Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-12-2016
- Ran by Wasted Time (administrator) on X17-2G7-W92 (19-12-2016 17:16:17)
- Running from C:\Users\Wasted Time\Downloads
- Loaded Profiles: Wasted Time (Available Profiles: Owner & Wasted Time & Cyemonkey)
- Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
- Internet Explorer Version 11 (Default browser: Opera)
- Boot Mode: Normal
- Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
- ==================== Processes (Whitelisted) =================
- (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
- (Intel Corporation) C:\Windows\System32\igfxCUIService.exe
- (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
- (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
- (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
- (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe
- () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
- (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
- () C:\Program Files (x86)\Intel Driver Update Utility\SUR\SurSvc.exe
- (TorchMedia Inc.) C:\Users\Exepe_000\AppData\Local\Torch\Update\TorchCrashHandler.exe
- (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe
- (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
- (NETGEAR) C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe
- (A-Volute) C:\ProgramData\Razer\Synapse\Devices\Razer Surround\Driver\RzSurroundVADStreamingService.exe
- (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
- (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
- (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
- () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
- (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
- (Intel Corporation) C:\Windows\System32\igfxEM.exe
- (Intel Corporation) C:\Windows\System32\igfxHK.exe
- (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe
- (Intel Corporation) C:\Windows\System32\igfxext.exe
- (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\SW Update\SWMAgent.exe
- (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
- (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
- (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
- (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
- (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
- (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
- (Spotify Ltd) C:\Users\Wasted Time\AppData\Roaming\Spotify\SpotifyWebHelper.exe
- () C:\Users\Wasted Time\AppData\Local\Amazon Music\Amazon Music Helper.exe
- (Hammer & Chisel, Inc.) C:\Users\Wasted Time\AppData\Local\DiscordPTB\app-0.0.31\DiscordPTB.exe
- (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
- (Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
- (Curse, Inc) C:\Users\Wasted Time\AppData\Roaming\Curse Client\Bin\Curse.exe
- (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
- (ShareX Team) C:\Program Files\ShareX\ShareX.exe
- (Curse, Inc.) C:\Users\Wasted Time\AppData\Roaming\Curse Client\Bin\Electron\CurseUI.exe
- () C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe
- (Curse, Inc.) C:\Users\Wasted Time\AppData\Roaming\Curse Client\Bin\Electron\CurseUI.exe
- (Curse, Inc.) C:\Users\Wasted Time\AppData\Roaming\Curse Client\Bin\Electron\CurseUI.exe
- (Curse, Inc.) C:\Users\Wasted Time\AppData\Roaming\Curse Client\Bin\Electron\CurseUI.exe
- (Hammer & Chisel, Inc.) C:\ProgramData\Wasted Time\Discord\app-0.0.296\Discord.exe
- (Hammer & Chisel, Inc.) C:\ProgramData\Wasted Time\Discord\app-0.0.296\Discord.exe
- (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
- (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
- (Hammer & Chisel, Inc.) C:\ProgramData\Wasted Time\Discord\app-0.0.296\Discord.exe
- (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
- () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
- (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe
- (Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe
- (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
- (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.85\opera.exe
- (Razer, Inc.) C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe
- (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.85\opera_crashreporter.exe
- (Razer, Inc.) C:\Users\Wasted Time\AppData\Local\Razer\InGameEngine\cache\RzStats.Manager\rzcefrenderprocess.exe
- (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.85\opera.exe
- (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.85\opera.exe
- (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.85\opera.exe
- (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.85\opera.exe
- (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.85\opera.exe
- (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.85\opera.exe
- (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.85\opera.exe
- (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.85\opera.exe
- (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.85\opera.exe
- () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkypeHost.exe
- (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.350_none_43278ee965418581\TiWorker.exe
- (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.85\opera.exe
- (Microsoft Corporation) C:\Windows\System32\smartscreen.exe
- (Opera Software) C:\Program Files (x86)\Opera\42.0.2393.85\opera.exe
- ==================== Registry (Whitelisted) ====================
- (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
- HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [14040296 2015-09-17] (Realtek Semiconductor)
- HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [15033976 2015-11-20] (Logitech Inc.)
- HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-05-05] (Adobe Systems Incorporated)
- HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2786768 2016-11-29] (Malwarebytes)
- HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-11] (Oracle Corporation)
- HKLM-x32\...\Run: [] => [X]
- HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [596640 2016-08-22] (Razer Inc.)
- HKLM-x32\...\Run: [DiscordPTB] => C:\ProgramData\SquirrelMachineInstalls\DiscordPTB.exe [46669488 2016-01-22] (Hammer & Chisel, Inc.)
- HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2380480 2016-06-08] (Adobe Systems Incorporated)
- HKLM-x32\...\Run: [Discord] => C:\ProgramData\SquirrelMachineInstalls\Discord.exe [50343608 2016-12-19] (Hammer & Chisel, Inc.)
- Winlogon\Notify\igfxcui: igfxdev.dll [X]
- HKU\S-1-5-21-4065172224-1480893673-3259940331-1011\...\Run: [Spotify Web Helper] => C:\Users\Wasted Time\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1444976 2016-12-09] (Spotify Ltd)
- HKU\S-1-5-21-4065172224-1480893673-3259940331-1011\...\Run: [Amazon Music] => C:\Users\Wasted Time\AppData\Local\Amazon Music\Amazon Music Helper.exe [5907944 2016-04-14] ()
- HKU\S-1-5-21-4065172224-1480893673-3259940331-1011\...\Run: [Spotify] => C:\Users\Wasted Time\AppData\Roaming\Spotify\Spotify.exe [7095408 2016-12-09] (Spotify Ltd)
- HKU\S-1-5-21-4065172224-1480893673-3259940331-1011\...\Run: [DiscordPTB] => C:\Users\Wasted Time\AppData\Local\DiscordPTB\app-0.0.31\DiscordPTB.exe [64270336 2016-12-06] (Hammer & Chisel, Inc.)
- HKU\S-1-5-21-4065172224-1480893673-3259940331-1011\...\Run: [Discord] => C:\ProgramData\Wasted Time\Discord\app-0.0.296\Discord.exe [62471352 2016-08-24] (Hammer & Chisel, Inc.)
- AppInit_DLLs: C:\Program Files C:\Program Files C:\Program Files C:\Program Files C:\Program Files C:\Program Files C:\Program Files => No File
- ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-05-22] ()
- ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-05-22] ()
- ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-05-22] ()
- Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass FF RunOnce.lnk [2016-11-23]
- ShortcutTarget: Install LastPass FF RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
- Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk [2016-11-23]
- ShortcutTarget: Install LastPass IE RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
- Startup: C:\Users\Cyemonkey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Gameroom.lnk [2016-11-18]
- ShortcutTarget: Facebook Gameroom.lnk -> C:\Users\Wasted Time\AppData\Local\Facebook\Games\FacebookGameroom.exe (No File)
- Startup: C:\Users\Exepe_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Curse.lnk [2015-10-01]
- ShortcutTarget: Curse.lnk -> C:\Users\Wasted Time\AppData\Roaming\Curse Client\Bin\Curse.exe (Curse, Inc)
- Startup: C:\Users\Wasted Time\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Curse.lnk [2016-12-01]
- ShortcutTarget: Curse.lnk -> C:\Users\Wasted Time\AppData\Roaming\Curse Client\Bin\Curse.exe (Curse, Inc)
- Startup: C:\Users\Wasted Time\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ShareX.lnk [2016-12-07]
- ShortcutTarget: ShareX.lnk -> C:\Program Files\ShareX\ShareX.exe (ShareX Team)
- GroupPolicyUsers\S-1-5-21-4065172224-1480893673-3259940331-1001\User: Restriction <======= ATTENTION
- CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
- ==================== Internet (Whitelisted) ====================
- (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
- Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
- Tcpip\..\Interfaces\{659a110b-bfb4-447a-a0e7-4e65597de828}: [NameServer] 8.8.8.8,8.8.4.4
- Tcpip\..\Interfaces\{659a110b-bfb4-447a-a0e7-4e65597de828}: [DhcpNameServer] 192.168.1.1
- Tcpip\..\Interfaces\{7a616093-7c46-4c91-9d41-8fe416e727bf}: [NameServer] 8.8.8.8,8.8.4.4
- Tcpip\..\Interfaces\{7a616093-7c46-4c91-9d41-8fe416e727bf}: [DhcpNameServer] 192.168.1.1
- Tcpip\..\Interfaces\{80979261-D638-4990-8E64-D95F0E67F43A}: [DhcpNameServer] 109.201.137.37 109.201.137.38
- Tcpip\..\Interfaces\{ed3b192a-86a7-4481-bb0d-0e5b0048372b}: [NameServer] 184.172.114.130,208.43.110.90
- Internet Explorer:
- ==================
- HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
- HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
- HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
- HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
- HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
- HKU\S-1-5-21-4065172224-1480893673-3259940331-1011\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung13.msn.com
- HKU\S-1-5-21-4065172224-1480893673-3259940331-1011\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung13.msn.com
- SearchScopes: HKU\S-1-5-21-4065172224-1480893673-3259940331-1011 -> DefaultScope {B4AAF7F3-BB97-4703-BE58-9C581D411D69} URL =
- SearchScopes: HKU\S-1-5-21-4065172224-1480893673-3259940331-1011 -> {B4AAF7F3-BB97-4703-BE58-9C581D411D69} URL =
- BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-08-10] (Qualcomm Atheros Commnucations)
- BHO: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2016-11-23] (LastPass)
- BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)
- BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-07-11] (Oracle Corporation)
- BHO-x32: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar.dll [2016-11-23] (LastPass)
- BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-07-11] (Oracle Corporation)
- Toolbar: HKLM - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2016-11-23] (LastPass)
- Toolbar: HKLM-x32 - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll [2016-11-23] (LastPass)
- DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
- DPF: HKLM-x32 {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} hxxp://content.systemrequirementslab.com/bin/srldetect_intel_4.5.24.0.cab
- DPF: HKLM-x32 {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} hxxp://3dlifeplayer.dl.3dvia.com/player/install/3DVIA_player_installer.exe
- Edge:
- ======
- Edge HomeButtonPage: HKU\S-1-5-21-4065172224-1480893673-3259940331-1011 -> hxxp://www.google.com/
- FireFox:
- ========
- FF DefaultProfile: 01nb2njy.default
- FF ProfilePath: C:\Users\Wasted Time\AppData\Roaming\Mozilla\Firefox\Profiles\01nb2njy.default [2016-12-18]
- FF Homepage: Mozilla\Firefox\Profiles\01nb2njy.default -> hxxps://google.com
- FF Extension: (Adguard AdBlocker) - C:\Users\Wasted Time\AppData\Roaming\Mozilla\Firefox\Profiles\01nb2njy.default\Extensions\adguardadblocker@adguard.com.xpi [2016-10-27]
- FF Extension: (Long URL Please) - C:\Users\Wasted Time\AppData\Roaming\Mozilla\Firefox\Profiles\01nb2njy.default\Extensions\longurlplease@darragh.curran.xpi [2016-09-18]
- FF HKLM-x32\...\Firefox\Extensions: [{BBB77B49-9FF4-4d5c-8FE2-92B1D6CD696C}] - C:\Program Files\Trend Micro\AMSP\module\20013\FxExt\firefoxextension => not found
- FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_186.dll [2016-12-13] ()
- FF Plugin: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2016-11-23] (LastPass)
- FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
- FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-06-08] (Adobe Systems)
- FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_24_0_0_186.dll [2016-12-13] ()
- FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
- FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
- FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-07-11] (Oracle Corporation)
- FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-07-11] (Oracle Corporation)
- FF Plugin-x32: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2016-11-23] (LastPass)
- FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
- FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-07-27] (Microsoft Corporation)
- FF Plugin-x32: @nexon.net/NxGame -> C:\ProgramData\NexonUS\NGM\npNxGameUS.dll [No File]
- FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2013-08-30] (Pando Networks)
- FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
- FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
- FF Plugin-x32: @virtools.com/3DviaPlayer -> C:\Program Files (x86)\Virtools\3D Life Player\npvirtools.dll [2012-04-05] (Dassault Systèmes)
- FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2012-09-23] (Adobe Systems Inc.)
- FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-06-08] (Adobe Systems)
- FF Plugin HKU\S-1-5-21-4065172224-1480893673-3259940331-1011: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Wasted Time\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-05-08] (Unity Technologies ApS)
- Chrome:
- =======
- CHR DefaultSearchKeyword: Default -> lp
- CHR Profile: C:\Users\Wasted Time\AppData\Local\Google\Chrome\User Data\Default [2016-12-14]
- CHR Extension: (Google Slides) - C:\Users\Wasted Time\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-03-19]
- CHR Extension: (BetterTTV) - C:\Users\Wasted Time\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajopnjidmegmdimjlfnijceegpefgped [2016-06-04]
- CHR Extension: (TechSmith Snagit (Extension)) - C:\Users\Wasted Time\AppData\Local\Google\Chrome\User Data\Default\Extensions\annopcfmbiofommjmcmcfmhklhgbhkce [2016-05-12]
- CHR Extension: (Google Docs) - C:\Users\Wasted Time\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-03-19]
- CHR Extension: (Google Drive) - C:\Users\Wasted Time\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-03-19]
- CHR Extension: (Adguard AdBlocker) - C:\Users\Wasted Time\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg [2016-12-13]
- CHR Extension: (YouTube) - C:\Users\Wasted Time\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-03-19]
- CHR Extension: (Slinky Elegant) - C:\Users\Wasted Time\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmanlajnpdncmhfkiccmbgeocgbncfln [2016-03-20]
- CHR Extension: (Black Menu for Google™) - C:\Users\Wasted Time\AppData\Local\Google\Chrome\User Data\Default\Extensions\eignhdfgaldabilaaegmdfbajngjmoke [2016-12-13]
- CHR Extension: (Gmail Offline) - C:\Users\Wasted Time\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk [2016-03-19]
- CHR Extension: (Google Sheets) - C:\Users\Wasted Time\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-03-19]
- CHR Extension: (Google Docs Offline) - C:\Users\Wasted Time\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-20]
- CHR Extension: (AdBlock) - C:\Users\Wasted Time\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-12-13]
- CHR Extension: (Grammarly for Chrome) - C:\Users\Wasted Time\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2016-12-13]
- CHR Extension: (Momentum) - C:\Users\Wasted Time\AppData\Local\Google\Chrome\User Data\Default\Extensions\laookkfknpbbblfpciffpaejjkokdgca [2016-12-13]
- CHR Extension: (Google Dictionary (by Google)) - C:\Users\Wasted Time\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2016-04-19]
- CHR Extension: (Chrome Web Store Payments) - C:\Users\Wasted Time\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-01]
- CHR Extension: (Browsec VPN - Privacy and Security Online) - C:\Users\Wasted Time\AppData\Local\Google\Chrome\User Data\Default\Extensions\omghfjlpggmjjaagoclmmobgdodcjboh [2016-12-13]
- CHR Extension: (Gmail) - C:\Users\Wasted Time\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-03-19]
- CHR Extension: (Chrome Media Router) - C:\Users\Wasted Time\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-13]
- CHR HKLM\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - hxxp://clients2.google.com/service/update2/crx
- CHR HKLM-x32\...\Chrome\Extension: [fmgckcapmffomaifonnhgkfdgljnkpgi] - C:\Program Files\Trend Micro\AMSP\module\20013\ChromeExt\chromeextension\TmOspreychromeExt.crx <not found>
- CHR HKLM-x32\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - hxxp://clients2.google.com/service/update2/crx
- Opera:
- =======
- OPR Extension: (Adguard AdBlocker) - C:\Users\Wasted Time\AppData\Roaming\Opera Software\Opera Stable\Extensions\bopfaehpakahokaelnomggbohfbimcia [2016-12-09]
- OPR Extension: (SurfEasy Proxy, an Opera Software Company) - C:\Users\Wasted Time\AppData\Roaming\Opera Software\Opera Stable\Extensions\ebpielhlnnpkiddeeacoephkilopgblc [2016-10-31]
- OPR Extension: (LastPass: Free Password Manager) - C:\Users\Wasted Time\AppData\Roaming\Opera Software\Opera Stable\Extensions\hnjalnkldgigidggphhmacmimbdlafdo [2016-11-23]
- ==================== Services (Whitelisted) ====================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [737984 2016-06-03] (Adobe Systems Incorporated)
- R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2218712 2016-12-13] (Adobe Systems, Incorporated)
- S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1447944 2016-12-16] ()
- R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1593976 2012-09-04] (Samsung Electronics CO., LTD.)
- S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [249104 2016-11-25] (EasyAntiCheat Ltd)
- S3 ESRV_SVC_WILLAMETTE; C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe [416408 2016-06-08] ()
- R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [337888 2016-10-24] (Intel Corporation)
- R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
- R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [193144 2015-11-20] (Logitech Inc.)
- R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4317648 2016-11-29] (Malwarebytes)
- R2 NETGEARGenieDaemon; C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe [231752 2012-09-25] (NETGEAR)
- R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [187824 2016-07-19] ()
- R2 RzSurroundVADStreamingService; C:\ProgramData\Razer\Synapse\Devices\Razer Surround\Driver\RzSurroundVADStreamingService.exe [4255232 2016-02-15] (A-Volute) [File not signed]
- R2 SystemUsageReportSvc_WILLAMETTE; C:\Program Files (x86)\Intel Driver Update Utility\SUR\SurSvc.exe [117400 2016-06-08] ()
- R2 TorchCrashHandler; C:\Users\Exepe_000\AppData\Local\Torch\Update\TorchCrashHandler.exe [1217400 2015-12-26] (TorchMedia Inc.) <==== ATTENTION
- S3 USER_ESRV_SVC_WILLAMETTE; C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe [416408 2016-06-08] ()
- S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
- S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
- R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-08-10] (Atheros) [File not signed]
- ===================== Drivers (Whitelisted) ======================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- R1 CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-24] (CyberLink)
- R3 i8042HDR; C:\WINDOWS\system32\DRIVERS\i8042HDR.sys [15920 2009-08-14] (Windows (R) Codename Longhorn DDK provider)
- R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech)
- R3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore.sys [68384 2015-06-10] (Logitech Inc.)
- R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [176064 2016-12-19] (Malwarebytes)
- S3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [43968 2016-12-19] (Malwarebytes)
- R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [250816 2016-12-19] (Malwarebytes)
- S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
- R2 NPF; C:\windows\system32\drivers\npf.sys [35344 2012-11-19] (CACE Technologies, Inc.)
- R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2016-07-16] (Realtek )
- R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [44144 2016-05-06] (Razer, Inc.)
- R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [136312 2016-06-27] (Razer, Inc.)
- R3 RZSURROUNDVADService; C:\WINDOWS\system32\drivers\RzSurroundVAD.sys [40640 2016-02-15] (Windows (R) Win 7 DDK provider)
- S3 semav6msr64; C:\WINDOWS\system32\drivers\semav6msr64.sys [21984 2015-06-04] ()
- S0 tmel; C:\WINDOWS\System32\DRIVERS\tmel.sys [37904 2013-07-10] (Trend Micro Inc.)
- R2 tmusa; C:\WINDOWS\system32\DRIVERS\tmusa.sys [103712 2013-07-07] (Trend Micro Inc.)
- S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
- S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
- S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
- U3 WMPNetworkSvc; no ImagePath
- ==================== NetSvcs (Whitelisted) ===================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- ==================== One Month Created files and folders ========
- (If an entry is included in the fixlist, the file/folder will be moved.)
- 2016-12-19 17:16 - 2016-12-19 17:19 - 00027785 _____ C:\Users\Wasted Time\Downloads\FRST.txt
- 2016-12-19 17:15 - 2016-12-19 17:16 - 00000000 ____D C:\FRST
- 2016-12-19 17:15 - 2016-12-19 17:15 - 02420224 _____ (Farbar) C:\Users\Wasted Time\Downloads\FRST64.exe
- 2016-12-19 17:14 - 2016-12-19 17:14 - 01762304 _____ (Farbar) C:\Users\Wasted Time\Downloads\FRST.exe
- 2016-12-19 17:04 - 2016-12-19 17:04 - 17175976 _____ (Bandisoft) C:\Users\Wasted Time\Downloads\bdcamsetup.exe
- 2016-12-19 16:46 - 2016-12-19 16:49 - 00000000 ____D C:\Users\Wasted Time\AppData\Roaming\discord
- 2016-12-19 16:46 - 2016-12-19 16:46 - 00000000 ____D C:\Users\Wasted Time\AppData\Roaming\discordptb
- 2016-12-19 16:26 - 2016-12-19 16:26 - 00000000 ____D C:\ProgramData\Wasted Time
- 2016-12-18 02:19 - 2016-12-18 02:19 - 00250816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\061507B3.sys
- 2016-12-17 17:48 - 2016-12-19 16:41 - 00176064 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
- 2016-12-17 17:46 - 2016-12-19 16:41 - 00102856 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
- 2016-12-17 17:46 - 2016-12-19 16:41 - 00091584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
- 2016-12-17 17:46 - 2016-12-19 16:41 - 00043968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
- 2016-12-17 17:45 - 2016-12-19 16:41 - 00250816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
- 2016-12-17 17:45 - 2016-12-17 17:45 - 00001912 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
- 2016-12-17 17:45 - 2016-12-17 17:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
- 2016-12-17 17:45 - 2016-12-17 17:45 - 00000000 ____D C:\Program Files\Malwarebytes
- 2016-12-17 17:45 - 2016-11-29 06:27 - 00077408 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
- 2016-12-17 17:43 - 2016-12-17 17:43 - 51969976 _____ (Malwarebytes ) C:\Users\Wasted Time\Downloads\mb3-setup-consumer-3.0.4.1269.exe
- 2016-12-17 08:54 - 2016-12-19 16:27 - 00002059 _____ C:\Users\Wasted Time\Desktop\Discord.lnk
- 2016-12-17 08:53 - 2016-12-19 15:16 - 00000000 ____D C:\Users\Wasted Time\AppData\Local\Discord
- 2016-12-16 17:29 - 2016-12-16 17:29 - 00000000 ____D C:\Users\Wasted Time\AppData\Local\Chromium
- 2016-12-15 15:53 - 2016-12-15 15:53 - 00003294 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
- 2016-12-15 05:39 - 2016-12-15 05:39 - 00000000 ____D C:\WINDOWS\Minidump
- 2016-12-13 15:59 - 2016-12-16 22:37 - 00000000 ____D C:\Users\Wasted Time\AppData\Local\DiscordPTB
- 2016-12-10 13:44 - 2016-12-10 13:44 - 00000222 _____ C:\Users\Cyemonkey\Desktop\Don't Starve Together.url
- 2016-12-09 06:22 - 2016-11-11 05:22 - 00590960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
- 2016-12-09 06:22 - 2016-11-11 05:14 - 00603488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
- 2016-12-09 06:22 - 2016-11-11 05:13 - 01886344 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
- 2016-12-09 06:22 - 2016-11-11 05:13 - 00352096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
- 2016-12-09 06:22 - 2016-11-11 05:03 - 01069720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
- 2016-12-09 06:22 - 2016-11-11 05:03 - 00266544 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
- 2016-12-09 06:22 - 2016-11-11 05:01 - 01859264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
- 2016-12-09 06:22 - 2016-11-11 05:01 - 01293152 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
- 2016-12-09 06:22 - 2016-11-11 04:57 - 22224480 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
- 2016-12-09 06:22 - 2016-11-11 04:56 - 00534096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
- 2016-12-09 06:22 - 2016-11-11 04:56 - 00424616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
- 2016-12-09 06:22 - 2016-11-11 04:56 - 00163752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTWorkQ.dll
- 2016-12-09 06:22 - 2016-11-11 04:29 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
- 2016-12-09 06:22 - 2016-11-11 04:26 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
- 2016-12-09 06:22 - 2016-11-11 04:26 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReportingCSP.dll
- 2016-12-09 06:22 - 2016-11-11 04:25 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
- 2016-12-09 06:22 - 2016-11-11 04:24 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
- 2016-12-09 06:22 - 2016-11-11 04:24 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
- 2016-12-09 06:22 - 2016-11-11 04:23 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\EAMProgressHandler.dll
- 2016-12-09 06:22 - 2016-11-11 04:22 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
- 2016-12-09 06:22 - 2016-11-11 04:22 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\EDPCleanup.exe
- 2016-12-09 06:22 - 2016-11-11 04:21 - 00748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
- 2016-12-09 06:22 - 2016-11-11 04:21 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
- 2016-12-09 06:22 - 2016-11-11 04:21 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
- 2016-12-09 06:22 - 2016-11-11 04:20 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
- 2016-12-09 06:22 - 2016-11-11 04:20 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
- 2016-12-09 06:22 - 2016-11-11 04:20 - 00260608 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
- 2016-12-09 06:22 - 2016-11-11 04:20 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
- 2016-12-09 06:22 - 2016-11-11 04:19 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
- 2016-12-09 06:22 - 2016-11-11 04:19 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
- 2016-12-09 06:22 - 2016-11-11 04:19 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll
- 2016-12-09 06:22 - 2016-11-11 04:18 - 17188352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
- 2016-12-09 06:22 - 2016-11-11 04:18 - 00967168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
- 2016-12-09 06:22 - 2016-11-11 04:17 - 01004032 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
- 2016-12-09 06:22 - 2016-11-11 04:14 - 00615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
- 2016-12-09 06:22 - 2016-11-11 04:13 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcuiu.dll
- 2016-12-09 06:22 - 2016-11-11 04:11 - 00942080 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
- 2016-12-09 06:22 - 2016-11-11 04:11 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
- 2016-12-09 06:22 - 2016-11-11 04:08 - 00539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
- 2016-12-09 06:22 - 2016-11-11 04:07 - 00347648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
- 2016-12-09 06:22 - 2016-11-11 04:06 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
- 2016-12-09 06:22 - 2016-11-11 04:04 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll
- 2016-12-09 06:22 - 2016-11-11 04:04 - 01232384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
- 2016-12-09 06:22 - 2016-11-11 04:04 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
- 2016-12-09 06:22 - 2016-11-11 04:03 - 00842240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
- 2016-12-09 06:22 - 2016-11-11 02:49 - 00263472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
- 2016-12-09 06:22 - 2016-11-11 02:48 - 02277248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
- 2016-12-09 06:22 - 2016-11-11 02:47 - 00527880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
- 2016-12-09 06:22 - 2016-11-11 02:42 - 03892864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
- 2016-12-09 06:22 - 2016-11-11 02:42 - 01852720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
- 2016-12-09 06:22 - 2016-11-11 02:42 - 01123912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
- 2016-12-09 06:22 - 2016-11-11 02:42 - 00952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
- 2016-12-09 06:22 - 2016-11-11 02:42 - 00091936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfaudiocnv.dll
- 2016-12-09 06:22 - 2016-11-11 02:23 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll
- 2016-12-09 06:22 - 2016-11-11 02:19 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
- 2016-12-09 06:22 - 2016-11-11 02:19 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll
- 2016-12-09 06:22 - 2016-11-11 02:19 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll
- 2016-12-09 06:22 - 2016-11-11 02:18 - 02333184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
- 2016-12-09 06:22 - 2016-11-11 02:17 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe
- 2016-12-09 06:22 - 2016-11-11 02:15 - 04612608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
- 2016-12-09 06:22 - 2016-11-11 02:15 - 01357824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
- 2016-12-09 06:22 - 2016-11-11 02:11 - 03306496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
- 2016-12-09 06:22 - 2016-11-11 02:09 - 00545280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
- 2016-12-09 06:22 - 2016-11-11 02:05 - 03370496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
- 2016-12-09 06:22 - 2016-11-11 02:04 - 02682880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll
- 2016-12-09 06:22 - 2016-11-11 02:04 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
- 2016-12-09 06:22 - 2016-11-11 02:03 - 00760832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
- 2016-12-09 06:21 - 2016-11-11 05:15 - 00198856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
- 2016-12-09 06:21 - 2016-11-11 05:15 - 00101216 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceReactivation.dll
- 2016-12-09 06:21 - 2016-11-11 05:14 - 02482280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
- 2016-12-09 06:21 - 2016-11-11 05:14 - 02186896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
- 2016-12-09 06:21 - 2016-11-11 05:13 - 07816032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
- 2016-12-09 06:21 - 2016-11-11 05:13 - 02213760 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
- 2016-12-09 06:21 - 2016-11-11 05:12 - 00128352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
- 2016-12-09 06:21 - 2016-11-11 05:10 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll
- 2016-12-09 06:21 - 2016-11-11 05:09 - 00764392 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
- 2016-12-09 06:21 - 2016-11-11 05:08 - 00142176 _____ (Microsoft Corporation) C:\WINDOWS\system32\migisol.dll
- 2016-12-09 06:21 - 2016-11-11 05:03 - 00328008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
- 2016-12-09 06:21 - 2016-11-11 05:02 - 02828376 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
- 2016-12-09 06:21 - 2016-11-11 05:02 - 00360040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
- 2016-12-09 06:21 - 2016-11-11 05:01 - 07219672 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
- 2016-12-09 06:21 - 2016-11-11 05:01 - 00637400 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
- 2016-12-09 06:21 - 2016-11-11 05:00 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
- 2016-12-09 06:21 - 2016-11-11 05:00 - 00219488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
- 2016-12-09 06:21 - 2016-11-11 04:59 - 02913136 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
- 2016-12-09 06:21 - 2016-11-11 04:59 - 01267512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
- 2016-12-09 06:21 - 2016-11-11 04:57 - 08170048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
- 2016-12-09 06:21 - 2016-11-11 04:57 - 04130432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
- 2016-12-09 06:21 - 2016-11-11 04:57 - 01988560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
- 2016-12-09 06:21 - 2016-11-11 04:57 - 01473048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
- 2016-12-09 06:21 - 2016-11-11 04:56 - 01274712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
- 2016-12-09 06:21 - 2016-11-11 04:56 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
- 2016-12-09 06:21 - 2016-11-11 04:56 - 00418952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
- 2016-12-09 06:21 - 2016-11-11 04:56 - 00241496 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
- 2016-12-09 06:21 - 2016-11-11 04:56 - 00187520 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudStorageWizard.exe
- 2016-12-09 06:21 - 2016-11-11 04:56 - 00126568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfaudiocnv.dll
- 2016-12-09 06:21 - 2016-11-11 04:55 - 01600624 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
- 2016-12-09 06:21 - 2016-11-11 04:55 - 00882680 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
- 2016-12-09 06:21 - 2016-11-11 04:55 - 00743224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
- 2016-12-09 06:21 - 2016-11-11 04:54 - 01418312 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
- 2016-12-09 06:21 - 2016-11-11 04:51 - 00454592 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
- 2016-12-09 06:21 - 2016-11-11 04:31 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
- 2016-12-09 06:21 - 2016-11-11 04:27 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
- 2016-12-09 06:21 - 2016-11-11 04:27 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
- 2016-12-09 06:21 - 2016-11-11 04:27 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpremove.exe
- 2016-12-09 06:21 - 2016-11-11 04:26 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
- 2016-12-09 06:21 - 2016-11-11 04:26 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\modem.sys
- 2016-12-09 06:21 - 2016-11-11 04:26 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgentc.exe
- 2016-12-09 06:21 - 2016-11-11 04:25 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\BcastDVRHelper.dll
- 2016-12-09 06:21 - 2016-11-11 04:25 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
- 2016-12-09 06:21 - 2016-11-11 04:25 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
- 2016-12-09 06:21 - 2016-11-11 04:25 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
- 2016-12-09 06:21 - 2016-11-11 04:24 - 00170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
- 2016-12-09 06:21 - 2016-11-11 04:24 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
- 2016-12-09 06:21 - 2016-11-11 04:24 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
- 2016-12-09 06:21 - 2016-11-11 04:24 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
- 2016-12-09 06:21 - 2016-11-11 04:24 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
- 2016-12-09 06:21 - 2016-11-11 04:23 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll
- 2016-12-09 06:21 - 2016-11-11 04:23 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
- 2016-12-09 06:21 - 2016-11-11 04:23 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
- 2016-12-09 06:21 - 2016-11-11 04:22 - 00489472 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
- 2016-12-09 06:21 - 2016-11-11 04:20 - 00657920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
- 2016-12-09 06:21 - 2016-11-11 04:20 - 00641024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
- 2016-12-09 06:21 - 2016-11-11 04:20 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
- 2016-12-09 06:21 - 2016-11-11 04:20 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
- 2016-12-09 06:21 - 2016-11-11 04:20 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupugc.exe
- 2016-12-09 06:21 - 2016-11-11 04:19 - 00620544 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
- 2016-12-09 06:21 - 2016-11-11 04:19 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
- 2016-12-09 06:21 - 2016-11-11 04:19 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
- 2016-12-09 06:21 - 2016-11-11 04:19 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
- 2016-12-09 06:21 - 2016-11-11 04:19 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
- 2016-12-09 06:21 - 2016-11-11 04:19 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
- 2016-12-09 06:21 - 2016-11-11 04:18 - 06285312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
- 2016-12-09 06:21 - 2016-11-11 04:18 - 02084352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll
- 2016-12-09 06:21 - 2016-11-11 04:18 - 00425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
- 2016-12-09 06:21 - 2016-11-11 04:18 - 00411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
- 2016-12-09 06:21 - 2016-11-11 04:18 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll
- 2016-12-09 06:21 - 2016-11-11 04:17 - 01220096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl
- 2016-12-09 06:21 - 2016-11-11 04:17 - 01002496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
- 2016-12-09 06:21 - 2016-11-11 04:17 - 00956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
- 2016-12-09 06:21 - 2016-11-11 04:17 - 00410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
- 2016-12-09 06:21 - 2016-11-11 04:17 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll
- 2016-12-09 06:21 - 2016-11-11 04:16 - 01477632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
- 2016-12-09 06:21 - 2016-11-11 04:16 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
- 2016-12-09 06:21 - 2016-11-11 04:16 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
- 2016-12-09 06:21 - 2016-11-11 04:16 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll
- 2016-12-09 06:21 - 2016-11-11 04:16 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\RjvMDMConfig.dll
- 2016-12-09 06:21 - 2016-11-11 04:15 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscinterop.dll
- 2016-12-09 06:21 - 2016-11-11 04:14 - 03777536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
- 2016-12-09 06:21 - 2016-11-11 04:14 - 02104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
- 2016-12-09 06:21 - 2016-11-11 04:14 - 01589760 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
- 2016-12-09 06:21 - 2016-11-11 04:14 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
- 2016-12-09 06:21 - 2016-11-11 04:14 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppnp.dll
- 2016-12-09 06:21 - 2016-11-11 04:13 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
- 2016-12-09 06:21 - 2016-11-11 04:12 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcprx.dll
- 2016-12-09 06:21 - 2016-11-11 04:11 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
- 2016-12-09 06:21 - 2016-11-11 04:10 - 13084160 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
- 2016-12-09 06:21 - 2016-11-11 04:09 - 05111296 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
- 2016-12-09 06:21 - 2016-11-11 04:09 - 01366016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
- 2016-12-09 06:21 - 2016-11-11 04:09 - 00164352 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll
- 2016-12-09 06:21 - 2016-11-11 04:08 - 00981504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
- 2016-12-09 06:21 - 2016-11-11 04:07 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
- 2016-12-09 06:21 - 2016-11-11 04:07 - 02009600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
- 2016-12-09 06:21 - 2016-11-11 04:07 - 01692672 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
- 2016-12-09 06:21 - 2016-11-11 04:07 - 01691136 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
- 2016-12-09 06:21 - 2016-11-11 04:07 - 00991232 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
- 2016-12-09 06:21 - 2016-11-11 04:06 - 02275840 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
- 2016-12-09 06:21 - 2016-11-11 04:06 - 00960000 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
- 2016-12-09 06:21 - 2016-11-11 04:05 - 04136448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
- 2016-12-09 06:21 - 2016-11-11 04:05 - 02852864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
- 2016-12-09 06:21 - 2016-11-11 04:05 - 01490944 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
- 2016-12-09 06:21 - 2016-11-11 04:05 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
- 2016-12-09 06:21 - 2016-11-11 04:04 - 04746752 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
- 2016-12-09 06:21 - 2016-11-11 04:04 - 02688512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
- 2016-12-09 06:21 - 2016-11-11 04:04 - 01359360 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
- 2016-12-09 06:21 - 2016-11-11 04:04 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
- 2016-12-09 06:21 - 2016-11-11 04:04 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll
- 2016-12-09 06:21 - 2016-11-11 04:04 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
- 2016-12-09 06:21 - 2016-11-11 04:03 - 04708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
- 2016-12-09 06:21 - 2016-11-11 04:03 - 03616768 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
- 2016-12-09 06:21 - 2016-11-11 04:03 - 02287616 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
- 2016-12-09 06:21 - 2016-11-11 04:03 - 00717824 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
- 2016-12-09 06:21 - 2016-11-11 04:03 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
- 2016-12-09 06:21 - 2016-11-11 04:03 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
- 2016-12-09 06:21 - 2016-11-11 04:03 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll
- 2016-12-09 06:21 - 2016-11-11 04:03 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
- 2016-12-09 06:21 - 2016-11-11 04:02 - 03542016 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
- 2016-12-09 06:21 - 2016-11-11 04:02 - 01726976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
- 2016-12-09 06:21 - 2016-11-11 04:01 - 01107456 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
- 2016-12-09 06:21 - 2016-11-11 03:39 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
- 2016-12-09 06:21 - 2016-11-11 03:00 - 01706488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
- 2016-12-09 06:21 - 2016-11-11 02:59 - 01572768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
- 2016-12-09 06:21 - 2016-11-11 02:56 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
- 2016-12-09 06:21 - 2016-11-11 02:54 - 00122208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\migisol.dll
- 2016-12-09 06:21 - 2016-11-11 02:49 - 00869848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
- 2016-12-09 06:21 - 2016-11-11 02:49 - 00248480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
- 2016-12-09 06:21 - 2016-11-11 02:47 - 05722832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
- 2016-12-09 06:21 - 2016-11-11 02:47 - 01503032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
- 2016-12-09 06:21 - 2016-11-11 02:47 - 01430720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
- 2016-12-09 06:21 - 2016-11-11 02:47 - 00861024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
- 2016-12-09 06:21 - 2016-11-11 02:45 - 02166752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
- 2016-12-09 06:21 - 2016-11-11 02:45 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
- 2016-12-09 06:21 - 2016-11-11 02:42 - 06668032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
- 2016-12-09 06:21 - 2016-11-11 02:42 - 00959112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
- 2016-12-09 06:21 - 2016-11-11 02:42 - 00382784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
- 2016-12-09 06:21 - 2016-11-11 02:42 - 00374448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
- 2016-12-09 06:21 - 2016-11-11 02:42 - 00152416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTWorkQ.dll
- 2016-12-09 06:21 - 2016-11-11 02:41 - 04311736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
- 2016-12-09 06:21 - 2016-11-11 02:41 - 00157536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudStorageWizard.exe
- 2016-12-09 06:21 - 2016-11-11 02:38 - 01263856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
- 2016-12-09 06:21 - 2016-11-11 02:28 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
- 2016-12-09 06:21 - 2016-11-11 02:27 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetCfgNotifyObjectHost.exe
- 2016-12-09 06:21 - 2016-11-11 02:27 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
- 2016-12-09 06:21 - 2016-11-11 02:26 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
- 2016-12-09 06:21 - 2016-11-11 02:26 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgentc.exe
- 2016-12-09 06:21 - 2016-11-11 02:25 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
- 2016-12-09 06:21 - 2016-11-11 02:25 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
- 2016-12-09 06:21 - 2016-11-11 02:24 - 00519168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll
- 2016-12-09 06:21 - 2016-11-11 02:24 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BcastDVRHelper.dll
- 2016-12-09 06:21 - 2016-11-11 02:24 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
- 2016-12-09 06:21 - 2016-11-11 02:24 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll
- 2016-12-09 06:21 - 2016-11-11 02:23 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
- 2016-12-09 06:21 - 2016-11-11 02:22 - 00505856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
- 2016-12-09 06:21 - 2016-11-11 02:22 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll
- 2016-12-09 06:21 - 2016-11-11 02:21 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
- 2016-12-09 06:21 - 2016-11-11 02:21 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
- 2016-12-09 06:21 - 2016-11-11 02:21 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
- 2016-12-09 06:21 - 2016-11-11 02:20 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
- 2016-12-09 06:21 - 2016-11-11 02:20 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
- 2016-12-09 06:21 - 2016-11-11 02:20 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
- 2016-12-09 06:21 - 2016-11-11 02:20 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe
- 2016-12-09 06:21 - 2016-11-11 02:19 - 13868544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
- 2016-12-09 06:21 - 2016-11-11 02:19 - 01755136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll
- 2016-12-09 06:21 - 2016-11-11 02:19 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll
- 2016-12-09 06:21 - 2016-11-11 02:19 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
- 2016-12-09 06:21 - 2016-11-11 02:19 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
- 2016-12-09 06:21 - 2016-11-11 02:19 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupugc.exe
- 2016-12-09 06:21 - 2016-11-11 02:18 - 01336320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
- 2016-12-09 06:21 - 2016-11-11 02:18 - 01196544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl
- 2016-12-09 06:21 - 2016-11-11 02:18 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
- 2016-12-09 06:21 - 2016-11-11 02:18 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
- 2016-12-09 06:21 - 2016-11-11 02:17 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
- 2016-12-09 06:21 - 2016-11-11 02:16 - 19415552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
- 2016-12-09 06:21 - 2016-11-11 02:16 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll
- 2016-12-09 06:21 - 2016-11-11 02:15 - 07626752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
- 2016-12-09 06:21 - 2016-11-11 02:15 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
- 2016-12-09 06:21 - 2016-11-11 02:15 - 00348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
- 2016-12-09 06:21 - 2016-11-11 02:15 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
- 2016-12-09 06:21 - 2016-11-11 02:14 - 19415552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
- 2016-12-09 06:21 - 2016-11-11 02:14 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
- 2016-12-09 06:21 - 2016-11-11 02:13 - 00499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
- 2016-12-09 06:21 - 2016-11-11 02:13 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
- 2016-12-09 06:21 - 2016-11-11 02:12 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcuiu.dll
- 2016-12-09 06:21 - 2016-11-11 02:10 - 12177920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
- 2016-12-09 06:21 - 2016-11-11 02:10 - 06109184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
- 2016-12-09 06:21 - 2016-11-11 02:10 - 00746496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcprx.dll
- 2016-12-09 06:21 - 2016-11-11 02:09 - 05380608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
- 2016-12-09 06:21 - 2016-11-11 02:09 - 03196416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
- 2016-12-09 06:21 - 2016-11-11 02:08 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xolehlp.dll
- 2016-12-09 06:21 - 2016-11-11 02:06 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
- 2016-12-09 06:21 - 2016-11-11 02:06 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
- 2016-12-09 06:21 - 2016-11-11 02:06 - 02362880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll
- 2016-12-09 06:21 - 2016-11-11 02:06 - 02109952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll
- 2016-12-09 06:21 - 2016-11-11 02:06 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll
- 2016-12-09 06:21 - 2016-11-11 02:06 - 00807424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll
- 2016-12-09 06:21 - 2016-11-11 02:06 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
- 2016-12-09 06:21 - 2016-11-11 02:06 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxclu.dll
- 2016-12-09 06:21 - 2016-11-11 02:05 - 06044160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
- 2016-12-09 06:21 - 2016-11-11 02:05 - 04423680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
- 2016-12-09 06:21 - 2016-11-11 02:04 - 01992704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
- 2016-12-09 06:21 - 2016-11-11 02:04 - 01880576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
- 2016-12-09 06:21 - 2016-11-11 02:04 - 01595392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
- 2016-12-09 06:21 - 2016-11-11 02:04 - 00912896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
- 2016-12-09 06:21 - 2016-11-11 02:04 - 00873472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
- 2016-12-09 06:21 - 2016-11-11 02:04 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll
- 2016-12-09 06:21 - 2016-11-11 02:03 - 02484736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll
- 2016-12-09 06:21 - 2016-11-11 02:03 - 02256384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
- 2016-12-09 06:21 - 2016-11-11 02:03 - 01576448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
- 2016-12-09 06:21 - 2016-11-11 02:03 - 01556480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
- 2016-12-09 06:21 - 2016-11-11 02:03 - 00565248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
- 2016-12-09 06:21 - 2016-11-11 02:02 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
- 2016-12-09 06:21 - 2016-11-11 02:01 - 02998272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
- 2016-12-09 06:21 - 2016-11-11 01:40 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
- 2016-12-09 06:20 - 2016-11-11 05:01 - 02189152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
- 2016-12-09 06:20 - 2016-11-11 05:01 - 01738048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
- 2016-12-09 06:20 - 2016-11-11 05:01 - 00658264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
- 2016-12-09 06:20 - 2016-11-11 05:01 - 00401760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
- 2016-12-09 06:20 - 2016-11-11 05:00 - 00223584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
- 2016-12-09 06:20 - 2016-11-11 04:59 - 00433504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
- 2016-12-09 06:20 - 2016-11-11 04:56 - 04673304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
- 2016-12-09 06:20 - 2016-11-11 04:51 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
- 2016-12-09 06:20 - 2016-11-11 04:31 - 22563840 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
- 2016-12-09 06:20 - 2016-11-11 04:28 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
- 2016-12-09 06:20 - 2016-11-11 04:28 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CbtBackgroundManagerPolicy.dll
- 2016-12-09 06:20 - 2016-11-11 04:25 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
- 2016-12-09 06:20 - 2016-11-11 04:25 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
- 2016-12-09 06:20 - 2016-11-11 04:24 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
- 2016-12-09 06:20 - 2016-11-11 04:24 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll
- 2016-12-09 06:20 - 2016-11-11 04:23 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
- 2016-12-09 06:20 - 2016-11-11 04:22 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
- 2016-12-09 06:20 - 2016-11-11 04:21 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
- 2016-12-09 06:20 - 2016-11-11 04:21 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
- 2016-12-09 06:20 - 2016-11-11 04:21 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
- 2016-12-09 06:20 - 2016-11-11 04:20 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
- 2016-12-09 06:20 - 2016-11-11 04:20 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
- 2016-12-09 06:20 - 2016-11-11 04:20 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll
- 2016-12-09 06:20 - 2016-11-11 04:20 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
- 2016-12-09 06:20 - 2016-11-11 04:20 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll
- 2016-12-09 06:20 - 2016-11-11 04:19 - 09131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
- 2016-12-09 06:20 - 2016-11-11 04:19 - 00388096 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
- 2016-12-09 06:20 - 2016-11-11 04:16 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
- 2016-12-09 06:20 - 2016-11-11 04:15 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe
- 2016-12-09 06:20 - 2016-11-11 04:14 - 07654400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
- 2016-12-09 06:20 - 2016-11-11 04:13 - 07812096 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
- 2016-12-09 06:20 - 2016-11-11 04:11 - 23678464 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
- 2016-12-09 06:20 - 2016-11-11 04:11 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpoext.dll
- 2016-12-09 06:20 - 2016-11-11 04:10 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
- 2016-12-09 06:20 - 2016-11-11 04:08 - 08127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
- 2016-12-09 06:20 - 2016-11-11 04:07 - 03441152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
- 2016-12-09 06:20 - 2016-11-11 04:07 - 02953216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
- 2016-12-09 06:20 - 2016-11-11 04:07 - 01060864 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
- 2016-12-09 06:20 - 2016-11-11 04:06 - 03400192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll
- 2016-12-09 06:20 - 2016-11-11 04:05 - 01779712 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
- 2016-12-09 06:20 - 2016-11-11 04:05 - 01031680 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
- 2016-12-09 06:20 - 2016-11-11 04:04 - 06664192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
- 2016-12-09 06:20 - 2016-11-11 04:04 - 02611200 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll
- 2016-12-09 06:20 - 2016-11-11 04:04 - 02317312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
- 2016-12-09 06:20 - 2016-11-11 04:04 - 01709056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
- 2016-12-09 06:20 - 2016-11-11 04:04 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
- 2016-12-09 06:20 - 2016-11-11 04:03 - 02669056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
- 2016-12-09 06:20 - 2016-11-11 04:03 - 01513472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
- 2016-12-09 06:20 - 2016-11-11 04:03 - 00905216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
- 2016-12-09 06:20 - 2016-11-11 04:03 - 00632320 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
- 2016-12-09 06:20 - 2016-11-11 04:02 - 00936448 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
- 2016-12-09 06:20 - 2016-11-11 04:02 - 00730112 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
- 2016-12-09 06:20 - 2016-11-11 03:01 - 02206496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
- 2016-12-09 06:20 - 2016-11-11 03:01 - 01969912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll
- 2016-12-09 06:20 - 2016-11-11 03:01 - 00167848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll
- 2016-12-09 06:20 - 2016-11-11 02:42 - 20969928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
- 2016-12-09 06:20 - 2016-11-11 02:20 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
- 2016-12-09 06:20 - 2016-11-11 02:18 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscinterop.dll
- 2016-12-09 06:20 - 2016-11-11 02:17 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
- 2016-12-09 06:20 - 2016-11-11 02:16 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
- 2016-12-09 06:20 - 2016-11-11 02:03 - 00772608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
- 2016-12-09 06:20 - 2016-11-11 02:03 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
- 2016-12-07 05:47 - 2016-12-19 16:49 - 00000000 ____D C:\Users\Wasted Time\Documents\ShareX
- 2016-12-07 05:47 - 2016-12-07 05:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ShareX
- 2016-12-07 05:47 - 2016-12-07 05:47 - 00000000 ____D C:\Program Files\ShareX
- 2016-12-07 05:43 - 2016-12-07 05:46 - 04792069 _____ (ShareX Team ) C:\Users\Wasted Time\Downloads\ShareX-11.4.1-setup.exe
- 2016-12-06 21:14 - 2016-12-18 18:41 - 00000000 ____D C:\Users\Wasted Time\AppData\LocalLow\Mozilla
- 2016-12-06 20:53 - 2016-12-18 02:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
- 2016-12-04 19:12 - 2016-12-04 19:12 - 00002005 _____ C:\Users\Cyemonkey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\toast.lnk
- 2016-12-04 19:11 - 2016-12-10 17:48 - 00000000 ____D C:\Users\Cyemonkey\AppData\Local\u-launcher
- 2016-12-01 05:46 - 2016-12-01 05:46 - 00001140 _____ C:\Users\Wasted Time\Desktop\Curse.lnk
- 2016-12-01 05:46 - 2016-12-01 05:46 - 00001126 _____ C:\Users\Wasted Time\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Curse.lnk
- 2016-12-01 05:45 - 2016-12-01 05:45 - 77903520 _____ (Curse) C:\Users\Wasted Time\Documents\CurseClientSetup.exe
- 2016-11-26 20:06 - 2016-11-26 20:06 - 00000000 ____D C:\Users\Cyemonkey\AppData\Roaming\Opera Software
- 2016-11-26 20:06 - 2016-11-26 20:06 - 00000000 ____D C:\Users\Cyemonkey\AppData\Local\Opera Software
- 2016-11-25 21:32 - 2016-12-04 19:23 - 00536312 _____ C:\WINDOWS\system32\Drivers\EasyAntiCheat.sys
- 2016-11-25 21:32 - 2016-11-25 21:32 - 00000000 ____D C:\Users\Cyemonkey\AppData\Local\CrashRpt
- 2016-11-25 21:31 - 2016-11-25 20:28 - 00249104 _____ (EasyAntiCheat Ltd) C:\WINDOWS\SysWOW64\EasyAntiCheat.exe
- 2016-11-25 21:22 - 2016-12-10 13:58 - 00000000 ____D C:\ProgramData\GFACE
- 2016-11-25 21:22 - 2016-11-26 20:04 - 00000000 ____D C:\Users\Cyemonkey\AppData\Local\wf-launcher
- 2016-11-25 20:28 - 2016-11-25 20:28 - 00000222 _____ C:\Users\Cyemonkey\Desktop\Warface.url
- 2016-11-25 11:34 - 2016-11-25 11:34 - 00000000 ____D C:\Users\Cyemonkey\AppData\LocalLow\LastPass
- 2016-11-23 22:54 - 2016-11-23 22:55 - 00000000 ____D C:\Users\Wasted Time\AppData\LocalLow\LastPass
- 2016-11-23 22:54 - 2016-11-23 22:55 - 00000000 ____D C:\Program Files (x86)\LastPass
- 2016-11-23 22:54 - 2016-11-23 22:54 - 00001152 _____ C:\Users\Public\Desktop\My LastPass Vault.lnk
- 2016-11-23 22:54 - 2016-11-23 22:54 - 00000000 ____D C:\Users\Wasted Time\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass
- 2016-11-23 22:54 - 2016-11-23 22:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LastPass
- 2016-11-23 22:53 - 2016-11-23 22:53 - 21874200 _____ (LastPass) C:\Users\Wasted Time\Documents\lastpass_x64.exe
- 2016-11-21 19:21 - 2016-11-21 19:25 - 00000000 ____D C:\Users\Wasted Time\Documents\Klei
- 2016-11-20 19:35 - 2016-11-20 19:35 - 00000222 _____ C:\Users\Wasted Time\Desktop\Crypt of the NecroDancer.url
- ==================== One Month Modified files and folders ========
- (If an entry is included in the fixlist, the file/folder will be moved.)
- 2016-12-19 17:18 - 2016-03-20 07:36 - 00000000 ____D C:\Users\Wasted Time\AppData\Roaming\Curse Client
- 2016-12-19 17:16 - 2016-07-16 06:36 - 00000000 ____D C:\WINDOWS\CbsTemp
- 2016-12-19 17:06 - 2016-03-21 17:14 - 00000000 ____D C:\Users\Wasted Time\AppData\Local\Spotify
- 2016-12-19 17:02 - 2016-01-07 15:42 - 00000000 _____ C:\WINDOWS\system32\RzSurroundVADAudioDeviceManager_log.txt
- 2016-12-19 16:59 - 2012-08-24 02:31 - 00000000 ____D C:\ProgramData\WinClon
- 2016-12-19 16:50 - 2016-03-21 17:13 - 00000000 ____D C:\Users\Wasted Time\AppData\Roaming\Spotify
- 2016-12-19 16:47 - 2016-03-19 20:51 - 00000000 ____D C:\Users\Wasted Time\AppData\Local\SquirrelTemp
- 2016-12-19 16:45 - 2016-01-03 15:33 - 00000000 ____D C:\ProgramData\TorchCrashHandler
- 2016-12-19 16:44 - 2016-03-19 20:49 - 00000000 __SHD C:\Users\Wasted Time\IntelGraphicsProfiles
- 2016-12-19 16:41 - 2016-10-24 20:02 - 00000000 ____D C:\Users\Wasted Time
- 2016-12-19 16:40 - 2016-10-24 20:34 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
- 2016-12-19 16:40 - 2016-10-24 19:53 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
- 2016-12-19 16:27 - 2016-03-19 20:52 - 00000000 ____D C:\Users\Wasted Time\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hammer & Chisel, Inc
- 2016-12-19 15:18 - 2016-01-23 09:03 - 00000000 ____D C:\ProgramData\SquirrelMachineInstalls
- 2016-12-19 15:02 - 2015-08-06 16:23 - 02757714 _____ C:\WINDOWS\system32\PerfStringBackup.INI
- 2016-12-19 05:46 - 2016-06-26 14:59 - 00000000 ____D C:\Users\Wasted Time\AppData\Local\Adobe
- 2016-12-18 12:06 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\AppReadiness
- 2016-12-18 02:28 - 2016-03-06 20:12 - 00000000 ____D C:\Program Files (x86)\Steam
- 2016-12-18 02:14 - 2016-09-17 14:27 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
- 2016-12-17 17:45 - 2014-06-30 01:21 - 00000000 ____D C:\ProgramData\Malwarebytes
- 2016-12-17 11:42 - 2016-07-16 06:47 - 00000000 ___HD C:\Program Files\WindowsApps
- 2016-12-16 17:29 - 2016-03-27 15:26 - 00000000 ____D C:\Users\Wasted Time\AppData\Local\Steam
- 2016-12-16 15:09 - 2016-10-24 20:34 - 00003416 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
- 2016-12-16 15:09 - 2016-10-24 20:34 - 00003292 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
- 2016-12-16 05:50 - 2016-10-24 20:34 - 00003962 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1474140175
- 2016-12-16 05:50 - 2016-09-17 14:23 - 00001120 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
- 2016-12-16 05:50 - 2016-09-17 14:21 - 00000000 ____D C:\Program Files (x86)\Opera
- 2016-12-15 15:53 - 2016-03-19 20:53 - 00002426 _____ C:\Users\Wasted Time\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
- 2016-12-15 15:53 - 2016-03-19 20:53 - 00000000 ___RD C:\Users\Wasted Time\OneDrive
- 2016-12-15 05:39 - 2016-11-01 16:09 - 00000892 _____ C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job
- 2016-12-15 05:39 - 2015-08-10 09:45 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
- 2016-12-15 05:39 - 2014-06-25 00:48 - 580439545 _____ C:\WINDOWS\MEMORY.DMP
- 2016-12-14 19:59 - 2016-11-01 16:09 - 00003986 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
- 2016-12-14 19:59 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
- 2016-12-14 19:59 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
- 2016-12-14 16:53 - 2016-06-27 19:22 - 00000000 ____D C:\Users\Wasted Time\AppData\Roaming\.minecraft
- 2016-12-13 17:26 - 2013-08-14 10:35 - 00000000 ____D C:\WINDOWS\system32\MRT
- 2016-12-13 17:21 - 2013-03-08 12:16 - 135632432 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
- 2016-12-13 15:32 - 2016-03-19 20:40 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
- 2016-12-11 18:56 - 2016-07-16 06:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
- 2016-12-11 18:56 - 2016-07-16 06:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
- 2016-12-10 17:49 - 2016-10-24 20:02 - 00000000 ____D C:\Users\Cyemonkey
- 2016-12-10 14:49 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
- 2016-12-10 13:57 - 2016-07-05 14:14 - 00000000 ____D C:\Users\Cyemonkey\AppData\Roaming\discordptb
- 2016-12-10 13:54 - 2016-05-13 19:36 - 00000000 __SHD C:\Users\Cyemonkey\IntelGraphicsProfiles
- 2016-12-10 13:29 - 2016-05-13 19:39 - 00002343 _____ C:\Users\Cyemonkey\Desktop\Discord PTB.lnk
- 2016-12-10 13:29 - 2016-05-13 19:39 - 00000000 ____D C:\Users\Cyemonkey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hammer & Chisel, Inc
- 2016-12-10 13:29 - 2016-05-13 19:39 - 00000000 ____D C:\Users\Cyemonkey\AppData\Local\DiscordPTB
- 2016-12-10 13:26 - 2016-05-13 19:36 - 00000000 ____D C:\Users\Cyemonkey\AppData\Local\Packages
- 2016-12-10 13:25 - 2012-11-17 09:32 - 00000000 __RHD C:\Users\Public\AccountPictures
- 2016-12-10 09:38 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\rescache
- 2016-12-09 15:14 - 2016-07-16 06:45 - 00000000 ____D C:\WINDOWS\INF
- 2016-12-09 15:12 - 2016-10-24 19:52 - 00202448 _____ C:\WINDOWS\system32\FNTCACHE.DAT
- 2016-12-09 15:11 - 2016-07-16 01:04 - 01835008 _____ C:\WINDOWS\system32\config\BBI
- 2016-12-09 15:09 - 2016-07-16 06:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
- 2016-12-09 15:09 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
- 2016-12-09 15:09 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
- 2016-12-09 15:09 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\system32\oobe
- 2016-12-09 15:09 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
- 2016-12-09 15:09 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\bcastdvr
- 2016-12-09 15:09 - 2016-07-16 01:04 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
- 2016-12-09 15:09 - 2016-07-16 01:04 - 00000000 ____D C:\WINDOWS\system32\Sysprep
- 2016-12-09 15:09 - 2016-07-16 01:04 - 00000000 ____D C:\WINDOWS\system32\Dism
- 2016-12-09 15:09 - 2016-07-16 01:04 - 00000000 ____D C:\WINDOWS\servicing
- 2016-12-09 05:46 - 2016-07-16 06:42 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
- 2016-12-07 05:48 - 2016-02-17 18:24 - 00000000 ____D C:\Program Files (x86)\Skillbrains
- 2016-12-03 22:36 - 2016-07-07 18:01 - 00000000 ____D C:\Users\Cyemonkey\AppData\LocalLow\Smartly Dressed Games
- 2016-12-02 19:27 - 2016-07-17 12:41 - 00000000 ____D C:\Users\Wasted Time\Documents\Lightshot
- 2016-12-01 15:07 - 2014-07-11 22:16 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
- 2016-11-25 21:23 - 2016-05-13 19:36 - 00000000 ____D C:\Users\Cyemonkey\AppData\Local\Google
- 2016-11-21 15:16 - 2016-03-19 20:49 - 00000000 ____D C:\Users\Wasted Time\AppData\Local\Packages
- 2016-11-20 19:35 - 2016-07-18 16:59 - 00000000 ____D C:\Users\Wasted Time\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
- 2016-11-20 12:51 - 2016-06-30 10:02 - 00000000 ____D C:\Users\Wasted Time\AppData\LocalLow\Smartly Dressed Games
- 2016-11-19 15:34 - 2016-11-18 20:13 - 00000000 ____D C:\Users\Cyemonkey\Documents\Klei
- 2016-11-19 13:23 - 2016-11-18 18:33 - 00000000 ____D C:\Users\Cyemonkey\AppData\Local\ConnectedDevicesPlatform
- ==================== Files in the root of some directories =======
- 2016-11-23 22:55 - 2016-11-23 22:55 - 21874200 _____ (LastPass) C:\Program Files (x86)\Common Files\lpuninstall.exe
- 2016-12-07 05:48 - 2016-12-07 05:48 - 0000003 _____ () C:\Users\Wasted Time\AppData\Local\updater.log
- 2014-02-01 23:50 - 2014-02-24 15:36 - 0002763 _____ () C:\ProgramData\connector.swf
- 2016-10-24 19:56 - 2016-10-24 19:56 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
- 2016-06-02 12:49 - 2016-06-02 12:49 - 0000259 _____ () C:\ProgramData\fontcacheev1.dat
- 2015-12-14 18:45 - 2015-10-15 18:45 - 0000032 ____R () C:\ProgramData\hash.dat
- 2012-08-24 02:36 - 2012-08-07 23:07 - 2258432 _____ (Samsung Electronics) C:\ProgramData\MakeMarkerFile.exe
- 2012-08-24 02:36 - 2012-08-07 05:11 - 0003196 _____ () C:\ProgramData\MakeMarkerFile.xml
- 2016-06-10 11:35 - 2016-06-10 11:35 - 0000016 _____ () C:\ProgramData\mntemp
- Files to move or delete:
- ====================
- C:\ProgramData\fontcacheev1.dat
- C:\ProgramData\hash.dat
- Some files in TEMP:
- ====================
- C:\Users\Exepe_000\AppData\Local\Temp\bdfilters.dll
- C:\Users\Exepe_000\AppData\Local\Temp\BingSvc.exe
- C:\Users\Exepe_000\AppData\Local\Temp\BSvcProcessor.exe
- C:\Users\Exepe_000\AppData\Local\Temp\BSvcUpdater.exe
- C:\Users\Exepe_000\AppData\Local\Temp\Gw2.exe
- C:\Users\Exepe_000\AppData\Local\Temp\icqsetup.exe
- C:\Users\Exepe_000\AppData\Local\Temp\jansi-64-8490731712498213211.dll
- C:\Users\Exepe_000\AppData\Local\Temp\utils.dll
- C:\Users\Exepe_000\AppData\Local\Temp\xmlUpdater.exe
- C:\Users\Wasted Time\AppData\Local\Temp\npp.6.9.2.Installer.exe
- C:\Users\Wasted Time\AppData\Local\Temp\xmlUpdater.exe
- ==================== Bamital & volsnap ======================
- (There is no automatic fix for files that do not pass verification.)
- C:\WINDOWS\system32\winlogon.exe => File is digitally signed
- C:\WINDOWS\system32\wininit.exe => File is digitally signed
- C:\WINDOWS\explorer.exe => File is digitally signed
- C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
- C:\WINDOWS\system32\svchost.exe => File is digitally signed
- C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
- C:\WINDOWS\system32\services.exe => File is digitally signed
- C:\WINDOWS\system32\User32.dll => File is digitally signed
- C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
- C:\WINDOWS\system32\userinit.exe => File is digitally signed
- C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
- C:\WINDOWS\system32\rpcss.dll => File is digitally signed
- C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
- C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
- C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
- LastRegBack: 2016-12-14 22:06
- ==================== End of FRST.txt ============================
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement