Jump to content

Unremovable malware?


Recommended Posts

I have the problem described here, but the solution also described here yields the exact same results - "resource is in use".

I ran malwarebytes awhile back when I first realized something was up.. it came back with nothing?  I knew SOMETHING was up though so I ran Windows Defender and a few other programs.. I don't remember which one finally picked up a few PUPs, but I removed those then quickly realized I still had the same odd processes running and that CCleaner wouldn't run anymore - _- Since then I have tried that mbar rootkit removal thing, rkill, Zemana, Hitman pro, adwcleaner, and avast and I don't even know what all else at this point.  All give the same message.  I can't disable these processes either and when I end them in task manager, of course they just pop right back up.  Any ideas what on earth might be able to remove this?  System restore/reinstalling windows are not options unfortunately :(

 

Edit** oops, to clarify malwarebytes and everything else give me the error message when I try to open now.

Edited by magepalm
Link to post
Share on other sites

It wont let me edit again... since I posted I have tried Trend Micro, tdsskiller, JRT, combofix, all give the same thing... running reason core now pretty much just going down the list and that was the first one to work, but it's already past scanning through the processes and start up processes and didn't catch anything at all so I don't have much faith in it :(

Link to post
Share on other sites

Hi magepalm :)

My name is Aura and I'll be assisting you with your malware issue. Since we'll be working together, you can call me Aura or Yoan, which is my real name, it's up to you! Now that we've broke the ice, I'll just ask you a few things during the time we'll be working together to clean your system and get it back to an operational state.

  • As you'll notice, the logs we are asking for here are quite lenghty, so it's normal for me to not reply exactly after you post them. This is because I need some time to analyse them and then act accordingly. However, I'll always reply within 24 hours, 48 hours at most if something unexpected happens;
  • As long as I'm assisting you on Malwarebytes Forums, in this thread, I'll ask you to not seek assistance anywhere else for any issue related to the system we are working on. If you have an issue, question, etc. about your computer, please ask it in this thread and I'll assist you;
  • The same principle applies to any modifications you make to your system, I would like you to ask me before you do any manipulations that aren't in the instructions I posted. This is to ensure that we are operating in sync and I know exactly what's happening on your system;
  • If you aren't sure about an instruction I'm giving you, ask me about it. This is to ensure that the clean-up process goes without any issue. I'll answer you and even give you more precise instructions/explanations if you need. There's no shame in asking questions here, better be safe than sorry!;
  • If you don't reply to your thread within 3 days, I'll bump this thread to let you know that I'm waiting for you. If you don't reply after 5 days, it'll be closed. If you return after that period, you can send me a PM to get it unlocked and we'll continue where we left off;
  • Since malware can work quickly, we want to get rid of them as fast as we can, before they make unknown changes to the system. This being said, I would appreciate if you could reply to this thread within 24 hours of me posting. This way, we'll have a good clean-up rhythm and the chances of complications will be reduced;
  • I'm against any form of pirated, illegal and counterfeit software and material. So if you have any installed on your system, I'll ask you to uninstall them right now. You don't have to tell me if you indeed had some or not, I'll give you the benefit of the doubt. Plus, this would be against Malwarebytes Forums's rules;
  • In the end, you are the one asking for assistance here. So if you wish to go a different way during the clean-up, like format and reinstall Windows, you are free to do so. I would appreciate you to let me know about it first, and if you need, I can also assist you in the process;
  • I would appreciate if you were to stay with me until the end, which means, until I declare your system clean. Just because your system isn't behaving weirdly anymore, or is running better than before, it doesn't mean that the infection is completely gone;
    This being said, I have a full time job so sometimes it'll take longer for me to reply to you. Don't worry, you'll be my first priority as soon as I get home and have time to look at your thread;


This being said, it's time to clean-up some malware, so let's get started, shall we? :)

If you launch the mbar.cmd file inside the MBAR folder, does MBAR open properly?

Link to post
Share on other sites

OOOHHH I looked right over it and was trying to use the executable files in that folder!   Well, I just tried it and after I selected yes it said access is denied.  It would be funny if it wasn't so frustrating lol.  Thank you so much for responding :D

Edited by magepalm
Link to post
Share on other sites

OMG it's worse than I realized apparently TrustedInstaller is on here too!!! ACK!!!!  Showing 6 svcvmx running in my task manager too.  After a full scan Reason Core picked up the Yelloadar adware that apparently is the big problem with the antiviruses not working... because it removed 5 other small adware things and that one wont go away, it just keeps telling me to restart in safe mode to remove it completely and everytime I do it tells me to remove it and the exact same thing again.  Really at a loss, unless ya think of something I'm gonna just keep going down the list til something either gets it to the point I can get somewhere or I run out of anti viruses to attempt LOL :S

Link to post
Share on other sites

The 960MB one should be fine then. Follow the instructions below.

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Fix mode
Follow the instructions below to execute a fix on your system using FRST, and provide the log in your next reply.

  • Download the right version of FRST for your system:
    • FRST 32-bit
    • FRST 64-bit
      Note: Only the right version will run on your system, the other will throw an error message. So if you don't know what your system's version is, simply download both of them, and the one that works is the one you should be using.
  • Download the attached fixlist.txt file, and save it on your Desktop (or wherever your FRST.exe/FRST64.exe executable is located);
  • Right-click on the FRST executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
  • Click on the Fix button;
    NYA5Cbr.png
  • On completion, a message will come up saying that the fix has been completed and it'll open a log in Notepad;
  • Copy and paste its content in your next reply;

 

fixlist.txt

Link to post
Share on other sites

Fix result of Farbar Recovery Scan Tool (x64) Version: 26-07-2017
Ran by dad (26-07-2017 18:08:52) Run:1
Running from C:\Users\dad\Desktop
Loaded Profiles: dad (Available Profiles: dad)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CMD: bcdedit.exe /set {bootmgr} displaybootmenu yes
CMD: bcdedit.exe /set {default} recoveryenabled yes
*****************


========= bcdedit.exe /set {bootmgr} displaybootmenu yes =========

The operation completed successfully.

========= End of CMD: =========


========= bcdedit.exe /set {default} recoveryenabled yes =========

The operation completed successfully.

========= End of CMD: =========


==== End of Fixlog 18:08:53 ====

Link to post
Share on other sites

Good. Now move the FRST executable on your USB Flash Drive, restart your computer and access the Recovery PE.

https://www.tenforums.com/tutorials/2294-boot-advanced-startup-options-windows-10-a.html

You need to get to the Advanced Options and click on Command Prompt.

Once in the Command Prompt:

  • In the command window type in notepad and press Enter.
  • The notepad opens. Under File menu select Open.
  • Select "Computer" and find your flash drive letter and close the notepad.
  • In the command window type e:\frst (for x64 bit version type e:\frst64) and press Enter
    Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run.
  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

Link to post
Share on other sites

Thank you so much for all the help by the way <3 

Just letting you know I haven't been ignoring this, just insanely busy anddd I kinda figured it would be wise to have someone that's done this before help me in person so I can see how it's done for future reference without chancing majorly screwing something up - I kind of have a terrible record of doing that lol.  I THINK we'll be doing it tomorrow I'm not 100% sure yet.  But I'm definitely staying on top of this.  I can't play most of my video games because of this crap so trust me I'm not going anywhere LOL

 

Link to post
Share on other sites

I've never had a problem anywhere near this bad on a computer only I had access to -_ - After some research, I think the culprit dl was a program called lightshot.... I'll leave out all the four letter words I feel towards my sea fight playing husband right now for infecting the computer with all this crap.  He's lucky he's awesome otherwise I'd divorce him for this, LOL it sucks that much D:

 

Link to post
Share on other sites

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 31-07-2017
Ran by SYSTEM on MININT-93O68CJ (31-07-2017 19:05:12)
Running from D:\
Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11
Boot Mode: Recovery
Default: ControlSet001
ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8790264 2016-01-14] (Realtek Semiconductor)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2017-04-27] (Microsoft Corporation)
HKLM-x32\...\Run: [PowerDVD14Agent] => C:\Program Files (x86)\CyberLink\PowerDVD14\PowerDVD14Agent.exe [795336 2015-06-21] (CyberLink Corp.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation)
HKLM-x32\...\Run: [Arc] => C:\Program Files (x86)\Arc\ArcLauncher.exe [414744 2017-02-22] (Perfect World Entertainment)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [34672 2008-06-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [cpx] => "C:\Users\dad\AppData\Local\ntuserlitelist\cpx\cpx.exe" -starup <==== ATTENTION
HKLM-x32\...\Run: [svcvmx] => C:\Users\dad\AppData\Local\ntuserlitelist\svcvmx\svcvmx.exe [884224 2017-04-21] ()
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
BootExecute: autocheck autochk * Partizan

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 ArcService; C:\Program Files (x86)\Arc\ArcService.exe [87064 2017-02-22] (Perfect World Entertainment Inc)
S4 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2016-11-16] (BitRaider, LLC)
S2 Dataup; C:\Users\dad\AppData\Local\ntuserlitelist\dataup\dataup.exe [77824 2017-01-05] () <==== ATTENTION
S3 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-06-02] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-06-02] (Dropbox, Inc.)
S4 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [387944 2016-05-11] (Digital Wave Ltd.)
S2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [328624 2016-01-22] (Intel Corporation)
S2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [373704 2015-07-15] (McAfee, Inc.)
S2 Razer Game Manager Service; C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe [147792 2017-06-15] (Razer Inc)
S2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [389896 2014-04-14] ()
S2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [316152 2016-01-14] (Realtek Semiconductor)
S2 RzActionSvc; C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe [183680 2017-04-13] (Razer Inc.)
S2 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [252176 2017-06-21] (Razer Inc.)
S4 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [7500048 2016-09-20] (TeamViewer GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-27] (Microsoft Corporation)
S2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103712 2017-04-27] (Microsoft Corporation)
S2 windowsmanagementservice; C:\Users\dad\AppData\Local\qixsn\ypzzsgy\ct.exe [689664 2017-05-30] () <==== ATTENTION
S4 srcsrv; C:\WINDOWS\src_srv\winsrcsrv.exe [X] <==== ATTENTION

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 A6100; C:\Windows\System32\drivers\A6100.sys [5004560 2016-02-17] (Realtek Semiconductor Corporation                           )
S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2016-11-17] (BitRaider)
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
S0 drmkpro64; C:\Windows\System32\drivers\ndistpr64.sys [80160 2013-09-03] () <==== ATTENTION
S1 MpKsl3fcd1700; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{07E353D3-87A2-4508-A3D2-4CB37E2115D9}\MpKsl3fcd1700.sys [44928 2017-07-31] (Microsoft Corporation)
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
S0 Partizan; C:\Windows\SysWOW64\drivers\Partizan.sys [40304 2017-07-26] (Greatis Software)
S3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [896768 2016-02-17] (Realtek                                            )
S3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [402136 2015-05-27] (Realsil Semiconductor Corporation)
S3 RTWlanE; C:\Windows\System32\drivers\rtwlane.sys [6804480 2017-05-03] (Realtek Semiconductor Corporation                           )
S2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [137840 2017-04-13] (Razer, Inc.)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
S3 TXEIx64; C:\Windows\System32\drivers\TXEIx64.sys [97320 2015-06-29] (Intel Corporation)
S1 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [119712 2016-04-18] (Oracle Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-07-29 21:17 - 2017-07-29 21:18 - 001636325 _____ C:\Users\dad\Downloads\CT-MegaT-v2.3.0.6.zip
2017-07-29 09:37 - 2017-07-29 21:18 - 002333184 _____ (Cyber Terminators) C:\Users\dad\Desktop\CT-MegaT-v2.3.0.6.exe
2017-07-28 12:28 - 2017-07-28 12:28 - 000001001 _____ C:\Users\Public\Desktop\Guild Wars 2.lnk
2017-07-28 12:27 - 2017-07-28 12:28 - 000000000 ____D C:\Program Files\Guild Wars 2
2017-07-28 12:25 - 2017-07-28 12:28 - 000000000 ____D C:\Users\dad\AppData\Roaming\Guild Wars 2
2017-07-28 12:25 - 2017-07-28 12:25 - 034201768 _____ (ArenaNet) C:\Users\dad\Desktop\Gw2Setup-64.tmp
2017-07-28 12:25 - 2017-07-28 12:25 - 000000000 ____D C:\Users\dad\Desktop\bin64
2017-07-28 12:25 - 2017-07-28 12:25 - 000000000 _____ C:\Users\dad\Desktop\Gw2.tmp
2017-07-28 12:25 - 2017-07-28 12:25 - 000000000 _____ C:\Users\dad\Desktop\Gw2.dat
2017-07-28 12:24 - 2017-07-28 12:25 - 034201768 _____ (ArenaNet) C:\Users\dad\Desktop\Gw2Setup-64.exe
2017-07-28 12:22 - 2017-07-28 12:24 - 000000000 ____D C:\Users\dad\Desktop\petz files
2017-07-28 12:22 - 2017-07-28 12:22 - 004359432 _____ (IObit ) C:\Users\dad\Desktop\iobit-gb3.4-setup.exe
2017-07-27 13:44 - 2017-04-13 09:52 - 000137840 _____ (Razer, Inc.) C:\Windows\System32\Drivers\rzpnk.sys
2017-07-27 13:43 - 2017-07-27 13:43 - 000001371 _____ C:\Users\dad\Desktop\Razer Cortex.lnk
2017-07-26 15:08 - 2017-07-26 15:08 - 002382848 _____ (Farbar) C:\Users\dad\Desktop\FRST64 (1).exe
2017-07-26 15:08 - 2017-07-26 15:08 - 000000753 _____ C:\Users\dad\Desktop\Fixlog.txt
2017-07-26 15:03 - 2017-07-26 15:06 - 161500736 _____ (Razer Inc. ) C:\Users\dad\Desktop\RazerCortexSetup_8.2.12.485.exe
2017-07-26 12:55 - 2017-07-26 12:55 - 000000000 ____D C:\Users\dad\AppData\Local\llssoft
2017-07-26 12:28 - 2017-07-28 11:37 - 000000000 ____D C:\Windows\Panther
2017-07-26 10:15 - 2017-07-26 12:53 - 000162160 _____ C:\Windows\SysWOW64\PARTIZAN.TXT
2017-07-26 10:15 - 2017-07-26 10:15 - 000000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2017-07-26 10:07 - 2017-07-26 10:07 - 000000000 ____D C:\@RestoreQuarantine
2017-07-26 09:24 - 2017-07-26 11:52 - 000000000 ____D C:\ProgramData\RegRun
2017-07-26 09:19 - 2017-07-26 09:19 - 000040304 _____ (Greatis Software) C:\Windows\SysWOW64\Drivers\Partizan.sys
2017-07-26 09:17 - 2017-07-26 12:13 - 000000000 ____D C:\Users\Public\Documents\regruninfo
2017-07-26 09:17 - 2017-07-26 12:10 - 000000000 ____D C:\Users\dad\Documents\RegRun2
2017-07-26 09:17 - 2017-07-26 09:17 - 000003416 _____ C:\Windows\System32\Tasks\UnHackMe Task Scheduler
2017-07-26 09:17 - 2017-07-26 09:17 - 000001083 _____ C:\Users\dad\Desktop\UnHackMe.lnk
2017-07-26 09:17 - 2017-07-26 09:17 - 000000002 RSHOT C:\Windows\winstart.bat
2017-07-26 09:17 - 2017-07-26 09:17 - 000000002 RSHOT C:\Windows\SysWOW64\CONFIG.NT
2017-07-26 09:17 - 2017-07-26 09:17 - 000000002 RSHOT C:\Windows\SysWOW64\AUTOEXEC.NT
2017-07-26 09:17 - 2017-06-22 12:03 - 000014984 _____ (Greatis Software, LLC.) C:\Windows\SysWOW64\Drivers\UnHackMeDrv.sys
2017-07-26 09:17 - 2015-12-28 08:32 - 000049968 _____ (Greatis Software) C:\Windows\System32\partizan.exe
2017-07-26 09:16 - 2017-07-26 09:17 - 000000000 ____D C:\Program Files (x86)\UnHackMe
2017-07-26 07:17 - 2017-07-26 07:17 - 000000000 ____D C:\ProgramData\Reason
2017-07-26 07:15 - 2017-07-26 07:15 - 000000000 ____D C:\Program Files\Reason
2017-07-26 07:07 - 2017-07-26 15:08 - 000000000 ____D C:\FRST
2017-07-26 07:06 - 2017-07-26 07:07 - 002382336 _____ (Farbar) C:\Users\dad\Desktop\FRST64.exe
2017-07-26 06:55 - 2017-07-26 06:55 - 000000000 ___HD C:\funtimes
2017-07-26 06:18 - 2017-07-26 06:18 - 000000000 ____D C:\mbar
2017-07-26 06:16 - 2017-07-26 06:18 - 016564750 _____ (Malwarebytes Corp.) C:\Users\dad\mbar-1.09.4.1001 (1).exe
2017-07-26 06:13 - 2017-07-26 06:14 - 000000000 ____D C:\Users\dad\Desktop\mbar
2017-07-26 06:13 - 2017-07-26 06:13 - 016564750 _____ (Malwarebytes Corp.) C:\Users\dad\Desktop\mbar-1.09.4.1001.exe
2017-07-26 05:43 - 2017-07-26 05:43 - 008162248 _____ (Malwarebytes) C:\Users\dad\Desktop\AdwCleaner.exe
2017-07-25 13:46 - 2017-07-26 09:14 - 018827264 _____ (Greatis Software, LLC. ) C:\Users\dad\Desktop\unhackme_setup.exe
2017-07-25 10:28 - 2017-07-25 10:28 - 000001171 _____ C:\Users\dad\Desktop\Cheat Engine.lnk
2017-07-25 10:27 - 2017-07-25 10:28 - 000000000 ____D C:\Program Files (x86)\Cheat Engine 6.6
2017-07-24 03:42 - 2017-07-24 16:37 - 000004422 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-07-21 18:55 - 2017-07-21 18:57 - 064025992 _____ (Malwarebytes ) C:\Users\dad\Downloads\mb3-setup-35891.35891-3.1.2.1733-1.0.139-1.0.2060 (1).exe
2017-07-21 18:53 - 2017-07-21 18:55 - 064025992 _____ (Malwarebytes ) C:\Users\dad\Downloads\mb3-setup-35891.35891-3.1.2.1733-1.0.139-1.0.2060.exe
2017-07-21 18:27 - 2017-07-21 18:27 - 000000865 _____ C:\Users\dad\Desktop\Start Tor Browser.lnk
2017-07-21 18:27 - 2017-07-21 18:27 - 000000000 ____D C:\Users\dad\Desktop\Tor Browser
2017-07-21 18:25 - 2017-07-21 18:26 - 054279480 _____ C:\Users\dad\Desktop\torbrowser-install-7.0.2_en-US.exe
2017-07-20 08:26 - 2017-07-20 08:27 - 021019230 _____ C:\Users\dad\Documents\NEWER US ARMY FM-21-76-Survival-2002.pdf
2017-07-20 08:26 - 2017-07-20 08:27 - 004367617 _____ C:\Users\dad\Documents\USMC-Winter-Survival-Course.pdf
2017-07-20 08:26 - 2017-07-20 08:27 - 004326295 _____ C:\Users\dad\Documents\USMC-Summer-Survival-Course.pdf
2017-07-20 08:26 - 2017-07-20 08:26 - 014796153 _____ C:\Users\dad\Documents\Alpine-Living-2008.pdf
2017-07-20 08:26 - 2017-07-20 08:26 - 003138297 _____ C:\Users\dad\Documents\SURVIVAL-EVASION-AND-RECOVERY.pdf
2017-07-20 08:26 - 2017-07-20 08:26 - 001649064 _____ C:\Users\dad\Documents\Marines-Individual-Terrorism-Survival.pdf
2017-07-20 08:26 - 2017-07-20 08:26 - 001088853 _____ C:\Users\dad\Documents\Aid-to-Survival.pdf
2017-07-20 08:26 - 2017-07-20 08:26 - 000698846 _____ C:\Users\dad\Documents\Survival-In-ColdWeather-Areas.pdf
2017-07-20 08:25 - 2017-07-20 08:26 - 006040392 _____ C:\Users\dad\Documents\Combat-Survival-Evasion.pdf
2017-07-20 08:25 - 2017-07-20 08:25 - 005978472 _____ C:\Users\dad\Documents\HHSPandemicInfluenzaPlan.pdf
2017-07-20 08:25 - 2017-07-20 08:25 - 002189764 _____ C:\Users\dad\Documents\How-to-Build-a-Debris-Hut.pdf
2017-07-20 08:25 - 2017-07-20 08:25 - 000271044 _____ C:\Users\dad\Documents\Cold-Weather-Survival-2005.pdf
2017-07-20 08:24 - 2017-07-20 08:24 - 006593781 _____ C:\Users\dad\Documents\Nuclear-War-Survival-Skills.pdf
2017-07-20 08:24 - 2017-07-20 08:24 - 001703003 _____ C:\Users\dad\Documents\Surviving-Terrorism.pdf
2017-07-20 08:24 - 2017-07-20 08:24 - 000134216 _____ C:\Users\dad\Documents\Preserving_Game_Meats.pdf
2017-07-20 08:24 - 2017-07-20 08:24 - 000071710 _____ C:\Users\dad\Documents\Survival-Water-Purification.pdf
2017-07-20 08:22 - 2017-07-20 08:23 - 013468736 _____ C:\Users\dad\Documents\Camp-Life-In-The-Woods-And-The-Tricks-Of-Trapping-And-Trap-Making.pdf
2017-07-20 08:22 - 2017-07-20 08:22 - 005306053 _____ C:\Users\dad\Documents\Woodsman-Ship.pdf
2017-07-20 08:22 - 2017-07-20 08:22 - 002562272 _____ C:\Users\dad\Documents\Urban-Preparation-Kit-Part-I-On.pdf
2017-07-20 08:22 - 2017-07-20 08:22 - 000528172 _____ C:\Users\dad\Documents\Traps.pdf
2017-07-20 08:21 - 2017-07-20 08:22 - 009493480 _____ C:\Users\dad\Documents\Bushcraft-Scouting-Woodlore-Notes.pdf
2017-07-20 08:21 - 2017-07-20 08:21 - 007583956 _____ C:\Users\dad\Documents\The-Book-of-Camplore-and-Woodcraft-Dan-Beard.pdf
2017-07-20 08:21 - 2017-07-20 08:21 - 000487158 _____ C:\Users\dad\Documents\Shelters-Shacks-Shanties-Daniel-Carter-Beard.pdf
2017-07-20 08:18 - 2017-07-20 08:18 - 003368547 _____ C:\Users\dad\Documents\The-Ten-Bushcraft-Books.pdf
2017-07-20 08:17 - 2017-07-20 08:20 - 020431027 _____ C:\Users\dad\Documents\The-Baby-Food.pdf
2017-07-20 08:17 - 2017-07-20 08:19 - 008676383 _____ C:\Users\dad\Documents\Australian Bushcraft PDF.pdf
2017-07-20 08:17 - 2017-07-20 08:19 - 007489678 _____ C:\Users\dad\Documents\bushcraft leather work PDF.pdf
2017-07-20 08:17 - 2017-07-20 08:17 - 002208576 _____ C:\Users\dad\Documents\The-New-Complete-Book-of-Food.pdf
2017-07-20 08:17 - 2017-07-20 08:17 - 000405681 _____ C:\Users\dad\Documents\The-Jerky-Chef.pdf
2017-07-20 08:17 - 2017-07-20 08:17 - 000335055 _____ C:\Users\dad\Documents\USDA-utah-can-guide-05.pdf
2017-07-20 08:17 - 2017-07-20 08:17 - 000271282 _____ C:\Users\dad\Documents\The-Back-Country-Recipe-Book.pdf
2017-07-20 08:17 - 2017-07-20 08:17 - 000208365 _____ C:\Users\dad\Documents\boyscout cookbook PDF.pdf
2017-07-20 08:17 - 2017-07-20 08:17 - 000134622 _____ C:\Users\dad\Documents\dutch oven cookbook PDF.pdf
2017-07-20 08:15 - 2017-07-20 08:19 - 023655221 _____ C:\Users\dad\Documents\Flintknapping PDF book.pdf
2017-07-20 08:15 - 2017-07-20 08:19 - 019487967 _____ C:\Users\dad\Documents\The-Complete-Guide-to-Home-Carpentry.pdf
2017-07-20 08:15 - 2017-07-20 08:18 - 015053370 _____ C:\Users\dad\Documents\The-Making-of-Leather-by-Procter-Makingofleather00procrich.pdf
2017-07-20 08:15 - 2017-07-20 08:18 - 014186918 _____ C:\Users\dad\Documents\Vegetable-Garden-Encyclopedia.pdf
2017-07-20 08:15 - 2017-07-20 08:15 - 000271282 _____ C:\Users\dad\Documents\Backcountry Cookbook PDF.pdf
2017-07-20 08:14 - 2017-07-20 08:15 - 013921741 _____ C:\Users\dad\Documents\Wilderness-Medicine-Course.pdf
2017-07-20 08:14 - 2017-07-20 08:15 - 011462156 _____ C:\Users\dad\Documents\Ditch-Medicine-Advanced-Field-Procedures-For-Emergencies-1993.pdf
2017-07-20 08:14 - 2017-07-20 08:14 - 002455031 _____ C:\Users\dad\Documents\Full-First-Aid-Manual-FM-2111.pdf
2017-07-20 08:14 - 2017-07-20 08:14 - 000314495 _____ C:\Users\dad\Documents\survival-personal-wilderness-medical-kit (1).pdf
2017-07-20 08:13 - 2017-07-20 08:13 - 000314495 _____ C:\Users\dad\Documents\survival-personal-wilderness-medical-kit.pdf
2017-07-20 08:12 - 2017-07-20 08:12 - 000873230 _____ C:\Users\dad\Documents\en_wtnd_2015_info.pdf
2017-07-20 08:12 - 2017-07-20 08:12 - 000521573 _____ C:\Users\dad\Documents\en_wtnd_2015_indx.pdf
2017-07-20 08:12 - 2017-07-20 08:12 - 000503698 _____ C:\Users\dad\Documents\en_wtnd_2015_resc.pdf
2017-07-20 08:12 - 2017-07-20 08:12 - 000498177 _____ C:\Users\dad\Documents\en_wtnd_2015_gloss.pdf
2017-07-20 08:12 - 2017-07-20 08:12 - 000358406 _____ C:\Users\dad\Documents\en_wtnd_2015_gp.pdf
2017-07-20 08:11 - 2017-07-20 08:11 - 001507564 _____ C:\Users\dad\Documents\en_wtnd_2015_21.pdf
2017-07-20 08:11 - 2017-07-20 08:11 - 001098248 _____ C:\Users\dad\Documents\en_wtnd_2015_15.pdf
2017-07-20 08:11 - 2017-07-20 08:11 - 001063545 _____ C:\Users\dad\Documents\en_wtnd_2015_19.pdf
2017-07-20 08:11 - 2017-07-20 08:11 - 000911036 _____ C:\Users\dad\Documents\en_wtnd_2015_12.pdf
2017-07-20 08:11 - 2017-07-20 08:11 - 000908167 _____ C:\Users\dad\Documents\en_wtnd_2015_11.pdf
2017-07-20 08:11 - 2017-07-20 08:11 - 000839658 _____ C:\Users\dad\Documents\en_wtnd_2015_01.pdf
2017-07-20 08:11 - 2017-07-20 08:11 - 000811803 _____ C:\Users\dad\Documents\en_wtnd_2015_20.pdf
2017-07-20 08:11 - 2017-07-20 08:11 - 000759867 _____ C:\Users\dad\Documents\en_wtnd_2015_03.pdf
2017-07-20 08:11 - 2017-07-20 08:11 - 000736926 _____ C:\Users\dad\Documents\en_wtnd_2015_10.pdf
2017-07-20 08:11 - 2017-07-20 08:11 - 000696322 _____ C:\Users\dad\Documents\en_wtnd_2015_fm.pdf
2017-07-20 08:11 - 2017-07-20 08:11 - 000691438 _____ C:\Users\dad\Documents\en_wtnd_2015_08.pdf
2017-07-20 08:11 - 2017-07-20 08:11 - 000669758 _____ C:\Users\dad\Documents\en_wtnd_2015_22.pdf
2017-07-20 08:11 - 2017-07-20 08:11 - 000650856 _____ C:\Users\dad\Documents\en_wtnd_2015_06.pdf
2017-07-20 08:11 - 2017-07-20 08:11 - 000604365 _____ C:\Users\dad\Documents\en_wtnd_2015_07.pdf
2017-07-20 08:11 - 2017-07-20 08:11 - 000602630 _____ C:\Users\dad\Documents\en_wtnd_2015_04.pdf
2017-07-20 08:11 - 2017-07-20 08:11 - 000594744 _____ C:\Users\dad\Documents\en_wtnd_2015_13.pdf
2017-07-20 08:11 - 2017-07-20 08:11 - 000177234 _____ C:\Users\dad\Documents\en_wtnd_2015_23.pdf
2017-07-20 08:10 - 2017-07-20 08:11 - 001148203 _____ C:\Users\dad\Documents\en_wtnd_2015_brp.pdf
2017-07-20 08:09 - 2017-07-20 08:09 - 007649690 _____ C:\Users\dad\Documents\Emergency-War-Surgery.pdf
2017-07-20 08:08 - 2017-07-20 08:08 - 001366604 _____ C:\Users\dad\Documents\Medical-Survival-Wound-Closure-Manual.pdf
2017-07-20 08:08 - 2017-07-20 08:08 - 000705482 _____ C:\Users\dad\Documents\en_wtnd_2015_18.pdf
2017-07-20 08:08 - 2017-07-20 08:08 - 000619095 _____ C:\Users\dad\Documents\en_wtnd_2015_17.pdf
2017-07-20 08:08 - 2017-07-20 08:08 - 000392549 _____ C:\Users\dad\Documents\en_wtnd_2015_16.pdf
2017-07-20 08:07 - 2017-07-20 08:08 - 000352924 _____ C:\Users\dad\Documents\en_wtnd_2015_14.pdf
2017-07-20 08:07 - 2017-07-20 08:07 - 000620867 _____ C:\Users\dad\Documents\en_wtnd_2015_09.pdf
2017-07-20 08:07 - 2017-07-20 08:07 - 000587268 _____ C:\Users\dad\Documents\en_wtnd_2015_05.pdf
2017-07-20 08:07 - 2017-07-20 08:07 - 000271500 _____ C:\Users\dad\Documents\en_wtnd_2015_02.pdf
2017-07-20 08:06 - 2017-07-20 08:06 - 007548494 _____ C:\Users\dad\Documents\Where-There-is-No-Dentist-Murray-Dickson.pdf
2017-07-11 16:02 - 2017-06-30 06:46 - 000835576 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-07-11 16:02 - 2017-06-30 06:46 - 000177656 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-07-11 15:26 - 2017-07-06 23:45 - 002263832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-07-11 15:26 - 2017-07-06 23:29 - 005686272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2017-07-11 15:26 - 2017-07-06 23:20 - 000059904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\l2gpstore.dll
2017-07-11 15:26 - 2017-07-06 23:11 - 000340480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-07-11 15:26 - 2017-07-06 22:54 - 002027008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-07-11 15:26 - 2017-07-06 22:53 - 002483200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-07-11 15:26 - 2017-07-06 22:52 - 001599488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-07-11 15:26 - 2017-06-20 23:22 - 000361104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsmf.dll
2017-07-11 15:26 - 2017-06-20 22:59 - 000255488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\unimdm.tsp
2017-07-11 15:26 - 2017-06-20 22:56 - 000237056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SyncSettings.dll
2017-07-11 15:26 - 2017-06-20 22:51 - 000846336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebcamUi.dll
2017-07-11 15:26 - 2017-06-20 22:51 - 000258048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsDocumentTargetPrint.dll
2017-07-11 15:26 - 2017-06-20 22:41 - 001255936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AzureSettingSyncProvider.dll
2017-07-11 15:26 - 2017-06-20 22:40 - 000090624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\olepro32.dll
2017-07-11 15:26 - 2017-06-20 22:37 - 007468544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2017-07-11 15:26 - 2017-06-20 22:35 - 002682880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netshell.dll
2017-07-11 15:26 - 2017-06-20 22:35 - 000732160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsSpellCheckingFacility.dll
2017-07-11 15:26 - 2017-06-20 22:30 - 000038912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tlscsp.dll
2017-07-11 15:25 - 2017-07-06 23:46 - 000781152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
2017-07-11 15:25 - 2017-07-06 23:09 - 000637952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2017-07-11 15:25 - 2017-07-06 23:06 - 007626752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2017-07-11 15:25 - 2017-07-06 22:54 - 002997248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
2017-07-11 15:25 - 2017-07-06 22:52 - 004561408 _____ (Microsoft) C:\Windows\SysWOW64\dbgeng.dll
2017-07-11 15:25 - 2017-07-06 22:52 - 001413632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OpcServices.dll
2017-07-11 15:25 - 2017-06-20 23:28 - 001504056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2017-07-11 15:25 - 2017-06-20 23:27 - 000975744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.appcore.dll
2017-07-11 15:25 - 2017-06-20 23:21 - 006665440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-07-11 15:25 - 2017-06-20 23:21 - 001557808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll
2017-07-11 15:25 - 2017-06-20 23:00 - 000156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDeviceRegistration.dll
2017-07-11 15:25 - 2017-06-20 22:59 - 000285184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.BlockedShutdown.dll
2017-07-11 15:25 - 2017-06-20 22:59 - 000177664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Web.Diagnostics.dll
2017-07-11 15:25 - 2017-06-20 22:58 - 000136192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinRtTracing.dll
2017-07-11 15:25 - 2017-06-20 22:58 - 000094208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepositoryClient.dll
2017-07-11 15:25 - 2017-06-20 22:58 - 000059904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.System.UserDeviceAssociation.dll
2017-07-11 15:25 - 2017-06-20 22:57 - 000088576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDeviceRegistration.Ngc.dll
2017-07-11 15:25 - 2017-06-20 22:56 - 000392192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Gaming.Input.dll
2017-07-11 15:25 - 2017-06-20 22:56 - 000315904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Gaming.XboxLive.Storage.dll
2017-07-11 15:25 - 2017-06-20 22:56 - 000299520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataAccountApis.dll
2017-07-11 15:25 - 2017-06-20 22:56 - 000180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgent.exe
2017-07-11 15:25 - 2017-06-20 22:55 - 000557568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StoreAgent.dll
2017-07-11 15:25 - 2017-06-20 22:55 - 000404992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dsreg.dll
2017-07-11 15:25 - 2017-06-20 22:55 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Core.dll
2017-07-11 15:25 - 2017-06-20 22:54 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgentUserBroker.exe
2017-07-11 15:25 - 2017-06-20 22:53 - 000218624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WwaApi.dll
2017-07-11 15:25 - 2017-06-20 22:53 - 000175616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Scanners.dll
2017-07-11 15:25 - 2017-06-20 22:51 - 000747520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Ocr.dll
2017-07-11 15:25 - 2017-06-20 22:51 - 000284672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.dll
2017-07-11 15:25 - 2017-06-20 22:50 - 001167360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2017-07-11 15:25 - 2017-06-20 22:50 - 000857600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EmailApis.dll
2017-07-11 15:25 - 2017-06-20 22:50 - 000529920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2017-07-11 15:25 - 2017-06-20 22:50 - 000297472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2017-07-11 15:25 - 2017-06-20 22:49 - 000295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.dll
2017-07-11 15:25 - 2017-06-20 22:48 - 002333184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2017-07-11 15:25 - 2017-06-20 22:48 - 000336384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\azroleui.dll
2017-07-11 15:25 - 2017-06-20 22:46 - 001323008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsp_fs.dll
2017-07-11 15:25 - 2017-06-20 22:46 - 001137152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsp_health.dll
2017-07-11 15:25 - 2017-06-20 22:44 - 000027136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fdProxy.dll
2017-07-11 15:25 - 2017-06-20 22:43 - 000468992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.InkControls.dll
2017-07-11 15:25 - 2017-06-20 22:43 - 000035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cnvfat.dll
2017-07-11 15:25 - 2017-06-20 22:42 - 002749440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mispace.dll
2017-07-11 15:25 - 2017-06-20 22:42 - 000853504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autofmt.exe
2017-07-11 15:25 - 2017-06-20 22:40 - 002641920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2017-07-11 15:25 - 2017-06-20 22:38 - 003520512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xpsrchvw.exe
2017-07-11 15:25 - 2017-06-20 22:38 - 000877056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autoconv.exe
2017-07-11 15:25 - 2017-06-20 22:38 - 000709120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2017-07-11 15:25 - 2017-06-20 22:36 - 002648576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertEnroll.dll
2017-07-11 15:25 - 2017-06-20 22:36 - 001988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2017-07-11 15:25 - 2017-06-20 22:35 - 001656320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Perception.dll
2017-07-11 15:25 - 2017-06-20 22:35 - 001232384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Maps.dll
2017-07-11 15:25 - 2017-06-20 22:35 - 001170944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Speech.dll
2017-07-11 15:25 - 2017-06-20 22:35 - 000827904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.appcore.dll
2017-07-11 15:25 - 2017-06-20 22:35 - 000598528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Web.dll
2017-07-11 15:25 - 2017-06-20 22:34 - 001886720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Logon.dll
2017-07-11 15:25 - 2017-06-20 22:34 - 000773120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2017-07-11 15:25 - 2017-06-20 22:34 - 000711168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll
2017-07-11 15:25 - 2017-06-20 22:34 - 000621056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.dll
2017-07-11 15:25 - 2017-06-20 22:33 - 001170944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Phone.dll
2017-07-11 15:25 - 2017-06-20 22:33 - 001013248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Web.Http.dll
2017-07-11 15:25 - 2017-06-20 22:32 - 001556992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll
2017-07-11 15:25 - 2017-03-03 22:56 - 000263472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Storage.ApplicationData.dll
2017-07-11 15:25 - 2017-03-03 22:21 - 001243136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.FaceAnalysis.dll
2017-07-11 15:25 - 2017-03-03 22:20 - 000426496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Wallet.dll
2017-07-11 15:25 - 2016-09-15 08:58 - 000092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2017-07-11 15:24 - 2017-07-06 23:49 - 000340824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-07-11 15:24 - 2017-07-06 23:40 - 020967840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2017-07-11 15:24 - 2017-07-06 23:19 - 000025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapprovp.dll
2017-07-11 15:24 - 2017-07-06 23:18 - 000450560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2017-07-11 15:24 - 2017-07-06 23:18 - 000210432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\onex.dll
2017-07-11 15:24 - 2017-07-06 23:17 - 000118784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\raschap.dll
2017-07-11 15:24 - 2017-07-06 23:13 - 000364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupShim.dll
2017-07-11 15:24 - 2017-07-06 23:10 - 000755200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-07-11 15:24 - 2017-07-06 23:09 - 000506368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-07-11 15:24 - 2017-07-06 23:03 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msinfo32.exe
2017-07-11 15:24 - 2017-07-06 23:02 - 001313280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdc.dll
2017-07-11 15:24 - 2017-07-06 23:00 - 000476160 _____ (Microsoft® Windows® Operating System) C:\Windows\SysWOW64\wvc.dll
2017-07-11 15:24 - 2017-07-06 22:56 - 006035456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2017-07-11 15:24 - 2017-07-06 22:55 - 003664896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-07-11 15:24 - 2017-07-06 22:55 - 001571840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2017-07-11 15:24 - 2017-06-20 23:42 - 001573280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-07-11 15:24 - 2017-06-20 23:42 - 000601712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2017-07-11 15:24 - 2017-06-20 23:38 - 000790752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-07-11 15:24 - 2017-06-20 23:27 - 001431232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2017-07-11 15:24 - 2017-06-20 23:27 - 000861024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LicenseManager.dll
2017-07-11 15:24 - 2017-06-20 23:27 - 000549088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2017-07-11 15:24 - 2017-06-20 23:25 - 001980776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2017-07-11 15:24 - 2017-06-20 23:24 - 000154432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntmarta.dll
2017-07-11 15:24 - 2017-06-20 23:21 - 004023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2017-07-11 15:24 - 2017-06-20 23:21 - 001845512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2017-07-11 15:24 - 2017-06-20 23:21 - 001277856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2017-07-11 15:24 - 2017-06-20 23:21 - 000952416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
2017-07-11 15:24 - 2017-06-20 23:21 - 000374448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFPlay.dll
2017-07-11 15:24 - 2017-06-20 23:20 - 001360464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetsrc.dll
2017-07-11 15:24 - 2017-06-20 23:20 - 000981888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetcore.dll
2017-07-11 15:24 - 2017-06-20 23:04 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcconf.dll
2017-07-11 15:24 - 2017-06-20 23:00 - 000519168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ngccredprov.dll
2017-07-11 15:24 - 2017-06-20 22:59 - 000123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.HostName.dll
2017-07-11 15:24 - 2017-06-20 22:59 - 000097792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.System.SystemManagement.dll
2017-07-11 15:24 - 2017-06-20 22:58 - 000087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-07-11 15:24 - 2017-06-20 22:57 - 000122880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sendmail.dll
2017-07-11 15:24 - 2017-06-20 22:55 - 000265728 _____ C:\Windows\SysWOW64\Windows.Perception.Stub.dll
2017-07-11 15:24 - 2017-06-20 22:55 - 000117760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AuthBroker.dll
2017-07-11 15:24 - 2017-06-20 22:55 - 000020480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\regsvr32.exe
2017-07-11 15:24 - 2017-06-20 22:54 - 000609280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Import.dll
2017-07-11 15:24 - 2017-06-20 22:54 - 000141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\easwrt.dll
2017-07-11 15:24 - 2017-06-20 22:53 - 000431616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\efswrt.dll
2017-07-11 15:24 - 2017-06-20 22:53 - 000325120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2017-07-11 15:24 - 2017-06-20 22:53 - 000185856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll
2017-07-11 15:24 - 2017-06-20 22:52 - 000182784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BioCredProv.dll
2017-07-11 15:24 - 2017-06-20 22:50 - 000661504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WpcWebFilter.dll
2017-07-11 15:24 - 2017-06-20 22:49 - 000500224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.Printing.dll
2017-07-11 15:24 - 2017-06-20 22:46 - 004615168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2017-07-11 15:24 - 2017-06-20 22:46 - 001077760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Editing.dll
2017-07-11 15:24 - 2017-06-20 22:46 - 000355328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RTMediaFrame.dll
2017-07-11 15:24 - 2017-06-20 22:45 - 000471552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll
2017-07-11 15:24 - 2017-06-20 22:44 - 000795648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MiracastReceiver.dll
2017-07-11 15:24 - 2017-06-20 22:44 - 000343040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToDevice.dll
2017-07-11 15:24 - 2017-06-20 22:43 - 001534464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.Printing.3D.dll
2017-07-11 15:24 - 2017-06-20 22:43 - 000713216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpnapps.dll
2017-07-11 15:24 - 2017-06-20 22:42 - 000470016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll
2017-07-11 15:24 - 2017-06-20 22:41 - 000459776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Playback.MediaPlayer.dll
2017-07-11 15:24 - 2017-06-20 22:40 - 002154496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\storagewmi.dll
2017-07-11 15:24 - 2017-06-20 22:40 - 000895488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Streaming.dll
2017-07-11 15:24 - 2017-06-20 22:40 - 000675840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll
2017-07-11 15:24 - 2017-06-20 22:40 - 000220672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToReceiver.dll
2017-07-11 15:24 - 2017-06-20 22:38 - 001221120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Audio.dll
2017-07-11 15:24 - 2017-06-20 22:38 - 000886272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aadtb.dll
2017-07-11 15:24 - 2017-06-20 22:37 - 006109696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mos.dll
2017-07-11 15:24 - 2017-06-20 22:37 - 000400384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToManager.dll
2017-07-11 15:24 - 2017-06-20 22:37 - 000103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Devices.dll
2017-07-11 15:24 - 2017-06-20 22:35 - 002740224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2017-07-11 15:24 - 2017-06-20 22:35 - 000589312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Sensors.dll
2017-07-11 15:24 - 2017-06-20 22:34 - 000542208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.Connectivity.dll
2017-07-11 15:24 - 2017-06-20 22:33 - 000751104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2017-07-11 15:24 - 2017-06-20 22:33 - 000691200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBroker.dll
2017-07-11 15:24 - 2017-06-20 22:31 - 003106304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2017-07-11 15:24 - 2017-03-03 22:20 - 000206336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vaultcli.dll
2017-07-11 15:24 - 2017-03-03 22:18 - 000525824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintDialogs.dll
2017-07-11 15:24 - 2017-03-03 22:16 - 000584192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2017-07-11 15:23 - 2017-07-06 23:19 - 000081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-07-11 15:23 - 2017-07-06 23:14 - 000270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-07-11 15:23 - 2017-07-06 23:14 - 000126464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2017-07-11 15:23 - 2017-07-06 23:13 - 000310272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll
2017-07-11 15:23 - 2017-07-06 23:06 - 018364928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2017-07-11 15:23 - 2017-07-06 23:05 - 019414528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-07-11 15:23 - 2017-07-06 23:00 - 012187136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-07-11 15:23 - 2017-07-06 22:57 - 000691712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-07-11 15:23 - 2017-06-20 23:41 - 001706488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-07-11 15:23 - 2017-06-20 23:30 - 000196960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ifsutil.dll
2017-07-11 15:23 - 2017-06-20 23:29 - 005722320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2017-07-11 15:23 - 2017-06-20 23:28 - 000170960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-07-11 15:23 - 2017-06-20 23:20 - 000312472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mftranscode.dll
2017-07-11 15:23 - 2017-06-20 23:19 - 004312248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2017-07-11 15:23 - 2017-06-20 23:00 - 000143360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uudf.dll
2017-07-11 15:23 - 2017-06-20 22:55 - 000533504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FXSCOMEX.dll
2017-07-11 15:23 - 2017-06-20 22:53 - 000332288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Bluetooth.dll
2017-07-11 15:23 - 2017-06-20 22:50 - 000238080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AboveLockAppHost.dll
2017-07-11 15:23 - 2017-06-20 22:45 - 000102400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uexfat.dll
2017-07-11 15:23 - 2017-06-20 22:44 - 000535040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\untfs.dll
2017-07-11 15:23 - 2017-06-20 22:44 - 000136704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ufat.dll
2017-07-11 15:23 - 2017-06-20 22:42 - 003307008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2017-07-11 15:23 - 2017-06-20 22:42 - 000525312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LogonController.dll
2017-07-11 15:23 - 2017-06-20 22:42 - 000380416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uReFSv1.dll
2017-07-11 15:23 - 2017-06-20 22:39 - 000546304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uReFS.dll
2017-07-11 15:23 - 2017-06-20 22:38 - 000753152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imapi2fs.dll
2017-07-11 15:23 - 2017-06-20 22:37 - 000357376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Geolocation.dll
2017-07-11 15:23 - 2017-06-20 22:36 - 001247232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Globalization.dll
2017-07-11 15:23 - 2017-06-20 22:34 - 000654336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApiPublic.dll
2017-07-11 15:23 - 2017-06-20 22:32 - 000353280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TextInputFramework.dll
2017-07-11 15:23 - 2017-03-03 22:19 - 000498688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mbsmsapi.dll
2017-07-11 15:23 - 2017-03-03 22:02 - 002138112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputService.dll
2017-07-11 15:22 - 2017-07-06 22:55 - 004423680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2017-07-11 15:22 - 2017-06-20 23:28 - 002277288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2017-07-11 15:22 - 2017-06-20 23:28 - 000524776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2017-07-11 15:22 - 2017-06-20 23:04 - 001631232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Resources.dll
2017-07-11 15:22 - 2017-06-20 23:00 - 000138240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DisplayManager.dll
2017-07-11 15:22 - 2017-06-20 22:54 - 000298496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Management.dll
2017-07-11 15:22 - 2017-06-20 22:53 - 000201728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExecModelClient.dll
2017-07-11 15:22 - 2017-06-20 22:48 - 000395264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dmenrollengine.dll
2017-07-11 15:22 - 2017-06-20 22:38 - 003733504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll
2017-07-11 15:22 - 2016-09-15 08:47 - 000134656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Energy.dll
2017-07-11 15:21 - 2017-06-20 23:39 - 002048496 _____ C:\Windows\SysWOW64\CoreUIComponents.dll
2017-07-11 15:21 - 2017-06-20 23:27 - 001122344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dcomp.dll
2017-07-11 15:21 - 2017-06-20 23:25 - 002168288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
2017-07-11 15:21 - 2017-06-20 23:24 - 000846560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinTypes.dll
2017-07-11 15:21 - 2017-06-20 23:01 - 000141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Radios.dll
2017-07-11 15:21 - 2017-06-20 22:58 - 000129024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.SerialCommunication.dll
2017-07-11 15:21 - 2017-06-20 22:57 - 000142336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.WiFi.dll
2017-07-11 15:21 - 2017-06-20 22:56 - 000374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.LowLevel.dll
2017-07-11 15:21 - 2017-06-20 22:56 - 000203776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credprovhost.dll
2017-07-11 15:21 - 2017-06-20 22:56 - 000113152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Lights.dll
2017-07-11 15:21 - 2017-06-20 22:53 - 000386048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.WiFiDirect.dll
2017-07-11 15:21 - 2017-06-20 22:53 - 000202752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll
2017-07-11 15:21 - 2017-06-20 22:52 - 000262144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Picker.dll
2017-07-11 15:21 - 2017-06-20 22:51 - 000314368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Usb.dll
2017-07-11 15:21 - 2017-06-20 22:49 - 000288256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CryptoWinRT.dll
2017-07-11 15:21 - 2017-06-20 22:47 - 013873664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2017-07-11 15:21 - 2017-06-20 22:40 - 000901120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Bluetooth.dll
2017-07-11 15:21 - 2017-06-20 22:35 - 000348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Midi.dll
2017-07-11 15:21 - 2017-03-03 22:21 - 000670208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.PointOfService.dll
2017-07-11 15:21 - 2017-03-03 22:20 - 000562176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.SmartCards.dll
2017-07-11 15:21 - 2016-10-05 01:15 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dialclient.dll
2017-07-11 15:20 - 2017-06-20 23:30 - 000869848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll
2017-07-11 15:20 - 2017-06-20 23:27 - 000116576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudExperienceHostCommon.dll
2017-07-11 15:20 - 2017-06-20 23:20 - 000962768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2017-07-11 15:20 - 2017-06-20 22:56 - 000231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2017-07-11 15:20 - 2017-06-20 22:56 - 000184320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserMgrProxy.dll
2017-07-11 15:20 - 2017-06-20 22:54 - 000483840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.AllJoyn.dll
2017-07-11 15:20 - 2017-06-20 22:53 - 000390656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CredProvDataModel.dll
2017-07-11 15:20 - 2017-06-20 22:53 - 000284672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepsync.dll
2017-07-11 15:20 - 2017-06-20 22:53 - 000271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\deviceaccess.dll
2017-07-11 15:20 - 2017-06-20 22:53 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepapi.dll
2017-07-11 15:20 - 2017-06-20 22:45 - 000891904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autochk.exe
2017-07-11 15:20 - 2017-06-20 22:45 - 000313856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2017-07-11 15:20 - 2017-06-20 22:43 - 000653312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.AccountsControl.dll
2017-07-11 15:20 - 2017-06-20 22:39 - 000134144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ErrorDetails.dll
2017-07-11 15:20 - 2017-06-20 22:34 - 000566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ShareHost.dll
2017-07-11 15:20 - 2017-06-20 22:10 - 000483840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreMessaging.dll
2017-07-11 15:03 - 2017-06-20 23:52 - 000088416 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\scmbus.sys
2017-07-11 15:03 - 2017-06-20 23:52 - 000081760 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\stornvme.sys
2017-07-11 15:03 - 2017-06-20 23:40 - 000328008 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Storage.ApplicationData.dll
2017-07-11 15:03 - 2017-06-20 23:02 - 000124928 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\scmdisk0101.sys
2017-07-11 15:03 - 2017-06-20 23:02 - 000124416 _____ (Microsoft Corporation) C:\Windows\System32\mssprxy.dll
2017-07-11 15:03 - 2017-06-20 23:00 - 000193536 _____ (Microsoft Corporation) C:\Windows\System32\WinRtTracing.dll
2017-07-11 15:03 - 2017-06-20 23:00 - 000114688 _____ (Microsoft Corporation) C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2017-07-11 15:03 - 2017-06-20 23:00 - 000082432 _____ (Microsoft Corporation) C:\Windows\System32\Windows.System.UserDeviceAssociation.dll
2017-07-11 15:03 - 2017-06-20 23:00 - 000073216 _____ (Microsoft Corporation) C:\Windows\System32\Windows.StateRepositoryBroker.dll
2017-07-11 15:03 - 2017-06-20 22:59 - 000467968 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Gaming.XboxLive.Storage.dll
2017-07-11 15:03 - 2017-06-20 22:59 - 000149504 _____ (Microsoft Corporation) C:\Windows\System32\Windows.ApplicationModel.Core.dll
2017-07-11 15:03 - 2017-06-20 22:59 - 000122880 _____ (Microsoft Corporation) C:\Windows\System32\Windows.StateRepositoryClient.dll
2017-07-11 15:03 - 2017-06-20 22:58 - 000547840 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Gaming.Input.dll
2017-07-11 15:03 - 2017-06-20 22:56 - 001507840 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Media.FaceAnalysis.dll
2017-07-11 15:03 - 2017-06-20 22:55 - 000358912 _____ (Microsoft Corporation) C:\Windows\System32\Windows.ApplicationModel.dll
2017-07-11 15:03 - 2017-06-20 22:55 - 000349184 _____ (Microsoft Corporation) C:\Windows\System32\SearchProtocolHost.exe
2017-07-11 15:03 - 2017-06-20 22:54 - 001159680 _____ (Microsoft Corporation) C:\Windows\System32\XblGameSave.dll
2017-07-11 15:03 - 2017-06-20 22:51 - 000634368 _____ (Microsoft Corporation) C:\Windows\System32\StructuredQuery.dll
2017-07-11 15:03 - 2017-06-20 22:49 - 002104320 _____ (Microsoft Corporation) C:\Windows\System32\wlidsvc.dll
2017-07-11 15:03 - 2017-06-20 22:44 - 000588288 _____ (Microsoft Corporation) C:\Windows\System32\wlidprov.dll
2017-07-11 15:03 - 2017-06-20 22:41 - 003400704 _____ (Microsoft Corporation) C:\Windows\System32\tquery.dll
2017-07-11 15:03 - 2017-06-20 22:41 - 001080320 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Media.Ocr.dll
2017-07-11 15:03 - 2017-06-20 22:39 - 002538496 _____ (Microsoft Corporation) C:\Windows\System32\mssrch.dll
2017-07-11 15:03 - 2017-06-20 22:39 - 001643008 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Media.Speech.dll
2017-07-11 15:03 - 2017-06-20 22:38 - 002424320 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Devices.Perception.dll
2017-07-11 15:03 - 2017-06-20 22:36 - 000903680 _____ (Microsoft Corporation) C:\Windows\System32\SearchIndexer.exe
2017-07-11 15:02 - 2017-06-20 23:32 - 008169024 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Media.Protection.PlayReady.dll
2017-07-11 15:01 - 2017-07-06 23:29 - 000857440 _____ (Microsoft Corporation) C:\Windows\System32\WWAHost.exe
2017-07-11 15:01 - 2017-07-06 22:44 - 000147456 _____ (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2017-07-11 15:01 - 2017-07-06 22:24 - 005388800 _____ (Microsoft) C:\Windows\System32\dbgeng.dll
2017-07-11 15:01 - 2017-07-06 22:24 - 003615744 _____ (Microsoft Corporation) C:\Windows\System32\win32kfull.sys
2017-07-11 15:01 - 2017-07-06 22:24 - 001513472 _____ (Microsoft Corporation) C:\Windows\System32\win32kbase.sys
2017-07-11 15:01 - 2017-06-20 23:38 - 001738560 _____ (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2017-07-11 15:01 - 2017-06-20 23:03 - 000013312 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\rootmdm.sys
2017-07-11 15:01 - 2017-06-20 23:02 - 000237568 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Web.Diagnostics.dll
2017-07-11 15:01 - 2017-06-20 23:01 - 000138752 _____ (Microsoft Corporation) C:\Windows\System32\VEDataLayerHelpers.dll
2017-07-11 15:01 - 2017-06-20 23:00 - 000295424 _____ (Microsoft Corporation) C:\Windows\System32\unimdm.tsp
2017-07-11 15:01 - 2017-06-20 22:59 - 000196096 _____ (Microsoft Corporation) C:\Windows\System32\UserDeviceRegistration.dll
2017-07-11 15:01 - 2017-06-20 22:59 - 000137216 _____ (Microsoft Corporation) C:\Windows\System32\tdlrecover.exe
2017-07-11 15:01 - 2017-06-20 22:59 - 000101888 _____ (Microsoft Corporation) C:\Windows\System32\UserDeviceRegistration.Ngc.dll
2017-07-11 15:01 - 2017-06-20 22:58 - 000224768 _____ (Microsoft Corporation) C:\Windows\System32\wpd_ci.dll
2017-07-11 15:01 - 2017-06-20 22:58 - 000211968 _____ (Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
2017-07-11 15:01 - 2017-06-20 22:57 - 000087552 _____ (Microsoft Corporation) C:\Windows\System32\wpdbusenum.dll
2017-07-11 15:01 - 2017-06-20 22:56 - 000748544 _____ (Microsoft Corporation) C:\Windows\System32\StoreAgent.dll
2017-07-11 15:01 - 2017-06-20 22:56 - 000260608 _____ (Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
2017-07-11 15:01 - 2017-06-20 22:56 - 000216576 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Devices.Scanners.dll
2017-07-11 15:01 - 2017-06-20 22:55 - 000561664 _____ (Microsoft Corporation) C:\Windows\System32\Windows.ApplicationModel.Wallet.dll
2017-07-11 15:01 - 2017-06-20 22:54 - 000574976 _____ (Microsoft Corporation) C:\Windows\System32\tileobjserver.dll
2017-07-11 15:01 - 2017-06-20 22:54 - 000245760 _____ (Microsoft Corporation) C:\Windows\System32\WwaApi.dll
2017-07-11 15:01 - 2017-06-20 22:53 - 000642048 _____ (Microsoft Corporation) C:\Windows\System32\Windows.UI.Xaml.InkControls.dll
2017-07-11 15:01 - 2017-06-20 22:53 - 000339968 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Graphics.dll
2017-07-11 15:01 - 2017-06-20 22:52 - 000963584 _____ (Microsoft Corporation) C:\Windows\System32\WebcamUi.dll
2017-07-11 15:01 - 2017-06-20 22:52 - 000775168 _____ (Microsoft Corporation) C:\Windows\System32\GamePanel.exe
2017-07-11 15:01 - 2017-06-20 22:49 - 001913856 _____ (Microsoft Corporation) C:\Windows\System32\wsp_fs.dll
2017-07-11 15:01 - 2017-06-20 22:49 - 001584128 _____ (Microsoft Corporation) C:\Windows\System32\wsp_health.dll
2017-07-11 15:01 - 2017-06-20 22:46 - 003290112 _____ (Microsoft Corporation) C:\Windows\System32\mispace.dll
2017-07-11 15:01 - 2017-06-20 22:39 - 002916864 _____ (Microsoft Corporation) C:\Windows\System32\CertEnroll.dll
2017-07-11 15:01 - 2017-06-20 22:39 - 000816640 _____ (Microsoft Corporation) C:\Windows\System32\Windows.UI.dll
2017-07-11 15:01 - 2017-06-20 22:39 - 000673792 _____ (Microsoft Corporation) C:\Windows\System32\winlogon.exe
2017-07-11 15:01 - 2017-06-20 22:38 - 002695680 _____ (Microsoft Corporation) C:\Windows\System32\Windows.UI.Logon.dll
2017-07-11 15:01 - 2017-06-20 22:38 - 000908800 _____ (Microsoft Corporation) C:\Windows\System32\Windows.UI.Search.dll
2017-07-11 15:01 - 2017-06-20 22:37 - 000774656 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Web.dll
2017-07-11 15:01 - 2017-06-20 22:36 - 002318848 _____ (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2017-07-11 15:01 - 2017-06-20 22:36 - 001424896 _____ (Microsoft Corporation) C:\Windows\System32\Windows.UI.Xaml.Maps.dll
2017-07-11 15:01 - 2017-06-20 22:35 - 001726976 _____ (Microsoft Corporation) C:\Windows\System32\Windows.UI.Immersive.dll
2017-07-11 15:01 - 2017-06-20 22:35 - 001369088 _____ (Microsoft Corporation) C:\Windows\System32\Windows.UI.Xaml.Phone.dll
2017-07-11 15:01 - 2017-06-20 22:35 - 001328640 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Web.Http.dll
2017-07-11 15:01 - 2017-05-22 20:58 - 000448576 _____ C:\Windows\System32\ApnDatabase.xml
2017-07-11 15:01 - 2017-03-03 22:12 - 004596224 _____ (Microsoft Corporation) C:\Windows\System32\xpsrchvw.exe
2017-07-11 15:00 - 2017-07-06 23:37 - 000118112 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tdx.sys
2017-07-11 15:00 - 2017-07-06 23:32 - 000404824 _____ (Microsoft Corporation) C:\Windows\System32\msv1_0.dll
2017-07-11 15:00 - 2017-07-06 23:28 - 000223584 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb20.sys
2017-07-11 15:00 - 2017-07-06 23:24 - 022220856 _____ (Microsoft Corporation) C:\Windows\System32\shell32.dll
2017-07-11 15:00 - 2017-07-06 23:23 - 001600624 _____ (Microsoft Corporation) C:\Windows\System32\sppobjs.dll
2017-07-11 15:00 - 2017-07-06 23:18 - 002532192 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2017-07-11 15:00 - 2017-07-06 22:47 - 000201728 _____ (Microsoft Corporation) C:\Windows\System32\ScDeviceEnum.dll
2017-07-11 15:00 - 2017-07-06 22:46 - 000231424 _____ (Microsoft Corporation) C:\Windows\System32\shutdownux.dll
2017-07-11 15:00 - 2017-07-06 22:45 - 000289792 _____ (Microsoft Corporation) C:\Windows\System32\DeveloperOptionsSettingsHandlers.dll
2017-07-11 15:00 - 2017-07-06 22:44 - 000193536 _____ (Microsoft Corporation) C:\Windows\System32\certprop.dll
2017-07-11 15:00 - 2017-07-06 22:43 - 001081856 _____ (Microsoft Corporation) C:\Windows\System32\Chakradiag.dll
2017-07-11 15:00 - 2017-07-06 22:42 - 000805888 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll
2017-07-11 15:00 - 2017-07-06 22:39 - 000282624 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb10.sys
2017-07-11 15:00 - 2017-07-06 22:34 - 009131008 _____ (Microsoft Corporation) C:\Windows\System32\twinui.dll
2017-07-11 15:00 - 2017-07-06 22:29 - 004749824 _____ (Microsoft Corporation) C:\Windows\System32\SettingsHandlers_nt.dll
2017-07-11 15:00 - 2017-07-06 22:29 - 000932864 _____ (Microsoft Corporation) C:\Windows\System32\kerberos.dll
2017-07-11 15:00 - 2017-07-06 22:28 - 000589312 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2017-07-11 15:00 - 2017-07-06 22:27 - 008120832 _____ (Microsoft Corporation) C:\Windows\System32\Chakra.dll
2017-07-11 15:00 - 2017-07-06 22:24 - 004744704 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2017-07-11 15:00 - 2017-06-20 23:38 - 001860288 _____ (Microsoft Corporation) C:\Windows\System32\Windows.ApplicationModel.Store.dll
2017-07-11 15:00 - 2017-06-20 23:37 - 001157008 _____ (Microsoft Corporation) C:\Windows\System32\twinapi.appcore.dll
2017-07-11 15:00 - 2017-06-20 23:33 - 000408600 _____ (Microsoft Corporation) C:\Windows\System32\tsmf.dll
2017-07-11 15:00 - 2017-06-20 23:02 - 000124416 _____ (Microsoft Corporation) C:\Windows\System32\Windows.System.SystemManagement.dll
2017-07-11 15:00 - 2017-06-20 23:01 - 000156160 _____ (Microsoft Corporation) C:\Windows\System32\Family.Client.dll
2017-07-11 15:00 - 2017-06-20 23:01 - 000108032 _____ (Microsoft Corporation) C:\Windows\System32\Family.Authentication.dll
2017-07-11 15:00 - 2017-06-20 23:01 - 000015872 _____ (Microsoft Corporation) C:\Windows\System32\snmptrap.exe
2017-07-11 15:00 - 2017-06-20 23:00 - 000259072 _____ (Microsoft Corporation) C:\Windows\System32\Family.SyncEngine.dll
2017-07-11 15:00 - 2017-06-20 23:00 - 000233984 _____ (Microsoft Corporation) C:\Windows\System32\ProvisioningHandlers.dll
2017-07-11 15:00 - 2017-06-20 23:00 - 000224256 _____ (Microsoft Corporation) C:\Windows\System32\SettingsHandlers_SignInOptions.dll
2017-07-11 15:00 - 2017-06-20 22:59 - 000136192 _____ (Microsoft Corporation) C:\Windows\System32\sendmail.dll
2017-07-11 15:00 - 2017-06-20 22:57 - 000418304 _____ (Microsoft Corporation) C:\Windows\System32\Windows.UI.BlockedShutdown.dll
2017-07-11 15:00 - 2017-06-20 22:57 - 000360448 _____ (Microsoft Corporation) C:\Windows\System32\rdpencom.dll
2017-07-11 15:00 - 2017-06-20 22:56 - 000590336 _____ (Microsoft Corporation) C:\Windows\System32\efswrt.dll
2017-07-11 15:00 - 2017-06-20 22:56 - 000267264 _____ (Microsoft Corporation) C:\Windows\System32\vaultcli.dll
2017-07-11 15:00 - 2017-06-20 22:55 - 000310784 _____ (Microsoft Corporation) C:\Windows\System32\SyncSettings.dll
2017-07-11 15:00 - 2017-06-20 22:55 - 000252416 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Security.Authentication.Identity.Provider.dll
2017-07-11 15:00 - 2017-06-20 22:54 - 000168960 _____ (Microsoft Corporation) C:\Windows\System32\easwrt.dll
2017-07-11 15:00 - 2017-06-20 22:53 - 000425984 _____ (Microsoft Corporation) C:\Windows\System32\aadcloudap.dll
2017-07-11 15:00 - 2017-06-20 22:52 - 000331264 _____ (Microsoft Corporation) C:\Windows\System32\NgcCtnrSvc.dll
2017-07-11 15:00 - 2017-06-20 22:49 - 000175616 _____ (Microsoft Corporation) C:\Windows\System32\SystemSettings.DeviceEncryptionHandlers.dll
2017-07-11 15:00 - 2017-06-20 22:46 - 001908224 _____ (Microsoft Corporation) C:\Windows\System32\AzureSettingSyncProvider.dll
2017-07-11 15:00 - 2017-06-20 22:46 - 000627200 _____ (Microsoft Corporation) C:\Windows\System32\SpaceControl.dll
2017-07-11 15:00 - 2017-06-20 22:45 - 002861056 _____ (Microsoft Corporation) C:\Windows\System32\storagewmi.dll
2017-07-11 15:00 - 2017-06-20 22:43 - 000130560 _____ (Microsoft Corporation) C:\Windows\System32\SpaceAgent.exe
2017-07-11 15:00 - 2017-06-20 22:42 - 000981504 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll
2017-07-11 15:00 - 2017-06-20 22:41 - 001359872 _____ (Microsoft Corporation) C:\Windows\System32\SharedStartModel.dll
2017-07-11 15:00 - 2017-06-20 22:41 - 000983040 _____ (Microsoft Corporation) C:\Windows\System32\ngcsvc.dll
2017-07-11 15:00 - 2017-06-20 22:39 - 008076288 _____ (Microsoft Corporation) C:\Windows\System32\mstscax.dll
2017-07-11 15:00 - 2017-06-20 22:39 - 000971264 _____ (Microsoft Corporation) C:\Windows\System32\twinui.appcore.dll
2017-07-11 15:00 - 2017-06-20 22:38 - 001984000 _____ (Microsoft Corporation) C:\Windows\System32\diagtrack.dll
2017-07-11 15:00 - 2017-06-20 22:38 - 000765440 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Devices.Sensors.dll
2017-07-11 15:00 - 2017-06-20 22:37 - 000875520 _____ (Microsoft Corporation) C:\Windows\System32\TokenBroker.dll
2017-07-11 15:00 - 2017-06-20 22:36 - 000881152 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.dll
2017-07-11 15:00 - 2017-06-20 22:34 - 003299840 _____ (Microsoft Corporation) C:\Windows\System32\mstsc.exe
2017-07-11 15:00 - 2017-06-20 22:34 - 001121280 _____ (Microsoft Corporation) C:\Windows\System32\aadtb.dll
2017-07-11 15:00 - 2017-06-20 22:34 - 000035328 _____ (Microsoft Corporation) C:\Windows\System32\spaceman.exe
2017-07-11 15:00 - 2017-06-20 22:33 - 000439296 _____ (Microsoft Corporation) C:\Windows\System32\wksprt.exe
2017-07-11 15:00 - 2017-06-20 22:33 - 000048128 _____ (Microsoft Corporation) C:\Windows\System32\tlscsp.dll
2017-07-11 15:00 - 2017-03-03 23:10 - 000360040 _____ (Microsoft Corporation) C:\Windows\System32\SystemSettingsAdminFlows.exe
2017-07-11 15:00 - 2017-03-03 22:23 - 001145856 _____ (Microsoft Corporation) C:\Windows\System32\EmailApis.dll
2017-07-11 15:00 - 2017-03-03 22:20 - 000800768 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll
2017-07-11 14:59 - 2017-07-06 23:44 - 000108896 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\pdc.sys
2017-07-11 14:59 - 2017-07-06 23:42 - 007781720 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2017-07-11 14:59 - 2017-07-06 23:37 - 000468320 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\netio.sys
2017-07-11 14:59 - 2017-07-06 22:49 - 000115200 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\bridge.sys
2017-07-11 14:59 - 2017-07-06 22:48 - 000030208 _____ (Microsoft Corporation) C:\Windows\System32\eapprovp.dll
2017-07-11 14:59 - 2017-07-06 22:45 - 000488960 _____ (Microsoft Corporation) C:\Windows\System32\NetSetupShim.dll
2017-07-11 14:59 - 2017-07-06 22:44 - 000502784 _____ (Microsoft Corporation) C:\Windows\System32\rastls.dll
2017-07-11 14:59 - 2017-07-06 22:44 - 000238592 _____ (Microsoft Corporation) C:\Windows\System32\onex.dll
2017-07-11 14:59 - 2017-07-06 22:44 - 000137728 _____ (Microsoft Corporation) C:\Windows\System32\raschap.dll
2017-07-11 14:59 - 2017-07-06 22:36 - 000369664 _____ (Microsoft Corporation) C:\Windows\System32\msinfo32.exe
2017-07-11 14:59 - 2017-07-06 22:35 - 001397760 _____ (Microsoft Corporation) C:\Windows\System32\wdc.dll
2017-07-11 14:59 - 2017-07-06 22:33 - 000576000 _____ (Microsoft® Windows® Operating System) C:\Windows\System32\wvc.dll
2017-07-11 14:59 - 2017-07-06 22:22 - 001826816 _____ (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2017-07-11 14:59 - 2017-06-20 23:52 - 001886344 _____ (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2017-07-11 14:59 - 2017-06-20 23:52 - 000774224 _____ (Microsoft Corporation) C:\Windows\System32\oleaut32.dll
2017-07-11 14:59 - 2017-06-20 23:51 - 002255712 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys
2017-07-11 14:59 - 2017-06-20 23:50 - 000126304 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mup.sys
2017-07-11 14:59 - 2017-06-20 23:37 - 002446704 _____ (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2017-07-11 14:59 - 2017-06-20 23:33 - 000092512 _____ (Microsoft Corporation) C:\Windows\System32\rdpudd.dll
2017-07-11 14:59 - 2017-06-20 23:32 - 004260576 _____ (Microsoft Corporation) C:\Windows\System32\mfcore.dll
2017-07-11 14:59 - 2017-06-20 23:32 - 001983408 _____ (Microsoft Corporation) C:\Windows\System32\mfmp4srcsnk.dll
2017-07-11 14:59 - 2017-06-20 23:32 - 001702392 _____ (Microsoft Corporation) C:\Windows\System32\mfasfsrcsnk.dll
2017-07-11 14:59 - 2017-06-20 23:32 - 001072248 _____ (Microsoft Corporation) C:\Windows\System32\mfnetcore.dll
2017-07-11 14:59 - 2017-06-20 23:26 - 000387864 _____ (Microsoft Corporation) C:\Windows\System32\wmpps.dll
2017-07-11 14:59 - 2017-06-20 23:06 - 000372736 _____ (Microsoft Corporation) C:\Windows\System32\RDXTaskFactory.dll
2017-07-11 14:59 - 2017-06-20 23:02 - 000030208 _____ (Microsoft Corporation) C:\Windows\System32\odbcconf.dll
2017-07-11 14:59 - 2017-06-20 23:00 - 000148480 _____ (Microsoft Corporation) C:\Windows\System32\Windows.System.Profile.RetailInfo.dll
2017-07-11 14:59 - 2017-06-20 23:00 - 000113664 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-07-11 14:59 - 2017-06-20 22:58 - 000418304 _____ C:\Windows\System32\Windows.Perception.Stub.dll
2017-07-11 14:59 - 2017-06-20 22:56 - 000852480 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Media.Import.dll
2017-07-11 14:59 - 2017-06-20 22:56 - 000719872 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\WdiWiFi.sys
2017-07-11 14:59 - 2017-06-20 22:55 - 000456192 _____ (Microsoft Corporation) C:\Windows\System32\puiobj.dll
2017-07-11 14:59 - 2017-06-20 22:52 - 006288384 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Media.dll
2017-07-11 14:59 - 2017-06-20 22:52 - 000352256 _____ (Microsoft Corporation) C:\Windows\System32\XpsDocumentTargetPrint.dll
2017-07-11 14:59 - 2017-06-20 22:49 - 001403392 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Media.Editing.dll
2017-07-11 14:59 - 2017-06-20 22:49 - 000458752 _____ (Microsoft Corporation) C:\Windows\System32\RTMediaFrame.dll
2017-07-11 14:59 - 2017-06-20 22:47 - 007655424 _____ (Microsoft Corporation) C:\Windows\System32\mos.dll
2017-07-11 14:59 - 2017-06-20 22:47 - 001105408 _____ (Microsoft Corporation) C:\Windows\System32\MiracastReceiver.dll
2017-07-11 14:59 - 2017-06-20 22:47 - 000442368 _____ (Microsoft Corporation) C:\Windows\System32\PlayToDevice.dll
2017-07-11 14:59 - 2017-06-20 22:43 - 001217024 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Media.Audio.dll
2017-07-11 14:59 - 2017-06-20 22:42 - 000539136 _____ (Microsoft Corporation) C:\Windows\System32\PlayToManager.dll
2017-07-11 14:59 - 2017-06-20 22:42 - 000139776 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Media.Devices.dll
2017-07-11 14:59 - 2017-06-20 22:41 - 000945664 _____ (Microsoft Corporation) C:\Windows\System32\WpcWebFilter.dll
2017-07-11 14:59 - 2017-06-20 22:41 - 000913920 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Networking.dll
2017-07-11 14:59 - 2017-06-20 22:40 - 001891328 _____ (Microsoft Corporation) C:\Windows\System32\pnidui.dll
2017-07-11 14:59 - 2017-06-20 22:40 - 000611328 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Graphics.Printing.dll
2017-07-11 14:59 - 2017-06-20 22:39 - 002208768 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Graphics.Printing.3D.dll
2017-07-11 14:59 - 2017-06-20 22:36 - 000701952 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Networking.Connectivity.dll
2017-07-11 14:59 - 2017-06-20 22:35 - 004149248 _____ (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
2017-07-11 14:59 - 2017-06-20 22:35 - 000924672 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Networking.BackgroundTransfer.dll
2017-07-11 14:59 - 2017-03-03 22:27 - 000391168 _____ (Microsoft Corporation) C:\Windows\System32\oleacc.dll
2017-07-11 14:59 - 2017-03-03 22:26 - 000307200 _____ (Microsoft Corporation) C:\Windows\System32\PrintDialogs3D.dll
2017-07-11 14:59 - 2017-03-03 22:23 - 000583680 _____ (Microsoft Corporation) C:\Windows\System32\PrintDialogs.dll
2017-07-11 14:59 - 2017-03-03 22:17 - 000864256 _____ (Microsoft Corporation) C:\Windows\System32\wpnapps.dll
2017-07-11 14:59 - 2017-03-03 22:15 - 001078784 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Media.Streaming.dll
2017-07-11 14:59 - 2017-03-03 22:14 - 000279552 _____ (Microsoft Corporation) C:\Windows\System32\PlayToReceiver.dll
2017-07-11 14:59 - 2016-10-05 01:32 - 000146432 _____ (Microsoft Corporation) C:\Windows\System32\AuthBroker.dll
2017-07-11 14:59 - 2016-08-26 21:12 - 000244816 _____ (Microsoft Corporation) C:\Windows\System32\mfps.dll
2017-07-11 14:58 - 2017-07-06 23:29 - 002759712 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2017-07-11 14:58 - 2017-07-06 23:18 - 001100120 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\http.sys
2017-07-11 14:58 - 2017-07-06 23:18 - 000057400 _____ (Microsoft Corporation) C:\Windows\System32\lsass.exe
2017-07-11 14:58 - 2017-07-06 22:51 - 022569984 _____ (Microsoft Corporation) C:\Windows\System32\edgehtml.dll
2017-07-11 14:58 - 2017-07-06 22:48 - 000071680 _____ (Microsoft Corporation) C:\Windows\System32\l2gpstore.dll
2017-07-11 14:58 - 2017-07-06 22:46 - 000052224 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tcpipreg.sys
2017-07-11 14:58 - 2017-07-06 22:45 - 000276992 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2017-07-11 14:58 - 2017-07-06 22:45 - 000223744 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2017-07-11 14:58 - 2017-07-06 22:44 - 000139264 _____ (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2017-07-11 14:58 - 2017-07-06 22:43 - 000387584 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2017-07-11 14:58 - 2017-07-06 22:43 - 000088576 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2017-07-11 14:58 - 2017-07-06 22:42 - 000352256 _____ (Microsoft Corporation) C:\Windows\System32\Wldap32.dll
2017-07-11 14:58 - 2017-07-06 22:31 - 023676416 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2017-07-11 14:58 - 2017-07-06 22:30 - 013090816 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2017-07-11 14:58 - 2017-07-06 22:28 - 002096640 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2017-07-11 14:58 - 2017-07-06 22:28 - 000759296 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2017-07-11 14:58 - 2017-07-06 22:24 - 002895872 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2017-07-11 14:58 - 2017-07-06 22:24 - 001783296 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2017-07-11 14:58 - 2017-06-20 23:53 - 000794928 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Internal.Shell.Broker.dll
2017-07-11 14:58 - 2017-06-20 23:52 - 002213760 _____ (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2017-07-11 14:58 - 2017-06-20 23:51 - 000434528 _____ (Microsoft Corporation) C:\Windows\System32\hal.dll
2017-07-11 14:58 - 2017-06-20 23:38 - 007220192 _____ (Microsoft Corporation) C:\Windows\System32\windows.storage.dll
2017-07-11 14:58 - 2017-06-20 23:36 - 000624048 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2017-07-11 14:58 - 2017-06-20 22:59 - 000082944 _____ (Microsoft Corporation) C:\Windows\System32\KdsCli.dll
2017-07-11 14:58 - 2017-06-20 22:54 - 000671744 _____ (Microsoft Corporation) C:\Windows\System32\mbsmsapi.dll
2017-07-11 14:58 - 2017-06-20 22:54 - 000472064 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Internal.Bluetooth.dll
2017-07-11 14:58 - 2017-06-20 22:53 - 000284160 _____ (Microsoft Corporation) C:\Windows\System32\AboveLockAppHost.dll
2017-07-11 14:58 - 2017-06-20 22:49 - 003778048 _____ (Microsoft Corporation) C:\Windows\System32\MFMediaEngine.dll
2017-07-11 14:58 - 2017-06-20 22:48 - 000112640 _____ (Microsoft Corporation) C:\Windows\System32\uexfat.dll
2017-07-11 14:58 - 2017-06-20 22:43 - 000961536 _____ (Microsoft Corporation) C:\Windows\System32\imapi2fs.dll
2017-07-11 14:58 - 2017-06-20 22:42 - 000467968 _____ (Microsoft Corporation) C:\Windows\System32\Geolocation.dll
2017-07-11 14:58 - 2017-06-20 22:42 - 000079360 _____ (Microsoft Corporation) C:\Windows\System32\LocationFrameworkInternalPS.dll
2017-07-11 14:58 - 2017-06-20 22:40 - 001586176 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Globalization.dll
2017-07-11 14:58 - 2017-06-20 22:39 - 001490432 _____ (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2017-07-11 14:58 - 2017-06-20 22:38 - 000846336 _____ (Microsoft Corporation) C:\Windows\System32\MbaeApiPublic.dll
2017-07-11 14:58 - 2017-06-20 22:37 - 000735744 _____ (Microsoft Corporation) C:\Windows\System32\LogonController.dll
2017-07-11 14:58 - 2016-10-14 19:45 - 001790464 _____ (Microsoft Corporation) C:\Windows\System32\LocationFramework.dll
2017-07-11 14:57 - 2017-07-06 23:40 - 000376672 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\clfs.sys
2017-07-11 14:57 - 2017-07-06 23:23 - 000241504 _____ (Microsoft Corporation) C:\Windows\System32\CloudExperienceHost.dll
2017-07-11 14:57 - 2017-07-06 22:58 - 007217152 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Data.Pdf.dll
2017-07-11 14:57 - 2017-07-06 22:43 - 000431616 _____ (Microsoft Corporation) C:\Windows\System32\WpAXHolder.dll
2017-07-11 14:57 - 2017-07-06 22:25 - 004708864 _____ (Microsoft Corporation) C:\Windows\System32\ExplorerFrame.dll
2017-07-11 14:57 - 2017-07-06 22:24 - 002217472 _____ (Microsoft Corporation) C:\Windows\System32\OpcServices.dll
2017-07-11 14:57 - 2017-06-20 23:54 - 000603488 _____ (Microsoft Corporation) C:\Windows\System32\ContentDeliveryManager.Utilities.dll
2017-07-11 14:57 - 2017-06-20 23:48 - 002681200 _____ C:\Windows\System32\CoreUIComponents.dll
2017-07-11 14:57 - 2017-06-20 23:40 - 001069720 _____ (Microsoft Corporation) C:\Windows\System32\MrmCoreR.dll
2017-07-11 14:57 - 2017-06-20 23:40 - 000224096 _____ (Microsoft Corporation) C:\Windows\System32\ifsutil.dll
2017-07-11 14:57 - 2017-06-20 23:37 - 001369240 _____ (Microsoft Corporation) C:\Windows\System32\dcomp.dll
2017-07-11 14:57 - 2017-06-20 23:35 - 002915704 _____ (Microsoft Corporation) C:\Windows\System32\combase.dll
2017-07-11 14:57 - 2017-06-20 23:35 - 001267512 _____ (Microsoft Corporation) C:\Windows\System32\WinTypes.dll
2017-07-11 14:57 - 2017-06-20 23:31 - 004674360 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2017-07-11 14:57 - 2017-06-20 23:31 - 001277824 _____ (Microsoft Corporation) C:\Windows\System32\ole32.dll
2017-07-11 14:57 - 2017-06-20 23:31 - 000160096 _____ (Microsoft Corporation) C:\Windows\System32\CloudExperienceHostBroker.dll
2017-07-11 14:57 - 2017-06-20 23:04 - 001631232 _____ (Microsoft Corporation) C:\Windows\System32\Windows.UI.Xaml.Resources.dll
2017-07-11 14:57 - 2017-06-20 23:03 - 000167936 _____ (Microsoft Corporation) C:\Windows\System32\uudf.dll
2017-07-11 14:57 - 2017-06-20 23:01 - 000185344 _____ (Microsoft Corporation) C:\Windows\System32\DisplayManager.dll
2017-07-11 14:57 - 2017-06-20 23:00 - 000193536 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Devices.WiFi.dll
2017-07-11 14:57 - 2017-06-20 22:59 - 000182272 _____ (Microsoft Corporation) C:\Windows\System32\DeviceDirectoryClient.dll
2017-07-11 14:57 - 2017-06-20 22:58 - 000257024 _____ (Microsoft Corporation) C:\Windows\System32\CloudDomainJoinDataModelServer.dll
2017-07-11 14:57 - 2017-06-20 22:58 - 000186368 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Devices.Radios.dll
2017-07-11 14:57 - 2017-06-20 22:58 - 000144896 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\dfsc.sys
2017-07-11 14:57 - 2017-06-20 22:57 - 000505856 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Devices.WiFiDirect.dll
2017-07-11 14:57 - 2017-06-20 22:57 - 000243712 _____ (Microsoft Corporation) C:\Windows\System32\credprovhost.dll
2017-07-11 14:57 - 2017-06-20 22:57 - 000171520 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Devices.SerialCommunication.dll
2017-07-11 14:57 - 2017-06-20 22:57 - 000144896 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Devices.Lights.dll
2017-07-11 14:57 - 2017-06-20 22:56 - 000912384 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Devices.SmartCards.dll
2017-07-11 14:57 - 2017-06-20 22:56 - 000568320 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Devices.LowLevel.dll
2017-07-11 14:57 - 2017-06-20 22:55 - 000407552 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Internal.Management.dll
2017-07-11 14:57 - 2017-06-20 22:54 - 000949248 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Devices.PointOfService.dll
2017-07-11 14:57 - 2017-06-20 22:54 - 000337408 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Devices.Picker.dll
2017-07-11 14:57 - 2017-06-20 22:54 - 000247808 _____ (Microsoft Corporation) C:\Windows\System32\ExecModelClient.dll
2017-07-11 14:57 - 2017-06-20 22:53 - 001010176 _____ (Microsoft Corporation) C:\Windows\System32\enterprisecsps.dll
2017-07-11 14:57 - 2017-06-20 22:53 - 000437248 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Devices.Usb.dll
2017-07-11 14:57 - 2017-06-20 22:52 - 017198592 _____ (Microsoft Corporation) C:\Windows\System32\Windows.UI.Xaml.dll
2017-07-11 14:57 - 2017-06-20 22:52 - 000410112 _____ (Microsoft Corporation) C:\Windows\System32\DevicesFlowBroker.dll
2017-07-11 14:57 - 2017-06-20 22:49 - 000169984 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Energy.dll
2017-07-11 14:57 - 2017-06-20 22:47 - 000574976 _____ (Microsoft Corporation) C:\Windows\System32\untfs.dll
2017-07-11 14:57 - 2017-06-20 22:47 - 000152064 _____ (Microsoft Corporation) C:\Windows\System32\ufat.dll
2017-07-11 14:57 - 2017-06-20 22:46 - 000516608 _____ (Microsoft Corporation) C:\Windows\System32\uReFSv1.dll
2017-07-11 14:57 - 2017-06-20 22:46 - 000187904 _____ (Microsoft Corporation) C:\Windows\System32\dialclient.dll
2017-07-11 14:57 - 2017-06-20 22:46 - 000039424 _____ (Microsoft Corporation) C:\Windows\System32\cnvfat.dll
2017-07-11 14:57 - 2017-06-20 22:43 - 000953344 _____ (Microsoft Corporation) C:\Windows\System32\autoconv.exe
2017-07-11 14:57 - 2017-06-20 22:43 - 000628736 _____ (Microsoft Corporation) C:\Windows\System32\uReFS.dll
2017-07-11 14:57 - 2017-06-20 22:41 - 000460800 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Devices.Midi.dll
2017-07-11 14:57 - 2017-06-20 22:40 - 004474368 _____ (Microsoft Corporation) C:\Windows\System32\D3DCompiler_47.dll
2017-07-11 14:57 - 2017-06-20 22:40 - 001421824 _____ (Microsoft Corporation) C:\Windows\System32\certutil.exe
2017-07-11 14:57 - 2017-06-20 22:40 - 000886784 _____ (Microsoft Corporation) C:\Windows\System32\CPFilters.dll
2017-07-11 14:57 - 2017-06-20 22:40 - 000376832 _____ (Microsoft Corporation) C:\Windows\System32\CryptoWinRT.dll
2017-07-11 14:57 - 2017-06-20 22:38 - 005611008 _____ (Microsoft Corporation) C:\Windows\System32\d2d1.dll
2017-07-11 14:57 - 2017-06-20 22:38 - 001275392 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Devices.Bluetooth.dll
2017-07-11 14:57 - 2017-06-20 22:36 - 000180224 _____ (Microsoft Corporation) C:\Windows\System32\enrollmentapi.dll
2017-07-11 14:57 - 2017-03-03 22:28 - 000279552 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Devices.HumanInterfaceDevice.dll
2017-07-11 14:57 - 2017-03-03 22:19 - 001589760 _____ (Microsoft Corporation) C:\Windows\System32\msdtctm.dll
2017-07-11 14:56 - 2017-07-06 22:28 - 000927744 _____ (Microsoft Corporation) C:\Windows\System32\SmartcardCredentialProvider.dll
2017-07-11 14:56 - 2017-06-20 23:47 - 000764392 _____ (Microsoft Corporation) C:\Windows\System32\CoreMessaging.dll
2017-07-11 14:56 - 2017-06-20 23:37 - 000146784 _____ (Microsoft Corporation) C:\Windows\System32\CloudExperienceHostCommon.dll
2017-07-11 14:56 - 2017-06-20 22:57 - 000651264 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Devices.AllJoyn.dll
2017-07-11 14:56 - 2017-06-20 22:57 - 000157696 _____ (Microsoft Corporation) C:\Windows\System32\XamlTileRender.dll
2017-07-11 14:56 - 2017-06-20 22:56 - 000379904 _____ (Microsoft Corporation) C:\Windows\System32\apprepsync.dll
2017-07-11 14:56 - 2017-06-20 22:56 - 000324608 _____ (Microsoft Corporation) C:\Windows\System32\Windows.ApplicationModel.LockScreen.dll
2017-07-11 14:56 - 2017-06-20 22:56 - 000268800 _____ (Microsoft Corporation) C:\Windows\System32\UserMgrProxy.dll
2017-07-11 14:56 - 2017-06-20 22:55 - 000176128 _____ (Microsoft Corporation) C:\Windows\System32\apprepapi.dll
2017-07-11 14:56 - 2017-06-20 22:53 - 000329728 _____ (Microsoft Corporation) C:\Windows\System32\deviceaccess.dll
2017-07-11 14:56 - 2017-06-20 22:52 - 000956416 _____ (Microsoft Corporation) C:\Windows\System32\AppXDeploymentExtensions.desktop.dll
2017-07-11 14:56 - 2017-06-20 22:52 - 000896512 _____ (Microsoft Corporation) C:\Windows\System32\Windows.AccountsControl.dll
2017-07-11 14:56 - 2017-06-20 22:52 - 000560128 _____ (Microsoft Corporation) C:\Windows\System32\AppReadiness.dll
2017-07-11 14:56 - 2017-06-20 22:51 - 000410112 _____ (Microsoft Corporation) C:\Windows\System32\AppXDeploymentClient.dll
2017-07-11 14:56 - 2017-06-20 22:50 - 001054208 _____ (Microsoft Corporation) C:\Windows\System32\qmgr.dll
2017-07-11 14:56 - 2017-06-20 22:48 - 000968192 _____ (Microsoft Corporation) C:\Windows\System32\autochk.exe
2017-07-11 14:56 - 2017-06-20 22:47 - 000064000 _____ (Microsoft Corporation) C:\Windows\System32\fdProxy.dll
2017-07-11 14:56 - 2017-06-20 22:46 - 000925184 _____ (Microsoft Corporation) C:\Windows\System32\autofmt.exe
2017-07-11 14:56 - 2017-06-20 22:44 - 000167936 _____ (Microsoft Corporation) C:\Windows\System32\ErrorDetails.dll
2017-07-11 14:56 - 2017-06-20 22:41 - 002279424 _____ (Microsoft Corporation) C:\Windows\System32\AppXDeploymentServer.dll
2017-07-11 14:56 - 2017-06-20 22:41 - 001692160 _____ (Microsoft Corporation) C:\Windows\System32\AppXDeploymentExtensions.onecore.dll
2017-07-11 14:56 - 2017-06-20 22:41 - 001021440 _____ (Microsoft Corporation) C:\Windows\System32\usermgr.dll
2017-07-11 14:56 - 2017-06-20 22:37 - 000716800 _____ (Microsoft Corporation) C:\Windows\System32\ShareHost.dll
2017-07-11 14:55 - 2017-06-20 23:36 - 000557408 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\spaceport.sys
2017-07-11 14:55 - 2017-06-20 23:36 - 000129888 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\USBSTOR.SYS
2017-07-11 10:38 - 2017-07-11 10:38 - 000157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\enrollmentapi.dll
2017-07-06 18:50 - 2017-07-06 18:50 - 000001479 _____ C:\Users\dad\Documents\emanonprologue.txt

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-07-31 15:56 - 2016-09-09 02:11 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-07-31 15:56 - 2016-09-09 01:34 - 000000000 ____D C:\users\dad
2017-07-31 15:56 - 2016-07-15 22:04 - 001572864 _____ C:\Windows\System32\config\BBI
2017-07-31 15:50 - 2016-09-09 01:26 - 000000000 ____D C:\Windows\System32\SleepStudy
2017-07-31 11:42 - 2017-01-18 20:28 - 000000000 ____D C:\Users\dad\AppData\Roaming\TS3Client
2017-07-31 07:47 - 2017-03-16 04:54 - 000000000 ____D C:\Users\dad\AppData\LocalLow\Mozilla
2017-07-31 01:31 - 2015-11-07 00:33 - 000000000 ____D C:\Program Files (x86)\Opera
2017-07-29 11:52 - 2017-06-29 23:25 - 000000000 ____D C:\Users\dad\AppData\Local\ntuserlitelist
2017-07-28 18:55 - 2015-11-07 10:27 - 000000000 ____D C:\Users\dad\AppData\Local\Battle.net
2017-07-28 16:48 - 2015-11-08 19:41 - 000000000 ____D C:\Program Files (x86)\World of Warcraft
2017-07-28 16:45 - 2015-11-07 10:21 - 000000000 ____D C:\Program Files (x86)\Battle.net
2017-07-28 15:24 - 2016-05-20 16:17 - 000000000 ____D C:\Users\dad\Documents\My Cheat Tables
2017-07-28 12:49 - 2016-12-07 22:36 - 000000000 ____D C:\Program Files (x86)\Steam
2017-07-28 12:42 - 2017-06-30 19:43 - 000000000 ____D C:\Program Files (x86)\Mr DJ
2017-07-28 12:29 - 2017-02-26 23:56 - 000000000 ____D C:\Program Files (x86)\AviSynth 2.5
2017-07-28 11:37 - 2017-03-18 19:20 - 000000000 ____D C:\$WINDOWS.~BT
2017-07-27 13:47 - 2017-03-17 22:24 - 000000000 ____D C:\Users\dad\AppData\Local\Razer
2017-07-27 13:44 - 2017-03-17 22:23 - 000000000 ____D C:\ProgramData\Razer
2017-07-27 13:44 - 2017-03-17 22:23 - 000000000 ____D C:\Program Files (x86)\Razer
2017-07-27 08:15 - 2015-08-09 04:00 - 000000000 _RSHD C:\hp
2017-07-26 12:55 - 2015-11-07 00:26 - 000000000 __SHD C:\Users\dad\IntelGraphicsProfiles
2017-07-26 12:49 - 2015-12-08 16:52 - 000000000 ____D C:\Program Files (x86)\Calix
2017-07-26 09:53 - 2017-01-24 21:19 - 000000000 ____D C:\Users\dad\AppData\Local\Estmob
2017-07-26 09:47 - 2016-07-16 03:45 - 000000000 ____D C:\Windows\INF
2017-07-26 09:46 - 2017-05-22 10:03 - 000000059 _____ C:\Users\dad\AppData\Local\UserProducts.xml
2017-07-26 09:15 - 2017-02-25 15:57 - 000000000 ____D C:\Users\dad\Desktop\Youtube
2017-07-26 08:06 - 2016-09-29 15:53 - 000000000 ____D C:\Users\dad\.oracle_jre_usage
2017-07-26 07:51 - 2017-03-16 04:53 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-07-24 16:37 - 2017-03-17 18:45 - 000004596 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2017-07-24 16:37 - 2016-07-16 03:47 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2017-07-24 16:37 - 2016-07-16 03:47 - 000000000 ____D C:\Windows\System32\Macromed
2017-07-24 03:42 - 2015-11-07 09:32 - 000000000 ____D C:\Users\dad\AppData\Local\Adobe
2017-07-22 15:02 - 2016-07-16 03:47 - 000000000 ____D C:\Windows\AppReadiness
2017-07-21 03:24 - 2016-07-16 03:47 - 000000000 ___HD C:\Program Files\WindowsApps
2017-07-16 20:13 - 2016-07-16 03:47 - 000000000 ____D C:\Windows\LiveKernelReports
2017-07-14 03:44 - 2016-07-16 03:47 - 000000000 ____D C:\Windows\rescache
2017-07-11 17:16 - 2015-07-16 06:00 - 000000000 __RHD C:\Users\Public\AccountPictures
2017-07-11 17:14 - 2016-09-09 01:33 - 001860008 _____ C:\Windows\System32\PerfStringBackup.INI
2017-07-11 17:09 - 2017-06-15 00:14 - 000223432 _____ C:\Windows\System32\FNTCACHE.DAT
2017-07-11 17:05 - 2016-07-16 03:47 - 000000000 ____D C:\Windows\System32\oobe
2017-07-11 17:05 - 2016-07-16 03:47 - 000000000 ____D C:\Windows\System32\appraiser
2017-07-11 17:04 - 2016-07-16 03:47 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2017-07-11 17:04 - 2016-07-16 03:47 - 000000000 ____D C:\Windows\ShellExperiences
2017-07-11 17:04 - 2016-07-16 03:47 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2017-07-11 17:04 - 2016-07-16 03:47 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-07-11 16:24 - 2016-07-16 03:36 - 000000000 ____D C:\Windows\CbsTemp
2017-07-11 16:02 - 2015-11-07 02:59 - 000000000 ____D C:\Windows\System32\MRT
2017-07-11 15:53 - 2015-11-07 02:59 - 135225752 ____C (Microsoft Corporation) C:\Windows\System32\MRT.exe
2017-07-07 10:11 - 2017-05-11 09:45 - 000000000 ____D C:\Windows\System32\UNP
2017-07-07 10:11 - 2017-05-11 09:45 - 000000000 ____D C:\Program Files\UNP
2017-07-05 23:41 - 2017-04-19 15:29 - 000000000 ____D C:\Users\dad\Documents\Razer
2017-07-03 12:55 - 2016-11-07 14:58 - 000000000 ____D C:\Users\dad\Documents\flourish wizard
2017-07-02 08:53 - 2015-08-21 22:24 - 000000000 ____D C:\Program Files (x86)\Dropbox
2017-07-01 15:27 - 2016-11-15 03:45 - 000000000 ___HD C:\Windows\msdownld.tmp
2017-07-01 15:27 - 2016-11-15 03:45 - 000000000 ____D C:\Windows\SysWOW64\directx
2017-07-01 13:39 - 2017-06-29 23:20 - 000000000 ____D C:\Users\dad\AppData\Roaming\tixati
2017-07-01 03:36 - 2016-10-17 09:57 - 000000000 ____D C:\Users\dad\AppData\Local\Deployment
2017-07-01 03:09 - 2015-12-09 07:59 - 000000000 ___RD C:\Program Files (x86)\Skype
2017-07-01 03:09 - 2015-12-09 07:59 - 000000000 ____D C:\ProgramData\Skype
2017-07-01 03:09 - 2015-11-08 12:01 - 000000000 ____D C:\Users\dad\AppData\Roaming\DropboxOEM
2017-07-01 02:47 - 2017-03-17 20:50 - 000000000 ____D C:\Users\dad\AppData\Roaming\Three Rings Design
2017-07-01 02:38 - 2015-11-07 00:26 - 000000000 ____D C:\Users\dad\AppData\Local\Packages
2017-07-01 02:23 - 2016-03-11 17:32 - 000000000 ____D C:\Users\dad\AppData\Roaming\IMVU
2017-07-01 02:22 - 2017-02-21 11:32 - 000000000 ____D C:\Fraps
2017-07-01 02:22 - 2015-08-21 21:58 - 000000000 ____D C:\Program Files\HP

Files to move or delete:
====================
C:\ProgramData\hash.dat
C:\Users\dad\mbar-1.09.4.1001 (1).exe


Some files in TEMP:
====================
2017-07-28 12:28 - 2017-02-26 23:56 - 000024348 _____ () C:\Users\dad\AppData\Local\Temp\A~NSISu_.exe
2017-07-28 12:25 - 2017-07-28 12:25 - 034201768 _____ (ArenaNet) C:\Users\dad\AppData\Local\Temp\Gw2.exe
2017-07-26 07:16 - 2017-07-26 07:17 - 001069856 _____ () C:\Users\dad\AppData\Local\Temp\rscp_setup.exe

==================== Known DLLs (Whitelisted) =========================


==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe
[2017-07-11 15:01] - [2017-06-20 22:39] - 000673792 _____ (Microsoft Corporation) CB440E1C4EC9C369EC9DD07B48A83F36

C:\Windows\System32\wininit.exe
[2016-07-16 03:42] - [2016-07-16 03:42] - 000304240 _____ (Microsoft Corporation) 99A19C9A74E2F9820E501DCE77F84F70

C:\Windows\explorer.exe
[2017-07-11 14:57] - [2017-06-20 23:31] - 004674360 _____ (Microsoft Corporation) C623B1A075298DD33D45B456837D278D

C:\Windows\SysWOW64\explorer.exe
[2017-07-11 15:23] - [2017-06-20 23:19] - 004312248 _____ (Microsoft Corporation) BDCF9C89E1EDD113AD18E0EC16823AFA

C:\Windows\System32\svchost.exe
[2016-07-16 03:42] - [2016-07-16 03:42] - 000044496 _____ (Microsoft Corporation) 36F670D89040709013F6A460176767EC

C:\Windows\SysWOW64\svchost.exe
[2016-07-16 03:42] - [2016-07-16 03:42] - 000038792 _____ (Microsoft Corporation) 1F8434DD4907C832E6E90D6298EAB85B

C:\Windows\System32\services.exe
[2017-05-10 05:37] - [2017-04-27 16:28] - 000453536 _____ (Microsoft Corporation) 9A3B47CD17283B299311013AD3D21D26

C:\Windows\System32\User32.dll
[2016-12-13 23:32] - [2016-12-09 02:10] - 001461200 _____ (Microsoft Corporation) C46EA86BF0E7C96235E9064CBAD6ED26

C:\Windows\SysWOW64\User32.dll
[2016-12-13 23:32] - [2016-12-09 01:52] - 001435896 _____ (Microsoft Corporation) 4BEC594A3D4AEAFAC400D88F7E328C7B

C:\Windows\System32\userinit.exe
[2016-07-16 03:42] - [2016-07-16 03:42] - 000033280 _____ (Microsoft Corporation) C1B1FFC800BE2F31EB2CF8CB40629C69

C:\Windows\SysWOW64\userinit.exe
[2016-07-16 03:42] - [2016-07-16 03:42] - 000027648 _____ (Microsoft Corporation) FA900E6CCCF0A429D5B720C6F0E2274B

C:\Windows\System32\rpcss.dll
[2017-05-10 05:35] - [2017-04-27 15:41] - 000890368 _____ (Microsoft Corporation) 4A7015195E49A3BA7DB967B277B21E9D

C:\Windows\System32\dnsapi.dll
[2017-03-14 18:49] - [2017-03-03 23:24] - 000646688 _____ (Microsoft Corporation) 2813C62F5BE7FAF0A1C5CC37E5C2F25D

C:\Windows\SysWOW64\dnsapi.dll
[2017-03-14 19:01] - [2017-03-03 23:09] - 000497416 _____ (Microsoft Corporation) AA86DC342B4ED1C1F839C3BC8AEA64B1

C:\Windows\System32\Drivers\volsnap.sys
[2016-07-16 03:42] - [2016-07-16 03:42] - 000391520 _____ (Microsoft Corporation) BF2546583BB75F01DDA60A7921DFB230


==================== Association (Whitelisted) =============


==================== Restore Points  =========================

Restore point date: 2017-07-31 18:58

==================== Memory info =========================== 

Percentage of memory in use: 20%
Total physical RAM: 3976.73 MB
Available physical RAM: 3170.89 MB
Total Virtual: 3976.73 MB
Available Virtual: 3211.33 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:912.58 GB) (Free:443.2 GB) NTFS
Drive d: (USBRECOVERY) (Removable) (Total:29.16 GB) (Free:29.09 GB) FAT32
Drive e: (Recovery Image) (Fixed) (Total:17.63 GB) (Free:2.25 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive g: (WINRE) (Fixed) (Total:0.83 GB) (Free:0.49 GB) NTFS
Drive x: (Boot) (Fixed) (Total:0.5 GB) (Free:0.5 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: C97EA54F)

Partition: GPT.

========================================================
Disk: 1 (Size: 29.2 GB) (Disk ID: 73FC86B8)
Partition 1: (Not Active) - (Size=29.2 GB) - (Type=0C)

LastRegBack: 2017-07-22 02:43

==================== End of FRST.txt ============================

Link to post
Share on other sites

Save the fixlist.txt below on your USB Flash Drive, and return in the Recovery Environment to launch FRST. But this time, instead of clicking on the Scan button, you'll click on the Fix button. Afterwards, a file called fixlog.txt will be on your USB Flash Drive. Attach it here.

fixlist.txt

Link to post
Share on other sites

Results....

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 31-07-2017
Ran by SYSTEM (31-07-2017 19:58:29) Run:2
Running from D:\
Boot Mode: Recovery
==============================================

fixlist content:
*****************
HKLM-x32\...\Run: [cpx] => "C:\Users\dad\AppData\Local\ntuserlitelist\cpx\cpx.exe" -starup <==== ATTENTION
HKLM-x32\...\Run: [svcvmx] => C:\Users\dad\AppData\Local\ntuserlitelist\svcvmx\svcvmx.exe [884224 2017-04-21] ()
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION

S2 Dataup; C:\Users\dad\AppData\Local\ntuserlitelist\dataup\dataup.exe [77824 2017-01-05] () <==== ATTENTION
S2 windowsmanagementservice; C:\Users\dad\AppData\Local\qixsn\ypzzsgy\ct.exe [689664 2017-05-30] () <==== ATTENTION
S4 srcsrv; C:\WINDOWS\src_srv\winsrcsrv.exe [X] <==== ATTENTION
S0 drmkpro64; C:\Windows\System32\drivers\ndistpr64.sys [80160 2013-09-03] () <==== ATTENTION

C:\Program Files (x86)\s5
C:\ProgramData\hash.dat
C:\Users\dad\AppData\Local\ntuserlitelist
C:\Users\dad\AppData\Local\qixsn
C:\Users\dad\AppData\Local\llssoft
C:\Users\dad\AppData\Roaming\c
C:\WINDOWS\src_srv
C:\Windows\System32\drivers\ndistpr64.sys
C:\Windows\Syswow64\tprdpw64.exe
*****************

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\cpx => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\svcvmx => value removed successfully
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION => restored successfully
HKLM\System\ControlSet001\Services\Dataup => key removed successfully
Dataup => service removed successfully
HKLM\System\ControlSet001\Services\windowsmanagementservice => key removed successfully
windowsmanagementservice => service removed successfully
HKLM\System\ControlSet001\Services\srcsrv => key removed successfully
srcsrv => service removed successfully
HKLM\System\ControlSet001\Services\drmkpro64 => key removed successfully
drmkpro64 => service removed successfully
"C:\Program Files (x86)\s5" => not found.
C:\ProgramData\hash.dat => moved successfully
C:\Users\dad\AppData\Local\ntuserlitelist => moved successfully
C:\Users\dad\AppData\Local\qixsn => moved successfully
C:\Users\dad\AppData\Local\llssoft => moved successfully
"C:\Users\dad\AppData\Roaming\c" => not found.
"C:\WINDOWS\src_srv" => not found.
C:\Windows\System32\drivers\ndistpr64.sys => moved successfully
"C:\Windows\Syswow64\tprdpw64.exe" => not found.

==== End of Fixlog 19:59:12 ====

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.