primaxuk
Members-
Posts
12 -
Joined
-
Last visited
Reputation
0 NeutralRecent Profile Visitors
The recent visitors block is disabled and is not being shown to other users.
-
Hi thanks for all your help so are you saying the logs are all clear now it looks like it working again Malwarebytes Kind regards Peter
- 21 replies
-
- trojan:win32/coinminer
- trojan
-
(and 1 more)
Tagged with:
-
Fix result of Farbar Recovery Scan Tool (x64) Version: 12-10-2019 Ran by Peter (12-10-2019 11:33:16) Run:2 Running from C:\Users\Peter\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\TempState\Downloads Loaded Profiles: Peter (Available Profiles: Peter) Boot Mode: Normal ============================================== fixlist content: ***************** CreateRestorePoint: EmptyTemp: CloseProcesses: S2 UtilitiesService; C:\Program Files\Utilities\UtilitiesService.exe [X] S3 AIDA64Driver; \??\C:\Program Files (x86)\FinalWire\AIDA64 Extreme\kerneld.x64 [X] S1 amsdk; \??\C:\WINDOWS\system32\drivers\amsdk.sys [X] ]FirewallRules: [{00534A32-2DF4-420B-B6C7-95ABE3556483}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Squad\squad_launcher.exe No File FirewallRules: [{A8B5AC5C-E0D3-43BE-A296-1A1FFA240247}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Squad\squad_launcher.exe No File FirewallRules: [TCP Query User{B4AFE14B-B5B8-46C7-B3DB-3C8A0D0EADDA}C:\program files (x86)\steam\steamapps\common\squad\squadgame\binaries\win64\squadgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\squad\squadgame\binaries\win64\squadgame.exe No File FirewallRules: [UDP Query User{62423C4C-5837-4569-BC04-0FFCD53E6C66}C:\program files (x86)\steam\steamapps\common\squad\squadgame\binaries\win64\squadgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\squad\squadgame\binaries\win64\squadgame.exe No File ***************** Restore point was successfully created. Processes closed successfully. HKLM\System\CurrentControlSet\Services\UtilitiesService => removed successfully UtilitiesService => service removed successfully HKLM\System\CurrentControlSet\Services\AIDA64Driver => removed successfully AIDA64Driver => service removed successfully HKLM\System\CurrentControlSet\Services\amsdk => removed successfully amsdk => service removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{00534A32-2DF4-420B-B6C7-95ABE3556483}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A8B5AC5C-E0D3-43BE-A296-1A1FFA240247}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{B4AFE14B-B5B8-46C7-B3DB-3C8A0D0EADDA}C:\program files (x86)\steam\steamapps\common\squad\squadgame\binaries\win64\squadgame.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{62423C4C-5837-4569-BC04-0FFCD53E6C66}C:\program files (x86)\steam\steamapps\common\squad\squadgame\binaries\win64\squadgame.exe" => removed successfully =========== EmptyTemp: ========== BITS transfer queue => 13656064 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 121970694 B Java, Flash, Steam htmlcache => 16969006 B Windows/system/drivers => 617258 B Edge => 127725986 B Chrome => 328010496 B Firefox => 953862045 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 0 B LocalService => 0 B NetworkService => 21234 B NetworkService => 21234 B Peter => 192743389 B RecycleBin => 0 B EmptyTemp: => 1.6 GB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 11:35:25 ====
- 21 replies
-
- trojan:win32/coinminer
- trojan
-
(and 1 more)
Tagged with:
-
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-10-2019 01 Ran by Peter (11-10-2019 13:18:13) Running from C:\Users\Peter\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\TempState\Downloads Windows 10 Home Version 1903 18362.418 (X64) (2019-08-30 10:33:15) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2643124959-2563984870-1026749049-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-2643124959-2563984870-1026749049-503 - Limited - Disabled) Guest (S-1-5-21-2643124959-2563984870-1026749049-501 - Limited - Disabled) Peter (S-1-5-21-2643124959-2563984870-1026749049-1001 - Administrator - Enabled) => C:\Users\Peter WDAGUtilityAccount (S-1-5-21-2643124959-2563984870-1026749049-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Kaspersky Free (Enabled - Up to date) {B1D2E896-6D96-7460-F17A-838B9D00DD65} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 64 Bit HP CIO Components Installer (HKLM\...\{5737101A-27C4-408A-8A57-D1DC78DF84B4}) (Version: 8.2.1 - Hewlett-Packard) Hidden 7-Zip 19.00 (x64) (HKLM\...\7-Zip) (Version: 19.00 - Igor Pavlov) Adobe Acrobat 8 Standard - English, Français, Deutsch (HKLM-x32\...\Adobe Acrobat 8 Standard - English, Français, Deutsch) (Version: 8.0.0 - Adobe Systems) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 4.0.1.188 - Adobe Systems Incorporated) Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.255 - Adobe) Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.255 - Adobe) Adobe Photoshop 7.0 (HKLM-x32\...\Adobe Photoshop 7.0) (Version: 7.0 - Adobe Systems, Inc.) Adobe Photoshop CC 2015.5 (HKLM-x32\...\PHSP_17_0_1) (Version: 17.0.1 - Adobe Systems Incorporated) Aiseesoft Data Recovery 1.1.18 (HKLM-x32\...\{E67DD0BA-233F-4EA9-B010-9B0A3D58F690}_is1) (Version: 1.1.18 - Aiseesoft Studio) Alt.Binz 0.39.4 (HKLM-x32\...\Alt.Binz) (Version: 0.39.4 - Rdl) ANT Drivers Installer x64 (HKLM\...\{7664AF65-7B0D-4171-9F0F-50455278B428}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden Apowersoft Online Launcher version 1.4.6 (HKLM-x32\...\{20BF67A8-D81A-4489-8225-FABAA0896E2D}_is1) (Version: 1.4.6 - APOWERSOFT LIMITED) Avanquest Message (HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\{20573C69-4A68-4BEF-A23D-365CB66924CE}) (Version: 2.08.0 - Avanquest Software) Avanquest update (HKLM-x32\...\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}) (Version: 1.34 - Avanquest Software) Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.8.2.48475 - Electronic Arts) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.0 - EA Digital Illusions CE AB) Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.6.1 - Canon Inc.) CanoScan LiDE 110 Scanner Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ2414) (Version: - Canon Inc.) CPUID CPU-Z 1.87 (HKLM\...\CPUID CPU-Z_is1) (Version: 1.87 - CPUID, Inc.) CyberSky 5 (HKLM-x32\...\CyberSky 5) (Version: 5.0.3 - Stephen Michael Schimpf) Discord (HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\Discord) (Version: 0.0.301 - Discord Inc.) Dropbox (HKLM-x32\...\Dropbox) (Version: 82.4.155 - Dropbox, Inc.) Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.241.1 - Dropbox, Inc.) Hidden DYNALOG (HKLM-x32\...\DYNALOG) (Version: 3.5.43 DYA - Julius Blum Ges.m.b.H) Elevated Installer (HKLM-x32\...\{1052502B-4C91-43F9-B160-AE39ED57C9F0}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries) Hidden Epic Games Launcher (HKLM-x32\...\{2DE76AAC-8061-4D9B-B7BA-A7CFBE0F8048}) (Version: 1.1.86.0 - Epic Games, Inc.) ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB) Far Cry 5 (HKLM-x32\...\{73B938C4-0DDA-448D-8E46-87401EA87339}_is1) (Version: - Ubisoft) Free Screen Video Recorder (HKLM-x32\...\Free Screen Video Recorder_is1) (Version: 3.0.45.1027 - Digital Wave Ltd) Garmin Express (HKLM-x32\...\{BCC7CA85-E57F-452D-BB44-15A1CE018BD0}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries) Hidden Garmin Express (HKLM-x32\...\{bd8bd200-9a60-4969-b267-6b565f36e3da}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries) Garmin Express Tray (HKLM-x32\...\{DA9C865D-6762-4931-8588-0B13B7A0796B}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries) Hidden GL USB2.0 UVC Camera Device (HKLM-x32\...\{9897BBD8-013A-49F3-928E-866A59B6E00C}) (Version: 17.3.20.0 - GenesysLogic) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 77.0.3865.90 - Google LLC) Google Earth Pro (HKLM\...\{70A0F34E-564B-4F93-ADD6-3BAEC6E44075}) (Version: 7.3.2.5776 - Google) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.301 - Google LLC) Hidden Grammarly (HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\GrammarlyForWindows) (Version: 1.5.34 - Grammarly) HP LJ300-400 color M351-M451 (HKLM-x32\...\{15CA73D8-3C82-4BAE-86CD-945BF9620516}) (Version: - Hewlett-Packard) HP Update (HKLM-x32\...\{85DF2EED-08BC-46FB-90DA-28B0D0A8E8A8}) (Version: 5.003.000.004 - Hewlett-Packard) hpbDSService (HKLM-x32\...\{9767CBB5-2A81-427D-8F05-497737D56AA0}) (Version: 001.001.05133 - Hewlett-Packard) Hidden hpbM351M451DSService (HKLM-x32\...\{BF2198EB-503D-4E0B-89FB-509AADD6D545}) (Version: 001.001.05164 - Hewlett-Packard) Hidden HPLaserJet300-400ColorM351-M451Series_HelpLearnCenter_SI (HKLM-x32\...\{BD019D8F-25B9-49D6-B301-07AFF65E35DD}) (Version: 1.02.0000 - Hewlett-Packard) HPLJDXPHelper (HKLM-x32\...\{5E4DD8C2-A906-4F1B-94B6-4F6A51D625B2}) (Version: 020.021.004 - HP) Hidden HPLJUTCore (HKLM-x32\...\{7C8660F9-42DC-4D4E-85D5-CCAE3A2E5B1F}) (Version: 1.02.0014 - HP) Hidden HPLJUTM351-M451 (HKLM-x32\...\{E25710A1-F024-4BAF-898C-32703F047737}) (Version: 1.02.0013 - HP) Hidden hppLaserJetService (HKLM-x32\...\{86F513F7-6CFD-4B07-A762-28E5ED2CEE97}) (Version: 009.022.00806 - Hewlett-Packard) Hidden hppM351_M451LaserJetService (HKLM-x32\...\{96C103D3-F058-4F9A-BDD9-BBE9C1431376}) (Version: 005.020.00094 - Hewlett-Packard) Hidden hppToolboxProxyM351 (HKLM-x32\...\{76595FA3-0B98-43EF-BDD2-D04004AEB3A6}) (Version: 020.021.004 - HP) Hidden hpStatusAlerts (HKLM-x32\...\{BD666C86-25CE-4D88-9F7D-C6266394C18D}) (Version: 020.025.1119 - Hewlett Packard) Hidden hpStatusAlertsM351_M451 (HKLM-x32\...\{56D8909F-DFAF-4F79-83E9-DCEA942F0264}) (Version: 020.023.01805 - Hewlett-Packard) Hidden IGdm 2.4.1 (only current user) (HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\1ead4f81-c61a-5fa6-9e81-7a8c0c868952) (Version: 2.4.1 - ifedapo olarewaju) InPixio Photo Clip 7 (HKLM-x32\...\{829CAB57-8D17-49F8-A5B0-302B501FCEC2}) (Version: 7.7.0 - InPixio) inPixio Photo Clip 8 (HKLM-x32\...\{65634D2B-B6D1-4B35-B4C9-F3999B8D008B}) (Version: 8.5.0 - InPixio) InstaCards (HKLM-x32\...\{58259C24-7B5E-4977-93B0-E9EEA1B884CE}) (Version: 1.6.2 - InPixio) InstanceFinder (HKLM-x32\...\{32C0FD10-8FB4-427E-A16F-ED57C9343CF0}) (Version: 020.021.004 - HP) Hidden Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4352 - Intel Corporation) IrfanView 64 (remove only) (HKLM\...\IrfanView64) (Version: 4.42 - Irfan Skiljan) Java 8 Update 221 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180221F0}) (Version: 8.0.2210.11 - Oracle Corporation) Kaspersky Secure Connection (HKLM-x32\...\{F10AA188-7166-430E-8810-FEAB2AD73DE3}) (Version: 19.0.0.1088 - Kaspersky Lab) Hidden Kaspersky Secure Connection (HKLM-x32\...\InstallWIX_{F10AA188-7166-430E-8810-FEAB2AD73DE3}) (Version: 19.0.0.1088 - Kaspersky Lab) Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden LJDXPHelperUI (HKLM-x32\...\{EAECD0D7-F27D-4F13-8312-A9C0B5C5F1B7}) (Version: 020.021.004 - HP) Hidden Mafia.III.Digital.Deluxe.Edition.v1.01.Incl.2Dlcs-ALI213 version 1.01 (HKLM-x32\...\{AFF51286-259D-443B-B735-C1E71F233DA6}}_is1) (Version: 1.01 - Ali213.net) Malwarebytes version 3.8.3.2965 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.8.3.2965 - Malwarebytes) McAfee True Key (HKLM\...\TrueKey) (Version: 5.3.138.1 - McAfee, LLC) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE (HKLM-x32\...\{2C9EE786-1DDB-4C98-8FA4-B1B9B5A66B77}) (Version: 3.1.186.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}) (Version: 3.1.99.0 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\OneDriveSetup.exe) (Version: 19.152.0927.0012 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Mozilla Firefox 69.0.2 (x64 en-GB) (HKLM\...\Mozilla Firefox 69.0.2 (x64 en-GB)) (Version: 69.0.2 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 65.0 - Mozilla) MySQL Connector/ODBC 5.1 (HKLM-x32\...\{6F206B58-E2F7-4A70-ACAC-8E0ABFBC62F6}) (Version: 5.1.8 - Oracle Corporation) Newsbin for Astraweb (HKLM\...\Newsbin6) (Version: 6.72 - DJI Interprises, LLC) NOW TV Player 6.8.0.0 (HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\com.bskyb.nowtvplayer_is1) (Version: 6.8.0.0 - NOW TV) NVIDIA Graphics Driver 436.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 436.30 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.38.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.21 - NVIDIA Corporation) NVIDIA PhysX System Software 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation) Origin (HKLM-x32\...\Origin) (Version: 10.5.48.31055 - Electronic Arts, Inc.) paint.net (HKLM\...\{6AC1101E-7561-43C9-BEEA-4AB1D220D8FF}) (Version: 4.0.13 - dotPDN LLC) pCloud Drive (HKLM-x32\...\{C3C0052D-E704-4261-91D5-AEAE31F70EFF}) (Version: 3.8.0.0 - pCloud AG) Hidden pCloud Drive (HKLM-x32\...\{e30b668e-667b-451c-8072-85674a7ddc54}) (Version: 3.8.0.0 - pCloud AG) Process Hacker 2.39 (r124) (HKLM\...\Process_Hacker2_is1) (Version: 2.39.0.124 - wj32) Project My Screen App (HKLM-x32\...\{64537E9A-4DAE-42F9-BCD8-8AEEB84D1786}) (Version: 8.0.12349 - Microsoft Corporation) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.) QuickPar 0.9 (HKLM-x32\...\QuickPar) (Version: 0.9 - Peter B. Clements) Rapport (HKLM-x32\...\{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}) (Version: 3.5.1930.429 - Trusteer) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7687 - Realtek Semiconductor Corp.) Sky Go 1.4.16.0 (HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\com.bskyb.skygoplayer_is1) (Version: 1.4.16.0 - Sky) Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation) Skype version 8.53 (HKLM-x32\...\Skype_is1) (Version: 8.53 - Skype Technologies S.A.) Skype Web Plugin (HKLM-x32\...\{EB96DF8B-65A7-4E72-BFB1-38DB36870D16}) (Version: 7.32.6.278 - Skype Technologies S.A.) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.75813 - TeamViewer) TomTom MyDrive Connect 4.1.4.3089 (HKLM-x32\...\MyDriveConnect) (Version: 4.1.4.3089 - TomTom) ToolboxProxy (HKLM-x32\...\{55757576-28B2-4552-AAF6-340F9FFBA9FA}) (Version: 020.023.005 - HP) Hidden Trusteer Endpoint Protection (HKLM-x32\...\Rapport_msi) (Version: 3.5.1930.429 - Trusteer) UE4 Prerequisites (x64) (HKLM\...\{36EAD5CF-44EF-4FCF-8BE1-D96C4835D7A4}) (Version: 1.0.11.0 - Epic Games, Inc.) Hidden UE4 Prerequisites (x64) (HKLM-x32\...\{2890ae6b-90e9-448d-b3e6-97e43c21e2fd}) (Version: 1.0.13.0 - Epic Games, Inc.) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{9CBA860F-7437-4A75-941C-8EF559F2D145}) (Version: 2.52.0.0 - Microsoft Corporation) Video Download Capture V6.1.0 (HKLM-x32\...\{b3336f66-e079-4ff6-abdb-51e2fab781d5}_is1) (Version: 6.1.0 - APOWERSOFT LIMITED) Visual Studio C++ 10.0 Runtime (HKLM-x32\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.) VLC media player (HKLM\...\VLC media player) (Version: 3.0.8 - VideoLAN) WhatsApp (HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\WhatsApp) (Version: 0.3.4679 - WhatsApp) Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.) Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software) WinZip 23.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C2411D}) (Version: 23.0.13300 - Corel Corporation) WinZip_Pro 22.0.12684_ENG_Pre-Activated (HKLM-x32\...\WinZip_Pro 22.0.12684_ENG_Pre-Activated) (Version: 22.0.12684_ENG_Pre-Activated - Corel Corporation) Zebra Font Downloader (HKLM-x32\...\Zebra Font Downloader_is1) (Version: - Zebra Technologies Corporation) Zoom (HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\ZoomUMX) (Version: 4.1 - Zoom Video Communications, Inc.) Packages: ========= Adobe Photoshop Express: Image Editor, Adjustments, Filters, Effects, Borders -> C:\Program Files\WindowsApps\AdobeSystemsIncorporated.AdobePhotoshopExpress_3.0.316.0_x64__ynb6jyjzte8ga [2019-05-25] (Adobe Inc.) Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.0.2.0_x64__tf1gferkr813w [2019-05-28] (Autodesk Inc.) Blu-ray PRO -> C:\Program Files\WindowsApps\YellowElephantProductions.Blu-rayPRO_1.73.71.0_x64__p3e1zgp7z7szg [2019-07-09] (Yellow Elephant Productions) Candy Crush Soda Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSodaSaga_1.149.100.0_x86__kgqvnymyfvs32 [2019-10-04] (king.com) Dropbox for S mode -> C:\Program Files\WindowsApps\C27EB4BA.DROPBOX_22.4.3.0_x64__xbfy0k16fey96 [2019-09-27] (Dropbox Inc.) F5 Access -> C:\Program Files\WindowsApps\F5Networks.vpn.client_1.3.0.0_x64__btcnfmkykcjs2 [2018-10-13] (F5 Networks) Forza Hub -> C:\Program Files\WindowsApps\Microsoft.Lucille_1.0.4.0_x64__8wekyb3d8bbwe [2018-02-18] (Microsoft Studios) Forza Motorsport 6: Apex -> C:\Program Files\WindowsApps\Microsoft.ApexPG_2.8.18.1000_x64__8wekyb3d8bbwe [2018-04-13] (Microsoft Studios) HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_100.1.581.0_x64__v10z8vjag6ke6 [2019-07-20] (HP Inc.) Instagram -> C:\Program Files\WindowsApps\Facebook.InstagramBeta_41.1788.50991.0_x86__8xx8rvfyw5nnt [2018-07-17] (Instagram) Mail and Calendar -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12026.20218.0_x64__8wekyb3d8bbwe [2019-09-27] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1808.3.0_x64__8wekyb3d8bbwe [2019-08-30] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-15] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-15] (Microsoft Corporation) [MS Ad] Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.32.12463.0_x64__8wekyb3d8bbwe [2019-09-11] (Microsoft Corporation) [MS Ad] Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.4.10022.0_x64__8wekyb3d8bbwe [2019-10-06] (Microsoft Studios) [MS Ad] MSN Money -> C:\Program Files\WindowsApps\Microsoft.BingFinance_4.31.11905.0_x64__8wekyb3d8bbwe [2019-07-20] (Microsoft Corporation) [MS Ad] MSN Sport -> C:\Program Files\WindowsApps\Microsoft.BingSports_4.31.11905.0_x64__8wekyb3d8bbwe [2019-07-20] (Microsoft Corporation) [MS Ad] MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.32.12463.0_x64__8wekyb3d8bbwe [2019-09-11] (Microsoft Corporation) [MS Ad] Photos Add-on -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2017.39121.36610.0_x64__8wekyb3d8bbwe [2018-09-13] (Microsoft Corporation) Player for Media -> C:\Program Files\WindowsApps\VirtualPulse.PlayerforMedia_1.69.153.0_x64__nh7p8cqfc4t04 [2019-06-17] (Virtual Pulse) Rar. Click here! -> C:\Program Files\WindowsApps\61262Arrowgance.Rar.Clickhere_1.2.0.0_neutral__erx5c4savp7xt [2018-02-25] (Arrowgance) TeamViewer: Remote Control -> C:\Program Files\WindowsApps\TeamViewer.31414B719FA93_14.0.100.0_x86__89446h4zmeyyt [2018-10-24] (TeamViewer) Twitter -> C:\Program Files\WindowsApps\9E2F88E3.Twitter_6.1.4.1000_neutral__wgeqdkkx372wm [2018-09-08] (Twitter Inc.) Video Player All Formats -> C:\Program Files\WindowsApps\10414Kingloft.VideoPlayerAllFormats_1.1.2.0_x64__hwg4vmr4pnwdp [2018-04-16] (Kingloft) [MS Ad] VLC for Windows Store -> C:\Program Files\WindowsApps\VideoLAN.VLCforWindows8_3.1.1.0_x86__paz6r1rewnh0a [2018-08-06] (VideoLAN) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2643124959-2563984870-1026749049-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-513FE7238137} -> [Creative Cloud Files] => C:\Users\Peter\Creative Cloud Files [2016-10-08 12:31] CustomCLSID: HKU\S-1-5-21-2643124959-2563984870-1026749049-1001_Classes\CLSID\{41052F6E-3662-4584-BCD3-77BCCAAE8470}\InprocServer32 -> C:\Users\Peter\AppData\Local\SkypePlugin\7.32.6.278\GatewayActiveX-x64.dll (Microsoft Corporation -> Skype Technologies S.A.) CustomCLSID: HKU\S-1-5-21-2643124959-2563984870-1026749049-1001_Classes\CLSID\{CB2B673F-D441-4CD4-AFBE-DC4037CA4220}\InprocServer32 -> C:\Program Files\WinZip\adxloader64.WinZipExpressForOffice.dll (Corel Corporation -> ) CustomCLSID: HKU\S-1-5-21-2643124959-2563984870-1026749049-1001_Classes\CLSID\{E31EA727-12ED-4702-820C-4B6445F28E1A} -> [Dropbox] => C:\Users\Peter\Downloads\drop box work\Dropbox [2016-04-07 15:52] CustomCLSID: HKU\S-1-5-21-2643124959-2563984870-1026749049-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems Incorporated -> Adobe Systems) SSODL: EldosMountNotificator-cbfs6 - {34505669-1400-447A-A735-B6A3413825D9} - C:\WINDOWS\system32\cbfsMntNtf6.dll (EldoS Corporation -> /n software, Inc.) SSODL-x32: EldosMountNotificator-cbfs6 - {34505669-1400-447A-A735-B6A3413825D9} - C:\WINDOWS\SysWOW64\cbfsMntNtf6.dll (EldoS Corporation -> /n software, Inc.) ShellServiceObjects: Virtual Storage Mount Notification -> {34505669-1400-447A-A735-B6A3413825D9} => C:\WINDOWS\system32\cbfsMntNtf6.dll [2016-09-09] (EldoS Corporation -> /n software, Inc.) ShellServiceObjects-x32: Virtual Storage Mount Notification -> {34505669-1400-447A-A735-B6A3413825D9} => C:\WINDOWS\SysWOW64\cbfsMntNtf6.dll [2016-09-09] (EldoS Corporation -> /n software, Inc.) ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2217832 2009-02-26] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ pCloudINPROGRESS] -> {D8BFAFBD-B670-4252-9C17-9CF1C64C2BAF} => C:\Program Files (x86)\pCloud Drive\OverlayIcon64.dll [2017-10-23] (TODO: <Company name>) [File not signed] ShellIconOverlayIdentifiers: [ pCloudINSYNC] -> {8D0C0582-552A-4A6B-9455-DA63E1F329C0} => C:\Program Files (x86)\pCloud Drive\OverlayIcon64.dll [2017-10-23] (TODO: <Company name>) [File not signed] ShellIconOverlayIdentifiers: [ pCloudNOSYNC] -> {3858ED1B-8F1C-42ED-A8A9-FDBF591E3C6B} => C:\Program Files (x86)\pCloud Drive\OverlayIcon64.dll [2017-10-23] (TODO: <Company name>) [File not signed] ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] (Adobe Systems Incorporated -> ) ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] (Adobe Systems Incorporated -> ) ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] (Adobe Systems Incorporated -> ) ShellIconOverlayIdentifiers: [EldosIconOverlay-cbfs6] -> {7BB0B781-331E-4EED-A0F6-05B01FC88898} => C:\WINDOWS\system32\cbfsMntNtf6.dll [2016-09-09] (EldoS Corporation -> /n software, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [EldosIconOverlay-cbfs6] -> {7BB0B781-331E-4EED-A0F6-05B01FC88898} => C:\WINDOWS\system32\cbfsMntNtf6.dll [2016-09-09] (EldoS Corporation -> /n software, Inc.) ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed] ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] (Adobe Systems Incorporated -> ) ContextMenuHandlers1-x32: [Adobe.Acrobat.ContextMenu] -> {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} => C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat Elements\ContextMenu.dll [2006-10-22] (Adobe Systems, Incorporated -> Adobe Systems Inc.) ContextMenuHandlers1: [ContextMenuExtension] -> {a0b73fac-351f-3948-9d8a-1dad9d870193} => C:\Program Files (x86)\pCloud Drive\ContextMenuHandler.DLL [2019-01-22] (pCloud AG) [File not signed] ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers1: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\WZSHLS64.DLL [2018-11-07] (Corel Corporation -> WinZip Computing) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed] ContextMenuHandlers4: [ContextMenuExtension] -> {a0b73fac-351f-3948-9d8a-1dad9d870193} => C:\Program Files (x86)\pCloud Drive\ContextMenuHandler.DLL [2019-01-22] (pCloud AG) [File not signed] ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\WZSHLS64.DLL [2018-11-07] (Corel Corporation -> WinZip Computing) ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2019-09-05] (NVIDIA Corporation -> NVIDIA Corporation) ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed] ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] (Adobe Systems Incorporated -> ) ContextMenuHandlers6-x32: [Adobe.Acrobat.ContextMenu] -> {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} => C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat Elements\ContextMenu.dll [2006-10-22] (Adobe Systems, Incorporated -> Adobe Systems Inc.) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers6: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\WZSHLS64.DLL [2018-11-07] (Corel Corporation -> WinZip Computing) ==================== Codecs (Whitelisted) ================== ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2017-01-25 20:07 - 2017-01-25 20:07 - 000125952 _____ () [File not signed] \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\ffi\build\Release\ffi_bindings.node 2017-01-25 20:07 - 2017-01-25 20:07 - 000118272 _____ () [File not signed] \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\fs-ext\build\Release\fs-ext.node 2017-01-25 20:07 - 2017-01-25 20:07 - 000086528 _____ () [File not signed] \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\idle-gc\build\Release\idle-gc.node 2017-01-25 20:07 - 2017-01-25 20:07 - 000214528 _____ () [File not signed] \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\node-vulcanjs\build\Release\VulcanJS.node 2017-01-25 20:06 - 2017-01-25 20:06 - 000117248 _____ () [File not signed] \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\ref\build\Release\binding.node 2017-03-28 15:32 - 2017-03-28 15:32 - 000073216 _____ () [File not signed] C:\Program Files (x86)\Garmin\Device Interaction Service\FixBootSector.dll 2017-02-14 09:42 - 2017-02-14 09:42 - 000326144 _____ () [File not signed] C:\Program Files (x86)\Garmin\Device Interaction Service\GpsImgWrapper.dll 2019-02-08 10:12 - 2019-10-03 21:42 - 001901568 _____ () [File not signed] C:\Program Files (x86)\Microsoft\Skype for Desktop\ffmpeg.dll 2018-10-20 17:56 - 2019-10-03 21:42 - 000115712 _____ () [File not signed] C:\Program Files (x86)\Microsoft\Skype for Desktop\libegl.dll 2018-10-20 17:56 - 2019-10-03 21:42 - 004636672 _____ () [File not signed] C:\Program Files (x86)\Microsoft\Skype for Desktop\libglesv2.dll 2016-07-20 17:24 - 2016-07-20 17:24 - 000266240 _____ () [File not signed] C:\Program Files (x86)\Origin\imageformats\qmng.dll 2019-10-08 00:07 - 2019-08-20 15:11 - 000015360 _____ () [File not signed] C:\Program Files (x86)\Origin\libEGL.DLL 2019-10-08 00:07 - 2019-08-20 15:11 - 003090944 _____ () [File not signed] C:\Program Files (x86)\Origin\libGLESv2.dll 2019-03-08 18:32 - 2019-03-08 18:32 - 001905152 _____ () [File not signed] C:\Program Files (x86)\pCloud Drive\pSyncLib.dll 2015-06-02 15:51 - 2015-06-02 15:51 - 000545792 _____ () [File not signed] C:\Program Files (x86)\Trusteer\Rapport\bin\js32.dll 2006-10-23 00:19 - 2006-10-23 00:19 - 000019968 _____ (Adobe Systems Inc.) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroTray.DEU 2006-10-23 00:10 - 2006-10-23 00:10 - 000019968 _____ (Adobe Systems Inc.) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroTray.FRA 2006-08-02 07:52 - 2006-08-02 07:52 - 000126976 ____R (Adobe Systems Inc.) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\asneu.dll 2006-09-14 23:20 - 2006-09-14 23:20 - 000212992 ____R (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\adobe_epic.dll 2006-09-14 23:46 - 2006-09-14 23:46 - 000208896 ____R (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\adobe_pcd.dll 2006-09-14 23:20 - 2006-09-14 23:20 - 000346112 ____R (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\adobe_personalization.dll 2017-03-28 15:32 - 2017-03-28 15:32 - 001976832 _____ (Apache Software Foundation) [File not signed] C:\Program Files (x86)\Garmin\Device Interaction Service\XercesLib.dll 2017-03-28 15:34 - 2017-03-28 15:34 - 000234496 _____ (Dynastream Innovations Inc.) [File not signed] C:\Program Files (x86)\Garmin\Device Interaction Service\ANT_WrappedLib.dll 2017-03-28 15:32 - 2017-03-28 15:32 - 002711552 _____ (Garmin International) [File not signed] C:\Program Files (x86)\Garmin\Device Interaction Service\legacyio.dll 2017-02-14 09:42 - 2017-02-14 09:42 - 000343552 _____ (Garmin International, Inc.) [File not signed] C:\Program Files (x86)\Garmin\Device Interaction Service\IMG_GPSMAP.dll 2017-03-28 15:32 - 2017-03-28 15:32 - 000425472 _____ (Garmin) [File not signed] C:\Program Files (x86)\Garmin\Device Interaction Service\XMLdll.dll 2009-09-16 19:44 - 2009-09-16 19:44 - 000153088 _____ (Hewlett Packard) [File not signed] C:\WINDOWS\System32\hptcpmib.dll 2009-09-16 19:45 - 2009-09-16 19:45 - 000331264 _____ (Hewlett Packard) [File not signed] C:\WINDOWS\System32\HpTcpMon.dll 2009-09-16 12:44 - 2009-09-16 12:44 - 000132096 _____ (Hewlett Packard) [File not signed] C:\WINDOWS\System32\hpzjrd01.dll 2006-09-15 13:58 - 2006-09-15 13:58 - 000934400 ____R (Macrovision Europe Ltd.) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\FNP_Act_Installer.dll 2008-08-25 23:50 - 2008-08-25 23:50 - 000155648 _____ (Microsoft Corporation) [File not signed] C:\Program Files (x86)\Common Files\Microsoft Shared\VBA\VBA6\1033\VBE6INTL.DLL 2009-09-16 19:45 - 2009-09-16 19:45 - 000317440 _____ (Microsoft Corporation) [File not signed] C:\WINDOWS\System32\HPTcpMUI.dll 2015-07-02 17:44 - 2015-07-02 17:44 - 000057344 _____ (Open Source Software community LGPL) [File not signed] C:\Program Files (x86)\pCloud Drive\pthreadVSE2.dll 2017-03-28 15:32 - 2017-03-28 15:32 - 000090112 _____ (Silicon Laboratories, Inc.) [File not signed] C:\Program Files (x86)\Garmin\Device Interaction Service\DSI_SiUSBXp_3_1.DLL 2019-10-08 00:06 - 2019-08-20 15:11 - 000002560 _____ (The ICU Project) [File not signed] C:\Program Files (x86)\Origin\icudt58.dll 2019-10-08 00:06 - 2019-08-20 15:11 - 001252864 _____ (The ICU Project) [File not signed] C:\Program Files (x86)\Origin\icuuc58.dll 2019-10-08 00:07 - 2019-08-20 15:11 - 001277440 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\LIBEAY32.dll 2019-10-08 00:07 - 2019-08-20 15:11 - 000279040 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\ssleay32.dll 2019-10-08 00:06 - 2019-08-20 15:11 - 000030208 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\imageformats\qgif.dll 2019-10-08 00:06 - 2019-08-20 15:11 - 000032768 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\imageformats\qico.dll 2019-10-08 00:06 - 2019-08-20 15:11 - 000256512 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\imageformats\qjpeg.dll 2019-10-08 00:06 - 2019-08-20 15:11 - 000026112 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\imageformats\qtga.dll 2019-10-08 00:06 - 2019-08-20 15:11 - 000305152 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\imageformats\qtiff.dll 2019-10-08 00:06 - 2019-08-20 15:11 - 000025600 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\imageformats\qwbmp.dll 2019-10-08 00:07 - 2019-08-20 15:11 - 001611264 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\platforms\qwindows.dll 2019-10-08 00:07 - 2019-08-20 15:11 - 005487104 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Core.dll 2019-10-08 00:07 - 2019-08-20 15:11 - 005841920 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Gui.dll 2019-10-08 00:07 - 2019-08-20 15:11 - 000709120 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Multimedia.dll 2019-10-08 00:07 - 2019-08-20 15:11 - 001179136 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Network.dll 2019-10-08 00:07 - 2019-08-20 15:11 - 000207360 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Positioning.dll 2019-10-08 00:07 - 2019-08-20 15:11 - 000310272 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5PrintSupport.dll 2019-10-08 00:07 - 2019-08-20 15:11 - 003513344 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Qml.dll 2019-10-08 00:07 - 2019-08-20 15:11 - 003390976 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Quick.dll 2019-10-08 00:07 - 2019-08-20 15:11 - 000068096 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5QuickWidgets.dll 2019-10-08 00:07 - 2019-08-20 15:11 - 000045568 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5TextToSpeech.dll 2019-10-08 00:07 - 2019-08-20 15:11 - 000116224 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5WebChannel.dll 2019-10-08 00:07 - 2019-08-20 15:11 - 054071296 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5WebEngineCore.dll 2019-10-08 00:07 - 2019-08-20 15:11 - 000211456 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5WebEngineWidgets.dll 2019-10-08 00:07 - 2019-08-20 15:11 - 000146432 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5WebSockets.dll 2019-10-08 00:07 - 2019-08-20 15:11 - 005089792 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Widgets.dll 2019-10-08 00:07 - 2019-08-20 15:11 - 000184832 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Xml.dll 2017-10-23 18:28 - 2017-10-23 18:28 - 000342016 _____ (TODO: <Company name>) [File not signed] C:\Program Files (x86)\pCloud Drive\OverlayIcon64.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\Peter\Desktop\2016-09-06 10.53.26.jpg:com.dropbox.attributes [385] AlternateDataStreams: C:\Users\Peter\Desktop\Dog try art.jpg:com.dropbox.attributes [168] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\amsdk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\amsdk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\localhost -> localhost IE trusted site: HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\webcompanion.com -> hxxp://webcompanion.com ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-10-30 08:24 - 2016-12-22 23:22 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\ HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Peter\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img1.jpg DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Prompt) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == If an entry is included in the fixlist, it will be removed. HKLM\...\StartupApproved\Run32: => "CanonQuickMenu" HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\StartupApproved\Run: => "GarminExpressTrayApp" HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\StartupApproved\Run: => "MyDriveConnect.exe" HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\StartupApproved\Run: => "Discord" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [UDP Query User{28DA58B9-107A-4342-825F-4D28AF7C76CF}C:\users\peter\appdata\roaming\sky\sky go\sky go.exe] => (Allow) C:\users\peter\appdata\roaming\sky\sky go\sky go.exe (Sky UK Limited -> Sky UK) FirewallRules: [TCP Query User{FF9BEF22-89C1-46AE-91D7-A71F2A752534}C:\users\peter\appdata\roaming\sky\sky go\sky go.exe] => (Allow) C:\users\peter\appdata\roaming\sky\sky go\sky go.exe (Sky UK Limited -> Sky UK) FirewallRules: [{D010BD56-CD66-46B3-AD5B-F678E9F66749}] => (Allow) C:\Program Files (x86)\pCloud Drive\pCloud.exe (pCloud AG -> pCloud AG) FirewallRules: [{1CC6CB33-F9ED-4CB1-B95E-59A46053DEC9}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BFLauncher_x86.exe (Electronic Arts -> EA Digital Illusions CE AB) FirewallRules: [{B34D619C-6D4B-4DF8-827E-F34402A3ABF0}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BFLauncher_x86.exe (Electronic Arts -> EA Digital Illusions CE AB) FirewallRules: [{459C331C-7DF4-4715-A8F9-0E6C71C081F5}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BFLauncher.exe (Electronic Arts -> EA Digital Illusions CE AB) FirewallRules: [{B42230AE-69FB-4FBC-BEC8-4175A9B77802}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BFLauncher.exe (Electronic Arts -> EA Digital Illusions CE AB) FirewallRules: [UDP Query User{D901C1EA-1B3D-4891-87CE-5EDF48834091}C:\program files (x86)\origin games\battlefield 4\bf4.exe] => (Allow) C:\program files (x86)\origin games\battlefield 4\bf4.exe (Electronic Arts -> EA Digital Illusions CE AB) FirewallRules: [TCP Query User{20EC1DFA-5EC6-42F8-B980-E992D3286389}C:\program files (x86)\origin games\battlefield 4\bf4.exe] => (Allow) C:\program files (x86)\origin games\battlefield 4\bf4.exe (Electronic Arts -> EA Digital Illusions CE AB) FirewallRules: [UDP Query User{BEF63613-334D-450D-9CB2-EC4917105634}C:\users\peter\appdata\local\skypeplugin\pluginhost.exe] => (Allow) C:\users\peter\appdata\local\skypeplugin\pluginhost.exe (Microsoft Corporation -> Skype Technologies S.A.) FirewallRules: [TCP Query User{3BA07005-6AA1-4770-83E9-3BBEE9FB4096}C:\users\peter\appdata\local\skypeplugin\pluginhost.exe] => (Allow) C:\users\peter\appdata\local\skypeplugin\pluginhost.exe (Microsoft Corporation -> Skype Technologies S.A.) FirewallRules: [UDP Query User{0C68D00C-B9BE-4917-B2B7-91E8103BC152}C:\program files (x86)\microsoft office\office12\groove.exe] => (Block) C:\program files (x86)\microsoft office\office12\groove.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [TCP Query User{08D18416-695C-4A09-B5DC-6E571C385E61}C:\program files (x86)\microsoft office\office12\groove.exe] => (Block) C:\program files (x86)\microsoft office\office12\groove.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [UDP Query User{A6D71720-C7BB-4857-AA32-C54A9C1805DA}C:\program files (x86)\mafia iii\mafia3.exe] => (Allow) C:\program files (x86)\mafia iii\mafia3.exe (2K Czech) [File not signed] FirewallRules: [TCP Query User{5E71B47C-69E3-4125-B9BD-F2DE4AADAB2B}C:\program files (x86)\mafia iii\mafia3.exe] => (Allow) C:\program files (x86)\mafia iii\mafia3.exe (2K Czech) [File not signed] FirewallRules: [UDP Query User{A7F4F472-69F2-463E-8F51-308211E7E98A}C:\program files (x86)\mafia iii\launcher.exe] => (Allow) C:\program files (x86)\mafia iii\launcher.exe (2K Games) [File not signed] FirewallRules: [TCP Query User{9D20E56A-7C64-48F0-B862-BC05B8C45B33}C:\program files (x86)\mafia iii\launcher.exe] => (Allow) C:\program files (x86)\mafia iii\launcher.exe (2K Games) [File not signed] FirewallRules: [{4D1ADD3A-3993-456B-AF7A-C32BC8333D41}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture 6\rtmpsrv.exe (Apowersoft Ltd -> ) FirewallRules: [{7A28407B-6648-4AC9-BB70-C17EEDA4993F}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture 6\rtmpsrv.exe (Apowersoft Ltd -> ) FirewallRules: [{D425ED22-E564-479D-85B9-29B791C92E51}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture 6\Video Download Capture 6.exe (Apowersoft Ltd -> Apowersoft) FirewallRules: [{2290E416-3B83-4D12-9F69-C0A8E05B2A0E}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture 6\Video Download Capture 6.exe (Apowersoft Ltd -> Apowersoft) FirewallRules: [{7C938066-335E-4FD7-ADC5-09308FAD4E04}] => (Allow) C:\Users\Peter\AppData\Local\Apowersoft\Online Video Downloader\Online Video Downloader.exe (Apowersoft Ltd -> Apowersoft) FirewallRules: [{BDC66059-10F4-40D1-A532-CF0A204D85A6}] => (Allow) C:\Users\Peter\AppData\Local\Apowersoft\Online Video Downloader\Online Video Downloader.exe (Apowersoft Ltd -> Apowersoft) FirewallRules: [{9518A486-2237-44FB-80E6-BDA7E1006019}] => (Allow) C:\Users\Peter\AppData\Local\Apowersoft\Apowersoft Online Launcher\Apowersoft Online Launcher.exe (Apowersoft Ltd -> Apowersoft) FirewallRules: [{2326C416-6308-44E8-88C5-632066056722}] => (Allow) C:\Users\Peter\AppData\Local\Apowersoft\Apowersoft Online Launcher\Apowersoft Online Launcher.exe (Apowersoft Ltd -> Apowersoft) FirewallRules: [UDP Query User{073B7D87-130F-435D-9E77-A564AAADC574}C:\program files (x86)\epic games\4.13\engine\binaries\win64\ue4editor.exe] => (Allow) C:\program files (x86)\epic games\4.13\engine\binaries\win64\ue4editor.exe (Epic Games Inc. -> Epic Games, Inc.) FirewallRules: [TCP Query User{2A0C94B7-F946-4B83-8C09-93D335DCE6F2}C:\program files (x86)\epic games\4.13\engine\binaries\win64\ue4editor.exe] => (Allow) C:\program files (x86)\epic games\4.13\engine\binaries\win64\ue4editor.exe (Epic Games Inc. -> Epic Games, Inc.) FirewallRules: [UDP Query User{1FA7AF85-8A31-464D-821A-11FD0258E22E}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.) FirewallRules: [TCP Query User{742B4A08-5632-4E62-801B-399D3F97B13D}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.) FirewallRules: [UDP Query User{E19B8A54-E21F-4B36-B4B1-8AEC0288585C}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.) FirewallRules: [TCP Query User{2AE4F5DF-63CE-4EE5-8F08-772B5FD40C47}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.) FirewallRules: [{B0A0C442-A8EA-4158-9751-70F727047571}] => (Allow) C:\Program Files\Newsbin\newsbinpro64.exe (DJI Interprises, LLC -> CMCEI) [File not signed] FirewallRules: [{17E3AAAE-1BBA-43D8-AB64-2964FC43F1F2}] => (Allow) C:\Program Files\Newsbin\newsbinpro64.exe (DJI Interprises, LLC -> CMCEI) [File not signed] FirewallRules: [{909C6D02-5B51-4BFD-9853-F1D46E1444DB}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{C27D32C6-280B-4E48-BFBA-A97AAEA29C33}] => (Allow) C:\Program Files\Newsbin\newsbinpro64.exe (DJI Interprises, LLC -> CMCEI) [File not signed] FirewallRules: [{ABE75BF8-9BAF-4534-9A7B-FB658CC8812E}] => (Allow) C:\Program Files\Newsbin\newsbinpro64.exe (DJI Interprises, LLC -> CMCEI) [File not signed] FirewallRules: [{55E0A659-8BE8-4AD4-850E-5403071CB3D5}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe (Even Balance, Inc. -> ) FirewallRules: [{D011CFD6-61CF-4E0C-935E-FC32CAC06197}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe (Even Balance, Inc. -> ) FirewallRules: [{599EFDAE-2C36-48DE-BB4D-56A64B1C3825}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe (Even Balance, Inc. -> ) FirewallRules: [{782961F5-0892-4854-BA07-FBFAD4FF012D}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe (Even Balance, Inc. -> ) FirewallRules: [{5CC3697F-22A4-40B6-BF84-3E62ECE13AD2}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe (Electronic Sports Network i Sverige AB -> ESN Social Software AB) FirewallRules: [{9C114559-9480-4E54-B843-2841A8958347}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe (Electronic Sports Network i Sverige AB -> ESN Social Software AB) FirewallRules: [{C8E615C6-FAA5-4303-BBEE-AF4B10796E25}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4WebHelper.exe (Electronic Arts -> EA Digital Illusions CE AB) FirewallRules: [{D18D6DD3-8E77-4A48-AF3B-0EC4FA2334F6}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4WebHelper.exe (Electronic Arts -> EA Digital Illusions CE AB) FirewallRules: [{1B8BA6FD-2272-4C17-ADFF-23FA97C32CC6}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4X86WebHelper.exe (Electronic Arts -> EA Digital Illusions CE AB) FirewallRules: [{0588C3DB-9AE7-46A6-97DA-2277DEE8DC9E}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4X86WebHelper.exe (Electronic Arts -> EA Digital Illusions CE AB) FirewallRules: [TCP Query User{E86BAA9A-AD5F-43D1-B34F-615C5080C6D1}C:\program files (x86)\origin games\battlefield 4\bf4.exe] => (Allow) C:\program files (x86)\origin games\battlefield 4\bf4.exe (Electronic Arts -> EA Digital Illusions CE AB) FirewallRules: [UDP Query User{870F63BC-908A-4A85-AEFE-42FF29643189}C:\program files (x86)\origin games\battlefield 4\bf4.exe] => (Allow) C:\program files (x86)\origin games\battlefield 4\bf4.exe (Electronic Arts -> EA Digital Illusions CE AB) FirewallRules: [{46FC59BE-8F46-48D1-8689-C05B95CBDC71}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation) FirewallRules: [{8759BAF8-31A5-475C-B7B0-2893395736AB}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation) FirewallRules: [{00534A32-2DF4-420B-B6C7-95ABE3556483}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Squad\squad_launcher.exe No File FirewallRules: [{A8B5AC5C-E0D3-43BE-A296-1A1FFA240247}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Squad\squad_launcher.exe No File FirewallRules: [{95D0C50F-E36E-40ED-BE3F-967544647F7E}] => (Allow) D:\SteamLibrary\steamapps\common\Grand Theft Auto IV\GTAIV\LaunchGTAIV.exe (Sony DADC Austria AG -> Sony DADC Austria AG) [File not signed] FirewallRules: [{0A189D0A-A70F-4DC9-AC6F-DE7649B96B4A}] => (Allow) D:\SteamLibrary\steamapps\common\Grand Theft Auto IV\GTAIV\LaunchGTAIV.exe (Sony DADC Austria AG -> Sony DADC Austria AG) [File not signed] FirewallRules: [{62D8605A-8E5C-47D9-87A7-612835C95B88}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) FirewallRules: [{CF905B86-1DBE-4978-91CE-C8FC57B8B808}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) FirewallRules: [{637EDFE0-D2EC-44F4-9EED-891BA7E32CB4}] => (Allow) C:\Users\Peter\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) FirewallRules: [{A73A6825-3DA1-4682-A455-453342E88651}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [TCP Query User{B4AFE14B-B5B8-46C7-B3DB-3C8A0D0EADDA}C:\program files (x86)\steam\steamapps\common\squad\squadgame\binaries\win64\squadgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\squad\squadgame\binaries\win64\squadgame.exe No File FirewallRules: [UDP Query User{62423C4C-5837-4569-BC04-0FFCD53E6C66}C:\program files (x86)\steam\steamapps\common\squad\squadgame\binaries\win64\squadgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\squad\squadgame\binaries\win64\squadgame.exe No File FirewallRules: [{CECFF37F-8AA5-47B6-956D-40A1561BCB91}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) FirewallRules: [{CF5F5B4F-2153-4D21-AC57-2F79E90E9EC9}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{05830255-4505-42CD-9608-216A9C3ACC61}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) ==================== Restore Points ========================= 08-10-2019 14:44:38 Scheduled Checkpoint ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (10/11/2019 01:19:26 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (876,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (10/11/2019 11:10:03 AM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (19708,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (10/11/2019 10:53:38 AM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (17232,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (10/11/2019 10:41:27 AM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (9156,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (10/11/2019 10:35:15 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: esu.exe, version: 1.0.0.0, time stamp: 0x58dac8d5 Faulting module name: KERNELBASE.dll, version: 10.0.18362.418, time stamp: 0x2b181c2c Exception code: 0xe0434352 Fault offset: 0x00113572 Faulting process id: 0x2440 Faulting application start time: 0x01d580172dc6c39b Faulting application path: C:\Program Files (x86)\Garmin\Express SelfUpdater\esu.exe Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll Report Id: 28028709-e647-46f1-bbec-3a8f26fc5b70 Faulting package full name: Faulting package-relative application ID: Error: (10/11/2019 10:35:15 AM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Application: esu.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.IO.FileNotFoundException at Garmin.Omt.Service.Shared.Overrides+<UpdateDatacenterOverridesAsync>d__61.MoveNext() at System.Runtime.CompilerServices.AsyncTaskMethodBuilder.Start[[Garmin.Omt.Service.Shared.Overrides+<UpdateDatacenterOverridesAsync>d__61, ExpressSelfUpdater, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null]](<UpdateDatacenterOverridesAsync>d__61 ByRef) at Garmin.Omt.Service.Shared.Overrides.UpdateDatacenterOverridesAsync(Boolean) at Garmin.Omt.Service.Shared.Overrides..cctor() Exception Info: System.TypeInitializationException at Garmin.Omt.Service.Shared.Overrides.get_OmtBaseUrl() at Garmin.Omt.Express.SelfUpdater.Program.RealMain() at Garmin.Omt.Express.SelfUpdater.Program.Main(System.String[]) Error: (10/11/2019 12:21:58 AM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (7820,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (10/11/2019 12:12:39 AM) (Source: Microsoft-Windows-Perflib) (EventID: 1020) (User: NT AUTHORITY) Description: The required buffer size is greater than the buffer size passed to the Collect function of the "C:\Windows\System32\perfts.dll" Extensible Counter DLL for the "LSM" service. The given buffer size was 23408 and the required size was 43712. System errors: ============= Error: (10/11/2019 11:50:49 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-HUP2O0G) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Error: (10/11/2019 11:50:49 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-HUP2O0G) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Error: (10/11/2019 11:50:49 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-HUP2O0G) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Error: (10/11/2019 11:50:49 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-HUP2O0G) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Error: (10/11/2019 11:50:48 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-HUP2O0G) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Error: (10/11/2019 11:50:48 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-HUP2O0G) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Error: (10/11/2019 11:50:48 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-HUP2O0G) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Error: (10/11/2019 11:50:48 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-HUP2O0G) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Windows Defender: =================================== Date: 2019-10-10 17:34:54.210 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {2D9F0E9B-B684-460F-A81B-8D289AD40E3F} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2019-10-10 15:42:31.471 Description: C:\Users\Peter\AppData\Local\Temp\is-4493R.tmp\NOWTVPlayer-Windows.tmp has been blocked from modifying %desktopdirectory%\ by Controlled Folder Access. Detection time: 2019-10-10T14:42:31.470Z Path: %desktopdirectory%\ Process Name: C:\Users\Peter\AppData\Local\Temp\is-4493R.tmp\NOWTVPlayer-Windows.tmp Security intelligence Version: 1.303.1350.0 Engine Version: 1.1.16400.2 Product Version: 4.18.1909.6 Date: 2019-10-09 14:14:05.220 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {810CCB34-3EDB-4D13-8633-BDBC3EFAFA84} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2019-10-08 14:30:44.734 Description: C:\Users\Peter\AppData\Local\Temp\is-DMEHL.tmp\mb-setup.tmp has been blocked from modifying %common_desktop%\ by Controlled Folder Access. Detection time: 2019-10-08T13:30:44.733Z Path: %common_desktop%\ Process Name: C:\Users\Peter\AppData\Local\Temp\is-DMEHL.tmp\mb-setup.tmp Security intelligence Version: 1.303.1189.0 Engine Version: 1.1.16400.2 Product Version: 4.18.1909.6 Date: 2019-10-08 14:27:08.403 Description: C:\Users\Peter\AppData\Local\Temp\mwbCFF4.tmp\mb-support.exe has been blocked from modifying %common_desktop%\ by Controlled Folder Access. Detection time: 2019-10-08T13:27:08.402Z Path: %common_desktop%\ Process Name: C:\Users\Peter\AppData\Local\Temp\mwbCFF4.tmp\mb-support.exe Security intelligence Version: 1.303.1189.0 Engine Version: 1.1.16400.2 Product Version: 4.18.1909.6 Date: 2019-10-04 18:45:30.180 Description: Windows Defender Antivirus Real-Time Protection feature has encountered an error and failed. Feature: On Access Error Code: 0x8007043c Error description: This service cannot be started in Safe Mode Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem. CodeIntegrity: =================================== Date: 2019-10-11 13:18:45.474 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2019-10-11 13:14:04.464 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2019-10-11 13:14:02.310 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2019-10-11 13:13:42.056 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2019-10-11 13:13:27.642 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2019-10-11 13:10:48.537 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2019-10-11 10:32:04.331 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2019-10-11 00:10:58.322 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. ==================== Memory info =========================== BIOS: American Megatrends Inc. 1002 09/27/2013 Motherboard: ASUSTeK COMPUTER INC. G10AC Processor: Intel(R) Core(TM) i5-4440S CPU @ 2.80GHz Percentage of memory in use: 85% Total physical RAM: 8099.13 MB Available physical RAM: 1151.91 MB Total Virtual: 20387.13 MB Available Virtual: 9941.44 MB ==================== Drives ================================ Drive 😄 () (Fixed) (Total:475.99 GB) (Free:70.19 GB) NTFS Drive d: (Hardy) (Fixed) (Total:1863 GB) (Free:1322.32 GB) NTFS Drive e: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0 GB) NTFS ==>[system with boot components (obtained from drive)] Drive f: () (Fixed) (Total:111.69 GB) (Free:11.61 GB) NTFS Drive g: () (Removable) (Total:57.87 GB) (Free:29.36 GB) FAT32 \\?\Volume{71ba5a6a-0000-0000-0000-100000000000}\ (System Reserved) (Fixed) (Total:0.49 GB) (Free:0.45 GB) NTFS \\?\Volume{71ba5a6a-0000-0000-0000-c01e77000000}\ () (Fixed) (Total:0.46 GB) (Free:0.04 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows XP) (Size: 1863 GB) (Disk ID: 70BA4F4B) Partition 2: (Active) - (Size=1863 GB) - (Type=05) ======================================================== Disk: 1 (MBR Code: Windows 7/8/10) (Size: 476.9 GB) (Disk ID: 71BA5A6A) Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=476 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=468 MB) - (Type=27) ======================================================== Disk: 2 (MBR Code: Windows 7/8/10) (Size: 111.8 GB) (Disk ID: 67EBA4D2) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=111.7 GB) - (Type=07 NTFS) ======================================================== Disk: 3 (Protective MBR) (Size: 57.9 GB) (Disk ID: 00000000) Partition: GPT. ==================== End of Addition.txt ============================
- 21 replies
-
- trojan:win32/coinminer
- trojan
-
(and 1 more)
Tagged with:
-
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 09-10-2019 01 Ran by Peter (administrator) on DESKTOP-HUP2O0G (ASUSTeK COMPUTER INC. G10AC) (11-10-2019 13:14:43) Running from C:\Users\Peter\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\TempState\Downloads Loaded Profiles: Peter (Available Profiles: Peter) Platform: Windows 10 Home Version 1903 18362.418 (X64) Language: English (United States) Default browser: Edge Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) () [File not signed] C:\Program Files (x86)\CoolingTech_PC_Camera\monitorpad.exe (Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe (Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (Adobe Systems Incorporated -> ) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe (Adobe Systems, Incorporated -> Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\acrotray.exe (Corel Corporation -> WinZip Computing) C:\Program Files\WinZip\WzPreloader.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe (Dropbox, Inc -> The Qt Company Ltd.) C:\Program Files (x86)\Dropbox\Client\82.4.155\QtWebEngineProcess.exe (Dropbox, Inc -> The Qt Company Ltd.) C:\Program Files (x86)\Dropbox\Client\82.4.155\QtWebEngineProcess.exe (Dropbox, Inc -> The Qt Company Ltd.) C:\Program Files (x86)\Dropbox\Client\82.4.155\QtWebEngineProcess.exe (Electronic Arts, Inc. -> ) C:\Program Files (x86)\Origin\QtWebEngineProcess.exe (Electronic Arts, Inc. -> ) C:\Program Files (x86)\Origin\QtWebEngineProcess.exe (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe (Even Balance, Inc. -> ) C:\Windows\System32\PnkBstrA.exe (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries) C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe (Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.302\GoogleCrashHandler.exe (Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.302\GoogleCrashHandler64.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Hewlett-Packard Company -> Hewlett-Packard Company) C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe (Hewlett-Packard Company -> Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Hewlett-Packard Company) [File not signed] C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe (IBM -> IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportHelper.exe (IBM -> IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportHelper.exe (IBM -> IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe (IBM -> IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe (IBM -> IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportInjService_x64.exe (IBM -> IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportInjService_x64.exe (Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksde.exe (Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksdeui.exe (Macrovision Europe Ltd.) [File not signed] C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (McAfee, Inc. -> McAfee, LLC.) C:\Program Files\McAfee\TrueKey\McAfee.TrueKey.Service.exe (McAfee, Inc. -> McAfee, LLC.) C:\Program Files\McAfee\TrueKey\McAfee.TrueKey.ServiceHelper.exe (McAfee, Inc. -> McAfee, LLC.) C:\Program Files\McAfee\TrueKey\McTkSchedulerService.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE (Microsoft Corporation -> Microsoft Corporation) C:\Users\Peter\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12026.20218.0_x64__8wekyb3d8bbwe\HxOutlook.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12026.20218.0_x64__8wekyb3d8bbwe\HxTsr.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11910.1001.4.0_x64__8wekyb3d8bbwe\WinStore.App.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.19091.313.0_x64__8wekyb3d8bbwe\YourPhone.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.18362.411_none_5f53d2d858cf8961\TiWorker.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1909.6-0\MsMpEng.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1909.6-0\NisSrv.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Node.js Foundation -> Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (pCloud AG -> pCloud AG) C:\Program Files (x86)\pCloud Drive\pCloud.exe (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.52.138.0_x64__kzf8qxf38zg5c\SkypeApp.exe (Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.52.138.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe (Valve -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated -> Adobe Systems Incorporated) HKLM\...\Run: [Seagull Drivers] => ssdal_nc.exe startup HKLM\...\Run: [GLSystray] => C:\Program Files (x86)\CoolingTech_PC_Camera\monitorpad.exe [69632 2010-04-27] () [File not signed] HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2872400 2019-09-25] (Adobe Inc. -> Adobe Systems, Incorporated) HKLM\...\Run: [WinZip UN] => C:\Program Files\WinZip\WZUpdateNotifier.exe [2862032 2018-11-07] (Corel Corporation -> Corel Corporation) HKLM\...\Run: [WinZip PreLoader] => C:\Program Files\WinZip\WzPreloader.exe [130624 2018-11-07] (Corel Corporation -> WinZip Computing) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8783616 2015-12-11] (Realtek Semiconductor Corp -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407104 2015-12-11] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation -> Microsoft Corporation) HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe [620152 2006-10-22] (Adobe Systems, Incorporated -> Adobe Systems Inc.) HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [6210368 2019-10-02] (Dropbox, Inc -> Dropbox, Inc.) HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1298456 2015-04-20] (Canon Inc. -> CANON INC.) HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2404952 2017-03-27] (Adobe Systems Incorporated -> Adobe Systems Incorporated) HKLM-x32\...\Run: [StatusAlerts] => C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe [136760 2011-07-19] (Hewlett-Packard Company -> Hewlett-Packard Company) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard Company -> Hewlett-Packard) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [644552 2019-07-04] (Oracle America, Inc. -> Oracle Corporation) HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3115792 2019-09-25] (Electronic Arts, Inc. -> Electronic Arts) HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3211040 2019-10-02] (Valve -> Valve Corporation) HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1421736 2017-03-28] (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries) HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\Run: [MyDriveConnect.exe] => C:\Program Files (x86)\MyDrive Connect\TomTom MyDrive Connect.exe [1906088 2017-01-17] (TomTom International BV -> TomTom) HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\Run: [pCloud] => C:\Program Files (x86)\pCloud Drive\pCloud.exe [4367488 2019-03-08] (pCloud AG -> pCloud AG) HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\Run: [Discord] => C:\Users\Peter\AppData\Local\Discord\app-0.0.301\Discord.exe [57816920 2018-04-30] (Discord Inc. -> Discord Inc.) HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [83525184 2019-10-03] (Skype Software Sarl -> Skype Technologies S.A.) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\77.0.3865.90\Installer\chrmstp.exe [2019-09-19] (Google LLC -> Google LLC) HKLM\Software\...\Authentication\Credential Providers: [{B7724AE5-1135-4889-8A5F-CA98BE6CA1ED}] -> C:\Program Files\McAfee\TrueKey\McAfee.TrueKey.CredentialProvider.dll [2019-03-09] (McAfee, Inc. -> McAfee, LLC.) Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter "C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter" "C:\Program Files\McAfee\TrueKey\McAfeeTrueKeyPasswordFilter" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk [2017-08-09] ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) [File not signed] ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {05849D66-2E75-4499-82F2-284DB8D2DF1D} - System32\Tasks\WinZip Update Notifier 1 => C:\Program Files\WinZip\WZUpdateNotifier.exe [2862032 2018-11-07] (Corel Corporation -> Corel Corporation) Task: {06A75F97-B65A-49BA-A9C1-E10D357174D4} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe Task: {08FD9976-8EE3-406F-92E9-3BFF76C797E8} - System32\Tasks\WinZip Update Notifier 2 => C:\Program Files\WinZip\WZUpdateNotifier.exe [2862032 2018-11-07] (Corel Corporation -> Corel Corporation) Task: {10277736-AE02-49B1-BB8F-BADB0B12E211} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-09-10] (Adobe Inc. -> Adobe) Task: {125EFDFE-A23A-4B81-9E16-F4EACF47FE90} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\MpCmdRun.exe [468120 2019-10-02] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {19948146-575A-4B76-86AB-32A595C26CD3} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1236048 2019-07-24] (Adobe Inc. -> Adobe Systems) Task: {1CD324DB-D36C-47AE-A975-F254AC9B8DBF} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_255_Plugin.exe [1457720 2019-09-10] (Adobe Inc. -> Adobe) Task: {1EDC0A9E-95AA-4334-B0D1-C2AB7D34BA04} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\MpCmdRun.exe [468120 2019-10-02] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {33959C1E-7F1F-4AFD-AFEA-0C8044DCEC2B} - System32\Tasks\RunAsStdUser Task => C:\Program Files (x86)\inPixio\InPixio Photo Clip 8\LauncherIPC8.exe Task: {34FC9C36-72A1-412D-BCDB-6EE18D4109D7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440 2016-03-26] (Google Inc -> Google Inc.) Task: {4391AFA1-A2C9-45F2-9CF9-649F282817D5} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_255_pepper.exe [1453112 2019-09-10] (Adobe Inc. -> Adobe) Task: {54468D4E-850A-4994-B788-EF5DEA5FD0C0} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-04-07] (Dropbox, Inc -> Dropbox, Inc.) Task: {5617B0EF-5F62-461B-A47D-89E960F1845C} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2872400 2019-09-25] (Adobe Inc. -> Adobe Systems, Incorporated) Task: {64C683AD-24B4-4A09-89DC-E57F7149972F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\MpCmdRun.exe [468120 2019-10-02] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {6973513C-1A63-459F-BDA8-2612545EB0DF} - System32\Tasks\WinZip Update Notifier 3 => C:\Program Files\WinZip\WZUpdateNotifier.exe [2862032 2018-11-07] (Corel Corporation -> Corel Corporation) Task: {69C858B6-6AF8-483F-B310-A825204E050F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440 2016-03-26] (Google Inc -> Google Inc.) Task: {76380687-2779-46CF-8675-008E4D07131A} - System32\Tasks\DropboxUpdateTaskMachineCore1d3ef5534012f1d => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-04-07] (Dropbox, Inc -> Dropbox, Inc.) Task: {A0D2268D-7C16-4853-A03C-3CC3395E309B} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-04-07] (Dropbox, Inc -> Dropbox, Inc.) Task: {A86C25B5-2E80-448F-B452-0E1ECE82E378} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK Task: {ADFEA57E-EB3B-479C-B989-50C9AF765364} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [39848 2017-03-28] (Garmin International, Inc. -> ) Task: {B280111D-BBB0-41E7-A5E5-6B73C0A68FCA} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [1873288 2019-09-18] (AVAST Software s.r.o. -> AVAST Software) Task: {B86B1346-9C61-48CA-9BA1-AA7DAFE6C5EE} - System32\Tasks\HPLJCustParticipation => C:\Program Files (x86)\HP\HPLJUT\HPLJUTSCH.exe [42552 2011-05-03] (Hewlett-Packard Company -> Hewlett Packard) Task: {B97F97B6-A7D2-4AC0-ADFE-D507B699C39B} - System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-petertwilson1@live.com => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated -> Adobe Systems Incorporated) Task: {B9B523F7-1E64-456A-B056-837CFEE98163} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\MpCmdRun.exe [468120 2019-10-02] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {CD8067CA-458D-4A5D-9444-B5CDF7E94547} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe [4639280 2018-12-02] (McAfee, Inc. -> McAfee, Inc.) Task: {F0707A67-33DD-47CA-84FB-3B579ACA0B73} - System32\Tasks\HPCeeScheduleForPeter => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [97848 2016-01-22] (Hewlett-Packard Company -> Hewlett-Packard) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore1d3ef5534012f1d.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\HPCeeScheduleForPeter.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{3c0f1f20-0c45-49a7-9429-d74cf10ea0e9}: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{45576c16-4147-4887-8322-faced857d039}: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{60ad152e-8a43-4fd9-b6c3-37cf135a7346}: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{fd1c198c-98ca-4777-b9c0-6406155290d0}: [NameServer] 8.8.8.8,8.8.4.4 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com BHO: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\McAfee\TrueKey\MSIE\truekey_ie64.dll [2018-04-23] (McAfee, Inc. -> Intel Security) BHO-x32: Adobe PDF Reader Link Helper -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) BHO-x32: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\McAfee\TrueKey\MSIE\truekey_ie.dll [2018-04-23] (McAfee, Inc. -> Intel Security) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_221\bin\ssv.dll [2019-10-03] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2006-10-22] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_221\bin\jp2ssv.dll [2019-10-03] (Oracle America, Inc. -> Oracle Corporation) Toolbar: HKLM - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\McAfee\TrueKey\MSIE\truekey_ie64.dll [2018-04-23] (McAfee, Inc. -> Intel Security) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2006-10-22] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) Toolbar: HKLM-x32 - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\McAfee\TrueKey\MSIE\truekey_ie.dll [2018-04-23] (McAfee, Inc. -> Intel Security) Edge: ====== DownloadDir: C:\Users\Peter\Downloads FireFox: ======== FF DefaultProfile: ba38mmpk.default-1475343481844 FF ProfilePath: C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\ba38mmpk.default-1475343481844 [2019-10-11] FF NewTabOverride: Mozilla\Firefox\Profiles\ba38mmpk.default-1475343481844 -> Disabled: {ae170991-a8c8-4caf-b6cc-a3cc994abe83} FF Extension: (IBM Security Rapport) - C:\Users\Peter\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\rapportext@trusteer.com (1).xpi [2018-04-11] [UpdateUrl:hxxps://clients2.google.com/service/update2/crx] FF Extension: (IBM Security Rapport) - C:\Users\Peter\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\rapportext@trusteer.com.xpi [2019-01-22] [UpdateUrl:hxxps://clients2.google.com/service/update2/crx] FF Extension: (Grammarly for Firefox) - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\ba38mmpk.default-1475343481844\Extensions\87677a2c52b84ad3a151a4a72f5bd3c4@jetpack.xpi [2019-06-15] FF Extension: (Autofill Forms) - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\ba38mmpk.default-1475343481844\Extensions\autofillForms@blueimp.net.xpi [2017-05-04] [Legacy] FF Extension: (AdBlock) - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\ba38mmpk.default-1475343481844\Extensions\jid1-NIfFY2CA8fy1tg@jetpack.xpi [2019-10-04] FF Extension: (Strict Pop-up Blocker) - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\ba38mmpk.default-1475343481844\Extensions\jid1-P34HaABBBpOerQ@jetpack.xpi [2019-08-29] FF Extension: (Popup Blocker Ultimate) - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\ba38mmpk.default-1475343481844\Extensions\{60B7679C-BED9-11E5-998D-8526BB8E7F8B}.xpi [2019-06-29] FF SearchPlugin: C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\ba38mmpk.default-1475343481844\searchplugins\bing-lavasoft.xml [2017-04-23] FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_255.dll [2019-09-10] (Adobe Inc. -> ) FF Plugin: @videolan.org/vlc,version=3.0.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2017-03-27] (Adobe Systems Incorporated -> Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_255.dll [2019-09-10] (Adobe Inc. -> ) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (Electronic Sports Network i Sverige AB -> ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB) [File not signed] FF Plugin-x32: @java.com/DTPlugin,version=11.221.2 -> C:\Program Files (x86)\Java\jre1.8.0_221\bin\dtplugin\npDeployJava1.dll [2019-10-03] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.221.2 -> C:\Program Files (x86)\Java\jre1.8.0_221\bin\plugin2\npjp2.dll [2019-10-03] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.35.302\npGoogleUpdate3.dll [2019-10-07] (Google Inc -> Google LLC) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.35.302\npGoogleUpdate3.dll [2019-10-07] (Google Inc -> Google LLC) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2017-03-27] (Adobe Systems Incorporated -> Adobe Systems) FF Plugin HKU\S-1-5-21-2643124959-2563984870-1026749049-1001: @zoom.us/ZoomVideoPlugin -> C:\Users\Peter\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2018-12-21] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) FF Plugin HKU\S-1-5-21-2643124959-2563984870-1026749049-1001: SkypePlugin -> C:\Users\Peter\AppData\Local\SkypePlugin\7.32.6.278\npGatewayNpapi.dll [2017-04-18] (Microsoft Corporation -> Skype Technologies S.A.) FF Plugin HKU\S-1-5-21-2643124959-2563984870-1026749049-1001: SkypePlugin64 -> C:\Users\Peter\AppData\Local\SkypePlugin\7.32.6.278\npGatewayNpapi-x64.dll [2017-04-18] (Microsoft Corporation -> Skype Technologies S.A.) Chrome: ======= CHR DefaultProfile: Default CHR HomePage: Default -> hxxp://www.google.com CHR Profile: C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default [2019-10-11] CHR Extension: (Slides) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-01-16] CHR Extension: (Docs) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-16] CHR Extension: (Google Drive) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-17] CHR Extension: (IBM Security Rapport) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjllphbppobebmjpjcijfbakobcheof [2019-08-15] CHR Extension: (YouTube) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-03-26] CHR Extension: (Dropbox for Gmail) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpdmhfocilnekecfjgimjdeckachfbec [2019-02-08] CHR Extension: (Sheets) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-16] CHR Extension: (Google Docs Offline) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-15] CHR Extension: (Grammarly for Chrome) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2019-09-24] CHR Extension: (Skype) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2018-01-16] CHR Extension: (Chrome Web Store Payments) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-01] CHR Extension: (Downloader for Instagram™ + Direct Message) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\olkpikmlhoaojbbmmpejnimiglejmboe [2019-09-18] CHR Extension: (Gmail) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-23] CHR Extension: (Chrome Media Router) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-09-20] CHR HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bbjllphbppobebmjpjcijfbakobcheof] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [771672 2017-03-14] (Adobe Systems Incorporated -> Adobe Systems Incorporated) R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3147344 2019-09-25] (Adobe Inc. -> Adobe Systems, Incorporated) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2914896 2019-09-25] (Adobe Inc. -> Adobe Systems, Incorporated) S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-04-07] (Dropbox, Inc -> Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-04-07] (Dropbox, Inc -> Dropbox, Inc.) R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [51024 2019-10-02] (Dropbox, Inc -> Dropbox, Inc.) S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [229648 2016-09-08] (EasyAntiCheat Oy -> EasyAntiCheat Ltd) R3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2016-04-04] (Macrovision Europe Ltd.) [File not signed] R2 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [1099280 2017-03-28] (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries) R2 HP DS Service; C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe [13824 2010-10-27] (Hewlett-Packard Company) [File not signed] S2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [162816 2011-07-08] (HP) [File not signed] R2 KSDE3.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksde.exe [617016 2018-03-01] (Kaspersky Lab -> AO Kaspersky Lab) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6744288 2019-06-26] (Malwarebytes Corporation -> Malwarebytes) S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed] S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2348336 2019-09-25] (Electronic Arts, Inc. -> Electronic Arts) R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3228464 2019-09-25] (Electronic Arts, Inc. -> Electronic Arts) S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed] R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2016-07-22] (Even Balance, Inc. -> ) R2 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [5274560 2019-04-15] (IBM -> IBM Corp.) R2 TrueKey; C:\Program Files\McAfee\TrueKey\McAfee.TrueKey.Service.exe [421432 2019-03-09] (McAfee, Inc. -> McAfee, LLC.) R2 TrueKeyScheduler; C:\Program Files\McAfee\TrueKey\McTkSchedulerService.exe [421432 2019-03-09] (McAfee, Inc. -> McAfee, LLC.) R2 TrueKeyServiceHelper; C:\Program Files\McAfee\TrueKey\McAfee.TrueKey.ServiceHelper.exe [194168 2019-03-09] (McAfee, Inc. -> McAfee, LLC.) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\NisSrv.exe [3004048 2019-10-02] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\MsMpEng.exe [103384 2019-10-02] (Microsoft Windows Publisher -> Microsoft Corporation) R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000 S2 UtilitiesService; C:\Program Files\Utilities\UtilitiesService.exe [X] ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.) R1 cbfs6; C:\WINDOWS\system32\drivers\cbfs6.sys [460992 2016-09-09] (EldoS Corporation -> /n software, Inc.) R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153312 2019-09-30] (Malwarebytes Corporation -> Malwarebytes) R3 kltap; C:\WINDOWS\System32\drivers\kltap.sys [48080 2018-02-12] (AnchorFree Inc -> The OpenVPN Project) S3 ManyCam; C:\WINDOWS\system32\DRIVERS\mcvidrv.sys [58792 2017-03-05] (ManyCam (VISICOM MÉDIA INC.) -> Visicom Media Inc.) R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [199768 2019-10-08] (Malwarebytes Corporation -> Malwarebytes) S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2019-06-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [224408 2019-10-10] (Malwarebytes Corporation -> Malwarebytes) R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [73584 2019-10-10] (Malwarebytes Corporation -> Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [275232 2019-10-10] (Malwarebytes Corporation -> Malwarebytes) R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [116832 2019-10-10] (Malwarebytes Corporation -> Malwarebytes) S3 mcaudrv_simple; C:\WINDOWS\system32\drivers\mcaudrv_x64.sys [35960 2014-12-29] (ManyCam -> Visicom Media Inc.) R2 npf; C:\WINDOWS\system32\drivers\npf.sys [36600 2015-08-21] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.) R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_830a0263f2ee97ce\nvlddmkm.sys [22370696 2019-09-06] (NVIDIA Corporation -> NVIDIA Corporation) S1 RapportAegle64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportAegle64.sys [503000 2019-04-15] (IBM -> IBM Corp.) S1 RapportCerberus_1930415; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1930415.sys [1659544 2019-06-12] (IBM -> IBM Corp.) S1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [727000 2019-04-15] (IBM -> IBM Corp.) S0 RapportHades64; C:\WINDOWS\System32\Drivers\RapportHades64.sys [463408 2019-04-15] (IBM -> IBM Corp.) S0 RapportKE64; C:\WINDOWS\System32\Drivers\RapportKE64.sys [610648 2019-04-15] (IBM -> IBM Corp.) S1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [766616 2019-04-15] (IBM -> IBM Corp.) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [662528 2019-03-19] (Microsoft Windows -> Realtek ) R3 rtux64w10; C:\WINDOWS\System32\drivers\rtux64w10.sys [411648 2019-03-19] (Microsoft Windows -> Realtek Corporation ) R3 vpnpbus; C:\WINDOWS\System32\drivers\vpnpbus.sys [18624 2016-09-09] (EldoS Corporation -> /n software, Inc.) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46688 2019-10-02] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [350136 2019-10-02] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54200 2019-10-02] (Microsoft Windows -> Microsoft Corporation) S3 AIDA64Driver; \??\C:\Program Files (x86)\FinalWire\AIDA64 Extreme\kerneld.x64 [X] S1 amsdk; \??\C:\WINDOWS\system32\drivers\amsdk.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-10-11 13:11 - 2019-10-11 13:11 - 000000000 ___HD C:\OneDriveTemp 2019-10-10 13:17 - 2019-10-10 13:17 - 001931666 _____ C:\Users\Peter\Downloads\WhatsAppVideo2019-10-10at11.47.40AM.mp4 2019-10-10 11:14 - 2019-10-10 15:28 - 000275232 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys 2019-10-10 11:14 - 2019-10-10 15:28 - 000073584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2019-10-10 11:14 - 2019-10-10 11:14 - 000224408 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys 2019-10-10 11:14 - 2019-10-10 11:14 - 000116832 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 2019-10-10 01:10 - 2019-10-10 01:10 - 025900544 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 025443840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 022628352 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 019849216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 019811840 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 018019840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 017787392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 014816256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 009928504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 008010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 007754240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 007600664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 007195648 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 007015936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 006517640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 006232064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 005915648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 005041664 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 004562688 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 004538880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 004129616 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 004012544 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 003771392 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 003701760 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 003525592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 003365376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 002861568 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsservices.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 002762504 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2019-10-10 01:10 - 2019-10-10 01:10 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 2019-10-10 01:10 - 2019-10-10 01:10 - 002723328 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2019-10-10 01:10 - 2019-10-10 01:10 - 002703360 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 002494440 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 002456064 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 002448712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 002422592 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL 2019-10-10 01:10 - 2019-10-10 01:10 - 002314648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 002284032 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 002236144 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 002138472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL 2019-10-10 01:10 - 2019-10-10 01:10 - 002114048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 002095104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 002081976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 002000168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 001952360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 001847808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsservices.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 001830200 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 001748480 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 001743672 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 001730560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 001721144 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 001687040 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 001664928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 001656392 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 001610752 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 001563648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 001562424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 001439744 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 001394488 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 001319936 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 001283072 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 001273392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 001217904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 001214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 001152016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 001149712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 001098712 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 001084432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 001072952 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 001066496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 001012792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000904208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000890472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000880088 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000856576 _____ C:\WINDOWS\system32\MBR2GPT.EXE 2019-10-10 01:10 - 2019-10-10 01:10 - 000844800 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 000843776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000842752 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000829536 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioIso.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 000818688 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000774672 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 000758584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000717312 _____ (Microsoft Corporation) C:\WINDOWS\system32\mousocoreworker.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 000701952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.FileExplorer.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000691712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000690176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000679880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000669496 _____ (Microsoft Corporation) C:\WINDOWS\system32\computecore.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000598024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000596992 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 000595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe 2019-10-10 01:10 - 2019-10-10 01:10 - 000537600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000520192 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000516408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 000515896 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 000513536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 000496640 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000487424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.FileExplorer.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000466416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000462848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000462136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000456504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys 2019-10-10 01:10 - 2019-10-10 01:10 - 000452408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 000436536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys 2019-10-10 01:10 - 2019-10-10 01:10 - 000429568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000422008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000412152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 000404392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000380216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicSvc.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000324408 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000300184 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicCapsule.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000247856 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msltus40.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000225080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys 2019-10-10 01:10 - 2019-10-10 01:10 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE 2019-10-10 01:10 - 2019-10-10 01:10 - 000224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000220472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 000202040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys 2019-10-10 01:10 - 2019-10-10 01:10 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000199480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000193592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000186880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE 2019-10-10 01:10 - 2019-10-10 01:10 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000165832 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000150328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatecsp.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000117048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys 2019-10-10 01:10 - 2019-10-10 01:10 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicAgent.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe 2019-10-10 01:10 - 2019-10-10 01:10 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000039304 _____ (Microsoft Corporation) C:\WINDOWS\system32\NtlmShared.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000037176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys 2019-10-10 01:10 - 2019-10-10 01:10 - 000033048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NtlmShared.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicPS.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\bindflt.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDJPN.DLL 2019-10-10 01:10 - 2019-10-10 01:10 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kbd106.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6r.dll 2019-10-10 01:10 - 2019-10-10 01:10 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6r.dll 2019-10-10 01:00 - 2019-09-20 05:36 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe 2019-10-10 01:00 - 2019-09-20 05:14 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe 2019-10-08 14:31 - 2019-10-08 14:31 - 000199768 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys 2019-10-08 14:31 - 2019-10-08 14:31 - 000000000 ____D C:\Users\Peter\AppData\Local\mbam 2019-10-08 14:30 - 2019-10-08 14:30 - 000000000 ____D C:\Users\Peter\AppData\Local\mbamtray 2019-10-08 14:30 - 2019-10-08 14:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2019-10-08 14:30 - 2019-10-08 14:30 - 000000000 ____D C:\ProgramData\Malwarebytes 2019-10-08 14:30 - 2019-09-30 06:25 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys 2019-10-08 14:30 - 2019-06-26 13:00 - 000020936 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys 2019-10-08 14:29 - 2019-10-08 14:30 - 066449256 _____ (Malwarebytes ) C:\WINDOWS\SysWOW64\mb-setup.exe 2019-10-08 14:26 - 2019-10-08 14:26 - 001615872 _____ (Farbar) C:\Users\Peter\Downloads\FRSTEnglish.exe 2019-10-07 18:47 - 2019-10-07 18:47 - 066367928 _____ (Malwarebytes ) C:\Users\Peter\Downloads\mb3-setup-37469.37469-3.8.3.2965-1.0.627-1.0.12633.exe 2019-10-07 16:00 - 2019-10-07 16:00 - 000070117 _____ C:\Users\Peter\Downloads\My-Family-7-Oct-2019(3).pdf 2019-10-07 15:59 - 2019-10-07 15:59 - 000070117 _____ C:\Users\Peter\Downloads\My-Family-7-Oct-2019(2).pdf 2019-10-07 15:58 - 2019-10-07 15:58 - 000072416 _____ C:\Users\Peter\Downloads\My-Family-7-Oct-2019(1).pdf 2019-10-07 15:40 - 2019-10-07 15:40 - 000072416 _____ C:\Users\Peter\Downloads\My-Family-7-Oct-2019.pdf 2019-10-06 11:55 - 2019-10-06 11:55 - 000203423 _____ C:\Users\Peter\Downloads\Transactions--980360-10465943--6-04-2019-6-09-2019.pdf 2019-10-05 20:14 - 2019-10-05 20:14 - 000123453 _____ C:\Users\Peter\Downloads\Bering.Sea.Gold.S11E03.1080p.HEVC.x265-MeGusta.nzb 2019-10-05 18:30 - 2019-10-05 18:30 - 000000000 ____D C:\Battlefield 4 2019-10-04 21:29 - 2019-10-04 21:29 - 000000000 ____D C:\Users\Peter\AppData\Local\Aiseesoft Studio 2019-10-04 21:28 - 2019-10-04 21:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aiseesoft 2019-10-04 21:28 - 2019-10-04 21:28 - 000000000 ____D C:\ProgramData\Aiseesoft Studio 2019-10-04 21:28 - 2019-10-04 21:28 - 000000000 ____D C:\Program Files (x86)\Aiseesoft Studio 2019-10-04 21:27 - 2019-10-04 21:27 - 011362440 _____ (Aiseesoft Studio ) C:\Users\Peter\Downloads\data-recovery.exe 2019-10-04 20:33 - 2019-10-11 13:15 - 000000000 ____D C:\FRST 2019-10-04 20:14 - 2019-10-06 10:47 - 001743536 _____ C:\WINDOWS\ZAM.krnl.trace 2019-10-04 20:14 - 2019-10-06 10:47 - 000000000 ____D C:\Users\Peter\AppData\Local\AMSDK 2019-10-04 20:14 - 2019-10-04 20:14 - 000000000 ____D C:\Users\Peter\AppData\Local\Zemana 2019-10-04 20:13 - 2019-10-04 20:14 - 012668536 _____ (Zemana Ltd. ) C:\Users\Peter\Downloads\AntiMalware_Setup(1).exe 2019-10-04 20:13 - 2019-10-04 20:13 - 012668536 _____ (Zemana Ltd. ) C:\Users\Peter\Downloads\AntiMalware_Setup.exe 2019-10-04 20:08 - 2019-10-04 20:12 - 000000000 ____D C:\ProgramData\HitmanPro 2019-10-04 20:08 - 2019-10-04 20:09 - 011539456 _____ (SurfRight B.V.) C:\Users\Peter\Downloads\HitmanPro_x64.exe 2019-10-04 19:18 - 2019-10-04 19:18 - 000001965 _____ C:\Users\Peter\Desktop\Process Hacker 2.lnk 2019-10-04 19:17 - 2019-10-04 19:17 - 002267848 _____ (wj32 ) C:\Users\Peter\Downloads\processhacker-2.39-setup (1).exe 2019-10-04 17:16 - 2019-10-04 17:16 - 001352267 _____ C:\Users\Peter\AppData\Local\census.cache 2019-10-04 17:14 - 2019-10-04 17:14 - 000474205 _____ C:\Users\Peter\AppData\Local\ars.cache 2019-10-04 16:52 - 2019-10-04 16:52 - 000000010 _____ C:\Users\Peter\AppData\Local\sponge.last.runtime.cache 2019-10-04 16:47 - 2019-10-04 16:47 - 000000000 ____D C:\WINDOWS\Trend Micro 2019-10-04 16:47 - 2019-10-04 16:47 - 000000000 ____D C:\ProgramData\Trend Micro 2019-10-04 16:46 - 2019-10-04 16:46 - 000000036 _____ C:\Users\Peter\AppData\Local\housecall.guid.cache 2019-10-04 16:45 - 2019-10-04 16:45 - 002527376 _____ (Trend Micro Inc.) C:\Users\Peter\Downloads\HousecallLauncher64.exe 2019-10-04 16:00 - 2019-10-04 16:00 - 006946736 _____ (EnigmaSoft Limited) C:\Users\Peter\Downloads\SpyHunter-Installer.exe 2019-10-04 15:35 - 2019-10-04 15:35 - 000000000 ____D C:\ProgramData\SecuritySuite 2019-10-04 15:03 - 2019-10-04 15:04 - 066748536 _____ (Malwarebytes ) C:\Users\Peter\Downloads\mb3-setup-consumer-3.8.3.2965-1.0.627-1.0.12751.exe 2019-10-04 01:49 - 2019-10-11 13:12 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox 2019-10-04 01:11 - 2019-10-04 01:11 - 006084048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 005865272 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizimg.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 005764872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 005105152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 004481536 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 003964056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 003742032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 002821120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 002799616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2019-10-04 01:11 - 2019-10-04 01:11 - 002258856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 002132280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001957008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001913296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001788728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001692160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001664376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001616784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001510752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001505320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001473488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001334064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ttdrecordcpu.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001297936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001263616 _____ (Microsoft Corporation) C:\WINDOWS\system32\opengl32.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001244944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001178816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001154656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001080320 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001054872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001047968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000939008 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000904704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\opengl32.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000893952 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000875008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000792296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputHost.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000784384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000783480 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000775768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000772656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000742912 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000722944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapi.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000673080 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000652800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000629248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.Search.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000623104 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000599040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000568336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000546816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxdiagn.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000541696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResourceMapper.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000539648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9on12.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000510464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000507704 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizeng.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000507152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000501232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp_win.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000500736 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2019-10-04 01:11 - 2019-10-04 01:11 - 000487576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\SessEnv.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000463272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxdiagn.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000450360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11on12.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000421376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2019-10-04 01:11 - 2019-10-04 01:11 - 000417280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SessEnv.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000387832 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000383984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MMDevAPI.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000379840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ws2_32.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000375720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000369664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxdiag.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000346624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\secproc.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapibase.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\VAN.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys 2019-10-04 01:11 - 2019-10-04 01:11 - 000315392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxdiag.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000285256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000283688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ttdwriter.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000279040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000278080 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000245248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\glu32.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000236520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cfgmgr32.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000210744 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000176440 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxlib.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\glu32.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000158208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys 2019-10-04 01:11 - 2019-10-04 01:11 - 000157184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ComposableShellProxyStub.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SpatialAudioLicenseSrv.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000143808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imm32.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sud.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000139264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prntvpt.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000137864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devobj.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000125232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KerbClientShared.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000116904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\userenv.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000110080 _____ C:\WINDOWS\system32\ResBParser.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000105832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000100664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmcl.sys 2019-10-04 01:11 - 2019-10-04 01:11 - 000093712 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EaseOfAccessDialog.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000089544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000084496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys 2019-10-04 01:11 - 2019-10-04 01:11 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvvmtransport.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcbuilder.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sethc.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000073024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000066832 _____ (Microsoft Corporation) C:\WINDOWS\system32\iumcrypt.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvvmtransport.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000056832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devrtl.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeUISrv.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnrollCtrl.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AssignedAccessRuntime.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enrollmentapi.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000021544 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000016696 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizres.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d8thk.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000011576 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxlibres.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCertResources.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin 2019-10-04 01:11 - 2019-10-04 01:11 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin 2019-10-04 01:11 - 2019-10-04 01:11 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin 2019-10-04 01:11 - 2019-10-04 01:11 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin 2019-10-04 01:11 - 2019-10-04 01:11 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin 2019-10-04 01:11 - 2019-10-04 01:11 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin 2019-10-04 01:11 - 2019-10-04 01:11 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin 2019-10-04 01:11 - 2019-10-04 01:11 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin 2019-10-04 01:11 - 2019-10-04 01:11 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin 2019-10-04 01:11 - 2019-10-04 01:11 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin 2019-10-04 01:11 - 2019-10-04 01:11 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin 2019-10-04 01:11 - 2019-10-04 01:11 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin 2019-10-04 01:10 - 2019-10-04 01:10 - 007905000 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 007848192 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 007263992 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 006425600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 006227624 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 006164480 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 004612520 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 004046336 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 003727360 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 003590968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 003553280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 003386880 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 003184128 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 003105280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 002772032 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 002590208 _____ C:\WINDOWS\system32\dwmscene.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 002552120 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 002466304 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 002160640 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 002120704 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 002120272 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 002069504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001942528 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001940952 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001857024 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001845408 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001835008 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001819136 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShell.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001757096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2019-10-04 01:10 - 2019-10-04 01:10 - 001657856 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001616608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ttdrecordcpu.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001607680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001543168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001512320 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 001482040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 001413704 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001412096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001383856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001372160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001366128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2019-10-04 01:10 - 2019-10-04 01:10 - 001261800 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001182240 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 001150240 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputHost.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001091584 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001036800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001029432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 001023128 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001009152 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000984376 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000975872 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000944664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000931840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000874296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000858112 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000839680 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9on12.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000833312 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000759488 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.Search.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000749568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000732176 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000674072 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000656960 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11on12.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000639400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp_win.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000617784 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000612864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000606208 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000598016 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000589384 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_PCDisplay.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000558592 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000551952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Vid.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000551936 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000551424 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000541480 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000518656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000457216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000449888 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMDevAPI.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000448000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000442704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ws2_32.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000441144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000415808 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000398728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000382976 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000363624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\MbbCx.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000355000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000342896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ttdwriter.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000334936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ComposableShellProxyStub.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000315904 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000293344 _____ (Microsoft Corporation) C:\WINDOWS\system32\cfgmgr32.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\directxdatabaseupdater.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000284160 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_CapabilityAccess.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3svc.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnservice.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\ManageCI.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000244736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndproxy.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Gpu.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000223032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelppm.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgiadaptercache.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000208184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\processr.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000201016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdppm.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000199480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdk8.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000179512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\prntvpt.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000176152 _____ (Microsoft Corporation) C:\WINDOWS\system32\imm32.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000173568 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvinst.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwbase.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000159112 _____ (Microsoft Corporation) C:\WINDOWS\system32\devobj.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000155648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_AppExecutionAlias.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000152408 _____ (Microsoft Corporation) C:\WINDOWS\system32\KerbClientShared.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000151568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbus.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_BackgroundApps.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000140496 _____ (Microsoft Corporation) C:\WINDOWS\system32\userenv.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmredir.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000132608 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_ForceSync.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000132408 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000132096 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinAUG.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000127064 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationControlCSP.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000119840 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\EaseOfAccessDialog.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShellExtFramework.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000105272 _____ (Microsoft Corporation) C:\WINDOWS\system32\icfupgd.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3msm.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000098816 _____ (Microsoft Corporation) C:\WINDOWS\system32\sethc.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000092624 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskhostw.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3api.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000088352 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000079376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\uaspstor.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwm.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnrollCtrl.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidspi.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AssignedAccessRuntime.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\devrtl.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\audioresourceregistrar.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnppolicy.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000053248 _____ C:\WINDOWS\system32\Drivers\UsbPmApi.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000052752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmstorfl.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringconfigsp.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000047616 _____ C:\WINDOWS\system32\UsbPmApi.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000047000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\cellulardatacapabilityhandler.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000043536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storvsc.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiredNetworkCSP.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\IcsEntitlementHost.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000028936 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmbuspipe.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndistapi.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32_DeviceGuard.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfapigp.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\CSystemEventsBrokerClient.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000020944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmsgapi.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d8thk.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\pacjsworker.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCertResources.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tier2punctuations.dll 2019-10-03 21:55 - 2019-10-03 21:55 - 000000000 ____D C:\WINDOWS\pss 2019-10-03 21:29 - 2019-10-04 18:46 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job 2019-10-03 21:29 - 2019-10-03 21:29 - 000107348 _____ C:\WINDOWS\ntbtlog.txt 2019-10-03 20:59 - 2019-10-03 21:04 - 000000000 __SHD C:\DrWeb Quarantine 2019-10-03 20:48 - 2019-10-03 20:48 - 000000000 ____D C:\Users\Peter\Doctor Web 2019-10-03 20:47 - 2019-10-03 20:47 - 000000000 ____D C:\Users\Peter\AppData\Roaming\Process Hacker 2 2019-10-03 20:46 - 2019-10-03 21:53 - 000000000 ____D C:\WINDOWS\system32\Tasks\Doctor Web 2019-10-03 20:44 - 2019-10-03 21:54 - 000000000 ____D C:\ProgramData\Doctor Web 2019-10-03 20:41 - 2019-10-03 20:44 - 543043536 _____ (Doctor Web, Ltd.) C:\Users\Peter\Downloads\drweb-12.0-ss-win.exe 2019-10-03 20:38 - 2019-10-03 20:38 - 019950348 _____ C:\Users\Peter\Downloads\drweb-12.4.2-ss-android.apk 2019-10-03 20:37 - 2019-10-04 19:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Process Hacker 2 2019-10-03 20:37 - 2019-10-04 19:18 - 000000000 ____D C:\Program Files\Process Hacker 2 2019-10-03 20:36 - 2019-10-03 20:36 - 002267848 _____ (wj32 ) C:\Users\Peter\Downloads\processhacker-2.39-setup.exe 2019-10-03 20:31 - 2019-10-03 20:31 - 047532112 _____ (FinalWire Ltd. ) C:\Users\Peter\Downloads\aida64extreme610.exe 2019-10-03 20:08 - 2019-10-03 20:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2019-10-03 20:06 - 2019-10-04 13:33 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData 2019-10-03 20:06 - 2019-10-04 13:33 - 000000000 ___HD C:\ProgramData\Documents\AdobeGCData 2019-10-03 20:06 - 2019-10-03 20:06 - 000003518 _____ C:\WINDOWS\system32\Tasks\AdobeGCInvoker-1.0 2019-10-03 19:24 - 2019-10-03 19:24 - 002065880 _____ (Oracle Corporation) C:\Users\Peter\Downloads\JavaSetup8u221.exe 2019-10-03 07:47 - 2019-10-10 01:45 - 097779712 _____ C:\WINDOWS\system32\config\SOFTWARE 2019-10-02 22:13 - 2019-10-02 22:13 - 000000000 ____D C:\Program Files\Malwarebytes 2019-10-02 21:22 - 2019-10-02 21:22 - 066722736 _____ (Malwarebytes ) C:\Users\Peter\Downloads\mb3-setup-consumer-3.8.3.2965-1.0.627-1.0.12735.exe 2019-10-02 13:14 - 2019-10-02 13:14 - 000051024 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe 2019-10-02 13:14 - 2019-10-02 13:14 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys 2019-10-02 13:14 - 2019-10-02 13:14 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys 2019-10-02 13:14 - 2019-10-02 13:14 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys 2019-10-02 10:35 - 2019-10-02 10:35 - 000000747 _____ C:\Users\Peter\Downloads\report (2).csv 2019-09-28 19:55 - 2019-09-28 19:55 - 000146870 _____ C:\Users\Peter\Downloads\Mister.Academy.2018.WEBRip.x264-ION10.nzb 2019-09-28 16:34 - 2019-09-28 16:34 - 000053805 _____ C:\Users\Peter\Downloads\bering.sea.gold.s11e02.unleash.the.beast.hdtv.x264-w4f.nzb 2019-09-27 17:47 - 2019-09-27 17:47 - 000000000 ___HD C:\$Windows.~WS 2019-09-27 17:47 - 2019-09-27 17:47 - 000000000 ____D C:\$WINDOWS.~BT 2019-09-20 21:04 - 2019-09-06 19:29 - 001012432 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll 2019-09-20 21:04 - 2019-09-06 19:29 - 001012432 _____ C:\WINDOWS\system32\vulkan-1.dll 2019-09-20 21:04 - 2019-09-06 19:29 - 000876240 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll 2019-09-20 21:04 - 2019-09-06 19:29 - 000876240 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll 2019-09-20 21:04 - 2019-09-06 19:29 - 000447368 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll 2019-09-20 21:04 - 2019-09-06 19:29 - 000351944 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll 2019-09-20 21:04 - 2019-09-06 19:29 - 000301264 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe 2019-09-20 21:04 - 2019-09-06 19:29 - 000301264 _____ C:\WINDOWS\system32\vulkaninfo.exe 2019-09-20 21:04 - 2019-09-06 19:29 - 000273104 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe 2019-09-20 21:04 - 2019-09-06 19:29 - 000273104 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe 2019-09-20 21:04 - 2019-09-06 19:28 - 011562376 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll 2019-09-20 21:04 - 2019-09-06 19:28 - 009937104 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll 2019-09-20 21:04 - 2019-09-06 19:27 - 002051008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll 2019-09-20 21:04 - 2019-09-06 19:27 - 001550080 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll 2019-09-20 21:04 - 2019-09-06 19:27 - 001477512 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll 2019-09-20 21:04 - 2019-09-06 19:27 - 001247432 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll 2019-09-20 21:04 - 2019-09-06 19:27 - 001140616 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll 2019-09-20 21:04 - 2019-09-06 19:27 - 000959424 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll 2019-09-20 21:04 - 2019-09-06 19:27 - 000812800 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll 2019-09-20 21:04 - 2019-09-06 19:27 - 000676096 _____ C:\WINDOWS\system32\nvofapi64.dll 2019-09-20 21:04 - 2019-09-06 19:27 - 000658880 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll 2019-09-20 21:04 - 2019-09-06 19:27 - 000632768 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll 2019-09-20 21:04 - 2019-09-06 19:27 - 000544648 _____ C:\WINDOWS\SysWOW64\nvofapi.dll 2019-09-20 21:04 - 2019-09-06 19:27 - 000524168 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll 2019-09-20 21:04 - 2019-09-06 19:26 - 040444856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll 2019-09-20 21:04 - 2019-09-06 19:26 - 035334536 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll 2019-09-20 21:04 - 2019-09-06 19:26 - 017300360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll 2019-09-20 21:04 - 2019-09-06 19:26 - 014921096 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll 2019-09-20 21:04 - 2019-09-06 19:26 - 005358472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll 2019-09-20 21:04 - 2019-09-06 19:26 - 004696968 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll 2019-09-20 21:04 - 2019-09-06 19:26 - 001726400 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6443630.dll 2019-09-20 21:04 - 2019-09-06 19:26 - 001491336 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6443630.dll 2019-09-20 21:04 - 2019-09-06 16:24 - 004263840 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll 2019-09-20 21:04 - 2019-09-05 22:19 - 000047272 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll 2019-09-20 20:52 - 2019-09-20 20:52 - 000000000 ____D C:\Users\Peter\AppData\Local\SquadGame 2019-09-20 15:45 - 2019-09-20 15:46 - 000053872 _____ C:\Users\Peter\Downloads\bering.sea.gold.s10e01.enter.a.titan.hdtv.x264-w4f.nzb 2019-09-20 14:30 - 2019-09-20 14:30 - 000059603 _____ C:\Users\Peter\Downloads\Bering.Sea.Gold.S11E00.Ready.Set.Gold.720p.HEVC.x265-MeGusta.nzb 2019-09-19 21:09 - 2019-09-19 21:09 - 013290562 _____ C:\Users\Peter\Documents\AVA 2019 - Christmas Menu.pdf 2019-09-19 18:39 - 2019-09-19 18:39 - 000111914 _____ C:\Users\Peter\Downloads\Bering.Sea.Gold.S11E01.1080p.HEVC.x265-MeGusta.nzb 2019-09-14 20:17 - 2019-09-14 20:17 - 000000747 _____ C:\Users\Peter\Downloads\report (1).csv 2019-09-12 00:16 - 2019-09-12 00:16 - 005500928 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 004306944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 003637760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 001105480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 000411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\DavSyncProvider.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 000329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DavSyncProvider.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 000307200 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 000283264 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdeunlock.exe 2019-09-12 00:16 - 2019-09-12 00:16 - 000179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.XamlHost.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.XamlHost.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 000035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdeui.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 000027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecerts.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 000021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fvecerts.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 005848840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 005013504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 004857856 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 003817472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 003750912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 003372448 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 002871608 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 002743808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 002586816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 002576384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 002562048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 002305536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 002224952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 001647072 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 001531656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 001488216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 001413624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 001368576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 001348096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 001312256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 001305608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 001283600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi 2019-09-12 00:15 - 2019-09-12 00:15 - 001214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdclt.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 001138688 _____ (Microsoft Corporation) C:\WINDOWS\system32\nettrace.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 001122816 _____ (Microsoft Corporation) C:\WINDOWS\system32\CBDHSvc.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 001007616 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000957952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000913408 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000913168 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000910336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontext.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000888832 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicExtensions.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000840704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000822416 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000822072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000810808 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000797112 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000776704 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000775680 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000771584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 2019-09-12 00:15 - 2019-09-12 00:15 - 000769024 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcIsoCtnr.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000740664 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000729088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FlightSettings.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000705536 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000699904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d8.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000680976 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000673456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000669696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000667272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000637752 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000636416 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000634880 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000631808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000628400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000626688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000609280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000593112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddraw.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000564736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Input.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000561680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys 2019-09-12 00:15 - 2019-09-12 00:15 - 000558080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000541264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StructuredQuery.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000538624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000529408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ddraw.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000529408 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000513336 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000511488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000511288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000510984 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000489472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Narrator.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000488056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000475648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxbde40.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000464696 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000464384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000454736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppResolver.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000431448 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000415760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000401208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys 2019-09-12 00:15 - 2019-09-12 00:15 - 000394752 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000380416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000362056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000359936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000327680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000320512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000316216 _____ (Microsoft Corporation) C:\WINDOWS\system32\computestorage.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000313344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd2x40.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000310072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000283136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000281600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\coredpus.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000274944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Lights.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000270848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngctasks.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000267496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000253952 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerCsp.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCenter.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000222208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netplwiz.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000211968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000205312 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiapi.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000185856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceCenter.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngOnline.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\twext.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiapi.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\NcaSvc.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000167136 _____ (Microsoft Corporation) C:\WINDOWS\system32\vertdll.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000164152 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000163840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BitLockerCsp.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twext.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000147184 _____ (Microsoft Corporation) C:\WINDOWS\system32\smss.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000145720 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-kernel-processor-power-events.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000141840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys 2019-09-12 00:15 - 2019-09-12 00:15 - 000130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000120344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\DafPrintProvider.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\compstui.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssitlb.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000106296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\compstui.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DafPrintProvider.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000084280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winhvr.sys 2019-09-12 00:15 - 2019-09-12 00:15 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\efsext.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000071480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\findnetprinters.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcadm.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\printui.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000063288 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthHost.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000062464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\printui.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\edpnotify.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssprxy.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efsext.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\findnetprinters.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ByteCodeGenerator.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edpnotify.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddrawex.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\compact.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GameInput.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\XInput1_4.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000042512 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ddrawex.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\compact.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XInputUap.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XInput1_4.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000036152 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ws2ifsl.sys 2019-09-12 00:15 - 2019-09-12 00:15 - 000019984 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDKOR.DLL 2019-09-12 00:15 - 2019-09-12 00:15 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaevts.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 007582752 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 004140544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 004009472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Service.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 003353088 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 003263488 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 003084800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 002870272 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 001918976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 001885184 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 001783296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 001744400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 001686528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 001601536 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 001259424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe 2019-09-12 00:14 - 2019-09-12 00:14 - 001158656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 001094144 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcRefreshTask.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 001068560 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000977408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontext.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000909736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000905728 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000893440 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000863744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Service.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000849920 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe 2019-09-12 00:14 - 2019-09-12 00:14 - 000810496 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrSvc.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000808960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Input.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000804880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys 2019-09-12 00:14 - 2019-09-12 00:14 - 000804664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys 2019-09-12 00:14 - 2019-09-12 00:14 - 000731648 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.immersiveshell.serviceprovider.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000722288 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000705024 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntimewindows.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntime.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000686080 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000683008 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationFrame.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000680448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000676632 _____ (Microsoft Corporation) C:\WINDOWS\system32\StructuredQuery.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000670208 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000654912 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000596008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppResolver.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000522176 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2019-09-12 00:14 - 2019-09-12 00:14 - 000477696 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000462848 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.ConversationalAgent.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000425472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\HdAudio.sys 2019-09-12 00:14 - 2019-09-12 00:14 - 000408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe 2019-09-12 00:14 - 2019-09-12 00:14 - 000396288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Lights.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000352256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcApi.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000338800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000331776 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFWSD.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000314368 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000295936 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000294400 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcTok.exe 2019-09-12 00:14 - 2019-09-12 00:14 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000245248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wosc.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe 2019-09-12 00:14 - 2019-09-12 00:14 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApproveChildRequest.exe 2019-09-12 00:14 - 2019-09-12 00:14 - 000237880 _____ C:\WINDOWS\system32\containerdevicemanagement.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000233472 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000232448 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthA2dp.sys 2019-09-12 00:14 - 2019-09-12 00:14 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000201528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys 2019-09-12 00:14 - 2019-09-12 00:14 - 000184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\AarSvc.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000182288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpioclx.sys 2019-09-12 00:14 - 2019-09-12 00:14 - 000160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000153088 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000149504 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe 2019-09-12 00:14 - 2019-09-12 00:14 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000146416 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssitlb.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe 2019-09-12 00:14 - 2019-09-12 00:14 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo-overrides.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ByteCodeGenerator.exe 2019-09-12 00:14 - 2019-09-12 00:14 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcimage.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\GameInput.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000055304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storufs.sys 2019-09-12 00:14 - 2019-09-12 00:14 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\XInputUap.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.Common.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilotdiag.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wci.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\dstokenclean.exe ==================== One month (modified) ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-10-11 13:11 - 2016-11-19 12:13 - 000000000 ____D C:\Users\Peter\AppData\LocalLow\Mozilla 2019-10-11 13:11 - 2016-09-08 15:24 - 000000000 ____D C:\Program Files (x86)\Steam 2019-10-11 13:11 - 2016-07-20 17:19 - 000000000 ____D C:\ProgramData\Origin 2019-10-11 13:11 - 2016-03-19 21:44 - 000000000 ___RD C:\Users\Peter\OneDrive 2019-10-11 13:10 - 2018-11-15 01:30 - 000000000 ____D C:\ProgramData\Kaspersky Lab 2019-10-11 11:50 - 2019-08-30 11:22 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2019-10-11 11:50 - 2016-09-23 08:37 - 000000000 ____D C:\ProgramData\NVIDIA 2019-10-11 11:44 - 2019-03-19 05:52 - 000000000 ___HD C:\Program Files\WindowsApps 2019-10-11 11:44 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\AppReadiness 2019-10-11 11:43 - 2019-03-19 05:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2019-10-11 10:35 - 2016-03-26 13:11 - 000000000 ____D C:\Users\Peter\AppData\Local\Adobe 2019-10-10 16:38 - 2018-11-15 20:12 - 000000000 ____D C:\Users\Peter\AppData\Roaming\NOW TV Player 2019-10-10 15:42 - 2018-11-15 20:10 - 000000000 ____D C:\Users\Peter\AppData\Roaming\NOW TV 2019-10-10 15:42 - 2018-11-15 20:10 - 000000000 ____D C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NOW TV 2019-10-10 15:34 - 2019-08-30 11:28 - 000840848 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2019-10-10 15:34 - 2019-03-19 05:50 - 000000000 ____D C:\WINDOWS\INF 2019-10-10 15:27 - 2019-08-30 11:33 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2019-10-10 15:02 - 2017-12-29 21:12 - 000000000 ____D C:\Users\Peter\AppData\Roaming\WhatsApp 2019-10-10 11:14 - 2017-01-14 23:46 - 000000364 _____ C:\WINDOWS\Tasks\HPCeeScheduleForPeter.job 2019-10-10 01:45 - 2019-03-19 05:52 - 000000000 ___RD C:\WINDOWS\PrintDialog 2019-10-10 01:45 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe 2019-10-10 01:45 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2019-10-10 01:45 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SystemResources 2019-10-10 01:45 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform 2019-10-10 01:45 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\oobe 2019-10-10 01:45 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\Dism 2019-10-10 01:45 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\bcastdvr 2019-10-10 01:45 - 2019-03-19 05:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2019-10-10 01:17 - 2019-03-19 05:37 - 000000000 ____D C:\WINDOWS\CbsTemp 2019-10-10 01:16 - 2016-03-19 21:48 - 000000000 ____D C:\WINDOWS\system32\MRT 2019-10-10 01:13 - 2016-03-19 21:48 - 127230528 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2019-10-09 18:25 - 2019-08-30 11:33 - 000003256 _____ C:\WINDOWS\system32\Tasks\HPCeeScheduleForPeter 2019-10-09 13:59 - 2018-10-20 17:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2019-10-08 14:30 - 2019-03-19 05:52 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2019-10-08 00:07 - 2016-07-20 17:19 - 000000000 ____D C:\Program Files (x86)\Origin 2019-10-07 19:30 - 2019-08-30 11:33 - 000003420 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA 2019-10-07 19:30 - 2019-08-30 11:33 - 000003296 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore 2019-10-07 19:30 - 2016-03-26 15:24 - 000000000 ____D C:\Program Files (x86)\Google 2019-10-07 18:28 - 2016-05-10 14:38 - 000000000 ____D C:\Users\Peter\AppData\LocalLow\Temp 2019-10-07 17:59 - 2018-02-17 13:18 - 000000000 ____D C:\Program Files\Utilities 2019-10-06 02:30 - 2016-07-20 17:24 - 000000000 ____D C:\Users\Peter\AppData\Roaming\Origin 2019-10-05 20:31 - 2018-04-16 10:52 - 000000000 ____D C:\Users\Peter\AppData\Roaming\vlc 2019-10-05 18:45 - 2016-07-21 19:46 - 000226168 _____ C:\WINDOWS\SysWOW64\PnkBstrB.exe 2019-10-05 18:45 - 2016-07-21 19:46 - 000214392 _____ C:\WINDOWS\SysWOW64\PnkBstrB.ex0 2019-10-05 18:29 - 2016-07-20 17:24 - 000000000 ____D C:\Program Files (x86)\Origin Games 2019-10-05 18:25 - 2016-09-08 16:41 - 001259632 _____ (EasyAntiCheat Oy) C:\WINDOWS\system32\Drivers\EasyAntiCheat.sys 2019-10-05 17:39 - 2019-08-30 11:33 - 000003380 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2643124959-2563984870-1026749049-1001 2019-10-05 17:39 - 2019-08-30 11:25 - 000002367 _____ C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2019-10-04 20:16 - 2016-11-26 17:55 - 000000258 __RSH C:\ProgramData\ntuser.pol 2019-10-04 19:18 - 2018-05-19 10:45 - 000000000 ____D C:\Users\Peter\AppData\Local\D3DSCache 2019-10-04 09:40 - 2017-12-09 17:04 - 000000000 ____D C:\Users\Peter\AppData\Local\PlaceholderTileLogoFolder 2019-10-04 08:29 - 2016-10-01 18:37 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2019-10-04 08:17 - 2016-10-01 18:37 - 000001232 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2019-10-04 08:15 - 2016-04-14 16:09 - 000000000 ___RD C:\Users\Peter\3D Objects 2019-10-04 08:15 - 2016-02-13 14:20 - 000000000 __RHD C:\Users\Public\AccountPictures 2019-10-04 08:14 - 2019-08-30 11:22 - 000447760 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2019-10-04 08:13 - 2019-03-19 05:52 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2019-10-04 08:13 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\WinMetadata 2019-10-04 08:13 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\migwiz 2019-10-04 08:13 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\PolicyDefinitions 2019-10-03 21:53 - 2017-05-10 18:00 - 000000000 ____D C:\Program Files\Common Files\AV 2019-10-03 21:11 - 2019-08-30 11:25 - 000000000 ____D C:\Users\Peter 2019-10-03 21:05 - 2016-11-26 17:55 - 000000000 ____D C:\Program Files (x86)\FreeCodecPack 2019-10-03 20:08 - 2016-04-07 13:26 - 000000000 ____D C:\Program Files (x86)\Dropbox 2019-10-03 19:26 - 2019-01-11 17:24 - 000000000 ____D C:\Program Files (x86)\Java 2019-10-03 19:25 - 2019-01-11 17:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2019-10-03 19:24 - 2019-01-11 17:24 - 000098288 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2019-10-03 17:25 - 2018-01-09 19:38 - 000000000 ____D C:\Users\Peter\AppData\Local\WhatsApp 2019-10-03 07:47 - 2018-02-19 01:47 - 000000000 ____D C:\WINDOWS\Microsoft Antimalware 2019-10-02 21:46 - 2018-11-15 01:30 - 000000000 ____D C:\Program Files (x86)\Kaspersky Lab 2019-10-02 21:46 - 2018-03-01 10:12 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2019-10-02 21:45 - 2019-03-19 05:37 - 000032768 _____ C:\WINDOWS\system32\config\ELAM 2019-10-02 21:45 - 2015-10-30 07:28 - 000000000 ____D C:\Users\Default.migrated 2019-10-02 12:56 - 2017-12-06 23:20 - 000000000 ____D C:\Users\Peter\AppData\Local\Packages 2019-09-29 21:12 - 2018-04-16 10:54 - 000000000 ____D C:\Users\Peter\AppData\Roaming\dvdcss 2019-09-29 21:09 - 2018-04-16 10:51 - 000000916 _____ C:\Users\Public\Desktop\VLC media player.lnk 2019-09-29 21:09 - 2018-04-16 10:51 - 000000916 _____ C:\ProgramData\Desktop\VLC media player.lnk 2019-09-27 17:47 - 2019-08-29 15:55 - 000000000 ___DC C:\WINDOWS\Panther 2019-09-23 20:34 - 2017-08-28 21:02 - 000000000 ____D C:\Users\Peter\AppData\Local\SquirrelTemp 2019-09-21 16:12 - 2016-03-26 00:32 - 000000000 ____D C:\Users\Peter\AppData\Local\ElevatedDiagnostics 2019-09-20 21:07 - 2018-03-18 20:00 - 000000000 ____D C:\NVIDIA 2019-09-20 21:06 - 2019-01-12 20:15 - 000000000 ____D C:\TEMP 2019-09-20 21:06 - 2017-05-15 15:43 - 000000000 ____D C:\ProgramData\NVIDIA Corporation 2019-09-20 21:06 - 2017-05-15 15:42 - 000000000 ____D C:\Program Files\NVIDIA Corporation 2019-09-20 21:04 - 2017-05-15 15:42 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2019-09-20 20:52 - 2017-12-22 23:05 - 000000000 ____D C:\Users\Peter\AppData\Roaming\EasyAntiCheat 2019-09-20 20:52 - 2016-09-08 16:41 - 000000000 ____D C:\Users\Peter\AppData\Local\UnrealEngine 2019-09-19 23:42 - 2019-06-23 12:58 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2019-09-19 23:42 - 2019-06-23 12:58 - 000002260 _____ C:\ProgramData\Desktop\Google Chrome.lnk 2019-09-19 23:42 - 2016-03-26 15:25 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2019-09-12 00:20 - 2019-03-19 05:52 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs 2019-09-12 00:20 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\TextInput 2019-09-12 00:20 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation 2019-09-12 00:20 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\ShellExperiences 2019-09-12 00:20 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\Provisioning 2019-09-12 00:18 - 2019-03-19 07:20 - 000021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\OEMDefaultAssociations.dll 2019-09-12 00:18 - 2019-03-19 07:20 - 000018903 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml 2019-09-12 00:18 - 2019-03-19 05:37 - 000000000 ____D C:\WINDOWS\servicing ==================== Files in the root of some directories ================ 2016-06-17 07:53 - 2016-06-17 07:53 - 000000775 _____ () C:\Users\Peter\AppData\Roaming\baynote80.js 2016-12-22 19:35 - 2016-12-22 19:35 - 000063618 _____ () C:\Users\Peter\AppData\Roaming\Cordovan.DyhO 2016-06-17 07:53 - 2016-06-17 07:53 - 000000874 _____ () C:\Users\Peter\AppData\Roaming\dbmanager_schema.xml 2016-11-29 01:37 - 2018-01-27 01:37 - 000000545 _____ () C:\Users\Peter\AppData\Roaming\WB.CFG 2017-12-25 13:26 - 2017-12-25 13:26 - 000000068 _____ () C:\Users\Peter\AppData\Local\8wne5tkb2q 2019-10-04 17:14 - 2019-10-04 17:14 - 000474205 _____ () C:\Users\Peter\AppData\Local\ars.cache 2019-10-04 17:16 - 2019-10-04 17:16 - 001352267 _____ () C:\Users\Peter\AppData\Local\census.cache 2017-12-13 18:45 - 2017-12-17 12:55 - 000000068 _____ () C:\Users\Peter\AppData\Local\ClaPyncRAj 2017-02-25 23:34 - 2017-02-25 23:35 - 000007168 _____ () C:\Users\Peter\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2019-10-04 16:46 - 2019-10-04 16:46 - 000000036 _____ () C:\Users\Peter\AppData\Local\housecall.guid.cache 2018-09-28 20:49 - 2019-09-22 14:03 - 000000104 _____ () C:\Users\Peter\AppData\Local\oobelibMkey.log 2019-10-04 16:52 - 2019-10-04 16:52 - 000000010 _____ () C:\Users\Peter\AppData\Local\sponge.last.runtime.cache 2017-12-17 12:45 - 2017-12-17 12:45 - 000000068 _____ () C:\Users\Peter\AppData\Local\xIaaeMKoWq 2019-09-07 02:44 - 2019-09-07 02:44 - 000000000 _____ () C:\Users\Peter\AppData\Local\{33853F11-5277-4F6D-A197-235C702AAC30} 2016-05-01 19:35 - 2016-05-01 19:36 - 000000000 _____ () C:\Users\Peter\AppData\Local\{59F1B21B-6A55-43B9-A9FA-17EA1C6E29E2} ==================== SigCheck =============================== (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ============================
- 21 replies
-
- trojan:win32/coinminer
- trojan
-
(and 1 more)
Tagged with:
-
Hi I think so some little problems will I send the new set test files just to be sure Kind Regards Primaxuk
- 21 replies
-
- trojan:win32/coinminer
- trojan
-
(and 1 more)
Tagged with:
-
Hi Nasdaq thanks for your help I think I have done it wright I sent the file that you showed me to Total virus and was pick up by about 9 virus checkers so I followed your instructions and a pasted the fix log in the reply I have Downloaded Malwarebytes and still not working Kind Regards Primaxuk
- 21 replies
-
- trojan:win32/coinminer
- trojan
-
(and 1 more)
Tagged with:
-
Fix result of Farbar Recovery Scan Tool (x64) Version: 06-10-2019 Ran by Peter (07-10-2019 18:09:36) Run:1 Running from C:\Users\Peter\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\TempState\Downloads Loaded Profiles: Peter (Available Profiles: Peter) Boot Mode: Normal ============================================== fixlist content: ***************** CreateRestorePoint: EmptyTemp: CloseProcesses: Task: {958FAD45-7A69-4510-BDD1-E04F1269F335} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION Toolbar: HKU\S-1-5-21-2643124959-2563984870-1026749049-1001 -> No Name - {C500C267-63BF-451F-8797-4D720C9A2ED9} - No File ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => -> No File AlternateDataStreams: C:\Users\Peter\Desktop\2016-09-06 10.53.26.jpg:com.dropbox.attributes [385] AlternateDataStreams: C:\Users\Peter\Desktop\Dog try art.jpg:com.dropbox.attributes [168] FirewallRules: [{15F1B4E1-4E51-4D0F-825B-3292AB54081F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe No File FirewallRules: [{32223D64-C931-48B9-AE0F-0CB840440FE7}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe No File FirewallRules: [{2BBAE440-284C-474B-97FE-9A2D3F2500BE}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe No File FirewallRules: [{083543A2-DF37-40D7-9DE9-A50E34A1992D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe No File FirewallRules: [UDP Query User{29F85D5A-ABE5-48E9-9365-6BB9C990C1B4}C:\program files (x86)\steam\steamapps\common\squad\squad\binaries\win64\squad.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\squad\squad\binaries\win64\squad.exe No File FirewallRules: [TCP Query User{357582B4-AB85-47E5-90EE-9675172B999A}C:\program files (x86)\steam\steamapps\common\squad\squad\binaries\win64\squad.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\squad\squad\binaries\win64\squad.exe No File FirewallRules: [{F613CC9E-526C-4888-869F-33AFE6FB1478}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File FirewallRules: [{A3C03B12-FC10-4435-904A-6B7ED850A426}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File FirewallRules: [{3F2EF14E-9E44-40E0-9592-AFE0FAE28161}] => (Allow) C:\Games\World_of_Warships\worldofwarships.exe No File FirewallRules: [{8C52E1B6-B9ED-413E-9EFE-5583B9EA6D16}] => (Allow) C:\Games\World_of_Warships\worldofwarships.exe No File FirewallRules: [{96A944B1-1B10-4B0C-A590-A2619176B34F}] => (Allow) C:\Games\World_of_Warships\WoWSLauncher.exe No File FirewallRules: [{066EEFCA-F4EA-4146-9EAE-976D74E5C713}] => (Allow) C:\Games\World_of_Warships\WoWSLauncher.exe No File FirewallRules: [{68E3ABB6-6E84-4739-B43D-EF09E3E53EBD}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe No File FirewallRules: [{87BFEEC3-940E-4A01-B648-8EE0219E901D}] => (Allow) C:\Users\Peter\AppData\Roaming\uTorrent\uTorrent.exe No File FirewallRules: [{69899881-B894-4CF5-A4BA-106BFA17C6C3}] => (Allow) C:\Users\Peter\AppData\Roaming\uTorrent\uTorrent.exe No File FirewallRules: [{CB8E54A6-E85C-4626-8799-D78099176923}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe No File FirewallRules: [{0A39A901-C9EE-4990-88ED-B99454888082}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe No File FirewallRules: [{30933D81-4EA0-472C-B251-147E494ED8C1}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe No File FirewallRules: [{C3C4133C-A5B3-4B25-A938-4742BD5D4BBF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe No File FirewallRules: [{E1A77D00-BFBB-410B-B5F4-36DFEAF6A034}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe No File FirewallRules: [{97040820-ABF7-4ED0-A099-9A8C59895B01}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe No File FirewallRules: [{2E9378D3-8B41-4309-B9D5-E06AADFB6991}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe No File FirewallRules: [{8DAD07C6-82DF-49DE-92EC-265CC90E3483}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe No File FirewallRules: [{0C478807-A659-48D4-9808-4DC7427E1430}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe No File FirewallRules: [TCP Query User{979149DF-441F-4A74-A400-E1F11B441156}C:\program files (x86)\steam\steamapps\common\squad\squad\binaries\win64\squad.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\squad\squad\binaries\win64\squad.exe No File FirewallRules: [UDP Query User{67BBC688-7774-4314-A5AF-68AFE57B234E}C:\program files (x86)\steam\steamapps\common\squad\squad\binaries\win64\squad.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\squad\squad\binaries\win64\squad.exe No File FirewallRules: [{1E19147F-9256-4C71-8CF1-54B45600D0DC}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe No File FirewallRules: [{EF28C03C-4196-4E82-9E0E-19BF5259233D}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe No File FirewallRules: [{8AD8D8BB-E97C-43D6-A658-B66C3ABF4B57}] => (Allow) C:\Users\Peter\AppData\Roaming\Zoom\bin\airhost.exe No File FirewallRules: [{468476CC-CA34-4DB6-B6A5-3210471D530B}] => (Allow) myportal.reedsrains.co.uk No File FirewallRules: [{118D388B-5EB6-498F-887B-7E2E4D827EC9}] => (Allow) myportal.reedsrains.co.uk No File FirewallRules: [{31DED1F0-7923-4ED5-839D-ABBDA0C73695}] => (Allow) C:\Users\Peter\AppData\Local\Temp\HouseCall\tmase\nmap\nmap.exe No File VirusTotal: C:\Program Files\Utilities\UtilitiesService.exe ***************** Restore point was successfully created. Processes closed successfully. "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{958FAD45-7A69-4510-BDD1-E04F1269F335}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{958FAD45-7A69-4510-BDD1-E04F1269F335}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager" => not found "HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C500C267-63BF-451F-8797-4D720C9A2ED9}" => removed successfully HKLM\Software\Classes\CLSID\{C500C267-63BF-451F-8797-4D720C9A2ED9} => not found HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => removed successfully HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast => removed successfully HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => not found HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxDTCM => removed successfully HKLM\Software\Classes\CLSID\{9B5F5829-A529-4B12-814A-E81BCB8D93FC} => not found C:\Users\Peter\Desktop\2016-09-06 10.53.26.jpg => ":com.dropbox.attributes" ADS could not remove. C:\Users\Peter\Desktop\Dog try art.jpg => ":com.dropbox.attributes" ADS could not remove. "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{15F1B4E1-4E51-4D0F-825B-3292AB54081F}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{32223D64-C931-48B9-AE0F-0CB840440FE7}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2BBAE440-284C-474B-97FE-9A2D3F2500BE}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{083543A2-DF37-40D7-9DE9-A50E34A1992D}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{29F85D5A-ABE5-48E9-9365-6BB9C990C1B4}C:\program files (x86)\steam\steamapps\common\squad\squad\binaries\win64\squad.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{357582B4-AB85-47E5-90EE-9675172B999A}C:\program files (x86)\steam\steamapps\common\squad\squad\binaries\win64\squad.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F613CC9E-526C-4888-869F-33AFE6FB1478}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A3C03B12-FC10-4435-904A-6B7ED850A426}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3F2EF14E-9E44-40E0-9592-AFE0FAE28161}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8C52E1B6-B9ED-413E-9EFE-5583B9EA6D16}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{96A944B1-1B10-4B0C-A590-A2619176B34F}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{066EEFCA-F4EA-4146-9EAE-976D74E5C713}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{68E3ABB6-6E84-4739-B43D-EF09E3E53EBD}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{87BFEEC3-940E-4A01-B648-8EE0219E901D}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{69899881-B894-4CF5-A4BA-106BFA17C6C3}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{CB8E54A6-E85C-4626-8799-D78099176923}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0A39A901-C9EE-4990-88ED-B99454888082}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{30933D81-4EA0-472C-B251-147E494ED8C1}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C3C4133C-A5B3-4B25-A938-4742BD5D4BBF}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E1A77D00-BFBB-410B-B5F4-36DFEAF6A034}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{97040820-ABF7-4ED0-A099-9A8C59895B01}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2E9378D3-8B41-4309-B9D5-E06AADFB6991}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8DAD07C6-82DF-49DE-92EC-265CC90E3483}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0C478807-A659-48D4-9808-4DC7427E1430}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{979149DF-441F-4A74-A400-E1F11B441156}C:\program files (x86)\steam\steamapps\common\squad\squad\binaries\win64\squad.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{67BBC688-7774-4314-A5AF-68AFE57B234E}C:\program files (x86)\steam\steamapps\common\squad\squad\binaries\win64\squad.exe" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1E19147F-9256-4C71-8CF1-54B45600D0DC}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{EF28C03C-4196-4E82-9E0E-19BF5259233D}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8AD8D8BB-E97C-43D6-A658-B66C3ABF4B57}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{468476CC-CA34-4DB6-B6A5-3210471D530B}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{118D388B-5EB6-498F-887B-7E2E4D827EC9}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{31DED1F0-7923-4ED5-839D-ABBDA0C73695}" => removed successfully "VirusTotal: C:\Program Files\Utilities\UtilitiesService.exe" => not found =========== EmptyTemp: ========== BITS transfer queue => 13656064 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 139644466 B Java, Flash, Steam htmlcache => 137514256 B Windows/system/drivers => 4880413 B Edge => 91086864 B Chrome => 478853463 B Firefox => 984824970 B Opera => 28826787 B Temp, IE cache, history, cookies, recent: Default => 0 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 120396 B LocalService => 120396 B NetworkService => 5041744 B NetworkService => 5041744 B Peter => 424062581 B RecycleBin => 12881265 B EmptyTemp: => 2.2 GB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 18:30:14 ====
- 21 replies
-
- trojan:win32/coinminer
- trojan
-
(and 1 more)
Tagged with:
-
Hi Nasdaq thanks for your help I would grateful for your help with getting rid of this Trojan:Win32/CoinMiner and if you see anything else in the logs Thanks in advance Primaxuk
- 21 replies
-
- trojan:win32/coinminer
- trojan
-
(and 1 more)
Tagged with:
-
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06-10-2019 Ran by Peter (06-10-2019 15:02:16) Running from C:\Users\Peter\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\TempState\Downloads Windows 10 Home Version 1903 18362.388 (X64) (2019-08-30 10:33:15) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2643124959-2563984870-1026749049-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-2643124959-2563984870-1026749049-503 - Limited - Disabled) Guest (S-1-5-21-2643124959-2563984870-1026749049-501 - Limited - Disabled) Peter (S-1-5-21-2643124959-2563984870-1026749049-1001 - Administrator - Enabled) => C:\Users\Peter WDAGUtilityAccount (S-1-5-21-2643124959-2563984870-1026749049-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Kaspersky Free (Enabled - Up to date) {B1D2E896-6D96-7460-F17A-838B9D00DD65} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 64 Bit HP CIO Components Installer (HKLM\...\{5737101A-27C4-408A-8A57-D1DC78DF84B4}) (Version: 8.2.1 - Hewlett-Packard) Hidden 7-Zip 19.00 (x64) (HKLM\...\7-Zip) (Version: 19.00 - Igor Pavlov) Adobe Acrobat 8 Standard - English, Français, Deutsch (HKLM-x32\...\Adobe Acrobat 8 Standard - English, Français, Deutsch) (Version: 8.0.0 - Adobe Systems) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 4.0.1.188 - Adobe Systems Incorporated) Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.255 - Adobe) Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.255 - Adobe) Adobe Photoshop 7.0 (HKLM-x32\...\Adobe Photoshop 7.0) (Version: 7.0 - Adobe Systems, Inc.) Adobe Photoshop CC 2015.5 (HKLM-x32\...\PHSP_17_0_1) (Version: 17.0.1 - Adobe Systems Incorporated) Aiseesoft Data Recovery 1.1.18 (HKLM-x32\...\{E67DD0BA-233F-4EA9-B010-9B0A3D58F690}_is1) (Version: 1.1.18 - Aiseesoft Studio) Alt.Binz 0.39.4 (HKLM-x32\...\Alt.Binz) (Version: 0.39.4 - Rdl) ANT Drivers Installer x64 (HKLM\...\{7664AF65-7B0D-4171-9F0F-50455278B428}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden Apowersoft Online Launcher version 1.4.6 (HKLM-x32\...\{20BF67A8-D81A-4489-8225-FABAA0896E2D}_is1) (Version: 1.4.6 - APOWERSOFT LIMITED) Avanquest Message (HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\{20573C69-4A68-4BEF-A23D-365CB66924CE}) (Version: 2.08.0 - Avanquest Software) Avanquest update (HKLM-x32\...\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}) (Version: 1.34 - Avanquest Software) Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.8.2.48475 - Electronic Arts) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.0 - EA Digital Illusions CE AB) Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.6.1 - Canon Inc.) CanoScan LiDE 110 Scanner Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ2414) (Version: - Canon Inc.) CPUID CPU-Z 1.87 (HKLM\...\CPUID CPU-Z_is1) (Version: 1.87 - CPUID, Inc.) CyberSky 5 (HKLM-x32\...\CyberSky 5) (Version: 5.0.3 - Stephen Michael Schimpf) Discord (HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\Discord) (Version: 0.0.301 - Discord Inc.) Dropbox (HKLM-x32\...\Dropbox) (Version: 82.4.155 - Dropbox, Inc.) Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.241.1 - Dropbox, Inc.) Hidden DYNALOG (HKLM-x32\...\DYNALOG) (Version: 3.5.43 DYA - Julius Blum Ges.m.b.H) Elevated Installer (HKLM-x32\...\{1052502B-4C91-43F9-B160-AE39ED57C9F0}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries) Hidden Epic Games Launcher (HKLM-x32\...\{2DE76AAC-8061-4D9B-B7BA-A7CFBE0F8048}) (Version: 1.1.86.0 - Epic Games, Inc.) ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB) Far Cry 5 (HKLM-x32\...\{73B938C4-0DDA-448D-8E46-87401EA87339}_is1) (Version: - Ubisoft) Free Screen Video Recorder (HKLM-x32\...\Free Screen Video Recorder_is1) (Version: 3.0.45.1027 - Digital Wave Ltd) Garmin Express (HKLM-x32\...\{BCC7CA85-E57F-452D-BB44-15A1CE018BD0}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries) Hidden Garmin Express (HKLM-x32\...\{bd8bd200-9a60-4969-b267-6b565f36e3da}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries) Garmin Express Tray (HKLM-x32\...\{DA9C865D-6762-4931-8588-0B13B7A0796B}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries) Hidden GL USB2.0 UVC Camera Device (HKLM-x32\...\{9897BBD8-013A-49F3-928E-866A59B6E00C}) (Version: 17.3.20.0 - GenesysLogic) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 77.0.3865.90 - Google LLC) Google Earth Pro (HKLM\...\{70A0F34E-564B-4F93-ADD6-3BAEC6E44075}) (Version: 7.3.2.5776 - Google) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.11 - Google LLC) Hidden Grammarly (HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\GrammarlyForWindows) (Version: 1.5.34 - Grammarly) HP LJ300-400 color M351-M451 (HKLM-x32\...\{15CA73D8-3C82-4BAE-86CD-945BF9620516}) (Version: - Hewlett-Packard) HP Update (HKLM-x32\...\{85DF2EED-08BC-46FB-90DA-28B0D0A8E8A8}) (Version: 5.003.000.004 - Hewlett-Packard) hpbDSService (HKLM-x32\...\{9767CBB5-2A81-427D-8F05-497737D56AA0}) (Version: 001.001.05133 - Hewlett-Packard) Hidden hpbM351M451DSService (HKLM-x32\...\{BF2198EB-503D-4E0B-89FB-509AADD6D545}) (Version: 001.001.05164 - Hewlett-Packard) Hidden HPLaserJet300-400ColorM351-M451Series_HelpLearnCenter_SI (HKLM-x32\...\{BD019D8F-25B9-49D6-B301-07AFF65E35DD}) (Version: 1.02.0000 - Hewlett-Packard) HPLJDXPHelper (HKLM-x32\...\{5E4DD8C2-A906-4F1B-94B6-4F6A51D625B2}) (Version: 020.021.004 - HP) Hidden HPLJUTCore (HKLM-x32\...\{7C8660F9-42DC-4D4E-85D5-CCAE3A2E5B1F}) (Version: 1.02.0014 - HP) Hidden HPLJUTM351-M451 (HKLM-x32\...\{E25710A1-F024-4BAF-898C-32703F047737}) (Version: 1.02.0013 - HP) Hidden hppLaserJetService (HKLM-x32\...\{86F513F7-6CFD-4B07-A762-28E5ED2CEE97}) (Version: 009.022.00806 - Hewlett-Packard) Hidden hppM351_M451LaserJetService (HKLM-x32\...\{96C103D3-F058-4F9A-BDD9-BBE9C1431376}) (Version: 005.020.00094 - Hewlett-Packard) Hidden hppToolboxProxyM351 (HKLM-x32\...\{76595FA3-0B98-43EF-BDD2-D04004AEB3A6}) (Version: 020.021.004 - HP) Hidden hpStatusAlerts (HKLM-x32\...\{BD666C86-25CE-4D88-9F7D-C6266394C18D}) (Version: 020.025.1119 - Hewlett Packard) Hidden hpStatusAlertsM351_M451 (HKLM-x32\...\{56D8909F-DFAF-4F79-83E9-DCEA942F0264}) (Version: 020.023.01805 - Hewlett-Packard) Hidden IGdm 2.4.1 (only current user) (HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\1ead4f81-c61a-5fa6-9e81-7a8c0c868952) (Version: 2.4.1 - ifedapo olarewaju) InPixio Photo Clip 7 (HKLM-x32\...\{829CAB57-8D17-49F8-A5B0-302B501FCEC2}) (Version: 7.7.0 - InPixio) inPixio Photo Clip 8 (HKLM-x32\...\{65634D2B-B6D1-4B35-B4C9-F3999B8D008B}) (Version: 8.5.0 - InPixio) InstaCards (HKLM-x32\...\{58259C24-7B5E-4977-93B0-E9EEA1B884CE}) (Version: 1.6.2 - InPixio) InstanceFinder (HKLM-x32\...\{32C0FD10-8FB4-427E-A16F-ED57C9343CF0}) (Version: 020.021.004 - HP) Hidden Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4352 - Intel Corporation) IrfanView 64 (remove only) (HKLM\...\IrfanView64) (Version: 4.42 - Irfan Skiljan) Java 8 Update 221 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180221F0}) (Version: 8.0.2210.11 - Oracle Corporation) Kaspersky Secure Connection (HKLM-x32\...\{F10AA188-7166-430E-8810-FEAB2AD73DE3}) (Version: 19.0.0.1088 - Kaspersky Lab) Hidden Kaspersky Secure Connection (HKLM-x32\...\InstallWIX_{F10AA188-7166-430E-8810-FEAB2AD73DE3}) (Version: 19.0.0.1088 - Kaspersky Lab) Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden LJDXPHelperUI (HKLM-x32\...\{EAECD0D7-F27D-4F13-8312-A9C0B5C5F1B7}) (Version: 020.021.004 - HP) Hidden Mafia.III.Digital.Deluxe.Edition.v1.01.Incl.2Dlcs-ALI213 version 1.01 (HKLM-x32\...\{AFF51286-259D-443B-B735-C1E71F233DA6}}_is1) (Version: 1.01 - Ali213.net) McAfee True Key (HKLM\...\TrueKey) (Version: 5.3.138.1 - McAfee, LLC) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE (HKLM-x32\...\{2C9EE786-1DDB-4C98-8FA4-B1B9B5A66B77}) (Version: 3.1.186.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}) (Version: 3.1.99.0 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\OneDriveSetup.exe) (Version: 19.152.0927.0012 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Mozilla Firefox 69.0.2 (x64 en-GB) (HKLM\...\Mozilla Firefox 69.0.2 (x64 en-GB)) (Version: 69.0.2 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 65.0 - Mozilla) MySQL Connector/ODBC 5.1 (HKLM-x32\...\{6F206B58-E2F7-4A70-ACAC-8E0ABFBC62F6}) (Version: 5.1.8 - Oracle Corporation) Newsbin for Astraweb (HKLM\...\Newsbin6) (Version: 6.72 - DJI Interprises, LLC) NOW TV Player 6.1.0.0 (HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\com.bskyb.nowtvplayer_is1) (Version: 6.1.0.0 - NOW TV) NVIDIA Graphics Driver 436.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 436.30 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.38.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.21 - NVIDIA Corporation) NVIDIA PhysX System Software 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation) Origin (HKLM-x32\...\Origin) (Version: 10.5.47.29954 - Electronic Arts, Inc.) paint.net (HKLM\...\{6AC1101E-7561-43C9-BEEA-4AB1D220D8FF}) (Version: 4.0.13 - dotPDN LLC) pCloud Drive (HKLM-x32\...\{C3C0052D-E704-4261-91D5-AEAE31F70EFF}) (Version: 3.8.0.0 - pCloud AG) Hidden pCloud Drive (HKLM-x32\...\{e30b668e-667b-451c-8072-85674a7ddc54}) (Version: 3.8.0.0 - pCloud AG) Process Hacker 2.39 (r124) (HKLM\...\Process_Hacker2_is1) (Version: 2.39.0.124 - wj32) Project My Screen App (HKLM-x32\...\{64537E9A-4DAE-42F9-BCD8-8AEEB84D1786}) (Version: 8.0.12349 - Microsoft Corporation) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.) QuickPar 0.9 (HKLM-x32\...\QuickPar) (Version: 0.9 - Peter B. Clements) Rapport (HKLM-x32\...\{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}) (Version: 3.5.1930.429 - Trusteer) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7687 - Realtek Semiconductor Corp.) Sky Go 1.4.16.0 (HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\com.bskyb.skygoplayer_is1) (Version: 1.4.16.0 - Sky) Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation) Skype version 8.52 (HKLM-x32\...\Skype_is1) (Version: 8.52 - Skype Technologies S.A.) Skype Web Plugin (HKLM-x32\...\{EB96DF8B-65A7-4E72-BFB1-38DB36870D16}) (Version: 7.32.6.278 - Skype Technologies S.A.) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.75813 - TeamViewer) TomTom MyDrive Connect 4.1.4.3089 (HKLM-x32\...\MyDriveConnect) (Version: 4.1.4.3089 - TomTom) ToolboxProxy (HKLM-x32\...\{55757576-28B2-4552-AAF6-340F9FFBA9FA}) (Version: 020.023.005 - HP) Hidden Trusteer Endpoint Protection (HKLM-x32\...\Rapport_msi) (Version: 3.5.1930.429 - Trusteer) UE4 Prerequisites (x64) (HKLM\...\{36EAD5CF-44EF-4FCF-8BE1-D96C4835D7A4}) (Version: 1.0.11.0 - Epic Games, Inc.) Hidden UE4 Prerequisites (x64) (HKLM-x32\...\{2890ae6b-90e9-448d-b3e6-97e43c21e2fd}) (Version: 1.0.13.0 - Epic Games, Inc.) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{9CBA860F-7437-4A75-941C-8EF559F2D145}) (Version: 2.52.0.0 - Microsoft Corporation) Video Download Capture V6.1.0 (HKLM-x32\...\{b3336f66-e079-4ff6-abdb-51e2fab781d5}_is1) (Version: 6.1.0 - APOWERSOFT LIMITED) Visual Studio C++ 10.0 Runtime (HKLM-x32\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.) VLC media player (HKLM\...\VLC media player) (Version: 3.0.8 - VideoLAN) WhatsApp (HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\WhatsApp) (Version: 0.3.4679 - WhatsApp) Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.) Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software) WinZip 23.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C2411D}) (Version: 23.0.13300 - Corel Corporation) WinZip_Pro 22.0.12684_ENG_Pre-Activated (HKLM-x32\...\WinZip_Pro 22.0.12684_ENG_Pre-Activated) (Version: 22.0.12684_ENG_Pre-Activated - Corel Corporation) Zebra Font Downloader (HKLM-x32\...\Zebra Font Downloader_is1) (Version: - Zebra Technologies Corporation) Zoom (HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\ZoomUMX) (Version: 4.1 - Zoom Video Communications, Inc.) Packages: ========= Adobe Photoshop Express: Image Editor, Adjustments, Filters, Effects, Borders -> C:\Program Files\WindowsApps\AdobeSystemsIncorporated.AdobePhotoshopExpress_3.0.316.0_x64__ynb6jyjzte8ga [2019-05-25] (Adobe Inc.) Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.0.2.0_x64__tf1gferkr813w [2019-05-28] (Autodesk Inc.) Blu-ray PRO -> C:\Program Files\WindowsApps\YellowElephantProductions.Blu-rayPRO_1.73.71.0_x64__p3e1zgp7z7szg [2019-07-09] (Yellow Elephant Productions) Candy Crush Soda Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSodaSaga_1.149.100.0_x86__kgqvnymyfvs32 [2019-10-04] (king.com) Dropbox for S mode -> C:\Program Files\WindowsApps\C27EB4BA.DROPBOX_22.4.3.0_x64__xbfy0k16fey96 [2019-09-27] (Dropbox Inc.) F5 Access -> C:\Program Files\WindowsApps\F5Networks.vpn.client_1.3.0.0_x64__btcnfmkykcjs2 [2018-10-13] (F5 Networks) Forza Hub -> C:\Program Files\WindowsApps\Microsoft.Lucille_1.0.4.0_x64__8wekyb3d8bbwe [2018-02-18] (Microsoft Studios) Forza Motorsport 6: Apex -> C:\Program Files\WindowsApps\Microsoft.ApexPG_2.8.18.1000_x64__8wekyb3d8bbwe [2018-04-13] (Microsoft Studios) HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_100.1.581.0_x64__v10z8vjag6ke6 [2019-07-20] (HP Inc.) Instagram -> C:\Program Files\WindowsApps\Facebook.InstagramBeta_41.1788.50991.0_x86__8xx8rvfyw5nnt [2018-07-17] (Instagram) Mail and Calendar -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12026.20218.0_x64__8wekyb3d8bbwe [2019-09-27] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1808.3.0_x64__8wekyb3d8bbwe [2019-08-30] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-15] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-15] (Microsoft Corporation) [MS Ad] Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.32.12463.0_x64__8wekyb3d8bbwe [2019-09-11] (Microsoft Corporation) [MS Ad] Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.4.10022.0_x64__8wekyb3d8bbwe [2019-10-06] (Microsoft Studios) [MS Ad] MSN Money -> C:\Program Files\WindowsApps\Microsoft.BingFinance_4.31.11905.0_x64__8wekyb3d8bbwe [2019-07-20] (Microsoft Corporation) [MS Ad] MSN Sport -> C:\Program Files\WindowsApps\Microsoft.BingSports_4.31.11905.0_x64__8wekyb3d8bbwe [2019-07-20] (Microsoft Corporation) [MS Ad] MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.32.12463.0_x64__8wekyb3d8bbwe [2019-09-11] (Microsoft Corporation) [MS Ad] Photos Add-on -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2017.39121.36610.0_x64__8wekyb3d8bbwe [2018-09-13] (Microsoft Corporation) Player for Media -> C:\Program Files\WindowsApps\VirtualPulse.PlayerforMedia_1.69.153.0_x64__nh7p8cqfc4t04 [2019-06-17] (Virtual Pulse) Rar. Click here! -> C:\Program Files\WindowsApps\61262Arrowgance.Rar.Clickhere_1.2.0.0_neutral__erx5c4savp7xt [2018-02-25] (Arrowgance) TeamViewer: Remote Control -> C:\Program Files\WindowsApps\TeamViewer.31414B719FA93_14.0.100.0_x86__89446h4zmeyyt [2018-10-24] (TeamViewer) Twitter -> C:\Program Files\WindowsApps\9E2F88E3.Twitter_6.1.4.1000_neutral__wgeqdkkx372wm [2018-09-08] (Twitter Inc.) Video Player All Formats -> C:\Program Files\WindowsApps\10414Kingloft.VideoPlayerAllFormats_1.1.2.0_x64__hwg4vmr4pnwdp [2018-04-16] (Kingloft) [MS Ad] VLC for Windows Store -> C:\Program Files\WindowsApps\VideoLAN.VLCforWindows8_3.1.1.0_x86__paz6r1rewnh0a [2018-08-06] (VideoLAN) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2643124959-2563984870-1026749049-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-513FE7238137} -> [Creative Cloud Files] => C:\Users\Peter\Creative Cloud Files [2016-10-08 12:31] CustomCLSID: HKU\S-1-5-21-2643124959-2563984870-1026749049-1001_Classes\CLSID\{41052F6E-3662-4584-BCD3-77BCCAAE8470}\InprocServer32 -> C:\Users\Peter\AppData\Local\SkypePlugin\7.32.6.278\GatewayActiveX-x64.dll (Microsoft Corporation -> Skype Technologies S.A.) CustomCLSID: HKU\S-1-5-21-2643124959-2563984870-1026749049-1001_Classes\CLSID\{CB2B673F-D441-4CD4-AFBE-DC4037CA4220}\InprocServer32 -> C:\Program Files\WinZip\adxloader64.WinZipExpressForOffice.dll (Corel Corporation -> ) CustomCLSID: HKU\S-1-5-21-2643124959-2563984870-1026749049-1001_Classes\CLSID\{E31EA727-12ED-4702-820C-4B6445F28E1A} -> [Dropbox] => C:\Users\Peter\Downloads\drop box work\Dropbox [2016-04-07 15:52] CustomCLSID: HKU\S-1-5-21-2643124959-2563984870-1026749049-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems Incorporated -> Adobe Systems) SSODL: EldosMountNotificator-cbfs6 - {34505669-1400-447A-A735-B6A3413825D9} - C:\WINDOWS\system32\cbfsMntNtf6.dll (EldoS Corporation -> /n software, Inc.) SSODL-x32: EldosMountNotificator-cbfs6 - {34505669-1400-447A-A735-B6A3413825D9} - C:\WINDOWS\SysWOW64\cbfsMntNtf6.dll (EldoS Corporation -> /n software, Inc.) ShellServiceObjects: Virtual Storage Mount Notification -> {34505669-1400-447A-A735-B6A3413825D9} => C:\WINDOWS\system32\cbfsMntNtf6.dll [2016-09-09] (EldoS Corporation -> /n software, Inc.) ShellServiceObjects-x32: Virtual Storage Mount Notification -> {34505669-1400-447A-A735-B6A3413825D9} => C:\WINDOWS\SysWOW64\cbfsMntNtf6.dll [2016-09-09] (EldoS Corporation -> /n software, Inc.) ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2217832 2009-02-26] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ pCloudINPROGRESS] -> {D8BFAFBD-B670-4252-9C17-9CF1C64C2BAF} => C:\Program Files (x86)\pCloud Drive\OverlayIcon64.dll [2017-10-23] (TODO: <Company name>) [File not signed] ShellIconOverlayIdentifiers: [ pCloudINSYNC] -> {8D0C0582-552A-4A6B-9455-DA63E1F329C0} => C:\Program Files (x86)\pCloud Drive\OverlayIcon64.dll [2017-10-23] (TODO: <Company name>) [File not signed] ShellIconOverlayIdentifiers: [ pCloudNOSYNC] -> {3858ED1B-8F1C-42ED-A8A9-FDBF591E3C6B} => C:\Program Files (x86)\pCloud Drive\OverlayIcon64.dll [2017-10-23] (TODO: <Company name>) [File not signed] ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] (Adobe Systems Incorporated -> ) ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] (Adobe Systems Incorporated -> ) ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] (Adobe Systems Incorporated -> ) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ShellIconOverlayIdentifiers: [EldosIconOverlay-cbfs6] -> {7BB0B781-331E-4EED-A0F6-05B01FC88898} => C:\WINDOWS\system32\cbfsMntNtf6.dll [2016-09-09] (EldoS Corporation -> /n software, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [EldosIconOverlay-cbfs6] -> {7BB0B781-331E-4EED-A0F6-05B01FC88898} => C:\WINDOWS\system32\cbfsMntNtf6.dll [2016-09-09] (EldoS Corporation -> /n software, Inc.) ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed] ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] (Adobe Systems Incorporated -> ) ContextMenuHandlers1-x32: [Adobe.Acrobat.ContextMenu] -> {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} => C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat Elements\ContextMenu.dll [2006-10-22] (Adobe Systems, Incorporated -> Adobe Systems Inc.) ContextMenuHandlers1: [ContextMenuExtension] -> {a0b73fac-351f-3948-9d8a-1dad9d870193} => C:/Program Files (x86)/pCloud Drive/ContextMenuHandler.DLL [2019-01-22] (pCloud AG) [File not signed] ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers1: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\WZSHLS64.DLL [2018-11-07] (Corel Corporation -> WinZip Computing) ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed] ContextMenuHandlers4: [ContextMenuExtension] -> {a0b73fac-351f-3948-9d8a-1dad9d870193} => C:/Program Files (x86)/pCloud Drive/ContextMenuHandler.DLL [2019-01-22] (pCloud AG) [File not signed] ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\WZSHLS64.DLL [2018-11-07] (Corel Corporation -> WinZip Computing) ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => -> No File ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2019-09-05] (NVIDIA Corporation -> NVIDIA Corporation) ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed] ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] (Adobe Systems Incorporated -> ) ContextMenuHandlers6-x32: [Adobe.Acrobat.ContextMenu] -> {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} => C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat Elements\ContextMenu.dll [2006-10-22] (Adobe Systems, Incorporated -> Adobe Systems Inc.) ContextMenuHandlers6: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\WZSHLS64.DLL [2018-11-07] (Corel Corporation -> WinZip Computing) ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2017-01-25 20:07 - 2017-01-25 20:07 - 000125952 _____ () [File not signed] \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\ffi\build\Release\ffi_bindings.node 2017-01-25 20:07 - 2017-01-25 20:07 - 000118272 _____ () [File not signed] \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\fs-ext\build\Release\fs-ext.node 2017-01-25 20:07 - 2017-01-25 20:07 - 000086528 _____ () [File not signed] \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\idle-gc\build\Release\idle-gc.node 2017-01-25 20:07 - 2017-01-25 20:07 - 000214528 _____ () [File not signed] \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\node-vulcanjs\build\Release\VulcanJS.node 2017-01-25 20:06 - 2017-01-25 20:06 - 000117248 _____ () [File not signed] \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\ref\build\Release\binding.node 2017-03-28 15:32 - 2017-03-28 15:32 - 000073216 _____ () [File not signed] C:\Program Files (x86)\Garmin\Device Interaction Service\FixBootSector.dll 2017-02-14 09:42 - 2017-02-14 09:42 - 000326144 _____ () [File not signed] C:\Program Files (x86)\Garmin\Device Interaction Service\GpsImgWrapper.dll 2019-02-08 10:12 - 2019-09-12 23:26 - 001901568 _____ () [File not signed] C:\Program Files (x86)\Microsoft\Skype for Desktop\ffmpeg.dll 2018-10-20 17:56 - 2019-09-12 23:26 - 000115712 _____ () [File not signed] C:\Program Files (x86)\Microsoft\Skype for Desktop\libegl.dll 2018-10-20 17:56 - 2019-09-12 23:26 - 004636672 _____ () [File not signed] C:\Program Files (x86)\Microsoft\Skype for Desktop\libglesv2.dll 2016-07-20 17:24 - 2016-07-20 17:24 - 000266240 _____ () [File not signed] C:\Program Files (x86)\Origin\imageformats\qmng.dll 2018-11-06 14:34 - 2019-08-20 15:11 - 000015360 _____ () [File not signed] C:\Program Files (x86)\Origin\libEGL.DLL 2018-11-06 14:34 - 2019-08-20 15:11 - 003090944 _____ () [File not signed] C:\Program Files (x86)\Origin\libGLESv2.dll 2019-03-08 18:32 - 2019-03-08 18:32 - 001905152 _____ () [File not signed] C:\Program Files (x86)\pCloud Drive\pSyncLib.dll 2015-06-02 15:51 - 2015-06-02 15:51 - 000545792 _____ () [File not signed] C:\Program Files (x86)\Trusteer\Rapport\bin\js32.dll 2006-10-23 00:19 - 2006-10-23 00:19 - 000019968 _____ (Adobe Systems Inc.) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroTray.DEU 2006-10-23 00:10 - 2006-10-23 00:10 - 000019968 _____ (Adobe Systems Inc.) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroTray.FRA 2006-08-02 07:52 - 2006-08-02 07:52 - 000126976 ____R (Adobe Systems Inc.) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\asneu.dll 2006-09-14 23:20 - 2006-09-14 23:20 - 000212992 ____R (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\adobe_epic.dll 2006-09-14 23:46 - 2006-09-14 23:46 - 000208896 ____R (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\adobe_pcd.dll 2006-09-14 23:20 - 2006-09-14 23:20 - 000346112 ____R (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\adobe_personalization.dll 2017-03-28 15:32 - 2017-03-28 15:32 - 001976832 _____ (Apache Software Foundation) [File not signed] C:\Program Files (x86)\Garmin\Device Interaction Service\XercesLib.dll 2017-03-28 15:34 - 2017-03-28 15:34 - 000234496 _____ (Dynastream Innovations Inc.) [File not signed] C:\Program Files (x86)\Garmin\Device Interaction Service\ANT_WrappedLib.dll 2017-03-28 15:32 - 2017-03-28 15:32 - 002711552 _____ (Garmin International) [File not signed] C:\Program Files (x86)\Garmin\Device Interaction Service\legacyio.dll 2017-02-14 09:42 - 2017-02-14 09:42 - 000343552 _____ (Garmin International, Inc.) [File not signed] C:\Program Files (x86)\Garmin\Device Interaction Service\IMG_GPSMAP.dll 2017-03-28 15:32 - 2017-03-28 15:32 - 000425472 _____ (Garmin) [File not signed] C:\Program Files (x86)\Garmin\Device Interaction Service\XMLdll.dll 2009-09-16 19:44 - 2009-09-16 19:44 - 000153088 _____ (Hewlett Packard) [File not signed] C:\WINDOWS\System32\hptcpmib.dll 2009-09-16 19:45 - 2009-09-16 19:45 - 000331264 _____ (Hewlett Packard) [File not signed] C:\WINDOWS\System32\HpTcpMon.dll 2009-09-16 12:44 - 2009-09-16 12:44 - 000132096 _____ (Hewlett Packard) [File not signed] C:\WINDOWS\System32\hpzjrd01.dll 2011-07-08 09:11 - 2011-07-08 09:11 - 000041472 _____ (Hewlett-Packard Company) [File not signed] C:\Program Files (x86)\HP\HPLaserJetService\HPHTTPProxy.dll 2011-07-08 09:11 - 2011-07-08 09:11 - 000073728 _____ (Hewlett-Packard Company) [File not signed] C:\Program Files (x86)\HP\HPLaserJetService\HPTools.dll 2011-07-08 09:11 - 2011-07-08 09:11 - 001174528 _____ (Hewlett-Packard Company) [File not signed] C:\Program Files (x86)\HP\HPLaserJetService\LEDMXMLObjects.dll 2011-07-08 09:11 - 2011-07-08 09:11 - 000034816 _____ (HP) [File not signed] C:\Program Files (x86)\HP\HPLaserJetService\HPServiceCommunicator.dll 2006-09-15 13:58 - 2006-09-15 13:58 - 000934400 ____R (Macrovision Europe Ltd.) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\FNP_Act_Installer.dll 2008-08-25 23:50 - 2008-08-25 23:50 - 000155648 _____ (Microsoft Corporation) [File not signed] C:\Program Files (x86)\Common Files\Microsoft Shared\VBA\VBA6\1033\VBE6INTL.DLL 2009-09-16 19:45 - 2009-09-16 19:45 - 000317440 _____ (Microsoft Corporation) [File not signed] C:\WINDOWS\System32\HPTcpMUI.dll 2015-07-02 17:44 - 2015-07-02 17:44 - 000057344 _____ (Open Source Software community LGPL) [File not signed] C:\Program Files (x86)\pCloud Drive\pthreadVSE2.dll 2017-03-28 15:32 - 2017-03-28 15:32 - 000090112 _____ (Silicon Laboratories, Inc.) [File not signed] C:\Program Files (x86)\Garmin\Device Interaction Service\DSI_SiUSBXp_3_1.DLL 2019-09-17 11:38 - 2019-08-20 15:11 - 000002560 _____ (The ICU Project) [File not signed] C:\Program Files (x86)\Origin\icudt58.dll 2019-09-17 11:38 - 2019-08-20 15:11 - 001252864 _____ (The ICU Project) [File not signed] C:\Program Files (x86)\Origin\icuuc58.dll 2018-11-06 14:34 - 2019-08-20 15:11 - 001277440 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\LIBEAY32.dll 2019-04-02 10:12 - 2019-08-20 15:11 - 000279040 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\ssleay32.dll 2019-09-17 11:38 - 2019-08-20 15:11 - 000030208 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\imageformats\qgif.dll 2019-09-17 11:38 - 2019-08-20 15:11 - 000032768 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\imageformats\qico.dll 2019-09-17 11:38 - 2019-08-20 15:11 - 000256512 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\imageformats\qjpeg.dll 2019-09-17 11:38 - 2019-08-20 15:11 - 000026112 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\imageformats\qtga.dll 2019-09-17 11:38 - 2019-08-20 15:11 - 000305152 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\imageformats\qtiff.dll 2019-09-17 11:38 - 2019-08-20 15:11 - 000025600 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\imageformats\qwbmp.dll 2018-11-06 14:34 - 2019-08-20 15:11 - 001611264 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\platforms\qwindows.dll 2019-09-17 11:38 - 2019-08-20 15:11 - 005487104 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Core.dll 2019-09-17 11:38 - 2019-08-20 15:11 - 005841920 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Gui.dll 2019-09-17 11:38 - 2019-08-20 15:11 - 000709120 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Multimedia.dll 2019-09-17 11:38 - 2019-08-20 15:11 - 001179136 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Network.dll 2019-09-17 11:38 - 2019-08-20 15:11 - 000207360 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Positioning.dll 2019-09-17 11:38 - 2019-08-20 15:11 - 000310272 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5PrintSupport.dll 2019-09-17 11:38 - 2019-08-20 15:11 - 003513344 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Qml.dll 2019-09-17 11:38 - 2019-08-20 15:11 - 003390976 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Quick.dll 2019-09-17 11:38 - 2019-08-20 15:11 - 000068096 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5QuickWidgets.dll 2019-09-17 11:38 - 2019-08-20 15:11 - 000045568 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5TextToSpeech.dll 2019-09-17 11:38 - 2019-08-20 15:11 - 000116224 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5WebChannel.dll 2019-09-17 11:38 - 2019-08-20 15:11 - 054071296 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5WebEngineCore.dll 2019-09-17 11:38 - 2019-08-20 15:11 - 000211456 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5WebEngineWidgets.dll 2019-09-17 11:38 - 2019-08-20 15:11 - 000146432 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5WebSockets.dll 2019-09-17 11:38 - 2019-08-20 15:11 - 005089792 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Widgets.dll 2019-09-17 11:38 - 2019-08-20 15:11 - 000184832 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Xml.dll 2017-10-23 18:28 - 2017-10-23 18:28 - 000342016 _____ (TODO: <Company name>) [File not signed] C:\Program Files (x86)\pCloud Drive\OverlayIcon64.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\Peter\Desktop\2016-09-06 10.53.26.jpg:com.dropbox.attributes [385] AlternateDataStreams: C:\Users\Peter\Desktop\Dog try art.jpg:com.dropbox.attributes [168] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\amsdk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\amsdk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\localhost -> localhost IE trusted site: HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\webcompanion.com -> hxxp://webcompanion.com ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-10-30 08:24 - 2016-12-22 23:22 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\ HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Peter\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img1.jpg DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Prompt) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == If an entry is included in the fixlist, it will be removed. HKLM\...\StartupApproved\Run32: => "CanonQuickMenu" HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\StartupApproved\Run: => "GarminExpressTrayApp" HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\StartupApproved\Run: => "MyDriveConnect.exe" HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\StartupApproved\Run: => "Discord" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [UDP Query User{28DA58B9-107A-4342-825F-4D28AF7C76CF}C:\users\peter\appdata\roaming\sky\sky go\sky go.exe] => (Allow) C:\users\peter\appdata\roaming\sky\sky go\sky go.exe (Sky UK Limited -> Sky UK) FirewallRules: [TCP Query User{FF9BEF22-89C1-46AE-91D7-A71F2A752534}C:\users\peter\appdata\roaming\sky\sky go\sky go.exe] => (Allow) C:\users\peter\appdata\roaming\sky\sky go\sky go.exe (Sky UK Limited -> Sky UK) FirewallRules: [{D010BD56-CD66-46B3-AD5B-F678E9F66749}] => (Allow) C:\Program Files (x86)\pCloud Drive\pCloud.exe (pCloud AG -> pCloud AG) FirewallRules: [{1CC6CB33-F9ED-4CB1-B95E-59A46053DEC9}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BFLauncher_x86.exe (Electronic Arts -> EA Digital Illusions CE AB) FirewallRules: [{B34D619C-6D4B-4DF8-827E-F34402A3ABF0}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BFLauncher_x86.exe (Electronic Arts -> EA Digital Illusions CE AB) FirewallRules: [{459C331C-7DF4-4715-A8F9-0E6C71C081F5}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BFLauncher.exe (Electronic Arts -> EA Digital Illusions CE AB) FirewallRules: [{B42230AE-69FB-4FBC-BEC8-4175A9B77802}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BFLauncher.exe (Electronic Arts -> EA Digital Illusions CE AB) FirewallRules: [UDP Query User{D901C1EA-1B3D-4891-87CE-5EDF48834091}C:\program files (x86)\origin games\battlefield 4\bf4.exe] => (Allow) C:\program files (x86)\origin games\battlefield 4\bf4.exe (Electronic Arts -> EA Digital Illusions CE AB) FirewallRules: [TCP Query User{20EC1DFA-5EC6-42F8-B980-E992D3286389}C:\program files (x86)\origin games\battlefield 4\bf4.exe] => (Allow) C:\program files (x86)\origin games\battlefield 4\bf4.exe (Electronic Arts -> EA Digital Illusions CE AB) FirewallRules: [UDP Query User{BEF63613-334D-450D-9CB2-EC4917105634}C:\users\peter\appdata\local\skypeplugin\pluginhost.exe] => (Allow) C:\users\peter\appdata\local\skypeplugin\pluginhost.exe (Microsoft Corporation -> Skype Technologies S.A.) FirewallRules: [TCP Query User{3BA07005-6AA1-4770-83E9-3BBEE9FB4096}C:\users\peter\appdata\local\skypeplugin\pluginhost.exe] => (Allow) C:\users\peter\appdata\local\skypeplugin\pluginhost.exe (Microsoft Corporation -> Skype Technologies S.A.) FirewallRules: [{15F1B4E1-4E51-4D0F-825B-3292AB54081F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe No File FirewallRules: [{32223D64-C931-48B9-AE0F-0CB840440FE7}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe No File FirewallRules: [{2BBAE440-284C-474B-97FE-9A2D3F2500BE}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe No File FirewallRules: [{083543A2-DF37-40D7-9DE9-A50E34A1992D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe No File FirewallRules: [UDP Query User{29F85D5A-ABE5-48E9-9365-6BB9C990C1B4}C:\program files (x86)\steam\steamapps\common\squad\squad\binaries\win64\squad.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\squad\squad\binaries\win64\squad.exe No File FirewallRules: [TCP Query User{357582B4-AB85-47E5-90EE-9675172B999A}C:\program files (x86)\steam\steamapps\common\squad\squad\binaries\win64\squad.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\squad\squad\binaries\win64\squad.exe No File FirewallRules: [UDP Query User{0C68D00C-B9BE-4917-B2B7-91E8103BC152}C:\program files (x86)\microsoft office\office12\groove.exe] => (Block) C:\program files (x86)\microsoft office\office12\groove.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [TCP Query User{08D18416-695C-4A09-B5DC-6E571C385E61}C:\program files (x86)\microsoft office\office12\groove.exe] => (Block) C:\program files (x86)\microsoft office\office12\groove.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [UDP Query User{A6D71720-C7BB-4857-AA32-C54A9C1805DA}C:\program files (x86)\mafia iii\mafia3.exe] => (Allow) C:\program files (x86)\mafia iii\mafia3.exe (2K Czech) [File not signed] FirewallRules: [TCP Query User{5E71B47C-69E3-4125-B9BD-F2DE4AADAB2B}C:\program files (x86)\mafia iii\mafia3.exe] => (Allow) C:\program files (x86)\mafia iii\mafia3.exe (2K Czech) [File not signed] FirewallRules: [UDP Query User{A7F4F472-69F2-463E-8F51-308211E7E98A}C:\program files (x86)\mafia iii\launcher.exe] => (Allow) C:\program files (x86)\mafia iii\launcher.exe (2K Games) [File not signed] FirewallRules: [TCP Query User{9D20E56A-7C64-48F0-B862-BC05B8C45B33}C:\program files (x86)\mafia iii\launcher.exe] => (Allow) C:\program files (x86)\mafia iii\launcher.exe (2K Games) [File not signed] FirewallRules: [{F613CC9E-526C-4888-869F-33AFE6FB1478}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File FirewallRules: [{A3C03B12-FC10-4435-904A-6B7ED850A426}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File FirewallRules: [{4D1ADD3A-3993-456B-AF7A-C32BC8333D41}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture 6\rtmpsrv.exe (Apowersoft Ltd -> ) FirewallRules: [{7A28407B-6648-4AC9-BB70-C17EEDA4993F}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture 6\rtmpsrv.exe (Apowersoft Ltd -> ) FirewallRules: [{D425ED22-E564-479D-85B9-29B791C92E51}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture 6\Video Download Capture 6.exe (Apowersoft Ltd -> Apowersoft) FirewallRules: [{2290E416-3B83-4D12-9F69-C0A8E05B2A0E}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture 6\Video Download Capture 6.exe (Apowersoft Ltd -> Apowersoft) FirewallRules: [{7C938066-335E-4FD7-ADC5-09308FAD4E04}] => (Allow) C:\Users\Peter\AppData\Local\Apowersoft\Online Video Downloader\Online Video Downloader.exe (Apowersoft Ltd -> Apowersoft) FirewallRules: [{BDC66059-10F4-40D1-A532-CF0A204D85A6}] => (Allow) C:\Users\Peter\AppData\Local\Apowersoft\Online Video Downloader\Online Video Downloader.exe (Apowersoft Ltd -> Apowersoft) FirewallRules: [{9518A486-2237-44FB-80E6-BDA7E1006019}] => (Allow) C:\Users\Peter\AppData\Local\Apowersoft\Apowersoft Online Launcher\Apowersoft Online Launcher.exe (Apowersoft Ltd -> Apowersoft) FirewallRules: [{2326C416-6308-44E8-88C5-632066056722}] => (Allow) C:\Users\Peter\AppData\Local\Apowersoft\Apowersoft Online Launcher\Apowersoft Online Launcher.exe (Apowersoft Ltd -> Apowersoft) FirewallRules: [UDP Query User{073B7D87-130F-435D-9E77-A564AAADC574}C:\program files (x86)\epic games\4.13\engine\binaries\win64\ue4editor.exe] => (Allow) C:\program files (x86)\epic games\4.13\engine\binaries\win64\ue4editor.exe (Epic Games Inc. -> Epic Games, Inc.) FirewallRules: [TCP Query User{2A0C94B7-F946-4B83-8C09-93D335DCE6F2}C:\program files (x86)\epic games\4.13\engine\binaries\win64\ue4editor.exe] => (Allow) C:\program files (x86)\epic games\4.13\engine\binaries\win64\ue4editor.exe (Epic Games Inc. -> Epic Games, Inc.) FirewallRules: [UDP Query User{1FA7AF85-8A31-464D-821A-11FD0258E22E}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.) FirewallRules: [TCP Query User{742B4A08-5632-4E62-801B-399D3F97B13D}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.) FirewallRules: [UDP Query User{E19B8A54-E21F-4B36-B4B1-8AEC0288585C}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.) FirewallRules: [TCP Query User{2AE4F5DF-63CE-4EE5-8F08-772B5FD40C47}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.) FirewallRules: [{3F2EF14E-9E44-40E0-9592-AFE0FAE28161}] => (Allow) C:\Games\World_of_Warships\worldofwarships.exe No File FirewallRules: [{8C52E1B6-B9ED-413E-9EFE-5583B9EA6D16}] => (Allow) C:\Games\World_of_Warships\worldofwarships.exe No File FirewallRules: [{96A944B1-1B10-4B0C-A590-A2619176B34F}] => (Allow) C:\Games\World_of_Warships\WoWSLauncher.exe No File FirewallRules: [{066EEFCA-F4EA-4146-9EAE-976D74E5C713}] => (Allow) C:\Games\World_of_Warships\WoWSLauncher.exe No File FirewallRules: [{B0A0C442-A8EA-4158-9751-70F727047571}] => (Allow) C:\Program Files\Newsbin\newsbinpro64.exe (DJI Interprises, LLC -> CMCEI) [File not signed] FirewallRules: [{17E3AAAE-1BBA-43D8-AB64-2964FC43F1F2}] => (Allow) C:\Program Files\Newsbin\newsbinpro64.exe (DJI Interprises, LLC -> CMCEI) [File not signed] FirewallRules: [{68E3ABB6-6E84-4739-B43D-EF09E3E53EBD}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe No File FirewallRules: [{909C6D02-5B51-4BFD-9853-F1D46E1444DB}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{C27D32C6-280B-4E48-BFBA-A97AAEA29C33}] => (Allow) C:\Program Files\Newsbin\newsbinpro64.exe (DJI Interprises, LLC -> CMCEI) [File not signed] FirewallRules: [{ABE75BF8-9BAF-4534-9A7B-FB658CC8812E}] => (Allow) C:\Program Files\Newsbin\newsbinpro64.exe (DJI Interprises, LLC -> CMCEI) [File not signed] FirewallRules: [{87BFEEC3-940E-4A01-B648-8EE0219E901D}] => (Allow) C:\Users\Peter\AppData\Roaming\uTorrent\uTorrent.exe No File FirewallRules: [{69899881-B894-4CF5-A4BA-106BFA17C6C3}] => (Allow) C:\Users\Peter\AppData\Roaming\uTorrent\uTorrent.exe No File FirewallRules: [{CB8E54A6-E85C-4626-8799-D78099176923}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe No File FirewallRules: [{0A39A901-C9EE-4990-88ED-B99454888082}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe No File FirewallRules: [{30933D81-4EA0-472C-B251-147E494ED8C1}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe No File FirewallRules: [{C3C4133C-A5B3-4B25-A938-4742BD5D4BBF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe No File FirewallRules: [{E1A77D00-BFBB-410B-B5F4-36DFEAF6A034}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe No File FirewallRules: [{97040820-ABF7-4ED0-A099-9A8C59895B01}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe No File FirewallRules: [{2E9378D3-8B41-4309-B9D5-E06AADFB6991}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe No File FirewallRules: [{55E0A659-8BE8-4AD4-850E-5403071CB3D5}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe (Even Balance, Inc. -> ) FirewallRules: [{D011CFD6-61CF-4E0C-935E-FC32CAC06197}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe (Even Balance, Inc. -> ) FirewallRules: [{599EFDAE-2C36-48DE-BB4D-56A64B1C3825}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe (Even Balance, Inc. -> ) FirewallRules: [{782961F5-0892-4854-BA07-FBFAD4FF012D}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe (Even Balance, Inc. -> ) FirewallRules: [{5CC3697F-22A4-40B6-BF84-3E62ECE13AD2}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe (Electronic Sports Network i Sverige AB -> ESN Social Software AB) FirewallRules: [{9C114559-9480-4E54-B843-2841A8958347}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe (Electronic Sports Network i Sverige AB -> ESN Social Software AB) FirewallRules: [{C8E615C6-FAA5-4303-BBEE-AF4B10796E25}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4WebHelper.exe (Electronic Arts -> EA Digital Illusions CE AB) FirewallRules: [{D18D6DD3-8E77-4A48-AF3B-0EC4FA2334F6}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4WebHelper.exe (Electronic Arts -> EA Digital Illusions CE AB) FirewallRules: [{1B8BA6FD-2272-4C17-ADFF-23FA97C32CC6}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4X86WebHelper.exe (Electronic Arts -> EA Digital Illusions CE AB) FirewallRules: [{0588C3DB-9AE7-46A6-97DA-2277DEE8DC9E}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4X86WebHelper.exe (Electronic Arts -> EA Digital Illusions CE AB) FirewallRules: [TCP Query User{E86BAA9A-AD5F-43D1-B34F-615C5080C6D1}C:\program files (x86)\origin games\battlefield 4\bf4.exe] => (Allow) C:\program files (x86)\origin games\battlefield 4\bf4.exe (Electronic Arts -> EA Digital Illusions CE AB) FirewallRules: [UDP Query User{870F63BC-908A-4A85-AEFE-42FF29643189}C:\program files (x86)\origin games\battlefield 4\bf4.exe] => (Allow) C:\program files (x86)\origin games\battlefield 4\bf4.exe (Electronic Arts -> EA Digital Illusions CE AB) FirewallRules: [{46FC59BE-8F46-48D1-8689-C05B95CBDC71}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation) FirewallRules: [{8759BAF8-31A5-475C-B7B0-2893395736AB}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation) FirewallRules: [{8DAD07C6-82DF-49DE-92EC-265CC90E3483}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe No File FirewallRules: [{0C478807-A659-48D4-9808-4DC7427E1430}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe No File FirewallRules: [{00534A32-2DF4-420B-B6C7-95ABE3556483}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Squad\squad_launcher.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd) FirewallRules: [{A8B5AC5C-E0D3-43BE-A296-1A1FFA240247}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Squad\squad_launcher.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd) FirewallRules: [TCP Query User{979149DF-441F-4A74-A400-E1F11B441156}C:\program files (x86)\steam\steamapps\common\squad\squad\binaries\win64\squad.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\squad\squad\binaries\win64\squad.exe No File FirewallRules: [UDP Query User{67BBC688-7774-4314-A5AF-68AFE57B234E}C:\program files (x86)\steam\steamapps\common\squad\squad\binaries\win64\squad.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\squad\squad\binaries\win64\squad.exe No File FirewallRules: [{95D0C50F-E36E-40ED-BE3F-967544647F7E}] => (Allow) D:\SteamLibrary\steamapps\common\Grand Theft Auto IV\GTAIV\LaunchGTAIV.exe (Sony DADC Austria AG -> Sony DADC Austria AG) [File not signed] FirewallRules: [{0A189D0A-A70F-4DC9-AC6F-DE7649B96B4A}] => (Allow) D:\SteamLibrary\steamapps\common\Grand Theft Auto IV\GTAIV\LaunchGTAIV.exe (Sony DADC Austria AG -> Sony DADC Austria AG) [File not signed] FirewallRules: [{62D8605A-8E5C-47D9-87A7-612835C95B88}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) FirewallRules: [{CF905B86-1DBE-4978-91CE-C8FC57B8B808}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) FirewallRules: [{1E19147F-9256-4C71-8CF1-54B45600D0DC}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe No File FirewallRules: [{EF28C03C-4196-4E82-9E0E-19BF5259233D}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe No File FirewallRules: [{637EDFE0-D2EC-44F4-9EED-891BA7E32CB4}] => (Allow) C:\Users\Peter\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) FirewallRules: [{8AD8D8BB-E97C-43D6-A658-B66C3ABF4B57}] => (Allow) C:\Users\Peter\AppData\Roaming\Zoom\bin\airhost.exe No File FirewallRules: [{468476CC-CA34-4DB6-B6A5-3210471D530B}] => (Allow) myportal.reedsrains.co.uk No File FirewallRules: [{118D388B-5EB6-498F-887B-7E2E4D827EC9}] => (Allow) myportal.reedsrains.co.uk No File FirewallRules: [{7E09D273-A3C0-4E44-A508-176789FB8842}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{5C18840E-6528-40BE-9804-4003FE30561D}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{A73A6825-3DA1-4682-A455-453342E88651}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [TCP Query User{B4AFE14B-B5B8-46C7-B3DB-3C8A0D0EADDA}C:\program files (x86)\steam\steamapps\common\squad\squadgame\binaries\win64\squadgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\squad\squadgame\binaries\win64\squadgame.exe (Offworld Industries -> Offworld Industries Ltd.) FirewallRules: [UDP Query User{62423C4C-5837-4569-BC04-0FFCD53E6C66}C:\program files (x86)\steam\steamapps\common\squad\squadgame\binaries\win64\squadgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\squad\squadgame\binaries\win64\squadgame.exe (Offworld Industries -> Offworld Industries Ltd.) FirewallRules: [{CECFF37F-8AA5-47B6-956D-40A1561BCB91}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) FirewallRules: [{31DED1F0-7923-4ED5-839D-ABBDA0C73695}] => (Allow) C:\Users\Peter\AppData\Local\Temp\HouseCall\tmase\nmap\nmap.exe No File ==================== Codecs (Whitelisted) ================== ==================== Restore Points ========================= 03-10-2019 20:45:14 Dr.Web Security Space installation ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (10/06/2019 03:02:55 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (19096,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (10/06/2019 02:00:52 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (16536,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (10/06/2019 01:51:41 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (18624,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (10/06/2019 01:43:47 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (9012,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (10/06/2019 12:56:06 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (8084,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (10/06/2019 12:32:37 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (12896,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (10/06/2019 12:22:12 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (21632,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (10/06/2019 12:09:54 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (2984,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. System errors: ============= Error: (10/06/2019 01:21:52 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-HUP2O0G) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Error: (10/06/2019 01:21:52 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-HUP2O0G) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Error: (10/06/2019 01:21:51 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-HUP2O0G) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Error: (10/06/2019 01:21:51 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-HUP2O0G) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Error: (10/06/2019 01:21:51 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-HUP2O0G) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Error: (10/06/2019 01:21:51 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-HUP2O0G) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Error: (10/06/2019 01:21:51 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-HUP2O0G) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Error: (10/06/2019 01:21:51 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-HUP2O0G) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Windows Defender: =================================== Date: 2019-10-06 14:53:58.634 Description: C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE has been blocked from modifying %userprofile%\Documents by Controlled Folder Access. Detection time: 2019-10-06T13:53:58.633Z Path: %userprofile%\Documents Process Name: C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE Security intelligence Version: 1.303.1004.0 Engine Version: 1.1.16400.2 Product Version: 4.18.1909.6 Date: 2019-10-06 13:31:25.791 Description: C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE has been blocked from modifying %userprofile%\Documents by Controlled Folder Access. Detection time: 2019-10-06T12:31:25.787Z Path: %userprofile%\Documents Process Name: C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE Security intelligence Version: 1.303.1004.0 Engine Version: 1.1.16400.2 Product Version: 4.18.1909.6 Date: 2019-10-06 10:42:35.886 Description: Controlled Folder Access blocked C:\Program Files (x86)\Zemana\AntiMalware\AntiMalware.exe from making changes to memory. Detection time: 2019-10-06T09:42:35.885Z Path: \Device\HarddiskVolume3 Process Name: C:\Program Files (x86)\Zemana\AntiMalware\AntiMalware.exe Security intelligence Version: 1.303.950.0 Engine Version: 1.1.16400.2 Product Version: 4.18.1909.6 Date: 2019-10-05 20:07:34.453 Description: C:\Program Files (x86)\Origin\Origin.exe has been blocked from modifying %userprofile%\Documents\Battlefield 4\settings\ by Controlled Folder Access. Detection time: 2019-10-05T19:07:34.452Z Path: %userprofile%\Documents\Battlefield 4\settings\ Process Name: C:\Program Files (x86)\Origin\Origin.exe Security intelligence Version: 1.303.950.0 Engine Version: 1.1.16400.2 Product Version: 4.18.1909.6 Date: 2019-10-05 18:45:17.825 Description: C:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exe has been blocked from modifying %userprofile%\Documents by Controlled Folder Access. Detection time: 2019-10-05T17:45:17.825Z Path: %userprofile%\Documents Process Name: C:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exe Security intelligence Version: 1.303.950.0 Engine Version: 1.1.16400.2 Product Version: 4.18.1909.6 Date: 2019-10-04 18:45:30.180 Description: Windows Defender Antivirus Real-Time Protection feature has encountered an error and failed. Feature: On Access Error Code: 0x8007043c Error description: This service cannot be started in Safe Mode Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem. Date: 2019-10-03 22:10:30.789 Description: Windows Defender Antivirus Real-Time Protection feature has encountered an error and failed. Feature: On Access Error Code: 0x8007043c Error description: This service cannot be started in Safe Mode Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem. Date: 2019-10-03 22:08:58.758 Description: Windows Defender Antivirus Real-Time Protection feature has encountered an error and failed. Feature: On Access Error Code: 0x8007043c Error description: This service cannot be started in Safe Mode Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem. Date: 2019-10-03 22:07:02.888 Description: Windows Defender Antivirus Real-Time Protection feature has encountered an error and failed. Feature: On Access Error Code: 0x8007043c Error description: This service cannot be started in Safe Mode Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem. Date: 2019-10-03 22:06:14.867 Description: Windows Defender Antivirus Real-Time Protection feature has encountered an error and failed. Feature: On Access Error Code: 0x8007043c Error description: This service cannot be started in Safe Mode Reason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem. CodeIntegrity: =================================== Date: 2019-10-06 11:16:46.974 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\cbfsNetRdr6.dll that did not meet the Microsoft signing level requirements. Date: 2019-10-06 11:16:46.935 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\cbfsMntNtf6.dll that did not meet the Microsoft signing level requirements. Date: 2019-10-06 11:16:46.911 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll that did not meet the Microsoft signing level requirements. Date: 2019-10-06 11:16:46.895 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll that did not meet the Microsoft signing level requirements. Date: 2019-10-06 11:16:46.827 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll that did not meet the Microsoft signing level requirements. Date: 2019-10-06 11:16:46.725 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll that did not meet the Microsoft signing level requirements. Date: 2019-10-06 11:16:46.624 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll that did not meet the Microsoft signing level requirements. Date: 2019-10-06 11:16:46.494 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll that did not meet the Microsoft signing level requirements. ==================== Memory info =========================== BIOS: American Megatrends Inc. 1002 09/27/2013 Motherboard: ASUSTeK COMPUTER INC. G10AC Processor: Intel(R) Core(TM) i5-4440S CPU @ 2.80GHz Percentage of memory in use: 75% Total physical RAM: 8099.13 MB Available physical RAM: 1964.4 MB Total Virtual: 16198.27 MB Available Virtual: 7628.87 MB ==================== Drives ================================ Drive 😄 () (Fixed) (Total:475.99 GB) (Free:16.67 GB) NTFS Drive d: (Hardy) (Fixed) (Total:1863 GB) (Free:1322.36 GB) NTFS Drive e: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0 GB) NTFS ==>[system with boot components (obtained from drive)] Drive f: () (Fixed) (Total:111.69 GB) (Free:11.61 GB) NTFS Drive g: () (Removable) (Total:57.87 GB) (Free:29.36 GB) FAT32 \\?\Volume{71ba5a6a-0000-0000-0000-100000000000}\ (System Reserved) (Fixed) (Total:0.49 GB) (Free:0.45 GB) NTFS \\?\Volume{71ba5a6a-0000-0000-0000-c01e77000000}\ () (Fixed) (Total:0.46 GB) (Free:0.04 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows XP) (Size: 1863 GB) (Disk ID: 70BA4F4B) Partition 2: (Active) - (Size=1863 GB) - (Type=05) ======================================================== Disk: 1 (MBR Code: Windows 7/8/10) (Size: 476.9 GB) (Disk ID: 71BA5A6A) Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=476 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=468 MB) - (Type=27) ======================================================== Disk: 2 (MBR Code: Windows 7/8/10) (Size: 111.8 GB) (Disk ID: 67EBA4D2) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=111.7 GB) - (Type=07 NTFS) ======================================================== Disk: 3 (Protective MBR) (Size: 57.9 GB) (Disk ID: 00000000) Partition: GPT. ==================== End of Addition.txt ============================
- 21 replies
-
- trojan:win32/coinminer
- trojan
-
(and 1 more)
Tagged with:
-
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06-10-2019 Ran by Peter (administrator) on DESKTOP-HUP2O0G (ASUSTeK COMPUTER INC. G10AC) (06-10-2019 14:59:10) Running from C:\Users\Peter\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\TempState\Downloads Loaded Profiles: Peter (Available Profiles: Peter) Platform: Windows 10 Home Version 1903 18362.388 (X64) Language: English (United States) Default browser: Edge Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) () [File not signed] C:\Program Files (x86)\CoolingTech_PC_Camera\monitorpad.exe (Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe (Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (Adobe Systems Incorporated -> ) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe (Adobe Systems, Incorporated -> Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\acrotray.exe (Corel Corporation -> WinZip Computing) C:\Program Files\WinZip\WzPreloader.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe (Dropbox, Inc -> The Qt Company Ltd.) C:\Program Files (x86)\Dropbox\Client\82.4.155\QtWebEngineProcess.exe (Dropbox, Inc -> The Qt Company Ltd.) C:\Program Files (x86)\Dropbox\Client\82.4.155\QtWebEngineProcess.exe (Dropbox, Inc -> The Qt Company Ltd.) C:\Program Files (x86)\Dropbox\Client\82.4.155\QtWebEngineProcess.exe (Electronic Arts, Inc. -> ) C:\Program Files (x86)\Origin\QtWebEngineProcess.exe (Electronic Arts, Inc. -> ) C:\Program Files (x86)\Origin\QtWebEngineProcess.exe (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe (Even Balance, Inc. -> ) C:\Windows\System32\PnkBstrA.exe (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries) C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe (Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler.exe (Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler64.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Hewlett-Packard Company -> Hewlett-Packard Company) C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe (Hewlett-Packard Company -> Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Hewlett-Packard Company) [File not signed] C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe (HP) [File not signed] C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (IBM -> IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportHelper.exe (IBM -> IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportHelper.exe (IBM -> IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe (IBM -> IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe (IBM -> IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportInjService_x64.exe (IBM -> IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportInjService_x64.exe (Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksde.exe (Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksdeui.exe (Macrovision Europe Ltd.) [File not signed] C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (McAfee, Inc. -> McAfee, LLC.) C:\Program Files\McAfee\TrueKey\McAfee.TrueKey.Service.exe (McAfee, Inc. -> McAfee, LLC.) C:\Program Files\McAfee\TrueKey\McAfee.TrueKey.ServiceHelper.exe (McAfee, Inc. -> McAfee, LLC.) C:\Program Files\McAfee\TrueKey\McTkSchedulerService.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE (Microsoft Corporation -> Microsoft Corporation) C:\Users\Peter\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12026.20218.0_x64__8wekyb3d8bbwe\HxOutlook.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12026.20218.0_x64__8wekyb3d8bbwe\HxTsr.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.19091.313.0_x64__8wekyb3d8bbwe\YourPhone.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19072.12011.0_x64__8wekyb3d8bbwe\Video.UI.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1909.6-0\MsMpEng.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1909.6-0\NisSrv.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Node.js Foundation -> Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (pCloud AG -> pCloud AG) C:\Program Files (x86)\pCloud Drive\pCloud.exe (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.52.138.0_x64__kzf8qxf38zg5c\SkypeApp.exe (Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.52.138.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe (Valve -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated -> Adobe Systems Incorporated) HKLM\...\Run: [Seagull Drivers] => ssdal_nc.exe startup HKLM\...\Run: [GLSystray] => C:\Program Files (x86)\CoolingTech_PC_Camera\monitorpad.exe [69632 2010-04-27] () [File not signed] HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2872400 2019-09-25] (Adobe Inc. -> Adobe Systems, Incorporated) HKLM\...\Run: [WinZip UN] => C:\Program Files\WinZip\WZUpdateNotifier.exe [2862032 2018-11-07] (Corel Corporation -> Corel Corporation) HKLM\...\Run: [WinZip PreLoader] => C:\Program Files\WinZip\WzPreloader.exe [130624 2018-11-07] (Corel Corporation -> WinZip Computing) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8783616 2015-12-11] (Realtek Semiconductor Corp -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407104 2015-12-11] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation -> Microsoft Corporation) HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe [620152 2006-10-22] (Adobe Systems, Incorporated -> Adobe Systems Inc.) HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [6210368 2019-10-02] (Dropbox, Inc -> Dropbox, Inc.) HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1298456 2015-04-20] (Canon Inc. -> CANON INC.) HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2404952 2017-03-27] (Adobe Systems Incorporated -> Adobe Systems Incorporated) HKLM-x32\...\Run: [StatusAlerts] => C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe [136760 2011-07-19] (Hewlett-Packard Company -> Hewlett-Packard Company) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard Company -> Hewlett-Packard) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [644552 2019-07-04] (Oracle America, Inc. -> Oracle Corporation) HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3115792 2019-09-04] (Electronic Arts, Inc. -> Electronic Arts) HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3211040 2019-10-02] (Valve -> Valve Corporation) HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1421736 2017-03-28] (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries) HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\Run: [MyDriveConnect.exe] => C:\Program Files (x86)\MyDrive Connect\TomTom MyDrive Connect.exe [1906088 2017-01-17] (TomTom International BV -> TomTom) HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\Run: [pCloud] => C:\Program Files (x86)\pCloud Drive\pCloud.exe [4367488 2019-03-08] (pCloud AG -> pCloud AG) HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\Run: [Discord] => C:\Users\Peter\AppData\Local\Discord\app-0.0.301\Discord.exe [57816920 2018-04-30] (Discord Inc. -> Discord Inc.) HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [83524968 2019-09-12] (Skype Software Sarl -> Skype Technologies S.A.) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\77.0.3865.90\Installer\chrmstp.exe [2019-09-19] (Google LLC -> Google LLC) HKLM\Software\...\Authentication\Credential Providers: [{B7724AE5-1135-4889-8A5F-CA98BE6CA1ED}] -> C:\Program Files\McAfee\TrueKey\McAfee.TrueKey.CredentialProvider.dll [2019-03-09] (McAfee, Inc. -> McAfee, LLC.) Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter "C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter" "C:\Program Files\McAfee\TrueKey\McAfeeTrueKeyPasswordFilter" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk [2017-08-09] ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) [File not signed] ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {05849D66-2E75-4499-82F2-284DB8D2DF1D} - System32\Tasks\WinZip Update Notifier 1 => C:\Program Files\WinZip\WZUpdateNotifier.exe [2862032 2018-11-07] (Corel Corporation -> Corel Corporation) Task: {06A75F97-B65A-49BA-A9C1-E10D357174D4} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe Task: {08FD9976-8EE3-406F-92E9-3BFF76C797E8} - System32\Tasks\WinZip Update Notifier 2 => C:\Program Files\WinZip\WZUpdateNotifier.exe [2862032 2018-11-07] (Corel Corporation -> Corel Corporation) Task: {10277736-AE02-49B1-BB8F-BADB0B12E211} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-09-10] (Adobe Inc. -> Adobe) Task: {125EFDFE-A23A-4B81-9E16-F4EACF47FE90} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\MpCmdRun.exe [468120 2019-10-02] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {19948146-575A-4B76-86AB-32A595C26CD3} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1236048 2019-07-24] (Adobe Inc. -> Adobe Systems) Task: {1CD324DB-D36C-47AE-A975-F254AC9B8DBF} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_255_Plugin.exe [1457720 2019-09-10] (Adobe Inc. -> Adobe) Task: {1EDC0A9E-95AA-4334-B0D1-C2AB7D34BA04} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\MpCmdRun.exe [468120 2019-10-02] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {33959C1E-7F1F-4AFD-AFEA-0C8044DCEC2B} - System32\Tasks\RunAsStdUser Task => C:\Program Files (x86)\inPixio\InPixio Photo Clip 8\LauncherIPC8.exe Task: {34FC9C36-72A1-412D-BCDB-6EE18D4109D7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440 2016-03-26] (Google Inc -> Google Inc.) Task: {4391AFA1-A2C9-45F2-9CF9-649F282817D5} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_255_pepper.exe [1453112 2019-09-10] (Adobe Inc. -> Adobe) Task: {54468D4E-850A-4994-B788-EF5DEA5FD0C0} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-04-07] (Dropbox, Inc -> Dropbox, Inc.) Task: {5617B0EF-5F62-461B-A47D-89E960F1845C} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2872400 2019-09-25] (Adobe Inc. -> Adobe Systems, Incorporated) Task: {64C683AD-24B4-4A09-89DC-E57F7149972F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\MpCmdRun.exe [468120 2019-10-02] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {6973513C-1A63-459F-BDA8-2612545EB0DF} - System32\Tasks\WinZip Update Notifier 3 => C:\Program Files\WinZip\WZUpdateNotifier.exe [2862032 2018-11-07] (Corel Corporation -> Corel Corporation) Task: {69C858B6-6AF8-483F-B310-A825204E050F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440 2016-03-26] (Google Inc -> Google Inc.) Task: {76380687-2779-46CF-8675-008E4D07131A} - System32\Tasks\DropboxUpdateTaskMachineCore1d3ef5534012f1d => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-04-07] (Dropbox, Inc -> Dropbox, Inc.) Task: {958FAD45-7A69-4510-BDD1-E04F1269F335} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION Task: {A0D2268D-7C16-4853-A03C-3CC3395E309B} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-04-07] (Dropbox, Inc -> Dropbox, Inc.) Task: {A86C25B5-2E80-448F-B452-0E1ECE82E378} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK Task: {ADFEA57E-EB3B-479C-B989-50C9AF765364} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [39848 2017-03-28] (Garmin International, Inc. -> ) Task: {B280111D-BBB0-41E7-A5E5-6B73C0A68FCA} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [1873288 2019-09-18] (AVAST Software s.r.o. -> AVAST Software) Task: {B86B1346-9C61-48CA-9BA1-AA7DAFE6C5EE} - System32\Tasks\HPLJCustParticipation => C:\Program Files (x86)\HP\HPLJUT\HPLJUTSCH.exe [42552 2011-05-03] (Hewlett-Packard Company -> Hewlett Packard) Task: {B97F97B6-A7D2-4AC0-ADFE-D507B699C39B} - System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-petertwilson1@live.com => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated -> Adobe Systems Incorporated) Task: {B9B523F7-1E64-456A-B056-837CFEE98163} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\MpCmdRun.exe [468120 2019-10-02] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {CD8067CA-458D-4A5D-9444-B5CDF7E94547} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe [4639280 2018-12-02] (McAfee, Inc. -> McAfee, Inc.) Task: {F0707A67-33DD-47CA-84FB-3B579ACA0B73} - System32\Tasks\HPCeeScheduleForPeter => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [97848 2016-01-22] (Hewlett-Packard Company -> Hewlett-Packard) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore1d3ef5534012f1d.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\HPCeeScheduleForPeter.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{3c0f1f20-0c45-49a7-9429-d74cf10ea0e9}: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{45576c16-4147-4887-8322-faced857d039}: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{60ad152e-8a43-4fd9-b6c3-37cf135a7346}: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{fd1c198c-98ca-4777-b9c0-6406155290d0}: [NameServer] 8.8.8.8,8.8.4.4 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com BHO: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\McAfee\TrueKey\MSIE\truekey_ie64.dll [2018-04-23] (McAfee, Inc. -> Intel Security) BHO-x32: Adobe PDF Reader Link Helper -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) BHO-x32: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\McAfee\TrueKey\MSIE\truekey_ie.dll [2018-04-23] (McAfee, Inc. -> Intel Security) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_221\bin\ssv.dll [2019-10-03] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2006-10-22] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_221\bin\jp2ssv.dll [2019-10-03] (Oracle America, Inc. -> Oracle Corporation) Toolbar: HKLM - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\McAfee\TrueKey\MSIE\truekey_ie64.dll [2018-04-23] (McAfee, Inc. -> Intel Security) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2006-10-22] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) Toolbar: HKLM-x32 - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\McAfee\TrueKey\MSIE\truekey_ie.dll [2018-04-23] (McAfee, Inc. -> Intel Security) Toolbar: HKU\S-1-5-21-2643124959-2563984870-1026749049-1001 -> No Name - {C500C267-63BF-451F-8797-4D720C9A2ED9} - No File Edge: ====== DownloadDir: C:\Users\Peter\Downloads FireFox: ======== FF DefaultProfile: ba38mmpk.default-1475343481844 FF ProfilePath: C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\ba38mmpk.default-1475343481844 [2019-10-06] FF NewTabOverride: Mozilla\Firefox\Profiles\ba38mmpk.default-1475343481844 -> Disabled: {ae170991-a8c8-4caf-b6cc-a3cc994abe83} FF Extension: (IBM Security Rapport) - C:\Users\Peter\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\rapportext@trusteer.com (1).xpi [2018-04-11] [UpdateUrl:hxxps://clients2.google.com/service/update2/crx] FF Extension: (IBM Security Rapport) - C:\Users\Peter\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\rapportext@trusteer.com.xpi [2019-01-22] [UpdateUrl:hxxps://clients2.google.com/service/update2/crx] FF Extension: (Grammarly for Firefox) - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\ba38mmpk.default-1475343481844\Extensions\87677a2c52b84ad3a151a4a72f5bd3c4@jetpack.xpi [2019-06-15] FF Extension: (Autofill Forms) - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\ba38mmpk.default-1475343481844\Extensions\autofillForms@blueimp.net.xpi [2017-05-04] [Legacy] FF Extension: (AdBlock) - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\ba38mmpk.default-1475343481844\Extensions\jid1-NIfFY2CA8fy1tg@jetpack.xpi [2019-10-04] FF Extension: (Strict Pop-up Blocker) - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\ba38mmpk.default-1475343481844\Extensions\jid1-P34HaABBBpOerQ@jetpack.xpi [2019-08-29] FF Extension: (Popup Blocker Ultimate) - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\ba38mmpk.default-1475343481844\Extensions\{60B7679C-BED9-11E5-998D-8526BB8E7F8B}.xpi [2019-06-29] FF SearchPlugin: C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\ba38mmpk.default-1475343481844\searchplugins\bing-lavasoft.xml [2017-04-23] FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_255.dll [2019-09-10] (Adobe Inc. -> ) FF Plugin: @videolan.org/vlc,version=3.0.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2017-03-27] (Adobe Systems Incorporated -> Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_255.dll [2019-09-10] (Adobe Inc. -> ) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (Electronic Sports Network i Sverige AB -> ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB) [File not signed] FF Plugin-x32: @java.com/DTPlugin,version=11.221.2 -> C:\Program Files (x86)\Java\jre1.8.0_221\bin\dtplugin\npDeployJava1.dll [2019-10-03] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.221.2 -> C:\Program Files (x86)\Java\jre1.8.0_221\bin\plugin2\npjp2.dll [2019-10-03] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2017-03-27] (Adobe Systems Incorporated -> Adobe Systems) FF Plugin HKU\S-1-5-21-2643124959-2563984870-1026749049-1001: @zoom.us/ZoomVideoPlugin -> C:\Users\Peter\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2018-12-21] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) FF Plugin HKU\S-1-5-21-2643124959-2563984870-1026749049-1001: SkypePlugin -> C:\Users\Peter\AppData\Local\SkypePlugin\7.32.6.278\npGatewayNpapi.dll [2017-04-18] (Microsoft Corporation -> Skype Technologies S.A.) FF Plugin HKU\S-1-5-21-2643124959-2563984870-1026749049-1001: SkypePlugin64 -> C:\Users\Peter\AppData\Local\SkypePlugin\7.32.6.278\npGatewayNpapi-x64.dll [2017-04-18] (Microsoft Corporation -> Skype Technologies S.A.) Chrome: ======= CHR DefaultProfile: Default CHR HomePage: Default -> hxxp://www.google.com CHR Profile: C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default [2019-10-06] CHR Extension: (Slides) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-01-16] CHR Extension: (Docs) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-16] CHR Extension: (Google Drive) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-17] CHR Extension: (IBM Security Rapport) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjllphbppobebmjpjcijfbakobcheof [2019-08-15] CHR Extension: (YouTube) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-03-26] CHR Extension: (Dropbox for Gmail) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpdmhfocilnekecfjgimjdeckachfbec [2019-02-08] CHR Extension: (Sheets) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-16] CHR Extension: (Google Docs Offline) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-15] CHR Extension: (Grammarly for Chrome) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2019-09-24] CHR Extension: (Skype) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2018-01-16] CHR Extension: (Chrome Web Store Payments) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-01] CHR Extension: (Downloader for Instagram™ + Direct Message) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\olkpikmlhoaojbbmmpejnimiglejmboe [2019-09-18] CHR Extension: (Gmail) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-23] CHR Extension: (Chrome Media Router) - C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-09-20] CHR HKU\S-1-5-21-2643124959-2563984870-1026749049-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bbjllphbppobebmjpjcijfbakobcheof] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [771672 2017-03-14] (Adobe Systems Incorporated -> Adobe Systems Incorporated) R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3147344 2019-09-25] (Adobe Inc. -> Adobe Systems, Incorporated) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2914896 2019-09-25] (Adobe Inc. -> Adobe Systems, Incorporated) S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-04-07] (Dropbox, Inc -> Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-04-07] (Dropbox, Inc -> Dropbox, Inc.) R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [51024 2019-10-02] (Dropbox, Inc -> Dropbox, Inc.) S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [229648 2016-09-08] (EasyAntiCheat Oy -> EasyAntiCheat Ltd) R3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2016-04-04] (Macrovision Europe Ltd.) [File not signed] R2 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [1099280 2017-03-28] (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries) R2 HP DS Service; C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe [13824 2010-10-27] (Hewlett-Packard Company) [File not signed] R2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [162816 2011-07-08] (HP) [File not signed] R2 KSDE3.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksde.exe [617016 2018-03-01] (Kaspersky Lab -> AO Kaspersky Lab) S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed] S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2347824 2019-09-04] (Electronic Arts, Inc. -> Electronic Arts) R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3222320 2019-09-04] (Electronic Arts, Inc. -> Electronic Arts) S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed] R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2016-07-22] (Even Balance, Inc. -> ) R2 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [5274560 2019-04-15] (IBM -> IBM Corp.) R2 TrueKey; C:\Program Files\McAfee\TrueKey\McAfee.TrueKey.Service.exe [421432 2019-03-09] (McAfee, Inc. -> McAfee, LLC.) R2 TrueKeyScheduler; C:\Program Files\McAfee\TrueKey\McTkSchedulerService.exe [421432 2019-03-09] (McAfee, Inc. -> McAfee, LLC.) R2 TrueKeyServiceHelper; C:\Program Files\McAfee\TrueKey\McAfee.TrueKey.ServiceHelper.exe [194168 2019-03-09] (McAfee, Inc. -> McAfee, LLC.) S2 UtilitiesService; C:\Program Files\Utilities\UtilitiesService.exe [374272 2018-02-15] () [File not signed] R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\NisSrv.exe [3004048 2019-10-02] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\MsMpEng.exe [103384 2019-10-02] (Microsoft Windows Publisher -> Microsoft Corporation) S3 MBAMService; "C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe" [X] R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000 ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.) R1 cbfs6; C:\WINDOWS\system32\drivers\cbfs6.sys [460992 2016-09-09] (EldoS Corporation -> /n software, Inc.) R3 kltap; C:\WINDOWS\System32\drivers\kltap.sys [48080 2018-02-12] (AnchorFree Inc -> The OpenVPN Project) S3 ManyCam; C:\WINDOWS\system32\DRIVERS\mcvidrv.sys [58792 2017-03-05] (ManyCam (VISICOM MÉDIA INC.) -> Visicom Media Inc.) S3 mcaudrv_simple; C:\WINDOWS\system32\drivers\mcaudrv_x64.sys [35960 2014-12-29] (ManyCam -> Visicom Media Inc.) R2 npf; C:\WINDOWS\system32\drivers\npf.sys [36600 2015-08-21] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.) R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_830a0263f2ee97ce\nvlddmkm.sys [22370696 2019-09-06] (NVIDIA Corporation -> NVIDIA Corporation) S1 RapportAegle64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportAegle64.sys [503000 2019-04-15] (IBM -> IBM Corp.) S1 RapportCerberus_1930415; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1930415.sys [1659544 2019-06-12] (IBM -> IBM Corp.) S1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [727000 2019-04-15] (IBM -> IBM Corp.) S0 RapportHades64; C:\WINDOWS\System32\Drivers\RapportHades64.sys [463408 2019-04-15] (IBM -> IBM Corp.) S0 RapportKE64; C:\WINDOWS\System32\Drivers\RapportKE64.sys [610648 2019-04-15] (IBM -> IBM Corp.) S1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [766616 2019-04-15] (IBM -> IBM Corp.) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [662528 2019-03-19] (Microsoft Windows -> Realtek ) R3 rtux64w10; C:\WINDOWS\System32\drivers\rtux64w10.sys [411648 2019-03-19] (Microsoft Windows -> Realtek Corporation ) R3 vpnpbus; C:\WINDOWS\System32\drivers\vpnpbus.sys [18624 2016-09-09] (EldoS Corporation -> /n software, Inc.) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46688 2019-10-02] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [350136 2019-10-02] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54200 2019-10-02] (Microsoft Windows -> Microsoft Corporation) S3 AIDA64Driver; \??\C:\Program Files (x86)\FinalWire\AIDA64 Extreme\kerneld.x64 [X] S1 amsdk; \??\C:\WINDOWS\system32\drivers\amsdk.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-10-06 14:53 - 2019-10-06 14:53 - 000000000 ___HD C:\OneDriveTemp 2019-10-06 11:55 - 2019-10-06 11:55 - 000203423 _____ C:\Users\Peter\Downloads\Transactions--980360-10465943--6-04-2019-6-09-2019.pdf 2019-10-05 20:14 - 2019-10-05 20:14 - 000123453 _____ C:\Users\Peter\Downloads\Bering.Sea.Gold.S11E03.1080p.HEVC.x265-MeGusta.nzb 2019-10-05 18:30 - 2019-10-05 18:30 - 000000000 ____D C:\Battlefield 4 2019-10-04 21:29 - 2019-10-04 21:29 - 000000000 ____D C:\Users\Peter\AppData\Local\Aiseesoft Studio 2019-10-04 21:28 - 2019-10-04 21:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aiseesoft 2019-10-04 21:28 - 2019-10-04 21:28 - 000000000 ____D C:\ProgramData\Aiseesoft Studio 2019-10-04 21:28 - 2019-10-04 21:28 - 000000000 ____D C:\Program Files (x86)\Aiseesoft Studio 2019-10-04 21:27 - 2019-10-04 21:27 - 011362440 _____ (Aiseesoft Studio ) C:\Users\Peter\Downloads\data-recovery.exe 2019-10-04 20:33 - 2019-10-06 14:59 - 000000000 ____D C:\FRST 2019-10-04 20:14 - 2019-10-06 10:47 - 001743536 _____ C:\WINDOWS\ZAM.krnl.trace 2019-10-04 20:14 - 2019-10-06 10:47 - 000000000 ____D C:\Users\Peter\AppData\Local\AMSDK 2019-10-04 20:14 - 2019-10-04 20:14 - 000000000 ____D C:\Users\Peter\AppData\Local\Zemana 2019-10-04 20:13 - 2019-10-04 20:14 - 012668536 _____ (Zemana Ltd. ) C:\Users\Peter\Downloads\AntiMalware_Setup(1).exe 2019-10-04 20:13 - 2019-10-04 20:13 - 012668536 _____ (Zemana Ltd. ) C:\Users\Peter\Downloads\AntiMalware_Setup.exe 2019-10-04 20:08 - 2019-10-04 20:12 - 000000000 ____D C:\ProgramData\HitmanPro 2019-10-04 20:08 - 2019-10-04 20:09 - 011539456 _____ (SurfRight B.V.) C:\Users\Peter\Downloads\HitmanPro_x64.exe 2019-10-04 19:18 - 2019-10-04 19:18 - 000001965 _____ C:\Users\Peter\Desktop\Process Hacker 2.lnk 2019-10-04 19:17 - 2019-10-04 19:17 - 002267848 _____ (wj32 ) C:\Users\Peter\Downloads\processhacker-2.39-setup (1).exe 2019-10-04 17:16 - 2019-10-04 17:16 - 001352267 _____ C:\Users\Peter\AppData\Local\census.cache 2019-10-04 17:14 - 2019-10-04 17:14 - 000474205 _____ C:\Users\Peter\AppData\Local\ars.cache 2019-10-04 16:52 - 2019-10-04 16:52 - 000000010 _____ C:\Users\Peter\AppData\Local\sponge.last.runtime.cache 2019-10-04 16:47 - 2019-10-04 16:47 - 000000000 ____D C:\WINDOWS\Trend Micro 2019-10-04 16:47 - 2019-10-04 16:47 - 000000000 ____D C:\ProgramData\Trend Micro 2019-10-04 16:46 - 2019-10-04 16:46 - 000000036 _____ C:\Users\Peter\AppData\Local\housecall.guid.cache 2019-10-04 16:45 - 2019-10-04 16:45 - 002527376 _____ (Trend Micro Inc.) C:\Users\Peter\Downloads\HousecallLauncher64.exe 2019-10-04 16:00 - 2019-10-04 16:00 - 006946736 _____ (EnigmaSoft Limited) C:\Users\Peter\Downloads\SpyHunter-Installer.exe 2019-10-04 15:35 - 2019-10-04 15:35 - 000000000 ____D C:\ProgramData\SecuritySuite 2019-10-04 15:33 - 2019-10-04 15:33 - 014584656 _____ C:\Users\Peter\Downloads\TotalAV_Setup.exe 2019-10-04 15:03 - 2019-10-04 15:04 - 066748536 _____ (Malwarebytes ) C:\Users\Peter\Downloads\mb3-setup-consumer-3.8.3.2965-1.0.627-1.0.12751.exe 2019-10-04 01:49 - 2019-10-04 08:29 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox 2019-10-04 01:11 - 2019-10-04 01:11 - 025900544 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 025443840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 022627328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 019849728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 019810816 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 018019840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 014816256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 007195648 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 006518736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 006232064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 006084048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 005865272 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizimg.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 005764872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 005105152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 004481536 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 004129624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 003964056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 003742032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 002821120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 002799616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2019-10-04 01:11 - 2019-10-04 01:11 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2019-10-04 01:11 - 2019-10-04 01:11 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 2019-10-04 01:11 - 2019-10-04 01:11 - 002258856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 002132280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 002095104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001957008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001913296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001788728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001726976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001692160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001664376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001616784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001610752 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001563648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001510752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001505320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001473488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001394488 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 001334064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ttdrecordcpu.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001319936 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001297936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001263616 _____ (Microsoft Corporation) C:\WINDOWS\system32\opengl32.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001244944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001218144 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 001178816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001154656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001098712 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001080320 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001072952 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 001054872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 001047968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000939008 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000904704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\opengl32.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000893952 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000875008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000843776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000792296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputHost.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000784384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000783480 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000775768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000774456 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000772656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000742912 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000722944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapi.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000701952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.FileExplorer.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000691712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000673080 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000652800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000629248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.Search.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000623104 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000599040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000568336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000546816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxdiagn.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000541696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResourceMapper.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000539648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9on12.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000510464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000507704 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizeng.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000507152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000501232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp_win.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000500736 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2019-10-04 01:11 - 2019-10-04 01:11 - 000487576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000487424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.FileExplorer.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\SessEnv.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000463360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000463272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxdiagn.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000450360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11on12.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000421376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2019-10-04 01:11 - 2019-10-04 01:11 - 000417280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SessEnv.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000387832 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000383984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MMDevAPI.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000381240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000379840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ws2_32.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000375720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000369664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxdiag.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000346624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\secproc.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapibase.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\VAN.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys 2019-10-04 01:11 - 2019-10-04 01:11 - 000315392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxdiag.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000300392 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000285256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000283688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ttdwriter.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000279040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000278080 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000245248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\glu32.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000236520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cfgmgr32.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000210744 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000176440 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxlib.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\glu32.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000158208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys 2019-10-04 01:11 - 2019-10-04 01:11 - 000157184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ComposableShellProxyStub.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SpatialAudioLicenseSrv.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000143808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imm32.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sud.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000139264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prntvpt.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000137864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devobj.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000125232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KerbClientShared.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000116904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\userenv.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000110080 _____ C:\WINDOWS\system32\ResBParser.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000105832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000100664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmcl.sys 2019-10-04 01:11 - 2019-10-04 01:11 - 000093712 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EaseOfAccessDialog.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000089544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000084496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys 2019-10-04 01:11 - 2019-10-04 01:11 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvvmtransport.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcbuilder.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sethc.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000073024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000066832 _____ (Microsoft Corporation) C:\WINDOWS\system32\iumcrypt.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvvmtransport.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000056832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devrtl.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeUISrv.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnrollCtrl.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AssignedAccessRuntime.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enrollmentapi.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe 2019-10-04 01:11 - 2019-10-04 01:11 - 000033056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NtlmShared.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000021544 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000016696 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizres.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d8thk.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000011576 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxlibres.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCertResources.dll 2019-10-04 01:11 - 2019-10-04 01:11 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin 2019-10-04 01:11 - 2019-10-04 01:11 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin 2019-10-04 01:11 - 2019-10-04 01:11 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin 2019-10-04 01:11 - 2019-10-04 01:11 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin 2019-10-04 01:11 - 2019-10-04 01:11 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin 2019-10-04 01:11 - 2019-10-04 01:11 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin 2019-10-04 01:11 - 2019-10-04 01:11 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin 2019-10-04 01:11 - 2019-10-04 01:11 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin 2019-10-04 01:11 - 2019-10-04 01:11 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin 2019-10-04 01:11 - 2019-10-04 01:11 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin 2019-10-04 01:11 - 2019-10-04 01:11 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin 2019-10-04 01:11 - 2019-10-04 01:11 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin 2019-10-04 01:10 - 2019-10-04 01:10 - 017787392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 009928720 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 007905000 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 007848192 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 007600664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 007263992 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 006425600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 006227624 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 006164480 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 004612520 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 004562688 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 004046336 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 004012544 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 003727360 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 003701248 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 003590968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 003553280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 003386880 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 003184128 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 003105280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 002772032 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 002762296 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 002723328 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 002703872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 002590208 _____ C:\WINDOWS\system32\dwmscene.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 002552120 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 002466304 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 002449920 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 002284544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 002160640 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 002120704 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 002120272 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 002082192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 002069504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001999960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001942528 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001940952 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001857024 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001845408 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001835008 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001819136 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShell.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001757096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2019-10-04 01:10 - 2019-10-04 01:10 - 001748480 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001743680 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001657856 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001616608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ttdrecordcpu.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001607680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001543168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001512320 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 001482040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 001439744 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 001413704 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001412096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001383856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001372160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001366128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2019-10-04 01:10 - 2019-10-04 01:10 - 001261800 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001182240 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 001150240 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputHost.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001149416 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 001091584 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001065984 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001036800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001029432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 001023128 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 001009152 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000984376 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000975872 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000944664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000931840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000889960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000874296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000858112 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000839680 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9on12.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000833312 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000759488 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.Search.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000749568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000732176 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000674072 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000656960 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11on12.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000639400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp_win.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000617784 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000612864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000606208 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000598016 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000589384 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_PCDisplay.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000558592 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000551952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Vid.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000551936 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000551424 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000541480 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000534016 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000520192 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000518656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000512000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000462136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000457216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000456720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000449888 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMDevAPI.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000448000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000442704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ws2_32.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000441144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000436024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000415808 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000398728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000382976 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000363624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\MbbCx.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000355000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000342896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ttdwriter.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000334936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ComposableShellProxyStub.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000315904 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000293344 _____ (Microsoft Corporation) C:\WINDOWS\system32\cfgmgr32.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\directxdatabaseupdater.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000284160 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_CapabilityAccess.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3svc.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnservice.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\ManageCI.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000244736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndproxy.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Gpu.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000223032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelppm.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgiadaptercache.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000208184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\processr.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000201016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdppm.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000199480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdk8.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000179512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\prntvpt.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000176152 _____ (Microsoft Corporation) C:\WINDOWS\system32\imm32.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000173568 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvinst.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwbase.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000159112 _____ (Microsoft Corporation) C:\WINDOWS\system32\devobj.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000155648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_AppExecutionAlias.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000152408 _____ (Microsoft Corporation) C:\WINDOWS\system32\KerbClientShared.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000151568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbus.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_BackgroundApps.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000140496 _____ (Microsoft Corporation) C:\WINDOWS\system32\userenv.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmredir.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000132608 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_ForceSync.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000132408 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000132096 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinAUG.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000127064 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationControlCSP.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000119840 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000117048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\EaseOfAccessDialog.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShellExtFramework.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000105272 _____ (Microsoft Corporation) C:\WINDOWS\system32\icfupgd.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3msm.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000098816 _____ (Microsoft Corporation) C:\WINDOWS\system32\sethc.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000092624 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskhostw.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3api.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000088352 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000079376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\uaspstor.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwm.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnrollCtrl.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidspi.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AssignedAccessRuntime.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\devrtl.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\audioresourceregistrar.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnppolicy.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000053248 _____ C:\WINDOWS\system32\Drivers\UsbPmApi.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000052752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmstorfl.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringconfigsp.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000047616 _____ C:\WINDOWS\system32\UsbPmApi.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000047000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\cellulardatacapabilityhandler.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000043536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storvsc.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiredNetworkCSP.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000039304 _____ (Microsoft Corporation) C:\WINDOWS\system32\NtlmShared.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\IcsEntitlementHost.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000028936 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmbuspipe.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndistapi.sys 2019-10-04 01:10 - 2019-10-04 01:10 - 000027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32_DeviceGuard.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfapigp.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\CSystemEventsBrokerClient.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000020944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmsgapi.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\bindflt.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d8thk.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\pacjsworker.exe 2019-10-04 01:10 - 2019-10-04 01:10 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCertResources.dll 2019-10-04 01:10 - 2019-10-04 01:10 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tier2punctuations.dll 2019-10-04 00:25 - 2019-09-24 04:52 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe 2019-10-04 00:25 - 2019-09-24 04:49 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe 2019-10-03 21:55 - 2019-10-03 21:55 - 000000000 ____D C:\WINDOWS\pss 2019-10-03 21:29 - 2019-10-04 18:46 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job 2019-10-03 21:29 - 2019-10-03 21:29 - 000107348 _____ C:\WINDOWS\ntbtlog.txt 2019-10-03 20:59 - 2019-10-03 21:04 - 000000000 __SHD C:\DrWeb Quarantine 2019-10-03 20:48 - 2019-10-03 20:48 - 000000000 ____D C:\Users\Peter\Doctor Web 2019-10-03 20:47 - 2019-10-03 20:47 - 000000000 ____D C:\Users\Peter\AppData\Roaming\Process Hacker 2 2019-10-03 20:46 - 2019-10-03 21:53 - 000000000 ____D C:\WINDOWS\system32\Tasks\Doctor Web 2019-10-03 20:44 - 2019-10-03 21:54 - 000000000 ____D C:\ProgramData\Doctor Web 2019-10-03 20:41 - 2019-10-03 20:44 - 543043536 _____ (Doctor Web, Ltd.) C:\Users\Peter\Downloads\drweb-12.0-ss-win.exe 2019-10-03 20:38 - 2019-10-03 20:38 - 019950348 _____ C:\Users\Peter\Downloads\drweb-12.4.2-ss-android.apk 2019-10-03 20:37 - 2019-10-04 19:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Process Hacker 2 2019-10-03 20:37 - 2019-10-04 19:18 - 000000000 ____D C:\Program Files\Process Hacker 2 2019-10-03 20:36 - 2019-10-03 20:36 - 002267848 _____ (wj32 ) C:\Users\Peter\Downloads\processhacker-2.39-setup.exe 2019-10-03 20:31 - 2019-10-03 20:31 - 047532112 _____ (FinalWire Ltd. ) C:\Users\Peter\Downloads\aida64extreme610.exe 2019-10-03 20:08 - 2019-10-03 20:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2019-10-03 20:06 - 2019-10-04 13:33 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData 2019-10-03 20:06 - 2019-10-04 13:33 - 000000000 ___HD C:\ProgramData\Documents\AdobeGCData 2019-10-03 20:06 - 2019-10-03 20:06 - 000003518 _____ C:\WINDOWS\system32\Tasks\AdobeGCInvoker-1.0 2019-10-03 19:24 - 2019-10-03 19:24 - 002065880 _____ (Oracle Corporation) C:\Users\Peter\Downloads\JavaSetup8u221.exe 2019-10-03 07:47 - 2019-10-05 11:39 - 097255424 _____ C:\WINDOWS\system32\config\SOFTWARE 2019-10-02 22:13 - 2019-10-02 22:13 - 000000000 ____D C:\Program Files\Malwarebytes 2019-10-02 21:23 - 2019-10-04 18:51 - 000000000 ____D C:\ProgramData\Malwarebytes 2019-10-02 21:22 - 2019-10-02 21:22 - 066722736 _____ (Malwarebytes ) C:\Users\Peter\Downloads\mb3-setup-consumer-3.8.3.2965-1.0.627-1.0.12735.exe 2019-10-02 13:14 - 2019-10-02 13:14 - 000051024 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe 2019-10-02 13:14 - 2019-10-02 13:14 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys 2019-10-02 13:14 - 2019-10-02 13:14 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys 2019-10-02 13:14 - 2019-10-02 13:14 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys 2019-10-02 10:35 - 2019-10-02 10:35 - 000000747 _____ C:\Users\Peter\Downloads\report (2).csv 2019-09-28 19:55 - 2019-09-28 19:55 - 000146870 _____ C:\Users\Peter\Downloads\Mister.Academy.2018.WEBRip.x264-ION10.nzb 2019-09-28 16:34 - 2019-09-28 16:34 - 000053805 _____ C:\Users\Peter\Downloads\bering.sea.gold.s11e02.unleash.the.beast.hdtv.x264-w4f.nzb 2019-09-27 17:47 - 2019-09-27 17:47 - 000000000 ___HD C:\$Windows.~WS 2019-09-27 17:47 - 2019-09-27 17:47 - 000000000 ____D C:\$WINDOWS.~BT 2019-09-20 21:04 - 2019-09-06 19:29 - 001012432 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll 2019-09-20 21:04 - 2019-09-06 19:29 - 001012432 _____ C:\WINDOWS\system32\vulkan-1.dll 2019-09-20 21:04 - 2019-09-06 19:29 - 000876240 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll 2019-09-20 21:04 - 2019-09-06 19:29 - 000876240 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll 2019-09-20 21:04 - 2019-09-06 19:29 - 000447368 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll 2019-09-20 21:04 - 2019-09-06 19:29 - 000351944 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll 2019-09-20 21:04 - 2019-09-06 19:29 - 000301264 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe 2019-09-20 21:04 - 2019-09-06 19:29 - 000301264 _____ C:\WINDOWS\system32\vulkaninfo.exe 2019-09-20 21:04 - 2019-09-06 19:29 - 000273104 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe 2019-09-20 21:04 - 2019-09-06 19:29 - 000273104 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe 2019-09-20 21:04 - 2019-09-06 19:28 - 011562376 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll 2019-09-20 21:04 - 2019-09-06 19:28 - 009937104 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll 2019-09-20 21:04 - 2019-09-06 19:27 - 002051008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll 2019-09-20 21:04 - 2019-09-06 19:27 - 001550080 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll 2019-09-20 21:04 - 2019-09-06 19:27 - 001477512 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll 2019-09-20 21:04 - 2019-09-06 19:27 - 001247432 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll 2019-09-20 21:04 - 2019-09-06 19:27 - 001140616 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll 2019-09-20 21:04 - 2019-09-06 19:27 - 000959424 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll 2019-09-20 21:04 - 2019-09-06 19:27 - 000812800 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll 2019-09-20 21:04 - 2019-09-06 19:27 - 000676096 _____ C:\WINDOWS\system32\nvofapi64.dll 2019-09-20 21:04 - 2019-09-06 19:27 - 000658880 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll 2019-09-20 21:04 - 2019-09-06 19:27 - 000632768 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll 2019-09-20 21:04 - 2019-09-06 19:27 - 000544648 _____ C:\WINDOWS\SysWOW64\nvofapi.dll 2019-09-20 21:04 - 2019-09-06 19:27 - 000524168 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll 2019-09-20 21:04 - 2019-09-06 19:26 - 040444856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll 2019-09-20 21:04 - 2019-09-06 19:26 - 035334536 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll 2019-09-20 21:04 - 2019-09-06 19:26 - 017300360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll 2019-09-20 21:04 - 2019-09-06 19:26 - 014921096 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll 2019-09-20 21:04 - 2019-09-06 19:26 - 005358472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll 2019-09-20 21:04 - 2019-09-06 19:26 - 004696968 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll 2019-09-20 21:04 - 2019-09-06 19:26 - 001726400 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6443630.dll 2019-09-20 21:04 - 2019-09-06 19:26 - 001491336 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6443630.dll 2019-09-20 21:04 - 2019-09-06 16:24 - 004263840 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll 2019-09-20 21:04 - 2019-09-05 22:19 - 000047272 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll 2019-09-20 20:52 - 2019-09-20 20:52 - 000000000 ____D C:\Users\Peter\AppData\Local\SquadGame 2019-09-20 15:45 - 2019-09-20 15:46 - 000053872 _____ C:\Users\Peter\Downloads\bering.sea.gold.s10e01.enter.a.titan.hdtv.x264-w4f.nzb 2019-09-20 14:30 - 2019-09-20 14:30 - 000059603 _____ C:\Users\Peter\Downloads\Bering.Sea.Gold.S11E00.Ready.Set.Gold.720p.HEVC.x265-MeGusta.nzb 2019-09-19 21:09 - 2019-09-19 21:09 - 013290562 _____ C:\Users\Peter\Documents\AVA 2019 - Christmas Menu.pdf 2019-09-19 18:39 - 2019-09-19 18:39 - 000111914 _____ C:\Users\Peter\Downloads\Bering.Sea.Gold.S11E01.1080p.HEVC.x265-MeGusta.nzb 2019-09-14 20:17 - 2019-09-14 20:17 - 000000747 _____ C:\Users\Peter\Downloads\report (1).csv 2019-09-12 00:16 - 2019-09-12 00:16 - 005500928 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 004306944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 003637760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 003525592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 003365376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe 2019-09-12 00:16 - 2019-09-12 00:16 - 002314440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 001105480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 000952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 000537608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 000411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\DavSyncProvider.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 000329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DavSyncProvider.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 000307200 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 000283264 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdeunlock.exe 2019-09-12 00:16 - 2019-09-12 00:16 - 000179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.XamlHost.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.XamlHost.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 000035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdeui.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 000027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecerts.dll 2019-09-12 00:16 - 2019-09-12 00:16 - 000021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fvecerts.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 008011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 007754240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 007014912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 005916672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 005848840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 005041664 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 005013504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 004857856 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 004538368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 003817472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 003771392 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 003750912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 003372448 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 002871608 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 002861568 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsservices.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 002743808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 002586816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 002576384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 002562048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 002494232 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 002305536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 002224952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 001721144 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 001647072 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 001531656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 001488216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 001413624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 001368576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 001348096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 001312256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 001305608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 001283600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi 2019-09-12 00:15 - 2019-09-12 00:15 - 001214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdclt.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 001214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 001138688 _____ (Microsoft Corporation) C:\WINDOWS\system32\nettrace.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 001122816 _____ (Microsoft Corporation) C:\WINDOWS\system32\CBDHSvc.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 001007616 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000957952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000913408 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000913168 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000910336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontext.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000888832 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicExtensions.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000844800 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000840704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000822416 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000822072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000810808 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000797112 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000776704 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000775680 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000771584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 2019-09-12 00:15 - 2019-09-12 00:15 - 000769024 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcIsoCtnr.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000740664 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000729088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FlightSettings.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000705536 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000699904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d8.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000680976 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000673456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000669696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000669496 _____ (Microsoft Corporation) C:\WINDOWS\system32\computecore.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000667272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000637752 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000636416 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000634880 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000631808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000628400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000626688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000609280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000593112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddraw.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000564736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Input.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000561680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys 2019-09-12 00:15 - 2019-09-12 00:15 - 000558080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000541264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StructuredQuery.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000538624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000531456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000529408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ddraw.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000529408 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000516752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000513336 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000511488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000511288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000510984 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000489472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Narrator.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000488056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000475648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxbde40.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000464696 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000464384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000454736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppResolver.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000431448 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000422008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000415760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000401208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys 2019-09-12 00:15 - 2019-09-12 00:15 - 000394752 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000380416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000362056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000359936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000327680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000324408 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000320512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000316216 _____ (Microsoft Corporation) C:\WINDOWS\system32\computestorage.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000313344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd2x40.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000310072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000283136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000281600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\coredpus.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000274944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Lights.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000270848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngctasks.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000267496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000253952 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerCsp.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCenter.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000222208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netplwiz.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000211968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000205312 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiapi.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000185856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceCenter.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngOnline.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\twext.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiapi.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\NcaSvc.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000167136 _____ (Microsoft Corporation) C:\WINDOWS\system32\vertdll.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000164152 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000163840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BitLockerCsp.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twext.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000147184 _____ (Microsoft Corporation) C:\WINDOWS\system32\smss.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000145720 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-kernel-processor-power-events.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000141840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys 2019-09-12 00:15 - 2019-09-12 00:15 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000120344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\DafPrintProvider.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\compstui.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssitlb.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000106296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\compstui.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DafPrintProvider.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000084280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winhvr.sys 2019-09-12 00:15 - 2019-09-12 00:15 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\efsext.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000071480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\findnetprinters.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcadm.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\printui.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000063288 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthHost.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000062464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\printui.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\edpnotify.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssprxy.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efsext.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\findnetprinters.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ByteCodeGenerator.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edpnotify.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddrawex.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\compact.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GameInput.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\XInput1_4.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000042512 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ddrawex.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\compact.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XInputUap.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XInput1_4.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000036152 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ws2ifsl.sys 2019-09-12 00:15 - 2019-09-12 00:15 - 000019984 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.exe 2019-09-12 00:15 - 2019-09-12 00:15 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDJPN.DLL 2019-09-12 00:15 - 2019-09-12 00:15 - 000013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDKOR.DLL 2019-09-12 00:15 - 2019-09-12 00:15 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaevts.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll 2019-09-12 00:15 - 2019-09-12 00:15 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 007582752 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 004140544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 004009472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Service.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 003353088 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 003263488 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 003084800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 002870272 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 001918976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 001885184 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 001783296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 001744400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 001686528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 001601536 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 001259424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe 2019-09-12 00:14 - 2019-09-12 00:14 - 001158656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 001094144 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcRefreshTask.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 001068560 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000977408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontext.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000909736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000905728 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000893440 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000863744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Service.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000849920 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe 2019-09-12 00:14 - 2019-09-12 00:14 - 000810496 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrSvc.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000808960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Input.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000804880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys 2019-09-12 00:14 - 2019-09-12 00:14 - 000804664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys 2019-09-12 00:14 - 2019-09-12 00:14 - 000731648 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.immersiveshell.serviceprovider.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000722288 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000705024 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntimewindows.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntime.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000686080 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000683008 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationFrame.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000680448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000676632 _____ (Microsoft Corporation) C:\WINDOWS\system32\StructuredQuery.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000670208 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000654912 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000596008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppResolver.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000522176 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2019-09-12 00:14 - 2019-09-12 00:14 - 000477696 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000462848 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.ConversationalAgent.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000425472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\HdAudio.sys 2019-09-12 00:14 - 2019-09-12 00:14 - 000411128 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe 2019-09-12 00:14 - 2019-09-12 00:14 - 000408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe 2019-09-12 00:14 - 2019-09-12 00:14 - 000396288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Lights.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000352256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcApi.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000338800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000331776 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFWSD.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000314368 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000295936 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000294400 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcTok.exe 2019-09-12 00:14 - 2019-09-12 00:14 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000245248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wosc.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe 2019-09-12 00:14 - 2019-09-12 00:14 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApproveChildRequest.exe 2019-09-12 00:14 - 2019-09-12 00:14 - 000237880 _____ C:\WINDOWS\system32\containerdevicemanagement.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000233472 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000232448 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthA2dp.sys 2019-09-12 00:14 - 2019-09-12 00:14 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000201528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys 2019-09-12 00:14 - 2019-09-12 00:14 - 000184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\AarSvc.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000182288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpioclx.sys 2019-09-12 00:14 - 2019-09-12 00:14 - 000160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000153088 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000149504 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe 2019-09-12 00:14 - 2019-09-12 00:14 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000146416 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssitlb.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatecsp.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe 2019-09-12 00:14 - 2019-09-12 00:14 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo-overrides.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ByteCodeGenerator.exe 2019-09-12 00:14 - 2019-09-12 00:14 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcimage.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\GameInput.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000055304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storufs.sys 2019-09-12 00:14 - 2019-09-12 00:14 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\XInputUap.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.Common.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilotdiag.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wci.dll 2019-09-12 00:14 - 2019-09-12 00:14 - 000013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\dstokenclean.exe 2019-09-10 22:09 - 2019-09-10 22:09 - 001234956 _____ C:\Users\Peter\Documents\Derek Strange top 5 accounts.pptx 2019-09-10 21:21 - 2019-09-10 22:08 - 001234953 _____ C:\Users\Peter\Documents\blank templates[382123].pptx 2019-09-07 02:44 - 2019-09-07 02:44 - 000000000 _____ C:\Users\Peter\AppData\Local\{33853F11-5277-4F6D-A197-235C702AAC30} ==================== One month (modified) ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-10-06 14:54 - 2016-09-08 15:24 - 000000000 ____D C:\Program Files (x86)\Steam 2019-10-06 14:54 - 2016-07-20 17:19 - 000000000 ____D C:\ProgramData\Origin 2019-10-06 14:53 - 2018-11-15 01:30 - 000000000 ____D C:\ProgramData\Kaspersky Lab 2019-10-06 14:53 - 2016-11-19 12:13 - 000000000 ____D C:\Users\Peter\AppData\LocalLow\Mozilla 2019-10-06 14:53 - 2016-03-19 21:44 - 000000000 ___RD C:\Users\Peter\OneDrive 2019-10-06 14:04 - 2019-03-19 05:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2019-10-06 14:04 - 2016-09-23 08:37 - 000000000 ____D C:\ProgramData\NVIDIA 2019-10-06 13:08 - 2019-08-30 11:22 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2019-10-06 02:33 - 2016-03-26 13:11 - 000000000 ____D C:\Users\Peter\AppData\Local\Adobe 2019-10-06 02:30 - 2016-07-20 17:24 - 000000000 ____D C:\Users\Peter\AppData\Roaming\Origin 2019-10-06 00:06 - 2019-03-19 05:52 - 000000000 ___HD C:\Program Files\WindowsApps 2019-10-06 00:06 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\AppReadiness 2019-10-05 20:31 - 2018-04-16 10:52 - 000000000 ____D C:\Users\Peter\AppData\Roaming\vlc 2019-10-05 18:45 - 2016-07-21 19:46 - 000226168 _____ C:\WINDOWS\SysWOW64\PnkBstrB.exe 2019-10-05 18:45 - 2016-07-21 19:46 - 000214392 _____ C:\WINDOWS\SysWOW64\PnkBstrB.ex0 2019-10-05 18:29 - 2016-07-20 17:24 - 000000000 ____D C:\Program Files (x86)\Origin Games 2019-10-05 18:25 - 2019-08-30 11:33 - 000003256 _____ C:\WINDOWS\system32\Tasks\HPCeeScheduleForPeter 2019-10-05 18:25 - 2017-01-14 23:46 - 000000364 _____ C:\WINDOWS\Tasks\HPCeeScheduleForPeter.job 2019-10-05 18:25 - 2016-09-08 16:41 - 001259632 _____ (EasyAntiCheat Oy) C:\WINDOWS\system32\Drivers\EasyAntiCheat.sys 2019-10-05 17:40 - 2019-08-30 11:28 - 000840848 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2019-10-05 17:40 - 2019-03-19 05:50 - 000000000 ____D C:\WINDOWS\INF 2019-10-05 17:39 - 2019-08-30 11:33 - 000003380 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2643124959-2563984870-1026749049-1001 2019-10-05 17:39 - 2019-08-30 11:25 - 000002367 _____ C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2019-10-05 17:37 - 2018-02-17 13:18 - 000000000 ____D C:\Program Files\Utilities 2019-10-05 17:34 - 2019-08-30 11:33 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2019-10-05 14:52 - 2017-12-29 21:12 - 000000000 ____D C:\Users\Peter\AppData\Roaming\WhatsApp 2019-10-05 11:39 - 2019-03-19 05:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2019-10-04 20:16 - 2016-11-26 17:55 - 000000258 __RSH C:\ProgramData\ntuser.pol 2019-10-04 19:18 - 2018-05-19 10:45 - 000000000 ____D C:\Users\Peter\AppData\Local\D3DSCache 2019-10-04 09:40 - 2017-12-09 17:04 - 000000000 ____D C:\Users\Peter\AppData\Local\PlaceholderTileLogoFolder 2019-10-04 08:29 - 2016-10-01 18:37 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2019-10-04 08:17 - 2016-10-01 18:37 - 000001232 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2019-10-04 08:15 - 2016-04-14 16:09 - 000000000 ___RD C:\Users\Peter\3D Objects 2019-10-04 08:15 - 2016-02-13 14:20 - 000000000 __RHD C:\Users\Public\AccountPictures 2019-10-04 08:14 - 2019-08-30 11:22 - 000447760 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2019-10-04 08:13 - 2019-03-19 05:52 - 000000000 ___RD C:\WINDOWS\PrintDialog 2019-10-04 08:13 - 2019-03-19 05:52 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2019-10-04 08:13 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe 2019-10-04 08:13 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2019-10-04 08:13 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SystemResources 2019-10-04 08:13 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\WinMetadata 2019-10-04 08:13 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\oobe 2019-10-04 08:13 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\migwiz 2019-10-04 08:13 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\Dism 2019-10-04 08:13 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\PolicyDefinitions 2019-10-04 08:13 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\bcastdvr 2019-10-04 01:18 - 2019-03-19 05:37 - 000000000 ____D C:\WINDOWS\CbsTemp 2019-10-03 21:53 - 2019-03-19 05:52 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2019-10-03 21:53 - 2017-05-10 18:00 - 000000000 ____D C:\Program Files\Common Files\AV 2019-10-03 21:11 - 2019-08-30 11:25 - 000000000 ____D C:\Users\Peter 2019-10-03 21:05 - 2016-11-26 17:55 - 000000000 ____D C:\Program Files (x86)\FreeCodecPack 2019-10-03 20:08 - 2016-04-07 13:26 - 000000000 ____D C:\Program Files (x86)\Dropbox 2019-10-03 19:26 - 2019-01-11 17:24 - 000000000 ____D C:\Program Files (x86)\Java 2019-10-03 19:25 - 2019-01-11 17:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2019-10-03 19:24 - 2019-01-11 17:24 - 000098288 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2019-10-03 17:25 - 2018-01-09 19:38 - 000000000 ____D C:\Users\Peter\AppData\Local\WhatsApp 2019-10-03 07:47 - 2018-02-19 01:47 - 000000000 ____D C:\WINDOWS\Microsoft Antimalware 2019-10-02 21:46 - 2018-11-15 01:30 - 000000000 ____D C:\Program Files (x86)\Kaspersky Lab 2019-10-02 21:46 - 2018-03-01 10:12 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2019-10-02 21:45 - 2019-03-19 05:37 - 000032768 _____ C:\WINDOWS\system32\config\ELAM 2019-10-02 21:45 - 2015-10-30 07:28 - 000000000 ____D C:\Users\Default.migrated 2019-10-02 12:56 - 2017-12-06 23:20 - 000000000 ____D C:\Users\Peter\AppData\Local\Packages 2019-09-29 21:12 - 2018-04-16 10:54 - 000000000 ____D C:\Users\Peter\AppData\Roaming\dvdcss 2019-09-29 21:09 - 2018-04-16 10:51 - 000000916 _____ C:\Users\Public\Desktop\VLC media player.lnk 2019-09-29 21:09 - 2018-04-16 10:51 - 000000916 _____ C:\ProgramData\Desktop\VLC media player.lnk 2019-09-27 17:47 - 2019-08-29 15:55 - 000000000 ___DC C:\WINDOWS\Panther 2019-09-23 20:34 - 2017-08-28 21:02 - 000000000 ____D C:\Users\Peter\AppData\Local\SquirrelTemp 2019-09-21 16:12 - 2016-03-26 00:32 - 000000000 ____D C:\Users\Peter\AppData\Local\ElevatedDiagnostics 2019-09-20 21:07 - 2018-03-18 20:00 - 000000000 ____D C:\NVIDIA 2019-09-20 21:06 - 2019-01-12 20:15 - 000000000 ____D C:\TEMP 2019-09-20 21:06 - 2017-05-15 15:43 - 000000000 ____D C:\ProgramData\NVIDIA Corporation 2019-09-20 21:06 - 2017-05-15 15:42 - 000000000 ____D C:\Program Files\NVIDIA Corporation 2019-09-20 21:04 - 2017-05-15 15:42 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2019-09-20 20:52 - 2017-12-22 23:05 - 000000000 ____D C:\Users\Peter\AppData\Roaming\EasyAntiCheat 2019-09-20 20:52 - 2016-09-08 16:41 - 000000000 ____D C:\Users\Peter\AppData\Local\UnrealEngine 2019-09-19 23:42 - 2019-06-23 12:58 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2019-09-19 23:42 - 2019-06-23 12:58 - 000002260 _____ C:\ProgramData\Desktop\Google Chrome.lnk 2019-09-19 23:42 - 2016-03-26 15:25 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2019-09-17 18:14 - 2018-10-20 17:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2019-09-17 11:38 - 2016-07-20 17:19 - 000000000 ____D C:\Program Files (x86)\Origin 2019-09-12 00:20 - 2019-03-19 05:52 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs 2019-09-12 00:20 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\TextInput 2019-09-12 00:20 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation 2019-09-12 00:20 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\ShellExperiences 2019-09-12 00:20 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\Provisioning 2019-09-12 00:18 - 2019-03-19 07:20 - 000021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\OEMDefaultAssociations.dll 2019-09-12 00:18 - 2019-03-19 07:20 - 000018903 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml 2019-09-12 00:18 - 2019-03-19 05:37 - 000000000 ____D C:\WINDOWS\servicing 2019-09-10 18:05 - 2019-08-30 11:33 - 000004600 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player PPAPI Notifier 2019-09-10 18:05 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed 2019-09-10 18:05 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\Macromed 2019-09-10 14:12 - 2019-08-30 11:33 - 000004588 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player NPAPI Notifier 2019-09-10 14:12 - 2019-08-30 11:33 - 000004386 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player Updater 2019-09-06 16:24 - 2019-06-15 21:07 - 005002192 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll 2019-09-06 10:43 - 2016-03-27 10:40 - 000094760 _____ C:\Users\Peter\AppData\Local\GDIPFONTCACHEV1.DAT ==================== Files in the root of some directories ================ 2016-06-17 07:53 - 2016-06-17 07:53 - 000000775 _____ () C:\Users\Peter\AppData\Roaming\baynote80.js 2016-12-22 19:35 - 2016-12-22 19:35 - 000063618 _____ () C:\Users\Peter\AppData\Roaming\Cordovan.DyhO 2016-06-17 07:53 - 2016-06-17 07:53 - 000000874 _____ () C:\Users\Peter\AppData\Roaming\dbmanager_schema.xml 2016-11-29 01:37 - 2018-01-27 01:37 - 000000545 _____ () C:\Users\Peter\AppData\Roaming\WB.CFG 2017-12-25 13:26 - 2017-12-25 13:26 - 000000068 _____ () C:\Users\Peter\AppData\Local\8wne5tkb2q 2019-10-04 17:14 - 2019-10-04 17:14 - 000474205 _____ () C:\Users\Peter\AppData\Local\ars.cache 2019-10-04 17:16 - 2019-10-04 17:16 - 001352267 _____ () C:\Users\Peter\AppData\Local\census.cache 2017-12-13 18:45 - 2017-12-17 12:55 - 000000068 _____ () C:\Users\Peter\AppData\Local\ClaPyncRAj 2017-02-25 23:34 - 2017-02-25 23:35 - 000007168 _____ () C:\Users\Peter\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2019-10-04 16:46 - 2019-10-04 16:46 - 000000036 _____ () C:\Users\Peter\AppData\Local\housecall.guid.cache 2018-09-28 20:49 - 2019-09-22 14:03 - 000000104 _____ () C:\Users\Peter\AppData\Local\oobelibMkey.log 2019-10-04 16:52 - 2019-10-04 16:52 - 000000010 _____ () C:\Users\Peter\AppData\Local\sponge.last.runtime.cache 2017-12-17 12:45 - 2017-12-17 12:45 - 000000068 _____ () C:\Users\Peter\AppData\Local\xIaaeMKoWq 2019-09-07 02:44 - 2019-09-07 02:44 - 000000000 _____ () C:\Users\Peter\AppData\Local\{33853F11-5277-4F6D-A197-235C702AAC30} 2016-05-01 19:35 - 2016-05-01 19:36 - 000000000 _____ () C:\Users\Peter\AppData\Local\{59F1B21B-6A55-43B9-A9FA-17EA1C6E29E2} ==================== SigCheck =============================== (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ============================
- 21 replies
-
- trojan:win32/coinminer
- trojan
-
(and 1 more)
Tagged with:
-
Help Please i cant get rid of this Trojan:Win32/CoinMiner I have tried Malwarebytes installed it tried to run it and as Admin as well but it kept saying not able to connect to server I tried the work around by renaming and all the other ones still it will not work any help would be great to get rid of this Trojan:Win32/CoinMiner Kind Regards Primaxuk
- 21 replies
-
- trojan:win32/coinminer
- trojan
-
(and 1 more)
Tagged with: