Jump to content

AmyH1974

Members
  • Content Count

    36
  • Joined

  • Last visited

Everything posted by AmyH1974

  1. Ok back, i restarted my laptop and was able to activate my license. Thank you So much for the help!
  2. Second Log Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-10-2019 Ran by Amy (22-10-2019 17:12:40) Running from C:\Users\amyh9\Downloads Windows 10 Home Version 1903 18362.418 (X64) (2019-06-20 12:30:25) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1292290140-421996718-3283151406-500 - Administrator - Disabled) Amy (S-1-5-21-1292290140-421996718-3283151406-1001 - Administrator - Enabled) => C:\Users\amyh9 DefaultAccount (S-1-5-21-1292290140-421996718-3283151406-503 - Limited - Disabled) Guest (S-1-5-21-1292290140-421996718-3283151406-501 - Limited - Disabled) WDAGUtilityAccount (S-1-5-21-1292290140-421996718-3283151406-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Malwarebytes (Disabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.270 - Adobe) AnswerWorks 5.0 English Runtime (HKLM-x32\...\{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}) (Version: 5.0.7 - Vantage Software Technologies) ANT Drivers Installer x64 (HKLM\...\{C14C3A1D-B5B3-41BB-9358-6FEA3FC642AF}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden CCleaner (HKLM\...\CCleaner) (Version: 5.62 - Piriform) Elevated Installer (HKLM-x32\...\{B11981DA-5AEA-459F-978A-F99541F77AD5}) (Version: 6.15.0.0 - Garmin Ltd or its subsidiaries) Hidden Facebook Gameroom 1.21.6907.27509 (HKLM-x32\...\{E34773A0-158F-4322-8849-2C13BBCD6C68}) (Version: 1.21.6907.27509 - Facebook) Garmin Express (HKLM-x32\...\{4cc2749e-1c2a-4f48-abdf-c17069bac4da}) (Version: 6.15.0.0 - Garmin Ltd or its subsidiaries) Garmin Express (HKLM-x32\...\{9BE7B09F-C8D2-4B1E-B83E-7387FDDA8BCD}) (Version: 6.15.0.0 - Garmin Ltd or its subsidiaries) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 77.0.3865.120 - Google LLC) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.301 - Google LLC) Hidden LastPass (uninstall only) (HKLM-x32\...\LastPass) (Version: - LastPass) Malwarebytes version 3.8.3.2965 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.8.3.2965 - Malwarebytes) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation) Quicken 2009 (HKLM-x32\...\{ED2A3C11-3EA8-4380-B59C-F2C1832731B0}) (Version: 18.1.4.14 - Intuit) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8302 - Realtek Semiconductor Corp.) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.3.31.31 - Synaptics Incorporated) Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{C3ACFCEA-240F-4DCC-A0C3-DD55FEE6C3C2}) (Version: 2.58.0.0 - Microsoft Corporation) Windows 10 Update Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22807 - Microsoft Corporation) Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.) Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software) Packages: ========= Adobe Reader Touch -> C:\Program Files\WindowsApps\AdobeSystemsIncorporated.AdobeReader_3.1.8.7675_x86__ynb6jyjzte8ga [2018-01-03] (Adobe Systems Incorporated) FreeCell Solitaire!! -> C:\Program Files\WindowsApps\476931bsyl.FreeCellSolitaire_1.5.0.0_x64__cgv7566y2ek3j [2019-04-08] (1bsyl) Frozen Free Fall -> C:\Program Files\WindowsApps\Disney.FrozenFreeFall_4.6.1.1_x86__6rarf9sa4v8jt [2018-01-06] (Disney) Mail and Calendar -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12026.20218.0_x64__8wekyb3d8bbwe [2019-09-26] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-10] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-10] (Microsoft Corporation) [MS Ad] MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.32.12463.0_x64__8wekyb3d8bbwe [2019-09-12] (Microsoft Corporation) [MS Ad] Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-09-07] (Microsoft Corporation) XLS Opener -> C:\Program Files\WindowsApps\BallardAppCraftery.CraftySpreadsheetViewer_1.3.4.0_x64__epyrqhfctk40t [2019-01-07] (Ballard App Craftery) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1292290140-421996718-3283151406-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation - pGFX -> Intel Corporation) CustomCLSID: HKU\S-1-5-21-1292290140-421996718-3283151406-1001_Classes\CLSID\{D9AC5E73-BB10-467b-B884-AA1E475C51F5}\Shell\Open\Command -> C:\Program Files\Synaptics\SynTP\SynTPCpl.dll (Synaptics Incorporated -> Synaptics Incorporated) ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2017-12-04] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes) ==================== Codecs (Whitelisted) ================== ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\amyh9\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\d249d9ddd424b688\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default ==================== Loaded Modules (Whitelisted) ============== ==================== Alternate Data Streams (Whitelisted) ========= ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2018-01-03 19:29 - 2018-01-03 19:25 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1292290140-421996718-3283151406-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\amyh9\Documents\Desktop Background Pictures\Autumn 2019.jpg DNS Servers: 192.168.0.1 - 205.171.2.26 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (If an entry is included in the fixlist, it will be removed.) HKLM\...\StartupApproved\Run: => "RTHDVCPL" HKLM\...\StartupApproved\Run: => "Logitech Download Assistant" HKU\S-1-5-21-1292290140-421996718-3283151406-1001\...\StartupApproved\StartupFolder: => "Facebook Gameroom.lnk" HKU\S-1-5-21-1292290140-421996718-3283151406-1001\...\StartupApproved\Run: => "GarminExpressTrayApp" HKU\S-1-5-21-1292290140-421996718-3283151406-1001\...\StartupApproved\Run: => "OneDriveSetup" HKU\S-1-5-21-1292290140-421996718-3283151406-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{BD72785A-B929-45D1-BB8B-DAFA9D88E05F}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd) FirewallRules: [{D9781BCE-D28E-4C0F-9739-2718F15838DD}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd) FirewallRules: [{06B8673E-3721-4AEB-A352-03DE7518F979}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) ==================== Restore Points ========================= 20-09-2019 23:44:32 Windows Update 04-10-2019 08:48:43 Scheduled Checkpoint 10-10-2019 02:49:43 Windows Update ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (10/22/2019 05:12:17 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (5740,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (10/22/2019 04:56:33 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (6340,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (10/22/2019 04:26:59 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (7100,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (10/22/2019 03:50:52 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (3888,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (10/22/2019 03:22:41 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (4576,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (10/22/2019 03:16:49 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (9000,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (10/22/2019 03:13:15 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: SecHealthUI.exe, version: 10.0.18362.387, time stamp: 0x5d8990a3 Faulting module name: ntdll.dll, version: 10.0.18362.418, time stamp: 0x99ca0526 Exception code: 0xc0000409 Fault offset: 0x000000000008c4df Faulting process id: 0x1cf4 Faulting application start time: 0x01d5890cbf83ce69 Faulting application path: C:\WINDOWS\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll Report Id: bd9d930a-449f-46eb-b71a-3b85c3402c06 Faulting package full name: Microsoft.Windows.SecHealthUI_10.0.18362.387_neutral__cw5n1h2txyewy Faulting package-relative application ID: SecHealthUI Error: (10/22/2019 03:06:05 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (3120,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. System errors: ============= Error: (10/22/2019 02:53:13 PM) (Source: BugCheck) (EventID: 1001) (User: ) Description: The computer has rebooted from a bugcheck. The bugcheck was: 0x00000139 (0x0000000000000003, 0xffffcb844d7097b0, 0xffffcb844d709708, 0x0000000000000000). A dump was saved in: C:\WINDOWS\MEMORY.DMP. Report Id: 14dbd5bc-0e0f-4c67-99ef-fb653630ac03. Error: (10/22/2019 02:49:08 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 2:34:06 PM on ‎10/‎22/‎2019 was unexpected. Error: (10/11/2019 12:12:05 PM) (Source: Microsoft-Windows-HAL) (EventID: 13) (User: NT AUTHORITY) Description: The system watchdog timer was triggered. Error: (10/11/2019 12:12:39 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 9:42:10 AM on ‎10/‎11/‎2019 was unexpected. Error: (10/10/2019 01:01:38 PM) (Source: DCOM) (EventID: 10000) (User: DESKTOP-BGJL67L) Description: Unable to start a DCOM Server: {0358B920-0AC7-461F-98F4-58E32CD89148}. The error: "2147942767" Happened while starting this command: C:\WINDOWS\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683} Error: (10/10/2019 12:59:51 PM) (Source: DCOM) (EventID: 10000) (User: DESKTOP-BGJL67L) Description: Unable to start a DCOM Server: {0358B920-0AC7-461F-98F4-58E32CD89148}. The error: "2147942767" Happened while starting this command: C:\WINDOWS\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683} Error: (10/09/2019 06:59:43 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Windows Presentation Foundation Font Cache 3.0.0.0 service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Error: (10/09/2019 06:59:43 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Presentation Foundation Font Cache 3.0.0.0 service to connect. Windows Defender: =================================== Date: 2019-10-22 13:38:38.572 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {F3534D9D-A2C9-4305-ACAB-0F5E1195E3B7} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2019-10-20 11:05:43.933 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {6BA37499-3B9F-455D-A451-534685E42929} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2019-10-20 10:37:57.041 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {1018CAD0-1A37-4E4E-A8C0-6338BC0A2996} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2019-10-19 21:51:07.017 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {07F508EC-C6EC-45A0-B2E7-953BD7C371EA} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2019-10-19 21:31:36.936 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {717EED3C-FDDB-4324-A590-8264199F4345} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2019-10-10 04:27:04.130 Description: Windows Defender Antivirus has encountered an error trying to update security intelligence. New security intelligence Version: Previous security intelligence Version: 1.303.1333.0 Update Source: Microsoft Update Server Security intelligence Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.16400.2 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. CodeIntegrity: =================================== Date: 2019-10-22 15:50:09.212 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2019-09-16 16:13:07.103 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements. Date: 2019-06-20 09:07:02.284 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2019-06-20 09:07:02.241 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== BIOS: Insyde F.23 06/04/2014 Motherboard: Hewlett-Packard 1971 Processor: Intel(R) Core(TM) i3-3130M CPU @ 2.60GHz Percentage of memory in use: 79% Total physical RAM: 3988.27 MB Available physical RAM: 815.31 MB Total Virtual: 5012.27 MB Available Virtual: 1601.05 MB ==================== Drives ================================ Drive 😄 () (Fixed) (Total:675.88 GB) (Free:638.63 GB) NTFS Drive d: (RECOVERY) (Fixed) (Total:21.07 GB) (Free:2.11 GB) NTFS ==>[system with boot components (obtained from drive)] \\?\Volume{4a488d36-c194-4761-a063-8452d724c080}\ (WINRE) (Fixed) (Total:0.39 GB) (Free:0.12 GB) NTFS \\?\Volume{5e284b89-6afc-4f09-a217-6cd29fb65e06}\ () (Fixed) (Total:0.91 GB) (Free:0.4 GB) NTFS \\?\Volume{321ae93c-3332-44f2-892e-7de5f1bc31ca}\ () (Fixed) (Total:0.25 GB) (Free:0.15 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 698.6 GB) (Disk ID: 24E7A700) Partition: GPT. ==================== End of Addition.txt ============================
  3. Ok here are the logs Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21-10-2019 Ran by Amy (administrator) on DESKTOP-BGJL67L (Hewlett-Packard HP Pavilion 17 Notebook PC) (22-10-2019 17:08:09) Running from C:\Users\amyh9\Downloads Loaded Profiles: Amy (Available Profiles: Amy) Platform: Windows 10 Home Version 1903 18362.418 (X64) Language: English (United States) Default browser: Chrome Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe (Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\usocoreworker.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1909.6-0\MsMpEng.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1909.6-0\NisSrv.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9235936 2017-12-04] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942864 2016-10-13] (Logitech -> Logitech, Inc.) HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-03-19] (Microsoft Windows -> Microsoft Corporation) HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-03-19] (Microsoft Windows -> Microsoft Corporation) HKU\S-1-5-21-1292290140-421996718-3283151406-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [24552064 2019-10-18] (Piriform Software Ltd -> Piriform Ltd) HKU\S-1-5-21-1292290140-421996718-3283151406-1001\...\MountPoints2: {d992d006-ec41-11e9-9999-a01d48d9cd92} - "F:\VerizonSWUpgradeAssistantLauncher.exe" HKU\S-1-5-18\...\Run: [GarminExpress] => C:\Program Files (x86)\Garmin\Express\express.exe [30860272 2019-06-18] (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\77.0.3865.120\Installer\chrmstp.exe [2019-10-18] (Google LLC -> Google LLC) Startup: C:\Users\amyh9\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Gameroom.lnk [2018-12-16] ShortcutTarget: Facebook Gameroom.lnk -> C:\Users\amyh9\AppData\Local\Facebook\Games\FacebookGameroom.exe (Facebook, Inc. -> Facebook) CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0F9F9DCB-B105-4B2F-A913-8E69EB1D636E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\MpCmdRun.exe [468120 2019-10-02] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {1487C5A4-3F2B-4EF1-AB0E-E1EC79551581} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [608384 2019-10-18] (Piriform Software Ltd -> Piriform Software Ltd) Task: {18D5F8DE-51CD-4AA2-B9ED-BAAAE9724D4B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18458752 2019-10-18] (Piriform Software Ltd -> Piriform Ltd) Task: {25D56E2C-A617-4482-B8EB-68326C8C18C2} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\MpCmdRun.exe [468120 2019-10-02] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {52E5D769-B104-4637-BA39-A424A00BB230} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_270_pepper.exe [1453112 2019-10-09] (Adobe Inc. -> Adobe) Task: {582CF27B-C616-4907-B45E-804D2B8731C1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\MpCmdRun.exe [468120 2019-10-02] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {7D37E1F1-1101-4AED-9C1D-B3764F109A87} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-10-09] (Adobe Inc. -> Adobe) Task: {9FBF8008-3F65-4D7C-8BB1-5B4B227B7D48} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-06-04] (Google Inc -> Google LLC) Task: {CADA7853-0474-41F0-9A40-2DC3F13835A1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-06-04] (Google Inc -> Google LLC) Task: {CFD3FFF0-D11D-4A6E-A88C-BD348F84606B} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [40432 2019-06-18] (Garmin International, Inc. -> ) Task: {D2DE21FC-2A81-4E9F-8362-F9A73D8DBAFC} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\MpCmdRun.exe [468120 2019-10-02] (Microsoft Windows Publisher -> Microsoft Corporation) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 205.171.2.26 Tcpip\..\Interfaces\{78ac1fd5-55fb-4b50-a23e-0e03abba16e4}: [DhcpNameServer] 192.168.0.1 205.171.2.26 Internet Explorer: ================== HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION HKU\S-1-5-21-1292290140-421996718-3283151406-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://centurylink.net/ BHO: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2018-02-07] (LogMeIn, Inc. -> LastPass) BHO-x32: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar.dll [2018-02-07] (LogMeIn, Inc. -> LastPass) Toolbar: HKLM - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2018-02-07] (LogMeIn, Inc. -> LastPass) Toolbar: HKLM-x32 - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll [2018-02-07] (LogMeIn, Inc. -> LastPass) FireFox: ======== FF Plugin: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2018-02-07] (LastPass (Marvasol Inc) -> LastPass) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2018-02-07] (LastPass (Marvasol Inc) -> LastPass) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.35.302\npGoogleUpdate3.dll [2019-10-07] (Google Inc -> Google LLC) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.35.302\npGoogleUpdate3.dll [2019-10-07] (Google Inc -> Google LLC) Chrome: ======= CHR HomePage: Default -> hxxp://centurylink.net/ CHR StartupUrls: Default -> "hxxp://centurylink.net/" CHR DefaultSearchKeyword: Default -> lp CHR Profile: C:\Users\amyh9\AppData\Local\Google\Chrome\User Data\Default [2019-10-22] CHR Extension: (Google Drive) - C:\Users\amyh9\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-06-04] CHR Extension: (YouTube) - C:\Users\amyh9\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-06-04] CHR Extension: (Forecastfox (fix version)) - C:\Users\amyh9\AppData\Local\Google\Chrome\User Data\Default\Extensions\boljdehmejbffnfiiicckjhafabdepnd [2019-09-25] CHR Extension: (Rakuten Ebates: Get Cash Back For Shopping) - C:\Users\amyh9\AppData\Local\Google\Chrome\User Data\Default\Extensions\chhjbpecpncaggjpdakmflnfcopglcmi [2019-10-03] CHR Extension: (AdBlock) - C:\Users\amyh9\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2019-10-22] CHR Extension: (LastPass: Free Password Manager) - C:\Users\amyh9\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2019-10-19] CHR Extension: (Social Fixer for Facebook) - C:\Users\amyh9\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifmhoabcaeehkljcfclfiieohkohdgbb [2019-10-07] CHR Extension: (Chrome Web Store Payments) - C:\Users\amyh9\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-03] CHR Extension: (Weather Forecast) - C:\Users\amyh9\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofobaelkgcpicbdoabokjlnmdcbjellg [2019-08-22] CHR Extension: (Classic Blue Theme for Google Chrome™) - C:\Users\amyh9\AppData\Local\Google\Chrome\User Data\Default\Extensions\oppbdedflbioggjkeneigjcmpomohajo [2019-08-16] CHR Extension: (Gmail) - C:\Users\amyh9\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-06-04] CHR Extension: (Chrome Media Router) - C:\Users\amyh9\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-09-19] CHR HKLM\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - hxxp://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - hxxp://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [319096 2017-12-04] (Intel Corporation - pGFX -> Intel Corporation) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6744288 2019-06-26] (Malwarebytes Corporation -> Malwarebytes) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [324576 2017-12-04] (Realtek Semiconductor Corp. -> Realtek Semiconductor) R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [269912 2017-12-04] (Synaptics Incorporated -> Synaptics Incorporated) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\NisSrv.exe [3004048 2019-10-02] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\MsMpEng.exe [103384 2019-10-02] (Microsoft Windows Publisher -> Microsoft Corporation) ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 Accelerometer; C:\WINDOWS\System32\drivers\Accelerometer.sys [53904 2019-07-22] (HP Inc. -> HP) S3 DSI_SiUSBXp_3_1; C:\WINDOWS\system32\drivers\DSI_SiUSBXp_3_1.sys [16384 2007-09-06] (Microsoft Windows Hardware Compatibility Publisher -> Silicon Laboratories) R0 hpdskflt; C:\WINDOWS\System32\drivers\hpdskflt.sys [41104 2019-07-22] (HP Inc. -> HP) R3 HpqKbFiltr; C:\WINDOWS\System32\drivers\HpqKbFiltr64.sys [37112 2017-12-04] (Hewlett-Packard Company -> Hewlett-Packard Company) S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2019-06-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [275232 2019-10-22] (Malwarebytes Corporation -> Malwarebytes) S3 RSP2STOR; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [310528 2015-06-05] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1010648 2017-12-04] (Realtek Semiconductor Corp. -> Realtek ) R3 RTWlanE; C:\WINDOWS\System32\drivers\rtwlane.sys [7904088 2018-04-20] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation ) S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [52392 2016-04-28] (Synaptics Incorporated -> Synaptics Incorporated) R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [52904 2016-04-28] (Synaptics Incorporated -> Synaptics Incorporated) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46688 2019-10-02] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [350136 2019-10-02] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54200 2019-10-02] (Microsoft Windows -> Microsoft Corporation) R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [34944 2018-05-11] (HP Inc. -> HP) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-10-22 17:08 - 2019-10-22 17:10 - 000017450 _____ C:\Users\amyh9\Downloads\FRST.txt 2019-10-22 17:05 - 2019-10-22 17:05 - 001617408 _____ (Farbar) C:\Users\amyh9\Downloads\FRST64.exe 2019-10-22 16:19 - 2019-10-22 16:19 - 000275232 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys 2019-10-22 16:19 - 2019-10-22 16:19 - 000001912 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2019-10-22 16:19 - 2019-10-22 16:19 - 000001912 _____ C:\ProgramData\Desktop\Malwarebytes.lnk 2019-10-22 16:19 - 2019-10-22 16:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2019-10-22 16:19 - 2019-09-30 06:25 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys 2019-10-22 16:19 - 2019-06-26 13:00 - 000020936 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys 2019-10-22 16:14 - 2019-10-22 17:09 - 000000000 ____D C:\FRST 2019-10-22 15:44 - 2019-10-22 16:19 - 000000000 ____D C:\ProgramData\Malwarebytes 2019-10-22 15:44 - 2019-10-22 15:44 - 000000000 ____D C:\Users\amyh9\AppData\Local\mbamtray 2019-10-22 15:44 - 2019-10-22 15:44 - 000000000 ____D C:\Users\amyh9\AppData\Local\mbam 2019-10-22 15:44 - 2019-10-22 15:44 - 000000000 ____D C:\Program Files\Malwarebytes 2019-10-22 14:49 - 2019-10-22 14:53 - 001268396 _____ C:\WINDOWS\Minidump\102219-40125-01.dmp 2019-10-22 14:48 - 2019-10-22 14:48 - 698620044 _____ C:\WINDOWS\MEMORY.DMP 2019-10-22 11:39 - 2019-10-22 11:42 - 000001608 _____ C:\Users\amyh9\Desktop\Downloads.lnk 2019-10-13 16:06 - 2015-07-15 16:41 - 000002744 _____ C:\WINDOWS\SysWOW64\lgAxconfig.ini 2019-10-13 16:06 - 2011-05-08 07:37 - 000655872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr90.dll 2019-10-13 16:06 - 2011-05-08 07:37 - 000568832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp90.dll 2019-10-13 16:06 - 2011-05-08 07:37 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcm90.dll 2019-10-13 16:06 - 2010-03-15 18:15 - 004342088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc100.dll 2019-10-13 16:06 - 2010-03-15 18:15 - 000770384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr100.dll 2019-10-13 16:06 - 2010-03-15 18:15 - 000421200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp100.dll 2019-10-13 16:06 - 2005-10-01 19:39 - 000044544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml4a.dll 2019-10-13 15:54 - 2019-10-13 15:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VZW Utility Application - LG 2019-10-10 11:55 - 2019-10-10 12:17 - 000000000 ____D C:\Users\amyh9\AppData\Roaming\Easeware 2019-10-10 03:28 - 2019-10-10 03:28 - 025443840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 022628352 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 019849216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 019811840 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 018019840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 008010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 007754240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 007195648 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 007015936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 006232064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 005915648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 004129616 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 003525592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 003365376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe 2019-10-10 03:28 - 2019-10-10 03:28 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2019-10-10 03:28 - 2019-10-10 03:28 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 2019-10-10 03:28 - 2019-10-10 03:28 - 002494440 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 002422592 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL 2019-10-10 03:28 - 2019-10-10 03:28 - 002314648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 002236144 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 002138472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL 2019-10-10 03:28 - 2019-10-10 03:28 - 001610752 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 001319936 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 001273392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 001214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 001152016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 001098712 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 001012792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 000952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 000882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 000843776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 000690176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 000667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 000537600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 000516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 000429568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msltus40.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 000186880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE 2019-10-10 03:28 - 2019-10-10 03:28 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll 2019-10-10 03:28 - 2019-10-10 03:28 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll 2019-10-10 03:27 - 2019-10-10 03:28 - 025900544 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 014816256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 009928504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2019-10-10 03:27 - 2019-10-10 03:27 - 007600664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 006517640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 005041664 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 004538880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 002861568 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsservices.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 002762504 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 002703360 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 002095104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 002081976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 002000168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 001952360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 001847808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsservices.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 001730560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 001687040 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 001664928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 001563648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 001562424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 001394488 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2019-10-10 03:27 - 2019-10-10 03:27 - 001283072 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 001217904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe 2019-10-10 03:27 - 2019-10-10 03:27 - 001072952 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2019-10-10 03:27 - 2019-10-10 03:27 - 000904208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000856576 _____ C:\WINDOWS\system32\MBR2GPT.EXE 2019-10-10 03:27 - 2019-10-10 03:27 - 000844800 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe 2019-10-10 03:27 - 2019-10-10 03:27 - 000842752 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000829536 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioIso.exe 2019-10-10 03:27 - 2019-10-10 03:27 - 000818688 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000774672 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2019-10-10 03:27 - 2019-10-10 03:27 - 000701952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.FileExplorer.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000691712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000679880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000669496 _____ (Microsoft Corporation) C:\WINDOWS\system32\computecore.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000598024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000515896 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe 2019-10-10 03:27 - 2019-10-10 03:27 - 000496640 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000487424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.FileExplorer.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000466416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000462848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000456504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys 2019-10-10 03:27 - 2019-10-10 03:27 - 000452408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe 2019-10-10 03:27 - 2019-10-10 03:27 - 000422008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000404392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000380216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000300184 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE 2019-10-10 03:27 - 2019-10-10 03:27 - 000224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000220472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe 2019-10-10 03:27 - 2019-10-10 03:27 - 000199480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe 2019-10-10 03:27 - 2019-10-10 03:27 - 000193592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000165832 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe 2019-10-10 03:27 - 2019-10-10 03:27 - 000150328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe 2019-10-10 03:27 - 2019-10-10 03:27 - 000122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000033048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NtlmShared.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDJPN.DLL 2019-10-10 03:27 - 2019-10-10 03:27 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kbd106.dll 2019-10-10 03:27 - 2019-10-10 03:27 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6r.dll 2019-10-10 03:26 - 2019-10-10 03:27 - 000247856 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 017787392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 004562688 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe 2019-10-10 03:26 - 2019-10-10 03:26 - 004012544 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 003771392 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 003701760 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 002723328 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2019-10-10 03:26 - 2019-10-10 03:26 - 002456064 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 002448712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 002284032 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 002114048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 001830200 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 001748480 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 001743672 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 001721144 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 001656392 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 001439744 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe 2019-10-10 03:26 - 2019-10-10 03:26 - 001149712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe 2019-10-10 03:26 - 2019-10-10 03:26 - 001084432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 001066496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 000890472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 000880088 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 000758584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 000717312 _____ (Microsoft Corporation) C:\WINDOWS\system32\mousocoreworker.exe 2019-10-10 03:26 - 2019-10-10 03:26 - 000596992 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2019-10-10 03:26 - 2019-10-10 03:26 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe 2019-10-10 03:26 - 2019-10-10 03:26 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 000520192 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 000516408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe 2019-10-10 03:26 - 2019-10-10 03:26 - 000513536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe 2019-10-10 03:26 - 2019-10-10 03:26 - 000462136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 000436536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys 2019-10-10 03:26 - 2019-10-10 03:26 - 000412152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe 2019-10-10 03:26 - 2019-10-10 03:26 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicSvc.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 000324408 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 000261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicCapsule.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 000225080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys 2019-10-10 03:26 - 2019-10-10 03:26 - 000202040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys 2019-10-10 03:26 - 2019-10-10 03:26 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 000121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatecsp.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 000117048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys 2019-10-10 03:26 - 2019-10-10 03:26 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe 2019-10-10 03:26 - 2019-10-10 03:26 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicAgent.exe 2019-10-10 03:26 - 2019-10-10 03:26 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe 2019-10-10 03:26 - 2019-10-10 03:26 - 000039304 _____ (Microsoft Corporation) C:\WINDOWS\system32\NtlmShared.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 000037176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys 2019-10-10 03:26 - 2019-10-10 03:26 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicPS.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\bindflt.dll 2019-10-10 03:26 - 2019-10-10 03:26 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6r.dll 2019-10-10 02:50 - 2019-10-10 02:51 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe 2019-10-10 02:50 - 2019-10-10 02:51 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe 2019-10-06 21:45 - 2019-10-06 21:45 - 000002287 _____ C:\Users\amyh9\AppData\Roaming\Microsoft\Windows\Start Menu\Solitaire Safari.lnk 2019-10-06 21:44 - 2019-10-06 21:44 - 000002317 _____ C:\Users\amyh9\AppData\Roaming\Microsoft\Windows\Start Menu\Forest Rescue 2 Friends United.lnk 2019-10-06 21:44 - 2019-10-06 21:44 - 000002305 _____ C:\Users\amyh9\AppData\Roaming\Microsoft\Windows\Start Menu\Forest Rescue Bubble Pop.lnk 2019-10-05 03:34 - 2019-10-05 03:34 - 000939008 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2019-10-05 03:34 - 2019-10-05 03:34 - 000742912 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll 2019-10-05 03:34 - 2019-10-05 03:34 - 000722944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapi.dll 2019-10-05 03:34 - 2019-10-05 03:34 - 000524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll 2019-10-05 03:34 - 2019-10-05 03:34 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll 2019-10-05 03:34 - 2019-10-05 03:34 - 000387832 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll 2019-10-05 03:34 - 2019-10-05 03:34 - 000334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapibase.dll 2019-10-05 03:34 - 2019-10-05 03:34 - 000053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeUISrv.exe 2019-10-05 03:33 - 2019-10-05 03:33 - 004481536 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll 2019-10-05 03:33 - 2019-10-05 03:33 - 002132280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll 2019-10-05 03:33 - 2019-10-05 03:33 - 001788728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll 2019-10-05 03:33 - 2019-10-05 03:33 - 001510752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll 2019-10-05 03:33 - 2019-10-05 03:33 - 001505320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll 2019-10-05 03:33 - 2019-10-05 03:33 - 001297936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll 2019-10-05 03:33 - 2019-10-05 03:33 - 001263616 _____ (Microsoft Corporation) C:\WINDOWS\system32\opengl32.dll 2019-10-05 03:33 - 2019-10-05 03:33 - 001244944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll 2019-10-05 03:33 - 2019-10-05 03:33 - 000904704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\opengl32.dll 2019-10-05 03:33 - 2019-10-05 03:33 - 000893952 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe 2019-10-05 03:33 - 2019-10-05 03:33 - 000802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll 2019-10-05 03:33 - 2019-10-05 03:33 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll 2019-10-05 03:33 - 2019-10-05 03:33 - 000546816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxdiagn.dll 2019-10-05 03:33 - 2019-10-05 03:33 - 000500736 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2019-10-05 03:33 - 2019-10-05 03:33 - 000483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\SessEnv.dll 2019-10-05 03:33 - 2019-10-05 03:33 - 000476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll 2019-10-05 03:33 - 2019-10-05 03:33 - 000450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxdiagn.dll 2019-10-05 03:33 - 2019-10-05 03:33 - 000421376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2019-10-05 03:33 - 2019-10-05 03:33 - 000417280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SessEnv.dll 2019-10-05 03:33 - 2019-10-05 03:33 - 000369664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxdiag.exe 2019-10-05 03:33 - 2019-10-05 03:33 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\VAN.dll 2019-10-05 03:33 - 2019-10-05 03:33 - 000315392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxdiag.exe 2019-10-05 03:33 - 2019-10-05 03:33 - 000245248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\glu32.dll 2019-10-05 03:33 - 2019-10-05 03:33 - 000174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll 2019-10-05 03:33 - 2019-10-05 03:33 - 000163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\glu32.dll 2019-10-05 03:33 - 2019-10-05 03:33 - 000158208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys 2019-10-05 03:33 - 2019-10-05 03:33 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sud.dll 2019-10-05 03:33 - 2019-10-05 03:33 - 000100664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmcl.sys 2019-10-05 03:33 - 2019-10-05 03:33 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll 2019-10-05 03:33 - 2019-10-05 03:33 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvvmtransport.dll 2019-10-05 03:33 - 2019-10-05 03:33 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvvmtransport.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 006084048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 005865272 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizimg.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 005764872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 005105152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 003964056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2019-10-05 03:32 - 2019-10-05 03:32 - 003742032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 002821120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 002799616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2019-10-05 03:32 - 2019-10-05 03:32 - 002772032 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 002258856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 002160640 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 001957008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 001913296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 001857024 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 001845408 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 001835008 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 001692160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 001664376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 001616784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 001473488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 001412096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 001334064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ttdrecordcpu.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 001178816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 001154656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 001080320 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 001054872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 001047968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000875008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000792296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputHost.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000784384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000783480 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe 2019-10-05 03:32 - 2019-10-05 03:32 - 000775768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000772656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000673080 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000652800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000629248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.Search.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000623104 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000612864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000599040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000568336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000551424 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe 2019-10-05 03:32 - 2019-10-05 03:32 - 000541696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResourceMapper.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000541480 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000539648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9on12.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000518656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000510464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000507704 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizeng.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000507152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000501232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp_win.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000487576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000463272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000450360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11on12.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000383984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MMDevAPI.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000382976 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000379840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ws2_32.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000375720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000346624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\secproc.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys 2019-10-05 03:32 - 2019-10-05 03:32 - 000315904 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000285256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000283688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ttdwriter.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000279040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000278080 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe 2019-10-05 03:32 - 2019-10-05 03:32 - 000244736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndproxy.sys 2019-10-05 03:32 - 2019-10-05 03:32 - 000243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Gpu.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000236520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cfgmgr32.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000210744 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\prntvpt.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000176440 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxlib.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000173568 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvinst.exe 2019-10-05 03:32 - 2019-10-05 03:32 - 000157184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ComposableShellProxyStub.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SpatialAudioLicenseSrv.exe 2019-10-05 03:32 - 2019-10-05 03:32 - 000143808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imm32.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000139264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prntvpt.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000137864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devobj.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000132608 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_ForceSync.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000125232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KerbClientShared.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000116904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\userenv.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000110080 _____ C:\WINDOWS\system32\ResBParser.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000105832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe 2019-10-05 03:32 - 2019-10-05 03:32 - 000094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe 2019-10-05 03:32 - 2019-10-05 03:32 - 000093712 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys 2019-10-05 03:32 - 2019-10-05 03:32 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EaseOfAccessDialog.exe 2019-10-05 03:32 - 2019-10-05 03:32 - 000089544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000084496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys 2019-10-05 03:32 - 2019-10-05 03:32 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcbuilder.exe 2019-10-05 03:32 - 2019-10-05 03:32 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sethc.exe 2019-10-05 03:32 - 2019-10-05 03:32 - 000073024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000066832 _____ (Microsoft Corporation) C:\WINDOWS\system32\iumcrypt.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000056832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devrtl.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnppolicy.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnrollCtrl.exe 2019-10-05 03:32 - 2019-10-05 03:32 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AssignedAccessRuntime.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enrollmentapi.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe 2019-10-05 03:32 - 2019-10-05 03:32 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndistapi.sys 2019-10-05 03:32 - 2019-10-05 03:32 - 000021544 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000016696 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizres.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d8thk.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d8thk.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000011576 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxlibres.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCertResources.dll 2019-10-05 03:32 - 2019-10-05 03:32 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin 2019-10-05 03:32 - 2019-10-05 03:32 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin 2019-10-05 03:32 - 2019-10-05 03:32 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin 2019-10-05 03:32 - 2019-10-05 03:32 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin 2019-10-05 03:32 - 2019-10-05 03:32 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin 2019-10-05 03:32 - 2019-10-05 03:32 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin 2019-10-05 03:32 - 2019-10-05 03:32 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin 2019-10-05 03:32 - 2019-10-05 03:32 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin 2019-10-05 03:32 - 2019-10-05 03:32 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin 2019-10-05 03:32 - 2019-10-05 03:32 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin 2019-10-05 03:32 - 2019-10-05 03:32 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin 2019-10-05 03:32 - 2019-10-05 03:32 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin 2019-10-05 03:31 - 2019-10-05 03:31 - 007263992 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 006425600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 006164480 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 004046336 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 003553280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 003386880 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 002590208 _____ C:\WINDOWS\system32\dwmscene.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 001940952 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 001819136 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShell.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 001757096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2019-10-05 03:31 - 2019-10-05 03:31 - 001657856 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 001512320 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2019-10-05 03:31 - 2019-10-05 03:31 - 001482040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys 2019-10-05 03:31 - 2019-10-05 03:31 - 001372160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 001366128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2019-10-05 03:31 - 2019-10-05 03:31 - 001261800 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 001182240 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2019-10-05 03:31 - 2019-10-05 03:31 - 001023128 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000984376 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000975872 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000858112 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000759488 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000674072 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe 2019-10-05 03:31 - 2019-10-05 03:31 - 000639400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp_win.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000617784 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000606208 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000598016 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_PCDisplay.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000558592 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000457216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys 2019-10-05 03:31 - 2019-10-05 03:31 - 000448000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000442704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ws2_32.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000398728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe 2019-10-05 03:31 - 2019-10-05 03:31 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000334936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ComposableShellProxyStub.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000293344 _____ (Microsoft Corporation) C:\WINDOWS\system32\cfgmgr32.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000284160 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000179512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys 2019-10-05 03:31 - 2019-10-05 03:31 - 000176152 _____ (Microsoft Corporation) C:\WINDOWS\system32\imm32.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000159112 _____ (Microsoft Corporation) C:\WINDOWS\system32\devobj.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000140496 _____ (Microsoft Corporation) C:\WINDOWS\system32\userenv.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmredir.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000132408 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinAUG.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000119840 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe 2019-10-05 03:31 - 2019-10-05 03:31 - 000116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\EaseOfAccessDialog.exe 2019-10-05 03:31 - 2019-10-05 03:31 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShellExtFramework.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000098816 _____ (Microsoft Corporation) C:\WINDOWS\system32\sethc.exe 2019-10-05 03:31 - 2019-10-05 03:31 - 000092624 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskhostw.exe 2019-10-05 03:31 - 2019-10-05 03:31 - 000071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwm.exe 2019-10-05 03:31 - 2019-10-05 03:31 - 000059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\devrtl.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000053248 _____ C:\WINDOWS\system32\Drivers\UsbPmApi.sys 2019-10-05 03:31 - 2019-10-05 03:31 - 000047616 _____ C:\WINDOWS\system32\UsbPmApi.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe 2019-10-05 03:31 - 2019-10-05 03:31 - 000020944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmsgapi.dll 2019-10-05 03:31 - 2019-10-05 03:31 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\pacjsworker.exe 2019-10-05 03:31 - 2019-10-05 03:31 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tier2punctuations.dll 2019-10-05 03:30 - 2019-10-05 03:31 - 003727360 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2019-10-05 03:30 - 2019-10-05 03:30 - 007905000 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 007848192 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 006227624 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 004612520 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2019-10-05 03:30 - 2019-10-05 03:30 - 003590968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2019-10-05 03:30 - 2019-10-05 03:30 - 003184128 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 003105280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 002552120 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 002466304 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 002120704 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 002120272 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 002069504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 001942528 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 001616608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ttdrecordcpu.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 001607680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 001543168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 001413704 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 001383856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 001150240 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputHost.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 001091584 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 001062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 001036800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 001029432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys 2019-10-05 03:30 - 2019-10-05 03:30 - 001009152 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000944664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000931840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys 2019-10-05 03:30 - 2019-10-05 03:30 - 000874296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2019-10-05 03:30 - 2019-10-05 03:30 - 000841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000839680 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9on12.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000833312 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe 2019-10-05 03:30 - 2019-10-05 03:30 - 000750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.Search.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000749568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000732176 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys 2019-10-05 03:30 - 2019-10-05 03:30 - 000656960 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11on12.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000589384 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2019-10-05 03:30 - 2019-10-05 03:30 - 000563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000551952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Vid.sys 2019-10-05 03:30 - 2019-10-05 03:30 - 000551936 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2019-10-05 03:30 - 2019-10-05 03:30 - 000449888 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMDevAPI.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000441144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2019-10-05 03:30 - 2019-10-05 03:30 - 000415808 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000363624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\MbbCx.sys 2019-10-05 03:30 - 2019-10-05 03:30 - 000355000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys 2019-10-05 03:30 - 2019-10-05 03:30 - 000342896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ttdwriter.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\directxdatabaseupdater.exe 2019-10-05 03:30 - 2019-10-05 03:30 - 000282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_CapabilityAccess.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3svc.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnservice.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys 2019-10-05 03:30 - 2019-10-05 03:30 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\ManageCI.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000223032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelppm.sys 2019-10-05 03:30 - 2019-10-05 03:30 - 000221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgiadaptercache.exe 2019-10-05 03:30 - 2019-10-05 03:30 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000208184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\processr.sys 2019-10-05 03:30 - 2019-10-05 03:30 - 000201016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdppm.sys 2019-10-05 03:30 - 2019-10-05 03:30 - 000199480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdk8.sys 2019-10-05 03:30 - 2019-10-05 03:30 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe 2019-10-05 03:30 - 2019-10-05 03:30 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwbase.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000155648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_AppExecutionAlias.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000152408 _____ (Microsoft Corporation) C:\WINDOWS\system32\KerbClientShared.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000151568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbus.sys 2019-10-05 03:30 - 2019-10-05 03:30 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_BackgroundApps.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000132096 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe 2019-10-05 03:30 - 2019-10-05 03:30 - 000127064 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationControlCSP.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000105272 _____ (Microsoft Corporation) C:\WINDOWS\system32\icfupgd.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3msm.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3api.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000088352 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000079376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\uaspstor.sys 2019-10-05 03:30 - 2019-10-05 03:30 - 000075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnrollCtrl.exe 2019-10-05 03:30 - 2019-10-05 03:30 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidspi.sys 2019-10-05 03:30 - 2019-10-05 03:30 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AssignedAccessRuntime.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\audioresourceregistrar.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000052752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmstorfl.sys 2019-10-05 03:30 - 2019-10-05 03:30 - 000052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringconfigsp.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000047000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2019-10-05 03:30 - 2019-10-05 03:30 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\cellulardatacapabilityhandler.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000043536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storvsc.sys 2019-10-05 03:30 - 2019-10-05 03:30 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiredNetworkCSP.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\IcsEntitlementHost.exe 2019-10-05 03:30 - 2019-10-05 03:30 - 000028936 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmbuspipe.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32_DeviceGuard.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfapigp.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\CSystemEventsBrokerClient.dll 2019-10-05 03:30 - 2019-10-05 03:30 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCertResources.dll 2019-10-05 01:37 - 2019-10-05 01:37 - 000002283 _____ C:\Users\amyh9\AppData\Roaming\Microsoft\Windows\Start Menu\Forest Rescue.lnk 2019-10-04 11:39 - 2019-10-22 14:49 - 000000000 ____D C:\WINDOWS\Minidump ==================== One month (modified) ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-10-22 16:50 - 2018-01-03 20:47 - 000001283 _____ C:\Users\amyh9\Desktop\Internet Explorer.lnk 2019-10-22 16:48 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\NDF 2019-10-22 16:19 - 2019-03-19 00:52 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2019-10-22 15:42 - 2019-03-19 00:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2019-10-22 15:38 - 2019-06-20 08:23 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2019-10-22 15:37 - 2019-06-20 01:28 - 000000000 ____D C:\Users\amyh9 2019-10-22 15:37 - 2019-03-19 00:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2019-10-22 15:07 - 2018-01-03 21:56 - 000000000 ____D C:\Users\amyh9\Documents\Quicken 2019-10-22 14:53 - 2019-03-19 00:50 - 000000000 ____D C:\WINDOWS\INF 2019-10-22 14:49 - 2019-06-20 07:51 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2019-10-22 14:48 - 2018-01-03 21:37 - 000000000 ____D C:\Program Files\CCleaner 2019-10-22 13:38 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\AppReadiness 2019-10-19 16:23 - 2019-06-20 08:23 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update 2019-10-19 02:21 - 2019-03-19 00:52 - 000000000 ___HD C:\Program Files\WindowsApps 2019-10-18 20:51 - 2019-06-04 09:52 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2019-10-18 20:51 - 2019-06-04 09:52 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2019-10-18 20:51 - 2019-06-04 09:52 - 000002260 _____ C:\ProgramData\Desktop\Google Chrome.lnk 2019-10-13 15:54 - 2019-06-20 08:09 - 000840848 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2019-10-12 11:57 - 2018-09-30 17:16 - 000000000 ____D C:\Users\amyh9\Desktop\Cross-Stitch World Pictures 2019-10-11 12:13 - 2018-01-03 22:48 - 000018960 _____ (Logitech, Inc.) C:\WINDOWS\system32\Drivers\LNonPnP.sys 2019-10-10 12:57 - 2018-01-03 21:37 - 000000863 _____ C:\Users\Public\Desktop\CCleaner.lnk 2019-10-10 12:57 - 2018-01-03 21:37 - 000000863 _____ C:\ProgramData\Desktop\CCleaner.lnk 2019-10-10 04:14 - 2019-03-19 00:52 - 000000000 ___RD C:\WINDOWS\PrintDialog 2019-10-10 04:14 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe 2019-10-10 04:14 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2019-10-10 04:14 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\SystemResources 2019-10-10 04:14 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform 2019-10-10 04:14 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\oobe 2019-10-10 04:14 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\Dism 2019-10-10 04:14 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\bcastdvr 2019-10-10 03:49 - 2019-03-19 00:37 - 000000000 ____D C:\WINDOWS\CbsTemp 2019-10-10 03:47 - 2018-01-03 20:31 - 000000000 ____D C:\WINDOWS\system32\MRT 2019-10-10 03:39 - 2018-01-03 20:30 - 127230528 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2019-10-09 16:53 - 2019-09-20 23:22 - 000004554 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player PPAPI Notifier 2019-10-09 16:53 - 2019-09-20 23:22 - 000004380 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player Updater 2019-10-09 16:53 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed 2019-10-09 16:53 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\Macromed 2019-10-07 16:22 - 2019-06-20 08:23 - 000003420 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA 2019-10-07 16:22 - 2019-06-20 08:23 - 000003296 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore 2019-10-07 16:22 - 2018-01-03 20:59 - 000000000 ____D C:\Program Files (x86)\Google 2019-10-05 04:30 - 2018-01-03 20:17 - 000000000 __RHD C:\Users\Public\AccountPictures 2019-10-05 04:30 - 2018-01-03 20:17 - 000000000 ___RD C:\Users\amyh9\3D Objects 2019-10-05 04:24 - 2019-06-20 07:51 - 000257824 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2019-10-05 04:20 - 2019-03-19 00:52 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2019-10-05 04:20 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\WinMetadata 2019-10-05 04:20 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\migwiz 2019-10-05 04:20 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\PolicyDefinitions 2019-10-03 21:21 - 2018-06-26 16:31 - 000000000 ____D C:\Users\amyh9\AppData\Local\ElevatedDiagnostics 2019-10-02 17:54 - 2018-02-26 00:22 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2019-09-29 02:09 - 2018-01-03 20:17 - 000000000 ____D C:\Users\amyh9\AppData\Local\Packages 2019-09-22 16:01 - 2018-06-18 20:27 - 000000000 ____D C:\Users\amyh9\AppData\Local\D3DSCache ==================== Files in the root of some directories ================ 2018-01-06 02:37 - 2018-01-06 02:37 - 000000017 _____ () C:\Users\amyh9\AppData\Local\resmon.resmoncfg ==================== SigCheck =============================== (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ============================
  4. Ok got the message and it wont work either Says Site can not be reached
  5. Ok i will try that then. I will wait a hour and if i still cant get it to work i will follow the instructions you gave me. Thanks
  6. Tried that link and it wont work wont let me download it all i get is site can not be reached
  7. I have already tried that for some reason it wont let me deactivate it.I get a message saying You cannot deactivate all for this subscription.
  8. Today i noticed that my Malwarebytes License is not activated so i hit the activate and i get this message (see attachment) What can i do to activate my license? As you can see i can post in here so i have internet connection. Thanks
  9. I keep getting a pop up that says something about hijacked being blocked every time i check my email. Can someone explain what all this means to me. This is what it it says when i click on the details of the popup from Malware bytes : Malwarebytes www.malwarebytes.com -Log Details- Protection Event Date: 6/10/18 Protection Event Time: 12:46 AM Log File: 3826e600-6c69-11e8-8c39-a01d48d9cd92.json Administrator: Yes -Software Information- Version: 3.5.1.2522 Components Version: 1.0.374 Update Package Version: 1.0.5420 License: Premium -System Information- OS: Windows 10 (Build 17134.48) CPU: x64 File System: NTFS User: System -Blocked Website Details- Malicious Website: 1 , , Blocked, [-1], [-1],0.0.0 -Website Data- Category: Hijack Domain: d8h.acroshe.eu IP Address: 167.99.235.86 Port: [53141] Type: Outbound File: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  10. Having the same issue. I have uninstall this program and now i can use my laptop again. It was so bad that i could not open ANYTHING on my laptop, could not even shut it down because i could not get to the screen i needed to do that. So i winded up just holding my power button down till it turn it's self off then i restarted it in safe mode, uninstalled Malware bytes then restarted my laptop. Now i have everything back and running on my laptop and i can use it again. I will re-install Malware bytes when they have the problem fixed, Hopefully they will let us know when it is fixed.
  11. Having the same issue. I have uninstall this program and now i can use my laptop again. It was so bad that i could not open ANYTHING on my laptop, could not even shut it down because i could not get to the screen i needed to do that. So i winded up just holding my power button down till it turn it's self off then i restarted it in safe mode, uninstalled Malware bytes then restarted my laptop. Now i have everything back and running on my laptop and i can use it again. I will re-install Malware bytes when they have the problem fixed.
  12. Having the same issue. I have uninstall this program and now i can use my laptop again. It was so bad that i could not open ANYTHING on my laptop, could not even shut it down because i could not get to the screen i needed to do that. So i winded up just holding my power button down till it turn it's self off then i restarted it in safe mode, uninstalled Malware bytes then restarted my laptop. Now i have everything back and running on my laptop and i can use it again. I will re-install Malware bytes when they have the problem fixed.
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.