Graphics.Display.DisplayEnhancementManagement.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000133632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppExtension.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000132608 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Storage.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000132408 _____ (Microsoft Corporation) C:\Windows\system32\offlinelsa.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000131584 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairingExperienceMEM.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000131072 _____ (Microsoft Corporation) C:\Windows\system32\CredDialogBroker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000130560 _____ (Microsoft Corporation) C:\Windows\system32\StorageUsage.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\CameraCaptureUI.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\CaptureService.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fdWSD.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000127064 _____ (Microsoft Corporation) C:\Windows\system32\win32u.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000125952 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000124928 _____ (Microsoft Corporation) C:\Windows\system32\wercplsupport.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintWSDAHost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000118784 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Background.SystemEventsBroker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000118272 _____ (Microsoft Corporation) C:\Windows\system32\EaseOfAccessDialog.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppointmentActivation.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000112128 _____ (Microsoft Corporation) C:\Windows\system32\AxInstSv.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000110040 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Credentials.UI.CredentialPicker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000107520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.SerialCommunication.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000105984 _____ (Microsoft Corporation) C:\Windows\system32\utcutil.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\sethc.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\Family.Authentication.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000100352 _____ (Microsoft Corporation) C:\Windows\system32\DiagnosticInvoker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000099328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000094720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CameraCaptureUI.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000094208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EaseOfAccessDialog.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000093184 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000092672 _____ (Microsoft Corporation) C:\Windows\system32\wsqmcons.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000091648 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Graphics.Display.DisplayColorManagement.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000090624 _____ (Microsoft Corporation) C:\Windows\system32\keyiso.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000089600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000089328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32u.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000089088 _____ (Microsoft Corporation) C:\Windows\system32\WaaSMedicAgent.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000086272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Credentials.UI.CredentialPicker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000083456 _____ (Microsoft Corporation) C:\Windows\system32\SystemUWPLauncher.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000082432 _____ (Microsoft Corporation) C:\Windows\system32\LocationFrameworkInternalPS.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000081408 _____ (Microsoft Corporation) C:\Windows\system32\Print.Workflow.Source.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000079360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sethc.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000076952 _____ (Microsoft Corporation) C:\Windows\system32\CredentialEnrollmentManagerForUser.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DiagnosticInvoker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000071168 _____ (Microsoft Corporation) C:\Windows\system32\MiracastReceiverExt.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000070248 _____ (Microsoft Corporation) C:\Windows\system32\ResourcePolicyClient.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000068096 _____ (Microsoft Corporation) C:\Windows\system32\udhisapi.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000066560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\keyiso.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Graphics.Display.DisplayColorManagement.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000065536 _____ (Microsoft Corporation) C:\Windows\system32\iemigplugin.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SystemUWPLauncher.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000063488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iemigplugin.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Print.Workflow.Source.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\mf3216.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\AxInstUI.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000058368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\udhisapi.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000058368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MiracastReceiverExt.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000052152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ResourcePolicyClient.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000046080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf3216.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000045056 _____ (Microsoft Corporation) C:\Windows\system32\npmproxy.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000044544 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\upnpcont.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000040248 _____ (Microsoft Corporation) C:\Windows\system32\LocationFrameworkPS.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000038912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werdiagcontroller.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000037376 _____ (Microsoft Corporation) C:\Windows\system32\UIMgrBroker.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\upnpcont.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\SystemEventsBrokerClient.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\nlmproxy.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\WaaSMedicPS.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\PrintWorkflowProxy.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000024064 _____ (Microsoft Corporation) C:\Windows\system32\CSystemEventsBrokerClient.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000021504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SystemEventsBrokerClient.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000017408 _____ (Microsoft Corporation) C:\Windows\system32\nlmsprep.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintWorkflowProxy.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.Printing.Workflow.Native.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000013824 _____ (Microsoft Corporation) C:\Windows\system32\UIManagerBrokerps.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.Printing.Workflow.Native.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000012288 _____ (Microsoft Corporation) C:\Windows\system32\RemoteFXvGPUDisablement.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000008192 _____ (Microsoft Corporation) C:\Windows\system32\msimg32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimg32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000003072 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000002560 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000000315 _____ C:\Windows\system32\DrtmAuth9.bin
    2020-07-22 23:45 - 2020-07-22 23:45 - 000000315 _____ C:\Windows\system32\DrtmAuth8.bin
    2020-07-22 23:45 - 2020-07-22 23:45 - 000000315 _____ C:\Windows\system32\DrtmAuth7.bin
    2020-07-22 23:45 - 2020-07-22 23:45 - 000000315 _____ C:\Windows\system32\DrtmAuth6.bin
    2020-07-22 23:45 - 2020-07-22 23:45 - 000000315 _____ C:\Windows\system32\DrtmAuth5.bin
    2020-07-22 23:45 - 2020-07-22 23:45 - 000000315 _____ C:\Windows\system32\DrtmAuth4.bin
    2020-07-22 23:45 - 2020-07-22 23:45 - 000000315 _____ C:\Windows\system32\DrtmAuth3.bin
    2020-07-22 23:45 - 2020-07-22 23:45 - 000000315 _____ C:\Windows\system32\DrtmAuth2.bin
    2020-07-22 23:45 - 2020-07-22 23:45 - 000000315 _____ C:\Windows\system32\DrtmAuth12.bin
    2020-07-22 23:45 - 2020-07-22 23:45 - 000000315 _____ C:\Windows\system32\DrtmAuth11.bin
    2020-07-22 23:45 - 2020-07-22 23:45 - 000000315 _____ C:\Windows\system32\DrtmAuth10.bin
    2020-07-22 23:45 - 2020-07-22 23:45 - 000000315 _____ C:\Windows\system32\DrtmAuth1.bin
    2020-07-22 23:44 - 2020-07-22 23:44 - 000656696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys
    2020-07-22 23:44 - 2020-07-22 23:44 - 000204608 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spacedump.sys
    2020-07-22 23:40 - 2020-06-29 23:32 - 000390656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
    2020-07-22 23:40 - 2020-06-29 23:26 - 000492544 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
    2020-07-22 05:48 - 2020-08-09 14:16 - 008960762 _____ C:\Users\jseym\Downloads\FileZilla_3.49.1_win64-setup.exe.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-22 05:48 - 2020-07-22 05:48 - 008174024 _____ (Tim Kosse) C:\Users\jseym\Downloads\FileZilla_3.49.1_win64-setup.exe
    2020-07-21 15:21 - 2020-08-09 17:19 - 000000000 ____D C:\Users\jseym\AppData\Local\ZoogVPN
    2020-07-21 15:15 - 2020-07-21 15:20 - 000000000 ____D C:\Program Files (x86)\ZoogVPN
    2020-07-21 15:15 - 2020-07-21 15:15 - 000001067 _____ C:\Users\Public\Desktop\ZoogVPN.lnk
    2020-07-21 15:15 - 2020-07-21 15:15 - 000001067 _____ C:\ProgramData\Desktop\ZoogVPN.lnk
    2020-07-21 15:15 - 2020-07-21 15:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZoogVPN
    2020-07-21 15:15 - 2020-07-21 15:15 - 000000000 ____D C:\Program Files\TAP-Windows
    2020-07-21 01:32 - 2020-08-09 14:16 - 011288952 _____ C:\Users\jseym\Downloads\earth-4k-green-screen-pack-re.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-14 21:49 - 2020-08-09 17:37 - 000000000 ____D C:\Users\jseym\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
    2020-07-14 21:49 - 2020-08-09 14:04 - 000000000 ____D C:\Users\jseym\AppData\Roaming\FileZilla
    2020-07-14 21:49 - 2020-08-09 04:49 - 000000000 ____D C:\Users\jseym\AppData\Local\FileZilla
    2020-07-14 21:49 - 2020-07-28 17:15 - 000001934 _____ C:\Users\jseym\Desktop\FileZilla Client.lnk
    2020-07-14 21:49 - 2020-07-28 17:15 - 000000000 ____D C:\Program Files\FileZilla FTP Client
    2020-07-14 21:44 - 2020-08-09 14:16 - 011649634 _____ C:\Users\jseym\Downloads\FileZilla_3.49.0_win64_sponsored-setup.exe.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-14 21:44 - 2020-07-14 21:48 - 010862880 _____ (Tim Kosse) C:\Users\jseym\Downloads\FileZilla_3.49.0_win64_sponsored-setup.exe
    2020-07-14 14:13 - 2020-07-14 14:13 - 000000000 ____D C:\Users\jseym\AppData\Roaming\Skype
    2020-07-13 15:06 - 2020-08-09 17:37 - 000000000 ____D C:\Users\jseym\AppData\Roaming\dvdcss
    2020-07-12 15:39 - 2020-08-09 17:37 - 000000000 ____D C:\Users\jseym\Downloads\Minecraft 1.8.9 (Full installer, Online, Serverlist)
    2020-07-10 15:53 - 2020-07-10 15:53 - 000000000 ____D C:\Users\jseym\AppData\LocalLow\Ookla
    2020-07-10 15:53 - 2020-07-10 15:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speedtest By Ookla
    2020-07-10 15:53 - 2020-07-10 15:53 - 000000000 ____D C:\Program Files\Speedtest

    ==================== One month (modified) ==================

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2020-08-09 19:03 - 2020-05-12 04:13 - 000000000 ____D C:\Users\jseym\AppData\Roaming\LBRY
    2020-08-09 19:03 - 2020-05-12 03:40 - 000000000 ____D C:\Users\jseym\AppData\LocalLow\uTorrent
    2020-08-09 18:59 - 2019-03-18 23:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2020-08-09 18:47 - 2020-05-11 22:57 - 000000000 ____D C:\Users\jseym\AppData\LocalLow\Mozilla
    2020-08-09 18:44 - 2020-05-11 22:45 - 000000000 __SHD C:\Users\jseym\IntelGraphicsProfiles
    2020-08-09 18:43 - 2020-05-11 22:39 - 000000000 ____D C:\Users\jseym
    2020-08-09 18:43 - 2019-11-15 11:46 - 000000000 ____D C:\Windows\system32\SleepStudy
    2020-08-09 17:52 - 2019-11-15 11:57 - 000840916 _____ C:\Windows\system32\PerfStringBackup.INI
    2020-08-09 17:52 - 2019-03-18 23:50 - 000000000 ____D C:\Windows\INF
    2020-08-09 17:46 - 2019-11-15 11:47 - 000000006 ____H C:\Windows\Tasks\SA.DAT
    2020-08-09 17:45 - 2019-11-15 11:50 - 000000000 __RHD C:\Users\Public\AccountPictures
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 __RHD C:\Users\Public\Libraries
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ___SD C:\Windows\SysWOW64\Nui
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ___SD C:\Windows\system32\Nui
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\SysWOW64\Bthprops
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\SystemResources
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\system32\Sysprep
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\system32\Keywords
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\system32\DDFs
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\system32\Bthprops
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\System
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\ShellExperiences
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\PolicyDefinitions
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\DiagTrack
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\bcastdvr
    2020-08-09 17:37 - 2020-06-29 02:46 - 000000000 ___RD C:\Users\jseym\Downloads\Stock for FX
    2020-08-09 17:37 - 2020-06-09 15:41 - 000000000 ____D C:\Users\jseym\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bing Wallpaper
    2020-08-09 17:37 - 2020-05-26 23:32 - 000000000 ____D C:\Users\jseym\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HandBrake
    2020-08-09 17:37 - 2020-05-18 13:32 - 000000000 ____D C:\Users\jseym\AppData\Roaming\vlc
    2020-08-09 17:37 - 2020-05-16 19:54 - 000000000 ____D C:\Users\jseym\AppData\Roaming\obs-studio
    2020-08-09 17:37 - 2020-05-16 19:54 - 000000000 ____D C:\ProgramData\obs-studio-hook
    2020-08-09 17:37 - 2020-05-14 22:58 - 000000000 ____D C:\Program Files (x86)\Red Giant Link
    2020-08-09 17:37 - 2020-05-13 18:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Red Giant
    2020-08-09 17:37 - 2020-05-13 18:45 - 000000000 ____D C:\Program Files\Red Giant
    2020-08-09 17:37 - 2020-05-12 15:44 - 000000000 ____D C:\ProgramData\Package Cache
    2020-08-09 17:37 - 2020-05-12 04:12 - 000000000 ____D C:\Users\jseym\AppData\Local\lbry-updater
    2020-08-09 17:37 - 2020-05-12 04:05 - 000000000 ____D C:\Users\jseym\AppData\Roaming\DAZ 3D
    2020-08-09 17:37 - 2020-05-11 22:57 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2020-08-09 17:37 - 2020-05-11 22:45 - 000000000 ___RD C:\Users\jseym\3D Objects
    2020-08-09 17:37 - 2020-05-11 22:45 - 000000000 ____D C:\Users\jseym\AppData\Local\ConnectedDevicesPlatform
    2020-08-09 17:37 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\appcompat
    2020-08-09 17:27 - 2019-03-18 23:52 - 000000000 ___HD C:\Program Files\WindowsApps
    2020-08-09 17:22 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\registration
    2020-08-09 17:19 - 2020-07-07 13:28 - 000000000 ____D C:\Users\Public\Pixologic
    2020-08-09 17:19 - 2020-06-29 22:36 - 000000000 ____D C:\Users\jseym\Downloads\j
    2020-08-09 17:19 - 2020-06-29 02:47 - 000000000 ____D C:\Users\jseym\Downloads\Daz
    2020-08-09 17:19 - 2020-06-29 02:42 - 000000000 ____D C:\Users\Public\Documents\My DAZ 3D Library
    2020-08-09 17:19 - 2020-06-29 02:42 - 000000000 ____D C:\ProgramData\Documents\My DAZ 3D Library
    2020-08-09 17:19 - 2020-06-29 02:41 - 000000000 ____D C:\Users\Public\Documents\DAZ 3D
    2020-08-09 17:19 - 2020-06-29 02:41 - 000000000 ____D C:\ProgramData\Documents\DAZ 3D
    2020-08-09 17:19 - 2020-06-18 22:05 - 000000000 ____D C:\Users\jseym\AppData\Local\VEGAS Pro
    2020-08-09 17:19 - 2020-06-08 01:01 - 000000000 ____D C:\Users\jseym\Documents\Adobe
    2020-08-09 17:19 - 2020-06-08 00:58 - 000000000 ____D C:\Users\Public\Documents\Adobe
    2020-08-09 17:19 - 2020-06-08 00:58 - 000000000 ____D C:\ProgramData\Documents\Adobe
    2020-08-09 17:19 - 2020-05-13 18:23 - 000000000 ____D C:\Users\jseym\AppData\Local\Red Giant
    2020-08-09 17:19 - 2020-05-13 18:21 - 000000000 ____D C:\Users\jseym\AppData\Roaming\Red Giant
    2020-08-09 17:19 - 2020-05-12 03:31 - 000000000 ____D C:\Users\jseym\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DAZ 3D
    2020-08-09 17:19 - 2020-05-11 23:31 - 000000000 ____D C:\Users\jseym\Documents\DAZ 3D
    2020-08-09 17:19 - 2020-05-11 22:45 - 000000000 ___HD C:\Users\jseym\MicrosoftEdgeBackups
    2020-08-09 17:19 - 2020-05-11 22:45 - 000000000 ____D C:\Users\jseym\AppData\Local\VirtualStore
    2020-08-09 17:18 - 2020-05-15 00:37 - 000000000 ____D C:\Program Files (x86)\Intel
    2020-08-09 17:18 - 2020-05-14 22:59 - 000000000 ____D C:\ProgramData\RedGiant
    2020-08-09 17:18 - 2020-05-13 18:20 - 000000000 ____D C:\ProgramData\Red Giant
    2020-08-09 16:48 - 2020-07-07 23:52 - 000000000 ____D C:\Users\jseym\Desktop\Fire Embers Ash Dust
    2020-08-09 16:11 - 2020-05-11 22:47 - 000000000 ___RD C:\Users\jseym\OneDrive
    2020-08-09 14:42 - 2020-05-26 23:32 - 000000000 ____D C:\Users\jseym\AppData\Roaming\HandBrake
    2020-08-09 14:25 - 2019-03-18 23:37 - 000000000 ____D C:\Windows\CbsTemp
    2020-08-09 14:16 - 2020-06-29 03:08 - 000000000 ____D C:\Users\jseym\Downloads\Books
    2020-08-09 14:15 - 2020-06-14 01:44 - 000000000 ____D C:\Users\jseym\Documents\The Silent Corner - Dean Koontz [EN EPUB MOBI] [ebook] [ps]
    2020-08-09 14:15 - 2020-06-12 20:03 - 000000000 ____D C:\Users\jseym\Documents\Sound recordings
    2020-08-09 14:15 - 2020-06-04 02:04 - 000000000 ____D C:\Users\jseym\Documents\Photo SHop
    2020-08-09 14:15 - 2020-05-12 04:19 - 070818500 _____ C:\Users\jseym\Documents\lbryum-2020-04-22T03-26-39.710Z.zip.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-07-08 00:32 - 000000000 ____D C:\Users\jseym\Desktop\new stock
    2020-08-09 14:05 - 2020-07-08 00:17 - 000000000 ____D C:\Users\jseym\Desktop\Blood
    2020-08-09 14:05 - 2020-07-08 00:08 - 046656791 _____ C:\Users\jseym\Desktop\Virtual Studio Blue Earth 2016.mp4
    2020-08-09 14:05 - 2020-07-07 23:53 - 000000000 ____D C:\Users\jseym\Desktop\Filter PNGs
    2020-08-09 14:05 - 2020-06-13 22:49 - 000000000 ____D C:\Users\jseym\Documents\Audacity
    2020-08-09 14:05 - 2020-06-13 22:16 - 000000000 ____D C:\Users\jseym\AppData\Roaming\Sony
    2020-08-09 14:05 - 2020-05-13 23:17 - 000000000 ____D C:\Users\jseym\Documents\Background_Lights
    2020-08-09 14:02 - 2020-05-12 03:23 - 000000000 ____D C:\Users\jseym\AppData\Local\BitTorrentHelper
    2020-08-09 04:52 - 2020-05-11 22:48 - 000000000 ____D C:\Users\jseym\AppData\Local\PlaceholderTileLogoFolder
    2020-08-09 04:49 - 2020-05-13 23:16 - 000000000 ____D C:\ProgramData\VideoCopilot
    2020-08-08 14:00 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\AppReadiness
    2020-08-04 19:53 - 2019-11-15 11:47 - 000000000 ____D C:\Windows\system32\Drivers\wd
    2020-08-03 15:21 - 2019-03-18 23:37 - 000786432 _____ C:\Windows\system32\config\BBI
    2020-07-30 15:01 - 2020-05-11 22:57 - 000001012 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
    2020-07-23 06:29 - 2020-05-11 22:45 - 000000000 ____D C:\Users\jseym\AppData\Local\Packages
    2020-07-23 05:53 - 2020-05-11 22:47 - 000003378 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-871970874-3256418639-2447214560-1004
    2020-07-23 05:53 - 2020-05-11 22:47 - 000002370 _____ C:\Users\jseym\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
    2020-07-23 01:26 - 2019-11-15 11:46 - 000257824 _____ C:\Windows\system32\FNTCACHE.DAT
    2020-07-23 01:26 - 2019-03-18 23:52 - 000000000 ___SD C:\Windows\system32\DiagSvcs
    2020-07-23 01:26 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\system32\oobe
    2020-07-23 01:26 - 2019-03-18 23:52 - 000000000 ____D C:\Program Files\Common Files\System
    2020-07-23 01:26 - 2019-03-18 23:37 - 000786432 _____ C:\Windows\system32\config\BBI(879)
    2020-07-21 14:43 - 2019-11-15 11:50 - 000000000 ____D C:\ProgramData\Packages
    2020-07-16 01:57 - 2020-05-26 16:13 - 000000000 ____D C:\Users\jseym\AppData\Local\ElevatedDiagnostics
    2020-07-14 15:13 - 2020-05-15 01:33 - 000001517 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Driver & Support Assistant.lnk
    2020-07-10 14:04 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\system32\NDF
    2020-07-10 02:27 - 2020-05-12 15:45 - 000000000 ____D C:\Users\jseym\AppData\Local\D3DSCache

    ==================== Files in the root of some directories ========

    2020-08-02 04:12 - 2020-08-02 04:12 - 000823296 _____ () C:\Users\Public\fxc.exe
    2020-08-02 04:18 - 2020-08-02 04:18 - 000823296 _____ () C:\Users\Public\ldz.exe
    2020-08-02 04:23 - 2020-08-02 04:23 - 000823296 _____ () C:\Users\Public\mlx.exe
    2020-08-02 04:23 - 2020-08-02 04:23 - 000823296 _____ () C:\Users\Public\rdn.exe
    2020-08-02 04:22 - 2020-08-02 04:22 - 000823296 _____ () C:\Users\Public\uwa.exe
    2020-08-02 04:11 - 2020-08-02 04:11 - 000823296 _____ () C:\Users\Public\xdg.exe
    2020-08-09 14:03 - 2020-08-09 14:03 - 000352402 _____ () C:\Users\jseym\AppData\Roaming\CodecsLE_Install.log.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-02 04:13 - 2020-08-02 04:12 - 000200192 _____ (H$a8qZ9|6&NbzD4*) C:\Users\jseym\AppData\Roaming\dllsha.exe
    2020-08-09 14:04 - 2020-08-09 14:04 - 000200450 _____ () C:\Users\jseym\AppData\Roaming\dllsha.exe.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 04:49 - 2020-08-09 04:49 - 000000402 _____ () C:\Users\jseym\AppData\Local\Iksl.url.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-02 04:12 - 2020-08-02 04:12 - 001034806 _____ () C:\Users\jseym\AppData\Local\Ikslsec.exe
    2020-08-09 04:49 - 2020-08-09 04:49 - 001035058 _____ () C:\Users\jseym\AppData\Local\Ikslsec.exe.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 04:52 - 2020-08-09 04:52 - 000000658 _____ () C:\Users\jseym\AppData\Local\oobelibMkey.log.id[244EA16D-2275].[helprecover@foxmail.com].help

    ==================== SigCheck ============================

    (There is no automatic fix for files that do not pass verification.)

    ==================== End of FRST.txt ========================


    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-08-2020
    Ran by jseym (09-08-2020 19:06:00)
    Running from C:\Users\jseym\Downloads
    Windows 10 Pro Version 1909 18363.959 (X64) (2020-05-12 04:04:31)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-871970874-3256418639-2447214560-500 - Administrator - Disabled)
    DefaultAccount (S-1-5-21-871970874-3256418639-2447214560-503 - Limited - Disabled)
    Guest (S-1-5-21-871970874-3256418639-2447214560-501 - Limited - Disabled)
    jseym (S-1-5-21-871970874-3256418639-2447214560-1004 - Administrator - Enabled) => C:\Users\jseym
    WDAGUtilityAccount (S-1-5-21-871970874-3256418639-2447214560-504 - Limited - Disabled)

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Adobe After Effects 2020 (HKLM-x32\...\AEFT_17_0) (Version: 17.0 - Adobe Systems Incorporated)
    Adobe Media Encoder 2020 (HKLM-x32\...\AME_14_0) (Version: 14.0 - Adobe Systems Incorporated)
    Adobe Photoshop 2020 (HKLM-x32\...\PHSP_21_0) (Version: 21.0 - Adobe Systems Incorporated)
    Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
    Apple Software Update (HKLM-x32\...\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
    Avid Codecs LE (HKLM-x32\...\{EDEE0982-74B9-4CD0-ACD3-5DAF23C64914}) (Version: 2.7.6.39455 - Avid Technology)
    Bing Wallpaper (HKLM-x32\...\{7537BF38-E61E-461C-96E0-27C6F960AB03}) (Version: 1.0.7.5 - Microsoft Corporation)
    DAZ Install Manager (64-bit) (HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\DAZ Install Manager (64-bit) 1.4.0.46) (Version: 1.4.0.46 - DAZ 3D)
    DazCentral (64-bit) (HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\DazCentral (64-bit) 1.0.0.15) (Version: 1.0.0.15 - DAZ 3D)
    FileZilla Client 3.49.1 (HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\FileZilla Client) (Version: 3.49.1 - Tim Kosse)
    HandBrake 1.3.2 (HKLM-x32\...\HandBrake) (Version: 1.3.2 - )
    Intel Driver && Support Assistant (HKLM-x32\...\{0B6D9E45-696A-452C-B0FE-32A37F1792F9}) (Version: 20.7.26.7 - Intel) Hidden
    Intel(R) C++ Redistributables on Intel(R) 64 (HKLM-x32\...\{F70BCE36-25F2-4475-A918-6209B3D85BF3}) (Version: 15.0.179 - Intel Corporation)
    Intel(R) Computing Improvement Program (HKLM\...\{D98C2DF9-C731-4322-A5F0-D897300216EE}) (Version: 2.4.05718 - Intel Corporation)
    Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.5129 - Intel Corporation)
    Intel® Driver & Support Assistant (HKLM-x32\...\{3fa11c9d-9f7f-4020-bcef-dbf9c9fe309f}) (Version: 20.7.26.7 - Intel)
    LBRY 0.47.1 (HKLM\...\e406725b-d361-5b1c-81f7-0a4c5ac54cb3) (Version: 0.47.1 - LBRY Inc.)
    Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 84.0.522.52 - Microsoft Corporation)
    Microsoft Edge Update (HKLM-x32\...\Microsoft Edge Update) (Version: 1.3.133.5 - )
    Microsoft OneDrive (HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\OneDriveSetup.exe) (Version: 20.114.0607.0002 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
    Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.23.27820 (HKLM-x32\...\{852adda4-4c78-4a38-b583-c0b360a329d6}) (Version: 14.23.27820.0 - Microsoft Corporation)
    Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.25.28508 (HKLM-x32\...\{6913e92a-b64e-41c9-a5e6-cef39207fe89}) (Version: 14.25.28508.3 - Microsoft Corporation)
    Microsoft Visual C++ 2017 Redistributable (x86) - 14.16.27027 (HKLM-x32\...\{39e28474-b67b-4209-af1b-e9ad0a83d8ca}) (Version: 14.16.27027.1 - Microsoft Corporation)
    Mozilla Firefox 79.0 (x64 en-US) (HKLM\...\Mozilla Firefox 79.0 (x64 en-US)) (Version: 79.0 - Mozilla)
    Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 76.0.1 - Mozilla)
    OBS Studio (HKLM-x32\...\OBS Studio) (Version: 25.0.8 - OBS Project)
    QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7695 - Realtek Semiconductor Corp.)
    Speedtest by Ookla (HKLM\...\{C199C004-CC2D-4741-A504-7A0C8EBB9174}) (Version: 1.7.124.001 - Ookla)
    SuperLuminal StarDust v1.1.2 CE for After Effects (HKLM\...\StarDust_is1) (Version: 1.1.2 - Team V.R)
    TAP-Windows 9.21.2 (HKLM\...\TAP-Windows) (Version: 9.21.2 - )
    Trapcode Suite (HKLM\...\Trapcode Suite v15.1.6) (Version: - Red Giant LLC)
    VEGAS Pro 16.0 (HKLM\...\{0A119E00-A098-11E8-A73C-00155D6302F2}) (Version: 16.0.248 - VEGAS)
    VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.8 - VideoLAN)
    ZoogVPN version 5.3.1.40 (HKLM-x32\...\ZoogVPN_is1) (Version: 5.3.1.40 - )

    Packages:
    =========
    Audacity - Audio Editor and Recorder -> C:\Program Files\WindowsApps\BluskySoftwareInc.17062EE08491F_2.0.6.0_x86__61yk12x6sxn40 [2020-08-09] (Blusky Software Inc.)
    BreeZip -> C:\Program Files\WindowsApps\3138AweZip.AweZip_1.3.18.0_x86__ffd303wmbhcjt [2020-08-09] (BreeZip) [MS Ad]
    GIF Maker - Photos to GIF, Video to GIF -> C:\Program Files\WindowsApps\12176PicturePerfectApps.GIFMaker-PhotostoGIFVideot_1.1.24.0_x64__e40414p8savay [2020-08-09] (Picture Perfect Apps) [MS Ad]
    Microsoft Access -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Access_16051.13001.20384.0_x86__8wekyb3d8bbwe [2020-08-09] (Microsoft Corporation)
    Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2020-08-09] (Microsoft Corporation) [MS Ad]
    Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2020-08-09] (Microsoft Corporation) [MS Ad]
    Microsoft Excel -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Excel_16051.13001.20384.0_x86__8wekyb3d8bbwe [2020-08-09] (Microsoft Corporation)
    Microsoft Office Desktop Apps -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop_16051.13001.20384.0_x86__8wekyb3d8bbwe [2020-08-09] (Microsoft Corporation)
    Microsoft Outlook -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.13001.20384.0_x86__8wekyb3d8bbwe [2020-08-09] (Microsoft Corporation)
    Microsoft PowerPoint -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.PowerPoint_16051.13001.20384.0_x86__8wekyb3d8bbwe [2020-08-09] (Microsoft Corporation)
    Microsoft Publisher -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Publisher_16051.13001.20384.0_x86__8wekyb3d8bbwe [2020-08-09] (Microsoft Corporation)
    Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.7.7162.0_x64__8wekyb3d8bbwe [2020-08-09] (Microsoft Studios) [MS Ad]
    Microsoft Word -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Word_16051.13001.20384.0_x86__8wekyb3d8bbwe [2020-08-09] (Microsoft Corporation)
    MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x64__8wekyb3d8bbwe [2020-08-09] (Microsoft Corporation) [MS Ad]
    RAR Opener -> C:\Program Files\WindowsApps\DeviceDoctor.RAROpener_1.3.48.0_x64__mkdtfchztkfbm [2020-08-09] (Tiny Opener)
    Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.138.558.0_x86__zpdnekdrzrea0 [2020-08-09] (Spotify AB) [Startup Task]

    ==================== Custom CLSID (Whitelisted): ==============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-871970874-3256418639-2447214560-1004_Classes\CLSID\{233525e0-5434-46ef-b464-fd7e45e2e145}\localserver32 -> C:\Program Files (x86)\Intel\Driver and Support Assistant\DSATray.exe (IDSA Production signing key -> Intel)
    CustomCLSID: HKU\S-1-5-21-871970874-3256418639-2447214560-1004_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel(R) pGFX -> Intel Corporation)
    ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )
    ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )
    ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )
    ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )
    ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
    ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2020-02-27] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
    ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )

    ==================== Codecs (Whitelisted) ====================

    ==================== Shortcuts & WMI ========================

    (The entries could be listed to be restored or removed.)

    Shortcut: C:\Users\jseym\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DAZ 3D\DazCentral (64-bit)\DazCentral (64-bit) Read Me.lnk -> hxxp:docs.daz3d.com\doku.php\public\read_me\index\69521
    Shortcut: C:\Users\jseym\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DAZ 3D\DAZ Install Manager (64-bit)\DAZ Install Manager (64-bit) Read Me.lnk -> hxxp:docs.daz3d.com\doku.php\public\read_me\index\14811

    ==================== Loaded Modules (Whitelisted) =============

    2015-12-09 13:59 - 2015-12-09 13:59 - 000221184 _____ (Apple Computer, Inc.) [File not signed] C:\Program Files (x86)\QuickTime\QTSystem\CoreVideo.qtx
    2015-12-09 13:59 - 2015-12-09 13:59 - 000061440 _____ (Apple Inc.) [File not signed] C:\Program Files (x86)\QuickTime\QTSystem\ExportControllerPS.dll
    2015-12-09 13:59 - 2015-12-09 13:59 - 000176128 _____ (Apple Inc.) [File not signed] C:\Program Files (x86)\QuickTime\QTSystem\QTCF.dll
    2015-12-09 13:59 - 2015-12-09 13:59 - 012369920 _____ (Apple Inc.) [File not signed] C:\Program Files (x86)\QuickTime\QTSystem\QuickTime.qts
    2015-12-09 13:59 - 2015-12-09 13:59 - 000217088 _____ (Apple Inc.) [File not signed] C:\Program Files (x86)\QuickTime\QTSystem\QuickTime3GPP.qtx
    2015-12-09 13:59 - 2015-12-09 13:59 - 000372736 _____ (Apple Inc.) [File not signed] C:\Program Files (x86)\QuickTime\QTSystem\QuickTime3GPPAuthoring.qtx
    2015-12-09 13:59 - 2015-12-09 13:59 - 000106496 _____ (Apple Inc.) [File not signed] C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeAudioSupport.qtx
    2015-12-09 13:59 - 2015-12-09 13:59 - 001974272 _____ (Apple Inc.) [File not signed] C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeAuthoring.qtx
    2015-12-09 13:59 - 2015-12-09 13:59 - 000331776 _____ (Apple Inc.) [File not signed] C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeCapture.qtx
    2015-12-09 13:59 - 2015-12-09 13:59 - 000585728 _____ (Apple Inc.) [File not signed] C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeEffects.qtx
    2015-12-09 13:59 - 2015-12-09 13:59 - 000339968 _____ (Apple Inc.) [File not signed] C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeEssentials.qtx
    2015-12-09 13:59 - 2015-12-09 13:59 - 003153920 _____ (Apple Inc.) [File not signed] C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeH264.qtx
    2015-12-09 13:59 - 2015-12-09 13:59 - 000987136 _____ (Apple Inc.) [File not signed] C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeImage.qtx
    2015-12-09 13:59 - 2015-12-09 13:59 - 000847872 _____ (Apple Inc.) [File not signed] C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeInternetExtras.qtx
    2015-12-09 13:59 - 2015-12-09 13:59 - 000491520 _____ (Apple Inc.) [File not signed] C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeMPEG.qtx
    2015-12-09 13:59 - 2015-12-09 13:59 - 000360448 _____ (Apple Inc.) [File not signed] C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeMPEG4.qtx
    2015-12-09 13:59 - 2015-12-09 13:59 - 000589824 _____ (Apple Inc.) [File not signed] C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeMPEG4Authoring.qtx
    2015-12-09 13:59 - 2015-12-09 13:59 - 000524288 _____ (Apple Inc.) [File not signed] C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeMusic.qtx
    2015-12-09 13:59 - 2015-12-09 13:59 - 000892928 _____ (Apple Inc.) [File not signed] C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeStreaming.qtx
    2015-12-09 13:59 - 2015-12-09 13:59 - 000364544 _____ (Apple Inc.) [File not signed] C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeStreamingAuthoring.qtx
    2015-12-09 13:59 - 2015-12-09 13:59 - 000176128 _____ (Apple Inc.) [File not signed] C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeStreamingExtras.qtx
    2015-12-09 13:59 - 2015-12-09 13:59 - 000598016 _____ (Apple Inc.) [File not signed] C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeThirdParty.qtx
    2015-12-09 13:59 - 2015-12-09 13:59 - 000888832 _____ (Apple Inc.) [File not signed] C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeVR.qtx
    2020-03-10 10:31 - 2020-03-10 10:31 - 001631744 _____ (Robert Simpson, et al.) [File not signed] C:\Program Files\Intel\SUR\QUEENCREEK\x64\SQLite.Interop.dll
    2020-03-10 10:31 - 2020-03-10 10:31 - 001918464 _____ (SQLite Development Team) [File not signed] C:\Program Files\Intel\SUR\QUEENCREEK\sqlite3.DLL
    2020-03-10 10:31 - 2020-03-10 10:31 - 001918464 _____ (SQLite Development Team) [File not signed] C:\Program Files\Intel\SUR\QUEENCREEK\x64\sqlite3.dll
    2020-05-13 18:45 - 2020-05-13 18:47 - 002080256 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files\Red Giant\Services\LIBEAY32.dll

    ==================== Alternate Data Streams (Whitelisted) ========

    ==================== Safe Mode (Whitelisted) ==================

    ==================== Association (Whitelisted) =================

    ==================== Internet Explorer trusted/restricted ==========

    (If an entry is included in the fixlist, it will be removed from the registry.)

    IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
    IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
    IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
    IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
    IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
    IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
    IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
    IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
    IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
    IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
    IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
    IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
    IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
    IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
    IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
    IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
    IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
    IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
    IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
    IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com

    There are 7942 more sites.

    IE trusted site: HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\localhost -> localhost
    IE trusted site: HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\webcompanion.com -> hxxp://webcompanion.com
    IE restricted site: HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\007guard.com -> install.007guard.com
    IE restricted site: HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\008i.com -> 008i.com
    IE restricted site: HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\008k.com -> www.008k.com
    IE restricted site: HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\00hq.com -> www.00hq.com
    IE restricted site: HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\010402.com -> 010402.com
    IE restricted site: HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
    IE restricted site: HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\0scan.com -> www.0scan.com
    IE restricted site: HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\1-2005-search.com -> www.1-2005-search.com
    IE restricted site: HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\1-domains-registrations.com -> www.1-domains-registrations.com
    IE restricted site: HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\1000gratisproben.com -> www.1000gratisproben.com
    IE restricted site: HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\1001namen.com -> www.1001namen.com
    IE restricted site: HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\100888290cs.com -> mir.100888290cs.com
    IE restricted site: HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\100sexlinks.com -> www.100sexlinks.com
    IE restricted site: HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\10sek.com -> www.10sek.com
    IE restricted site: HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\12-26.net -> user1.12-26.net
    IE restricted site: HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\12-27.net -> user1.12-27.net
    IE restricted site: HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\123fporn.info -> www.123fporn.info
    IE restricted site: HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
    IE restricted site: HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\123moviedownload.com -> www.123moviedownload.com
    IE restricted site: HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\123simsen.com -> www.123simsen.com

    There are 7942 more sites.


    ==================== Hosts content: =========================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2019-03-18 23:49 - 2020-08-02 05:43 - 000454708 _____ C:\Windows\system32\drivers\etc\hosts
    127.0.0.1 www.007guard.com
    127.0.0.1 007guard.com
    127.0.0.1 008i.com
    127.0.0.1 www.008k.com
    127.0.0.1 008k.com
    127.0.0.1 www.00hq.com
    127.0.0.1 00hq.com
    127.0.0.1 010402.com
    127.0.0.1 www.032439.com
    127.0.0.1 032439.com
    127.0.0.1 www.0scan.com
    127.0.0.1 0scan.com
    127.0.0.1 1000gratisproben.com
    127.0.0.1 www.1000gratisproben.com
    127.0.0.1 1001namen.com
    127.0.0.1 www.1001namen.com
    127.0.0.1 100888290cs.com
    127.0.0.1 www.100888290cs.com
    127.0.0.1 www.100sexlinks.com
    127.0.0.1 100sexlinks.com
    127.0.0.1 10sek.com
    127.0.0.1 www.10sek.com
    127.0.0.1 www.1-2005-search.com
    127.0.0.1 1-2005-search.com
    127.0.0.1 123fporn.info
    127.0.0.1 www.123fporn.info
    127.0.0.1 www.123haustiereundmehr.com
    127.0.0.1 123haustiereundmehr.com
    127.0.0.1 123moviedownload.com
    127.0.0.1 www.123moviedownload.com

    There are 15607 more lines.


    ==================== Other Areas ===========================

    (Currently there is no automatic fix for this section.)

    HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> %INTEL_DEV_REDIST%redist\intel64\compiler;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files (x86)\QuickTime\QTSystem\
    HKU\S-1-5-21-871970874-3256418639-2447214560-1004\Control Panel\Desktop\\Wallpaper -> C:\Users\jseym\AppData\Local\Microsoft\BingWallpaperApp\WPImages\EmbeddedImage1.jpg
    DNS Servers: 192.168.2.1
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    ==================== FirewallRules (Whitelisted) ================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [{9A4194AB-37A4-4D42-84B4-C56E7FD1B2FF}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
    FirewallRules: [{DFBB96EA-3FC4-49C5-960A-BB967BA014B4}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
    FirewallRules: [{D9262B17-427A-4636-BA58-150C71F1BFD2}] => (Allow) C:\Users\jseym\AppData\Roaming\uTorrent\uTorrent.exe => No File
    FirewallRules: [{172E7AC0-46F2-4A79-BF6A-0DC437D23241}] => (Allow) C:\Users\jseym\AppData\Roaming\uTorrent\uTorrent.exe => No File
    FirewallRules: [TCP Query User{D7ED88A2-CDAE-4C90-9667-5905FF354654}C:\program files\lbry\resources\static\daemon\lbrynet.exe] => (Allow) C:\program files\lbry\resources\static\daemon\lbrynet.exe (LBRY, Inc -> )
    FirewallRules: [UDP Query User{DE47757D-94FA-403D-8936-957D51F36F91}C:\program files\lbry\resources\static\daemon\lbrynet.exe] => (Allow) C:\program files\lbry\resources\static\daemon\lbrynet.exe (LBRY, Inc -> )
    FirewallRules: [{0D292D24-A86E-4CC4-BC0C-B25EA0EC1E3D}] => (Block) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
    FirewallRules: [{B989BBB4-B2CF-4E7D-B06E-4EC66424B7D5}] => (Block) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
    FirewallRules: [{AF540F79-0DC6-4157-8682-4D6191318690}] => (Allow) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
    FirewallRules: [{B7F2D767-DDED-4B15-835C-43EFC59D2775}] => (Allow) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
    FirewallRules: [{56031744-8581-4DD7-81CF-CE5F40884B6D}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe (Apple Inc. -> Apple Inc.)
    FirewallRules: [TCP Query User{A18A4DA0-74F8-4353-AD91-DECC907CE56D}C:\program files\adobe media encoder 2020\adobe media encoder.exe] => (Allow) C:\program files\adobe media encoder 2020\adobe media encoder.exe => No File
    FirewallRules: [UDP Query User{C56AADA7-EDA1-45B3-B845-4A6FA339A24E}C:\program files\adobe media encoder 2020\adobe media encoder.exe] => (Allow) C:\program files\adobe media encoder 2020\adobe media encoder.exe => No File
    FirewallRules: [{8B508725-9D01-4A8E-8DA1-A209E10721B2}] => (Block) C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe (Adobe Inc. -> Adobe Systems Incorporated)
    FirewallRules: [{754E92EE-6E80-464C-BAAA-AD615D6D6609}] => (Block) %ProgramFiles% (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe => No File
    FirewallRules: [{B1189649-91BA-431F-A839-7B99169C3B34}] => (Block) %ProgramFiles% (x86)\Adobe\Adobe Creative Cloud\Utils\Creative Cloud Desktop App.exe => No File
    FirewallRules: [{70C9CD6D-CDDF-45BB-90F3-14A92B4A112F}] => (Block) %ProgramFiles% (x86)\Adobe\Adobe Creative Cloud\Utils\CC Troubleshooter.exe => No File
    FirewallRules: [{9724FD93-407C-40AF-A918-6E2384D1FFFA}] => (Block) %ProgramFiles% (x86)\Adobe\Adobe Creative Cloud\Utils\CC Troubleshooter.exe => No File
    FirewallRules: [{20D35D74-BDB7-4BC2-BA1D-9CF35EFC12E4}] => (Block) %ProgramFiles% (x86)\Adobe\Adobe Creative Cloud\Utils\TQCacheCleaner.exe => No File
    FirewallRules: [{4167709C-C120-4649-BC92-747CD172F234}] => (Block) C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CoreSync.exe (Adobe Inc. -> )
    FirewallRules: [{ACC9BDCD-C401-4CBE-A38C-FA07304CC8B4}] => (Block) %ProgramFiles%\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe => No File
    FirewallRules: [{607DF8B7-ADCD-4CDB-933E-5B0E65190C0C}] => (Block) %ProgramFiles%\Adobe\Adobe Creative Cloud\ACC\Creative Cloud CustomHook.exe => No File
    FirewallRules: [{649E3203-8731-4433-9E92-38E00827F3FE}] => (Block) %ProgramFiles%\Adobe\Adobe Creative Cloud\ACC\CRLogTransport.exe => No File
    FirewallRules: [{76ADCDA4-1646-45AD-B996-F6BA4F2C77B2}] => (Block) %ProgramFiles%\Adobe\Adobe Creative Cloud\ACC\CRWindowsClientService.exe => No File
    FirewallRules: [{0FC4F5DD-2E89-4558-816E-379D52A959F0}] => (Allow) %ProgramFiles%\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe => No File
    FirewallRules: [{7E05B2D3-85FA-44A6-8588-65A62D7CA205}] => (Block) %ProgramFiles% (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe => No File
    FirewallRules: [{71FD984D-7BC8-4F2F-A50D-4458590E88A4}] => (Block) %ProgramFiles% (x86)\Adobe\Adobe Creative Cloud\Utils\Creative Cloud Desktop App.exe => No File
    FirewallRules: [{1F5C7316-003B-425A-92B5-57E63931F9B7}] => (Block) C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe (Adobe Inc. -> Adobe Systems Incorporated)
    FirewallRules: [TCP Query User{4191DF03-0C7E-459D-819F-116C7649575C}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
    FirewallRules: [UDP Query User{2C028E45-7365-455E-B50C-7A6B367DBC4E}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
    FirewallRules: [TCP Query User{5EC41BCD-767A-4257-B6B8-C98431F951E4}C:\program files\daz 3d\dazstudio4\dazstudio.exe] => (Allow) C:\program files\daz 3d\dazstudio4\dazstudio.exe (DAZ PRODUCTIONS, INC. -> Daz 3D, Inc.)
    FirewallRules: [UDP Query User{68FE6B3C-2B62-4AA7-A105-8BFD73FE3EA0}C:\program files\daz 3d\dazstudio4\dazstudio.exe] => (Allow) C:\program files\daz 3d\dazstudio4\dazstudio.exe (DAZ PRODUCTIONS, INC. -> Daz 3D, Inc.)
    FirewallRules: [{563CC3E4-91ED-4C49-ADAD-FD50FA82FC56}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
    FirewallRules: [{028A8229-F26C-42AE-9169-CC0C847895D6}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
    FirewallRules: [{A02B71AE-1F1A-4C58-9FE9-94C420041E72}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
    FirewallRules: [{080C3309-E959-45AF-BBED-BBAC9B798358}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
    FirewallRules: [{69E061BC-0D4C-44BB-BAD9-2FF049B29F7F}] => (Allow) C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.13001.20384.0_x86__8wekyb3d8bbwe\Office16\OUTLOOK.exe (Microsoft Corporation -> Microsoft Corporation)
    FirewallRules: [TCP Query User{A9E42657-40AD-46C4-A20B-B2D6DF3F5613}C:\program files (x86)\zoogvpn\ike-scan\ike-scan.exe] => (Allow) C:\program files (x86)\zoogvpn\ike-scan\ike-scan.exe () [File not signed]
    FirewallRules: [UDP Query User{0923273A-8632-4038-825C-3C0FBD184AAA}C:\program files (x86)\zoogvpn\ike-scan\ike-scan.exe] => (Allow) C:\program files (x86)\zoogvpn\ike-scan\ike-scan.exe () [File not signed]
    FirewallRules: [{D07C38C6-F7FB-4F46-AFA6-B84035995C27}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.138.558.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
    FirewallRules: [{EDDF16CB-E3A4-4FF1-9479-7B03A704E4FA}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.138.558.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
    FirewallRules: [{6D039414-10B4-4105-A0F3-34D00C0630F0}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.138.558.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
    FirewallRules: [{3DC6D5C8-0A97-4CA8-8313-F7101E1D1B0B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.138.558.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
    FirewallRules: [{520D7A7A-4779-4338-A8CC-B282DAF9DF7D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.138.558.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
    FirewallRules: [{0673D8CF-F018-4302-B864-D9649FA84887}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.138.558.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
    FirewallRules: [{DB4D4D5E-80C4-4502-97EF-ABA9899BDF43}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.138.558.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
    FirewallRules: [{A67433CC-042D-4F16-9551-322F4753FA54}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.138.558.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
    FirewallRules: [{4340656C-CA0E-4700-BDE4-CD69AC8AE85D}] => (Allow) C:\Program Files\FileZilla FTP Client\filezilla.exe (Tim Kosse -> FileZilla Project)
    FirewallRules: [{3423F8D9-2AC9-4051-BDB8-7261F23700C4}] => (Allow) C:\Program Files\FileZilla FTP Client\filezilla.exe (Tim Kosse -> FileZilla Project)
    FirewallRules: [{7DDCBFDA-5582-460A-91A7-C64B8BF06197}] => (Allow) C:\Program Files\FileZilla FTP Client\filezilla.exe (Tim Kosse -> FileZilla Project)
    FirewallRules: [{A0FA1B30-4BDC-44DA-BC4C-37CDF25232BE}] => (Allow) C:\Program Files\FileZilla FTP Client\filezilla.exe (Tim Kosse -> FileZilla Project)

    ==================== Restore Points =========================

    09-08-2020 18:13:02 Scheduled Checkpoint

    ==================== Faulty Device Manager Devices ============


    ==================== Event log errors: ========================

    Application errors:
    ==================
    Error: (08/09/2020 04:35:32 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: SDUpdate.exe, version: 2.8.68.100, time stamp: 0x5ea5e0d1
    Faulting module name: SDUpdate.exe, version: 2.8.68.100, time stamp: 0x5ea5e0d1
    Exception code: 0xc0000005
    Fault offset: 0x00005c92
    Faulting process id: 0x29f8
    Faulting application start time: 0x01d66e95016a5a61
    Faulting application path: C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
    Faulting module path: C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
    Report Id: 1f2c9d21-98b1-4a4e-a21f-4dced1b9e06b
    Faulting package full name:
    Faulting package-relative application ID:

    Error: (08/09/2020 04:01:59 PM) (Source: System Restore) (EventID: 8210) (User: )
    Description: An unspecified error occurred during System Restore: (Scheduled Checkpoint). Additional information: 0xc000003a.

    Error: (08/09/2020 03:21:16 PM) (Source: ESENT) (EventID: 455) (User: )
    Description: svchost (3184,R,98) SRUJet: Error -1811 (0xfffff8ed) occurred while opening logfile C:\Windows\system32\SRU\SRU01A29.log.

    Error: (08/09/2020 02:59:05 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: SDUpdate.exe, version: 2.8.68.100, time stamp: 0x5ea5e0d1
    Faulting module name: hhctrl.ocx_unloaded, version: 10.0.18362.1, time stamp: 0xa2f44e16
    Exception code: 0xc0000005
    Fault offset: 0x00026236
    Faulting process id: 0x21e8
    Faulting application start time: 0x01d66e85a49910a5
    Faulting application path: C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
    Faulting module path: hhctrl.ocx
    Report Id: 86d85e85-7eaa-4e74-b30d-dd6618a156ae
    Faulting package full name:
    Faulting package-relative application ID:

    Error: (08/09/2020 02:45:35 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: SDUpdate.exe, version: 2.8.68.100, time stamp: 0x5ea5e0d1
    Faulting module name: SDUpdate.exe, version: 2.8.68.100, time stamp: 0x5ea5e0d1
    Exception code: 0xc0000005
    Fault offset: 0x00005c92
    Faulting process id: 0x21e8
    Faulting application start time: 0x01d66e85a49910a5
    Faulting application path: C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
    Faulting module path: C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
    Report Id: eed07220-6efd-4c46-91b9-5797cb46c217
    Faulting package full name:
    Faulting package-relative application ID:

    Error: (08/09/2020 02:11:21 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: DESKTOP-V4HLLCM)
    Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.

    Error: (08/09/2020 02:09:43 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: glgxuq.exe, version: 2.4.3.0, time stamp: 0x5e2c52a3
    Faulting module name: ntdll.dll, version: 10.0.18362.815, time stamp: 0x2995af02
    Exception code: 0xc0000005
    Fault offset: 0x000366c1
    Faulting process id: 0x2674
    Faulting application start time: 0x01d66e80a38f373c
    Faulting application path: C:\Users\jseym\AppData\Local\glgxuq.exe
    Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
    Report Id: 9e02c09a-74cb-48cd-b5ee-2a7fcf65e39c
    Faulting package full name:
    Faulting package-relative application ID:

    Error: (08/09/2020 02:09:05 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: glgxuq.exe, version: 2.4.3.0, time stamp: 0x5e2c52a3
    Faulting module name: ntdll.dll, version: 10.0.18362.815, time stamp: 0x2995af02
    Exception code: 0xc0000005
    Fault offset: 0x000366c1
    Faulting process id: 0x246c
    Faulting application start time: 0x01d66e808cdae8d3
    Faulting application path: C:\Users\jseym\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\glgxuq.exe
    Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
    Report Id: 98b8813f-fb2f-478d-a48e-c1c1761dc0f3
    Faulting package full name:
    Faulting package-relative application ID:


    System errors:
    =============
    Error: (08/09/2020 06:47:18 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-V4HLLCM)
    Description: The server Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca did not register with DCOM within the required timeout.

    Error: (08/09/2020 05:46:50 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The AGSService service failed to start due to the following error:
    The system cannot find the file specified.

    Error: (08/09/2020 05:46:50 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The AGMService service failed to start due to the following error:
    The system cannot find the file specified.

    Error: (08/09/2020 05:17:05 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The Windows Defender Antivirus Network Inspection Service service failed to start due to the following error:
    The service did not respond to the start or control request in a timely fashion.

    Error: (08/09/2020 04:35:29 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The Spybot Security Center Integration Service service failed to start due to the following error:
    Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Error: (08/09/2020 04:35:26 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The Spybot Security Center Integration Service service failed to start due to the following error:
    Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Error: (08/09/2020 04:31:57 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-V4HLLCM)
    Description: The server Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca did not register with DCOM within the required timeout.

    Error: (08/09/2020 04:15:19 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: The Mozilla Maintenance Service service terminated with the following error:
    Incorrect function.


    Windows Defender:
    ===================================
    Date: 2020-08-09 17:57:00.555
    Description:
    Windows Defender Antivirus scan has been stopped before completion.
    Scan ID: {1F3D8156-9B9D-445C-9C2C-4EA52B0C4BC2}
    Scan Type: Antimalware
    Scan Parameters: Quick Scan

    Date: 2020-08-09 15:31:25.153
    Description:
    Windows Defender Antivirus scan has been stopped before completion.
    Scan ID: {17BC7C8F-8BE8-4D85-BA03-B2FD0B33B28F}
    Scan Type: Antimalware
    Scan Parameters: Quick Scan

    Date: 2020-08-02 04:09:13.243
    Description:
    Windows Defender Antivirus has detected malware or other potentially unwanted software.
    For more information please see the following:
    https://go.microsoft.com/fwlink/?lin...0&enterprise=0
    Name: Trojan:Win32/Occamy.C
    ID: 2147726780
    Severity: Severe
    Category: Trojan
    Path: file:_C:\Users\jseym\Downloads\Red Giant Trapcode Suite 15.1.4 (x64) + Key {B4tman}\Red Giant Trapcode Suite 15.1.4 (x64) (Win 10) {B4tman}\Red Giant Trapcode Suite 15.1.4 (x64) (Win 10) {B4tman}\TCSuite_Win_Full_15.1.4\patch.exe
    Detection Origin: Local machine
    Detection Type: FastPath
    Detection Source: Real-Time Protection
    Process Name: C:\Windows\SysWOW64\cmd.exe
    Security intelligence Version: AV: 1.321.379.0, AS: 1.321.379.0, NIS: 1.321.379.0
    Engine Version: AM: 1.1.17300.4, NIS: 1.1.17300.4

    Date: 2020-08-02 04:07:38.796
    Description:
    Windows Defender Antivirus has detected malware or other potentially unwanted software.
    For more information please see the following:
    https://go.microsoft.com/fwlink/?lin...2&enterprise=0
    Name: Trojan:Win32/Skeeyah.A!rfn
    ID: 2147694182
    Severity: Severe
    Category: Trojan
    Path: file:_C:\Users\jseym\Downloads\Red Giant Trapcode Suite 15.1.4 (x64) + Key {B4tman}\Red Giant Trapcode Suite 15.1.4 (x64) (Win 10) {B4tman}\Red Giant Trapcode Suite 15.1.4 (x64) (Win 10) {B4tman}\TCSuite_Win_Full_15.1.4\patch.exe
    Detection Origin: Local machine
    Detection Type: Concrete
    Detection Source: Real-Time Protection
    Process Name: C:\Users\jseym\Downloads\Red Giant Trapcode Suite 15.1.4 (x64) + Key {B4tman}\Red Giant Trapcode Suite 15.1.4 (x64) (Win 10) {B4tman}\Red Giant Trapcode Suite 15.1.4 (x64) (Win 10) {B4tman}\TCSuite_Win_Full_15.1.4\Trapcode Suite 15.1.4 Installer.exe
    Security intelligence Version: AV: 1.321.379.0, AS: 1.321.379.0, NIS: 1.321.379.0
    Engine Version: AM: 1.1.17300.4, NIS: 1.1.17300.4

    Date: 2020-08-02 04:06:46.555
    Description:
    Windows Defender Antivirus has detected malware or other potentially unwanted software.
    For more information please see the following:
    https://go.microsoft.com/fwlink/?lin...0&enterprise=0
    Name: Trojan:Win32/Execution!rfn
    ID: 2147745900
    Severity: Severe
    Category: Trojan
    Path: file:_C:\Users\jseym\Downloads\Red Giant Trapcode Suite 15.1.4 (x64) + Key {B4tman}\Red Giant Trapcode Suite 15.1.4 (x64) (Win 10) {B4tman}\Red Giant Trapcode Suite 15.1.4 (x64) (Win 10) {B4tman}\TCSuite_Win_Full_15.1.4\Trapcode Suite 15.1.4 Installer.exe
    Detection Origin: Local machine
    Detection Type: Concrete
    Detection Source: Real-Time Protection
    Process Name: C:\Windows\explorer.exe
    Security intelligence Version: AV: 1.321.379.0, AS: 1.321.379.0, NIS: 1.321.379.0
    Engine Version: AM: 1.1.17300.4, NIS: 1.1.17300.4

    Date: 2020-08-09 17:57:08.909
    Description:
    Windows Defender Antivirus has encountered an error trying to update security intelligence.
    New security intelligence Version:
    Previous security intelligence Version: 1.321.948.0
    Update Source: Microsoft Update Server
    Security intelligence Type: AntiVirus
    Update Type: Full
    Current Engine Version:
    Previous Engine Version: 1.1.17300.4
    Error code: 0x80240438
    Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

    Date: 2020-08-09 17:46:56.493
    Description:
    Windows Defender Antivirus has encountered an error trying to load security intelligence and will attempt reverting back to a known-good version.
    Security intelligence Attempted: Current
    Error Code: 0x80070003
    Error description: The system cannot find the path specified.
    Security intelligence version: 0.0.0.0;0.0.0.0
    Engine version: 0.0.0.0

    Date: 2020-08-09 15:31:33.175
    Description:
    Windows Defender Antivirus has encountered an error trying to update security intelligence.
    New security intelligence Version:
    Previous security intelligence Version: 1.321.948.0
    Update Source: Microsoft Update Server
    Security intelligence Type: AntiVirus
    Update Type: Full
    Current Engine Version:
    Previous Engine Version: 1.1.17300.4
    Error code: 0x80240438
    Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

    Date: 2020-08-09 15:21:20.406
    Description:
    Windows Defender Antivirus has encountered an error trying to load security intelligence and will attempt reverting back to a known-good version.
    Security intelligence Attempted: Current
    Error Code: 0x80070003
    Error description: The system cannot find the path specified.
    Security intelligence version: 0.0.0.0;0.0.0.0
    Engine version: 0.0.0.0

    Date: 2020-08-08 18:54:35.228
    Description:
    Windows Defender Antivirus has encountered an error trying to update security intelligence.
    New security intelligence Version:
    Previous security intelligence Version: 1.321.948.0
    Update Source: Microsoft Update Server
    Security intelligence Type: AntiVirus
    Update Type: Full
    Current Engine Version:
    Previous Engine Version: 1.1.17300.4
    Error code: 0x8024402c
    Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.

    CodeIntegrity:
    ===================================

    Date: 2020-08-09 16:35:29.805
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2020-08-09 16:35:26.260
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2020-08-09 14:45:31.615
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2020-08-09 14:45:28.225
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2020-08-02 05:11:59.902
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2020-08-02 05:11:57.896
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2020-06-08 00:39:28.758
    Description:
    Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\spoolsv.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\spool\drivers\x64\3\ADUIGP.DLL that did not meet the Unchecked signing level requirements.

    Date: 2020-06-07 23:01:18.923
    Description:
    Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\spoolsv.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\AdobePDF.dll that did not meet the Unchecked signing level requirements.

    ==================== Memory info ===========================

    BIOS: LENOVO 9SKT57AUS 12/11/2012
    Motherboard: LENOVO MAHOBAY
    Processor: Intel(R) Core(TM) i5-3470 CPU @ 3.20GHz
    Percentage of memory in use: 27%
    Total physical RAM: 16172.47 MB
    Available physical RAM: 11680.44 MB
    Total Virtual: 18604.47 MB
    Available Virtual: 14276.92 MB

    ==================== Drives ================================

    Drive c: (Windows) (Fixed) (Total:475.86 GB) (Free:277 GB) NTFS
    Drive d: (New Volume) (Fixed) (Total:1863.01 GB) (Free:1502.06 GB) NTFS

    \\?\Volume{025d21ad-0000-0000-0000-100000000000}\ (System) (Fixed) (Total:0.34 GB) (Free:0.31 GB) NTFS
    \\?\Volume{025d21ad-0000-0000-0050-310d77000000}\ (Recovery image) (Fixed) (Total:0.73 GB) (Free:0.31 GB) NTFS

    ==================== MBR & Partition Table ====================

    ==========================================================
    Disk: 0 (MBR Code: Windows 7/8/10) (Size: 476.9 GB) (Disk ID: 025D21AD)
    Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=475.9 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=750 MB) - (Type=27)

    ==========================================================
    Disk: 1 (MBR Code: Windows 7/8/10) (Size: 1863 GB) (Disk ID: 2A239D93)
    Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)

    ==================== End of Addition.txt =======================


    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 09-08-2020
    Ran by jseym (administrator) on DESKTOP-V4HLLCM (LENOVO 3302F1U) (09-08-2020 19:05:01)
    Running from C:\Users\jseym\Downloads
    Loaded Profiles: jseym
    Platform: Windows 10 Pro Version 1909 18363.959 (X64) Language: English (United States)
    Default browser: Edge
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Adobe Inc. -> Adobe Inc) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe
    (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe
    (Apple Inc. -> Apple Inc.) C:\Program Files (x86)\QuickTime\QuickTimePlayer.exe
    (IDSA Production signing key -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe
    (IDSA Production signing key -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe
    (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
    (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
    (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
    (Intel(R) Software Development Products -> ) C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe
    (Intel(R) Software Development Products -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe
    (Microsoft Corporation -> Microsoft Corporation) C:\Users\jseym\AppData\Local\Temp\InstallUtil.exe
    (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
    (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2005.23.0_x64__8wekyb3d8bbwe\Calculator.exe
    (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12007.1001.2.0_x64__8wekyb3d8bbwe\WinStore.App.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
    (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2007.8-0\MsMpEng.exe
    (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2007.8-0\NisSrv.exe
    (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <10>
    (Node.js Foundation -> Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\libs\node.exe
    (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    (Red Giant LLC -> Red Giant LLC) C:\Program Files\Red Giant\Services\Red Giant Service.exe

    ==================== Registry (Whitelisted) ===================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [Unattend0000000001{15A3A1EB-3696-4573-ACE7-3A352B79D405}] => C:\Windows\system32\devmgmt.msc [145622 2019-03-18] (Microsoft Windows -> )
    HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc. -> Apple Inc.)
    HKLM-x32\...\Run: [Intel Driver & Support Assistant] => C:\Program Files (x86)\Intel\Driver and Support Assistant\DSATray.exe [236392 2020-07-09] (IDSA Production signing key -> Intel)
    HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\Run: [CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [144008 2019-10-22] (Adobe Inc. -> Adobe Systems Incorporated)
    HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\Run: [BingWallpaperApp] => C:\Users\jseym\AppData\Local\Microsoft\BingWallpaperApp\BingWallpaperApp.exe [2759032 2020-06-05] (Microsoft Corporation -> Microsoft Corporation)
    HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\Run: [LBRY] => C:\Program Files\LBRY\LBRY.exe [94038840 2020-07-23] (LBRY, Inc -> LBRY Inc.)
    HKU\S-1-5-21-871970874-3256418639-2447214560-1004\...\Run: [Llscs] => C:\Users\jseym\AppData\Roaming\dllsha.exe [200192 2020-08-02] (H$a8qZ9|6&NbzD4*) [File not signed]
    BootExecute: autocheck autochk * sdnclean64.exe

    ==================== Scheduled Tasks (Whitelisted) ============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {12A02D8D-0063-41A7-848D-0C344F6D7A22} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.8-0\MpCmdRun.exe [516776 2020-08-04] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {346C02FC-3387-4911-8518-2BA0410A6C58} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe
    Task: {34E6AADE-F756-41C3-A8E3-86B93E764E7F} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [3087184 2020-03-10] (Intel(R) Software Development Products -> Intel Corporation)
    Task: {3F326A1B-ECAD-4843-824F-3BE4B7BF8A39} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16408320 2015-12-18] (Realtek Semiconductor Corp -> Realtek Semiconductor)
    Task: {59AE585F-069F-4531-836E-E4730D211956} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [563000 2015-08-27] (Apple Inc. -> Apple Inc.)
    Task: {657AB868-8072-4FC8-8B84-A4A1B73F5203} - System32\Tasks\RtHDVBg_LENOVO_MICPKEY => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2015-12-18] (Realtek Semiconductor Corp -> Realtek Semiconductor)
    Task: {66FC4DF8-75BA-4D33-84C3-7CB64D9A5161} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.8-0\MpCmdRun.exe [516776 2020-08-04] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {8934F1CB-1858-4F8B-82AC-FAA7E2660794} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.8-0\MpCmdRun.exe [516776 2020-08-04] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {B661171E-78E9-45C9-B2DF-471024657433} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [123600 2020-07-29] (Mozilla Corporation -> Mozilla Foundation)
    Task: {BD3F409C-D89E-41FA-97B4-9C89662F7FE4} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.8-0\MpCmdRun.exe [516776 2020-08-04] (Microsoft Windows Publisher -> Microsoft Corporation)
    Task: {CFF297AE-1D3D-4160-9B81-4057F48A8782} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => "C:\Windows\System32\Wscript.exe" //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"
    Task: {F2004AA5-EBD0-42BB-99B7-3C14E14ECF5B} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [3087184 2020-03-10] (Intel(R) Software Development Products -> Intel Corporation)
    Task: {F85CA6E8-62FE-45E2-9157-0DFAA6EA2898} - System32\Tasks\Red Giant Link => C:\Program [Argument = Files (x86)\Red Giant Link\Red Giant Link.exe]
    Task: {FE78B23E-54CA-4DD0-984F-D692E228522D} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
    Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
    Tcpip\..\Interfaces\{16ea75fc-585d-492a-aab4-e91f59e2c07d}: [DhcpNameServer] 192.168.2.1
    Tcpip\..\Interfaces\{ed2b5ddf-5cce-4285-a77f-ace87df4d112}: [DhcpNameServer] 8.8.8.8 8.8.4.4

    Internet Explorer:
    ==================
    HKU\S-1-5-21-871970874-3256418639-2447214560-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/?pc=COS2&ptag=D051220-A915F698E57&form=CONMHP&conlogo=CT3335818
    SearchScopes: HKU\S-1-5-21-871970874-3256418639-2447214560-1004 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?pc=COS2&ptag=D051220-N0700A915F698E57&form=CONBDF&conlogo=CT3335818&q={searchTerms}
    BHO: IEToEdge BHO -> {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} -> C:\Program Files (x86)\Microsoft\Edge\Application\84.0.522.52\BHO\ie_to_edge_bho_64.dll [2020-08-01] (Microsoft Corporation -> Microsoft Corporation)
    BHO-x32: IEToEdge BHO -> {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} -> C:\Program Files (x86)\Microsoft\Edge\Application\84.0.522.52\BHO\ie_to_edge_bho.dll [2020-08-01] (Microsoft Corporation -> Microsoft Corporation)

    Edge:
    ======
    Edge Profile: C:\Users\jseym\AppData\Local\Microsoft\Edge\User Data\Default [2020-08-09]

    FireFox:
    ========
    FF DefaultProfile: ezc0qb7c.default
    FF ProfilePath: C:\Users\jseym\AppData\Roaming\Mozilla\Firefox\Profiles\ezc0qb7c.default [2020-08-09]
    FF NewTab: Mozilla\Firefox\Profiles\ezc0qb7c.default -> hxxps://defaultsearch.co/homepage?hp=1&pId=BT170603&iDate=2020-05-12 08:24:24&bName=&bitmask=0600
    FF ProfilePath: C:\Users\jseym\AppData\Roaming\Mozilla\Firefox\Profiles\6x38r1q0.default-release [2020-08-09]
    FF Homepage: Mozilla\Firefox\Profiles\6x38r1q0.default-release -> www.google.com
    FF NewTab: Mozilla\Firefox\Profiles\6x38r1q0.default-release -> hxxps://defaultsearch.co/homepage?hp=1&pId=BT170603&iDate=2020-05-12 08:24:24&bName=&bitmask=0600
    FF Extension: (No Name) - C:\Users\jseym\AppData\Roaming\Mozilla\Firefox\Profiles\6x38r1q0.default-release\Extensions\@hoxx-vpn.xpi.id[244EA16D-2275].[helprecover@foxmail.com].help [2020-08-09] [not signed]
    FF Extension: (No Name) - C:\Users\jseym\AppData\Roaming\Mozilla\Firefox\Profiles\6x38r1q0.default-release\Extensions\ffext_basicvideoext@startpage24.xpi.id[244EA16D-2275].[helprecover@foxmail.com].help [2020-08-09] [not signed]
    FF Extension: (No Name) - C:\Users\jseym\AppData\Roaming\Mozilla\Firefox\Profiles\6x38r1q0.default-release\Extensions\{667ef836-c20c-4a01-bfa4-af9b3e17299b}.xpi.id[244EA16D-2275].[helprecover@foxmail.com].help [2020-08-09] [not signed]
    FF Extension: (No Name) - C:\Users\jseym\AppData\Roaming\Mozilla\Firefox\Profiles\6x38r1q0.default-release\Extensions\{adeadebb-fedc-4180-a7f4-cfdd87496551}.xpi.id[244EA16D-2275].[helprecover@foxmail.com].help [2020-08-09] [not signed]
    FF Extension: (No Name) - C:\Users\jseym\AppData\Roaming\Mozilla\Firefox\Profiles\6x38r1q0.default-release\Extensions\{f73df109-8fb4-453e-8373-f59e61ca4da3}.xpi.id[244EA16D-2275].[helprecover@foxmail.com].help [2020-08-09] [not signed]
    FF Plugin-x32: @videolan.org/vlc,version=3.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)

    ==================== Services (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 Red Giant Service; C:\Program Files\Red Giant\Services\Red Giant Service.exe [5950024 2020-05-13] (Red Giant LLC -> Red Giant LLC)
    S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5930136 2020-05-12] (Microsoft Windows Publisher -> Microsoft Corporation)
    R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.8-0\NisSrv.exe [2169568 2020-08-04] (Microsoft Windows Publisher -> Microsoft Corporation)
    R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2007.8-0\MsMpEng.exe [128376 2020-08-04] (Microsoft Windows Publisher -> Microsoft Corporation)
    S2 AGMService; "C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe" [X]
    S2 AGSService; "C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe" [X]

    ===================== Drivers (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S3 AgereSoftModem; C:\Windows\system32\DRIVERS\agrsm64.sys [1146880 2019-03-18] (Microsoft Windows -> LSI Corp)
    R3 atmeltpm; C:\Windows\System32\drivers\atmeltpm64.sys [19456 2011-08-05] (Microsoft Windows Hardware Compatibility Publisher -> Atmel, Inc.)
    S3 bcmsmbsp; C:\Windows\System32\drivers\bcmsmbsp.sys [53024 2015-07-10] (Broadcom Corporation -> Broadcom Corporation.)
    S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [231936 2019-10-06] (Microsoft Corporation) [File not signed]
    S3 ETDSMBus; C:\Windows\System32\drivers\ETDSMBus.sys [30808 2015-12-17] (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronic Corp.)
    R3 int0800; C:\Windows\System32\drivers\flashud.sys [51712 2009-09-09] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
    R3 LBAI; C:\Windows\System32\Drivers\LBAI.sys [30432 2017-04-29] (Lenovo -> Lenovo)
    R3 netr28ux; C:\Windows\System32\drivers\netr28ux.sys [2224128 2019-03-18] (Microsoft Windows -> MediaTek Inc.)
    S3 NETwNe64; C:\Windows\System32\drivers\NETwew01.sys [3343872 2019-03-18] (Microsoft Windows -> Intel Corporation)
    R3 tap0901; C:\Windows\System32\drivers\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
    S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [78216 2020-08-04] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
    R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [430320 2020-08-04] (Microsoft Windows -> Microsoft Corporation)
    R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [98520 2020-08-04] (Microsoft Windows -> Microsoft Corporation)

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One month (created) ===================

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2020-08-09 19:01 - 2020-08-09 19:04 - 005198336 _____ (AVAST Software) C:\Users\jseym\Downloads\aswMBR.exe
    2020-08-09 18:56 - 2020-08-09 18:57 - 000051328 _____ C:\Users\jseym\Desktop\Addition.txt
    2020-08-09 18:55 - 2020-08-09 19:05 - 000014830 _____ C:\Users\jseym\Downloads\FRST.txt
    2020-08-09 18:55 - 2020-08-09 18:57 - 000111594 _____ C:\Users\jseym\Desktop\FRST.txt
    2020-08-09 18:52 - 2020-08-09 19:05 - 000000000 ____D C:\FRST
    2020-08-09 18:50 - 2020-08-09 18:50 - 002296320 _____ (Farbar) C:\Users\jseym\Downloads\FRST64.exe
    2020-08-09 16:41 - 2020-08-09 16:41 - 000000000 ____D C:\Users\jseym\AppData\Local\mbam
    2020-08-09 16:40 - 2020-08-09 16:40 - 000000000 ____D C:\ProgramData\Malwarebytes
    2020-08-09 16:39 - 2020-08-09 16:39 - 000000000 ____D C:\Program Files\Malwarebytes
    2020-08-09 14:52 - 2020-08-09 14:52 - 000000000 ___HD C:\$SysReset
    2020-08-09 14:45 - 2020-08-09 17:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
    2020-08-09 14:45 - 2020-08-09 16:46 - 000000000 ____D C:\Safer-Networking Ltd
    2020-08-09 14:45 - 2020-08-09 15:17 - 000000000 ____D C:\Users\jseym\AppData\Roaming\Waterfox
    2020-08-09 14:45 - 2020-08-09 14:45 - 000000000 ____D C:\Users\jseym\AppData\Local\Waterfox
    2020-08-09 14:45 - 2020-08-09 14:45 - 000000000 ____D C:\ProgramData\Waterfox
    2020-08-09 14:34 - 2020-08-09 14:34 - 000001478 _____ C:\Users\jseym\Desktop\info.txt
    2020-08-09 14:22 - 2020-08-09 14:22 - 000823538 _____ C:\Users\Public\xdg.exe.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:22 - 2020-08-09 14:22 - 000823538 _____ C:\Users\Public\uwa.exe.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:22 - 2020-08-09 14:22 - 000823538 _____ C:\Users\Public\rdn.exe.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:22 - 2020-08-09 14:22 - 000823538 _____ C:\Users\Public\mlx.exe.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:22 - 2020-08-09 14:22 - 000823538 _____ C:\Users\Public\ldz.exe.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:22 - 2020-08-09 14:22 - 000823538 _____ C:\Users\Public\fxc.exe.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:22 - 2020-08-09 14:22 - 000000418 ___SH C:\Users\Public\Downloads\desktop.ini.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:17 - 2020-08-09 14:17 - 000000530 ___SH C:\Users\Public\Documents\desktop.ini.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:17 - 2020-08-09 14:17 - 000000530 ___SH C:\ProgramData\Documents\desktop.ini.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:17 - 2020-08-09 14:17 - 000000418 ___SH C:\Users\Public\desktop.ini.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:17 - 2020-08-09 14:17 - 000000274 ___SH C:\Users\jseym\ntuser.ini.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 001099090 _____ C:\Users\jseym\Downloads\Hd Drops Dripping Down The Glass Stock Video - Download Video Clip Now - iStock.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 001007154 _____ C:\Users\jseym\Downloads\jungle-601542_1920.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000606626 _____ C:\Users\jseym\Downloads\loading screen free download - DASH_V.webm.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000491538 _____ C:\Users\jseym\Downloads\Haywood County Schools - Framework and Protocol for Re-Opening - 2020-2021-2-1.pdf.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000487522 _____ C:\Users\jseym\Downloads\kisspng-smartphone-feature-phone-mobile-phone-vector-blue-overlooking-smartphone-5a83d097ba45a6.773556601518588055763.png.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000464658 _____ C:\Users\jseym\Downloads\kisspng-sony-xperia-z3-sony-xperia-t-sony-xperia-m-sony-xp-phone-prototype-5a9d81c6960475.8869652515202718146145.png.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000354898 _____ C:\Users\jseym\Downloads\kisspng-smartphone-mobile-phones-telephone-5af29a9e6fb496.5137883115258487344576.png.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000219362 _____ C:\Users\jseym\Downloads\tech-rings.png.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000217874 _____ C:\Users\jseym\Downloads\puerto_madero_at_night_20___wet_street_by_maxi_exequiel-d5lmge0.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000192706 _____ C:\Users\jseym\Downloads\Blank Links.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000174690 _____ C:\Users\jseym\Downloads\France_Night_City_Roads_HDR_wet_rain_lights_sky_clouds_roads-2560X1600-915x515.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000116866 _____ C:\Users\jseym\Downloads\wet_leaf_by_wuestenbrand-d6ivd2a.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000080914 _____ C:\Users\jseym\Downloads\circle002png.png.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000075954 _____ C:\Users\jseym\Downloads\EeDUz5QXkAsgV-2.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000074946 _____ C:\Users\jseym\Downloads\kisspng-nexus-6p-google-nexus-smartphone-oncallers-cell-phone-repair-computer-services-5b52a047ae03b6.4705107915321416397128.png.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000071250 _____ C:\Users\jseym\Downloads\Product fufillment email.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000051090 _____ C:\Users\jseym\Downloads\landscape-1454360218-barndo.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000042098 _____ C:\Users\jseym\Downloads\kisspng-smartphone-feature-phone-sony-xperia-tipo-iphone-mobile-phone-vector-5a80e6827f88e5.1130330015183970585224.png.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000041218 _____ C:\Users\jseym\Downloads\kisspng-iphone-7-plus-ipad-3-car-audi-a3-phone-template-5aae63debc3189.6586718815213782707709.png.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000016706 _____ C:\Users\jseym\Downloads\Donate_Button.png.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000011378 _____ C:\Users\jseym\Downloads\circle003 black.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000007602 _____ C:\Users\jseym\Downloads\loading screen free download - DASH_A.webm.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000001010 _____ C:\Users\jseym\Downloads\Desktop - Shortcut.lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000000530 ___SH C:\Users\jseym\Downloads\desktop.ini.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:16 - 2020-08-09 14:16 - 000000354 _____ C:\Users\jseym\Downloads\credit.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000287666 _____ C:\Users\jseym\Downloads\8c38ce171e6f98a184153e8f8a6c9b30.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000023330 _____ C:\Users\jseym\Downloads\744px-Black-android-phone.svg.png.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000007602 _____ C:\Users\jseym\Downloads\3-2-paypal-donate-button-png-image-thumb.png.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000004354 _____ C:\Users\jseym\Documents\Tutorial Script.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000003106 _____ C:\Users\jseym\Documents\new script.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000000738 _____ C:\Users\jseym\Documents\Liberty line-up Aug 8th 2020.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000000706 _____ C:\Users\jseym\Documents\Tutorial Script new order for command.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000000658 ___SH C:\Users\jseym\Documents\desktop.ini.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000000626 _____ C:\Users\jseym\Documents\LBRY 02 & 03 logo giphy.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000000498 _____ C:\Users\jseym\Documents\Possible warnings for Adult SFX.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000000498 _____ C:\Users\jseym\Documents\Media Browser Provider Exception.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000000466 _____ C:\Users\jseym\Documents\delete temp w instruction.txt
    2020-08-09 14:15 - 2020-08-09 14:15 - 000000434 _____ C:\Users\jseym\Documents\SharedView Column Settings.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000000434 _____ C:\Users\jseym\Documents\Recent Directories.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000000322 _____ C:\Users\jseym\Documents\liberty changes.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000000274 _____ C:\Users\jseym\Documents\FileZilla.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:15 - 2020-08-09 14:15 - 000000274 _____ C:\Users\jseym\Documents\delete temp.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000005506 _____ C:\Users\jseym\Desktop\long story.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000002274 _____ C:\Users\jseym\Desktop\DAZ Install Manager (64-bit).lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000002258 _____ C:\Users\jseym\Desktop\DazCentral (64-bit).lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000002194 _____ C:\Users\jseym\Desktop\FileZilla Client.lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000002034 _____ C:\Users\jseym\Desktop\Audacity - Audio Editor and Recorder.lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000001442 _____ C:\Users\jseym\Desktop\DAZ Studio 4.12 (64-bit).lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000001426 _____ C:\Users\jseym\Desktop\Hexagon 2.5.lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000001426 _____ C:\Users\jseym\Desktop\Adobe Media Encoder 2020.lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000001378 _____ C:\Users\jseym\Documents\Benefit show.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000001346 _____ C:\Users\jseym\Desktop\Adobe Photoshop 2020.lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000001122 _____ C:\Users\jseym\Desktop\HandBrake.lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000001042 _____ C:\Users\jseym\Desktop\Documents - Shortcut.lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000000706 _____ C:\Users\jseym\Desktop\New Volume (D).lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000000530 ___SH C:\Users\jseym\Desktop\desktop.ini.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000000482 _____ C:\Users\jseym\Desktop\Call Landon.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000000386 _____ C:\Users\jseym\Desktop\Website important stats.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000000338 _____ C:\Users\jseym\Desktop\wrong length lower thirds redo.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-08-09 14:05 - 000000306 _____ C:\Users\jseym\Documents\att account number.txt.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:04 - 2020-08-09 14:04 - 000200450 _____ C:\Users\jseym\AppData\Roaming\dllsha.exe.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:04 - 2020-08-09 14:04 - 000002626 _____ C:\Users\jseym\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:04 - 2020-08-09 14:04 - 000001138 _____ C:\Users\jseym\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:04 - 2020-08-09 14:04 - 000000706 _____ C:\Users\jseym\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\New Volume (D).lnk.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:04 - 2020-08-09 14:04 - 000000514 ___SH C:\Users\jseym\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:04 - 2020-08-09 14:04 - 000000418 ___SH C:\Users\jseym\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:03 - 2020-08-09 14:03 - 000352402 _____ C:\Users\jseym\AppData\Roaming\CodecsLE_Install.log.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 04:52 - 2020-08-09 04:52 - 000000658 _____ C:\Users\jseym\AppData\Local\oobelibMkey.log.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 04:49 - 2020-08-09 04:49 - 001035058 _____ C:\Users\jseym\AppData\Local\Ikslsec.exe.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 04:49 - 2020-08-09 04:49 - 000000402 _____ C:\Users\jseym\AppData\Local\Iksl.url.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 04:44 - 2020-08-09 04:44 - 000260802 ____H C:\Users\jseym\AppData\Local\IconCache.db.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-07 23:17 - 2020-08-09 14:05 - 126215202 _____ C:\Users\jseym\Desktop\FireExplosion01.mov
    2020-08-07 23:17 - 2020-08-09 14:05 - 044930191 _____ C:\Users\jseym\Desktop\FireExplosion02.mov.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-07 01:26 - 2020-08-09 14:16 - 023330707 _____ C:\Users\jseym\Downloads\Trapcode Particular 2.zip.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-05 21:04 - 2020-08-09 14:05 - 039059569 _____ C:\Users\jseym\Desktop\Lava Flow GS 1080.m4v
    2020-08-03 16:16 - 2020-08-09 14:05 - 021630573 _____ C:\Users\jseym\Desktop\Blood Drip Run on Glass original.wmv
    2020-08-03 15:20 - 2020-08-03 15:20 - 000000085 _____ C:\Windows\wininit.ini
    2020-08-03 05:29 - 2020-08-09 14:16 - 1127828789 _____ C:\Users\jseym\Downloads\ALIVE 2020 HDRip 720p H264 Mkvking.mkv.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-02 05:43 - 2019-03-18 23:49 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts.20200802-054355.backup
    2020-08-02 05:16 - 2020-08-02 05:16 - 000000000 ____D C:\Users\jseym\AppData\Local\Safer-Networking Ltd
    2020-08-02 05:11 - 2020-08-09 17:37 - 000000000 ____D C:\ProgramData\Spybot - Search & Destroy
    2020-08-02 05:11 - 2020-08-09 17:37 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
    2020-08-02 04:30 - 2020-08-02 04:53 - 069300040 _____ (Safer-Networking Ltd. ) C:\Users\jseym\Downloads\spybotsd-2.8.68.0.exe
    2020-08-02 04:23 - 2020-08-02 04:23 - 000823296 _____ C:\Users\Public\rdn.exe
    2020-08-02 04:23 - 2020-08-02 04:23 - 000823296 _____ C:\Users\Public\mlx.exe
    2020-08-02 04:22 - 2020-08-02 04:22 - 000823296 _____ C:\Users\Public\uwa.exe
    2020-08-02 04:18 - 2020-08-02 04:18 - 000823296 _____ C:\Users\Public\ldz.exe
    2020-08-02 04:13 - 2020-08-02 04:13 - 000000000 ____D C:\Windows\Finex
    2020-08-02 04:13 - 2020-08-02 04:12 - 000200192 _____ (H$a8qZ9/6&NbzD4*) C:\Users\jseym\AppData\Roaming\dllsha.exe
    2020-08-02 04:12 - 2020-08-02 04:12 - 001034806 _____ C:\Users\jseym\AppData\Local\Ikslsec.exe
    2020-08-02 04:12 - 2020-08-02 04:12 - 000823296 _____ C:\Users\Public\fxc.exe
    2020-08-02 04:11 - 2020-08-09 17:37 - 000000000 ____D C:\Users\jseym\AppData\LocalLow\3098htrhpen8ifg0
    2020-08-02 04:11 - 2020-08-02 04:11 - 000823296 _____ C:\Users\Public\xdg.exe
    2020-08-02 04:08 - 2020-08-02 04:20 - 000403768 _____ (Intel Corporation) C:\Windows\system32\tbb.dll
    2020-08-02 04:08 - 2020-08-02 04:20 - 000234808 _____ (Intel Corporation) C:\Windows\system32\tbbmalloc.dll
    2020-08-01 03:41 - 2020-08-09 14:16 - 000000000 ____D C:\Users\jseym\Downloads\oiwa
    2020-07-30 15:01 - 2020-08-09 17:45 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
    2020-07-29 16:43 - 2020-08-09 17:37 - 000000000 ____D C:\Program Files\Mozilla Firefox
    2020-07-29 01:31 - 2020-08-09 14:16 - 005396816 _____ C:\Users\jseym\Downloads\Rollin.mp3.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-29 01:29 - 2020-08-09 14:16 - 005124130 _____ C:\Users\jseym\Downloads\Mint_Chocolate_2a.mp3.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-29 01:28 - 2020-08-09 14:16 - 005381143 _____ C:\Users\jseym\Downloads\Flexxx.mp3.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-29 01:27 - 2020-08-09 14:16 - 004700946 _____ C:\Users\jseym\Downloads\Yellow_Rose_of_Berkeley.mp3.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-28 17:23 - 2020-07-28 17:23 - 000000000 ____D C:\Program Files\LBRY
    2020-07-28 05:06 - 2020-08-09 14:16 - 004192169 _____ C:\Users\jseym\Downloads\Wageningen's_Hoogstraat_after_spring_rain.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-28 05:02 - 2020-08-09 14:15 - 005159223 _____ C:\Users\jseym\Downloads\5417452809_e4ddfa3507_o.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-27 01:10 - 2020-08-09 14:16 - 002419899 _____ C:\Users\jseym\Downloads\city-1595830222804-339.jpg.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 23:37 - 2020-08-09 14:16 - 043254829 _____ C:\Users\jseym\Downloads\Waterfall Relaxing_Guru pixabay.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 23:35 - 2020-08-09 14:16 - 051815945 _____ C:\Users\jseym\Downloads\Videvo02.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 23:33 - 2020-08-09 14:16 - 309294980 _____ C:\Users\jseym\Downloads\videzzy2.mov.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 23:32 - 2020-08-09 14:16 - 290431860 _____ C:\Users\jseym\Downloads\Videzzy.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 23:25 - 2020-08-09 14:16 - 054892548 _____ C:\Users\jseym\Downloads\Videvo 1.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 23:15 - 2020-08-09 14:16 - 009994835 _____ C:\Users\jseym\Downloads\Videvo.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 21:22 - 2020-08-09 14:16 - 041281178 _____ C:\Users\jseym\Downloads\Rain - 44791.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 19:57 - 2020-08-09 14:16 - 021456843 _____ C:\Users\jseym\Downloads\Rainy Day - 5275.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 19:49 - 2020-08-09 14:16 - 067627255 _____ C:\Users\jseym\Downloads\mixkit-times-square-during-a-rainy-night-4332.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 19:45 - 2020-08-09 14:16 - 006989111 _____ C:\Users\jseym\Downloads\mixkit-thunderstorm-in-the-city-night-7239-medium.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 14:58 - 2020-08-09 14:15 - 000000000 ____D C:\Users\jseym\Downloads\AEdownload
    2020-07-24 06:00 - 2020-08-09 14:16 - 015110400 _____ C:\Users\jseym\Downloads\AEdownload.com-19242729-rain2.rar.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 05:42 - 2020-08-09 14:16 - 015110400 _____ C:\Users\jseym\Downloads\AEdownload.com-19242729-rain.rar.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 04:56 - 2020-08-09 14:16 - 006462955 _____ C:\Users\jseym\Downloads\Water Drop Heavy Rain On Window Stock Video - Download Video Clip Now - iStock.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-24 04:47 - 2020-07-24 04:47 - 000000747 _____ C:\Users\jseym\Downloads\Desktop - Shortcut.lnk
    2020-07-23 21:46 - 2020-08-09 14:16 - 022161852 _____ C:\Users\jseym\Downloads\London - 27028.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-23 21:42 - 2020-08-09 14:16 - 032393493 _____ C:\Users\jseym\Downloads\Water - 19799.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-23 21:06 - 2020-08-09 14:16 - 029882358 _____ C:\Users\jseym\Downloads\mixkit-busy-avenue-in-las-vegas-4251.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-23 20:41 - 2020-08-09 14:16 - 1037927686 _____ C:\Users\jseym\Downloads\Techno_0003.mov.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-23 20:31 - 2020-08-09 14:16 - 002989116 _____ C:\Users\jseym\Downloads\Hud Element Futuristic Loading Pending Screen Loopable Parts Alpha Mask Included Stock Video - Download Video Clip Now - iStock.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-23 19:25 - 2020-08-09 14:16 - 002502824 _____ C:\Users\jseym\Downloads\Loading Circle Icon On White Background Animation With Optional Luma Matte Alpha Luma Matte Included 4k Video Stock Video - Download Video Clip Now - iStock.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-23 19:23 - 2020-08-09 14:16 - 003433457 _____ C:\Users\jseym\Downloads\downloading_bar.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-23 17:37 - 2020-08-09 14:16 - 000000000 ____D C:\Users\jseym\Downloads\New folder
    2020-07-23 17:33 - 2020-08-09 14:15 - 048903784 _____ C:\Users\jseym\Downloads\200207_London Streets_1_4k_033.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-23 17:33 - 2020-08-09 14:15 - 029295016 _____ C:\Users\jseym\Downloads\200207_London Streets_1_4k_049.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-23 17:32 - 2020-08-09 14:15 - 039696900 _____ C:\Users\jseym\Downloads\200207_London Streets_1_4k_037.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-23 17:08 - 2020-08-09 14:16 - 008598929 _____ C:\Users\jseym\Downloads\radar_02.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-23 05:42 - 2020-07-23 05:42 - 000000000 ____D C:\Users\jseym\AppData\Roaming\Maxon
    2020-07-23 01:27 - 2020-08-02 01:41 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
    2020-07-23 01:27 - 2020-08-02 01:41 - 000002283 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
    2020-07-23 01:27 - 2020-08-02 01:41 - 000002283 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk
    2020-07-23 01:27 - 2020-07-23 14:48 - 000003478 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
    2020-07-23 01:27 - 2020-07-23 14:48 - 000003354 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
    2020-07-22 23:45 - 2020-07-22 23:45 - 025902592 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 025444352 _____ (Microsoft Corporation) C:\Windows\system32\Hydrogen.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 022641664 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 019851776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 019812864 _____ (Microsoft Corporation) C:\Windows\system32\HologramWorld.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 018031104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 017792512 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 014820352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 009931576 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 008015872 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 007917408 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 007850288 _____ (Microsoft Corporation) C:\Windows\system32\OneCoreUAPCommonProxyStub.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 007823912 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 007604584 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 007297536 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 007269376 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 007268640 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 007012864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 006523856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 006437376 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 006292992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 006233080 _____ (Microsoft Corporation) C:\Windows\system32\StartTileData.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 006169088 _____ (Microsoft Corporation) C:\Windows\system32\twinui.pcshell.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 006089512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 005946368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 005765648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 005111808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 005099384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 004625192 _____ (Microsoft Corporation) C:\Windows\explorer.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 004565264 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 004129424 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 004014592 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Bluetooth.Service.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 003980800 _____ (Microsoft Corporation) C:\Windows\system32\tellib.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 003974368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 003800576 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 003748352 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 003743048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OneCoreUAPCommonProxyStub.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 003727360 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
    2020-07-22 23:45 - 2020-07-22 23:45 - 003712000 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 003084800 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002799104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
    2020-07-22 23:45 - 2020-07-22 23:45 - 002768984 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002737664 _____ (Microsoft Corporation) C:\Windows\system32\WebRuntimeManager.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002716672 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
    2020-07-22 23:45 - 2020-07-22 23:45 - 002576896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002552120 _____ (Microsoft Corporation) C:\Windows\system32\UpdateAgent.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002505496 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.appcore.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002494744 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002467840 _____ (Microsoft Corporation) C:\Windows\system32\InstallService.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002448712 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002357248 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Perception.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002285056 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.Printing.3D.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002264064 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Bluetooth.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002237096 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002161664 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.PointOfService.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002087168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002074112 _____ (Microsoft Corporation) C:\Windows\system32\ISM.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 002060288 _____ (Microsoft Corporation) C:\Windows\system32\cdprt.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001991592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.appcore.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001952880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001946144 _____ (Microsoft Corporation) C:\Windows\system32\dcomp.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001918464 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001885184 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001877504 _____ (Microsoft Corporation) C:\Windows\system32\LocationFramework.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001827328 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Speech.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001821696 _____ (Microsoft Corporation) C:\Windows\system32\CoreShell.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001787392 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Globalization.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001764336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001745728 _____ (Microsoft Corporation) C:\Windows\system32\ContentDeliveryManager.Utilities.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001743680 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001737728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallService.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001723392 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001697792 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001665728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001658368 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001656904 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001655472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001654304 _____ (Microsoft Corporation) C:\Windows\system32\gdi32full.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001640448 _____ (Microsoft Corporation) C:\Windows\system32\TaskFlowDataEngine.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001612800 _____ (Microsoft Corporation) C:\Windows\system32\wpncore.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001610240 _____ (Microsoft Corporation) C:\Windows\system32\HologramCompositor.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001604608 _____ (Microsoft Corporation) C:\Windows\system32\dosvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001581568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Perception.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001550336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.Printing.3D.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001540608 _____ (Microsoft Corporation) C:\Windows\system32\WindowManagement.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001512960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdprt.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001500160 _____ (Microsoft Corporation) C:\Windows\system32\TokenBroker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001495040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Bluetooth.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001486848 _____ (Microsoft Corporation) C:\Windows\system32\usocoreworker.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 001484384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001477632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dcomp.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001463808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.PointOfService.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001458688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001420328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32full.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001397568 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 001392128 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.FaceAnalysis.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001385696 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001374208 _____ (Microsoft Corporation) C:\Windows\system32\NotificationController.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001371136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001357824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Globalization.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001346048 _____ (Microsoft Corporation) C:\Windows\system32\HoloSI.PCShell.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001344512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Audio.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001337856 _____ (Microsoft Corporation) C:\Windows\system32\wpnapps.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001335296 _____ (Microsoft Corporation) C:\Windows\system32\MiracastReceiver.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001312256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001307136 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Audio.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001306944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ContentDeliveryManager.Utilities.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001290192 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Sensors.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001284608 _____ (Microsoft Corporation) C:\Windows\system32\werconcpl.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001284608 _____ (Microsoft Corporation) C:\Windows\system32\usermgr.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001271296 _____ (Microsoft Corporation) C:\Windows\system32\SEMgrSvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001265152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Speech.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001247232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBroker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001223168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.FaceAnalysis.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001195008 _____ (Microsoft Corporation) C:\Windows\system32\sdengin2.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001183744 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.Web.Core.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001159168 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApiPublic.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001151816 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001151304 _____ (Microsoft Corporation) C:\Windows\system32\InputHost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001149712 _____ (Microsoft Corporation) C:\Windows\system32\ApplyTrustOffline.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 001125376 _____ (Microsoft Corporation) C:\Windows\system32\CBDHSvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001121792 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001100800 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001086776 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Services.TargetedContent.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001081344 _____ (Microsoft Corporation) C:\Windows\system32\ShareHost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001077048 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 001068544 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001059840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001055232 _____ (Microsoft Corporation) C:\Windows\system32\Windows.AccountsControl.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001048992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001028336 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Perception.Stub.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001014784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpnapps.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001009152 _____ (Microsoft Corporation) C:\Windows\system32\StorSvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001008960 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHostCommon.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 001007616 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000995840 _____ (Microsoft Corporation) C:\Windows\system32\EdgeManager.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000967680 _____ (Microsoft Corporation) C:\Windows\system32\WebcamUi.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000958608 _____ (Microsoft Corporation) C:\Windows\system32\AppContracts.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000950272 _____ (Microsoft Corporation) C:\Windows\system32\rasapi32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000949760 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Ocr.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000945176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Sensors.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000931840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Management.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000922624 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Management.Service.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000919880 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000917504 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.OnlineId.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000913408 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000912896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MiracastReceiver.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000904192 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.SmartCards.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000899584 _____ (Microsoft Corporation) C:\Windows\system32\MdmDiagnostics.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000898048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000895600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000892928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApiPublic.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000891392 _____ (Microsoft Corporation) C:\Windows\system32\HolographicExtensions.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000889416 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Shell.Broker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000882184 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000882176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ShareHost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000875008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasapi32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000867840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000865280 _____ (Microsoft Corporation) C:\Windows\system32\efswrt.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000848384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000844096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudExperienceHostCommon.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000827904 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Import.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000822200 _____ (Microsoft Corporation) C:\Windows\system32\fontdrvhost.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000821232 _____ (Microsoft Corporation) C:\Windows\system32\windows.applicationmodel.datatransfer.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000815616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebcamUi.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000814080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000809984 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Gaming.Input.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000797448 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000793320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputHost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000783488 _____ (Microsoft Corporation) C:\Windows\system32\tcblaunch.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000782848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000779080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Services.TargetedContent.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000778872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppContracts.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000750592 _____ (Microsoft Corporation) C:\Windows\system32\ActivationManager.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000750080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.OnlineId.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000742712 _____ (Microsoft Corporation) C:\Windows\system32\LicensingWinRT.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000737792 _____ (Microsoft Corporation) C:\Windows\system32\Windows.System.Launcher.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000733184 _____ (Microsoft Corporation) C:\Windows\system32\windows.immersiveshell.serviceprovider.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000727040 _____ (Microsoft Corporation) C:\Windows\system32\agentactivationruntime.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000722072 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.AccountsControl.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000716288 _____ (Microsoft Corporation) C:\Windows\system32\agentactivationruntimewindows.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Mirage.Internal.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000695208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000694784 _____ (Microsoft Corporation) C:\Windows\system32\gpprefcl.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000692224 _____ (Microsoft Corporation) C:\Windows\system32\LockController.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000689664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Ocr.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000685384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000684864 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000678720 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000673448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontdrvhost.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000669184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EdgeManager.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000653824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Management.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000651264 _____ (Microsoft Corporation) C:\Windows\system32\DevicesFlowBroker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000639488 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000638464 _____ (Microsoft Corporation) C:\Windows\system32\twinui.appcore.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000630784 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.AllJoyn.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000628416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000628024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LicensingWinRT.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000624640 _____ (Microsoft Corporation) C:\Windows\system32\TileDataRepository.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000616960 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.LowLevel.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000614912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\efswrt.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000614912 _____ (Microsoft Corporation) C:\Windows\system32\netprofmsvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000608256 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.SmartCards.Phone.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000605896 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000602112 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Payments.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000600064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActivationManager.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000596992 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000594992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Perception.Stub.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000593408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000584704 _____ (Microsoft Corporation) C:\Windows\system32\PlayToManager.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000582056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.applicationmodel.datatransfer.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000570368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Import.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000565248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Gaming.Input.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000564736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpprefcl.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000550400 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2020-07-22 23:45 - 2020-07-22 23:45 - 000549048 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.MediaControl.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000544256 _____ (Microsoft Corporation) C:\Windows\system32\usosvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000542288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000540672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.SmartCards.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000538664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000534016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000533504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000526848 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000524784 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Enumeration.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000522240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.System.Launcher.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000521728 _____ (Microsoft Corporation) C:\Windows\system32\WinBioDataModel.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000518656 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000518464 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000513024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000513024 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Activities.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000512000 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Cortana.Desktop.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000502784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.appcore.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000502784 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.WiFiDirect.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000501760 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.LockScreen.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000497664 _____ (Microsoft Corporation) C:\Windows\system32\werui.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000495616 _____ (Microsoft Corporation) C:\Windows\system32\RTMediaFrame.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000490496 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000484352 _____ (Microsoft Corporation) C:\Windows\system32\MixedReality.Broker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000478296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000477184 _____ (Microsoft Corporation) C:\Windows\system32\CloudDomainJoinDataModelServer.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000476160 _____ (Microsoft Corporation) C:\Windows\system32\MicrosoftAccountWAMExtension.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000475136 _____ (Microsoft Corporation) C:\Windows\system32\Geolocation.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000467960 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000467456 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Picker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000467456 _____ (Microsoft Corporation) C:\Windows\system32\modernexecserver.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000466432 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.Printing.Workflow.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000462848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000461112 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000458240 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.ConversationalAgent.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000456704 _____ (Microsoft Corporation) C:\Windows\system32\upnphost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000453944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000452096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TileDataRepository.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000444416 _____ (Microsoft Corporation) C:\Windows\system32\fhsettingsprovider.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000444416 _____ (Microsoft Corporation) C:\Windows\system32\edgeIso.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.AllJoyn.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000442096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.MediaControl.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000434176 _____ (Microsoft Corporation) C:\Windows\system32\MicrosoftAccountExtension.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000432128 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Midi.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000432128 _____ (Microsoft Corporation) C:\Windows\system32\WalletService.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000430592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werui.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000419328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000419328 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.NetworkOperators.ESim.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000416768 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Usb.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000416768 _____ (Microsoft Corporation) C:\Windows\system32\RDXTaskFactory.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000412672 _____ (Microsoft Corporation) C:\Windows\system32\AboveLockAppHost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000411640 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Devices.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000411136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToManager.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000410112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.SmartCards.Phone.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000406992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Enumeration.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000406992 _____ (Microsoft Corporation) C:\Windows\system32\tsmf.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000405944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Faultrep.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000403968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Payments.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000399672 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettings.DataModel.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000397824 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Lights.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000395264 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Gaming.Preview.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000392504 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000388096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.LowLevel.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000387584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.LockScreen.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000382976 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000381152 _____ (Microsoft Corporation) C:\Windows\system32\CredentialEnrollmentManager.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000380224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000375296 _____ (Microsoft Corporation) C:\Windows\system32\Windows.System.Diagnostics.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000374272 _____ (Microsoft Corporation) C:\Windows\system32\PickerPlatform.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000371712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Geolocation.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000361472 _____ (Microsoft Corporation) C:\Windows\system32\vaultsvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000361472 _____ (Microsoft Corporation) C:\Windows\system32\QuickActionsDataModel.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.WiFiDirect.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000355840 _____ (Microsoft Corporation) C:\Windows\system32\wpnclient.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000355840 _____ (Microsoft Corporation) C:\Windows\system32\WaaSMedicSvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000355328 _____ (Microsoft Corporation) C:\Windows\system32\ConsoleLogon.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RTMediaFrame.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000352256 _____ (Microsoft Corporation) C:\Windows\system32\APHostService.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000345560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsmf.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AboveLockAppHost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000340328 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Storage.ApplicationData.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000338944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Picker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000335360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MicrosoftAccountWAMExtension.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000334336 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_Cortana.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000329728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\upnphost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000328192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgeIso.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.Printing.Workflow.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\windows.internal.shellcommon.shareexperience.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32k.sys
    2020-07-22 23:45 - 2020-07-22 23:45 - 000317440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Midi.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\SyncSettings.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000311608 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHostBroker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000311440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Devices.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000306688 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.CredDialogController.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000295936 _____ (Microsoft Corporation) C:\Windows\system32\TDLMigration.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000293888 _____ (Microsoft Corporation) C:\Windows\system32\CXHProvisioningServer.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpnclient.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000292864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.System.Diagnostics.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000290304 _____ (Microsoft Corporation) C:\Windows\system32\vaultcli.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000287744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Gaming.Preview.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000285184 _____ (Microsoft Corporation) C:\Windows\system32\WaaSMedicCapsule.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000283648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.NetworkOperators.ESim.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000283136 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.AppDefaults.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000281600 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.HumanInterfaceDevice.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000280576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Usb.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000275968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Lights.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000274432 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.Identity.Provider.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000272384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PickerPlatform.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000268552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Storage.ApplicationData.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000266552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SystemSettings.DataModel.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000265728 _____ (Microsoft Corporation) C:\Windows\system32\netman.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000261632 _____ (Microsoft Corporation) C:\Windows\system32\bthprops.cpl
    2020-07-22 23:45 - 2020-07-22 23:45 - 000260288 _____ (Microsoft Corporation) C:\Windows\system32\logoncli.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000256000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ConsoleLogon.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000248832 _____ (Microsoft Corporation) C:\Windows\system32\PasswordEnrollmentManager.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000247864 _____ (Microsoft Corporation) C:\Windows\system32\weretw.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000243200 _____ (Microsoft Corporation) C:\Windows\system32\SystemEventsBrokerServer.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000242688 _____ (Microsoft Corporation) C:\Windows\system32\CapabilityAccessManagerClient.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.CredDialogController.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000240640 _____ (Microsoft Corporation) C:\Windows\system32\dialclient.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000239928 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Management.Workplace.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000237056 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.CapturePicker.Desktop.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000237056 _____ (Microsoft Corporation) C:\Windows\system32\psmsrv.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000237056 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000231424 _____ (Microsoft Corporation) C:\Windows\system32\HoloShellRuntime.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000228864 _____ (Microsoft Corporation) C:\Windows\system32\wersvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000228864 _____ (Microsoft Corporation) C:\Windows\system32\netprofm.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000227840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SyncSettings.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000224768 _____ (Microsoft Corporation) C:\Windows\system32\DWWIN.EXE
    2020-07-22 23:45 - 2020-07-22 23:45 - 000220992 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000220672 _____ (Microsoft Corporation) C:\Windows\system32\MtcModel.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000219136 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000217600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bthprops.cpl
    2020-07-22 23:45 - 2020-07-22 23:45 - 000217600 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Core.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\UserDeviceRegistration.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000215040 _____ (Microsoft Corporation) C:\Windows\system32\PeopleBand.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000215040 _____ (Microsoft Corporation) C:\Windows\system32\DiagSvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000211256 _____ (Microsoft Corporation) C:\Windows\system32\tcbloader.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000210944 _____ (Microsoft Corporation) C:\Windows\system32\ErrorDetails.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000206336 _____ (Microsoft Corporation) C:\Windows\system32\useractivitybroker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000200704 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Internal.Input.ExpressiveInput.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000199496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000196096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000195584 _____ (Microsoft Corporation) C:\Windows\system32\AarSvc.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000193600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\weretw.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000190056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logoncli.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000188928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000188928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWWIN.EXE
    2020-07-22 23:45 - 2020-07-22 23:45 - 000186368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000183808 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Energy.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000180224 _____ (Microsoft Corporation) C:\Windows\system32\dialserver.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000179712 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_Clipboard.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000179512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
    2020-07-22 23:45 - 2020-07-22 23:45 - 000179200 _____ (Microsoft Corporation) C:\Windows\system32\PrintWorkflowService.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000179200 _____ (Microsoft Corporation) C:\Windows\system32\easwrt.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000179200 _____ (Microsoft Corporation) C:\Windows\system32\AppExtension.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000178688 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Graphics.Display.DisplayEnhancementManagement.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000176952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Management.Workplace.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\HoloShellRuntime.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dialclient.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000172032 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.CapturePicker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000165840 _____ (Microsoft Corporation) C:\Windows\system32\WerFaultSecure.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000165376 _____ (Microsoft Corporation) C:\Windows\splwow64.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000162816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ErrorDetails.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDeviceRegistration.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000160768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CapabilityAccessManagerClient.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000159744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Core.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000157184 _____ (Microsoft Corporation) C:\Windows\system32\PrintWSDAHost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000152064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\useractivitybroker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000151552 _____ (Microsoft Corporation) C:\Windows\system32\fdWSD.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000151040 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.SerialCommunication.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000150336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFaultSecure.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000147968 _____ (Microsoft Corporation) C:\Windows\system32\Family.Client.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000146232 _____ (Microsoft Corporation) C:\Windows\system32\ResourcePolicyServer.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\AppointmentActivation.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000143360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\easwrt.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintWorkflowService.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000140800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Energy.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000133632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Graphics.Display.DisplayEnhancementManagement.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000133632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppExtension.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000132608 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Storage.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000132408 _____ (Microsoft Corporation) C:\Windows\system32\offlinelsa.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000131584 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairingExperienceMEM.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000131072 _____ (Microsoft Corporation) C:\Windows\system32\CredDialogBroker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000130560 _____ (Microsoft Corporation) C:\Windows\system32\StorageUsage.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\CameraCaptureUI.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\CaptureService.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fdWSD.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000127064 _____ (Microsoft Corporation) C:\Windows\system32\win32u.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000125952 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000124928 _____ (Microsoft Corporation) C:\Windows\system32\wercplsupport.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintWSDAHost.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000118784 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Background.SystemEventsBroker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000118272 _____ (Microsoft Corporation) C:\Windows\system32\EaseOfAccessDialog.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppointmentActivation.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000112128 _____ (Microsoft Corporation) C:\Windows\system32\AxInstSv.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000110040 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Credentials.UI.CredentialPicker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000107520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.SerialCommunication.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000105984 _____ (Microsoft Corporation) C:\Windows\system32\utcutil.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\sethc.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\Family.Authentication.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000100352 _____ (Microsoft Corporation) C:\Windows\system32\DiagnosticInvoker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000099328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000094720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CameraCaptureUI.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000094208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EaseOfAccessDialog.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000093184 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000092672 _____ (Microsoft Corporation) C:\Windows\system32\wsqmcons.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000091648 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Graphics.Display.DisplayColorManagement.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000090624 _____ (Microsoft Corporation) C:\Windows\system32\keyiso.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000089600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000089328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32u.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000089088 _____ (Microsoft Corporation) C:\Windows\system32\WaaSMedicAgent.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000086272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Credentials.UI.CredentialPicker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000083456 _____ (Microsoft Corporation) C:\Windows\system32\SystemUWPLauncher.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000082432 _____ (Microsoft Corporation) C:\Windows\system32\LocationFrameworkInternalPS.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000081408 _____ (Microsoft Corporation) C:\Windows\system32\Print.Workflow.Source.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000079360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sethc.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000076952 _____ (Microsoft Corporation) C:\Windows\system32\CredentialEnrollmentManagerForUser.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DiagnosticInvoker.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000071168 _____ (Microsoft Corporation) C:\Windows\system32\MiracastReceiverExt.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000070248 _____ (Microsoft Corporation) C:\Windows\system32\ResourcePolicyClient.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000068096 _____ (Microsoft Corporation) C:\Windows\system32\udhisapi.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000066560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\keyiso.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Graphics.Display.DisplayColorManagement.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000065536 _____ (Microsoft Corporation) C:\Windows\system32\iemigplugin.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SystemUWPLauncher.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000063488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iemigplugin.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Print.Workflow.Source.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\mf3216.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\AxInstUI.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000058368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\udhisapi.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000058368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MiracastReceiverExt.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000052152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ResourcePolicyClient.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000046080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf3216.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000045056 _____ (Microsoft Corporation) C:\Windows\system32\npmproxy.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000044544 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\upnpcont.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000040248 _____ (Microsoft Corporation) C:\Windows\system32\LocationFrameworkPS.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000038912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werdiagcontroller.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000037376 _____ (Microsoft Corporation) C:\Windows\system32\UIMgrBroker.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\upnpcont.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\SystemEventsBrokerClient.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\nlmproxy.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\WaaSMedicPS.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\PrintWorkflowProxy.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000024064 _____ (Microsoft Corporation) C:\Windows\system32\CSystemEventsBrokerClient.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000021504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SystemEventsBrokerClient.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000017408 _____ (Microsoft Corporation) C:\Windows\system32\nlmsprep.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintWorkflowProxy.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.Printing.Workflow.Native.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000013824 _____ (Microsoft Corporation) C:\Windows\system32\UIManagerBrokerps.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.Printing.Workflow.Native.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000012288 _____ (Microsoft Corporation) C:\Windows\system32\RemoteFXvGPUDisablement.exe
    2020-07-22 23:45 - 2020-07-22 23:45 - 000011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000008192 _____ (Microsoft Corporation) C:\Windows\system32\msimg32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimg32.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000003072 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000002560 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
    2020-07-22 23:45 - 2020-07-22 23:45 - 000000315 _____ C:\Windows\system32\DrtmAuth9.bin
    2020-07-22 23:45 - 2020-07-22 23:45 - 000000315 _____ C:\Windows\system32\DrtmAuth8.bin
    2020-07-22 23:45 - 2020-07-22 23:45 - 000000315 _____ C:\Windows\system32\DrtmAuth7.bin
    2020-07-22 23:45 - 2020-07-22 23:45 - 000000315 _____ C:\Windows\system32\DrtmAuth6.bin
    2020-07-22 23:45 - 2020-07-22 23:45 - 000000315 _____ C:\Windows\system32\DrtmAuth5.bin
    2020-07-22 23:45 - 2020-07-22 23:45 - 000000315 _____ C:\Windows\system32\DrtmAuth4.bin
    2020-07-22 23:45 - 2020-07-22 23:45 - 000000315 _____ C:\Windows\system32\DrtmAuth3.bin
    2020-07-22 23:45 - 2020-07-22 23:45 - 000000315 _____ C:\Windows\system32\DrtmAuth2.bin
    2020-07-22 23:45 - 2020-07-22 23:45 - 000000315 _____ C:\Windows\system32\DrtmAuth12.bin
    2020-07-22 23:45 - 2020-07-22 23:45 - 000000315 _____ C:\Windows\system32\DrtmAuth11.bin
    2020-07-22 23:45 - 2020-07-22 23:45 - 000000315 _____ C:\Windows\system32\DrtmAuth10.bin
    2020-07-22 23:45 - 2020-07-22 23:45 - 000000315 _____ C:\Windows\system32\DrtmAuth1.bin
    2020-07-22 23:44 - 2020-07-22 23:44 - 000656696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys
    2020-07-22 23:44 - 2020-07-22 23:44 - 000204608 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spacedump.sys
    2020-07-22 23:40 - 2020-06-29 23:32 - 000390656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
    2020-07-22 23:40 - 2020-06-29 23:26 - 000492544 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
    2020-07-22 05:48 - 2020-08-09 14:16 - 008960762 _____ C:\Users\jseym\Downloads\FileZilla_3.49.1_win64-setup.exe.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-22 05:48 - 2020-07-22 05:48 - 008174024 _____ (Tim Kosse) C:\Users\jseym\Downloads\FileZilla_3.49.1_win64-setup.exe
    2020-07-21 15:21 - 2020-08-09 17:19 - 000000000 ____D C:\Users\jseym\AppData\Local\ZoogVPN
    2020-07-21 15:15 - 2020-07-21 15:20 - 000000000 ____D C:\Program Files (x86)\ZoogVPN
    2020-07-21 15:15 - 2020-07-21 15:15 - 000001067 _____ C:\Users\Public\Desktop\ZoogVPN.lnk
    2020-07-21 15:15 - 2020-07-21 15:15 - 000001067 _____ C:\ProgramData\Desktop\ZoogVPN.lnk
    2020-07-21 15:15 - 2020-07-21 15:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZoogVPN
    2020-07-21 15:15 - 2020-07-21 15:15 - 000000000 ____D C:\Program Files\TAP-Windows
    2020-07-21 01:32 - 2020-08-09 14:16 - 011288952 _____ C:\Users\jseym\Downloads\earth-4k-green-screen-pack-re.mp4.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-14 21:49 - 2020-08-09 17:37 - 000000000 ____D C:\Users\jseym\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
    2020-07-14 21:49 - 2020-08-09 14:04 - 000000000 ____D C:\Users\jseym\AppData\Roaming\FileZilla
    2020-07-14 21:49 - 2020-08-09 04:49 - 000000000 ____D C:\Users\jseym\AppData\Local\FileZilla
    2020-07-14 21:49 - 2020-07-28 17:15 - 000001934 _____ C:\Users\jseym\Desktop\FileZilla Client.lnk
    2020-07-14 21:49 - 2020-07-28 17:15 - 000000000 ____D C:\Program Files\FileZilla FTP Client
    2020-07-14 21:44 - 2020-08-09 14:16 - 011649634 _____ C:\Users\jseym\Downloads\FileZilla_3.49.0_win64_sponsored-setup.exe.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-07-14 21:44 - 2020-07-14 21:48 - 010862880 _____ (Tim Kosse) C:\Users\jseym\Downloads\FileZilla_3.49.0_win64_sponsored-setup.exe
    2020-07-14 14:13 - 2020-07-14 14:13 - 000000000 ____D C:\Users\jseym\AppData\Roaming\Skype
    2020-07-13 15:06 - 2020-08-09 17:37 - 000000000 ____D C:\Users\jseym\AppData\Roaming\dvdcss
    2020-07-12 15:39 - 2020-08-09 17:37 - 000000000 ____D C:\Users\jseym\Downloads\Minecraft 1.8.9 (Full installer, Online, Serverlist)
    2020-07-10 15:53 - 2020-07-10 15:53 - 000000000 ____D C:\Users\jseym\AppData\LocalLow\Ookla
    2020-07-10 15:53 - 2020-07-10 15:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speedtest By Ookla
    2020-07-10 15:53 - 2020-07-10 15:53 - 000000000 ____D C:\Program Files\Speedtest

    ==================== One month (modified) ==================

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2020-08-09 19:03 - 2020-05-12 04:13 - 000000000 ____D C:\Users\jseym\AppData\Roaming\LBRY
    2020-08-09 19:03 - 2020-05-12 03:40 - 000000000 ____D C:\Users\jseym\AppData\LocalLow\uTorrent
    2020-08-09 18:59 - 2019-03-18 23:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2020-08-09 18:47 - 2020-05-11 22:57 - 000000000 ____D C:\Users\jseym\AppData\LocalLow\Mozilla
    2020-08-09 18:44 - 2020-05-11 22:45 - 000000000 __SHD C:\Users\jseym\IntelGraphicsProfiles
    2020-08-09 18:43 - 2020-05-11 22:39 - 000000000 ____D C:\Users\jseym
    2020-08-09 18:43 - 2019-11-15 11:46 - 000000000 ____D C:\Windows\system32\SleepStudy
    2020-08-09 17:52 - 2019-11-15 11:57 - 000840916 _____ C:\Windows\system32\PerfStringBackup.INI
    2020-08-09 17:52 - 2019-03-18 23:50 - 000000000 ____D C:\Windows\INF
    2020-08-09 17:46 - 2019-11-15 11:47 - 000000006 ____H C:\Windows\Tasks\SA.DAT
    2020-08-09 17:45 - 2019-11-15 11:50 - 000000000 __RHD C:\Users\Public\AccountPictures
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 __RHD C:\Users\Public\Libraries
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ___SD C:\Windows\SysWOW64\Nui
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ___SD C:\Windows\system32\Nui
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\SysWOW64\Bthprops
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\SystemResources
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\system32\Sysprep
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\system32\Keywords
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\system32\DDFs
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\system32\Bthprops
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\System
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\ShellExperiences
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\PolicyDefinitions
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\DiagTrack
    2020-08-09 17:45 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\bcastdvr
    2020-08-09 17:37 - 2020-06-29 02:46 - 000000000 ___RD C:\Users\jseym\Downloads\Stock for FX
    2020-08-09 17:37 - 2020-06-09 15:41 - 000000000 ____D C:\Users\jseym\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bing Wallpaper
    2020-08-09 17:37 - 2020-05-26 23:32 - 000000000 ____D C:\Users\jseym\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HandBrake
    2020-08-09 17:37 - 2020-05-18 13:32 - 000000000 ____D C:\Users\jseym\AppData\Roaming\vlc
    2020-08-09 17:37 - 2020-05-16 19:54 - 000000000 ____D C:\Users\jseym\AppData\Roaming\obs-studio
    2020-08-09 17:37 - 2020-05-16 19:54 - 000000000 ____D C:\ProgramData\obs-studio-hook
    2020-08-09 17:37 - 2020-05-14 22:58 - 000000000 ____D C:\Program Files (x86)\Red Giant Link
    2020-08-09 17:37 - 2020-05-13 18:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Red Giant
    2020-08-09 17:37 - 2020-05-13 18:45 - 000000000 ____D C:\Program Files\Red Giant
    2020-08-09 17:37 - 2020-05-12 15:44 - 000000000 ____D C:\ProgramData\Package Cache
    2020-08-09 17:37 - 2020-05-12 04:12 - 000000000 ____D C:\Users\jseym\AppData\Local\lbry-updater
    2020-08-09 17:37 - 2020-05-12 04:05 - 000000000 ____D C:\Users\jseym\AppData\Roaming\DAZ 3D
    2020-08-09 17:37 - 2020-05-11 22:57 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2020-08-09 17:37 - 2020-05-11 22:45 - 000000000 ___RD C:\Users\jseym\3D Objects
    2020-08-09 17:37 - 2020-05-11 22:45 - 000000000 ____D C:\Users\jseym\AppData\Local\ConnectedDevicesPlatform
    2020-08-09 17:37 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\appcompat
    2020-08-09 17:27 - 2019-03-18 23:52 - 000000000 ___HD C:\Program Files\WindowsApps
    2020-08-09 17:22 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\registration
    2020-08-09 17:19 - 2020-07-07 13:28 - 000000000 ____D C:\Users\Public\Pixologic
    2020-08-09 17:19 - 2020-06-29 22:36 - 000000000 ____D C:\Users\jseym\Downloads\j
    2020-08-09 17:19 - 2020-06-29 02:47 - 000000000 ____D C:\Users\jseym\Downloads\Daz
    2020-08-09 17:19 - 2020-06-29 02:42 - 000000000 ____D C:\Users\Public\Documents\My DAZ 3D Library
    2020-08-09 17:19 - 2020-06-29 02:42 - 000000000 ____D C:\ProgramData\Documents\My DAZ 3D Library
    2020-08-09 17:19 - 2020-06-29 02:41 - 000000000 ____D C:\Users\Public\Documents\DAZ 3D
    2020-08-09 17:19 - 2020-06-29 02:41 - 000000000 ____D C:\ProgramData\Documents\DAZ 3D
    2020-08-09 17:19 - 2020-06-18 22:05 - 000000000 ____D C:\Users\jseym\AppData\Local\VEGAS Pro
    2020-08-09 17:19 - 2020-06-08 01:01 - 000000000 ____D C:\Users\jseym\Documents\Adobe
    2020-08-09 17:19 - 2020-06-08 00:58 - 000000000 ____D C:\Users\Public\Documents\Adobe
    2020-08-09 17:19 - 2020-06-08 00:58 - 000000000 ____D C:\ProgramData\Documents\Adobe
    2020-08-09 17:19 - 2020-05-13 18:23 - 000000000 ____D C:\Users\jseym\AppData\Local\Red Giant
    2020-08-09 17:19 - 2020-05-13 18:21 - 000000000 ____D C:\Users\jseym\AppData\Roaming\Red Giant
    2020-08-09 17:19 - 2020-05-12 03:31 - 000000000 ____D C:\Users\jseym\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DAZ 3D
    2020-08-09 17:19 - 2020-05-11 23:31 - 000000000 ____D C:\Users\jseym\Documents\DAZ 3D
    2020-08-09 17:19 - 2020-05-11 22:45 - 000000000 ___HD C:\Users\jseym\MicrosoftEdgeBackups
    2020-08-09 17:19 - 2020-05-11 22:45 - 000000000 ____D C:\Users\jseym\AppData\Local\VirtualStore
    2020-08-09 17:18 - 2020-05-15 00:37 - 000000000 ____D C:\Program Files (x86)\Intel
    2020-08-09 17:18 - 2020-05-14 22:59 - 000000000 ____D C:\ProgramData\RedGiant
    2020-08-09 17:18 - 2020-05-13 18:20 - 000000000 ____D C:\ProgramData\Red Giant
    2020-08-09 16:48 - 2020-07-07 23:52 - 000000000 ____D C:\Users\jseym\Desktop\Fire Embers Ash Dust
    2020-08-09 16:11 - 2020-05-11 22:47 - 000000000 ___RD C:\Users\jseym\OneDrive
    2020-08-09 14:42 - 2020-05-26 23:32 - 000000000 ____D C:\Users\jseym\AppData\Roaming\HandBrake
    2020-08-09 14:25 - 2019-03-18 23:37 - 000000000 ____D C:\Windows\CbsTemp
    2020-08-09 14:16 - 2020-06-29 03:08 - 000000000 ____D C:\Users\jseym\Downloads\Books
    2020-08-09 14:15 - 2020-06-14 01:44 - 000000000 ____D C:\Users\jseym\Documents\The Silent Corner - Dean Koontz [EN EPUB MOBI] [ebook] [ps]
    2020-08-09 14:15 - 2020-06-12 20:03 - 000000000 ____D C:\Users\jseym\Documents\Sound recordings
    2020-08-09 14:15 - 2020-06-04 02:04 - 000000000 ____D C:\Users\jseym\Documents\Photo SHop
    2020-08-09 14:15 - 2020-05-12 04:19 - 070818500 _____ C:\Users\jseym\Documents\lbryum-2020-04-22T03-26-39.710Z.zip.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 14:05 - 2020-07-08 00:32 - 000000000 ____D C:\Users\jseym\Desktop\new stock
    2020-08-09 14:05 - 2020-07-08 00:17 - 000000000 ____D C:\Users\jseym\Desktop\Blood
    2020-08-09 14:05 - 2020-07-08 00:08 - 046656791 _____ C:\Users\jseym\Desktop\Virtual Studio Blue Earth 2016.mp4
    2020-08-09 14:05 - 2020-07-07 23:53 - 000000000 ____D C:\Users\jseym\Desktop\Filter PNGs
    2020-08-09 14:05 - 2020-06-13 22:49 - 000000000 ____D C:\Users\jseym\Documents\Audacity
    2020-08-09 14:05 - 2020-06-13 22:16 - 000000000 ____D C:\Users\jseym\AppData\Roaming\Sony
    2020-08-09 14:05 - 2020-05-13 23:17 - 000000000 ____D C:\Users\jseym\Documents\Background_Lights
    2020-08-09 14:02 - 2020-05-12 03:23 - 000000000 ____D C:\Users\jseym\AppData\Local\BitTorrentHelper
    2020-08-09 04:52 - 2020-05-11 22:48 - 000000000 ____D C:\Users\jseym\AppData\Local\PlaceholderTileLogoFolder
    2020-08-09 04:49 - 2020-05-13 23:16 - 000000000 ____D C:\ProgramData\VideoCopilot
    2020-08-08 14:00 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\AppReadiness
    2020-08-04 19:53 - 2019-11-15 11:47 - 000000000 ____D C:\Windows\system32\Drivers\wd
    2020-08-03 15:21 - 2019-03-18 23:37 - 000786432 _____ C:\Windows\system32\config\BBI
    2020-07-30 15:01 - 2020-05-11 22:57 - 000001012 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
    2020-07-23 06:29 - 2020-05-11 22:45 - 000000000 ____D C:\Users\jseym\AppData\Local\Packages
    2020-07-23 05:53 - 2020-05-11 22:47 - 000003378 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-871970874-3256418639-2447214560-1004
    2020-07-23 05:53 - 2020-05-11 22:47 - 000002370 _____ C:\Users\jseym\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
    2020-07-23 01:26 - 2019-11-15 11:46 - 000257824 _____ C:\Windows\system32\FNTCACHE.DAT
    2020-07-23 01:26 - 2019-03-18 23:52 - 000000000 ___SD C:\Windows\system32\DiagSvcs
    2020-07-23 01:26 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\system32\oobe
    2020-07-23 01:26 - 2019-03-18 23:52 - 000000000 ____D C:\Program Files\Common Files\System
    2020-07-23 01:26 - 2019-03-18 23:37 - 000786432 _____ C:\Windows\system32\config\BBI(879)
    2020-07-21 14:43 - 2019-11-15 11:50 - 000000000 ____D C:\ProgramData\Packages
    2020-07-16 01:57 - 2020-05-26 16:13 - 000000000 ____D C:\Users\jseym\AppData\Local\ElevatedDiagnostics
    2020-07-14 15:13 - 2020-05-15 01:33 - 000001517 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Driver & Support Assistant.lnk
    2020-07-10 14:04 - 2019-03-18 23:52 - 000000000 ____D C:\Windows\system32\NDF
    2020-07-10 02:27 - 2020-05-12 15:45 - 000000000 ____D C:\Users\jseym\AppData\Local\D3DSCache

    ==================== Files in the root of some directories ========

    2020-08-02 04:12 - 2020-08-02 04:12 - 000823296 _____ () C:\Users\Public\fxc.exe
    2020-08-02 04:18 - 2020-08-02 04:18 - 000823296 _____ () C:\Users\Public\ldz.exe
    2020-08-02 04:23 - 2020-08-02 04:23 - 000823296 _____ () C:\Users\Public\mlx.exe
    2020-08-02 04:23 - 2020-08-02 04:23 - 000823296 _____ () C:\Users\Public\rdn.exe
    2020-08-02 04:22 - 2020-08-02 04:22 - 000823296 _____ () C:\Users\Public\uwa.exe
    2020-08-02 04:11 - 2020-08-02 04:11 - 000823296 _____ () C:\Users\Public\xdg.exe
    2020-08-09 14:03 - 2020-08-09 14:03 - 000352402 _____ () C:\Users\jseym\AppData\Roaming\CodecsLE_Install.log.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-02 04:13 - 2020-08-02 04:12 - 000200192 _____ (H$a8qZ9|6&NbzD4*) C:\Users\jseym\AppData\Roaming\dllsha.exe
    2020-08-09 14:04 - 2020-08-09 14:04 - 000200450 _____ () C:\Users\jseym\AppData\Roaming\dllsha.exe.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 04:49 - 2020-08-09 04:49 - 000000402 _____ () C:\Users\jseym\AppData\Local\Iksl.url.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-02 04:12 - 2020-08-02 04:12 - 001034806 _____ () C:\Users\jseym\AppData\Local\Ikslsec.exe
    2020-08-09 04:49 - 2020-08-09 04:49 - 001035058 _____ () C:\Users\jseym\AppData\Local\Ikslsec.exe.id[244EA16D-2275].[helprecover@foxmail.com].help
    2020-08-09 04:52 - 2020-08-09 04:52 - 000000658 _____ () C:\Users\jseym\AppData\Local\oobelibMkey.log.id[244EA16D-2275].[helprecover@foxmail.com].help

    ==================== SigCheck ============================

    (There is no automatic fix for files that do not pass verification.)

    ==================== End of FRST.txt ========================

  2. #2
    Security Expert Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    3,931

    Default

    Hi
    We've got a problem here. This infection also known as Phobos ransomware

    Unfortunately, there is no known method to decrypt files encrypted by any Phobos Ransomware

    Please read over the below links
    https://www.bleepingcomputer.com/for...verfoxmailcom/
    https://www.bleepingcomputer.com/for...xmailcom-help/
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  3. #3
    Member
    Join Date
    Sep 2009
    Posts
    34

    Default Thank You.

    Thank you for your help. I read the articles (& a few more). I also came across the ransom note & something called Info.hte

    Interestingly enough, while experimenting I found that MP3 files can be reverted by renaming with proper ext. Odd yes?


    Hopefully someday soon someone will find the key. I'll save my files just in case.

    Thank you for all you do.
    Jseymour3000

  4. #4
    Security Expert Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    3,931

    Default

    Wish there was something I could do but, there isn't anything available at the moment.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  5. #5
    Security Expert Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    3,931

    Default

    Glad we could help.
    Since this issue appears resolved ... this Topic is closed.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •