Jump to content

Rootkit Infections - Cannot Open MBAR


SpinnersB

Recommended Posts

I am currently operating on Windows 10, 64-bit.  I have performed multiple full scans using MB and I have discovered multiple Trojan Agents, Spyware, Adware, and Backdoor Agents.  There was also a rootkit shown at 'C:/Windows/System32/drivers/msidntfs.sys'.  I performed multiple scans and removals of these objects, and scans are still showing detections.  I tried to download MBAR and the application won't execute to install.  Please see attached for a recent scanning history log. 

Scanning History Log 200917_1432.txt

Link to post
Share on other sites

Hi SpinnersB :)

My name is Aura and I'll be assisting you with your malware issue. Since we'll be working together, you can call me Aura or Yoan, which is my real name, it's up to you! Now that we've broke the ice, I'll just ask you a few things during the time we'll be working together to clean your system and get it back to an operational state.

  • As you'll notice, the logs we are asking for here are quite lenghty, so it's normal for me to not reply exactly after you post them. This is because I need some time to analyse them and then act accordingly. However, I'll always reply within 24 hours, 48 hours at most if something unexpected happens
  • As long as I'm assisting you on Malwarebytes Forums, in this thread, I'll ask you to not seek assistance anywhere else for any issue related to the system we are working on. If you have an issue, question, etc. about your computer, please ask it in this thread and I'll assist you
  • The same principle applies to any modifications you make to your system, I would like you to ask me before you do any manipulations that aren't in the instructions I posted. This is to ensure that we are operating in sync and I know exactly what's happening on your system
  • If you aren't sure about an instruction I'm giving you, ask me about it. This is to ensure that the clean-up process goes without any issue. I'll answer you and even give you more precise instructions/explanations if you need. There's no shame in asking questions here, better be safe than sorry!
  • If you don't reply to your thread within 3 days, I'll bump this thread to let you know that I'm waiting for you. If you don't reply after 5 days, it'll be closed. If you return after that period, you can send me a PM to get it unlocked and we'll continue where we left off;
  • Since malware can work quickly, we want to get rid of them as fast as we can, before they make unknown changes to the system. This being said, I would appreciate if you could reply to this thread within 24 hours of me posting. This way, we'll have a good clean-up rhythm and the chances of complications will be reduced
  • I'm against any form of pirated, illegal and counterfeit software and material. So if you have any installed on your system, I'll ask you to uninstall them right now. You don't have to tell me if you indeed had some or not, I'll give you the benefit of the doubt. Plus, this would be against Malwarebytes Forums's rules
  • In the end, you are the one asking for assistance here. So if you wish to go a different way during the clean-up, like format and reinstall Windows, you are free to do so. I would appreciate you to let me know about it first, and if you need, I can also assist you in the process
  • I would appreciate if you were to stay with me until the end, which means, until I declare your system clean. Just because your system isn't behaving weirdly anymore, or is running better than before, it doesn't mean that the infection is completely gone
    This being said, I have a full time job so sometimes it'll take longer for me to reply to you. Don't worry, you'll be my first priority as soon as I get home and have time to look at your thread


This being said, it's time to clean-up some malware, so let's get started, shall we? :)

Do you have a USB Flash Drive? If so, how big is it?

Also, follow the instructions below.

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Fix mode
Follow the instructions below to execute a fix on your system using FRST, and provide the log in your next reply.

  • Download the attached fixlist.txt file, and save it on your Desktop (or wherever your FRST.exe/FRST64.exe executable is located)
  • Right-click on the FRST executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Click on the Fix button
    NYA5Cbr.png
  • On completion, a message will come up saying that the fix has been completed and it'll open a log in Notepad
  • Copy and paste its content in your next reply

fixlist.txt

Link to post
Share on other sites

Fix result of Farbar Recovery Scan Tool (x64) Version: 20-09-2017
Ran by SpenserB (20-09-2017 20:15:32) Run:1
Running from C:\Users\SpenserB\Desktop
Loaded Profiles: SpenserB (Available Profiles: SpenserB)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CMD: bcdedit.exe /set {default} recoveryenabled yes
CMD: dir C:\Windows\
CMD: dir C:\Windows\system32\drivers
*****************


========= bcdedit.exe /set {default} recoveryenabled yes =========

The operation completed successfully.

========= End of CMD: =========


========= dir C:\Windows\ =========

 Volume in drive C has no label.
 Volume Serial Number is 9076-E3B9

 Directory of C:\Windows

09/20/2017  08:14 PM    <DIR>          .
09/20/2017  08:14 PM    <DIR>          ..
04/30/2014  04:23 PM            11,248 acpimof.dll
07/16/2016  07:47 AM    <DIR>          addins
09/24/2016  05:21 AM    <DIR>          appcompat
06/17/2017  05:56 AM    <DIR>          AppPatch
09/20/2017  08:51 AM    <DIR>          AppReadiness
03/08/2016  12:08 AM                 0 ativpsrm.bin
09/20/2017  01:53 PM                20 b56696979
08/11/2017  05:29 PM    <DIR>          bcastdvr
07/16/2016  07:42 AM            61,440 bfsvc.exe
07/16/2016  07:47 AM    <DIR>          Boot
07/16/2016  07:47 AM    <DIR>          Branding
09/12/2017  09:27 PM    <DIR>          CbsTemp
09/23/2016  11:59 AM            13,278 comsetup.log
08/09/2015  01:22 PM    <DIR>          CSC
07/16/2016  07:47 AM    <DIR>          Cursors
09/27/2016  11:26 AM    <DIR>          debug
09/23/2016  11:59 AM             7,623 diagerr.xml
07/16/2016  07:47 AM    <DIR>          diagnostics
09/23/2016  11:59 AM             7,623 diagwrn.xml
07/16/2016  10:14 AM    <DIR>          DigitalLocker
08/07/2017  03:10 PM           308,876 DirectX.log
08/05/2016  04:55 PM            10,096 DPINST.LOG
09/23/2016  11:57 AM             4,176 DtcInstall.log
07/16/2016  10:14 AM    <DIR>          en-US
07/12/2017  01:55 AM         4,674,872 explorer.exe
07/16/2016  07:47 AM    <DIR>          GameBarPresenceWriter
09/20/2017  02:26 PM    <DIR>          Globalization
07/16/2016  10:14 AM    <DIR>          Help
06/03/2017  04:52 AM           975,872 HelpPane.exe
07/16/2016  07:42 AM            18,432 hh.exe
07/16/2016  10:14 AM    <DIR>          IME
09/13/2017  01:15 AM    <DIR>          ImmersiveControlPanel
09/20/2017  06:39 PM    <DIR>          INF
07/16/2016  07:47 AM    <DIR>          InfusedApps
09/23/2016  11:57 AM    <DIR>          InputMethod
07/16/2016  07:47 AM    <DIR>          L2Schemas
09/20/2017  06:39 PM    <DIR>          LastGood
09/20/2017  01:58 PM    <DIR>          LastGood.Tmp
03/15/2017  02:19 PM    <DIR>          LiveKernelReports
09/23/2016  11:56 AM               388 LkmdfCoInst.log
08/06/2017  05:53 AM    <DIR>          Logs
09/20/2017  04:31 PM    <DIR>          MediaViewer
08/06/2017  05:46 AM       717,348,747 MEMORY.DMP
07/16/2016  07:42 AM            43,131 mib.bin
09/20/2017  05:53 PM    <DIR>          Microsoft.NET
07/16/2016  07:47 AM    <DIR>          Migration
08/06/2017  05:46 AM    <DIR>          Minidump
09/23/2016  11:56 AM    <DIR>          MiracastView
09/20/2017  02:37 PM    <DIR>          ModemLogs
07/16/2016  07:43 AM           243,200 notepad.exe
07/16/2016  10:15 AM    <DIR>          OCR
07/16/2016  07:47 AM    <DIR>          Offline Web Pages
09/17/2017  09:54 PM    <DIR>          Panther
07/16/2016  07:47 AM    <DIR>          Performance
09/20/2017  07:43 PM           303,092 PFRO.log
07/16/2016  07:47 AM    <DIR>          PLA
08/11/2017  05:29 PM    <DIR>          PolicyDefinitions
09/20/2017  08:14 PM    <DIR>          Prefetch
03/19/2017  05:46 AM    <DIR>          PrintDialog
07/16/2016  07:43 AM            33,882 Professional.xml
09/13/2017  01:15 AM    <DIR>          Provisioning
03/04/2017  02:18 AM           320,512 regedit.exe
09/23/2016  11:59 AM    <DIR>          Registration
07/16/2016  10:29 AM    <DIR>          RemotePackages
09/17/2017  08:12 PM    <DIR>          rescache
07/16/2016  07:47 AM    <DIR>          Resources
09/22/2016  03:55 PM         2,839,520 RtlExUpd.dll
07/16/2016  07:47 AM    <DIR>          SchCache
07/16/2016  07:47 AM    <DIR>          schemas
07/16/2016  10:29 AM    <DIR>          security
09/23/2016  11:55 AM    <DIR>          ServiceProfiles
12/12/2016  06:49 AM    <DIR>          servicing
07/16/2016  07:49 AM    <DIR>          Setup
09/20/2017  06:38 PM            25,545 setupact.log
09/23/2016  11:55 AM                 0 setuperr.log
09/20/2017  03:37 PM    <DIR>          ShellExperiences
07/16/2016  10:14 AM    <DIR>          SKB
09/23/2016  11:59 AM    <DIR>          SoftwareDistribution
07/16/2016  07:47 AM    <DIR>          Speech
07/16/2016  07:47 AM    <DIR>          Speech_OneCore
10/14/2016  11:59 PM           130,560 splwow64.exe
07/16/2016  07:47 AM    <DIR>          System
08/22/2013  09:25 AM               219 system.ini
09/20/2017  07:49 PM    <DIR>          System32
07/16/2016  10:31 AM    <DIR>          SystemApps
07/16/2016  07:47 AM    <DIR>          SystemResources
09/20/2017  07:43 PM    <DIR>          SysWOW64
07/16/2016  07:47 AM    <DIR>          TAPI
02/13/2017  11:58 PM    <DIR>          Tasks
09/20/2017  08:08 PM    <DIR>          Temp
02/13/2016  06:17 PM    <DIR>          ToastData
07/16/2016  07:47 AM    <DIR>          tracing
07/16/2016  07:47 AM    <DIR>          twain_32
07/16/2016  07:43 AM            66,560 twain_32.dll
08/22/2013  11:36 AM    <DIR>          vpnplugins
07/16/2016  07:47 AM    <DIR>          Vss
07/16/2016  07:47 AM    <DIR>          Web
08/22/2013  09:25 AM                92 win.ini
09/20/2017  08:14 PM               275 WindowsUpdate.log
07/16/2016  07:42 AM            10,240 winhlp32.exe
09/20/2017  03:58 PM                85 wininit.ini
09/14/2017  04:05 PM    <DIR>          WinSxS
07/16/2016  07:43 AM           316,640 WMSysPr9.prx
07/16/2016  07:42 AM            11,264 write.exe
              32 File(s)    727,787,508 bytes
              74 Dir(s)  113,477,754,880 bytes free

========= End of CMD: =========


========= dir C:\Windows\system32\drivers =========

 Volume in drive C has no label.
 Volume Serial Number is 9076-E3B9

 Directory of C:\Windows\system32\drivers

09/20/2017  07:43 PM    <DIR>          .
09/20/2017  07:43 PM    <DIR>          ..
09/20/2017  02:48 PM           192,216 0FB25110.sys
07/16/2016  07:41 AM           235,520 1394ohci.sys
09/20/2017  05:24 PM           192,216 2BA74ADF.sys
09/20/2017  02:21 PM           192,216 33CC3ECC.sys
09/20/2017  07:29 PM           253,888 3C692A81.sys
07/16/2016  07:41 AM           107,360 3ware.sys
09/20/2017  02:02 PM           192,216 41ED3024.sys
09/20/2017  04:34 PM           192,216 4FC0249E.sys
09/20/2017  01:58 PM           192,216 654C2D14.sys
09/20/2017  07:43 PM           253,888 745E3573.sys
07/16/2016  07:41 AM           705,888 acpi.sys
07/16/2016  07:41 AM            18,432 AcpiDev.sys
07/16/2016  07:42 AM           126,816 acpiex.sys
07/16/2016  07:41 AM            12,288 acpipagr.sys
07/16/2016  07:41 AM            14,336 acpipmi.sys
07/16/2016  07:41 AM            13,312 acpitime.sys
07/16/2016  07:41 AM         1,135,456 adp80xx.sys
10/15/2016  12:21 AM           584,032 afd.sys
07/16/2016  07:42 AM           107,520 agilevpn.sys
10/14/2016  11:31 PM           227,328 ahcache.sys
07/16/2016  07:41 AM           123,392 amdk8.sys
08/18/2016  08:41 AM            49,448 amdkmafd.sys
07/16/2016  07:41 AM           120,832 amdppm.sys
07/16/2016  07:41 AM            83,296 amdsata.sys
07/16/2016  07:41 AM           259,424 amdsbs.sys
07/16/2016  07:41 AM            26,976 amdxata.sys
07/16/2016  07:42 AM           172,896 appid.sys
07/16/2016  07:42 AM            15,360 applockerfltr.sys
09/15/2016  01:29 PM           127,328 AppVStrm.sys
07/16/2016  10:27 AM           157,024 AppvVemgr.sys
07/16/2016  10:27 AM           141,152 AppvVfs.sys
07/16/2016  07:41 AM           131,936 arcsas.sys
07/16/2016  07:42 AM            28,160 asyncmac.sys
07/16/2016  07:41 AM            28,512 atapi.sys
07/16/2016  07:41 AM           191,840 ataport.sys
09/13/2016  10:08 PM            60,920 ati2erec.dll
07/15/2015  06:20 AM           102,912 AtihdWB6.sys
12/08/2016  02:50 AM           101,376 AtihdWT6.sys
09/13/2016  10:08 PM        26,706,432 atikmdag.sys
09/13/2016  10:08 PM           518,656 atikmpag.sys
03/28/2017  01:36 AM            56,320 BasicDisplay.sys
06/03/2017  05:15 AM            41,472 BasicRender.sys
07/16/2016  07:41 AM            36,192 battc.sys
07/16/2016  07:41 AM             9,728 bcmfn.sys
07/16/2016  07:41 AM             9,728 bcmfn2.sys
07/16/2016  07:42 AM             9,728 beep.sys
11/02/2016  06:23 AM           101,888 bowser.sys
07/07/2017  02:49 AM           115,200 bridge.sys
07/16/2016  07:41 AM            22,016 BtaMPM.sys
07/16/2016  07:41 AM            43,008 BthAvrcpTg.sys
07/16/2016  07:41 AM            65,536 bthhfenum.sys
07/16/2016  07:41 AM            31,232 BthhfHid.sys
07/16/2016  07:41 AM            66,048 bthmodem.sys
07/16/2016  07:41 AM            38,912 buttonconverter.sys
01/22/2016  07:10 PM           144,456 bwcW10x64.sys
06/19/2015  03:01 PM           118,320 bwcW8x64.sys
07/16/2016  07:41 AM           533,856 bxvbda.sys
09/10/2016  09:21 AM           118,272 capimg.sys
07/16/2016  07:42 AM            92,160 cdfs.sys
07/16/2016  07:41 AM           173,056 cdrom.sys
07/16/2016  07:42 AM            76,640 CEA.sys
07/16/2016  07:41 AM           102,752 cht4dx64.sys
07/16/2016  07:41 AM           346,976 cht4sx64.sys
07/16/2016  07:41 AM         2,104,160 cht4vx64.sys
07/16/2016  07:41 AM            48,640 circlass.sys
03/04/2017  03:20 AM           379,744 Classpnp.sys
08/08/2017  02:01 AM           376,672 clfs.sys
09/23/2016  03:53 PM           681,304 ClipSp.sys
07/16/2016  07:41 AM            29,696 CmBatt.sys
09/15/2016  01:29 PM            23,392 cmimcext.sys
09/07/2017  01:53 AM           624,048 cng.sys
07/16/2016  07:42 AM            38,752 cnghwassist.sys
07/16/2016  07:42 AM            53,088 condrv.sys
10/15/2016  12:29 AM            79,200 crashdmp.sys
03/04/2017  02:19 AM           552,960 csc.sys
09/20/2017  07:43 PM           115,024 cwadhknq.sys
03/04/2017  03:15 AM            63,328 dam.sys
07/16/2016  07:41 AM            44,032 devauthe.sys
06/21/2017  02:58 AM           144,896 dfsc.sys
08/08/2017  02:03 AM           102,240 disk.sys
07/16/2016  07:42 AM            38,240 Diskdump.sys
07/16/2016  07:42 AM            14,336 Dmpusbstor.sys
07/16/2016  07:41 AM            35,840 dmvsc.sys
10/19/2012  05:52 AM           151,968 Dot4.sys
10/19/2012  05:52 AM            27,040 Dot4Prt.sys
10/19/2012  05:52 AM            49,056 Dot4usb.sys
07/16/2016  07:41 AM            97,280 drmk.sys
07/16/2016  07:41 AM            16,168 drmkaud.sys
07/16/2016  07:42 AM            35,680 Dumpata.sys
07/16/2016  07:44 AM            89,560 dumpfve.sys
06/03/2017  05:54 AM           187,232 dumpsd.sys
07/16/2016  07:42 AM            31,744 dumpsdport.sys
09/07/2017  01:54 AM         2,188,128 dxgkrnl.sys
09/07/2017  01:54 AM           402,784 dxgmms1.sys
09/07/2017  01:54 AM           658,784 dxgmms2.sys
10/07/2015  05:02 PM           156,744 e22w10x64.sys
02/09/2017  02:15 PM           543,272 EasyAntiCheat.sys
07/16/2016  07:42 AM            88,416 EhStorClass.sys
09/23/2016  03:53 PM           118,112 EhStorTcgDrv.sys
08/11/2017  05:29 PM    <DIR>          en-US
07/16/2016  07:41 AM            13,312 errdev.sys
09/23/2016  11:58 AM    <DIR>          etc
07/16/2016  07:41 AM         3,418,976 evbda.sys
07/16/2016  07:42 AM           334,848 exfat.sys
09/20/2017  07:43 PM           101,824 farflt.sys
11/11/2016  06:13 AM           352,096 fastfat.sys
07/16/2016  07:41 AM            32,256 fdc.sys
07/16/2016  07:42 AM            88,576 filecrypt.sys
07/16/2016  07:42 AM            85,344 fileinfo.sys
07/16/2016  07:42 AM            35,840 filetrace.sys
07/16/2016  07:41 AM            26,112 flpydisk.sys
07/16/2016  07:42 AM           377,696 fltMgr.sys
04/27/2017  08:44 PM            62,816 fsdepends.sys
07/16/2016  07:42 AM            31,584 fs_rec.sys
08/08/2017  01:52 AM           649,568 fvevol.sys
03/04/2017  03:17 AM           409,952 FWPKCLNT.SYS
07/16/2016  07:41 AM            20,480 genericusbfn.sys
07/16/2016  07:42 AM         3,440,660 gm.dls
07/16/2016  07:42 AM               646 gmreadme.txt
07/16/2016  07:42 AM             8,192 gpuenergydrv.sys
07/16/2016  07:41 AM            83,456 hdaudbus.sys
07/16/2016  07:41 AM           410,624 HdAudio.sys
07/16/2016  07:41 AM            36,704 hidbatt.sys
07/16/2016  07:41 AM           108,032 hidbth.sys
10/14/2016  11:55 PM           156,672 hidclass.sys
07/16/2016  07:41 AM            51,200 hidi2c.sys
07/16/2016  07:41 AM            50,016 hidinterrupt.sys
07/16/2016  07:41 AM            46,592 hidir.sys
09/23/2016  03:53 PM            40,960 hidparse.sys
09/23/2016  03:53 PM            38,400 hidusb.sys
07/16/2016  07:41 AM            64,352 HpSAMD.sys
08/08/2017  01:45 AM         1,102,176 http.sys
09/23/2016  03:53 PM            73,568 hvservice.sys
03/04/2017  03:07 AM           110,944 hvsocket.sys
07/16/2016  07:42 AM            29,536 hwpolicy.sys
07/16/2016  07:41 AM            16,384 hyperkbd.sys
07/27/2015  01:37 AM            41,760 I2cHkBurn.sys
07/16/2016  07:41 AM           114,176 i8042prt.sys
07/16/2016  07:41 AM            33,280 iagpio.sys
07/16/2016  07:41 AM            81,408 iai2c.sys
07/16/2016  07:41 AM            64,512 iaLPSS2i_GPIO2.sys
07/16/2016  07:41 AM           176,384 iaLPSS2i_I2C.sys
07/16/2016  07:41 AM            38,128 iaLPSSi_GPIO.sys
07/16/2016  07:41 AM           113,152 iaLPSSi_I2C.sys
07/16/2016  07:41 AM           673,120 iaStorAV.sys
07/16/2016  07:41 AM           412,000 iaStorV.sys
07/16/2016  07:41 AM           526,176 ibbus.sys
09/24/2015  12:51 AM            38,680 ICCWDT.sys
07/16/2016  07:42 AM            35,840 IndirectKmd.sys
07/16/2016  07:41 AM            19,296 intelide.sys
07/10/2015  11:29 PM            18,720 IntelMEFWVer.dll
07/16/2016  07:41 AM            48,152 intelpep.sys
07/16/2016  07:41 AM           134,144 intelppm.sys
11/02/2016  06:55 AM            48,992 iorate.sys
07/16/2016  07:42 AM            85,504 ipfltdrv.sys
03/04/2017  03:24 AM            90,976 IPMIDrv.sys
07/16/2016  07:42 AM           212,480 ipnat.sys
07/16/2016  07:42 AM           120,320 irda.sys
07/16/2016  07:42 AM            19,456 irenum.sys
07/16/2016  07:41 AM            22,880 isapnp.sys
09/20/2017  02:37 PM            79,064 jbbn.sys
07/16/2016  07:41 AM            62,304 kbdclass.sys
09/15/2016  12:43 PM            39,424 kbdhid.sys
07/16/2016  07:41 AM            25,088 kdnic.sys
03/04/2017  02:28 AM           394,752 ks.sys
08/08/2017  02:06 AM           133,984 ksecdd.sys
09/07/2017  01:58 AM           168,800 ksecpkg.sys
07/16/2016  07:42 AM            26,112 ksthunk.sys
04/15/2013  02:51 PM           410,008 ladfGSCamd64.sys
04/15/2013  02:51 PM           102,808 ladfGSRamd64.sys
06/10/2015  07:33 PM            37,408 LGBusEnum.sys
06/10/2015  07:33 PM            68,384 LGJoyXlCore.sys
05/30/2013  12:16 PM            64,280 LGSHidFilt.Sys
06/10/2015  07:33 PM            26,912 LGVirHid.sys
07/16/2016  07:42 AM            66,048 lltdio.sys
09/23/2016  11:56 AM            18,960 LNonPnP.sys
07/16/2016  07:41 AM           108,896 lsi_sas.sys
07/16/2016  07:41 AM           105,824 lsi_sas2i.sys
07/16/2016  07:41 AM           101,216 lsi_sas3i.sys
07/16/2016  07:41 AM            82,776 lsi_sss.sys
07/16/2016  07:42 AM           125,952 luafv.sys
08/24/2017  11:27 AM            77,440 mbae64.sys
09/20/2017  07:43 PM            45,472 mbam.sys
09/20/2017  06:58 PM           192,960 MBAMChameleon.sys
09/20/2017  07:34 PM           253,888 MBAMSwissArmy.sys
10/21/2016  02:16 PM            41,088 MBfilt64.sys
07/16/2016  07:42 AM            22,528 mcd.sys
07/16/2016  07:41 AM            59,744 megasas.sys
10/05/2016  06:09 AM            64,352 MegaSas2i.sys
07/16/2016  07:41 AM           575,840 megasr.sys
07/16/2016  07:41 AM           842,584 mlx4_bus.sys
07/16/2016  07:42 AM            48,128 mmcss.sys
11/11/2016  05:26 AM            42,496 modem.sys
07/16/2016  07:41 AM            38,400 monitor.sys
07/16/2016  07:41 AM            59,232 mouclass.sys
07/16/2016  07:41 AM            32,256 mouhid.sys
07/16/2016  07:42 AM           104,800 mountmgr.sys
07/16/2016  07:42 AM            75,776 mpsdrv.sys
10/05/2016  05:20 AM           143,872 mrxdav.sys
08/08/2017  01:52 AM           450,400 mrxsmb.sys
07/07/2017  02:39 AM           282,624 mrxsmb10.sys
07/12/2017  02:00 AM           223,072 mrxsmb20.sys
07/16/2016  07:42 AM            31,232 msfs.sys
10/30/2015  03:18 AM                 3 MsftWdf_Kernel_01017_Inbox_Critical.Wdf
07/16/2016  07:42 AM                 3 MsftWdf_Kernel_01019_Inbox_Critical.Wdf
07/16/2016  07:42 AM                 3 MsftWdf_User_01_11_00_Inbox_Critical.Wdf
07/16/2016  07:42 AM           168,800 msgpioclx.sys
07/16/2016  07:41 AM            50,528 msgpiowin32.sys
07/16/2016  07:42 AM             8,704 mshidkmdf.sys
07/16/2016  07:42 AM            11,776 mshidumdf.sys
09/20/2017  07:43 PM            81,696 msidntfs.sys
07/16/2016  07:41 AM            18,784 msisadrv.sys
07/12/2017  01:56 AM           277,856 msiscsi.sys
03/04/2017  02:36 AM            27,136 mskssrv.sys
07/16/2016  07:42 AM            78,336 mslldp.sys
07/16/2016  07:42 AM            10,752 mspclock.sys
07/16/2016  07:42 AM            10,752 mspqm.sys
07/16/2016  07:42 AM           361,312 msrpc.sys
07/16/2016  10:28 AM           179,040 mssecflt.sys
07/16/2016  07:41 AM            43,360 mssmbios.sys
07/16/2016  07:42 AM            12,800 mstee.sys
07/16/2016  07:41 AM            15,872 MTConfig.sys
06/21/2017  03:50 AM           126,304 mup.sys
07/16/2016  07:41 AM            63,840 mvumis.sys
09/20/2017  07:38 PM            94,144 mwac.sys
07/16/2016  07:41 AM           108,896 ndfltr.sys
07/12/2017  02:09 AM         1,181,024 ndis.sys
07/16/2016  07:42 AM            50,176 ndiscap.sys
07/16/2016  07:42 AM           126,464 NdisImPlatform.sys
07/16/2016  07:42 AM            26,112 ndistapi.sys
07/16/2016  07:42 AM            63,488 ndisuio.sys
07/16/2016  07:42 AM            20,480 NdisVirtualBus.sys
07/16/2016  07:42 AM           189,440 ndiswan.sys
07/16/2016  07:42 AM            60,928 ndproxy.sys
07/16/2016  07:42 AM           125,440 Ndu.sys
01/16/2015  05:22 PM            23,040 netaapl64.sys
07/16/2016  07:42 AM            90,624 NetAdapterCx.sys
07/16/2016  07:42 AM            57,184 netbios.sys
09/07/2017  01:18 AM           279,040 netbt.sys
07/07/2017  03:37 AM           468,320 netio.sys
07/16/2016  07:42 AM            68,608 npfs.sys
07/16/2016  07:41 AM            26,624 npsvctrig.sys
09/07/2017  01:20 AM            77,824 nsiproxy.sys
08/08/2017  02:03 AM         2,253,664 ntfs.sys
07/16/2016  07:43 AM            19,296 ntosext.sys
07/16/2016  07:42 AM             7,168 null.sys
07/16/2016  07:41 AM           150,368 nvraid.sys
07/16/2016  07:41 AM           166,240 nvstor.sys
03/04/2017  02:30 AM           535,552 nwifi.sys
07/12/2017  02:00 AM           160,608 pacer.sys
07/16/2016  07:41 AM            96,768 parport.sys
03/04/2017  03:20 AM           128,352 partmgr.sys
12/14/2016  01:18 AM           335,712 pci.sys
07/16/2016  07:41 AM            16,224 pciide.sys
07/16/2016  07:41 AM            52,576 pciidex.sys
07/16/2016  07:41 AM           118,112 pcmcia.sys
07/16/2016  07:42 AM            51,552 pcw.sys
07/07/2017  03:44 AM           108,896 pdc.sys
07/16/2016  07:42 AM           723,968 PEAuth.sys
07/16/2016  07:41 AM            58,720 percsas2i.sys
07/16/2016  07:41 AM            61,792 percsas3i.sys
07/16/2016  07:41 AM           366,592 portcls.sys
07/16/2016  07:41 AM           119,808 processr.sys
09/20/2017  02:13 PM            79,064 qpsx.sys
07/16/2016  07:42 AM            48,640 qwavedrv.sys
07/16/2016  07:42 AM            17,408 rasacd.sys
07/16/2016  07:42 AM           104,960 rasl2tp.sys
04/27/2017  08:03 PM            81,408 raspppoe.sys
07/16/2016  07:42 AM            96,256 raspptp.sys
07/16/2016  07:42 AM            77,824 rassstp.sys
04/27/2017  08:38 PM           431,968 rdbss.sys
07/16/2016  10:29 AM            26,112 rdpbus.sys
07/16/2016  10:27 AM           177,152 rdpdr.sys
07/16/2016  10:28 AM            29,536 rdpvideominiport.sys
07/16/2016  07:42 AM           267,104 rdyboost.sys
07/16/2016  07:42 AM           928,608 refsv1.sys
07/16/2016  07:42 AM            70,144 registry.sys
07/16/2016  07:41 AM            39,936 RfxVmt.sys
07/16/2016  07:42 AM           147,968 rmcast.sys
07/16/2016  07:42 AM            34,304 RNDISMP.sys
06/21/2017  03:03 AM            13,312 rootmdm.sys
07/16/2016  07:42 AM            81,408 rspndr.sys
01/05/2017  03:07 AM         9,120,792 RTAIODAT.DAT
01/05/2017  09:31 AM         5,542,400 RTKVHD64.sys
07/16/2016  07:41 AM           110,432 sbp2port.sys
07/16/2016  07:42 AM            43,008 scfilter.sys
06/21/2017  03:52 AM            88,416 scmbus.sys
07/12/2017  01:24 AM           124,928 scmdisk0101.sys
07/16/2016  07:42 AM           173,408 scsiport.sys
06/03/2017  06:16 AM           279,904 sdbus.sys
07/16/2016  07:42 AM            95,584 sdport.sys
07/12/2017  02:00 AM            95,584 sdstor.sys
07/16/2016  07:42 AM            74,592 SerCx.sys
07/16/2016  07:42 AM           151,904 SerCx2.sys
07/16/2016  07:41 AM            25,088 serenum.sys
07/16/2016  07:41 AM            83,968 serial.sys
07/16/2016  07:41 AM            27,648 sermouse.sys
05/15/2016  09:24 PM           497,664 SET1F99.tmp
10/21/2016  02:16 PM         5,371,912 SET2739.tmp
04/03/2016  09:31 PM           676,864 SET2D3D.tmp
07/16/2016  07:41 AM            41,472 SET3E17.tmp
07/16/2016  07:41 AM            56,320 SET3E28.tmp
03/21/2016  09:57 AM           102,400 SET4755.tmp
01/22/2016  08:01 AM           679,952 SETB28C.tmp
03/27/2016  12:56 PM           685,584 SETC562.tmp
09/17/2015  08:38 PM           102,912 SETD0D1.tmp
05/15/2016  09:35 PM           101,376 SETFB21.tmp
07/16/2016  07:41 AM            18,432 sfloppy.sys
07/16/2016  07:41 AM            44,896 sisraid2.sys
07/16/2016  07:41 AM            81,760 sisraid4.sys
07/16/2016  07:42 AM            22,016 smclib.sys
08/08/2017  01:53 AM           557,408 spaceport.sys
07/16/2016  07:42 AM            79,200 SpbCx.sys
04/27/2017  07:51 PM           409,600 srv.sys
04/27/2017  07:51 PM           713,216 srv2.sys
09/07/2017  01:03 AM           248,320 srvnet.sys
07/16/2016  07:41 AM            31,072 stexstor.sys
03/04/2017  03:08 AM           130,912 storahci.sys
07/12/2017  02:17 AM            81,760 stornvme.sys
06/03/2017  05:49 AM           509,280 storport.sys
07/16/2016  07:42 AM            78,336 storqosflt.sys
07/16/2016  07:41 AM            32,096 storufs.sys
07/16/2016  07:41 AM            36,192 storvsc.sys
07/16/2016  07:42 AM            74,240 stream.sys
07/16/2016  07:41 AM            17,760 swenum.sys
07/16/2016  07:41 AM            64,000 Synth3dVsc.sys
07/16/2016  07:42 AM            30,720 tape.sys
07/16/2016  07:42 AM            26,976 tbs.sys
09/07/2017  01:45 AM         2,532,704 tcpip.sys
07/07/2017  02:46 AM            52,224 tcpipreg.sys
07/16/2016  07:42 AM            40,288 tdi.sys
08/08/2017  01:59 AM           118,112 tdx.sys
07/07/2015  08:45 PM           184,608 TeeDriverW8x64.sys
07/16/2016  10:29 AM            38,752 terminpt.sys
06/03/2017  06:11 AM           128,864 tm.sys
11/11/2016  06:00 AM           219,488 tpm.sys
07/16/2016  07:42 AM            61,440 TsUsbFlt.sys
07/16/2016  07:41 AM            34,304 TsUsbGD.sys
07/16/2016  10:28 AM           123,392 tsusbhub.sys
07/16/2016  07:42 AM           158,208 tunnel.sys
07/16/2016  07:41 AM            77,152 uaspstor.sys
07/16/2016  07:42 AM            95,744 UcmCx.sys
07/16/2016  07:42 AM           108,544 UcmTcpciCx.sys
07/16/2016  07:41 AM            50,688 UcmUcsi.sys
07/16/2016  07:42 AM           210,272 Ucx01000.sys
07/16/2016  07:42 AM            45,568 Udecx.sys
07/16/2016  07:42 AM           320,000 udfs.sys
07/16/2016  07:41 AM            28,512 uefi.sys
07/16/2016  10:28 AM            40,288 UevAgentDriver.sys
07/16/2016  07:42 AM           263,008 ufx01000.sys
07/16/2016  07:41 AM            96,608 UfxChipidea.sys
07/16/2016  07:41 AM           137,056 ufxsynopsys.sys
07/16/2016  07:41 AM            56,832 umbus.sys
05/13/2017  01:08 PM    <DIR>          UMDF
07/16/2016  07:41 AM            13,824 umpass.sys
07/16/2016  07:41 AM            28,512 urschipidea.sys
07/16/2016  07:42 AM            57,696 urscx01000.sys
07/16/2016  07:41 AM            27,488 urssynopsys.sys
07/16/2016  07:42 AM            23,040 usb8023.sys
06/10/2015  11:08 PM            54,784 usbaapl64.sys
07/16/2016  07:41 AM           132,096 USBAUDIO.sys
07/16/2016  07:42 AM            36,864 USBCAMD2.sys
07/16/2016  07:41 AM           169,312 usbccgp.sys
07/16/2016  07:41 AM           102,400 usbcir.sys
07/16/2016  07:41 AM            32,608 usbd.sys
07/16/2016  07:41 AM            96,096 usbehci.sys
07/16/2016  07:41 AM           501,088 usbhub.sys
07/16/2016  07:41 AM           535,904 USBHUB3.SYS
07/16/2016  07:41 AM            30,208 usbohci.sys
07/16/2016  07:41 AM           455,520 usbport.sys
07/16/2016  07:41 AM            27,648 usbprint.sys
07/16/2016  07:43 AM            32,256 usbrpm.sys
07/16/2016  07:41 AM            69,120 usbser.sys
06/21/2017  03:36 AM           129,888 USBSTOR.SYS
07/16/2016  07:41 AM            35,328 usbuhci.sys
06/03/2017  05:50 AM           381,792 USBXHCI.SYS
07/16/2016  07:41 AM            53,088 vdrvroot.sys
07/16/2016  07:42 AM           201,056 VerifierExt.sys
08/08/2017  01:53 AM           715,104 vhdmp.sys
07/16/2016  07:42 AM            32,256 vhf.sys
07/16/2016  07:42 AM            50,176 videoprt.sys
08/08/2017  01:52 AM            79,712 vmbkmcl.sys
08/08/2017  01:20 AM            80,896 vmbkmclr.sys
07/16/2016  07:41 AM           104,288 vmbus.sys
07/16/2016  07:41 AM            25,088 VMBusHID.sys
07/16/2016  07:41 AM            13,312 vmgencounter.sys
07/16/2016  07:41 AM            10,240 vmgid.sys
07/16/2016  07:41 AM             9,216 vms3cap.sys
07/16/2016  07:41 AM            46,944 vmstorfl.sys
07/16/2016  07:41 AM            80,224 volmgr.sys
07/16/2016  07:42 AM           367,456 volmgrx.sys
07/16/2016  07:42 AM           391,520 volsnap.sys
07/16/2016  07:41 AM            16,224 volume.sys
09/15/2016  01:29 PM            74,080 vpci.sys
07/16/2016  07:41 AM           166,752 vsmraid.sys
07/16/2016  07:41 AM           305,504 VSTXRAID.SYS
07/16/2016  07:42 AM            26,624 vwifibus.sys
07/16/2016  07:42 AM            73,216 vwififlt.sys
04/27/2017  08:02 PM            40,448 vwifimp.sys
07/16/2016  07:41 AM            30,208 wacompen.sys
07/16/2016  07:42 AM            79,872 wanarp.sys
07/16/2016  07:42 AM            56,320 watchdog.sys
09/15/2016  01:14 PM           119,648 wcifs.sys
07/12/2017  01:25 AM            66,560 wcnfs.sys
07/16/2016  07:43 AM            44,056 WdBoot.sys
11/12/2015  11:50 PM            26,880 wdcsam64.sys
07/16/2016  07:42 AM           861,296 Wdf01000.sys
07/16/2016  07:43 AM           290,144 WdFilter.sys
07/16/2016  07:42 AM            61,040 WdfLdr.sys
06/21/2017  02:56 AM           719,872 WdiWiFi.sys
07/16/2016  07:43 AM           123,232 WdNisDrv.sys
07/16/2016  07:42 AM            39,776 werkernel.sys
07/12/2017  02:01 AM           156,000 wfplwfs.sys
07/16/2016  07:42 AM            35,680 wimmount.sys
07/16/2016  07:42 AM           107,032 WindowsTrustedRT.sys
07/16/2016  07:41 AM            17,944 WindowsTrustedRTProxy.sys
07/16/2016  07:42 AM            31,584 winhv.sys
09/15/2016  12:42 PM            51,712 winhvr.sys
07/16/2016  07:41 AM            32,096 winmad.sys
07/16/2016  07:41 AM            89,088 winusb.sys
07/16/2016  07:41 AM            64,864 winverbs.sys
07/16/2016  07:41 AM            18,432 wmiacpi.sys
07/16/2016  07:42 AM            20,320 wmilib.sys
09/20/2017  02:26 PM            79,064 wnbynmak.sys
09/23/2016  03:50 PM           199,008 wof.sys
07/16/2016  07:44 AM            30,560 WpdUpFltr.sys
07/16/2016  07:42 AM            31,584 WppRecorder.sys
07/16/2016  07:42 AM            22,528 ws2ifsl.sys
07/16/2016  07:41 AM            22,528 WSDPrint.sys
07/16/2016  07:42 AM            99,328 WUDFPf.sys
07/16/2016  07:42 AM           216,064 WUDFRd.sys
03/04/2017  02:34 AM           258,560 xboxgip.sys
09/23/2016  03:53 PM            43,520 xinputhid.sys
07/10/2015  03:48 PM            63,840 XtuAcpiDriver.sys
09/20/2017  04:31 PM            79,064 xvdygxd.sys
09/20/2017  03:37 PM            79,064 ykbobn.sys
             433 File(s)    124,020,219 bytes
               5 Dir(s)  113,477,664,768 bytes free

========= End of CMD: =========


==== End of Fixlog 20:15:33 ====

Link to post
Share on other sites

Good. Follow the instructions below.

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Recovery Environment Scan
Follow the instructions below to download and execute a scan on your system with FRST from the Recovery Environment, and provide the logs in your next reply.

Item(s) required:

  • USB Flash Drive (size depend on if you have to create a USB Recovery or Installation media)
  • CD/DVD (optional: only needed if you need to create a Recovery or Installation media and your USB Flash Drive is too small)
  • Another computer (optional: only needed if you cannot work from the infected computer directly)

Preparing the USB Flash Drive

  • Download the right version of FRST for your system:
  • Move the executable (FRST.exe or FRST64.exe) on your USB Flash Drive
  • Download the attached fixlist.txt, and move it on your USB Flash Drive as well

Boot in the Recovery Environment

  • Plug your USB Flash Drive in the infected computer
  • To enter the Recovery Environment with Windows Vista and Windows 7, follow the instructions below:
    • Restart the computer
    • Once you've seen your BIOS splashscreen (the computer manufacturer logo), tap the F8 key repeatedly until the Advanced Boot Options menu appears
    • Use the arrow keys to select Repair your computer, and press on Enter
    • Select your keyboard layout (US, French, etc.) and click on Next
    • Click on Command Prompt to open the command prompt
      Note:If you can't access the Recovery Environment using the F8 method above, you'll need to create a Windows installation or repair media. It can be made on the computer itself or another one running the same version of Windows as the one you plan to use it on. For more information, check out this tutorial on SevenForums.
  • To enter the Recovery Environment with Windows 8 or Windows 8.1, follow the instructions in this tutorial on EightForums
    Note:If you can't access the Recovery Environment using the method above, you'll need to create a Windows installation or repair media. It can be made on the computer itself or another one running the same version of Windows as the one you plan to use it on. For more information, check out this tutorial.
  • To enter the Recovery Environment with Windows 10, follow the instructions in this tutorial on TenForums
    Note:If you can't access the Recovery Environment using the method above, you'll need to create a Windows installation or repair media. It can be made on the computer itself or another one running the same version of Windows as the one you plan to use it on. For more information, check out this tutorial on TenForums.

Once in the command prompt

  • In the command prompt, type notepad and press on Enter
  • Notepad will open. Click on the File menu and select Open
  • Click on Computer/This PC, find the letter for your USB Flash Drive, then close the window and Notepad
  • In the command prompt, type e:\frst.exe (for the x64 version, type e:\frst64.exe and press on Enter
  • Note: Replace the letter e with the drive letter of your USB Flash Drive
  • FRST will open
  • Click on Yes to accept the disclaimer
  • Click on the Fix button and wait for the scan to complete
  • A log called fixlog.txt will be saved on your USB Flash Drive. Attach it in your next reply

fixlist.txt

Link to post
Share on other sites

How did you enable the legacy F8 boot menu? The fix I made you run above should've enabled it.

========= bcdedit.exe /set {default} recoveryenabled yes =========

The operation completed successfully.

Also now you should be able to install and run a scan with Malwarebytes.

j1Bynr2.pngMalwarebytes - Clean Mode

  • Download and install the free version of Malwarebytes
    Note: If you have Malwarebytes already installed, you don't need to install it again. Simply start from the next bullet point
  • Once Malwarebytes is installed, launch it and let it update his database. You might have to click on the little arrow by Scan Status in the middle right pane for it to do so
  • Click on the Settings tab, then go to the Protection one and enable Scan for rootkits
  • Once the database update is complete, click on the Scan tab, then select the Threat Scan button and click on Start Scan
  • Let the scan run, the time required to complete the scan depends of your system and computer specs
  • Once the scan is complete, make sure that the first checkbox at the top is checked (which will automatically check every detected item), then click on the Quarantine Selected button
    • If it asks you to restart your computer to complete the removal, do so
  • Click on Export Summary after the deletion (in the bottom-left corner) and select Copy to Clipboard. Paste the content in your next reply
Link to post
Share on other sites

Oh I see. So you did {bootmgr} instead of {default}. Interesting. I'll keep that in mind for the next user that tells me that he's unable to access the F8 options. Because the command that runs in the fix works for 50% of the users, and doesn't work for the other 50% and I always wondered why.

Link to post
Share on other sites

Yup, these were removed with the 1st FRST fix :) Now let's do a sweep with AdwCleaner and RogueKiller.

zcMPezJ.pngAdwCleaner - Fix Mode

  • Download AdwCleaner and move it to your Desktop
  • Right-click on AdwCleaner.exe and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Accept the EULA (I accept), then click on Scan
  • Let the scan complete. Once it's done, make sure that every item listed in the different tabs is checked and click on the Clean button. This will kill all active processes
    V7SD4El.png
  • Once the cleaning process is complete, AdwCleaner will ask to restart your computer, do it
  • After the restart, a log will open when logging in. Please copy/paste the content of that log in your next reply

RQKuhw1.pngRogueKiller

  • Download the right version of RogueKiller for your Windows version (32 or 64-bit)
  • Once done, move the executable file to your Desktop, right-click on it and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Click on the Start Scan button in the right panel, which will bring you to another tab, and click on it again (this time it'll be in the bottom right corner)
  • Wait for the scan to complete
  • On completion, the results will be displayed
  • Check every single entry (threat found), and click on the Remove Selected button
  • On completion, the results will be displayed. Click on the Open Report button in the bottom left corner, followed by the Open TXT button (also in the bottom left corner)
  • This will open the report in Notepad. Copy/paste its content in your next reply

Your next reply(ies) should therefore contain:

  • Copy/pasted AdwCleaner clean log
  • Copy/pasted RogueKiller clean log

Link to post
Share on other sites

# AdwCleaner 7.0.2.1 - Logfile created on Thu Sep 21 02:45:24 2017
# Updated on 2017/29/08 by Malwarebytes 
# Running on Windows 10 Pro (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services deleted.

***** [ Folders ] *****

No malicious folders deleted.

***** [ Files ] *****

No malicious files deleted.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks deleted.

***** [ Registry ] *****

Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}


***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries deleted.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries deleted.

*************************

::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0

*************************

C:/AdwCleaner/AdwCleaner[C0].txt - [1656 B] - [2017/9/20 21:22:34]
C:/AdwCleaner/AdwCleaner[S0].txt - [1572 B] - [2017/9/20 21:15:7]
C:/AdwCleaner/AdwCleaner[S1].txt - [1245 B] - [2017/9/21 2:42:26]


########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt ##########

 

Link to post
Share on other sites

In that case, let's move on to FRST. Follow the instructions below.

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Scan mode
Follow the instructions below to download and execute a scan on your system with FRST, and provide the logs in your next reply.

  • Right-click on the executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Accept the disclaimer by clicking on Yes, and FRST will then do a back-up of your Registry which should take a few seconds
  • Click on the Scan button
  • On completion, two message box will open, saying that the results were saved to FRST.txt and Addition.txt, then open two Notepad files
  • Copy and paste the content of both FRST.txt and Addition.txt in your next reply

Link to post
Share on other sites

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-09-2017
Ran by SpenserB (administrator) on SPENSER (20-09-2017 23:24:32)
Running from C:\Users\SpenserB\Desktop
Loaded Profiles: SpenserB (Available Profiles: SpenserB)
Platform: Windows 10 Pro Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe
() C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe
(Rivet Networks) C:\Program Files\Killer Networking\Network Manager\KillerService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe
(MSI) C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe
(MSI) C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe
(MICRO-STAR INTERNATIONAL CO., LTD.) C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe
(MSI) C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(MSI) C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe
(Electronic Arts) D:\Origin\OriginWebHelperService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\VideoCardMonitorII.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\EyeRest.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\TriggerModeMonitor.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey.exe
(MSI) C:\Windows\SysWOW64\muachost.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(BitTorrent Inc.) C:\Users\SpenserB\AppData\Roaming\uTorrent\uTorrent.exe
(Spotify Ltd) C:\Users\SpenserB\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(BitTorrent Inc.) C:\Users\SpenserB\AppData\Roaming\uTorrent\updates\3.5.0_43916\utorrentie.exe
(BitTorrent Inc.) C:\Users\SpenserB\AppData\Roaming\uTorrent\updates\3.5.0_43916\utorrentie.exe
(Micro-Star INT'L CO.,LTD.) C:\Program Files (x86)\MSI\Fast Boot\FastBoot.exe
(GOG.com) C:\Program Files (x86)\GOG Galaxy\GalaxyClient.exe
(GOG.com) C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe
(GOG.com) C:\Program Files (x86)\GOG Galaxy\GalaxyClient Helper.exe
(GOG.com) C:\Program Files (x86)\GOG Galaxy\GOG Galaxy Notifications Renderer.exe
(GOG.com) C:\Program Files (x86)\GOG Galaxy\GalaxyClient Helper.exe
(GOG.com) C:\Program Files (x86)\GOG Galaxy\GalaxyClient Helper.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel(R) Corporation) C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\XtuService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Spotify Ltd) C:\Users\SpenserB\AppData\Roaming\Spotify\Spotify.exe
(Spotify Ltd) C:\Users\SpenserB\AppData\Roaming\Spotify\Spotify.exe
(Spotify Ltd) C:\Users\SpenserB\AppData\Roaming\Spotify\Spotify.exe
(Spotify Ltd) C:\Users\SpenserB\AppData\Roaming\Spotify\Spotify.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft® Windows® Operating System) C:\Windows\System32\Taskmgr.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9192960 2017-01-05] (Realtek Semiconductor)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [14601160 2015-07-01] (Logitech Inc.)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2017-04-27] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] => D:\iTunes\iTunesHelper.exe [176440 2016-09-09] (Apple Inc.)
HKLM-x32\...\Run: [Command Center] => C:\Program Files (x86)\MSI\Command Center\StartCommandCenter.exe [835680 2016-06-14] (MSI)
HKLM-x32\...\Run: [Fast Boot] => C:\Program Files (x86)\MSI\Fast Boot\StartFastBoot.exe [759120 2015-04-22] ()
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-103190811-3506236208-3295715728-1001\...\Run: [GoogleChromeAutoLaunch_064C9B99C2D3F816C72AD15A5BF9F5D9] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1301848 2017-08-23] (Google Inc.)
HKU\S-1-5-21-103190811-3506236208-3295715728-1001\...\Run: [Steam] => D:\Steam\steam.exe [3099424 2017-09-19] (Valve Corporation)
HKU\S-1-5-21-103190811-3506236208-3295715728-1001\...\Run: [Google Update] => C:\Users\SpenserB\AppData\Local\Google\Update\1.3.33.5\GoogleUpdateCore.exe [601168 2017-05-01] (Google Inc.)
HKU\S-1-5-21-103190811-3506236208-3295715728-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27250144 2016-12-20] (Skype Technologies S.A.)
HKU\S-1-5-21-103190811-3506236208-3295715728-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [25622168 2017-08-31] (Google)
HKU\S-1-5-21-103190811-3506236208-3295715728-1001\...\Run: [uTorrent] => C:\Users\SpenserB\AppData\Roaming\uTorrent\uTorrent.exe [2146496 2017-07-09] (BitTorrent Inc.)
HKU\S-1-5-21-103190811-3506236208-3295715728-1001\...\Run: [GalaxyClient] => C:\Program Files (x86)\GOG Galaxy\GalaxyClient.exe [5161536 2017-09-08] (GOG.com)
HKU\S-1-5-21-103190811-3506236208-3295715728-1001\...\Run: [Spotify] => C:\Users\SpenserB\AppData\Roaming\Spotify\Spotify.exe [20644976 2017-09-18] (Spotify Ltd)
HKU\S-1-5-21-103190811-3506236208-3295715728-1001\...\Run: [Spotify Web Helper] => C:\Users\SpenserB\AppData\Roaming\Spotify\SpotifyWebHelper.exe [777840 2017-09-18] (Spotify Ltd)
HKU\S-1-5-21-103190811-3506236208-3295715728-1001\...\MountPoints2: {745cd2b4-764b-11e7-8321-d8cb8a5e9855} - "E:\DT4000G2_Launcher.exe" 
HKU\S-1-5-18\...\RunOnce: [Application Restart #3] => C:\MSI\LiveUpdate\DL_FILE\Liveinst.exe [2959872 2016-12-02] (Micro-Star INT'L CO., LTD.)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\Parameters: [NameServer] 8.8.8.8,8.8.8.4
Tcpip\..\Interfaces\{b82b50d0-0f91-4708-bb79-ccd72634f7df}: [DhcpNameServer] 192.168.1.254
ManualProxies: 

Internet Explorer:
==================

FireFox:
========
FF DefaultProfile: ctlak5dm.default
FF ProfilePath: C:\Users\SpenserB\AppData\Roaming\Mozilla\Firefox\Profiles\ctlak5dm.default [2017-09-20]
FF Plugin: @videolan.org/vlc,version=2.2.6 -> E:\VLC\npvlc.dll [No File]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-01] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-01] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin HKU\S-1-5-21-103190811-3506236208-3295715728-1001: @tools.google.com/Google Update;version=3 -> C:\Users\SpenserB\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-01] (Google Inc.)
FF Plugin HKU\S-1-5-21-103190811-3506236208-3295715728-1001: @tools.google.com/Google Update;version=9 -> C:\Users\SpenserB\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-01] (Google Inc.)

Chrome: 
=======
CHR HomePage: Default -> hxxp://www.facebook.com/
CHR StartupUrls: Default -> "hxxp://www.google.com"
CHR Profile: C:\Users\SpenserB\AppData\Local\Google\Chrome\User Data\Default [2017-09-20]
CHR Extension: (Google Slides) - C:\Users\SpenserB\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-09]
CHR Extension: (Google Drive) - C:\Users\SpenserB\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-23]
CHR Extension: (YouTube) - C:\Users\SpenserB\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Honey) - C:\Users\SpenserB\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2017-09-20]
CHR Extension: (uBlock Origin) - C:\Users\SpenserB\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2017-09-08]
CHR Extension: (Google Search) - C:\Users\SpenserB\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28]
CHR Extension: (Gmail Offline) - C:\Users\SpenserB\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk [2015-08-09]
CHR Extension: (Google Calendar) - C:\Users\SpenserB\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2017-01-07]
CHR Extension: (Google Docs Offline) - C:\Users\SpenserB\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (Auto Refresh) - C:\Users\SpenserB\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifooldnmmcmlbdennkpdnlnbgbmfalko [2017-07-14]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\SpenserB\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2017-09-17]
CHR Extension: (Google Voice (by Google)) - C:\Users\SpenserB\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcnhkahnjcbndmmehfkdnkjomaanaooo [2016-03-01]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\SpenserB\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2016-07-02]
CHR Extension: (Ghostery) - C:\Users\SpenserB\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2017-09-01]
CHR Extension: (Chrome Web Store Payments) - C:\Users\SpenserB\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-27]
CHR Extension: (Gmail) - C:\Users\SpenserB\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-09]
CHR Extension: (Chrome Media Router) - C:\Users\SpenserB\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-08]
CHR Profile: C:\Users\SpenserB\AppData\Local\Google\Chrome\User Data\System Profile [2015-08-09]
CHR HKU\S-1-5-21-103190811-3506236208-3295715728-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-08-05] (Apple Inc.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1317920 2016-02-04] ()
S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [400656 2017-02-09] (EasyAntiCheat Ltd)
S3 GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [532544 2017-09-08] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [8242752 2017-08-27] (GOG.com)
R2 GamingApp_Service; C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe [47056 2017-07-13] (Micro-Star Int'l Co., Ltd.)
R2 GamingHotkey_Service; C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe [2019792 2016-10-13] (Micro-Star INT'L CO., LTD.)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation)
S3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed]
R2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [223520 2015-07-10] (Intel Corporation)
R2 Killer Service V2; C:\Program Files\Killer Networking\Network Manager\KillerService.exe [454872 2016-01-28] (Rivet Networks)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-07] (Malwarebytes)
S3 MSIClock_CC; C:\Program Files (x86)\MSI\Command Center\ClockGen\MSIClockService.exe [4163680 2016-09-09] (MSI)
S3 MSICOMM_CC; C:\Program Files (x86)\MSI\Command Center\MSICommService.exe [2206304 2017-01-06] (MSI)
S3 MSICPU_CC; C:\Program Files (x86)\MSI\Command Center\CPU\MSICPUService.exe [4172896 2016-12-14] (MSI)
R2 MSICTL_CC; C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe [2102880 2017-02-15] (MSI)
R2 MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe [2331744 2017-02-15] (MSI)
S3 MSISMB_CC; C:\Program Files (x86)\MSI\Command Center\SMBus\MSISMBService.exe [2076768 2016-12-05] (MSI)
S3 MSISuperIO_CC; C:\Program Files (x86)\MSI\Command Center\SuperIO\MSISuperIOService.exe [611936 2017-02-10] (MSI)
R2 MSI_ActiveX_Service; C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe [80824 2017-06-30] (Micro-Star INT'L CO., LTD.)
R2 MSI_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe [111568 2017-04-05] (MSI)
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe [174032 2017-04-28] (MSI)
R2 MSI_Trigger_Service; C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe [30240 2013-09-26] (MICRO-STAR INTERNATIONAL CO., LTD.)
S3 Origin Client Service; D:\Origin\OriginClientService.exe [2098528 2017-09-20] (Electronic Arts)
R2 Origin Web Helper Service; D:\Origin\OriginWebHelperService.exe [2977640 2017-09-20] (Electronic Arts)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2017-08-08] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-27] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2017-08-08] (Microsoft Corporation)
R2 XTU3SERVICE; C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\XtuService.exe [19192 2015-10-06] (Intel(R) Corporation)
S2 amdacpusrsvc; "C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe" [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S0 amdkmafd; C:\WINDOWS\System32\drivers\amdkmafd.sys [49448 2016-08-18] (Advanced Micro Devices, Inc.)
R3 amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0317685.inf_amd64_f4ed8f05a31c5d2d\atikmdag.sys [38761496 2017-09-07] (Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0317685.inf_amd64_f4ed8f05a31c5d2d\atikmpag.sys [541720 2017-09-07] (Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [101376 2016-12-08] (Advanced Micro Devices)
R1 BfLwf; C:\WINDOWS\system32\DRIVERS\bwcW10x64.sys [144456 2016-01-22] (Rivet Networks, LLC.)
S3 dot4; C:\WINDOWS\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\WINDOWS\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
R1 epp; C:\EEK\bin64\epp.sys [124552 2016-11-23] (Emsisoft Ltd)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77440 2017-08-24] ()
R3 I2cHkBurn; C:\WINDOWS\system32\drivers\I2cHkBurn.sys [41760 2015-07-27] (FINTEK Corp.)
R2 iocbios2; C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [30224 2015-05-28] (Intel Corporation)
S3 ipadtst; C:\Program Files (x86)\MSI\Super Charger\ipadtst_64.sys [20464 2013-11-11] (Windows (R) Win 7 DDK provider)
S3 ipadtst2; C:\Program Files (x86)\MSI\Super Charger\ipadtst2_64.sys [16336 2016-07-29] (MSI)
R3 KillerEth; C:\WINDOWS\System32\drivers\e22w10x64.sys [156744 2015-10-07] (Qualcomm Atheros, Inc.)
R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech)
R3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore.sys [68384 2015-06-10] (Logitech Inc.)
R3 LGSHidFilt; C:\WINDOWS\system32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
R0 MBAMChameleon; C:\WINDOWS\System32\drivers\MBAMChameleon.sys [192960 2017-09-20] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\DRIVERS\farflt.sys [101824 2017-09-20] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [45472 2017-09-20] (Malwarebytes)
R4 MBAMSwissArmy; C:\WINDOWS\system32\drivers\4C1F4C85.sys [253888 2017-09-20] (Malwarebytes)
S3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [94144 2017-09-20] (Malwarebytes)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 NTIOLib_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\NTIOLib_X64.sys [14288 2017-03-29] (MSI)
R3 NTIOLib_MBAPI; C:\Program Files (x86)\MSI\Gaming APP\Lib\NTIOLib_X64.sys [14288 2017-07-10] (MSI)
R3 NTIOLib_MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\NTIOLib_X64.sys [13368 2012-11-26] (MSI)
R3 NTIOLib_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\NTIOLib_X64.sys [14288 2017-03-15] (MSI)
S3 pbfilter; C:\Program Files\PeerBlock\pbfilter.sys [22600 2014-01-04] ()
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
R3 XtuAcpiDriver; C:\WINDOWS\System32\drivers\XtuAcpiDriver.sys [63840 2015-07-10] (Intel Corporation)
S2 amdacpksd; \??\C:\WINDOWS\system32\drivers\amdacpksd.sys [X]
S3 BRDriver64_1_3_3_E02B25FC; \??\C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [X]
U0 Partizan; system32\drivers\Partizan.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-09-20 23:15 - 2017-09-20 23:15 - 035884000 _____ (Adlice Software ) C:\Users\SpenserB\Downloads\setup (1).exe
2017-09-20 23:01 - 2017-09-20 23:01 - 000000000 ____D C:\Users\SpenserB\AppData\LocalLow\uTorrent
2017-09-20 23:00 - 2017-09-20 23:00 - 000253888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\4C1F4C85.sys
2017-09-20 22:59 - 2017-09-20 23:00 - 000115024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cwanruxa.sys
2017-09-20 22:53 - 2017-09-20 22:53 - 026696776 _____ C:\Users\SpenserB\Downloads\RogueKiller_portable64.exe
2017-09-20 22:50 - 2017-09-20 22:50 - 035884000 _____ (Adlice Software ) C:\Users\SpenserB\Desktop\setup.exe
2017-09-20 22:31 - 2017-09-20 22:31 - 000001241 _____ C:\Users\SpenserB\Desktop\Scan Log 200917 2230.txt
2017-09-20 22:29 - 2017-09-20 22:29 - 000253888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\5CDD3438.sys
2017-09-20 22:23 - 2017-09-20 23:00 - 000101824 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2017-09-20 22:01 - 2017-09-20 22:23 - 000253888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\05B41F77.sys
2017-09-20 21:50 - 2017-09-20 21:50 - 000018432 _____ C:\WINDOWS\system32\UserMgrLog.etl
2017-09-20 21:49 - 2017-09-20 21:50 - 000012288 _____ C:\WINDOWS\system32\umstartup.etl
2017-09-20 21:42 - 2017-09-20 21:42 - 000253888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\242B1081.sys
2017-09-20 21:40 - 2017-09-20 21:40 - 000253888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\581E0EBB.sys
2017-09-20 21:36 - 2017-09-20 21:40 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2017-09-20 21:36 - 2017-09-20 21:36 - 000253888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\32DF0C3B.sys
2017-09-20 21:35 - 2017-09-20 21:35 - 000000000 ____D C:\WINDOWS\pss
2017-09-20 21:33 - 2017-09-20 21:33 - 000253888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\220B0959.sys
2017-09-20 21:27 - 2017-09-20 21:27 - 018357776 _____ (Microsoft Corporation) C:\Users\SpenserB\Downloads\MediaCreationTool.exe
2017-09-20 21:18 - 2017-09-20 21:18 - 000253888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\463A7E46.sys
2017-09-20 21:07 - 2017-09-20 21:07 - 000253888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\5F8C75CE.sys
2017-09-20 21:04 - 2017-09-20 21:04 - 000253888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\5E29736F.sys
2017-09-20 21:02 - 2017-09-20 21:02 - 000253888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\51A97211.sys
2017-09-20 20:58 - 2017-09-20 20:58 - 000253888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\66BC6F46.sys
2017-09-20 20:50 - 2017-09-20 20:50 - 000000000 ____D C:\$Windows.~WS
2017-09-20 20:42 - 2017-09-20 20:42 - 000253888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\4A3A6304.sys
2017-09-20 20:39 - 2017-09-20 20:39 - 000253888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\7F13606D.sys
2017-09-20 20:15 - 2017-09-20 20:15 - 000029482 _____ C:\Users\SpenserB\Desktop\Fixlog.txt
2017-09-20 20:14 - 2017-09-20 23:24 - 000022824 _____ C:\Users\SpenserB\Desktop\FRST.txt
2017-09-20 20:14 - 2017-09-20 20:14 - 000070329 _____ C:\Users\SpenserB\Desktop\Addition.txt
2017-09-20 19:43 - 2017-09-20 19:43 - 000253888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\745E3573.sys
2017-09-20 19:29 - 2017-09-20 19:43 - 000001120 _____ C:\WINDOWS\SysWOW64\PARTIZAN.TXT
2017-09-20 19:29 - 2017-09-20 19:29 - 000253888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\3C692A81.sys
2017-09-20 19:20 - 2017-09-20 19:20 - 000000000 ____D C:\@RestoreQuarantine
2017-09-20 19:13 - 2017-09-20 19:46 - 000000000 ____D C:\Program Files (x86)\UnHackMe
2017-09-20 19:13 - 2017-09-20 19:40 - 000000000 ____D C:\Users\SpenserB\Documents\RegRun2
2017-09-20 19:13 - 2017-09-20 19:35 - 000000000 ____D C:\ProgramData\RegRun
2017-09-20 19:13 - 2017-09-20 19:13 - 000000002 RSHOT C:\WINDOWS\winstart.bat
2017-09-20 19:13 - 2017-09-20 19:13 - 000000002 RSHOT C:\WINDOWS\SysWOW64\CONFIG.NT
2017-09-20 19:13 - 2017-09-20 19:13 - 000000002 RSHOT C:\WINDOWS\SysWOW64\AUTOEXEC.NT
2017-09-20 18:58 - 2017-09-20 23:00 - 000045472 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2017-09-20 18:58 - 2017-09-20 22:46 - 000253888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-09-20 18:58 - 2017-09-20 22:23 - 000192960 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
2017-09-20 18:58 - 2017-09-20 22:17 - 000094144 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2017-09-20 18:58 - 2017-09-20 18:58 - 000001912 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-09-20 18:58 - 2017-09-20 18:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-09-20 18:58 - 2017-09-20 18:58 - 000000000 ____D C:\ProgramData\Malwarebytes
2017-09-20 18:58 - 2017-09-20 18:58 - 000000000 ____D C:\Program Files\Malwarebytes
2017-09-20 18:58 - 2017-08-24 11:27 - 000077440 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-09-20 18:40 - 2017-09-20 18:40 - 000003160 _____ C:\WINDOWS\System32\Tasks\StartCN
2017-09-20 18:40 - 2017-09-20 18:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Settings
2017-09-20 18:39 - 2017-09-20 18:39 - 000000000 ____D C:\WINDOWS\LastGood
2017-09-20 18:38 - 2017-09-20 18:38 - 000000000 ____D C:\Users\SpenserB\AppData\LocalLow\AMD
2017-09-20 18:21 - 2017-09-20 18:21 - 000000000 ____D C:\ProgramData\Sophos
2017-09-20 18:18 - 2017-09-20 18:18 - 000002775 _____ C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
2017-09-20 18:18 - 2017-09-20 18:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2017-09-20 18:18 - 2017-09-20 18:18 - 000000000 ____D C:\Program Files (x86)\Sophos
2017-09-20 18:17 - 2017-09-20 18:17 - 176868624 _____ (Sophos Limited) C:\Users\SpenserB\Downloads\Sophos Virus Removal Tool.exe
2017-09-20 17:24 - 2017-09-20 17:24 - 000192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\2BA74ADF.sys
2017-09-20 16:58 - 2017-09-20 16:58 - 000070975 _____ C:\Users\SpenserB\Downloads\Addition.txt
2017-09-20 16:57 - 2017-09-20 23:24 - 000000000 ____D C:\FRST
2017-09-20 16:57 - 2017-09-20 16:58 - 000117561 _____ C:\Users\SpenserB\Downloads\FRST.txt
2017-09-20 16:57 - 2017-09-20 16:57 - 002399744 _____ (Farbar) C:\Users\SpenserB\Desktop\FRST64.exe
2017-09-20 16:37 - 2017-09-20 16:37 - 000000000 ____D C:\ProgramData\Emsisoft
2017-09-20 16:34 - 2017-09-20 16:34 - 000192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\4FC0249E.sys
2017-09-20 16:32 - 2017-09-20 17:06 - 000000000 ____D C:\EEK
2017-09-20 16:31 - 2017-09-20 16:31 - 329572272 _____ C:\Users\SpenserB\Downloads\EmsisoftEmergencyKit.exe
2017-09-20 16:30 - 2017-09-20 22:45 - 000000000 ____D C:\AdwCleaner
2017-09-20 16:29 - 2017-09-20 16:30 - 008182736 _____ (Malwarebytes) C:\Users\SpenserB\Downloads\adwcleaner_7.0.2.1.exe
2017-09-20 16:23 - 2017-09-20 16:23 - 000000017 _____ C:\Users\SpenserB\AppData\Local\resmon.resmoncfg
2017-09-20 16:19 - 2017-09-20 16:19 - 000126277 _____ C:\Users\SpenserB\Downloads\Scanning History Log 200917_1432.txt
2017-09-20 16:15 - 2017-09-20 16:15 - 000181883 _____ C:\Users\SpenserB\Downloads\Scanning History Log 200917_1432.xml
2017-09-20 16:06 - 2017-09-20 16:06 - 000000000 ____D C:\WINDOWS\system32\appmgmt
2017-09-20 15:58 - 2017-09-20 15:58 - 000000085 _____ C:\WINDOWS\wininit.ini
2017-09-20 15:44 - 2017-09-20 16:33 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2017-09-20 15:44 - 2017-09-20 15:58 - 000000000 ____D C:\ProgramData\Spybot - Search & Destroy
2017-09-20 15:44 - 2017-09-20 15:44 - 000000000 ____D C:\WINDOWS\System32\Tasks\Safer-Networking
2017-09-20 15:43 - 2017-09-20 15:44 - 051725936 _____ (Safer-Networking Ltd. ) C:\Users\SpenserB\Downloads\spybotsd-2.6.46.exe
2017-09-20 14:48 - 2017-09-20 14:48 - 016563352 _____ (Malwarebytes Corp.) C:\Users\SpenserB\Downloads\mbar-1.09.3.1001.exe
2017-09-20 14:45 - 2017-09-20 14:48 - 000192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\0FB25110.sys
2017-09-20 14:21 - 2017-09-20 14:21 - 000192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\33CC3ECC.sys
2017-09-20 14:02 - 2017-09-20 14:02 - 000192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\41ED3024.sys
2017-09-20 13:58 - 2017-09-20 13:58 - 000192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\654C2D14.sys
2017-09-20 13:58 - 2017-09-20 13:58 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2017-09-20 13:57 - 2017-09-20 13:57 - 000000000 ____D C:\Users\SpenserB\AppData\Local\AMDDriverProfiles
2017-09-20 13:55 - 2017-09-20 13:55 - 034890000 _____ (AMD Inc.) C:\Users\SpenserB\Downloads\radeon-crimson-relive-17.9.1-minimalsetup-170907_64bit.exe
2017-09-20 08:48 - 2014-10-19 15:54 - 000447752 _____ (On2.com) C:\WINDOWS\SysWOW64\vp6vfw.dll
2017-09-20 08:33 - 2017-09-20 08:33 - 000000000 ____D C:\Users\SpenserB\.Origin
2017-09-12 21:18 - 2017-09-07 02:32 - 000918304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2017-09-12 21:18 - 2017-09-07 02:24 - 000263472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2017-09-12 21:18 - 2017-09-07 02:22 - 001504056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2017-09-12 21:18 - 2017-09-07 02:21 - 002265368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2017-09-12 21:18 - 2017-09-07 02:21 - 000975744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2017-09-12 21:18 - 2017-09-07 02:21 - 000780640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2017-09-12 21:18 - 2017-09-07 02:20 - 000037200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbs.dll
2017-09-12 21:18 - 2017-09-07 02:17 - 006665952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-09-12 21:18 - 2017-09-07 02:17 - 001557808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2017-09-12 21:18 - 2017-09-07 02:12 - 000306800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MediaControl.dll
2017-09-12 21:18 - 2017-09-07 02:07 - 005686784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2017-09-12 21:18 - 2017-09-07 01:59 - 000062464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntprint.exe
2017-09-12 21:18 - 2017-09-07 01:58 - 000554496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2017-09-12 21:18 - 2017-09-07 01:58 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IconCodecService.dll
2017-09-12 21:18 - 2017-09-07 01:57 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2017-09-12 21:18 - 2017-09-07 01:57 - 000264704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\socialapis.dll
2017-09-12 21:18 - 2017-09-07 01:57 - 000177664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Diagnostics.dll
2017-09-12 21:18 - 2017-09-07 01:57 - 000156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDeviceRegistration.dll
2017-09-12 21:18 - 2017-09-07 01:56 - 000255488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unimdm.tsp
2017-09-12 21:18 - 2017-09-07 01:55 - 000136192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinRtTracing.dll
2017-09-12 21:18 - 2017-09-07 01:55 - 000094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll
2017-09-12 21:18 - 2017-09-07 01:54 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Input.dll
2017-09-12 21:18 - 2017-09-07 01:54 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2017-09-12 21:18 - 2017-09-07 01:54 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDeviceRegistration.Ngc.dll
2017-09-12 21:18 - 2017-09-07 01:53 - 000501248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\psisdecd.dll
2017-09-12 21:18 - 2017-09-07 01:53 - 000404992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsreg.dll
2017-09-12 21:18 - 2017-09-07 01:53 - 000315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.XboxLive.Storage.dll
2017-09-12 21:18 - 2017-09-07 01:53 - 000313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntprint.dll
2017-09-12 21:18 - 2017-09-07 01:53 - 000299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2017-09-12 21:18 - 2017-09-07 01:53 - 000237568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncSettings.dll
2017-09-12 21:18 - 2017-09-07 01:53 - 000180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2017-09-12 21:18 - 2017-09-07 01:52 - 000557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2017-09-12 21:18 - 2017-09-07 01:52 - 000115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Core.dll
2017-09-12 21:18 - 2017-09-07 01:51 - 001243136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.FaceAnalysis.dll
2017-09-12 21:18 - 2017-09-07 01:51 - 000576512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
2017-09-12 21:18 - 2017-09-07 01:51 - 000426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Wallet.dll
2017-09-12 21:18 - 2017-09-07 01:51 - 000306688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-09-12 21:18 - 2017-09-07 01:51 - 000223232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe
2017-09-12 21:18 - 2017-09-07 01:51 - 000145920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
2017-09-12 21:18 - 2017-09-07 01:50 - 000534528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PCPTpm12.dll
2017-09-12 21:18 - 2017-09-07 01:50 - 000244224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecsExt.dll
2017-09-12 21:18 - 2017-09-07 01:50 - 000218624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WwaApi.dll
2017-09-12 21:18 - 2017-09-07 01:50 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll
2017-09-12 21:18 - 2017-09-07 01:49 - 000819200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll
2017-09-12 21:18 - 2017-09-07 01:49 - 000747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Ocr.dll
2017-09-12 21:18 - 2017-09-07 01:49 - 000567808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2017-09-12 21:18 - 2017-09-07 01:49 - 000415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2017-09-12 21:18 - 2017-09-07 01:49 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2017-09-12 21:18 - 2017-09-07 01:48 - 000396800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2017-09-12 21:18 - 2017-09-07 01:48 - 000297472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2017-09-12 21:18 - 2017-09-07 01:48 - 000284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.dll
2017-09-12 21:18 - 2017-09-07 01:48 - 000225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shdocvw.dll
2017-09-12 21:18 - 2017-09-07 01:47 - 001456640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2017-09-12 21:18 - 2017-09-07 01:47 - 000858112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2017-09-12 21:18 - 2017-09-07 01:47 - 000846336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebcamUi.dll
2017-09-12 21:18 - 2017-09-07 01:47 - 000816640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NaturalLanguage6.dll
2017-09-12 21:18 - 2017-09-07 01:46 - 007626240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2017-09-12 21:18 - 2017-09-07 01:45 - 000336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\azroleui.dll
2017-09-12 21:18 - 2017-09-07 01:44 - 000468992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.InkControls.dll
2017-09-12 21:18 - 2017-09-07 01:38 - 001255936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2017-09-12 21:18 - 2017-09-07 01:37 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2017-09-12 21:18 - 2017-09-07 01:36 - 003520512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2017-09-12 21:18 - 2017-09-07 01:36 - 002641920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2017-09-12 21:18 - 2017-09-07 01:35 - 007470080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2017-09-12 21:18 - 2017-09-07 01:34 - 000709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2017-09-12 21:18 - 2017-09-07 01:33 - 002682880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll
2017-09-12 21:18 - 2017-09-07 01:33 - 001656320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Perception.dll
2017-09-12 21:18 - 2017-09-07 01:33 - 001599488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-09-12 21:18 - 2017-09-07 01:33 - 001135616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
2017-09-12 21:18 - 2017-09-07 01:32 - 002482688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-09-12 21:18 - 2017-09-07 01:32 - 001170944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2017-09-12 21:18 - 2017-09-07 01:32 - 000827904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2017-09-12 21:18 - 2017-09-07 01:32 - 000773120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2017-09-12 21:18 - 2017-09-07 01:31 - 002028032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2017-09-12 21:18 - 2017-09-07 01:31 - 001988608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2017-09-12 21:18 - 2017-09-07 01:31 - 001886720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2017-09-12 21:18 - 2017-09-07 01:31 - 001509376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2017-09-12 21:18 - 2017-09-07 01:31 - 001004544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2017-09-12 21:18 - 2017-09-07 01:31 - 000621056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2017-09-12 21:18 - 2017-09-07 01:31 - 000598528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2017-09-12 21:18 - 2017-09-07 01:30 - 002648576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2017-09-12 21:18 - 2017-09-07 01:30 - 001556992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2017-09-12 21:18 - 2017-09-07 01:30 - 001413632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpcServices.dll
2017-09-12 21:18 - 2017-09-07 01:30 - 001170944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Phone.dll
2017-09-12 21:18 - 2017-09-07 01:30 - 001013248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2017-09-12 21:18 - 2017-09-07 01:29 - 002997760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-09-12 21:18 - 2017-09-07 01:29 - 000711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2017-09-12 21:18 - 2017-09-07 01:28 - 000449536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2017-09-12 21:18 - 2017-08-22 01:08 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2017-09-12 21:18 - 2017-08-22 00:57 - 000711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2017-09-12 21:18 - 2017-08-22 00:55 - 002333184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2017-09-12 21:18 - 2017-08-08 01:16 - 000294952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtapi.dll
2017-09-12 21:18 - 2017-08-08 00:58 - 000095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2017-09-12 21:18 - 2017-08-08 00:56 - 000224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll
2017-09-12 21:18 - 2017-08-08 00:54 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VCardParser.dll
2017-09-12 21:18 - 2017-08-08 00:53 - 000098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.XamlHost.dll
2017-09-12 21:18 - 2017-08-08 00:50 - 000334848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastlsext.dll
2017-09-12 21:18 - 2017-08-08 00:49 - 000052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dataclen.dll
2017-09-12 21:18 - 2017-08-08 00:47 - 000260096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Phoneutil.dll
2017-09-12 21:18 - 2017-03-04 02:17 - 000529920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StructuredQuery.dll
2017-09-12 21:18 - 2017-03-04 02:05 - 000458752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidprov.dll
2017-09-12 21:18 - 2017-03-04 02:01 - 001232384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Maps.dll
2017-09-12 21:18 - 2016-12-21 00:43 - 000285184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll
2017-09-12 21:17 - 2017-09-07 03:07 - 000315744 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2017-09-12 21:17 - 2017-09-07 02:59 - 001470816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll
2017-09-12 21:17 - 2017-09-07 02:32 - 001706488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2017-09-12 21:17 - 2017-09-07 02:32 - 001573792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2017-09-12 21:17 - 2017-09-07 02:29 - 002048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-09-12 21:17 - 2017-09-07 02:24 - 000869848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2017-09-12 21:17 - 2017-09-07 02:22 - 001431232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2017-09-12 21:17 - 2017-09-07 02:21 - 005722320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2017-09-12 21:17 - 2017-09-07 02:21 - 000861024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2017-09-12 21:17 - 2017-09-07 02:21 - 000116576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll
2017-09-12 21:17 - 2017-09-07 02:20 - 001980776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2017-09-12 21:17 - 2017-09-07 02:20 - 000577976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2017-09-12 21:17 - 2017-09-07 02:20 - 000367208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2017-09-12 21:17 - 2017-09-07 02:20 - 000339896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2017-09-12 21:17 - 2017-09-07 02:20 - 000267104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2017-09-12 21:17 - 2017-09-07 02:20 - 000139104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2017-09-12 21:17 - 2017-09-07 02:19 - 002168288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2017-09-12 21:17 - 2017-09-07 02:19 - 000846560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2017-09-12 21:17 - 2017-09-07 02:19 - 000606560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2017-09-12 21:17 - 2017-09-07 02:19 - 000111968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2017-09-12 21:17 - 2017-09-07 02:17 - 004023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2017-09-12 21:17 - 2017-09-07 02:17 - 001845512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2017-09-12 21:17 - 2017-09-07 02:17 - 001360464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2017-09-12 21:17 - 2017-09-07 02:17 - 001277856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2017-09-12 21:17 - 2017-09-07 02:17 - 000981888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2017-09-12 21:17 - 2017-09-07 02:16 - 020967840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-09-12 21:17 - 2017-09-07 02:16 - 000962768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2017-09-12 21:17 - 2017-09-07 02:13 - 001412640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2017-09-12 21:17 - 2017-09-07 02:13 - 000546456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2017-09-12 21:17 - 2017-09-07 02:01 - 001631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2017-09-12 21:17 - 2017-09-07 02:01 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
2017-09-12 21:17 - 2017-09-07 02:00 - 000037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2017-09-12 21:17 - 2017-09-07 01:58 - 000141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Radios.dll
2017-09-12 21:17 - 2017-09-07 01:57 - 000138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2017-09-12 21:17 - 2017-09-07 01:57 - 000123904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.HostName.dll
2017-09-12 21:17 - 2017-09-07 01:57 - 000081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2017-09-12 21:17 - 2017-09-07 01:56 - 000097792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.SystemManagement.dll
2017-09-12 21:17 - 2017-09-07 01:55 - 000129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.SerialCommunication.dll
2017-09-12 21:17 - 2017-09-07 01:54 - 000506368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2017-09-12 21:17 - 2017-09-07 01:54 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2017-09-12 21:17 - 2017-09-07 01:54 - 000184320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
2017-09-12 21:17 - 2017-09-07 01:54 - 000142336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.WiFi.dll
2017-09-12 21:17 - 2017-09-07 01:54 - 000113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Lights.dll
2017-09-12 21:17 - 2017-09-07 01:53 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.LowLevel.dll
2017-09-12 21:17 - 2017-09-07 01:53 - 000098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Credentials.UI.UserConsentVerifier.dll
2017-09-12 21:17 - 2017-09-07 01:52 - 001300480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll
2017-09-12 21:17 - 2017-09-07 01:52 - 000265728 _____ C:\WINDOWS\SysWOW64\Windows.Perception.Stub.dll
2017-09-12 21:17 - 2017-09-07 01:52 - 000126464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2017-09-12 21:17 - 2017-09-07 01:52 - 000117760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthBroker.dll
2017-09-12 21:17 - 2017-09-07 01:51 - 000670208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.PointOfService.dll
2017-09-12 21:17 - 2017-09-07 01:51 - 000609280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll
2017-09-12 21:17 - 2017-09-07 01:51 - 000483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.AllJoyn.dll
2017-09-12 21:17 - 2017-09-07 01:51 - 000386048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.WiFiDirect.dll
2017-09-12 21:17 - 2017-09-07 01:51 - 000332288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2017-09-12 21:17 - 2017-09-07 01:51 - 000298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2017-09-12 21:17 - 2017-09-07 01:51 - 000202752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll
2017-09-12 21:17 - 2017-09-07 01:51 - 000185856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll
2017-09-12 21:17 - 2017-09-07 01:50 - 000498688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mbsmsapi.dll
2017-09-12 21:17 - 2017-09-07 01:50 - 000431616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
2017-09-12 21:17 - 2017-09-07 01:50 - 000325120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll
2017-09-12 21:17 - 2017-09-07 01:50 - 000284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll
2017-09-12 21:17 - 2017-09-07 01:50 - 000236544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2017-09-12 21:17 - 2017-09-07 01:50 - 000206336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vaultcli.dll
2017-09-12 21:17 - 2017-09-07 01:50 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll
2017-09-12 21:17 - 2017-09-07 01:49 - 000662528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2017-09-12 21:17 - 2017-09-07 01:49 - 000262144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Picker.dll
2017-09-12 21:17 - 2017-09-07 01:48 - 000755200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2017-09-12 21:17 - 2017-09-07 01:48 - 000525824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintDialogs.dll
2017-09-12 21:17 - 2017-09-07 01:48 - 000314368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll
2017-09-12 21:17 - 2017-09-07 01:48 - 000285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2017-09-12 21:17 - 2017-09-07 01:48 - 000238080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2017-09-12 21:17 - 2017-09-07 01:47 - 000787968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sbe.dll
2017-09-12 21:17 - 2017-09-07 01:47 - 000661504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2017-09-12 21:17 - 2017-09-07 01:47 - 000500224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.dll
2017-09-12 21:17 - 2017-09-07 01:47 - 000368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2017-09-12 21:17 - 2017-09-07 01:47 - 000288256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CryptoWinRT.dll
2017-09-12 21:17 - 2017-09-07 01:45 - 013875712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2017-09-12 21:17 - 2017-09-07 01:44 - 004615168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2017-09-12 21:17 - 2017-09-07 01:44 - 001534464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.3D.dll
2017-09-12 21:17 - 2017-09-07 01:44 - 000901120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2017-09-12 21:17 - 2017-09-07 01:44 - 000675840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2017-09-12 21:17 - 2017-09-07 01:43 - 000693248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2017-09-12 21:17 - 2017-09-07 01:43 - 000653312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
2017-09-12 21:17 - 2017-09-07 01:42 - 001077760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll
2017-09-12 21:17 - 2017-09-07 01:42 - 000355328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTMediaFrame.dll
2017-09-12 21:17 - 2017-09-07 01:42 - 000134656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Energy.dll
2017-09-12 21:17 - 2017-09-07 01:41 - 019413504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-09-12 21:17 - 2017-09-07 01:41 - 000471552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll
2017-09-12 21:17 - 2017-09-07 01:40 - 003307008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2017-09-12 21:17 - 2017-09-07 01:40 - 003198464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2017-09-12 21:17 - 2017-09-07 01:40 - 000795648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MiracastReceiver.dll
2017-09-12 21:17 - 2017-09-07 01:40 - 000746496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcprx.dll
2017-09-12 21:17 - 2017-09-07 01:40 - 000713216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2017-09-12 21:17 - 2017-09-07 01:40 - 000343040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
2017-09-12 21:17 - 2017-09-07 01:39 - 018363904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-09-12 21:17 - 2017-09-07 01:39 - 006109696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2017-09-12 21:17 - 2017-09-07 01:39 - 000470016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll
2017-09-12 21:17 - 2017-09-07 01:38 - 000895488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2017-09-12 21:17 - 2017-09-07 01:38 - 000459776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.MediaPlayer.dll
2017-09-12 21:17 - 2017-09-07 01:37 - 012204544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-09-12 21:17 - 2017-09-07 01:37 - 000220672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToReceiver.dll
2017-09-12 21:17 - 2017-09-07 01:36 - 001221120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2017-09-12 21:17 - 2017-09-07 01:36 - 000089600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CameraCaptureUI.dll
2017-09-12 21:17 - 2017-09-07 01:35 - 000641024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2017-09-12 21:17 - 2017-09-07 01:35 - 000357376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Geolocation.dll
2017-09-12 21:17 - 2017-09-07 01:35 - 000103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll
2017-09-12 21:17 - 2017-09-07 01:34 - 006032384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-09-12 21:17 - 2017-09-07 01:34 - 003733504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2017-09-12 21:17 - 2017-09-07 01:34 - 000400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2017-09-12 21:17 - 2017-09-07 01:34 - 000339968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll
2017-09-12 21:17 - 2017-09-07 01:33 - 000886272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2017-09-12 21:17 - 2017-09-07 01:33 - 000589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2017-09-12 21:17 - 2017-09-07 01:33 - 000348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll
2017-09-12 21:17 - 2017-09-07 01:32 - 001993216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2017-09-12 21:17 - 2017-09-07 01:32 - 001247232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
2017-09-12 21:17 - 2017-09-07 01:32 - 000690688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2017-09-12 21:17 - 2017-09-07 01:31 - 003663872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-09-12 21:17 - 2017-09-07 01:31 - 000654336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
2017-09-12 21:17 - 2017-09-07 01:31 - 000566784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
2017-09-12 21:17 - 2017-09-07 01:31 - 000542208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2017-09-12 21:17 - 2017-09-07 01:30 - 002747904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
2017-09-12 21:17 - 2017-09-07 01:30 - 002740224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2017-09-12 21:17 - 2017-09-07 01:30 - 000353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2017-09-12 21:17 - 2017-09-07 01:29 - 001576448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2017-09-12 21:17 - 2017-09-07 01:29 - 000751104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2017-09-12 21:17 - 2017-09-07 01:28 - 003106304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2017-09-12 21:17 - 2017-09-07 01:28 - 000783360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2017-09-12 21:17 - 2017-09-07 01:07 - 000483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-09-12 21:17 - 2017-08-22 00:50 - 012349440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2017-09-12 21:17 - 2017-08-22 00:49 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dlnashext.dll
2017-09-12 21:17 - 2017-08-08 02:03 - 000218976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinesam.dll
2017-09-12 21:17 - 2017-08-08 01:56 - 000054240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appidapi.dll
2017-09-12 21:17 - 2017-08-08 01:25 - 000255168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sechost.dll
2017-09-12 21:17 - 2017-08-08 01:21 - 000340832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2017-09-12 21:17 - 2017-08-08 01:16 - 000086232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mpr.dll
2017-09-12 21:17 - 2017-08-08 00:56 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appidtel.exe
2017-09-12 21:17 - 2017-08-08 00:53 - 000450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2017-09-12 21:17 - 2017-08-08 00:53 - 000119808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srpapi.dll
2017-09-12 21:17 - 2017-08-08 00:50 - 000531456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtrmgr.dll
2017-09-12 21:17 - 2017-08-08 00:50 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sscore.dll
2017-09-12 21:17 - 2017-08-08 00:48 - 000388608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2017-09-12 21:17 - 2017-08-08 00:41 - 000525824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2017-09-12 21:17 - 2017-03-04 02:53 - 000136032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostUser.dll
2017-09-12 21:17 - 2017-03-04 02:24 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-09-12 21:17 - 2017-03-04 02:13 - 006474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2017-09-12 21:17 - 2016-11-02 06:43 - 000270336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2017-09-12 21:10 - 2017-09-07 01:56 - 000328008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2017-09-12 21:10 - 2017-09-07 01:22 - 000123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2017-09-12 21:10 - 2017-09-07 01:19 - 000467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.XboxLive.Storage.dll
2017-09-12 21:10 - 2017-09-07 01:19 - 000193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinRtTracing.dll
2017-09-12 21:10 - 2017-09-07 01:19 - 000149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Core.dll
2017-09-12 21:10 - 2017-09-07 01:19 - 000122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2017-09-12 21:10 - 2017-09-07 01:18 - 000547840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Input.dll
2017-09-12 21:10 - 2017-09-07 01:17 - 000730112 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2017-09-12 21:10 - 2017-09-07 01:16 - 001507840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.FaceAnalysis.dll
2017-09-12 21:10 - 2017-09-07 01:15 - 000349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2017-09-12 21:10 - 2017-09-07 01:14 - 000358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.dll
2017-09-12 21:10 - 2017-09-07 01:13 - 001159680 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblGameSave.dll
2017-09-12 21:10 - 2017-09-07 01:11 - 000634368 _____ (Microsoft Corporation) C:\WINDOWS\system32\StructuredQuery.dll
2017-09-12 21:10 - 2017-09-07 01:07 - 002104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2017-09-12 21:10 - 2017-09-07 01:01 - 003401216 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2017-09-12 21:10 - 2017-09-07 00:57 - 001643008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2017-09-12 21:10 - 2017-09-07 00:56 - 002539008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2017-09-12 21:10 - 2017-09-07 00:55 - 002424320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Perception.dll
2017-09-12 21:10 - 2017-09-07 00:54 - 000903680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2017-09-12 21:10 - 2017-08-22 01:02 - 000221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe
2017-09-12 21:10 - 2017-03-04 02:32 - 000073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2017-09-12 21:10 - 2016-09-15 12:40 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2017-09-12 21:10 - 2016-09-15 12:24 - 001080320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Ocr.dll
2017-09-12 21:09 - 2017-09-07 02:03 - 007780704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-09-12 21:09 - 2017-09-07 02:03 - 000998920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2017-09-12 21:09 - 2017-09-07 02:02 - 032693432 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecsRaw.dll
2017-09-12 21:09 - 2017-09-07 02:01 - 002049480 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2017-09-12 21:09 - 2017-09-07 01:54 - 001860288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2017-09-12 21:09 - 2017-09-07 01:54 - 001739072 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2017-09-12 21:09 - 2017-09-07 01:54 - 001157008 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2017-09-12 21:09 - 2017-09-07 01:54 - 000857440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2017-09-12 21:09 - 2017-09-07 01:53 - 000097128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Credentials.UI.CredentialPicker.dll
2017-09-12 21:09 - 2017-09-07 01:52 - 000044464 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbs.dll
2017-09-12 21:09 - 2017-09-07 01:51 - 000092512 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2017-09-12 21:09 - 2017-09-07 01:50 - 022220864 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-09-12 21:09 - 2017-09-07 01:50 - 008168000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-09-12 21:09 - 2017-09-07 01:50 - 001694712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2017-09-12 21:09 - 2017-09-07 01:49 - 001600632 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2017-09-12 21:09 - 2017-09-07 01:45 - 002532704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2017-09-12 21:09 - 2017-09-07 01:23 - 000053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2017-09-12 21:09 - 2017-09-07 01:22 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2017-09-12 21:09 - 2017-09-07 01:22 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2017-09-12 21:09 - 2017-09-07 01:22 - 000021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnpinst.exe
2017-09-12 21:09 - 2017-09-07 01:21 - 000238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2017-09-12 21:09 - 2017-09-07 01:21 - 000237568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Diagnostics.dll
2017-09-12 21:09 - 2017-09-07 01:21 - 000124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.SystemManagement.dll
2017-09-12 21:09 - 2017-09-07 01:21 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.Authentication.dll
2017-09-12 21:09 - 2017-09-07 01:21 - 000098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2017-09-12 21:09 - 2017-09-07 01:21 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntprint.exe
2017-09-12 21:09 - 2017-09-07 01:20 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\unimdm.tsp
2017-09-12 21:09 - 2017-09-07 01:20 - 000259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.SyncEngine.dll
2017-09-12 21:09 - 2017-09-07 01:20 - 000156160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.Client.dll
2017-09-12 21:09 - 2017-09-07 01:20 - 000148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Profile.RetailInfo.dll
2017-09-12 21:09 - 2017-09-07 01:20 - 000129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_ClosedCaptioning.dll
2017-09-12 21:09 - 2017-09-07 01:20 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nsiproxy.sys
2017-09-12 21:09 - 2017-09-07 01:19 - 000196096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.dll
2017-09-12 21:09 - 2017-09-07 01:19 - 000101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.Ngc.dll
2017-09-12 21:09 - 2017-09-07 01:18 - 000418304 _____ C:\WINDOWS\system32\Windows.Perception.Stub.dll
2017-09-12 21:09 - 2017-09-07 01:18 - 000368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneBackupHandler.dll
2017-09-12 21:09 - 2017-09-07 01:18 - 000354816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntprint.dll
2017-09-12 21:09 - 2017-09-07 01:18 - 000211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2017-09-12 21:09 - 2017-09-07 01:18 - 000127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Credentials.UI.UserConsentVerifier.dll
2017-09-12 21:09 - 2017-09-07 01:17 - 000418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2017-09-12 21:09 - 2017-09-07 01:17 - 000360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
2017-09-12 21:09 - 2017-09-07 01:17 - 000105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll
2017-09-12 21:09 - 2017-09-07 01:17 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2017-09-12 21:09 - 2017-09-07 01:16 - 000781824 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2017-09-12 21:09 - 2017-09-07 01:16 - 000748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2017-09-12 21:09 - 2017-09-07 01:16 - 000680448 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2017-09-12 21:09 - 2017-09-07 01:16 - 000335872 _____ (Microsoft Corporation) C:\WINDOWS\system32\socialapis.dll
2017-09-12 21:09 - 2017-09-07 01:16 - 000174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetpp.dll
2017-09-12 21:09 - 2017-09-07 01:16 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-09-12 21:09 - 2017-09-07 01:15 - 001081856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2017-09-12 21:09 - 2017-09-07 01:15 - 000590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2017-09-12 21:09 - 2017-09-07 01:15 - 000553984 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-09-12 21:09 - 2017-09-07 01:15 - 000391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll
2017-09-12 21:09 - 2017-09-07 01:15 - 000381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2017-09-12 21:09 - 2017-09-07 01:15 - 000277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecsExt.dll
2017-09-12 21:09 - 2017-09-07 01:15 - 000267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultcli.dll
2017-09-12 21:09 - 2017-09-07 01:15 - 000260608 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
2017-09-12 21:09 - 2017-09-07 01:15 - 000146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll
2017-09-12 21:09 - 2017-09-07 01:14 - 006288384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2017-09-12 21:09 - 2017-09-07 01:14 - 000805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2017-09-12 21:09 - 2017-09-07 01:14 - 000748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2017-09-12 21:09 - 2017-09-07 01:14 - 000678912 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2017-09-12 21:09 - 2017-09-07 01:14 - 000561664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll
2017-09-12 21:09 - 2017-09-07 01:14 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\tpmvsc.dll
2017-09-12 21:09 - 2017-09-07 01:14 - 000358400 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2017-09-12 21:09 - 2017-09-07 01:14 - 000252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2017-09-12 21:09 - 2017-09-07 01:14 - 000078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2017-09-12 21:09 - 2017-09-07 01:13 - 000645120 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2017-09-12 21:09 - 2017-09-07 01:13 - 000480768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
2017-09-12 21:09 - 2017-09-07 01:13 - 000425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2017-09-12 21:09 - 2017-09-07 01:13 - 000245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\WwaApi.dll
2017-09-12 21:09 - 2017-09-07 01:12 - 001145856 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2017-09-12 21:09 - 2017-09-07 01:12 - 000963584 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebcamUi.dll
2017-09-12 21:09 - 2017-09-07 01:12 - 000642048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.InkControls.dll
2017-09-12 21:09 - 2017-09-07 01:11 - 000966144 _____ (Microsoft Corporation) C:\WINDOWS\system32\sbe.dll
2017-09-12 21:09 - 2017-09-07 01:11 - 000775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2017-09-12 21:09 - 2017-09-07 01:11 - 000583680 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs.dll
2017-09-12 21:09 - 2017-09-07 01:11 - 000527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2017-09-12 21:09 - 2017-09-07 01:09 - 000945664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2017-09-12 21:09 - 2017-09-07 01:09 - 000864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\printfilterpipelinesvc.exe
2017-09-12 21:09 - 2017-09-07 01:08 - 009129984 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2017-09-12 21:09 - 2017-09-07 01:08 - 000932864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2017-09-12 21:09 - 2017-09-07 01:08 - 000800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2017-09-12 21:09 - 2017-09-07 01:08 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2017-09-12 21:09 - 2017-09-07 01:07 - 001403392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll
2017-09-12 21:09 - 2017-09-07 01:07 - 000458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTMediaFrame.dll
2017-09-12 21:09 - 2017-09-07 01:05 - 000864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2017-09-12 21:09 - 2017-09-07 01:05 - 000442368 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
2017-09-12 21:09 - 2017-09-07 01:04 - 004749824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-09-12 21:09 - 2017-09-07 01:04 - 001908224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-09-12 21:09 - 2017-09-07 01:03 - 000361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdechangepin.exe
2017-09-12 21:09 - 2017-09-07 01:03 - 000248320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2017-09-12 21:09 - 2017-09-07 01:02 - 000279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToReceiver.dll
2017-09-12 21:09 - 2017-09-07 01:01 - 004596224 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2017-09-12 21:09 - 2017-09-07 01:01 - 002390016 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
2017-09-12 21:09 - 2017-09-07 01:01 - 000061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\vss_ps.dll
2017-09-12 21:09 - 2017-09-07 01:00 - 008114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-09-12 21:09 - 2017-09-07 01:00 - 008077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2017-09-12 21:09 - 2017-09-07 01:00 - 000981504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
2017-09-12 21:09 - 2017-09-07 01:00 - 000539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2017-09-12 21:09 - 2017-09-07 01:00 - 000391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll
2017-09-12 21:09 - 2017-09-07 00:59 - 002510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-09-12 21:09 - 2017-09-07 00:59 - 001359872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2017-09-12 21:09 - 2017-09-07 00:59 - 000821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2017-09-12 21:09 - 2017-09-07 00:59 - 000650752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2017-09-12 21:09 - 2017-09-07 00:59 - 000611328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2017-09-12 21:09 - 2017-09-07 00:59 - 000243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\shdocvw.dll
2017-09-12 21:09 - 2017-09-07 00:58 - 001700352 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2017-09-12 21:09 - 2017-09-07 00:58 - 001656320 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2017-09-12 21:09 - 2017-09-07 00:58 - 000816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2017-09-12 21:09 - 2017-09-07 00:57 - 003134976 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2017-09-12 21:09 - 2017-09-07 00:57 - 002916864 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2017-09-12 21:09 - 2017-09-07 00:57 - 001424896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll
2017-09-12 21:09 - 2017-09-07 00:57 - 000874496 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2017-09-12 21:09 - 2017-09-07 00:56 - 004149248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2017-09-12 21:09 - 2017-09-07 00:56 - 002695680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-09-12 21:09 - 2017-09-07 00:56 - 002208768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll
2017-09-12 21:09 - 2017-09-07 00:56 - 000971264 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2017-09-12 21:09 - 2017-09-07 00:56 - 000909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2017-09-12 21:09 - 2017-09-07 00:56 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2017-09-12 21:09 - 2017-09-07 00:55 - 003616256 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-09-12 21:09 - 2017-09-07 00:55 - 001984000 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2017-09-12 21:09 - 2017-09-07 00:55 - 001512448 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-09-12 21:09 - 2017-09-07 00:55 - 001369088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
2017-09-12 21:09 - 2017-09-07 00:55 - 001131520 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2017-09-12 21:09 - 2017-09-07 00:55 - 000774656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2017-09-12 21:09 - 2017-09-07 00:54 - 004743680 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-09-12 21:09 - 2017-09-07 00:54 - 001328640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2017-09-12 21:09 - 2017-09-07 00:54 - 000834560 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2017-09-12 21:09 - 2017-09-07 00:53 - 001726976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-09-12 21:09 - 2017-09-07 00:52 - 003299840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2017-09-12 21:09 - 2017-09-07 00:52 - 001121280 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-09-12 21:09 - 2017-09-07 00:52 - 000998912 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2017-09-12 21:09 - 2017-09-07 00:52 - 000531968 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2017-09-12 21:09 - 2017-08-22 01:46 - 000360040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2017-09-12 21:09 - 2017-08-22 01:43 - 000026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2017-09-12 21:09 - 2017-08-22 01:09 - 000048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2017-09-12 21:09 - 2017-08-22 01:06 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2017-09-12 21:09 - 2017-08-22 01:05 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll
2017-09-12 21:09 - 2017-08-22 01:04 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2017-09-12 21:09 - 2017-08-22 00:57 - 002716672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2017-09-12 21:09 - 2017-08-22 00:47 - 000869888 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2017-09-12 21:09 - 2017-08-22 00:43 - 002852864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2017-09-12 21:09 - 2017-08-22 00:43 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2017-09-12 21:09 - 2017-08-22 00:41 - 002319872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-09-12 21:09 - 2017-08-22 00:38 - 000221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\tspubwmi.dll
2017-09-12 21:09 - 2017-08-08 01:59 - 000357984 _____ (Microsoft Corporation) C:\WINDOWS\system32\sechost.dll
2017-09-12 21:09 - 2017-08-08 01:59 - 000118112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2017-09-12 21:09 - 2017-08-08 01:55 - 000404320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2017-09-12 21:09 - 2017-08-08 01:52 - 000649568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2017-09-12 21:09 - 2017-08-08 01:52 - 000450400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2017-09-12 21:09 - 2017-08-08 01:45 - 000453544 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2017-09-12 21:09 - 2017-08-08 01:23 - 000119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-09-12 21:09 - 2017-08-08 01:18 - 000187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll
2017-09-12 21:09 - 2017-08-08 01:18 - 000048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\sscore.dll
2017-09-12 21:09 - 2017-08-08 01:17 - 000375296 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastlsext.dll
2017-09-12 21:09 - 2017-08-08 01:17 - 000231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2017-09-12 21:09 - 2017-08-08 01:16 - 000121344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.XamlHost.dll
2017-09-12 21:09 - 2017-08-08 01:15 - 000556544 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtrmgr.dll
2017-09-12 21:09 - 2017-08-08 01:15 - 000502272 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2017-09-12 21:09 - 2017-08-08 01:14 - 000658432 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2017-09-12 21:09 - 2017-08-08 01:14 - 000315904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Phoneutil.dll
2017-09-12 21:09 - 2017-08-08 01:13 - 000472064 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2017-09-12 21:09 - 2017-08-08 01:04 - 000798720 _____ (Microsoft Corporation) C:\WINDOWS\system32\pwcreator.exe
2017-09-12 21:09 - 2017-08-08 00:58 - 000304128 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvsvc.dll
2017-09-12 21:09 - 2017-08-08 00:51 - 001817088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2017-09-12 21:09 - 2017-03-04 02:39 - 000372736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2017-09-12 21:09 - 2017-03-04 02:29 - 000289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2017-09-12 21:09 - 2017-03-04 02:28 - 000216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2017-09-12 21:09 - 2017-03-04 02:27 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2017-09-12 21:09 - 2017-03-04 02:27 - 000311296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll
2017-09-12 21:09 - 2017-03-04 02:08 - 001266176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2017-09-12 21:08 - 2017-09-07 02:16 - 000379232 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2017-09-12 21:08 - 2017-09-07 02:10 - 000603488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2017-09-12 21:08 - 2017-09-07 02:03 - 002213760 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2017-09-12 21:08 - 2017-09-07 02:03 - 001887408 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2017-09-12 21:08 - 2017-09-07 02:01 - 002681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2017-09-12 21:08 - 2017-09-07 01:58 - 000168800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2017-09-12 21:08 - 2017-09-07 01:56 - 001069720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2017-09-12 21:08 - 2017-09-07 01:54 - 007220696 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2017-09-12 21:08 - 2017-09-07 01:54 - 002761248 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2017-09-12 21:08 - 2017-09-07 01:54 - 002188128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-09-12 21:08 - 2017-09-07 01:54 - 000658784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2017-09-12 21:08 - 2017-09-07 01:54 - 000402784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2017-09-12 21:08 - 2017-09-07 01:53 - 002446704 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2017-09-12 21:08 - 2017-09-07 01:53 - 000684896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2017-09-12 21:08 - 2017-09-07 01:53 - 000624048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-09-12 21:08 - 2017-09-07 01:53 - 000383776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2017-09-12 21:08 - 2017-09-07 01:53 - 000296288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2017-09-12 21:08 - 2017-09-07 01:53 - 000144736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2017-09-12 21:08 - 2017-09-07 01:52 - 002915704 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2017-09-12 21:08 - 2017-09-07 01:52 - 001267512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2017-09-12 21:08 - 2017-09-07 01:52 - 000858464 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2017-09-12 21:08 - 2017-09-07 01:52 - 000148832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2017-09-12 21:08 - 2017-09-07 01:50 - 004260064 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2017-09-12 21:08 - 2017-09-07 01:50 - 001983408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-09-12 21:08 - 2017-09-07 01:50 - 001702392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2017-09-12 21:08 - 2017-09-07 01:50 - 001072248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2017-09-12 21:08 - 2017-09-07 01:50 - 000244824 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2017-09-12 21:08 - 2017-09-07 01:49 - 001277824 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2017-09-12 21:08 - 2017-09-07 01:49 - 000241504 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2017-09-12 21:08 - 2017-09-07 01:46 - 001566552 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-09-12 21:08 - 2017-09-07 01:46 - 000628552 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2017-09-12 21:08 - 2017-09-07 01:45 - 000387872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
2017-09-12 21:08 - 2017-09-07 01:30 - 007218176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-09-12 21:08 - 2017-09-07 01:24 - 001631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2017-09-12 21:08 - 2017-09-07 01:23 - 022569984 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-09-12 21:08 - 2017-09-07 01:22 - 000045056 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2017-09-12 21:08 - 2017-09-07 01:22 - 000030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2017-09-12 21:08 - 2017-09-07 01:22 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\IconCodecService.dll
2017-09-12 21:08 - 2017-09-07 01:21 - 000185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2017-09-12 21:08 - 2017-09-07 01:21 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Printers.dll
2017-09-12 21:08 - 2017-09-07 01:20 - 000113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-09-12 21:08 - 2017-09-07 01:19 - 000193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFi.dll
2017-09-12 21:08 - 2017-09-07 01:18 - 000840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipsecsnp.dll
2017-09-12 21:08 - 2017-09-07 01:18 - 000279040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbt.sys
2017-09-12 21:08 - 2017-09-07 01:18 - 000186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Radios.dll
2017-09-12 21:08 - 2017-09-07 01:17 - 000505856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
2017-09-12 21:08 - 2017-09-07 01:17 - 000276992 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2017-09-12 21:08 - 2017-09-07 01:17 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2017-09-12 21:08 - 2017-09-07 01:17 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SerialCommunication.dll
2017-09-12 21:08 - 2017-09-07 01:17 - 000144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Lights.dll
2017-09-12 21:08 - 2017-09-07 01:17 - 000139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2017-09-12 21:08 - 2017-09-07 01:16 - 000912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.dll
2017-09-12 21:08 - 2017-09-07 01:16 - 000691200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-09-12 21:08 - 2017-09-07 01:16 - 000568320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.LowLevel.dll
2017-09-12 21:08 - 2017-09-07 01:16 - 000279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.HumanInterfaceDevice.dll
2017-09-12 21:08 - 2017-09-07 01:15 - 000852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll
2017-09-12 21:08 - 2017-09-07 01:15 - 000432128 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2017-09-12 21:08 - 2017-09-07 01:15 - 000389120 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2017-09-12 21:08 - 2017-09-07 01:15 - 000095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
2017-09-12 21:08 - 2017-09-07 01:15 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2017-09-12 21:08 - 2017-09-07 01:14 - 000949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2017-09-12 21:08 - 2017-09-07 01:14 - 000451072 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2017-09-12 21:08 - 2017-09-07 01:14 - 000407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2017-09-12 21:08 - 2017-09-07 01:14 - 000337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Picker.dll
2017-09-12 21:08 - 2017-09-07 01:14 - 000171008 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
2017-09-12 21:08 - 2017-09-07 01:13 - 000671744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mbsmsapi.dll
2017-09-12 21:08 - 2017-09-07 01:13 - 000472064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2017-09-12 21:08 - 2017-09-07 01:13 - 000437248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll
2017-09-12 21:08 - 2017-09-07 01:13 - 000284160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2017-09-12 21:08 - 2017-09-07 01:12 - 001010688 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2017-09-12 21:08 - 2017-09-07 01:12 - 000156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
2017-09-12 21:08 - 2017-09-07 01:11 - 000262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2017-09-12 21:08 - 2017-09-07 01:10 - 017200128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-09-12 21:08 - 2017-09-07 01:10 - 001037312 _____ (Microsoft Corporation) C:\WINDOWS\system32\nettrace.dll
2017-09-12 21:08 - 2017-09-07 01:08 - 001639424 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2017-09-12 21:08 - 2017-09-07 01:08 - 000393216 _____ (Microsoft Corporation) C:\WINDOWS\system32\msihnd.dll
2017-09-12 21:08 - 2017-09-07 01:07 - 007655424 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2017-09-12 21:08 - 2017-09-07 01:07 - 003778048 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2017-09-12 21:08 - 2017-09-07 01:07 - 001589760 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
2017-09-12 21:08 - 2017-09-07 01:07 - 000104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CastLaunch.dll
2017-09-12 21:08 - 2017-09-07 01:05 - 005114368 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2017-09-12 21:08 - 2017-09-07 01:05 - 001105408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MiracastReceiver.dll
2017-09-12 21:08 - 2017-09-07 01:04 - 000870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2017-09-12 21:08 - 2017-09-07 01:04 - 000352256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe
2017-09-12 21:08 - 2017-09-07 01:04 - 000187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialclient.dll
2017-09-12 21:08 - 2017-09-07 01:03 - 001837056 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2017-09-12 21:08 - 2017-09-07 01:03 - 001078784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2017-09-12 21:08 - 2017-09-07 01:02 - 013107712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-09-12 21:08 - 2017-09-07 01:01 - 023675904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-09-12 21:08 - 2017-09-07 01:01 - 001217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2017-09-12 21:08 - 2017-09-07 01:01 - 000937984 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2017-09-12 21:08 - 2017-09-07 01:01 - 000411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2017-09-12 21:08 - 2017-09-07 01:01 - 000219136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.ps.dll
2017-09-12 21:08 - 2017-09-07 01:00 - 000467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Geolocation.dll
2017-09-12 21:08 - 2017-09-07 01:00 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll
2017-09-12 21:08 - 2017-09-07 00:59 - 004474368 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2017-09-12 21:08 - 2017-09-07 00:59 - 001281536 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2017-09-12 21:08 - 2017-09-07 00:59 - 001040896 _____ (Microsoft Corporation) C:\WINDOWS\system32\NaturalLanguage6.dll
2017-09-12 21:08 - 2017-09-07 00:59 - 000821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2017-09-12 21:08 - 2017-09-07 00:59 - 000760320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2017-09-12 21:08 - 2017-09-07 00:59 - 000460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll
2017-09-12 21:08 - 2017-09-07 00:58 - 002800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll
2017-09-12 21:08 - 2017-09-07 00:58 - 002097152 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2017-09-12 21:08 - 2017-09-07 00:58 - 001708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2017-09-12 21:08 - 2017-09-07 00:58 - 000913920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2017-09-12 21:08 - 2017-09-07 00:58 - 000886784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2017-09-12 21:08 - 2017-09-07 00:58 - 000376832 _____ (Microsoft Corporation) C:\WINDOWS\system32\CryptoWinRT.dll
2017-09-12 21:08 - 2017-09-07 00:58 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2017-09-12 21:08 - 2017-09-07 00:57 - 005611520 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2017-09-12 21:08 - 2017-09-07 00:57 - 002895360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-09-12 21:08 - 2017-09-07 00:57 - 001586176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2017-09-12 21:08 - 2017-09-07 00:57 - 001486336 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2017-09-12 21:08 - 2017-09-07 00:57 - 001275392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2017-09-12 21:08 - 2017-09-07 00:56 - 003202048 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2017-09-12 21:08 - 2017-09-07 00:56 - 002286592 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2017-09-12 21:08 - 2017-09-07 00:56 - 000846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2017-09-12 21:08 - 2017-09-07 00:55 - 002820096 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2017-09-12 21:08 - 2017-09-07 00:55 - 002217472 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll
2017-09-12 21:08 - 2017-09-07 00:55 - 001783296 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-09-12 21:08 - 2017-09-07 00:55 - 001637888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2017-09-12 21:08 - 2017-09-07 00:53 - 000701952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2017-09-12 21:08 - 2017-09-07 00:52 - 000924672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2017-09-12 21:08 - 2017-09-07 00:50 - 000119808 ____R (Microsoft Corporation) C:\WINDOWS\system32\SecureAssessmentHandlers.dll
2017-09-12 21:08 - 2017-08-22 00:53 - 013441536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2017-09-12 21:08 - 2017-08-08 02:15 - 000245600 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
2017-09-12 21:08 - 2017-08-08 02:06 - 000133984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
2017-09-12 21:08 - 2017-08-08 02:03 - 002253664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2017-09-12 21:08 - 2017-08-08 02:01 - 000376672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2017-09-12 21:08 - 2017-08-08 01:52 - 000386408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtapi.dll
2017-09-12 21:08 - 2017-08-08 01:52 - 000101776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mpr.dll
2017-09-12 21:08 - 2017-08-08 01:45 - 001102176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2017-09-12 21:08 - 2017-08-08 01:16 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\dataclen.dll
2017-09-12 21:08 - 2017-08-08 01:15 - 000326656 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2017-09-12 21:08 - 2017-08-08 01:12 - 000579584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll
2017-09-12 21:08 - 2017-08-08 01:10 - 000945664 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2017-09-12 21:08 - 2017-08-08 01:04 - 000883712 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2017-09-12 21:08 - 2017-08-08 00:55 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2017-09-12 21:08 - 2017-08-08 00:54 - 001228288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2017-09-12 21:08 - 2017-08-01 01:09 - 000182272 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceDirectoryClient.dll
2017-09-12 21:08 - 2017-03-04 03:03 - 000160096 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostBroker.dll
2017-09-12 21:08 - 2017-03-04 02:28 - 000223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.HostName.dll
2017-09-12 21:08 - 2017-03-04 02:13 - 000112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\CameraCaptureUI.dll
2017-09-12 21:08 - 2017-03-04 02:10 - 006664192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2017-09-12 21:08 - 2016-09-15 12:34 - 000441856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AccountsRt.dll
2017-09-12 21:08 - 2016-09-15 12:30 - 000169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Energy.dll
2017-09-12 21:07 - 2017-09-07 02:11 - 000076128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncAppvPublishingServer.exe
2017-09-12 21:07 - 2017-09-07 02:10 - 002170720 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll
2017-09-12 21:07 - 2017-09-07 02:10 - 001670496 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVIntegration.dll
2017-09-12 21:07 - 2017-09-07 02:10 - 001408352 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystemController.dll
2017-09-12 21:07 - 2017-09-07 02:10 - 001054048 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPolicy.dll
2017-09-12 21:07 - 2017-09-07 02:10 - 000992096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVManifest.dll
2017-09-12 21:07 - 2017-09-07 02:10 - 000825696 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVClient.exe
2017-09-12 21:07 - 2017-09-07 02:10 - 000813408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntStreamingManager.dll
2017-09-12 21:07 - 2017-09-07 02:10 - 000779616 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVReporting.dll
2017-09-12 21:07 - 2017-09-07 02:10 - 000766304 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVOrchestration.dll
2017-09-12 21:07 - 2017-09-07 02:10 - 000704352 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntVirtualization.dll
2017-09-12 21:07 - 2017-09-07 02:10 - 000699232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPublishing.dll
2017-09-12 21:07 - 2017-09-07 02:10 - 000567136 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVCatalog.dll
2017-09-12 21:07 - 2017-09-07 02:10 - 000513376 _____ (Microsoft Corporation) C:\WINDOWS\system32\TransportDSA.dll
2017-09-12 21:07 - 2017-09-07 02:10 - 000412512 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVScripting.dll
2017-09-12 21:07 - 2017-09-07 02:10 - 000241504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVShNotify.exe
2017-09-12 21:07 - 2017-09-07 02:10 - 000202592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVStreamingUX.dll
2017-09-12 21:07 - 2017-09-07 02:04 - 000894096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2017-09-12 21:07 - 2017-09-07 02:00 - 000764392 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-09-12 21:07 - 2017-09-07 01:54 - 000146784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2017-09-12 21:07 - 2017-09-07 01:53 - 000431296 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2017-09-12 21:07 - 2017-09-07 01:52 - 001100128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-09-12 21:07 - 2017-09-07 01:52 - 000989024 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-09-12 21:07 - 2017-09-07 01:45 - 000372440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2017-09-12 21:07 - 2017-09-07 01:17 - 000157696 _____ (Microsoft Corporation) C:\WINDOWS\system32\XamlTileRender.dll
2017-09-12 21:07 - 2017-09-07 01:17 - 000150016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2017-09-12 21:07 - 2017-09-07 01:16 - 000651264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
2017-09-12 21:07 - 2017-09-07 01:16 - 000623104 _____ (Microsoft Corporation) C:\WINDOWS\system32\PCPTpm12.dll
2017-09-12 21:07 - 2017-09-07 01:16 - 000268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2017-09-12 21:07 - 2017-09-07 01:15 - 000379904 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
2017-09-12 21:07 - 2017-09-07 01:15 - 000324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2017-09-12 21:07 - 2017-09-07 01:15 - 000176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
2017-09-12 21:07 - 2017-09-07 01:12 - 000956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2017-09-12 21:07 - 2017-09-07 01:12 - 000896512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2017-09-12 21:07 - 2017-09-07 01:04 - 000337920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2017-09-12 21:07 - 2017-09-07 01:03 - 000942080 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2017-09-12 21:07 - 2017-09-07 01:02 - 000167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ErrorDetails.dll
2017-09-12 21:07 - 2017-09-07 00:59 - 002279424 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-09-12 21:07 - 2017-09-07 00:58 - 001692160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-09-12 21:07 - 2017-09-07 00:54 - 003542016 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2017-09-12 21:07 - 2017-09-07 00:54 - 000716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2017-09-12 21:07 - 2017-08-22 00:52 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll
2017-09-12 21:07 - 2017-08-08 02:09 - 000065648 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidapi.dll
2017-09-12 21:07 - 2017-08-08 02:03 - 000102240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\disk.sys
2017-09-12 21:07 - 2017-08-08 01:53 - 000715104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2017-09-12 21:07 - 2017-08-08 01:53 - 000557408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2017-09-12 21:07 - 2017-08-08 01:53 - 000026976 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser_broker.exe
2017-09-12 21:07 - 2017-08-08 01:52 - 000079712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmcl.sys
2017-09-12 21:07 - 2017-08-08 01:20 - 000173056 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe
2017-09-12 21:07 - 2017-08-08 01:20 - 000137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\srpapi.dll
2017-09-12 21:07 - 2017-08-08 01:20 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmclr.sys
2017-09-12 21:07 - 2017-08-08 01:20 - 000027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidtel.exe
2017-09-12 21:07 - 2017-08-08 01:18 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2017-09-12 21:07 - 2017-08-08 01:13 - 000305152 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvc.dll
2017-09-12 21:07 - 2017-03-04 03:09 - 000178520 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostUser.dll
2017-09-12 21:07 - 2017-03-04 03:07 - 000947552 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi
2017-09-07 11:37 - 2017-09-07 11:37 - 001058328 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxx.dll
2017-09-07 11:37 - 2017-09-07 11:37 - 000136728 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2017-09-07 11:37 - 2017-09-07 11:37 - 000115224 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2017-09-07 11:37 - 2017-09-07 11:37 - 000032804 _____ C:\WINDOWS\system32\AMDKernelEvents.man
2017-09-07 11:37 - 2017-09-07 11:37 - 000029720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\detoured.dll
2017-09-07 11:37 - 2017-09-07 11:37 - 000029720 _____ (Microsoft Corporation) C:\WINDOWS\system32\detoured.dll
2017-09-04 08:55 - 2017-09-04 08:55 - 000436132 _____ C:\Users\SpenserB\Downloads\Mercedes Benz Stadium Parking.pdf
2017-09-03 09:05 - 2017-08-04 01:31 - 001564512 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2017-09-03 09:05 - 2017-08-04 01:31 - 001214816 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2017-09-03 09:05 - 2017-08-04 01:31 - 000629088 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2017-09-03 09:05 - 2017-08-04 01:31 - 000544096 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2017-09-03 09:05 - 2017-08-04 01:31 - 000335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2017-09-03 09:05 - 2017-08-04 01:31 - 000334176 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2017-09-03 09:05 - 2017-08-04 01:31 - 000233824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2017-09-03 09:05 - 2017-08-04 01:31 - 000136032 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2017-09-03 09:05 - 2017-08-04 01:31 - 000096608 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2017-09-03 09:05 - 2017-08-04 01:31 - 000034656 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2017-09-03 09:05 - 2017-08-04 00:26 - 000192864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-09-20 23:21 - 2015-08-09 15:53 - 000000000 ____D C:\Users\SpenserB\AppData\Roaming\uTorrent
2017-09-20 23:06 - 2016-03-08 00:16 - 003149460 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-09-20 23:03 - 2015-08-10 17:26 - 000000000 ____D C:\Users\SpenserB\AppData\Roaming\Spotify
2017-09-20 23:01 - 2016-07-02 21:17 - 000000000 ___RD C:\Users\SpenserB\Google Drive
2017-09-20 23:00 - 2016-09-23 11:59 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-09-20 23:00 - 2016-07-16 02:04 - 018087936 _____ C:\WINDOWS\system32\config\HARDWARE
2017-09-20 23:00 - 2016-07-16 02:04 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2017-09-20 22:59 - 2016-09-23 11:55 - 000065536 _____ C:\WINDOWS\system32\spu_storage.bin
2017-09-20 22:34 - 2015-08-10 17:26 - 000000000 ____D C:\Users\SpenserB\AppData\Local\Spotify
2017-09-20 22:23 - 2016-09-23 11:56 - 000000000 ____D C:\Users\SpenserB
2017-09-20 22:12 - 2017-02-16 17:18 - 000000000 ____D C:\Users\SpenserB\AppData\Roaming\AlbionOnline
2017-09-20 22:12 - 2017-02-09 14:12 - 000000000 ____D C:\ProgramData\Hi-Rez Studios
2017-09-20 22:12 - 2015-08-09 13:48 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-09-20 21:46 - 2016-01-13 21:13 - 000000000 ___RD C:\Users\SpenserB\OneDrive
2017-09-20 21:33 - 2015-07-22 10:25 - 000000000 ____D C:\MSI
2017-09-20 21:23 - 2017-07-11 02:54 - 000000000 ____D C:\$WINDOWS.~BT
2017-09-20 21:23 - 2016-09-23 15:54 - 000000000 ___DC C:\WINDOWS\Panther
2017-09-20 20:58 - 2016-09-23 11:59 - 000012355 _____ C:\WINDOWS\diagwrn.xml
2017-09-20 20:58 - 2016-09-23 11:59 - 000009528 _____ C:\WINDOWS\diagerr.xml
2017-09-20 20:58 - 2015-08-09 12:40 - 000000000 __RHD C:\ESD
2017-09-20 20:48 - 2016-09-23 11:55 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2017-09-20 19:56 - 2016-04-18 12:47 - 000000000 ____D C:\Users\SpenserB\AppData\Local\MicrosoftEdge
2017-09-20 19:46 - 2016-02-21 13:47 - 000000000 ____D C:\Users\SpenserB\AppData\Local\Black_Tree_Gaming
2017-09-20 19:46 - 2015-08-10 17:32 - 000000000 ____D C:\Program Files\Rockstar Games
2017-09-20 19:46 - 2015-08-10 17:32 - 000000000 ____D C:\Program Files (x86)\Rockstar Games
2017-09-20 18:39 - 2016-07-16 07:45 - 000000000 ____D C:\WINDOWS\INF
2017-09-20 18:38 - 2017-01-12 21:06 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2017-09-20 18:37 - 2017-02-13 23:52 - 000000060 _____ C:\ProgramData\SoftwareUpdateTemp.xml
2017-09-20 18:15 - 2015-12-02 20:51 - 000000000 ____D C:\Program Files (x86)\Zenimax Online
2017-09-20 16:31 - 2013-08-22 11:36 - 000000000 ____D C:\WINDOWS\MediaViewer
2017-09-20 16:07 - 2015-12-02 20:51 - 000000000 ____D C:\Users\SpenserB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Elder Scrolls Online
2017-09-20 15:37 - 2016-07-16 07:47 - 000000000 ____D C:\WINDOWS\ShellExperiences
2017-09-20 14:37 - 2016-07-16 07:47 - 000000000 ____D C:\WINDOWS\ModemLogs
2017-09-20 14:29 - 2015-08-09 16:16 - 000000000 ____D C:\Program Files\PeerBlock
2017-09-20 14:26 - 2016-07-16 07:47 - 000000000 ____D C:\WINDOWS\Globalization
2017-09-20 14:18 - 2015-12-02 20:06 - 000000000 ____D C:\Users\SpenserB\AppData\Roaming\Origin
2017-09-20 14:17 - 2015-12-02 20:04 - 000000000 ____D C:\ProgramData\Origin
2017-09-20 14:02 - 2013-08-22 11:36 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2017-09-20 13:58 - 2016-09-23 11:55 - 000000000 ____D C:\Program Files\AMD
2017-09-20 13:55 - 2015-07-22 11:21 - 000000000 ____D C:\AMD
2017-09-20 13:54 - 2016-12-16 17:15 - 000000000 ____D C:\Users\SpenserB\AppData\LocalLow\Mozilla
2017-09-20 13:47 - 2015-08-12 07:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2017-09-20 13:24 - 2017-06-27 17:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\A3Launcher
2017-09-20 13:24 - 2017-06-27 17:59 - 000000000 ____D C:\Program Files (x86)\A3Launcher
2017-09-20 08:51 - 2016-07-16 07:47 - 000000000 ___HD C:\Program Files\WindowsApps
2017-09-20 08:51 - 2016-07-16 07:47 - 000000000 ____D C:\WINDOWS\AppReadiness
2017-09-20 08:51 - 2015-07-22 09:19 - 000000000 ____D C:\Users\SpenserB\AppData\Local\Packages
2017-09-20 08:50 - 2016-09-23 11:55 - 000000000 ____D C:\ProgramData\Package Cache
2017-09-19 06:15 - 2016-07-02 21:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2017-09-17 23:57 - 2015-12-02 20:11 - 000000000 ____D C:\Users\SpenserB\AppData\Local\Glyph
2017-09-17 20:12 - 2016-07-16 07:47 - 000000000 ____D C:\WINDOWS\rescache
2017-09-14 15:47 - 2016-03-08 00:13 - 000000000 __RHD C:\Users\Public\AccountPictures
2017-09-14 15:40 - 2016-09-23 11:55 - 000203232 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-09-13 01:15 - 2016-07-16 10:29 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2017-09-13 01:15 - 2016-07-16 07:47 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-09-13 01:15 - 2016-07-16 07:47 - 000000000 ___SD C:\WINDOWS\system32\F12
2017-09-13 01:15 - 2016-07-16 07:47 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-09-13 01:15 - 2016-07-16 07:47 - 000000000 ___RD C:\Program Files\Windows Defender
2017-09-13 01:15 - 2016-07-16 07:47 - 000000000 ____D C:\WINDOWS\system32\oobe
2017-09-13 01:15 - 2016-07-16 07:47 - 000000000 ____D C:\WINDOWS\system32\migwiz
2017-09-13 01:15 - 2016-07-16 07:47 - 000000000 ____D C:\WINDOWS\Provisioning
2017-09-13 01:15 - 2016-07-16 07:47 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2017-09-13 01:15 - 2016-07-16 07:47 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-09-13 01:15 - 2016-07-16 07:47 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2017-09-12 21:27 - 2016-07-16 07:36 - 000000000 ____D C:\WINDOWS\CbsTemp
2017-09-12 21:23 - 2015-08-10 17:50 - 000000000 ____D C:\WINDOWS\system32\MRT
2017-09-12 21:22 - 2015-08-10 17:50 - 138202976 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-09-12 20:47 - 2016-07-16 07:43 - 000333312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2017-09-12 20:47 - 2016-07-16 07:42 - 000439296 _____ (Microsoft Corporation) C:\WINDOWS\system32\wksprt.exe
2017-09-12 20:47 - 2016-07-16 07:42 - 000079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkInternalPS.dll
2017-09-11 14:58 - 2017-01-30 19:41 - 000000000 ____D C:\Users\SpenserB\AppData\Local\The Witcher
2017-09-08 23:52 - 2017-07-27 13:24 - 000003366 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-103190811-3506236208-3295715728-1001
2017-09-08 23:52 - 2017-01-30 13:13 - 000000000 ____D C:\Program Files (x86)\GOG Galaxy
2017-09-08 23:52 - 2016-03-08 00:15 - 000002372 _____ C:\Users\SpenserB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-09-07 11:37 - 2017-07-26 19:05 - 000925208 _____ (AMD) C:\WINDOWS\system32\coinst_17.30.dll
2017-09-07 11:37 - 2017-04-11 14:11 - 000547352 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Rapidfire64.dll
2017-09-07 11:37 - 2017-04-11 14:11 - 000478744 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\Rapidfire.dll
2017-09-07 11:37 - 2017-04-11 14:11 - 000045592 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\RapidFireServer64.dll
2017-09-07 11:37 - 2017-04-11 14:11 - 000043032 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\RapidFireServer.dll
2017-09-07 11:37 - 2016-12-29 07:21 - 000113176 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdxc64.dll
2017-09-07 11:37 - 2016-12-29 07:21 - 000099864 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdxc32.dll
2017-09-07 11:37 - 2016-10-01 05:10 - 000574464 _____ C:\WINDOWS\system32\amdmiracast.dll
2017-09-07 11:37 - 2016-10-01 05:10 - 000196840 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdhcp64.dll
2017-09-07 11:37 - 2016-10-01 05:10 - 000139744 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdave64.dll
2017-09-07 11:37 - 2016-10-01 05:10 - 000131944 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdpcom64.dll
2017-09-07 11:37 - 2016-10-01 05:06 - 000467992 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atidemgy.dll
2017-09-07 11:37 - 2016-10-01 05:05 - 000069656 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ati2erec.dll
2017-09-07 11:37 - 2016-10-01 05:03 - 000864792 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdlvr64.dll
2017-09-07 11:37 - 2016-10-01 05:03 - 000515096 _____ C:\WINDOWS\system32\amdgfxinfo64.dll
2017-09-07 11:37 - 2016-10-01 05:03 - 000092184 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmcl64.dll
2017-09-07 11:37 - 2016-10-01 04:56 - 001541144 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiadlxx.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 012515352 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdvlk64.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 010294808 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdvlk32.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 002915864 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amfrt64.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 002530328 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amfrt32.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 001058328 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxy.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000781848 _____ (AMD) C:\WINDOWS\system32\atieclxx.exe
2017-09-07 11:37 - 2016-09-13 22:08 - 000696856 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdlvr32.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000666648 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiapfxx.exe
2017-09-07 11:37 - 2016-09-13 22:08 - 000552984 _____ C:\WINDOWS\system32\dgtrayicon.exe
2017-09-07 11:37 - 2016-09-13 22:08 - 000552472 _____ (AMD) C:\WINDOWS\system32\atiesrxx.exe
2017-09-07 11:37 - 2016-09-13 22:08 - 000531992 _____ C:\WINDOWS\system32\GameManager64.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000484376 _____ C:\WINDOWS\system32\atieah64.exe
2017-09-07 11:37 - 2016-09-13 22:08 - 000370200 _____ C:\WINDOWS\system32\clinfo.exe
2017-09-07 11:37 - 2016-09-13 22:08 - 000366104 _____ C:\WINDOWS\SysWOW64\GameManager32.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000360984 _____ C:\WINDOWS\SysWOW64\amdgfxinfo32.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000334872 _____ C:\WINDOWS\SysWOW64\atieah32.exe
2017-09-07 11:37 - 2016-09-13 22:08 - 000277016 _____ C:\WINDOWS\system32\hsa-thunk64.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000245784 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6txx.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000242712 _____ C:\WINDOWS\SysWOW64\hsa-thunk.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000204312 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atigktxx.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000192024 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantle64.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000170520 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantleaxl64.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000168472 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atisamu64.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000165072 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdhcp32.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000157360 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\aticfx64.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000151576 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantle32.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000149104 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\aticfx32.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000136216 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantleaxl32.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000134168 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atisamu32.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000131944 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atimpc64.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000124952 _____ (AMD) C:\WINDOWS\system32\atimuixx.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000116736 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdave32.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000115736 _____ C:\WINDOWS\system32\atidxx64.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000103184 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdpcom32.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000103176 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atimpc32.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000102424 _____ C:\WINDOWS\SysWOW64\atidxx32.dll
2017-09-07 11:37 - 2016-09-13 22:08 - 000075800 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdmcl32.dll
2017-09-07 11:37 - 2016-06-24 16:37 - 000822448 _____ C:\WINDOWS\SysWOW64\atiapfxx.blb
2017-09-07 11:37 - 2016-06-24 16:37 - 000822448 _____ C:\WINDOWS\system32\atiapfxx.blb
2017-09-07 11:37 - 2016-06-24 16:33 - 003437632 _____ C:\WINDOWS\system32\atiumd6a.cap
2017-09-07 11:37 - 2016-06-24 16:28 - 003471376 _____ C:\WINDOWS\SysWOW64\atiumdva.cap
2017-09-07 11:37 - 2015-12-16 21:06 - 000000145 _____ C:\WINDOWS\system32\amd-vulkan64.json
2017-09-07 11:37 - 2015-12-15 17:54 - 000000145 _____ C:\WINDOWS\SysWOW64\amd-vulkan32.json
2017-09-05 15:01 - 2017-04-23 16:05 - 000835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-09-05 15:01 - 2017-04-23 16:05 - 000177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-09-05 01:23 - 2015-08-09 16:20 - 000000000 ____D C:\Users\SpenserB\AppData\Roaming\vlc
2017-09-03 09:03 - 2015-08-09 13:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
2017-09-03 09:03 - 2015-08-09 13:54 - 000000000 ____D C:\Program Files (x86)\MSI
2017-09-01 21:00 - 2015-08-10 17:16 - 000002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-09-01 21:00 - 2015-08-10 17:16 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-08-27 23:37 - 2017-02-16 17:00 - 000000829 _____ C:\Users\SpenserB\Desktop\AlbionOnline.lnk

==================== Files in the root of some directories =======

2015-08-09 13:47 - 2015-08-09 17:58 - 000000000 _____ () C:\Users\SpenserB\AppData\Local\Driver_LOM_8161Present.flag
2017-09-20 16:23 - 2017-09-20 16:23 - 000000017 _____ () C:\Users\SpenserB\AppData\Local\resmon.resmoncfg
2017-07-18 23:35 - 2017-07-18 23:35 - 000000121 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
2017-02-13 23:52 - 2017-09-20 18:37 - 000000060 _____ () C:\ProgramData\SoftwareUpdateTemp.xml

Some files in TEMP:
====================
2017-09-20 16:06 - 2017-09-20 16:06 - 000363208 _____ (BitRaider, LLC) C:\Users\SpenserB\AppData\Local\Temp\BRSVC_1558921_hlp.exe
2016-12-08 17:46 - 2016-12-05 14:38 - 024693376 _____ (MSI                                                         ) C:\Users\SpenserB\AppData\Local\Temp\Command Center.exe
2017-08-02 07:20 - 2017-08-02 07:20 - 000036864 _____ () C:\Users\SpenserB\AppData\Local\Temp\DT4000 G2-0016-E-ParaDelay.exe
2017-09-20 20:12 - 2017-09-20 20:12 - 000036864 _____ () C:\Users\SpenserB\AppData\Local\Temp\DT4000 G2-0768-E-ParaDelay.exe
2017-09-20 18:56 - 2017-09-20 17:35 - 068408664 _____ (Malwarebytes                                                ) C:\Users\SpenserB\AppData\Local\Temp\mbam-setup.exe
2017-02-08 21:11 - 2017-02-08 21:12 - 043976160 _____ (Skype Technologies S.A.) C:\Users\SpenserB\AppData\Local\Temp\SkypeSetup.exe
2017-08-08 09:27 - 2017-08-08 09:27 - 013767776 _____ (Microsoft Corporation) C:\Users\SpenserB\AppData\Local\Temp\vcredist_x86.exe
2017-06-20 21:14 - 2017-08-06 09:37 - 030950664 _____ () C:\Users\SpenserB\AppData\Local\Temp\vlc-2.2.6-win32.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-09-18 15:54

==================== End of FRST.txt ============================

 

 

Link to post
Share on other sites

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-09-2017
Ran by SpenserB (20-09-2017 23:24:56)
Running from C:\Users\SpenserB\Desktop
Windows 10 Pro Version 1607 (X64) (2016-09-23 16:00:13)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-103190811-3506236208-3295715728-500 - Administrator - Disabled)
ASPNET (S-1-5-21-103190811-3506236208-3295715728-1003 - Limited - Enabled)
DefaultAccount (S-1-5-21-103190811-3506236208-3295715728-503 - Limited - Disabled)
Guest (S-1-5-21-103190811-3506236208-3295715728-501 - Limited - Disabled)
SpenserB (S-1-5-21-103190811-3506236208-3295715728-1001 - Administrator - Enabled) => C:\Users\SpenserB

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-103190811-3506236208-3295715728-1001\...\uTorrent) (Version: 3.5.0.43916 - BitTorrent Inc.)
7-Zip 15.14 (x64) (HKLM\...\7-Zip) (Version: 15.14 - Igor Pavlov)
A3Launcher version 0.1.5.5 (HKLM-x32\...\{1E29A86E-9AE2-4CD8-74C8-6B170ED3C4D2}_is1) (Version: 0.1.5.5 - Maca134)
Albion Online (HKLM-x32\...\SandboxAlbionOnline) (Version:  - Sandbox Interactive GmbH)
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.8 - Advanced Micro Devices, Inc.)
Apple Application Support (32-bit) (HKLM-x32\...\{29DB9165-5FC1-48F0-9188-26123F526848}) (Version: 5.0.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{5905C8CF-1C88-4478-A48E-4E458AD1BC7E}) (Version: 5.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{D4D86CB2-2370-4691-8272-3869EDED6C64}) (Version: 10.0.0.18 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
BattlEye for OA Uninstall (HKLM-x32\...\BattlEye for OA) (Version:  - )
Becker's CPA Exam Review (HKLM-x32\...\{21548F9B-1132-474C-968C-EC197316529C}) (Version: 13.15.0 - Becker Professional Education)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Borderlands (HKLM\...\Steam App 8980) (Version:  - Gearbox Software)
Catalyst Control Center Next Localization BR (HKLM\...\{118C2119-84B6-E32C-63E2-B56DBCF41CE5}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (HKLM\...\{6A69EDE3-D163-A85B-EFF5-B6BFD8EF5939}) (Version: 2017.0905.1156.19665 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{4F486CF2-F8AF-2DD4-BA15-82BD71BC3035}) (Version: 2017.0905.1156.19665 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{5A083A57-10D6-D4E5-292C-F274870E73A4}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{08E3C0C2-26E9-9DDF-0FBD-A4A71C970D75}) (Version: 2017.0905.1156.19665 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{DF0D7C1C-72B6-9FFB-DF66-B3720237BB80}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{0DA8E688-E5E8-6036-A272-E88E6DADDBC0}) (Version: 2015.1118.123.2413 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{238F6F6F-2544-86CF-3AB6-2CDADAB58CF0}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{E8ED0DBD-DAC0-1BC5-87A7-5FC3BEAD33AB}) (Version: 2017.0905.1156.19665 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{2802B62A-05D9-356B-9DB6-AFEE51E9EF5E}) (Version: 2017.0905.1156.19665 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{6B2CF40F-BACE-9E09-7C8B-BB3FD80CE4EF}) (Version: 2015.1118.123.2413 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{EC688BD0-240D-AE40-55F3-234E54919AE6}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{8E1F1F1A-38D8-DC76-FE6C-B8412AF9396D}) (Version: 2017.0905.1156.19665 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{E27224E3-7913-DA1E-5B08-9BEEC8FEE3D1}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{E930EF99-63C8-CDB4-64A3-1C81C88B93D2}) (Version: 2015.1118.123.2413 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{95A52FC1-C728-841D-1BFC-CC793B77B0A4}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{D3376CD8-E366-C5F5-B9D1-2B8017C4F1C5}) (Version: 2017.0905.1156.19665 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{D38AD24D-4C74-7510-B738-0C61ADEB748F}) (Version: 2015.1118.123.2413 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{6E1A9892-7E25-1C75-C264-AEFC043603B3}) (Version: 2015.1118.123.2413 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{A22CDEBA-6DB5-12CD-F6CE-6238C2D78363}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{C8013991-2166-AFC4-B75B-7E58FBEF02AF}) (Version: 2017.0905.1156.19665 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{3CB92C15-57A0-E469-1CE3-236BB1569F88}) (Version: 2017.0905.1156.19665 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{6F86ED69-6EA1-5E28-B1C9-88951D4C11D4}) (Version: 2015.1118.123.2413 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{C0BFC67D-E447-02C8-6046-C078DFE9EC97}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{7B321DF7-3626-0CC3-C602-006B2339FCC8}) (Version: 2015.1118.123.2413 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{94C72EBE-2908-F0AC-62DA-D61951830F8F}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{D9E8F7A4-5D65-FA27-F201-F5F0FD82D035}) (Version: 2017.0905.1156.19665 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{5B987681-3652-492B-6A11-E02AC0FE5959}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{60821F44-17A1-0286-10E7-3FE3956D3B85}) (Version: 2017.0905.1156.19665 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{04E38C1D-A2B0-1419-8ACC-98B6FEAD2AE3}) (Version: 2017.0905.1156.19665 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{86BFE5B4-1FCE-3C02-6373-92B1AE6431E8}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{0742432E-42D9-2240-4CA1-8595CCCBAA77}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{082B8683-4ED5-212D-33E6-7F0993292B6D}) (Version: 2017.0905.1156.19665 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{CBE7BA08-EAC5-DE2B-440F-F4D8BEB70AF0}) (Version: 2017.0905.1156.19665 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{EAEAA839-44F4-22DF-D1CC-88C3B2A3D4B1}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{0B3B12AC-956C-3D2B-E375-CA8A210A8B3C}) (Version: 2017.0905.1156.19665 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{A3973655-E448-4A1B-477C-988A79D132D9}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{6DC92550-D065-4B36-C4D3-D8D7A702A7A7}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{7443BBA4-32DB-B648-5092-0C52676507CD}) (Version: 2017.0905.1156.19665 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{B2A83706-3F14-1532-20CD-B4EE715A8945}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{D519CA66-2A8D-EA88-7904-0ADF96FC975B}) (Version: 2017.0905.1156.19665 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{44ED2CDA-4197-E9E9-B328-26E1FB749116}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{591B77CA-0AE6-A405-5A73-D5600D45F9E8}) (Version: 2017.0905.1156.19665 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{3450566C-4561-0EE8-B1AB-D5C79CCE8D2C}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{FB81D531-71CC-69A0-F776-95C2498492F0}) (Version: 2017.0905.1156.19665 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{31BA3CC8-6A73-126C-B424-16A56B64C75F}) (Version: 2017.0905.1156.19665 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{FCE8438C-3272-D63F-479F-670F082B294B}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{203DA8C6-D37D-632D-6606-187E3BEAB254}) (Version: 2017.0905.1156.19665 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{25D1751E-7CA2-5F6D-0125-0A16E47AF9FE}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
ChromecastApp (HKU\S-1-5-21-103190811-3506236208-3295715728-1001\...\{079ede36-133d-44b0-8053-c7c1fa8d2e0d}_is1) (Version: 1.5.1693.0 - Google Inc.)
DayZLauncher version 0.0.2.5 (HKLM-x32\...\{E31045B4-9DB5-9EBD-44DF-BD4E6CFD40DF}_is1) (Version: 0.0.2.5 - Maca134)
Discord (HKU\S-1-5-21-103190811-3506236208-3295715728-1001\...\Discord) (Version: 0.0.298 - Discord Inc.)
GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version:  - GOG.com)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 60.0.3112.113 - Google Inc.)
Google Drive (HKLM-x32\...\{F9A2761E-C1E4-4384-92A3-5732C9738327}) (Version: 2.34.6717.9565 - Google, Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
Intel(R) Chipset Device Software (HKLM-x32\...\{c7f54569-0018-439c-809a-48046a4d4ebc}) (Version: 10.1.1.9 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1158 - Intel Corporation)
Intel® Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation)
iTunes (HKLM\...\{9946A4F7-E0FD-4A33-82D1-06CBFFBBB9F9}) (Version: 12.5.1.21 - Apple Inc.)
Killer Bandwidth Control Filter Driver (HKLM\...\{5B7A2B7B-CEA9-4E50-B0E4-E82F204CBE78}) (Version: 1.1.57.1125 - Rivet Networks) Hidden
Killer E220x Drivers (HKLM\...\{77C95134-CA2D-4614-9C86-55B7A6A281AA}) (Version: 1.1.57.1125 - Rivet Networks) Hidden
Killer Network Manager (HKLM\...\{51B5A084-A40D-4F4B-90AA-EF8354EA7D96}) (Version: 1.1.57.1125 - Rivet Networks) Hidden
Killer Performance Suite (HKLM-x32\...\{E70DB50B-10B4-46BC-9DE2-AB8B49E061EE}) (Version: 1.1.57.1125 - Rivet Networks)
League of Legends (HKLM-x32\...\{79BF4901-1EC4-4726-B3C2-A7859706C6E7}) (Version: 3.0.1 - Riot Games) Hidden
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
Logitech Gaming Software 8.70 (HKLM\...\Logitech Gaming Software) (Version: 8.70.315 - Logitech Inc.)
Malwarebytes version 3.2.2.2029 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.2.2.2029 - Malwarebytes)
Mass Effect™ (HKLM-x32\...\{44A570EE-FD93-4086-8997-2C38DFDE0019}) (Version: 1.2.20608.0 - Electronic Arts)
Microsoft .NET Framework 1.1 (HKLM-x32\...\Microsoft .NET Framework 1.1  (1033)) (Version:  - )
Microsoft OneDrive (HKU\S-1-5-21-103190811-3506236208-3295715728-1001\...\OneDriveSetup.exe) (Version: 17.3.6966.0824 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)
MotioninJoy Gamepad tool 0.7.1001 (HKLM\...\{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1) (Version: 0.7.1001 - www.motioninjoy.com)
MSI Command Center (HKLM-x32\...\{85A2564E-9ED9-448A-91E4-B9211EE58A08}_is1) (Version: 1.0.1.18 - MSI)
MSI Fast Boot (HKLM-x32\...\{0F212E7A-65EB-4668-A8D7-749026A64F8E}_is1) (Version: 1.0.1.11 - MSI)
MSI Gaming APP (HKLM-x32\...\{E0229316-E73B-484B-B9E0-45098AB38D8C}}_is1) (Version: 6.2.0.27 - MSI)
MSI Smart Tool (HKLM-x32\...\{DDCCA038-DAB1-4D09-B85C-848020AA75D6}}_is1) (Version: 1.0.0.19 - MSI)
MSI Super Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.3.0.18 - MSI)
MSI(R) Intel(R) Extreme Tuning Utility (HKLM-x32\...\{5D85C662-99AB-4B25-A6F0-ABB9D702F552}) (Version: 6.0.2.102 - Intel Corporation) Hidden
MSI(R) Intel(R) Extreme Tuning Utility (HKLM-x32\...\{bcbf202c-9746-4173-a49b-649bfd0adca6}) (Version: 6.0.2.102 - Intel Corporation)
NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
PCSX2 - Playstation 2 Emulator (HKLM-x32\...\pcsx2) (Version:  - )
PeerBlock 1.1+ (r691) (HKLM\...\{015C5B35-B678-451C-9AEE-821E8D69621C}_is1) (Version: 1.1.0.691 - PeerBlock, LLC)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8034 - Realtek Semiconductor Corp.)
Sid Meier's Civilization V (HKLM-x32\...\steam app 8930) (Version:  - 2K Games, Inc.)
Skype™ 7.31 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.31.104 - Skype Technologies S.A.)
Skyrim Script Extender (SKSE) (HKLM-x32\...\Steam App 365720) (Version:  - The SKSE Team)
Sophos Virus Removal Tool (HKLM-x32\...\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.6.1 - Sophos Limited)
SoulseekQt version 2017.2.20 (HKLM-x32\...\{8A4E1646-488C-4E5B-AC31-F784400E8D2D}_is1) (Version: 2017.2.20 - Soulseek LLC)
Spotify (HKU\S-1-5-21-103190811-3506236208-3295715728-1001\...\Spotify) (Version: 1.0.63.617.g5aca9a2a - Spotify AB)
Star Wars: Knights of the Old Republic (HKLM-x32\...\Steam App 32370) (Version:  - BioWare)
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH)
The Witcher Enhanced Edition Director's Cut (HKLM-x32\...\1207658924_is1) (Version: 2.1.0.15 - GOG.com)
Uplay (HKLM-x32\...\Uplay) (Version: 27.0 - Ubisoft)
VGA Boost (HKLM-x32\...\{809ACFAE-9A4D-4C60-9223-D8B615CD8CBA}}_is1) (Version: 1.0.0.8 - MSI)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.6 - VideoLAN)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.6 - VideoLAN)
Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.37.0 (HKLM\...\VulkanRT1.0.37.0) (Version: 1.0.37.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.39.1 (HKLM\...\VulkanRT1.0.39.1) (Version: 1.0.39.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.39.1 (HKLM\...\VulkanRT1.0.39.1-2) (Version: 1.0.39.1 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.51.0 (HKLM\...\VulkanRT1.0.51.0) (Version: 1.0.51.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.54.0 (HKLM\...\VulkanRT1.0.54.0) (Version: 1.0.54.0 - LunarG, Inc.)
Windows 10 Update and Privacy Settings (HKLM\...\{4DFCD818-036A-4229-A67D-CF17DC461D92}) (Version: 1.0.14.0 - Microsoft Corporation)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-103190811-3506236208-3295715728-1001_Classes\CLSID\{144DF3B2-2402-47AE-9583-5A045929A8D4}\InprocServer32 -> C:\Users\SpenserB\AppData\Local\Google\Update\1.3.33.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-103190811-3506236208-3295715728-1001_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\SpenserB\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-103190811-3506236208-3295715728-1001_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\SpenserB\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-103190811-3506236208-3295715728-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\SpenserB\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-103190811-3506236208-3295715728-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\SpenserB\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-103190811-3506236208-3295715728-1001_Classes\CLSID\{8C46158B-D978-483C-A312-16EE5013BE04}\InprocServer32 -> C:\Users\SpenserB\AppData\Local\Google\Update\1.3.33.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-103190811-3506236208-3295715728-1001_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\SpenserB\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-103190811-3506236208-3295715728-1001_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\SpenserB\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-103190811-3506236208-3295715728-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\SpenserB\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-103190811-3506236208-3295715728-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\SpenserB\AppData\Local\Google\Update\1.3.33.5\psuser_64.dll (Google Inc.)
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-08-31] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-08-31] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-08-31] (Google)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-12-31] (Igor Pavlov)
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-08-31] (Google)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-12-31] (Igor Pavlov)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-08-31] (Google)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} =>  -> No File
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-12-31] (Igor Pavlov)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0D9F06F4-1816-43DA-8D70-32A2AB12184C} - System32\Tasks\MSIOSDx86_Host => c:\program files (x86)\msi\gaming app\OSD\x86\MsiGamingOSD_x86.exe [2016-07-28] (Micro-Star INT'L CO., LTD.)
Task: {1B41F4F3-03AD-4163-9F49-D6C8DBC091D3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-09] (Google Inc.)
Task: {241510C3-B23A-45D9-AD48-B2EA157A9322} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {34FA781D-9D43-49AD-B7DD-1E23A2A92BAE} - System32\Tasks\MSIOSDx64_Host => c:\program files (x86)\msi\gaming app\OSD\x64\MsiGamingOSD_x64.exe [2016-07-28] (Micro-Star INT'L CO., LTD.)
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\WINDOWS\System32\AutoWorkplace.exe
Task: {3DF6C939-7223-4F22-B181-6BBCC49CAD1E} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
Task: {3DFEA55B-0E2A-4063-B0AE-1E72C74254D8} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {47AFC908-5AF5-4AE5-BCFF-77803CB462CA} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-103190811-3506236208-3295715728-1001Core1d258b4c42c70e5 => C:\Users\SpenserB\AppData\Local\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {4B9FF657-85A1-46B4-82E5-143D7D4F81CE} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {4BFF83DE-5EB2-4CD8-B144-32E35B11E054} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {535A9CD2-C276-455D-BCFF-C776F39C99DE} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-103190811-3506236208-3295715728-1001UA => C:\Users\SpenserB\AppData\Local\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {59CE60CE-3398-4862-A344-BFCF7FA0DAF6} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {60CA5814-3CA8-41D1-817C-EE5A0806A971} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {65D17CB9-96C3-43C1-AC73-14A59DE73B62} - \7530278 -> No File <==== ATTENTION
Task: {6EC346E4-D1CE-420B-94B7-C10254EBA6B5} - System32\Tasks\MSIGH_Host => c:\program files (x86)\msi\gaming app\GamingHotkey.exe [2017-06-23] (Micro-Star INT'L CO., LTD.)
Task: {737E59EC-EFA7-4B7A-810A-3AB4DCACB241} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {75F82A11-EA75-4F32-BB8C-5ABBA3FDB842} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-103190811-3506236208-3295715728-1001UA1d258b4c42f7e50 => C:\Users\SpenserB\AppData\Local\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {88C0A2D9-C5C2-45F5-BEAC-53434526AF37} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {92E6AEF8-1352-4E1A-9BCF-8746C7023DB4} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-09-12] (Microsoft Corporation)
Task: {9E420D17-06C4-436F-BAF5-3C3B3D92DD82} - System32\Tasks\Intel\Intel Telemetry 2 (x86) => C:\Program Files (x86)\Intel\Telemetry 2.0\lrio.exe [2015-05-05] (Intel Corporation)
Task: {A170C0D6-E2A9-405B-B05B-1C02A5A28B50} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {BA1EAE19-23B8-4776-84D5-4286FC84063B} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-103190811-3506236208-3295715728-1001Core => C:\Users\SpenserB\AppData\Local\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {BBBDB208-35EE-4BB8-93C1-BC7EDD1BEC09} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {CB503C23-240D-491B-B326-CC1AAB459920} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
Task: {EFB34BB4-5926-42A6-B296-031134E7C0B2} - System32\Tasks\MSISW_Host => C:\WINDOWS\SysWOW64\muachost.exe [2015-08-18] (MSI)
Task: {F178303D-2AE7-45A8-8AB3-3C923664BDAF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-09] (Google Inc.)
Task: {F8660A7B-5CA4-44EF-8AA0-389BAA2CE27E} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {FE7DAE62-7DD4-455E-A9E0-C56A4A2B97E5} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [2017-09-05] (Advanced Micro Devices, Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-103190811-3506236208-3295715728-1001Core.job => C:\Users\SpenserB\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-103190811-3506236208-3295715728-1001UA.job => C:\Users\SpenserB\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2016-07-16 07:42 - 2016-07-16 07:42 - 000231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2017-09-12 21:08 - 2017-09-07 02:01 - 002681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-09-01 18:12 - 2016-09-01 18:12 - 000092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-09-01 18:12 - 2016-09-01 18:12 - 001353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-05-19 09:11 - 2015-05-19 09:11 - 000007680 _____ () C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe
2017-08-07 15:09 - 2016-06-14 16:35 - 000187392 _____ () c:\program files (x86)\msi\gaming app\OSD\x64\D3D11FontDraw.dll
2016-09-23 15:53 - 2016-09-23 15:53 - 000134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-03-14 17:24 - 2017-03-04 02:31 - 000474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2017-03-14 17:25 - 2017-03-04 02:12 - 009760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-03-14 17:25 - 2017-03-04 02:05 - 001401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-03-14 17:25 - 2017-03-04 02:05 - 000757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-09-12 21:08 - 2017-09-07 00:53 - 001033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2017-09-12 21:08 - 2017-09-07 00:53 - 002424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-09-12 21:08 - 2017-09-07 00:59 - 004853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2017-08-27 23:42 - 2017-08-27 23:42 - 000074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2017-08-27 23:42 - 2017-08-27 23:42 - 000203264 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2017-08-27 23:42 - 2017-08-27 23:42 - 036162048 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2017-08-27 23:42 - 2017-08-27 23:42 - 002237952 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\skypert.dll
2016-09-13 02:01 - 2016-09-13 02:01 - 000014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll
2016-09-13 02:01 - 2016-09-13 02:01 - 000739840 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll
2016-09-13 02:01 - 2016-09-13 02:01 - 000014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll
2016-09-13 02:01 - 2016-09-13 02:01 - 000071168 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll
2016-09-13 02:01 - 2016-09-13 02:01 - 000011776 _____ () C:\Program Files\AMD\CNext\CNext\libEGL.dll
2016-09-13 02:01 - 2016-09-13 02:01 - 002013696 _____ () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
2016-09-13 02:01 - 2016-09-13 02:01 - 000191488 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Dialogs\dialogplugin.dll
2015-03-06 20:07 - 2015-03-06 20:07 - 000908568 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll
2015-07-01 20:28 - 2015-07-01 20:28 - 001095448 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll
2015-03-06 20:07 - 2015-03-06 20:07 - 000060184 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll
2015-07-01 20:28 - 2015-07-01 20:28 - 000240408 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll
2017-09-01 21:00 - 2017-08-23 04:48 - 003824472 _____ () C:\Program Files (x86)\Google\Chrome\Application\60.0.3112.113\libglesv2.dll
2017-09-01 21:00 - 2017-08-23 04:48 - 000100184 _____ () C:\Program Files (x86)\Google\Chrome\Application\60.0.3112.113\libegl.dll
2017-09-20 23:01 - 2017-09-20 23:01 - 000098816 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\win32api.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000110080 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\pywintypes27.dll
2017-09-20 23:01 - 2017-09-20 23:01 - 000364544 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\pythoncom27.dll
2017-09-20 23:01 - 2017-09-20 23:01 - 000320512 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\win32com.shell.shell.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000914432 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\_hashlib.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 001176576 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\wx._core_.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000806400 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\wx._gdi_.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000816128 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\wx._windows_.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 001067008 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\wx._controls_.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000733184 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\wx._misc_.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000682496 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\pysqlite2._sqlite.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000088064 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\_ctypes.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000686080 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\unicodedata.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000119808 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\win32file.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000108544 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\win32security.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000007168 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\hashobjs_ext.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000017920 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\thumbnails_ext.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000088064 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\usb_ext.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000012800 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\common.time34.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000018432 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\win32event.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000167936 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\win32gui.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000046080 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\_socket.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 001303552 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\_ssl.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000128512 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\_elementtree.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000127488 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\pyexpat.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000038912 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\win32inet.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000036864 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\_psutil_windows.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000525208 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\windows._lib_cacheinvalidation.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000011264 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\win32crypt.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000123392 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\wx._wizard.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000077312 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\wx._html2.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000027648 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\_multiprocessing.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000020480 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\_yappi.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000035840 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\win32process.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000078848 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\wx._animate.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000024064 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\win32pipe.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000010240 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\select.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000025600 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\win32pdh.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000017408 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\win32profile.pyd
2017-09-20 23:01 - 2017-09-20 23:01 - 000022528 ____R () C:\Users\SpenserB\AppData\Local\Temp\_MEI75682\win32ts.pyd
2017-01-30 13:13 - 2016-12-20 12:43 - 053018112 _____ () C:\Program Files (x86)\GOG Galaxy\libcef.dll
2017-01-30 13:13 - 2017-09-08 23:51 - 000507968 _____ () C:\Program Files (x86)\GOG Galaxy\PocoUtil.dll
2017-01-30 13:13 - 2017-09-08 23:51 - 001076800 _____ () C:\Program Files (x86)\GOG Galaxy\PocoNet.dll
2017-01-30 13:13 - 2017-09-08 23:51 - 001854528 _____ () C:\Program Files (x86)\GOG Galaxy\PocoData.dll
2017-01-30 13:13 - 2017-09-08 23:51 - 000393280 _____ () C:\Program Files (x86)\GOG Galaxy\PocoDataSQLite.dll
2017-01-30 13:13 - 2017-09-08 23:51 - 001589312 _____ () C:\Program Files (x86)\GOG Galaxy\PocoFoundation.dll
2017-01-30 13:13 - 2017-09-08 23:51 - 000307776 _____ () C:\Program Files (x86)\GOG Galaxy\PocoNetSSL.dll
2017-01-30 13:13 - 2017-09-08 23:51 - 000330816 _____ () C:\Program Files (x86)\GOG Galaxy\PocoJSON.dll
2017-06-21 17:48 - 2017-09-08 23:51 - 000130112 _____ () C:\Program Files (x86)\GOG Galaxy\xdelta3.dll
2017-01-30 13:13 - 2017-09-08 23:51 - 000104000 _____ () C:\Program Files (x86)\GOG Galaxy\zlib.dll
2017-01-30 13:13 - 2017-09-08 23:51 - 000520768 _____ () C:\Program Files (x86)\GOG Galaxy\PocoXML.dll
2017-01-30 13:13 - 2017-09-08 23:51 - 000272448 _____ () C:\Program Files (x86)\GOG Galaxy\PocoZip.dll
2017-01-30 13:13 - 2017-09-08 23:51 - 000680000 _____ () C:\Program Files (x86)\GOG Galaxy\sqlite.dll
2017-01-30 13:13 - 2017-09-08 23:51 - 000425536 _____ () C:\Program Files (x86)\GOG Galaxy\pcre.dll
2017-01-30 13:13 - 2017-09-08 23:51 - 000157760 _____ () C:\Program Files (x86)\GOG Galaxy\PocoCrypto.dll
2017-01-30 13:13 - 2017-09-08 23:51 - 000152128 _____ () C:\Program Files (x86)\GOG Galaxy\expat.dll
2017-01-30 13:13 - 2017-09-08 23:51 - 001589312 _____ () C:\ProgramData\GOG.com\Galaxy\redists\PocoFoundation.dll
2017-01-30 13:13 - 2017-09-08 23:51 - 000330816 _____ () C:\ProgramData\GOG.com\Galaxy\redists\PocoJSON.dll
2017-01-30 13:13 - 2017-09-08 23:51 - 000507968 _____ () C:\ProgramData\GOG.com\Galaxy\redists\PocoUtil.dll
2017-01-30 13:13 - 2017-09-08 23:51 - 000104000 _____ () C:\ProgramData\GOG.com\Galaxy\redists\zlib.dll
2017-01-30 13:13 - 2017-09-08 23:51 - 000425536 _____ () C:\ProgramData\GOG.com\Galaxy\redists\pcre.dll
2017-01-30 13:13 - 2017-09-08 23:51 - 000520768 _____ () C:\ProgramData\GOG.com\Galaxy\redists\PocoXML.dll
2017-01-30 13:13 - 2017-09-08 23:51 - 000152128 _____ () C:\ProgramData\GOG.com\Galaxy\redists\expat.dll
2017-01-30 13:13 - 2016-12-20 12:43 - 001738752 _____ () C:\Program Files (x86)\GOG Galaxy\libglesv2.dll
2017-01-30 13:13 - 2016-12-20 12:43 - 000078848 _____ () C:\Program Files (x86)\GOG Galaxy\libegl.dll
2015-07-10 23:37 - 2015-07-10 23:37 - 001243936 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2015-08-10 17:26 - 2017-09-18 08:31 - 071818864 _____ () C:\Users\SpenserB\AppData\Roaming\Spotify\libcef.dll
2015-08-10 17:26 - 2017-09-18 08:31 - 002969200 _____ () C:\Users\SpenserB\AppData\Roaming\Spotify\libglesv2.dll
2015-08-10 17:26 - 2017-09-18 08:31 - 000086640 _____ () C:\Users\SpenserB\AppData\Roaming\Spotify\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:D62C83D5 [282]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 09:25 - 2017-09-20 19:02 - 000000713 _____ C:\WINDOWS\system32\Drivers\etc\hosts

5.149.252.98 www.gstatic.com
5.149.252.98 www.google-analytics.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-103190811-3506236208-3295715728-1001\Control Panel\Desktop\\Wallpaper -> D:\Personal Stuff\Pictures\squidbillies6.png
DNS Servers: 192.168.1.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

HKLM\...\StartupApproved\Run: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "Raptr"
HKU\S-1-5-21-103190811-3506236208-3295715728-1001\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_064C9B99C2D3F816C72AD15A5BF9F5D9"
HKU\S-1-5-21-103190811-3506236208-3295715728-1001\...\StartupApproved\Run: => "Google Update"
HKU\S-1-5-21-103190811-3506236208-3295715728-1001\...\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-103190811-3506236208-3295715728-1001\...\StartupApproved\Run: => "Spotify"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{8DF00CA8-6FF8-4B0B-8CA1-39353D4E6497}] => (Allow) D:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
FirewallRules: [{1163B76D-75AA-4B0D-B1F5-5563056AF717}] => (Allow) D:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
FirewallRules: [{F2B02D19-DCB7-4E53-A597-299C9C198608}] => (Allow) D:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe
FirewallRules: [{189626DF-BF46-49B6-B7F8-1F141C405795}] => (Allow) D:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe
FirewallRules: [{5BE4F156-2508-4B45-A535-EE51B744067B}] => (Allow) D:\Program Files (x86)\Origin Games\Mass Effect\Binaries\MassEffect.exe
FirewallRules: [{86950E35-349D-468E-8B91-3239363622D9}] => (Allow) D:\Program Files (x86)\Origin Games\Mass Effect\Binaries\MassEffect.exe
FirewallRules: [{3E35D5CD-78B7-46D6-8992-81C7C2A09DF6}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe
FirewallRules: [{C765911C-CDD5-4B77-98A0-0B2C18978B64}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe
FirewallRules: [{6B98109A-24EF-41C7-BD80-9C3D827D5645}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe
FirewallRules: [{A92062C6-8B8D-4797-94EF-A4A9ED3951B6}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe
FirewallRules: [{2402B6F6-B348-467B-BCCC-03F3A65E61E6}] => (Block) D:\steam\steamapps\common\lord of the rings online\lotroclient.exe
FirewallRules: [{1E3A6092-4378-48B4-AB7B-98D7CB14177A}] => (Block) D:\steam\steamapps\common\lord of the rings online\lotroclient.exe
FirewallRules: [UDP Query User{EDCD022D-A87B-4281-9BE5-E6C98A43BF21}D:\steam\steamapps\common\lord of the rings online\lotroclient.exe] => (Allow) D:\steam\steamapps\common\lord of the rings online\lotroclient.exe
FirewallRules: [TCP Query User{597CAEB5-AB68-4257-AE63-0A052D9CE7D7}D:\steam\steamapps\common\lord of the rings online\lotroclient.exe] => (Allow) D:\steam\steamapps\common\lord of the rings online\lotroclient.exe
FirewallRules: [{551934F1-36ED-4416-A955-CC703072080D}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe
FirewallRules: [{F3B54269-2F70-4156-8438-2B2A05702B9F}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe
FirewallRules: [TCP Query User{DBCDA7B9-1F0C-4D55-8CE4-533F0F18B595}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{CD64D81C-1459-48C2-815F-6E8736B7D056}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{3188D21E-72A7-4327-93CE-FAACD4D234DE}C:\users\spenserb\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\spenserb\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{E47BDAB3-95DE-4341-8033-9FA668E4BAD1}C:\users\spenserb\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\spenserb\appdata\roaming\spotify\spotify.exe
FirewallRules: [{79C3B20A-09BB-42C7-B8F9-812ADD87F7DD}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{CF9B8AB7-59BB-4706-8B36-2633109261DF}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{0AB79158-513F-4A00-BD17-FA8342924D17}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto V\GTA5.exe
FirewallRules: [{61F07C13-5245-4DC4-8E02-CDE6532EDAA2}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto V\GTA5.exe
FirewallRules: [TCP Query User{2F9F8595-1A8D-40C8-8A1E-B01C249B4836}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{BFBDF1D4-AA24-4E5C-8C1D-E60B2F710AF6}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{B41FD869-940B-4862-B85E-F0D8808FD19D}C:\users\spenserb\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\spenserb\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{2F0B4DB5-4E42-4CFE-8A78-B73C441E114E}C:\users\spenserb\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\spenserb\appdata\roaming\spotify\spotify.exe
FirewallRules: [{540AA4D4-845A-4467-909A-DF513118858C}] => (Allow) D:\Star Wars-The Old Republic\launcher.exe
FirewallRules: [{FD2AC07F-F868-4CE2-BFD3-2C3E83FEA733}] => (Allow) D:\Star Wars-The Old Republic\launcher.exe
FirewallRules: [{A97C007A-8690-42FB-941B-7260430C298D}] => (Allow) D:\Star Wars-The Old Republic\launcher.exe
FirewallRules: [{7CEA6DD3-C580-4EA5-8EC5-18F74BEE855B}] => (Allow) D:\Star Wars-The Old Republic\launcher.exe
FirewallRules: [TCP Query User{AFDF74A6-05C2-4BAA-ACC6-C494160A5C0F}C:\users\spenserb\appdata\local\temp\i1439416072\windows\resource\jre\bin\javaw.exe] => (Allow) C:\users\spenserb\appdata\local\temp\i1439416072\windows\resource\jre\bin\javaw.exe
FirewallRules: [UDP Query User{D96D2F34-E15C-40B1-83D0-DEBB8D2463E0}C:\users\spenserb\appdata\local\temp\i1439416072\windows\resource\jre\bin\javaw.exe] => (Allow) C:\users\spenserb\appdata\local\temp\i1439416072\windows\resource\jre\bin\javaw.exe
FirewallRules: [TCP Query User{702BE903-19E7-4F1F-90D5-87DA3CE0D931}C:\users\spenserb\appdata\local\temp\i1439417793\windows\resource\jre\bin\javaw.exe] => (Allow) C:\users\spenserb\appdata\local\temp\i1439417793\windows\resource\jre\bin\javaw.exe
FirewallRules: [UDP Query User{AD50D448-5337-48EA-B6CF-602F3CE93DFE}C:\users\spenserb\appdata\local\temp\i1439417793\windows\resource\jre\bin\javaw.exe] => (Allow) C:\users\spenserb\appdata\local\temp\i1439417793\windows\resource\jre\bin\javaw.exe
FirewallRules: [TCP Query User{1AE32F05-F5A1-4141-83B5-7E9AB892B1CF}C:\users\spenserb\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\spenserb\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [UDP Query User{7ADD1B89-D3A6-4C58-A792-E009BCBAB1F8}C:\users\spenserb\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\spenserb\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [TCP Query User{AB760A36-6F69-41B5-A6AC-7BFCB6755A20}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe
FirewallRules: [UDP Query User{A11D8F99-EB96-4D2D-9165-E299C777CDDE}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe
FirewallRules: [TCP Query User{6A68D964-C4C4-4CA7-B9D9-9576CB46376F}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe
FirewallRules: [UDP Query User{73409D39-C39A-4624-8209-A340ED6F5BE2}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe
FirewallRules: [{61EAADBE-3043-4FA0-B5F0-CBD6AAAED414}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{2DCBA65D-3AB1-42D6-BD0D-58BF43FD3289}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{E96F4E85-4C61-4186-A15A-0D889F8E6020}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{AFE2BF4E-31BB-484C-AC02-F55E96E17801}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{60B6E0F3-449B-4529-A971-B70FF3D0D436}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{1729084F-B705-4E85-97E4-40569D938DB3}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{FD971473-2E07-49AB-B32D-EB648ACA4992}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{7D42A4BA-B471-48EA-AC97-CD6AB6601932}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [TCP Query User{6A72E7E8-29D3-4B0D-8E3D-4FAAB2C7402F}C:\users\spenserb\appdata\local\temp\i1449103725\windows\resource\jre\bin\javaw.exe] => (Allow) C:\users\spenserb\appdata\local\temp\i1449103725\windows\resource\jre\bin\javaw.exe
FirewallRules: [UDP Query User{40284EE0-17CB-4D82-8F3A-3FB091AC841B}C:\users\spenserb\appdata\local\temp\i1449103725\windows\resource\jre\bin\javaw.exe] => (Allow) C:\users\spenserb\appdata\local\temp\i1449103725\windows\resource\jre\bin\javaw.exe
FirewallRules: [TCP Query User{2A89D04B-9435-4A43-8748-5A8F1B8AFE3F}C:\users\spenserb\appdata\local\temp\i1449103908\windows\resource\jre\bin\javaw.exe] => (Allow) C:\users\spenserb\appdata\local\temp\i1449103908\windows\resource\jre\bin\javaw.exe
FirewallRules: [UDP Query User{9AC00C9E-9B71-49C5-B10F-18D955A84B94}C:\users\spenserb\appdata\local\temp\i1449103908\windows\resource\jre\bin\javaw.exe] => (Allow) C:\users\spenserb\appdata\local\temp\i1449103908\windows\resource\jre\bin\javaw.exe
FirewallRules: [{29593FE5-A4CE-4DCB-B7B5-2C2415EE110C}] => (Allow) D:\Steam\steamapps\common\swkotor\swkotor.exe
FirewallRules: [{0A4DBCFC-4A3A-453F-95E2-9C024780DB66}] => (Allow) D:\Steam\steamapps\common\swkotor\swkotor.exe
FirewallRules: [{E66915B8-A4D0-498B-A53F-4048A0D4A11B}] => (Allow) D:\Steam\steamapps\common\Dark Forces\DosBox\dosbox.exe
FirewallRules: [{1651E4CC-53C2-4163-9729-2BAFEEB81748}] => (Allow) D:\Steam\steamapps\common\Dark Forces\DosBox\dosbox.exe
FirewallRules: [{99CDED63-3E79-43EE-BDD7-8A5037AAB33C}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto V\GTA5.exe
FirewallRules: [{03560008-F589-4D0A-B89D-4C581685EE1A}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto V\GTA5.exe
FirewallRules: [{44434613-E1B4-4543-953A-D7D15430E301}] => (Allow) D:\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{52185B6A-0169-4CCF-BFB5-161A2196D77A}] => (Allow) D:\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{13F71721-29D7-4830-9ED5-A7F89C7060A4}] => (Allow) D:\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{946069C4-FBC6-427C-9F40-2E7BC05603FF}] => (Allow) D:\Steam\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{A6755BF1-1514-43CF-A6E9-BBF80FCA257A}] => (Allow) D:\Steam\steamapps\common\Skyrim\skse_steam_boot.exe
FirewallRules: [{AA42C42E-9B86-435D-9A8B-505773AB8F8A}] => (Allow) D:\Steam\steamapps\common\Skyrim\skse_steam_boot.exe
FirewallRules: [TCP Query User{AD7F3A17-E790-466A-9BF7-559289DE9702}D:\battle.net\diablo iii\diablo iii.exe] => (Allow) D:\battle.net\diablo iii\diablo iii.exe
FirewallRules: [UDP Query User{7E548F8F-6782-4A77-9D65-B571148753E2}D:\battle.net\diablo iii\diablo iii.exe] => (Allow) D:\battle.net\diablo iii\diablo iii.exe
FirewallRules: [{68A8294C-8C04-4CB6-9C01-D8FDC7ABBB0D}] => (Allow) D:\iTunes\iTunes.exe
FirewallRules: [{9A03F713-25F0-4A51-ACAA-8DDAEBCF8BC8}] => (Allow) D:\Steam\steamapps\common\Borderlands\Binaries\Borderlands.exe
FirewallRules: [{823A2A82-D910-4E47-A201-66DCE0487BE4}] => (Allow) D:\Steam\steamapps\common\Borderlands\Binaries\Borderlands.exe
FirewallRules: [{FB066BC2-5AFF-4EBD-B662-F8E938048141}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{4EA1F020-138F-4722-A86C-B173CCE71E6D}] => (Allow) D:\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{C1FA91D5-E74E-46EF-B923-528A04834F8E}] => (Allow) D:\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{24D86F44-6C57-4C34-A125-DFF5EF234C99}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe
FirewallRules: [{B2C8D5D5-5793-4861-87EA-8FA275967F38}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe
FirewallRules: [{EC7436E6-5996-4751-B91A-78AB02387D2D}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe
FirewallRules: [{F188BDD4-F1D8-4B2E-A9AC-C50B533F7441}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe
FirewallRules: [TCP Query User{7190CE2E-97F3-4B79-9846-88EABD013272}D:\steam\steamapps\common\paladins\binaries\win32\paladins.exe] => (Allow) D:\steam\steamapps\common\paladins\binaries\win32\paladins.exe
FirewallRules: [UDP Query User{5815AFFB-8ABD-4710-A08D-182EF1B7299B}D:\steam\steamapps\common\paladins\binaries\win32\paladins.exe] => (Allow) D:\steam\steamapps\common\paladins\binaries\win32\paladins.exe
FirewallRules: [TCP Query User{6B044420-0BB4-4A87-AD62-39919A2CE50A}C:\program files (x86)\soulseekqt\soulseekqt.exe] => (Allow) C:\program files (x86)\soulseekqt\soulseekqt.exe
FirewallRules: [UDP Query User{65BBDD85-3FE1-4C14-8E25-F776715478C0}C:\program files (x86)\soulseekqt\soulseekqt.exe] => (Allow) C:\program files (x86)\soulseekqt\soulseekqt.exe
FirewallRules: [{496C0291-95D0-44D8-8258-35786D676112}] => (Allow) D:\Steam\steamapps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [{0FEF40F8-8B5B-476F-8F75-04CB0BD57B8C}] => (Allow) D:\Steam\steamapps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [{B5C03AF6-4395-4864-A99B-0FF97D59D42B}] => (Allow) LPort=26789
FirewallRules: [{ADF27F0C-CCD0-4F5E-9C23-762C6027FA7A}] => (Allow) D:\Steam\steamapps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [{2286C167-744B-4996-AA73-63B29929202C}] => (Allow) D:\Steam\steamapps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [TCP Query User{B387B9BB-D530-4B75-AA2B-9AD3909FBB87}D:\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe] => (Allow) D:\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe
FirewallRules: [UDP Query User{D62AFF66-AC4B-46F6-A620-C5714D8757A4}D:\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe] => (Allow) D:\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe
FirewallRules: [{3969B604-8F22-4C4D-B90E-CA18F2E4AC73}] => (Block) D:\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe
FirewallRules: [{68F140BD-FF6A-48CE-AD59-BCC8F58E097C}] => (Block) D:\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe
FirewallRules: [{EA4623B5-0CC7-4628-92E6-160751D0C8BD}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [TCP Query User{09892F71-10FE-4732-BD51-12FDBAA2CDCC}C:\program files (x86)\soulseekqt\soulseekqt.exe] => (Allow) C:\program files (x86)\soulseekqt\soulseekqt.exe
FirewallRules: [UDP Query User{17EB6A56-6496-437D-AB3B-5F7E16AB4553}C:\program files (x86)\soulseekqt\soulseekqt.exe] => (Allow) C:\program files (x86)\soulseekqt\soulseekqt.exe
FirewallRules: [{F758611C-54BF-4277-A83D-B8A38DFB136F}] => (Allow) C:\WINDOWS\system32\rundll32.exe
FirewallRules: [{D7E2D5A0-3FB2-4469-B01D-C671DE2DBF6A}] => (Allow) C:\Program Files (x86)\Confluent\ideation.exe
FirewallRules: [{A0073674-1D18-4AA2-A249-A2B6F426EAF6}] => (Allow) C:\Program Files (x86)\Microclimate\ideation.exe

==================== Restore Points =========================

09-09-2017 08:22:49 Scheduled Checkpoint
12-09-2017 21:21:47 Windows Update
12-09-2017 21:21:59 Windows Update
20-09-2017 08:50:39 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (09/20/2017 10:46:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Local Hostname Spenser.local already in use; will try Spenser-2.local instead

Error: (09/20/2017 10:46:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: ProbeCount 0; will deregister   16 Spenser.local. AAAA FE80:0000:0000:0000:7976:4791:616D:13E4

Error: (09/20/2017 10:46:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from FE80:0000:0000:0000:7976:4791:616D:13E4:5353   16 Spenser.local. AAAA 2602:0306:3B88:1370:0000:0000:0000:03E9

Error: (09/20/2017 10:26:32 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program explorer.exe version 10.0.14393.1532 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: 15e0

Start Time: 01d33280c932d762

Termination Time: 60000

Application Path: C:\Windows\explorer.exe

Report Id: 1e1af971-9e74-11e7-835a-d8cb8a5e9855

Faulting package full name: 

Faulting package-relative application ID:

Error: (09/20/2017 09:42:25 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Local Hostname Spenser.local already in use; will try Spenser-2.local instead

Error: (09/20/2017 09:42:25 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: ProbeCount 0; will deregister   16 Spenser.local. AAAA FE80:0000:0000:0000:7976:4791:616D:13E4

Error: (09/20/2017 09:42:25 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from FE80:0000:0000:0000:7976:4791:616D:13E4:5353   16 Spenser.local. AAAA 2602:0306:3B88:1370:0000:0000:0000:03E9

Error: (09/20/2017 09:40:14 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: SPENSER)
Description: Activation of app Microsoft.Getstarted_5.11.1641.0_x64__8wekyb3d8bbwe:App.AppX7mv0s3r0wanj0n66dy6vax24ps6avzvz.mca failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (09/20/2017 09:39:04 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 512) (User: )
Description: The Cryptographic Services service failed to initialize the VSS backup "System Writer" object.

Details:
Could not query the status of the EventSystem service.

System Error:
A system shutdown is in progress.
.

Error: (09/20/2017 09:37:26 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: SPENSER)
Description: Activation of app Microsoft.Getstarted_5.11.1641.0_x64__8wekyb3d8bbwe:App.AppX7mv0s3r0wanj0n66dy6vax24ps6avzvz.mca failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.


System errors:
=============
Error: (09/20/2017 11:18:21 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (09/20/2017 11:06:18 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0xc1900107: Feature update to Windows 10, version 1703.

Error: (09/20/2017 11:01:08 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (09/20/2017 11:00:48 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The amdacpusrsvc service failed to start due to the following error: 
The system cannot find the file specified.

Error: (09/20/2017 11:00:48 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The amdacpksd service failed to start due to the following error: 
The system cannot find the file specified.

Error: (09/20/2017 11:00:43 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 35) (User: NT AUTHORITY)
Description: Performance power management features on Hyper-V logical processor 3 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.

Error: (09/20/2017 11:00:43 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 35) (User: NT AUTHORITY)
Description: Performance power management features on Hyper-V logical processor 2 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.

Error: (09/20/2017 11:00:43 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 35) (User: NT AUTHORITY)
Description: Performance power management features on Hyper-V logical processor 1 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.

Error: (09/20/2017 11:00:43 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 35) (User: NT AUTHORITY)
Description: Performance power management features on Hyper-V logical processor 0 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.

Error: (09/20/2017 10:59:48 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.


CodeIntegrity:
===================================
  Date: 2017-09-20 19:09:31.015
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2017-09-20 19:09:31.014
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2017-09-20 16:57:15.496
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2017-09-20 16:57:15.489
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2017-06-27 17:56:28.368
  Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume6\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2017-06-27 17:56:28.367
  Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume6\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i5-4690K CPU @ 3.50GHz
Percentage of memory in use: 44%
Total physical RAM: 8140.79 MB
Available physical RAM: 4526.9 MB
Total Virtual: 12108.79 MB
Available Virtual: 6923 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:231.93 GB) (Free:113.98 GB) NTFS
Drive d: (HDD) (Fixed) (Total:931.39 GB) (Free:679.06 GB) NTFS
Drive e: (DT4000G2) (CDROM) (Total:0.02 GB) (Free:0 GB) CDFS
Drive g: (Spenser) (Fixed) (Total:1862.93 GB) (Free:693.73 GB) exFAT
Drive h: (JTTODD) (Removable) (Total:7.44 GB) (Free:7.44 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 00000000)

Partition: GPT.

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 00000000)

Partition: GPT.

========================================================
Disk: 2 (Size: 1863 GB) (Disk ID: 0005F107)
Partition 1: (Active) - (Size=1863 GB) - (Type=07 NTFS)

========================================================
Disk: 4 (Size: 7.5 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt ============================

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.