Jump to content
PincoIta

Malwarebytes error don't scan and redirect ads in russia and slow pc HELP

Recommended Posts

 

Hi, 

I upgrade win 10 to the last version , and i do a cleaner install. 

But Every browsers i use have 100 cpu consuming % . I try to see the dns or the ipconfiguration and i saw a lot of redirect ads, and if i ping google i connect to a strange russian company.

For all this things i download Malwarebytes but don't start, tell me that therì is an error..and i can't do a check of virus (windows antivirus don't find nothing and i think ther'is something wrong)

I think i'm in a botnet or something ... can you help me please ? to find the problem

if i do a clear reinstallation of windows ,after 3 days , i'm at the same point , or my modem is hacked or i don't know.

 

Screenshot (42).png

Screenshot (23).png

Screenshot (27).png

Screenshot (48).png

Screenshot (62).png

Screenshot (69).png

Screenshot (70).png

Screenshot (72).png

Screenshot (77).png

Screenshot (82).png

Screenshot (83).png

Screenshot (86).png

Screenshot (87).png

Screenshot (88).png

Screenshot (92).png

Screenshot (93).png

Share this post


Link to post
Share on other sites
Hello PincoIta and welcome to Malwarebytes,

Run the following and post the two produced logs...

Download Farbar Recovery Scan Tool and save it to your desktop.

Alternative download option: http://www.techspot.com/downloads/6731-farbar-recovery-scan-tool.html

Note: You need to run the version compatible with your system (32 bit or 64 bit). If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

If your security alerts to FRST either, accept the alert or turn your security off to allow FRST to run. It is not malicious or infected in any way...

Be aware FRST must be run from an account with Administrator status...
 
  • Double-click to run it. When the tool opens click Yes to disclaimer.(Windows 8/10 users will be prompted about Windows SmartScreen protection - click More information and Run.)
  • Make sure Addition.txt is checkmarked under "Optional scans"
    user posted image
     
  • Press Scan button to run the tool....
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The tool will also make a log named (Addition.txt) Please attach that log to your reply.


Thank you,

Kevin...

Share this post


Link to post
Share on other sites

Hello Pincolta,

Continue with the following:

Reset your router, instructons available at the following link:

http://setuprouter.com/networking/how-to-reset-your-router/

Follow those instructions very carefully.

Next,

Download and unzip DNSJumper to your Desktop, the tool is portable no installation necessary.

Tool can be downloaded here: http://www.sordum.org/downloads/?dns-jumper
 
  • Right click on Dnsjumper.exe and select "Run as Administrator" to start the tool, For XP just double click to run.
  • From the left hand pane select "Flush DNS"
  • From the main interface select the dropdown under "Choose a DNS Server"
  • From the list select either "Google Public DNS" or "Open DNS"
  • From the left hand pane select "Apply DNS"


When done re-boot your system....

Next,

Download AdwCleaner by Malwarebytes onto your Desktop.

Or from this Mirror
 
  • Right-click on AdwCleaner.exe and select user posted imageRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Accept the EULA (I accept), then click on Scan
  • Let the scan complete. Once it's done, make sure that every item listed in the different tabs is checked and click on the Clean button. This will kill all the active processes
  • Once the cleaning process is complete, AdwCleaner will ask to restart your computer, do it
  • After the restart, a log will open when logging in. Please copy/paste the content of that log in your next reply


Next,

Please download Zemana AntiMalware and save it to your Desktop.
 
  • Install the program and once the installation is complete it will start automatically.
  • Without changing any options, press Scan to begin.
  • After the short scan is finished, if threats are detected press Next to remove them.
    Note: If restart is required to finish the cleaning process, you should click Reboot. If reboot isn't required, please re-boot your computer manually.
     
  • Open Zemana AntiMalware again.
  • Click on user posted image icon and double click the latest report.
  • Now click File > Save As and choose your Desktop before pressing Save.
  • Attach saved report in your next message.


Next,

Download Sophos Free Virus Removal Tool and save it to your desktop.

If your security alerts to this scan either accept the alert or turn off your security to allow Sophos to run and complete.....

Please Do Not use your PC whilst the scan is in progress.... This scan is very thorough so may take several hours...
 
  • Double click the icon and select Run
  • Click Next
  • Select I accept the terms in this license agreement, then click Next twice
  • Click Install
  • Click Finish to launch the program
  • Once the virus database has been updated click Start Scanning
  • If any threats are found click Details, then View log file... (bottom left hand corner)
  • Copy and paste the results in your reply
  • Close the Notepad document, close the Threat Details screen, then click Start cleanup
  • Click Exit to close the program
  • If no threats were found please confirm that result....



The Virus Removal Tool scans the following areas of your computer:
  • Memory, including system memory on 32-bit (x86) versions of Windows
  • The Windows registry
  • All local hard drives, fixed and removable
  • Mapped network drives are not scanned.


Note: If threats are found in the computer memory, the scan stops. This is because further scanning could enable the threat to spread. You will be asked to click Start Cleanup to remove the threats before continuing the scan.

Post those logs to your next reply, also tell me if there are any remaining issues or concerns.....

Thank you,

Kevin.

 

Share this post


Link to post
Share on other sites
Posted (edited)

Hi thanks .

I don't know why but today malwarebytes work. I do a scan with thtat and it found a lot of PUP.

I do all with dns-jumper and reset dns (with open dns) and flush dns (i do that a lot in these day but on cmd ipconfig /flushdns)

For the modem i reset every week , but i see that ther'is a problem, ...i Have dgn2200v4 and recently it was one of the modems affected of vpnfilter. (on modem i put the dns of my provider tim

85.37.17.10  and 85.38.28.86) I need to change that too?

I upgrade, but if i open wireless in the menu it says wirless close (but works) , or on the wps panel i can't stop pin , and he's gray. I put some screen at the end.

For me someone enter and put a lot of virus or other things on my pc or my devices, that happened after that i enter in a site oraridiapertura24.it  (on this site ther'is a webmaster that hack people router on russia redirect)

 

Adwcleaner find other pup or virus

Zemana can't start or i have a problem to start tell me that ther'is a problem (screen)

Sophos remind me on a page where i need to put name..ecc.. and they send me to mail, is correct?

 

 

 

 

Screenshot (96).png

Screenshot (100).png

Screenshot (103).png

Screenshot (104).png

Screenshot (105).png

Screenshot (106).png

 

Screenshot (109).png

report malwarebytes.txt

AdwCleaner[C00].txt

AdwCleaner[S00].txt

Edited by PincoIta

Share this post


Link to post
Share on other sites

Can you run Sophos AV, on the page where you submit name and email address leave the box to checkmark for updates for Sophos products and service clear, do not checkmark that box....

Share this post


Link to post
Share on other sites
Posted (edited)

Hi , thanks for reply

I got Sophos and its scan for about 3 hours and don't find nothing... When was scanning i try to install again Zenmana , and again the error about memory incompatibility. I enter on Windows Secutity Center and i disable (under security devices -- >  core isolation ) the memory integrity.. in all this time the computer was so slow (when sophos check) very slow ...cpu 135% i see in task a lot of process like audiodg.exe that consuming a lot of cpu..After try to stop (its start byself ever) sophos stop to scan and tell me no virus found.

I Restart and after the memory integrity change ,zenmana work , and the pc seems a little fast, but for me someone change my connection or i connected to a pc remotely , a pc that enter in my wlan i don't know but when zenmana check the virus on the list for about 10 sceond is showing Sophos like a problem..

The problem is that when i use the browser sometimes the position change, i'm not in italy ..Google tell me that i'm in another country (Ukraine, Finland, ...), someone chenge my dns or i have a backdoor ...

I do another check with farbar ... 

Sorry for all the screens

Screenshot (138).png

Screenshot (140).png

Screenshot (141).png

Screenshot (144).png

Screenshot (145).png

Screenshot (147).png

Screenshot (150).png

Screenshot (153).png

Screenshot (155).png

Screenshot (156).png

Screenshot (158).png

Screenshot (159).png

Screenshot (160).png

Addition.txt

FRST.txt

Zenmana 2018.08.08-15.41.11-i0-t92-d1.txt

Edited by PincoIta
I forgot Zenmana report

Share this post


Link to post
Share on other sites
21 hours ago, kevinf80 said:

FRST logs are clean, how is your PC responding at present; are there any remaining issues or concerns. One point of note, your hard drive has minimal space left, that fact can cause problems for your OS. Read the following:

https://www.howtogeek.com/324956/how-much-free-space-should-you-leave-on-your-windows-pc/

Thanks Kevinf80. Yes I cleaned the little Hd

Now is a little Better, not much ..but a little...the boost of performance was putting off the memory Integrity in Windows Security Center. I don't know why, maybe need a lot of memory for that? i doubt.. After the last upgrade of Windows 1803 i have a very bad performance ..  i know that my notebook is very low level.. but with 1709 i don't have problem of cpu 100% ever, audio stuttering or black screen.. etc.. (now seems all ok but how long? If someone "spy my connection in ddos , see that i entered in these forum..and now he leave me alone)

for the lan i think the problem remain because  a lot of point are not clear like that i can't disable wps or pin.. or the impossibility of closing the door 135

All the problem born when i entered on oradiapertura24.it (i work for they) , after few days the peole on that portal see what i do, and redirect me to a fake or http page. for example same days on the browser the schedules open byself..like remote control, and the tabs that opened in the browser was 888.com or sisal etc.. betting... or 2 different url but same tab..and other problem ..I reported the problem to the authorities but no change. 

I need to wait. Thanks a lot .

Share this post


Link to post
Share on other sites
Lets try running your system in "Clean Boot" mode, see if that makes any difference...

Set windows up for "Clean Boot" mode, full instructions here: https://support.microsoft.com/en-gb/kb/929135

Basically all none MS services are disabled, see how your system runs in that mode. Obviously 3rd party services that affect security or internet connection can be left active.

If clean boot makes your system faster and more responsive it is now a process of elimination to find which non MS service(s) was affecting your system...

Go through the process again, this time with all MS services hidden again enable the top half of non MS services, re-boot and see how your system responds, if still ok the top half can be left enabled.

Repeat again, enable so many of the bottom half then re-boot. Continue until you locate the problem service(s). A process of elimination, a bit long winded but worth the effort. Let me know the outcome...

Share this post


Link to post
Share on other sites

I scan now Adwcleaner

and again pup ...but dnsjumper ...how is possible?

 

 

 

# -------------------------------
# Malwarebytes AdwCleaner 7.2.1.0
# -------------------------------
# Build:    06-26-2018
# Database: 2018-08-07.3
# Support:  https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start:    08-09-2018
# Duration: 00:00:50
# OS:       Windows 10 Pro
# Scanned:  41478
# Detected: 4


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

PUP.Adware.Heuristic            C:\Program Files (x86)\DNSJUMPER

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

PUP.Adware.Heuristic            C:\Windows\System32\Tasks\DNSJUMPER_PEPPO

***** [ Registry ] *****

PUP.Adware.Heuristic            HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E51B1F98-561D-4B2F-8CFD-ACDBB3D1D918} 
PUP.Adware.Heuristic            HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DnsJumper_Peppo

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.


AdwCleaner[S00].txt - [2442 octets] - [07/08/2018 10:55:47]
AdwCleaner[C00].txt - [2404 octets] - [07/08/2018 10:56:45]
AdwCleaner[S01].txt - [1363 octets] - [07/08/2018 12:24:18]
AdwCleaner[S02].txt - [1424 octets] - [07/08/2018 17:31:12]
AdwCleaner[C02].txt - [1741 octets] - [07/08/2018 17:40:08]
AdwCleaner[S03].txt - [1546 octets] - [07/08/2018 17:55:25]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S04].txt ##########
 

 

image.thumb.png.4a874e6541e07a030f474a876d76d4c0.png

Screenshot (162).png

Share this post


Link to post
Share on other sites

Ok . Thanks. I do an error.

i Click clean and Repair on Adwcleaner, reboot, and after at the start, i see a cmd open byself on netsh.exe  and now ethernet go normally but i lost the icon on the bar and in the setting i see "Internet not disponible" .

mmmhhh

I need to try what you tell me about Clean boot..

Screenshot (167).png

Screenshot (169).png

Share this post


Link to post
Share on other sites

Nothing..I try to unistall the lan cardbut no icon in the bar

now windows Upgrade can' tupgrade , Firewall don't work... i try Repair trouble on windows and nothing..i see a strange process.. mod_frst.exe...

i need to do again another clear reinstallation of windows?

 

FRST.txt

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02.08.2018
Ran by Peppo (administrator) on DESKTOP-ALDNS74 (09-08-2018 22:22:23)
Running from C:\Users\Peppo\Downloads
Loaded Profiles: Peppo (Available Profiles: Peppo & Administrator)
Platform: Windows 10 Pro Version 1803 17134.191 (X64) Language: Italiano (Italia)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(ICEpower a/s) C:\Windows\System32\ICEsoundService64.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1807.18075-0\MsMpEng.exe
(Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1807.18075-0\NisSrv.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
() C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18061.13911.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe
(www.sordum.org) C:\Users\Peppo\Desktop\DnsJumper\DnsJumper.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Corporation)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [ZAM] => C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [15775888 2017-08-09] (Copyright 2017.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-07-07] (Oracle Corporation)
HKU\S-1-5-21-1728740447-1116186292-1611782332-1001\...\Run: [Spotify] => C:\Users\Peppo\AppData\Roaming\Spotify\Spotify.exe [24529296 2018-08-03] (Spotify Ltd)
HKU\S-1-5-21-1728740447-1116186292-1611782332-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [18385368 2018-06-24] (Piriform Ltd)
GroupPolicy: Restriction ? <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\..\Interfaces\{ee2ca276-f9f8-418d-a18b-560d6ced8d3f}: [NameServer] 208.67.222.222,208.67.220.220

Internet Explorer:
==================
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\ssv.dll [2018-08-06] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\jp2ssv.dll [2018-08-06] (Oracle Corporation)

Edge: 
======
Edge Extension: (No Name) -> EdgeExtension_AdguardAdguardAdBlocker_m055xr0c82818 => C:\Program Files\WindowsApps\Adguard.AdguardAdBlocker_2.9.2.0_neutral__m055xr0c82818 [2018-08-03]

FireFox:
========
FF DefaultProfile: ovzgwxct.default
FF ProfilePath: C:\Users\Peppo\AppData\Roaming\Mozilla\Firefox\Profiles\ovzgwxct.default [2018-08-09]
FF Extension: (AdGuard AdBlocker) - C:\Users\Peppo\AppData\Roaming\Mozilla\Firefox\Profiles\ovzgwxct.default\Extensions\adguardadblocker@adguard.com.xpi [2018-08-06]
FF Plugin-x32: @java.com/DTPlugin,version=11.181.2 -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\dtplugin\npDeployJava1.dll [2018-08-06] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.181.2 -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\plugin2\npjp2.dll [2018-08-06] (Oracle Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-08-03] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-08-03] (Google Inc.)

Chrome: 
=======
CHR Profile: C:\Users\Peppo\AppData\Local\Google\Chrome\User Data\Default [2018-08-09]
CHR Extension: (Presentazioni) - C:\Users\Peppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-08-03]
CHR Extension: (Documenti) - C:\Users\Peppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-08-03]
CHR Extension: (Google Drive) - C:\Users\Peppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-08-03]
CHR Extension: (AdGuard AdBlocker) - C:\Users\Peppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg [2018-08-03]
CHR Extension: (YouTube) - C:\Users\Peppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-08-03]
CHR Extension: (Fogli) - C:\Users\Peppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-08-03]
CHR Extension: (Google Documenti offline) - C:\Users\Peppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-03]
CHR Extension: (No Coin - Block miners on the web!) - C:\Users\Peppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\gojamcfopckidlocpkbelmpjcgmbgjcl [2018-08-04]
CHR Extension: (Pagamenti Chrome Web Store) - C:\Users\Peppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-08-03]
CHR Extension: (Gmail) - C:\Users\Peppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-08-03]
CHR Extension: (Chrome Media Router) - C:\Users\Peppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-08-03]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 esifsvc; C:\WINDOWS\System32\Intel\DPTF\esif_uf.exe [1643064 2018-08-03] (Intel Corporation)
R2 ICEsoundService; C:\WINDOWS\system32\ICEsoundService64.exe [483808 2018-08-03] (ICEpower a/s)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [372720 2016-06-08] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6541008 2018-05-09] (Malwarebytes)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4737448 2018-07-15] (Microsoft Corporation)
S3 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\NisSrv.exe [3905952 2018-08-03] (Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MsMpEng.exe [110944 2018-08-03] (Microsoft Corporation)
R2 ZAMSvc; C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [15775888 2017-08-09] (Copyright 2017.)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 dg_ssudbus; C:\WINDOWS\System32\drivers\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.)
R3 dptf_acpi; C:\WINDOWS\System32\drivers\dptf_acpi.sys [77224 2018-08-03] (Intel Corporation)
R3 dptf_cpu; C:\WINDOWS\System32\drivers\dptf_cpu.sys [70568 2018-08-03] (Intel Corporation)
R3 esif_lf; C:\WINDOWS\System32\drivers\esif_lf.sys [399784 2018-08-03] (Intel Corporation)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [152688 2018-08-06] (Malwarebytes)
R3 ETDSMBus; C:\WINDOWS\System32\drivers\ETDSMBus.sys [31816 2018-08-01] (ELAN Microelectronic Corp.)
R3 HIDSwitch; C:\WINDOWS\System32\drivers\AsRadioControl.sys [31144 2017-11-23] (ASUS)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2018-08-03] (REALiX(tm))
R3 igfxLP; C:\WINDOWS\system32\DRIVERS\igdkmd64lp.sys [5925360 2016-06-08] (Intel Corporation)
R0 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [191208 2018-08-07] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [114920 2018-08-09] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [48360 2018-08-09] (Malwarebytes)
R0 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [253664 2018-08-09] (Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [102632 2018-08-09] (Malwarebytes)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [604160 2018-04-12] (Realtek )
S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [64912 2017-05-18] (QUALCOMM Incorporated)
R3 TXEIx64; C:\WINDOWS\System32\drivers\TXEIx64.sys [146200 2018-08-01] (Intel Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46584 2018-08-03] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [340008 2018-08-03] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [61992 2018-08-03] (Microsoft Corporation)
R1 ZAM; C:\WINDOWS\System32\drivers\zam64.sys [203680 2018-08-08] (Zemana Ltd.)
R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [203680 2018-08-08] (Zemana Ltd.)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-08-09 22:13 - 2018-08-09 22:13 - 000000000 ___HD C:\OneDriveTemp
2018-08-09 19:37 - 2018-08-09 19:38 - 000025966 _____ C:\Users\Peppo\Downloads\Addition.txt
2018-08-09 19:32 - 2018-08-09 22:23 - 000011609 _____ C:\Users\Peppo\Downloads\FRST.txt
2018-08-09 18:53 - 2018-08-09 18:54 - 000000000 ____D C:\Users\Peppo\Desktop\DnsJumper
2018-08-08 17:41 - 2018-08-08 17:42 - 000000000 ____D C:\Users\Peppo\Desktop\frst64 2nd scan
2018-08-08 16:21 - 2018-08-08 16:21 - 000000000 ____D C:\Users\Peppo\Desktop\frst64 1st scan
2018-08-08 15:51 - 2018-08-08 15:51 - 000001327 _____ C:\Users\Peppo\Desktop\Zenmana 2018.08.08-15.41.11-i0-t92-d1.txt
2018-08-08 15:32 - 2018-08-09 22:22 - 000066501 _____ C:\WINDOWS\ZAM.krnl.trace
2018-08-08 15:32 - 2018-08-09 22:22 - 000031358 _____ C:\WINDOWS\ZAM_Guard.krnl.trace
2018-08-08 15:32 - 2018-08-08 15:32 - 000203680 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zamguard64.sys
2018-08-08 15:32 - 2018-08-08 15:32 - 000203680 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zam64.sys
2018-08-08 15:32 - 2018-08-08 15:32 - 000001221 _____ C:\Users\Public\Desktop\Zemana AntiMalware.lnk
2018-08-08 15:32 - 2018-08-08 15:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
2018-08-08 12:27 - 2018-08-08 12:27 - 000000000 ____D C:\ProgramData\Sophos
2018-08-08 12:25 - 2018-08-08 12:25 - 000002775 _____ C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
2018-08-08 12:25 - 2018-08-08 12:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2018-08-08 12:25 - 2018-08-08 12:25 - 000000000 ____D C:\Program Files (x86)\Sophos
2018-08-08 12:19 - 2018-08-08 12:21 - 203090080 _____ (Sophos Limited) C:\Users\Peppo\Downloads\Sophos Virus Removal Tool.exe
2018-08-07 17:28 - 2018-08-09 21:30 - 000004210 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2018-08-07 17:28 - 2018-08-07 17:28 - 000002870 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2018-08-07 17:28 - 2018-08-07 17:28 - 000000863 _____ C:\Users\Public\Desktop\CCleaner.lnk
2018-08-07 17:28 - 2018-08-07 17:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2018-08-07 17:28 - 2018-08-07 17:28 - 000000000 ____D C:\Program Files\CCleaner
2018-08-07 16:50 - 2018-08-07 16:51 - 015989160 _____ (Piriform Ltd) C:\Users\Peppo\Downloads\ccsetup544 (1).exe
2018-08-07 11:04 - 2018-08-08 15:32 - 000000000 ____D C:\Program Files (x86)\Zemana AntiMalware
2018-08-07 11:04 - 2018-08-07 11:04 - 000000000 ____D C:\Users\Peppo\AppData\Local\Zemana
2018-08-07 11:03 - 2018-08-07 10:56 - 000002404 _____ C:\Users\Peppo\Desktop\AdwCleaner[C00].txt
2018-08-07 11:03 - 2018-08-07 10:55 - 000002442 _____ C:\Users\Peppo\Desktop\AdwCleaner[S00].txt
2018-08-07 11:02 - 2018-08-07 11:02 - 006625600 _____ (Zemana Ltd. ) C:\Users\Peppo\Downloads\Zemana.AntiMalware.Setup.exe
2018-08-07 10:54 - 2018-08-07 10:56 - 000000000 ____D C:\AdwCleaner
2018-08-07 10:53 - 2018-08-07 10:53 - 007395536 _____ (Malwarebytes) C:\Users\Peppo\Desktop\AdwCleaner.exe
2018-08-07 10:40 - 2018-08-07 10:41 - 000712900 _____ C:\Users\Peppo\Downloads\DnsJumper.zip
2018-08-07 10:31 - 2018-08-07 10:31 - 000002706 _____ C:\Users\Peppo\Desktop\report malwarebytes.txt
2018-08-07 08:56 - 2018-08-09 22:22 - 000000000 ____D C:\FRST
2018-08-07 08:54 - 2018-08-07 08:54 - 002412544 _____ (Farbar) C:\Users\Peppo\Downloads\FRST64.exe
2018-08-07 08:28 - 2018-08-09 22:14 - 000102632 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2018-08-07 08:28 - 2018-08-09 22:06 - 000048360 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2018-08-07 08:28 - 2018-08-09 22:05 - 000114920 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2018-08-07 08:28 - 2018-08-09 19:11 - 000253664 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2018-08-07 08:28 - 2018-08-07 08:28 - 000191208 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2018-08-06 23:26 - 2018-08-06 23:26 - 000035860 _____ C:\Users\Peppo\Documents\cc_20180806_232603.reg
2018-08-06 20:44 - 2018-08-06 20:44 - 000001912 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-08-06 20:44 - 2018-08-06 20:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-08-06 20:43 - 2018-08-06 21:21 - 000152688 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2018-08-06 20:43 - 2018-08-06 20:43 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-08-06 20:43 - 2018-08-06 20:43 - 000000000 ____D C:\Program Files\Malwarebytes
2018-08-06 20:32 - 2018-08-06 20:33 - 076534856 _____ (Malwarebytes ) C:\Users\Peppo\Downloads\mb3-setup-35891.35891-3.5.1.2522-1.0.365-1.0.5292.exe
2018-08-06 16:59 - 2018-08-06 16:59 - 000000000 ____D C:\Users\Peppo\AppData\Local\Microsoft_Corporation
2018-08-06 13:31 - 2018-08-06 13:31 - 000000000 ____D C:\Users\Peppo\AppData\Roaming\Sun
2018-08-06 13:31 - 2018-08-06 13:31 - 000000000 ____D C:\Users\Peppo\AppData\LocalLow\Sun
2018-08-06 13:30 - 2018-08-06 13:29 - 000098680 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2018-08-06 13:29 - 2018-08-06 13:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2018-08-06 13:28 - 2018-08-06 13:28 - 000000000 ____D C:\ProgramData\Oracle
2018-08-06 13:27 - 2018-08-06 13:27 - 000000000 ____D C:\Program Files (x86)\Java
2018-08-06 13:23 - 2018-08-06 13:23 - 001902968 _____ (Oracle Corporation) C:\Users\Peppo\Downloads\JavaSetup8u181.exe
2018-08-06 13:03 - 2018-08-06 19:44 - 000000000 ____D C:\Users\Peppo\AppData\LocalLow\Mozilla
2018-08-06 13:03 - 2018-08-06 13:10 - 000000000 ____D C:\Users\Peppo\AppData\Local\Mozilla
2018-08-06 13:03 - 2018-08-06 13:03 - 000000000 ____D C:\Users\Peppo\AppData\Roaming\Mozilla
2018-08-06 13:02 - 2018-08-06 13:02 - 000000000 ____D C:\WINDOWS\System32\Tasks\S-1-5-21-1728740447-1116186292-1611782332-1001
2018-08-06 13:01 - 2018-08-06 13:01 - 000313896 _____ (Mozilla) C:\Users\Peppo\Downloads\Firefox Installer.exe
2018-08-06 12:51 - 2018-08-09 20:32 - 000000000 ____D C:\Users\Peppo\AppData\Local\ElevatedDiagnostics
2018-08-06 12:12 - 2018-08-08 17:40 - 000007612 _____ C:\Users\Peppo\AppData\Local\Resmon.ResmonCfg
2018-08-04 22:28 - 2018-08-07 10:48 - 000000000 ____D C:\Users\Peppo\AppData\Local\D3DSCache
2018-08-04 22:24 - 2018-08-04 22:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2018-08-04 22:24 - 2018-08-04 22:24 - 000000000 ____D C:\Program Files\7-Zip
2018-08-04 22:22 - 2018-08-04 22:23 - 001438086 _____ (Igor Pavlov) C:\Users\Peppo\Downloads\7z1805-x64.exe
2018-08-04 20:45 - 2018-08-09 20:40 - 000000000 ____D C:\Users\Peppo\AppData\LocalLow\uTorrent
2018-08-04 19:55 - 2018-08-04 19:55 - 000000000 ____D C:\Users\Peppo\AppData\Local\DBG
2018-08-04 19:54 - 2018-08-04 19:54 - 000000000 ____D C:\Users\Peppo\AppData\Local\PeerDistRepub
2018-08-04 19:53 - 2018-08-09 20:40 - 000000000 ____D C:\Users\Peppo\AppData\Roaming\uTorrent
2018-08-04 19:53 - 2018-08-04 19:53 - 000000876 _____ C:\Users\Peppo\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2018-08-04 19:50 - 2018-08-04 19:51 - 002971704 _____ (BitTorrent Inc.) C:\Users\Peppo\Downloads\uTorrent.exe
2018-08-04 19:35 - 2018-08-04 19:35 - 000001865 _____ C:\Users\Peppo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent Web.lnk
2018-08-04 19:23 - 2018-08-04 19:23 - 000000000 ____D C:\Users\Peppo\AppData\Roaming\Adobe
2018-08-04 18:09 - 2018-08-09 19:39 - 000003378 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1728740447-1116186292-1611782332-1001
2018-08-04 15:01 - 2018-08-04 15:01 - 000000418 __RSH C:\ProgramData\ntuser.pol
2018-08-03 23:01 - 2018-08-04 14:58 - 000000000 ____D C:\Users\Peppo\Desktop\Everybody's Gone to the Rapture
2018-08-03 19:21 - 2018-08-03 22:48 - 000000000 ____D C:\Users\Peppo\Desktop\Rime Ost
2018-08-03 13:22 - 2018-08-03 13:22 - 000000000 ____D C:\Program Files (x86)\Lame For Audacity
2018-08-03 13:21 - 2018-08-03 13:21 - 000527423 _____ ( ) C:\Users\Peppo\Downloads\Lame_v3.99.3_for_Windows.exe
2018-08-03 12:56 - 2018-08-06 23:24 - 000000000 ____D C:\Users\Peppo\AppData\Local\Spotify
2018-08-03 12:56 - 2018-08-03 12:56 - 000001850 _____ C:\Users\Peppo\Desktop\Spotify.lnk
2018-08-03 12:52 - 2018-08-03 12:52 - 000809496 ____R (Creative Labs Inc.) C:\WINDOWS\SysWOW64\tmpC30E.tmp
2018-08-03 12:52 - 2018-08-03 12:52 - 000809496 ____R (Creative Labs Inc.) C:\WINDOWS\SysWOW64\tmpC2ED.tmp
2018-08-03 12:52 - 2018-08-03 12:52 - 000466456 _____ (Creative Labs) C:\WINDOWS\system32\wrap_oal.dll
2018-08-03 12:52 - 2018-08-03 12:52 - 000444952 _____ (Creative Labs) C:\WINDOWS\SysWOW64\wrap_oal.dll
2018-08-03 12:52 - 2018-08-03 12:52 - 000122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\WINDOWS\system32\OpenAL32.dll
2018-08-03 12:52 - 2018-08-03 12:52 - 000109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\WINDOWS\SysWOW64\OpenAL32.dll
2018-08-03 12:52 - 2018-08-03 12:52 - 000000000 ____D C:\Program Files (x86)\OpenAL
2018-08-03 12:51 - 2018-08-03 12:51 - 000590434 _____ C:\Users\Peppo\Downloads\oalinst.zip
2018-08-03 12:40 - 2018-08-04 19:36 - 000000000 ____D C:\ProgramData\Package Cache
2018-08-03 12:39 - 2018-08-03 12:39 - 014572000 _____ (Microsoft Corporation) C:\Users\Peppo\Downloads\vc_redist.x64.exe
2018-08-03 12:33 - 2018-08-03 12:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Realtek
2018-08-03 12:32 - 2018-08-03 12:32 - 000000000 ____D C:\WINDOWS\system32\DAX3
2018-08-03 12:30 - 2018-08-03 12:30 - 007178432 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEP64A.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 007101704 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64A.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 006270152 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64AF3.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 005346960 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv211.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 003690856 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 003452120 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 003417976 _____ (DTS, Inc.) C:\WINDOWS\system32\slcnt64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 003306776 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE2.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 003223832 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RltkAPO.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 003215184 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 003128768 _____ (DTS, Inc.) C:\WINDOWS\system32\sltech64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 002930624 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 002444648 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv201.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 002197944 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 001971328 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64A.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 001965120 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64AF3.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 001787920 _____ (DTS) C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 001598360 _____ (DTS) C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 001516232 _____ (DTS) C:\WINDOWS\system32\DTSBoostDLL64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 001448736 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyAPOv251gm.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 001435104 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRRPTR64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 001382200 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tosade.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 001353280 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 001346568 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SECOMN64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 001337600 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tossaeapo64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 001268984 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDHF64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 001259696 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOvlldp.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 001209528 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEAPO64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 001164584 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyAPOvlldpgm.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 001159144 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOProp.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 001133560 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDRA64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 001041208 _____ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SECOMN32.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 001000616 _____ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SEHDHF32.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000994648 _____ (DTS, Inc.) C:\WINDOWS\system32\sl3apo64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000964984 _____ (Sony Corporation) C:\WINDOWS\system32\SFSS_APO.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000873424 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo264.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000852096 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tosasfapo64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000751264 _____ (DTS) C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000734736 _____ (DTS) C:\WINDOWS\system32\DTSSymmetryDLL64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000715616 _____ (DTS) C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000714432 _____ (ICEpower a/s) C:\WINDOWS\system32\ICEsoundAPO64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000692128 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000604760 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tossaemaxapo64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000541080 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSX64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000511608 _____ (DTS) C:\WINDOWS\system32\DTSNeoPCDLL64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000467120 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRAPO64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000453240 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EED64A.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000452696 _____ (DTS) C:\WINDOWS\system32\DTSLimiterDLL64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000448568 _____ (DTS) C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000447144 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\toseaeapo64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000416472 _____ (Harman) C:\WINDOWS\system32\HMUI.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000406416 _____ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2APIPCLL.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000392832 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEP64A.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000381368 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000378344 _____ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2API.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000367576 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64AF3.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000366080 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\HMAPO.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000360304 _____ (Harman) C:\WINDOWS\system32\HMClariFi.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000343672 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000341112 _____ (Synopsys, Inc.) C:\WINDOWS\SysWOW64\SRCOM.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000341112 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000332976 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64A.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000327232 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DHT64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000327232 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DAA64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000315936 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64F3.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000266520 _____ (TODO: <Company name>) C:\WINDOWS\system32\slprp64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000261200 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPO64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000261168 _____ (DTS) C:\WINDOWS\system32\DTSLFXAPO64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000260176 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPONS64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000231880 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFNHK64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000230664 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSH64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000220352 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEED64A.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000218232 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSHP64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000203800 _____ (Harman) C:\WINDOWS\system32\HMHVS.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000192944 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000190896 _____ (Harman) C:\WINDOWS\system32\HMEQ_Voice.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000190896 _____ (Harman) C:\WINDOWS\system32\HMEQ.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000179560 _____ (Harman) C:\WINDOWS\system32\HMLimiter.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000174904 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSWOW64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000158656 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000157312 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEL64A.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000154320 _____ (Harman) C:\WINDOWS\system32\HarmanAudioInterface.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000139720 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEA64A.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000116504 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEL64A.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000093864 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEG64A.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000090880 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFCOM64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000090136 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEG64A.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000088280 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFAPO64.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000083584 _____ (Virage Logic Corporation / Sonic Focus) C:\WINDOWS\SysWOW64\SFCOM.dll
2018-08-03 12:30 - 2018-08-03 12:30 - 000075504 _____ (TOSHIBA CORPORATION.) C:\WINDOWS\system32\tepeqapo64.dll
2018-08-03 12:29 - 2018-08-03 12:30 - 000278232 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64.dll
2018-08-03 12:29 - 2018-08-03 12:29 - 072520672 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoRes64.dat
2018-08-03 12:29 - 2018-08-03 12:29 - 019206179 _____ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT
2018-08-03 12:29 - 2018-08-03 12:29 - 003677120 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl
2018-08-03 12:29 - 2018-08-03 12:29 - 001544216 _____ (Dolby Laboratories) C:\WINDOWS\system32\DAX3APOProp.dll
2018-08-03 12:29 - 2018-08-03 12:29 - 001372352 _____ (Dolby Laboratories) C:\WINDOWS\system32\DAX3APOv251.dll
2018-08-03 12:29 - 2018-08-03 12:29 - 000483808 _____ (ICEpower a/s) C:\WINDOWS\system32\ICEsoundService64.exe
2018-08-03 12:29 - 2018-08-03 12:29 - 000169481 _____ C:\WINDOWS\system32\ICEsoundService.bin
2018-08-03 12:29 - 2018-08-03 12:29 - 000122280 _____ (Real Sound Lab SIA) C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll
2018-08-03 12:29 - 2018-08-03 12:29 - 000118552 _____ C:\WINDOWS\system32\AcpiServiceVnA64.dll
2018-08-03 12:29 - 2018-08-03 12:29 - 000105272 _____ C:\WINDOWS\system32\audioLibVc.dll
2018-08-03 12:28 - 2018-08-03 12:28 - 000480800 _____ (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\IntcDAud.sys
2018-08-03 12:11 - 2018-08-07 12:26 - 000000000 ____D C:\ProgramData\ProductData
2018-08-03 12:11 - 2018-08-03 12:11 - 000000000 ____D C:\WINDOWS\IObit
2018-08-03 12:02 - 2018-08-03 11:54 - 000563832 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2018-08-03 11:58 - 2018-08-03 12:02 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-08-03 11:58 - 2018-08-03 11:58 - 000002375 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-08-03 11:58 - 2018-08-03 11:58 - 000002334 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-08-03 11:57 - 2018-08-05 11:26 - 000003434 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2018-08-03 11:57 - 2018-08-03 12:33 - 000003216 _____ C:\WINDOWS\System32\Tasks\RTKCPL
2018-08-03 11:57 - 2018-08-03 11:57 - 134675576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-08-03 11:57 - 2018-08-03 11:57 - 000003260 _____ C:\WINDOWS\System32\Tasks\RtHDVBg_ListenToDevice
2018-08-03 11:56 - 2018-08-03 12:32 - 000000000 ____D C:\WINDOWS\system32\DAX2
2018-08-03 11:56 - 2018-08-03 11:56 - 000000000 ____H C:\ProgramData\DP45977C.lfl
2018-08-03 11:55 - 2018-08-03 12:32 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2018-08-03 11:55 - 2018-08-03 11:55 - 000000000 ____D C:\Program Files\Realtek
2018-08-03 11:49 - 2018-08-04 14:04 - 000000000 ____D C:\Users\Peppo\AppData\Local\PlaceholderTileLogoFolder
2018-08-03 11:43 - 2018-08-03 11:43 - 000027552 _____ (REALiX(tm)) C:\WINDOWS\SysWOW64\Drivers\HWiNFO64A.SYS
2018-08-03 11:42 - 2018-08-07 12:27 - 000000000 ____D C:\Users\Peppo\AppData\Roaming\IObit
2018-08-03 11:42 - 2018-08-03 12:12 - 000000000 ____D C:\ProgramData\IObit
2018-08-03 11:40 - 2018-08-06 23:16 - 000000000 ____D C:\Users\Peppo\AppData\Roaming\Spotify
2018-08-03 11:39 - 2018-08-03 21:51 - 000000000 ____D C:\Users\Peppo\AppData\Local\Google
2018-08-03 11:39 - 2018-08-03 11:58 - 000000000 ____D C:\Program Files (x86)\Google
2018-08-03 11:23 - 2018-08-03 11:23 - 000001395 _____ C:\Users\Peppo\Desktop\Mp3tag.lnk
2018-08-03 11:22 - 2018-08-07 08:35 - 000000000 ____D C:\Users\Peppo\Mp3tag
2018-08-03 11:21 - 2018-08-06 22:53 - 000000000 ____D C:\Users\Peppo\AppData\Roaming\audacity
2018-08-03 11:21 - 2018-08-03 11:21 - 000001092 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2018-08-03 11:21 - 2018-08-03 11:21 - 000001080 _____ C:\Users\Public\Desktop\Audacity.lnk
2018-08-03 11:21 - 2018-08-03 11:21 - 000000000 ____D C:\Users\Peppo\AppData\Local\Audacity
2018-08-03 11:20 - 2018-08-03 11:21 - 000000000 ____D C:\Program Files (x86)\Audacity
2018-08-03 09:44 - 2018-08-03 09:44 - 000000000 ____D C:\Users\Peppo\AppData\Local\Comms
2018-08-02 23:33 - 2018-08-02 23:33 - 000000000 ____D C:\WINDOWS\InfusedApps
2018-08-02 23:30 - 2018-08-02 23:32 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2018-08-02 23:30 - 2018-08-02 23:30 - 000000000 ____D C:\WINDOWS\system32\Intel
2018-08-02 23:28 - 2018-08-02 23:28 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2018-08-02 23:27 - 2018-08-02 23:27 - 000000000 ____D C:\WINDOWS\Setup
2018-08-02 23:26 - 2018-08-02 23:33 - 000000000 ____D C:\WINDOWS\containers
2018-08-02 23:22 - 2018-08-09 22:09 - 000744934 _____ C:\WINDOWS\system32\perfh010.dat
2018-08-02 23:22 - 2018-08-09 22:09 - 000138504 _____ C:\WINDOWS\system32\perfc010.dat
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\zu-ZA
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\yo-NG
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\xh-ZA
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\wo-SN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\uz-Latn-UZ
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ur-PK
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ug-CN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\tt-RU
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\tn-ZA
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\tk-TM
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ti-ET
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\tg-Cyrl-TJ
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\te-IN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ta-IN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\sw-KE
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-RS
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-BA
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\sq-AL
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\si-LK
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\sd-Arab-PK
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\rw-RW
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\quz-PE
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\quc-Latn-GT
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\prs-AF
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-IN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-Arab-PK
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\or-IN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\nso-ZA
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\nn-NO
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ne-NP
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mt-MT
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mr-IN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mn-MN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ml-IN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mk-MK
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\mi-NZ
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lo-LA
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\lb-LU
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ky-KG
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ku-Arab-IQ
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\kok-IN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\kn-IN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\km-KH
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\kk-KZ
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ka-GE
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\is-IS
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ig-NG
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\hy-AM
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ha-Latn-NG
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\gu-IN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\gd-GB
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ga-IE
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\fil-PH
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\fa-IR
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\cy-GB
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\chr-CHER-US
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES-valencia
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\bs-Latn-BA
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-IN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-BD
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\be-BY
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\az-Latn-AZ
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\as-IN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\am-ET
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\af-ZA
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\zu-ZA
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\yo-NG
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\xh-ZA
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\wo-SN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\vi-VN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\uz-Latn-UZ
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\ur-PK
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\ug-CN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\tt-RU
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\tn-ZA
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\tk-TM
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\ti-ET
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\tg-Cyrl-TJ
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\te-IN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\sw-KE
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-RS
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-BA
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\sq-AL
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\sd-Arab-PK
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\rw-RW
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\quz-PE
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\quc-Latn-GT
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\prs-AF
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\pa-IN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\pa-Arab-PK
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\or-IN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\nso-ZA
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\nn-NO
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\ne-NP
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\mt-MT
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\mr-IN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\mn-MN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\ml-IN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\mk-MK
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\mi-NZ
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\lo-LA
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\lb-LU
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\ky-KG
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\ku-Arab-IQ
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\kok-IN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\kn-IN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\km-KH
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\kk-KZ
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\ka-GE
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\is-IS
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\ig-NG
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\id-ID
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\hy-AM
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\ha-Latn-NG
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\gu-IN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\gd-GB
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\ga-IE
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\fil-PH
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\fa-IR
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\cy-GB
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\chr-CHER-US
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\ca-ES-valencia
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\bs-Latn-BA
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\bn-IN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\bn-BD
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\be-BY
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\az-Latn-AZ
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\as-IN
2018-08-02 23:22 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\af-ZA
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\SysWOW64\winrm
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\SysWOW64\sysprep
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\SysWOW64\slmgr
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\SysWOW64\it
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\SysWOW64\hi-IN
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\SysWOW64\gl-ES
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\SysWOW64\eu-ES
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\SysWOW64\0409
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\system32\winrm
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\system32\WCN
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\system32\slmgr
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\system32\it
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\system32\hi-IN
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\system32\gl-ES
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\system32\eu-ES
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\system32\ca-ES
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\system32\0409
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\OCR
2018-08-02 23:22 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\DigitalLocker
2018-08-02 23:22 - 2018-08-02 23:21 - 000341166 _____ C:\WINDOWS\system32\perfi010.dat
2018-08-02 23:22 - 2018-08-02 23:21 - 000039860 _____ C:\WINDOWS\system32\perfd010.dat
2018-08-02 23:19 - 2018-08-02 23:19 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2018-08-02 23:18 - 2018-06-29 03:13 - 000835064 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2018-08-02 23:18 - 2018-06-29 03:13 - 000179704 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2018-08-02 23:13 - 2018-08-09 22:22 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-08-02 23:13 - 2018-08-09 20:50 - 000000000 ____D C:\WINDOWS\system32\NDF
2018-08-02 23:13 - 2018-08-09 18:22 - 000000000 ___RD C:\Program Files (x86)
2018-08-02 23:13 - 2018-08-07 17:34 - 000000000 ___HD C:\Program Files\WindowsApps
2018-08-02 23:13 - 2018-08-07 17:34 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-08-02 23:13 - 2018-08-07 16:42 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2018-08-02 23:13 - 2018-08-06 22:22 - 000000000 ____D C:\WINDOWS\Registration
2018-08-02 23:13 - 2018-08-06 11:44 - 000000000 ____D C:\WINDOWS\system32\AppLocker
2018-08-02 23:13 - 2018-08-04 15:00 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2018-08-02 23:13 - 2018-08-04 11:02 - 000000000 ____D C:\WINDOWS\appcompat
2018-08-02 23:13 - 2018-08-03 12:02 - 000000000 ____D C:\Program Files\Windows Defender
2018-08-02 23:13 - 2018-08-02 23:33 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2018-08-02 23:13 - 2018-08-02 23:33 - 000000000 __RHD C:\Users\Public\Libraries
2018-08-02 23:13 - 2018-08-02 23:33 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2018-08-02 23:13 - 2018-08-02 23:33 - 000000000 ____D C:\WINDOWS\CSC
2018-08-02 23:13 - 2018-08-02 23:26 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2018-08-02 23:13 - 2018-08-02 23:26 - 000000000 ___SD C:\WINDOWS\system32\UNP
2018-08-02 23:13 - 2018-08-02 23:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2018-08-02 23:13 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\TextInput
2018-08-02 23:13 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2018-08-02 23:13 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2018-08-02 23:13 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2018-08-02 23:13 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2018-08-02 23:13 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\ta-in
2018-08-02 23:13 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2018-08-02 23:13 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\si-lk
2018-08-02 23:13 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2018-08-02 23:13 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\setup
2018-08-02 23:13 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2018-08-02 23:13 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2018-08-02 23:13 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-08-02 23:13 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\system32\am-et
2018-08-02 23:13 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2018-08-02 23:13 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\Provisioning
2018-08-02 23:13 - 2018-08-02 23:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2018-08-02 23:13 - 2018-08-02 23:26 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2018-08-02 23:13 - 2018-08-02 23:26 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2018-08-02 23:13 - 2018-08-02 23:26 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2018-08-02 23:13 - 2018-08-02 23:26 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2018-08-02 23:13 - 2018-08-02 23:22 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2018-08-02 23:13 - 2018-08-02 23:22 - 000000000 ___SD C:\WINDOWS\system32\dsc
2018-08-02 23:13 - 2018-08-02 23:22 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2018-08-02 23:13 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI
2018-08-02 23:13 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\SysWOW64\com
2018-08-02 23:13 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2018-08-02 23:13 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\system32\MUI
2018-08-02 23:13 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\system32\migwiz
2018-08-02 23:13 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\system32\com
2018-08-02 23:13 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2018-08-02 23:13 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\IME
2018-08-02 23:13 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\Help
2018-08-02 23:13 - 2018-08-02 23:22 - 000000000 ____D C:\Program Files\Common Files\system
2018-08-02 23:13 - 2018-08-02 23:22 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2018-08-02 23:13 - 2018-08-02 23:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 __SHD C:\WINDOWS\BitLockerDiscoveryVolumeContents
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 __SHD C:\Program Files\Windows Sidebar
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 __SHD C:\Program Files (x86)\Windows Sidebar
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 __RSD C:\WINDOWS\media
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ___SD C:\WINDOWS\SysWOW64\Nui
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ___SD C:\WINDOWS\SysWOW64\Configuration
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ___SD C:\WINDOWS\system32\Nui
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ___SD C:\WINDOWS\system32\Configuration
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ___SD C:\WINDOWS\system32\AppV
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ___RD C:\WINDOWS\Offline Web Pages
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ___HD C:\WINDOWS\LanguageOverlayCache
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\Web
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\WaaS
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\Vss
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\tracing
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\TAPI
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\SysWOW64\SMI
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\SysWOW64\ras
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\SysWOW64\NDF
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\SysWOW64\Msdtc
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\SysWOW64\Ipmi
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\SysWOW64\InputMethod
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\SysWOW64\IME
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\SysWOW64\icsxml
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicyUsers
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\SysWOW64\downlevel
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\SysWOW64\Bthprops
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\SysWOW64\AppLocker
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\SystemResources
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\SystemApps
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\winevt
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\ta-lk
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\ras
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\ProximityToast
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\PointOfService
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\my-mm
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\Macromed
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\Ipmi
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\InputMethod
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\inetsrv
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\IME
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\icsxml
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\ias
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\hydrogen
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\GroupPolicyUsers
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\DriverState
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\Drivers\DriverData
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\downlevel
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\DDFs
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\config\systemprofile
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\config\Journal
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\Bthprops
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\System
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\SKB
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\ShellComponents
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\ServiceState
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\security
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\schemas
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\SchCache
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\Resources
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\rescache
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\RemotePackages
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\PLA
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\Performance
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\ModemLogs
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\L2Schemas
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\InputMethod
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\IdentityCRL
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\Globalization
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\GameBarPresenceWriter
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\Cursors
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\Branding
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\addins
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\ProgramData\WindowsHolographicDevices
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\Program Files\Windows Security
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\Program Files\Windows Portable Devices
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\Program Files\Windows Multimedia Platform
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\Program Files\Common Files\Services
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\Program Files (x86)\windows nt
2018-08-02 23:13 - 2018-08-02 23:13 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2018-08-02 23:13 - 2018-08-02 23:09 - 000215943 _____ C:\WINDOWS\SysWOW64\dssec.dat
2018-08-02 23:13 - 2018-08-02 23:09 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2018-08-02 23:13 - 2018-08-02 23:09 - 000000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT
2018-08-02 23:13 - 2018-08-02 23:08 - 000229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2018-08-02 23:13 - 2018-08-02 23:08 - 000215943 _____ C:\WINDOWS\system32\dssec.dat
2018-08-02 23:13 - 2018-08-02 23:08 - 000017635 _____ C:\WINDOWS\system32\Drivers\etc\services
2018-08-02 23:13 - 2018-08-02 23:08 - 000017346 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2018-08-02 23:13 - 2018-08-02 23:08 - 000003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam
2018-08-02 23:13 - 2018-08-02 23:08 - 000001358 _____ C:\WINDOWS\system32\Drivers\etc\protocol
2018-08-02 23:13 - 2018-08-02 23:08 - 000000858 _____ C:\WINDOWS\system32\DefaultQuestions.json
2018-08-02 23:13 - 2018-08-02 23:08 - 000000741 _____ C:\WINDOWS\system32\NOISE.DAT
2018-08-02 23:13 - 2018-08-02 23:08 - 000000407 _____ C:\WINDOWS\system32\Drivers\etc\networks
2018-08-02 23:13 - 2018-08-02 23:08 - 000000219 _____ C:\WINDOWS\system.ini
2018-08-02 23:13 - 2018-08-02 23:08 - 000000092 _____ C:\WINDOWS\win.ini
2018-08-02 23:13 - 2018-08-02 22:44 - 000000000 ____D C:\Program Files\windows nt
2018-08-02 23:13 - 2018-08-02 22:43 - 000000000 ____D C:\WINDOWS\system32\spool
2018-08-02 23:13 - 2018-08-02 22:43 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2018-08-02 23:13 - 2018-08-02 22:37 - 000000000 ___RD C:\WINDOWS\PrintDialog
2018-08-02 23:13 - 2018-08-02 22:37 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2018-08-02 23:13 - 2018-08-02 22:37 - 000000000 ____D C:\ProgramData\USOPrivate
2018-08-02 23:13 - 2018-08-02 22:34 - 000000000 ____D C:\WINDOWS\system32\config\TxR
2018-08-02 23:13 - 2018-08-02 22:34 - 000000000 ____D C:\WINDOWS\system32\config\RegBack
2018-08-02 23:13 - 2016-06-08 07:37 - 000103968 _____ (Khronos Group) C:\WINDOWS\SysWOW64\opencl.dll
2018-08-02 23:09 - 2018-08-09 22:09 - 000000000 ____D C:\WINDOWS\INF
2018-08-02 23:02 - 2018-08-03 12:25 - 000000000 ____D C:\ProgramData\Packages
2018-08-02 23:00 - 2018-08-09 16:55 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-08-02 22:58 - 2018-08-09 22:04 - 075235328 _____ C:\WINDOWS\system32\config\SOFTWARE
2018-08-02 22:58 - 2018-08-09 22:04 - 014417920 _____ C:\WINDOWS\system32\config\SYSTEM
2018-08-02 22:58 - 2018-08-09 22:04 - 001835008 _____ C:\WINDOWS\system32\config\DEFAULT
2018-08-02 22:58 - 2018-08-09 22:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-08-02 22:58 - 2018-08-09 22:04 - 000073728 _____ C:\WINDOWS\system32\config\SAM
2018-08-02 22:58 - 2018-08-09 22:04 - 000057344 _____ C:\WINDOWS\system32\config\SECURITY
2018-08-02 22:58 - 2018-08-03 11:42 - 000000000 ____D C:\WINDOWS\Panther
2018-08-02 22:58 - 2018-08-02 23:22 - 000000000 ____D C:\WINDOWS\servicing
2018-08-02 22:58 - 2018-08-02 23:13 - 000000000 ____D C:\WINDOWS\system32\SMI
2018-08-02 22:58 - 2018-08-02 22:44 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2018-08-02 22:49 - 2018-08-09 22:09 - 001662796 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-08-02 22:47 - 2018-08-03 11:55 - 000000000 ____D C:\Users\Peppo\AppData\Local\MicrosoftEdge
2018-08-02 22:47 - 2018-08-02 22:47 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2018-08-02 22:46 - 2018-08-02 22:46 - 000000000 ____D C:\Users\Peppo\AppData\Local\Publishers
2018-08-02 22:45 - 2018-08-07 17:34 - 000000000 ____D C:\Users\Peppo\AppData\Local\Packages
2018-08-02 22:45 - 2018-08-03 11:55 - 000000000 ____D C:\Users\Peppo\AppData\Local\ConnectedDevicesPlatform
2018-08-02 22:45 - 2018-08-02 22:45 - 000000020 ___SH C:\Users\Peppo\ntuser.ini
2018-08-02 22:45 - 2018-08-02 22:45 - 000000000 ____D C:\Users\Peppo\AppData\Local\VirtualStore
2018-08-02 22:44 - 2018-08-02 22:44 - 000000000 _SHDL C:\Users\Default\AppData\Local\Dati applicazioni
2018-08-02 22:44 - 2018-08-02 22:44 - 000000000 _SHDL C:\Users\Default\AppData\Local\Cronologia
2018-08-02 22:44 - 2018-08-02 22:44 - 000000000 _SHDL C:\Users\Default User\AppData\Local\Dati applicazioni
2018-08-02 22:44 - 2018-08-02 22:44 - 000000000 _SHDL C:\Users\Default User\AppData\Local\Cronologia
2018-08-02 22:44 - 2018-08-02 22:44 - 000000000 _SHDL C:\Users\Default User
2018-08-02 22:44 - 2018-08-02 22:44 - 000000000 _SHDL C:\Users\All Users
2018-08-02 22:44 - 2018-08-02 22:44 - 000000000 _SHDL C:\ProgramData\Modelli
2018-08-02 22:44 - 2018-08-02 22:44 - 000000000 _SHDL C:\ProgramData\Menu Avvio
2018-08-02 22:44 - 2018-08-02 22:44 - 000000000 _SHDL C:\ProgramData\Documenti
2018-08-02 22:44 - 2018-08-02 22:44 - 000000000 _SHDL C:\ProgramData\Dati applicazioni
2018-08-02 22:44 - 2018-08-02 22:44 - 000000000 _SHDL C:\Program Files\File comuni
2018-08-02 22:43 - 2018-08-09 22:05 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-08-02 22:43 - 2018-08-03 12:02 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-08-02 22:43 - 2018-08-02 22:43 - 000009664 _____ C:\Users\Peppo\Desktop\Applicazioni rimosse.html
2018-08-02 22:43 - 2018-08-02 22:43 - 000008932 _____ C:\Users\Administrator\Desktop\Applicazioni rimosse.html
2018-08-02 22:43 - 2018-08-02 22:43 - 000000000 ____D C:\Users\Peppo\Documents\FreshStart
2018-08-02 22:43 - 2018-08-02 22:43 - 000000000 ____D C:\Users\Administrator\Documents\FreshStart
2018-08-02 22:40 - 2018-08-09 19:39 - 000002413 _____ C:\Users\Peppo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-08-02 22:40 - 2018-08-07 17:40 - 000000000 ____D C:\Users\Peppo
2018-08-02 22:40 - 2018-08-02 22:42 - 000000000 ____D C:\Users\Administrator
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Peppo\Risorse di stampa
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Peppo\Risorse di rete
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Peppo\Recenti
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Peppo\Modelli
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Peppo\Menu Avvio
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Peppo\Impostazioni locali
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Peppo\Documents\Video
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Peppo\Documents\Musica
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Peppo\Documents\Immagini
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Peppo\Documenti
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Peppo\Dati applicazioni
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Peppo\AppData\Roaming\Microsoft\Windows\Start Menu\Programmi
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Peppo\AppData\Local\Dati applicazioni
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Peppo\AppData\Local\Cronologia
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Administrator\Risorse di stampa
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Administrator\Risorse di rete
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Administrator\Recenti
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Administrator\Modelli
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Administrator\Menu Avvio
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Administrator\Impostazioni locali
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Administrator\Documents\Video
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Administrator\Documents\Musica
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Administrator\Documents\Immagini
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Administrator\Documenti
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Administrator\Dati applicazioni
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programmi
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Administrator\AppData\Local\Dati applicazioni
2018-08-02 22:40 - 2018-08-02 22:40 - 000000000 _SHDL C:\Users\Administrator\AppData\Local\Cronologia
2018-08-02 22:40 - 2018-04-12 01:34 - 000001105 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-08-02 22:37 - 2018-08-02 22:37 - 000000000 ____D C:\ProgramData\USOShared
2018-08-02 22:37 - 2018-04-12 01:33 - 002752000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2018-08-02 22:36 - 2016-06-08 07:37 - 000099864 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2018-08-02 22:35 - 2018-08-09 22:05 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2018-08-02 22:35 - 2018-08-02 22:35 - 000000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
2018-08-02 22:35 - 2018-08-02 22:35 - 000000000 ____D C:\Program Files\Intel
2018-08-02 22:34 - 2018-08-09 21:59 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-08-02 22:34 - 2018-08-02 22:41 - 000235288 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-08-02 21:56 - 2018-08-02 23:33 - 000000000 ___HD C:\$SysReset
2018-08-02 21:48 - 2018-08-07 08:33 - 000000000 ____D C:\Users\Peppo\Desktop\2018Agosto
2018-08-02 20:20 - 2018-08-07 10:56 - 000000000 ____D C:\Users\Administrator\AppData\LocalLow\IObit
2018-08-02 20:20 - 2018-08-02 20:20 - 000001417 _____ C:\Users\Administrator\Desktop\Microsoft Edge.lnk
2018-08-02 20:17 - 2018-08-02 20:20 - 000000000 ___RD C:\Users\Administrator\3D Objects
2018-08-02 20:16 - 2018-08-02 20:19 - 000000000 __SHD C:\Users\Administrator\IntelGraphicsProfiles
2018-08-02 18:12 - 2018-08-02 18:14 - 212785420 _____ C:\Users\Peppo\Downloads\win64_15.40.38.4963.zip
2018-08-02 17:29 - 2018-08-02 18:25 - 000000000 ____D C:\Intel
2018-08-02 16:03 - 2018-08-02 16:03 - 000000000 ____D C:\Users\Peppo\Downloads\Intel Driver and Support Assistant
2018-08-02 15:59 - 2018-08-02 15:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Driver and Support Assistant
2018-08-02 15:57 - 2018-08-02 15:57 - 014909632 _____ (Intel) C:\Users\Peppo\Downloads\Intel Driver and Support Assistant Installer (1).exe
2018-08-02 13:45 - 2018-08-02 13:45 - 001130840 _____ (Google Inc.) C:\Users\Peppo\Downloads\ChromeSetup (2).exe
2018-08-02 12:15 - 2018-08-02 23:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter
2018-08-02 11:54 - 2018-08-02 11:54 - 042042560 _____ (IObit ) C:\Users\Peppo\Downloads\IObit-Malware-Fighter-Setup.exe
2018-08-01 23:30 - 2018-08-01 23:30 - 000146200 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\TXEIx64.sys
2018-08-01 22:45 - 2018-08-01 22:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller
2018-08-01 22:43 - 2018-08-03 12:27 - 000077224 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\dptf_acpi.sys
2018-08-01 22:42 - 2018-08-03 12:27 - 000399784 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\esif_lf.sys
2018-08-01 22:42 - 2018-08-03 12:27 - 000070568 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\dptf_cpu.sys
2018-08-01 22:42 - 2018-08-01 22:42 - 000338880 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RtsBaStor.sys
2018-08-01 22:40 - 2018-08-01 22:40 - 001804688 _____ (Microsoft Corporation) C:\WINDOWS\system32\WdfCoInstaller01011.dll
2018-08-01 22:40 - 2018-08-01 22:40 - 000031816 _____ (ELAN Microelectronic Corp.) C:\WINDOWS\system32\Drivers\ETDSMBus.sys
2018-08-01 22:32 - 2018-08-07 10:56 - 000000000 ____D C:\Users\Peppo\AppData\LocalLow\IObit
2018-08-01 22:29 - 2018-08-01 22:30 - 020024376 _____ (IObit ) C:\Users\Peppo\Downloads\driver_booster_setup.exe
2018-08-01 22:22 - 2018-08-01 22:22 - 011020380 _____ C:\Users\Peppo\Downloads\0029-Install_Win10_10028_07252018.zip
2018-08-01 21:31 - 2018-08-01 21:32 - 008569378 _____ C:\Users\Peppo\Downloads\Bluetooth_QualcommAtheros_Win10_64_VER100113.zip
2018-07-30 21:31 - 2018-07-15 03:01 - 002266528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll
2018-07-30 21:31 - 2018-07-15 03:00 - 000183736 _____ (Microsoft Corporation) C:\WINDOWS\system32\mavinject.exe
2018-07-30 21:31 - 2018-07-15 02:58 - 000094112 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2018-07-30 21:31 - 2018-07-15 02:56 - 001523240 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2018-07-30 21:31 - 2018-07-15 02:44 - 006587392 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2018-07-30 21:31 - 2018-07-15 02:42 - 008624128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2018-07-30 21:31 - 2018-07-15 02:42 - 004708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2018-07-30 21:31 - 2018-07-15 02:41 - 000169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.XamlHost.dll
2018-07-30 21:31 - 2018-07-15 02:41 - 000075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll
2018-07-30 21:31 - 2018-07-15 02:39 - 001787392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2018-07-30 21:31 - 2018-07-15 02:39 - 001605632 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2018-07-30 21:31 - 2018-07-15 02:38 - 003652608 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-07-30 21:31 - 2018-07-15 02:38 - 002051584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2018-07-30 21:31 - 2018-07-15 02:38 - 001364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
2018-07-30 21:31 - 2018-07-15 02:38 - 001180160 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2018-07-30 21:31 - 2018-07-15 02:38 - 001004032 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2018-07-30 21:31 - 2018-07-15 02:38 - 000615936 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2018-07-30 21:31 - 2018-07-15 02:36 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe
2018-07-30 21:31 - 2018-07-15 01:31 - 001538968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll
2018-07-30 21:31 - 2018-07-15 01:31 - 000148888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mavinject.exe
2018-07-30 21:31 - 2018-07-15 01:28 - 001327424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2018-07-30 21:31 - 2018-07-15 01:14 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.XamlHost.dll
2018-07-30 21:31 - 2018-07-15 01:13 - 002895360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-07-30 21:31 - 2018-07-15 01:13 - 000775168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2018-07-30 21:31 - 2018-07-15 01:13 - 000485376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2018-07-30 21:31 - 2018-07-15 01:13 - 000343552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2018-07-30 21:31 - 2018-07-14 06:37 - 000230304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2018-07-30 21:31 - 2018-07-14 06:30 - 000272288 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave.dll
2018-07-30 21:31 - 2018-07-14 06:24 - 001174432 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2018-07-30 21:31 - 2018-07-14 06:23 - 001034624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2018-07-30 21:31 - 2018-07-14 06:23 - 000760888 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2018-07-30 21:31 - 2018-07-14 06:23 - 000269224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2018-07-30 21:31 - 2018-07-14 06:22 - 000510392 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2018-07-30 21:31 - 2018-07-14 06:22 - 000203560 _____ (Microsoft Corporation) C:\WINDOWS\system32\rsaenh.dll
2018-07-30 21:31 - 2018-07-14 06:21 - 001063328 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2018-07-30 21:31 - 2018-07-14 06:21 - 001012640 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2018-07-30 21:31 - 2018-07-14 06:21 - 000722824 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2018-07-30 21:31 - 2018-07-14 06:21 - 000192920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2018-07-30 21:31 - 2018-07-14 06:20 - 001457128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-07-30 21:31 - 2018-07-14 06:20 - 000567176 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2018-07-30 21:31 - 2018-07-14 06:20 - 000184472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rsaenh.dll
2018-07-30 21:31 - 2018-07-14 06:20 - 000134552 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2018-07-30 21:31 - 2018-07-14 06:19 - 009147808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-07-30 21:31 - 2018-07-14 06:19 - 001258280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-07-30 21:31 - 2018-07-14 06:19 - 000981920 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2018-07-30 21:31 - 2018-07-14 06:19 - 000636944 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2018-07-30 21:31 - 2018-07-14 06:19 - 000483024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll
2018-07-30 21:31 - 2018-07-14 06:18 - 007436112 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-07-30 21:31 - 2018-07-14 06:18 - 001017584 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2018-07-30 21:31 - 2018-07-14 06:18 - 000930712 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2018-07-30 21:31 - 2018-07-14 06:18 - 000613176 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2018-07-30 21:31 - 2018-07-14 06:18 - 000443216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2018-07-30 21:31 - 2018-07-14 06:18 - 000376216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2018-07-30 21:31 - 2018-07-14 06:17 - 002420632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2018-07-30 21:31 - 2018-07-14 06:17 - 001140568 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-07-30 21:31 - 2018-07-14 06:17 - 000983008 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-07-30 21:31 - 2018-07-14 06:17 - 000885848 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2018-07-30 21:31 - 2018-07-14 06:17 - 000743320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2018-07-30 21:31 - 2018-07-14 06:16 - 000506728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2018-07-30 21:31 - 2018-07-14 06:15 - 006044112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2018-07-30 21:31 - 2018-07-14 06:15 - 001174552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2018-07-30 21:31 - 2018-07-14 06:15 - 000829856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2018-07-30 21:31 - 2018-07-14 06:15 - 000567144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2018-07-30 21:31 - 2018-07-14 06:03 - 006661120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2018-07-30 21:31 - 2018-07-14 06:01 - 006647296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2018-07-30 21:31 - 2018-07-14 05:59 - 009084928 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2018-07-30 21:31 - 2018-07-14 05:59 - 005883392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2018-07-30 21:31 - 2018-07-14 05:59 - 003553280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2018-07-30 21:31 - 2018-07-14 05:58 - 008188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2018-07-30 21:31 - 2018-07-14 05:58 - 004371456 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2018-07-30 21:31 - 2018-07-14 05:58 - 000172544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enrollmentapi.dll
2018-07-30 21:31 - 2018-07-14 05:58 - 000094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2018-07-30 21:31 - 2018-07-14 05:58 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2018-07-30 21:31 - 2018-07-14 05:57 - 007057920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2018-07-30 21:31 - 2018-07-14 05:57 - 000391168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2018-07-30 21:31 - 2018-07-14 05:56 - 002697216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Controls.dll
2018-07-30 21:31 - 2018-07-14 05:56 - 002449408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll
2018-07-30 21:31 - 2018-07-14 05:56 - 001986560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll
2018-07-30 21:31 - 2018-07-14 05:56 - 001703936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Controls.dll
2018-07-30 21:31 - 2018-07-14 05:56 - 001558016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll
2018-07-30 21:31 - 2018-07-14 05:56 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2018-07-30 21:31 - 2018-07-14 05:56 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll
2018-07-30 21:31 - 2018-07-14 05:56 - 000073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\WFDSConMgr.dll
2018-07-30 21:31 - 2018-07-14 05:55 - 003392512 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2018-07-30 21:31 - 2018-07-14 05:55 - 001124352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdprt.dll
2018-07-30 21:31 - 2018-07-14 05:55 - 000993792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Vpn.dll
2018-07-30 21:31 - 2018-07-14 05:55 - 000582144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2018-07-30 21:31 - 2018-07-14 05:55 - 000458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2018-07-30 21:31 - 2018-07-14 05:55 - 000414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys
2018-07-30 21:31 - 2018-07-14 05:55 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\system32\RasMediaManager.dll
2018-07-30 21:31 - 2018-07-14 05:55 - 000317440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore.dll
2018-07-30 21:31 - 2018-07-14 05:55 - 000282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2018-07-30 21:31 - 2018-07-14 05:55 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2018-07-30 21:31 - 2018-07-14 05:55 - 000209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2018-07-30 21:31 - 2018-07-14 05:55 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2018-07-30 21:31 - 2018-07-14 05:55 - 000205312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreCommonProxyStub.dll
2018-07-30 21:31 - 2018-07-14 05:55 - 000204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2018-07-30 21:31 - 2018-07-14 05:55 - 000185856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2018-07-30 21:31 - 2018-07-14 05:55 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\datamarketsvc.dll
2018-07-30 21:31 - 2018-07-14 05:55 - 000119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2018-07-30 21:31 - 2018-07-14 05:55 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2018-07-30 21:31 - 2018-07-14 05:54 - 003319808 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2018-07-30 21:31 - 2018-07-14 05:54 - 002825728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
2018-07-30 21:31 - 2018-07-14 05:54 - 001627136 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2018-07-30 21:31 - 2018-07-14 05:54 - 000999936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2018-07-30 21:31 - 2018-07-14 05:54 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2018-07-30 21:31 - 2018-07-14 05:54 - 000729088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2018-07-30 21:31 - 2018-07-14 05:54 - 000678400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2018-07-30 21:31 - 2018-07-14 05:54 - 000603648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PCPKsp.dll
2018-07-30 21:31 - 2018-07-14 05:54 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2018-07-30 21:31 - 2018-07-14 05:54 - 000444416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2018-07-30 21:31 - 2018-07-14 05:54 - 000409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
2018-07-30 21:31 - 2018-07-14 05:54 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2018-07-30 21:31 - 2018-07-14 05:54 - 000358400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\exfat.sys
2018-07-30 21:31 - 2018-07-14 05:54 - 000352768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore.dll
2018-07-30 21:31 - 2018-07-14 05:54 - 000262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\PushToInstall.dll
2018-07-30 21:31 - 2018-07-14 05:54 - 000137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\raschap.dll
2018-07-30 21:31 - 2018-07-14 05:53 - 004770816 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2018-07-30 21:31 - 2018-07-14 05:53 - 003381248 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
2018-07-30 21:31 - 2018-07-14 05:53 - 002368512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2018-07-30 21:31 - 2018-07-14 05:53 - 001825792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll
2018-07-30 21:31 - 2018-07-14 05:53 - 001668096 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdprt.dll
2018-07-30 21:31 - 2018-07-14 05:53 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2018-07-30 21:31 - 2018-07-14 05:53 - 000713216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll
2018-07-30 21:31 - 2018-07-14 05:53 - 000705024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2018-07-30 21:31 - 2018-07-14 05:53 - 000681984 _____ (Microsoft Corporation) C:\WINDOWS\system32\WFDSConMgrSvc.dll
2018-07-30 21:31 - 2018-07-14 05:53 - 000566272 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2018-07-30 21:31 - 2018-07-14 05:53 - 000450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreCommonProxyStub.dll
2018-07-30 21:31 - 2018-07-14 05:53 - 000396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2018-07-30 21:31 - 2018-07-14 05:53 - 000220160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2018-07-30 21:31 - 2018-07-14 05:52 - 002172928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2018-07-30 21:31 - 2018-07-14 05:52 - 001550848 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2018-07-30 21:31 - 2018-07-14 05:52 - 000972800 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2018-07-30 21:31 - 2018-07-14 05:52 - 000916480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2018-07-30 21:31 - 2018-07-14 05:52 - 000790528 _____ (Microsoft Corporation) C:\WINDOWS\system32\PCPKsp.dll
2018-07-30 21:31 - 2018-07-14 05:52 - 000755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2018-07-30 21:31 - 2018-07-14 05:52 - 000506880 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofmsvc.dll
2018-07-30 21:31 - 2018-07-14 05:52 - 000311296 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2018-07-30 21:31 - 2018-07-14 05:51 - 003376640 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2018-07-30 21:31 - 2018-07-14 05:51 - 002904576 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2018-07-30 21:31 - 2018-07-14 05:51 - 001804288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2018-07-30 21:31 - 2018-07-14 05:51 - 001747968 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll
2018-07-30 21:31 - 2018-07-14 05:51 - 001395712 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2018-07-30 21:31 - 2018-07-14 05:51 - 001304064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2018-07-30 21:31 - 2018-07-14 05:51 - 000491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragsvc.dll
2018-07-30 21:31 - 2018-07-14 05:51 - 000466432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2018-07-30 21:31 - 2018-07-14 05:50 - 002236928 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2018-07-30 21:31 - 2018-07-14 05:50 - 001457664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2018-07-30 21:31 - 2018-07-14 05:50 - 001359360 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpasvc.dll
2018-07-30 21:31 - 2018-07-14 05:50 - 001225216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2018-07-30 21:31 - 2018-07-14 05:50 - 000949760 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2018-07-30 21:31 - 2018-07-14 05:50 - 000943616 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll
2018-07-30 21:31 - 2018-07-14 05:50 - 000932352 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2018-07-30 21:31 - 2018-07-14 05:50 - 000884224 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2018-07-30 21:31 - 2018-07-14 05:50 - 000522752 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2018-07-30 21:31 - 2018-07-14 05:50 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2018-07-30 21:31 - 2018-07-14 05:49 - 000884736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2018-07-30 21:31 - 2018-07-14 04:35 - 000001310 _____ C:\WINDOWS\system32\tcbres.wim
2018-07-30 21:30 - 2018-07-15 02:44 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2018-07-30 21:30 - 2018-07-15 02:43 - 012710400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2018-07-30 21:30 - 2018-07-15 02:38 - 000391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2018-07-30 21:30 - 2018-07-15 02:38 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpinit.exe
2018-07-30 21:30 - 2018-07-15 02:37 - 000463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpshell.exe
2018-07-30 21:30 - 2018-07-15 01:18 - 005657600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2018-07-30 21:30 - 2018-07-15 01:17 - 011901440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2018-07-30 21:30 - 2018-07-15 01:15 - 007987712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2018-07-30 21:30 - 2018-07-15 01:13 - 001452544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2018-07-30 21:30 - 2018-07-15 01:13 - 001308160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2018-07-30 21:30 - 2018-07-15 01:11 - 000080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcbuilder.exe
2018-07-30 21:30 - 2018-07-14 08:46 - 023862784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2018-07-30 21:30 - 2018-07-14 08:42 - 019525632 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2018-07-30 21:30 - 2018-07-14 06:37 - 000375712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2018-07-30 21:30 - 2018-07-14 06:22 - 006813744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2018-07-30 21:30 - 2018-07-14 06:22 - 001144664 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2018-07-30 21:30 - 2018-07-14 06:19 - 002535032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2018-07-30 21:30 - 2018-07-14 06:19 - 001946752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2018-07-30 21:30 - 2018-07-14 06:19 - 000713368 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2018-07-30 21:30 - 2018-07-14 06:18 - 002563984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2018-07-30 21:30 - 2018-07-14 06:18 - 002371416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2018-07-30 21:30 - 2018-07-14 06:18 - 001097648 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2018-07-30 21:30 - 2018-07-14 06:17 - 006527056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2018-07-30 21:30 - 2018-07-14 06:16 - 002331576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2018-07-30 21:30 - 2018-07-14 06:16 - 001143096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2018-07-30 21:30 - 2018-07-14 06:15 - 001559368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2018-07-30 21:30 - 2018-07-14 06:15 - 001129640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2018-07-30 21:30 - 2018-07-14 06:15 - 000581696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVideoDSP.dll
2018-07-30 21:30 - 2018-07-14 06:08 - 022006784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2018-07-30 21:30 - 2018-07-14 06:03 - 019404288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-07-30 21:30 - 2018-07-14 06:01 - 025846784 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-07-30 21:30 - 2018-07-14 06:00 - 022714368 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-07-30 21:30 - 2018-07-14 05:57 - 005779456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2018-07-30 21:30 - 2018-07-14 05:57 - 004331008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2018-07-30 21:30 - 2018-07-14 05:57 - 001361408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSPhotography.dll
2018-07-30 21:30 - 2018-07-14 05:57 - 001295360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll
2018-07-30 21:30 - 2018-07-14 05:57 - 000608768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2018-07-30 21:30 - 2018-07-14 05:57 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2018-07-30 21:30 - 2018-07-14 05:56 - 004559872 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2018-07-30 21:30 - 2018-07-14 05:56 - 002900992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2018-07-30 21:30 - 2018-07-14 05:56 - 000257536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WiFiDisplay.dll
2018-07-30 21:30 - 2018-07-14 05:56 - 000118784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\raschap.dll
2018-07-30 21:30 - 2018-07-14 05:55 - 001627136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2018-07-30 21:30 - 2018-07-14 05:55 - 000619520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2018-07-30 21:30 - 2018-07-14 05:55 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\EASPolicyManagerBrokerHost.exe
2018-07-30 21:30 - 2018-07-14 05:54 - 007579648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2018-07-30 21:30 - 2018-07-14 05:54 - 001537024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
2018-07-30 21:30 - 2018-07-14 05:54 - 001307648 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2018-07-30 21:30 - 2018-07-14 05:54 - 000808448 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2018-07-30 21:30 - 2018-07-14 05:54 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\EasPolicyManagerBrokerPS.dll
2018-07-30 21:30 - 2018-07-14 05:53 - 001931776 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeangle.dll
2018-07-30 21:30 - 2018-07-14 05:53 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2018-07-30 21:30 - 2018-07-14 05:52 - 001708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSPhotography.dll
2018-07-30 21:30 - 2018-07-14 05:50 - 001773056 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2018-07-19 00:13 - 2018-08-02 23:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Data Recovery Wizard
2018-07-18 20:49 - 2018-07-18 20:49 - 001073608 _____ (File Repair ) C:\Users\Peppo\Downloads\file-repair-setup_2.1.2.exe
2018-07-18 20:39 - 2018-07-18 20:39 - 008685920 _____ (Stellar Information Technology Pvt Ltd. ) C:\Users\Peppo\Downloads\StellarPhoenixJPEGRepair.exe
2018-07-18 18:56 - 2018-07-18 18:56 - 000000080 ___SH C:\bootTel.dat
2018-07-18 18:54 - 2018-07-18 18:54 - 000000000 ____D C:\easeus_tb_cloud
2018-07-18 18:14 - 2018-08-02 23:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Todo Backup 11.0
2018-07-18 18:07 - 2018-07-18 18:08 - 074752192 _____ (CHENGDU YIWO Tech Development Co., Ltd ) C:\Users\Peppo\Downloads\tb_free.exe
2018-07-18 17:43 - 2018-07-18 17:43 - 042406544 _____ (EaseUS ) C:\Users\Peppo\Downloads\drw_free.exe
2018-07-18 17:02 - 2018-07-18 17:02 - 000000000 ____D C:\Users\Peppo\Downloads\testdisk-7.1-WIP.win
2018-07-18 16:25 - 2018-07-18 16:25 - 020339774 _____ C:\Users\Peppo\Downloads\testdisk-7.1-WIP.win.zip
2018-07-18 16:22 - 2018-07-18 16:22 - 005562976 _____ (Piriform Ltd) C:\Users\Peppo\Downloads\rcsetup153.exe
2018-07-18 13:49 - 2018-07-13 06:34 - 000709816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2018-07-18 13:49 - 2018-07-13 06:32 - 000170904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2018-07-18 13:49 - 2018-07-13 06:30 - 002718624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2018-07-18 13:49 - 2018-07-13 05:59 - 001535488 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-07-18 13:49 - 2018-07-11 12:23 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll
2018-07-18 13:49 - 2018-05-20 13:26 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2018-07-18 13:48 - 2018-07-11 11:24 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll
2018-07-18 13:22 - 2018-07-18 13:24 - 000000000 ____D C:\Users\Peppo\Downloads\usbdeview
2018-07-18 13:21 - 2018-07-18 13:21 - 000082989 _____ C:\Users\Peppo\Downloads\usbdeview.zip
2018-07-12 21:19 - 2018-07-12 21:19 - 062299901 _____ C:\Users\Peppo\Downloads\Aggiornamento_BlueMe_5.5_06.03.2012.zip
2018-07-12 21:19 - 2018-07-12 21:19 - 004837447 _____ C:\Users\Peppo\Downloads\Aggiornamento_BlueMe_5.6_11.05.2012.zip
2018-07-12 20:23 - 2018-07-12 20:23 - 000245268 _____ C:\Users\Peppo\Downloads\kingston_format_utility.exe
2018-07-12 17:31 - 2018-08-02 23:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master 11.5
2018-07-12 17:29 - 2018-07-12 17:29 - 049067928 _____ (EaseUS ) C:\Users\Peppo\Downloads\epm (1).exe
2018-07-12 16:17 - 2018-07-12 16:17 - 003633120 _____ C:\Users\Peppo\Downloads\mp3tagv289setup.exe
2018-07-11 21:00 - 2018-08-02 23:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2018-07-11 20:57 - 2018-07-11 20:57 - 011821597 _____ C:\Users\Peppo\Downloads\ATKPackage_Win10_64_VER100050.zip
2018-07-11 20:57 - 2018-07-11 20:57 - 002815130 _____ C:\Users\Peppo\Downloads\Chipset_Intel_Skylate_Win10_64_VER101111.zip
2018-07-11 20:47 - 2018-07-11 20:47 - 049446448 _____ C:\Users\Peppo\Downloads\win-mg2500-1_1-mcd.exe
2018-07-11 20:32 - 2018-07-11 21:44 - 000002727 _____ C:\Users\Peppo\Documents\lettera.txt
2018-07-11 17:31 - 2018-07-11 17:31 - 013906720 _____ (Intel) C:\Users\Peppo\Downloads\Intel Driver and Support Assistant Installer.exe
2018-07-11 17:26 - 2018-06-15 07:12 - 007519992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-07-11 17:26 - 2018-06-15 07:03 - 006572000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-07-11 17:25 - 2018-06-15 19:49 - 021388856 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2018-07-11 17:25 - 2018-06-08 21:02 - 004527680 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2018-07-11 17:25 - 2018-05-20 13:34 - 016592384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2018-07-11 17:25 - 2018-05-20 13:23 - 013873152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2018-07-11 17:24 - 2018-07-06 08:58 - 004867584 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-07-11 17:24 - 2018-06-15 17:25 - 020383720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2018-07-11 17:24 - 2018-06-15 07:21 - 001213368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2018-07-11 17:24 - 2018-06-15 07:08 - 004403304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2018-07-11 17:24 - 2018-06-15 07:08 - 001784584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2018-07-11 17:24 - 2018-06-15 07:08 - 001288840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2018-07-11 17:24 - 2018-06-15 07:07 - 001611584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2018-07-11 17:24 - 2018-06-15 07:03 - 004788504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2018-07-11 17:24 - 2018-06-15 07:03 - 001710240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2018-07-11 17:24 - 2018-06-15 06:46 - 004706816 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2018-07-11 17:24 - 2018-06-08 20:45 - 004392448 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2018-07-11 17:24 - 2018-06-08 20:43 - 002922496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2018-07-11 17:24 - 2018-06-08 18:47 - 003492864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll
2018-07-11 17:24 - 2018-06-08 12:38 - 005821544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2018-07-11 17:24 - 2018-06-08 12:37 - 002417840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2018-07-11 17:24 - 2018-06-08 12:31 - 007900984 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2018-07-11 17:24 - 2018-06-08 12:31 - 003180176 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2018-07-11 17:24 - 2018-06-08 11:30 - 003296896 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2018-07-11 17:24 - 2018-06-08 11:30 - 001017080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2adec.dll
2018-07-11 17:24 - 2018-06-08 11:29 - 004970360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2018-07-11 17:24 - 2018-06-08 11:29 - 003283408 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll
2018-07-11 17:24 - 2018-06-08 11:29 - 002462272 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2018-07-11 17:24 - 2018-06-08 11:12 - 000861616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2adec.dll
2018-07-11 17:24 - 2018-06-08 11:10 - 002479272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2018-07-11 17:24 - 2018-06-08 11:10 - 001988072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2018-07-11 17:24 - 2018-06-08 11:09 - 004469832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2018-07-11 17:24 - 2018-06-08 11:09 - 002486992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2018-07-11 17:24 - 2018-06-08 11:00 - 001285120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll
2018-07-11 17:24 - 2018-06-08 10:59 - 006032384 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2018-07-11 17:24 - 2018-06-08 10:57 - 003348992 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2018-07-11 17:24 - 2018-06-08 10:56 - 005307392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2018-07-11 17:24 - 2018-06-08 10:56 - 002364928 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll
2018-07-11 17:24 - 2018-06-08 10:55 - 002248192 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2018-07-11 17:24 - 2018-06-08 10:55 - 002061824 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2018-07-11 17:24 - 2018-06-08 10:54 - 002789376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2018-07-11 17:24 - 2018-06-06 20:57 - 003733320 _____ C:\WINDOWS\system32\Windows.Mirage.dll
2018-07-11 17:24 - 2018-06-06 06:20 - 002841312 _____ C:\WINDOWS\SysWOW64\Windows.Mirage.dll
2018-07-11 17:24 - 2018-05-20 13:53 - 002178136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2018-07-11 17:24 - 2018-05-20 13:53 - 001012408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2018-07-11 17:24 - 2018-05-20 13:33 - 001665920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2018-07-11 17:24 - 2018-05-20 13:26 - 003392512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2018-07-11 17:24 - 2018-05-20 13:17 - 002699776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2018-07-11 17:24 - 2018-04-28 15:17 - 012500992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2018-07-11 17:24 - 2018-04-28 05:58 - 003086336 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2018-07-11 17:24 - 2018-04-28 04:43 - 001953280 _____ C:\WINDOWS\system32\rdpnano.dll
2018-07-11 17:23 - 2018-07-06 16:20 - 002868640 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2018-07-11 17:23 - 2018-07-06 16:20 - 001610648 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2018-07-11 17:23 - 2018-07-06 16:20 - 000689560 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2018-07-11 17:23 - 2018-07-06 16:17 - 003932672 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2018-07-11 17:23 - 2018-07-06 14:06 - 003611368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2018-07-11 17:23 - 2018-07-06 09:31 - 000462752 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2018-07-11 17:23 - 2018-07-06 09:25 - 002753040 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2018-07-11 17:23 - 2018-07-06 09:25 - 002571728 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2018-07-11 17:23 - 2018-07-06 09:24 - 000380824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2018-07-11 17:23 - 2018-07-06 08:56 - 001817600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2018-07-11 17:23 - 2018-07-06 08:55 - 003440128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-07-11 17:23 - 2018-06-15 19:48 - 002395056 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
2018-07-11 17:23 - 2018-06-15 07:09 - 001798552 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2018-07-11 17:23 - 2018-06-15 07:03 - 001020160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2018-07-11 17:23 - 2018-06-15 06:45 - 002548736 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
2018-07-11 17:23 - 2018-06-15 06:41 - 001768448 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2018-07-11 17:23 - 2018-06-08 20:42 - 003999232 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll
2018-07-11 17:23 - 2018-06-08 12:34 - 001299056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
2018-07-11 17:23 - 2018-06-08 12:34 - 000748512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2018-07-11 17:23 - 2018-06-08 10:59 - 001318400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2018-07-11 17:23 - 2018-06-08 10:59 - 000673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2018-07-11 17:23 - 2018-06-08 10:58 - 001676800 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShell.dll
2018-07-11 17:23 - 2018-06-08 10:56 - 003293696 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2018-07-11 17:23 - 2018-06-08 10:55 - 001192448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Maps.dll
2018-07-11 17:23 - 2018-06-08 10:55 - 001160192 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2018-07-11 17:23 - 2018-06-08 10:55 - 000776192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2018-07-11 17:23 - 2018-06-08 10:55 - 000667648 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2018-07-11 17:23 - 2018-06-08 10:54 - 001586176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2018-07-11 17:23 - 2018-06-08 10:54 - 001128448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2018-07-11 17:23 - 2018-06-08 10:54 - 000950272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2018-07-11 17:23 - 2018-06-08 10:53 - 001675264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2018-07-11 17:23 - 2018-05-20 21:42 - 001649760 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2018-07-11 17:23 - 2018-05-20 21:23 - 000947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmsys.cpl
2018-07-11 17:23 - 2018-05-20 21:23 - 000899072 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2018-07-11 17:23 - 2018-05-20 21:22 - 001665024 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2018-07-11 17:23 - 2018-05-20 20:14 - 001490144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2018-07-11 17:23 - 2018-05-20 20:00 - 000864768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmsys.cpl
2018-07-11 17:23 - 2018-05-20 18:45 - 001271296 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloSI.PCShell.dll
2018-07-11 17:23 - 2018-05-20 13:52 - 000735560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2018-07-11 17:23 - 2018-05-20 13:32 - 001034096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
2018-07-11 17:23 - 2018-05-20 13:31 - 001456640 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2018-07-11 17:23 - 2018-05-20 13:21 - 001210880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2018-07-11 17:23 - 2018-05-20 13:11 - 001005568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2018-07-11 17:23 - 2018-04-28 15:12 - 001380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
2018-07-11 17:22 - 2018-07-06 16:20 - 000792472 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2018-07-11 17:22 - 2018-07-06 16:20 - 000612248 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2018-07-11 17:22 - 2018-07-06 16:20 - 000451992 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2018-07-11 17:22 - 2018-07-06 09:14 - 002242208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2018-07-11 17:22 - 2018-07-06 09:14 - 001981896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2018-07-11 17:22 - 2018-07-06 09:13 - 001620872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2018-07-11 17:22 - 2018-07-06 08:57 - 003712512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-07-11 17:22 - 2018-07-06 08:54 - 003015680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2018-07-11 17:22 - 2018-07-06 08:54 - 001214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2018-07-11 17:22 - 2018-06-15 19:50 - 001376576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2018-07-11 17:22 - 2018-06-15 19:30 - 001308672 _____ C:\WINDOWS\system32\FaceProcessor.dll
2018-07-11 17:22 - 2018-06-15 19:30 - 001254400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2018-07-11 17:22 - 2018-06-15 19:30 - 001186816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.CommonBridge.dll
2018-07-11 17:22 - 2018-06-15 19:30 - 000878592 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2018-07-11 17:22 - 2018-06-15 17:02 - 000704000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2018-07-11 17:22 - 2018-06-15 07:09 - 002830240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2018-07-11 17:22 - 2018-06-15 07:09 - 002546592 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2018-07-11 17:22 - 2018-06-15 07:09 - 001659296 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2018-07-11 17:22 - 2018-06-15 07:09 - 001209800 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2018-07-11 17:22 - 2018-06-15 07:04 - 001462824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2018-07-11 17:22 - 2018-06-15 07:03 - 001380192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2018-07-11 17:22 - 2018-06-15 06:49 - 002962944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2018-07-11 17:22 - 2018-06-15 06:40 - 001487360 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2018-07-11 17:22 - 2018-06-15 06:38 - 001854976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2018-07-11 17:22 - 2018-06-15 06:37 - 001374208 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2018-07-11 17:22 - 2018-06-08 21:01 - 001046944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2018-07-11 17:22 - 2018-06-08 20:41 - 001180672 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2018-07-11 17:22 - 2018-06-08 18:58 - 000917408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
2018-07-11 17:22 - 2018-06-08 18:46 - 000908288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2018-07-11 17:22 - 2018-06-08 18:06 - 000976384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe
2018-07-11 17:22 - 2018-06-08 18:05 - 000944640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
2018-07-11 17:22 - 2018-06-08 16:00 - 000658432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2018-07-11 17:22 - 2018-06-08 12:35 - 001613200 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2018-07-11 17:22 - 2018-06-08 11:29 - 001364184 _____ (Microsoft Corporation) C:\WINDOWS\system32\webservices.dll
2018-07-11 17:22 - 2018-06-08 11:29 - 001190152 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2018-07-11 17:22 - 2018-06-08 11:29 - 000416144 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
2018-07-11 17:22 - 2018-06-08 11:10 - 000457152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAudDecMFT.dll
2018-07-11 17:22 - 2018-06-08 11:09 - 001584128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll
2018-07-11 17:22 - 2018-06-08 11:09 - 001077504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webservices.dll
2018-07-11 17:22 - 2018-06-08 10:55 - 001171968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2018-07-11 17:22 - 2018-06-08 10:55 - 000652800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2018-07-11 17:22 - 2018-06-08 10:55 - 000630784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.MediaPlayer.dll
2018-07-11 17:22 - 2018-06-08 10:54 - 000646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll
2018-07-11 17:22 - 2018-06-08 10:53 - 000669696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2018-07-11 17:22 - 2018-05-20 21:22 - 000804352 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVolSSO.dll
2018-07-11 17:22 - 2018-05-20 19:59 - 000747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SndVolSSO.dll
2018-07-11 17:22 - 2018-05-20 13:32 - 000560488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2018-07-11 17:22 - 2018-05-20 13:23 - 000933376 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2018-07-11 17:22 - 2018-04-28 06:29 - 000776880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2018-07-11 17:22 - 2018-04-28 05:59 - 000553984 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationExtensions.dll
2018-07-11 17:21 - 2018-07-06 16:20 - 000309664 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2018-07-11 17:21 - 2018-07-06 16:20 - 000144792 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2018-07-11 17:21 - 2018-07-06 15:53 - 000672768 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpprefcl.dll
2018-07-11 17:21 - 2018-07-06 15:53 - 000340992 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2018-07-11 17:21 - 2018-07-06 13:51 - 002401280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2018-07-11 17:21 - 2018-07-06 09:32 - 000480672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2018-07-11 17:21 - 2018-07-06 09:26 - 001148800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2018-07-11 17:21 - 2018-07-06 09:25 - 001945784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2018-07-11 17:21 - 2018-07-06 09:14 - 000988640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2018-07-11 17:21 - 2018-07-06 08:59 - 001153536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2018-07-11 17:21 - 2018-07-06 08:58 - 000670720 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2018-07-11 17:21 - 2018-07-06 08:57 - 000473088 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2018-07-11 17:21 - 2018-07-06 08:56 - 001567744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll
2018-07-11 17:21 - 2018-07-06 08:56 - 000784896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2018-07-11 17:21 - 2018-07-06 08:56 - 000327680 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioCredProv.dll
2018-07-11 17:21 - 2018-07-06 08:55 - 001264640 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2018-07-11 17:21 - 2018-07-06 08:54 - 000542208 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2018-07-11 17:21 - 2018-07-06 08:54 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2018-07-11 17:21 - 2018-07-06 08:52 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2018-07-11 17:21 - 2018-06-15 19:48 - 000338352 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSrvPolicyManager.dll
2018-07-11 17:21 - 2018-06-15 19:31 - 002193920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ModernAppAgent.dll
2018-07-11 17:21 - 2018-06-15 19:29 - 000740864 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2018-07-11 17:21 - 2018-06-15 17:22 - 001026896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2018-07-11 17:21 - 2018-06-15 17:16 - 002206528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
2018-07-11 17:21 - 2018-06-15 15:23 - 000788992 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll
2018-07-11 17:21 - 2018-06-15 07:15 - 000753152 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2018-07-11 17:21 - 2018-06-15 07:12 - 000661152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2018-07-11 17:21 - 2018-06-15 07:12 - 000491304 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2018-07-11 17:21 - 2018-06-15 07:10 - 001934400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2018-07-11 17:21 - 2018-06-15 07:10 - 000717208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2018-07-11 17:21 - 2018-06-15 07:09 - 001742272 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2018-07-11 17:21 - 2018-06-15 07:09 - 001112600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2018-07-11 17:21 - 2018-06-15 07:09 - 000594128 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2018-07-11 17:21 - 2018-06-15 07:08 - 002062488 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2018-07-11 17:21 - 2018-06-15 07:08 - 000898760 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2018-07-11 17:21 - 2018-06-15 07:05 - 000550608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2018-07-11 17:21 - 2018-06-15 07:04 - 001251736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll
2018-07-11 17:21 - 2018-06-15 07:04 - 000719552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2018-07-11 17:21 - 2018-06-15 07:03 - 002163184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2018-07-11 17:21 - 2018-06-15 07:03 - 001805752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2018-07-11 17:21 - 2018-06-15 07:03 - 001011968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2018-07-11 17:21 - 2018-06-15 07:03 - 000770152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2018-07-11 17:21 - 2018-06-15 06:46 - 001356800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2018-07-11 17:21 - 2018-06-15 06:46 - 000593408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2018-07-11 17:21 - 2018-06-15 06:46 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2018-07-11 17:21 - 2018-06-15 06:45 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2018-07-11 17:21 - 2018-06-15 06:44 - 001342976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2018-07-11 17:21 - 2018-06-15 06:43 - 001110528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2018-07-11 17:21 - 2018-06-15 06:43 - 000312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagnosticLogCSP.dll
2018-07-11 17:21 - 2018-06-15 06:42 - 000102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2018-07-11 17:21 - 2018-06-15 06:41 - 001724928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2018-07-11 17:21 - 2018-06-15 06:41 - 000625152 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2018-07-11 17:21 - 2018-06-15 06:40 - 000827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2018-07-11 17:21 - 2018-06-15 06:39 - 002583552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2018-07-11 17:21 - 2018-06-15 06:39 - 000916992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2018-07-11 17:21 - 2018-06-15 06:39 - 000847360 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2018-07-11 17:21 - 2018-06-15 06:39 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2018-07-11 17:21 - 2018-06-15 06:38 - 001581568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2018-07-11 17:21 - 2018-06-15 06:38 - 001305088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2018-07-11 17:21 - 2018-06-15 06:38 - 001070080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2018-07-11 17:21 - 2018-06-15 06:38 - 001036288 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2018-07-11 17:21 - 2018-06-15 06:38 - 000910848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2018-07-11 17:21 - 2018-06-15 06:38 - 000596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2018-07-11 17:21 - 2018-06-08 21:02 - 001634808 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2018-07-11 17:21 - 2018-06-08 20:45 - 000808960 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2018-07-11 17:21 - 2018-06-08 20:44 - 001121792 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2018-07-11 17:21 - 2018-06-08 20:44 - 000625152 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2018-07-11 17:21 - 2018-06-08 20:43 - 003640832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2018-07-11 17:21 - 2018-06-08 20:43 - 001719808 _____ (Microsoft Corporation) C:\WINDOWS\system32\dui70.dll
2018-07-11 17:21 - 2018-06-08 20:43 - 001659904 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2018-07-11 17:21 - 2018-06-08 20:43 - 001543680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
2018-07-11 17:21 - 2018-06-08 20:42 - 000800256 _____ (Microsoft Corporation) C:\WINDOWS\system32\pwcreator.exe
2018-07-11 17:21 - 2018-06-08 20:40 - 000465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXP.dll
2018-07-11 17:21 - 2018-06-08 18:47 - 001462784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dui70.dll
2018-07-11 17:21 - 2018-06-08 18:47 - 001032704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
2018-07-11 17:21 - 2018-06-08 18:46 - 003444224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2018-07-11 17:21 - 2018-06-08 12:35 - 000613144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2018-07-11 17:21 - 2018-06-08 12:30 - 000705440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2018-07-11 17:21 - 2018-06-08 11:30 - 001363632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2018-07-11 17:21 - 2018-06-08 11:30 - 000723360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2018-07-11 17:21 - 2018-06-08 11:30 - 000565152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2018-07-11 17:21 - 2018-06-08 11:30 - 000527264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2018-07-11 17:21 - 2018-06-08 11:29 - 001792808 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
2018-07-11 17:21 - 2018-06-08 11:29 - 000678840 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2018-07-11 17:21 - 2018-06-08 11:29 - 000164768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2018-07-11 17:21 - 2018-06-08 11:12 - 000786176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2018-07-11 17:21 - 2018-06-08 11:10 - 000880152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2018-07-11 17:21 - 2018-06-08 11:09 - 000607648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2018-07-11 17:21 - 2018-06-08 11:09 - 000553248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2018-07-11 17:21 - 2018-06-08 11:01 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2018-07-11 17:21 - 2018-06-08 11:00 - 000329216 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll
2018-07-11 17:21 - 2018-06-08 10:58 - 000781824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2018-07-11 17:21 - 2018-06-08 10:58 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FSClient.dll
2018-07-11 17:21 - 2018-06-08 10:57 - 000483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTMediaFrame.dll
2018-07-11 17:21 - 2018-06-08 10:56 - 000871424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll
2018-07-11 17:21 - 2018-06-08 10:56 - 000858112 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll
2018-07-11 17:21 - 2018-06-08 10:56 - 000264704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovs.dll
2018-07-11 17:21 - 2018-06-08 10:55 - 001242112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2018-07-11 17:21 - 2018-06-08 10:54 - 000842240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2018-07-11 17:21 - 2018-06-08 10:54 - 000729088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FlightSettings.dll
2018-07-11 17:21 - 2018-06-08 10:54 - 000593408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2018-07-11 17:21 - 2018-06-08 10:54 - 000375808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTMediaFrame.dll
2018-07-11 17:21 - 2018-06-08 10:53 - 001466368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2018-07-11 17:21 - 2018-06-08 10:53 - 000528384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2018-07-11 17:21 - 2018-05-20 19:59 - 000863232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll
2018-07-11 17:21 - 2018-05-20 13:53 - 001017088 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2018-07-11 17:21 - 2018-05-20 13:52 - 000347704 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2018-07-11 17:21 - 2018-05-20 13:34 - 000861096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll
2018-07-11 17:21 - 2018-05-20 13:32 - 000286200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2018-07-11 17:21 - 2018-05-20 13:24 - 000234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyMATEnc.dll
2018-07-11 17:21 - 2018-05-20 13:21 - 000960512 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2018-07-11 17:21 - 2018-05-20 13:21 - 000783360 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyHrtfEnc.dll
2018-07-11 17:21 - 2018-05-20 13:12 - 000860160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2018-07-11 17:21 - 2018-04-28 16:00 - 000695296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hhctrl.ocx
2018-07-11 17:21 - 2018-04-28 15:58 - 001855488 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2018-07-11 17:21 - 2018-04-28 06:29 - 000788216 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2018-07-11 17:21 - 2018-04-28 06:29 - 000494488 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2018-07-11 17:21 - 2018-04-28 06:14 - 000434584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2018-07-11 17:21 - 2018-04-28 06:12 - 000606448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2018-07-11 17:20 - 2018-07-06 16:20 - 000070040 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2018-07-11 17:20 - 2018-07-06 16:14 - 000541592 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2018-07-11 17:20 - 2018-07-06 15:53 - 000409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2018-07-11 17:20 - 2018-07-06 15:53 - 000386048 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2018-07-11 17:20 - 2018-07-06 15:52 - 000677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2018-07-11 17:20 - 2018-07-06 13:53 - 000565248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpprefcl.dll
2018-07-11 17:20 - 2018-07-06 13:53 - 000347136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
2018-07-11 17:20 - 2018-07-06 09:31 - 000035232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2018-07-11 17:20 - 2018-07-06 09:27 - 000057440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.ShellCommon.Broker.dll
2018-07-11 17:20 - 2018-07-06 09:26 - 000766608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2018-07-11 17:20 - 2018-07-06 09:25 - 001026464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2018-07-11 17:20 - 2018-07-06 09:25 - 000335776 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2018-07-11 17:20 - 2018-07-06 09:25 - 000267680 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2018-07-11 17:20 - 2018-07-06 09:25 - 000139672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
2018-07-11 17:20 - 2018-07-06 09:14 - 000573904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2018-07-11 17:20 - 2018-07-06 09:01 - 000104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2018-07-11 17:20 - 2018-07-06 09:01 - 000014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll
2018-07-11 17:20 - 2018-07-06 09:00 - 000151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2018-07-11 17:20 - 2018-07-06 09:00 - 000094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2018-07-11 17:20 - 2018-07-06 09:00 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
2018-07-11 17:20 - 2018-07-06 09:00 - 000053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll
2018-07-11 17:20 - 2018-07-06 09:00 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsTelemetry.dll
2018-07-11 17:20 - 2018-07-06 09:00 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll
2018-07-11 17:20 - 2018-07-06 08:59 - 000334336 _____ (Microsoft Corporation) C:\WINDOWS\system32\NmaDirect.dll
2018-07-11 17:20 - 2018-07-06 08:59 - 000200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Geolocation.dll
2018-07-11 17:20 - 2018-07-06 08:59 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2018-07-11 17:20 - 2018-07-06 08:59 - 000048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\tokenbinding.dll
2018-07-11 17:20 - 2018-07-06 08:59 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2018-07-11 17:20 - 2018-07-06 08:58 - 000236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Core.dll
2018-07-11 17:20 - 2018-07-06 08:58 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Cortana.dll
2018-07-11 17:20 - 2018-07-06 08:58 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProv2faHelper.dll
2018-07-11 17:20 - 2018-07-06 08:58 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2018-07-11 17:20 - 2018-07-06 08:58 - 000075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mpsdrv.sys
2018-07-11 17:20 - 2018-07-06 08:58 - 000035840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tokenbinding.dll
2018-07-11 17:20 - 2018-07-06 08:57 - 000839680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2018-07-11 17:20 - 2018-07-06 08:57 - 000676864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Devices.dll
2018-07-11 17:20 - 2018-07-06 08:57 - 000262656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NmaDirect.dll
2018-07-11 17:20 - 2018-07-06 08:56 - 000814592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2018-07-11 17:20 - 2018-07-06 08:56 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuietHours.dll
2018-07-11 17:20 - 2018-07-06 08:56 - 000508416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2018-07-11 17:20 - 2018-07-06 08:56 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2018-07-11 17:20 - 2018-07-06 08:56 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2018-07-11 17:20 - 2018-07-06 08:56 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2018-07-11 17:20 - 2018-07-06 08:56 - 000181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Core.dll
2018-07-11 17:20 - 2018-07-06 08:56 - 000081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProv2faHelper.dll
2018-07-11 17:20 - 2018-07-06 08:55 - 000415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2018-07-11 17:20 - 2018-07-06 08:55 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2018-07-11 17:20 - 2018-07-06 08:54 - 000978944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2018-07-11 17:20 - 2018-07-06 08:54 - 000899072 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2018-07-11 17:20 - 2018-07-06 08:54 - 000275968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2018-07-11 17:20 - 2018-07-06 08:54 - 000254464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BioCredProv.dll
2018-07-11 17:20 - 2018-07-06 08:53 - 000778240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2018-07-11 17:20 - 2018-06-15 19:55 - 000542888 _____ C:\WINDOWS\system32\FaceProcessorCore.dll
2018-07-11 17:20 - 2018-06-15 19:53 - 000348256 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2018-07-11 17:20 - 2018-06-15 19:34 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\DsmUserTask.exe
2018-07-11 17:20 - 2018-06-15 19:34 - 000025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfnet.dll
2018-07-11 17:20 - 2018-06-15 19:33 - 000182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpdr.sys
2018-07-11 17:20 - 2018-06-15 19:33 - 000156160 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupManagerAPI.dll
2018-07-11 17:20 - 2018-06-15 19:33 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2018-07-11 17:20 - 2018-06-15 19:32 - 000755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.PrinterCustomActions.dll
2018-07-11 17:20 - 2018-06-15 19:32 - 000406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.CscUnpinTool.exe
2018-07-11 17:20 - 2018-06-15 19:32 - 000301568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcLayers.dll
2018-07-11 17:20 - 2018-06-15 19:32 - 000145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2018-07-11 17:20 - 2018-06-15 19:31 - 000907776 _____ (Microsoft Corporation) C:\WINDOWS\system32\autofmt.exe
2018-07-11 17:20 - 2018-06-15 19:31 - 000220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2018-07-11 17:20 - 2018-06-15 19:30 - 001127936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplySettingsTemplateCatalog.exe
2018-07-11 17:20 - 2018-06-15 19:30 - 001054720 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2018-07-11 17:20 - 2018-06-15 19:29 - 002084352 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2018-07-11 17:20 - 2018-06-15 19:29 - 000932352 _____ (Microsoft Corporation) C:\WINDOWS\system32\autoconv.exe
2018-07-11 17:20 - 2018-06-15 19:29 - 000757248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2018-07-11 17:20 - 2018-06-15 19:29 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\shdocvw.dll
2018-07-11 17:20 - 2018-06-15 19:29 - 000103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSoftwareInstallationClient.dll
2018-07-11 17:20 - 2018-06-15 19:28 - 000223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpd_ci.dll
2018-07-11 17:20 - 2018-06-15 19:28 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll
2018-07-11 17:20 - 2018-06-15 19:03 - 000055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UevAppMonitor.exe
2018-07-11 17:20 - 2018-06-15 19:00 - 000058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ModernAppCore.dll
2018-07-11 17:20 - 2018-06-15 17:06 - 000022016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfnet.dll
2018-07-11 17:20 - 2018-06-15 17:04 - 000851968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autoconv.exe
2018-07-11 17:20 - 2018-06-15 17:04 - 000373248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcLayers.dll
2018-07-11 17:20 - 2018-06-15 17:03 - 000831488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autofmt.exe
2018-07-11 17:20 - 2018-06-15 17:03 - 000667648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2018-07-11 17:20 - 2018-06-15 17:01 - 002015744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2018-07-11 17:20 - 2018-06-15 17:01 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shdocvw.dll
2018-07-11 17:20 - 2018-06-15 09:11 - 000611232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2018-07-11 17:20 - 2018-06-15 09:10 - 000048544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storufs.sys
2018-07-11 17:20 - 2018-06-15 09:03 - 000083360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
2018-07-11 17:20 - 2018-06-15 07:19 - 000116632 _____ (Microsoft Corporation) C:\WINDOWS\system32\DTUHandler.exe
2018-07-11 17:20 - 2018-06-15 07:19 - 000093600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2018-07-11 17:20 - 2018-06-15 07:18 - 000228768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll
2018-07-11 17:20 - 2018-06-15 07:16 - 000562080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2018-07-11 17:20 - 2018-06-15 07:16 - 000433560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2018-07-11 17:20 - 2018-06-15 07:13 - 000324000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2018-07-11 17:20 - 2018-06-15 07:12 - 000260896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2018-07-11 17:20 - 2018-06-15 07:12 - 000118872 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll
2018-07-11 17:20 - 2018-06-15 07:10 - 000326024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExecModelClient.dll
2018-07-11 17:20 - 2018-06-15 07:09 - 000247984 _____ (Microsoft Corporation) C:\WINDOWS\system32\RESAMPLEDMO.DLL
2018-07-11 17:20 - 2018-06-15 07:08 - 001921944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys
2018-07-11 17:20 - 2018-06-15 07:08 - 001150408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVP9DEC.dll
2018-07-11 17:20 - 2018-06-15 07:08 - 000945568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refsv1.sys
2018-07-11 17:20 - 2018-06-15 07:08 - 000642088 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp_win.dll
2018-07-11 17:20 - 2018-06-15 07:08 - 000604576 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2018-07-11 17:20 - 2018-06-15 07:08 - 000500552 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2018-07-11 17:20 - 2018-06-15 07:08 - 000413816 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2018-07-11 17:20 - 2018-06-15 07:08 - 000072768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WindowsTrustedRT.sys
2018-07-11 17:20 - 2018-06-15 07:04 - 001397192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVP9DEC.dll
2018-07-11 17:20 - 2018-06-15 07:04 - 000281080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExecModelClient.dll
2018-07-11 17:20 - 2018-06-15 07:04 - 000105376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll
2018-07-11 17:20 - 2018-06-15 07:03 - 000472136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2018-07-11 17:20 - 2018-06-15 07:03 - 000356960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2018-07-11 17:20 - 2018-06-15 07:03 - 000232488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RESAMPLEDMO.DLL
2018-07-11 17:20 - 2018-06-15 07:03 - 000129192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2018-07-11 17:20 - 2018-06-15 06:48 - 000311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Diagnostics.dll
2018-07-11 17:20 - 2018-06-15 06:47 - 000622080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsreg.dll
2018-07-11 17:20 - 2018-06-15 06:47 - 000515072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\untfs.dll
2018-07-11 17:20 - 2018-06-15 06:47 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2018-07-11 17:20 - 2018-06-15 06:46 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Input.dll
2018-07-11 17:20 - 2018-06-15 06:46 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
2018-07-11 17:20 - 2018-06-15 06:45 - 000871424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autochk.exe
2018-07-11 17:20 - 2018-06-15 06:45 - 000740352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2018-07-11 17:20 - 2018-06-15 06:45 - 000380416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2018-07-11 17:20 - 2018-06-15 06:45 - 000193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll
2018-07-11 17:20 - 2018-06-15 06:45 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\system32\DTUHandlerPS.dll
2018-07-11 17:20 - 2018-06-15 06:44 - 000873472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2018-07-11 17:20 - 2018-06-15 06:44 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
2018-07-11 17:20 - 2018-06-15 06:44 - 000185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2018-07-11 17:20 - 2018-06-15 06:44 - 000135680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smartscreenps.dll
2018-07-11 17:20 - 2018-06-15 06:44 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatecsp.dll
2018-07-11 17:20 - 2018-06-15 06:44 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcimage.dll
2018-07-11 17:20 - 2018-06-15 06:44 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\cellulardatacapabilityhandler.dll
2018-07-11 17:20 - 2018-06-15 06:43 - 001114112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.PointOfService.dll
2018-07-11 17:20 - 2018-06-15 06:43 - 000675840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2018-07-11 17:20 - 2018-06-15 06:43 - 000426496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2018-07-11 17:20 - 2018-06-15 06:43 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\RdpRelayTransport.dll
2018-07-11 17:20 - 2018-06-15 06:43 - 000191488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VideoHandlers.dll
2018-07-11 17:20 - 2018-06-15 06:43 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2018-07-11 17:20 - 2018-06-15 06:43 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2018-07-11 17:20 - 2018-06-15 06:42 - 000978432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2018-07-11 17:20 - 2018-06-15 06:42 - 000558592 _____ (Microsoft Corporation) C:\WINDOWS\system32\untfs.dll
2018-07-11 17:20 - 2018-06-15 06:42 - 000431104 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2018-07-11 17:20 - 2018-06-15 06:42 - 000386048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Diagnostics.dll
2018-07-11 17:20 - 2018-06-15 06:42 - 000319488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2018-07-11 17:20 - 2018-06-15 06:42 - 000273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2018-07-11 17:20 - 2018-06-15 06:42 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2018-07-11 17:20 - 2018-06-15 06:42 - 000216064 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2018-07-11 17:20 - 2018-06-15 06:42 - 000141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2018-07-11 17:20 - 2018-06-15 06:41 - 000953856 _____ (Microsoft Corporation) C:\WINDOWS\system32\autochk.exe
2018-07-11 17:20 - 2018-06-15 06:41 - 000811520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Input.dll
2018-07-11 17:20 - 2018-06-15 06:41 - 000270336 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2018-07-11 17:20 - 2018-06-15 06:41 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManager.dll
2018-07-11 17:20 - 2018-06-15 06:41 - 000265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2018-07-11 17:20 - 2018-06-15 06:41 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupManager.dll
2018-07-11 17:20 - 2018-06-15 06:40 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
2018-07-11 17:20 - 2018-06-15 06:40 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreenps.dll
2018-07-11 17:20 - 2018-06-15 06:37 - 000883712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2018-07-11 17:20 - 2018-06-15 06:36 - 000159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cdrom.sys
2018-07-11 17:20 - 2018-06-08 21:07 - 000506184 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2018-07-11 17:20 - 2018-06-08 21:07 - 000040864 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVClientPS.dll
2018-07-11 17:20 - 2018-06-08 21:07 - 000019872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVTerminator.dll
2018-07-11 17:20 - 2018-06-08 21:02 - 000661160 _____ (Microsoft Corporation) C:\WINDOWS\system32\GenValObj.exe
2018-07-11 17:20 - 2018-06-08 20:47 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2018-07-11 17:20 - 2018-06-08 20:46 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2018-07-11 17:20 - 2018-06-08 20:45 - 001560576 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdt.exe
2018-07-11 17:20 - 2018-06-08 20:44 - 000285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcredprov.dll
2018-07-11 17:20 - 2018-06-08 20:42 - 000503296 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2018-07-11 17:20 - 2018-06-08 20:41 - 002019840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2018-07-11 17:20 - 2018-06-08 20:41 - 000577024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2018-07-11 17:20 - 2018-06-08 20:41 - 000182272 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
2018-07-11 17:20 - 2018-06-08 19:04 - 001454024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2018-07-11 17:20 - 2018-06-08 18:50 - 001508352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdt.exe
2018-07-11 17:20 - 2018-06-08 18:47 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcredprov.dll
2018-07-11 17:20 - 2018-06-08 12:31 - 000029600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\uefi.sys
2018-07-11 17:20 - 2018-06-08 11:31 - 000226720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Ucx01000.sys
2018-07-11 17:20 - 2018-06-08 11:30 - 000194456 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2018-07-11 17:20 - 2018-06-08 11:30 - 000137568 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll
2018-07-11 17:20 - 2018-06-08 11:29 - 002590400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVDECOD.DLL
2018-07-11 17:20 - 2018-06-08 11:29 - 000659096 _____ (Microsoft Corporation) C:\WINDOWS\system32\StateRepository.Core.dll
2018-07-11 17:20 - 2018-06-08 11:29 - 000375712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msrpc.sys
2018-07-11 17:20 - 2018-06-08 11:29 - 000313592 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll
2018-07-11 17:20 - 2018-06-08 11:29 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\vertdll.dll
2018-07-11 17:20 - 2018-06-08 11:29 - 000084288 _____ (Microsoft Corporation) C:\WINDOWS\system32\LanguageOverlayUtil.dll
2018-07-11 17:20 - 2018-06-08 11:29 - 000057960 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel.appcore.dll
2018-07-11 17:20 - 2018-06-08 11:10 - 002307336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVDECOD.DLL
2018-07-11 17:20 - 2018-06-08 11:10 - 000097176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll
2018-07-11 17:20 - 2018-06-08 11:09 - 000568720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryPS.dll
2018-07-11 17:20 - 2018-06-08 11:09 - 000064648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LanguageOverlayUtil.dll
2018-07-11 17:20 - 2018-06-08 11:09 - 000050208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel.appcore.dll
2018-07-11 17:20 - 2018-06-08 11:03 - 000906752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.PhoneNumberFormatting.dll
2018-07-11 17:20 - 2018-06-08 11:03 - 000038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryCore.dll
2018-07-11 17:20 - 2018-06-08 11:03 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mskssrv.sys
2018-07-11 17:20 - 2018-06-08 11:02 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll
2018-07-11 17:20 - 2018-06-08 11:02 - 000059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\edpnotify.exe
2018-07-11 17:20 - 2018-06-08 11:02 - 000035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
2018-07-11 17:20 - 2018-06-08 11:01 - 000342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserexport.exe
2018-07-11 17:20 - 2018-06-08 11:01 - 000294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll
2018-07-11 17:20 - 2018-06-08 11:01 - 000182272 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerCsp.dll
2018-07-11 17:20 - 2018-06-08 11:01 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2018-07-11 17:20 - 2018-06-08 11:01 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\hidparse.sys
2018-07-11 17:20 - 2018-06-08 11:01 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys
2018-07-11 17:20 - 2018-06-08 11:00 - 000275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe
2018-07-11 17:20 - 2018-06-08 11:00 - 000149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2018-07-11 17:20 - 2018-06-08 11:00 - 000100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManagerClient.dll
2018-07-11 17:20 - 2018-06-08 10:59 - 000983040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2018-07-11 17:20 - 2018-06-08 10:59 - 000456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
2018-07-11 17:20 - 2018-06-08 10:59 - 000177152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll
2018-07-11 17:20 - 2018-06-08 10:59 - 000174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2018-07-11 17:20 - 2018-06-08 10:58 - 000029184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
2018-07-11 17:20 - 2018-06-08 10:57 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys
2018-07-11 17:20 - 2018-06-08 10:57 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2018-07-11 17:20 - 2018-06-08 10:57 - 000150016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll
2018-07-11 17:20 - 2018-06-08 10:57 - 000038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2018-07-11 17:20 - 2018-06-08 10:56 - 000908800 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSMPEG2ENC.DLL
2018-07-11 17:20 - 2018-06-08 10:56 - 000869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
2018-07-11 17:20 - 2018-06-08 10:56 - 000715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2018-07-11 17:20 - 2018-06-08 10:55 - 000849408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll
2018-07-11 17:20 - 2018-06-08 10:55 - 000778752 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2018-07-11 17:20 - 2018-06-08 10:54 - 001348096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpcServices.dll
2018-07-11 17:20 - 2018-06-08 10:54 - 000857088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSMPEG2ENC.DLL
2018-07-11 17:20 - 2018-06-08 10:54 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAC3ENC.DLL
2018-07-11 17:20 - 2018-06-08 10:53 - 000648192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll
2018-07-11 17:20 - 2018-06-01 07:18 - 000058524 _____ C:\WINDOWS\system32\srms.dat
2018-07-11 17:20 - 2018-05-25 05:24 - 000340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2018-07-11 17:20 - 2018-05-20 21:42 - 000759192 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingWinRT.dll
2018-07-11 17:20 - 2018-05-20 21:26 - 000486912 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasplap.dll
2018-07-11 17:20 - 2018-05-20 21:23 - 004070400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2018-07-11 17:20 - 2018-05-20 21:22 - 001292288 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2018-07-11 17:20 - 2018-05-20 21:22 - 000941056 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdlg.dll
2018-07-11 17:20 - 2018-05-20 20:20 - 000022936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hvsicontainerservice.dll
2018-07-11 17:20 - 2018-05-20 20:15 - 000653208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicensingWinRT.dll
2018-07-11 17:20 - 2018-05-20 20:02 - 000461312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasplap.dll
2018-07-11 17:20 - 2018-05-20 18:35 - 000677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\HeadTrackerStorage.dll
2018-07-11 17:20 - 2018-05-20 18:34 - 000238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloShellRuntime.dll
2018-07-11 17:20 - 2018-05-20 16:54 - 000184320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\HoloShellRuntime.dll
2018-07-11 17:20 - 2018-05-20 14:33 - 000105368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2018-07-11 17:20 - 2018-05-20 13:53 - 000792984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2018-07-11 17:20 - 2018-05-20 13:53 - 000131232 _____ (Microsoft Corporation) C:\WINDOWS\system32\rmclient.dll
2018-07-11 17:20 - 2018-05-20 13:53 - 000088472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\crashdmp.sys
2018-07-11 17:20 - 2018-05-20 13:52 - 000413080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2018-07-11 17:20 - 2018-05-20 13:52 - 000130456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvsocket.sys
2018-07-11 17:20 - 2018-05-20 13:52 - 000089984 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompPkgSup.dll
2018-07-11 17:20 - 2018-05-20 13:33 - 000101288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rmclient.dll
2018-07-11 17:20 - 2018-05-20 13:32 - 000077040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CompPkgSup.dll
2018-07-11 17:20 - 2018-05-20 13:28 - 000111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppHostRegistrationVerifier.exe
2018-07-11 17:20 - 2018-05-20 13:27 - 000109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApiSetHost.AppExecutionAlias.dll
2018-07-11 17:20 - 2018-05-20 13:26 - 000356352 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWfdProvider.dll
2018-07-11 17:20 - 2018-05-20 13:26 - 000236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtutil.exe
2018-07-11 17:20 - 2018-05-20 13:26 - 000098816 _____ (Microsoft Corporation) C:\WINDOWS\system32\TelephonyInteractiveUser.dll
2018-07-11 17:20 - 2018-05-20 13:26 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSHEIF.dll
2018-07-11 17:20 - 2018-05-20 13:25 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2018-07-11 17:20 - 2018-05-20 13:25 - 000384000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Phoneutil.dll
2018-07-11 17:20 - 2018-05-20 13:24 - 000726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2018-07-11 17:20 - 2018-05-20 13:23 - 005951488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2018-07-11 17:20 - 2018-05-20 13:21 - 001371136 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2018-07-11 17:20 - 2018-05-20 13:16 - 000081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ApiSetHost.AppExecutionAlias.dll
2018-07-11 17:20 - 2018-05-20 13:15 - 000142848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2018-07-11 17:20 - 2018-05-20 13:15 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSHEIF.dll
2018-07-11 17:20 - 2018-05-20 13:14 - 000167936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtutil.exe
2018-07-11 17:20 - 2018-05-20 13:13 - 004929024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2018-07-11 17:20 - 2018-05-20 13:13 - 000317440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Phoneutil.dll
2018-07-11 17:20 - 2018-05-20 13:11 - 001036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2018-07-11 17:20 - 2018-05-20 10:26 - 000018716 _____ C:\WINDOWS\system32\srms-apr.dat
2018-07-11 17:20 - 2018-05-18 19:08 - 000018716 _____ C:\WINDOWS\SysWOW64\srms-apr.dat
2018-07-11 17:20 - 2018-04-28 16:25 - 000652184 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPublishing.dll
2018-07-11 17:20 - 2018-04-28 16:24 - 000749976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVReporting.dll
2018-07-11 17:20 - 2018-04-28 16:23 - 000826776 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVClient.exe
2018-07-11 17:20 - 2018-04-28 16:23 - 000399768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVScripting.dll
2018-07-11 17:20 - 2018-04-28 16:03 - 013570560 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2018-07-11 17:20 - 2018-04-28 16:03 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\itss.dll
2018-07-11 17:20 - 2018-04-28 16:03 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedPCCSP.dll
2018-07-11 17:20 - 2018-04-28 16:01 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MixedReality.Broker.dll
2018-07-11 17:20 - 2018-04-28 15:18 - 000150016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\itss.dll
2018-07-11 17:20 - 2018-04-28 15:14 - 000581120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hhctrl.ocx
2018-07-11 17:20 - 2018-04-28 15:13 - 001585664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2018-07-11 17:20 - 2018-04-28 12:58 - 000159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Analog.dll
2018-07-11 17:20 - 2018-04-28 06:29 - 001565592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2018-07-11 17:20 - 2018-04-28 06:29 - 000382872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2018-07-11 17:20 - 2018-04-28 06:13 - 001426328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2018-07-11 17:20 - 2018-04-28 06:13 - 000665320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2018-07-11 17:20 - 2018-04-28 06:03 - 000585728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.rs3.dll
2018-07-11 17:20 - 2018-04-28 06:03 - 000444416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.rs1.dll
2018-07-11 17:20 - 2018-04-28 06:03 - 000288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.th.dll
2018-07-11 17:20 - 2018-04-28 06:03 - 000241664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.win81.dll
2018-07-11 17:20 - 2018-04-28 06:02 - 000613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.rs4.dll
2018-07-11 17:20 - 2018-04-28 06:02 - 000474624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.rs2.dll
2018-07-11 17:20 - 2018-04-28 06:02 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2018-07-11 17:20 - 2018-04-28 06:02 - 000142336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.win8rtm.dll
2018-07-11 17:20 - 2018-04-28 06:01 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\credssp.dll
2018-07-11 17:20 - 2018-04-28 06:00 - 000143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSpkg.dll
2018-07-11 17:20 - 2018-04-28 05:57 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credssp.dll
2018-07-11 17:20 - 2018-04-28 05:55 - 001421312 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpbase.dll
2018-07-11 17:20 - 2018-04-28 05:54 - 000561664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2018-07-11 17:20 - 2018-04-28 05:53 - 001235968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpbase.dll
2018-07-11 17:20 - 2018-04-28 05:53 - 000117760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSpkg.dll
2018-07-11 16:33 - 2018-07-11 16:33 - 001520792 _____ C:\Users\Peppo\Downloads\BlueMeConfigurator.zip

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-08-09 22:13 - 2018-06-16 00:00 - 000000000 ___RD C:\Users\Peppo\OneDrive
2018-08-09 22:07 - 2018-07-05 04:20 - 000000000 ____D C:\Users\Peppo\MicrosoftEdgeBackups
2018-08-09 22:05 - 2018-06-16 02:48 - 000000000 ____D C:\Users\Peppo\IntelGraphicsProfiles
2018-08-09 21:20 - 2018-07-05 03:46 - 000001210 _____ C:\Users\Peppo\Desktop\Command Prompt.lnk
2018-08-03 17:49 - 2016-02-13 15:23 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-08-03 12:56 - 2018-06-16 16:38 - 000001836 _____ C:\Users\Peppo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2018-08-03 12:30 - 2015-12-25 11:59 - 006156744 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys
2018-08-03 12:30 - 2015-12-25 11:59 - 000023656 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll
2018-08-02 23:22 - 2018-04-12 18:24 - 009137664 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmploc.DLL
2018-08-02 23:22 - 2018-04-12 18:24 - 000011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwmp.dll
2018-08-02 23:22 - 2018-04-12 18:24 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdxm.ocx
2018-08-02 23:22 - 2018-04-12 18:24 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxmasf.dll
2018-08-02 23:08 - 2018-04-12 01:34 - 000960512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
2018-08-02 23:08 - 2018-04-12 01:34 - 000087448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryBroker.dll
2018-08-02 23:08 - 2018-04-12 01:34 - 000021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanelExternalHook.dll
2018-08-02 23:07 - 2018-04-12 01:34 - 000128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwbase.dll
2018-08-02 23:07 - 2018-04-12 01:34 - 000099808 _____ (Microsoft Corporation) C:\WINDOWS\system32\FsIso.exe
2018-08-02 23:07 - 2018-04-12 01:34 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfapigp.dll
2018-08-02 23:06 - 2018-04-12 01:34 - 000154624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReInfo.dll
2018-08-02 23:06 - 2018-04-12 01:34 - 000116640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll
2018-08-02 23:06 - 2018-04-12 01:34 - 000039424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XInputUap.dll
2018-08-02 23:06 - 2018-04-11 23:04 - 000118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2018-08-02 23:05 - 2018-04-12 01:35 - 000067072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UXInit.dll
2018-08-02 23:05 - 2018-04-12 01:34 - 000115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2018-08-02 23:05 - 2018-04-12 01:34 - 000105984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2018-08-02 23:05 - 2018-04-12 01:33 - 000049688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
2018-08-02 22:47 - 2018-07-05 03:57 - 000001417 _____ C:\Users\Peppo\Desktop\Microsoft Edge.lnk
2018-08-02 22:45 - 2018-07-05 03:54 - 000000000 ___RD C:\Users\Peppo\3D Objects
2018-08-02 11:55 - 2018-06-16 13:54 - 000000000 ____D C:\Users\Peppo\Downloads\eMule
2018-08-02 00:14 - 2018-04-12 01:35 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSErrRedir.dll
2018-08-02 00:14 - 2018-04-12 01:34 - 000466840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2018-08-02 00:14 - 2018-04-12 01:34 - 000088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\UXInit.dll
2018-08-02 00:14 - 2018-04-12 01:33 - 000123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2018-08-02 00:13 - 2018-04-12 01:34 - 000409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosResource.dll
2018-08-02 00:13 - 2018-04-12 01:34 - 000130976 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2018-08-02 00:13 - 2018-04-12 01:34 - 000113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
2018-08-02 00:13 - 2018-04-12 01:34 - 000009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
2018-08-02 00:13 - 2018-04-12 01:34 - 000009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
2018-08-02 00:13 - 2018-04-12 01:34 - 000008192 _____ C:\WINDOWS\system32\settings.dat
2018-08-02 00:13 - 2018-04-12 01:33 - 000073632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2018-08-02 00:13 - 2018-04-12 01:33 - 000020896 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll

==================== Files in the root of some directories =======

2018-08-06 12:12 - 2018-08-08 17:40 - 000007612 _____ () C:\Users\Peppo\AppData\Local\Resmon.ResmonCfg

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-08-02 22:34

==================== End of FRST.txt ============================



Addition.txt

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02.08.2018
Ran by Peppo (09-08-2018 22:26:17)
Running from C:\Users\Peppo\Downloads
Windows 10 Pro Version 1803 17134.191 (X64) (2018-08-02 20:44:18)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1728740447-1116186292-1611782332-500 - Administrator - Enabled) => C:\Users\Administrator
DefaultAccount (S-1-5-21-1728740447-1116186292-1611782332-503 - Limited - Disabled)
Guest (S-1-5-21-1728740447-1116186292-1611782332-501 - Limited - Disabled)
Peppo (S-1-5-21-1728740447-1116186292-1611782332-1001 - Administrator - Enabled) => C:\Users\Peppo
WDAGUtilityAccount (S-1-5-21-1728740447-1116186292-1611782332-504 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-1728740447-1116186292-1611782332-1001\...\uTorrent) (Version: 3.5.4.44498 - BitTorrent Inc.)
7-Zip 18.05 (x64) (HKLM\...\7-Zip) (Version: 18.05 - Igor Pavlov)
Audacity 2.2.2 (HKLM-x32\...\Audacity_is1) (Version: 2.2.2 - Audacity Team)
CCleaner (HKLM\...\CCleaner) (Version: 5.44 - Piriform)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 68.0.3440.84 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
Java 8 Update 181 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180181F0}) (Version: 8.0.1810.13 - Oracle Corporation)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
Malwarebytes versione 3.5.1.2522 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.5.1.2522 - Malwarebytes)
Microsoft OneDrive (HKU\S-1-5-21-1728740447-1116186292-1611782332-1001\...\OneDriveSetup.exe) (Version: 18.131.0701.0007 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8419 - Realtek Semiconductor Corp.)
Sophos Virus Removal Tool (HKLM-x32\...\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.7.0 - Sophos Limited)
Spotify (HKU\S-1-5-21-1728740447-1116186292-1611782332-1001\...\Spotify) (Version: 1.0.86.337.ga8d5cef9 - Spotify AB)
Zemana AntiMalware (HKLM-x32\...\{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1) (Version: 2.74.0.150 - Zemana Ltd.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ContextMenuHandlers1: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll [2018-08-08] ()
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2016-06-08] (Intel Corporation)
ContextMenuHandlers6: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll [2018-08-08] ()
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {07A07F78-46D6-4929-8B35-CA98B9C3DBA1} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-12] ()
Task: {186EAE76-FF17-458D-AE39-0DA08BE12EBE} - System32\Tasks\S-1-5-21-1728740447-1116186292-1611782332-1001\DataSenseLiveTileTask => C:\WINDOWS\System32\DataUsageLiveTileTask.exe [2018-04-12] (Microsoft Corporation)
Task: {2FE0BB2B-5D9D-4952-AE75-AF8E10180EF0} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-06-24] (Piriform Ltd)
Task: {5006477B-9FD8-4879-AD2B-244125F7D608} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MpCmdRun.exe [2018-08-03] (Microsoft Corporation)
Task: {54929690-59CB-4A86-B4E1-0985F07E5402} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MpCmdRun.exe [2018-08-03] (Microsoft Corporation)
Task: {67321055-6BDE-473F-B7F4-EA2243F4535E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MpCmdRun.exe [2018-08-03] (Microsoft Corporation)
Task: {6778FA35-1C6D-4EF2-9855-57083144A8E6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-08-03] (Google Inc.)
Task: {C28BC764-3D14-4277-A505-8447A959883E} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2018-08-03] (Realtek Semiconductor)
Task: {CED17608-6352-4349-9CE1-210C4AD749B1} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-06-24] (Piriform Ltd)
Task: {FC3992E5-AE09-4B65-95B9-356890CA2984} - System32\Tasks\RtHDVBg_ListenToDevice => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2018-08-03] (Realtek Semiconductor)
Task: {FCD4C4A7-3806-4D88-92BF-1CC7F659B405} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MpCmdRun.exe [2018-08-03] (Microsoft Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2016-06-08 07:37 - 2016-06-08 07:37 - 000414192 _____ () C:\WINDOWS\system32\igfxTray.exe
2018-04-12 01:34 - 2018-04-12 01:34 - 000491744 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2018-04-12 01:34 - 2018-04-12 01:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll
2018-04-12 01:34 - 2018-04-12 01:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2018-08-08 15:32 - 2018-08-08 15:32 - 000155504 _____ () C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll
2018-08-06 20:44 - 2018-08-06 21:21 - 002433744 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2018-08-06 20:44 - 2018-08-06 21:20 - 002535120 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2018-07-11 17:23 - 2018-07-06 08:55 - 002185728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-08-03 12:21 - 2018-08-03 12:22 - 035195392 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18061.13911.0_x64__8wekyb3d8bbwe\Video.UI.exe
2018-08-03 12:21 - 2018-08-03 12:21 - 000290816 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18061.13911.0_x64__8wekyb3d8bbwe\SharedUI.dll
2018-08-03 12:21 - 2018-08-03 12:21 - 006373376 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18061.13911.0_x64__8wekyb3d8bbwe\EntCommon.dll
2018-04-12 18:31 - 2018-04-12 18:31 - 003553704 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18061.13911.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2018-08-03 12:21 - 2018-08-03 12:21 - 008903168 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18061.13911.0_x64__8wekyb3d8bbwe\EntPlat.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-1728740447-1116186292-1611782332-1001\...\localhost -> localhost

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2018-08-02 23:13 - 2018-08-09 18:22 - 000000852 _____ C:\WINDOWS\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1728740447-1116186292-1611782332-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Peppo\Pictures\Cat Sleep.jpg
DNS Servers: 208.67.222.222 - 208.67.220.220
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
HKU\S-1-5-21-1728740447-1116186292-1611782332-1001\...\StartupApproved\Run: => "Spotify"
HKU\S-1-5-21-1728740447-1116186292-1611782332-1001\...\StartupApproved\Run: => "utweb"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [TCP Query User{C9472963-F309-4CA8-8885-F0A94FE12353}C:\users\peppo\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\peppo\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [UDP Query User{625FDC92-D46A-45DA-B65B-B3A61CA63CBD}C:\users\peppo\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\peppo\appdata\roaming\utorrent\utorrent.exe

==================== Restore Points =========================


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (08/09/2018 10:25:32 PM) (Source: Microsoft-Windows-SpellChecker) (EventID: 33) (User: DESKTOP-ALDNS74)
Description: httphttp-2147467263

Error: (08/09/2018 10:01:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome dell'applicazione che ha generato l'errore: AUDIODG.EXE, versione: 10.0.17134.137, timestamp: 0xecd85e98
Nome del modulo che ha generato l'errore: unknown, versione: 0.0.0.0, timestamp: 0x00000000
Codice eccezione: 0xc0000005
Offset errore 0x0000000000000000
ID processo che ha generato l'errore: 0xac0
Ora di avvio dell'applicazione che ha generato l'errore: 0x01d4301bb583684a
Percorso dell'applicazione che ha generato l'errore: C:\WINDOWS\system32\AUDIODG.EXE
Percorso del modulo che ha generato l'errore: unknown
ID segnalazione: cf81c803-1a0b-4824-92da-faa61dd95e73
Nome completo pacchetto che ha generato l'errore: 
ID applicazione relativo al pacchetto che ha generato l'errore:

Error: (08/09/2018 07:37:16 PM) (Source: Microsoft-Windows-SpellChecker) (EventID: 33) (User: DESKTOP-ALDNS74)
Description: httphttp-2147467263

Error: (08/09/2018 07:36:59 PM) (Source: Microsoft-Windows-SpellChecker) (EventID: 33) (User: DESKTOP-ALDNS74)
Description: httphttp-2147467263

Error: (08/08/2018 06:37:39 PM) (Source: ESENT) (EventID: 489) (User: )
Description: CCleaner64 (4032,G,0) Un tentativo di apertura del file "C:\Users\Peppo\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat" per l'accesso in sola lettura non è riuscito con l'errore di sistema 32 (0x00000020): "Impossibile accedere al file. Il file è utilizzato da un altro processo. ".  L'operazione di apertura del file non verrà eseguita con l'errore -1032 (0xfffffbf8).

Error: (08/08/2018 03:24:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nome dell'applicazione che ha generato l'errore: chrome.exe, versione: 68.0.3440.84, timestamp: 0x5b5f9bd1
Nome del modulo che ha generato l'errore: unknown, versione: 0.0.0.0, timestamp: 0x00000000
Codice eccezione: 0xc0000005
Offset errore 0x00007ff99fff045f
ID processo che ha generato l'errore: 0x2368
Ora di avvio dell'applicazione che ha generato l'errore: 0x01d42f1b201273a1
Percorso dell'applicazione che ha generato l'errore: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Percorso del modulo che ha generato l'errore: unknown
ID segnalazione: 419aee7d-4e49-4973-aea2-3c1f230c333a
Nome completo pacchetto che ha generato l'errore: 
ID applicazione relativo al pacchetto che ha generato l'errore:

Error: (08/08/2018 12:53:26 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Il programma svchost.exe versione 10.0.17134.1 non interagisce più con Windows ed è stato chiuso. Per vedere se sono disponibili ulteriori informazioni sul problema, verificare la cronologia del problema in Sicurezza e manutenzione nel Pannello di controllo.

ID processo: 6e8

Ora di avvio: 01d42efd96bdb902

Ora di chiusura: 4294967295

Percorso applicazione: C:\Windows\System32\svchost.exe

ID segnalazione: 8674dd71-31c3-409a-bd68-4319f20e1987

Nome completo pacchetto che ha generato l'errore: 

ID applicazione relativo al pacchetto che ha generato l'errore:

Error: (08/08/2018 12:07:14 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Il programma MicrosoftEdgeCP.exe versione 11.0.17134.191 non interagisce più con Windows ed è stato chiuso. Per vedere se sono disponibili ulteriori informazioni sul problema, verificare la cronologia del problema in Sicurezza e manutenzione nel Pannello di controllo.

ID processo: 2004

Ora di avvio: 01d42eff3538f122

Ora di chiusura: 4294967295

Percorso applicazione: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe

ID segnalazione: 0c1f01c9-567b-49a0-9bfe-69882480cc75

Nome completo pacchetto che ha generato l'errore: Microsoft.MicrosoftEdge_42.17134.1.0_neutral__8wekyb3d8bbwe

ID applicazione relativo al pacchetto che ha generato l'errore: ContentProcess


System errors:
=============
Error: (08/09/2018 10:27:08 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-ALDNS74)
Description: DCOM: errore "%%1068 = Avvio del gruppo o del servizio di dipendenza non riuscito." durante il tentativo di avvio del servizio netprofm con gli argomenti "Non disponibile" per eseguire il server 
{A47979D2-C419-11D9-A5B4-001185AD2B89}

Error: (08/09/2018 10:27:08 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Il servizio Servizio Elenco reti dipende dal servizio Riconoscimento presenza in rete che non è stato avviato per il seguente errore: 
Avvio del gruppo o del servizio di dipendenza non riuscito.

Error: (08/09/2018 10:27:08 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Il servizio Riconoscimento presenza in rete dipende dal servizio Client DHCP che non è stato avviato per il seguente errore: 
L'account specificato per questo servizio è diverso da quello specificato per altri servizi eseguiti nello stesso processo.

Error: (08/09/2018 10:27:08 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Il servizio Client DHCP non è stato avviato per il seguente errore: 
L'account specificato per questo servizio è diverso da quello specificato per altri servizi eseguiti nello stesso processo.

Error: (08/09/2018 10:26:51 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-ALDNS74)
Description: DCOM: errore "%%1068 = Avvio del gruppo o del servizio di dipendenza non riuscito." durante il tentativo di avvio del servizio netprofm con gli argomenti "Non disponibile" per eseguire il server 
{A47979D2-C419-11D9-A5B4-001185AD2B89}

Error: (08/09/2018 10:26:51 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Il servizio Servizio Elenco reti dipende dal servizio Riconoscimento presenza in rete che non è stato avviato per il seguente errore: 
Avvio del gruppo o del servizio di dipendenza non riuscito.

Error: (08/09/2018 10:26:51 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Il servizio Riconoscimento presenza in rete dipende dal servizio Client DHCP che non è stato avviato per il seguente errore: 
L'account specificato per questo servizio è diverso da quello specificato per altri servizi eseguiti nello stesso processo.

Error: (08/09/2018 10:26:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Il servizio Client DHCP non è stato avviato per il seguente errore: 
L'account specificato per questo servizio è diverso da quello specificato per altri servizi eseguiti nello stesso processo.


Windows Defender:
===================================
Date: 2018-08-08 17:48:16.288
Description: 
Windows Defender Antivirus: analisi interrotta prima del completamento.
ID analisi: {21C9B03C-0B37-4A2F-8E9B-C7B09BC37E4A}
Tipo analisi: Antimalware
Parametri analisi: Analisi veloce
Utente: NT AUTHORITY\SYSTEM

Date: 2018-08-08 12:49:34.647
Description: 
Windows Defender Antivirus: analisi interrotta prima del completamento.
ID analisi: {77189E8E-5F4B-45C5-B75C-7C973E29706B}
Tipo analisi: Antimalware
Parametri analisi: Analisi veloce
Utente: NT AUTHORITY\SYSTEM

Date: 2018-08-06 17:07:06.771
Description: 
Windows Defender Antivirus: analisi interrotta prima del completamento.
ID analisi: {F4D36666-7120-421D-BBAF-DC4DAF1471AC}
Tipo analisi: Antimalware
Parametri analisi: Analisi veloce
Utente: NT AUTHORITY\SYSTEM

Date: 2018-08-09 22:16:05.796
Description: 
Windows Defender Antivirus: errore durante il tentativo di aggiornare le firme.
Nuova versione firma: 
Versione firma precedente: 1.273.1034.0
Origine aggiornamento: Server Microsoft Update
Tipo firma: Antivirus
Tipo aggiornamento: Completo
Utente: NT AUTHORITY\SYSTEM
Versione motore corrente: 
Versione motore precedente: 1.1.15100.1
Codice errore: 0x80240022
Descrizione errore: Impossibile cercare gli aggiornamenti delle definizioni. 

Date: 2018-08-09 22:16:05.795
Description: 
Windows Defender Antivirus: errore durante il tentativo di aggiornare le firme.
Nuova versione firma: 
Versione firma precedente: 1.273.1034.0
Origine aggiornamento: Server Microsoft Update
Tipo firma: Antivirus
Tipo aggiornamento: Completo
Utente: NT AUTHORITY\SYSTEM
Versione motore corrente: 
Versione motore precedente: 1.1.15100.1
Codice errore: 0x80240022
Descrizione errore: Impossibile cercare gli aggiornamenti delle definizioni. 

Date: 2018-08-09 21:29:19.977
Description: 
Windows Defender Antivirus: errore durante il tentativo di aggiornare le firme.
Nuova versione firma: 
Versione firma precedente: 1.273.1034.0
Origine aggiornamento: Server Microsoft Update
Tipo firma: Antivirus
Tipo aggiornamento: Completo
Utente: NT AUTHORITY\SYSTEM
Versione motore corrente: 
Versione motore precedente: 1.1.15100.1
Codice errore: 0x80240438
Descrizione errore: Problema imprevisto durante la ricerca degli aggiornamenti. Per informazioni sull'installazione degli aggiornamenti o la risoluzione dei problemi relativi, consultare Guida e supporto tecnico. 

Date: 2018-08-09 19:22:41.462
Description: 
Windows Defender Antivirus: errore durante il tentativo di aggiornare le firme.
Nuova versione firma: 
Versione firma precedente: 1.273.1034.0
Origine aggiornamento: Server Microsoft Update
Tipo firma: Antivirus
Tipo aggiornamento: Completo
Utente: NT AUTHORITY\SYSTEM
Versione motore corrente: 
Versione motore precedente: 1.1.15100.1
Codice errore: 0x80240022
Descrizione errore: Impossibile cercare gli aggiornamenti delle definizioni. 

Date: 2018-08-09 19:22:41.424
Description: 
Windows Defender Antivirus: errore durante il tentativo di aggiornare le firme.
Nuova versione firma: 
Versione firma precedente: 1.273.1034.0
Origine aggiornamento: Server Microsoft Update
Tipo firma: Antivirus
Tipo aggiornamento: Completo
Utente: NT AUTHORITY\SYSTEM
Versione motore corrente: 
Versione motore precedente: 1.1.15100.1
Codice errore: 0x80240022
Descrizione errore: Impossibile cercare gli aggiornamenti delle definizioni. 

CodeIntegrity:
===================================

Date: 2018-08-09 22:06:45.949
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

Date: 2018-08-09 22:06:44.678
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

Date: 2018-08-09 22:06:41.650
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

Date: 2018-08-09 22:06:37.589
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

Date: 2018-08-09 22:06:37.589
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

Date: 2018-08-09 22:06:37.325
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

Date: 2018-08-09 22:06:37.091
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

Date: 2018-08-09 22:06:37.067
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

==================== Memory info =========================== 

Processor: Intel(R) Celeron(R) CPU N3050 @ 1.60GHz
Percentage of memory in use: 63%
Total physical RAM: 1951.95 MB
Available physical RAM: 720.49 MB
Total Virtual: 3251.95 MB
Available Virtual: 974.07 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:28.57 GB) (Free:6.54 GB) NTFS

\\?\Volume{ed6c3e1c-3a62-4e5c-a4cd-fe24bdf1e318}\ (Ripristino) (Fixed) (Total:0.44 GB) (Free:0.05 GB) NTFS
\\?\Volume{12f74161-4e60-4564-b8ce-12fadd87a2fa}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 29.1 GB) (Disk ID: 978705C1)

Partition: GPT.

==================== End of Addition.txt ============================

 

 

 

 

 

Share this post


Link to post
Share on other sites

Hi Kevinf80

No no.. i don't do nothing. The report is for understand what happen

I ask to know if i need to do or not..

i don't know what happen but windows update tell me error 0x8007042c. All that problem after the cleaner of adwcleaner about dnsjumper.. 

Share this post


Link to post
Share on other sites

Yeah thanks a lot Kevinf80.  After i do a refresh again.

I can't use pc for more than two week.. After a week something goes wrong on update or security don't work and again refresh install. But the problem don't disappear with clean pc (maybe i have a hacked version of windows .. i dn't know).... so annoying..

 

Share this post


Link to post
Share on other sites
Posted (edited)

 

Hi Kevinf80 , yes it would be better do a clean install but, the problem return again, so i decided to do a fresh installation via Security Defender Panel..at least i saved the latest version of windows alredy updated. Unlike a long time ago , now (with 1803) some pups or viruses are detected. In previous version (1709) it is true that i had no problem for speed but i never found anithing for a long time , no virus nothing (and i'm for sure not clean)  . So the index of slowness of now is due to some mechanism that still conflicts. After a fresh reinstall now go a little better, .. but one really problem was the audiodg.exe . I found a lot of error in the log , and the problem was to the module ICEsoundAPO64.dll (Screen 2)

The person that hack me use surely a program or something via audio. I found in the setting of Audio an app (Unknow that is "Sconosciuto" in Italian Screen 1 under) that is active and do a lot of stuttering of audio.I see on web and i rename the file ICEsoundAPO64.dll (that is a legitimate program of asus notebook , BUT THAT I DON'T FIND, I HAVE ONLY THAT FILEin the system32 to ICEsoundAPO64.old and unistall every audio driver.

Now is disappear the strange mixer audio card that i have saw, and the audio no stutter and the pc is a little better and the cpu is not ever 100%

Yes the problem was a conflit on Notebook, but i see an audio problem in all device in my house...sometimes sky decoder have the same iusse, or ps4 , etc.... i suppose that someone put a fake controller Pci on my device that "recall" something that they want..a backdoor , a server , i don't know..

 

 

Screenshot (188).png

Screenshot (191).png

Edited by PincoIta
Writing Mistakes

Share this post


Link to post
Share on other sites

Yes , but for all time i don't find nothing.

Today i have try to do a scan with adwcleaner or malwarebytes, and they don't find nothing, for curiosity i dowload eset online and again PUP.D  "Webcompanion"

What is this "Webcompanion" and the pup is on the chrome installer and ccleaner installer, that i download on official site.

Someone that arp me (or ManintheMiddle) put his things on my dowload before that came to me.. is impossible that all things that i download on official sites are virus.

And another strange thing. If i install a program like Malwarebytes, on first and second scan ,find something, after 2 days nothing.

That happen to Adwcleaner or other antivirus. Is like someone change some files and that program don't run correctly anymore. I need to reinstall or download another program .

 

 

Screenshot (218).png

Screenshot (225).png

Screenshot (226).png

eset.txt

Share this post


Link to post
Share on other sites

Your ESET log shows webcompanion bundled with uTorrent, no surprises there. The other two entries are for Google Toolbar, not really malicious....

P2P (peer to peer) software and associated applications are never far from the possibility of infection....

Share this post


Link to post
Share on other sites
On 8/13/2018 at 9:42 PM, kevinf80 said:

Your ESET log shows webcompanion bundled with uTorrent, no surprises there. The other two entries are for Google Toolbar, not really malicious....

P2P (peer to peer) software and associated applications are never far from the possibility of infection....

Hi Kevinf80 , yes i see  and you right.

Now seems to run better, maybe because i enter here and show all,i don't know,  but now finally i can use 

Hope Microsoft do quick the version lite of win10 at the end of these year, maybe that can run much better .

Thank you.

Share this post


Link to post
Share on other sites

Are we ok to close out your thread...? do you need any further assistance...

Share this post


Link to post
Share on other sites
Guest
This topic is now closed to further replies.

  • Recently Browsing   0 members

    No registered users viewing this page.

×

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.