Jump to content

EEPers

Members
  • Content Count

    9
  • Joined

  • Last visited

About EEPers

  • Rank
    New Member

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

  1. Support followed up right before you request here. She examined and praised your help, but asked that I download a fixlist and get the most current log, which is: Fix result of Farbar Recovery Scan Tool (x64) Version: 30-06-2020 Ran by elain (01-07-2020 11:06:05) Run:2 Running from C:\Users\elain\Downloads Loaded Profiles: elain Boot Mode: Normal ============================================== fixlist content: ***************** Startup: C:\Users\elain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JfQPKiheALIH.lnK [2020-06-22] ShortcutAndArgument: JfQPKiheALIH.lnK -> C:\Users\elain\AppData\Roaming\JfQPKiheALIH.Cmd => Startup: C:\Users\elain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\puWJErhMmRyz.lnK [2020-06-22] ShortcutAndArgument: puWJErhMmRyz.lnK -> C:\Users\elain\AppData\Roaming\puWJErhMmRyz.Cmd => Startup: C:\Users\elain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WvMSIJCpwORq.LNk [2020-05-16] ShortcutAndArgument: WvMSIJCpwORq.LNk -> C:\Users\elain\AppData\Roaming\WvMSIJCpwORq.cMD => 2020-06-22 07:34 - 2020-06-22 07:34 - 000114688 _____ () C:\Users\elain\AppData\Roaming\JfQPKiheALIH 2020-06-22 07:34 - 2020-06-22 07:34 - 000000662 _____ () C:\Users\elain\AppData\Roaming\JfQPKiheALIH.cMD 2020-06-22 07:33 - 2020-06-22 07:33 - 000114688 _____ () C:\Users\elain\AppData\Roaming\puWJErhMmRyz 2020-06-22 07:33 - 2020-06-22 07:33 - 000000662 _____ () C:\Users\elain\AppData\Roaming\puWJErhMmRyz.cMD 2020-05-16 11:10 - 2020-05-16 11:10 - 000071000 _____ () C:\Users\elain\AppData\Roaming\WvMSIJCpwORq 2020-05-16 11:10 - 2020-05-16 11:10 - 000000662 _____ () C:\Users\elain\AppData\Roaming\WvMSIJCpwORq.Cmd ***************** C:\Users\elain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JfQPKiheALIH.lnK => moved successfully ShortcutAndArgument: JfQPKiheALIH.lnK -> C:\Users\elain\AppData\Roaming\JfQPKiheALIH.Cmd => => Error: No automatic fix found for this entry. C:\Users\elain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\puWJErhMmRyz.lnK => moved successfully ShortcutAndArgument: puWJErhMmRyz.lnK -> C:\Users\elain\AppData\Roaming\puWJErhMmRyz.Cmd => => Error: No automatic fix found for this entry. C:\Users\elain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WvMSIJCpwORq.LNk => moved successfully ShortcutAndArgument: WvMSIJCpwORq.LNk -> C:\Users\elain\AppData\Roaming\WvMSIJCpwORq.cMD => => Error: No automatic fix found for this entry. "C:\Users\elain\AppData\Roaming\JfQPKiheALIH" => not found "C:\Users\elain\AppData\Roaming\JfQPKiheALIH.cMD" => not found "C:\Users\elain\AppData\Roaming\puWJErhMmRyz" => not found "C:\Users\elain\AppData\Roaming\puWJErhMmRyz.cMD" => not found "C:\Users\elain\AppData\Roaming\WvMSIJCpwORq" => not found "C:\Users\elain\AppData\Roaming\WvMSIJCpwORq.Cmd" => not found ==== End of Fixlog 11:06:05 ==== Are we good or is there more to do?
  2. I meant to say, "quit dogging me". LOL
  3. I think it's running quite well and that trojan seems to keep dogging me now. It did stop after I removed the windows power shell which it was attached to. When I rebooted the windows power shell did not re-appear in the task menu and I don't know if that's of concern or not. Outside that, thank you for giving me the aide and tools necessary to stop this. Thank you Keven.
  4. THIS TEXT POPPED UP WHEN OPENING A REPLY, DON'T KNOW IF IT'S RELEVANT: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 6/30/20 Scan Time: 7:53 AM Log File: 78ce5a3a-bae1-11ea-b415-dcf5054c5e90.json -Software Information- Version: 4.1.0.56 Components Version: 1.0.955 Update Package Version: 1.0.26201 License: Premium -System Information- OS: Windows 10 (Build 19041.329) CPU: x64 File System: NTFS User: EEPHOMEOFFICE\elain -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 329314 Threats Detected: 0 Threats Quarantined: 0 Time Elapsed: 0 min, 56 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 0 (No malicious items detected) Registry Value: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 0 (No malicious items detected) File: 0 (No malicious items detected) Physical Sector: 0 (No malicious items detected) WMI: 0 (No malicious items detected) (end) COULD NOT GET A LOG, BUT I DID A VIEW SECOND TIME AROUND:
  5. FROM ADWCLEANER: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 6/30/20 Scan Time: 7:53 AM Log File: 78ce5a3a-bae1-11ea-b415-dcf5054c5e90.json -Software Information- Version: 4.1.0.56 Components Version: 1.0.955 Update Package Version: 1.0.26201 License: Premium -System Information- OS: Windows 10 (Build 19041.329) CPU: x64 File System: NTFS User: EEPHOMEOFFICE\elain -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 329314 Threats Detected: 0 Threats Quarantined: 0 Time Elapsed: 0 min, 56 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled # ------------------------------- # Malwarebytes AdwCleaner 8.0.5.0 # ------------------------------- # Build: 05-25-2020 # Database: 2020-06-15.1 (Cloud) # Support: https://www.malwarebytes.com/support # # ------------------------------- # Mode: Clean # ------------------------------- # Start: 06-30-2020 # Duration: 00:00:02 # OS: Windows 10 Home # Cleaned: 22 # Failed: 1 ***** [ Services ] ***** No malicious services cleaned. ***** [ Folders ] ***** No malicious folders cleaned. ***** [ Files ] ***** No malicious files cleaned. ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** No malicious tasks cleaned. ***** [ Registry ] ***** Deleted HKLM\Software\Conduit ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries cleaned. ***** [ Chromium URLs ] ***** No malicious Chromium URLs cleaned. ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries cleaned. ***** [ Firefox URLs ] ***** No malicious Firefox URLs cleaned. ***** [ Hosts File Entries ] ***** No malicious hosts file entries cleaned. ***** [ Preinstalled Software ] ***** Deleted Preinstalled.ASUSDeviceActivation Folder C:\Program Files (x86)\ASUS\ASUS DEVICE ACTIVATION Deleted Preinstalled.ASUSDeviceActivation Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{9C4B0706-9F9A-47BF-B417-0A111FC52B04} Deleted Preinstalled.ASUSGiftBox Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{4701E5AB-AF91-4D40-8F18-358CC80E4E5B} Deleted Preinstalled.ASUSHello Folder C:\Program Files (x86)\ASUS\ASUS HELLO Deleted Preinstalled.ASUSHello Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9486D21E-E9EB-43F8-85AF-E3EC0FCF2A9A} Deleted Preinstalled.ASUSHello Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASUS Hello Deleted Preinstalled.ASUSHello Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{D8CE1923-92A9-4036-817E-9E0D8AA2169B} Deleted Preinstalled.ASUSHello Task C:\Windows\System32\Tasks\ASUS HELLO Deleted Preinstalled.ASUSLiveUpdate Folder C:\Program Files (x86)\ASUS\ASUS LIVE UPDATE Deleted Preinstalled.ASUSLiveUpdate Folder C:\ProgramData\ASUS\ASUS LIVE UPDATE Deleted Preinstalled.ASUSLiveUpdate Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AAF27842-7BD7-422C-9FCA-415FCB87001F} Deleted Preinstalled.ASUSLiveUpdate Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update Checker Deleted Preinstalled.ASUSLiveUpdate Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4} Deleted Preinstalled.ASUSLiveUpdate Task C:\Windows\System32\Tasks\UPDATE CHECKER Deleted Preinstalled.ASUSProductRegistration Folder C:\ProgramData\ASUS\APRP Deleted Preinstalled.ASUSSplendid Folder C:\Program Files (x86)\ASUS\SPLENDID Deleted Preinstalled.ASUSSplendid Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{180AB9D4-E685-40A9-A6A2-D23D35C7C381} Deleted Preinstalled.ASUSSplendid Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASUS Splendid ACMON Deleted Preinstalled.ASUSSplendid Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{0969AF05-4FF6-4C00-9406-43599238DE0D} Deleted Preinstalled.ASUSSplendid Task C:\Windows\System32\Tasks\ASUS SPLENDID ACMON Deleted Preinstalled.CyberLinkService Folder C:\Program Files\CYBERLINK\SHARED FILES\PLUGIN\NEWBLUE Not Deleted Preinstalled.ASUSGiftBox Folder C:\Program Files (x86)\ASUS\ASUS GIFTBOX SERVICE ************************* [+] Delete Tracing Keys [+] Reset Winsock ************************* AdwCleaner[S00].txt - [4123 octets] - [30/06/2020 08:17:14] ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
  6. Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 6/30/20 Scan Time: 7:53 AM Log File: 78ce5a3a-bae1-11ea-b415-dcf5054c5e90.json -Software Information- Version: 4.1.0.56 Components Version: 1.0.955 Update Package Version: 1.0.26201 License: Premium -System Information- OS: Windows 10 (Build 19041.329) CPU: x64 File System: NTFS User: EEPHOMEOFFICE\elain -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 329314 Threats Detected: 0 Threats Quarantined: 0 Time Elapsed: 0 min, 56 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 0 (No malicious items detected) Registry Value: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 0 (No malicious items detected) File: 0 (No malicious items detected) Physical Sector: 0 (No malicious items detected) WMI: 0 (No malicious items detected) (end)
  7. Fix result of Farbar Recovery Scan Tool (x64) Version: 30-06-2020 Ran by elain (30-06-2020 07:34:54) Run:1 Running from C:\Users\elain\Downloads Loaded Profiles: elain Boot Mode: Normal ============================================== fixlist content: ***************** CloseProcesses: SystemRestore: On CreateRestorePoint: HKU\S-1-5-21-131675017-3346686803-3792727656-1002\...\RunOnce: [Application Restart #3] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --user-data-dir="C:\Users\elain\AppData\Local\Temp\\{0EEDB3FB-1591-70AF-0F22-19A4B3765D18}_CR" --no-sandbox --allow-no-sandbox-job --disabl (the data entry has 154 more characters). <==== ATTENTION 2020-06-22 07:34 - 2020-06-22 07:34 - 000114688 _____ C:\Users\elain\AppData\Roaming\JfQPKiheALIH 2020-06-22 07:34 - 2020-06-22 07:34 - 000000662 _____ C:\Users\elain\AppData\Roaming\JfQPKiheALIH.cMD 2020-06-22 07:33 - 2020-06-22 07:33 - 000114688 _____ C:\Users\elain\AppData\Roaming\puWJErhMmRyz 2020-06-22 07:33 - 2020-06-22 07:33 - 000000662 _____ C:\Users\elain\AppData\Roaming\puWJErhMmRyz.cMD 2020-05-16 11:10 - 2020-05-16 11:10 - 000071000 _____ () C:\Users\elain\AppData\Roaming\WvMSIJCpwORq 2020-05-16 11:10 - 2020-05-16 11:10 - 000000662 _____ () C:\Users\elain\AppData\Roaming\WvMSIJCpwORq.Cmd AlternateDataStreams: C:\ProgramData\TEMP:065D25EE [358] AlternateDataStreams: C:\ProgramData\TEMP:0FD841FF [183] FirewallRules: [{17D0B180-07DB-4EC3-A0E4-596D469F324A}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe => No File FirewallRules: [{A14BF976-27E0-4750-9A1F-AFABAB9FC0E0}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe => No File FirewallRules: [{3445F090-653A-42AD-ABA2-07A6971665DF}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe => No File CMD: winmgmt /verifyrepository Hosts: EmptyTemp: ***************** Processes closed successfully. SystemRestore: On => completed Restore point was successfully created. "HKU\S-1-5-21-131675017-3346686803-3792727656-1002\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Application Restart #3" => removed successfully C:\Users\elain\AppData\Roaming\JfQPKiheALIH => moved successfully C:\Users\elain\AppData\Roaming\JfQPKiheALIH.cMD => moved successfully C:\Users\elain\AppData\Roaming\puWJErhMmRyz => moved successfully C:\Users\elain\AppData\Roaming\puWJErhMmRyz.cMD => moved successfully C:\Users\elain\AppData\Roaming\WvMSIJCpwORq => moved successfully C:\Users\elain\AppData\Roaming\WvMSIJCpwORq.Cmd => moved successfully C:\ProgramData\TEMP => ":065D25EE" ADS removed successfully C:\ProgramData\TEMP => ":0FD841FF" ADS removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{17D0B180-07DB-4EC3-A0E4-596D469F324A}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A14BF976-27E0-4750-9A1F-AFABAB9FC0E0}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3445F090-653A-42AD-ABA2-07A6971665DF}" => removed successfully ========= winmgmt /verifyrepository ========= WMI repository is consistent ========= End of CMD: ========= C:\Windows\System32\Drivers\etc\hosts => moved successfully Hosts restored successfully. =========== EmptyTemp: ========== BITS transfer queue => 10248192 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 286009652 B Java, Flash, Steam htmlcache => 735 B Windows/system/drivers => 19495458 B Edge => 10823619 B Chrome => 1355784471 B Firefox => 1329371088 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 269862 B NetworkService => 319926 B elain => 129708721 B RecycleBin => 0 B EmptyTemp: => 2.9 GB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 07:42:18 ====
  8. Log from FIRST.TXT Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-06-2020 Ran by elain (administrator) on EEPHOMEOFFICE (ASUSTeK COMPUTER INC. Vivo AIO 27 V272UA) (29-06-2020 10:58:04) Running from C:\Users\elain\Downloads Loaded Profiles: elain Platform: Windows 10 Home Version 2004 19041.329 (X64) Language: English (United States) Default browser: Chrome Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) () [File not signed] [File is in use] C:\Program Files (x86)\ACT\Act for Windows\Act.Outlook64.Service.exe () [File not signed] [File is in use] C:\Program Files (x86)\ACT\Act for Windows\Integration Services Patch for Act!\ISPA.exe () [File not signed] [File is in use] C:\Program Files (x86)\ACT\Act.Web.API\bin\act.web.api.hosting.exe (Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems, Incorporated -> Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Arvato Digital Services Canada Inc -> arvato digital services llc) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (ASUS) [File not signed] [File is in use] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUSTeK Computer Inc. -> ) C:\Program Files (x86)\ASUS\ASUS Hello\ASUSHelloBG.exe (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (Avanquest Software SAS -> Avanquest Software) C:\Users\elain\AppData\Local\Avanquest\Avanquest Message\AQNotif.exe (Centered Systems -> Centered Systems) C:\Program Files (x86)\Second Copy 8\ScVssService64.exe (Centered Systems -> Centered Systems) C:\Program Files (x86)\Second Copy 8\SecCopy.exe (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries) C:\Program Files (x86)\Garmin\Express\express.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <21> (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe (Google LLC -> Google) C:\Users\elain\AppData\Local\Google\Chrome\User Data\SwReporter\83.238.200\software_reporter_tool.exe <4> (ICEpower a/s -> ICEpower A/S) C:\Windows\System32\ICEsoundService64.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_9196e89091d8bdbb\esif_uf.exe (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_31a8dbbf39dcdc3b\jhi_service.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_ca6dea73b8394fc3\igfxCUIService.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_ca6dea73b8394fc3\igfxEM.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_ca6dea73b8394fc3\igfxext.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_ca6dea73b8394fc3\IntelCpHDCPSvc.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_ca6dea73b8394fc3\IntelCpHeciSvc.exe (Macrovision Corporation -> Macrovision Europe Ltd.) [File not signed] [File is in use] C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10_50.ACT7\MSSQL\Binn\sqlservr.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SystemSettingsAdminFlows.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.329_none_e77145332606deb0\TiWorker.exe (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) C:\Windows\System32\drivers\AdminService.exe (Microsoft) [File not signed] [File is in use] C:\Program Files (x86)\ACT\Act for Windows\Act.Server.Host.exe (Nero AG -> Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Qualcomm Atheros -> Qualcomm Technologies Inc.) C:\Windows\System32\drivers\QcomWlanSrvx64.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe <6> (Swiftpage ACT! LLC -> Swiftpage ACT! LLC) C:\Program Files (x86)\ACT\Act for Windows\Act!.Integration.exe (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\Program Files (x86)\ACT\Act for Windows\Act.Outlook.Service.exe (Valusoft Finance, LLC -> ValuSoft Finance, LLC) C:\Program Files (x86)\MasterCook 15\MyMasterCook\MyMasterCook.exe (Zeon Corporation -> ) C:\Program Files (x86)\HotDocs\bin\ZNLSvc.exe Failed to access process -> GiftBoxService.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [19677472 2019-12-13] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_ListenToDevice] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3617568 2019-12-13] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [37232 2008-06-12] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [640376 2008-06-11] (Adobe Systems, Incorporated -> Adobe Systems Inc.) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc. -> Apple Inc.) HKLM-x32\...\Run: [Act.Outlook.Service] => C:\Program Files (x86)\ACT\Act for Windows\Act.Outlook.Service.exe [19456 2018-03-15] (Swiftpage ACT! LLC) [File not signed] [File is in use] HKLM-x32\...\Run: [Act.Outlook64.Service] => C:\Program Files (x86)\ACT\Act for Windows\Act.Outlook64.Service.exe [23552 2018-03-15] () [File not signed] [File is in use] HKLM-x32\...\Run: [Act! Preloader] => C:\Program Files (x86)\ACT\Act for Windows\Act!.exe [272336 2019-09-24] (Swiftpage ACT! LLC -> Swiftpage ACT! LLC) HKLM-x32\...\Run: [Polarr] => C:\ProgramData\SquirrelMachineInstalls\Polarr.exe [73300232 2020-05-16] (Polarr, Inc. -> Polarr, Inc.) [File not signed] [File is in use] HKU\S-1-5-21-131675017-3346686803-3792727656-1002\...\Run: [Second Copy] => C:\Program Files (x86)\Second Copy 8\SecCopy.exe [3128616 2013-01-27] (Centered Systems -> Centered Systems) HKU\S-1-5-21-131675017-3346686803-3792727656-1002\...\Run: [Avanquest Message] => C:\Users\elain\AppData\Local\Avanquest\Avanquest Message\AQNotif.exe [439784 2020-04-02] (Avanquest Software SAS -> Avanquest Software) HKU\S-1-5-21-131675017-3346686803-3792727656-1002\...\Run: [ISPA] => C:\Program Files (x86)\ACT\Act for Windows\Integration Services Patch for Act!\ISPA.exe [15635456 2019-07-26] () [File not signed] [File is in use] HKU\S-1-5-21-131675017-3346686803-3792727656-1002\...\Run: [GarminExpress] => C:\Program Files (x86)\Garmin\Express\express.exe [30868464 2019-12-12] (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries) HKU\S-1-5-21-131675017-3346686803-3792727656-1002\...\RunOnce: [Application Restart #3] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --user-data-dir="C:\Users\elain\AppData\Local\Temp\\{0EEDB3FB-1591-70AF-0F22-19A4B3765D18}_CR" --no-sandbox --allow-no-sandbox-job --disabl (the data entry has 154 more characters). <==== ATTENTION HKLM\...\Windows x64\Print Processors\hpcpp155: C:\Windows\System32\spool\prtprocs\x64\hpcpp155.DLL [597792 2013-09-04] (Hewlett-Packard Company -> Hewlett-Packard Corporation) HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\WINDOWS\system32\AdobePDF.dll [51032 2008-04-07] (Adobe Systems, Incorporated -> Adobe Systems Inc) HKLM\...\Print\Monitors\novaPDF 7 Monitor: C:\WINDOWS\system32\novamnk7.dll [29472 2014-06-16] (Softland S.R.L. -> Softland) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\83.0.4103.116\Installer\chrmstp.exe [2020-06-22] (Google LLC -> Google LLC) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Act! Integration.lnk [2020-01-05] ShortcutTarget: Act! Integration.lnk -> C:\Program Files (x86)\ACT\Act for Windows\Act!.Integration.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk [2019-12-12] ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) [File not signed] [File is in use] Startup: C:\Users\elain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JfQPKiheALIH.lnK [2020-06-22] ShortcutAndArgument: JfQPKiheALIH.lnK -> C:\Users\elain\AppData\Roaming\JfQPKiheALIH.Cmd => Startup: C:\Users\elain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\puWJErhMmRyz.lnK [2020-06-22] ShortcutAndArgument: puWJErhMmRyz.lnK -> C:\Users\elain\AppData\Roaming\puWJErhMmRyz.Cmd => Startup: C:\Users\elain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WvMSIJCpwORq.LNk [2020-05-16] ShortcutAndArgument: WvMSIJCpwORq.LNk -> C:\Users\elain\AppData\Roaming\WvMSIJCpwORq.cMD => ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {010F5DD3-B691-460F-B9A1-38F605E1822F} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe Task: {01E6D4BB-B74A-43C1-81AC-0E06E0EE9320} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [127176 2020-05-20] (Mozilla Corporation -> Mozilla Foundation) Task: {180AB9D4-E685-40A9-A6A2-D23D35C7C381} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [75776 2017-10-24] (ASUS) [File not signed] [File is in use] Task: {5C52AC7E-FED3-4ADB-930D-4C40397FF8E0} - System32\Tasks\McAfee\DAD.Execute.Updates => C:\Program Files\Common Files\McAfee\DynamicAppDownloader\1.4.111\DADUpdater.exe Task: {65EB50B5-EAD0-41A4-BE98-F913B7301D30} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-11-27] (Google Inc -> Google LLC) Task: {88823972-A1BC-4741-A625-DB3704A00E40} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Systems) Task: {8EC9FA58-4F01-4444-BAC6-EBBB9F576F0A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-11-27] (Google Inc -> Google LLC) Task: {93C13921-8182-42E7-A567-628B93BBC9EB} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-131675017-3346686803-3792727656-1002 => C:\Users\elain\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe Task: {9486D21E-E9EB-43F8-85AF-E3EC0FCF2A9A} - System32\Tasks\ASUS Hello => C:\Program Files (x86)\ASUS\ASUS Hello\ASUSHelloBG.exe [642448 2018-05-31] (ASUSTeK Computer Inc. -> ) Task: {A1F87101-B717-4971-B1DD-7E819D1E03FB} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [40432 2019-12-12] (Garmin International, Inc. -> ) Task: {A6B38897-6866-4936-9349-7C48D6BC56D2} - System32\Tasks\McAfeeLogon => C:\PROGRA~1\COMMON~1\McAfee\Platform\McUICnt.exe Task: {AAF27842-7BD7-422C-9FCA-415FCB87001F} - System32\Tasks\Update Checker => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [143160 2019-03-12] (ASUSTek Computer Inc. -> ASUSTek Computer Inc.) Task: {B1E00102-23E1-4C28-9985-C57CD82D4FC9} - System32\Tasks\OneDrive Standalone Update Task v2 => C:\Users\elain\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe Task: {D9126DCC-53D5-4595-86D0-F90FA7CB6A9D} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent => {ABCECA3B-EA5A-496B-A021-5C6BAB365E5C} "C:\Program Files\Common Files\McAfee\TaskScheduler\McAMTaskAgent.exe" Task: {E0E249A3-D98F-448E-96E0-013107FD05D3} - System32\Tasks\McAfee\McAfee Idle Detection Task => {ABCDCA3B-DE6B-5A7C-B132-6D7CBA63E5C5} "C:\Program Files\Common Files\McAfee\TaskScheduler\McAMTaskAgent.exe" Task: {E5E03A5F-FEE9-4964-B6FF-56EE76A7D601} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [124304 2017-11-23] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) Task: {FB2B59E2-B6C4-414E-8D11-A68C98F5B483} - System32\Tasks\ATK Package A22126881260 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [124304 2017-11-23] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.10.1 Tcpip\..\Interfaces\{16701ce0-2bd6-458b-974b-3425a244c327}: [DhcpNameServer] 192.168.10.1 Tcpip\..\Interfaces\{24c6f243-7ff7-49f0-b4bb-7a14b385a2ed}: [NameServer] 8.8.8.8 Internet Explorer: ================== HKU\S-1-5-21-131675017-3346686803-3792727656-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?gws_rd=ssl#spf=1575318724860 HKU\S-1-5-21-131675017-3346686803-3792727656-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus17win10.msn.com/?pc=ASTE SearchScopes: HKU\S-1-5-21-131675017-3346686803-3792727656-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-131675017-3346686803-3792727656-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\x64\IEPlugin.dll => No File BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll => No File BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile -> {D5233FCD-D258-4903-89B8-FB1568E7413D} -> C:\Program Files (x86)\ACT\Act for Windows\Plugins\Act.UI.InternetExplorer.Plugins.AttachFile.DLL [2018-03-15] (Swiftpage ACT! LLC) [File not signed] [File is in use] BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) Toolbar: HKU\S-1-5-21-131675017-3346686803-3792727656-1002 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\mcafee\msc\mcsniepl.dll No File FireFox: ======== FF DefaultProfile: r6cwiyap.default FF ProfilePath: C:\Users\elain\AppData\Roaming\Mozilla\Firefox\Profiles\r6cwiyap.default [2019-12-06] FF ProfilePath: C:\Users\elain\AppData\Roaming\Mozilla\Firefox\Profiles\ulxgegji.default-release [2020-06-23] FF Notifications: Mozilla\Firefox\Profiles\ulxgegji.default-release -> hxxps://calendar.google.com FF Extension: (Honey) - C:\Users\elain\AppData\Roaming\Mozilla\Firefox\Profiles\ulxgegji.default-release\Extensions\jid1-93CWPmRbVPjRQA@jetpack.xpi [2020-04-15] FF Extension: (DuckDuckGo Privacy Essentials) - C:\Users\elain\AppData\Roaming\Mozilla\Firefox\Profiles\ulxgegji.default-release\Extensions\jid1-ZAdIEUB7XOzOJw@jetpack.xpi [2020-05-20] FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi => not found FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi => not found FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => not found FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [No File] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [No File] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2012-08-10] (Nero AG -> Nero AG) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-05-03] (Adobe Inc. -> Adobe Systems Inc.) Chrome: ======= CHR Profile: C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default [2020-06-29] CHR Notifications: Default -> hxxps://mail.google.com CHR DefaultSearchURL: Default -> hxxps://duckduckgo.com/?q={searchTerms} CHR DefaultSearchKeyword: Default -> duckduckgo.com CHR DefaultNewTabURL: Default -> hxxps://duckduckgo.com/chrome_newtab CHR DefaultSuggestURL: Default -> hxxps://duckduckgo.com/ac/?q={searchTerms}&type=list CHR Extension: (Slides) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-11-27] CHR Extension: (Docs) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-11-27] CHR Extension: (Google Drive) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-11-27] CHR Extension: (DuckDuckGo) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkdgflcldnnnapblkhphbgpggdiikppg [2020-05-29] CHR Extension: (YouTube) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-11-27] CHR Extension: (Honey) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2020-05-29] CHR Extension: (Dropbox for Gmail) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpdmhfocilnekecfjgimjdeckachfbec [2019-11-27] CHR Extension: (Adobe Acrobat) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2020-06-11] CHR Extension: (Chrome Remote Desktop) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\efmjfjelnicpmdcmfikempdhlmainjcb [2020-04-14] CHR Extension: (Sheets) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-11-27] CHR Extension: (Google Docs Offline) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-05-26] CHR Extension: (Pinterest Save Button) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2020-06-17] CHR Extension: (Chrome Remote Desktop) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\inomeogfingihgjfjlpeplalcfajhgai [2019-12-02] CHR Extension: (Chrome Web Store Payments) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-11-27] CHR Extension: (Gmail) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-11-27] CHR Extension: (Chrome Media Router) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-05-28] CHR Profile: C:\Users\elain\AppData\Local\Google\Chrome\User Data\System Profile [2020-05-26] CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S2 Act! Scheduler; C:\Program Files (x86)\ACT\Act for Windows\Act.Scheduler.exe [90112 2018-03-15] (Swiftpage ACT! LLC) [File not signed] [File is in use] R2 ActService; C:\Program Files (x86)\ACT\Act for Windows\Act.Server.Host.exe [27648 2018-03-15] (Microsoft) [File not signed] [File is in use] R2 ActSmartTaskService; C:\Program Files (x86)\ACT\Act for Windows\Act.Server.Host.exe [27648 2018-03-15] (Microsoft) [File not signed] [File is in use] R2 ActWebApiService; C:\Program Files (x86)\ACT\Act.Web.API\bin\act.web.api.hosting.exe [22016 2019-12-05] () [File not signed] [File is in use] R2 AtherosSvc; C:\WINDOWS\System32\drivers\AdminService.exe [387192 2019-11-03] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) S3 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\84.0.4147.39\remoting_host.exe [73200 2020-06-08] (Google LLC -> Google Inc.) S2 DevActSvc; C:\Program Files (x86)\ASUS\ASUS Device Activation\DevActSvc.exe [325456 2018-06-11] (ASUSTek Computer Inc. -> ) R3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2019-12-02] (Macrovision Corporation -> Macrovision Europe Ltd.) [File not signed] [File is in use] S2 GiftBox.Service; C:\Program Files (x86)\ASUS\ASUS GiftBox Service\GiftBoxService.exe [302416 2018-06-28] (ASUSTek Computer Inc. -> ASUSTeK Computer Inc.) R2 ICEsoundService; C:\WINDOWS\system32\ICEsoundService64.exe [814368 2019-12-13] (ICEpower a/s -> ICEpower A/S) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6933272 2020-03-11] (Malwarebytes Inc -> Malwarebytes) R2 MSSQL$ACT7; C:\Program Files\Microsoft SQL Server\MSSQL10_50.ACT7\MSSQL\Binn\sqlservr.exe [61913952 2011-09-21] (Microsoft Corporation -> Microsoft Corporation) S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [50688 2013-05-16] (Hewlett-Packard) [File not signed] [File is in use] S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [66048 2013-05-16] (Hewlett-Packard) [File not signed] [File is in use] R2 PSI_SVC_2; C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [252344 2012-06-15] (Arvato Digital Services Canada Inc -> arvato digital services llc) R2 QcomWlanSrv; C:\WINDOWS\System32\drivers\QcomWlanSrvx64.exe [191768 2019-11-04] (Qualcomm Atheros -> Qualcomm Technologies Inc.) R2 ScVssService64; C:\Program Files (x86)\Second Copy 8\ScVssService64.exe [75048 2013-01-27] (Centered Systems -> Centered Systems) S4 SQLAgent$ACT7; C:\Program Files\Microsoft SQL Server\MSSQL10_50.ACT7\MSSQL\Binn\SQLAGENT.EXE [428384 2011-09-21] (Microsoft Corporation -> Microsoft Corporation) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2005.5-0\NisSrv.exe [2484256 2020-06-11] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2005.5-0\MsMpEng.exe [103168 2020-06-11] (Microsoft Windows Publisher -> Microsoft Corporation) R2 ZNLSvc; C:\Program Files (x86)\HotDocs\Bin\ZNLSvc.exe [186200 2008-09-08] (Zeon Corporation -> ) ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 ATKWMIACPIIO; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [20096 2015-05-08] (Microsoft Windows Hardware Compatibility Publisher -> ASUSTek Computer Inc.) R3 BtFilter; C:\WINDOWS\System32\drivers\btfilter.sys [83432 2019-11-03] (Qualcomm Atheros -> Qualcomm) R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153312 2020-04-20] (Malwarebytes Corporation -> Malwarebytes) R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [214496 2020-06-23] (Malwarebytes Inc -> Malwarebytes) S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2020-06-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [196456 2020-06-28] (Malwarebytes Inc -> Malwarebytes) R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [73368 2020-06-28] (Malwarebytes Inc -> Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248968 2020-06-05] (Malwarebytes Inc -> Malwarebytes) R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [131728 2020-06-25] (Malwarebytes Inc -> Malwarebytes) R3 Qcamain10x64; C:\WINDOWS\System32\drivers\Qcamain10x64.sys [2432280 2019-11-04] (Qualcomm Atheros -> Qualcomm Atheros, Inc.) R3 voxaldriver; C:\WINDOWS\system32\DRIVERS\voxaldriverx64.sys [52976 2019-12-16] (NCH Software Pty Ltd -> ) S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45960 2020-06-11] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.) S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [401120 2020-06-11] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [64224 2020-06-11] (Microsoft Windows -> Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) =================== (If an entry is included in the fixlist, the file/folder will be moved.) 2020-06-29 10:58 - 2020-06-29 10:58 - 000029968 _____ C:\Users\elain\Downloads\FRST.txt 2020-06-29 10:56 - 2020-06-29 10:56 - 002291712 _____ (Farbar) C:\Users\elain\Downloads\FRST64.exe 2020-06-29 10:51 - 2020-06-29 10:51 - 000216433 _____ C:\Users\elain\Downloads\2018 - SCF (2).pdf 2020-06-29 10:50 - 2020-06-29 10:50 - 000472323 _____ C:\Users\elain\Downloads\MLS PDF Cancelled Morning Star PAAR Only.pdf 2020-06-29 10:50 - 2020-06-29 10:50 - 000216785 _____ C:\Users\elain\Downloads\2018 - SCF (1).pdf 2020-06-29 10:49 - 2020-06-29 10:49 - 008565254 _____ C:\Users\elain\Downloads\PROOF - 5975 S Morning Star Lane, Prescott, AZ 86303 Eblast.pdf 2020-06-29 10:49 - 2020-06-29 10:49 - 000000282 _____ C:\Users\elain\Downloads\text.000000.txt 2020-06-29 10:48 - 2020-06-29 10:48 - 000197953 _____ C:\Users\elain\Downloads\2018 - SCF.pdf 2020-06-29 10:47 - 2020-06-29 10:47 - 000607918 _____ C:\Users\elain\Downloads\PDFS-Forms (1).pdf 2020-06-29 10:46 - 2020-06-29 10:46 - 000607918 _____ C:\Users\elain\Downloads\PDFS-Forms.pdf 2020-06-29 10:44 - 2020-06-29 10:44 - 003978992 _____ C:\Users\elain\Downloads\List Docs Morning Star.pdf 2020-06-29 10:43 - 2020-06-29 10:43 - 002417747 _____ C:\Users\elain\Downloads\SPDS Morning Star.pdf 2020-06-29 10:43 - 2020-06-29 10:43 - 001103442 _____ C:\Users\elain\Downloads\Morning Star - Pickens CMA as of Aug 2019.pdf 2020-06-29 09:30 - 2020-06-29 09:30 - 000000000 ____D C:\Users\elain\AppData\LocalLow\IGDump 2020-06-29 08:04 - 2020-06-29 08:04 - 000632588 _____ C:\Users\elain\Downloads\SimpleKetoSystem.pdf 2020-06-28 11:16 - 2020-06-28 11:16 - 000000155 _____ C:\Users\elain\Desktop\Malwarebytes Forum.url 2020-06-28 09:14 - 2020-06-28 09:15 - 009154656 _____ C:\Users\elain\Downloads\mb-support-1.6.1.784 (2).exe 2020-06-27 17:25 - 2020-06-27 17:25 - 009154656 _____ C:\Users\elain\Downloads\mb-support-1.6.1.784 (1).exe 2020-06-27 10:50 - 2020-06-29 10:58 - 000000000 ____D C:\FRST 2020-06-27 10:33 - 2020-06-28 09:15 - 002291712 _____ (Farbar) C:\Users\elain\Downloads\FRSTEnglish.exe 2020-06-27 10:32 - 2020-06-27 10:32 - 009154656 _____ C:\Users\elain\Downloads\mb-support-1.6.1.784.exe 2020-06-27 10:06 - 2020-06-27 10:06 - 000181814 _____ C:\Users\elain\Downloads\5975_S_Morning_Star_Ln.pdf 2020-06-26 13:55 - 2020-06-28 09:06 - 000196456 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys 2020-06-26 13:55 - 2020-06-28 09:06 - 000073368 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2020-06-25 11:11 - 2020-06-25 11:11 - 000131728 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 2020-06-24 15:50 - 2020-06-24 15:50 - 000098313 _____ C:\Users\elain\Downloads\RecipeExport2232.mz2 2020-06-22 07:34 - 2020-06-22 07:34 - 000114688 _____ C:\Users\elain\AppData\Roaming\JfQPKiheALIH 2020-06-22 07:34 - 2020-06-22 07:34 - 000000662 _____ C:\Users\elain\AppData\Roaming\JfQPKiheALIH.cMD 2020-06-22 07:33 - 2020-06-22 07:33 - 000114688 _____ C:\Users\elain\AppData\Roaming\puWJErhMmRyz 2020-06-22 07:33 - 2020-06-22 07:33 - 000000662 _____ C:\Users\elain\AppData\Roaming\puWJErhMmRyz.cMD 2020-06-18 07:22 - 2020-06-18 07:22 - 000065320 _____ C:\Users\elain\Downloads\amazon chase 17 account close Secure Messages - chase.com.pdf 2020-06-18 07:12 - 2020-06-18 07:12 - 000035410 _____ C:\Users\elain\Downloads\message_v4.rpmsg 2020-06-18 05:51 - 2020-06-18 05:51 - 000000000 ____D C:\Users\elain\AppData\Roaming\Skype 2020-06-17 09:50 - 2020-06-17 09:50 - 000009480 _____ C:\Users\elain\Downloads\RecipeExport1990.mz2 2020-06-17 09:29 - 2020-06-17 09:30 - 000052793 _____ C:\Users\elain\Downloads\RecipeExport1983.mz2 2020-06-15 13:27 - 2020-06-15 13:27 - 009449238 _____ C:\Users\elain\Downloads\Untitled attachment 01250.mp4 2020-06-12 07:15 - 2020-06-12 07:15 - 000000111 _____ C:\Users\elain\Desktop\whodns.url 2020-06-11 14:46 - 2020-06-11 14:47 - 000112719 _____ C:\Users\elain\Downloads\OontZ Angle 3 Portable Bluetooth Speaker Reset.pdf 2020-06-11 04:13 - 2020-06-23 11:28 - 000214496 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys 2020-06-10 20:46 - 2020-06-10 20:46 - 036171046 _____ C:\Users\elain\Downloads\Audio_DCH_Realtek_Win10_64_V6088211 (1).zip 2020-06-10 20:43 - 2020-06-11 05:56 - 000000000 ____D C:\Users\elain\Documents\Realtek Driver Download 2020-06-10 20:40 - 2020-06-11 05:56 - 000000000 ____D C:\Users\elain\Documents\Realtek 2020-06-10 20:40 - 2019-10-16 15:46 - 000003716 _____ C:\Users\elain\Documents\InstallPackage.bat 2020-06-10 20:40 - 2019-03-18 21:44 - 000281088 _____ (Microsoft Corporation) C:\Users\elain\Documents\pnputil.exe 2020-06-10 20:40 - 2019-01-22 15:01 - 000000569 _____ C:\Users\elain\Documents\InstallStep.txt 2020-06-10 20:39 - 2020-06-11 05:56 - 000000000 ____D C:\Users\elain\NCH Software Suite 2020-06-10 20:38 - 2020-06-10 20:38 - 036171046 _____ C:\Users\elain\Downloads\Audio_DCH_Realtek_Win10_64_V6088211.zip 2020-06-10 20:24 - 2020-06-11 06:15 - 000000311 _____ C:\WINDOWS\gethelp_audiotroubleshooter_latestpackage.zip 2020-06-10 19:31 - 2020-06-10 19:31 - 026271232 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 024265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 023431168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 019868160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 018766848 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 018066944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 011490816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 010921280 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 010336896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 009493504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 008895160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 008188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 007992320 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 007961824 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 007756288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 007593984 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 007591456 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 007069696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 006920192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 006404608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 006352896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 006173184 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 006069888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 006052352 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 005963472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 005858128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 005821952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 005420648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 005371536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 004880384 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 004783328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 004734976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 004629312 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 004484696 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 003925336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 003901952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 003860480 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 003859456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 003811776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 003810304 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2020-06-10 19:31 - 2020-06-10 19:31 - 003784192 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 003779896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2020-06-10 19:31 - 2020-06-10 19:31 - 003749376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Service.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 003547800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 003498216 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 003431424 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 003380736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 003332608 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 003304960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 003299840 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 002974720 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 002964992 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2020-06-10 19:31 - 2020-06-10 19:31 - 002918208 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 002827776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2020-06-10 19:31 - 2020-06-10 19:31 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 2020-06-10 19:31 - 2020-06-10 19:31 - 002744320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2020-06-10 19:31 - 2020-06-10 19:31 - 002685440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 002647040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 002631008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 002601472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 002585400 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 002413056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmcndmgr.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 002317312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 002284560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 002244608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 002202624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVidCtl.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 002198016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 002193736 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 002177536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001912320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmc.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 001876992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001869312 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001805184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2020-06-10 19:31 - 2020-06-10 19:31 - 001751424 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001714176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001710080 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001704960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmcndmgr.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001695744 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001686528 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001668384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001640960 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001583616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 001557816 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 001538136 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 001537024 _____ (Microsoft Corporation) C:\WINDOWS\system32\TaskFlowDataEngine.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001506816 _____ (Microsoft Corporation) C:\WINDOWS\system32\MoUsoCoreWorker.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 001493504 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpsharercom.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001476096 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001473024 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 001473024 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001470976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001448448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001430528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001413120 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 001411072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmc.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 001400216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001394032 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2020-06-10 19:31 - 2020-06-10 19:31 - 001357312 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMNetMgr.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001353216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001352232 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001337168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryPS.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001320448 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagperf.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001312256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001301592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001296384 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001255936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpsharercom.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001255736 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 001252864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001250816 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001233408 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001230848 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdclt.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 001218560 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdengin2.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001208832 _____ (Microsoft Corporation) C:\WINDOWS\system32\windowsperformancerecordercontrol.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001204968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 001197232 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 001194496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001150752 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 001126472 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001125888 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001111552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMNetMgr.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001105408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001078784 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdosys.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001071224 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001066304 _____ (Microsoft Corporation) C:\WINDOWS\system32\DismApi.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001047040 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001021440 _____ (Microsoft Corporation) C:\WINDOWS\system32\BTAGService.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001014872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001005056 _____ (Microsoft Corporation) C:\WINDOWS\system32\tapi3.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001004032 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi2fs.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001001984 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcRefreshTask.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 001001984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000975672 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000967680 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000961192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\InkObjCore.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000945152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000941056 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000937472 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000935936 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000908288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000907456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000906528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000902968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2020-06-10 19:31 - 2020-06-10 19:31 - 000902144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000897536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windowsperformancerecordercontrol.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000887296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MdmDiagnostics.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000886784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000886272 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000884736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000884224 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000880088 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000879104 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntimewindows.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000867840 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofmsvc.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000859136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imapi2fs.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000858624 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntime.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000855272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000854016 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000850944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tapi3.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000849920 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000837120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000832512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdosys.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000831016 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000803328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000802816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000801544 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000799232 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000798208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000784896 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000783360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000778752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.ConversationalAgent.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000764456 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000759608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DismApi.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000751616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000746808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000742912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapi.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000742400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000733184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BTAGService.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000725600 _____ (Microsoft Corporation) C:\WINDOWS\system32\StateRepository.Core.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000722944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000711680 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000711168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000706048 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000702976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000695720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000690176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000689664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InkObjCore.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000687104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000683008 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000682496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiaaut.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000677888 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000676560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000673792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000666624 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000640000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\agentactivationruntimewindows.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000635824 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000633856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\agentactivationruntime.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\azroles.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000632536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSCOMEX.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000614912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000613888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.ConversationalAgent.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000611840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000608768 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000607744 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000606880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000602184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryPS.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000601400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS 2020-06-10 19:31 - 2020-06-10 19:31 - 000600616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000598528 _____ (Microsoft Corporation) C:\WINDOWS\system32\psisdecd.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000596992 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2020-06-10 19:31 - 2020-06-10 19:31 - 000596992 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicesFlowBroker.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000588288 _____ (Microsoft Corporation) C:\WINDOWS\system32\msra.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000583608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StateRepository.Core.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000583168 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000580096 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr 2020-06-10 19:31 - 2020-06-10 19:31 - 000579072 _____ (Microsoft® Windows® Operating System) C:\WINDOWS\system32\wvc.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000577392 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000573752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys 2020-06-10 19:31 - 2020-06-10 19:31 - 000572928 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000569656 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000569344 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000568832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wiaaut.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000565760 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000563200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000562688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000556544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000553984 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000552448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000549888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000540480 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\IESettingSync.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000535552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000534016 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000530440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000528696 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizeng.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000520192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Launcher.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000519168 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi2.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000508720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000503808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FXSCOMEX.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000499712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr 2020-06-10 19:31 - 2020-06-10 19:31 - 000498688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\azroles.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000488096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000486912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000485888 _____ (Microsoft Corporation) C:\WINDOWS\system32\msTextPrediction.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000484352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\psisdecd.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000482624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000477184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Picker.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000475136 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000474112 _____ (Microsoft® Windows® Operating System) C:\WINDOWS\SysWOW64\wvc.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000469936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000468992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsregcmd.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000464896 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000463360 _____ (Microsoft Corporation) C:\WINDOWS\system32\iassdo.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000454968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2020-06-10 19:31 - 2020-06-10 19:31 - 000449536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wksprt.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000443704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000439808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WalletService.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000435200 _____ (Microsoft Corporation) C:\WINDOWS\system32\termmgr.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000434504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboutSettingsHandlers.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000432128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AarSvc.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000430592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000428680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000428544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mswmdm.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000422728 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DataModel.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000421376 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imapi2.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000418816 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000410592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000408576 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationApi.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000407864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spwizeng.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000399360 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMM.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000398848 _____ (Microsoft Corporation) C:\WINDOWS\system32\qdvd.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SpeechPrivacy.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000391680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManager.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Preview.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000373064 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000368640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000361472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\termmgr.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000359936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iassdo.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000352256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapibase.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswmdm.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000340992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\VAN.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000338944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Picker.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000335360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000332288 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpviewerax.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AarSvc.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys 2020-06-10 19:31 - 2020-06-10 19:31 - 000323072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LocationApi.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000321024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpr.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys 2020-06-10 19:31 - 2020-06-10 19:31 - 000312120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemSettings.DataModel.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RASMM.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000303616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WlanMM.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000299008 _____ (Microsoft Corporation) C:\WINDOWS\system32\CXHProvisioningServer.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000297984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000290816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Preview.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000287232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceDirectoryClient.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000286720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000285496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Dism.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\netman.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000272896 _____ (Microsoft Corporation) C:\WINDOWS\system32\InkEd.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000272384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpviewerax.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.FileExplorer.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000267776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000266240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mpg2splt.ax 2020-06-10 19:31 - 2020-06-10 19:31 - 000265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000264192 _____ (Microsoft Corporation) C:\WINDOWS\system32\wavemsp.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000259264 _____ (Microsoft Corporation) C:\WINDOWS\system32\logoncli.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcTok.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000253024 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000249856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VAN.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000249656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\FileHistory.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\RdpRelayTransport.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000244736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000242688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManagerClient.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000233984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000232448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InkEd.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000229376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000228664 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofm.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000226304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.FileExplorer.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wavemsp.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000223544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Dism.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdigest.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpdxm.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000217912 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000215552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pku2u.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000214840 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SIUF.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000214016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\cic.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mpg2splt.ax 2020-06-10 19:31 - 2020-06-10 19:31 - 000204000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityCenterBroker.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000203976 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsBroker.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000202752 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmidx.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000201536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000195240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcmnutils.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000195144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000192000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000190056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\logoncli.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000186368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wdigest.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasrecst.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000183296 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3mm.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000182784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netprofm.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000180024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys 2020-06-10 19:31 - 2020-06-10 19:31 - 000176440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000170488 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\msaatext.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpdxm.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cic.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000159032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys 2020-06-10 19:31 - 2020-06-10 19:31 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdrsvc.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000151864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleprn.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasnap.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000146944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmidx.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000146432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000143160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys 2020-06-10 19:31 - 2020-06-10 19:31 - 000142000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmcmnutils.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkspbrokerAx.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Feedback.Analog.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000134968 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000133744 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpapi.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasrecst.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000132744 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000131896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000131072 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssitlb.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdshext.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000126976 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkStatus.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAMM.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msaatext.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000118072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000116024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleprn.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imapi.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssitlb.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000110512 _____ (Microsoft Corporation) C:\WINDOWS\system32\devenum.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000107520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasnap.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthRadioMedia.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkspbrokerAx.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFolders.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\bindfltapi.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000101288 _____ (Microsoft Corporation) C:\WINDOWS\system32\FsIso.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmjpegdec.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000099640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryBroker.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\atl.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000093952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devenum.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000092952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WwanRadioManager.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx 2020-06-10 19:31 - 2020-06-10 19:31 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\UsoClient.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\RpcEpMap.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmjpegdec.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\atl.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasads.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000072704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx 2020-06-10 19:31 - 2020-06-10 19:31 - 000070968 _____ (Microsoft Corporation) C:\WINDOWS\system32\GameInput.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxGipRadioManager.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000068608 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanRadioManager.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtutils.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnrollCtrl.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000064840 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthHost.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000064016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000061752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GameInput.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssprxy.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryCore.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasads.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeUISrv.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\NfcRadioMedia.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagnosticdataquery.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000053760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtutils.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MdmDiagnosticsTool.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnrollCtrl.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000049664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\npmproxy.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000042320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryCore.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000041864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityCenterBrokerPS.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\atlthunk.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\atlthunk.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\CIDiag.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmproxy.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000028384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SecurityCenterBrokerPS.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimsg.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000024288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerEnc.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000020648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerEnc.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmsprep.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000013312 _____ C:\WINDOWS\system32\agentactivationruntimestarter.exe 2020-06-10 19:31 - 2020-06-10 19:31 - 000010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMAlertListener.ProxyStub.dll 2020-06-10 19:31 - 2020-06-10 19:31 - 000009265 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim 2020-06-10 19:31 - 2020-06-10 19:31 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DMAlertListener.ProxyStub.dll 2020-06-10 19:25 - 2020-06-02 21:53 - 000391168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe 2020-06-10 19:25 - 2020-06-02 21:51 - 000495616 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe 2020-06-10 18:29 - 2019-12-13 01:55 - 003306920 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE2.dll 2020-06-10 18:29 - 2019-12-13 01:55 - 002198112 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE.dll 2020-06-10 18:29 - 2019-12-13 01:55 - 001382336 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tosade.dll 2020-06-10 18:29 - 2019-12-13 01:55 - 001337744 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tossaeapo64.dll 2020-06-10 18:29 - 2019-12-13 01:55 - 000852240 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tosasfapo64.dll 2020-06-10 18:29 - 2019-12-13 01:55 - 000604896 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tossaemaxapo64.dll 2020-06-10 18:29 - 2019-12-13 01:55 - 000447280 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\toseaeapo64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 072520608 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoRes64.dat 2020-06-10 18:29 - 2019-12-13 01:54 - 007227992 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys 2020-06-10 18:29 - 2019-12-13 01:54 - 007178360 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEP64A.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 007101640 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64A.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 006270088 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64AF3.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 005346888 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv211.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 003776792 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 003676960 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl 2020-06-10 18:29 - 2019-12-13 01:54 - 003445872 _____ (DTS, Inc.) C:\WINDOWS\system32\slcnt64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 003353936 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 003284024 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RltkAPO.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 003168488 _____ (DTS, Inc.) C:\WINDOWS\system32\sltech64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 003159672 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 002930048 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 002444576 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv201.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 001971472 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64A.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 001965048 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64AF3.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 001787848 _____ (DTS) C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 001610848 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyAPOv251gm.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 001598288 _____ (DTS) C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 001544360 _____ (Dolby Laboratories) C:\WINDOWS\system32\DAX3APOProp.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 001516160 _____ (DTS) C:\WINDOWS\system32\DTSBoostDLL64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 001435272 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRRPTR64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 001397080 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SECOMN64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 001386888 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDHF64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 001372496 _____ (Dolby Laboratories) C:\WINDOWS\system32\DAX3APOv251.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 001353216 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 001294400 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEAPO64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 001287496 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyAPOvlldpgm.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 001259624 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOvlldp.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 001181000 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDRA64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 001159080 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOProp.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 001110280 _____ (DTS, Inc.) C:\WINDOWS\system32\sl3apo64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 001078792 _____ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SEHDHF32.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 001061672 _____ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SECOMN32.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000965152 _____ (Sony Corporation) C:\WINDOWS\system32\SFSS_APO.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000873592 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo264.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000814368 _____ (ICEpower A/S) C:\WINDOWS\system32\ICEsoundService64.exe 2020-06-10 18:29 - 2019-12-13 01:54 - 000751192 _____ (DTS) C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000734664 _____ (DTS) C:\WINDOWS\system32\DTSSymmetryDLL64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000715544 _____ (DTS) C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000692056 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000641624 _____ (ICEpower A/S) C:\WINDOWS\system32\ICEsoundAPO64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000541216 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSX64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000511536 _____ (DTS) C:\WINDOWS\system32\DTSNeoPCDLL64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000467264 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRAPO64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000453168 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EED64A.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000452632 _____ (DTS) C:\WINDOWS\system32\DTSLimiterDLL64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000448496 _____ (DTS) C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000416400 _____ (Harman) C:\WINDOWS\system32\HMUI.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000406344 _____ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2APIPCLL.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000392768 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEP64A.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000381536 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000378280 _____ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2API.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000367504 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64AF3.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000366016 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\HMAPO.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000360240 _____ (Harman) C:\WINDOWS\system32\HMClariFi.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000343808 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000341256 _____ (Synopsys, Inc.) C:\WINDOWS\SysWOW64\SRCOM.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000341256 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000332904 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64A.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000327168 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DHT64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000327168 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DAA64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000316080 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64F3.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000278376 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000266448 _____ (TODO: <Company name>) C:\WINDOWS\system32\slprp64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000261128 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPO64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000261096 _____ (DTS) C:\WINDOWS\system32\DTSLFXAPO64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000260104 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPONS64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000232024 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFNHK64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000230832 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSH64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000220280 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEED64A.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000218376 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSHP64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000203736 _____ (Harman) C:\WINDOWS\system32\HMHVS.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000193088 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000190824 _____ (Harman) C:\WINDOWS\system32\HMEQ_Voice.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000190824 _____ (Harman) C:\WINDOWS\system32\HMEQ.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000179488 _____ (Harman) C:\WINDOWS\system32\HMLimiter.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000175040 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSWOW64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000167232 _____ (ASUSTeK COMPUTER INC.) C:\WINDOWS\system32\ATKWMI.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000158800 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000157240 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEL64A.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000154256 _____ (Harman) C:\WINDOWS\system32\HarmanAudioInterface.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000139648 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEA64A.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000122216 _____ (Real Sound Lab SIA) C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000118488 _____ C:\WINDOWS\system32\AcpiServiceVnA64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000116432 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEL64A.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000105200 _____ C:\WINDOWS\system32\audioLibVc.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000093800 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEG64A.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000091016 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFCOM64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000090064 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEG64A.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000088424 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFAPO64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000083728 _____ (Virage Logic Corporation / Sonic Focus) C:\WINDOWS\SysWOW64\SFCOM.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000075648 _____ (TOSHIBA CORPORATION.) C:\WINDOWS\system32\tepeqapo64.dll 2020-06-10 18:29 - 2019-12-13 01:54 - 000023584 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll 2020-06-10 18:29 - 2019-12-13 00:37 - 037280673 _____ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT 2020-06-10 18:29 - 2019-12-13 00:37 - 005804772 _____ C:\WINDOWS\system32\Drivers\rtvienna.dat 2020-06-10 18:29 - 2019-12-13 00:37 - 000242934 _____ C:\WINDOWS\system32\ICEsoundService.bin 2020-06-03 07:27 - 2020-06-03 07:27 - 000000000 ___HD C:\$WinREAgent 2020-06-02 12:30 - 2020-06-02 12:35 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate 2020-06-02 12:30 - 2020-06-02 12:30 - 000000000 ____D C:\WINDOWS\system32\Intel 2020-06-02 12:29 - 2020-06-02 12:30 - 000000000 ____D C:\WINDOWS\ServiceProfiles 2020-06-02 12:29 - 2020-06-02 12:29 - 000008192 _____ C:\WINDOWS\system32\config\userdiff 2020-06-02 12:27 - 2020-06-02 12:27 - 000000000 ____D C:\Program Files\Reference Assemblies 2020-06-02 12:27 - 2020-06-02 12:27 - 000000000 ____D C:\Program Files\MSBuild 2020-06-02 12:27 - 2020-06-02 12:27 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies 2020-06-02 12:27 - 2020-06-02 12:27 - 000000000 ____D C:\Program Files (x86)\MSBuild 2020-06-02 12:27 - 2019-12-03 15:04 - 000781384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll 2020-06-02 12:27 - 2019-12-03 15:04 - 000105544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2020-06-02 12:27 - 2019-12-03 15:04 - 000037864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe 2020-06-02 12:27 - 2019-11-08 15:44 - 001168968 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll 2020-06-02 12:27 - 2019-11-08 15:44 - 000127056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll 2020-06-02 12:27 - 2019-11-08 15:44 - 000038072 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe 2020-06-02 11:46 - 2020-06-02 11:46 - 000000000 ____D C:\ProgramData\Microsoft OneDrive 2020-06-02 11:44 - 2020-06-29 06:26 - 000004162 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{6818F6E0-4385-41C2-94FE-1230EEA14738} 2020-06-02 11:44 - 2020-06-28 09:06 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2020-06-02 11:44 - 2020-06-10 20:47 - 000000000 ____D C:\WINDOWS\system32\Tasks\NCH Software 2020-06-02 11:44 - 2020-06-02 11:44 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task 2020-06-02 11:44 - 2020-06-02 11:44 - 000003348 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA 2020-06-02 11:44 - 2020-06-02 11:44 - 000003124 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore 2020-06-02 11:44 - 2020-06-02 11:44 - 000002974 _____ C:\WINDOWS\system32\Tasks\Update Checker 2020-06-02 11:44 - 2020-06-02 11:44 - 000002924 _____ C:\WINDOWS\system32\Tasks\ATK Package 36D18D69AFC3 2020-06-02 11:44 - 2020-06-02 11:44 - 000002858 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-131675017-3346686803-3792727656-1002 2020-06-02 11:44 - 2020-06-02 11:44 - 000002768 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task v2 2020-06-02 11:44 - 2020-06-02 11:44 - 000002702 _____ C:\WINDOWS\system32\Tasks\GarminUpdaterTask 2020-06-02 11:44 - 2020-06-02 11:44 - 000002646 _____ C:\WINDOWS\system32\Tasks\McAfee Remediation (Prepare) 2020-06-02 11:44 - 2020-06-02 11:44 - 000002486 _____ C:\WINDOWS\system32\Tasks\McAfeeLogon 2020-06-02 11:44 - 2020-06-02 11:44 - 000002338 _____ C:\WINDOWS\system32\Tasks\ASUS Hello 2020-06-02 11:44 - 2020-06-02 11:44 - 000002302 _____ C:\WINDOWS\system32\Tasks\ASUS Splendid ACMON 2020-06-02 11:44 - 2020-06-02 11:44 - 000002214 _____ C:\WINDOWS\system32\Tasks\ATK Package A22126881260 2020-06-02 11:44 - 2020-06-02 11:44 - 000000020 ___SH C:\Users\elain\ntuser.ini 2020-06-02 11:44 - 2020-06-02 11:44 - 000000000 ____D C:\WINDOWS\system32\Tasks\OfficeSoftwareProtectionPlatform 2020-06-02 11:44 - 2020-06-02 11:44 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla 2020-06-02 11:44 - 2020-06-02 11:44 - 000000000 ____D C:\WINDOWS\system32\Tasks\McAfee 2020-06-02 11:43 - 2020-06-02 11:44 - 000007623 _____ C:\WINDOWS\diagwrn.xml 2020-06-02 11:43 - 2020-06-02 11:44 - 000007623 _____ C:\WINDOWS\diagerr.xml 2020-06-02 11:40 - 2020-06-28 09:11 - 000933278 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2020-06-02 11:38 - 2020-06-10 19:31 - 002876416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2020-06-02 11:38 - 2020-06-05 00:15 - 000248968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys 2020-06-02 11:38 - 2018-03-12 07:20 - 000144848 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL 2020-06-02 11:38 - 2018-03-12 07:20 - 000119752 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL 2020-06-02 11:36 - 2020-06-27 11:31 - 000000000 ____D C:\Users\elain 2020-06-02 11:36 - 2019-12-07 02:10 - 000001105 _____ C:\Users\elain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2020-06-02 11:35 - 2020-06-29 10:41 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2020-06-02 11:35 - 2020-06-28 09:06 - 000008192 ___SH C:\DumpStack.log.tmp 2020-06-02 11:35 - 2020-06-10 20:07 - 001733016 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2020-06-02 10:48 - 2020-06-14 11:51 - 000000000 ___DC C:\WINDOWS\Panther 2020-06-02 10:46 - 2020-06-02 10:47 - 000000000 ___HD C:\$GetCurrent 2020-06-02 10:42 - 2020-06-02 10:42 - 000000000 ___HD C:\$Windows.~WS 2020-06-02 10:35 - 2020-06-02 10:48 - 000000036 _____ C:\WINDOWS\progress.ini 2020-06-01 14:04 - 2020-06-02 12:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileASSASSIN 2020-06-01 14:04 - 2020-06-01 14:04 - 000000000 ____D C:\Program Files (x86)\FileASSASSIN ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2020-06-29 10:47 - 2019-12-07 02:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2020-06-29 09:42 - 2019-11-27 22:18 - 000000000 ____D C:\ProgramData\MasterCook 15 2020-06-29 09:39 - 2019-11-30 06:56 - 000000000 ___RD C:\Users\elain\Desktop\HOME 2020-06-29 09:07 - 2019-11-29 13:01 - 000000000 ____D C:\Users\elain\Desktop\EMAIL 2020-06-29 06:26 - 2019-11-27 19:26 - 000000358 _____ C:\Users\elain\AppData\Roaming\sp_data.sys 2020-06-28 11:46 - 2019-12-09 09:32 - 000000000 ____D C:\Users\elain\AppData\Local\ElevatedDiagnostics 2020-06-28 09:11 - 2019-12-07 02:13 - 000000000 ____D C:\WINDOWS\INF 2020-06-28 09:06 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\ServiceState 2020-06-28 09:06 - 2019-11-28 11:28 - 000000000 __SHD C:\Users\elain\IntelGraphicsProfiles 2020-06-28 09:05 - 2019-12-07 02:03 - 000262144 _____ C:\WINDOWS\system32\config\BBI 2020-06-26 18:54 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2020-06-26 14:12 - 2019-12-07 02:14 - 000000000 ___HD C:\Program Files\WindowsApps 2020-06-26 14:12 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2020-06-26 12:07 - 2019-11-29 18:02 - 000000000 ____D C:\Scans3 2020-06-23 20:32 - 2019-12-06 17:02 - 000000000 ____D C:\Users\elain\AppData\LocalLow\Mozilla 2020-06-22 13:05 - 2019-11-27 22:33 - 000000000 ____D C:\Program Files (x86)\Google 2020-06-22 13:04 - 2019-11-27 22:33 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2020-06-16 06:45 - 2019-12-07 02:50 - 000000000 ____D C:\WINDOWS\system32\FxsTmp 2020-06-11 06:42 - 2019-11-30 17:36 - 000000000 ____D C:\Users\elain\Desktop\APPS-SHARED 2020-06-11 06:32 - 2019-11-22 06:54 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM 2020-06-11 06:32 - 2019-11-22 06:54 - 000000000 ____D C:\WINDOWS\system32\DAX3 2020-06-11 06:32 - 2019-11-22 06:54 - 000000000 ____D C:\WINDOWS\system32\DAX2 2020-06-11 06:32 - 2019-11-22 06:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Realtek 2020-06-11 05:56 - 2019-12-16 09:52 - 000000000 ____D C:\ProgramData\Autoplay Menu Designer 2020-06-11 05:56 - 2019-12-07 02:52 - 000000000 ____D C:\Program Files\Windows Portable Devices 2020-06-11 05:56 - 2019-12-07 02:52 - 000000000 ____D C:\Program Files\Windows Photo Viewer 2020-06-11 05:56 - 2019-12-07 02:52 - 000000000 ____D C:\Program Files\Windows Multimedia Platform 2020-06-11 05:56 - 2019-12-07 02:52 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices 2020-06-11 05:56 - 2019-12-07 02:52 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2020-06-11 05:56 - 2019-12-07 02:52 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform 2020-06-11 05:56 - 2019-12-07 02:50 - 000000000 ____D C:\WINDOWS\system32\OpenSSH 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ___SD C:\WINDOWS\system32\UNP 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ___SD C:\WINDOWS\system32\F12 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ___SD C:\WINDOWS\system32\dsc 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ___RD C:\WINDOWS\PrintDialog 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Licenses 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Keywords 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\InputMethod 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\IME 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\downlevel 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Com 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SystemResources 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\Sysprep 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\setup 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\oobe 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\MUI 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\migwiz 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\Macromed 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\Licenses 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\Keywords 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\InputMethod 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\IME 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\ias 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\downlevel 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\Dism 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\Com 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\appraiser 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\ShellExperiences 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\ShellComponents 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\schemas 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\Provisioning 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\IME 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\DiagTrack 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\Containers 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\Branding 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\bcastdvr 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\Program Files\Common Files\System 2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared 2020-06-11 05:56 - 2019-12-07 02:03 - 000000000 ____D C:\WINDOWS\servicing 2020-06-11 05:56 - 2019-12-03 13:06 - 000000000 ____D C:\Program Files\Microsoft Silverlight 2020-06-11 05:11 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\registration 2020-06-11 04:12 - 2018-05-09 11:24 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2020-06-10 22:39 - 2019-12-13 09:07 - 000000000 ____D C:\Users\elain\Downloads\programs and such 2020-06-10 22:39 - 2019-12-02 18:27 - 000000000 ____D C:\ProgramData\FLEXnet 2020-06-10 22:39 - 2019-11-27 22:18 - 000000000 ____D C:\Users\Public\Documents\MasterCook 15 2020-06-10 22:39 - 2019-11-27 22:18 - 000000000 ____D C:\ProgramData\Documents\MasterCook 15 2020-06-10 22:39 - 2019-11-27 22:10 - 000000000 ____D C:\Users\elain\AppData\Roaming\Tabs3 2020-06-10 20:47 - 2019-12-15 13:48 - 000000000 ____D C:\Users\elain\Downloads\recipes 2020-06-10 20:39 - 2019-12-03 10:16 - 000001260 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Zip File Compression.lnk 2020-06-10 20:39 - 2019-12-03 08:24 - 000000000 ____D C:\Users\elain\AppData\Roaming\NCH Software 2020-06-10 19:33 - 2019-12-07 02:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2020-06-05 08:35 - 2019-11-30 06:56 - 000000000 ____D C:\Users\elain\Desktop\OFFICE 2020-06-05 00:15 - 2019-12-02 12:57 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys 2020-06-04 18:11 - 2019-11-28 11:28 - 000000000 ____D C:\Users\elain\AppData\Local\Packages 2020-06-04 12:41 - 2020-01-21 13:03 - 000000000 ____D C:\ProgramData\Garmin 2020-06-04 12:41 - 2019-12-07 02:14 - 000000000 __RHD C:\Users\Public\Libraries 2020-06-04 12:41 - 2019-12-03 10:51 - 000000000 ____D C:\Users\Public\Documents\MAGIX 2020-06-04 12:41 - 2019-12-03 10:51 - 000000000 ____D C:\ProgramData\Documents\MAGIX 2020-06-04 12:41 - 2019-12-02 15:43 - 000000000 ____D C:\Users\Public\Documents\Hewlett-Packard 2020-06-04 12:41 - 2019-12-02 15:43 - 000000000 ____D C:\ProgramData\Documents\Hewlett-Packard 2020-06-04 12:41 - 2019-01-18 11:39 - 000000000 __RHD C:\Users\Public\AccountPictures 2020-06-04 12:15 - 2019-12-12 13:49 - 000000000 ____D C:\Users\Public\Documents\Reallusion 2020-06-04 12:15 - 2019-12-12 13:49 - 000000000 ____D C:\ProgramData\Documents\Reallusion 2020-06-04 12:15 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\appcompat 2020-06-04 12:15 - 2019-11-29 17:29 - 000000000 ____D C:\Users\Public\Documents\ACT 2020-06-04 12:15 - 2019-11-29 17:29 - 000000000 ____D C:\ProgramData\Documents\ACT 2020-06-03 10:32 - 2019-12-03 18:52 - 000000000 ____D C:\ProgramData\Packages 2020-06-03 07:27 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\Drivers\DriverData 2020-06-02 17:20 - 2019-12-02 17:13 - 000000000 ____D C:\Users\elain\AppData\Local\D3DSCache 2020-06-02 12:35 - 2020-01-29 09:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BleachBit 2020-06-02 12:35 - 2020-01-21 13:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin 2020-06-02 12:35 - 2020-01-09 09:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW 7 2020-06-02 12:35 - 2020-01-05 08:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Act! Pro 2020-06-02 12:35 - 2019-12-20 12:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Abrosoft FantaMorph 3 2020-06-02 12:35 - 2019-12-16 17:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2020-06-02 12:35 - 2019-12-16 16:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\muvee Reveal 12 2020-06-02 12:35 - 2019-12-16 15:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArtRage 6 2020-06-02 12:35 - 2019-12-16 15:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArtRage 2 Deluxe 2020-06-02 12:35 - 2019-12-16 14:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Magic 2020-06-02 12:35 - 2019-12-16 09:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autoplay Menu Designer 5 2020-06-02 12:35 - 2019-12-13 09:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewBlue 2020-06-02 12:35 - 2019-12-12 14:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrazyTalk Animator 2 Training DVD 2020-06-02 12:35 - 2019-12-12 13:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrazyTalk Animator 3 Fundamentals Training Videos 2020-06-02 12:35 - 2019-12-12 13:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cartoon Animator 4 2020-06-02 12:35 - 2019-12-08 11:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Instant Photo Effects 2 2020-06-02 12:35 - 2019-12-07 02:14 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template 2020-06-02 12:35 - 2019-12-07 02:14 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files 2020-06-02 12:35 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase 2020-06-02 12:35 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\spool 2020-06-02 12:35 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\NDF 2020-06-02 12:35 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\Cursors 2020-06-02 12:35 - 2019-12-03 15:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Family Historian 2020-06-02 12:35 - 2019-12-03 13:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2020-06-02 12:35 - 2019-12-03 12:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2020-06-02 12:35 - 2019-12-03 10:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Personal Historian 3 2020-06-02 12:35 - 2019-12-03 10:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RootsMagic 7 2020-06-02 12:35 - 2019-12-03 08:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Legacy 9.0 2020-06-02 12:35 - 2019-12-03 08:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 5 SDK 2020-06-02 12:35 - 2019-12-03 08:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HotDocs 11 2020-06-02 12:35 - 2019-12-02 19:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WordPerfect Office 2002 2020-06-02 12:35 - 2019-12-02 18:40 - 000000000 ____D C:\WINDOWS\SHELLNEW 2020-06-02 12:35 - 2019-12-02 18:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Second Copy 8 2020-06-02 12:35 - 2019-12-02 18:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stamps.com 2020-06-02 12:35 - 2019-12-02 16:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2008 R2 2020-06-02 12:35 - 2019-12-02 15:14 - 000000000 ____D C:\WINDOWS\SysWOW64\1033 2020-06-02 12:35 - 2019-12-02 15:14 - 000000000 ____D C:\WINDOWS\system32\1033 2020-06-02 12:35 - 2019-12-02 12:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2020-06-02 12:35 - 2019-12-02 10:18 - 000000000 ____D C:\Program Files\UNP 2020-06-02 12:35 - 2019-11-27 22:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MasterCook 15 2020-06-02 12:35 - 2019-11-22 06:54 - 000000000 ____D C:\Program Files\Intel 2020-06-02 12:35 - 2019-11-22 06:43 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated 2020-06-02 12:35 - 2019-11-22 06:43 - 000000000 ____D C:\WINDOWS\system32\MsDtc 2020-06-02 12:35 - 2019-01-18 12:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS 2020-06-02 12:34 - 2019-11-22 06:49 - 000000000 ____D C:\WINDOWS\InfusedApps 2020-06-02 12:30 - 2020-02-07 11:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Better Homes and Gardens 2020-06-02 12:30 - 2019-12-16 16:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serif Applications 2020-06-02 12:30 - 2019-12-13 08:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VEGAS 2020-06-02 12:30 - 2019-12-11 12:38 - 000000000 ____D C:\ProgramData\DisplayLink 2020-06-02 12:30 - 2019-12-11 10:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 2020-06-02 12:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\Resources 2020-06-02 12:30 - 2019-12-03 10:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX 2020-06-02 12:30 - 2019-12-02 19:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Corel WordPerfect Suite 8 2020-06-02 12:30 - 2019-12-02 16:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2008 2020-06-02 12:30 - 2019-11-27 22:14 - 000000000 ____D C:\Users\elain\AppData\Local\PlaceholderTileLogoFolder 2020-06-02 12:30 - 2019-11-22 06:54 - 000000000 ____D C:\Program Files\Realtek 2020-06-02 12:30 - 2019-01-18 12:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ICEpower 2020-06-02 12:28 - 2019-12-07 02:18 - 000000000 ____D C:\WINDOWS\Setup 2020-06-02 12:27 - 2019-12-07 02:10 - 000383488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnet.dll 2020-06-02 12:27 - 2019-12-07 02:10 - 000215552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplayx.dll 2020-06-02 12:27 - 2019-12-07 02:10 - 000060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnathlp.dll 2020-06-02 12:27 - 2019-12-07 02:10 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpwsockx.dll 2020-06-02 12:27 - 2019-12-07 02:10 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpmodemx.dll 2020-06-02 12:27 - 2019-12-07 02:10 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnsvr.exe 2020-06-02 12:27 - 2019-12-07 02:10 - 000020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplaysvr.exe 2020-06-02 12:27 - 2019-12-07 02:10 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhupnp.dll 2020-06-02 12:27 - 2019-12-07 02:10 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhpast.dll 2020-06-02 12:27 - 2019-12-07 02:10 - 000005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnlobby.dll 2020-06-02 12:27 - 2019-12-07 02:10 - 000005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnaddr.dll 2020-06-02 12:27 - 2019-12-07 02:09 - 000494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnet.dll 2020-06-02 12:27 - 2019-12-07 02:09 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnathlp.dll 2020-06-02 12:27 - 2019-12-07 02:09 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnsvr.exe 2020-06-02 12:27 - 2019-12-07 02:09 - 000010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhupnp.dll 2020-06-02 12:27 - 2019-12-07 02:09 - 000010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhpast.dll 2020-06-02 12:27 - 2019-12-07 02:09 - 000006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnlobby.dll 2020-06-02 12:27 - 2019-12-07 02:09 - 000006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnaddr.dll 2020-06-02 11:44 - 2019-12-07 02:14 - 000000000 ____D C:\ProgramData\USOPrivate 2020-06-02 11:44 - 2019-12-07 02:14 - 000000000 ____D C:\Program Files\Windows Defender 2020-06-02 11:44 - 2019-12-07 02:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM 2020-06-02 11:44 - 2019-11-28 11:28 - 000000000 ___RD C:\Users\elain\3D Objects 2020-06-02 11:37 - 2020-04-14 14:05 - 000000000 ____D C:\Users\elain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps 2020-06-02 11:12 - 2019-12-12 08:40 - 000002143 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2020-06-02 10:46 - 2020-05-27 08:42 - 000000738 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 10 Update Assistant.lnk 2020-06-02 10:46 - 2020-05-27 08:42 - 000000000 ____D C:\Windows10Upgrade 2020-06-02 10:46 - 2020-05-26 23:19 - 000000000 ____D C:\ESD 2020-06-01 22:52 - 2019-12-07 02:18 - 000835480 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2020-06-01 22:52 - 2019-12-07 02:18 - 000179608 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2020-06-01 14:08 - 2020-01-29 09:42 - 000000000 ____D C:\Users\elain\.dbus-keyrings ==================== Files in the root of some directories ======== 2019-12-02 15:06 - 2019-12-02 16:33 - 192307320 _____ (Swiftpage Act! LLC ) C:\Users\elain\AppData\Roaming\act2010update8ss.exe 2020-01-05 08:31 - 2020-01-05 08:32 - 193313114 _____ (Swiftpage Act! LLC ) C:\Users\elain\AppData\Roaming\act2010update9ss.exe 2019-12-02 16:40 - 2019-12-02 16:40 - 000000000 ____H () C:\Users\elain\AppData\Roaming\ActUpdate.log 2020-06-22 07:34 - 2020-06-22 07:34 - 000114688 _____ () C:\Users\elain\AppData\Roaming\JfQPKiheALIH 2020-06-22 07:34 - 2020-06-22 07:34 - 000000662 _____ () C:\Users\elain\AppData\Roaming\JfQPKiheALIH.cMD 2019-12-02 16:21 - 2020-01-05 08:35 - 000032305 _____ () C:\Users\elain\AppData\Roaming\NGEN_AppLog_Install.txt 2019-12-02 16:28 - 2020-01-05 08:24 - 000009727 _____ () C:\Users\elain\AppData\Roaming\NGEN_AppLog_Uninstall.txt 2019-12-02 19:21 - 2019-12-02 19:21 - 000012358 _____ () C:\Users\elain\AppData\Roaming\PFP100JCM.{PB 2019-12-02 19:21 - 2019-12-02 19:21 - 000061678 _____ () C:\Users\elain\AppData\Roaming\PFP100JPR.{PB 2020-06-22 07:33 - 2020-06-22 07:33 - 000114688 _____ () C:\Users\elain\AppData\Roaming\puWJErhMmRyz 2020-06-22 07:33 - 2020-06-22 07:33 - 000000662 _____ () C:\Users\elain\AppData\Roaming\puWJErhMmRyz.cMD 2019-11-27 19:26 - 2020-06-29 06:26 - 000000358 _____ () C:\Users\elain\AppData\Roaming\sp_data.sys 2019-12-16 09:08 - 2019-12-16 09:08 - 000001167 _____ () C:\Users\elain\AppData\Roaming\trace_FilterInstaller.txt 2019-12-16 09:08 - 2019-12-16 09:08 - 000000000 _____ () C:\Users\elain\AppData\Roaming\trace_FilterInstaller.txt-CRT.txt 2020-05-16 11:10 - 2020-05-16 11:10 - 000071000 _____ () C:\Users\elain\AppData\Roaming\WvMSIJCpwORq 2020-05-16 11:10 - 2020-05-16 11:10 - 000000662 _____ () C:\Users\elain\AppData\Roaming\WvMSIJCpwORq.Cmd 2019-12-16 16:20 - 2019-12-16 18:22 - 000007168 _____ () C:\Users\elain\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2020-04-14 10:09 - 2020-04-14 10:09 - 000007601 _____ () C:\Users\elain\AppData\Local\Resmon.ResmonCfg ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ======================== LOG FROM ADDITION.TXT: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-06-2020 Ran by elain (29-06-2020 10:59:02) Running from C:\Users\elain\Downloads Windows 10 Home Version 2004 19041.329 (X64) (2020-06-02 18:44:21) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-131675017-3346686803-3792727656-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-131675017-3346686803-3792727656-503 - Limited - Disabled) eepic (S-1-5-21-131675017-3346686803-3792727656-1005 - Limited - Enabled) elain (S-1-5-21-131675017-3346686803-3792727656-1002 - Administrator - Enabled) => C:\Users\elain Guest (S-1-5-21-131675017-3346686803-3792727656-501 - Limited - Enabled) tax46 (S-1-5-21-131675017-3346686803-3792727656-1004 - Limited - Enabled) WDAGUtilityAccount (S-1-5-21-131675017-3346686803-3792727656-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 64 Bit HP CIO Components Installer (HKLM\...\{345F3F90-0505-4EDF-B7A9-5E3AC1AC6CE4}) (Version: 15.2.1 - Hewlett-Packard) Hidden Abrosoft FantaMorph 3.7 (HKLM-x32\...\Abrosoft FantaMorph 3_is1) (Version: 3.7 - Abrosoft) Act! Pro (HKLM-x32\...\{EFE72412-EEF7-4F36-BEBF-05760A66F4D8}) (Version: 20.1.0.0 - Swiftpage ACT! LLC) Hidden Act! Pro (HKLM-x32\...\InstallShield_{EFE72412-EEF7-4F36-BEBF-05760A66F4D8}) (Version: 20.1.0.0 - Swiftpage ACT! LLC) Adobe Acrobat 9 Pro - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7760-000000000004}{AC76BA86-1033-F400-7760-000000000004}) (Version: 9.0.0 - Adobe Systems) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 20.009.20067 - Adobe Systems Incorporated) Adobe Photoshop 7.0 (HKLM-x32\...\Adobe Photoshop 7.0) (Version: 7.0 - Adobe Systems, Inc.) ANT Drivers Installer x64 (HKLM\...\{99B72734-4395-42D0-ADFD-A9722A7AD7B0}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ArtRage 2 Deluxe (HKLM-x32\...\{58936A21-4252-4188-AC6A-440F867BDB00}) (Version: 2.5.20 - Ambient Design) ArtRage 6 (HKLM\...\{7AF6962D-016E-4084-ADF8-84891B95D815}) (Version: 6.1.2.0 - Ambient Design) Hidden ArtRage 6 (HKLM-x32\...\ArtRage 6 6.1.2.0) (Version: 6.1.2.0 - Ambient Design) ASUS Device Activation (HKLM-x32\...\{9C4B0706-9F9A-47BF-B417-0A111FC52B04}) (Version: 1.0.5.0 - ASUSTeK COMPUTER INC.) ASUS GiftBox Service (HKLM-x32\...\{4701E5AB-AF91-4D40-8F18-358CC80E4E5B}) (Version: 3.2.3.0 - ASUSTeK COMPUTER INC.) ASUS Hello (HKLM-x32\...\{D8CE1923-92A9-4036-817E-9E0D8AA2169B}) (Version: 1.1.4.0 - ASUSTeK COMPUTER INC.) ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.6.8 - ASUSTeK COMPUTER INC.) ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 3.23.0001 - ASUS) ATK Package (ASUS Keyboard Hotkeys) (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0060 - ASUSTeK COMPUTER INC.) AudioWizard (HKLM-x32\...\{57E770A2-2BAF-4CAA-BAA3-BD896E2254D3}) (Version: 1.0.8.8 - ICEpower a/s) Autoplay Menu Designer - Additional Templates Packs (HKLM-x32\...\Autoplay Menu Designer - Additional Templates Packs_is1) (Version: - Visual Designing) Autoplay Menu Designer 5.3 (HKLM-x32\...\Autoplay Menu Designer 5_is1) (Version: - Visual Designing) Avanquest Message (HKU\S-1-5-21-131675017-3346686803-3792727656-1002\...\{20573C69-4A68-4BEF-A23D-365CB66924CE}) (Version: 2.10.0 - Avanquest Software) BleachBit 3.0 (HKLM-x32\...\BleachBit) (Version: 3.0 - BleachBit) Cartoon Animator v4.11 Pipeline (HKLM-x32\...\{9400CD28-76E6-48F2-B8EE-00697D8E72B3}) (Version: 4.11.1123.1 - Reallusion Inc.) Chrome Remote Desktop Host (HKLM-x32\...\{FEA4124F-FABE-440B-BA03-489722A59439}) (Version: 84.0.4147.39 - Google Inc.) Corel Applications (HKLM-x32\...\Corel Applications) (Version: - ) Corel WordPerfect Suite 8 (HKLM-x32\...\Corel WordPerfect Suite 😎 (Version: - ) CrazyTalk Animator 2 Training DVD (HKLM-x32\...\{699FB10B-82FA-4DD6-A9F3-93B54C4772ED}) (Version: 2.0.0328.1 - Reallusion) CrazyTalk Animator 3 Fundamentals Training Videos (HKLM-x32\...\{C12EAE1C-2CBC-48DB-8A6E-F0EF74EDD48D}) (Version: 3.0.0725.1 - Reallusion) Debut Video Capture Software (HKLM-x32\...\Debut) (Version: 5.05 - NCH Software) Doxillion Document Converter (HKLM-x32\...\Doxillion) (Version: 3.19 - NCH Software) DVD Architect (HKLM-x32\...\{1D8D144F-3558-11E9-A3D6-00155D6302F2}) (Version: 7.0.100 - VEGAS) Elevated Installer (HKLM-x32\...\{EDCD0A1B-09BE-493A-B871-13F86760A5D0}) (Version: 6.19.4.0 - Garmin Ltd or its subsidiaries) Hidden Express Scribe Transcription Software (HKLM-x32\...\Scribe) (Version: 8.26 - NCH Software) Express Zip File Compression (HKLM-x32\...\ExpressZip) (Version: 7.18 - NCH Software) FaceGen Modeller 3.3 Free (HKLM-x32\...\{7DCFE14B-8F0E-47BF-863A-84757F038D7C}) (Version: 3.3.0 - Singular Inversions Inc.) Family Historian 6.2.7 (HKLM-x32\...\family_historian_is1) (Version: - Calico Pie Limited) Family Historian PDF (novaPDF 7.7 printer) (HKLM\...\Family Historian PDF_is1) (Version: 7.7.400 - Softland) FileASSASSIN (HKLM-x32\...\FileASSASSIN) (Version: 1.06 - Malwarebytes) Garmin Express (HKLM-x32\...\{0a5a7c12-97db-47da-874c-cfeeeac5676f}) (Version: 6.19.4.0 - Garmin Ltd or its subsidiaries) Garmin Express (HKLM-x32\...\{DD4EE84A-E101-4F03-A881-AF498F68811C}) (Version: 6.19.4.0 - Garmin Ltd or its subsidiaries) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 83.0.4103.116 - Google LLC) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden HD Camcorder Add-on (HKLM-x32\...\{3DB8CE13-3DDF-4FC0-93C1-C70B69388B34}) (Version: 1.0.38.7596 - muvee Technologies Pte Ltd) Home Designer Suite 8 (HKLM-x32\...\{900792CC-3203-356C-EC2D-C3E558991ACE}) (Version: 8.4.1.8 - Chief Architect Inc) HotDocs Developer 11 (64bit) (HKLM\...\{712012F2-9C95-4618-B075-9B0B82265652}) (Version: 11.00.3077 - HotDocs Corporation) Instant Photo Effects 2.0 (HKLM-x32\...\Photon) (Version: - ) Integration Services Patch for Act! (HKLM-x32\...\{58AEEE89-2CD8-45D0-BC80-A9F5E3DE465C}) (Version: 1.0.1150.0 - Integration Services Patch for Act!) Intel(R) Chipset Device Software (HKLM-x32\...\{44ded3eb-1686-46a6-9770-fd79096c29f7}) (Version: 10.1.1.45 - Intel(R) Corporation) Hidden Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\...\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.3.10208.5644 - Intel Corporation) Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1069 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 23.20.16.4973 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.9.1.1020 - Intel Corporation) Intel(R) Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.49.166.0 - Intel Corporation) Hidden Intel(R) Trusted Connect Services Client (HKLM-x32\...\{df682aff-4294-4ad1-aaa7-276931d5781f}) (Version: 1.49.166.0 - Intel Corporation) Hidden Legacy 9.0 (HKLM-x32\...\Legacy 9.0) (Version: 9.0 - Millennia Corporation) Magic v2.12 (64-bit) (HKLM\...\{15E5FBA4-6FD2-4AAD-B56E-BDC40E417F41}_is1) (Version: 2.12 - Color & Music, LLC) MAGIX Analogue Modelling Suite Plus (HKLM\...\{F485F2FE-1D3D-4F6D-AD4E-13FA5FB22A88}) (Version: 1.0.0.0 - MAGIX Software GmbH) Hidden MAGIX Analogue Modelling Suite Plus (HKLM\...\MX.{F485F2FE-1D3D-4F6D-AD4E-13FA5FB22A88}) (Version: 1.0.0.0 - MAGIX Software GmbH) MAGIX Content and Soundpools (HKLM-x32\...\MAGIX_GlobalContent) (Version: 1.0.0.0 - MAGIX Software GmbH) MAGIX Samplitude Music Studio (HKLM\...\{9258C82B-1DC4-4C2E-A039-316021B08965}) (Version: 24.0.0.36 - MAGIX Software GmbH) Hidden MAGIX Samplitude Music Studio (HKLM\...\MX.{9258C82B-1DC4-4C2E-A039-316021B08965}) (Version: 24.0.0.36 - MAGIX Software GmbH) MAGIX Samplitude Music Studio (Object synthesizers) (HKLM\...\{9F11D8E5-A862-4482-AFD1-F829ABFBC403}) (Version: 1.0.0.0 - MAGIX Software GmbH) Hidden MAGIX Samplitude Music Studio (Object synthesizers) (HKLM-x32\...\MX.{9F11D8E5-A862-4482-AFD1-F829ABFBC403}) (Version: 1.0.0.0 - MAGIX Software GmbH) MAGIX Soundpool Music Maker - Feel good (HKLM\...\{62ED0962-0942-4859-8448-D350614BF248}) (Version: 1.0.0.0 - MAGIX Software GmbH) Hidden MAGIX Soundpools 2019 (HKLM\...\{14AE7BED-9521-4436-9D83-533D263E5349}) (Version: 1.0.0.0 - MAGIX Software GmbH) Hidden MAGIX Speed burnR (HKLM\...\{CB82E569-C28F-4140-A7C0-0ACD70D1D0AB}) (Version: 7.0.1.27 - MAGIX Software GmbH) Hidden MAGIX Speed burnR (HKLM-x32\...\MX.{CB82E569-C28F-4140-A7C0-0ACD70D1D0AB}) (Version: 7.0.1.27 - MAGIX Software GmbH) MAGIX Vandal VST-PlugIn (HKLM\...\{24F96DED-7B99-49C4-B877-CDCDC37762FA}) (Version: 1.0.0.0 - MAGIX Software GmbH) Hidden MAGIX Vandal VST-PlugIn (HKLM\...\MX.{24F96DED-7B99-49C4-B877-CDCDC37762FA}) (Version: 1.0.0.0 - MAGIX Software GmbH) MAGIX VariVerb II VST-PlugIn (HKLM\...\{7A97538C-6D3F-4BB5-B2A1-D0ECFB199A4C}) (Version: 1.0.0.0 - MAGIX Software GmbH) Hidden MAGIX VariVerb II VST-PlugIn (HKLM\...\MX.{7A97538C-6D3F-4BB5-B2A1-D0ECFB199A4C}) (Version: 1.0.0.0 - MAGIX Software GmbH) Malwarebytes version 4.1.0.56 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.1.0.56 - Malwarebytes) MasterCook 15 (HKLM-x32\...\{1E492158-401F-434B-957B-477D6B5A46AA}) (Version: 15.00.24 - Valusoft Cosmi) Microsoft ODBC Driver 11 for SQL Server (HKLM\...\{A106FA6F-E94C-44C9-8A0F-C34BD82C9FE6}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft Office Home and Student 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-131675017-3346686803-3792727656-1002\...\OneDriveSetup.exe) (Version: 19.232.1124.0008 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation) Microsoft Silverlight 5 SDK (HKLM-x32\...\{E1FBB3D4-ADB0-4949-B101-855DA061C735}) (Version: 5.0.61118.0 - Microsoft Corporation) Microsoft SQL Server 2008 R2 (64-bit) (HKLM\...\Microsoft SQL Server 2008 R2) (Version: - Microsoft Corporation) Microsoft SQL Server 2008 R2 Native Client (HKLM\...\{2180B33F-3225-423E-BBC1-7798CFD3CD1F}) (Version: 10.50.1600.1 - Microsoft Corporation) Microsoft SQL Server 2008 R2 Setup (English) (HKLM\...\{6D10FB2C-82A9-40F2-91D0-7BE64CF0DAF2}) (Version: 10.50.1600.1 - Microsoft Corporation) Microsoft SQL Server 2008 Setup Support Files (HKLM\...\{B40EE88B-400A-4266-A17B-E3DE64E94431}) (Version: 10.1.2731.0 - Microsoft Corporation) Microsoft SQL Server Browser (HKLM-x32\...\{BF9BF038-FE03-429D-9B26-2FA0FD756052}) (Version: 10.50.1600.1 - Microsoft Corporation) Microsoft Sync Framework 2.0 Core Components (x64) ENU (HKLM\...\{8CCBEC22-D2DB-4DC9-A58A-E1A1F3A38C8A}) (Version: 2.0.1578.0 - Microsoft Corporation) Microsoft Sync Framework 2.0 Core Components (x86) ENU (HKLM-x32\...\{FF63121D-91C6-42CC-B341-F1AA729728E7}) (Version: 2.0.1578.0 - Microsoft Corporation) Microsoft Sync Framework 2.0 Provider Services (x64) ENU (HKLM\...\{03AC245F-4C64-425C-89CF-7783C1D3AB2C}) (Version: 2.0.1578.0 - Microsoft Corporation) Microsoft Sync Framework 2.0 Provider Services (x86) ENU (HKLM-x32\...\{D3A80508-CD83-4CA3-8671-914A1BC78B61}) (Version: 2.0.1578.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{90ffcee5-8608-4e94-8c18-a4feb4f83fb8}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.23.27820 (HKLM-x32\...\{45231ab4-69fd-486a-859d-7a59fcd11013}) (Version: 14.23.27820.0 - Microsoft Corporation) Microsoft Visual FoxPro OLE DB Provider (HKLM-x32\...\{3DA245C5-23B1-4874-BFA7-287B7D6C1EF6}) (Version: 1.0.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.60724 - Microsoft Corporation) Microsoft VSS Writer for SQL Server 2014 (HKLM\...\{366CD715-2FF4-40B4-A8B4-A05E5D21A945}) (Version: 12.0.2000.8 - Microsoft Corporation) Movie Studio 15.0 Platinum (HKLM\...\{1A9D1980-DDE6-11E8-804F-9C6873244263}) (Version: 15.0.157 - VEGAS) Movie Studio 16.0 Platinum (HKLM\...\{616969A1-0193-11EA-B40D-A6CFD62728D8}) (Version: 16.0.167 - VEGAS) Mozilla Firefox 76.0.1 (x64 en-US) (HKLM\...\Mozilla Firefox 76.0.1 (x64 en-US)) (Version: 76.0.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 71.0 - Mozilla) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) Music Maker (HKLM\...\{DC21CFD5-02AC-4C89-8D35-85506A9FEB55}) (Version: 28.0.2.43 - MAGIX Software GmbH) Hidden Music Maker (HKLM-x32\...\MX.{DC21CFD5-02AC-4C89-8D35-85506A9FEB55}) (Version: 28.0.2.45 - MAGIX Software GmbH) Music Maker Update (HKLM\...\{20C81740-F574-48DF-929A-99B4BCD3F2D9}) (Version: 28.0.2.45 - MAGIX Software GmbH) Hidden muvee Adrenaline Rush stylePack (HKLM-x32\...\{D52DB394-76CF-75C8-7C83-B7D5D478A05F}) (Version: 8.0.0.14850 - muvee Technologies Pte Ltd) muvee American Journal stylePack (HKLM-x32\...\{F30C1B19-5BAD-451A-A797-DF77E8375215}) (Version: 6.00.100 - muvee Technologies) muvee Back To School Style (HKLM-x32\...\{C15540B8-4D1F-2510-A140-8B8EC95E93A7}) (Version: 6.1.38.8069 - muvee Technologies Pte Ltd) muvee California pack (HKLM-x32\...\{0DB19E6B-F160-8526-75F8-13D54D083F51}) (Version: 8.0.1.17059 - muvee Technologies Pte Ltd) muvee Christmas Cheer stylePack (HKLM-x32\...\{3F837C38-92C4-4DC3-8824-E3E41377C143}) (Version: 4.00.100 - ) muvee Christmas stylePack (HKLM-x32\...\{231FB9C0-4ABF-439E-8D24-C006D2252360}) (Version: 5.00.102 - muvee Technologies) muvee coolStyles 1 (HKLM-x32\...\{92518780-C904-409C-B674-528822FEA6E2}) (Version: 6.00.108 - muvee Technologies) muvee coolStyles 2 (HKLM-x32\...\{AFB057E3-03AF-420D-9E85-F846739CE211}) (Version: 6.00.108 - muvee Technologies) muvee corePack (HKLM-x32\...\{1B0BD0D6-D7D1-4D49-9815-5A85081ECC45}) (Version: 6.00.105 - muvee Technologies) muvee efx stylePack (HKLM-x32\...\{05F6E091-D014-41AA-AC4F-E3F7AECA9F3D}) (Version: 5.00.100 - muvee Technologies) muvee Essentials pack (HKLM-x32\...\{93C61B28-0D1F-0A68-F6AD-50BF7AEE152A}) (Version: 8.0.1.17085 - muvee Technologies Pte Ltd) muvee Halloween Horrors Style (HKLM-x32\...\{E156B26A-7BF2-9B28-26D7-AB3BC75B0BBB}) (Version: 6.1.38.8069 - muvee Technologies Pte Ltd) muvee Halloween stylePack (HKLM-x32\...\{BB66B899-A0E2-48F3-856B-D6053ECF03E0}) (Version: 6.00.103 - muvee Technologies) muvee Hi-Octane stylePack (HKLM-x32\...\{EB320D1D-16E2-45AE-AE48-7952D3E9542C}) (Version: 5.00.100 - muvee Technologies) muvee Independence Day Style (HKLM-x32\...\{195B9E5D-CB08-45D0-8374-974924E81D16}) (Version: 6.1.38.8069 - muvee Technologies Pte Ltd) muvee Keep It All stylePack (HKLM-x32\...\{C2912FA4-7263-4F0E-831F-0BF0160CFA28}) (Version: 4.00.100 - muvee Technologies) muvee Kids stylePack (HKLM-x32\...\{886EA322-81B7-4DB8-BA8E-5300243A3CFD}) (Version: 4.00.100 - muvee Technologies) muvee Laurence Gartel stylePack (HKLM-x32\...\{07195CBF-8D91-499E-8BB2-510A6F5544EA}) (Version: 5.00.100 - muvee Technologies) muvee Life Story Style (HKLM-x32\...\{3D2BAE84-7CD4-7911-BDE7-673E03BAC9AA}) (Version: 9.0.1.20252 - muvee Technologies Pte Ltd) muvee Mix It Up stylePack (HKLM-x32\...\{C3FD195E-1FEA-4B93-97ED-B74AA7115D56}) (Version: 6.1.36.6339 - muvee Technologies Pte Ltd) muvee Photo-Centric stylePack (HKLM-x32\...\{F7344B66-C8AA-4597-B73E-08BBF449EE26}) (Version: 4.00.100 - muvee Technologies) muvee photoFocus stylePack (HKLM-x32\...\{C69362F6-C6AD-43DD-835D-E0F897BE99F7}) (Version: 6.1.37.7135 - muvee Technologies Pte Ltd) muvee photoGenie stylePack (HKLM-x32\...\{A022E277-568F-E87B-A091-CE1933698A5E}) (Version: 8.0.0.14850 - muvee Technologies Pte Ltd) muvee photoMemories stylePack (HKLM-x32\...\{2C14545B-8EE2-4994-B0C0-07A666DB37B9}) (Version: 5.00.100 - muvee Technologies) muvee Pro Classic stylePack (HKLM-x32\...\{F4AD1D69-B6AF-48C3-AF65-CB39C2BFFEC3}) (Version: 5.00.104 - muvee Technologies) muvee Pro Modern stylePack (HKLM-x32\...\{9A1686DD-E593-4556-8BD1-426A3F28A263}) (Version: 5.00.104 - muvee Technologies) muvee Reveal 12 (HKLM-x32\...\{120D679C-3A3A-B700-AD88-CD1106010D56}) (Version: 12.0.0.27842 - muvee Technologies Pte Ltd) muvee Reveal Runtime (HKLM-x32\...\{86EFEB9A-FE52-40FE-9FA7-47108D4FADA9}) (Version: 12.0.0.27842 - muvee Technologies Pte Ltd) muvee Soccer stylePack (HKLM-x32\...\{4314E111-3621-4613-BD2B-0736DA8EFAA9}) (Version: 5.00.100 - muvee Technologies) muvee Spring Break stylePack (HKLM-x32\...\{13B1CEE2-9513-42CF-8D10-36D83DE7E912}) (Version: 6.00.100 - muvee Technologies) muvee Style Pack 1 & 2 (HKLM-x32\...\{AD1CE924-4897-4BA3-AEF9-F491716FE493}) (Version: 1.00.101 - ) muvee Valentine stylePack (HKLM-x32\...\{A03087D3-3E28-4FCE-9799-59A314AC95E2}) (Version: 4.00.100 - muvee Technologies) muvee Wedding stylePack (HKLM-x32\...\{1DE5377D-C99D-CC34-068B-336677C163CE}) (Version: 8.0.0.14850 - muvee Technologies Pte Ltd) Nero 12 (HKLM-x32\...\{560FC78C-A4B2-461D-9B47-820C1EEF87B8}) (Version: 12.0.02000 - Nero AG) Nero 2014 Content Pack (HKLM-x32\...\{204A26F0-01B8-4656-8607-5CCEDE820BC2}) (Version: 15.0.00200 - Nero AG) NewBlue Filters 5 Recolor (HKLM-x32\...\NewBlue Filters 5 Recolor) (Version: 5.0.180730 - NewBlue) NewBlue Transitions 5 Ultimate (HKLM-x32\...\NewBlue Transitions 5 Ultimate) (Version: 5.0.180730 - NewBlue) Open XML SDK 2.0 for Microsoft Office (HKLM-x32\...\{171D8D76-3F05-455A-A8AF-C561C2679905}) (Version: 2.0.5022 - Microsoft Corporation) Personal Historian 3.0.2.0 (HKLM-x32\...\{76BD4014-A57B-4EA7-BB81-2A1E687915AA}_is1) (Version: - RootsMagic, Inc.) Photopea PSD Editor Plug-in v1.0 for Cartoon Animator (HKLM-x32\...\{EDAFF67C-096E-4A7B-B3CD-8CFAB4384934}) (Version: 1.0.1016.1 - Reallusion Inc.) PhotoStage Slideshow Producer (HKLM-x32\...\PhotoStage) (Version: 5.15 - NCH Software) Pixillion Image Converter (HKLM-x32\...\Pixillion) (Version: 6.15 - NCH Software) Prerequisite installer (HKLM-x32\...\{3AAB08A3-F129-4BD5-B409-AE674F93759D}) (Version: 12.0.0002 - Nero AG) Hidden Prerequisite installer (HKLM-x32\...\{5909A89E-C97F-407C-AE2B-47BDED86BF5D}) (Version: 15.0.0005 - Nero AG) Hidden Prism Video File Converter (HKLM-x32\...\Prism) (Version: 4.07 - NCH Software) QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.8858.1 - Realtek Semiconductor Corp.) RootsMagic 7.0.4.0 (HKLM-x32\...\{D6286873-A757-4A4D-A6EF-0081B3EE32CA}_is1) (Version: RootsMagic 7.0.4.0 - RootsMagic, Inc.) Second Copy 8 (HKLM-x32\...\Second Copy 8_is1) (Version: 8.1.2.0 - Centered Systems) Serif DrawPlus X6 (HKLM\...\{8A8AB2D3-53DE-4A65-8D35-68A09AA1AD7A}) (Version: 13.0.3.26 - Serif (Europe) Ltd) Serif PhotoPlus X6 (HKLM\...\{CCD2C5E4-F484-4499-BCB3-61E787416757}) (Version: 16.0.1.029 - Serif (Europe) Ltd) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft) SQL Server 2008 R2 Common Files (HKLM\...\{234F6B0D-10AE-4BB7-B2F3-E48D4861952D}) (Version: 10.50.1600.1 - Microsoft Corporation) Hidden SQL Server 2008 R2 Common Files (HKLM\...\{36F70DEE-1EBF-4707-AFA2-E035EEAEBAA1}) (Version: 10.50.1600.1 - Microsoft Corporation) Hidden SQL Server 2008 R2 Database Engine Services (HKLM\...\{FA7394B8-CE65-4F9E-AC99-F372AD365424}) (Version: 10.50.1600.1 - Microsoft Corporation) Hidden SQL Server 2008 R2 Database Engine Services (HKLM\...\{FBD367D1-642F-47CF-B79B-9BE48FB34007}) (Version: 10.50.1600.1 - Microsoft Corporation) Hidden SQL Server 2008 R2 Database Engine Shared (HKLM\...\{A2122A9C-A699-4365-ADF8-68FEAC125D61}) (Version: 10.50.1600.1 - Microsoft Corporation) Hidden SQL Server 2008 R2 Database Engine Shared (HKLM\...\{C942A025-A840-4BF2-8987-849C0DD44574}) (Version: 10.50.1600.1 - Microsoft Corporation) Hidden Sql Server Customer Experience Improvement Program (HKLM\...\{6476DB81-F263-4C04-8574-AAD31136C304}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden Sql Server Customer Experience Improvement Program (HKLM\...\{F31183CF-E10F-4DE1-BB59-6C0FF38E481E}) (Version: 10.50.1600.1 - Microsoft Corporation) Hidden Stamps.com (HKLM-x32\...\{698AC01B-DF0C-4BCE-940C-EB29AD23A560}) (Version: 16.3.0.3873 - Stamps.com, Inc.) Hidden Stamps.com (HKLM-x32\...\Stamps.com) (Version: 16.3.0.3873 - Stamps.com, Inc.) Stamps.com Address Book Support for ACT! 3.05 - 6.0 (HKLM-x32\...\{831AA8FB-B67A-48E0-95FF-D609BC31AF0C}) (Version: 6.2.0.1488 - Stamps.com, Inc.) Hidden Stamps.com Address Book Support for Common Harmony (HKLM-x32\...\{D00324C0-5343-4917-BF1E-D5E45D22B7E8}) (Version: 6.2.0.1488 - Stamps.com, Inc.) Hidden Stamps.com Address Book Support for Outlook Express, Works, IE (HKLM-x32\...\{9E404AA6-7C63-4D95-B8D2-72256ABB6A9E}) (Version: 6.2.0.1488 - Stamps.com, Inc.) Hidden Stamps.com Application Support for Corel WordPerfect 9 (HKLM-x32\...\{BE0C8089-BE6E-466D-A79E-E5D2AE089FE9}) (Version: 6.2.0.1488 - Stamps.com, Inc.) Hidden Stamps.com support for ACT! 3.05 - 6.0 (HKLM-x32\...\Stamps.com support for ACT! 3.05 - 6.0) (Version: - Stamps.com, Inc.) Stamps.com support for Corel WordPerfect 9 (HKLM-x32\...\Stamps.com support for Corel WordPerfect 9) (Version: - Stamps.com, Inc.) Stamps.com support for Harmony (HKLM-x32\...\Stamps.com support for Harmony) (Version: - Stamps.com, Inc.) Stamps.com support for Outlook Express, Works, IE (HKLM-x32\...\Stamps.com support for Outlook Express, Works, IE) (Version: - Stamps.com, Inc.) UFR II Printer Driver Uninstaller (HKLM\...\Canon UFR II Printer Driver) (Version: 6, 3, 1, 0 - Canon Inc.) Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{32DC821E-4A7D-4878-BEE8-337FA153D7F2}) (Version: 2.63.0.0 - Microsoft Corporation) Hidden Update for Windows 10 for x64-based Systems (KB4480730) (HKLM\...\{3BAE4496-6F6C-4330-A8AA-B93D3D346FA5}) (Version: 2.53.0.0 - Microsoft Corporation) VideoPad Video Editor (HKLM-x32\...\VideoPad) (Version: 6.00 - NCH Software) Vita 2 (HKLM\...\{40161542-D9DF-4601-AA60-E969B017FB48}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden Vita 2 add-on content (HKLM\...\{946AF57B-74AA-4F40-AA9A-732438F81D0B}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden Vita 2 common (HKLM\...\{C7B5259E-11DC-4B21-BBDD-DDAAA88C1F36}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden Vita Accordion (HKLM\...\{C9106851-C36F-4EBA-A17C-58B40C7397CB}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden Vita Choir (HKLM\...\{9098B857-4CC8-4399-AF6A-0A0A59352487}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden Vita Church Organ (HKLM\...\{ED854B8E-17E3-4A38-80C5-F4DF85C1F540}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden Vita Cinematic Soundscapes (HKLM\...\{8DDAE083-BECC-4675-AB3E-D9BC3BF16F38}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden Vita Cinematic Synth (HKLM\...\{A90ABDBE-D391-461E-A928-EF0F0DC7628D}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden Vita Concert Grand (HKLM\...\{29691FB3-299F-4675-B899-851183C4BF92}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden Vita Concert Grand LE (HKLM\...\{57C401B8-C121-462E-A2B1-9E9EE57875A8}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden Vita Drum Engine (HKLM\...\{46038AEE-DD50-49FC-A69F-F9D64D83D6FA}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden Vita Folk (HKLM\...\{2A3B3E17-A261-4999-AAE3-6ECCFDFE1CA7}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden Vita Grand Piano (HKLM\...\{27741FAD-2C70-45FB-AF5E-F69DD4561AEA}) (Version: 2.5.0.286 - MAGIX Software GmbH) Hidden Vita Jazz Drums (HKLM\...\{8E867DF7-58FE-48B9-83AD-43FA9D982A01}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden Vita Lead Synth (HKLM\...\{61DE70FD-A4A9-4ACB-8B50-C79D30F31F09}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden Vita Orchestral Ensemble (HKLM\...\{0EAA851B-DD1E-4371-A815-97A22E2C78CE}) (Version: 2.5.0.286 - MAGIX Software GmbH) Hidden Vita Pop Drums (HKLM\...\{5109B03D-84D7-4D22-B9E1-56C025EE61B9}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden Vita Rock Drums (HKLM\...\{5C33024E-0633-4D90-8294-66F4D074DC70}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden Vita Sansula (HKLM\...\{AA80E297-5415-47C9-B1EA-3BA27F2B60CD}) (Version: 2.5.0.286 - MAGIX Software GmbH) Hidden Vita Soundtrack Percussion (HKLM\...\{9987EF58-80B1-4803-8A91-3F53BA564206}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden Voxal Voice Changer (HKLM-x32\...\Voxal) (Version: 2.00 - NCH Software) Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-2) (Version: 1.0.65.1 - LunarG, Inc.) Hidden WavePad Sound Editor (HKLM-x32\...\WavePad) (Version: 8.00 - NCH Software) Welcome App (Start-up experience) (HKLM-x32\...\{828175FA-7307-4DBF-95AD-9CEE086B6F45}) (Version: 12.0.14000 - Nero AG) Hidden Windows 10 Update Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.23072 - Microsoft Corporation) Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.) Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software) WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 3.2.10.0 - ASUSTeK COMPUTER INC.) WordPerfect Office 2002 Professional (HKLM-x32\...\{F73E7B59-F951-11D4-884D-00902761A46D}) (Version: 10 - Corel) Hidden Packages: ========= ASUS GIFTBOX -> C:\Program Files\WindowsApps\B9ECED6F.ASUSGIFTBOX_3.1.8.0_x64__qmba6cd70vzyy [2020-06-11] (ASUSTeK COMPUTER INC.) ASUS Product Registration Program -> C:\Program Files\WindowsApps\B9ECED6F.ASUSProductRegistrationProgram_3.0.3.0_x86__qmba6cd70vzyy [2020-06-11] (ASUSTeK COMPUTER INC.) [Startup Task] Canon Office Printer Utility -> C:\Program Files\WindowsApps\34791E63.CanonOfficePrinterUtility_12.7.0.0_x64__6e5tt8cgb93ep [2020-06-11] (Canon Inc.) Cortana -> C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_2.2005.5739.0_x64__8wekyb3d8bbwe [2020-06-11] (Microsoft Corporation) [Startup Task] HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_115.1.152.0_x64__v10z8vjag6ke6 [2020-06-11] (HP Inc.) Microsoft Access -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Access_16051.12827.20336.0_x86__8wekyb3d8bbwe [2020-06-15] (Microsoft Corporation) Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2020-06-11] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2020-06-11] (Microsoft Corporation) [MS Ad] Microsoft Excel -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Excel_16051.12827.20336.0_x86__8wekyb3d8bbwe [2020-06-15] (Microsoft Corporation) Microsoft Office Desktop Apps -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop_16051.12827.20336.0_x86__8wekyb3d8bbwe [2020-06-15] (Microsoft Corporation) Microsoft Outlook -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.12827.20336.0_x86__8wekyb3d8bbwe [2020-06-15] (Microsoft Corporation) Microsoft PowerPoint -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.PowerPoint_16051.12827.20336.0_x86__8wekyb3d8bbwe [2020-06-15] (Microsoft Corporation) Microsoft Publisher -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Publisher_16051.12827.20336.0_x86__8wekyb3d8bbwe [2020-06-15] (Microsoft Corporation) Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.7.5012.0_x64__8wekyb3d8bbwe [2020-06-11] (Microsoft Studios) [MS Ad] Microsoft Word -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Word_16051.12827.20336.0_x86__8wekyb3d8bbwe [2020-06-15] (Microsoft Corporation) MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x64__8wekyb3d8bbwe [2020-06-11] (Microsoft Corporation) [MS Ad] MyASUS -> C:\Program Files\WindowsApps\B9ECED6F.ASUSPCAssistant_2.2.22.0_x64__qmba6cd70vzyy [2020-06-15] (ASUSTeK COMPUTER INC.) MyASUS-Service Center -> C:\Program Files\WindowsApps\B9ECED6F.MyASUS_3.3.11.0_x86__qmba6cd70vzyy [2020-06-11] (ASUSTeK COMPUTER INC.) [Startup Task] Photos Add-on -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2017.39121.36610.0_x64__8wekyb3d8bbwe [2020-06-11] (Microsoft Corporation) Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2020-06-11] (Microsoft Corporation) Skype -> C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c [2020-06-25] (Skype) [Startup Task] Xbox 360 SmartGlass -> C:\Program Files\WindowsApps\Microsoft.XboxCompanion_1.4.3.0_x64__8wekyb3d8bbwe [2020-06-11] (Microsoft Corporation) [MS Ad] ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat Elements\ContextMenu64.dll [2008-06-11] (Adobe Systems, Incorporated -> Adobe Systems Inc.) ContextMenuHandlers1: [ExpressZip] -> {8EEA165E-0B8B-4BA7-9796-50214C767171} => C:\Program Files (x86)\NCH Software\ExpressZip\ezcm64.dll [2019-12-03] () [File not signed] [File is in use] ContextMenuHandlers1: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => c:\PROGRA~1\mcafee\msc\MCCTXM~1.DLL -> No File ContextMenuHandlers1-x32: [Zeon.MFCDirectShellExt] -> {353C642C-F13D-4699-9FF2-EFAF490B6C69} => C:\Program Files (x86)\HotDocs\bin\DirectShellExt.dll [2008-12-17] (Zeon International Investment Corp.) [File not signed] [File is in use] ContextMenuHandlers3-x32: [FAExt] -> {05672D66-9736-42F5-8BEB-FA1DD3CA51C4} => C:\Program Files (x86)\FileASSASSIN\FileASSASSINExt.dll [2007-03-30] (Malwarebytes) [File not signed] [File is in use] ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-12-02] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_ca6dea73b8394fc3\igfxDTCM.dll [2018-03-12] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) ContextMenuHandlers6: [Adobe.Acrobat.ContextMenu] -> {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat Elements\ContextMenu64.dll [2008-06-11] (Adobe Systems, Incorporated -> Adobe Systems Inc.) ContextMenuHandlers6: [ExpressZip] -> {8EEA165E-0B8B-4BA7-9796-50214C767171} => C:\Program Files (x86)\NCH Software\ExpressZip\ezcm64.dll [2019-12-03] () [File not signed] [File is in use] ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-12-02] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers6: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => c:\PROGRA~1\mcafee\msc\MCCTXM~1.DLL -> No File ==================== Codecs (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Drivers32: [vidc.tscc] => C:\Windows\SysWOW64\tsccvid.dll [102400 2006-04-30] (TechSmith Corporation) [File not signed] [File is in use] ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) Shortcut: C:\Users\elain\Pictures\PHOTOS\Chronological Photos\2016-2020\2018\12\craigslist_facebook_marketplace\chair\Extras\Adobe Reader Download.lnk -> hxxp://get.adobe.com/reader ShortcutWithArgument: C:\Users\elain\Desktop\APPS-SHARED\Chrome Remote Desktop.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=efmjfjelnicpmdcmfikempdhlmainjcb ShortcutWithArgument: C:\Users\elain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome Remote Desktop.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=efmjfjelnicpmdcmfikempdhlmainjcb ==================== Loaded Modules (Whitelisted) ============= 2020-06-04 13:32 - 2020-06-04 13:32 - 000032256 _____ ((c)2013 Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Shared.7319adae#\1596a776eef6ed93cc32358b405cf97c\Act.Shared.UI.Utilities.ni.dll 2017-10-03 14:45 - 2017-10-03 14:45 - 000147968 _____ () [File not signed] [File is in use] C:\Program Files (x86)\ASUS\Splendid\CCTAdjust.dll 2017-10-24 13:24 - 2017-10-24 13:24 - 000036864 _____ () [File not signed] [File is in use] C:\Program Files (x86)\ASUS\Splendid\DetectDisplayDC.dll 2017-06-21 12:51 - 2017-06-21 12:51 - 000029184 _____ () [File not signed] [File is in use] C:\Program Files (x86)\ASUS\Splendid\VideoEnhance.dll 2019-09-09 07:13 - 2019-09-09 07:13 - 001364992 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\CefSharp.Core.dll 2019-12-12 13:34 - 2019-12-12 13:34 - 000073216 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\FixBootSector.dll 2017-05-08 09:35 - 2017-05-08 09:35 - 000325632 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\GpsImgWrapper.dll 2019-07-27 08:57 - 2019-07-27 08:57 - 096071680 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\libcef.dll 2019-12-03 10:16 - 2019-12-03 10:16 - 000105984 _____ () [File not signed] [File is in use] C:\Program Files (x86)\NCH Software\ExpressZip\ezcm64.dll 2019-12-12 13:34 - 2019-12-12 13:34 - 001976832 _____ (Apache Software Foundation) [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\XercesLib.dll 2017-10-24 13:24 - 2017-10-24 13:24 - 000073216 _____ (ASUS TeK Computer Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ASUS\Splendid\ApplyLUT.dll 2017-10-24 13:24 - 2017-10-24 13:24 - 000242688 _____ (ASUS TeK Computer Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ASUS\Splendid\GenLUT.dll 2017-10-24 13:24 - 2017-10-24 13:24 - 000407040 _____ (ASUSTeK Computer Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ASUS\Splendid\ColorU.dll 2019-12-12 13:36 - 2019-12-12 13:36 - 000234496 _____ (Dynastream Innovations Inc.) [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\ANT_WrappedLib.dll 2019-12-12 13:34 - 2019-12-12 13:34 - 002711552 _____ (Garmin International) [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\legacyio.dll 2017-05-08 09:35 - 2017-05-08 09:35 - 000343552 _____ (Garmin International, Inc.) [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\IMG_GPSMAP.dll 2019-12-12 13:34 - 2019-12-12 13:34 - 000425472 _____ (Garmin) [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\XMLdll.dll 2020-06-04 13:32 - 2020-06-04 13:32 - 000332288 _____ (Infragistics, Inc.) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Infragisticaa8fcf78#\a05d2d62d2b01c83efefaf9d6069f574\Infragistics.Act.Shared.ni.dll 2020-06-04 13:32 - 2020-06-04 13:32 - 002721792 _____ (Infragistics, Inc.) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Infragisticcc7b0f04#\e24bda6ab167d19752d195bb4dd04034\Infragistics.Act.Win.UltraWinSchedule.ni.dll 2020-06-04 13:32 - 2020-06-04 13:32 - 003194880 _____ (Infragistics, Inc.) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Infragistics.Act.Win\783b3c56dd01a351cbd7724a45a02056\Infragistics.Act.Win.ni.dll 2019-12-12 13:35 - 2019-12-12 13:35 - 000090112 _____ (Silicon Laboratories, Inc.) [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\DSI_SiUSBXp_3_1.DLL 2020-06-04 13:31 - 2020-06-04 13:31 - 000089600 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Data.ActDb\ec52c807f6ad3c3abff5ef03812e3007\Act.Data.ActDb.ni.dll 2020-06-04 13:31 - 2020-06-04 13:31 - 002308608 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Data.Resources\e71976dd4029228c0cf55d8b5759be17\Act.Data.Resources.ni.dll 2020-06-04 13:31 - 2020-06-04 13:31 - 000128000 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Data\60e6cf8d33e7cb0f3956a0772d6d421a\Act.Data.ni.dll 2020-06-04 13:31 - 2020-06-04 13:31 - 000757760 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Framewo2acccfe4#\ea3bd7794350889d5bbb0ac468863277\Act.Framework.BusinessLink.LinkConnector.ni.dll 2020-06-04 13:31 - 2020-06-04 13:31 - 000573440 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Framewoa7c82375#\86a56207f9f56fe3dc3ee97ca9f848f1\Act.Framework.BusinessLink.Synchronization.ni.dll 2020-06-04 13:31 - 2020-06-04 13:31 - 001558528 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Framewob25cef3d#\044293dbcb154e68db8814b39b6ccecc\Act.Framework.Synchronization.ni.dll 2020-06-04 13:31 - 2020-06-04 13:31 - 000048640 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Outlook22f3a37f#\088adc401713c181cfbb4ac4ba534fa3\Act.Outlook.Service.Interfaces.ni.dll 2020-06-04 13:31 - 2020-06-04 13:31 - 000096768 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Outlook267d4dc5#\7f4e3ae363f842202ac0fa71fb35d82e\Act.Outlook.Service.AppCommon.ni.dll 2020-06-04 13:31 - 2020-06-04 13:31 - 000590336 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Outlooke08b44a0#\38e34a27787918cc932b1dc46c8b3774\Act.Outlook.Service.Shared.ni.dll 2020-06-04 13:31 - 2020-06-04 13:31 - 000129536 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Shared.3cd8e10e#\ffefab3a4a05397d04c0ed90bd935173\Act.Shared.Diagnostics.ni.dll 2020-06-04 13:31 - 2020-06-04 13:31 - 000123904 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Shared.4c707719#\908ca214147784d9a986bbef1d32b88e\Act.Shared.Localization.ni.dll 2020-06-04 13:31 - 2020-06-04 13:31 - 000163840 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Shared.7f9f27da#\c34918a8c4f2d7e6ab840e80d5b7213c\Act.Shared.ComponentModel.ni.dll 2020-06-04 13:32 - 2020-06-04 13:32 - 000327680 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Shared.85fb1d61#\1209f4dc29ddf01c2e7376a7d4c852ba\Act.Shared.Wpf.Controls.ni.dll 2020-06-04 13:31 - 2020-06-04 13:31 - 000210432 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Shared.c5db5c3f#\e4cd1e058763522058c4f038ab2b3be5\Act.Shared.Collections.ni.dll 2020-06-04 13:31 - 2020-06-04 13:31 - 000088576 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Shared.Config\76464817175fcd5e1ab0159c159ff601\Act.Shared.Config.ni.dll 2020-06-04 13:32 - 2020-06-04 13:32 - 004396032 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Shared.dbaddaae#\b6daac94460ee84cfeec3ea962057bde\Act.Shared.Windows.Forms.ni.dll 2020-06-04 13:31 - 2020-06-04 13:31 - 020137984 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Shared.Images\74f8fbf5a96bb32aee227e36cb70d520\Act.Shared.Images.ni.dll 2020-06-04 13:31 - 2020-06-04 13:31 - 000033280 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Shared.Licensing\338a703fd605dd1069358899513652ec\Act.Shared.Licensing.ni.dll 2020-06-04 13:32 - 2020-06-04 13:32 - 000192000 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Shared.Utilities\affe52b4be87328e92b0b964de040ed1\Act.Shared.Utilities.ni.dll 2020-06-04 13:32 - 2020-06-04 13:32 - 000709120 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Shared.Win32\c1806d7db1cc3d7b49f619d795d3584a\Act.Shared.Win32.ni.dll 2019-07-27 08:57 - 2019-07-27 08:57 - 000762368 _____ (The Chromium Authors) [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\chrome_elf.dll 2017-10-24 13:24 - 2017-10-24 13:24 - 000403968 _____ (TODO: <Company name>) [File not signed] [File is in use] C:\Program Files (x86)\ASUS\Splendid\ColorUGameDLL.dll 2017-10-24 13:24 - 2017-10-24 13:24 - 000029184 _____ (TODO: <Company name>) [File not signed] [File is in use] C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll ==================== Alternate Data Streams (Whitelisted) ======== (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:065D25EE [358] AlternateDataStreams: C:\ProgramData\TEMP:0FD841FF [183] ==================== Safe Mode (Whitelisted) ================== ==================== Association (Whitelisted) ================= ==================== Internet Explorer trusted/restricted ========== ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2018-04-11 16:38 - 2018-04-11 16:36 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\iCLS\;C:\Program Files\Intel\Intel(R) Management Engine Components\iCLS\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;C:\Program Files\Microsoft SQL Server\100\Tools\Binn\;C:\Program Files\Microsoft SQL Server\100\DTS\Binn\;C:\Program Files (x86)\QuickTime\QTSystem\ HKU\S-1-5-21-131675017-3346686803-3792727656-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\asus\wallpapers\asus.jpg DNS Servers: 8.8.8.8 - 192.168.10.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: ) Windows Firewall is disabled. ==================== MSCONFIG/TASK MANAGER disabled items == (If an entry is included in the fixlist, it will be removed.) HKLM\...\StartupApproved\Run32: => "Dropbox" HKU\S-1-5-21-131675017-3346686803-3792727656-1002\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-131675017-3346686803-3792727656-1002\...\StartupApproved\Run: => "QMxNetworkSync" ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{7937A23F-4657-4188-9457-FAF470AF86FD}] => (Allow) C:\Program Files\Microsoft SQL Server\MSSQL10_50.ACT7\MSSQL\Binn\sqlservr.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{4850843C-0430-4FB5-BAA3-FFE763DCC770}] => (Allow) C:\Program Files\Microsoft SQL Server\MSSQL10_50.ACT7\MSSQL\Binn\sqlservr.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{8442A8D1-4753-4E3F-9DCF-662D0CBC722D}] => (Allow) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{236ACDD7-F5D8-4559-A0C4-8A032888137C}] => (Allow) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{D518AACE-6F0D-4586-9E08-AD8B9BFFA7D7}] => (Allow) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Arvato Digital Services Canada Inc -> arvato digital services llc) FirewallRules: [{B9C6EF4E-6B21-4802-B858-54103B8D4291}] => (Allow) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Arvato Digital Services Canada Inc -> arvato digital services llc) FirewallRules: [{6A18A6F3-39DB-4704-91F7-1CD2F5A96FD9}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act.Server.Host.exe (Microsoft) [File not signed] [File is in use] FirewallRules: [{02071AC5-D228-43A3-A76F-DD9E4F11A50B}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act.Server.Host.exe (Microsoft) [File not signed] [File is in use] FirewallRules: [{70844CA0-C060-44EA-AAAA-F3557B9DFA85}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act15.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC) FirewallRules: [{63878C5B-3FD8-4303-A890-87437C2F143F}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act15.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC) FirewallRules: [{969F5F75-56EE-47A4-8DA3-5BD2DA816E9D}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\ActEmail.exe (Swiftpage ACT! LLC) [File not signed] [File is in use] FirewallRules: [{F2643FF6-2E76-4955-A7C5-E96F2D57E1F0}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\ActEmail.exe (Swiftpage ACT! LLC) [File not signed] [File is in use] FirewallRules: [{AE864CF9-995C-4B98-8716-78DD49B3332D}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act!.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC) FirewallRules: [{16388773-440C-48B9-BF22-C5837945412C}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act!.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC) FirewallRules: [{83FC276E-33E3-4217-91AA-A44EDC29B817}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{31C55C18-67E1-4E6B-8DC4-2593FACE9F1C}] => (Allow) C:\Program Files\MAGIX\Samplitude Music Studio\2019\MusicStudio.exe (MAGIX Software GmbH -> MAGIX Software GmbH) FirewallRules: [{39748117-8DC5-4243-8A67-459AB864FD0B}] => (Allow) C:\Program Files (x86)\MAGIX\Music Maker\28\MusicMaker.exe (MAGIX Software GmbH -> MAGIX Software GmbH) FirewallRules: [{E5C68139-03F6-450A-A955-0E815383C78C}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{A71D9024-5534-4BC3-A544-6685DDCEEBC4}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [UDP Query User{286A06A9-321A-4AE1-AA2D-87F5925E46A6}C:\program files (x86)\corel\wordperfect office 2002\register\navbrowser.exe] => (Allow) C:\program files (x86)\corel\wordperfect office 2002\register\navbrowser.exe (Naviant, Inc.) [File not signed] [File is in use] FirewallRules: [TCP Query User{0F755A48-DDCE-48BB-A641-36796431C436}C:\program files (x86)\corel\wordperfect office 2002\register\navbrowser.exe] => (Allow) C:\program files (x86)\corel\wordperfect office 2002\register\navbrowser.exe (Naviant, Inc.) [File not signed] [File is in use] FirewallRules: [{5829778B-927D-4645-9F6C-73BDB1FCE1AD}] => (Allow) C:\Program Files\Microsoft SQL Server\MSSQL10_50.ACT7\MSSQL\Binn\sqlservr.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{587B3420-16CC-45B7-AA9C-D433045051E6}] => (Allow) C:\Program Files\Microsoft SQL Server\MSSQL10_50.ACT7\MSSQL\Binn\sqlservr.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{898CFB39-3F1E-434B-990E-4190707B2424}] => (Allow) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{AB7FB710-7411-4776-A8A9-519BB83AA1F9}] => (Allow) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{23CF8E6F-D7B4-4EC6-AECC-03DEA8730CC8}] => (Allow) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Arvato Digital Services Canada Inc -> arvato digital services llc) FirewallRules: [{36B1C6BE-AD5D-468E-840E-1F46E0CEAB12}] => (Allow) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Arvato Digital Services Canada Inc -> arvato digital services llc) FirewallRules: [{53A3352E-756F-4BF6-9D00-3A9CEFB613E7}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act.Server.Host.exe (Microsoft) [File not signed] [File is in use] FirewallRules: [{CD2FC46C-6489-4912-B474-FD945403C188}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act.Server.Host.exe (Microsoft) [File not signed] [File is in use] FirewallRules: [{182D664B-912D-42FB-A1E1-26EA3F2763DE}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act15.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC) FirewallRules: [{3F6439CC-499B-41B5-B09D-212BE3DED12A}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act15.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC) FirewallRules: [{678D9ED1-7BA2-4216-8655-81D5E4A2DCD5}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\ActEmail.exe (Swiftpage ACT! LLC) [File not signed] [File is in use] FirewallRules: [{2F032D96-7FA2-4FFC-B8B6-C6A35A0C12D5}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\ActEmail.exe (Swiftpage ACT! LLC) [File not signed] [File is in use] FirewallRules: [{F19D14E7-1492-4793-A1CD-6115278C7B2C}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act!.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC) FirewallRules: [{C5D3BC0D-5FA6-4022-8DFB-0B6F52090134}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act!.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC) FirewallRules: [{F6FAE180-4C56-4468-9C9A-5F60F3FFD6B3}] => (Allow) C:\Program Files\Microsoft SQL Server\MSSQL10_50.ACT7\MSSQL () FirewallRules: [{76D57CB5-AEC9-4782-A01C-BDB344A7D046}] => (Allow) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{80ED20B0-3CA5-43E8-99C6-E88D3FD89393}] => (Allow) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Arvato Digital Services Canada Inc -> arvato digital services llc) FirewallRules: [{17D0B180-07DB-4EC3-A0E4-596D469F324A}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe => No File FirewallRules: [{A14BF976-27E0-4750-9A1F-AFABAB9FC0E0}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe => No File FirewallRules: [{3445F090-653A-42AD-ABA2-07A6971665DF}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe => No File FirewallRules: [{EBC6B69B-163A-4AF6-A7EE-DE95CD3029F8}] => (Allow) C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.12827.20336.0_x86__8wekyb3d8bbwe\Office16\OUTLOOK.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{467BE0C2-A4F8-4EBC-8C72-F8E645E2A378}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [{830D7612-3572-4636-89ED-37E364DAD9A0}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\84.0.4147.39\remoting_host.exe (Google LLC -> Google Inc.) FirewallRules: [{C71895E3-8299-4703-9A46-78550595C17A}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{2CF14EB2-229A-45FD-97BD-D0135784C5CB}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{2108C6A7-5224-4408-BAC0-19639A0169A7}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{E97F746B-77E7-4B4C-9CE7-2BA869D99907}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) ==================== Restore Points ========================= 23-06-2020 12:13:35 06/23/2020 before windows update at 12:13pm ==================== Faulty Device Manager Devices ============ ==================== Event log errors: ======================== Application errors: ================== Error: (06/28/2020 09:06:49 AM) (Source: Desktop History Queue Provider) (EventID: 0) (User: ) Description: Restarting the timer to handle future records Error: (06/28/2020 09:06:49 AM) (Source: Desktop History Queue Provider) (EventID: 0) (User: ) Description: Setting Processing to False Error: (06/28/2020 09:06:49 AM) (Source: Desktop History Queue Provider) (EventID: 0) (User: ) Description: Queues Have Been Processed Error: (06/28/2020 09:06:49 AM) (Source: Desktop History Queue Provider) (EventID: 0) (User: ) Description: ProcessingQueueSize is: 0 Error: (06/28/2020 09:06:49 AM) (Source: Desktop History Queue Provider) (EventID: 0) (User: ) Description: ProcessingQueues Error: (06/28/2020 09:06:49 AM) (Source: Desktop History Queue Provider) (EventID: 0) (User: ) Description: Stopped the Queues Timer Error: (06/28/2020 09:06:03 AM) (Source: Act! Scheduler) (EventID: 0) (User: ) Description: Service cannot be started. System.Exception: Unable to start scheduler service. ScheduledItems count is less than or equal to 0. at Act.Scheduler.SchedulerService.OnStart(String[] args) at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (06/28/2020 09:06:03 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: GiftBoxService.exe, version: 3.2.3.0, time stamp: 0x5b349c0a Faulting module name: GiftBoxService.exe, version: 3.2.3.0, time stamp: 0x5b349c0a Exception code: 0xc0000005 Fault offset: 0x0000642c Faulting process id: 0x1098 Faulting application start time: 0x01d64d66056813b1 Faulting application path: C:\Program Files (x86)\ASUS\ASUS GiftBox Service\GiftBoxService.exe Faulting module path: C:\Program Files (x86)\ASUS\ASUS GiftBox Service\GiftBoxService.exe Report Id: bd4b38d7-6bc9-400d-9532-44dadff7fc9b Faulting package full name: Faulting package-relative application ID: System errors: ============= Error: (06/29/2020 09:57:58 AM) (Source: bowser) (EventID: 8003) (User: ) Description: The master browser has received a server announcement from the computer LINKSYS01345 that believes that it is the master browser for the domain on transport NetBT_Tcpip_{16701CE0-2BD6-458B-974B-3425A244C327}. The master browser is stopping or an election is being forced. Error: (06/29/2020 08:57:22 AM) (Source: bowser) (EventID: 8003) (User: ) Description: The master browser has received a server announcement from the computer LINKSYS01345 that believes that it is the master browser for the domain on transport NetBT_Tcpip_{16701CE0-2BD6-458B-974B-3425A244C327}. The master browser is stopping or an election is being forced. Error: (06/29/2020 07:57:17 AM) (Source: bowser) (EventID: 8003) (User: ) Description: The master browser has received a server announcement from the computer LINKSYS01345 that believes that it is the master browser for the domain on transport NetBT_Tcpip_{16701CE0-2BD6-458B-974B-3425A244C327}. The master browser is stopping or an election is being forced. Error: (06/29/2020 06:32:29 AM) (Source: bowser) (EventID: 8003) (User: ) Description: The master browser has received a server announcement from the computer LINKSYS01345 that believes that it is the master browser for the domain on transport NetBT_Tcpip_{16701CE0-2BD6-458B-974B-3425A244C327}. The master browser is stopping or an election is being forced. Error: (06/28/2020 09:09:09 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The ASUS GiftBox Service service terminated unexpectedly. It has done this 1 time(s). Error: (06/28/2020 09:07:06 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the GiftBox.Service service. Error: (06/28/2020 09:06:36 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the GiftBox.Service service. Error: (06/28/2020 09:05:10 AM) (Source: Service Control Manager) (EventID: 7043) (User: ) Description: The Malwarebytes Service service did not shut down properly after receiving a preshutdown control. Windows Defender: =================================== Date: 2020-06-25 11:12:16.5470000Z Description: Microsoft Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=Program:Win32/Uwasson.A!ml&threatid=251745&enterprise=0 Name: Program:Win32/Uwasson.A!ml ID: 251745 Severity: Low Category: Potentially Unwanted Software Path: amsi:_C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Detection Origin: Unknown Detection Type: Concrete Detection Source: AMSI Process Name: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Security intelligence Version: AV: 1.317.1134.0, AS: 1.317.1134.0, NIS: 1.317.1134.0 Engine Version: AM: 1.1.17100.2, NIS: 1.1.17100.2 Date: 2020-06-22 10:13:16.5750000Z Description: Microsoft Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=Program:Win32/Uwasson.A!ml&threatid=251745&enterprise=0 Name: Program:Win32/Uwasson.A!ml ID: 251745 Severity: Low Category: Potentially Unwanted Software Path: amsi:_C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Detection Origin: Unknown Detection Type: Concrete Detection Source: AMSI Process Name: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Security intelligence Version: AV: 1.317.1134.0, AS: 1.317.1134.0, NIS: 1.317.1134.0 Engine Version: AM: 1.1.17100.2, NIS: 1.1.17100.2 Date: 2020-06-22 10:12:36.1630000Z Description: Microsoft Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=Program:Win32/Uwasson.A!ml&threatid=251745&enterprise=0 Name: Program:Win32/Uwasson.A!ml ID: 251745 Severity: Low Category: Potentially Unwanted Software Path: amsi:_C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Detection Origin: Unknown Detection Type: Concrete Detection Source: AMSI Process Name: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Security intelligence Version: AV: 1.317.1134.0, AS: 1.317.1134.0, NIS: 1.317.1134.0 Engine Version: AM: 1.1.17100.2, NIS: 1.1.17100.2 Date: 2020-06-19 07:10:03.6900000Z Description: Microsoft Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=Program:Win32/Uwasson.A!ml&threatid=251745&enterprise=0 Name: Program:Win32/Uwasson.A!ml ID: 251745 Severity: Low Category: Potentially Unwanted Software Path: amsi:_C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Detection Origin: Unknown Detection Type: Concrete Detection Source: AMSI Process Name: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Security intelligence Version: AV: 1.317.1134.0, AS: 1.317.1134.0, NIS: 1.317.1134.0 Engine Version: AM: 1.1.17100.2, NIS: 1.1.17100.2 Date: 2020-06-18 09:05:03.9030000Z Description: Microsoft Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=Program:Win32/Uwasson.A!ml&threatid=251745&enterprise=0 Name: Program:Win32/Uwasson.A!ml ID: 251745 Severity: Low Category: Potentially Unwanted Software Path: amsi:_C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Detection Origin: Unknown Detection Type: Concrete Detection Source: AMSI Process Name: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Security intelligence Version: AV: 1.317.1134.0, AS: 1.317.1134.0, NIS: 1.317.1134.0 Engine Version: AM: 1.1.17100.2, NIS: 1.1.17100.2 Date: 2020-06-22 10:14:54.9870000Z Description: Microsoft Defender Antivirus has encountered an error trying to update security intelligence. New security intelligence Version: Previous security intelligence Version: 1.317.1134.0 Update Source: Microsoft Update Server Security intelligence Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.17100.2 Error code: 0x80240017 Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. Date: 2020-06-10 21:49:50.1860000Z Description: Microsoft Defender Antivirus has encountered an error trying to update security intelligence. New security intelligence Version: Previous security intelligence Version: 1.317.483.0 Update Source: Microsoft Update Server Security intelligence Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.17100.2 Error code: 0x8007045b Error description: A system shutdown is in progress. CodeIntegrity: =================================== Date: 2020-06-29 06:29:28.6840000Z Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2020-06-29 06:29:28.0580000Z Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2020-06-29 06:29:26.6420000Z Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2020-06-29 06:29:26.1550000Z Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2020-06-29 06:29:24.5740000Z Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2020-06-29 06:29:23.9020000Z Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2020-06-29 06:28:49.7680000Z Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2020-06-29 06:28:49.7510000Z Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== BIOS: American Megatrends Inc. 301 08/21/2018 Motherboard: ASUSTeK COMPUTER INC. V272UA Processor: Intel(R) Core(TM) i5-8250U CPU @ 1.60GHz Percentage of memory in use: 22% Total physical RAM: 32655.1 MB Available physical RAM: 25430.09 MB Total Virtual: 37519.1 MB Available Virtual: 29946.26 MB ==================== Drives ================================ Drive 😄 (Windows) (Fixed) (Total:1907.1 GB) (Free:764.76 GB) NTFS Drive d: (My Book) (Fixed) (Total:5589 GB) (Free:1477.73 GB) NTFS Drive e: (DATA) (Fixed) (Total:3725.9 GB) (Free:221.91 GB) NTFS Drive f: (My Book) (Fixed) (Total:5589 GB) (Free:847.61 GB) NTFS Drive p: (Windows) (Network) (Total:1907.1 GB) (Free:764.76 GB) NTFS Drive y: (Windows) (Network) (Total:1907.1 GB) (Free:764.76 GB) NTFS \\?\Volume{32123bc8-773a-48a1-a209-7bbd9435f14d}\ () (Fixed) (Total:0.51 GB) (Free:0.08 GB) NTFS \\?\Volume{3690d6b4-1e22-42dc-9fd7-97069e42e4a2}\ (SYSTEM) (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32 ==================== MBR & Partition Table ==================== ========================================================== Disk: 0 (Size: 1907.7 GB) (Disk ID: B92FD1AB) Partition: GPT. ========================================================== Disk: 1 (Size: 5589 GB) (Disk ID: 16F2A91F) Partition: GPT. Attempted reading MBR returned 0 bytes. Could not read MBR for disk 2. ========================================================== Disk: 3 (Size: 3726 GB) (Disk ID: 107B8359) Partition: GPT. ==================== End of Addition.txt ======================= MIND YOU, I STILL HAVE WINDOWS POWER SHELL TEMPORARILY DELETED FROM THE TASK WINDOW. THANK YOU FOR HELPING.
  9. My computer is being dogged by a trojan - which Malwarebytes is blocking. Problem is, Malwarebytes is not removing the trojan but instead every few seconds when the trojan wants to spread, the malwarebytes protection shield also pops up. This means every few second this battle ensues. The trojan is using the windows power shell. I found I could pause the battle when going into task bar and ending the power shell task. When reporting a support ticket or otherwise to solve this issue, Malwarebytes wants me to download the security tool and run it to get a log. I have done this repeatedly and the log fails everytime. I cannot get a log and therefore cannot get help. When I send emails I don't think a human looks at it and it just tells me to download the tool that won't download. I'm at my wits end. Is it safe to uninstall the windows power shell or am I just delaying the problem. Why doesn't Malwarebytes GET RID OF IT? Thanks for listening. The trojan is an outbound (why?) trojan that changes ips.
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.