Jump to content
qdv

Outbound Alerts

Recommended Posts

I get constant alerts from MBAM about Outbound connections to  IP 239.255.255.250 on different ports: (49xxx-64xxx)

Outbound connections related with svchost, chome, skypehost, but its start from chrome.

Also i can't did a system restore, i got an error

4 days ago i reinstall whole os systeme

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 01-03-2017
Ran by daz (administrator) on DESKTOP-ICP4TLM (02-03-2017 19:20:00)
Running from C:\Users\daz\Downloads
Loaded Profiles: daz (Available Profiles: defaultuser0 & daz)
Platform: Windows 10 Pro Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHostIntegrationAgent.exe
(Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Malwarebytes) C:\Program Files\MB\MBAMService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Malwarebytes) C:\Program Files\MB\mbamtray.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Яндекс) C:\Users\daz\AppData\Roaming\Yandex\YandexDisk\YandexDisk.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrotray.exe
(Slack Technologies) C:\Users\daz\AppData\Local\slack\app-2.5.1\slack.exe
(Slack Technologies) C:\Users\daz\AppData\Local\slack\app-2.5.1\slack.exe
(Slack Technologies) C:\Users\daz\AppData\Local\slack\app-2.5.1\slack.exe
(Slack Technologies) C:\Users\daz\AppData\Local\slack\app-2.5.1\slack.exe
(Slack Technologies) C:\Users\daz\AppData\Local\slack\app-2.5.1\slack.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft) C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeApp.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(AkelSoft) D:\Program Files\AkelPad\AkelPad.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\MRT.exe
(Microsoft Corporation) C:\Windows\System32\MRT.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-11-20] (Microsoft Corporation)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MB\mbamtray.exe [2780112 2017-01-20] (Malwarebytes)
HKLM\...\Run: [StartCN] => C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [8027016 2016-11-21] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [558496 2014-02-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [1870928 2016-12-23] (Adobe Systems Inc.)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-3323146596-3808808021-4093420219-1001\...\Run: [SyncManPath] => C:\Users\daz\AppData\Roaming\Yandex\YandexDisk\YandexDisk.exe [25003328 2017-01-26] (Яндекс)
HKU\S-1-5-21-3323146596-3808808021-4093420219-1001\...\Run: [AdobeBridge] => [X]
IFEO\notepad.exe: [Debugger] "d:\Program Files\AkelPad\AkelPad.exe" /z
ShellIconOverlayIdentifiers: [    YndCase0Sync] -> {63D48440-63AB-44D0-B323-4731DFCDE9E9} => C:\Users\daz\AppData\Roaming\Yandex\YandexDisk\YandexDiskOverlays-2398.dll [2017-01-26] (Яндекс)
ShellIconOverlayIdentifiers: [    YndCase1Modified] -> {7E7DC279-E6BE-4D57-9DEC-14FA0339DBC0} => C:\Users\daz\AppData\Roaming\Yandex\YandexDisk\YandexDiskOverlays-2398.dll [2017-01-26] (Яндекс)
ShellIconOverlayIdentifiers: [    YndCase2Error] -> {FB2FE984-05F5-4512-9D9B-69D3DE61F6D9} => C:\Users\daz\AppData\Roaming\Yandex\YandexDisk\YandexDiskOverlays-2398.dll [2017-01-26] (Яндекс)
ShellIconOverlayIdentifiers: [    YndCase3Shared] -> {AF8D197E-7022-4c3d-BD88-68AD35C9C169} => C:\Users\daz\AppData\Roaming\Yandex\YandexDisk\YandexDiskOverlays-2398.dll [2017-01-26] (Яндекс)
Startup: C:\Users\daz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Slack.lnk [2017-02-27]
ShortcutTarget: Slack.lnk -> C:\Users\daz\AppData\Local\slack\slack.exe (Slack Technologies)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{4a989b70-de58-4915-8dc2-aebd6ab8a432}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-12-23] (Adobe Systems Incorporated)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> D:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2015-07-31] (Microsoft Corporation)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-12-23] (Adobe Systems Incorporated)
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-12-23] (Adobe Systems Incorporated)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2015-07-31] (Microsoft Corporation)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-12-23] (Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-12-23] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-12-23] (Adobe Systems Incorporated)
Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - D:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - D:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation)

FireFox:
========
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.15@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn
FF Extension: (Adobe Acrobat DC - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn [2017-02-28]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> D:\Program Files\Microsoft Office\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2014-04-28] (Adobe Systems)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-03-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-03-02] (Google Inc.)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2014-04-28] (Adobe Systems)

Chrome: 
=======
CHR Profile: C:\Users\daz\AppData\Local\Google\Chrome\User Data\Default [2017-03-02]
CHR Extension: (Google Презентации) - C:\Users\daz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-03-02]
CHR Extension: (Документы Google) - C:\Users\daz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-03-02]
CHR Extension: (Диск Google) - C:\Users\daz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-03-02]
CHR Extension: (YouTube) - C:\Users\daz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-03-02]
CHR Extension: (Adobe Acrobat) - C:\Users\daz\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-02]
CHR Extension: (Google Таблицы) - C:\Users\daz\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-03-02]
CHR Extension: (Google Документы офлайн) - C:\Users\daz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-03-02]
CHR Extension: (Платежная система Рнтернет-магазина Chrome) - C:\Users\daz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-02]
CHR Extension: (Gmail) - C:\Users\daz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-03-02]
CHR Extension: (Chrome Media Router) - C:\Users\daz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-03-02]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2227312 2017-01-19] (Adobe Systems, Incorporated)
R2 MBAMService; C:\Program Files\MB\mbamservice.exe [4355024 2017-01-20] (Malwarebytes)
R2 NIHostIntegrationAgent; C:\Program Files\Common Files\Native Instruments\Hardware\NIHostIntegrationAgent.exe [10091120 2017-02-24] (Native Instruments GmbH)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-11-20] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 amdkmdag; C:\Windows\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmdag.sys [26568848 2017-01-25] (Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\Windows\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmpag.sys [536600 2017-01-25] (Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [110104 2016-09-28] (Advanced Micro Devices)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77416 2017-01-20] ()
R2 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [176584 2017-02-28] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [110536 2017-03-02] (Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [43968 2017-03-02] (Malwarebytes)
R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [251848 2017-03-02] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [91584 2017-03-02] (Malwarebytes)
R3 mc2avs; C:\Windows\System32\Drivers\mc2avs.sys [358520 2012-06-06] (Native Instruments GmbH)
R3 mc2usb_svc; C:\Windows\System32\Drivers\mc2usb.sys [81016 2012-06-06] (Native Instruments GmbH)
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 NIWinCDEmu; C:\Windows\System32\drivers\NIWinCDEmu.sys [112408 2017-02-27] ()
R3 RDID1119; C:\Windows\system32\Drivers\RDWM1119.SYS [170752 2015-07-22] (Roland Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2016-07-16] (Realtek                                            )
R3 rtwlane_13; C:\Windows\System32\drivers\rtwlane_13.sys [3717120 2016-07-16] (Realtek Semiconductor Corporation                           )
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-03-02 19:20 - 2017-03-02 19:20 - 00015380 _____ C:\Users\daz\Downloads\FRST.txt
2017-03-02 19:19 - 2017-03-02 19:20 - 00000000 ____D C:\FRST
2017-03-02 19:19 - 2017-03-02 19:19 - 02423808 _____ (Farbar) C:\Users\daz\Downloads\FRST64.exe
2017-03-02 18:44 - 2017-03-02 18:44 - 00003486 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-03-02 18:44 - 2017-03-02 18:44 - 00003362 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-03-02 18:44 - 2017-03-02 18:44 - 00002344 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-03-02 18:44 - 2017-03-02 18:44 - 00002332 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-03-02 18:43 - 2017-03-02 18:51 - 00000000 ____D C:\Users\daz\AppData\Local\Google
2017-03-02 18:43 - 2017-03-02 18:44 - 00000000 ____D C:\Program Files (x86)\Google
2017-03-02 13:28 - 2016-08-31 16:55 - 00021983 _____ C:\Users\daz\Documents\рене-почасовая.xlsx
2017-03-02 13:28 - 2015-12-12 09:23 - 00008825 _____ C:\Users\daz\Documents\СЃСЏ-zdorovie74.xlsx
2017-03-02 13:28 - 2015-09-20 06:38 - 00000258 _____ C:\Users\daz\Documents\Module1.bas
2017-03-02 13:28 - 2015-08-12 13:18 - 00014882 _____ C:\Users\daz\Documents\rene-hours3.xlsx
2017-03-02 13:28 - 2015-07-12 02:40 - 00012705 _____ C:\Users\daz\Documents\rene-hours.xlsx
2017-03-02 13:28 - 2015-06-21 14:36 - 00000882 _____ C:\Users\daz\Documents\Downloads - Shortcut.lnk
2017-03-02 13:28 - 2015-06-19 22:46 - 02968835 _____ C:\Users\daz\Documents\растения против алкоголя.pdf
2017-03-02 13:28 - 2015-06-18 00:40 - 00010308 _____ C:\Users\daz\Documents\РІРѕРІР°.xlsx
2017-03-02 13:28 - 2015-04-29 00:56 - 00047545 _____ C:\Users\daz\Documents\temx - объем рынка, СЯ.xlsx
2017-03-02 13:28 - 2015-04-28 11:56 - 00047456 _____ C:\Users\daz\Documents\wordpress.xlsx
2017-03-02 13:28 - 2015-04-25 13:01 - 00011646 _____ C:\Users\daz\Documents\russian.xlsx
2017-03-02 13:28 - 2015-03-29 16:24 - 00014032 _____ C:\Users\daz\Documents\Greenhouse.mp3.sfk
2017-03-02 13:28 - 2015-03-29 16:10 - 00060904 _____ C:\Users\daz\Documents\my2-5.mp3.sfk
2017-03-02 13:14 - 2017-03-02 13:14 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsign22e3fc5dbe13989e
2017-03-02 13:13 - 2017-03-02 13:13 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsign198338c56f6a36de
2017-03-02 12:47 - 2017-03-02 12:47 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsignbc6e520ee417ed3e
2017-03-02 12:33 - 2017-03-02 12:33 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsign27ca298698005d0a
2017-03-02 12:28 - 2017-03-02 12:28 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsigne8d45e9d705c6eb5
2017-03-02 12:28 - 2017-03-02 12:28 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsign186c70b4e76880d4
2017-03-02 12:22 - 2017-03-02 12:22 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsign4beea38c1ac7b40a
2017-03-02 12:22 - 2017-03-02 12:22 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsign0f9c9d4fb39784d4
2017-03-01 21:58 - 2017-03-01 21:58 - 00000000 __HDC C:\ProgramData\{F5271FB0-B5A4-420D-90D3-FF2900A84AA7}
2017-03-01 21:58 - 2017-03-01 21:58 - 00000000 ____D C:\Users\Public\Documents\West Africa
2017-03-01 21:48 - 2017-03-01 21:48 - 00000000 __HDC C:\ProgramData\{81FF46FD-55BF-4932-A9A8-86FF2C15E0ED}
2017-03-01 21:48 - 2017-03-01 21:48 - 00000000 ____D C:\Users\Public\Documents\Vintage Organs
2017-03-01 21:38 - 2017-03-01 21:38 - 00000000 __HDC C:\ProgramData\{93EAA4DB-27EC-4331-A128-E3891121AA47}
2017-03-01 21:37 - 2017-03-01 21:37 - 00000000 ____D C:\Users\Public\Documents\The Gentleman
2017-03-01 21:10 - 2017-03-01 21:10 - 00000000 __HDC C:\ProgramData\{8587A52E-BFFE-4BA1-8B2B-11732D6AA38C}
2017-03-01 21:10 - 2017-03-01 21:10 - 00000000 ____D C:\Users\Public\Documents\Static Friction
2017-03-01 21:08 - 2017-03-01 21:08 - 00000000 __HDC C:\ProgramData\{19D8F7AC-BFDC-4BE5-8903-2F3BFDFE1A3E}
2017-03-01 21:07 - 2017-03-01 21:07 - 00000000 __HDC C:\ProgramData\{306A1EF4-D27D-4F5A-BA93-F05B10576F40}
2017-03-01 21:07 - 2017-03-01 21:07 - 00000000 ____D C:\Users\Public\Documents\Scarbee Mark I
2017-03-01 20:57 - 2017-03-01 20:57 - 00000000 __HDC C:\ProgramData\{20C7291D-0FE3-4567-86A5-795DA8DD43DC}
2017-03-01 20:57 - 2017-03-01 20:57 - 00000000 ____D C:\Users\Public\Documents\Retro Machines Mk2
2017-03-01 20:29 - 2017-03-01 20:29 - 00000000 __HDC C:\ProgramData\{69D837C2-05C2-4CB1-A968-868E8A4B4BBF}
2017-03-01 20:28 - 2017-03-01 20:28 - 00000000 __HDC C:\ProgramData\{29717DE6-69BF-4629-B743-C10C0EB6114F}
2017-03-01 20:28 - 2017-03-01 20:28 - 00000000 ____D C:\Users\Public\Documents\Reaktor Factory Selection R2
2017-03-01 20:27 - 2017-03-01 20:27 - 00000939 _____ C:\Users\Public\Desktop\Reaktor 6.lnk
2017-03-01 20:27 - 2017-03-01 20:27 - 00000000 __HDC C:\ProgramData\{AC8F26C0-3B02-4AF3-9273-FBA6B76AB966}
2017-03-01 20:27 - 2017-03-01 20:27 - 00000000 __HDC C:\ProgramData\{52383D4F-7016-471C-854F-3926047FB172}
2017-03-01 20:27 - 2017-03-01 20:27 - 00000000 ____D C:\Users\Public\Documents\Reaktor Blocks Wired
2017-03-01 20:26 - 2017-03-01 20:26 - 00000936 _____ C:\Users\Public\Desktop\Reaktor 5.lnk
2017-03-01 20:26 - 2017-03-01 20:26 - 00000000 __HDC C:\ProgramData\{D9728A28-7722-4D89-9A50-355260FF8E2B}
2017-03-01 20:12 - 2017-03-01 20:12 - 00000000 __HDC C:\ProgramData\{72FB1413-664A-4676-A4A4-98A0C2C4CCA1}
2017-03-01 20:12 - 2017-03-01 20:12 - 00000000 ____D C:\Users\Public\Documents\Queensbridge Story
2017-03-01 20:11 - 2017-03-01 20:11 - 00000000 __HDC C:\ProgramData\{4074D429-4894-48B8-AD81-515C4C772FEB}
2017-03-01 20:11 - 2017-03-01 20:11 - 00000000 ____D C:\Users\Public\Documents\Pulswerk
2017-03-01 20:07 - 2017-03-01 20:07 - 00000000 __HDC C:\ProgramData\{6A919520-D0F4-494D-953B-8FB56B977891}
2017-03-01 20:07 - 2017-03-01 20:07 - 00000000 ____D C:\Users\Public\Documents\Prospect Haze
2017-03-01 20:06 - 2017-03-01 20:06 - 00000000 __HDC C:\ProgramData\{BBD6476E-3DD8-447E-ACC3-81C30FC4A118}
2017-03-01 20:06 - 2017-03-01 20:06 - 00000000 ____D C:\Users\Public\Documents\Prism
2017-03-01 20:05 - 2017-03-01 20:05 - 00000000 __HDC C:\ProgramData\{CFDD872E-E643-48CF-82E8-8889713D990D}
2017-03-01 20:05 - 2017-03-01 20:05 - 00000000 __HDC C:\ProgramData\{8B5F4544-3724-4AFD-9ACA-A8679A6CBC07}
2017-03-01 20:05 - 2017-03-01 20:05 - 00000000 ____D C:\Users\Public\Documents\Paradise Rinse
2017-03-01 20:05 - 2017-03-01 20:05 - 00000000 ____D C:\Users\Public\Documents\Monark
2017-03-01 20:04 - 2017-03-01 20:04 - 00000923 _____ C:\Users\Public\Desktop\Massive.lnk
2017-03-01 20:04 - 2017-03-01 20:04 - 00000000 __HDC C:\ProgramData\{87AEDB84-EF6C-4240-A009-B8FA027D1315}
2017-03-01 20:01 - 2017-03-01 20:01 - 00000000 __HDC C:\ProgramData\{860ABD3F-95F3-4051-ABC5-24E14346F472}
2017-03-01 20:01 - 2017-03-01 20:01 - 00000000 ____D C:\Users\Public\Documents\Magnate Hustle
2017-03-01 19:56 - 2017-03-01 19:56 - 00000000 __HDC C:\ProgramData\{01D9AEC6-F048-4FDD-A511-FE98B3E7E4ED}
2017-03-01 19:56 - 2017-03-01 19:56 - 00000000 ____D C:\Users\Public\Documents\Lazer Dice
2017-03-01 19:54 - 2017-03-01 19:54 - 00000000 __HDC C:\ProgramData\{B24A8FDF-FA25-4388-B484-1351A9EC40BC}
2017-03-01 19:54 - 2017-03-01 19:54 - 00000000 ____D C:\Users\Public\Documents\Kontakt Factory Selection
2017-03-01 19:52 - 2017-03-01 19:52 - 00000939 _____ C:\Users\Public\Desktop\Kontakt 5.lnk
2017-03-01 19:52 - 2017-03-01 19:52 - 00000000 __HDC C:\ProgramData\{F0F3660E-3963-4E9E-B44E-192B34C6DECD}
2017-03-01 19:43 - 2017-03-01 19:43 - 00000997 _____ C:\Users\Public\Desktop\Komplete Kontrol.lnk
2017-03-01 19:43 - 2017-03-01 19:43 - 00000000 __HDC C:\ProgramData\{641043DC-5B59-4AA4-8C9B-151554F6C26E}
2017-03-01 19:43 - 2017-03-01 19:43 - 00000000 ____D C:\Program Files\Common Files\Steinberg
2017-03-01 19:42 - 2017-03-01 19:42 - 00001167 _____ C:\Users\Public\Desktop\Controller Editor.lnk
2017-03-01 19:42 - 2017-03-01 19:42 - 00000000 __HDC C:\ProgramData\{8CC41642-A33B-4E4A-BAEB-8E38CB5359E3}
2017-03-01 19:39 - 2017-03-01 19:39 - 00000000 __HDC C:\ProgramData\{9755C351-8776-4805-A1B0-F2041E82093D}
2017-03-01 19:38 - 2017-03-01 19:39 - 00000000 ____D C:\Users\Public\Documents\Helios Ray
2017-03-01 19:36 - 2017-03-01 19:36 - 00000000 __HDC C:\ProgramData\{80E1859D-389E-4D4B-8377-121DB4A144EA}
2017-03-01 19:36 - 2017-03-01 19:36 - 00000000 ____D C:\Users\Public\Documents\Golden Kingdom
2017-03-01 19:35 - 2017-03-01 19:35 - 00000000 __HDC C:\ProgramData\{CBB8CD62-36FC-4E55-B041-B054E4708942}
2017-03-01 19:34 - 2017-03-01 19:34 - 00000000 ____D C:\Users\Public\Documents\Electric Vice
2017-03-01 19:32 - 2017-03-01 19:32 - 00000000 __HDC C:\ProgramData\{55AEE408-DC39-477F-B7A7-07C6498E734D}
2017-03-01 19:32 - 2017-03-01 19:32 - 00000000 ____D C:\Users\Public\Documents\Drum Lab
2017-03-01 19:28 - 2017-03-01 19:28 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsign93652202fdcc3e6f
2017-03-01 19:28 - 2017-03-01 19:28 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsign7205ed1ce8a9774f
2017-03-01 19:28 - 2017-03-01 19:28 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsign2ac3f787bbe4db13
2017-03-01 19:11 - 2017-03-01 19:11 - 00000000 __HDC C:\ProgramData\{3A6A7E43-2C42-4BCC-A995-963BF0352A3D}
2017-03-01 19:11 - 2017-03-01 19:11 - 00000000 ____D C:\Users\Public\Documents\Circuit Halo
2017-03-01 19:06 - 2017-03-01 19:06 - 00000000 __HDC C:\ProgramData\{71AFA3E1-57C4-4AC0-ACBE-51730799AD58}
2017-03-01 19:06 - 2017-03-01 19:06 - 00000000 ____D C:\Users\Public\Documents\Caribbean Current
2017-03-01 19:05 - 2017-03-01 19:05 - 00000000 __HDC C:\ProgramData\{BFD85CF8-F48E-4F8C-B79E-BC45F7B52B9B}
2017-03-01 19:05 - 2017-03-01 19:05 - 00000000 ____D C:\Users\Public\Documents\Astral Flutter
2017-03-01 18:30 - 2017-03-01 18:30 - 00000000 __HDC C:\ProgramData\{E3946D55-17E5-4835-88DE-C4030F818EA2}
2017-03-01 18:21 - 2017-03-01 18:21 - 00000000 ____D C:\Users\daz\AppData\Roaming\Native Instruments
2017-03-01 18:21 - 2017-03-01 18:21 - 00000000 ____D C:\Users\daz\AppData\Local\cache
2017-03-01 18:19 - 2017-03-01 18:19 - 00000949 _____ C:\Users\Public\Desktop\Maschine 2.lnk
2017-03-01 18:19 - 2017-03-01 18:19 - 00000000 __HDC C:\ProgramData\{A4537A95-B126-4043-B60D-EEE792C8DD37}
2017-03-01 18:18 - 2017-03-01 18:18 - 00000000 __HDC C:\ProgramData\{73631698-31A0-419C-B151-F478AEBC136A}
2017-03-01 18:18 - 2017-03-01 18:18 - 00000000 __HDC C:\ProgramData\{2CD659BC-750F-4694-B214-40A0CE94308D}
2017-03-01 18:17 - 2017-03-01 18:17 - 00000000 __HDC C:\ProgramData\{81B3FE58-8826-44EC-8271-083D201CEA19}
2017-03-01 18:16 - 2017-03-01 18:16 - 00000000 __HDC C:\ProgramData\{6495CC1D-C10B-40C5-A92B-241A2B2C8D20}
2017-03-01 18:15 - 2017-03-01 18:15 - 00000000 __HDC C:\ProgramData\{9C588B44-42B6-434D-90BD-824BBB1F328A}
2017-03-01 18:13 - 2017-03-01 18:13 - 00001127 _____ C:\Users\Public\Desktop\Native Access.lnk
2017-03-01 18:13 - 2017-03-01 18:13 - 00000000 __HDC C:\ProgramData\{559CC4E6-942D-4376-BA28-E4E187F2F399}
2017-03-01 18:07 - 2017-03-01 18:10 - 60632900 _____ C:\Users\daz\Downloads\Native_Access_Installer.zip
2017-03-01 18:07 - 2017-03-01 18:07 - 47791234 _____ C:\Users\daz\Desktop\Controller_Editor_202_PC.zip
2017-03-01 15:52 - 2017-03-01 15:52 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsignf02216c839ed1a69
2017-03-01 15:52 - 2017-03-01 15:52 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsignba707bde49d92927
2017-02-28 18:22 - 2017-03-02 11:04 - 00000000 ____D C:\Windows\system32\MRT
2017-02-28 18:22 - 2017-02-28 18:22 - 138020592 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-02-28 18:17 - 2016-12-21 13:08 - 00245600 _____ (Microsoft Corporation) C:\Windows\system32\offlinesam.dll
2017-02-28 18:17 - 2016-12-21 13:08 - 00136032 _____ (Microsoft Corporation) C:\Windows\system32\ImplatSetup.dll
2017-02-28 18:17 - 2016-12-21 12:49 - 00328008 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Storage.ApplicationData.dll
2017-02-28 18:17 - 2016-12-21 12:46 - 00624048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2017-02-28 18:17 - 2016-12-21 12:43 - 04130440 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2017-02-28 18:17 - 2016-12-21 12:43 - 01454504 _____ (Microsoft Corporation) C:\Windows\system32\mfnetsrc.dll
2017-02-28 18:17 - 2016-12-21 12:43 - 01071736 _____ (Microsoft Corporation) C:\Windows\system32\mfnetcore.dll
2017-02-28 18:17 - 2016-12-21 12:43 - 00092512 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2017-02-28 18:17 - 2016-12-21 12:42 - 22224480 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2017-02-28 18:17 - 2016-12-21 12:42 - 01988560 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
2017-02-28 18:17 - 2016-12-21 12:42 - 01702392 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll
2017-02-28 18:17 - 2016-12-21 12:42 - 01300600 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll
2017-02-28 18:17 - 2016-12-21 12:41 - 01600632 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2017-02-28 18:17 - 2016-12-21 12:15 - 22563840 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2017-02-28 18:17 - 2016-12-21 12:14 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\LaunchWinApp.exe
2017-02-28 18:17 - 2016-12-21 12:09 - 00368640 _____ (Microsoft Corporation) C:\Windows\system32\OneBackupHandler.dll
2017-02-28 18:17 - 2016-12-21 12:08 - 00360448 _____ (Microsoft Corporation) C:\Windows\system32\rdpencom.dll
2017-02-28 18:17 - 2016-12-21 12:08 - 00289792 _____ (Microsoft Corporation) C:\Windows\system32\DeveloperOptionsSettingsHandlers.dll
2017-02-28 18:17 - 2016-12-21 12:06 - 06285312 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2017-02-28 18:17 - 2016-12-21 12:05 - 00425984 _____ (Microsoft Corporation) C:\Windows\system32\aadcloudap.dll
2017-02-28 18:17 - 2016-12-21 12:05 - 00261632 _____ (Microsoft Corporation) C:\Windows\system32\indexeddbserver.dll
2017-02-28 18:17 - 2016-12-21 12:05 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Shell.dll
2017-02-28 18:17 - 2016-12-21 12:01 - 09131008 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2017-02-28 18:17 - 2016-12-21 11:59 - 01908224 _____ (Microsoft Corporation) C:\Windows\system32\AzureSettingSyncProvider.dll
2017-02-28 18:17 - 2016-12-21 11:59 - 00883712 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2017-02-28 18:17 - 2016-12-21 11:58 - 23678464 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-02-28 18:17 - 2016-12-21 11:56 - 00947712 _____ (Microsoft Corporation) C:\Windows\system32\MSVP9DEC.dll
2017-02-28 18:17 - 2016-12-21 11:56 - 00936960 _____ (Microsoft Corporation) C:\Windows\system32\MCRecvSrc.dll
2017-02-28 18:17 - 2016-12-21 11:55 - 08129536 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2017-02-28 18:17 - 2016-12-21 11:55 - 04749312 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
2017-02-28 18:17 - 2016-12-21 11:54 - 05511680 _____ (Microsoft Corporation) C:\Windows\system32\aclui.dll
2017-02-28 18:17 - 2016-12-21 11:53 - 06664192 _____ (Microsoft Corporation) C:\Windows\system32\mspaint.exe
2017-02-28 18:17 - 2016-12-21 11:53 - 04474368 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll
2017-02-28 18:17 - 2016-12-21 11:51 - 08075776 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2017-02-28 18:17 - 2016-12-21 11:51 - 05611008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2017-02-28 18:17 - 2016-12-21 11:50 - 01490432 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-02-28 18:17 - 2016-12-21 11:49 - 04149248 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2017-02-28 18:17 - 2016-12-21 11:49 - 01062912 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll
2017-02-28 18:17 - 2016-12-21 11:47 - 01121280 _____ (Microsoft Corporation) C:\Windows\system32\aadtb.dll
2017-02-28 18:17 - 2016-12-21 10:59 - 00218976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\offlinesam.dll
2017-02-28 18:17 - 2016-12-21 10:09 - 00263472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Storage.ApplicationData.dll
2017-02-28 18:17 - 2016-12-21 10:01 - 20969928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2017-02-28 18:17 - 2016-12-21 09:46 - 00034304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LaunchWinApp.exe
2017-02-28 18:17 - 2016-12-21 09:43 - 00285184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.BlockedShutdown.dll
2017-02-28 18:17 - 2016-12-21 09:41 - 00253952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.BioFeedback.dll
2017-02-28 18:17 - 2016-12-21 09:41 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2017-02-28 18:17 - 2016-12-21 09:40 - 00557568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StoreAgent.dll
2017-02-28 18:17 - 2016-12-21 09:40 - 00318976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpencom.dll
2017-02-28 18:17 - 2016-12-21 09:40 - 00237056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SyncSettings.dll
2017-02-28 18:17 - 2016-12-21 09:40 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgent.exe
2017-02-28 18:17 - 2016-12-21 09:39 - 01300480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVPXENC.dll
2017-02-28 18:17 - 2016-12-21 09:39 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgentUserBroker.exe
2017-02-28 18:17 - 2016-12-21 09:38 - 00866816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Cred.dll
2017-02-28 18:17 - 2016-12-21 09:35 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\indexeddbserver.dll
2017-02-28 18:17 - 2016-12-21 09:34 - 07626752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2017-02-28 18:17 - 2016-12-21 09:33 - 19413504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2017-02-28 18:17 - 2016-12-21 09:32 - 19417600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-02-28 18:17 - 2016-12-21 09:30 - 05398016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aclui.dll
2017-02-28 18:17 - 2016-12-21 09:30 - 01255936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AzureSettingSyncProvider.dll
2017-02-28 18:17 - 2016-12-21 09:26 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVP9DEC.dll
2017-02-28 18:17 - 2016-12-21 09:25 - 07469056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2017-02-28 18:17 - 2016-12-21 09:25 - 06474752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mspaint.exe
2017-02-28 18:17 - 2016-12-21 09:24 - 06044160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2017-02-28 18:17 - 2016-12-21 09:22 - 01883648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Logon.dll
2017-02-28 18:17 - 2016-12-14 10:41 - 01235296 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2017-02-28 18:17 - 2016-12-14 10:34 - 02482280 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2017-02-28 18:17 - 2016-12-14 10:33 - 02169184 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntSubsystems64.dll
2017-02-28 18:17 - 2016-12-14 10:33 - 01669984 _____ (Microsoft Corporation) C:\Windows\system32\AppVIntegration.dll
2017-02-28 18:17 - 2016-12-14 10:33 - 01400160 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntSubsystemController.dll
2017-02-28 18:17 - 2016-12-14 10:33 - 01054048 _____ (Microsoft Corporation) C:\Windows\system32\AppVPolicy.dll
2017-02-28 18:17 - 2016-12-14 10:33 - 00992096 _____ (Microsoft Corporation) C:\Windows\system32\AppVManifest.dll
2017-02-28 18:17 - 2016-12-14 10:33 - 00822624 _____ (Microsoft Corporation) C:\Windows\system32\AppVClient.exe
2017-02-28 18:17 - 2016-12-14 10:33 - 00813408 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntStreamingManager.dll
2017-02-28 18:17 - 2016-12-14 10:33 - 00779616 _____ (Microsoft Corporation) C:\Windows\system32\AppVReporting.dll
2017-02-28 18:17 - 2016-12-14 10:33 - 00752992 _____ (Microsoft Corporation) C:\Windows\system32\AppVOrchestration.dll
2017-02-28 18:17 - 2016-12-14 10:33 - 00704352 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntVirtualization.dll
2017-02-28 18:17 - 2016-12-14 10:33 - 00696160 _____ (Microsoft Corporation) C:\Windows\system32\AppVPublishing.dll
2017-02-28 18:17 - 2016-12-14 10:33 - 00571744 _____ (Microsoft Corporation) C:\Windows\system32\AppVCatalog.dll
2017-02-28 18:17 - 2016-12-14 10:33 - 00513376 _____ (Microsoft Corporation) C:\Windows\system32\TransportDSA.dll
2017-02-28 18:17 - 2016-12-14 10:33 - 00406368 _____ (Microsoft Corporation) C:\Windows\system32\AppVScripting.dll
2017-02-28 18:17 - 2016-12-14 10:33 - 00241504 _____ (Microsoft Corporation) C:\Windows\system32\AppVShNotify.exe
2017-02-28 18:17 - 2016-12-14 10:33 - 00190816 _____ (Microsoft Corporation) C:\Windows\system32\AppVDllSurrogate.exe
2017-02-28 18:17 - 2016-12-14 10:23 - 00404832 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-02-28 18:17 - 2016-12-14 10:21 - 02206496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2017-02-28 18:17 - 2016-12-14 10:19 - 00584544 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncHost.exe
2017-02-28 18:17 - 2016-12-14 10:17 - 00319288 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-02-28 18:17 - 2016-12-14 10:14 - 01694712 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll
2017-02-28 18:17 - 2016-12-14 10:01 - 01557808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll
2017-02-28 18:17 - 2016-12-14 10:01 - 00382784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2017-02-28 18:17 - 2016-12-14 10:01 - 00076984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\remoteaudioendpoint.dll
2017-02-28 18:17 - 2016-12-14 09:48 - 01631232 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.dll
2017-02-28 18:17 - 2016-12-14 09:46 - 01631232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Resources.dll
2017-02-28 18:17 - 2016-12-14 09:46 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-02-28 18:17 - 2016-12-14 09:44 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netvsc.sys
2017-02-28 18:17 - 2016-12-14 09:43 - 00201728 _____ (Microsoft Corporation) C:\Windows\system32\ScDeviceEnum.dll
2017-02-28 18:17 - 2016-12-14 09:42 - 00236544 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
2017-02-28 18:17 - 2016-12-14 09:42 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.UI.Logon.ProxyStub.dll
2017-02-28 18:17 - 2016-12-14 09:42 - 00167424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll
2017-02-28 18:17 - 2016-12-14 09:41 - 00223744 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-02-28 18:17 - 2016-12-14 09:40 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudBackupSettings.dll
2017-02-28 18:17 - 2016-12-14 09:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\certprop.dll
2017-02-28 18:17 - 2016-12-14 09:39 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\updatehandlers.dll
2017-02-28 18:17 - 2016-12-14 09:38 - 17188864 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2017-02-28 18:17 - 2016-12-14 09:38 - 13869056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2017-02-28 18:17 - 2016-12-14 09:38 - 00213504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.CredDialogController.dll
2017-02-28 18:17 - 2016-12-14 09:37 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\updatepolicy.dll
2017-02-28 18:17 - 2016-12-14 09:36 - 00539648 _____ (Microsoft Corporation) C:\Windows\system32\usocore.dll
2017-02-28 18:17 - 2016-12-14 09:36 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\updatepolicy.dll
2017-02-28 18:17 - 2016-12-14 09:35 - 00755712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-02-28 18:17 - 2016-12-14 09:35 - 00600576 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2017-02-28 18:17 - 2016-12-14 09:35 - 00553984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2017-02-28 18:17 - 2016-12-14 09:26 - 00932864 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-02-28 18:17 - 2016-12-14 09:26 - 00869888 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-02-28 18:17 - 2016-12-14 09:24 - 01005568 _____ (Microsoft Corporation) C:\Windows\system32\D3D12.dll
2017-02-28 18:17 - 2016-12-14 09:24 - 00673792 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2017-02-28 18:17 - 2016-12-14 09:23 - 03134976 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2017-02-28 18:17 - 2016-12-14 09:22 - 02748416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2017-02-28 18:17 - 2016-12-14 09:22 - 02317824 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-02-28 18:17 - 2016-12-14 09:22 - 01513472 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2017-02-28 18:17 - 2016-12-14 09:22 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll
2017-02-28 18:17 - 2016-12-14 09:21 - 03616768 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2017-02-28 18:17 - 2016-12-09 15:42 - 01637728 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2017-02-28 18:17 - 2016-12-09 15:42 - 00137568 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2017-02-28 18:17 - 2016-12-09 15:29 - 02681200 _____ C:\Windows\system32\CoreUIComponents.dll
2017-02-28 18:17 - 2016-12-09 15:28 - 00764392 _____ (Microsoft Corporation) C:\Windows\system32\CoreMessaging.dll
2017-02-28 18:17 - 2016-12-09 15:27 - 00172528 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-02-28 18:17 - 2016-12-09 15:20 - 02677544 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2017-02-28 18:17 - 2016-12-09 15:20 - 02189664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2017-02-28 18:17 - 2016-12-09 15:20 - 01738560 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2017-02-28 18:17 - 2016-12-09 15:20 - 00658784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys
2017-02-28 18:17 - 2016-12-09 15:20 - 00402272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2017-02-28 18:17 - 2016-12-09 15:19 - 01293152 _____ (Microsoft Corporation) C:\Windows\system32\LicenseManager.dll
2017-02-28 18:17 - 2016-12-09 15:19 - 00168424 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-02-28 18:17 - 2016-12-09 15:18 - 02913144 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll
2017-02-28 18:17 - 2016-12-09 15:18 - 01267512 _____ (Microsoft Corporation) C:\Windows\system32\WinTypes.dll
2017-02-28 18:17 - 2016-12-09 15:18 - 01100128 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe
2017-02-28 18:17 - 2016-12-09 15:18 - 00989024 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe
2017-02-28 18:17 - 2016-12-09 15:18 - 00947552 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.efi
2017-02-28 18:17 - 2016-12-09 15:18 - 00811872 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.exe
2017-02-28 18:17 - 2016-12-09 15:15 - 08168000 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2017-02-28 18:17 - 2016-12-09 15:11 - 02048496 _____ C:\Windows\SysWOW64\CoreUIComponents.dll
2017-02-28 18:17 - 2016-12-09 15:10 - 01461200 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2017-02-28 18:17 - 2016-12-09 15:01 - 01503544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2017-02-28 18:17 - 2016-12-09 15:01 - 00861024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LicenseManager.dll
2017-02-28 18:17 - 2016-12-09 15:00 - 00106896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-02-28 18:17 - 2016-12-09 14:59 - 02166752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
2017-02-28 18:17 - 2016-12-09 14:59 - 00846560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinTypes.dll
2017-02-28 18:17 - 2016-12-09 14:57 - 06668040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-02-28 18:17 - 2016-12-09 14:56 - 00959112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2017-02-28 18:17 - 2016-12-09 14:52 - 01435896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2017-02-28 18:17 - 2016-12-09 14:52 - 01415752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32full.dll
2017-02-28 18:17 - 2016-12-09 14:42 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2017-02-28 18:17 - 2016-12-09 14:41 - 00380928 _____ (Microsoft Corporation) C:\Windows\system32\wincorlib.dll
2017-02-28 18:17 - 2016-12-09 14:41 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WordBreakers.dll
2017-02-28 18:17 - 2016-12-09 14:37 - 00411136 _____ (Microsoft Corporation) C:\Windows\system32\facecredentialprovider.dll
2017-02-28 18:17 - 2016-12-09 14:36 - 03059200 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2017-02-28 18:17 - 2016-12-09 14:36 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
2017-02-28 18:17 - 2016-12-09 14:34 - 00288768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincorlib.dll
2017-02-28 18:17 - 2016-12-09 14:33 - 03777536 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2017-02-28 18:17 - 2016-12-09 14:32 - 00635904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-02-28 18:17 - 2016-12-09 14:31 - 03689984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2017-02-28 18:17 - 2016-12-09 14:31 - 00313856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2017-02-28 18:17 - 2016-12-09 14:28 - 01004544 _____ (Microsoft Corporation) C:\Windows\system32\enterprisecsps.dll
2017-02-28 18:17 - 2016-12-09 14:27 - 13084160 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-02-28 18:17 - 2016-12-09 14:27 - 00981504 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.OnlineId.dll
2017-02-28 18:17 - 2016-12-09 14:25 - 00376832 _____ (Microsoft Corporation) C:\Windows\system32\CryptoWinRT.dll
2017-02-28 18:17 - 2016-12-09 14:23 - 12177920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-02-28 18:17 - 2016-12-09 14:21 - 04746752 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-02-28 18:17 - 2016-12-09 14:20 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2017-02-28 18:17 - 2016-12-09 14:20 - 00187392 _____ (Microsoft Corporation) C:\Windows\system32\mdmregistration.dll
2017-02-28 18:17 - 2016-12-09 14:20 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\DeviceEnroller.exe
2017-02-28 18:17 - 2016-12-09 14:18 - 03666432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-02-28 18:17 - 2016-12-09 14:18 - 02138112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputService.dll
2017-02-28 18:17 - 2016-12-09 14:18 - 00165376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mdmregistration.dll
2017-02-28 18:17 - 2016-12-09 14:16 - 00353280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TextInputFramework.dll
2017-02-28 18:17 - 2016-12-09 14:15 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Core.TextInput.dll
2017-02-28 18:17 - 2016-12-09 14:15 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputLocaleManager.dll
2017-02-28 18:17 - 2016-12-09 14:15 - 00068096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EditBufferTestHook.dll
2017-02-28 18:17 - 2016-12-09 13:54 - 00483840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreMessaging.dll
2017-02-28 18:17 - 2016-11-11 15:15 - 00101216 _____ (Microsoft Corporation) C:\Windows\system32\DeviceReactivation.dll
2017-02-28 18:17 - 2016-11-11 15:14 - 02186896 _____ (Microsoft Corporation) C:\Windows\system32\hevcdecoder.dll
2017-02-28 18:17 - 2016-11-11 15:14 - 00603488 _____ (Microsoft Corporation) C:\Windows\system32\ContentDeliveryManager.Utilities.dll
2017-02-28 18:17 - 2016-11-11 15:13 - 02213760 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-02-28 18:17 - 2016-11-11 15:13 - 01886344 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-02-28 18:17 - 2016-11-11 15:13 - 00352096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys
2017-02-28 18:17 - 2016-11-11 15:12 - 00128352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2017-02-28 18:17 - 2016-11-11 15:08 - 00142176 _____ (Microsoft Corporation) C:\Windows\system32\migisol.dll
2017-02-28 18:17 - 2016-11-11 15:03 - 01069720 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
2017-02-28 18:17 - 2016-11-11 15:03 - 00266544 _____ (Microsoft Corporation) C:\Windows\system32\policymanager.dll
2017-02-28 18:17 - 2016-11-11 15:02 - 02828376 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2017-02-28 18:17 - 2016-11-11 15:01 - 07219672 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
2017-02-28 18:17 - 2016-11-11 15:01 - 00637400 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2017-02-28 18:17 - 2016-11-11 15:00 - 00223584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-02-28 18:17 - 2016-11-11 15:00 - 00219488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tpm.sys
2017-02-28 18:17 - 2016-11-11 14:59 - 00433504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2017-02-28 18:17 - 2016-11-11 14:57 - 01473048 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2017-02-28 18:17 - 2016-11-11 14:56 - 04673304 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2017-02-28 18:17 - 2016-11-11 14:56 - 01062480 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll
2017-02-28 18:17 - 2016-11-11 14:56 - 00187520 _____ (Microsoft Corporation) C:\Windows\system32\CloudStorageWizard.exe
2017-02-28 18:17 - 2016-11-11 14:56 - 00126568 _____ (Microsoft Corporation) C:\Windows\system32\mfaudiocnv.dll
2017-02-28 18:17 - 2016-11-11 14:55 - 00882680 _____ (Microsoft Corporation) C:\Windows\system32\EditionUpgradeManagerObj.dll
2017-02-28 18:17 - 2016-11-11 14:55 - 00743224 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll
2017-02-28 18:17 - 2016-11-11 14:54 - 01418312 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2017-02-28 18:17 - 2016-11-11 14:51 - 00454592 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2017-02-28 18:17 - 2016-11-11 14:27 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\NetCfgNotifyObjectHost.exe
2017-02-28 18:17 - 2016-11-11 14:26 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\xboxgip.sys
2017-02-28 18:17 - 2016-11-11 14:26 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\EnterpriseModernAppMgmtCSP.dll
2017-02-28 18:17 - 2016-11-11 14:26 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\ReportingCSP.dll
2017-02-28 18:17 - 2016-11-11 14:26 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\ReAgentc.exe
2017-02-28 18:17 - 2016-11-11 14:25 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\BcastDVRHelper.dll
2017-02-28 18:17 - 2016-11-11 14:25 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\DisplayManager.dll
2017-02-28 18:17 - 2016-11-11 14:25 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\dmcertinst.exe
2017-02-28 18:17 - 2016-11-11 14:25 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\HttpsDataSource.dll
2017-02-28 18:17 - 2016-11-11 14:25 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryBroker.dll
2017-02-28 18:17 - 2016-11-11 14:24 - 00170496 _____ (Microsoft Corporation) C:\Windows\system32\AppCapture.dll
2017-02-28 18:17 - 2016-11-11 14:24 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\VEStoreEventHandlers.dll
2017-02-28 18:17 - 2016-11-11 14:24 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sendmail.dll
2017-02-28 18:17 - 2016-11-11 14:24 - 00122880 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryClient.dll
2017-02-28 18:17 - 2016-11-11 14:24 - 00110080 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2017-02-28 18:17 - 2016-11-11 14:24 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\VPNv2CSP.dll
2017-02-28 18:17 - 2016-11-11 14:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\browserbroker.dll
2017-02-28 18:17 - 2016-11-11 14:23 - 00567296 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairing.dll
2017-02-28 18:17 - 2016-11-11 14:23 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Shell.Search.UriHandler.dll
2017-02-28 18:17 - 2016-11-11 14:23 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\EAMProgressHandler.dll
2017-02-28 18:17 - 2016-11-11 14:22 - 00489472 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupShim.dll
2017-02-28 18:17 - 2016-11-11 14:22 - 00143360 _____ (Microsoft Corporation) C:\Windows\system32\EDPCleanup.exe
2017-02-28 18:17 - 2016-11-11 14:21 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\ieproxy.dll
2017-02-28 18:17 - 2016-11-11 14:21 - 00587776 _____ (Microsoft Corporation) C:\Windows\system32\vpnike.dll
2017-02-28 18:17 - 2016-11-11 14:21 - 00379392 _____ (Microsoft Corporation) C:\Windows\system32\apprepsync.dll
2017-02-28 18:17 - 2016-11-11 14:20 - 00657920 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll
2017-02-28 18:17 - 2016-11-11 14:20 - 00574464 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_StorageSense.dll
2017-02-28 18:17 - 2016-11-11 14:20 - 00407552 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Management.dll
2017-02-28 18:17 - 2016-11-11 14:20 - 00176128 _____ (Microsoft Corporation) C:\Windows\system32\apprepapi.dll
2017-02-28 18:17 - 2016-11-11 14:20 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\setupugc.exe
2017-02-28 18:17 - 2016-11-11 14:20 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\IdCtrls.dll
2017-02-28 18:17 - 2016-11-11 14:19 - 00620544 _____ (Microsoft Corporation) C:\Windows\system32\bcastdvr.exe
2017-02-28 18:17 - 2016-11-11 14:19 - 00495104 _____ (Microsoft Corporation) C:\Windows\system32\DataSenseHandlers.dll
2017-02-28 18:17 - 2016-11-11 14:19 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\ActivationManager.dll
2017-02-28 18:17 - 2016-11-11 14:19 - 00388096 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll
2017-02-28 18:17 - 2016-11-11 14:19 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\EnterpriseAppMgmtSvc.dll
2017-02-28 18:17 - 2016-11-11 14:19 - 00198144 _____ (Microsoft Corporation) C:\Windows\system32\dpapisrv.dll
2017-02-28 18:17 - 2016-11-11 14:18 - 02084352 _____ (Microsoft Corporation) C:\Windows\system32\DeviceFlows.DataModel.dll
2017-02-28 18:17 - 2016-11-11 14:18 - 00278016 _____ (Microsoft Corporation) C:\Windows\system32\netplwiz.dll
2017-02-28 18:17 - 2016-11-11 14:16 - 02716672 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2017-02-28 18:17 - 2016-11-11 14:16 - 01477632 _____ (Microsoft Corporation) C:\Windows\system32\wsecedit.dll
2017-02-28 18:17 - 2016-11-11 14:16 - 00560128 _____ (Microsoft Corporation) C:\Windows\system32\AppReadiness.dll
2017-02-28 18:17 - 2016-11-11 14:16 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\EditionUpgradeHelper.dll
2017-02-28 18:17 - 2016-11-11 14:15 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2017-02-28 18:17 - 2016-11-11 14:14 - 02104320 _____ (Microsoft Corporation) C:\Windows\system32\wlidsvc.dll
2017-02-28 18:17 - 2016-11-11 14:14 - 00615424 _____ (Microsoft Corporation) C:\Windows\system32\wpnprv.dll
2017-02-28 18:17 - 2016-11-11 14:14 - 00178176 _____ (Microsoft Corporation) C:\Windows\system32\sppnp.dll
2017-02-28 18:17 - 2016-11-11 14:13 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\StorSvc.dll
2017-02-28 18:17 - 2016-11-11 14:11 - 00870400 _____ (Microsoft Corporation) C:\Windows\system32\mfmkvsrcsnk.dll
2017-02-28 18:17 - 2016-11-11 14:11 - 00096256 _____ (Microsoft Corporation) C:\Windows\system32\umpoext.dll
2017-02-28 18:17 - 2016-11-11 14:09 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\dialserver.dll
2017-02-28 18:17 - 2016-11-11 14:07 - 01691136 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2017-02-28 18:17 - 2016-11-11 14:07 - 00779776 _____ (Microsoft Corporation) C:\Windows\system32\cscui.dll
2017-02-28 18:17 - 2016-11-11 14:07 - 00347648 _____ (Microsoft Corporation) C:\Windows\system32\rascustom.dll
2017-02-28 18:17 - 2016-11-11 14:06 - 03400192 _____ (Microsoft Corporation) C:\Windows\system32\SyncCenter.dll
2017-02-28 18:17 - 2016-11-11 14:06 - 00650752 _____ (Microsoft Corporation) C:\Windows\system32\RDXService.dll
2017-02-28 18:17 - 2016-11-11 14:05 - 04136448 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepository.dll
2017-02-28 18:17 - 2016-11-11 14:05 - 01779712 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-02-28 18:17 - 2016-11-11 14:04 - 02800128 _____ (Microsoft Corporation) C:\Windows\system32\netshell.dll
2017-02-28 18:17 - 2016-11-11 14:04 - 02611200 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2017-02-28 18:17 - 2016-11-11 14:04 - 01709056 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll
2017-02-28 18:17 - 2016-11-11 14:04 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\usercpl.dll
2017-02-28 18:17 - 2016-11-11 14:04 - 00909312 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll
2017-02-28 18:17 - 2016-11-11 14:04 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\dmenrollengine.dll
2017-02-28 18:17 - 2016-11-11 14:04 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\stobject.dll
2017-02-28 18:17 - 2016-11-11 14:03 - 02669056 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-02-28 18:17 - 2016-11-11 14:03 - 02287616 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2017-02-28 18:17 - 2016-11-11 14:03 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll
2017-02-28 18:17 - 2016-11-11 14:03 - 00632320 _____ (Microsoft Corporation) C:\Windows\system32\rasapi32.dll
2017-02-28 18:17 - 2016-11-11 14:03 - 00283648 _____ (Microsoft Corporation) C:\Windows\system32\wkssvc.dll
2017-02-28 18:17 - 2016-11-11 13:01 - 01969912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hevcdecoder.dll
2017-02-28 18:17 - 2016-11-11 13:00 - 01706488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-02-28 18:17 - 2016-11-11 12:54 - 00122208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\migisol.dll
2017-02-28 18:17 - 2016-11-11 12:49 - 00869848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll
2017-02-28 18:17 - 2016-11-11 12:49 - 00248480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\policymanager.dll
2017-02-28 18:17 - 2016-11-11 12:47 - 05722832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2017-02-28 18:17 - 2016-11-11 12:47 - 01430720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2017-02-28 18:17 - 2016-11-11 12:42 - 00152416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RTWorkQ.dll
2017-02-28 18:17 - 2016-11-11 12:41 - 04311736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2017-02-28 18:17 - 2016-11-11 12:38 - 01263856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2017-02-28 18:17 - 2016-11-11 12:25 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapsBtSvc.dll
2017-02-28 18:17 - 2016-11-11 12:25 - 00071168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MosStorage.dll
2017-02-28 18:17 - 2016-11-11 12:24 - 00138240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DisplayManager.dll
2017-02-28 18:17 - 2016-11-11 12:24 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Shell.Search.UriHandler.dll
2017-02-28 18:17 - 2016-11-11 12:23 - 00094208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepositoryClient.dll
2017-02-28 18:17 - 2016-11-11 12:22 - 00122880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sendmail.dll
2017-02-28 18:17 - 2016-11-11 12:21 - 00332288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapConfiguration.dll
2017-02-28 18:17 - 2016-11-11 12:21 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2017-02-28 18:17 - 2016-11-11 12:20 - 00306176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieproxy.dll
2017-02-28 18:17 - 2016-11-11 12:19 - 00506880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DevicePairing.dll
2017-02-28 18:17 - 2016-11-11 12:19 - 00298496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Management.dll
2017-02-28 18:17 - 2016-11-11 12:19 - 00284672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepsync.dll
2017-02-28 18:17 - 2016-11-11 12:19 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepapi.dll
2017-02-28 18:17 - 2016-11-11 12:18 - 02333184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2017-02-28 18:17 - 2016-11-11 12:18 - 01336320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsecedit.dll
2017-02-28 18:17 - 2016-11-11 12:18 - 00318464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFolder.dll
2017-02-28 18:17 - 2016-11-11 12:17 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2017-02-28 18:17 - 2016-11-11 12:16 - 00253952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2017-02-28 18:17 - 2016-11-11 12:15 - 01357824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCore.dll
2017-02-28 18:17 - 2016-11-11 12:15 - 00838144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JpMapControl.dll
2017-02-28 18:17 - 2016-11-11 12:14 - 00395264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dmenrollengine.dll
2017-02-28 18:17 - 2016-11-11 12:12 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdtcuiu.dll
2017-02-28 18:17 - 2016-11-11 12:10 - 06109184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mos.dll
2017-02-28 18:17 - 2016-11-11 12:09 - 05380608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BingMaps.dll
2017-02-28 18:17 - 2016-11-11 12:06 - 02362880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapRouter.dll
2017-02-28 18:17 - 2016-11-11 12:06 - 02109952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapGeocoder.dll
2017-02-28 18:17 - 2016-11-11 12:06 - 00400384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToManager.dll
2017-02-28 18:17 - 2016-11-11 12:05 - 03370496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepository.dll
2017-02-28 18:17 - 2016-11-11 12:04 - 02682880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netshell.dll
2017-02-28 18:17 - 2016-11-11 12:04 - 00912896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.dll
2017-02-28 18:17 - 2016-11-11 12:04 - 00715264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapControlCore.dll
2017-02-28 18:17 - 2016-11-11 12:04 - 00358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\stobject.dll
2017-02-28 18:17 - 2016-11-11 12:03 - 02484736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
2017-02-28 18:17 - 2016-11-11 12:03 - 01576448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2017-02-28 18:17 - 2016-11-11 12:03 - 01556480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll
2017-02-28 18:17 - 2016-11-11 12:03 - 00772608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll
2017-02-28 18:17 - 2016-11-11 12:03 - 00760832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NMAA.dll
2017-02-28 18:17 - 2016-11-11 12:03 - 00565248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasapi32.dll
2017-02-28 18:17 - 2016-11-11 12:02 - 00711680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll
2017-02-28 18:16 - 2016-12-21 13:04 - 07816032 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-02-28 18:16 - 2016-12-21 12:42 - 00241504 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHost.dll
2017-02-28 18:16 - 2016-12-21 12:37 - 00455520 _____ (Microsoft Corporation) C:\Windows\system32\securekernel.exe
2017-02-28 18:16 - 2016-12-21 12:13 - 00119808 _____ (Microsoft Corporation) C:\Windows\system32\KnobsCsp.dll
2017-02-28 18:16 - 2016-12-21 12:12 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\ProvPluginEng.dll
2017-02-28 18:16 - 2016-12-21 12:10 - 00234496 _____ (Microsoft Corporation) C:\Windows\system32\KnobsCore.dll
2017-02-28 18:16 - 2016-12-21 12:09 - 00363520 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.BioFeedback.dll
2017-02-28 18:16 - 2016-12-21 12:08 - 01292288 _____ (Microsoft Corporation) C:\Windows\system32\MSVPXENC.dll
2017-02-28 18:16 - 2016-12-21 12:08 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.BlockedShutdown.dll
2017-02-28 18:16 - 2016-12-21 12:08 - 00349184 _____ (Microsoft Corporation) C:\Windows\system32\provengine.dll
2017-02-28 18:16 - 2016-12-21 12:08 - 00211968 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgent.exe
2017-02-28 18:16 - 2016-12-21 12:07 - 00748544 _____ (Microsoft Corporation) C:\Windows\system32\StoreAgent.dll
2017-02-28 18:16 - 2016-12-21 12:06 - 00310784 _____ (Microsoft Corporation) C:\Windows\system32\SyncSettings.dll
2017-02-28 18:16 - 2016-12-21 12:06 - 00260608 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgentUserBroker.exe
2017-02-28 18:16 - 2016-12-21 12:06 - 00147456 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-02-28 18:16 - 2016-12-21 12:00 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\fhcfg.dll
2017-02-28 18:16 - 2016-12-21 11:57 - 00462336 _____ (Microsoft Corporation) C:\Windows\system32\fhsettingsprovider.dll
2017-02-28 18:16 - 2016-12-21 11:53 - 01692672 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.onecore.dll
2017-02-28 18:16 - 2016-12-21 11:51 - 02275840 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2017-02-28 18:16 - 2016-12-21 11:49 - 02691072 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Logon.dll
2017-02-28 18:16 - 2016-12-21 10:02 - 03892864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2017-02-28 18:16 - 2016-12-21 10:02 - 01852720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2017-02-28 18:16 - 2016-12-21 10:02 - 01360464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetsrc.dll
2017-02-28 18:16 - 2016-12-21 10:02 - 01277344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2017-02-28 18:16 - 2016-12-21 10:02 - 01201872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll
2017-02-28 18:16 - 2016-12-21 10:02 - 00980832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetcore.dll
2017-02-28 18:16 - 2016-12-21 09:35 - 04612608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2017-02-28 18:16 - 2016-12-21 09:27 - 00640000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MCRecvSrc.dll
2017-02-28 18:16 - 2016-12-21 09:24 - 05061120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2017-02-28 18:16 - 2016-12-21 09:24 - 03733504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll
2017-02-28 18:16 - 2016-12-21 09:24 - 00886272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aadtb.dll
2017-02-28 18:16 - 2016-12-21 09:22 - 00860672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll
2017-02-28 18:16 - 2016-12-14 10:41 - 00590960 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2017-02-28 18:16 - 2016-12-14 10:33 - 01356864 _____ (Microsoft Corporation) C:\Windows\system32\ClipUp.exe
2017-02-28 18:16 - 2016-12-14 10:26 - 01469792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppVEntSubsystems32.dll
2017-02-28 18:16 - 2016-12-14 10:18 - 00715104 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys
2017-02-28 18:16 - 2016-12-14 10:18 - 00335712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2017-02-28 18:16 - 2016-12-14 10:14 - 00418952 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2017-02-28 18:16 - 2016-12-14 10:14 - 00089416 _____ (Microsoft Corporation) C:\Windows\system32\remoteaudioendpoint.dll
2017-02-28 18:16 - 2016-12-14 10:08 - 00341344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-02-28 18:16 - 2016-12-14 10:06 - 00509792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncHost.exe
2017-02-28 18:16 - 2016-12-14 09:45 - 00147968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32k.sys
2017-02-28 18:16 - 2016-12-14 09:42 - 00352768 _____ (Microsoft Corporation) C:\Windows\system32\cloudAP.dll
2017-02-28 18:16 - 2016-12-14 09:40 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\domgmt.dll
2017-02-28 18:16 - 2016-12-14 09:40 - 00266752 _____ (Microsoft Corporation) C:\Windows\system32\ConsoleLogon.dll
2017-02-28 18:16 - 2016-12-14 09:40 - 00104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.UI.Logon.ProxyStub.dll
2017-02-28 18:16 - 2016-12-14 09:39 - 00837632 _____ (Microsoft Corporation) C:\Windows\system32\wbiosrvc.dll
2017-02-28 18:16 - 2016-12-14 09:39 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.CredDialogController.dll
2017-02-28 18:16 - 2016-12-14 09:38 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\CloudBackupSettings.dll
2017-02-28 18:16 - 2016-12-14 09:36 - 01002496 _____ (Microsoft Corporation) C:\Windows\system32\SRH.dll
2017-02-28 18:16 - 2016-12-14 09:35 - 00712192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2017-02-28 18:16 - 2016-12-14 09:32 - 00806400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3D12.dll
2017-02-28 18:16 - 2016-12-14 09:32 - 00497152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LogonController.dll
2017-02-28 18:16 - 2016-12-14 09:25 - 02009600 _____ (Microsoft Corporation) C:\Windows\system32\SRHInproc.dll
2017-02-28 18:16 - 2016-12-14 09:23 - 01231872 _____ (Microsoft Corporation) C:\Windows\system32\dosvc.dll
2017-02-28 18:16 - 2016-12-14 09:22 - 02998272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
2017-02-28 18:16 - 2016-12-14 09:22 - 00707584 _____ (Microsoft Corporation) C:\Windows\system32\LogonController.dll
2017-02-28 18:16 - 2016-12-09 15:34 - 01051112 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2017-02-28 18:16 - 2016-12-09 15:34 - 00894096 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2017-02-28 18:16 - 2016-12-09 15:33 - 01354320 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2017-02-28 18:16 - 2016-12-09 15:33 - 01173496 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2017-02-28 18:16 - 2016-12-09 15:30 - 00377184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\clfs.sys
2017-02-28 18:16 - 2016-12-09 15:14 - 01274712 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2017-02-28 18:16 - 2016-12-09 15:10 - 01572768 _____ (Microsoft Corporation) C:\Windows\system32\gdi32full.dll
2017-02-28 18:16 - 2016-12-09 15:01 - 02323728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2017-02-28 18:16 - 2016-12-09 14:51 - 00117240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-02-28 18:16 - 2016-12-09 14:45 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\WordBreakers.dll
2017-02-28 18:16 - 2016-12-09 14:33 - 01589760 _____ (Microsoft Corporation) C:\Windows\system32\msdtctm.dll
2017-02-28 18:16 - 2016-12-09 14:28 - 03306496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2017-02-28 18:16 - 2016-12-09 14:27 - 05114368 _____ (Microsoft Corporation) C:\Windows\system32\cdp.dll
2017-02-28 18:16 - 2016-12-09 14:22 - 02820096 _____ (Microsoft Corporation) C:\Windows\system32\InputService.dll
2017-02-28 18:16 - 2016-12-09 14:21 - 00716800 _____ (Microsoft Corporation) C:\Windows\system32\ShareHost.dll
2017-02-28 18:16 - 2016-12-09 14:20 - 03198464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdp.dll
2017-02-28 18:16 - 2016-12-09 14:19 - 00433664 _____ (Microsoft Corporation) C:\Windows\system32\TextInputFramework.dll
2017-02-28 18:16 - 2016-12-09 14:19 - 00261120 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Core.TextInput.dll
2017-02-28 18:16 - 2016-12-09 14:19 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\InputLocaleManager.dll
2017-02-28 18:16 - 2016-12-09 14:19 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\EditBufferTestHook.dll
2017-02-28 18:16 - 2016-12-09 14:17 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ShareHost.dll
2017-02-28 18:16 - 2016-11-11 15:15 - 00198856 _____ (Microsoft Corporation) C:\Windows\system32\wscapi.dll
2017-02-28 18:16 - 2016-11-11 15:02 - 00360040 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsAdminFlows.exe
2017-02-28 18:16 - 2016-11-11 15:01 - 01859264 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2017-02-28 18:16 - 2016-11-11 14:56 - 00424616 _____ (Microsoft Corporation) C:\Windows\system32\MFPlay.dll
2017-02-28 18:16 - 2016-11-11 14:56 - 00163752 _____ (Microsoft Corporation) C:\Windows\system32\RTWorkQ.dll
2017-02-28 18:16 - 2016-11-11 14:31 - 00366080 _____ (Microsoft Corporation) C:\Windows\system32\RDXTaskFactory.dll
2017-02-28 18:16 - 2016-11-11 14:28 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\CbtBackgroundManagerPolicy.dll
2017-02-28 18:16 - 2016-11-11 14:27 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\lpremove.exe
2017-02-28 18:16 - 2016-11-11 14:26 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\modem.sys
2017-02-28 18:16 - 2016-11-11 14:25 - 00151040 _____ (Microsoft Corporation) C:\Windows\system32\MapsBtSvc.dll
2017-02-28 18:16 - 2016-11-11 14:25 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\MosStorage.dll
2017-02-28 18:16 - 2016-11-11 14:24 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\ACPBackgroundManagerPolicy.dll
2017-02-28 18:16 - 2016-11-11 14:23 - 00409088 _____ (Microsoft Corporation) C:\Windows\system32\NgcCtnr.dll
2017-02-28 18:16 - 2016-11-11 14:22 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\moshost.dll
2017-02-28 18:16 - 2016-11-11 14:21 - 00313856 _____ (Microsoft Corporation) C:\Windows\system32\moshostcore.dll
2017-02-28 18:16 - 2016-11-11 14:20 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\ngccredprov.dll
2017-02-28 18:16 - 2016-11-11 14:20 - 00590336 _____ (Microsoft Corporation) C:\Windows\system32\efswrt.dll
2017-02-28 18:16 - 2016-11-11 14:20 - 00446976 _____ (Microsoft Corporation) C:\Windows\system32\MapConfiguration.dll
2017-02-28 18:16 - 2016-11-11 14:20 - 00381952 _____ (Microsoft Corporation) C:\Windows\system32\cryptngc.dll
2017-02-28 18:16 - 2016-11-11 14:20 - 00339456 _____ (Microsoft Corporation) C:\Windows\system32\cdpusersvc.dll
2017-02-28 18:16 - 2016-11-11 14:19 - 00411648 _____ (Microsoft Corporation) C:\Windows\system32\cdpsvc.dll
2017-02-28 18:16 - 2016-11-11 14:19 - 00366080 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll
2017-02-28 18:16 - 2016-11-11 14:19 - 00320000 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2017-02-28 18:16 - 2016-11-11 14:17 - 01220096 _____ (Microsoft Corporation) C:\Windows\system32\wscui.cpl
2017-02-28 18:16 - 2016-11-11 14:17 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\ProvSysprep.dll
2017-02-28 18:16 - 2016-11-11 14:16 - 00184832 _____ (Microsoft Corporation) C:\Windows\system32\wscsvc.dll
2017-02-28 18:16 - 2016-11-11 14:16 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\RjvMDMConfig.dll
2017-02-28 18:16 - 2016-11-11 14:15 - 00282624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-02-28 18:16 - 2016-11-11 14:15 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\wscinterop.dll
2017-02-28 18:16 - 2016-11-11 14:14 - 07654400 _____ (Microsoft Corporation) C:\Windows\system32\mos.dll
2017-02-28 18:16 - 2016-11-11 14:14 - 00713216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2017-02-28 18:16 - 2016-11-11 14:13 - 07812096 _____ (Microsoft Corporation) C:\Windows\system32\BingMaps.dll
2017-02-28 18:16 - 2016-11-11 14:13 - 00306176 _____ (Microsoft Corporation) C:\Windows\system32\msdtcuiu.dll
2017-02-28 18:16 - 2016-11-11 14:12 - 00870912 _____ (Microsoft Corporation) C:\Windows\system32\msdtcprx.dll
2017-02-28 18:16 - 2016-11-11 14:09 - 01366016 _____ (Microsoft Corporation) C:\Windows\system32\wpncore.dll
2017-02-28 18:16 - 2016-11-11 14:08 - 00539136 _____ (Microsoft Corporation) C:\Windows\system32\PlayToManager.dll
2017-02-28 18:16 - 2016-11-11 14:07 - 03441152 _____ (Microsoft Corporation) C:\Windows\system32\MapRouter.dll
2017-02-28 18:16 - 2016-11-11 14:07 - 02953216 _____ (Microsoft Corporation) C:\Windows\system32\MapGeocoder.dll
2017-02-28 18:16 - 2016-11-11 14:07 - 02510848 _____ (Microsoft Corporation) C:\Windows\system32\NetworkMobileSettings.dll
2017-02-28 18:16 - 2016-11-11 14:07 - 01060864 _____ (Microsoft Corporation) C:\Windows\system32\JpMapControl.dll
2017-02-28 18:16 - 2016-11-11 14:07 - 00991232 _____ (Microsoft Corporation) C:\Windows\system32\comdlg32.dll
2017-02-28 18:16 - 2016-11-11 14:06 - 00960000 _____ (Microsoft Corporation) C:\Windows\system32\modernexecserver.dll
2017-02-28 18:16 - 2016-11-11 14:05 - 02852864 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsThresholdAdminFlowUI.dll
2017-02-28 18:16 - 2016-11-11 14:05 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\MapsStore.dll
2017-02-28 18:16 - 2016-11-11 14:04 - 00691712 _____ (Microsoft Corporation) C:\Windows\system32\lsm.dll
2017-02-28 18:16 - 2016-11-11 14:03 - 04708864 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2017-02-28 18:16 - 2016-11-11 14:03 - 00905216 _____ (Microsoft Corporation) C:\Windows\system32\MapControlCore.dll
2017-02-28 18:16 - 2016-11-11 14:02 - 03542016 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2017-02-28 18:16 - 2016-11-11 14:02 - 01726976 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll
2017-02-28 18:16 - 2016-11-11 14:02 - 00936448 _____ (Microsoft Corporation) C:\Windows\system32\NMAA.dll
2017-02-28 18:16 - 2016-11-11 13:01 - 00167848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll
2017-02-28 18:16 - 2016-11-11 12:59 - 01572768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-02-28 18:16 - 2016-11-11 12:48 - 02277248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2017-02-28 18:16 - 2016-11-11 12:47 - 00527880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2017-02-28 18:16 - 2016-11-11 12:42 - 01123912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2017-02-28 18:16 - 2016-11-11 12:42 - 00952416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
2017-02-28 18:16 - 2016-11-11 12:42 - 00374448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFPlay.dll
2017-02-28 18:16 - 2016-11-11 12:42 - 00091936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfaudiocnv.dll
2017-02-28 18:16 - 2016-11-11 12:41 - 00157536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudStorageWizard.exe
2017-02-28 18:16 - 2016-11-11 12:27 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetCfgNotifyObjectHost.exe
2017-02-28 18:16 - 2016-11-11 12:26 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgentc.exe
2017-02-28 18:16 - 2016-11-11 12:24 - 00519168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ngccredprov.dll
2017-02-28 18:16 - 2016-11-11 12:24 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BcastDVRHelper.dll
2017-02-28 18:16 - 2016-11-11 12:23 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppCapture.dll
2017-02-28 18:16 - 2016-11-11 12:22 - 00505856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcastdvr.exe
2017-02-28 18:16 - 2016-11-11 12:19 - 01755136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DeviceFlows.DataModel.dll
2017-02-28 18:16 - 2016-11-11 12:19 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupShim.dll
2017-02-28 18:16 - 2016-11-11 12:19 - 00114176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupugc.exe
2017-02-28 18:16 - 2016-11-11 12:18 - 01196544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscui.cpl
2017-02-28 18:16 - 2016-11-11 12:18 - 00431616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\efswrt.dll
2017-02-28 18:16 - 2016-11-11 12:18 - 00108544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscinterop.dll
2017-02-28 18:16 - 2016-11-11 12:17 - 00333312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActivationManager.dll
2017-02-28 18:16 - 2016-11-11 12:15 - 00348672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\zipfldr.dll
2017-02-28 18:16 - 2016-11-11 12:15 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptngc.dll
2017-02-28 18:16 - 2016-11-11 12:10 - 00746496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdtcprx.dll
2017-02-28 18:16 - 2016-11-11 12:09 - 00545280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmkvsrcsnk.dll
2017-02-28 18:16 - 2016-11-11 12:08 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xolehlp.dll
2017-02-28 18:16 - 2016-11-11 12:06 - 01228288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usercpl.dll
2017-02-28 18:16 - 2016-11-11 12:06 - 00359936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxclu.dll
2017-02-28 18:16 - 2016-11-11 12:05 - 04423680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2017-02-28 18:16 - 2016-11-11 12:04 - 01992704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2017-02-28 18:16 - 2016-11-11 12:04 - 01595392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-02-28 18:16 - 2016-11-11 12:03 - 02256384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-02-28 18:06 - 2016-12-21 12:08 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2017-02-28 18:06 - 2016-12-21 09:44 - 00120320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2017-02-28 17:33 - 2017-03-02 11:22 - 00000000 ____D C:\ProgramData\boost_interprocess
2017-02-28 17:33 - 2017-02-28 17:33 - 00000000 ____D C:\Users\Public\Documents\NI Resources
2017-02-28 17:32 - 2017-02-28 17:32 - 00000000 ____D C:\Program Files\Common Files\Avid
2017-02-28 17:31 - 2017-02-28 17:31 - 00000000 __HDC C:\ProgramData\{B49C92CB-1A73-4A41-A84C-5091582E7AA8}
2017-02-28 17:30 - 2017-02-28 17:30 - 00000000 __HDC C:\ProgramData\{90D8CE90-3E6B-4034-A281-BC9F19B60A5B}
2017-02-28 17:13 - 2017-02-28 17:13 - 00000000 ____D C:\Users\daz\AppData\Local\ElevatedDiagnostics
2017-02-28 16:59 - 2017-02-28 16:59 - 00000000 ____D C:\Users\daz\Downloads\tricap_w10d_v103
2017-02-28 16:54 - 2017-02-28 16:54 - 00094173 _____ C:\Users\daz\Downloads\tricap_w10d_v103.zip
2017-02-28 16:52 - 2017-02-28 16:52 - 234087194 _____ C:\Users\daz\Documents\28022017.reg
2017-02-28 16:48 - 2017-02-28 16:48 - 13802246 _____ C:\Users\daz\Downloads\Maschine_200_Downloader_Win.zip
2017-02-28 16:48 - 2017-02-28 16:48 - 00000000 ____D C:\Users\daz\Downloads\Maschine_200_Downloader_Win
2017-02-28 16:01 - 2017-02-28 16:01 - 00000893 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CC 2017.lnk
2017-02-28 16:00 - 2017-02-28 16:00 - 00001619 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Application Manager.lnk
2017-02-28 14:21 - 2017-02-28 14:21 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsign449a8d0c8b792b80
2017-02-28 14:17 - 2017-02-28 14:17 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsign8e7f300ddfa3e464
2017-02-28 14:17 - 2017-02-28 14:17 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsign7964ae0d3a81a8f3
2017-02-28 12:58 - 2017-02-28 12:58 - 01211051 _____ C:\Users\daz\Downloads\AkelPad-4.9.8-x64-setup.exe
2017-02-28 12:56 - 2017-02-28 12:56 - 00251848 _____ (Malwarebytes) C:\Windows\system32\Drivers\6A861D3C.sys
2017-02-28 12:54 - 2017-02-28 12:54 - 00000000 ____D C:\Users\daz\AppData\LocalLow\Yandex
2017-02-28 12:54 - 2017-02-28 12:54 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsignfc6da9ca5fce4ee5
2017-02-28 12:51 - 2017-03-02 19:05 - 00000000 ___RD C:\Users\daz\YandexDisk
2017-02-28 12:51 - 2017-02-28 12:54 - 00000000 ____D C:\Users\daz\AppData\Roaming\Yandex
2017-02-28 12:51 - 2017-02-28 12:51 - 00002008 _____ C:\Users\daz\Desktop\Яндекс.Диск.lnk
2017-02-28 12:51 - 2017-02-28 12:51 - 00000000 ____D C:\Users\daz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Яндекс.Диск
2017-02-28 12:51 - 2017-02-28 12:51 - 00000000 ____D C:\Users\daz\AppData\Local\Yandex
2017-02-28 12:51 - 2017-02-28 12:51 - 00000000 ____D C:\ProgramData\Yandex
2017-02-28 12:51 - 2017-02-28 12:51 - 00000000 ____D C:\Program Files\Yandex
2017-02-28 12:51 - 2017-02-28 12:51 - 00000000 ____D C:\Program Files (x86)\Yandex
2017-02-28 12:50 - 2017-02-28 12:51 - 01672072 _____ (Яндекс) C:\Users\daz\Downloads\YandexDiskSetupRu.exe
2017-02-28 12:50 - 2017-02-28 12:50 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsignaca85ac9feb22847
2017-02-28 12:50 - 2017-02-28 12:50 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsign61a0a692459e6aef
2017-02-28 12:24 - 2017-02-28 16:09 - 00004562 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-02-28 12:24 - 2017-02-28 12:24 - 00002469 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk
2017-02-28 12:24 - 2017-02-28 12:24 - 00002114 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk
2017-02-28 12:24 - 2017-02-28 12:24 - 00000040 ____H C:\CFF07C1717DE
2017-02-28 12:23 - 2017-02-28 12:23 - 00000000 ____D C:\Program Files (x86)\Adobe
2017-02-28 12:20 - 2017-03-02 12:28 - 00000034 _____ C:\Users\daz\AppData\Roaming\AdobeWLCMCache.dat
2017-02-28 12:20 - 2017-02-28 12:20 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsignb3f30a7105871b0e
2017-02-28 12:20 - 2017-02-28 12:20 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsign67e3f0304adb7510
2017-02-28 12:16 - 2017-02-28 12:16 - 00001314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Illustrator CC 2017.lnk
2017-02-28 11:56 - 2017-02-28 11:56 - 00003804 _____ C:\Windows\System32\Tasks\KMSAutoNet
2017-02-28 11:56 - 2017-02-28 11:56 - 00000000 ____D C:\Users\daz\AppData\Local\PeerDistRepub
2017-02-28 11:56 - 2017-02-28 11:56 - 00000000 ____D C:\ProgramData\KMSAutoS
2017-02-28 11:55 - 2017-02-28 11:56 - 00000000 ____D C:\Users\daz\AppData\Local\MSfree Inc
2017-02-28 11:48 - 2017-02-28 11:46 - 00485032 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2017-02-28 11:32 - 2017-02-28 11:32 - 00002662 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2017-02-28 11:32 - 2017-02-28 11:32 - 00002656 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
2017-02-28 11:32 - 2017-02-28 11:32 - 00002648 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2017-02-28 11:32 - 2017-02-28 11:32 - 00002648 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
2017-02-28 11:32 - 2017-02-28 11:32 - 00002642 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
2017-02-28 11:32 - 2017-02-28 11:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
2017-02-28 11:32 - 2017-02-28 11:32 - 00000000 ____D C:\Windows\PCHEALTH
2017-02-28 11:32 - 2017-02-28 11:32 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2017-02-28 11:31 - 2017-02-28 11:31 - 00000000 ____D C:\Windows\SHELLNEW
2017-02-28 11:31 - 2017-02-28 11:31 - 00000000 ____D C:\Users\daz\AppData\Local\Microsoft Help
2017-02-28 11:31 - 2017-02-28 11:31 - 00000000 ____D C:\Program Files\Microsoft Analysis Services
2017-02-28 11:31 - 2017-02-28 11:31 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-02-28 11:31 - 2017-02-28 11:31 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2017-02-28 11:26 - 2017-03-02 11:52 - 00000000 ____D C:\Users\daz\Documents\Native Instruments
2017-02-28 11:26 - 2017-03-02 11:50 - 00000000 ____D C:\Users\daz\AppData\Local\Native Instruments
2017-02-28 11:26 - 2017-02-28 11:26 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsigne4c9f2144a3ad300
2017-02-28 11:26 - 2017-02-28 11:26 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsignc930c2d59326671e
2017-02-28 11:26 - 2017-02-28 11:26 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsignc102af645290397e
2017-02-28 05:57 - 2017-02-27 18:59 - 00000000 ____D C:\Windows\Panther
2017-02-27 20:11 - 2017-02-27 20:11 - 00001003 _____ C:\Users\Public\Desktop\Maschine.lnk
2017-02-27 20:11 - 2017-02-27 20:11 - 00000000 __HDC C:\ProgramData\{F142EE57-68C1-4CB1-8798-C465F706CCDC}
2017-02-27 20:08 - 2017-02-27 20:08 - 00000000 __HDC C:\ProgramData\{F57C376F-E7ED-4527-9EE2-4D50799418BC}
2017-02-27 20:07 - 2017-03-01 21:48 - 00000000 ____D C:\Program Files\Common Files\Native Instruments
2017-02-27 20:07 - 2017-03-01 20:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments
2017-02-27 20:07 - 2017-03-01 19:42 - 00000000 ____D C:\Program Files\Native Instruments
2017-02-27 20:07 - 2017-02-28 17:30 - 00001132 _____ C:\Users\Public\Desktop\Service Center.lnk
2017-02-27 20:07 - 2017-02-27 20:07 - 00000000 ____D C:\ProgramData\Native Instruments
2017-02-27 19:59 - 2017-02-27 19:59 - 00000000 ____D C:\Users\daz\AppData\Roaming\NexusFont
2017-02-27 19:59 - 2017-02-27 19:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\nexusfont
2017-02-27 19:59 - 2017-02-27 19:59 - 00000000 ____D C:\Program Files (x86)\nexusfont
2017-02-27 19:57 - 2017-02-27 19:58 - 02392038 _____ (xiles ) C:\Users\daz\Downloads\nexusfont_setup_2.6.2.exe
2017-02-27 19:55 - 2017-02-27 19:55 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsign32c22daadb39ccdd
2017-02-27 19:53 - 2017-03-02 17:39 - 00001456 _____ C:\Users\daz\AppData\Local\Adobe Save for Web 13.0 Prefs
2017-02-27 19:45 - 2017-02-27 19:45 - 1078990848 _____ C:\Users\daz\Downloads\Maschine.iso
2017-02-27 19:37 - 2017-02-27 19:37 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsigne809c10088127882
2017-02-27 19:37 - 2017-02-27 19:37 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsignc52145eb38c1c966
2017-02-27 19:36 - 2017-02-27 19:36 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsign29e808eedf4481e9
2017-02-27 19:34 - 2017-02-27 19:34 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsign24f6ff309c09d19e
2017-02-27 19:12 - 2017-02-28 12:25 - 00000000 ____D C:\Users\daz\AppData\LocalLow\Adobe
2017-02-27 19:00 - 2017-02-27 19:00 - 00000020 ___SH C:\Users\defaultuser0\ntuser.ini
2017-02-27 19:00 - 2017-02-27 19:00 - 00000000 _SHDL C:\Users\Public\Documents\My Videos
2017-02-27 19:00 - 2017-02-27 19:00 - 00000000 _SHDL C:\Users\Public\Documents\My Pictures
2017-02-27 19:00 - 2017-02-27 19:00 - 00000000 _SHDL C:\Users\Public\Documents\My Music
2017-02-27 19:00 - 2017-02-27 19:00 - 00000000 _SHDL C:\Users\defaultuser0\My Documents
2017-02-27 19:00 - 2017-02-27 19:00 - 00000000 _SHDL C:\Users\defaultuser0\Documents\My Videos
2017-02-27 19:00 - 2017-02-27 19:00 - 00000000 _SHDL C:\Users\defaultuser0\Documents\My Pictures
2017-02-27 19:00 - 2017-02-27 19:00 - 00000000 _SHDL C:\Users\defaultuser0\Documents\My Music
2017-02-27 19:00 - 2017-02-27 19:00 - 00000000 _SHDL C:\Users\Default\My Documents
2017-02-27 19:00 - 2017-02-27 19:00 - 00000000 _SHDL C:\Users\Default\Documents\My Videos
2017-02-27 19:00 - 2017-02-27 19:00 - 00000000 _SHDL C:\Users\Default\Documents\My Pictures
2017-02-27 19:00 - 2017-02-27 19:00 - 00000000 _SHDL C:\Users\Default\Documents\My Music
2017-02-27 19:00 - 2017-02-27 19:00 - 00000000 _SHDL C:\Users\Default User\Documents\My Videos
2017-02-27 19:00 - 2017-02-27 19:00 - 00000000 _SHDL C:\Users\Default User\Documents\My Pictures
2017-02-27 19:00 - 2017-02-27 19:00 - 00000000 _SHDL C:\Users\Default User\Documents\My Music
2017-02-27 19:00 - 2017-02-27 19:00 - 00000000 _SHDL C:\Documents and Settings
2017-02-27 19:00 - 2017-02-27 19:00 - 00000000 ____D C:\Users\defaultuser0
2017-02-27 18:58 - 2017-02-27 18:58 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2017-02-27 18:58 - 2017-02-27 18:58 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2017-02-27 18:46 - 2017-02-27 18:46 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsign8a058cfccd6350ab
2017-02-27 18:46 - 2017-02-27 18:46 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsign72116a3c01f82575
2017-02-27 18:46 - 2017-02-27 18:46 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsign1df3678137c9dc65
2017-02-27 18:38 - 2017-02-28 12:25 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2017-02-27 18:38 - 2017-02-27 18:38 - 00003626 _____ C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-DESKTOP-ICP4TLM-daz
2017-02-27 18:38 - 2017-02-27 18:38 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsigna583b532b1c345b2
2017-02-27 18:38 - 2017-02-27 18:38 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsign72b86b7d4e5d6685
2017-02-27 18:38 - 2017-02-27 18:38 - 00000000 ____D C:\Users\daz\AppData\Local\Tempzxpsign5e7ce925615e71d8
2017-02-27 18:38 - 2017-02-27 18:38 - 00000000 ____D C:\Users\daz\AppData\Local\CEF
2017-02-27 18:34 - 2017-02-27 18:34 - 00001085 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2017.lnk
2017-02-27 18:34 - 2017-02-27 18:34 - 00000000 ____D C:\Program Files\Adobe
2017-02-27 18:32 - 2017-02-28 12:16 - 00000000 ____D C:\Program Files\Common Files\Adobe
2017-02-27 18:30 - 2017-03-02 02:00 - 00000000 ____D C:\Users\daz\AppData\Local\Adobe
2017-02-27 18:30 - 2017-02-28 19:01 - 00000000 ____D C:\ProgramData\Adobe
2017-02-27 18:30 - 2017-02-27 18:30 - 00000000 ____D C:\Users\daz\AppData\LocalLow\AMD
2017-02-27 18:30 - 2017-02-27 18:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Settings
2017-02-27 18:30 - 2017-02-27 18:30 - 00000000 ____D C:\Program Files\ATI Technologies
2017-02-27 18:30 - 2017-02-27 18:30 - 00000000 ____D C:\Program Files (x86)\AMD
2017-02-27 18:28 - 2017-02-27 18:28 - 00000000 ____D C:\Windows\system32\СЏСЏСЏСЏСЏСЏСЏСЏerStore
2017-02-27 18:20 - 2017-02-27 18:20 - 00112408 _____ C:\Windows\system32\Drivers\NIWinCDEmu.sys
2017-02-27 18:20 - 2017-02-27 18:20 - 00000000 ____D C:\Program Files (x86)\Native Instruments
2017-02-27 18:08 - 2017-02-27 18:20 - 14193152 _____ (Native Instruments GmbH) C:\Users\daz\Downloads\Maschine_Downloader.exe
2017-02-27 17:56 - 2017-02-27 17:56 - 00015988 _____ C:\Users\daz\Downloads\[rutracker.org].t5340991.torrent
2017-02-27 17:53 - 2017-02-27 17:53 - 00012444 _____ C:\Users\daz\Downloads\[rutracker.org].t5343465.torrent
2017-02-27 17:35 - 2017-02-27 17:35 - 00000000 ___RD C:\Program Files (x86)\Skype
2017-02-27 17:35 - 2017-02-27 17:35 - 00000000 ____D C:\Users\daz\Tracing
2017-02-27 17:35 - 2017-02-27 17:35 - 00000000 ____D C:\ProgramData\Skype
2017-02-27 17:35 - 2017-02-27 17:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2017-02-27 17:34 - 2017-02-27 17:34 - 01218008 _____ (Skype Technologies S.A.) C:\Users\daz\Downloads\SkypeSetup.exe
2017-02-27 17:33 - 2017-02-27 19:54 - 00000000 ____D C:\Users\daz\AppData\Roaming\uTorrent
2017-02-27 17:33 - 2017-02-27 17:33 - 00000000 ____D C:\Users\daz\Downloads\Utorrent-2.2
2017-02-27 17:32 - 2017-02-27 17:32 - 00406876 _____ C:\Users\daz\Downloads\Utorrent-2.2.zip
2017-02-27 17:28 - 2017-02-27 17:28 - 00019936 _____ C:\Users\daz\Downloads\[rutracker.org].t5325863.torrent
2017-02-27 17:25 - 2017-02-27 17:25 - 00000000 ____D C:\Users\daz\AppData\Local\GHISLER
2017-02-27 17:24 - 2017-02-28 13:00 - 00000000 ____D C:\Program Files\totalcmd
2017-02-27 17:24 - 2017-02-27 17:25 - 00000000 ____D C:\Users\daz\AppData\Roaming\GHISLER
2017-02-27 17:24 - 2017-02-27 17:24 - 04987672 _____ (Ghisler Software GmbH) C:\Users\daz\Downloads\tcmd900ax64.exe
2017-02-27 17:24 - 2017-02-27 17:24 - 00000000 ____D C:\Users\daz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander
2017-02-27 17:21 - 2017-02-28 12:56 - 00176584 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
2017-02-27 17:20 - 2017-03-02 19:09 - 00091584 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2017-02-27 17:20 - 2017-03-02 19:05 - 00251848 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-02-27 17:20 - 2017-03-02 19:05 - 00110536 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2017-02-27 17:20 - 2017-03-02 19:05 - 00043968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-02-27 17:20 - 2017-02-27 17:20 - 00001627 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-02-27 17:20 - 2017-02-27 17:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MB
2017-02-27 17:20 - 2017-02-27 17:20 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-02-27 17:20 - 2017-02-27 17:20 - 00000000 ____D C:\Program Files\MB
2017-02-27 17:20 - 2017-01-20 07:47 - 00077416 _____ C:\Windows\system32\Drivers\mbae64.sys
2017-02-27 17:18 - 2017-02-27 17:20 - 55566792 _____ (Malwarebytes ) C:\Users\daz\Downloads\mb3-setup-consumer-3.0.6.1469.exe
2017-02-27 17:17 - 2017-02-27 17:17 - 00001051 _____ C:\Users\daz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optional Features.lnk
2017-02-27 17:17 - 2016-07-15 19:29 - 08628736 _____ (Microsoft Corporation) C:\Windows\system32\prm0019.dll
2017-02-27 17:16 - 2017-03-02 19:05 - 00000000 ____D C:\Users\daz\AppData\Roaming\Slack
2017-02-27 17:16 - 2017-02-27 17:16 - 00000000 ____D C:\Users\daz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Slack Technologies
2017-02-27 17:16 - 2017-02-27 17:16 - 00000000 ____D C:\Users\daz\AppData\Local\SquirrelTemp
2017-02-27 17:16 - 2017-02-27 17:16 - 00000000 ____D C:\Users\daz\AppData\Local\slack
2017-02-27 17:15 - 2017-02-27 17:15 - 00000000 ____D C:\Users\daz\AppData\Local\Comms
2017-02-27 17:13 - 2017-02-27 17:13 - 00000000 ____D C:\Users\daz\AppData\Roaming\FastStone
2017-02-27 17:13 - 2017-02-27 17:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FastStone Image Viewer
2017-02-27 17:13 - 2017-02-27 17:13 - 00000000 ____D C:\Program Files (x86)\FastStone Image Viewer
2017-02-27 17:12 - 2017-02-27 17:13 - 06689526 _____ (FastStone Soft) C:\Users\daz\Downloads\FSViewerSetup62.exe
2017-02-27 17:08 - 2017-02-28 11:24 - 00000000 ____D C:\Users\daz\AppData\Local\AMD
2017-02-27 17:08 - 2017-02-27 17:16 - 78537696 _____ (Slack Technologies) C:\Users\daz\Downloads\SlackSetup.exe
2017-02-27 17:07 - 2017-03-02 19:04 - 00065536 _____ C:\Windows\system32\spu_storage.bin
2017-02-27 17:07 - 2017-02-28 17:30 - 00000000 ____D C:\ProgramData\Package Cache
2017-02-27 17:07 - 2017-02-27 18:28 - 00000000 ____D C:\AMD
2017-02-27 17:07 - 2017-02-27 17:07 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2017-02-27 17:07 - 2017-02-27 17:07 - 00000000 ____D C:\Program Files\AMD
2017-02-27 17:05 - 2017-02-28 19:01 - 00003286 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task v2
2017-02-27 17:05 - 2017-02-27 17:06 - 01129376 _____ (Google Inc.) C:\Users\daz\Downloads\ChromeSetup.exe
2017-02-27 17:04 - 2017-02-28 19:01 - 00002361 _____ C:\Users\daz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-02-27 17:04 - 2017-02-28 19:01 - 00000000 ___RD C:\Users\daz\OneDrive
2017-02-27 17:04 - 2017-02-28 18:00 - 00000000 ____D C:\Users\daz\AppData\Roaming\Skype
2017-02-27 17:04 - 2017-02-27 17:04 - 00000000 ____D C:\Users\daz\AppData\Roaming\Macromedia
2017-02-27 17:04 - 2017-02-27 17:04 - 00000000 ____D C:\Users\daz\AppData\Local\MicrosoftEdge
2017-02-27 17:04 - 2017-02-27 17:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roland
2017-02-27 17:04 - 2017-02-27 17:04 - 00000000 ____D C:\Program Files\Roland
2017-02-27 17:02 - 2017-03-02 11:01 - 00000000 ____D C:\Users\daz
2017-02-27 17:02 - 2017-02-28 16:13 - 00000000 ____D C:\Users\daz\AppData\Roaming\Adobe
2017-02-27 17:02 - 2017-02-27 18:31 - 00000000 ____D C:\Users\daz\AppData\Local\ConnectedDevicesPlatform
2017-02-27 17:02 - 2017-02-27 18:15 - 00000000 ____D C:\Users\daz\AppData\Local\Packages
2017-02-27 17:02 - 2017-02-27 17:02 - 00000020 ___SH C:\Users\daz\ntuser.ini
2017-02-27 17:02 - 2017-02-27 17:02 - 00000000 _SHDL C:\Users\daz\My Documents
2017-02-27 17:02 - 2017-02-27 17:02 - 00000000 _SHDL C:\Users\daz\Documents\My Videos
2017-02-27 17:02 - 2017-02-27 17:02 - 00000000 _SHDL C:\Users\daz\Documents\My Pictures
2017-02-27 17:02 - 2017-02-27 17:02 - 00000000 _SHDL C:\Users\daz\Documents\My Music
2017-02-27 17:02 - 2017-02-27 17:02 - 00000000 ____D C:\Users\daz\AppData\Local\VirtualStore
2017-02-27 17:02 - 2017-02-27 17:02 - 00000000 ____D C:\Users\daz\AppData\Local\TileDataLayer
2017-02-27 17:02 - 2017-02-27 17:02 - 00000000 ____D C:\Users\daz\AppData\Local\Publishers
2017-02-27 17:01 - 2017-02-27 17:02 - 00000000 ____D C:\Users\defaultuser0\AppData\Local\Packages
2017-02-27 17:01 - 2017-02-27 17:01 - 00000000 ____D C:\Users\defaultuser0\AppData\Local\VirtualStore
2017-02-27 17:01 - 2017-02-27 17:01 - 00000000 ____D C:\Users\defaultuser0\AppData\Local\TileDataLayer
2017-02-27 17:01 - 2017-02-27 17:01 - 00000000 ____D C:\Users\defaultuser0\AppData\Local\ConnectedDevicesPlatform
2017-02-27 17:00 - 2017-02-27 17:00 - 00000000 ____D C:\Windows\CSC

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-03-02 19:09 - 2016-11-20 23:51 - 00922600 _____ C:\Windows\system32\PerfStringBackup.INI
2017-03-02 19:05 - 2016-11-20 23:41 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-03-02 19:04 - 2016-07-16 11:04 - 00262144 _____ C:\Windows\system32\config\BBI
2017-03-02 19:02 - 2016-07-16 16:47 - 00000000 ____D C:\Windows\registration
2017-03-02 17:33 - 2016-07-16 16:47 - 00000000 ____D C:\Windows\rescache
2017-03-02 15:31 - 2016-11-20 23:41 - 00000000 ____D C:\Windows\system32\SleepStudy
2017-03-02 11:10 - 2016-07-16 16:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-03-02 11:10 - 2016-07-16 16:47 - 00000000 ____D C:\Windows\AppReadiness
2017-03-01 18:18 - 2016-07-16 16:45 - 00000000 ____D C:\Windows\INF
2017-02-28 19:00 - 2016-11-20 23:54 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-02-28 18:56 - 2016-11-20 23:40 - 00221208 _____ C:\Windows\system32\FNTCACHE.DAT
2017-02-28 18:55 - 2016-07-16 16:47 - 00000000 ___RD C:\Windows\ImmersiveControlPanel
2017-02-28 18:55 - 2016-07-16 16:47 - 00000000 ____D C:\Windows\SysWOW64\oobe
2017-02-28 18:55 - 2016-07-16 16:47 - 00000000 ____D C:\Windows\system32\WinBioPlugIns
2017-02-28 18:55 - 2016-07-16 16:47 - 00000000 ____D C:\Windows\system32\oobe
2017-02-28 18:55 - 2016-07-16 16:47 - 00000000 ____D C:\Windows\ShellExperiences
2017-02-28 18:55 - 2016-07-16 16:47 - 00000000 ____D C:\Windows\Provisioning
2017-02-28 18:55 - 2016-07-16 16:47 - 00000000 ____D C:\Windows\PolicyDefinitions
2017-02-28 18:55 - 2016-07-16 16:47 - 00000000 ____D C:\Windows\bcastdvr
2017-02-28 18:55 - 2016-07-16 11:04 - 00000000 ____D C:\Windows\SysWOW64\Dism
2017-02-28 18:55 - 2016-07-16 11:04 - 00000000 ____D C:\Windows\system32\Sysprep
2017-02-28 18:55 - 2016-07-16 11:04 - 00000000 ____D C:\Windows\system32\Dism
2017-02-28 18:55 - 2016-07-16 11:04 - 00000000 ____D C:\Windows\servicing
2017-02-28 18:22 - 2016-07-16 16:36 - 00000000 ____D C:\Windows\CbsTemp
2017-02-28 18:03 - 2016-07-16 16:42 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\enrollmentapi.dll
2017-02-28 17:13 - 2016-07-16 16:47 - 00000000 ____D C:\Windows\system32\NDF
2017-02-28 11:32 - 2016-07-16 16:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-02-28 11:32 - 2016-07-16 16:47 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2017-02-28 11:24 - 2016-07-16 16:47 - 00000000 ____D C:\Windows\appcompat
2017-02-28 05:57 - 2016-07-16 16:47 - 00028672 _____ C:\Windows\system32\config\BCD-Template
2017-02-27 17:17 - 2016-11-20 23:12 - 00000000 ____D C:\Windows\OCR
2017-02-27 17:02 - 2016-07-16 16:47 - 00000000 ____D C:\Windows\system32\WinBioDatabase
2017-02-27 17:02 - 2016-07-16 16:47 - 00000000 ____D C:\Windows\LiveKernelReports
2017-02-07 00:48 - 2016-07-16 16:49 - 00835576 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-02-07 00:48 - 2016-07-16 16:49 - 00177656 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

==================== Files in the root of some directories =======

2017-02-28 12:20 - 2017-03-02 12:28 - 0000034 _____ () C:\Users\daz\AppData\Roaming\AdobeWLCMCache.dat
2017-02-27 19:53 - 2017-03-02 17:39 - 0001456 _____ () C:\Users\daz\AppData\Local\Adobe Save for Web 13.0 Prefs

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-02-27 18:58

==================== End of FRST.txt ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-03-2017
Ran by daz (02-03-2017 19:20:53)
Running from C:\Users\daz\Downloads
Windows 10 Pro Version 1607 (X64) (2017-02-27 12:01:44)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3323146596-3808808021-4093420219-500 - Administrator - Disabled)
daz (S-1-5-21-3323146596-3808808021-4093420219-1001 - Administrator - Enabled) => C:\Users\daz
DefaultAccount (S-1-5-21-3323146596-3808808021-4093420219-503 - Limited - Disabled)
defaultuser0 (S-1-5-21-3323146596-3808808021-4093420219-1000 - Limited - Disabled) => C:\Users\defaultuser0
Guest (S-1-5-21-3323146596-3808808021-4093420219-501 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

ВµTorrent (HKLM-x32\...\uTorrent) (Version: 2.2.1 - )
Adobe Acrobat DC (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-0C0F074E4100}) (Version: 15.023.20053 - Adobe Systems Incorporated)
Adobe Bridge CC 2017 (HKLM-x32\...\{21A21021-4348-58E4-B1DF-BDB415F23E7C}) (Version: 7.0 - Adobe Systems Incorporated)
Adobe Illustrator CC 2017 (HKLM-x32\...\{F2321021-08A2-44D6-B1DF-BDB415F23EC7}) (Version: 21.0.2 - Adobe Systems Incorporated)
Adobe Photoshop CC 2017 (HKLM-x32\...\{2D99B50E-431D-4AA8-85C1-172A6F8BCF03}) (Version: 18.0.1 - Adobe Systems Incorporated)
AkelPad 4.9.8-x64 (HKLM\...\AkelPad) (Version: 4.9.8-x64 - )
AMD Settings (HKLM\...\WUCCCApp) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.)
Catalyst Control Center Next Localization BR (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
FastStone Image Viewer 6.2 (HKLM-x32\...\FastStone Image Viewer) (Version: 6.2 - FastStone Soft)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Google Inc.)
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
Herramientas de correcciГіn de Microsoft Office 2016: espaГ±ol (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Malwarebytes version 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes)
Microsoft Office Standard 2016 (HKLM\...\Office16.STANDARD) (Version: 16.0.4266.1001 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3323146596-3808808021-4093420219-1001\...\OneDriveSetup.exe) (Version: 17.3.6798.0207 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24516 (HKLM-x32\...\{b8e12890-118d-4721-8e54-05d978086712}) (Version: 14.0.24516.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24516 (HKLM-x32\...\{c325004c-5538-45b3-a7ad-94473a4dcd3b}) (Version: 14.0.24516.0 - Microsoft Corporation)
Native Instruments Astral Flutter (HKLM-x32\...\Native Instruments Astral Flutter) (Version: 1.0.0.1 - Native Instruments)
Native Instruments Caribbean Current (HKLM-x32\...\Native Instruments Caribbean Current) (Version: 1.1.0.1 - Native Instruments)
Native Instruments Circuit Halo (HKLM-x32\...\Native Instruments Circuit Halo) (Version: 1.1.0.1 - Native Instruments)
Native Instruments Controller Editor (HKLM-x32\...\Native Instruments Controller Editor) (Version: 2.0.2.150 - Native Instruments)
Native Instruments Drum Lab (HKLM-x32\...\Native Instruments Drum Lab) (Version: 1.2.0.6 - Native Instruments)
Native Instruments Electric Vice (HKLM-x32\...\Native Instruments Electric Vice) (Version: 1.2.0.2 - Native Instruments)
Native Instruments Golden Kingdom (HKLM-x32\...\Native Instruments Golden Kingdom) (Version: 1.0.0.8 - Native Instruments)
Native Instruments Helios Ray (HKLM-x32\...\Native Instruments Helios Ray) (Version: 1.2.1.1 - Native Instruments)
Native Instruments Komplete Kontrol (HKLM-x32\...\Native Instruments Komplete Kontrol) (Version: 1.8.0.5 - Native Instruments)
Native Instruments Komplete Kontrol Driver (HKLM-x32\...\Native Instruments Komplete Kontrol Driver) (Version:  - Native Instruments)
Native Instruments Kontakt 5 (HKLM-x32\...\Native Instruments Kontakt 5) (Version: 5.6.6.16 - Native Instruments)
Native Instruments Kontakt Factory Selection (HKLM-x32\...\Native Instruments Kontakt Factory Selection) (Version: 1.4.1.1 - Native Instruments)
Native Instruments Lazer Dice (HKLM-x32\...\Native Instruments Lazer Dice) (Version: 1.2.0.1 - Native Instruments)
Native Instruments Magnate Hustle (HKLM-x32\...\Native Instruments Magnate Hustle) (Version: 1.1.0.1 - Native Instruments)
Native Instruments Maschine (HKLM-x32\...\Native Instruments Maschine) (Version:  - Native Instruments)
Native Instruments Maschine 2 (HKLM-x32\...\Native Instruments Maschine 2) (Version: 2.6.1.79 - Native Instruments)
Native Instruments Maschine 2 Factory Library (HKLM-x32\...\Native Instruments Maschine 2 Factory Library) (Version: 1.3.0.16 - Native Instruments)
Native Instruments Maschine Controller Driver (HKLM-x32\...\Native Instruments Maschine Controller Driver) (Version:  - Native Instruments)
Native Instruments Maschine Controller MK2 Driver (HKLM-x32\...\Native Instruments Maschine Controller MK2 Driver) (Version:  - Native Instruments)
Native Instruments Maschine Jam Driver (HKLM-x32\...\Native Instruments Maschine Jam Driver) (Version:  - Native Instruments)
Native Instruments Maschine Mikro Driver (HKLM-x32\...\Native Instruments Maschine Mikro Driver) (Version:  - Native Instruments)
Native Instruments Maschine Mikro MK2 Driver (HKLM-x32\...\Native Instruments Maschine Mikro MK2 Driver) (Version:  - Native Instruments)
Native Instruments Maschine Studio Driver (HKLM-x32\...\Native Instruments Maschine Studio Driver) (Version:  - Native Instruments)
Native Instruments Massive (HKLM-x32\...\Native Instruments Massive) (Version: 1.5.1.637 - Native Instruments)
Native Instruments Monark (HKLM-x32\...\Native Instruments Monark) (Version: 1.3.0.3 - Native Instruments)
Native Instruments Native Access (HKLM-x32\...\Native Instruments Native Access) (Version: 1.0.25.37 - Native Instruments)
Native Instruments Paradise Rinse (HKLM-x32\...\Native Instruments Paradise Rinse) (Version: 1.1.0.1 - Native Instruments)
Native Instruments Prospect Haze (HKLM-x32\...\Native Instruments Prospect Haze) (Version: 1.0.0.1 - Native Instruments)
Native Instruments Pulswerk (HKLM-x32\...\Native Instruments Pulswerk) (Version: 1.2.0.2 - Native Instruments)
Native Instruments Queensbridge Story (HKLM-x32\...\Native Instruments Queensbridge Story) (Version: 1.0.0.8 - Native Instruments)
Native Instruments Reaktor 5 (HKLM-x32\...\Native Instruments Reaktor 5) (Version: 5.9.4.1512 - Native Instruments)
Native Instruments Reaktor 6 (HKLM-x32\...\Native Instruments Reaktor 6) (Version: 6.1.1.35 - Native Instruments)
Native Instruments Reaktor Blocks Wired (HKLM-x32\...\Native Instruments Reaktor Blocks Wired) (Version: 1.0.0.3 - Native Instruments)
Native Instruments Reaktor Factory Selection R2 (HKLM-x32\...\Native Instruments Reaktor Factory Selection R2) (Version: 1.0.0.1 - Native Instruments)
Native Instruments Reaktor Prism (HKLM-x32\...\Native Instruments Reaktor Prism) (Version: 1.6.0.2 - Native Instruments)
Native Instruments Replika (HKLM-x32\...\Native Instruments Replika) (Version: 1.3.2.50 - Native Instruments)
Native Instruments Retro Machines Mk2 (HKLM-x32\...\Native Instruments Retro Machines Mk2) (Version: 1.3.0.4 - Native Instruments)
Native Instruments Scarbee Mark I (HKLM-x32\...\Native Instruments Scarbee Mark I) (Version: 1.4.0.15 - Native Instruments)
Native Instruments Service Center (HKLM-x32\...\Native Instruments Service Center) (Version: 2.6.0.137 - Native Instruments)
Native Instruments Solid Bus Comp FX (HKLM-x32\...\Native Instruments Solid Bus Comp FX) (Version: 1.3.1.45 - Native Instruments)
Native Instruments Static Friction (HKLM-x32\...\Native Instruments Static Friction) (Version: 1.2.0.1 - Native Instruments)
Native Instruments The Gentleman (HKLM-x32\...\Native Instruments The Gentleman) (Version: 1.2.0.3 - Native Instruments)
Native Instruments Vintage Organs (HKLM-x32\...\Native Instruments Vintage Organs) (Version: 1.4.0.6 - Native Instruments)
Native Instruments West Africa (HKLM-x32\...\Native Instruments West Africa) (Version: 1.3.0.3 - Native Instruments)
nexusfont 2.6 (ver 2.6.2.1870) (HKLM-x32\...\{EFEDD205-43FE-4208-B682-0937E803E19E}_is1) (Version:  - xiles)
Outils de vérification linguistique 2016 de Microsoft Office - Français (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Skypeв„ў 7.32 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.32.104 - Skype Technologies S.A.)
Slack (HKU\S-1-5-21-3323146596-3808808021-4093420219-1001\...\slack) (Version: 2.5.1 - Slack Technologies)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 9.0a - Ghisler Software GmbH)
TRI-CAPTURE Driver (HKLM\...\RolandRDID0119) (Version:  - Roland Corporation)
Яндекс.Диск (HKU\S-1-5-21-3323146596-3808808021-4093420219-1001\...\YandexDisk) (Version: 1.4.14.5242 - Яндекс)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3323146596-3808808021-4093420219-1001_Classes\CLSID\{19170A69-A883-40D5-AF97-F6DC41495F15}\InprocServer32 -> C:\Users\daz\AppData\Roaming\Yandex\YandexDisk\YandexDiskShellExt-4724.dll (Яндекс)
CustomCLSID: HKU\S-1-5-21-3323146596-3808808021-4093420219-1001_Classes\CLSID\{2D6BD2F0-5F84-4a06-924F-AEE0598B6272}\InprocServer32 -> C:\Users\daz\AppData\Roaming\Yandex\YandexDisk\YandexDiskShellExt-4724.dll (Яндекс)
CustomCLSID: HKU\S-1-5-21-3323146596-3808808021-4093420219-1001_Classes\CLSID\{33A431BB-FF15-4047-8FEC-F82FD3523A00}\localserver32 -> C:\Users\daz\AppData\Roaming\Yandex\YandexDisk\YandexDisk.exe (Яндекс)
CustomCLSID: HKU\S-1-5-21-3323146596-3808808021-4093420219-1001_Classes\CLSID\{63D48440-63AB-44D0-B323-4731DFCDE9E9}\InprocServer32 -> C:\Users\daz\AppData\Roaming\Yandex\YandexDisk\YandexDiskOverlays-2398.dll (Яндекс)
CustomCLSID: HKU\S-1-5-21-3323146596-3808808021-4093420219-1001_Classes\CLSID\{7E7DC279-E6BE-4D57-9DEC-14FA0339DBC0}\InprocServer32 -> C:\Users\daz\AppData\Roaming\Yandex\YandexDisk\YandexDiskOverlays-2398.dll (Яндекс)
CustomCLSID: HKU\S-1-5-21-3323146596-3808808021-4093420219-1001_Classes\CLSID\{97836AB9-12C5-4C30-A128-B75196DD1787}\InprocServer32 -> C:\Users\daz\AppData\Roaming\Yandex\YandexDisk\YandexDiskShellExt-4724.dll (Яндекс)
CustomCLSID: HKU\S-1-5-21-3323146596-3808808021-4093420219-1001_Classes\CLSID\{AF8D197E-7022-4c3d-BD88-68AD35C9C169}\InprocServer32 -> C:\Users\daz\AppData\Roaming\Yandex\YandexDisk\YandexDiskOverlays-2398.dll (Яндекс)
CustomCLSID: HKU\S-1-5-21-3323146596-3808808021-4093420219-1001_Classes\CLSID\{E36606FE-036A-4dd0-ABA9-A58F409803F0}\InprocServer32 -> C:\Users\daz\AppData\Roaming\Yandex\YandexDisk\YandexDiskShellExt-4724.dll (Яндекс)
CustomCLSID: HKU\S-1-5-21-3323146596-3808808021-4093420219-1001_Classes\CLSID\{FB2FE984-05F5-4512-9D9B-69D3DE61F6D9}\InprocServer32 -> C:\Users\daz\AppData\Roaming\Yandex\YandexDisk\YandexDiskOverlays-2398.dll (Яндекс)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0FEB2FDB-FC7C-4CCA-9F92-73F9984B8C95} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {292BE385-C842-4007-B6D2-A5AD2BCF6DDD} - System32\Tasks\KMSAutoNet => C:\ProgramData\KMSAutoS\KMSAuto Net.exe [2015-08-04] (MSFree Inc.)
Task: {510D7A09-0CE7-4984-8B87-8DC39C775807} - System32\Tasks\AdobeAAMUpdater-1.0-DESKTOP-ICP4TLM-daz => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-02-27] (Adobe Systems Incorporated)
Task: {A2FBB063-E80B-448C-971A-026039F1AF07} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2015-07-31] (Microsoft Corporation)
Task: {AEF9F64D-77D3-42CC-9F42-A7F2BD1EF53A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-03-02] (Google Inc.)
Task: {CF1FEF0F-3FAA-494B-8F92-E5ADD4A62441} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-03-02] (Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\daz\Links\Яндекс.Диск.lnk -> C:\Users\daz\AppData\Roaming\Yandex\YandexDisk\YandexDisk.exe (Яндекс) <===== Cyrillic
Shortcut: C:\Users\daz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Яндекс.Диск\Скриншоты в Яндекс.Диске.lnk -> C:\Users\daz\AppData\Roaming\Yandex\YandexDisk\YandexDiskScreenshotEditor.exe (Яндекс) <===== Cyrillic

ShortcutWithArgument: C:\Users\daz\Desktop\Яндекс.Диск.lnk -> C:\Users\daz\AppData\Roaming\Yandex\YandexDisk\YandexDiskStarter.exe (Яндекс) -> -desktop <===== Cyrillic
ShortcutWithArgument: C:\Users\daz\AppData\Roaming\Microsoft\Word\Описание%20UI%20Kits-переводчику-часть2-перевод305774550620423236\Описание%20UI%20Kits-переводчику-часть2-перевод.docx.lnk -> C:\Users\daz\Documents\Описание UI Kits-переводчику-часть2-перевод.docx () -> 0 <===== Cyrillic
ShortcutWithArgument: C:\Users\daz\AppData\Roaming\Microsoft\Word\Описание%20UI%20Kits-переводчику-часть1-перевод305774570158418806\Описание%20UI%20Kits-переводчику-часть1-перевод.docx.lnk -> C:\Users\daz\Documents\Описание UI Kits-переводчику-часть1-перевод.docx () -> 14 <===== Cyrillic
ShortcutWithArgument: C:\Users\daz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Яндекс.Диск\Яндекс.Диск.lnk -> C:\Users\daz\AppData\Roaming\Yandex\YandexDisk\YandexDiskStarter.exe (Яндекс) -> -desktop <===== Cyrillic

==================== Loaded Modules (Whitelisted) ==============

2016-07-16 16:42 - 2016-07-16 16:42 - 00231424 _____ () C:\Windows\SYSTEM32\ism32k.dll
2017-02-28 18:17 - 2016-12-09 15:29 - 02681200 _____ () C:\Windows\system32\CoreUIComponents.dll
2017-02-27 17:20 - 2017-01-20 07:47 - 02264352 _____ () C:\PROGRAM FILES\MB\PoliciesControllerImpl.dll
2017-02-27 17:20 - 2017-01-20 07:47 - 02829776 _____ () C:\PROGRAM FILES\MB\arwlib.dll
2017-02-27 17:20 - 2017-01-20 07:47 - 02254800 _____ () C:\PROGRAM FILES\MB\MwacLib.dll
2017-02-28 18:17 - 2016-12-09 15:29 - 02681200 _____ () C:\Windows\SYSTEM32\CoreUIComponents.dll
2016-11-20 23:11 - 2016-11-20 23:11 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-02-28 18:17 - 2016-12-21 12:09 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2017-02-28 18:16 - 2016-12-21 11:54 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-02-28 18:16 - 2016-12-21 11:48 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-02-28 18:16 - 2016-12-21 11:48 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-02-28 18:16 - 2016-12-21 11:48 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-02-28 18:16 - 2016-12-21 11:53 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2017-02-27 17:45 - 2017-02-27 17:47 - 00073728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2017-02-27 17:45 - 2017-02-27 17:47 - 00179712 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2017-02-27 17:45 - 2017-02-27 17:47 - 42895360 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2017-02-27 17:45 - 2017-02-27 17:47 - 02215424 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\roottools.dll
2017-02-27 17:45 - 2017-02-27 17:47 - 00132608 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeHost.Proxies.dll
2016-06-30 19:12 - 2016-06-30 19:12 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll
2016-06-30 19:12 - 2016-06-30 19:12 - 00739840 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll
2016-06-30 19:12 - 2016-06-30 19:12 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll
2016-06-30 19:12 - 2016-06-30 19:12 - 00071168 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll
2016-06-30 19:12 - 2016-06-30 19:12 - 00011776 _____ () C:\Program Files\AMD\CNext\CNext\libEGL.dll
2016-06-30 19:12 - 2016-06-30 19:12 - 02013696 _____ () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
2017-02-28 12:51 - 2017-01-26 15:03 - 00302944 _____ () C:\Users\daz\AppData\Roaming\Yandex\YandexDisk\libpng14-14-x64.dll
2017-02-28 12:51 - 2017-01-26 15:03 - 00187744 _____ () C:\Users\daz\AppData\Roaming\Yandex\YandexDisk\zlib1-x64.dll
2017-02-27 17:16 - 2017-02-27 17:16 - 02266592 _____ () C:\Users\daz\AppData\Local\slack\app-2.5.1\ffmpeg.dll
2017-02-27 17:16 - 2017-02-27 17:16 - 00218592 _____ () \\?\C:\Users\daz\AppData\Local\slack\app-2.5.1\resources\app.asar.unpacked\node_modules\nslog\build\Release\nslog.node
2017-02-27 17:16 - 2017-02-27 17:16 - 00094688 _____ () \\?\C:\Users\daz\AppData\Local\slack\app-2.5.1\resources\app.asar.unpacked\node_modules\@paulcbetts\gc\build\Release\gc.node
2017-02-27 17:16 - 2017-02-27 17:16 - 00095712 _____ () \\?\C:\Users\daz\AppData\Local\slack\app-2.5.1\resources\app.asar.unpacked\node_modules\@paulcbetts\system-idle-time\build\Release\system_idle_time.node
2017-02-27 17:16 - 2017-02-27 17:16 - 02924000 _____ () C:\Users\daz\AppData\Local\slack\app-2.5.1\libglesv2.dll
2017-02-27 17:16 - 2017-02-27 17:16 - 00101856 _____ () C:\Users\daz\AppData\Local\slack\app-2.5.1\libegl.dll
2017-02-27 17:16 - 2017-02-27 17:16 - 00489440 _____ () \\?\C:\Users\daz\AppData\Local\slack\app-2.5.1\resources\app.asar.unpacked\node_modules\@paulcbetts\spellchecker\build\Release\spellchecker.node
2017-02-27 17:16 - 2017-02-27 17:16 - 00163296 _____ () \\?\C:\Users\daz\AppData\Local\slack\app-2.5.1\resources\app.asar.unpacked\node_modules\keyboard-layout\build\Release\keyboard-layout-manager.node
2017-02-27 17:16 - 2017-02-27 17:16 - 00165344 _____ () \\?\C:\Users\daz\AppData\Local\slack\app-2.5.1\resources\app.asar.unpacked\node_modules\ref\build\Release\binding.node
2017-02-27 17:16 - 2017-02-27 17:16 - 00174560 _____ () \\?\C:\Users\daz\AppData\Local\slack\app-2.5.1\resources\app.asar.unpacked\node_modules\ffi\build\Release\ffi_bindings.node
2017-02-27 17:16 - 2017-02-27 17:16 - 00765408 _____ () \\?\C:\Users\daz\AppData\Local\slack\app-2.5.1\resources\app.asar.unpacked\node_modules\@nodert-win10\windows.data.xml.dom\build\Release\binding.node
2017-02-27 17:16 - 2017-02-27 17:16 - 00404960 _____ () \\?\C:\Users\daz\AppData\Local\slack\app-2.5.1\resources\app.asar.unpacked\node_modules\@nodert-win10\windows.ui.notifications\build\Release\binding.node
2017-02-27 17:16 - 2017-02-27 17:16 - 00093152 _____ () \\?\C:\Users\daz\AppData\Local\slack\app-2.5.1\resources\app.asar.unpacked\node_modules\windows-quiet-hours\build\Release\quiethours.node
2017-02-27 17:16 - 2017-02-27 17:16 - 00417760 _____ () \\?\C:\Users\daz\AppData\Local\slack\app-2.5.1\resources\app.asar.unpacked\node_modules\@paulcbetts\slack-calls\build\Release\slack-calls.node
2017-02-27 17:16 - 2017-02-27 17:16 - 07323104 _____ () \\?\C:\Users\daz\AppData\Local\slack\app-2.5.1\resources\app.asar.unpacked\node_modules\@paulcbetts\slack-calls\build\Release\CallsCore.dll
2017-02-27 17:16 - 2017-02-27 17:16 - 01488352 _____ () \\?\C:\Users\daz\AppData\Local\slack\app-2.5.1\resources\app.asar.unpacked\node_modules\@paulcbetts\slack-calls\build\Release\boringssl.dll
2017-02-27 17:16 - 2017-02-27 17:16 - 00230880 _____ () \\?\C:\Users\daz\AppData\Local\slack\app-2.5.1\resources\app.asar.unpacked\node_modules\@paulcbetts\slack-calls\build\Release\protobuf_lite.dll
2017-02-27 17:45 - 2017-02-27 17:47 - 00181248 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\Microsoft.Skype.ImageTool.dll
2017-02-27 17:45 - 2017-02-27 17:47 - 00040960 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\TraceProvider.dll
2017-02-27 17:45 - 2017-02-27 17:47 - 00797696 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\VideoN.dll
2017-03-02 18:44 - 2017-02-01 14:47 - 02459992 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libglesv2.dll
2017-03-02 18:44 - 2017-02-01 14:47 - 00099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2016-07-16 16:47 - 2017-02-27 18:35 - 00001030 ____A C:\Windows\system32\Drivers\etc\hosts

127.0.0.1 na1r.services.adobe.com 
127.0.0.1 hlrcv.stage.adobe.com 
127.0.0.1 lmlicenses.wip4.adobe.com 
127.0.0.1 lm.licenses.adobe.com 
127.0.0.1 activate.adobe.com 
127.0.0.1 practivate.adobe.com 

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3323146596-3808808021-4093420219-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\windows\img0.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

HKU\S-1-5-21-3323146596-3808808021-4093420219-1001\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_6E0814A85AB7B03A51F496B6E0592550"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{A134D5DF-4487-47B3-8EE4-00FF4819DB39}] => (Allow) d:\Program Files (x86)\uTorrent\uTorrent.exe
FirewallRules: [{C4BF12E6-03BD-4910-8993-A26C892AB77D}] => (Allow) d:\Program Files (x86)\uTorrent\uTorrent.exe
FirewallRules: [{9F17D36C-95DB-4041-8B11-60A5AAFFA085}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{4312C720-2D5A-4D22-BAB3-A68EF8A034FD}C:\users\daz\appdata\local\slack\app-2.5.1\slack.exe] => (Allow) C:\users\daz\appdata\local\slack\app-2.5.1\slack.exe
FirewallRules: [UDP Query User{9EDE7C76-859E-43CB-A784-8495FC3BC145}C:\users\daz\appdata\local\slack\app-2.5.1\slack.exe] => (Allow) C:\users\daz\appdata\local\slack\app-2.5.1\slack.exe
FirewallRules: [{3A9F87AF-63C1-45D9-A1B4-0304982DFE4B}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================

27-02-2017 17:07:32 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
28-02-2017 16:53:21 28022017 - work fine
01-03-2017 18:14:34 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
02-03-2017 18:53:22 Restore Operation

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (03/02/2017 07:11:50 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.

Error: (03/02/2017 07:05:29 PM) (Source: System Restore) (EventID: 8210) (User: )
Description: An unspecified error occurred during System Restore: (28022017 - work fine). Additional information: 0x80070091.

Error: (03/02/2017 06:58:32 PM) (Source: System Restore) (EventID: 8210) (User: )
Description: An unspecified error occurred during System Restore: (Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005). Additional information: 0x80070091.

Error: (03/02/2017 06:53:24 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:
Access is denied.
.

Error: (03/02/2017 10:47:25 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: mbamservice.exe, version: 3.1.0.415, time stamp: 0x5881b7a1
Faulting module name: ntdll.dll, version: 10.0.14393.479, time stamp: 0x5825887f
Exception code: 0xc0000374
Fault offset: 0x00000000000f8283
Faulting process id: 0x8fc
Faulting application start time: 0x01d291ca82c8cf96
Faulting application path: C:\Program Files\MB\mbamservice.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: 7c5f6e1e-f0e0-44a7-a1b8-899daa305cfd
Faulting package full name: 
Faulting package-relative application ID:

Error: (03/01/2017 07:59:21 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Native Access.exe version 1.0.25.37 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: b44

Start Time: 01d2929437491863

Termination Time: 4294967295

Application Path: C:\Program Files\Native Instruments\Native Access\Native Access.exe

Report Id: a5cfacc6-fe8f-11e6-b428-bcaec5e1eda3

Faulting package full name: 

Faulting package-relative application ID:

Error: (03/01/2017 06:15:19 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW.  hr = 0x80070006, The handle is invalid.
.


Operation:
   Executing Asynchronous Operation

Context:
   Current State: DoSnapshotSet

Error: (03/01/2017 06:14:59 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:
Access is denied.
.

Error: (03/01/2017 06:14:37 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:
Access is denied.
.

Error: (02/28/2017 04:53:24 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:
Access is denied.
.


System errors:
=============
Error: (03/02/2017 07:05:27 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (03/02/2017 07:01:24 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the MBAMService service.

Error: (03/02/2017 07:00:52 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (03/02/2017 06:58:30 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (03/02/2017 06:54:24 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the MBAMService service.

Error: (03/02/2017 06:54:23 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-ICP4TLM)
Description: The server {9BA05972-F6A8-11CF-A442-00A0C90A8F39} did not register with DCOM within the required timeout.

Error: (03/02/2017 06:53:41 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (03/02/2017 06:32:54 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (03/02/2017 06:26:00 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (03/02/2017 12:36:17 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.


CodeIntegrity:
===================================
  Date: 2017-02-27 17:20:55.253
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\MB\mbae64.dll that did not meet the Store signing level requirements.

  Date: 2017-02-27 17:20:55.253
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\MB\mbae64.dll that did not meet the Store signing level requirements.

  Date: 2017-02-27 17:20:55.252
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\MB\mbae64.dll that did not meet the Store signing level requirements.

  Date: 2017-02-27 17:20:55.248
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\MB\mbae64.dll that did not meet the Store signing level requirements.


==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i5-2500 CPU @ 3.30GHz
Percentage of memory in use: 44%
Total physical RAM: 8173.22 MB
Available physical RAM: 4511.96 MB
Total Virtual: 10093.22 MB
Available Virtual: 6033.32 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:237.92 GB) (Free:151.46 GB) NTFS
Drive d: (HGST) (Fixed) (Total:2794.39 GB) (Free:1373.97 GB) NTFS
Drive e: (ESD-USB) (Removable) (Total:7.04 GB) (Free:2.61 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: 8E73DA59)

Partition: GPT.

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 2794.5 GB) (Disk ID: 00000000)

Partition: GPT.

========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 7.1 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt ============================

 

Share this post


Link to post
Share on other sites

This was a false positive and has been corrected. Please check you've got the latest database updates.

If you have the latest updates and still experience this, please restart your machine.

Share this post


Link to post
Share on other sites

Whatever this is it is either the worst virus infection I have ever acquired or Malwarebytes has a lot of repair work to do. I have run updates that were supposed to fix the issue according to the moderator and have restarted to no avail. I am getting alerts from virtually every program that has a need to access the internet. I'm leaving Malwarebytes alone for now in case there really is something wrong but please advise if this is a real problem of just a software issue.

 

Dave D 

Share this post


Link to post
Share on other sites

You may be right!

Things seem to have calmed down although I'll reserve judgement until I know all my programs that need to update can update. I have the new 1.0.1404 update now in use as it seems to have updated in the last hour or so.

Dave D.

Share this post


Link to post
Share on other sites

Hi all

This false positive will now be fixed with the most recent database update > 1.0.1404

Again our sincerest apologies on this guys.

* As this issue is confirmed to be resolved i will lock the thread now.

Share this post


Link to post
Share on other sites
Guest
This topic is now closed to further replies.

  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.