Jump to content

Windows has been blocked


Recommended Posts

I assume I have a virus and when I click on links I sometimes get this (see attachment/picture). I know it's not legit. I have not downloaded anything for months on this computer aside from some games on Steam. Malwarebytes found nothing and ADWcleaner found two things (aol.com and ask.com) and deleted them (not too sure what that was about).

Also I have NoScript (Firefox) and did I avert further damage? I had to use Task Manager to get out this because ALT+f4 wouldn't work and I know better than to even click that [Canel] button (developers can make legit looking Windows Environment popups appear legit within the css/javascript).

Anyways, if Malwarebytes found nothing should I be concerned?

 

w10blocked.jpg

Link to post
Share on other sites

Hello CrowTrobot and welcome to Malwarebytes,

Run the following diagnostic scan and post the two produced logs:

Download Farbar Recovery Scan Tool and save it to your desktop.

Alternative download option: http://www.techspot.com/downloads/6731-farbar-recovery-scan-tool.html

Note: You need to run the version compatible with your system (32 bit or 64 bit). If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

If your security alerts to FRST either, accept the alert or turn your security off to allow FRST to run. It is not malicious or infected in any way...
 
  • Double-click to run it. When the tool opens click Yes to disclaimer.(Windows 8/10 users will be prompted about Windows SmartScreen protection - click More information and Run.)
  • Make sure Addition.txt is checkmarked under "Optional scans"
  • Press Scan button to run the tool....
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The tool will also make a log named (Addition.txt) Please attach that log to your reply.

Thank you,

Kevin.

Link to post
Share on other sites

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-11-2016 01
Ran by Matt (administrator) on MATT-PC (22-11-2016 18:00:38)
Running from C:\Users\Matt\Desktop
Loaded Profiles: Matt (Available Profiles: Matt & DefaultAppPool)
Platform: Windows 10 Pro Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\CtHdaSvc.exe
(HP) C:\Windows\System32\HPSIsvc.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP ENVY 5660 series\Bin\ScanToPCActivationApp.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Recon3Di\Sound Blaster Recon3Di Control Panel\SBRcni.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP ENVY 5660 series\Bin\HPNetworkCommunicatorCom.exe
(Corsair Components  Inc) C:\Program Files (x86)\Corsair\M65 Mouse\M65Hid.exe
(Hewlett-Packard) C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Corsair Components  Inc) C:\Program Files (x86)\Corsair\M65 Mouse\CorsTra.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Recon3Di\Sound Blaster Recon3Di Control Panel\CTJckCfg.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Almico Software (www.almico.com)) C:\Program Files (x86)\SpeedFan\speedfan.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe


==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2014-04-11] (Intel Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2397120 2016-06-14] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [V0790Mon.exe] => C:\WINDOWS\V0790Mon.exe
HKLM-x32\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [Sound Blaster Recon3Di SBX Control Panel] => C:\Program Files (x86)\Creative\Sound Blaster Recon3Di\Sound Blaster Recon3Di Control Panel\SBRcni.exe [976896 2012-11-28] (Creative Technology Ltd)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2014-02-21] (Intel Corporation)
HKLM-x32\...\Run: [KeePass 2 PreLoad] => C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [2117632 2014-07-06] (Dominik Reichl)
HKLM-x32\...\Run: [Live! Central 3] => C:\Program Files (x86)\Creative\Creative Live! Cam\Live! Central 3\CTLVCentral3.exe [461312 2013-08-02] (Creative Technology Ltd)
HKLM-x32\...\Run: [FastAccess Web Alert] => C:\Program Files (x86)\Creative\Creative Live! Cam\Live! Central 3\FAInstaller\FATRY.exe [2033648 2011-07-12] (Microsoft)
HKLM-x32\...\Run: [Corsair M65 Mouse] => C:\Program Files (x86)\Corsair\M65 Mouse\M65Hid.exe [1766912 2013-08-15] (Corsair Components  Inc)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation)
HKU\S-1-5-21-183162068-1737580067-508966621-1000\...\Run: [Google Update] => C:\Users\Matt\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-27] (Google Inc.)
HKU\S-1-5-21-183162068-1737580067-508966621-1000\...\Run: [HP ENVY 5660 series (NET)] => C:\Program Files\HP\HP ENVY 5660 series\Bin\ScanToPCActivationApp.exe [3483656 2014-08-22] (Hewlett-Packard Development Company, LP)
GroupPolicy: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{9ce1e404-f577-4100-83c2-744c784a7e85}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-183162068-1737580067-508966621-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/
HKU\S-1-5-21-183162068-1737580067-508966621-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
SearchScopes: HKU\S-1-5-21-183162068-1737580067-508966621-1000 -> DefaultScope {F0DD65B5-3ECB-40C8-B5A3-CFD3E672E3FA} URL =
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2016-10-23] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-10-23] (Oracle Corporation)

FireFox:
========
FF DefaultProfile: fk6o2xd5.default
FF ProfilePath: C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\fk6o2xd5.default [2016-11-22]
FF NewTab: Mozilla\Firefox\Profiles\fk6o2xd5.default -> about:blank
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\fk6o2xd5.default -> Google
FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\fk6o2xd5.default -> Google
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\fk6o2xd5.default -> Yahoo!
FF Homepage: Mozilla\Firefox\Profiles\fk6o2xd5.default -> hxxps://start.duckduckgo.com/
FF Extension: (ADB Helper) - C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\fk6o2xd5.default\Extensions\adbhelper@mozilla.org [2016-11-03]
FF Extension: (Element Hiding Helper for Adblock Plus) - C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\fk6o2xd5.default\Extensions\elemhidehelper@adblockplus.org.xpi [2016-10-27]
FF Extension: (Valence) - C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\fk6o2xd5.default\Extensions\fxdevtools-adapters@mozilla.org [2016-07-14]
FF Extension: (The Addon Bar (restored)) - C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\fk6o2xd5.default\Extensions\the-addon-bar@GeekInTraining-GiT.xpi [2016-05-03]
FF Extension: (ColorZilla) - C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\fk6o2xd5.default\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326} [2016-08-18]
FF Extension: (NoScript) - C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\fk6o2xd5.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2016-08-08]
FF Extension: (Adblock Plus) - C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\fk6o2xd5.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-10-28]
FF ProfilePath: C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r07rbpu2.dev-edition-default [2016-10-30]
FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\r07rbpu2.dev-edition-default -> Google
FF Homepage: Mozilla\Firefox\Profiles\r07rbpu2.dev-edition-default -> about:blank
FF Extension: (ADB Helper) - C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r07rbpu2.dev-edition-default\Extensions\adbhelper@mozilla.org [2016-08-02]
FF Extension: (Valence) - C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r07rbpu2.dev-edition-default\Extensions\fxdevtools-adapters@mozilla.org [2016-08-02]
FF Extension: (ColorZilla) - C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r07rbpu2.dev-edition-default\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326} [2016-08-18]
FF Extension: (Web Developer) - C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\r07rbpu2.dev-edition-default\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2016-10-05]
FF ProfilePath: C:\Users\Matt\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\ih18tsw7.default [2016-11-06]
FF Homepage: Moonchild Productions\Pale Moon\Profiles\ih18tsw7.default -> hxxps://google.com
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt => not found
FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-10-23] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-10-23] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-04-01] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-08-11] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-08-11] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-183162068-1737580067-508966621-1000: @talk.google.com/GoogleTalkPlugin -> C:\Users\Matt\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-183162068-1737580067-508966621-1000: @talk.google.com/O1DPlugin -> C:\Users\Matt\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-183162068-1737580067-508966621-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Matt\AppData\Local\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-183162068-1737580067-508966621-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Matt\AppData\Local\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Matt\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Matt\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)
StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Firefox Developer Edition\firefox.exe

Chrome:
=======
CHR DefaultProfile: Default
CHR StartupUrls: Default -> "hxxps://google.com/"
CHR Profile: C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default [2016-11-22]
CHR Extension: (Google Slides) - C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-08]
CHR Extension: (Google Docs) - C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-08]
CHR Extension: (Google Drive) - C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-27]
CHR Extension: (YouTube) - C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-29]
CHR Extension: (Adblock Plus) - C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-11-06]
CHR Extension: (Google Search) - C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Google Sheets) - C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-08]
CHR Extension: (Google Docs Offline) - C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-18]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-05]
CHR Extension: (Gmail) - C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-01]
CHR Extension: (Chrome Media Router) - C:\Users\Matt\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-11-06]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2014-12-18] (BitRaider, LLC)
S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [477960 2014-09-19] (BitRaider, LLC)
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2014-09-12] (Creative Labs) [File not signed]
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2014-09-12] (Creative Labs) [File not signed]
R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [423424 2012-10-08] (Creative Technology Ltd) [File not signed]
R2 CtHdaSvc; C:\WINDOWS\sysWow64\CtHdaSvc.exe [113160 2015-12-26] (Creative Technology Ltd)
S3 DAUpdaterSvc; C:\Program Files (x86)\Steam\steamapps\common\Dragon Age Ultimate Edition\bin_ship\DAUpdaterSvc.Service.exe [25832 2016-08-30] (BioWare)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [614624 2014-12-10] (Futuremark)
S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [277056 2016-08-31] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6514752 2016-08-28] (GOG.com)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163712 2016-06-14] (NVIDIA Corporation)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [16232 2014-04-11] (Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373744 2016-11-01] (Intel Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-06-14] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3632576 2016-06-14] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2521024 2016-06-14] (NVIDIA Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2016-10-25] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2016-10-25] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BRDriver64; C:\ProgramData\BitRaider\BRDriver64.sys [75048 2014-09-20] (BitRaider)
S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2015-12-05] (BitRaider)
S3 CorsairVBusDriver; C:\WINDOWS\System32\drivers\CorsairVBusDriver.sys [47840 2015-10-30] (Corsair)
S3 CorsairVHidDriver; C:\WINDOWS\System32\drivers\CorsairVHidDriver.sys [21728 2015-10-30] (Corsair)
R3 cthda; C:\WINDOWS\system32\drivers\cthda.sys [1067304 2015-12-26] (Creative Technology Ltd)
S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2014-09-13] ()
S3 Ke2200; C:\WINDOWS\System32\drivers\e22w7x64.sys [154320 2013-03-20] (Qualcomm Atheros, Inc.)
R3 KillerEth; C:\WINDOWS\System32\drivers\e22w10x64.sys [156744 2015-12-26] (Qualcomm Atheros, Inc.)
R3 MEIx64; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [129312 2014-09-30] (Intel Corporation)
S3 mvusbews; C:\WINDOWS\System32\Drivers\mvusbews.sys [20480 2012-09-26] (Marvell Semiconductor, Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-06-14] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [56384 2016-04-14] (NVIDIA Corporation)
R3 SnakeEyes; C:\WINDOWS\system32\drivers\SnakeEyes.sys [25600 2012-09-05] ( )
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
S3 XSplit_Dummy; C:\WINDOWS\system32\drivers\xspltspk.sys [26200 2015-05-26] (SplitmediaLabs Limited)
R3 XtuAcpiDriver; C:\WINDOWS\System32\drivers\XtuAcpiDriver.sys [63840 2015-06-06] (Intel Corporation)
U3 idsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-11-22 18:00 - 2016-11-22 18:00 - 00019144 _____ C:\Users\Matt\Desktop\FRST.txt
2016-11-22 18:00 - 2016-11-22 18:00 - 00000000 ____D C:\FRST
2016-11-22 17:50 - 2016-11-22 18:00 - 02412544 _____ (Farbar) C:\Users\Matt\Desktop\FRST64.exe
2016-11-22 13:57 - 2016-11-22 14:09 - 00000000 ____D C:\AdwCleaner
2016-11-22 13:53 - 2016-11-22 13:57 - 03910208 _____ C:\Users\Matt\Desktop\adwcleaner_6.030.exe
2016-11-19 10:01 - 2016-11-22 14:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-11-09 10:44 - 2016-11-02 08:32 - 00316256 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-11-09 10:44 - 2016-11-02 08:31 - 00546968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-11-09 10:44 - 2016-11-02 07:51 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2016-11-09 10:44 - 2016-10-25 04:34 - 00454496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbport.sys
2016-11-09 10:44 - 2016-10-25 03:32 - 01862000 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2016-11-09 10:44 - 2016-10-25 03:32 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2016-11-09 10:44 - 2016-10-25 03:32 - 00845568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2016-11-09 10:44 - 2016-10-25 03:32 - 00034088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll
2016-11-09 10:44 - 2016-10-25 03:28 - 01083648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Taskmgr.exe
2016-11-09 10:44 - 2016-10-25 03:05 - 00712032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2016-11-09 10:44 - 2016-10-25 02:45 - 00032096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbd.sys
2016-11-09 10:44 - 2016-10-25 02:39 - 00306840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2016-11-09 10:44 - 2016-10-25 02:37 - 02180128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2016-11-09 10:44 - 2016-10-25 02:37 - 01349632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2016-11-09 10:44 - 2016-10-25 02:37 - 00980352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2016-11-09 10:44 - 2016-10-25 02:37 - 00895080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2016-11-09 10:44 - 2016-10-25 02:37 - 00882720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2016-11-09 10:44 - 2016-10-25 02:37 - 00709176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2016-11-09 10:44 - 2016-10-25 02:31 - 01824272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2016-11-09 10:44 - 2016-10-25 02:31 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2016-11-09 10:44 - 2016-10-25 02:30 - 02938920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-11-09 10:44 - 2016-10-25 02:30 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2016-11-09 10:44 - 2016-10-25 02:29 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2016-11-09 10:44 - 2016-10-25 02:27 - 21123320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-11-09 10:44 - 2016-10-25 02:27 - 00465760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2016-11-09 10:44 - 2016-10-25 02:27 - 00256704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2016-11-09 10:44 - 2016-10-25 02:26 - 05240952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2016-11-09 10:44 - 2016-10-25 02:26 - 04074160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2016-11-09 10:44 - 2016-10-25 02:26 - 01355344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll
2016-11-09 10:44 - 2016-10-25 02:26 - 00836752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2016-11-09 10:44 - 2016-10-25 02:26 - 00569752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2016-11-09 10:44 - 2016-10-25 02:22 - 00268040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2016-11-09 10:44 - 2016-10-25 02:22 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthAvrcpTg.sys
2016-11-09 10:44 - 2016-10-25 02:19 - 00295776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-11-09 10:44 - 2016-10-25 02:18 - 01536088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2016-11-09 10:44 - 2016-10-25 02:12 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hdaudbus.sys
2016-11-09 10:44 - 2016-10-25 01:56 - 02195640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2016-11-09 10:44 - 2016-10-25 01:56 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe
2016-11-09 10:44 - 2016-10-25 01:54 - 01522160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2016-11-09 10:44 - 2016-10-25 01:54 - 00273760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\input.dll
2016-11-09 10:44 - 2016-10-25 01:53 - 01174008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2016-11-09 10:44 - 2016-10-25 01:27 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2016-11-09 10:44 - 2016-10-25 01:26 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2016-11-09 10:44 - 2016-10-25 01:21 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll
2016-11-09 10:44 - 2016-10-25 01:18 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
2016-11-09 10:44 - 2016-10-25 01:09 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2016-11-09 10:44 - 2016-10-25 01:08 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2016-11-09 10:44 - 2016-10-25 01:06 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-11-09 10:44 - 2016-10-25 01:05 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2016-11-09 10:44 - 2016-10-25 01:03 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SCardDlg.dll
2016-11-09 10:44 - 2016-10-25 01:01 - 00183296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSMDesktopProvider.dll
2016-11-09 10:44 - 2016-10-25 01:00 - 00256512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unimdm.tsp
2016-11-09 10:44 - 2016-10-25 01:00 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll
2016-11-09 10:44 - 2016-10-25 00:59 - 00205312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oemlicense.dll
2016-11-09 10:44 - 2016-10-25 00:54 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IdCtrls.dll
2016-11-09 10:44 - 2016-10-25 00:51 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UXInit.dll
2016-11-09 10:44 - 2016-10-25 00:50 - 00430080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\intl.cpl
2016-11-09 10:44 - 2016-10-25 00:50 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\azroleui.dll
2016-11-09 10:44 - 2016-10-25 00:50 - 00260096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll
2016-11-09 10:44 - 2016-10-25 00:50 - 00205824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2016-11-09 10:44 - 2016-10-25 00:49 - 02597888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2016-11-09 10:44 - 2016-10-25 00:49 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3ui.dll
2016-11-09 10:44 - 2016-10-25 00:48 - 00217600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DafPrintProvider.dll
2016-11-09 10:44 - 2016-10-25 00:48 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll
2016-11-09 10:44 - 2016-10-25 00:45 - 00564736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\objsel.dll
2016-11-09 10:44 - 2016-10-25 00:45 - 00541184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
2016-11-09 10:44 - 2016-10-25 00:45 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2016-11-09 10:44 - 2016-10-25 00:45 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneOm.dll
2016-11-09 10:44 - 2016-10-25 00:44 - 00240128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAnimation.dll
2016-11-09 10:44 - 2016-10-25 00:43 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\filemgmt.dll
2016-11-09 10:44 - 2016-10-25 00:42 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2016-11-09 10:44 - 2016-10-25 00:41 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll
2016-11-09 10:44 - 2016-10-25 00:41 - 00499712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2016-11-09 10:44 - 2016-10-25 00:40 - 01336832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
2016-11-09 10:44 - 2016-10-25 00:39 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2016-11-09 10:44 - 2016-10-25 00:39 - 00356864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certreq.exe
2016-11-09 10:44 - 2016-10-25 00:39 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-11-09 10:44 - 2016-10-25 00:37 - 04143104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WlanMM.dll
2016-11-09 10:44 - 2016-10-25 00:37 - 01226752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wcnwiz.dll
2016-11-09 10:44 - 2016-10-25 00:37 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasgcw.dll
2016-11-09 10:44 - 2016-10-25 00:37 - 00334848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-11-09 10:44 - 2016-10-25 00:36 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2016-11-09 10:44 - 2016-10-25 00:36 - 00616960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2016-11-09 10:44 - 2016-10-25 00:36 - 00502272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll
2016-11-09 10:44 - 2016-10-25 00:36 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mbsmsapi.dll
2016-11-09 10:44 - 2016-10-25 00:36 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wvc.dll
2016-11-09 10:44 - 2016-10-25 00:36 - 00413696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WLanConn.dll
2016-11-09 10:44 - 2016-10-25 00:36 - 00153088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSSync.dll
2016-11-09 10:44 - 2016-10-25 00:35 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
2016-11-09 10:44 - 2016-10-25 00:35 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2016-11-09 10:44 - 2016-10-25 00:35 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2016-11-09 10:44 - 2016-10-25 00:34 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2016-11-09 10:44 - 2016-10-25 00:33 - 01063936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll
2016-11-09 10:44 - 2016-10-25 00:33 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2016-11-09 10:44 - 2016-10-25 00:32 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2016-11-09 10:44 - 2016-10-25 00:32 - 00738816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appwiz.cpl
2016-11-09 10:44 - 2016-10-25 00:32 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SmartcardCredentialProvider.dll
2016-11-09 10:44 - 2016-10-25 00:32 - 00645632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.Search.dll
2016-11-09 10:44 - 2016-10-25 00:31 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2016-11-09 10:44 - 2016-10-25 00:30 - 00434688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2016-11-09 10:44 - 2016-10-25 00:29 - 01497088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
2016-11-09 10:44 - 2016-10-25 00:29 - 01117184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2016-11-09 10:44 - 2016-10-25 00:29 - 00673280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
2016-11-09 10:44 - 2016-10-25 00:28 - 02578432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll
2016-11-09 10:44 - 2016-10-25 00:28 - 00885248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2016-11-09 10:44 - 2016-10-25 00:28 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2016-11-09 10:44 - 2016-10-25 00:28 - 00769536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2016-11-09 10:44 - 2016-10-25 00:28 - 00760320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2016-11-09 10:44 - 2016-10-25 00:27 - 01448960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.3D.dll
2016-11-09 10:44 - 2016-10-25 00:27 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll
2016-11-09 10:44 - 2016-10-25 00:26 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2016-11-09 10:44 - 2016-10-25 00:25 - 03695104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2016-11-09 10:44 - 2016-10-25 00:25 - 01309696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wdc.dll
2016-11-09 10:44 - 2016-10-25 00:25 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2016-11-09 10:44 - 2016-10-25 00:25 - 00667648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2016-11-09 10:44 - 2016-10-25 00:25 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
2016-11-09 10:44 - 2016-10-25 00:24 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\licensingdiag.exe
2016-11-09 10:44 - 2016-10-25 00:23 - 02362880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVidCtl.dll
2016-11-09 10:44 - 2016-10-25 00:23 - 00964096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2016-11-09 10:44 - 2016-10-25 00:22 - 01562624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmc.exe
2016-11-09 10:44 - 2016-10-25 00:21 - 03577344 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2016-11-09 10:44 - 2016-10-25 00:21 - 00639488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2016-11-09 10:44 - 2016-10-25 00:17 - 00581632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll
2016-11-09 10:44 - 2016-10-25 00:14 - 00683008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2016-11-09 10:44 - 2016-10-25 00:11 - 06471168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2016-11-09 10:44 - 2016-10-25 00:11 - 04078592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2016-11-09 10:44 - 2016-10-25 00:11 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2016-11-09 10:44 - 2016-10-25 00:09 - 01448960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dui70.dll
2016-11-09 10:44 - 2016-10-25 00:09 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2016-11-09 10:44 - 2016-10-25 00:07 - 03671040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2016-11-09 10:44 - 2016-10-25 00:04 - 00835072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2016-11-09 10:44 - 2016-10-25 00:03 - 01500160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-11-09 10:44 - 2016-10-25 00:01 - 02361856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmcndmgr.dll
2016-11-09 10:44 - 2016-10-25 00:00 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-11-09 10:44 - 2016-10-25 00:00 - 04412928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2016-11-09 10:44 - 2016-10-25 00:00 - 02555904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-11-09 10:44 - 2016-10-25 00:00 - 01984000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2016-11-09 10:44 - 2016-10-25 00:00 - 01708032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
2016-11-09 10:44 - 2016-10-24 23:59 - 02680320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2016-11-09 10:44 - 2016-10-24 23:59 - 01556992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpcServices.dll
2016-11-09 10:44 - 2016-10-24 23:58 - 09920512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-11-09 10:44 - 2016-10-24 23:57 - 06296064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-11-09 10:44 - 2016-10-24 23:56 - 01799680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-11-09 10:44 - 2016-10-24 23:55 - 02001408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2016-11-09 10:44 - 2016-10-24 23:55 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prnfldr.dll
2016-11-09 10:44 - 2016-10-24 23:54 - 04759040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2016-11-09 10:44 - 2016-10-24 23:53 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2016-11-09 10:44 - 2016-10-24 23:47 - 05205504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-11-09 10:44 - 2016-10-24 23:46 - 02771968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2016-11-09 10:44 - 2016-10-24 23:45 - 02679808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll
2016-11-09 10:44 - 2016-10-24 23:44 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2016-11-09 10:44 - 2016-10-24 23:43 - 04404736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2016-11-09 10:44 - 2016-10-24 23:41 - 02519552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themecpl.dll
2016-11-09 10:44 - 2016-10-24 23:40 - 05325824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2016-11-09 10:44 - 2016-10-24 23:38 - 01582080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2016-11-09 10:44 - 2016-10-24 23:37 - 02798080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-11-09 10:44 - 2016-10-24 23:36 - 02155008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2016-11-09 10:44 - 2016-10-24 23:35 - 02604032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2016-11-09 10:44 - 2016-10-24 23:35 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll
2016-11-09 10:44 - 2016-10-24 23:34 - 02062336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2016-11-09 10:44 - 2016-10-24 23:34 - 01249280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll
2016-11-09 10:44 - 2016-10-24 23:34 - 01228800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
2016-11-09 10:44 - 2016-10-24 23:33 - 00574976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hgcpl.dll
2016-11-09 10:44 - 2016-10-24 23:32 - 06743040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2016-11-09 10:44 - 2016-10-24 23:32 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserLanguagesCpl.dll
2016-11-09 10:44 - 2016-10-24 23:32 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2016-11-09 10:44 - 2016-10-24 23:27 - 03065344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2016-11-09 10:44 - 2016-10-24 23:23 - 00712704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2016-11-09 10:44 - 2016-10-24 23:21 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GlobCollationHost.dll
2016-11-09 10:44 - 2016-10-24 23:07 - 00461824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2016-11-09 10:43 - 2016-10-25 04:42 - 07468384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-11-09 10:43 - 2016-10-25 04:42 - 01142560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-11-09 10:43 - 2016-10-25 04:25 - 01637216 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2016-11-09 10:43 - 2016-10-25 04:24 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2016-11-09 10:43 - 2016-10-25 04:18 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2016-11-09 10:43 - 2016-10-25 03:51 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2016-11-09 10:43 - 2016-10-25 03:49 - 00588328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmdrmdev.dll
2016-11-09 10:43 - 2016-10-25 03:49 - 00245840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2016-11-09 10:43 - 2016-10-25 03:48 - 02544256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2016-11-09 10:43 - 2016-10-25 03:48 - 01554152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2016-11-09 10:43 - 2016-10-25 03:48 - 01552104 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2016-11-09 10:43 - 2016-10-25 03:48 - 01152328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2016-11-09 10:43 - 2016-10-25 03:48 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2016-11-09 10:43 - 2016-10-25 03:48 - 01017024 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2016-11-09 10:43 - 2016-10-25 03:48 - 00847648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-11-09 10:43 - 2016-10-25 03:42 - 02607336 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2016-11-09 10:43 - 2016-10-25 03:42 - 00808288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2016-11-09 10:43 - 2016-10-25 03:41 - 03694088 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-11-09 10:43 - 2016-10-25 03:39 - 01750440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2016-11-09 10:43 - 2016-10-25 03:38 - 22561256 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-11-09 10:43 - 2016-10-25 03:37 - 06605544 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2016-11-09 10:43 - 2016-10-25 03:37 - 01040792 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2016-11-09 10:43 - 2016-10-25 03:35 - 06536248 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2016-11-09 10:43 - 2016-10-25 03:32 - 01557776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2016-11-09 10:43 - 2016-10-25 03:30 - 01848072 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2016-11-09 10:43 - 2016-10-25 03:30 - 00360288 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-11-09 10:43 - 2016-10-25 02:47 - 28851216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecsRaw.dll
2016-11-09 10:43 - 2016-10-25 02:47 - 02641928 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
2016-11-09 10:43 - 2016-10-25 02:47 - 00305808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpeffects.dll
2016-11-09 10:43 - 2016-10-25 02:46 - 00388896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
2016-11-09 10:43 - 2016-10-25 02:40 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2016-11-09 10:43 - 2016-10-25 02:40 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2016-11-09 10:43 - 2016-10-25 02:35 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
2016-11-09 10:43 - 2016-10-25 02:33 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\genericusbfn.sys
2016-11-09 10:43 - 2016-10-25 02:32 - 00824320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2016-11-09 10:43 - 2016-10-25 02:31 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2016-11-09 10:43 - 2016-10-25 02:30 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2016-11-09 10:43 - 2016-10-25 02:26 - 00046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2016-11-09 10:43 - 2016-10-25 02:23 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2016-11-09 10:43 - 2016-10-25 02:20 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2016-11-09 10:43 - 2016-10-25 02:18 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-11-09 10:43 - 2016-10-25 02:14 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2016-11-09 10:43 - 2016-10-25 02:13 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2016-11-09 10:43 - 2016-10-25 02:12 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\racpldlg.dll
2016-11-09 10:43 - 2016-10-25 02:10 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceClassExtension.dll
2016-11-09 10:43 - 2016-10-25 02:06 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2016-11-09 10:43 - 2016-10-25 02:06 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceConnectApi.dll
2016-11-09 10:43 - 2016-10-25 02:05 - 00270848 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-11-09 10:43 - 2016-10-25 02:04 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\LegacyNetUXHost.exe
2016-11-09 10:43 - 2016-10-25 01:59 - 00243200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2016-11-09 10:43 - 2016-10-25 01:59 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2016-11-09 10:43 - 2016-10-25 01:56 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2016-11-09 10:43 - 2016-10-25 01:55 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-11-09 10:43 - 2016-10-25 01:55 - 00287232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DafPrintProvider.dll
2016-11-09 10:43 - 2016-10-25 01:54 - 00752128 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2016-11-09 10:43 - 2016-10-25 01:53 - 00813056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll
2016-11-09 10:43 - 2016-10-25 01:52 - 00577536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll
2016-11-09 10:43 - 2016-10-25 01:52 - 00383488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2016-11-09 10:43 - 2016-10-25 01:51 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2016-11-09 10:43 - 2016-10-25 01:51 - 00412672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanui.dll
2016-11-09 10:43 - 2016-10-25 01:50 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdrm.dll
2016-11-09 10:43 - 2016-10-25 01:50 - 00510464 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMediaManager.dll
2016-11-09 10:43 - 2016-10-25 01:50 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAnimation.dll
2016-11-09 10:43 - 2016-10-25 01:49 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2016-11-09 10:43 - 2016-10-25 01:49 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WalletService.dll
2016-11-09 10:43 - 2016-10-25 01:48 - 00639488 _____ (Microsoft Corporation) C:\WINDOWS\system32\PortableDeviceApi.dll
2016-11-09 10:43 - 2016-10-25 01:46 - 00857600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll
2016-11-09 10:43 - 2016-10-25 01:43 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2016-11-09 10:43 - 2016-10-25 01:43 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-11-09 10:43 - 2016-10-25 01:42 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2016-11-09 10:43 - 2016-10-25 01:41 - 01294336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcnwiz.dll
2016-11-09 10:43 - 2016-10-25 01:41 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs.dll
2016-11-09 10:43 - 2016-10-25 01:40 - 02331480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
2016-11-09 10:43 - 2016-10-25 01:40 - 01216512 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcenter.dll
2016-11-09 10:43 - 2016-10-25 01:40 - 00947200 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasgcw.dll
2016-11-09 10:43 - 2016-10-25 01:40 - 00432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-11-09 10:43 - 2016-10-25 01:40 - 00253088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpeffects.dll
2016-11-09 10:43 - 2016-10-25 01:39 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-11-09 10:43 - 2016-10-25 01:39 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscui.dll
2016-11-09 10:43 - 2016-10-25 01:39 - 00674304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mbsmsapi.dll
2016-11-09 10:43 - 2016-10-25 01:39 - 00519680 _____ (Microsoft Corporation) C:\WINDOWS\system32\WLanConn.dll
2016-11-09 10:43 - 2016-10-25 01:38 - 02088960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdshext.dll
2016-11-09 10:43 - 2016-10-25 01:38 - 01048576 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebcamUi.dll
2016-11-09 10:43 - 2016-10-25 01:38 - 00853504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-11-09 10:43 - 2016-10-25 01:38 - 00610304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmdrmsdk.dll
2016-11-09 10:43 - 2016-10-25 01:37 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2016-11-09 10:43 - 2016-10-25 01:37 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll
2016-11-09 10:43 - 2016-10-25 01:35 - 01434112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll
2016-11-09 10:43 - 2016-10-25 01:35 - 01132544 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
2016-11-09 10:43 - 2016-10-25 01:35 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-11-09 10:43 - 2016-10-25 01:35 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-11-09 10:43 - 2016-10-25 01:34 - 00697856 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2016-11-09 10:43 - 2016-10-25 01:33 - 02127360 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2016-11-09 10:43 - 2016-10-25 01:33 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-11-09 10:43 - 2016-10-25 01:33 - 00817152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.Search.dll
2016-11-09 10:43 - 2016-10-25 01:32 - 00939520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-11-09 10:43 - 2016-10-25 01:29 - 00896512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2016-11-09 10:43 - 2016-10-25 01:28 - 01752576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2016-11-09 10:43 - 2016-10-25 01:28 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2016-11-09 10:43 - 2016-10-25 01:27 - 02050560 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs3D.dll
2016-11-09 10:43 - 2016-10-25 01:27 - 01466368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Pimstore.dll
2016-11-09 10:43 - 2016-10-25 01:27 - 01346048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMNetMgr.dll
2016-11-09 10:43 - 2016-10-25 01:27 - 01040896 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2016-11-09 10:43 - 2016-10-25 01:27 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2016-11-09 10:43 - 2016-10-25 01:23 - 00865792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2016-11-09 10:43 - 2016-10-25 01:22 - 00268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2016-11-09 10:43 - 2016-10-25 01:21 - 02054144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2016-11-09 10:43 - 2016-10-25 01:19 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2016-11-09 10:43 - 2016-10-25 01:16 - 01965568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmc.exe
2016-11-09 10:43 - 2016-10-25 01:12 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2016-11-09 10:43 - 2016-10-25 01:07 - 00900608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2016-11-09 10:43 - 2016-10-25 01:05 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdengin2.dll
2016-11-09 10:43 - 2016-10-25 01:05 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\StikyNot.exe
2016-11-09 10:43 - 2016-10-25 01:03 - 05123072 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2016-11-09 10:43 - 2016-10-25 01:03 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2016-11-09 10:43 - 2016-10-25 01:01 - 01121792 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2016-11-09 10:43 - 2016-10-25 01:00 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceClassExtension.dll
2016-11-09 10:43 - 2016-10-25 00:59 - 03351040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2016-11-09 10:43 - 2016-10-25 00:57 - 02285568 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebSync.dll
2016-11-09 10:43 - 2016-10-25 00:57 - 00833536 _____ (Microsoft Corporation) C:\WINDOWS\system32\pmcsnap.dll
2016-11-09 10:43 - 2016-10-25 00:56 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceConnectApi.dll
2016-11-09 10:43 - 2016-10-25 00:55 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2016-11-09 10:43 - 2016-10-25 00:53 - 02280960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-11-09 10:43 - 2016-10-25 00:53 - 01728000 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-11-09 10:43 - 2016-10-25 00:49 - 03081216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-11-09 10:43 - 2016-10-25 00:46 - 02055168 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll
2016-11-09 10:43 - 2016-10-25 00:46 - 00486912 _____ (Microsoft Corporation) C:\WINDOWS\system32\prnfldr.dll
2016-11-09 10:43 - 2016-10-25 00:46 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2016-11-09 10:43 - 2016-10-25 00:45 - 07977984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-11-09 10:43 - 2016-10-25 00:43 - 00520704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PortableDeviceApi.dll
2016-11-09 10:43 - 2016-10-25 00:42 - 02876928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2016-11-09 10:43 - 2016-10-25 00:41 - 02444800 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2016-11-09 10:43 - 2016-10-25 00:36 - 04646400 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2016-11-09 10:43 - 2016-10-25 00:36 - 00879616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebcamUi.dll
2016-11-09 10:43 - 2016-10-25 00:35 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmdrmsdk.dll
2016-11-09 10:43 - 2016-10-25 00:34 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-11-09 10:43 - 2016-10-25 00:32 - 02050048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2016-11-09 10:43 - 2016-10-25 00:30 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-11-09 10:43 - 2016-10-25 00:28 - 07200256 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-11-09 10:43 - 2016-10-25 00:28 - 01526272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2016-11-09 10:43 - 2016-10-25 00:28 - 01186816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMNetMgr.dll
2016-11-09 10:43 - 2016-10-25 00:28 - 00882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2016-11-09 10:43 - 2016-10-25 00:25 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2016-11-09 10:43 - 2016-10-25 00:24 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2016-11-09 10:43 - 2016-10-25 00:23 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2016-11-09 10:43 - 2016-10-25 00:19 - 16984576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-11-09 10:43 - 2016-10-25 00:17 - 04895744 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-11-09 10:43 - 2016-10-25 00:14 - 02911744 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2016-11-09 10:43 - 2016-10-25 00:13 - 22375936 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-11-09 10:43 - 2016-10-25 00:05 - 06312448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2016-11-09 10:43 - 2016-10-25 00:05 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-11-09 10:43 - 2016-10-25 00:05 - 02582016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2016-11-09 10:43 - 2016-10-25 00:05 - 01385472 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
2016-11-09 10:43 - 2016-10-25 00:02 - 24610304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-11-09 10:43 - 2016-10-25 00:01 - 13392384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-11-09 10:43 - 2016-10-24 23:59 - 14258688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-11-09 10:43 - 2016-10-24 23:58 - 07536128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2016-11-09 10:43 - 2016-10-24 23:55 - 04171264 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2016-11-09 10:43 - 2016-10-24 23:55 - 02217984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2016-11-09 10:43 - 2016-10-24 23:53 - 03294208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2016-11-09 10:43 - 2016-10-24 23:53 - 00583680 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr
2016-11-09 10:43 - 2016-10-24 23:52 - 03555840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2016-11-09 10:43 - 2016-10-24 23:52 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2016-11-09 10:43 - 2016-10-24 23:51 - 00341504 _____ (Microsoft Corporation) C:\WINDOWS\system32\RADCUI.dll
2016-11-09 10:43 - 2016-10-24 23:50 - 01487872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll
2016-11-09 10:43 - 2016-10-24 23:48 - 07838208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-11-09 10:43 - 2016-10-24 23:48 - 00958976 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2016-11-09 10:43 - 2016-10-24 23:45 - 18673664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-11-09 10:43 - 2016-10-24 23:44 - 19348480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-11-09 10:43 - 2016-10-24 23:44 - 12134400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-11-09 10:43 - 2016-10-24 23:43 - 03664384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-11-09 10:43 - 2016-10-24 23:30 - 12590080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2016-11-09 10:43 - 2016-10-24 23:29 - 00515584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr
2016-11-09 10:43 - 2016-10-24 23:26 - 05660160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-11-09 10:43 - 2016-10-24 20:47 - 00445873 _____ C:\WINDOWS\system32\ApnDatabase.xml
2016-11-09 10:43 - 2016-09-07 00:22 - 00604920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-11-09 10:42 - 2016-11-02 10:12 - 00379232 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-11-09 10:42 - 2016-11-02 10:08 - 00636296 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-11-09 10:42 - 2016-11-02 09:25 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-11-09 10:42 - 2016-10-25 04:44 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-11-09 10:42 - 2016-10-25 04:44 - 00875480 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-11-09 10:42 - 2016-10-25 04:42 - 02656952 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2016-11-09 10:42 - 2016-10-25 04:42 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-11-09 10:42 - 2016-10-25 04:42 - 01098648 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2016-11-09 10:42 - 2016-10-25 04:42 - 00125280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mup.sys
2016-11-09 10:42 - 2016-10-25 04:42 - 00037744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2016-11-09 10:42 - 2016-10-25 04:41 - 01819208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-11-09 10:42 - 2016-10-25 04:40 - 00384864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2016-11-09 10:42 - 2016-10-25 04:39 - 01238584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Taskmgr.exe
2016-11-09 10:42 - 2016-10-25 04:39 - 00754664 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2016-11-09 10:42 - 2016-10-25 04:26 - 00528736 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2016-11-09 10:42 - 2016-10-25 04:19 - 03449168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2016-11-09 10:42 - 2016-10-25 03:50 - 00439136 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcfgx.dll
2016-11-09 10:42 - 2016-10-25 03:42 - 01322248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2016-11-09 10:42 - 2016-10-25 03:39 - 00730352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2016-11-09 10:42 - 2016-10-25 03:39 - 00304752 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2016-11-09 10:42 - 2016-10-25 03:38 - 00565600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2016-11-09 10:42 - 2016-10-25 03:38 - 00374008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-11-09 10:42 - 2016-10-25 03:37 - 04515256 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2016-11-09 10:42 - 2016-10-25 03:37 - 01603224 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
2016-11-09 10:42 - 2016-10-25 03:37 - 00725776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2016-11-09 10:42 - 2016-10-25 03:36 - 01540216 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2016-11-09 10:42 - 2016-10-25 03:36 - 00692136 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2016-11-09 10:42 - 2016-10-25 03:34 - 01128104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2016-11-09 10:42 - 2016-10-25 03:34 - 00625000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2016-11-09 10:42 - 2016-10-25 03:34 - 00106928 _____ (Microsoft Corporation) C:\WINDOWS\system32\phoneactivate.exe
2016-11-09 10:42 - 2016-10-25 03:33 - 00341936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2016-11-09 10:42 - 2016-10-25 03:03 - 02549456 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2016-11-09 10:42 - 2016-10-25 03:03 - 01988440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-11-09 10:42 - 2016-10-25 03:02 - 00577376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-11-09 10:42 - 2016-10-25 03:02 - 00393568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2016-11-09 10:42 - 2016-10-25 03:01 - 01776768 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2016-11-09 10:42 - 2016-10-25 03:01 - 01415200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2016-11-09 10:42 - 2016-10-25 03:01 - 00324448 _____ (Microsoft Corporation) C:\WINDOWS\system32\input.dll
2016-11-09 10:42 - 2016-10-25 02:46 - 00376528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2016-11-09 10:42 - 2016-10-25 02:45 - 00503600 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMRServer.dll
2016-11-09 10:42 - 2016-10-25 02:32 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfp.dll
2016-11-09 10:42 - 2016-10-25 02:31 - 00299008 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
2016-11-09 10:42 - 2016-10-25 02:31 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\vss_ps.dll
2016-11-09 10:42 - 2016-10-25 02:30 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkInternalPS.dll
2016-11-09 10:42 - 2016-10-25 02:24 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bowser.sys
2016-11-09 10:42 - 2016-10-25 02:21 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2016-11-09 10:42 - 2016-10-25 02:21 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2016-11-09 10:42 - 2016-10-25 02:19 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\scfilter.sys
2016-11-09 10:42 - 2016-10-25 02:16 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2016-11-09 10:42 - 2016-10-25 02:13 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardDlg.dll
2016-11-09 10:42 - 2016-10-25 02:13 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2016-11-09 10:42 - 2016-10-25 02:12 - 00257536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpr.exe
2016-11-09 10:42 - 2016-10-25 02:12 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSMDesktopProvider.dll
2016-11-09 10:42 - 2016-10-25 02:12 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2016-11-09 10:42 - 2016-10-25 02:10 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\system32\unimdm.tsp
2016-11-09 10:42 - 2016-10-25 02:10 - 00245248 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountExtension.dll
2016-11-09 10:42 - 2016-10-25 02:10 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll
2016-11-09 10:42 - 2016-10-25 02:09 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\oemlicense.dll
2016-11-09 10:42 - 2016-10-25 02:08 - 00188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndiswan.sys
2016-11-09 10:42 - 2016-10-25 02:05 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\FingerprintEnrollment.dll
2016-11-09 10:42 - 2016-10-25 02:02 - 00291328 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2016-11-09 10:42 - 2016-10-25 02:02 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2016-11-09 10:42 - 2016-10-25 02:02 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll
2016-11-09 10:42 - 2016-10-25 02:00 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2016-11-09 10:42 - 2016-10-25 01:59 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2016-11-09 10:42 - 2016-10-25 01:59 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\certprop.dll
2016-11-09 10:42 - 2016-10-25 01:59 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsvc.dll
2016-11-09 10:42 - 2016-10-25 01:59 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\UXInit.dll
2016-11-09 10:42 - 2016-10-25 01:58 - 00463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\intl.cpl
2016-11-09 10:42 - 2016-10-25 01:58 - 00289280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2016-11-09 10:42 - 2016-10-25 01:58 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFPlatform.dll
2016-11-09 10:42 - 2016-10-25 01:57 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2016-11-09 10:42 - 2016-10-25 01:57 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
2016-11-09 10:42 - 2016-10-25 01:56 - 00319488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3ui.dll
2016-11-09 10:42 - 2016-10-25 01:56 - 00317952 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll
2016-11-09 10:42 - 2016-10-25 01:56 - 00301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Dxpserver.exe
2016-11-09 10:42 - 2016-10-25 01:55 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll
2016-11-09 10:42 - 2016-10-25 01:55 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
2016-11-09 10:42 - 2016-10-25 01:55 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkDesktopSettings.dll
2016-11-09 10:42 - 2016-10-25 01:54 - 00188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.PicturePassword.dll
2016-11-09 10:42 - 2016-10-25 01:53 - 00714240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2016-11-09 10:42 - 2016-10-25 01:53 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\AdmTmpl.dll
2016-11-09 10:42 - 2016-10-25 01:53 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2016-11-09 10:42 - 2016-10-25 01:53 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2016-11-09 10:42 - 2016-10-25 01:53 - 00279040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ListSvc.dll
2016-11-09 10:42 - 2016-10-25 01:52 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
2016-11-09 10:42 - 2016-10-25 01:52 - 00522240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
2016-11-09 10:42 - 2016-10-25 01:52 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2016-11-09 10:42 - 2016-10-25 01:52 - 00370688 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack_win.dll
2016-11-09 10:42 - 2016-10-25 01:52 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\APHostService.dll
2016-11-09 10:42 - 2016-10-25 01:51 - 00950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\WFS.exe
2016-11-09 10:42 - 2016-10-25 01:51 - 00715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2016-11-09 10:42 - 2016-10-25 01:51 - 00469504 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsettingsprovider.dll
2016-11-09 10:42 - 2016-10-25 01:51 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll
2016-11-09 10:42 - 2016-10-25 01:51 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExecModelClient.dll
2016-11-09 10:42 - 2016-10-25 01:50 - 00492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2016-11-09 10:42 - 2016-10-25 01:50 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXP.dll
2016-11-09 10:42 - 2016-10-25 01:50 - 00363008 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneOm.dll
2016-11-09 10:42 - 2016-10-25 01:49 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\netman.dll
2016-11-09 10:42 - 2016-10-25 01:48 - 00344064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Picker.dll
2016-11-09 10:42 - 2016-10-25 01:47 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll
2016-11-09 10:42 - 2016-10-25 01:47 - 00392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2016-11-09 10:42 - 2016-10-25 01:47 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.OneCore.dll
2016-11-09 10:42 - 2016-10-25 01:47 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\system32\edputil.dll
2016-11-09 10:42 - 2016-10-25 01:46 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\system32\windowsperformancerecordercontrol.dll
2016-11-09 10:42 - 2016-10-25 01:46 - 00630784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2016-11-09 10:42 - 2016-10-25 01:45 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2016-11-09 10:42 - 2016-10-25 01:44 - 01479168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2016-11-09 10:42 - 2016-10-25 01:44 - 00602112 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll
2016-11-09 10:42 - 2016-10-25 01:43 - 00606720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2016-11-09 10:42 - 2016-10-25 01:43 - 00440832 _____ (Microsoft Corporation) C:\WINDOWS\system32\certreq.exe
2016-11-09 10:42 - 2016-10-25 01:42 - 01813504 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2016-11-09 10:42 - 2016-10-25 01:42 - 00656896 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll
2016-11-09 10:42 - 2016-10-25 01:42 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToReceiver.dll
2016-11-09 10:42 - 2016-10-25 01:41 - 00892416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.dll
2016-11-09 10:42 - 2016-10-25 01:41 - 00492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll
2016-11-09 10:42 - 2016-10-25 01:41 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2016-11-09 10:42 - 2016-10-25 01:41 - 00356864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2016-11-09 10:42 - 2016-10-25 01:40 - 00607232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxApplicabilityEngine.dll
2016-11-09 10:42 - 2016-10-25 01:40 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrGidsHandler.dll
2016-11-09 10:42 - 2016-10-25 01:40 - 00466944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2016-11-09 10:42 - 2016-10-25 01:39 - 00941568 _____ (Microsoft Corporation) C:\WINDOWS\system32\MiracastReceiver.dll
2016-11-09 10:42 - 2016-10-25 01:39 - 00791552 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2016-11-09 10:42 - 2016-10-25 01:39 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2016-11-09 10:42 - 2016-10-25 01:39 - 00183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSSync.dll
2016-11-09 10:42 - 2016-10-25 01:38 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2016-11-09 10:42 - 2016-10-25 01:38 - 00588288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wvc.dll
2016-11-09 10:42 - 2016-10-25 01:38 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
2016-11-09 10:42 - 2016-10-25 01:38 - 00480768 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2016-11-09 10:42 - 2016-10-25 01:37 - 02125312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll
2016-11-09 10:42 - 2016-10-25 01:37 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2016-11-09 10:42 - 2016-10-25 01:36 - 00965632 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2016-11-09 10:42 - 2016-10-25 01:36 - 00538112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2016-11-09 10:42 - 2016-10-25 01:36 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2016-11-09 10:42 - 2016-10-25 01:35 - 00515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2016-11-09 10:42 - 2016-10-25 01:34 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-11-09 10:42 - 2016-10-25 01:34 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2016-11-09 10:42 - 2016-10-25 01:33 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
2016-11-09 10:42 - 2016-10-25 01:32 - 01387008 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-11-09 10:42 - 2016-10-25 01:32 - 01159168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationFrame.dll
2016-11-09 10:42 - 2016-10-25 01:32 - 01053696 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-11-09 10:42 - 2016-10-25 01:32 - 01037824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmartcardCredentialProvider.dll
2016-11-09 10:42 - 2016-10-25 01:32 - 00990208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2016-11-09 10:42 - 2016-10-25 01:32 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2016-11-09 10:42 - 2016-10-25 01:32 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncutil.dll
2016-11-09 10:42 - 2016-10-25 01:30 - 00853504 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2016-11-09 10:42 - 2016-10-25 01:30 - 00529920 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2016-11-09 10:42 - 2016-10-25 01:29 - 01847808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2016-11-09 10:42 - 2016-10-25 01:29 - 01575936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-11-09 10:42 - 2016-10-25 01:29 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-11-09 10:42 - 2016-10-25 01:27 - 02731008 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll
2016-11-09 10:42 - 2016-10-25 01:27 - 00961536 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2016-11-09 10:42 - 2016-10-25 01:26 - 02103296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll
2016-11-09 10:42 - 2016-10-25 01:25 - 01872896 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2016-11-09 10:42 - 2016-10-25 01:25 - 01319424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2016-11-09 10:42 - 2016-10-25 01:25 - 01291776 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2016-11-09 10:42 - 2016-10-25 01:24 - 04456448 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2016-11-09 10:42 - 2016-10-25 01:24 - 01211904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2016-11-09 10:42 - 2016-10-25 01:24 - 00549888 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2016-11-09 10:42 - 2016-10-25 01:23 - 01073152 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2016-11-09 10:42 - 2016-10-25 01:22 - 01424384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdc.dll
2016-11-09 10:42 - 2016-10-25 01:22 - 00638976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2016-11-09 10:42 - 2016-10-25 01:21 - 01570816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe
2016-11-09 10:42 - 2016-10-25 01:21 - 00236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\licensingdiag.exe
2016-11-09 10:42 - 2016-10-25 01:21 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-11-09 10:42 - 2016-10-25 01:20 - 03549696 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll
2016-11-09 10:42 - 2016-10-25 01:17 - 00821760 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2016-11-09 10:42 - 2016-10-25 01:16 - 03415040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll
2016-11-09 10:42 - 2016-10-25 01:16 - 01062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2016-11-09 10:42 - 2016-10-25 01:11 - 00701952 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
2016-11-09 10:42 - 2016-10-25 01:09 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2016-11-09 10:42 - 2016-10-25 01:05 - 03587584 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-11-09 10:42 - 2016-10-25 01:05 - 02610176 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-11-09 10:42 - 2016-10-25 01:03 - 06675968 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2016-11-09 10:42 - 2016-10-25 01:03 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2016-11-09 10:42 - 2016-10-25 01:01 - 01755648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dui70.dll
2016-11-09 10:42 - 2016-10-25 01:01 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2016-11-09 10:42 - 2016-10-25 00:54 - 02067968 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-11-09 10:42 - 2016-10-25 00:54 - 01097216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-11-09 10:42 - 2016-10-25 00:54 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2016-11-09 10:42 - 2016-10-25 00:53 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2016-11-09 10:42 - 2016-10-25 00:52 - 04170240 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll
2016-11-09 10:42 - 2016-10-25 00:52 - 00693760 _____ (Microsoft Corporation) C:\WINDOWS\system32\internetmail.dll
2016-11-09 10:42 - 2016-10-25 00:52 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2016-11-09 10:42 - 2016-10-25 00:51 - 02175488 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-11-09 10:42 - 2016-10-25 00:50 - 02874880 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmcndmgr.dll
2016-11-09 10:42 - 2016-10-25 00:49 - 01997312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2016-11-09 10:42 - 2016-10-25 00:48 - 04826624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2016-11-09 10:42 - 2016-10-25 00:47 - 03355136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2016-11-09 10:42 - 2016-10-25 00:47 - 00453632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AdmTmpl.dll
2016-11-09 10:42 - 2016-10-25 00:43 - 02635776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-11-09 10:42 - 2016-10-25 00:40 - 00984576 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2016-11-09 10:42 - 2016-10-25 00:39 - 05503488 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2016-11-09 10:42 - 2016-10-25 00:38 - 03585536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2016-11-09 10:42 - 2016-10-25 00:37 - 00765952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-11-09 10:42 - 2016-10-25 00:35 - 02902528 _____ (Microsoft Corporation) C:\WINDOWS\system32\themeui.dll
2016-11-09 10:42 - 2016-10-25 00:34 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-11-09 10:42 - 2016-10-25 00:34 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2016-11-09 10:42 - 2016-10-25 00:28 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll
2016-11-09 10:42 - 2016-10-25 00:26 - 02563584 _____ (Microsoft Corporation) C:\WINDOWS\system32\themecpl.dll
2016-11-09 10:42 - 2016-10-25 00:20 - 01797120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2016-11-09 10:42 - 2016-10-25 00:14 - 00651776 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserLanguagesCpl.dll
2016-11-09 10:42 - 2016-10-25 00:13 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2016-11-09 10:42 - 2016-10-25 00:12 - 11544576 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-11-09 10:42 - 2016-10-25 00:10 - 01568256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2016-11-09 10:42 - 2016-10-25 00:10 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
2016-11-09 10:42 - 2016-10-25 00:05 - 02352128 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2016-11-09 10:42 - 2016-10-25 00:03 - 00636928 _____ (Microsoft Corporation) C:\WINDOWS\system32\hgcpl.dll
2016-11-09 10:42 - 2016-10-25 00:02 - 06976512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-11-09 10:42 - 2016-10-25 00:02 - 03994624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-11-09 10:42 - 2016-10-25 00:02 - 03459584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll
2016-11-09 10:42 - 2016-10-24 23:44 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2016-11-09 10:42 - 2016-10-24 23:43 - 00321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\GlobCollationHost.dll
2016-11-09 10:42 - 2016-10-24 21:19 - 00775336 _____ C:\WINDOWS\SysWOW64\locale.nls
2016-11-09 10:42 - 2016-10-24 21:19 - 00775336 _____ C:\WINDOWS\system32\locale.nls
2016-11-08 21:58 - 2016-11-08 21:58 - 00001100 _____ C:\Users\Public\Desktop\Diablo III Public Test.lnk
2016-11-08 21:58 - 2016-11-08 21:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III Public Test
2016-11-08 21:54 - 2016-11-22 17:12 - 00000000 ____D C:\Program Files (x86)\Diablo III Public Test
2016-11-03 13:10 - 2016-11-03 13:10 - 06668096 _____ (Tim Kosse) C:\Users\Matt\Downloads\FileZilla_3.22.2.2_win64-setup.exe
2016-11-03 13:10 - 2016-11-03 13:10 - 00002162 _____ C:\Users\Public\Desktop\FileZilla Client.lnk
2016-11-02 16:36 - 2016-11-02 16:36 - 00003746 _____ C:\WINDOWS\System32\Tasks\HP AR Program Upload - 84dfd3c3ee044e3694a3c09b0b06da23d70ae608ce0b4ea89076e7c5558c523c
2016-11-02 11:48 - 2016-11-02 11:48 - 00000000 _____ C:\WINDOWS\system32\GfxValDisplayLog.bin
2016-11-01 22:06 - 2016-11-01 22:06 - 39862848 _____ (Intel Corporation) C:\WINDOWS\system32\igdumdim64.dll
2016-11-01 22:06 - 2016-11-01 22:06 - 38903912 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdumdim32.dll
2016-11-01 22:06 - 2016-11-01 22:06 - 34823872 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd11dxva32.dll
2016-11-01 22:06 - 2016-11-01 22:06 - 33479360 _____ (Intel Corporation) C:\WINDOWS\system32\igd11dxva64.dll
2016-11-01 22:06 - 2016-11-01 22:06 - 12680800 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd10iumd32.dll
2016-11-01 22:06 - 2016-11-01 22:06 - 06696832 _____ (Intel Corporation) C:\WINDOWS\system32\igdusc64.dll
2016-11-01 22:06 - 2016-11-01 22:06 - 05140472 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdusc32.dll
2016-11-01 22:06 - 2016-11-01 22:06 - 02393176 _____ (Intel Corporation) C:\WINDOWS\system32\igdmd64.dll
2016-11-01 22:06 - 2016-11-01 22:06 - 01816720 _____ (Intel Corporation) C:\WINDOWS\system32\iglhsip64.dll
2016-11-01 22:06 - 2016-11-01 22:06 - 01814064 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\iglhsip32.dll
2016-11-01 22:06 - 2016-11-01 22:06 - 00242160 _____ (Intel Corporation) C:\WINDOWS\system32\iglhcp64.dll
2016-11-01 22:06 - 2016-11-01 22:06 - 00205360 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\iglhcp32.dll
2016-11-01 22:06 - 2016-11-01 22:06 - 00183984 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcmrt64.dll
2016-11-01 22:06 - 2016-11-01 22:06 - 00182960 _____ (Intel Corporation) C:\WINDOWS\system32\igfx11cmrt64.dll
2016-11-01 22:06 - 2016-11-01 22:06 - 00160272 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxcmrt32.dll
2016-11-01 22:06 - 2016-11-01 22:06 - 00160272 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfx11cmrt32.dll
2016-11-01 22:06 - 2016-11-01 22:06 - 00055248 _____ (Intel Corporation) C:\WINDOWS\system32\igfxexps.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 29101576 _____ (Intel Corporation) C:\WINDOWS\system32\common_clang64.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 19861512 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\common_clang32.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 15837984 _____ (Intel Corporation) C:\WINDOWS\system32\igd10iumd64.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 15488928 _____ (Intel Corporation) C:\WINDOWS\system32\igc64.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 13483208 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igc32.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 11742216 _____ (Intel Corporation) C:\WINDOWS\system32\ig75icd64.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 08732168 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\ig75icd32.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 05688840 _____ (Intel Corporation) C:\WINDOWS\system32\igdmcl64.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 05262856 _____ (Intel Corporation) C:\WINDOWS\system32\GfxResources.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 04928528 _____ (Intel Corporation) C:\WINDOWS\system32\igdrcl64.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 04363784 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdrcl32.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 04270680 _____ (Intel Corporation) C:\WINDOWS\system32\igd12umd64.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 04239704 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd12umd32.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 03971592 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdmcl32.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 01858640 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdmd32.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 01590792 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcmjit64.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 01178632 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxcmjit32.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 01027056 _____ C:\WINDOWS\system32\igfxSDK.exe
2016-11-01 22:05 - 2016-11-01 22:05 - 00968168 _____ (Intel Corporation) C:\WINDOWS\system32\Gfxv4_0.exe
2016-11-01 22:05 - 2016-11-01 22:05 - 00964592 _____ (Intel Corporation) C:\WINDOWS\system32\Gfxv2_0.exe
2016-11-01 22:05 - 2016-11-01 22:05 - 00705032 _____ (Intel Corporation) C:\WINDOWS\system32\MetroIntelGenericUIFramework.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00536560 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiUMS64.exe
2016-11-01 22:05 - 2016-11-01 22:05 - 00466920 _____ (Intel Corporation) C:\WINDOWS\system32\GfxUIEx.exe
2016-11-01 22:05 - 2016-11-01 22:05 - 00448496 _____ (Intel Corporation) C:\WINDOWS\system32\IntelCpHDCPSvc.exe
2016-11-01 22:05 - 2016-11-01 22:05 - 00439304 _____ (Intel Corporation) C:\WINDOWS\system32\igdbcl64.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00416264 _____ (Intel Corporation) C:\WINDOWS\system32\IntelOpenCL64.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00401896 _____ C:\WINDOWS\system32\igfxTray.exe
2016-11-01 22:05 - 2016-11-01 22:05 - 00390152 _____ (Intel Corporation) C:\WINDOWS\system32\igfxOSP.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00388616 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdbcl32.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00350184 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiMCComp64.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00318472 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\IntelOpenCL32.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00312304 _____ (Intel Corporation) C:\WINDOWS\system32\igd10idpp64.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00301552 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\IntelCpHeciSvc.exe
2016-11-01 22:05 - 2016-11-01 22:05 - 00297168 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd10idpp32.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00273416 _____ C:\WINDOWS\system32\igfxCPL.cpl
2016-11-01 22:05 - 2016-11-01 22:05 - 00268784 _____ (Intel Corporation) C:\WINDOWS\system32\igfxHK.exe
2016-11-01 22:05 - 2016-11-01 22:05 - 00266248 _____ (Intel Corporation) C:\WINDOWS\system32\igdfcl64.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00237040 _____ (Intel Corporation) C:\WINDOWS\system32\igfxext.exe
2016-11-01 22:05 - 2016-11-01 22:05 - 00232432 _____ (Intel Corporation) C:\WINDOWS\system32\DPTopologyApp.exe
2016-11-01 22:05 - 2016-11-01 22:05 - 00231920 _____ (Intel Corporation) C:\WINDOWS\system32\DPTopologyAppv2_0.exe
2016-11-01 22:05 - 2016-11-01 22:05 - 00225288 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdfcl32.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00223248 _____ (Intel Corporation) C:\WINDOWS\system32\igdde64.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00212488 _____ (Intel Corporation) C:\WINDOWS\system32\igfxCoIn_v4531.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00193032 _____ (Intel Corporation) C:\WINDOWS\system32\igdail64.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00181840 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdde32.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00175088 _____ (Intel Corporation) C:\WINDOWS\system32\difx64.exe
2016-11-01 22:05 - 2016-11-01 22:05 - 00174088 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdail32.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00111624 _____ ( ) C:\WINDOWS\system32\igfxSDKLibv2_0.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00103952 _____ (Khronos Group) C:\WINDOWS\SysWOW64\Intel_OpenCL_ICD32.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00103432 _____ C:\WINDOWS\system32\igfxCUIServicePS.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00100872 _____ ( ) C:\WINDOWS\system32\igfxSDKLib.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00099848 _____ (Khronos Group) C:\WINDOWS\system32\Intel_OpenCL_ICD64.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00095240 _____ ( ) C:\WINDOWS\system32\igfxDHLibv2_0.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00084488 _____ ( ) C:\WINDOWS\system32\igfxDHLib.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00052744 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxexps32.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00029192 _____ ( ) C:\WINDOWS\system32\igfxDILibv2_0.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00029192 _____ ( ) C:\WINDOWS\system32\igfxDILib.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00027656 _____ ( ) C:\WINDOWS\system32\igfxEMLibv2_0.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00027656 _____ ( ) C:\WINDOWS\system32\igfxEMLib.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00022536 _____ ( ) C:\WINDOWS\system32\igfxLHMLibv2_0.dll
2016-11-01 22:05 - 2016-11-01 22:05 - 00022536 _____ ( ) C:\WINDOWS\system32\igfxLHMLib.dll
2016-10-27 19:09 - 2016-10-27 19:10 - 00041177 _____ C:\Users\Matt\Desktop\seans_version_6.2_major_changes.odt
2016-10-27 10:15 - 2016-10-27 10:17 - 00036081 _____ C:\Users\Matt\Desktop\sean_new_class_paths.odt
2016-10-25 13:01 - 2016-11-06 21:01 - 00000000 ___HD C:\Users\Matt\Desktop\Corel Auto-Preserve

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-11-22 17:50 - 2016-03-13 16:25 - 00004146 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{3C2B78E5-8E20-4852-B8CD-033795BCDA3F}
2016-11-22 17:50 - 2014-09-14 03:17 - 00000000 ____D C:\Users\Matt\AppData\Local\Battle.net
2016-11-22 17:44 - 2015-12-04 08:41 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-11-22 17:21 - 2014-12-20 21:23 - 00000920 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-183162068-1737580067-508966621-1000UA.job
2016-11-22 17:21 - 2014-09-18 01:08 - 00000922 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-11-22 17:18 - 2016-08-18 13:35 - 00000000 ____D C:\Users\Matt\AppData\LocalLow\Mozilla
2016-11-22 14:30 - 2014-09-14 03:17 - 00000000 ____D C:\Program Files (x86)\Battle.net
2016-11-22 14:08 - 2016-01-24 10:12 - 01024140 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-11-22 14:08 - 2015-10-30 02:21 - 00000000 ____D C:\WINDOWS\INF
2016-11-22 14:04 - 2014-09-13 05:07 - 00000000 ____D C:\Program Files (x86)\SpeedFan
2016-11-22 14:03 - 2014-09-18 01:08 - 00000918 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-11-22 14:02 - 2016-01-24 10:09 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-11-22 14:02 - 2014-09-12 01:24 - 00000000 __SHD C:\Users\Matt\IntelGraphicsProfiles
2016-11-22 14:01 - 2016-08-22 08:22 - 00000000 ____D C:\ProgramData\NVIDIA
2016-11-22 14:01 - 2016-01-24 10:23 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-11-22 14:01 - 2014-09-12 03:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-11-22 14:00 - 2015-10-30 01:28 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2016-11-22 02:33 - 2015-10-30 02:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-11-22 02:33 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-11-21 18:21 - 2014-12-20 21:23 - 00000868 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-183162068-1737580067-508966621-1000Core.job
2016-11-20 14:33 - 2014-09-14 15:08 - 00000000 ____D C:\Program Files (x86)\Steam
2016-11-16 14:02 - 2014-09-18 00:06 - 00000000 ____D C:\Users\Matt\AppData\Roaming\FileZilla
2016-11-16 13:31 - 2014-10-08 23:10 - 00000600 _____ C:\Users\Matt\AppData\Local\PUTTY.RND
2016-11-14 20:22 - 2014-09-18 01:09 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-11-13 10:24 - 2014-09-18 01:08 - 00000000 ____D C:\Users\Matt\AppData\Local\Google
2016-11-12 15:30 - 2014-09-14 03:19 - 00000000 ____D C:\Program Files (x86)\Diablo III
2016-11-12 12:14 - 2015-07-01 00:50 - 00000000 ____D C:\Users\Matt\Desktop\card game
2016-11-12 10:46 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\rescache
2016-11-10 22:28 - 2016-02-06 01:09 - 00000000 ____D C:\Users\Matt\AppData\LocalLow\Obsidian Entertainment
2016-11-10 08:45 - 2014-10-02 02:49 - 00000000 ____D C:\Users\Matt\AppData\Roaming\KeePass
2016-11-10 08:02 - 2015-09-10 00:44 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-11-10 03:32 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-11-10 03:32 - 2015-10-30 02:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-11-10 03:21 - 2016-01-24 10:05 - 00255632 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-11-10 03:17 - 2015-10-30 02:24 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2016-11-10 03:17 - 2015-10-30 02:24 - 00000000 ___SD C:\WINDOWS\system32\F12
2016-11-10 03:17 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-11-10 03:17 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\migwiz
2016-11-10 03:16 - 2015-10-30 02:24 - 00000000 ___RD C:\WINDOWS\PrintDialog
2016-11-10 03:16 - 2015-10-30 02:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-11-10 03:16 - 2015-10-30 02:24 - 00000000 ___RD C:\WINDOWS\DevicesFlow
2016-11-10 03:16 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\Provisioning
2016-11-10 03:16 - 2015-10-30 02:24 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2016-11-10 03:16 - 2015-10-30 02:24 - 00000000 ____D C:\Program Files\Windows Defender
2016-11-10 03:16 - 2015-10-30 02:24 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2016-11-10 03:16 - 2015-10-30 02:24 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2016-11-09 11:34 - 2014-10-02 02:35 - 00000000 ____D C:\000000
2016-11-09 11:12 - 2014-09-12 02:00 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-11-09 11:10 - 2014-09-12 02:00 - 141011376 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-11-09 10:18 - 2016-01-24 13:02 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
2016-11-08 22:27 - 2014-09-14 04:44 - 00000000 ____D C:\Users\Matt\Documents\Diablo III
2016-11-03 13:10 - 2016-10-16 14:37 - 06647224 _____ (Tim Kosse) C:\Users\Matt\Downloads\FileZilla_3.22.1_win64-setup.exe
2016-11-03 13:10 - 2014-09-18 00:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2016-11-03 13:10 - 2014-09-18 00:06 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client
2016-11-02 11:48 - 2016-01-24 10:09 - 00000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
2016-11-01 22:05 - 2016-01-24 10:09 - 00099848 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2016-11-01 22:05 - 2016-01-24 09:40 - 07966192 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\igdkmd64.sys
2016-11-01 22:05 - 2016-01-24 09:40 - 02142224 _____ (Intel Corporation) C:\WINDOWS\system32\igfxLHM.dll
2016-11-01 22:05 - 2016-01-24 09:40 - 00756744 _____ (Intel Corporation) C:\WINDOWS\system32\igfxDH.dll
2016-11-01 22:05 - 2016-01-24 09:40 - 00398856 _____ (Intel Corporation) C:\WINDOWS\system32\igfxDI.dll
2016-11-01 22:05 - 2016-01-24 09:40 - 00373744 _____ (Intel Corporation) C:\WINDOWS\system32\igfxCUIService.exe
2016-11-01 22:05 - 2016-01-24 09:40 - 00354800 _____ (Intel Corporation) C:\WINDOWS\system32\igfxEM.exe
2016-11-01 22:05 - 2016-01-24 09:40 - 00254984 _____ (Intel Corporation) C:\WINDOWS\system32\igfxDTCM.dll
2016-11-01 22:05 - 2015-10-30 02:18 - 00103952 _____ (Khronos Group) C:\WINDOWS\SysWOW64\opencl.dll
2016-10-28 16:48 - 2015-10-30 02:26 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-10-28 16:48 - 2015-10-30 02:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-10-28 15:44 - 2014-09-13 06:05 - 00000000 ____D C:\Users\Matt\AppData\Local\CrashDumps
2016-10-27 20:22 - 2010-11-20 22:27 - 00485032 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-10-25 03:58 - 2016-01-24 10:08 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2016-10-23 10:06 - 2014-10-18 09:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-10-23 10:06 - 2014-10-18 09:50 - 00000000 ____D C:\Program Files (x86)\Java
2016-10-23 10:06 - 2014-09-17 18:16 - 00000000 ____D C:\ProgramData\Oracle
2016-10-23 10:05 - 2014-10-18 09:50 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll

==================== Files in the root of some directories =======

2015-08-15 13:53 - 2015-08-15 13:53 - 0000100 _____ () C:\Users\Matt\AppData\Roaming\ScriptStudioLayout.ini
2015-08-15 13:53 - 2015-08-15 13:53 - 0000046 _____ () C:\Users\Matt\AppData\Roaming\ScriptStudioOptions.ini
2014-12-21 18:21 - 2014-12-21 18:34 - 0003584 _____ () C:\Users\Matt\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-12-26 01:33 - 2015-12-26 01:33 - 0000000 _____ () C:\Users\Matt\AppData\Local\Driver_LOM_8161Present.flag
2014-10-08 23:10 - 2016-11-16 13:31 - 0000600 _____ () C:\Users\Matt\AppData\Local\PUTTY.RND
2016-09-29 22:07 - 2016-09-29 22:07 - 0000724 _____ () C:\Users\Matt\AppData\Local\recently-used.xbel
2014-09-15 23:49 - 2016-03-17 16:24 - 0007638 _____ () C:\Users\Matt\AppData\Local\resmon.resmoncfg
2016-09-21 15:10 - 2016-09-21 15:10 - 0000057 _____ () C:\ProgramData\Ament.ini

Some files in TEMP:
====================
C:\Users\Matt\AppData\Local\Temp\jansi-32-2255424595499729363.dll
C:\Users\Matt\AppData\Local\Temp\jansi-32-8708393685809737409.dll
C:\Users\Matt\AppData\Local\Temp\jre-8u101-windows-au.exe
C:\Users\Matt\AppData\Local\Temp\jre-8u111-windows-au.exe
C:\Users\Matt\AppData\Local\Temp\jre-8u71-windows-au.exe
C:\Users\Matt\AppData\Local\Temp\jre-8u73-windows-au.exe
C:\Users\Matt\AppData\Local\Temp\jre-8u77-windows-au.exe
C:\Users\Matt\AppData\Local\Temp\jre-8u91-windows-au.exe
C:\Users\Matt\AppData\Local\Temp\npp.6.9.2.Installer.exe
C:\Users\Matt\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Matt\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Matt\AppData\Local\Temp\nvStInst.exe
C:\Users\Matt\AppData\Local\Temp\sfamcc00001.dll
C:\Users\Matt\AppData\Local\Temp\sfareca00001.dll
C:\Users\Matt\AppData\Local\Temp\xmlUpdater.exe


==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-11-21 11:39

==================== End of FRST.txt ============================

Addition.txt

Link to post
Share on other sites

Negative. It happened a few times (5 or 6) this afternoon and since I rebooted not once again.

Like to note every time this happened I was following a link on facebook titled "Suggested Post" (which is facebooks advertising). Doing this action is the only times it has happened.

Edited by CrowTrobot
Link to post
Share on other sites

Your logs do not show any obvious malware or infection. run one more scan with Malwarebytes with the following settings..

Please open Malwarebytes Anti-Malware.
 
  • On the Settings tab > Detection and Protection sub tab, Detection Options, tick the box "Scan for rootkits".
  • Under Non-Malware Protection sub tab Change PUP and PUM entries to Treat detections as Malware
  • Click on the Scan tab, then click on Scan Now >> . If an update is available, click the Update Now button.
  • A Threat Scan will begin.
  • When the Scan is complete Apply Actions to any found entries.
  • Wait for the prompt to restart the computer to appear (if applicable), then click on Yes.
  • After the restart once you are back at your desktop, open MBAM once more.

To get the log from Malwarebytes do the following:
 
  • Click on the History tab > Application Logs.
  • Double click on the Scan log which shows the Date and time of the scan just performed.
  • Click Export > From export you have three options:
    Copy to Clipboard - if seleted right click to your reply and select "Paste" log will be pasted to your reply
    Text file (*.txt) - if selected you will have to name the file and save to a place of choice, recommend "Desktop" then attach to reply
    XML file (*.xml) - if selected you will have to name the file and save to a place of choice, recommend "Desktop" then attach to reply
     
  • Please use "Copy to Clipboard, then Right click to your reply > select "Paste" that will copy the log to your reply…

Thank you,

Kevin.

Link to post
Share on other sites

Way ahead of you after reading a recent reply of yours in another thread. =)

--

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 11/22/2016
Scan Time: 5:44 PM
Logfile: 
Administrator: Yes

Version: 2.2.1.1043
Malware Database: v2016.11.22.14
Rootkit Database: v2016.11.20.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 10
CPU: x64
File System: NTFS
User: Matt

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 395573
Time Elapsed: 14 min, 45 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)

 

Link to post
Share on other sites

Bit of maintenance:

Download attached fixlist.txt file (end of reply) and save it to the Desktop, or the folder you saved FRST into.
NOTE. It's important that both FRST and fixlist.txt are in the same location or the fix will not work.

Open FRST and press the Fix button just once and wait.
The tool will make a log on the Desktop (Fixlog.txt) or the folder it was ran from. Please post it to your reply.
 

 

fixlist.txt

Link to post
Share on other sites

Fix result of Farbar Recovery Scan Tool (x64) Version: 20-11-2016 01
Ran by Matt (22-11-2016 18:47:33) Run:1
Running from C:\Users\Matt\Desktop
Loaded Profiles: Matt (Available Profiles: Matt & DefaultAppPool)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
GroupPolicy: Restriction <======= ATTENTION
U3 idsvc; no ImagePath
C:\Users\Matt\AppData\Local\Temp\jansi-32-2255424595499729363.dll
C:\Users\Matt\AppData\Local\Temp\jansi-32-8708393685809737409.dll
C:\Users\Matt\AppData\Local\Temp\jre-8u101-windows-au.exe
C:\Users\Matt\AppData\Local\Temp\jre-8u111-windows-au.exe
C:\Users\Matt\AppData\Local\Temp\jre-8u71-windows-au.exe
C:\Users\Matt\AppData\Local\Temp\jre-8u73-windows-au.exe
C:\Users\Matt\AppData\Local\Temp\jre-8u77-windows-au.exe
C:\Users\Matt\AppData\Local\Temp\jre-8u91-windows-au.exe
C:\Users\Matt\AppData\Local\Temp\npp.6.9.2.Installer.exe
C:\Users\Matt\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Matt\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Matt\AppData\Local\Temp\nvStInst.exe
C:\Users\Matt\AppData\Local\Temp\sfamcc00001.dll
C:\Users\Matt\AppData\Local\Temp\sfareca00001.dll
C:\Users\Matt\AppData\Local\Temp\xmlUpdater.exe
CustomCLSID: HKU\S-1-5-21-183162068-1737580067-508966621-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Matt\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay => No File
CustomCLSID: HKU\S-1-5-21-183162068-1737580067-508966621-1000_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Matt\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183162068-1737580067-508966621-1000_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\Matt\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183162068-1737580067-508966621-1000_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Matt\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183162068-1737580067-508966621-1000_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\Matt\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183162068-1737580067-508966621-1000_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\Matt\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183162068-1737580067-508966621-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Matt\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183162068-1737580067-508966621-1000_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\Matt\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183162068-1737580067-508966621-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Matt\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-183162068-1737580067-508966621-1000_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\Matt\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => No File
EmptyTemp:
end

 


*****************

Processes closed successfully.
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
idsvc => service removed successfully
C:\Users\Matt\AppData\Local\Temp\jansi-32-2255424595499729363.dll => moved successfully
C:\Users\Matt\AppData\Local\Temp\jansi-32-8708393685809737409.dll => moved successfully
C:\Users\Matt\AppData\Local\Temp\jre-8u101-windows-au.exe => moved successfully
C:\Users\Matt\AppData\Local\Temp\jre-8u111-windows-au.exe => moved successfully
C:\Users\Matt\AppData\Local\Temp\jre-8u71-windows-au.exe => moved successfully
C:\Users\Matt\AppData\Local\Temp\jre-8u73-windows-au.exe => moved successfully
C:\Users\Matt\AppData\Local\Temp\jre-8u77-windows-au.exe => moved successfully
C:\Users\Matt\AppData\Local\Temp\jre-8u91-windows-au.exe => moved successfully
C:\Users\Matt\AppData\Local\Temp\npp.6.9.2.Installer.exe => moved successfully
C:\Users\Matt\AppData\Local\Temp\nvSCPAPI.dll => moved successfully
C:\Users\Matt\AppData\Local\Temp\nvSCPAPI64.dll => moved successfully
C:\Users\Matt\AppData\Local\Temp\nvStInst.exe => moved successfully
C:\Users\Matt\AppData\Local\Temp\sfamcc00001.dll => moved successfully
C:\Users\Matt\AppData\Local\Temp\sfareca00001.dll => moved successfully
C:\Users\Matt\AppData\Local\Temp\xmlUpdater.exe => moved successfully
"HKU\S-1-5-21-183162068-1737580067-508966621-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}" => key removed successfully
"HKU\S-1-5-21-183162068-1737580067-508966621-1000_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}" => key removed successfully
"HKU\S-1-5-21-183162068-1737580067-508966621-1000_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}" => key removed successfully
"HKU\S-1-5-21-183162068-1737580067-508966621-1000_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}" => key removed successfully
"HKU\S-1-5-21-183162068-1737580067-508966621-1000_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}" => key removed successfully
"HKU\S-1-5-21-183162068-1737580067-508966621-1000_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}" => key removed successfully
"HKU\S-1-5-21-183162068-1737580067-508966621-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}" => key removed successfully
"HKU\S-1-5-21-183162068-1737580067-508966621-1000_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}" => key removed successfully
"HKU\S-1-5-21-183162068-1737580067-508966621-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}" => key removed successfully
"HKU\S-1-5-21-183162068-1737580067-508966621-1000_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}" => key removed successfully

=========== EmptyTemp: ==========

BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 24120798 B
Java, Flash, Steam htmlcache => 391399943 B
Windows/system/drivers => 44131115 B
Edge => 2334440 B
Chrome => 41367425 B
Firefox => 652553859 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 6144 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 2212270 B
Matt => 1083953925 B
DefaultAppPool => 6144 B

RecycleBin => 30939326 B
EmptyTemp: => 2.1 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 18:49:08 ====

Link to post
Share on other sites

Unless you have any remaining issues or concerns you should be good to go, run the following to clean up:

Download "Delfix by Xplode" and save it to your desktop.

Or use the following if first link is down:

"Delfix link mirror"

If your security program alerts to Delfix either, accept the alert or turn your security off.

Double Click to start the program. If you are using Vista or higher, please right-click and choose run as administrator

Make Sure only the following item is checked:

 
  • Remove disinfection tools <----- this will remove tools we have used.


Now click on "Run" and wait patiently until the tool has completed.

The tool will create a log when it has completed. We don't need you to post this.

Any remnant files/logs from tools we have used can be deleted…

Next,

Read the following links to fully understand PC Security and Best Practices, you may find them useful....

Answers to Common Security Questions and best Practices

Do I need a Registry Cleaner?

Take care and surf safe

Kevin... user posted image

 

Link to post
Share on other sites

  • Root Admin

Glad we could help. :)If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.