Jump to content

Recommended Posts

My computer is being dogged by a trojan - which Malwarebytes is blocking.  Problem is, Malwarebytes is not removing the trojan but instead every few seconds when the trojan wants to spread, the malwarebytes protection shield also pops up.  This means every few second this battle ensues.  The trojan is using the windows power shell.  I found I could pause the battle when going into task bar and ending the power shell task.  When reporting a support ticket or otherwise to solve this issue, Malwarebytes wants me to download the security tool and run it to get a log.  I have done this repeatedly and the log fails everytime.  I cannot get a log and therefore cannot get help.  When I send emails I don't think a human looks at it and it just tells me to download the tool that won't download.  I'm at my wits end.  Is it safe to uninstall the windows power shell or am I just delaying the problem.  Why doesn't Malwarebytes GET RID OF IT?  Thanks for listening.  The trojan is an outbound (why?) trojan that changes ips.

malwarebytes support2 unable.JPG

Link to post
Share on other sites
Hello EEPers and welcome to malwarebytes....

Continue with the following:

Download Farbar Recovery Scan Tool and save it to your desktop.

Alternative download option: http://www.techspot.com/downloads/6731-farbar-recovery-scan-tool.html

Note: You need to run the version compatible with your system (32 bit or 64 bit). If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

If your security alerts to FRST either, accept the alert or turn your security off to allow FRST to run. It is not malicious or infected in any way...

Be aware FRST must be run from an account with Administrator status...
 
  • Double-click to run it. When the tool opens click Yes to disclaimer.(Windows 8/10 users will be prompted about Windows SmartScreen protection - click More information and Run.)
  • Make sure Addition.txt is checkmarked under "Optional scans"
    user posted image
     
  • Press Scan button to run the tool....
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The tool will also make a log named (Addition.txt) Please attach that log to your reply.


Let me see those logs in your reply...

Thank you,

Kevin....
Link to post
Share on other sites

Log from FIRST.TXT

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-06-2020
Ran by elain (administrator) on EEPHOMEOFFICE (ASUSTeK COMPUTER INC. Vivo AIO 27 V272UA) (29-06-2020 10:58:04)
Running from C:\Users\elain\Downloads
Loaded Profiles: elain
Platform: Windows 10 Home Version 2004 19041.329 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() [File not signed] [File is in use] C:\Program Files (x86)\ACT\Act for Windows\Act.Outlook64.Service.exe
() [File not signed] [File is in use] C:\Program Files (x86)\ACT\Act for Windows\Integration Services Patch for Act!\ISPA.exe
() [File not signed] [File is in use] C:\Program Files (x86)\ACT\Act.Web.API\bin\act.web.api.hosting.exe
(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Systems, Incorporated -> Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
(Arvato Digital Services Canada Inc -> arvato digital services llc) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(ASUS) [File not signed] [File is in use] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTeK Computer Inc. -> ) C:\Program Files (x86)\ASUS\ASUS Hello\ASUSHelloBG.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Avanquest Software SAS -> Avanquest Software) C:\Users\elain\AppData\Local\Avanquest\Avanquest Message\AQNotif.exe
(Centered Systems -> Centered Systems) C:\Program Files (x86)\Second Copy 8\ScVssService64.exe
(Centered Systems -> Centered Systems) C:\Program Files (x86)\Second Copy 8\SecCopy.exe
(Garmin International, Inc. -> Garmin Ltd. or its subsidiaries) C:\Program Files (x86)\Garmin\Express\express.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <21>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe
(Google LLC -> Google) C:\Users\elain\AppData\Local\Google\Chrome\User Data\SwReporter\83.238.200\software_reporter_tool.exe <4>
(ICEpower a/s -> ICEpower A/S) C:\Windows\System32\ICEsoundService64.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_9196e89091d8bdbb\esif_uf.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_31a8dbbf39dcdc3b\jhi_service.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_ca6dea73b8394fc3\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_ca6dea73b8394fc3\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_ca6dea73b8394fc3\igfxext.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_ca6dea73b8394fc3\IntelCpHDCPSvc.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_ca6dea73b8394fc3\IntelCpHeciSvc.exe
(Macrovision Corporation -> Macrovision Europe Ltd.) [File not signed] [File is in use] C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10_50.ACT7\MSSQL\Binn\sqlservr.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SystemSettingsAdminFlows.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.329_none_e77145332606deb0\TiWorker.exe
(Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) C:\Windows\System32\drivers\AdminService.exe
(Microsoft) [File not signed] [File is in use] C:\Program Files (x86)\ACT\Act for Windows\Act.Server.Host.exe
(Nero AG -> Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Qualcomm Atheros -> Qualcomm Technologies Inc.) C:\Windows\System32\drivers\QcomWlanSrvx64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe <6>
(Swiftpage ACT! LLC -> Swiftpage ACT! LLC) C:\Program Files (x86)\ACT\Act for Windows\Act!.Integration.exe
(Swiftpage ACT! LLC) [File not signed] [File is in use] C:\Program Files (x86)\ACT\Act for Windows\Act.Outlook.Service.exe
(Valusoft Finance, LLC -> ValuSoft Finance, LLC) C:\Program Files (x86)\MasterCook 15\MyMasterCook\MyMasterCook.exe
(Zeon Corporation -> ) C:\Program Files (x86)\HotDocs\bin\ZNLSvc.exe
Failed to access process -> GiftBoxService.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [19677472 2019-12-13] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_ListenToDevice] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3617568 2019-12-13] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [37232 2008-06-12] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [640376 2008-06-11] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [Act.Outlook.Service] => C:\Program Files (x86)\ACT\Act for Windows\Act.Outlook.Service.exe [19456 2018-03-15] (Swiftpage ACT! LLC) [File not signed] [File is in use]
HKLM-x32\...\Run: [Act.Outlook64.Service] => C:\Program Files (x86)\ACT\Act for Windows\Act.Outlook64.Service.exe [23552 2018-03-15] () [File not signed] [File is in use]
HKLM-x32\...\Run: [Act! Preloader] => C:\Program Files (x86)\ACT\Act for Windows\Act!.exe [272336 2019-09-24] (Swiftpage ACT! LLC -> Swiftpage ACT! LLC)
HKLM-x32\...\Run: [Polarr] => C:\ProgramData\SquirrelMachineInstalls\Polarr.exe [73300232 2020-05-16] (Polarr, Inc. -> Polarr, Inc.) [File not signed] [File is in use]
HKU\S-1-5-21-131675017-3346686803-3792727656-1002\...\Run: [Second Copy] => C:\Program Files (x86)\Second Copy 8\SecCopy.exe [3128616 2013-01-27] (Centered Systems -> Centered Systems)
HKU\S-1-5-21-131675017-3346686803-3792727656-1002\...\Run: [Avanquest Message] => C:\Users\elain\AppData\Local\Avanquest\Avanquest Message\AQNotif.exe [439784 2020-04-02] (Avanquest Software SAS -> Avanquest Software)
HKU\S-1-5-21-131675017-3346686803-3792727656-1002\...\Run: [ISPA] => C:\Program Files (x86)\ACT\Act for Windows\Integration Services Patch for Act!\ISPA.exe [15635456 2019-07-26] () [File not signed] [File is in use]
HKU\S-1-5-21-131675017-3346686803-3792727656-1002\...\Run: [GarminExpress] => C:\Program Files (x86)\Garmin\Express\express.exe [30868464 2019-12-12] (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-131675017-3346686803-3792727656-1002\...\RunOnce: [Application Restart #3] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe  --user-data-dir="C:\Users\elain\AppData\Local\Temp\\{0EEDB3FB-1591-70AF-0F22-19A4B3765D18}_CR" --no-sandbox --allow-no-sandbox-job --disabl (the data entry has 154 more characters). <==== ATTENTION
HKLM\...\Windows x64\Print Processors\hpcpp155: C:\Windows\System32\spool\prtprocs\x64\hpcpp155.DLL [597792 2013-09-04] (Hewlett-Packard Company -> Hewlett-Packard Corporation)
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\WINDOWS\system32\AdobePDF.dll [51032 2008-04-07] (Adobe Systems, Incorporated -> Adobe Systems Inc)
HKLM\...\Print\Monitors\novaPDF 7 Monitor: C:\WINDOWS\system32\novamnk7.dll [29472 2014-06-16] (Softland S.R.L. -> Softland)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\83.0.4103.116\Installer\chrmstp.exe [2020-06-22] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Act! Integration.lnk [2020-01-05]
ShortcutTarget: Act! Integration.lnk -> C:\Program Files (x86)\ACT\Act for Windows\Act!.Integration.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk [2019-12-12]
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) [File not signed] [File is in use]
Startup: C:\Users\elain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JfQPKiheALIH.lnK [2020-06-22]
ShortcutAndArgument: JfQPKiheALIH.lnK -> C:\Users\elain\AppData\Roaming\JfQPKiheALIH.Cmd => 
Startup: C:\Users\elain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\puWJErhMmRyz.lnK [2020-06-22]
ShortcutAndArgument: puWJErhMmRyz.lnK -> C:\Users\elain\AppData\Roaming\puWJErhMmRyz.Cmd => 
Startup: C:\Users\elain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WvMSIJCpwORq.LNk [2020-05-16]
ShortcutAndArgument: WvMSIJCpwORq.LNk -> C:\Users\elain\AppData\Roaming\WvMSIJCpwORq.cMD => 

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {010F5DD3-B691-460F-B9A1-38F605E1822F} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe
Task: {01E6D4BB-B74A-43C1-81AC-0E06E0EE9320} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [127176 2020-05-20] (Mozilla Corporation -> Mozilla Foundation)
Task: {180AB9D4-E685-40A9-A6A2-D23D35C7C381} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [75776 2017-10-24] (ASUS) [File not signed] [File is in use]
Task: {5C52AC7E-FED3-4ADB-930D-4C40397FF8E0} - System32\Tasks\McAfee\DAD.Execute.Updates => C:\Program Files\Common Files\McAfee\DynamicAppDownloader\1.4.111\DADUpdater.exe
Task: {65EB50B5-EAD0-41A4-BE98-F913B7301D30} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-11-27] (Google Inc -> Google LLC)
Task: {88823972-A1BC-4741-A625-DB3704A00E40} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Systems)
Task: {8EC9FA58-4F01-4444-BAC6-EBBB9F576F0A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-11-27] (Google Inc -> Google LLC)
Task: {93C13921-8182-42E7-A567-628B93BBC9EB} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-131675017-3346686803-3792727656-1002 => C:\Users\elain\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Task: {9486D21E-E9EB-43F8-85AF-E3EC0FCF2A9A} - System32\Tasks\ASUS Hello => C:\Program Files (x86)\ASUS\ASUS Hello\ASUSHelloBG.exe [642448 2018-05-31] (ASUSTeK Computer Inc. -> )
Task: {A1F87101-B717-4971-B1DD-7E819D1E03FB} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [40432 2019-12-12] (Garmin International, Inc. -> )
Task: {A6B38897-6866-4936-9349-7C48D6BC56D2} - System32\Tasks\McAfeeLogon => C:\PROGRA~1\COMMON~1\McAfee\Platform\McUICnt.exe
Task: {AAF27842-7BD7-422C-9FCA-415FCB87001F} - System32\Tasks\Update Checker => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [143160 2019-03-12] (ASUSTek Computer Inc. -> ASUSTek Computer Inc.)
Task: {B1E00102-23E1-4C28-9985-C57CD82D4FC9} - System32\Tasks\OneDrive Standalone Update Task v2 => C:\Users\elain\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Task: {D9126DCC-53D5-4595-86D0-F90FA7CB6A9D} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent => {ABCECA3B-EA5A-496B-A021-5C6BAB365E5C} "C:\Program Files\Common Files\McAfee\TaskScheduler\McAMTaskAgent.exe"
Task: {E0E249A3-D98F-448E-96E0-013107FD05D3} - System32\Tasks\McAfee\McAfee Idle Detection Task => {ABCDCA3B-DE6B-5A7C-B132-6D7CBA63E5C5} "C:\Program Files\Common Files\McAfee\TaskScheduler\McAMTaskAgent.exe"
Task: {E5E03A5F-FEE9-4964-B6FF-56EE76A7D601} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [124304 2017-11-23] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {FB2B59E2-B6C4-414E-8D11-A68C98F5B483} - System32\Tasks\ATK Package A22126881260 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [124304 2017-11-23] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.10.1
Tcpip\..\Interfaces\{16701ce0-2bd6-458b-974b-3425a244c327}: [DhcpNameServer] 192.168.10.1
Tcpip\..\Interfaces\{24c6f243-7ff7-49f0-b4bb-7a14b385a2ed}: [NameServer] 8.8.8.8

Internet Explorer:
==================
HKU\S-1-5-21-131675017-3346686803-3792727656-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?gws_rd=ssl#spf=1575318724860
HKU\S-1-5-21-131675017-3346686803-3792727656-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus17win10.msn.com/?pc=ASTE
SearchScopes: HKU\S-1-5-21-131675017-3346686803-3792727656-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-131675017-3346686803-3792727656-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\x64\IEPlugin.dll => No File
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll => No File
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile -> {D5233FCD-D258-4903-89B8-FB1568E7413D} -> C:\Program Files (x86)\ACT\Act for Windows\Plugins\Act.UI.InternetExplorer.Plugins.AttachFile.DLL [2018-03-15] (Swiftpage ACT! LLC) [File not signed] [File is in use]
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Toolbar: HKU\S-1-5-21-131675017-3346686803-3792727656-1002 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -  No File
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\mcafee\msc\mcsniepl.dll No File

FireFox:
========
FF DefaultProfile: r6cwiyap.default
FF ProfilePath: C:\Users\elain\AppData\Roaming\Mozilla\Firefox\Profiles\r6cwiyap.default [2019-12-06]
FF ProfilePath: C:\Users\elain\AppData\Roaming\Mozilla\Firefox\Profiles\ulxgegji.default-release [2020-06-23]
FF Notifications: Mozilla\Firefox\Profiles\ulxgegji.default-release -> hxxps://calendar.google.com
FF Extension: (Honey) - C:\Users\elain\AppData\Roaming\Mozilla\Firefox\Profiles\ulxgegji.default-release\Extensions\jid1-93CWPmRbVPjRQA@jetpack.xpi [2020-04-15]
FF Extension: (DuckDuckGo Privacy Essentials) - C:\Users\elain\AppData\Roaming\Mozilla\Firefox\Profiles\ulxgegji.default-release\Extensions\jid1-ZAdIEUB7XOzOJw@jetpack.xpi [2020-05-20]
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi => not found
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi => not found
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => not found
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2012-08-10] (Nero AG -> Nero AG)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-05-03] (Adobe Inc. -> Adobe Systems Inc.)

Chrome: 
=======
CHR Profile: C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default [2020-06-29]
CHR Notifications: Default -> hxxps://mail.google.com
CHR DefaultSearchURL: Default -> hxxps://duckduckgo.com/?q={searchTerms}
CHR DefaultSearchKeyword: Default -> duckduckgo.com
CHR DefaultNewTabURL: Default -> hxxps://duckduckgo.com/chrome_newtab
CHR DefaultSuggestURL: Default -> hxxps://duckduckgo.com/ac/?q={searchTerms}&type=list
CHR Extension: (Slides) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-11-27]
CHR Extension: (Docs) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-11-27]
CHR Extension: (Google Drive) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-11-27]
CHR Extension: (DuckDuckGo) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkdgflcldnnnapblkhphbgpggdiikppg [2020-05-29]
CHR Extension: (YouTube) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-11-27]
CHR Extension: (Honey) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2020-05-29]
CHR Extension: (Dropbox for Gmail) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpdmhfocilnekecfjgimjdeckachfbec [2019-11-27]
CHR Extension: (Adobe Acrobat) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2020-06-11]
CHR Extension: (Chrome Remote Desktop) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\efmjfjelnicpmdcmfikempdhlmainjcb [2020-04-14]
CHR Extension: (Sheets) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-11-27]
CHR Extension: (Google Docs Offline) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-05-26]
CHR Extension: (Pinterest Save Button) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2020-06-17]
CHR Extension: (Chrome Remote Desktop) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\inomeogfingihgjfjlpeplalcfajhgai [2019-12-02]
CHR Extension: (Chrome Web Store Payments) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-11-27]
CHR Extension: (Gmail) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-11-27]
CHR Extension: (Chrome Media Router) - C:\Users\elain\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-05-28]
CHR Profile: C:\Users\elain\AppData\Local\Google\Chrome\User Data\System Profile [2020-05-26]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 Act! Scheduler; C:\Program Files (x86)\ACT\Act for Windows\Act.Scheduler.exe [90112 2018-03-15] (Swiftpage ACT! LLC) [File not signed] [File is in use]
R2 ActService; C:\Program Files (x86)\ACT\Act for Windows\Act.Server.Host.exe [27648 2018-03-15] (Microsoft) [File not signed] [File is in use]
R2 ActSmartTaskService; C:\Program Files (x86)\ACT\Act for Windows\Act.Server.Host.exe [27648 2018-03-15] (Microsoft) [File not signed] [File is in use]
R2 ActWebApiService; C:\Program Files (x86)\ACT\Act.Web.API\bin\act.web.api.hosting.exe [22016 2019-12-05] () [File not signed] [File is in use]
R2 AtherosSvc; C:\WINDOWS\System32\drivers\AdminService.exe [387192 2019-11-03] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
S3 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\84.0.4147.39\remoting_host.exe [73200 2020-06-08] (Google LLC -> Google Inc.)
S2 DevActSvc; C:\Program Files (x86)\ASUS\ASUS Device Activation\DevActSvc.exe [325456 2018-06-11] (ASUSTek Computer Inc. -> )
R3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2019-12-02] (Macrovision Corporation -> Macrovision Europe Ltd.) [File not signed] [File is in use]
S2 GiftBox.Service; C:\Program Files (x86)\ASUS\ASUS GiftBox Service\GiftBoxService.exe [302416 2018-06-28] (ASUSTek Computer Inc. -> ASUSTeK Computer Inc.)
R2 ICEsoundService; C:\WINDOWS\system32\ICEsoundService64.exe [814368 2019-12-13] (ICEpower a/s -> ICEpower A/S)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6933272 2020-03-11] (Malwarebytes Inc -> Malwarebytes)
R2 MSSQL$ACT7; C:\Program Files\Microsoft SQL Server\MSSQL10_50.ACT7\MSSQL\Binn\sqlservr.exe [61913952 2011-09-21] (Microsoft Corporation -> Microsoft Corporation)
S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [50688 2013-05-16] (Hewlett-Packard) [File not signed] [File is in use]
S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [66048 2013-05-16] (Hewlett-Packard) [File not signed] [File is in use]
R2 PSI_SVC_2; C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [252344 2012-06-15] (Arvato Digital Services Canada Inc -> arvato digital services llc)
R2 QcomWlanSrv; C:\WINDOWS\System32\drivers\QcomWlanSrvx64.exe [191768 2019-11-04] (Qualcomm Atheros -> Qualcomm Technologies Inc.)
R2 ScVssService64; C:\Program Files (x86)\Second Copy 8\ScVssService64.exe [75048 2013-01-27] (Centered Systems -> Centered Systems)
S4 SQLAgent$ACT7; C:\Program Files\Microsoft SQL Server\MSSQL10_50.ACT7\MSSQL\Binn\SQLAGENT.EXE [428384 2011-09-21] (Microsoft Corporation -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2005.5-0\NisSrv.exe [2484256 2020-06-11] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2005.5-0\MsMpEng.exe [103168 2020-06-11] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 ZNLSvc; C:\Program Files (x86)\HotDocs\Bin\ZNLSvc.exe [186200 2008-09-08] (Zeon Corporation -> )

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 ATKWMIACPIIO; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [20096 2015-05-08] (Microsoft Windows Hardware Compatibility Publisher -> ASUSTek Computer Inc.)
R3 BtFilter; C:\WINDOWS\System32\drivers\btfilter.sys [83432 2019-11-03] (Qualcomm Atheros -> Qualcomm)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153312 2020-04-20] (Malwarebytes Corporation -> Malwarebytes)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [214496 2020-06-23] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2020-06-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [196456 2020-06-28] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [73368 2020-06-28] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248968 2020-06-05] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [131728 2020-06-25] (Malwarebytes Inc -> Malwarebytes)
R3 Qcamain10x64; C:\WINDOWS\System32\drivers\Qcamain10x64.sys [2432280 2019-11-04] (Qualcomm Atheros -> Qualcomm Atheros, Inc.)
R3 voxaldriver; C:\WINDOWS\system32\DRIVERS\voxaldriverx64.sys [52976 2019-12-16] (NCH Software Pty Ltd -> )
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45960 2020-06-11] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [401120 2020-06-11] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [64224 2020-06-11] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-06-29 10:58 - 2020-06-29 10:58 - 000029968 _____ C:\Users\elain\Downloads\FRST.txt
2020-06-29 10:56 - 2020-06-29 10:56 - 002291712 _____ (Farbar) C:\Users\elain\Downloads\FRST64.exe
2020-06-29 10:51 - 2020-06-29 10:51 - 000216433 _____ C:\Users\elain\Downloads\2018 - SCF (2).pdf
2020-06-29 10:50 - 2020-06-29 10:50 - 000472323 _____ C:\Users\elain\Downloads\MLS PDF Cancelled Morning Star PAAR Only.pdf
2020-06-29 10:50 - 2020-06-29 10:50 - 000216785 _____ C:\Users\elain\Downloads\2018 - SCF (1).pdf
2020-06-29 10:49 - 2020-06-29 10:49 - 008565254 _____ C:\Users\elain\Downloads\PROOF - 5975 S Morning Star Lane, Prescott, AZ 86303 Eblast.pdf
2020-06-29 10:49 - 2020-06-29 10:49 - 000000282 _____ C:\Users\elain\Downloads\text.000000.txt
2020-06-29 10:48 - 2020-06-29 10:48 - 000197953 _____ C:\Users\elain\Downloads\2018 - SCF.pdf
2020-06-29 10:47 - 2020-06-29 10:47 - 000607918 _____ C:\Users\elain\Downloads\PDFS-Forms (1).pdf
2020-06-29 10:46 - 2020-06-29 10:46 - 000607918 _____ C:\Users\elain\Downloads\PDFS-Forms.pdf
2020-06-29 10:44 - 2020-06-29 10:44 - 003978992 _____ C:\Users\elain\Downloads\List Docs Morning Star.pdf
2020-06-29 10:43 - 2020-06-29 10:43 - 002417747 _____ C:\Users\elain\Downloads\SPDS Morning Star.pdf
2020-06-29 10:43 - 2020-06-29 10:43 - 001103442 _____ C:\Users\elain\Downloads\Morning Star - Pickens CMA as of Aug 2019.pdf
2020-06-29 09:30 - 2020-06-29 09:30 - 000000000 ____D C:\Users\elain\AppData\LocalLow\IGDump
2020-06-29 08:04 - 2020-06-29 08:04 - 000632588 _____ C:\Users\elain\Downloads\SimpleKetoSystem.pdf
2020-06-28 11:16 - 2020-06-28 11:16 - 000000155 _____ C:\Users\elain\Desktop\Malwarebytes Forum.url
2020-06-28 09:14 - 2020-06-28 09:15 - 009154656 _____ C:\Users\elain\Downloads\mb-support-1.6.1.784 (2).exe
2020-06-27 17:25 - 2020-06-27 17:25 - 009154656 _____ C:\Users\elain\Downloads\mb-support-1.6.1.784 (1).exe
2020-06-27 10:50 - 2020-06-29 10:58 - 000000000 ____D C:\FRST
2020-06-27 10:33 - 2020-06-28 09:15 - 002291712 _____ (Farbar) C:\Users\elain\Downloads\FRSTEnglish.exe
2020-06-27 10:32 - 2020-06-27 10:32 - 009154656 _____ C:\Users\elain\Downloads\mb-support-1.6.1.784.exe
2020-06-27 10:06 - 2020-06-27 10:06 - 000181814 _____ C:\Users\elain\Downloads\5975_S_Morning_Star_Ln.pdf
2020-06-26 13:55 - 2020-06-28 09:06 - 000196456 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2020-06-26 13:55 - 2020-06-28 09:06 - 000073368 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2020-06-25 11:11 - 2020-06-25 11:11 - 000131728 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2020-06-24 15:50 - 2020-06-24 15:50 - 000098313 _____ C:\Users\elain\Downloads\RecipeExport2232.mz2
2020-06-22 07:34 - 2020-06-22 07:34 - 000114688 _____ C:\Users\elain\AppData\Roaming\JfQPKiheALIH
2020-06-22 07:34 - 2020-06-22 07:34 - 000000662 _____ C:\Users\elain\AppData\Roaming\JfQPKiheALIH.cMD
2020-06-22 07:33 - 2020-06-22 07:33 - 000114688 _____ C:\Users\elain\AppData\Roaming\puWJErhMmRyz
2020-06-22 07:33 - 2020-06-22 07:33 - 000000662 _____ C:\Users\elain\AppData\Roaming\puWJErhMmRyz.cMD
2020-06-18 07:22 - 2020-06-18 07:22 - 000065320 _____ C:\Users\elain\Downloads\amazon chase 17 account close Secure Messages - chase.com.pdf
2020-06-18 07:12 - 2020-06-18 07:12 - 000035410 _____ C:\Users\elain\Downloads\message_v4.rpmsg
2020-06-18 05:51 - 2020-06-18 05:51 - 000000000 ____D C:\Users\elain\AppData\Roaming\Skype
2020-06-17 09:50 - 2020-06-17 09:50 - 000009480 _____ C:\Users\elain\Downloads\RecipeExport1990.mz2
2020-06-17 09:29 - 2020-06-17 09:30 - 000052793 _____ C:\Users\elain\Downloads\RecipeExport1983.mz2
2020-06-15 13:27 - 2020-06-15 13:27 - 009449238 _____ C:\Users\elain\Downloads\Untitled attachment 01250.mp4
2020-06-12 07:15 - 2020-06-12 07:15 - 000000111 _____ C:\Users\elain\Desktop\whodns.url
2020-06-11 14:46 - 2020-06-11 14:47 - 000112719 _____ C:\Users\elain\Downloads\OontZ Angle 3 Portable Bluetooth Speaker Reset.pdf
2020-06-11 04:13 - 2020-06-23 11:28 - 000214496 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2020-06-10 20:46 - 2020-06-10 20:46 - 036171046 _____ C:\Users\elain\Downloads\Audio_DCH_Realtek_Win10_64_V6088211 (1).zip
2020-06-10 20:43 - 2020-06-11 05:56 - 000000000 ____D C:\Users\elain\Documents\Realtek Driver Download
2020-06-10 20:40 - 2020-06-11 05:56 - 000000000 ____D C:\Users\elain\Documents\Realtek
2020-06-10 20:40 - 2019-10-16 15:46 - 000003716 _____ C:\Users\elain\Documents\InstallPackage.bat
2020-06-10 20:40 - 2019-03-18 21:44 - 000281088 _____ (Microsoft Corporation) C:\Users\elain\Documents\pnputil.exe
2020-06-10 20:40 - 2019-01-22 15:01 - 000000569 _____ C:\Users\elain\Documents\InstallStep.txt
2020-06-10 20:39 - 2020-06-11 05:56 - 000000000 ____D C:\Users\elain\NCH Software Suite
2020-06-10 20:38 - 2020-06-10 20:38 - 036171046 _____ C:\Users\elain\Downloads\Audio_DCH_Realtek_Win10_64_V6088211.zip
2020-06-10 20:24 - 2020-06-11 06:15 - 000000311 _____ C:\WINDOWS\gethelp_audiotroubleshooter_latestpackage.zip
2020-06-10 19:31 - 2020-06-10 19:31 - 026271232 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 024265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 023431168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 019868160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 018766848 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 018066944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 011490816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 010921280 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 010336896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 009493504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 008895160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 008188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 007992320 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 007961824 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 007756288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 007593984 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 007591456 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 007069696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 006920192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 006404608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 006352896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 006173184 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 006069888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 006052352 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 005963472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 005858128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 005821952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 005420648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 005371536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 004880384 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 004783328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 004734976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 004629312 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 004484696 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 003925336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 003901952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 003860480 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 003859456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 003811776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 003810304 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2020-06-10 19:31 - 2020-06-10 19:31 - 003784192 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 003779896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2020-06-10 19:31 - 2020-06-10 19:31 - 003749376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Service.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 003547800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 003498216 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 003431424 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 003380736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 003332608 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 003304960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 003299840 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 002974720 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 002964992 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2020-06-10 19:31 - 2020-06-10 19:31 - 002918208 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 002827776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2020-06-10 19:31 - 2020-06-10 19:31 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2020-06-10 19:31 - 2020-06-10 19:31 - 002744320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2020-06-10 19:31 - 2020-06-10 19:31 - 002685440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 002647040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 002631008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 002601472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 002585400 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 002413056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmcndmgr.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 002317312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 002284560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 002244608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 002202624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVidCtl.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 002198016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 002193736 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 002177536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001912320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmc.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 001876992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001869312 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001805184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2020-06-10 19:31 - 2020-06-10 19:31 - 001751424 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001714176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001710080 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001704960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmcndmgr.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001695744 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001686528 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001668384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001640960 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001583616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 001557816 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 001538136 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 001537024 _____ (Microsoft Corporation) C:\WINDOWS\system32\TaskFlowDataEngine.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001506816 _____ (Microsoft Corporation) C:\WINDOWS\system32\MoUsoCoreWorker.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 001493504 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpsharercom.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001476096 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001473024 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 001473024 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001470976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001448448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001430528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001413120 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 001411072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmc.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 001400216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001394032 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2020-06-10 19:31 - 2020-06-10 19:31 - 001357312 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMNetMgr.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001353216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001352232 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001337168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryPS.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001320448 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagperf.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001312256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001301592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001296384 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001255936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpsharercom.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001255736 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 001252864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001250816 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001233408 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001230848 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdclt.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 001218560 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdengin2.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001208832 _____ (Microsoft Corporation) C:\WINDOWS\system32\windowsperformancerecordercontrol.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001204968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 001197232 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 001194496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001150752 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 001126472 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001125888 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001111552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMNetMgr.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001105408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001078784 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdosys.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001071224 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001066304 _____ (Microsoft Corporation) C:\WINDOWS\system32\DismApi.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001047040 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001021440 _____ (Microsoft Corporation) C:\WINDOWS\system32\BTAGService.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001014872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001005056 _____ (Microsoft Corporation) C:\WINDOWS\system32\tapi3.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001004032 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi2fs.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001001984 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcRefreshTask.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 001001984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000975672 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000967680 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000961192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\InkObjCore.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000945152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000941056 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000937472 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000935936 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000908288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000907456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000906528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000902968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2020-06-10 19:31 - 2020-06-10 19:31 - 000902144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000897536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windowsperformancerecordercontrol.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000887296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MdmDiagnostics.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000886784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000886272 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000884736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000884224 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000880088 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000879104 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntimewindows.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000867840 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofmsvc.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000859136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imapi2fs.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000858624 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntime.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000855272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000854016 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000850944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tapi3.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000849920 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000837120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000832512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdosys.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000831016 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000803328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000802816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000801544 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000799232 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000798208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000784896 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000783360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000778752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.ConversationalAgent.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000764456 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000759608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DismApi.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000751616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000746808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000742912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapi.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000742400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000733184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BTAGService.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000725600 _____ (Microsoft Corporation) C:\WINDOWS\system32\StateRepository.Core.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000722944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000711680 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000711168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000706048 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000702976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000695720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000690176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000689664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InkObjCore.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000687104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000683008 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000682496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiaaut.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000677888 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000676560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000673792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000666624 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000640000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\agentactivationruntimewindows.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000635824 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000633856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\agentactivationruntime.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\azroles.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000632536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSCOMEX.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000614912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000613888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.ConversationalAgent.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000611840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000608768 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000607744 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000606880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000602184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryPS.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000601400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2020-06-10 19:31 - 2020-06-10 19:31 - 000600616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000598528 _____ (Microsoft Corporation) C:\WINDOWS\system32\psisdecd.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000596992 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2020-06-10 19:31 - 2020-06-10 19:31 - 000596992 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicesFlowBroker.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000588288 _____ (Microsoft Corporation) C:\WINDOWS\system32\msra.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000583608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StateRepository.Core.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000583168 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000580096 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr
2020-06-10 19:31 - 2020-06-10 19:31 - 000579072 _____ (Microsoft® Windows® Operating System) C:\WINDOWS\system32\wvc.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000577392 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000573752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2020-06-10 19:31 - 2020-06-10 19:31 - 000572928 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000569656 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000569344 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000568832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wiaaut.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000565760 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000563200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000562688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000556544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000553984 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000552448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000549888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000540480 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\IESettingSync.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000535552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000534016 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000530440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000528696 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizeng.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000520192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Launcher.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000519168 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi2.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000508720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000503808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FXSCOMEX.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000499712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr
2020-06-10 19:31 - 2020-06-10 19:31 - 000498688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\azroles.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000488096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000486912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000485888 _____ (Microsoft Corporation) C:\WINDOWS\system32\msTextPrediction.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000484352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\psisdecd.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000482624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000477184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Picker.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000475136 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000474112 _____ (Microsoft® Windows® Operating System) C:\WINDOWS\SysWOW64\wvc.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000469936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000468992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsregcmd.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000464896 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000463360 _____ (Microsoft Corporation) C:\WINDOWS\system32\iassdo.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000454968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2020-06-10 19:31 - 2020-06-10 19:31 - 000449536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wksprt.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000443704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000439808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WalletService.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000435200 _____ (Microsoft Corporation) C:\WINDOWS\system32\termmgr.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000434504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboutSettingsHandlers.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000432128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AarSvc.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000430592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000428680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000428544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mswmdm.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000422728 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DataModel.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000421376 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imapi2.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000418816 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000410592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000408576 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationApi.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000407864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spwizeng.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000399360 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMM.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000398848 _____ (Microsoft Corporation) C:\WINDOWS\system32\qdvd.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SpeechPrivacy.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000391680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManager.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Preview.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000373064 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000368640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000361472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\termmgr.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000359936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iassdo.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000352256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapibase.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswmdm.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000340992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\VAN.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000338944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Picker.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000335360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000332288 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpviewerax.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AarSvc.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2020-06-10 19:31 - 2020-06-10 19:31 - 000323072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LocationApi.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000321024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpr.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2020-06-10 19:31 - 2020-06-10 19:31 - 000312120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SystemSettings.DataModel.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RASMM.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000303616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WlanMM.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000299008 _____ (Microsoft Corporation) C:\WINDOWS\system32\CXHProvisioningServer.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000297984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000290816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Preview.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000287232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceDirectoryClient.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000286720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000285496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Dism.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\netman.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000272896 _____ (Microsoft Corporation) C:\WINDOWS\system32\InkEd.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000272384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpviewerax.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.FileExplorer.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000267776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000266240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mpg2splt.ax
2020-06-10 19:31 - 2020-06-10 19:31 - 000265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000264192 _____ (Microsoft Corporation) C:\WINDOWS\system32\wavemsp.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000259264 _____ (Microsoft Corporation) C:\WINDOWS\system32\logoncli.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcTok.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000253024 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000249856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VAN.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000249656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\FileHistory.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\RdpRelayTransport.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000244736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000242688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManagerClient.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000233984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000232448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InkEd.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000229376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000228664 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofm.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000226304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.FileExplorer.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wavemsp.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000223544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Dism.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdigest.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpdxm.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000217912 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000215552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pku2u.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000214840 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SIUF.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000214016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\cic.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mpg2splt.ax
2020-06-10 19:31 - 2020-06-10 19:31 - 000204000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityCenterBroker.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000203976 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsBroker.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000202752 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmidx.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000201536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000195240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcmnutils.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000195144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000192000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000190056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\logoncli.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000186368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wdigest.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasrecst.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000183296 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3mm.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000182784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netprofm.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000180024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2020-06-10 19:31 - 2020-06-10 19:31 - 000176440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000170488 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\msaatext.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpdxm.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cic.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000159032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2020-06-10 19:31 - 2020-06-10 19:31 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdrsvc.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000151864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleprn.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasnap.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000146944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmidx.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000146432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000143160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys
2020-06-10 19:31 - 2020-06-10 19:31 - 000142000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmcmnutils.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkspbrokerAx.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Feedback.Analog.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000134968 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000133744 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpapi.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasrecst.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000132744 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000131896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000131072 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssitlb.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdshext.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000126976 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkStatus.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAMM.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msaatext.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000118072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000116024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleprn.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imapi.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssitlb.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000110512 _____ (Microsoft Corporation) C:\WINDOWS\system32\devenum.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000107520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasnap.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthRadioMedia.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkspbrokerAx.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFolders.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\bindfltapi.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000101288 _____ (Microsoft Corporation) C:\WINDOWS\system32\FsIso.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmjpegdec.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000099640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryBroker.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\atl.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000093952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devenum.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000092952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WwanRadioManager.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2020-06-10 19:31 - 2020-06-10 19:31 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\UsoClient.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\RpcEpMap.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmjpegdec.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\atl.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasads.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000072704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2020-06-10 19:31 - 2020-06-10 19:31 - 000070968 _____ (Microsoft Corporation) C:\WINDOWS\system32\GameInput.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxGipRadioManager.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000068608 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanRadioManager.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtutils.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnrollCtrl.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000064840 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthHost.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000064016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000061752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GameInput.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssprxy.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryCore.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasads.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeUISrv.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\NfcRadioMedia.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagnosticdataquery.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000053760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtutils.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MdmDiagnosticsTool.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnrollCtrl.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000049664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\npmproxy.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000042320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryCore.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000041864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityCenterBrokerPS.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\atlthunk.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\atlthunk.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\CIDiag.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmproxy.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000028384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SecurityCenterBrokerPS.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimsg.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000024288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerEnc.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000020648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerEnc.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmsprep.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000013312 _____ C:\WINDOWS\system32\agentactivationruntimestarter.exe
2020-06-10 19:31 - 2020-06-10 19:31 - 000010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMAlertListener.ProxyStub.dll
2020-06-10 19:31 - 2020-06-10 19:31 - 000009265 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2020-06-10 19:31 - 2020-06-10 19:31 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DMAlertListener.ProxyStub.dll
2020-06-10 19:25 - 2020-06-02 21:53 - 000391168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2020-06-10 19:25 - 2020-06-02 21:51 - 000495616 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2020-06-10 18:29 - 2019-12-13 01:55 - 003306920 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE2.dll
2020-06-10 18:29 - 2019-12-13 01:55 - 002198112 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE.dll
2020-06-10 18:29 - 2019-12-13 01:55 - 001382336 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tosade.dll
2020-06-10 18:29 - 2019-12-13 01:55 - 001337744 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tossaeapo64.dll
2020-06-10 18:29 - 2019-12-13 01:55 - 000852240 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tosasfapo64.dll
2020-06-10 18:29 - 2019-12-13 01:55 - 000604896 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tossaemaxapo64.dll
2020-06-10 18:29 - 2019-12-13 01:55 - 000447280 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\toseaeapo64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 072520608 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoRes64.dat
2020-06-10 18:29 - 2019-12-13 01:54 - 007227992 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys
2020-06-10 18:29 - 2019-12-13 01:54 - 007178360 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEP64A.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 007101640 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64A.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 006270088 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64AF3.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 005346888 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv211.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 003776792 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 003676960 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl
2020-06-10 18:29 - 2019-12-13 01:54 - 003445872 _____ (DTS, Inc.) C:\WINDOWS\system32\slcnt64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 003353936 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 003284024 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RltkAPO.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 003168488 _____ (DTS, Inc.) C:\WINDOWS\system32\sltech64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 003159672 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 002930048 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 002444576 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv201.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 001971472 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64A.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 001965048 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64AF3.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 001787848 _____ (DTS) C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 001610848 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyAPOv251gm.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 001598288 _____ (DTS) C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 001544360 _____ (Dolby Laboratories) C:\WINDOWS\system32\DAX3APOProp.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 001516160 _____ (DTS) C:\WINDOWS\system32\DTSBoostDLL64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 001435272 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRRPTR64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 001397080 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SECOMN64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 001386888 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDHF64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 001372496 _____ (Dolby Laboratories) C:\WINDOWS\system32\DAX3APOv251.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 001353216 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 001294400 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEAPO64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 001287496 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyAPOvlldpgm.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 001259624 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOvlldp.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 001181000 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDRA64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 001159080 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOProp.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 001110280 _____ (DTS, Inc.) C:\WINDOWS\system32\sl3apo64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 001078792 _____ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SEHDHF32.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 001061672 _____ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SECOMN32.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000965152 _____ (Sony Corporation) C:\WINDOWS\system32\SFSS_APO.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000873592 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo264.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000814368 _____ (ICEpower A/S) C:\WINDOWS\system32\ICEsoundService64.exe
2020-06-10 18:29 - 2019-12-13 01:54 - 000751192 _____ (DTS) C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000734664 _____ (DTS) C:\WINDOWS\system32\DTSSymmetryDLL64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000715544 _____ (DTS) C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000692056 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000641624 _____ (ICEpower A/S) C:\WINDOWS\system32\ICEsoundAPO64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000541216 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSX64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000511536 _____ (DTS) C:\WINDOWS\system32\DTSNeoPCDLL64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000467264 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRAPO64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000453168 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EED64A.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000452632 _____ (DTS) C:\WINDOWS\system32\DTSLimiterDLL64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000448496 _____ (DTS) C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000416400 _____ (Harman) C:\WINDOWS\system32\HMUI.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000406344 _____ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2APIPCLL.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000392768 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEP64A.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000381536 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000378280 _____ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2API.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000367504 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64AF3.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000366016 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\HMAPO.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000360240 _____ (Harman) C:\WINDOWS\system32\HMClariFi.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000343808 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000341256 _____ (Synopsys, Inc.) C:\WINDOWS\SysWOW64\SRCOM.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000341256 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000332904 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64A.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000327168 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DHT64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000327168 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DAA64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000316080 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64F3.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000278376 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000266448 _____ (TODO: <Company name>) C:\WINDOWS\system32\slprp64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000261128 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPO64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000261096 _____ (DTS) C:\WINDOWS\system32\DTSLFXAPO64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000260104 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPONS64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000232024 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFNHK64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000230832 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSH64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000220280 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEED64A.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000218376 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSHP64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000203736 _____ (Harman) C:\WINDOWS\system32\HMHVS.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000193088 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000190824 _____ (Harman) C:\WINDOWS\system32\HMEQ_Voice.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000190824 _____ (Harman) C:\WINDOWS\system32\HMEQ.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000179488 _____ (Harman) C:\WINDOWS\system32\HMLimiter.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000175040 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSWOW64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000167232 _____ (ASUSTeK COMPUTER INC.) C:\WINDOWS\system32\ATKWMI.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000158800 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000157240 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEL64A.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000154256 _____ (Harman) C:\WINDOWS\system32\HarmanAudioInterface.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000139648 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEA64A.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000122216 _____ (Real Sound Lab SIA) C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000118488 _____ C:\WINDOWS\system32\AcpiServiceVnA64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000116432 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEL64A.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000105200 _____ C:\WINDOWS\system32\audioLibVc.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000093800 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEG64A.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000091016 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFCOM64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000090064 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEG64A.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000088424 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFAPO64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000083728 _____ (Virage Logic Corporation / Sonic Focus) C:\WINDOWS\SysWOW64\SFCOM.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000075648 _____ (TOSHIBA CORPORATION.) C:\WINDOWS\system32\tepeqapo64.dll
2020-06-10 18:29 - 2019-12-13 01:54 - 000023584 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll
2020-06-10 18:29 - 2019-12-13 00:37 - 037280673 _____ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT
2020-06-10 18:29 - 2019-12-13 00:37 - 005804772 _____ C:\WINDOWS\system32\Drivers\rtvienna.dat
2020-06-10 18:29 - 2019-12-13 00:37 - 000242934 _____ C:\WINDOWS\system32\ICEsoundService.bin
2020-06-03 07:27 - 2020-06-03 07:27 - 000000000 ___HD C:\$WinREAgent
2020-06-02 12:30 - 2020-06-02 12:35 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2020-06-02 12:30 - 2020-06-02 12:30 - 000000000 ____D C:\WINDOWS\system32\Intel
2020-06-02 12:29 - 2020-06-02 12:30 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2020-06-02 12:29 - 2020-06-02 12:29 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2020-06-02 12:27 - 2020-06-02 12:27 - 000000000 ____D C:\Program Files\Reference Assemblies
2020-06-02 12:27 - 2020-06-02 12:27 - 000000000 ____D C:\Program Files\MSBuild
2020-06-02 12:27 - 2020-06-02 12:27 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2020-06-02 12:27 - 2020-06-02 12:27 - 000000000 ____D C:\Program Files (x86)\MSBuild
2020-06-02 12:27 - 2019-12-03 15:04 - 000781384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2020-06-02 12:27 - 2019-12-03 15:04 - 000105544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2020-06-02 12:27 - 2019-12-03 15:04 - 000037864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2020-06-02 12:27 - 2019-11-08 15:44 - 001168968 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2020-06-02 12:27 - 2019-11-08 15:44 - 000127056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2020-06-02 12:27 - 2019-11-08 15:44 - 000038072 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2020-06-02 11:46 - 2020-06-02 11:46 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2020-06-02 11:44 - 2020-06-29 06:26 - 000004162 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{6818F6E0-4385-41C2-94FE-1230EEA14738}
2020-06-02 11:44 - 2020-06-28 09:06 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-06-02 11:44 - 2020-06-10 20:47 - 000000000 ____D C:\WINDOWS\system32\Tasks\NCH Software
2020-06-02 11:44 - 2020-06-02 11:44 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2020-06-02 11:44 - 2020-06-02 11:44 - 000003348 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-06-02 11:44 - 2020-06-02 11:44 - 000003124 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-06-02 11:44 - 2020-06-02 11:44 - 000002974 _____ C:\WINDOWS\system32\Tasks\Update Checker
2020-06-02 11:44 - 2020-06-02 11:44 - 000002924 _____ C:\WINDOWS\system32\Tasks\ATK Package 36D18D69AFC3
2020-06-02 11:44 - 2020-06-02 11:44 - 000002858 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-131675017-3346686803-3792727656-1002
2020-06-02 11:44 - 2020-06-02 11:44 - 000002768 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task v2
2020-06-02 11:44 - 2020-06-02 11:44 - 000002702 _____ C:\WINDOWS\system32\Tasks\GarminUpdaterTask
2020-06-02 11:44 - 2020-06-02 11:44 - 000002646 _____ C:\WINDOWS\system32\Tasks\McAfee Remediation (Prepare)
2020-06-02 11:44 - 2020-06-02 11:44 - 000002486 _____ C:\WINDOWS\system32\Tasks\McAfeeLogon
2020-06-02 11:44 - 2020-06-02 11:44 - 000002338 _____ C:\WINDOWS\system32\Tasks\ASUS Hello
2020-06-02 11:44 - 2020-06-02 11:44 - 000002302 _____ C:\WINDOWS\system32\Tasks\ASUS Splendid ACMON
2020-06-02 11:44 - 2020-06-02 11:44 - 000002214 _____ C:\WINDOWS\system32\Tasks\ATK Package A22126881260
2020-06-02 11:44 - 2020-06-02 11:44 - 000000020 ___SH C:\Users\elain\ntuser.ini
2020-06-02 11:44 - 2020-06-02 11:44 - 000000000 ____D C:\WINDOWS\system32\Tasks\OfficeSoftwareProtectionPlatform
2020-06-02 11:44 - 2020-06-02 11:44 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2020-06-02 11:44 - 2020-06-02 11:44 - 000000000 ____D C:\WINDOWS\system32\Tasks\McAfee
2020-06-02 11:43 - 2020-06-02 11:44 - 000007623 _____ C:\WINDOWS\diagwrn.xml
2020-06-02 11:43 - 2020-06-02 11:44 - 000007623 _____ C:\WINDOWS\diagerr.xml
2020-06-02 11:40 - 2020-06-28 09:11 - 000933278 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-06-02 11:38 - 2020-06-10 19:31 - 002876416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2020-06-02 11:38 - 2020-06-05 00:15 - 000248968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2020-06-02 11:38 - 2018-03-12 07:20 - 000144848 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2020-06-02 11:38 - 2018-03-12 07:20 - 000119752 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL
2020-06-02 11:36 - 2020-06-27 11:31 - 000000000 ____D C:\Users\elain
2020-06-02 11:36 - 2019-12-07 02:10 - 000001105 _____ C:\Users\elain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-06-02 11:35 - 2020-06-29 10:41 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-06-02 11:35 - 2020-06-28 09:06 - 000008192 ___SH C:\DumpStack.log.tmp
2020-06-02 11:35 - 2020-06-10 20:07 - 001733016 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-06-02 10:48 - 2020-06-14 11:51 - 000000000 ___DC C:\WINDOWS\Panther
2020-06-02 10:46 - 2020-06-02 10:47 - 000000000 ___HD C:\$GetCurrent
2020-06-02 10:42 - 2020-06-02 10:42 - 000000000 ___HD C:\$Windows.~WS
2020-06-02 10:35 - 2020-06-02 10:48 - 000000036 _____ C:\WINDOWS\progress.ini
2020-06-01 14:04 - 2020-06-02 12:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileASSASSIN
2020-06-01 14:04 - 2020-06-01 14:04 - 000000000 ____D C:\Program Files (x86)\FileASSASSIN

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-06-29 10:47 - 2019-12-07 02:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-06-29 09:42 - 2019-11-27 22:18 - 000000000 ____D C:\ProgramData\MasterCook 15
2020-06-29 09:39 - 2019-11-30 06:56 - 000000000 ___RD C:\Users\elain\Desktop\HOME
2020-06-29 09:07 - 2019-11-29 13:01 - 000000000 ____D C:\Users\elain\Desktop\EMAIL
2020-06-29 06:26 - 2019-11-27 19:26 - 000000358 _____ C:\Users\elain\AppData\Roaming\sp_data.sys
2020-06-28 11:46 - 2019-12-09 09:32 - 000000000 ____D C:\Users\elain\AppData\Local\ElevatedDiagnostics
2020-06-28 09:11 - 2019-12-07 02:13 - 000000000 ____D C:\WINDOWS\INF
2020-06-28 09:06 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\ServiceState
2020-06-28 09:06 - 2019-11-28 11:28 - 000000000 __SHD C:\Users\elain\IntelGraphicsProfiles
2020-06-28 09:05 - 2019-12-07 02:03 - 000262144 _____ C:\WINDOWS\system32\config\BBI
2020-06-26 18:54 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2020-06-26 14:12 - 2019-12-07 02:14 - 000000000 ___HD C:\Program Files\WindowsApps
2020-06-26 14:12 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-06-26 12:07 - 2019-11-29 18:02 - 000000000 ____D C:\Scans3
2020-06-23 20:32 - 2019-12-06 17:02 - 000000000 ____D C:\Users\elain\AppData\LocalLow\Mozilla
2020-06-22 13:05 - 2019-11-27 22:33 - 000000000 ____D C:\Program Files (x86)\Google
2020-06-22 13:04 - 2019-11-27 22:33 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-06-16 06:45 - 2019-12-07 02:50 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2020-06-11 06:42 - 2019-11-30 17:36 - 000000000 ____D C:\Users\elain\Desktop\APPS-SHARED
2020-06-11 06:32 - 2019-11-22 06:54 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2020-06-11 06:32 - 2019-11-22 06:54 - 000000000 ____D C:\WINDOWS\system32\DAX3
2020-06-11 06:32 - 2019-11-22 06:54 - 000000000 ____D C:\WINDOWS\system32\DAX2
2020-06-11 06:32 - 2019-11-22 06:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Realtek
2020-06-11 05:56 - 2019-12-16 09:52 - 000000000 ____D C:\ProgramData\Autoplay Menu Designer
2020-06-11 05:56 - 2019-12-07 02:52 - 000000000 ____D C:\Program Files\Windows Portable Devices
2020-06-11 05:56 - 2019-12-07 02:52 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2020-06-11 05:56 - 2019-12-07 02:52 - 000000000 ____D C:\Program Files\Windows Multimedia Platform
2020-06-11 05:56 - 2019-12-07 02:52 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices
2020-06-11 05:56 - 2019-12-07 02:52 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2020-06-11 05:56 - 2019-12-07 02:52 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2020-06-11 05:56 - 2019-12-07 02:50 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ___SD C:\WINDOWS\system32\F12
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ___SD C:\WINDOWS\system32\dsc
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Licenses
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Keywords
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\InputMethod
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\IME
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\downlevel
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SystemResources
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\setup
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\MUI
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\Macromed
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\Licenses
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\Keywords
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\InputMethod
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\IME
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\ias
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\downlevel
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\Com
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\schemas
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\Provisioning
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\IME
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\DiagTrack
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\Containers
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\Branding
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\Program Files\Common Files\System
2020-06-11 05:56 - 2019-12-07 02:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2020-06-11 05:56 - 2019-12-07 02:03 - 000000000 ____D C:\WINDOWS\servicing
2020-06-11 05:56 - 2019-12-03 13:06 - 000000000 ____D C:\Program Files\Microsoft Silverlight
2020-06-11 05:11 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\registration
2020-06-11 04:12 - 2018-05-09 11:24 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2020-06-10 22:39 - 2019-12-13 09:07 - 000000000 ____D C:\Users\elain\Downloads\programs and such
2020-06-10 22:39 - 2019-12-02 18:27 - 000000000 ____D C:\ProgramData\FLEXnet
2020-06-10 22:39 - 2019-11-27 22:18 - 000000000 ____D C:\Users\Public\Documents\MasterCook 15
2020-06-10 22:39 - 2019-11-27 22:18 - 000000000 ____D C:\ProgramData\Documents\MasterCook 15
2020-06-10 22:39 - 2019-11-27 22:10 - 000000000 ____D C:\Users\elain\AppData\Roaming\Tabs3
2020-06-10 20:47 - 2019-12-15 13:48 - 000000000 ____D C:\Users\elain\Downloads\recipes
2020-06-10 20:39 - 2019-12-03 10:16 - 000001260 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Zip File Compression.lnk
2020-06-10 20:39 - 2019-12-03 08:24 - 000000000 ____D C:\Users\elain\AppData\Roaming\NCH Software
2020-06-10 19:33 - 2019-12-07 02:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-06-05 08:35 - 2019-11-30 06:56 - 000000000 ____D C:\Users\elain\Desktop\OFFICE
2020-06-05 00:15 - 2019-12-02 12:57 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2020-06-04 18:11 - 2019-11-28 11:28 - 000000000 ____D C:\Users\elain\AppData\Local\Packages
2020-06-04 12:41 - 2020-01-21 13:03 - 000000000 ____D C:\ProgramData\Garmin
2020-06-04 12:41 - 2019-12-07 02:14 - 000000000 __RHD C:\Users\Public\Libraries
2020-06-04 12:41 - 2019-12-03 10:51 - 000000000 ____D C:\Users\Public\Documents\MAGIX
2020-06-04 12:41 - 2019-12-03 10:51 - 000000000 ____D C:\ProgramData\Documents\MAGIX
2020-06-04 12:41 - 2019-12-02 15:43 - 000000000 ____D C:\Users\Public\Documents\Hewlett-Packard
2020-06-04 12:41 - 2019-12-02 15:43 - 000000000 ____D C:\ProgramData\Documents\Hewlett-Packard
2020-06-04 12:41 - 2019-01-18 11:39 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-06-04 12:15 - 2019-12-12 13:49 - 000000000 ____D C:\Users\Public\Documents\Reallusion
2020-06-04 12:15 - 2019-12-12 13:49 - 000000000 ____D C:\ProgramData\Documents\Reallusion
2020-06-04 12:15 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\appcompat
2020-06-04 12:15 - 2019-11-29 17:29 - 000000000 ____D C:\Users\Public\Documents\ACT
2020-06-04 12:15 - 2019-11-29 17:29 - 000000000 ____D C:\ProgramData\Documents\ACT
2020-06-03 10:32 - 2019-12-03 18:52 - 000000000 ____D C:\ProgramData\Packages
2020-06-03 07:27 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\Drivers\DriverData
2020-06-02 17:20 - 2019-12-02 17:13 - 000000000 ____D C:\Users\elain\AppData\Local\D3DSCache
2020-06-02 12:35 - 2020-01-29 09:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BleachBit
2020-06-02 12:35 - 2020-01-21 13:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
2020-06-02 12:35 - 2020-01-09 09:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW 7
2020-06-02 12:35 - 2020-01-05 08:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Act! Pro
2020-06-02 12:35 - 2019-12-20 12:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Abrosoft FantaMorph 3
2020-06-02 12:35 - 2019-12-16 17:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2020-06-02 12:35 - 2019-12-16 16:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\muvee Reveal 12
2020-06-02 12:35 - 2019-12-16 15:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArtRage 6
2020-06-02 12:35 - 2019-12-16 15:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArtRage 2 Deluxe
2020-06-02 12:35 - 2019-12-16 14:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Magic
2020-06-02 12:35 - 2019-12-16 09:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autoplay Menu Designer 5
2020-06-02 12:35 - 2019-12-13 09:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewBlue
2020-06-02 12:35 - 2019-12-12 14:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrazyTalk Animator 2 Training DVD
2020-06-02 12:35 - 2019-12-12 13:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrazyTalk Animator 3 Fundamentals Training Videos
2020-06-02 12:35 - 2019-12-12 13:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cartoon Animator 4
2020-06-02 12:35 - 2019-12-08 11:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Instant Photo Effects 2
2020-06-02 12:35 - 2019-12-07 02:14 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2020-06-02 12:35 - 2019-12-07 02:14 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
2020-06-02 12:35 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2020-06-02 12:35 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\spool
2020-06-02 12:35 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2020-06-02 12:35 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\Cursors
2020-06-02 12:35 - 2019-12-03 15:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Family Historian
2020-06-02 12:35 - 2019-12-03 13:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2020-06-02 12:35 - 2019-12-03 12:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2020-06-02 12:35 - 2019-12-03 10:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Personal Historian 3
2020-06-02 12:35 - 2019-12-03 10:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RootsMagic 7
2020-06-02 12:35 - 2019-12-03 08:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Legacy 9.0
2020-06-02 12:35 - 2019-12-03 08:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 5 SDK
2020-06-02 12:35 - 2019-12-03 08:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HotDocs 11
2020-06-02 12:35 - 2019-12-02 19:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WordPerfect Office 2002
2020-06-02 12:35 - 2019-12-02 18:40 - 000000000 ____D C:\WINDOWS\SHELLNEW
2020-06-02 12:35 - 2019-12-02 18:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Second Copy 8
2020-06-02 12:35 - 2019-12-02 18:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stamps.com
2020-06-02 12:35 - 2019-12-02 16:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2008 R2
2020-06-02 12:35 - 2019-12-02 15:14 - 000000000 ____D C:\WINDOWS\SysWOW64\1033
2020-06-02 12:35 - 2019-12-02 15:14 - 000000000 ____D C:\WINDOWS\system32\1033
2020-06-02 12:35 - 2019-12-02 12:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2020-06-02 12:35 - 2019-12-02 10:18 - 000000000 ____D C:\Program Files\UNP
2020-06-02 12:35 - 2019-11-27 22:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MasterCook 15
2020-06-02 12:35 - 2019-11-22 06:54 - 000000000 ____D C:\Program Files\Intel
2020-06-02 12:35 - 2019-11-22 06:43 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2020-06-02 12:35 - 2019-11-22 06:43 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2020-06-02 12:35 - 2019-01-18 12:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
2020-06-02 12:34 - 2019-11-22 06:49 - 000000000 ____D C:\WINDOWS\InfusedApps
2020-06-02 12:30 - 2020-02-07 11:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Better Homes and Gardens
2020-06-02 12:30 - 2019-12-16 16:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serif Applications
2020-06-02 12:30 - 2019-12-13 08:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VEGAS
2020-06-02 12:30 - 2019-12-11 12:38 - 000000000 ____D C:\ProgramData\DisplayLink
2020-06-02 12:30 - 2019-12-11 10:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero
2020-06-02 12:30 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\Resources
2020-06-02 12:30 - 2019-12-03 10:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
2020-06-02 12:30 - 2019-12-02 19:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Corel WordPerfect Suite 8
2020-06-02 12:30 - 2019-12-02 16:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2008
2020-06-02 12:30 - 2019-11-27 22:14 - 000000000 ____D C:\Users\elain\AppData\Local\PlaceholderTileLogoFolder
2020-06-02 12:30 - 2019-11-22 06:54 - 000000000 ____D C:\Program Files\Realtek
2020-06-02 12:30 - 2019-01-18 12:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ICEpower
2020-06-02 12:28 - 2019-12-07 02:18 - 000000000 ____D C:\WINDOWS\Setup
2020-06-02 12:27 - 2019-12-07 02:10 - 000383488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnet.dll
2020-06-02 12:27 - 2019-12-07 02:10 - 000215552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplayx.dll
2020-06-02 12:27 - 2019-12-07 02:10 - 000060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnathlp.dll
2020-06-02 12:27 - 2019-12-07 02:10 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpwsockx.dll
2020-06-02 12:27 - 2019-12-07 02:10 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpmodemx.dll
2020-06-02 12:27 - 2019-12-07 02:10 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnsvr.exe
2020-06-02 12:27 - 2019-12-07 02:10 - 000020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplaysvr.exe
2020-06-02 12:27 - 2019-12-07 02:10 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhupnp.dll
2020-06-02 12:27 - 2019-12-07 02:10 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhpast.dll
2020-06-02 12:27 - 2019-12-07 02:10 - 000005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnlobby.dll
2020-06-02 12:27 - 2019-12-07 02:10 - 000005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnaddr.dll
2020-06-02 12:27 - 2019-12-07 02:09 - 000494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnet.dll
2020-06-02 12:27 - 2019-12-07 02:09 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnathlp.dll
2020-06-02 12:27 - 2019-12-07 02:09 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnsvr.exe
2020-06-02 12:27 - 2019-12-07 02:09 - 000010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhupnp.dll
2020-06-02 12:27 - 2019-12-07 02:09 - 000010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhpast.dll
2020-06-02 12:27 - 2019-12-07 02:09 - 000006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnlobby.dll
2020-06-02 12:27 - 2019-12-07 02:09 - 000006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnaddr.dll
2020-06-02 11:44 - 2019-12-07 02:14 - 000000000 ____D C:\ProgramData\USOPrivate
2020-06-02 11:44 - 2019-12-07 02:14 - 000000000 ____D C:\Program Files\Windows Defender
2020-06-02 11:44 - 2019-12-07 02:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2020-06-02 11:44 - 2019-11-28 11:28 - 000000000 ___RD C:\Users\elain\3D Objects
2020-06-02 11:37 - 2020-04-14 14:05 - 000000000 ____D C:\Users\elain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2020-06-02 11:12 - 2019-12-12 08:40 - 000002143 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2020-06-02 10:46 - 2020-05-27 08:42 - 000000738 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 10 Update Assistant.lnk
2020-06-02 10:46 - 2020-05-27 08:42 - 000000000 ____D C:\Windows10Upgrade
2020-06-02 10:46 - 2020-05-26 23:19 - 000000000 ____D C:\ESD
2020-06-01 22:52 - 2019-12-07 02:18 - 000835480 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2020-06-01 22:52 - 2019-12-07 02:18 - 000179608 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2020-06-01 14:08 - 2020-01-29 09:42 - 000000000 ____D C:\Users\elain\.dbus-keyrings

==================== Files in the root of some directories ========

2019-12-02 15:06 - 2019-12-02 16:33 - 192307320 _____ (Swiftpage Act! LLC                                          ) C:\Users\elain\AppData\Roaming\act2010update8ss.exe
2020-01-05 08:31 - 2020-01-05 08:32 - 193313114 _____ (Swiftpage Act! LLC                                          ) C:\Users\elain\AppData\Roaming\act2010update9ss.exe
2019-12-02 16:40 - 2019-12-02 16:40 - 000000000 ____H () C:\Users\elain\AppData\Roaming\ActUpdate.log
2020-06-22 07:34 - 2020-06-22 07:34 - 000114688 _____ () C:\Users\elain\AppData\Roaming\JfQPKiheALIH
2020-06-22 07:34 - 2020-06-22 07:34 - 000000662 _____ () C:\Users\elain\AppData\Roaming\JfQPKiheALIH.cMD
2019-12-02 16:21 - 2020-01-05 08:35 - 000032305 _____ () C:\Users\elain\AppData\Roaming\NGEN_AppLog_Install.txt
2019-12-02 16:28 - 2020-01-05 08:24 - 000009727 _____ () C:\Users\elain\AppData\Roaming\NGEN_AppLog_Uninstall.txt
2019-12-02 19:21 - 2019-12-02 19:21 - 000012358 _____ () C:\Users\elain\AppData\Roaming\PFP100JCM.{PB
2019-12-02 19:21 - 2019-12-02 19:21 - 000061678 _____ () C:\Users\elain\AppData\Roaming\PFP100JPR.{PB
2020-06-22 07:33 - 2020-06-22 07:33 - 000114688 _____ () C:\Users\elain\AppData\Roaming\puWJErhMmRyz
2020-06-22 07:33 - 2020-06-22 07:33 - 000000662 _____ () C:\Users\elain\AppData\Roaming\puWJErhMmRyz.cMD
2019-11-27 19:26 - 2020-06-29 06:26 - 000000358 _____ () C:\Users\elain\AppData\Roaming\sp_data.sys
2019-12-16 09:08 - 2019-12-16 09:08 - 000001167 _____ () C:\Users\elain\AppData\Roaming\trace_FilterInstaller.txt
2019-12-16 09:08 - 2019-12-16 09:08 - 000000000 _____ () C:\Users\elain\AppData\Roaming\trace_FilterInstaller.txt-CRT.txt
2020-05-16 11:10 - 2020-05-16 11:10 - 000071000 _____ () C:\Users\elain\AppData\Roaming\WvMSIJCpwORq
2020-05-16 11:10 - 2020-05-16 11:10 - 000000662 _____ () C:\Users\elain\AppData\Roaming\WvMSIJCpwORq.Cmd
2019-12-16 16:20 - 2019-12-16 18:22 - 000007168 _____ () C:\Users\elain\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2020-04-14 10:09 - 2020-04-14 10:09 - 000007601 _____ () C:\Users\elain\AppData\Local\Resmon.ResmonCfg

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

 

 

LOG FROM ADDITION.TXT:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-06-2020
Ran by elain (29-06-2020 10:59:02)
Running from C:\Users\elain\Downloads
Windows 10 Home Version 2004 19041.329 (X64) (2020-06-02 18:44:21)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-131675017-3346686803-3792727656-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-131675017-3346686803-3792727656-503 - Limited - Disabled)
eepic (S-1-5-21-131675017-3346686803-3792727656-1005 - Limited - Enabled)
elain (S-1-5-21-131675017-3346686803-3792727656-1002 - Administrator - Enabled) => C:\Users\elain
Guest (S-1-5-21-131675017-3346686803-3792727656-501 - Limited - Enabled)
tax46 (S-1-5-21-131675017-3346686803-3792727656-1004 - Limited - Enabled)
WDAGUtilityAccount (S-1-5-21-131675017-3346686803-3792727656-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

64 Bit HP CIO Components Installer (HKLM\...\{345F3F90-0505-4EDF-B7A9-5E3AC1AC6CE4}) (Version: 15.2.1 - Hewlett-Packard) Hidden
Abrosoft FantaMorph 3.7 (HKLM-x32\...\Abrosoft FantaMorph 3_is1) (Version: 3.7 - Abrosoft)
Act! Pro (HKLM-x32\...\{EFE72412-EEF7-4F36-BEBF-05760A66F4D8}) (Version: 20.1.0.0 - Swiftpage ACT! LLC) Hidden
Act! Pro (HKLM-x32\...\InstallShield_{EFE72412-EEF7-4F36-BEBF-05760A66F4D8}) (Version: 20.1.0.0 - Swiftpage ACT! LLC)
Adobe Acrobat 9 Pro - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7760-000000000004}{AC76BA86-1033-F400-7760-000000000004}) (Version: 9.0.0 - Adobe Systems)
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 20.009.20067 - Adobe Systems Incorporated)
Adobe Photoshop 7.0 (HKLM-x32\...\Adobe Photoshop 7.0) (Version: 7.0 - Adobe Systems, Inc.)
ANT Drivers Installer x64 (HKLM\...\{99B72734-4395-42D0-ADFD-A9722A7AD7B0}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArtRage 2 Deluxe (HKLM-x32\...\{58936A21-4252-4188-AC6A-440F867BDB00}) (Version: 2.5.20 - Ambient Design)
ArtRage 6 (HKLM\...\{7AF6962D-016E-4084-ADF8-84891B95D815}) (Version: 6.1.2.0 - Ambient Design) Hidden
ArtRage 6 (HKLM-x32\...\ArtRage 6 6.1.2.0) (Version: 6.1.2.0 - Ambient Design)
ASUS Device Activation (HKLM-x32\...\{9C4B0706-9F9A-47BF-B417-0A111FC52B04}) (Version: 1.0.5.0 - ASUSTeK COMPUTER INC.)
ASUS GiftBox Service (HKLM-x32\...\{4701E5AB-AF91-4D40-8F18-358CC80E4E5B}) (Version: 3.2.3.0 - ASUSTeK COMPUTER INC.)
ASUS Hello (HKLM-x32\...\{D8CE1923-92A9-4036-817E-9E0D8AA2169B}) (Version: 1.1.4.0 - ASUSTeK COMPUTER INC.)
ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.6.8 - ASUSTeK COMPUTER INC.)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 3.23.0001 - ASUS)
ATK Package (ASUS Keyboard Hotkeys) (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0060 - ASUSTeK COMPUTER INC.)
AudioWizard (HKLM-x32\...\{57E770A2-2BAF-4CAA-BAA3-BD896E2254D3}) (Version: 1.0.8.8 - ICEpower a/s)
Autoplay Menu Designer - Additional Templates Packs (HKLM-x32\...\Autoplay Menu Designer - Additional Templates Packs_is1) (Version:  - Visual Designing)
Autoplay Menu Designer 5.3 (HKLM-x32\...\Autoplay Menu Designer 5_is1) (Version:  - Visual Designing)
Avanquest Message (HKU\S-1-5-21-131675017-3346686803-3792727656-1002\...\{20573C69-4A68-4BEF-A23D-365CB66924CE}) (Version: 2.10.0 - Avanquest Software)
BleachBit 3.0 (HKLM-x32\...\BleachBit) (Version: 3.0 - BleachBit)
Cartoon Animator v4.11 Pipeline (HKLM-x32\...\{9400CD28-76E6-48F2-B8EE-00697D8E72B3}) (Version: 4.11.1123.1 - Reallusion Inc.)
Chrome Remote Desktop Host (HKLM-x32\...\{FEA4124F-FABE-440B-BA03-489722A59439}) (Version: 84.0.4147.39 - Google Inc.)
Corel Applications (HKLM-x32\...\Corel Applications) (Version:  - )
Corel WordPerfect Suite 8 (HKLM-x32\...\Corel WordPerfect Suite 😎 (Version:  - )
CrazyTalk Animator 2 Training DVD (HKLM-x32\...\{699FB10B-82FA-4DD6-A9F3-93B54C4772ED}) (Version: 2.0.0328.1 - Reallusion)
CrazyTalk Animator 3 Fundamentals Training Videos (HKLM-x32\...\{C12EAE1C-2CBC-48DB-8A6E-F0EF74EDD48D}) (Version: 3.0.0725.1 - Reallusion)
Debut Video Capture Software (HKLM-x32\...\Debut) (Version: 5.05 - NCH Software)
Doxillion Document Converter (HKLM-x32\...\Doxillion) (Version: 3.19 - NCH Software)
DVD Architect (HKLM-x32\...\{1D8D144F-3558-11E9-A3D6-00155D6302F2}) (Version: 7.0.100 - VEGAS)
Elevated Installer (HKLM-x32\...\{EDCD0A1B-09BE-493A-B871-13F86760A5D0}) (Version: 6.19.4.0 - Garmin Ltd or its subsidiaries) Hidden
Express Scribe Transcription Software (HKLM-x32\...\Scribe) (Version: 8.26 - NCH Software)
Express Zip File Compression (HKLM-x32\...\ExpressZip) (Version: 7.18 - NCH Software)
FaceGen Modeller 3.3 Free (HKLM-x32\...\{7DCFE14B-8F0E-47BF-863A-84757F038D7C}) (Version: 3.3.0 - Singular Inversions Inc.)
Family Historian 6.2.7 (HKLM-x32\...\family_historian_is1) (Version:  - Calico Pie Limited)
Family Historian PDF (novaPDF 7.7 printer) (HKLM\...\Family Historian PDF_is1) (Version: 7.7.400 - Softland)
FileASSASSIN (HKLM-x32\...\FileASSASSIN) (Version: 1.06 - Malwarebytes)
Garmin Express (HKLM-x32\...\{0a5a7c12-97db-47da-874c-cfeeeac5676f}) (Version: 6.19.4.0 - Garmin Ltd or its subsidiaries)
Garmin Express (HKLM-x32\...\{DD4EE84A-E101-4F03-A881-AF498F68811C}) (Version: 6.19.4.0 - Garmin Ltd or its subsidiaries) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 83.0.4103.116 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
HD Camcorder Add-on (HKLM-x32\...\{3DB8CE13-3DDF-4FC0-93C1-C70B69388B34}) (Version: 1.0.38.7596 - muvee Technologies Pte Ltd)
Home Designer Suite 8 (HKLM-x32\...\{900792CC-3203-356C-EC2D-C3E558991ACE}) (Version: 8.4.1.8 - Chief Architect Inc)
HotDocs Developer 11 (64bit) (HKLM\...\{712012F2-9C95-4618-B075-9B0B82265652}) (Version: 11.00.3077 - HotDocs Corporation)
Instant Photo Effects 2.0 (HKLM-x32\...\Photon) (Version:  - )
Integration Services Patch for Act! (HKLM-x32\...\{58AEEE89-2CD8-45D0-BC80-A9F5E3DE465C}) (Version: 1.0.1150.0 - Integration Services Patch for Act!)
Intel(R) Chipset Device Software (HKLM-x32\...\{44ded3eb-1686-46a6-9770-fd79096c29f7}) (Version: 10.1.1.45 - Intel(R) Corporation) Hidden
Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\...\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.3.10208.5644 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1069 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 23.20.16.4973 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.9.1.1020 - Intel Corporation)
Intel(R) Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.49.166.0 - Intel Corporation) Hidden
Intel(R) Trusted Connect Services Client (HKLM-x32\...\{df682aff-4294-4ad1-aaa7-276931d5781f}) (Version: 1.49.166.0 - Intel Corporation) Hidden
Legacy 9.0 (HKLM-x32\...\Legacy 9.0) (Version: 9.0  - Millennia Corporation)
Magic v2.12 (64-bit) (HKLM\...\{15E5FBA4-6FD2-4AAD-B56E-BDC40E417F41}_is1) (Version: 2.12 - Color & Music, LLC)
MAGIX Analogue Modelling Suite Plus (HKLM\...\{F485F2FE-1D3D-4F6D-AD4E-13FA5FB22A88}) (Version: 1.0.0.0 - MAGIX Software GmbH) Hidden
MAGIX Analogue Modelling Suite Plus (HKLM\...\MX.{F485F2FE-1D3D-4F6D-AD4E-13FA5FB22A88}) (Version: 1.0.0.0 - MAGIX Software GmbH)
MAGIX Content and Soundpools (HKLM-x32\...\MAGIX_GlobalContent) (Version: 1.0.0.0 - MAGIX Software GmbH)
MAGIX Samplitude Music Studio (HKLM\...\{9258C82B-1DC4-4C2E-A039-316021B08965}) (Version: 24.0.0.36 - MAGIX Software GmbH) Hidden
MAGIX Samplitude Music Studio (HKLM\...\MX.{9258C82B-1DC4-4C2E-A039-316021B08965}) (Version: 24.0.0.36 - MAGIX Software GmbH)
MAGIX Samplitude Music Studio (Object synthesizers) (HKLM\...\{9F11D8E5-A862-4482-AFD1-F829ABFBC403}) (Version: 1.0.0.0 - MAGIX Software GmbH) Hidden
MAGIX Samplitude Music Studio (Object synthesizers) (HKLM-x32\...\MX.{9F11D8E5-A862-4482-AFD1-F829ABFBC403}) (Version: 1.0.0.0 - MAGIX Software GmbH)
MAGIX Soundpool Music Maker - Feel good (HKLM\...\{62ED0962-0942-4859-8448-D350614BF248}) (Version: 1.0.0.0 - MAGIX Software GmbH) Hidden
MAGIX Soundpools 2019 (HKLM\...\{14AE7BED-9521-4436-9D83-533D263E5349}) (Version: 1.0.0.0 - MAGIX Software GmbH) Hidden
MAGIX Speed burnR (HKLM\...\{CB82E569-C28F-4140-A7C0-0ACD70D1D0AB}) (Version: 7.0.1.27 - MAGIX Software GmbH) Hidden
MAGIX Speed burnR (HKLM-x32\...\MX.{CB82E569-C28F-4140-A7C0-0ACD70D1D0AB}) (Version: 7.0.1.27 - MAGIX Software GmbH)
MAGIX Vandal VST-PlugIn (HKLM\...\{24F96DED-7B99-49C4-B877-CDCDC37762FA}) (Version: 1.0.0.0 - MAGIX Software GmbH) Hidden
MAGIX Vandal VST-PlugIn (HKLM\...\MX.{24F96DED-7B99-49C4-B877-CDCDC37762FA}) (Version: 1.0.0.0 - MAGIX Software GmbH)
MAGIX VariVerb II VST-PlugIn (HKLM\...\{7A97538C-6D3F-4BB5-B2A1-D0ECFB199A4C}) (Version: 1.0.0.0 - MAGIX Software GmbH) Hidden
MAGIX VariVerb II VST-PlugIn (HKLM\...\MX.{7A97538C-6D3F-4BB5-B2A1-D0ECFB199A4C}) (Version: 1.0.0.0 - MAGIX Software GmbH)
Malwarebytes version 4.1.0.56 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.1.0.56 - Malwarebytes)
MasterCook 15 (HKLM-x32\...\{1E492158-401F-434B-957B-477D6B5A46AA}) (Version: 15.00.24 - Valusoft Cosmi)
Microsoft ODBC Driver 11 for SQL Server (HKLM\...\{A106FA6F-E94C-44C9-8A0F-C34BD82C9FE6}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-131675017-3346686803-3792727656-1002\...\OneDriveSetup.exe) (Version: 19.232.1124.0008 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation)
Microsoft Silverlight 5 SDK (HKLM-x32\...\{E1FBB3D4-ADB0-4949-B101-855DA061C735}) (Version: 5.0.61118.0 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 (64-bit) (HKLM\...\Microsoft SQL Server 2008 R2) (Version:  - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Native Client (HKLM\...\{2180B33F-3225-423E-BBC1-7798CFD3CD1F}) (Version: 10.50.1600.1 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Setup (English) (HKLM\...\{6D10FB2C-82A9-40F2-91D0-7BE64CF0DAF2}) (Version: 10.50.1600.1 - Microsoft Corporation)
Microsoft SQL Server 2008 Setup Support Files  (HKLM\...\{B40EE88B-400A-4266-A17B-E3DE64E94431}) (Version: 10.1.2731.0 - Microsoft Corporation)
Microsoft SQL Server Browser (HKLM-x32\...\{BF9BF038-FE03-429D-9B26-2FA0FD756052}) (Version: 10.50.1600.1 - Microsoft Corporation)
Microsoft Sync Framework 2.0 Core Components (x64) ENU  (HKLM\...\{8CCBEC22-D2DB-4DC9-A58A-E1A1F3A38C8A}) (Version: 2.0.1578.0 - Microsoft Corporation)
Microsoft Sync Framework 2.0 Core Components (x86) ENU  (HKLM-x32\...\{FF63121D-91C6-42CC-B341-F1AA729728E7}) (Version: 2.0.1578.0 - Microsoft Corporation)
Microsoft Sync Framework 2.0 Provider Services (x64) ENU  (HKLM\...\{03AC245F-4C64-425C-89CF-7783C1D3AB2C}) (Version: 2.0.1578.0 - Microsoft Corporation)
Microsoft Sync Framework 2.0 Provider Services (x86) ENU  (HKLM-x32\...\{D3A80508-CD83-4CA3-8671-914A1BC78B61}) (Version: 2.0.1578.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{90ffcee5-8608-4e94-8c18-a4feb4f83fb8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.23.27820 (HKLM-x32\...\{45231ab4-69fd-486a-859d-7a59fcd11013}) (Version: 14.23.27820.0 - Microsoft Corporation)
Microsoft Visual FoxPro OLE DB Provider (HKLM-x32\...\{3DA245C5-23B1-4874-BFA7-287B7D6C1EF6}) (Version: 1.0.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.60724 - Microsoft Corporation)
Microsoft VSS Writer for SQL Server 2014 (HKLM\...\{366CD715-2FF4-40B4-A8B4-A05E5D21A945}) (Version: 12.0.2000.8 - Microsoft Corporation)
Movie Studio 15.0 Platinum (HKLM\...\{1A9D1980-DDE6-11E8-804F-9C6873244263}) (Version: 15.0.157 - VEGAS)
Movie Studio 16.0 Platinum (HKLM\...\{616969A1-0193-11EA-B40D-A6CFD62728D8}) (Version: 16.0.167 - VEGAS)
Mozilla Firefox 76.0.1 (x64 en-US) (HKLM\...\Mozilla Firefox 76.0.1 (x64 en-US)) (Version: 76.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 71.0 - Mozilla)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
Music Maker (HKLM\...\{DC21CFD5-02AC-4C89-8D35-85506A9FEB55}) (Version: 28.0.2.43 - MAGIX Software GmbH) Hidden
Music Maker (HKLM-x32\...\MX.{DC21CFD5-02AC-4C89-8D35-85506A9FEB55}) (Version: 28.0.2.45 - MAGIX Software GmbH)
Music Maker Update (HKLM\...\{20C81740-F574-48DF-929A-99B4BCD3F2D9}) (Version: 28.0.2.45 - MAGIX Software GmbH) Hidden
muvee Adrenaline Rush stylePack (HKLM-x32\...\{D52DB394-76CF-75C8-7C83-B7D5D478A05F}) (Version: 8.0.0.14850 - muvee Technologies Pte Ltd)
muvee American Journal stylePack (HKLM-x32\...\{F30C1B19-5BAD-451A-A797-DF77E8375215}) (Version: 6.00.100 - muvee Technologies)
muvee Back To School Style (HKLM-x32\...\{C15540B8-4D1F-2510-A140-8B8EC95E93A7}) (Version: 6.1.38.8069 - muvee Technologies Pte Ltd)
muvee California pack (HKLM-x32\...\{0DB19E6B-F160-8526-75F8-13D54D083F51}) (Version: 8.0.1.17059 - muvee Technologies Pte Ltd)
muvee Christmas Cheer stylePack (HKLM-x32\...\{3F837C38-92C4-4DC3-8824-E3E41377C143}) (Version: 4.00.100 - )
muvee Christmas stylePack (HKLM-x32\...\{231FB9C0-4ABF-439E-8D24-C006D2252360}) (Version: 5.00.102 - muvee Technologies)
muvee coolStyles 1  (HKLM-x32\...\{92518780-C904-409C-B674-528822FEA6E2}) (Version: 6.00.108 - muvee Technologies)
muvee coolStyles 2  (HKLM-x32\...\{AFB057E3-03AF-420D-9E85-F846739CE211}) (Version: 6.00.108 - muvee Technologies)
muvee corePack  (HKLM-x32\...\{1B0BD0D6-D7D1-4D49-9815-5A85081ECC45}) (Version: 6.00.105 - muvee Technologies)
muvee efx stylePack (HKLM-x32\...\{05F6E091-D014-41AA-AC4F-E3F7AECA9F3D}) (Version: 5.00.100 - muvee Technologies)
muvee Essentials pack (HKLM-x32\...\{93C61B28-0D1F-0A68-F6AD-50BF7AEE152A}) (Version: 8.0.1.17085 - muvee Technologies Pte Ltd)
muvee Halloween Horrors Style (HKLM-x32\...\{E156B26A-7BF2-9B28-26D7-AB3BC75B0BBB}) (Version: 6.1.38.8069 - muvee Technologies Pte Ltd)
muvee Halloween stylePack (HKLM-x32\...\{BB66B899-A0E2-48F3-856B-D6053ECF03E0}) (Version: 6.00.103 - muvee Technologies)
muvee Hi-Octane stylePack (HKLM-x32\...\{EB320D1D-16E2-45AE-AE48-7952D3E9542C}) (Version: 5.00.100 - muvee Technologies)
muvee Independence Day Style (HKLM-x32\...\{195B9E5D-CB08-45D0-8374-974924E81D16}) (Version: 6.1.38.8069 - muvee Technologies Pte Ltd)
muvee Keep It All stylePack (HKLM-x32\...\{C2912FA4-7263-4F0E-831F-0BF0160CFA28}) (Version: 4.00.100 - muvee Technologies)
muvee Kids stylePack (HKLM-x32\...\{886EA322-81B7-4DB8-BA8E-5300243A3CFD}) (Version: 4.00.100 - muvee Technologies)
muvee Laurence Gartel stylePack (HKLM-x32\...\{07195CBF-8D91-499E-8BB2-510A6F5544EA}) (Version: 5.00.100 - muvee Technologies)
muvee Life Story Style (HKLM-x32\...\{3D2BAE84-7CD4-7911-BDE7-673E03BAC9AA}) (Version: 9.0.1.20252 - muvee Technologies Pte Ltd)
muvee Mix It Up stylePack (HKLM-x32\...\{C3FD195E-1FEA-4B93-97ED-B74AA7115D56}) (Version: 6.1.36.6339 - muvee Technologies Pte Ltd)
muvee Photo-Centric stylePack (HKLM-x32\...\{F7344B66-C8AA-4597-B73E-08BBF449EE26}) (Version: 4.00.100 - muvee Technologies)
muvee photoFocus stylePack (HKLM-x32\...\{C69362F6-C6AD-43DD-835D-E0F897BE99F7}) (Version: 6.1.37.7135 - muvee Technologies Pte Ltd)
muvee photoGenie stylePack (HKLM-x32\...\{A022E277-568F-E87B-A091-CE1933698A5E}) (Version: 8.0.0.14850 - muvee Technologies Pte Ltd)
muvee photoMemories stylePack (HKLM-x32\...\{2C14545B-8EE2-4994-B0C0-07A666DB37B9}) (Version: 5.00.100 - muvee Technologies)
muvee Pro Classic stylePack (HKLM-x32\...\{F4AD1D69-B6AF-48C3-AF65-CB39C2BFFEC3}) (Version: 5.00.104 - muvee Technologies)
muvee Pro Modern stylePack (HKLM-x32\...\{9A1686DD-E593-4556-8BD1-426A3F28A263}) (Version: 5.00.104 - muvee Technologies)
muvee Reveal 12 (HKLM-x32\...\{120D679C-3A3A-B700-AD88-CD1106010D56}) (Version: 12.0.0.27842 - muvee Technologies Pte Ltd)
muvee Reveal Runtime (HKLM-x32\...\{86EFEB9A-FE52-40FE-9FA7-47108D4FADA9}) (Version: 12.0.0.27842 - muvee Technologies Pte Ltd)
muvee Soccer stylePack  (HKLM-x32\...\{4314E111-3621-4613-BD2B-0736DA8EFAA9}) (Version: 5.00.100 - muvee Technologies)
muvee Spring Break stylePack (HKLM-x32\...\{13B1CEE2-9513-42CF-8D10-36D83DE7E912}) (Version: 6.00.100 - muvee Technologies)
muvee Style Pack 1 & 2 (HKLM-x32\...\{AD1CE924-4897-4BA3-AEF9-F491716FE493}) (Version: 1.00.101 - )
muvee Valentine stylePack (HKLM-x32\...\{A03087D3-3E28-4FCE-9799-59A314AC95E2}) (Version: 4.00.100 - muvee Technologies)
muvee Wedding stylePack (HKLM-x32\...\{1DE5377D-C99D-CC34-068B-336677C163CE}) (Version: 8.0.0.14850 - muvee Technologies Pte Ltd)
Nero 12 (HKLM-x32\...\{560FC78C-A4B2-461D-9B47-820C1EEF87B8}) (Version: 12.0.02000 - Nero AG)
Nero 2014 Content Pack (HKLM-x32\...\{204A26F0-01B8-4656-8607-5CCEDE820BC2}) (Version: 15.0.00200 - Nero AG)
NewBlue Filters 5 Recolor (HKLM-x32\...\NewBlue Filters 5 Recolor) (Version: 5.0.180730 - NewBlue)
NewBlue Transitions 5 Ultimate (HKLM-x32\...\NewBlue Transitions 5 Ultimate) (Version: 5.0.180730 - NewBlue)
Open XML SDK 2.0 for Microsoft Office (HKLM-x32\...\{171D8D76-3F05-455A-A8AF-C561C2679905}) (Version: 2.0.5022 - Microsoft Corporation)
Personal Historian 3.0.2.0 (HKLM-x32\...\{76BD4014-A57B-4EA7-BB81-2A1E687915AA}_is1) (Version:  - RootsMagic, Inc.)
Photopea PSD Editor Plug-in v1.0 for Cartoon Animator (HKLM-x32\...\{EDAFF67C-096E-4A7B-B3CD-8CFAB4384934}) (Version: 1.0.1016.1 - Reallusion Inc.)
PhotoStage Slideshow Producer (HKLM-x32\...\PhotoStage) (Version: 5.15 - NCH Software)
Pixillion Image Converter (HKLM-x32\...\Pixillion) (Version: 6.15 - NCH Software)
Prerequisite installer (HKLM-x32\...\{3AAB08A3-F129-4BD5-B409-AE674F93759D}) (Version: 12.0.0002 - Nero AG) Hidden
Prerequisite installer (HKLM-x32\...\{5909A89E-C97F-407C-AE2B-47BDED86BF5D}) (Version: 15.0.0005 - Nero AG) Hidden
Prism Video File Converter (HKLM-x32\...\Prism) (Version: 4.07 - NCH Software)
QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.8858.1 - Realtek Semiconductor Corp.)
RootsMagic 7.0.4.0 (HKLM-x32\...\{D6286873-A757-4A4D-A6EF-0081B3EE32CA}_is1) (Version: RootsMagic 7.0.4.0 - RootsMagic, Inc.)
Second Copy 8 (HKLM-x32\...\Second Copy 8_is1) (Version: 8.1.2.0 - Centered Systems)
Serif DrawPlus X6 (HKLM\...\{8A8AB2D3-53DE-4A65-8D35-68A09AA1AD7A}) (Version: 13.0.3.26 - Serif (Europe) Ltd)
Serif PhotoPlus X6 (HKLM\...\{CCD2C5E4-F484-4499-BCB3-61E787416757}) (Version: 16.0.1.029 - Serif (Europe) Ltd)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version:  - Microsoft)
SQL Server 2008 R2 Common Files (HKLM\...\{234F6B0D-10AE-4BB7-B2F3-E48D4861952D}) (Version: 10.50.1600.1 - Microsoft Corporation) Hidden
SQL Server 2008 R2 Common Files (HKLM\...\{36F70DEE-1EBF-4707-AFA2-E035EEAEBAA1}) (Version: 10.50.1600.1 - Microsoft Corporation) Hidden
SQL Server 2008 R2 Database Engine Services (HKLM\...\{FA7394B8-CE65-4F9E-AC99-F372AD365424}) (Version: 10.50.1600.1 - Microsoft Corporation) Hidden
SQL Server 2008 R2 Database Engine Services (HKLM\...\{FBD367D1-642F-47CF-B79B-9BE48FB34007}) (Version: 10.50.1600.1 - Microsoft Corporation) Hidden
SQL Server 2008 R2 Database Engine Shared (HKLM\...\{A2122A9C-A699-4365-ADF8-68FEAC125D61}) (Version: 10.50.1600.1 - Microsoft Corporation) Hidden
SQL Server 2008 R2 Database Engine Shared (HKLM\...\{C942A025-A840-4BF2-8987-849C0DD44574}) (Version: 10.50.1600.1 - Microsoft Corporation) Hidden
Sql Server Customer Experience Improvement Program (HKLM\...\{6476DB81-F263-4C04-8574-AAD31136C304}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden
Sql Server Customer Experience Improvement Program (HKLM\...\{F31183CF-E10F-4DE1-BB59-6C0FF38E481E}) (Version: 10.50.1600.1 - Microsoft Corporation) Hidden
Stamps.com (HKLM-x32\...\{698AC01B-DF0C-4BCE-940C-EB29AD23A560}) (Version: 16.3.0.3873 - Stamps.com, Inc.) Hidden
Stamps.com (HKLM-x32\...\Stamps.com) (Version: 16.3.0.3873 - Stamps.com, Inc.)
Stamps.com Address Book Support for ACT! 3.05 - 6.0 (HKLM-x32\...\{831AA8FB-B67A-48E0-95FF-D609BC31AF0C}) (Version: 6.2.0.1488 - Stamps.com, Inc.) Hidden
Stamps.com Address Book Support for Common Harmony (HKLM-x32\...\{D00324C0-5343-4917-BF1E-D5E45D22B7E8}) (Version: 6.2.0.1488 - Stamps.com, Inc.) Hidden
Stamps.com Address Book Support for Outlook Express, Works, IE (HKLM-x32\...\{9E404AA6-7C63-4D95-B8D2-72256ABB6A9E}) (Version: 6.2.0.1488 - Stamps.com, Inc.) Hidden
Stamps.com Application Support for Corel WordPerfect 9 (HKLM-x32\...\{BE0C8089-BE6E-466D-A79E-E5D2AE089FE9}) (Version: 6.2.0.1488 - Stamps.com, Inc.) Hidden
Stamps.com support for ACT! 3.05 - 6.0 (HKLM-x32\...\Stamps.com support for ACT! 3.05 - 6.0) (Version:  - Stamps.com, Inc.)
Stamps.com support for Corel WordPerfect 9 (HKLM-x32\...\Stamps.com support for Corel WordPerfect 9) (Version:  - Stamps.com, Inc.)
Stamps.com support for Harmony (HKLM-x32\...\Stamps.com support for Harmony) (Version:  - Stamps.com, Inc.)
Stamps.com support for Outlook Express, Works, IE (HKLM-x32\...\Stamps.com support for Outlook Express, Works, IE) (Version:  - Stamps.com, Inc.)
UFR II Printer Driver Uninstaller (HKLM\...\Canon UFR II Printer Driver) (Version: 6, 3, 1, 0 - Canon Inc.)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{32DC821E-4A7D-4878-BEE8-337FA153D7F2}) (Version: 2.63.0.0 - Microsoft Corporation) Hidden
Update for Windows 10 for x64-based Systems (KB4480730) (HKLM\...\{3BAE4496-6F6C-4330-A8AA-B93D3D346FA5}) (Version: 2.53.0.0 - Microsoft Corporation)
VideoPad Video Editor (HKLM-x32\...\VideoPad) (Version: 6.00 - NCH Software)
Vita 2 (HKLM\...\{40161542-D9DF-4601-AA60-E969B017FB48}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita 2 add-on content (HKLM\...\{946AF57B-74AA-4F40-AA9A-732438F81D0B}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita 2 common (HKLM\...\{C7B5259E-11DC-4B21-BBDD-DDAAA88C1F36}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita Accordion (HKLM\...\{C9106851-C36F-4EBA-A17C-58B40C7397CB}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita Choir (HKLM\...\{9098B857-4CC8-4399-AF6A-0A0A59352487}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita Church Organ (HKLM\...\{ED854B8E-17E3-4A38-80C5-F4DF85C1F540}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita Cinematic Soundscapes (HKLM\...\{8DDAE083-BECC-4675-AB3E-D9BC3BF16F38}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita Cinematic Synth (HKLM\...\{A90ABDBE-D391-461E-A928-EF0F0DC7628D}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita Concert Grand (HKLM\...\{29691FB3-299F-4675-B899-851183C4BF92}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita Concert Grand LE (HKLM\...\{57C401B8-C121-462E-A2B1-9E9EE57875A8}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita Drum Engine (HKLM\...\{46038AEE-DD50-49FC-A69F-F9D64D83D6FA}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita Folk (HKLM\...\{2A3B3E17-A261-4999-AAE3-6ECCFDFE1CA7}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita Grand Piano (HKLM\...\{27741FAD-2C70-45FB-AF5E-F69DD4561AEA}) (Version: 2.5.0.286 - MAGIX Software GmbH) Hidden
Vita Jazz Drums (HKLM\...\{8E867DF7-58FE-48B9-83AD-43FA9D982A01}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita Lead Synth (HKLM\...\{61DE70FD-A4A9-4ACB-8B50-C79D30F31F09}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita Orchestral Ensemble (HKLM\...\{0EAA851B-DD1E-4371-A815-97A22E2C78CE}) (Version: 2.5.0.286 - MAGIX Software GmbH) Hidden
Vita Pop Drums (HKLM\...\{5109B03D-84D7-4D22-B9E1-56C025EE61B9}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita Rock Drums (HKLM\...\{5C33024E-0633-4D90-8294-66F4D074DC70}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita Sansula (HKLM\...\{AA80E297-5415-47C9-B1EA-3BA27F2B60CD}) (Version: 2.5.0.286 - MAGIX Software GmbH) Hidden
Vita Soundtrack Percussion (HKLM\...\{9987EF58-80B1-4803-8A91-3F53BA564206}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Voxal Voice Changer (HKLM-x32\...\Voxal) (Version: 2.00 - NCH Software)
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-2) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
WavePad Sound Editor (HKLM-x32\...\WavePad) (Version: 8.00 - NCH Software)
Welcome App (Start-up experience) (HKLM-x32\...\{828175FA-7307-4DBF-95AD-9CEE086B6F45}) (Version: 12.0.14000 - Nero AG) Hidden
Windows 10 Update Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.23072 - Microsoft Corporation)
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 3.2.10.0 - ASUSTeK COMPUTER INC.)
WordPerfect Office 2002 Professional (HKLM-x32\...\{F73E7B59-F951-11D4-884D-00902761A46D}) (Version: 10 - Corel) Hidden

Packages:
=========
ASUS GIFTBOX -> C:\Program Files\WindowsApps\B9ECED6F.ASUSGIFTBOX_3.1.8.0_x64__qmba6cd70vzyy [2020-06-11] (ASUSTeK COMPUTER INC.)
ASUS Product Registration Program -> C:\Program Files\WindowsApps\B9ECED6F.ASUSProductRegistrationProgram_3.0.3.0_x86__qmba6cd70vzyy [2020-06-11] (ASUSTeK COMPUTER INC.) [Startup Task]
Canon Office Printer Utility -> C:\Program Files\WindowsApps\34791E63.CanonOfficePrinterUtility_12.7.0.0_x64__6e5tt8cgb93ep [2020-06-11] (Canon Inc.)
Cortana -> C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_2.2005.5739.0_x64__8wekyb3d8bbwe [2020-06-11] (Microsoft Corporation) [Startup Task]
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_115.1.152.0_x64__v10z8vjag6ke6 [2020-06-11] (HP Inc.)
Microsoft Access -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Access_16051.12827.20336.0_x86__8wekyb3d8bbwe [2020-06-15] (Microsoft Corporation)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2020-06-11] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2020-06-11] (Microsoft Corporation) [MS Ad]
Microsoft Excel -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Excel_16051.12827.20336.0_x86__8wekyb3d8bbwe [2020-06-15] (Microsoft Corporation)
Microsoft Office Desktop Apps -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop_16051.12827.20336.0_x86__8wekyb3d8bbwe [2020-06-15] (Microsoft Corporation)
Microsoft Outlook -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.12827.20336.0_x86__8wekyb3d8bbwe [2020-06-15] (Microsoft Corporation)
Microsoft PowerPoint -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.PowerPoint_16051.12827.20336.0_x86__8wekyb3d8bbwe [2020-06-15] (Microsoft Corporation)
Microsoft Publisher -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Publisher_16051.12827.20336.0_x86__8wekyb3d8bbwe [2020-06-15] (Microsoft Corporation)
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.7.5012.0_x64__8wekyb3d8bbwe [2020-06-11] (Microsoft Studios) [MS Ad]
Microsoft Word -> C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Word_16051.12827.20336.0_x86__8wekyb3d8bbwe [2020-06-15] (Microsoft Corporation)
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x64__8wekyb3d8bbwe [2020-06-11] (Microsoft Corporation) [MS Ad]
MyASUS -> C:\Program Files\WindowsApps\B9ECED6F.ASUSPCAssistant_2.2.22.0_x64__qmba6cd70vzyy [2020-06-15] (ASUSTeK COMPUTER INC.)
MyASUS-Service Center -> C:\Program Files\WindowsApps\B9ECED6F.MyASUS_3.3.11.0_x86__qmba6cd70vzyy [2020-06-11] (ASUSTeK COMPUTER INC.) [Startup Task]
Photos Add-on -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2017.39121.36610.0_x64__8wekyb3d8bbwe [2020-06-11] (Microsoft Corporation)
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2020-06-11] (Microsoft Corporation)
Skype -> C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c [2020-06-25] (Skype) [Startup Task]
Xbox 360 SmartGlass -> C:\Program Files\WindowsApps\Microsoft.XboxCompanion_1.4.3.0_x64__8wekyb3d8bbwe [2020-06-11] (Microsoft Corporation) [MS Ad]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat Elements\ContextMenu64.dll [2008-06-11] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
ContextMenuHandlers1: [ExpressZip] -> {8EEA165E-0B8B-4BA7-9796-50214C767171} => C:\Program Files (x86)\NCH Software\ExpressZip\ezcm64.dll [2019-12-03] () [File not signed] [File is in use]
ContextMenuHandlers1: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => c:\PROGRA~1\mcafee\msc\MCCTXM~1.DLL -> No File
ContextMenuHandlers1-x32: [Zeon.MFCDirectShellExt] -> {353C642C-F13D-4699-9FF2-EFAF490B6C69} => C:\Program Files (x86)\HotDocs\bin\DirectShellExt.dll [2008-12-17] (Zeon International Investment Corp.) [File not signed] [File is in use]
ContextMenuHandlers3-x32: [FAExt] -> {05672D66-9736-42F5-8BEB-FA1DD3CA51C4} => C:\Program Files (x86)\FileASSASSIN\FileASSASSINExt.dll [2007-03-30] (Malwarebytes) [File not signed] [File is in use]
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-12-02] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_ca6dea73b8394fc3\igfxDTCM.dll [2018-03-12] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [Adobe.Acrobat.ContextMenu] -> {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat Elements\ContextMenu64.dll [2008-06-11] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
ContextMenuHandlers6: [ExpressZip] -> {8EEA165E-0B8B-4BA7-9796-50214C767171} => C:\Program Files (x86)\NCH Software\ExpressZip\ezcm64.dll [2019-12-03] () [File not signed] [File is in use]
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-12-02] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => c:\PROGRA~1\mcafee\msc\MCCTXM~1.DLL -> No File

==================== Codecs (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32: [vidc.tscc] => C:\Windows\SysWOW64\tsccvid.dll [102400 2006-04-30] (TechSmith Corporation) [File not signed] [File is in use]

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\elain\Pictures\PHOTOS\Chronological Photos\2016-2020\2018\12\craigslist_facebook_marketplace\chair\Extras\Adobe Reader Download.lnk -> hxxp://get.adobe.com/reader
ShortcutWithArgument: C:\Users\elain\Desktop\APPS-SHARED\Chrome Remote Desktop.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=efmjfjelnicpmdcmfikempdhlmainjcb
ShortcutWithArgument: C:\Users\elain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome Remote Desktop.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=efmjfjelnicpmdcmfikempdhlmainjcb

==================== Loaded Modules (Whitelisted) =============

2020-06-04 13:32 - 2020-06-04 13:32 - 000032256 _____ ((c)2013 Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Shared.7319adae#\1596a776eef6ed93cc32358b405cf97c\Act.Shared.UI.Utilities.ni.dll
2017-10-03 14:45 - 2017-10-03 14:45 - 000147968 _____ () [File not signed] [File is in use] C:\Program Files (x86)\ASUS\Splendid\CCTAdjust.dll
2017-10-24 13:24 - 2017-10-24 13:24 - 000036864 _____ () [File not signed] [File is in use] C:\Program Files (x86)\ASUS\Splendid\DetectDisplayDC.dll
2017-06-21 12:51 - 2017-06-21 12:51 - 000029184 _____ () [File not signed] [File is in use] C:\Program Files (x86)\ASUS\Splendid\VideoEnhance.dll
2019-09-09 07:13 - 2019-09-09 07:13 - 001364992 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\CefSharp.Core.dll
2019-12-12 13:34 - 2019-12-12 13:34 - 000073216 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\FixBootSector.dll
2017-05-08 09:35 - 2017-05-08 09:35 - 000325632 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\GpsImgWrapper.dll
2019-07-27 08:57 - 2019-07-27 08:57 - 096071680 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\libcef.dll
2019-12-03 10:16 - 2019-12-03 10:16 - 000105984 _____ () [File not signed] [File is in use] C:\Program Files (x86)\NCH Software\ExpressZip\ezcm64.dll
2019-12-12 13:34 - 2019-12-12 13:34 - 001976832 _____ (Apache Software Foundation) [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\XercesLib.dll
2017-10-24 13:24 - 2017-10-24 13:24 - 000073216 _____ (ASUS TeK Computer Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ASUS\Splendid\ApplyLUT.dll
2017-10-24 13:24 - 2017-10-24 13:24 - 000242688 _____ (ASUS TeK Computer Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ASUS\Splendid\GenLUT.dll
2017-10-24 13:24 - 2017-10-24 13:24 - 000407040 _____ (ASUSTeK Computer Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ASUS\Splendid\ColorU.dll
2019-12-12 13:36 - 2019-12-12 13:36 - 000234496 _____ (Dynastream Innovations Inc.) [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\ANT_WrappedLib.dll
2019-12-12 13:34 - 2019-12-12 13:34 - 002711552 _____ (Garmin International) [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\legacyio.dll
2017-05-08 09:35 - 2017-05-08 09:35 - 000343552 _____ (Garmin International, Inc.) [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\IMG_GPSMAP.dll
2019-12-12 13:34 - 2019-12-12 13:34 - 000425472 _____ (Garmin) [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\XMLdll.dll
2020-06-04 13:32 - 2020-06-04 13:32 - 000332288 _____ (Infragistics, Inc.) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Infragisticaa8fcf78#\a05d2d62d2b01c83efefaf9d6069f574\Infragistics.Act.Shared.ni.dll
2020-06-04 13:32 - 2020-06-04 13:32 - 002721792 _____ (Infragistics, Inc.) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Infragisticcc7b0f04#\e24bda6ab167d19752d195bb4dd04034\Infragistics.Act.Win.UltraWinSchedule.ni.dll
2020-06-04 13:32 - 2020-06-04 13:32 - 003194880 _____ (Infragistics, Inc.) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Infragistics.Act.Win\783b3c56dd01a351cbd7724a45a02056\Infragistics.Act.Win.ni.dll
2019-12-12 13:35 - 2019-12-12 13:35 - 000090112 _____ (Silicon Laboratories, Inc.) [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\DSI_SiUSBXp_3_1.DLL
2020-06-04 13:31 - 2020-06-04 13:31 - 000089600 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Data.ActDb\ec52c807f6ad3c3abff5ef03812e3007\Act.Data.ActDb.ni.dll
2020-06-04 13:31 - 2020-06-04 13:31 - 002308608 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Data.Resources\e71976dd4029228c0cf55d8b5759be17\Act.Data.Resources.ni.dll
2020-06-04 13:31 - 2020-06-04 13:31 - 000128000 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Data\60e6cf8d33e7cb0f3956a0772d6d421a\Act.Data.ni.dll
2020-06-04 13:31 - 2020-06-04 13:31 - 000757760 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Framewo2acccfe4#\ea3bd7794350889d5bbb0ac468863277\Act.Framework.BusinessLink.LinkConnector.ni.dll
2020-06-04 13:31 - 2020-06-04 13:31 - 000573440 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Framewoa7c82375#\86a56207f9f56fe3dc3ee97ca9f848f1\Act.Framework.BusinessLink.Synchronization.ni.dll
2020-06-04 13:31 - 2020-06-04 13:31 - 001558528 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Framewob25cef3d#\044293dbcb154e68db8814b39b6ccecc\Act.Framework.Synchronization.ni.dll
2020-06-04 13:31 - 2020-06-04 13:31 - 000048640 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Outlook22f3a37f#\088adc401713c181cfbb4ac4ba534fa3\Act.Outlook.Service.Interfaces.ni.dll
2020-06-04 13:31 - 2020-06-04 13:31 - 000096768 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Outlook267d4dc5#\7f4e3ae363f842202ac0fa71fb35d82e\Act.Outlook.Service.AppCommon.ni.dll
2020-06-04 13:31 - 2020-06-04 13:31 - 000590336 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Outlooke08b44a0#\38e34a27787918cc932b1dc46c8b3774\Act.Outlook.Service.Shared.ni.dll
2020-06-04 13:31 - 2020-06-04 13:31 - 000129536 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Shared.3cd8e10e#\ffefab3a4a05397d04c0ed90bd935173\Act.Shared.Diagnostics.ni.dll
2020-06-04 13:31 - 2020-06-04 13:31 - 000123904 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Shared.4c707719#\908ca214147784d9a986bbef1d32b88e\Act.Shared.Localization.ni.dll
2020-06-04 13:31 - 2020-06-04 13:31 - 000163840 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Shared.7f9f27da#\c34918a8c4f2d7e6ab840e80d5b7213c\Act.Shared.ComponentModel.ni.dll
2020-06-04 13:32 - 2020-06-04 13:32 - 000327680 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Shared.85fb1d61#\1209f4dc29ddf01c2e7376a7d4c852ba\Act.Shared.Wpf.Controls.ni.dll
2020-06-04 13:31 - 2020-06-04 13:31 - 000210432 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Shared.c5db5c3f#\e4cd1e058763522058c4f038ab2b3be5\Act.Shared.Collections.ni.dll
2020-06-04 13:31 - 2020-06-04 13:31 - 000088576 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Shared.Config\76464817175fcd5e1ab0159c159ff601\Act.Shared.Config.ni.dll
2020-06-04 13:32 - 2020-06-04 13:32 - 004396032 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Shared.dbaddaae#\b6daac94460ee84cfeec3ea962057bde\Act.Shared.Windows.Forms.ni.dll
2020-06-04 13:31 - 2020-06-04 13:31 - 020137984 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Shared.Images\74f8fbf5a96bb32aee227e36cb70d520\Act.Shared.Images.ni.dll
2020-06-04 13:31 - 2020-06-04 13:31 - 000033280 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Shared.Licensing\338a703fd605dd1069358899513652ec\Act.Shared.Licensing.ni.dll
2020-06-04 13:32 - 2020-06-04 13:32 - 000192000 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Shared.Utilities\affe52b4be87328e92b0b964de040ed1\Act.Shared.Utilities.ni.dll
2020-06-04 13:32 - 2020-06-04 13:32 - 000709120 _____ (Swiftpage ACT! LLC) [File not signed] [File is in use] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Act.Shared.Win32\c1806d7db1cc3d7b49f619d795d3584a\Act.Shared.Win32.ni.dll
2019-07-27 08:57 - 2019-07-27 08:57 - 000762368 _____ (The Chromium Authors) [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\chrome_elf.dll
2017-10-24 13:24 - 2017-10-24 13:24 - 000403968 _____ (TODO: <Company name>) [File not signed] [File is in use] C:\Program Files (x86)\ASUS\Splendid\ColorUGameDLL.dll
2017-10-24 13:24 - 2017-10-24 13:24 - 000029184 _____ (TODO: <Company name>) [File not signed] [File is in use] C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:065D25EE [358]
AlternateDataStreams: C:\ProgramData\TEMP:0FD841FF [183]

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer trusted/restricted ==========

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2018-04-11 16:38 - 2018-04-11 16:36 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\iCLS\;C:\Program Files\Intel\Intel(R) Management Engine Components\iCLS\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;C:\Program Files\Microsoft SQL Server\100\Tools\Binn\;C:\Program Files\Microsoft SQL Server\100\DTS\Binn\;C:\Program Files (x86)\QuickTime\QTSystem\
HKU\S-1-5-21-131675017-3346686803-3792727656-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\asus\wallpapers\asus.jpg
DNS Servers: 8.8.8.8 - 192.168.10.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is disabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run32: => "Dropbox"
HKU\S-1-5-21-131675017-3346686803-3792727656-1002\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-131675017-3346686803-3792727656-1002\...\StartupApproved\Run: => "QMxNetworkSync"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{7937A23F-4657-4188-9457-FAF470AF86FD}] => (Allow) C:\Program Files\Microsoft SQL Server\MSSQL10_50.ACT7\MSSQL\Binn\sqlservr.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{4850843C-0430-4FB5-BAA3-FFE763DCC770}] => (Allow) C:\Program Files\Microsoft SQL Server\MSSQL10_50.ACT7\MSSQL\Binn\sqlservr.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{8442A8D1-4753-4E3F-9DCF-662D0CBC722D}] => (Allow) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{236ACDD7-F5D8-4559-A0C4-8A032888137C}] => (Allow) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D518AACE-6F0D-4586-9E08-AD8B9BFFA7D7}] => (Allow) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Arvato Digital Services Canada Inc -> arvato digital services llc)
FirewallRules: [{B9C6EF4E-6B21-4802-B858-54103B8D4291}] => (Allow) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Arvato Digital Services Canada Inc -> arvato digital services llc)
FirewallRules: [{6A18A6F3-39DB-4704-91F7-1CD2F5A96FD9}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act.Server.Host.exe (Microsoft) [File not signed] [File is in use]
FirewallRules: [{02071AC5-D228-43A3-A76F-DD9E4F11A50B}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act.Server.Host.exe (Microsoft) [File not signed] [File is in use]
FirewallRules: [{70844CA0-C060-44EA-AAAA-F3557B9DFA85}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act15.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC)
FirewallRules: [{63878C5B-3FD8-4303-A890-87437C2F143F}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act15.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC)
FirewallRules: [{969F5F75-56EE-47A4-8DA3-5BD2DA816E9D}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\ActEmail.exe (Swiftpage ACT! LLC) [File not signed] [File is in use]
FirewallRules: [{F2643FF6-2E76-4955-A7C5-E96F2D57E1F0}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\ActEmail.exe (Swiftpage ACT! LLC) [File not signed] [File is in use]
FirewallRules: [{AE864CF9-995C-4B98-8716-78DD49B3332D}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act!.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC)
FirewallRules: [{16388773-440C-48B9-BF22-C5837945412C}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act!.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC)
FirewallRules: [{83FC276E-33E3-4217-91AA-A44EDC29B817}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{31C55C18-67E1-4E6B-8DC4-2593FACE9F1C}] => (Allow) C:\Program Files\MAGIX\Samplitude Music Studio\2019\MusicStudio.exe (MAGIX Software GmbH -> MAGIX Software GmbH)
FirewallRules: [{39748117-8DC5-4243-8A67-459AB864FD0B}] => (Allow) C:\Program Files (x86)\MAGIX\Music Maker\28\MusicMaker.exe (MAGIX Software GmbH -> MAGIX Software GmbH)
FirewallRules: [{E5C68139-03F6-450A-A955-0E815383C78C}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{A71D9024-5534-4BC3-A544-6685DDCEEBC4}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{286A06A9-321A-4AE1-AA2D-87F5925E46A6}C:\program files (x86)\corel\wordperfect office 2002\register\navbrowser.exe] => (Allow) C:\program files (x86)\corel\wordperfect office 2002\register\navbrowser.exe (Naviant, Inc.) [File not signed] [File is in use]
FirewallRules: [TCP Query User{0F755A48-DDCE-48BB-A641-36796431C436}C:\program files (x86)\corel\wordperfect office 2002\register\navbrowser.exe] => (Allow) C:\program files (x86)\corel\wordperfect office 2002\register\navbrowser.exe (Naviant, Inc.) [File not signed] [File is in use]
FirewallRules: [{5829778B-927D-4645-9F6C-73BDB1FCE1AD}] => (Allow) C:\Program Files\Microsoft SQL Server\MSSQL10_50.ACT7\MSSQL\Binn\sqlservr.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{587B3420-16CC-45B7-AA9C-D433045051E6}] => (Allow) C:\Program Files\Microsoft SQL Server\MSSQL10_50.ACT7\MSSQL\Binn\sqlservr.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{898CFB39-3F1E-434B-990E-4190707B2424}] => (Allow) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{AB7FB710-7411-4776-A8A9-519BB83AA1F9}] => (Allow) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{23CF8E6F-D7B4-4EC6-AECC-03DEA8730CC8}] => (Allow) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Arvato Digital Services Canada Inc -> arvato digital services llc)
FirewallRules: [{36B1C6BE-AD5D-468E-840E-1F46E0CEAB12}] => (Allow) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Arvato Digital Services Canada Inc -> arvato digital services llc)
FirewallRules: [{53A3352E-756F-4BF6-9D00-3A9CEFB613E7}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act.Server.Host.exe (Microsoft) [File not signed] [File is in use]
FirewallRules: [{CD2FC46C-6489-4912-B474-FD945403C188}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act.Server.Host.exe (Microsoft) [File not signed] [File is in use]
FirewallRules: [{182D664B-912D-42FB-A1E1-26EA3F2763DE}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act15.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC)
FirewallRules: [{3F6439CC-499B-41B5-B09D-212BE3DED12A}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act15.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC)
FirewallRules: [{678D9ED1-7BA2-4216-8655-81D5E4A2DCD5}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\ActEmail.exe (Swiftpage ACT! LLC) [File not signed] [File is in use]
FirewallRules: [{2F032D96-7FA2-4FFC-B8B6-C6A35A0C12D5}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\ActEmail.exe (Swiftpage ACT! LLC) [File not signed] [File is in use]
FirewallRules: [{F19D14E7-1492-4793-A1CD-6115278C7B2C}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act!.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC)
FirewallRules: [{C5D3BC0D-5FA6-4022-8DFB-0B6F52090134}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act!.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC)
FirewallRules: [{F6FAE180-4C56-4468-9C9A-5F60F3FFD6B3}] => (Allow) C:\Program Files\Microsoft SQL Server\MSSQL10_50.ACT7\MSSQL ()
FirewallRules: [{76D57CB5-AEC9-4782-A01C-BDB344A7D046}] => (Allow) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{80ED20B0-3CA5-43E8-99C6-E88D3FD89393}] => (Allow) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Arvato Digital Services Canada Inc -> arvato digital services llc)
FirewallRules: [{17D0B180-07DB-4EC3-A0E4-596D469F324A}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe => No File
FirewallRules: [{A14BF976-27E0-4750-9A1F-AFABAB9FC0E0}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe => No File
FirewallRules: [{3445F090-653A-42AD-ABA2-07A6971665DF}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe => No File
FirewallRules: [{EBC6B69B-163A-4AF6-A7EE-DE95CD3029F8}] => (Allow) C:\Program Files\WindowsApps\Microsoft.Office.Desktop.Outlook_16051.12827.20336.0_x86__8wekyb3d8bbwe\Office16\OUTLOOK.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{467BE0C2-A4F8-4EBC-8C72-F8E645E2A378}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{830D7612-3572-4636-89ED-37E364DAD9A0}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\84.0.4147.39\remoting_host.exe (Google LLC -> Google Inc.)
FirewallRules: [{C71895E3-8299-4703-9A46-78550595C17A}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{2CF14EB2-229A-45FD-97BD-D0135784C5CB}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{2108C6A7-5224-4408-BAC0-19639A0169A7}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{E97F746B-77E7-4B4C-9CE7-2BA869D99907}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)

==================== Restore Points =========================

23-06-2020 12:13:35 06/23/2020 before windows update at 12:13pm

==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (06/28/2020 09:06:49 AM) (Source: Desktop History Queue Provider) (EventID: 0) (User: )
Description: Restarting the timer to handle future records

Error: (06/28/2020 09:06:49 AM) (Source: Desktop History Queue Provider) (EventID: 0) (User: )
Description: Setting Processing to False

Error: (06/28/2020 09:06:49 AM) (Source: Desktop History Queue Provider) (EventID: 0) (User: )
Description: Queues Have Been Processed

Error: (06/28/2020 09:06:49 AM) (Source: Desktop History Queue Provider) (EventID: 0) (User: )
Description: ProcessingQueueSize is: 0

Error: (06/28/2020 09:06:49 AM) (Source: Desktop History Queue Provider) (EventID: 0) (User: )
Description: ProcessingQueues

Error: (06/28/2020 09:06:49 AM) (Source: Desktop History Queue Provider) (EventID: 0) (User: )
Description: Stopped the Queues Timer

Error: (06/28/2020 09:06:03 AM) (Source: Act! Scheduler) (EventID: 0) (User: )
Description: Service cannot be started. System.Exception: Unable to start scheduler service. ScheduledItems count is less than or equal to 0.
   at Act.Scheduler.SchedulerService.OnStart(String[] args)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (06/28/2020 09:06:03 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: GiftBoxService.exe, version: 3.2.3.0, time stamp: 0x5b349c0a
Faulting module name: GiftBoxService.exe, version: 3.2.3.0, time stamp: 0x5b349c0a
Exception code: 0xc0000005
Fault offset: 0x0000642c
Faulting process id: 0x1098
Faulting application start time: 0x01d64d66056813b1
Faulting application path: C:\Program Files (x86)\ASUS\ASUS GiftBox Service\GiftBoxService.exe
Faulting module path: C:\Program Files (x86)\ASUS\ASUS GiftBox Service\GiftBoxService.exe
Report Id: bd4b38d7-6bc9-400d-9532-44dadff7fc9b
Faulting package full name: 
Faulting package-relative application ID:


System errors:
=============
Error: (06/29/2020 09:57:58 AM) (Source: bowser) (EventID: 8003) (User: )
Description: The master browser has received a server announcement from the computer LINKSYS01345
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{16701CE0-2BD6-458B-974B-3425A244C327}.
The master browser is stopping or an election is being forced.

Error: (06/29/2020 08:57:22 AM) (Source: bowser) (EventID: 8003) (User: )
Description: The master browser has received a server announcement from the computer LINKSYS01345
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{16701CE0-2BD6-458B-974B-3425A244C327}.
The master browser is stopping or an election is being forced.

Error: (06/29/2020 07:57:17 AM) (Source: bowser) (EventID: 8003) (User: )
Description: The master browser has received a server announcement from the computer LINKSYS01345
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{16701CE0-2BD6-458B-974B-3425A244C327}.
The master browser is stopping or an election is being forced.

Error: (06/29/2020 06:32:29 AM) (Source: bowser) (EventID: 8003) (User: )
Description: The master browser has received a server announcement from the computer LINKSYS01345
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{16701CE0-2BD6-458B-974B-3425A244C327}.
The master browser is stopping or an election is being forced.

Error: (06/28/2020 09:09:09 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The ASUS GiftBox Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (06/28/2020 09:07:06 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the GiftBox.Service service.

Error: (06/28/2020 09:06:36 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the GiftBox.Service service.

Error: (06/28/2020 09:05:10 AM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: The Malwarebytes Service service did not shut down properly after receiving a preshutdown control.


Windows Defender:
===================================
Date: 2020-06-25 11:12:16.5470000Z
Description: 
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=Program:Win32/Uwasson.A!ml&threatid=251745&enterprise=0
Name: Program:Win32/Uwasson.A!ml
ID: 251745
Severity: Low
Category: Potentially Unwanted Software
Path: amsi:_C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
Detection Origin: Unknown
Detection Type: Concrete
Detection Source: AMSI
Process Name: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
Security intelligence Version: AV: 1.317.1134.0, AS: 1.317.1134.0, NIS: 1.317.1134.0
Engine Version: AM: 1.1.17100.2, NIS: 1.1.17100.2

Date: 2020-06-22 10:13:16.5750000Z
Description: 
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=Program:Win32/Uwasson.A!ml&threatid=251745&enterprise=0
Name: Program:Win32/Uwasson.A!ml
ID: 251745
Severity: Low
Category: Potentially Unwanted Software
Path: amsi:_C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
Detection Origin: Unknown
Detection Type: Concrete
Detection Source: AMSI
Process Name: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
Security intelligence Version: AV: 1.317.1134.0, AS: 1.317.1134.0, NIS: 1.317.1134.0
Engine Version: AM: 1.1.17100.2, NIS: 1.1.17100.2

Date: 2020-06-22 10:12:36.1630000Z
Description: 
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=Program:Win32/Uwasson.A!ml&threatid=251745&enterprise=0
Name: Program:Win32/Uwasson.A!ml
ID: 251745
Severity: Low
Category: Potentially Unwanted Software
Path: amsi:_C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
Detection Origin: Unknown
Detection Type: Concrete
Detection Source: AMSI
Process Name: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
Security intelligence Version: AV: 1.317.1134.0, AS: 1.317.1134.0, NIS: 1.317.1134.0
Engine Version: AM: 1.1.17100.2, NIS: 1.1.17100.2

Date: 2020-06-19 07:10:03.6900000Z
Description: 
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=Program:Win32/Uwasson.A!ml&threatid=251745&enterprise=0
Name: Program:Win32/Uwasson.A!ml
ID: 251745
Severity: Low
Category: Potentially Unwanted Software
Path: amsi:_C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
Detection Origin: Unknown
Detection Type: Concrete
Detection Source: AMSI
Process Name: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
Security intelligence Version: AV: 1.317.1134.0, AS: 1.317.1134.0, NIS: 1.317.1134.0
Engine Version: AM: 1.1.17100.2, NIS: 1.1.17100.2

Date: 2020-06-18 09:05:03.9030000Z
Description: 
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=Program:Win32/Uwasson.A!ml&threatid=251745&enterprise=0
Name: Program:Win32/Uwasson.A!ml
ID: 251745
Severity: Low
Category: Potentially Unwanted Software
Path: amsi:_C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
Detection Origin: Unknown
Detection Type: Concrete
Detection Source: AMSI
Process Name: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
Security intelligence Version: AV: 1.317.1134.0, AS: 1.317.1134.0, NIS: 1.317.1134.0
Engine Version: AM: 1.1.17100.2, NIS: 1.1.17100.2

Date: 2020-06-22 10:14:54.9870000Z
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.317.1134.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.17100.2
Error code: 0x80240017
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. 

Date: 2020-06-10 21:49:50.1860000Z
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.317.483.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.17100.2
Error code: 0x8007045b
Error description: A system shutdown is in progress. 

CodeIntegrity:
===================================

Date: 2020-06-29 06:29:28.6840000Z
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2020-06-29 06:29:28.0580000Z
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2020-06-29 06:29:26.6420000Z
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2020-06-29 06:29:26.1550000Z
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2020-06-29 06:29:24.5740000Z
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2020-06-29 06:29:23.9020000Z
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2020-06-29 06:28:49.7680000Z
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2020-06-29 06:28:49.7510000Z
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

==================== Memory info =========================== 

BIOS: American Megatrends Inc. 301 08/21/2018
Motherboard: ASUSTeK COMPUTER INC. V272UA
Processor: Intel(R) Core(TM) i5-8250U CPU @ 1.60GHz
Percentage of memory in use: 22%
Total physical RAM: 32655.1 MB
Available physical RAM: 25430.09 MB
Total Virtual: 37519.1 MB
Available Virtual: 29946.26 MB

==================== Drives ================================

Drive 😄 (Windows) (Fixed) (Total:1907.1 GB) (Free:764.76 GB) NTFS
Drive d: (My Book) (Fixed) (Total:5589 GB) (Free:1477.73 GB) NTFS
Drive e: (DATA) (Fixed) (Total:3725.9 GB) (Free:221.91 GB) NTFS
Drive f: (My Book) (Fixed) (Total:5589 GB) (Free:847.61 GB) NTFS
Drive p: (Windows) (Network) (Total:1907.1 GB) (Free:764.76 GB) NTFS
Drive y: (Windows) (Network) (Total:1907.1 GB) (Free:764.76 GB) NTFS

\\?\Volume{32123bc8-773a-48a1-a209-7bbd9435f14d}\ () (Fixed) (Total:0.51 GB) (Free:0.08 GB) NTFS
\\?\Volume{3690d6b4-1e22-42dc-9fd7-97069e42e4a2}\ (SYSTEM) (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 1907.7 GB) (Disk ID: B92FD1AB)

Partition: GPT.

==========================================================
Disk: 1 (Size: 5589 GB) (Disk ID: 16F2A91F)

Partition: GPT.
Attempted reading MBR returned 0 bytes.
 Could not read MBR for disk 2.

==========================================================
Disk: 3 (Size: 3726 GB) (Disk ID: 107B8359)

Partition: GPT.

==================== End of Addition.txt =======================

 

MIND YOU, I STILL HAVE WINDOWS POWER SHELL TEMPORARILY DELETED FROM THE TASK WINDOW.

 

THANK YOU FOR HELPING.

 

Link to post
Share on other sites

Hiya EEPers,

Thanks for those logs, continue please:

Download attached fixlist.txt file (end of reply) and save it to the Desktop, or the folder you saved FRST into. "Do not open that file when running FRST fix"
NOTE. It's important that both FRST and fixlist.txt are in the same location or the fix will not work.

Open FRST and press the Fix button just once and wait.
The tool will make a log on the Desktop (Fixlog.txt) or the folder it was ran from. Please post it to your reply.

Next,

Open Malwarebytes, select > "settings" > "security tab"

Scroll down to "Scan Options" ensure Scan for Rootkits and Scan within Archives are both on....

Go back to "DashBoard" select the Blue "Scan Now" tab......

When the scan completes quarantine any found entries...

To get the log from Malwarebytes do the following:
 
  • Single click on the target sight above scanner window.
  • In the new window select Report
  • Double click on the Scan log which shows the Date and time of the scan just performed.
  • Click Export > From export you have two options:
    Copy to Clipboard - if seleted right click to your reply and select "Paste" log will be pasted to your reply
    Export toTxt - if selected you will have to name the file and save to a place of choice, recommend "Desktop" then attach to reply

     
  • Please use "Export to Txt" then attach the log to your reply...


Next,

Download AdwCleaner by Malwarebytes onto your Desktop.

Or from this Mirror
 
  • Right-click on AdwCleaner.exe and select user posted imageRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Accept the EULA (I accept), then click on Scan
  • Let the scan complete. Once it's done, make sure that every item listed in the different tabs is checked and click on the Quarantine button. This will kill all the active processes
  • Once the cleaning process is complete, AdwCleaner will ask to restart your computer, do it
  • After the restart, a log will open when logging in. Please copy/paste the content of that log in your next reply


Next,

Download "Microsoft's Safety Scanner" and save direct to the desktop

Ensure to get the correct version for your system....

https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/safety-scanner-download


Right click on the Tool, select “Run as Administrator” the tool will expand to the options Window
In the "Scan Type" window, select Quick Scan
Perform a scan and Click Finish when the scan is done.


Retrieve the MSRT log as follows, and post it in your next reply:

1) Select the Windows key and R key together to open the "Run" function
2) Type or Copy/Paste the following command to the "Run Line" and Press Enter:

notepad c:\windows\debug\mrt.log

The log will include log details for each time MSRT has run, we only need the most recent log by date and time....

Let me see those logs in your next reply...

Thank you,

Kevin..

 

fixlist.txt

Link to post
Share on other sites

Fix result of Farbar Recovery Scan Tool (x64) Version: 30-06-2020
Ran by elain (30-06-2020 07:34:54) Run:1
Running from C:\Users\elain\Downloads
Loaded Profiles: elain
Boot Mode: Normal
==============================================

fixlist content:
*****************
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
HKU\S-1-5-21-131675017-3346686803-3792727656-1002\...\RunOnce: [Application Restart #3] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe  --user-data-dir="C:\Users\elain\AppData\Local\Temp\\{0EEDB3FB-1591-70AF-0F22-19A4B3765D18}_CR" --no-sandbox --allow-no-sandbox-job --disabl (the data entry has 154 more characters). <==== ATTENTION
2020-06-22 07:34 - 2020-06-22 07:34 - 000114688 _____ C:\Users\elain\AppData\Roaming\JfQPKiheALIH
2020-06-22 07:34 - 2020-06-22 07:34 - 000000662 _____ C:\Users\elain\AppData\Roaming\JfQPKiheALIH.cMD
2020-06-22 07:33 - 2020-06-22 07:33 - 000114688 _____ C:\Users\elain\AppData\Roaming\puWJErhMmRyz
2020-06-22 07:33 - 2020-06-22 07:33 - 000000662 _____ C:\Users\elain\AppData\Roaming\puWJErhMmRyz.cMD
2020-05-16 11:10 - 2020-05-16 11:10 - 000071000 _____ () C:\Users\elain\AppData\Roaming\WvMSIJCpwORq
2020-05-16 11:10 - 2020-05-16 11:10 - 000000662 _____ () C:\Users\elain\AppData\Roaming\WvMSIJCpwORq.Cmd
AlternateDataStreams: C:\ProgramData\TEMP:065D25EE [358]
AlternateDataStreams: C:\ProgramData\TEMP:0FD841FF [183] 
FirewallRules: [{17D0B180-07DB-4EC3-A0E4-596D469F324A}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe => No File
FirewallRules: [{A14BF976-27E0-4750-9A1F-AFABAB9FC0E0}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe => No File
FirewallRules: [{3445F090-653A-42AD-ABA2-07A6971665DF}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe => No File
CMD: winmgmt /verifyrepository
Hosts:
EmptyTemp:

*****************

Processes closed successfully.
SystemRestore: On => completed
Restore point was successfully created.
"HKU\S-1-5-21-131675017-3346686803-3792727656-1002\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Application Restart #3" => removed successfully
C:\Users\elain\AppData\Roaming\JfQPKiheALIH => moved successfully
C:\Users\elain\AppData\Roaming\JfQPKiheALIH.cMD => moved successfully
C:\Users\elain\AppData\Roaming\puWJErhMmRyz => moved successfully
C:\Users\elain\AppData\Roaming\puWJErhMmRyz.cMD => moved successfully
C:\Users\elain\AppData\Roaming\WvMSIJCpwORq => moved successfully
C:\Users\elain\AppData\Roaming\WvMSIJCpwORq.Cmd => moved successfully
C:\ProgramData\TEMP => ":065D25EE" ADS removed successfully
C:\ProgramData\TEMP => ":0FD841FF" ADS removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{17D0B180-07DB-4EC3-A0E4-596D469F324A}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A14BF976-27E0-4750-9A1F-AFABAB9FC0E0}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3445F090-653A-42AD-ABA2-07A6971665DF}" => removed successfully

========= winmgmt /verifyrepository =========

WMI repository is consistent

========= End of CMD: =========

C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 10248192 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 286009652 B
Java, Flash, Steam htmlcache => 735 B
Windows/system/drivers => 19495458 B
Edge => 10823619 B
Chrome => 1355784471 B
Firefox => 1329371088 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 269862 B
NetworkService => 319926 B
elain => 129708721 B

RecycleBin => 0 B
EmptyTemp: => 2.9 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 07:42:18 ====

Link to post
Share on other sites

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 6/30/20
Scan Time: 7:53 AM
Log File: 78ce5a3a-bae1-11ea-b415-dcf5054c5e90.json

-Software Information-
Version: 4.1.0.56
Components Version: 1.0.955
Update Package Version: 1.0.26201
License: Premium

-System Information-
OS: Windows 10 (Build 19041.329)
CPU: x64
File System: NTFS
User: EEPHOMEOFFICE\elain

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 329314
Threats Detected: 0
Threats Quarantined: 0
Time Elapsed: 0 min, 56 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 0
(No malicious items detected)

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)

Link to post
Share on other sites

FROM ADWCLEANER:

 

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 6/30/20
Scan Time: 7:53 AM
Log File: 78ce5a3a-bae1-11ea-b415-dcf5054c5e90.json

-Software Information-
Version: 4.1.0.56
Components Version: 1.0.955
Update Package Version: 1.0.26201
License: Premium

-System Information-
OS: Windows 10 (Build 19041.329)
CPU: x64
File System: NTFS
User: EEPHOMEOFFICE\elain

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 329314
Threats Detected: 0
Threats Quarantined: 0
Time Elapsed: 0 min, 56 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled

# -------------------------------
# Malwarebytes AdwCleaner 8.0.5.0
# -------------------------------
# Build:    05-25-2020
# Database: 2020-06-15.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start:    06-30-2020
# Duration: 00:00:02
# OS:       Windows 10 Home
# Cleaned:  22
# Failed:   1


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted       HKLM\Software\Conduit

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

Deleted       Preinstalled.ASUSDeviceActivation   Folder   C:\Program Files (x86)\ASUS\ASUS DEVICE ACTIVATION
Deleted       Preinstalled.ASUSDeviceActivation   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{9C4B0706-9F9A-47BF-B417-0A111FC52B04}
Deleted       Preinstalled.ASUSGiftBox   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{4701E5AB-AF91-4D40-8F18-358CC80E4E5B}
Deleted       Preinstalled.ASUSHello   Folder   C:\Program Files (x86)\ASUS\ASUS HELLO
Deleted       Preinstalled.ASUSHello   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9486D21E-E9EB-43F8-85AF-E3EC0FCF2A9A} 
Deleted       Preinstalled.ASUSHello   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASUS Hello
Deleted       Preinstalled.ASUSHello   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{D8CE1923-92A9-4036-817E-9E0D8AA2169B}
Deleted       Preinstalled.ASUSHello   Task   C:\Windows\System32\Tasks\ASUS HELLO
Deleted       Preinstalled.ASUSLiveUpdate   Folder   C:\Program Files (x86)\ASUS\ASUS LIVE UPDATE
Deleted       Preinstalled.ASUSLiveUpdate   Folder   C:\ProgramData\ASUS\ASUS LIVE UPDATE
Deleted       Preinstalled.ASUSLiveUpdate   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AAF27842-7BD7-422C-9FCA-415FCB87001F} 
Deleted       Preinstalled.ASUSLiveUpdate   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update Checker
Deleted       Preinstalled.ASUSLiveUpdate   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}
Deleted       Preinstalled.ASUSLiveUpdate   Task   C:\Windows\System32\Tasks\UPDATE CHECKER
Deleted       Preinstalled.ASUSProductRegistration   Folder   C:\ProgramData\ASUS\APRP
Deleted       Preinstalled.ASUSSplendid   Folder   C:\Program Files (x86)\ASUS\SPLENDID
Deleted       Preinstalled.ASUSSplendid   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{180AB9D4-E685-40A9-A6A2-D23D35C7C381} 
Deleted       Preinstalled.ASUSSplendid   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASUS Splendid ACMON
Deleted       Preinstalled.ASUSSplendid   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{0969AF05-4FF6-4C00-9406-43599238DE0D}
Deleted       Preinstalled.ASUSSplendid   Task   C:\Windows\System32\Tasks\ASUS SPLENDID ACMON
Deleted       Preinstalled.CyberLinkService   Folder   C:\Program Files\CYBERLINK\SHARED FILES\PLUGIN\NEWBLUE
Not Deleted   Preinstalled.ASUSGiftBox   Folder   C:\Program Files (x86)\ASUS\ASUS GIFTBOX SERVICE


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [4123 octets] - [30/06/2020 08:17:14]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
 

Link to post
Share on other sites

THIS TEXT POPPED UP WHEN OPENING A REPLY, DON'T KNOW IF IT'S RELEVANT:

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 6/30/20
Scan Time: 7:53 AM
Log File: 78ce5a3a-bae1-11ea-b415-dcf5054c5e90.json

-Software Information-
Version: 4.1.0.56
Components Version: 1.0.955
Update Package Version: 1.0.26201
License: Premium

-System Information-
OS: Windows 10 (Build 19041.329)
CPU: x64
File System: NTFS
User: EEPHOMEOFFICE\elain

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 329314
Threats Detected: 0
Threats Quarantined: 0
Time Elapsed: 0 min, 56 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 0
(No malicious items detected)

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)

 

COULD NOT GET A LOG, BUT I DID A VIEW SECOND TIME AROUND:

 

cannotfind mrtlog.jpg

microsoft safety scanner.JPG

Link to post
Share on other sites

I think it's running quite well and that trojan seems to keep dogging me now.  It did stop after I removed the windows power shell which it was attached to.  When I rebooted the windows power shell did not re-appear in the task menu and I don't know if that's of concern or not.

 

Outside that, thank you for giving me the aide and tools necessary to stop this.

 

Thank you Keven.

Link to post
Share on other sites

Hello EEPers,

Good to hear the issue has stopped and your system is ok again... All we need to do is finish up..

Right click on FRST here: C:\Users\elain\Downloads\FRST64.exe and rename uninstall.exe when complete right click on uninstall.exe and select "Run as Administrator"

If you do not see the .exe appended that is because file extensions are hidden, in that case just rename FRST64 to uninstall

That action will remove FRST and all created files and folders...

Next,

Remove all System Restore Points: https://www.tenforums.com/tutorials/33593-delete-system-restore-points-windows-10-a.html#option2

Create clean fresh Restore Point: http://www.thewindowsclub.com/create-system-restore-point

Run Windows Disk Clean Up Utility - https://neosmart.net/wiki/disk-cleanup/

From there you should be good to go...

Next,

Read the following links to fully understand PC Security and Best Practices, you may find them useful....

Answers to Common Security Questions and best Practices

Do I need a Registry Cleaner?

Take care and surf safe

Kevin... user posted image
Link to post
Share on other sites

Support followed up right before you request here.  She examined and praised your help, but asked that I download a fixlist and get the most current log, which is:

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 30-06-2020
Ran by elain (01-07-2020 11:06:05) Run:2
Running from C:\Users\elain\Downloads
Loaded Profiles: elain
Boot Mode: Normal
==============================================

fixlist content:
*****************
Startup: C:\Users\elain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JfQPKiheALIH.lnK [2020-06-22]
ShortcutAndArgument: JfQPKiheALIH.lnK -> C:\Users\elain\AppData\Roaming\JfQPKiheALIH.Cmd => 
Startup: C:\Users\elain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\puWJErhMmRyz.lnK [2020-06-22]
ShortcutAndArgument: puWJErhMmRyz.lnK -> C:\Users\elain\AppData\Roaming\puWJErhMmRyz.Cmd => 
Startup: C:\Users\elain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WvMSIJCpwORq.LNk [2020-05-16]
ShortcutAndArgument: WvMSIJCpwORq.LNk -> C:\Users\elain\AppData\Roaming\WvMSIJCpwORq.cMD => 
2020-06-22 07:34 - 2020-06-22 07:34 - 000114688 _____ () C:\Users\elain\AppData\Roaming\JfQPKiheALIH
2020-06-22 07:34 - 2020-06-22 07:34 - 000000662 _____ () C:\Users\elain\AppData\Roaming\JfQPKiheALIH.cMD
2020-06-22 07:33 - 2020-06-22 07:33 - 000114688 _____ () C:\Users\elain\AppData\Roaming\puWJErhMmRyz
2020-06-22 07:33 - 2020-06-22 07:33 - 000000662 _____ () C:\Users\elain\AppData\Roaming\puWJErhMmRyz.cMD
2020-05-16 11:10 - 2020-05-16 11:10 - 000071000 _____ () C:\Users\elain\AppData\Roaming\WvMSIJCpwORq
2020-05-16 11:10 - 2020-05-16 11:10 - 000000662 _____ () C:\Users\elain\AppData\Roaming\WvMSIJCpwORq.Cmd

*****************

C:\Users\elain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JfQPKiheALIH.lnK => moved successfully
ShortcutAndArgument: JfQPKiheALIH.lnK -> C:\Users\elain\AppData\Roaming\JfQPKiheALIH.Cmd => => Error: No automatic fix found for this entry.
C:\Users\elain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\puWJErhMmRyz.lnK => moved successfully
ShortcutAndArgument: puWJErhMmRyz.lnK -> C:\Users\elain\AppData\Roaming\puWJErhMmRyz.Cmd => => Error: No automatic fix found for this entry.
C:\Users\elain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WvMSIJCpwORq.LNk => moved successfully
ShortcutAndArgument: WvMSIJCpwORq.LNk -> C:\Users\elain\AppData\Roaming\WvMSIJCpwORq.cMD => => Error: No automatic fix found for this entry.
"C:\Users\elain\AppData\Roaming\JfQPKiheALIH" => not found
"C:\Users\elain\AppData\Roaming\JfQPKiheALIH.cMD" => not found
"C:\Users\elain\AppData\Roaming\puWJErhMmRyz" => not found
"C:\Users\elain\AppData\Roaming\puWJErhMmRyz.cMD" => not found
"C:\Users\elain\AppData\Roaming\WvMSIJCpwORq" => not found
"C:\Users\elain\AppData\Roaming\WvMSIJCpwORq.Cmd" => not found

==== End of Fixlog 11:06:05 ====

 

Are we good or is there more to do?

Link to post
Share on other sites

Glad we could help.

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this topic with your request.

This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread.

Please review the following for Tips to help protect from infection

Thank you

 

 

Link to post
Share on other sites
Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.