Desktop ethernet connection stopped working overnight... may be an infection

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • nick1234
    PCHF Member
    • Jun 2017
    • 4

    #1

    Desktop ethernet connection stopped working overnight... may be an infection

    I was redirected here by a user in a different channel, who after looking at my MiniToolBox logs, said that he believes there is an infection of some sort causing my computer issues.

    Back story:
    My desktop stopped connecting to the internet using my laptop… I don’t know why, it happened over night, and I woke up to a broken connection. I’ve tried ipconfig /release, and /renew, however when i type in renew i get the error:

    An error occured while renewing interface Ethernet: unable to contact your DHCP server. Request has timed out

    I have already tried resetting the adapter on both computers, and the winsh winsock jargon on my desktop. What could be the issue, and why is it all of the sudden just not working? My desktop lists the network, but says identifying, or simply “Unidentified Network - No Internet Connection.” It did not do this before, and I did not change anything. I did notice my computer slowed down for a weird stretch last night and FPS spiked while playing a game of League… My windows explorer also crashed, which i reset and it fixed the issue. Could that be all interconnected? It makes zero sense, and I even went and did a full reset on my desktop using the Win10 reset feature, and still nothing! Help!

    And the Logs:
    FRST:

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-06-2017
    Ran by Nick (administrator) on DESKTOP-SSRSVP2 (14-06-2017 21:24:49)
    Running from C:\Users\Nick\Desktop
    Loaded Profiles: Nick (Available Profiles: defaultuser0 & Nick)
    Platform: Windows 10 Pro Version 1607 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: Edge)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (AMD) C:\Windows\System32\atiesrxx.exe
    (AMD) C:\Windows\System32\atieclxx.exe
    (DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
    () C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.ex e
    (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
    (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.82_none _5be7b69702339d1d\TiWorker.exe
    (Microsoft Corporation) C:\Windows\System32\smartscreen.exe

    ==================== Registry (Whitelisted) ====================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM...\Run: [SynTPEnh] => %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
    HKLM...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2017-06-14] (Microsoft Corporation)
    HKLM...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800 2015-06-24] (Realtek Semiconductor)
    HKLM...\Run: [RtHDVBg_DTS] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-24] (Realtek Semiconductor)
    HKLM...\Run: [StartCN] => C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [6613896 2016-06-24] (Advanced Micro Devices, Inc.)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
    [HEADING=1]Internet Explorer:[/HEADING]
    ==================== Services (Whitelisted) ====================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [138752 2016-06-24] () [File not signed]
    R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [249328 2015-06-24] (DTS, Inc)
    S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2017-06-14] (Microsoft Corporation)
    R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2017-06-14] (Microsoft Corporation)
    R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2017-06-14] (Microsoft Corporation)

    ===================== Drivers (Whitelisted) ======================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S0 amdkmafd; C:\WINDOWS\System32\drivers\amdkmafd.sys [23240 2016-03-21] (Advanced Micro Devices, Inc.)
    R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [110096 2016-04-26] (Advanced Micro Devices)
    S3 dg_ssudbus; C:\WINDOWS\System32\drivers\ssudbus.sys [129152 2016-04-25] (Samsung Electronics Co., Ltd.)
    S3 e1cexpress; C:\WINDOWS\system32\DRIVERS\e1c64x64.sys [468240 2013-08-21] (Intel Corporation)
    R3 i8042HDR; C:\WINDOWS\System32\drivers\i8042HDR.sys [15920 2009-08-15] (Windows (R) Codename Longhorn DDK provider)
    S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
    S3 rzbtendpt; C:\WINDOWS\System32\drivers\rzbtendpt.sys [51912 2015-08-13] (Razer Inc)
    S3 rzdaendpt; C:\WINDOWS\System32\drivers\rzdaendpt.sys [43720 2015-08-13] (Razer Inc)
    R3 rzendpt; C:\WINDOWS\System32\drivers\rzendpt.sys [50392 2015-08-13] (Razer Inc)
    S3 rzhnet; C:\WINDOWS\System32\Drivers\rzhnet.sys [29912 2015-08-13] (Razer Inc)
    S3 rzjstk; C:\WINDOWS\System32\drivers\rzjstk.sys [36568 2015-08-13] (Razer Inc)
    S3 rzkeypadendpt; C:\WINDOWS\System32\drivers\rzkeypadendpt.sys [46280 2015-08-13] (Razer Inc)
    S3 rzmpos; C:\WINDOWS\System32\drivers\rzmpos.sys [48840 2015-08-13] (Razer Inc)
    S3 rzp1endpt; C:\WINDOWS\System32\drivers\rzp1endpt.sys [52424 2015-08-13] (Razer Inc)
    S3 rzvkeyboard; C:\WINDOWS\System32\drivers\rzvkeyboard.sys [44232 2015-08-13] (Razer Inc)
    S3 rzvmouse; C:\WINDOWS\System32\drivers\rzvmouse.sys [42712 2015-08-13] (Razer Inc)
    R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [33960 1999-12-31] (Synaptics Incorporated)
    S3 sscdserd; C:\WINDOWS\System32\drivers\sscdserd.sys [158024 2016-01-08] (MCCI Corporation)
    S3 ssceserd; C:\WINDOWS\System32\drivers\ssceserd.sys [158024 2016-01-08] (MCCI Corporation)
    S3 ssuddmgr; C:\WINDOWS\System32\drivers\ssuddmgr.sys [213088 2016-01-08] (DEVGURU Co., LTD.(www.devguru.co.kr))
    S3 ssudobex; C:\WINDOWS\System32\drivers\ssudobex.sys [213088 2016-01-08] (DEVGURU Co., LTD.(www.devguru.co.kr))
    S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [64640 2016-04-25] (QUALCOMM Incorporated)
    S3 ssudrmnet; C:\WINDOWS\System32\drivers\ssudrmnet.sys [77408 2016-01-08] (DEVGURU Co., LTD.)
    S3 ssudserd; C:\WINDOWS\System32\drivers\ssudserd.sys [213088 2016-01-08] (DEVGURU Co., LTD.(www.devguru.co.kr))
    S3 ss_conn_usb_driver; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver.sys [33376 2016-01-08] (DEVGURU Co., LTD.)
    S3 VBoxUSB; C:\WINDOWS\System32\Drivers\VBoxUSB.sys [125008 2016-01-19] (Oracle Corporation)
    S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
    R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
    R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2017-06-14 21:24 - 2017-06-14 21:25 - 00006807 _____ C:\Users\Nick\Desktop\FRST.txt
    2017-06-14 21:24 - 2017-06-14 21:24 - 00000000 ____D C:\FRST
    2017-06-14 21:24 - 2017-06-14 21:20 - 05200384 _____ (AVAST Software) C:\Users\Nick\Desktop\aswmbr.exe
    2017-06-14 21:18 - 2017-06-14 21:12 - 02438656 _____ (Farbar) C:\Users\Nick\Desktop\FRST64.exe
    2017-06-14 20:11 - 2017-06-14 20:11 - 00000000 ____D C:\Users\Nick\AppData\Local\Comms
    2017-06-14 20:03 - 2017-06-14 20:03 - 00000000 ____D C:\Users\Nick\AppData\Local\MicrosoftEdge
    2017-06-14 20:01 - 2017-06-14 20:01 - 00001296 _____ C:\Users\Nick\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\AMD Radeon Settings.lnk
    2017-06-14 19:58 - 2017-06-14 19:58 - 00000000 ____D C:\Users\Nick\AppData\Local\PeerDistRepub
    2017-06-14 19:56 - 2017-06-14 19:56 - 00002364 _____ C:\Users\Nick\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\OneDrive.lnk
    2017-06-14 19:56 - 2017-06-14 19:56 - 00000000 ___RD C:\Users\Nick\OneDrive
    2017-06-14 19:55 - 2017-06-14 19:55 - 00000000 ____D C:\Users\Nick\AppData\Local\AMD
    2017-06-14 19:55 - 2017-06-14 19:55 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
    2017-06-14 19:54 - 2017-06-14 19:54 - 00000000 ____D C:\Users\Nick\AppData\Local\Publishers
    2017-06-14 19:53 - 2017-06-14 21:23 - 00000000 ____D C:\Users\Nick
    2017-06-14 19:53 - 2017-06-14 20:43 - 00000000 ____D C:\Users\Nick\AppData\Local\ConnectedDevicesPlatfo rm
    2017-06-14 19:53 - 2017-06-14 20:11 - 00000000 ____D C:\Users\Nick\AppData\Local\Packages
    2017-06-14 19:53 - 2017-06-14 19:53 - 00000020 ___SH C:\Users\Nick\ntuser.ini
    2017-06-14 19:53 - 2017-06-14 19:53 - 00000000 _SHDL C:\Users\Nick\My Documents
    2017-06-14 19:53 - 2017-06-14 19:53 - 00000000 _SHDL C:\Users\Nick\Documents\My Videos
    2017-06-14 19:53 - 2017-06-14 19:53 - 00000000 _SHDL C:\Users\Nick\Documents\My Pictures
    2017-06-14 19:53 - 2017-06-14 19:53 - 00000000 _SHDL C:\Users\Nick\Documents\My Music
    2017-06-14 19:53 - 2017-06-14 19:53 - 00000000 __RHD C:\Users\Public\AccountPictures
    2017-06-14 19:53 - 2017-06-14 19:53 - 00000000 ____D C:\Users\Nick\AppData\Roaming\Adobe
    2017-06-14 19:53 - 2017-06-14 19:53 - 00000000 ____D C:\Users\Nick\AppData\Local\VirtualStore
    2017-06-14 19:53 - 2017-06-14 19:53 - 00000000 ____D C:\Users\Nick\AppData\Local\TileDataLayer
    2017-06-14 19:53 - 2017-06-14 19:53 - 00000000 ____D C:\Users\defaultuser0\AppData\Local\VirtualStore
    2017-06-14 19:53 - 2017-06-14 19:53 - 00000000 ____D C:\Users\defaultuser0\AppData\Local\Packages
    2017-06-14 19:52 - 2017-06-14 19:52 - 00000020 ___SH C:\Users\defaultuser0\ntuser.ini
    2017-06-14 19:52 - 2017-06-14 19:52 - 00000000 _SHDL C:\Users\defaultuser0\My Documents
    2017-06-14 19:52 - 2017-06-14 19:52 - 00000000 _SHDL C:\Users\defaultuser0\Documents\My Videos
    2017-06-14 19:52 - 2017-06-14 19:52 - 00000000 _SHDL C:\Users\defaultuser0\Documents\My Pictures
    2017-06-14 19:52 - 2017-06-14 19:52 - 00000000 _SHDL C:\Users\defaultuser0\Documents\My Music
    2017-06-14 19:52 - 2017-06-14 19:52 - 00000000 ____D C:\Users\defaultuser0\AppData\Local\TileDataLayer
    2017-06-14 19:52 - 2017-06-14 19:52 - 00000000 ____D C:\Users\defaultuser0\AppData\Local\ConnectedDevic esPlatform
    2017-06-14 19:52 - 2017-06-14 19:52 - 00000000 ____D C:\Users\defaultuser0
    2017-06-14 19:46 - 2017-06-14 20:05 - 00953534 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2017-06-14 19:43 - 2017-06-14 19:09 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
    2017-06-14 19:41 - 2017-06-14 19:41 - 00000000 _SHDL C:\Users\Public\Documents\My Videos
    2017-06-14 19:41 - 2017-06-14 19:41 - 00000000 _SHDL C:\Users\Public\Documents\My Pictures
    2017-06-14 19:41 - 2017-06-14 19:41 - 00000000 _SHDL C:\Users\Public\Documents\My Music
    2017-06-14 19:41 - 2017-06-14 19:41 - 00000000 _SHDL C:\Users\Default\My Documents
    2017-06-14 19:41 - 2017-06-14 19:41 - 00000000 _SHDL C:\Users\Default\Documents\My Videos
    2017-06-14 19:41 - 2017-06-14 19:41 - 00000000 _SHDL C:\Users\Default\Documents\My Pictures
    2017-06-14 19:41 - 2017-06-14 19:41 - 00000000 _SHDL C:\Users\Default\Documents\My Music
    2017-06-14 19:41 - 2017-06-14 19:41 - 00000000 _SHDL C:\Users\Default User\Documents\My Videos
    2017-06-14 19:41 - 2017-06-14 19:41 - 00000000 _SHDL C:\Users\Default User\Documents\My Pictures
    2017-06-14 19:41 - 2017-06-14 19:41 - 00000000 _SHDL C:\Users\Default User\Documents\My Music
    2017-06-14 19:41 - 2017-06-14 19:41 - 00000000 _SHDL C:\Users\Default User
    2017-06-14 19:41 - 2017-06-14 19:41 - 00000000 _SHDL C:\Users\All Users
    2017-06-14 19:41 - 2017-06-14 19:41 - 00000000 _SHDL C:\Documents and Settings
    2017-06-14 19:33 - 2017-06-14 19:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Settings
    2017-06-14 19:32 - 2017-06-14 19:32 - 00000000 ____D C:\Program Files\ATI Technologies
    2017-06-14 19:32 - 2017-06-14 19:32 - 00000000 ____D C:\Program Files (x86)\AMD
    2017-06-14 19:31 - 2017-06-14 20:00 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin
    2017-06-14 19:31 - 2017-06-14 19:32 - 00000000 ____D C:\ProgramData\Package Cache
    2017-06-14 19:31 - 2017-06-14 19:32 - 00000000 ____D C:\Program Files\AMD
    2017-06-14 19:31 - 2017-06-14 19:31 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
    2017-06-14 19:31 - 2017-06-14 19:31 - 00000000 ____D C:\AMD
    2017-06-14 19:30 - 2017-06-14 19:30 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_Smb_driver _Intel_01011.Wdf
    2017-06-14 19:30 - 2017-06-14 19:30 - 00000000 ____H C:\ProgramData\DP45977C.lfl
    2017-06-14 19:30 - 2017-06-14 19:30 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
    2017-06-14 19:30 - 2017-06-14 19:30 - 00000000 ____D C:\WINDOWS\system32\DAX2
    2017-06-14 19:30 - 2017-06-14 19:30 - 00000000 ____D C:\Program Files\Synaptics
    2017-06-14 19:30 - 2017-06-14 19:30 - 00000000 ____D C:\Program Files\Realtek
    2017-06-14 19:28 - 2017-06-14 19:28 - 00000000 ____D C:\ProgramData\USOShared
    2017-06-14 19:27 - 2017-06-14 19:27 - 00000000 ____D C:\WINDOWS\InfusedApps
    2017-06-14 19:26 - 2017-06-14 21:06 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
    2017-06-14 19:26 - 2017-06-14 20:01 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2017-06-14 19:26 - 2017-06-14 19:52 - 00000000 ___DC C:\WINDOWS\Panther
    2017-06-14 19:26 - 2017-06-14 19:26 - 00194192 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2017-06-14 19:26 - 2017-06-14 19:26 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
    2017-06-14 19:26 - 2017-06-14 19:26 - 00000000 ____D C:\WINDOWS\ServiceProfiles
    2017-06-14 19:26 - 2017-06-14 19:26 - 00000000 ____D C:\Windows.old
    2017-06-14 19:24 - 2017-06-14 19:24 - 00000000 ____D C:\WINDOWS\Setup
    2017-06-14 19:22 - 2017-06-14 19:12 - 00892416 _____ (Farbar) C:\Users\Nick\Desktop\MiniToolBox.exe
    2017-06-14 19:21 - 2017-06-14 19:21 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_ 00.Wdf
    2017-06-14 19:20 - 2017-06-14 19:20 - 00000000 ____D C:\WINDOWS\OCR
    2017-06-14 19:20 - 2017-06-14 19:20 - 00000000 ____D C:\Program Files\Reference Assemblies
    2017-06-14 19:20 - 2017-06-14 19:20 - 00000000 ____D C:\Program Files\MSBuild
    2017-06-14 19:20 - 2017-06-14 19:20 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
    2017-06-14 19:20 - 2017-06-14 19:20 - 00000000 ____D C:\Program Files (x86)\MSBuild
    2017-06-14 19:18 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm
    2017-06-14 19:18 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
    2017-06-14 19:18 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
    2017-06-14 19:18 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr
    2017-06-14 19:18 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
    2017-06-14 19:18 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\SysWOW64\0409
    2017-06-14 19:18 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\system32\winrm
    2017-06-14 19:18 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\system32\WCN
    2017-06-14 19:18 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\system32\slmgr
    2017-06-14 19:18 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
    2017-06-14 19:18 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\system32\0409
    2017-06-14 19:18 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\DigitalLocker
    2017-06-14 19:14 - 2017-06-14 19:09 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
    2017-06-14 19:14 - 2017-06-14 19:09 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
    2017-06-14 19:13 - 2017-06-14 19:10 - 00215943 _____ C:\WINDOWS\SysWOW64\dssec.dat
    2017-06-14 19:13 - 2017-06-14 19:10 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
    2017-06-14 19:13 - 2017-06-14 19:10 - 00000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT
    2017-06-14 19:12 - 2017-06-14 21:17 - 00000000 ___HD C:\Program Files\WindowsApps
    2017-06-14 19:12 - 2017-06-14 20:16 - 00000000 ____D C:\WINDOWS\AppReadiness
    2017-06-14 19:12 - 2017-06-14 19:53 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
    2017-06-14 19:12 - 2017-06-14 19:46 - 00000000 ____D C:\WINDOWS\system32\NDF
    2017-06-14 19:12 - 2017-06-14 19:45 - 00000000 ____D C:\WINDOWS\rescache
    2017-06-14 19:12 - 2017-06-14 19:44 - 00000000 ____D C:\WINDOWS\system32\spool
    2017-06-14 19:12 - 2017-06-14 19:44 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
    2017-06-14 19:12 - 2017-06-14 19:43 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2017-06-14 19:12 - 2017-06-14 19:40 - 00000000 ____D C:\WINDOWS\CSC
    2017-06-14 19:12 - 2017-06-14 19:36 - 00000000 ____D C:\WINDOWS\system32\Sysprep
    2017-06-14 19:12 - 2017-06-14 19:33 - 00000000 ___RD C:\WINDOWS\PrintDialog
    2017-06-14 19:12 - 2017-06-14 19:33 - 00000000 ___RD C:\WINDOWS\MiracastView
    2017-06-14 19:12 - 2017-06-14 19:33 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
    2017-06-14 19:12 - 2017-06-14 19:28 - 00000000 ____D C:\ProgramData\USOPrivate
    2017-06-14 19:12 - 2017-06-14 19:26 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
    2017-06-14 19:12 - 2017-06-14 19:20 - 00000000 ____D C:\WINDOWS\SystemApps
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ___SD C:\WINDOWS\system32\F12
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ___SD C:\WINDOWS\system32\dsc
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\SysWOW64\setup
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\SysWOW64\Com
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\system32\setup
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\system32\oobe
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\system32\MUI
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\system32\migwiz
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\system32\Dism
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\system32\Com
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\IME
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\Help
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ____D C:\Program Files\Windows Photo Viewer
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ____D C:\Program Files\Windows Defender
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ____D C:\Program Files\Common Files\System
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
    2017-06-14 19:12 - 2017-06-14 19:18 - 00000000 ____D C:\Program Files (x86)\Windows Defender
    2017-06-14 19:12 - 2017-06-14 19:13 - 00000000 ___SD C:\WINDOWS\SysWOW64\Nui
    2017-06-14 19:12 - 2017-06-14 19:13 - 00000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
    2017-06-14 19:12 - 2017-06-14 19:13 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
    2017-06-14 19:12 - 2017-06-14 19:13 - 00000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync
    2017-06-14 19:12 - 2017-06-14 19:13 - 00000000 ____D C:\WINDOWS\SysWOW64\icsxml
    2017-06-14 19:12 - 2017-06-14 19:13 - 00000000 ____D C:\WINDOWS\SysWOW64\downlevel
    2017-06-14 19:12 - 2017-06-14 19:13 - 00000000 ____D C:\WINDOWS\SysWOW64\Bthprops
    2017-06-14 19:12 - 2017-06-14 19:13 - 00000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 __SHD C:\WINDOWS\BitLockerDiscoveryVolumeContents
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 __SHD C:\Program Files\Windows Sidebar
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 __RSD C:\WINDOWS\Media
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 __RHD C:\Users\Public\Libraries
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ___SD C:\WINDOWS\SysWOW64\Configuration
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ___SD C:\WINDOWS\system32\Nui
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ___SD C:\WINDOWS\system32\Configuration
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ___RD C:\WINDOWS\Offline Web Pages
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\Web
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\Vss
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\tracing
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\TAPI
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\SysWOW64\ras
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\SysWOW64\NDF
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\SysWOW64\MsDtc
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\SysWOW64\Ipmi
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\SysWOW64\InputMethod
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicyUsers
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\SysWOW64\AppLocker
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\SystemResources
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\WinMetadata
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\winevt
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\SecureBootUpdates
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\ras
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\ProximityToast
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\PointOfService
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\MsDtc
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\Macromed
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\Ipmi
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\InputMethod
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\inetsrv
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\IME
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\icsxml
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\ias
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\GroupPolicyUsers
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\downlevel
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\DDFs
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\config\Journal
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\Bthprops
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\appraiser
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\AppLocker
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\AdvancedInstallers
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\System
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\SKB
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\ShellExperiences
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\security
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\schemas
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\SchCache
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\Resources
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\RemotePackages
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\Registration
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\Provisioning
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\PLA
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\Performance
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\ModemLogs
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\LiveKernelReports
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\L2Schemas
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\InputMethod
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\Globalization
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\GameBarPresenceWriter
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\Cursors
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\Branding
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\bcastdvr
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\appcompat
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\addins
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\ProgramData\Comms
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\Program Files\Windows Portable Devices
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\Program Files\Windows NT
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\Program Files\Common Files\Services
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\Program Files (x86)\Windows NT
    2017-06-14 19:12 - 2017-06-14 19:12 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
    2017-06-14 19:12 - 2017-06-14 19:10 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
    2017-06-14 19:12 - 2017-06-14 19:10 - 00215943 _____ C:\WINDOWS\system32\dssec.dat
    2017-06-14 19:12 - 2017-06-14 19:10 - 00017463 _____ C:\WINDOWS\system32\Drivers\etc\services
    2017-06-14 19:12 - 2017-06-14 19:10 - 00015462 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
    2017-06-14 19:12 - 2017-06-14 19:10 - 00004096 _____ C:\WINDOWS\system32\config\VSMIDK
    2017-06-14 19:12 - 2017-06-14 19:10 - 00003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam
    2017-06-14 19:12 - 2017-06-14 19:10 - 00001358 _____ C:\WINDOWS\system32\Drivers\etc\protocol
    2017-06-14 19:12 - 2017-06-14 19:10 - 00000858 _____ C:\WINDOWS\system32\DefaultQuestions.json
    2017-06-14 19:12 - 2017-06-14 19:10 - 00000741 _____ C:\WINDOWS\system32\NOISE.DAT
    2017-06-14 19:12 - 2017-06-14 19:10 - 00000407 _____ C:\WINDOWS\system32\Drivers\etc\networks
    2017-06-14 19:12 - 2017-06-14 19:10 - 00000219 _____ C:\WINDOWS\system.ini
    2017-06-14 19:12 - 2017-06-14 19:10 - 00000092 _____ C:\WINDOWS\win.ini
    2017-06-14 19:11 - 2017-06-14 20:08 - 00000000 ____D C:\WINDOWS\INF
    2017-06-14 18:56 - 2017-06-14 19:23 - 00000000 ____D C:\WINDOWS\CbsTemp
    2017-06-14 18:47 - 2017-06-14 20:00 - 00262144 _____ C:\WINDOWS\system32\config\BBI
    2017-06-14 18:47 - 2017-06-14 19:27 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
    2017-06-14 18:47 - 2017-06-14 19:18 - 00000000 ____D C:\WINDOWS\servicing
    2017-06-14 18:47 - 2017-06-14 19:12 - 00000000 ____D C:\WINDOWS\system32\SMI
    2017-06-14 18:47 - 2017-06-14 18:47 - 00000000 ____D C:$WINDOWS.~BT
    2017-06-14 14:24 - 2017-06-14 19:27 - 00000000 ___HD C:$SysReset

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2017-06-14 19:09 - 2016-07-16 07:44 - 00572416 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr
    2017-06-14 19:09 - 2016-07-16 07:44 - 00360960 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdechangepin.exe
    2017-06-14 19:09 - 2016-07-16 07:44 - 00204288 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\DscCoreConfProv.dll
    2017-06-14 19:09 - 2016-07-16 07:44 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpdxm.dll
    2017-06-14 19:09 - 2016-07-16 07:44 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpshell.dll
    2017-06-14 19:09 - 2016-07-16 07:43 - 07217664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
    2017-06-14 19:09 - 2016-07-16 07:43 - 04312248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
    2017-06-14 19:09 - 2016-07-16 07:43 - 02458112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themecpl.dll
    2017-06-14 19:09 - 2016-07-16 07:43 - 01562112 _____ (Microsoft Corporation) C:\WINDOWS\system32\vssapi.dll
    2017-06-14 19:09 - 2016-07-16 07:43 - 00913920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
    2017-06-14 19:09 - 2016-07-16 07:43 - 00895488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
    2017-06-14 19:09 - 2016-07-16 07:43 - 00850432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasgcw.dll
    2017-06-14 19:09 - 2016-07-16 07:43 - 00798208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
    2017-06-14 19:09 - 2016-07-16 07:43 - 00787968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sbe.dll
    2017-06-14 19:09 - 2016-07-16 07:43 - 00765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
    2017-06-14 19:09 - 2016-07-16 07:43 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
    2017-06-14 19:09 - 2016-07-16 07:43 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenterCPL.dll
    2017-06-14 19:09 - 2016-07-16 07:43 - 00544256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
    2017-06-14 19:09 - 2016-07-16 07:43 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.UserAccountsHan dlers.dll
    2017-06-14 19:09 - 2016-07-16 07:43 - 00491520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
    2017-06-14 19:09 - 2016-07-16 07:43 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXP.dll
    2017-06-14 19:09 - 2016-07-16 07:43 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
    2017-06-14 19:09 - 2016-07-16 07:43 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
    2017-06-14 19:09 - 2016-07-16 07:43 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
    2017-06-14 19:09 - 2016-07-16 07:43 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
    2017-06-14 19:09 - 2016-07-16 07:43 - 00236032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
    2017-06-14 19:09 - 2016-07-16 07:43 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BcastDVRHelper.dll
    2017-06-14 19:09 - 2016-07-16 07:43 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
    2017-06-14 19:09 - 2016-07-16 07:43 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfui.dll
    2017-06-14 19:09 - 2016-07-16 07:43 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthExt.dll
    2017-06-14 19:09 - 2016-07-16 07:43 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModelOOBE.exe
    2017-06-14 19:09 - 2016-07-16 07:43 - 00019968 _____ C:\WINDOWS\SysWOW64\GamePanelExternalHook.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 07468032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 03769856 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 03617792 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
    2017-06-14 19:09 - 2016-07-16 07:42 - 03369984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 02712064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 02643456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 02277800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 02183792 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 01990648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 01987584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 01762816 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSPhotography.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 01726976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 01714688 _____ (Microsoft Corporation) C:\WINDOWS\system32\dui70.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 01709056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 01573376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 01360464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 01358336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 01354304 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
    2017-06-14 19:09 - 2016-07-16 07:42 - 01274712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 01201360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 01105408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MiracastReceiver.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 01077760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 01004544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00981504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authenticatio n.OnlineId.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00959488 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00940032 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontext.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00883712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00869888 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00820224 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintRenderAPIHost.DLL
    2017-06-14 19:09 - 2016-07-16 07:42 - 00781312 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00773120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
    2017-06-14 19:09 - 2016-07-16 07:42 - 00741888 _____ (Microsoft Corporation) C:\WINDOWS\system32\internetmail.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00714752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00691200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00679936 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00654336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00653312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00640984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00628040 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
    2017-06-14 19:09 - 2016-07-16 07:42 - 00620544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00603488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utiliti es.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authenticatio n.Web.Core.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddraw.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00576408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00573952 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrGidsHandler.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00556544 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtrmgr.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00553984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptui.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00538624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00526848 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dl l
    2017-06-14 19:09 - 2016-07-16 07:42 - 00509792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
    2017-06-14 19:09 - 2016-07-16 07:42 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprdim.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00467456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Geolocation.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\das.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00444416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00443744 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMDevAPI.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00437248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00410624 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00388608 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00386560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SessEnv.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00380416 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationApi.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00380256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
    2017-06-14 19:09 - 2016-07-16 07:42 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00378720 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00378072 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
    2017-06-14 19:09 - 2016-07-16 07:42 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00343040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00338944 _____ (Microsoft Corporation) C:\WINDOWS\system32\adsnt.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00300544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mscandui.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
    2017-06-14 19:09 - 2016-07-16 07:42 - 00295936 _____ (Microsoft Corporation) C:\WINDOWS\system32\pdh.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00291840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.d ll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00284160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataExchange.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcuiu.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssphtb.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authenticatio n.Identity.Provider.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\discan.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\scksp.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WwaApi.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
    2017-06-14 19:09 - 2016-07-16 07:42 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00201056 _____ (Microsoft Corporation) C:\WINDOWS\system32\basecsp.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Radios.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00185368 _____ C:\WINDOWS\SysWOW64\weretw.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe
    2017-06-14 19:09 - 2016-07-16 07:42 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.OneCore.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthserv.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
    2017-06-14 19:09 - 2016-07-16 07:42 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\rshx32.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupugc.exe
    2017-06-14 19:09 - 2016-07-16 07:42 - 00122208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\migisol.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Backg round.SystemEventsBroker.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00114192 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssitlb.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00112120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpapi.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00101376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.SystemManagemen t.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00097128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Credentials.U I.CredentialPicker.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\dasHost.exe
    2017-06-14 19:09 - 2016-07-16 07:42 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient. dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00079712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmcl.sys
    2017-06-14 19:09 - 2016-07-16 07:42 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iscsiwmi.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothDesktopHandlers.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpipreg.sys
    2017-06-14 19:09 - 2016-07-16 07:42 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BackgroundMediaPolicy.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceassociation.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddrawex.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandle r.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00045056 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00038768 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompPkgSup.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgentc.exe
    2017-06-14 19:09 - 2016-07-16 07:42 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
    2017-06-14 19:09 - 2016-07-16 07:42 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
    2017-06-14 19:09 - 2016-07-16 07:41 - 00220000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
    2017-06-14 19:09 - 2016-07-16 07:41 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
    2017-06-14 19:09 - 2016-07-16 07:41 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
    2017-06-14 19:08 - 2016-07-16 07:44 - 19417088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
    2017-06-14 19:08 - 2016-07-16 07:44 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptio nHandlers.dll
    2017-06-14 19:08 - 2016-07-16 07:44 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
    2017-06-14 19:08 - 2016-07-16 07:43 - 08124928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
    2017-06-14 19:08 - 2016-07-16 07:43 - 03194368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
    2017-06-14 19:08 - 2016-07-16 07:43 - 02095616 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
    2017-06-14 19:08 - 2016-07-16 07:43 - 01836032 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
    2017-06-14 19:08 - 2016-07-16 07:43 - 01081856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
    2017-06-14 19:08 - 2016-07-16 07:43 - 01040896 _____ (Microsoft Corporation) C:\WINDOWS\system32\NaturalLanguage6.dll
    2017-06-14 19:08 - 2016-07-16 07:43 - 00963072 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebcamUi.dll
    2017-06-14 19:08 - 2016-07-16 07:43 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\system32\pmcsnap.dll
    2017-06-14 19:08 - 2016-07-16 07:43 - 00774656 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
    2017-06-14 19:08 - 2016-07-16 07:43 - 00769024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ipsecsnp.dll
    2017-06-14 19:08 - 2016-07-16 07:43 - 00760832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appwiz.cpl
    2017-06-14 19:08 - 2016-07-16 07:43 - 00646656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiaservc.dll
    2017-06-14 19:08 - 2016-07-16 07:43 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
    2017-06-14 19:08 - 2016-07-16 07:43 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ipsmsnap.dll
    2017-06-14 19:08 - 2016-07-16 07:43 - 00415744 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpshell.exe
    2017-06-14 19:08 - 2016-07-16 07:43 - 00412672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SndVolSSO.dll
    2017-06-14 19:08 - 2016-07-16 07:43 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
    2017-06-14 19:08 - 2016-07-16 07:43 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
    2017-06-14 19:08 - 2016-07-16 07:43 - 00299008 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpinit.exe
    2017-06-14 19:08 - 2016-07-16 07:43 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dl l
    2017-06-14 19:08 - 2016-07-16 07:43 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
    2017-06-14 19:08 - 2016-07-16 07:43 - 00264192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ppcsnap.dll
    2017-06-14 19:08 - 2016-07-16 07:43 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapp3hst.dll
    2017-06-14 19:08 - 2016-07-16 07:43 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapphost.dll
    2017-06-14 19:08 - 2016-07-16 07:43 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
    2017-06-14 19:08 - 2016-07-16 07:43 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bthprops.cpl
    2017-06-14 19:08 - 2016-07-16 07:43 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappcfg.dll
    2017-06-14 19:08 - 2016-07-16 07:43 - 00152064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autoplay.dll
    2017-06-14 19:08 - 2016-07-16 07:43 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
    2017-06-14 19:08 - 2016-07-16 07:43 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFolders.exe
    2017-06-14 19:08 - 2016-07-16 07:43 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappgnui.dll
    2017-06-14 19:08 - 2016-07-16 07:43 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
    2017-06-14 19:08 - 2016-07-16 07:43 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmifw.dll
    2017-06-14 19:08 - 2016-07-16 07:43 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappprxy.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 20965248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 05723344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 05622600 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
    2017-06-14 19:08 - 2016-07-16 07:42 - 05611008 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 03244032 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 02368512 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 02206496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 02138112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 02005504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 01992704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 01980416 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 01875456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 01738048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 01707512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 01364480 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 01320448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 01277344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 01155584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVP9DEC.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 01154560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Pimstore.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 01128960 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 01037312 _____ (Microsoft Corporation) C:\WINDOWS\system32\nettrace.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 01022304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 01013248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00998912 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00936960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00884736 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00861184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00856872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00837632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00790760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00787968 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
    2017-06-14 19:08 - 2016-07-16 07:42 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsregcmd.exe
    2017-06-14 19:08 - 2016-07-16 07:42 - 00674304 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
    2017-06-14 19:08 - 2016-07-16 07:42 - 00655872 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00653824 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserLanguagesCpl.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00647680 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00640000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00611328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense. dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00538112 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00527880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00527808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00525312 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
    2017-06-14 19:08 - 2016-07-16 07:42 - 00502784 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.BackgroundMediaP layback.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00470016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.Backgro undMediaPlayer.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.MediaPl ayer.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTMediaFrame.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00439296 _____ (Microsoft Corporation) C:\WINDOWS\system32\wksprt.exe
    2017-06-14 19:08 - 2016-07-16 07:42 - 00425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmrdvcore.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00412160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00407392 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00404992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsreg.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00396168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.LowLevel.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00374448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkBindingEngineMigPlugin. dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\system32\usbmon.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00322400 _____ (Microsoft Corporation) C:\WINDOWS\system32\input.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00318784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifiprofilessettinghandler.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmWmiPl.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00271360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00265728 _____ C:\WINDOWS\SysWOW64\Windows.Perception.Stub.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00263680 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExSMime.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\system32\icm32.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00237568 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcpipcfg.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSrvPolicyManager.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairingFolder.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiapi.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00178528 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostUser.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SerialCommunic ation.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00170960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\system32\XamlTileRender.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDeviceRegistration.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00152928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTWorkQ.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00150016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Profile.RetailI nfo.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
    2017-06-14 19:08 - 2016-07-16 07:42 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppc.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\slc.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceAgent.exe
    2017-06-14 19:08 - 2016-07-16 07:42 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
    2017-06-14 19:08 - 2016-07-16 07:42 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblGameSaveExt.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\DafPrintProvider.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthBroker.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Core. dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\CameraCaptureUI.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
    2017-06-14 19:08 - 2016-07-16 07:42 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\CastLaunch.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Printers.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDeviceRegistration.Ngc.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.UserDeviceAssoc iation.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\AddressParser.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\POSyncServices.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataPlatformHelperUtil.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactActivation.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00045920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\iorate.sys
    2017-06-14 19:08 - 2016-07-16 07:42 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTypeHelperUtil.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataLanguageUtil.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\EAMProgressHandler.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CbtBackgroundManagerPolicy.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthTelemetry.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\netiougc.exe
    2017-06-14 19:08 - 2016-07-16 07:42 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\smphost.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExtrasXmlParser.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\slcext.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stdole2.tlb
    2017-06-14 19:08 - 2016-07-16 07:42 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
    2017-06-14 19:08 - 2016-07-16 07:42 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccessRes.dll
    2017-06-14 19:08 - 2016-07-16 07:41 - 00131424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys
    2017-06-14 19:08 - 2016-07-16 07:41 - 00088416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\scmbus.sys
    2017-06-14 19:08 - 2016-07-16 07:41 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicDisplay.sys
    2017-06-14 19:07 - 2016-07-16 07:44 - 11854848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
    2017-06-14 19:07 - 2016-07-16 07:44 - 00727040 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
    2017-06-14 19:07 - 2016-07-16 07:44 - 00645472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
    2017-06-14 19:07 - 2016-07-16 07:44 - 00471040 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll
    2017-06-14 19:07 - 2016-07-16 07:44 - 00254656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpeffects.dll
    2017-06-14 19:07 - 2016-07-16 07:44 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
    2017-06-14 19:07 - 2016-07-16 07:44 - 00156160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.Client.dll
    2017-06-14 19:07 - 2016-07-16 07:44 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
    2017-06-14 19:07 - 2016-07-16 07:43 - 05398016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aclui.dll
    2017-06-14 19:07 - 2016-07-16 07:43 - 03753984 _____ (Microsoft Corporation) C:\WINDOWS\system32\bootux.dll
    2017-06-14 19:07 - 2016-07-16 07:43 - 01694200 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
    2017-06-14 19:07 - 2016-07-16 07:43 - 01493504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
    2017-06-14 19:07 - 2016-07-16 07:43 - 01461088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll
    2017-06-14 19:07 - 2016-07-16 07:43 - 01220096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl
    2017-06-14 19:07 - 2016-07-16 07:43 - 00690176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
    2017-06-14 19:07 - 2016-07-16 07:43 - 00534528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PCPTpm12.dll
    2017-06-14 19:07 - 2016-07-16 07:43 - 00507904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
    2017-06-14 19:07 - 2016-07-16 07:43 - 00363520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll
    2017-06-14 19:07 - 2016-07-16 07:43 - 00334848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastlsext.dll
    2017-06-14 19:07 - 2016-07-16 07:43 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll
    2017-06-14 19:07 - 2016-07-16 07:43 - 00276992 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
    2017-06-14 19:07 - 2016-07-16 07:43 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ListSvc.dll
    2017-06-14 19:07 - 2016-07-16 07:43 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dlnashext.dll
    2017-06-14 19:07 - 2016-07-16 07:43 - 00248472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
    2017-06-14 19:07 - 2016-07-16 07:43 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToReceiver.dll
    2017-06-14 19:07 - 2016-07-16 07:43 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll
    2017-06-14 19:07 - 2016-07-16 07:43 - 00198856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
    2017-06-14 19:07 - 2016-07-16 07:43 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
    2017-06-14 19:07 - 2016-07-16 07:43 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscinterop.dll
    2017-06-14 19:07 - 2016-07-16 07:43 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.Se cureAssessment.dll
    2017-06-14 19:07 - 2016-07-16 07:43 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll
    2017-06-14 19:07 - 2016-07-16 07:43 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.UI.Logon.Prox yStub.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 17184256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 09125888 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 07792640 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 07655424 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 05384192 _____ (Microsoft) C:\WINDOWS\system32\dbgeng.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 04612096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 03434496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 03116032 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAJApi.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 03059200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 02947072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 02740224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 02646016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 02424320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Perception.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 02323728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 02208768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.3D.d ll
    2017-06-14 19:07 - 2016-07-16 07:42 - 02143744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 02009600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 01937920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmc.exe
    2017-06-14 19:07 - 2016-07-16 07:42 - 01917440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 01883784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 01691136 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
    2017-06-14 19:07 - 2016-07-16 07:42 - 01656320 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 01556200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 01476608 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
    2017-06-14 19:07 - 2016-07-16 07:42 - 01424896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 01349128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
    2017-06-14 19:07 - 2016-07-16 07:42 - 01348608 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 01322848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 01272832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 01217888 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 01163696 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
    2017-06-14 19:07 - 2016-07-16 07:42 - 01067632 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 01060352 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 01052672 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 01046976 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
    2017-06-14 19:07 - 2016-07-16 07:42 - 01029120 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 01002496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00996192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
    2017-06-14 19:07 - 2016-07-16 07:42 - 00968704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00945664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00939872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pidgenx.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00936448 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00907480 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00905216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00885832 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
    2017-06-14 19:07 - 2016-07-16 07:42 - 00871424 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcprx.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00868824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00857088 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprddm.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcRefreshTask.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00820736 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00814592 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00811416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00806912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00803840 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00772608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00762384 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_sr.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00681312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00670208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.PointOfService .dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00650240 _____ (Microsoft) C:\WINDOWS\system32\DbgModel.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00643072 _____ (Microsoft Corporation) C:\WINDOWS\system32\main.cpl
    2017-06-14 19:07 - 2016-07-16 07:42 - 00629248 _____ (Microsoft Corporation) C:\WINDOWS\system32\hgcpl.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00583680 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.UXRes.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00561664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Walle t.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00552288 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00545280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00529920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StructuredQuery.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00505856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00501248 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi2.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00500064 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00496872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00489472 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00446464 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00423776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
    2017-06-14 19:07 - 2016-07-16 07:42 - 00411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCenter.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00409600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVSENCD.DLL
    2017-06-14 19:07 - 2016-07-16 07:42 - 00409600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanui.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosResource.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00408600 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\NmaDirect.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00334848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DavSyncProvider.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockS creen.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.XboxLive.Storag e.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Phoneutil.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00313344 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00303968 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CryptoWinRT.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\accountaccessor.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfksproxy.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcTok.exe
    2017-06-14 19:07 - 2016-07-16 07:42 - 00218008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
    2017-06-14 19:07 - 2016-07-16 07:42 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipboardServer.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00160768 _____ C:\WINDOWS\system32\EditionUpgradeHelper.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00146784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00141312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dialclient.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00137936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthHost.exe
    2017-06-14 19:07 - 2016-07-16 07:42 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsentUX.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00128352 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00128352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
    2017-06-14 19:07 - 2016-07-16 07:42 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BrowserSettingSync.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.HostName.dl l
    2017-06-14 19:07 - 2016-07-16 07:42 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00117240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00110944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvsocket.sys
    2017-06-14 19:07 - 2016-07-16 07:42 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00101216 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceReactivation.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\adsmsext.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.ServiceDisc overy.Dnssd.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
    2017-06-14 19:07 - 2016-07-16 07:42 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BluetoothApis.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00078176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\crashdmp.sys
    2017-06-14 19:07 - 2016-07-16 07:42 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00075888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfaudiocnv.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ConfigureExpandedStorage.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\virtdisk.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerUI.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvps.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\spaceman.exe
    2017-06-14 19:07 - 2016-07-16 07:42 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
    2017-06-14 19:07 - 2016-07-16 07:42 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\delegatorprovider.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi_passthru.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
    2017-06-14 19:07 - 2016-07-16 07:42 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
    2017-06-14 19:07 - 2016-07-16 07:41 - 00089952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\IPMIDrv.sys
    2017-06-14 19:06 - 2016-07-16 07:44 - 00279960 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdeunlock.exe
    2017-06-14 19:06 - 2016-07-16 07:44 - 00217600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpdxm.dll
    2017-06-14 19:06 - 2016-07-16 07:43 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
    2017-06-14 19:06 - 2016-07-16 07:43 - 03400192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll
    2017-06-14 19:06 - 2016-07-16 07:43 - 01637888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
    2017-06-14 19:06 - 2016-07-16 07:43 - 01415752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
    2017-06-14 19:06 - 2016-07-16 07:43 - 01413632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpcServices.dll
    2017-06-14 19:06 - 2016-07-16 07:43 - 01231360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wcnwiz.dll
    2017-06-14 19:06 - 2016-07-16 07:43 - 01078272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
    2017-06-14 19:06 - 2016-07-16 07:43 - 00935936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srmclient.dll
    2017-06-14 19:06 - 2016-07-16 07:43 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
    2017-06-14 19:06 - 2016-07-16 07:43 - 00523712 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMRServer.dll
    2017-06-14 19:06 - 2016-07-16 07:43 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll
    2017-06-14 19:06 - 2016-07-16 07:43 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
    2017-06-14 19:06 - 2016-07-16 07:43 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
    2017-06-14 19:06 - 2016-07-16 07:43 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
    2017-06-14 19:06 - 2016-07-16 07:43 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
    2017-06-14 19:06 - 2016-07-16 07:43 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RADCUI.dll
    2017-06-14 19:06 - 2016-07-16 07:43 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
    2017-06-14 19:06 - 2016-07-16 07:43 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlancfg.dll
    2017-06-14 19:06 - 2016-07-16 07:43 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enrollmentapi.dll
    2017-06-14 19:06 - 2016-07-16 07:43 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfp.dll
    2017-06-14 19:06 - 2016-07-16 07:43 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
    2017-06-14 19:06 - 2016-07-16 07:43 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 04673304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
    2017-06-14 19:06 - 2016-07-16 07:42 - 04136448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 03405824 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 03056640 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 02828384 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 02746880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 02630144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 02538496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 02257248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
    2017-06-14 19:06 - 2016-07-16 07:42 - 01827840 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 01811968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 01755136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 01723568 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
    2017-06-14 19:06 - 2016-07-16 07:42 - 01710080 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 01600632 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 01454000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 01429696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store .dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 01402880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 01336320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 01300056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 01265424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 01247232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 01225728 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 01182048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
    2017-06-14 19:06 - 2016-07-16 07:42 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Phone.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 01106432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 01086976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 01082368 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 01046368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
    2017-06-14 19:06 - 2016-07-16 07:42 - 01025536 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00992256 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00908800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00903680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
    2017-06-14 19:06 - 2016-07-16 07:42 - 00896512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00875520 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00873472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00857600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00850944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00845824 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00841056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00819200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authenticatio n.Web.Core.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00782176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
    2017-06-14 19:06 - 2016-07-16 07:42 - 00778752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00775680 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
    2017-06-14 19:06 - 2016-07-16 07:42 - 00755648 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00753152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imapi2fs.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00751104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundT ransfer.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Ocr.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00747008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00717312 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskbarcpl.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00682816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00678400 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00665776 _____ (Microsoft Corporation) C:\WINDOWS\system32\GenValObj.exe
    2017-06-14 19:06 - 2016-07-16 07:42 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00614912 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
    2017-06-14 19:06 - 2016-07-16 07:42 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00587456 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00584544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
    2017-06-14 19:06 - 2016-07-16 07:42 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00553984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00540160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00531456 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00516096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00501088 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizeng.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsettingsprovider.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00442368 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcfg.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00435040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
    2017-06-14 19:06 - 2016-07-16 07:42 - 00434528 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00424960 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicesFlowBroker.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00394752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys
    2017-06-14 19:06 - 2016-07-16 07:42 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00390144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.d ll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00381728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00356704 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00354264 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
    2017-06-14 19:06 - 2016-07-16 07:42 - 00352096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
    2017-06-14 19:06 - 2016-07-16 07:42 - 00349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
    2017-06-14 19:06 - 2016-07-16 07:42 - 00338944 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcpl.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00336896 _____ C:\WINDOWS\SysWOW64\msinfo32.exe
    2017-06-14 19:06 - 2016-07-16 07:42 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\azroleui.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00326656 _____ C:\WINDOWS\system32\wc_storage.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00326656 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrSvc.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00326144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00310272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcuiu.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00300544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\regedit.exe
    2017-06-14 19:06 - 2016-07-16 07:42 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00272384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_WorkAccess.dl l
    2017-06-14 19:06 - 2016-07-16 07:42 - 00262960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationDat a.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssphtb.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store .TestingFramework.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\WwaApi.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00236488 _____ C:\WINDOWS\system32\weretw.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudBackupSettings.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe
    2017-06-14 19:06 - 2016-07-16 07:42 - 00215552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apds.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00212992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cemapi.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vaultcli.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00205824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
    2017-06-14 19:06 - 2016-07-16 07:42 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00202752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.HumanInterface Device.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GlobCollationHost.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\BcastDVRHelper.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
    2017-06-14 19:06 - 2016-07-16 07:42 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netiohlp.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00168448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Tabbtn.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00134144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ErrorDetails.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00128648 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpapi.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Credentials.U I.UserConsentVerifier.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00126976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssitlb.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.SystemManagemen t.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient. dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bridge.sys
    2017-06-14 19:06 - 2016-07-16 07:42 - 00108384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
    2017-06-14 19:06 - 2016-07-16 07:42 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpoext.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundT ransfer.BackgroundManagerPolicy.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsiwmi.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00075960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker. dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncPolicy.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.UI.GameBar.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ErrorDetailsUpdate.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00062816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fsdepends.sys
    2017-06-14 19:06 - 2016-07-16 07:42 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandle r.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\BackgroundMediaPolicy.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00050880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
    2017-06-14 19:06 - 2016-07-16 07:42 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ffbroker.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00041824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe
    2017-06-14 19:06 - 2016-07-16 07:42 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmintegrator.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mskssrv.sys
    2017-06-14 19:06 - 2016-07-16 07:42 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
    2017-06-14 19:06 - 2016-07-16 07:42 - 00025088 _____ C:\WINDOWS\system32\GamePanelExternalHook.dll
    2017-06-14 19:06 - 2016-07-16 07:42 - 00021856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cmimcext.sys
    2017-06-14 19:06 - 2016-07-16 07:42 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.exe
    2017-06-14 19:06 - 2016-07-16 07:41 - 00118112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\EhStorTcgDrv.sys
    2017-06-14 19:06 - 2016-07-16 07:41 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
    2017-06-14 19:06 - 2016-07-16 07:41 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
    2017-06-14 19:06 - 2016-07-16 07:41 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdhid.sys
    2017-06-14 19:05 - 2016-07-16 07:44 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
    2017-06-14 19:05 - 2016-07-16 07:44 - 03520512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
    2017-06-14 19:05 - 2016-07-16 07:44 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
    2017-06-14 19:05 - 2016-07-16 07:44 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
    2017-06-14 19:05 - 2016-07-16 07:44 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
    2017-06-14 19:05 - 2016-07-16 07:44 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpshell.dll
    2017-06-14 19:05 - 2016-07-16 07:43 - 23681536 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
    2017-06-14 19:05 - 2016-07-16 07:43 - 05110272 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
    2017-06-14 19:05 - 2016-07-16 07:43 - 03478528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll
    2017-06-14 19:05 - 2016-07-16 07:43 - 02251440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
    2017-06-14 19:05 - 2016-07-16 07:43 - 01600512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
    2017-06-14 19:05 - 2016-07-16 07:43 - 01424488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
    2017-06-14 19:05 - 2016-07-16 07:43 - 01293312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
    2017-06-14 19:05 - 2016-07-16 07:43 - 00966144 _____ (Microsoft Corporation) C:\WINDOWS\system32\sbe.dll
    2017-06-14 19:05 - 2016-07-16 07:43 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
    2017-06-14 19:05 - 2016-07-16 07:43 - 00866816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
    2017-06-14 19:05 - 2016-07-16 07:43 - 00749408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\drvstore.dll
    2017-06-14 19:05 - 2016-07-16 07:43 - 00597344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
    2017-06-14 19:05 - 2016-07-16 07:43 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
    2017-06-14 19:05 - 2016-07-16 07:43 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
    2017-06-14 19:05 - 2016-07-16 07:43 - 00306800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MediaControl.dll
    2017-06-14 19:05 - 2016-07-16 07:43 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esentutl.exe
    2017-06-14 19:05 - 2016-07-16 07:43 - 00298064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtapi.dll
    2017-06-14 19:05 - 2016-07-16 07:43 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unimdm.tsp
    2017-06-14 19:05 - 2016-07-16 07:43 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tapi32.dll
    2017-06-14 19:05 - 2016-07-16 07:43 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dggpext.dll
    2017-06-14 19:05 - 2016-07-16 07:43 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pwrshplugin.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 22219328 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 08075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 07222240 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 06654104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayR eady.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 06574592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 03893888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 02914304 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 02852864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFl owUI.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 02820096 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 02681344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 02512384 _____ (Microsoft Corporation) C:\WINDOWS\system32\themecpl.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 02511792 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVDECOD.DLL
    2017-06-14 19:05 - 2016-07-16 07:42 - 02481768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 02476544 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 02389504 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
    2017-06-14 19:05 - 2016-07-16 07:42 - 02289664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 02214784 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 02190176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
    2017-06-14 19:05 - 2016-07-16 07:42 - 02104832 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 01980776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 01791488 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 01702392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 01639424 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 01507840 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
    2017-06-14 19:05 - 2016-07-16 07:42 - 01435896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 01399296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Pimstore.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 01328128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 01305088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 01281536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 01266176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 01176664 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 01122856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 01112928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 01062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 01020928 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00982528 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00948224 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVP9DEC.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00945152 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasgcw.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00862064 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00827904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00788632 _____ C:\WINDOWS\SysWOW64\locale.nls
    2017-06-14 19:05 - 2016-07-16 07:42 - 00776704 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabletPC.cpl
    2017-06-14 19:05 - 2016-07-16 07:42 - 00755200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.BackgroundMediaP layback.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00719360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
    2017-06-14 19:05 - 2016-07-16 07:42 - 00718848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.Backgro undMediaPlayer.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00714240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
    2017-06-14 19:05 - 2016-07-16 07:42 - 00702976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.MediaPl ayer.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.Search.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00687936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00674304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00658264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
    2017-06-14 19:05 - 2016-07-16 07:42 - 00637400 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00634368 _____ (Microsoft Corporation) C:\WINDOWS\system32\StructuredQuery.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00630784 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00616048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00602464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00568320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.LowLevel.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00542208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivit y.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
    2017-06-14 19:05 - 2016-07-16 07:42 - 00529416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00509280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
    2017-06-14 19:05 - 2016-07-16 07:42 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mbsmsapi.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.AllJoyn.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00480768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00468992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidprov.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00445952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprapi.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVolSSO.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00424616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00418304 _____ C:\WINDOWS\system32\Windows.Perception.Stub.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dl l
    2017-06-14 19:05 - 2016-07-16 07:42 - 00403888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ws2_32.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00401760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
    2017-06-14 19:05 - 2016-07-16 07:42 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00392192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Gaming.Input.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00389120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneBackupHandler.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00360040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
    2017-06-14 19:05 - 2016-07-16 07:42 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxclu.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00352256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Enumeration.dl l
    2017-06-14 19:05 - 2016-07-16 07:42 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00327680 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00321024 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkUXBroker.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00307200 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs3D.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvc.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00302592 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00261120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinDataModelServer .dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00256512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
    2017-06-14 19:05 - 2016-07-16 07:42 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\shdocvw.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00243200 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00236544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAnimation.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Flights.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthprops.cpl
    2017-06-14 19:05 - 2016-07-16 07:42 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore6.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\RdpRelayTransport.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00206096 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00196096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00177664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Diagnostics.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
    2017-06-14 19:05 - 2016-07-16 07:42 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinSCard.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00163752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTWorkQ.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00160096 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostBroker.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00157536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudStorageWizard.exe
    2017-06-14 19:05 - 2016-07-16 07:42 - 00152064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCCSEngineShared.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00152064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\biwinrt.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Core. dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovslegacy.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\EDPCleanup.exe
    2017-06-14 19:05 - 2016-07-16 07:42 - 00142176 _____ (Microsoft Corporation) C:\WINDOWS\system32\migisol.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00121376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00118112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
    2017-06-14 19:05 - 2016-07-16 07:42 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfui.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Lights.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00111968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.Ngc.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\tabcal.exe
    2017-06-14 19:05 - 2016-07-16 07:42 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmclr.sys
    2017-06-14 19:05 - 2016-07-16 07:42 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\powercfg.exe
    2017-06-14 19:05 - 2016-07-16 07:42 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappprxy.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00062816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
    2017-06-14 19:05 - 2016-07-16 07:42 - 00054272 _____ (Microsoft Corporation) C:\WINDOWS\system32\MultiDigiMon.exe
    2017-06-14 19:05 - 2016-07-16 07:42 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winhvr.sys
    2017-06-14 19:05 - 2016-07-16 07:42 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\modem.sys
    2017-06-14 19:05 - 2016-07-16 07:42 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwifimp.sys
    2017-06-14 19:05 - 2016-07-16 07:42 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XInputUap.dll
    2017-06-14 19:05 - 2016-07-16 07:42 - 00036176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
    2017-06-14 19:05 - 2016-07-16 07:42 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgentc.exe
    2017-06-14 19:05 - 2016-07-16 07:42 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\stdole2.tlb
    2017-06-14 19:05 - 2016-07-16 07:41 - 00544608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
    2017-06-14 19:05 - 2016-07-16 07:41 - 00521216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
    2017-06-14 19:05 - 2016-07-16 07:41 - 00074080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vpci.sys
    2017-06-14 19:04 - 2016-07-16 07:44 - 19422208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
    2017-06-14 19:04 - 2016-07-16 07:44 - 12342272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
    2017-06-14 19:04 - 2016-07-16 07:44 - 09260032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmploc.DLL
    2017-06-14 19:04 - 2016-07-16 07:44 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
    2017-06-14 19:04 - 2016-07-16 07:44 - 01547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe
    2017-06-14 19:04 - 2016-07-16 07:44 - 01362512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpmde.dll
    2017-06-14 19:04 - 2016-07-16 07:44 - 00510464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr
    2017-06-14 19:04 - 2016-07-16 07:44 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetworkCollectionAgent.dll
    2017-06-14 19:04 - 2016-07-16 07:44 - 00292872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpeffects.dll
    2017-06-14 19:04 - 2016-07-16 07:44 - 00279040 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
    2017-06-14 19:04 - 2016-07-16 07:44 - 00211456 _____ (Microsoft Corporation) C:\WINDOWS\system32\manage-bde.exe
    2017-06-14 19:04 - 2016-07-16 07:44 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll
    2017-06-14 19:04 - 2016-07-16 07:44 - 00171008 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvenotify.exe
    2017-06-14 19:04 - 2016-07-16 07:44 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WPDShServiceObj.dll
    2017-06-14 19:04 - 2016-07-16 07:44 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdeui.dll
    2017-06-14 19:04 - 2016-07-16 07:44 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spwmp.dll
    2017-06-14 19:04 - 2016-07-16 07:44 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdxm.ocx
    2017-06-14 19:04 - 2016-07-16 07:44 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxmasf.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 12760576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 05682688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 04423680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 04148224 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 02484736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 02356736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVidCtl.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 02155872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 01556480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 01535488 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 00779776 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscui.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 00645120 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 00565248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 00553984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 00552448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\csc.sys
    2017-06-14 19:04 - 2016-07-16 07:43 - 00549376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActionCenterCPL.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 00547840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ddraw.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
    2017-06-14 19:04 - 2016-07-16 07:43 - 00424960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msutb.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 00411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 00308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenter.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToReceiver.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Picker.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_G18030.DLL
    2017-06-14 19:04 - 2016-07-16 07:43 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bowser.sys
    2017-06-14 19:04 - 2016-07-16 07:43 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSpkg.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 00092512 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ddrawex.dll
    2017-06-14 19:04 - 2016-07-16 07:43 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_IS2022.DLL
    2017-06-14 19:04 - 2016-07-16 07:43 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\c_GSM7.DLL
    2017-06-14 19:04 - 2016-07-16 07:42 - 07814496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
    2017-06-14 19:04 - 2016-07-16 07:42 - 06284800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 03733504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 03203072 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 03105792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
    2017-06-14 19:04 - 2016-07-16 07:42 - 02846208 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 02678056 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 02538848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
    2017-06-14 19:04 - 2016-07-16 07:42 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 02166240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 01858752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store .dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 01851144 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 01792512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 01708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 01643008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 01586176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 01575936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 01572768 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 01564160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe
    2017-06-14 19:04 - 2016-07-16 07:42 - 01359360 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 01357312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSPhotography.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 01343936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 01312768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorDataService.exe
    2017-06-14 19:04 - 2016-07-16 07:42 - 01280512 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 01258336 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 01243136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.FaceAnalysis.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 01220608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 01184256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 01092096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationFrame.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 01069208 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 01012224 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 01006080 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00976184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00975744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00965472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00961024 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi2fs.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService .dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00940544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_sr.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00893952 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00842240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
    2017-06-14 19:04 - 2016-07-16 07:42 - 00743424 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00699744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00646136 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00633920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00623104 _____ (Microsoft Corporation) C:\WINDOWS\system32\PCPTpm12.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00622080 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceControl.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00598528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.UXRes.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.SmartCards.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00526176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
    2017-06-14 19:04 - 2016-07-16 07:42 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
    2017-06-14 19:04 - 2016-07-16 07:42 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00468480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.InkControls.dl l
    2017-06-14 19:04 - 2016-07-16 07:42 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.XboxLive.Storag e.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00461824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00449376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
    2017-06-14 19:04 - 2016-07-16 07:42 - 00435095 _____ C:\WINDOWS\system32\ApnDatabase.xml
    2017-06-14 19:04 - 2016-07-16 07:42 - 00425472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
    2017-06-14 19:04 - 2016-07-16 07:42 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00409952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
    2017-06-14 19:04 - 2016-07-16 07:42 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00383488 _____ (Microsoft Corporation) C:\WINDOWS\system32\DavSyncProvider.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00376832 _____ (Microsoft Corporation) C:\WINDOWS\system32\CryptoWinRT.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00375296 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastlsext.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00369664 _____ C:\WINDOWS\system32\msinfo32.exe
    2017-06-14 19:04 - 2016-07-16 07:42 - 00349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\GlobCollationHost.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store .TestingFramework.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00271664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00266544 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00264192 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
    2017-06-14 19:04 - 2016-07-16 07:42 - 00241504 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.HostName.dl l
    2017-06-14 19:04 - 2016-07-16 07:42 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scksp.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00213504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.CredDialogControlle r.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
    2017-06-14 19:04 - 2016-07-16 07:42 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.UI.Logon.Prox yStub.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00205312 _____ (Microsoft Corporation) C:\WINDOWS\system32\netiohlp.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialclient.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00172896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\basecsp.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00172528 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReInfo.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00164352 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\autoplay.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\RelPost.exe
    2017-06-14 19:04 - 2016-07-16 07:42 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\BrowserSettingSync.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00153600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
    2017-06-14 19:04 - 2016-07-16 07:42 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinRtTracing.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Energy.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\MediaFoundation.DefaultPercept ionProvider.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00133472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
    2017-06-14 19:04 - 2016-07-16 07:42 - 00132096 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintWSDAHost.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_ClosedCaption ing.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00116064 _____ (Microsoft Corporation) C:\WINDOWS\system32\icfupgd.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.ServiceDisc overy.Dnssd.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00109056 _____ C:\WINDOWS\SysWOW64\chartv.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00109016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfaudiocnv.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00106896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmifw.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00083128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devenum.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\raspppoe.sys
    2017-06-14 19:04 - 2016-07-16 07:42 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmjpegdec.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthTokenBrokerExt.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpremove.exe
    2017-06-14 19:04 - 2016-07-16 07:42 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
    2017-06-14 19:04 - 2016-07-16 07:42 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlug in.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00057400 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsass.exe
    2017-06-14 19:04 - 2016-07-16 07:42 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthManagerProxy.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00031232 _____ C:\WINDOWS\SysWOW64\efsext.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisionin g.ProxyStub.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\delegatorprovider.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi_passthru.dll
    2017-06-14 19:04 - 2016-07-16 07:42 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\encapi.dll
    2017-06-14 19:04 - 2016-07-16 07:41 - 00277344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys
    2017-06-14 19:04 - 2016-07-16 07:41 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys
    2017-06-14 19:04 - 2016-07-16 07:41 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys
    2017-06-14 19:04 - 2016-07-16 07:41 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidusb.sys
    2017-06-14 19:04 - 2016-07-16 02:04 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
    2017-06-14 19:03 - 2016-07-16 07:44 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebcamUi.dll
    2017-06-14 19:03 - 2016-07-16 07:44 - 00796672 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
    2017-06-14 19:03 - 2016-07-16 07:44 - 00387872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
    2017-06-14 19:03 - 2016-07-16 07:44 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
    2017-06-14 19:03 - 2016-07-16 07:44 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
    2017-06-14 19:03 - 2016-07-16 07:44 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveprompt.exe
    2017-06-14 19:03 - 2016-07-16 07:44 - 00141824 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\SysWOW64\DscCoreConfProv.dll
    2017-06-14 19:03 - 2016-07-16 07:44 - 00108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.Authentication.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 04060672 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 02682880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 02026496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
    2017-06-14 19:03 - 2016-07-16 07:43 - 01555456 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
    2017-06-14 19:03 - 2016-07-16 07:43 - 01344512 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmclient.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 01189376 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdengin2.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 01133568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vssapi.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00896512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontext.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00886784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NaturalLanguage6.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00798720 _____ (Microsoft Corporation) C:\WINDOWS\system32\pwcreator.exe
    2017-06-14 19:03 - 2016-07-16 07:43 - 00758784 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00654336 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmscan.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00632832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sud.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00560640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserLanguagesCpl.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00531456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtrmgr.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00438784 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDec.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00430592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprdim.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00413696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
    2017-06-14 19:03 - 2016-07-16 07:43 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\input.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00266240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00262656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pdh.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mscandui.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
    2017-06-14 19:03 - 2016-07-16 07:43 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdshext.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\pwrshplugin.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
    2017-06-14 19:03 - 2016-07-16 07:43 - 00026464 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser_broker.exe
    2017-06-14 19:03 - 2016-07-16 07:42 - 08155056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayR eady.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 06664192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
    2017-06-14 19:03 - 2016-07-16 07:42 - 05511168 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 03132928 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 02999296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
    2017-06-14 19:03 - 2016-07-16 07:42 - 02812416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 02446704 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 02216960 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 02083840 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 01966296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 01908224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 01883648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 01853232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 01546240 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 01477632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 01472536 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 01460688 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 01418312 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 01369088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 01293312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcnwiz.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 01145344 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 01107456 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 01099104 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
    2017-06-14 19:03 - 2016-07-16 07:42 - 01080320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Ocr.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 01066336 _____ (Microsoft Corporation) C:\WINDOWS\system32\pidgenx.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 01060352 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 01013760 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00987488 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
    2017-06-14 19:03 - 2016-07-16 07:42 - 00983040 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00983040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00959112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00945664 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00944640 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00942432 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi
    2017-06-14 19:03 - 2016-07-16 07:42 - 00924672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundT ransfer.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00911872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00907104 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvstore.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00857440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
    2017-06-14 19:03 - 2016-07-16 07:42 - 00848736 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00807776 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe
    2017-06-14 19:03 - 2016-07-16 07:42 - 00807424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authenticatio n.OnlineId.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00795648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MiracastReceiver.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00788632 _____ C:\WINDOWS\system32\locale.nls
    2017-06-14 19:03 - 2016-07-16 07:42 - 00770560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00681824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys
    2017-06-14 19:03 - 2016-07-16 07:42 - 00671744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mbsmsapi.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00640000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00631296 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMediaManager.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00594472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00590952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00588288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidprov.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\system32\energy.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00547840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Input.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00545944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
    2017-06-14 19:03 - 2016-07-16 07:42 - 00534096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mscms.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00511488 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprapi.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00509440 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Enumeration.dl l
    2017-06-14 19:03 - 2016-07-16 07:42 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
    2017-06-14 19:03 - 2016-07-16 07:42 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00453120 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00450048 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00441856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AccountsRt.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dl l
    2017-06-14 19:03 - 2016-07-16 07:42 - 00425664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ws2_32.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00417928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00408576 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00406016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Geolocation.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00352768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MMDevAPI.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvcext.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00340992 _____ (Microsoft Corporation) C:\WINDOWS\system32\RADCUI.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SessEnv.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00328008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationDat a.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00320512 _____ (Microsoft Corporation) C:\WINDOWS\system32\thumbcache.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00320512 _____ (Microsoft Corporation) C:\WINDOWS\regedit.exe
    2017-06-14 19:03 - 2016-07-16 07:42 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LocationApi.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00318176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
    2017-06-14 19:03 - 2016-07-16 07:42 - 00315744 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00314368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00296448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlancfg.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00291328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adsnt.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00283136 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.HumanInterface Device.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAnimation.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
    2017-06-14 19:03 - 2016-07-16 07:42 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultcli.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00257536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DataExchange.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\cemapi.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkDesktopSettings.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafpos.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00238080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncSettings.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\flvprophandler.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00230912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\icm32.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
    2017-06-14 19:03 - 2016-07-16 07:42 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00224096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
    2017-06-14 19:03 - 2016-07-16 07:42 - 00217600 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfp.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00198496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
    2017-06-14 19:03 - 2016-07-16 07:42 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authenticatio n.Identity.Provider.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00184416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IPHLPAPI.DLL
    2017-06-14 19:03 - 2016-07-16 07:42 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\biwinrt.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00168504 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ErrorDetails.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
    2017-06-14 19:03 - 2016-07-16 07:42 - 00148832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VCardParser.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Lights.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00142336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.WiFi.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Radios.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovs.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00128864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
    2017-06-14 19:03 - 2016-07-16 07:42 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ProximityCommon.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\FontProvider.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slc.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupugc.exe
    2017-06-14 19:03 - 2016-07-16 07:42 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundT ransfer.BackgroundManagerPolicy.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppc.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\DuCsps.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Backg round.SystemEventsBroker.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00087880 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.UI.GameBar.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncPolicy.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00079544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00073568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
    2017-06-14 19:03 - 2016-07-16 07:42 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ErrorDetailsUpdate.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Sens.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\vss_ps.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.UserDeviceAssoc iation.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\POSyncServices.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataPlatformHelperUtil.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00054272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AddressParser.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactActivation.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\XInputUap.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00044472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
    2017-06-14 19:03 - 2016-07-16 07:42 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTypeHelperUtil.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataLanguageUtil.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceassociation.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00033544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CompPkgSup.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00020320 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExtrasXmlParser.dll
    2017-06-14 19:03 - 2016-07-16 07:42 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccessRes.dll
    2017-06-14 19:03 - 2016-07-16 07:41 - 00714080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
    2017-06-14 19:03 - 2016-07-16 07:41 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
    2017-06-14 19:02 - 2016-07-16 07:44 - 06044672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
    2017-06-14 19:02 - 2016-07-16 07:44 - 04596224 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
    2017-06-14 19:02 - 2016-07-16 07:44 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
    2017-06-14 19:02 - 2016-07-16 07:44 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
    2017-06-14 19:02 - 2016-07-16 07:44 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
    2017-06-14 19:02 - 2016-07-16 07:44 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\baaupdate.exe
    2017-06-14 19:02 - 2016-07-16 07:43 - 22571520 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 04748288 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 03496960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
    2017-06-14 19:02 - 2016-07-16 07:43 - 02217472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 01669984 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVIntegration.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 01456640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 01388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 01196544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl
    2017-06-14 19:02 - 2016-07-16 07:43 - 00992096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVManifest.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00823136 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVClient.exe
    2017-06-14 19:02 - 2016-07-16 07:43 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00783360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00762368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprddm.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00730624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d8.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00631296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\main.cpl
    2017-06-14 19:02 - 2016-07-16 07:43 - 00580608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hgcpl.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00525824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintDialogs.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00512864 _____ (Microsoft Corporation) C:\WINDOWS\system32\TransportDSA.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00433832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanui.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00313568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeveloperOptionsSettingsHandle rs.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00261120 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\tspubwmi.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00190816 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVDllSurrogate.exe
    2017-06-14 19:02 - 2016-07-16 07:43 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tcpipcfg.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00175104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiapi.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00126304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\AppVStrm.sys
    2017-06-14 19:02 - 2016-07-16 07:43 - 00119808 ____R (Microsoft Corporation) C:\WINDOWS\system32\SecureAssessmentHandlers.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00111104 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersGPExt.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscinterop.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DafPrintProvider.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
    2017-06-14 19:02 - 2016-07-16 07:43 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\findnetprinters.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\virtdisk.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerUI.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll
    2017-06-14 19:02 - 2016-07-16 07:43 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netiougc.exe
    2017-06-14 19:02 - 2016-07-16 07:43 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanhlp.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 06109184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 05375488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 05061120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 04474368 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 04131976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 03541504 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 03299328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
    2017-06-14 19:02 - 2016-07-16 07:42 - 02913616 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 02745232 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 02710016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 02360832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 02333184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 02314752 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 02264064 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 02107392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 01892352 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 01847048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 01840640 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 01785856 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 01690112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.oneco re.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 01656320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Perception.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 01609408 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 01543680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmc.exe
    2017-06-14 19:02 - 2016-07-16 07:42 - 01534464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.3D.d ll
    2017-06-14 19:02 - 2016-07-16 07:42 - 01507840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.FaceAnalysis.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 01503032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 01490944 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 01467584 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 01368576 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 01267512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 01232384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Maps.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 01071736 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 01004032 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00975360 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
    2017-06-14 19:02 - 2016-07-16 07:42 - 00971264 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00958632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.deskt op.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00932864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00831488 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00809984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.Search.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00794416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker. dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00774656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00762856 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00761344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00729600 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00725672 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00718848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00717824 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00701952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivit y.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00699880 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00691592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00651264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\vds.exe
    2017-06-14 19:02 - 2016-07-16 07:42 - 00632320 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00619368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
    2017-06-14 19:02 - 2016-07-16 07:42 - 00609280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00593992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00583520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
    2017-06-14 19:02 - 2016-07-16 07:42 - 00582656 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.UX.EapReque stHandler.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00561664 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00549088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\system32\timedate.cpl
    2017-06-14 19:02 - 2016-07-16 07:42 - 00541696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00536576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00520192 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32time.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00518656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00500224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00477696 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00471040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msutb.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00454600 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
    2017-06-14 19:02 - 2016-07-16 07:42 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imapi2.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosResource.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00389512 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtapi.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00376160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
    2017-06-14 19:02 - 2016-07-16 07:42 - 00361104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00355328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTMediaFrame.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.Pho ne.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00342880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00340920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\esentutl.exe
    2017-06-14 19:02 - 2016-07-16 07:42 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\unimdm.tsp
    2017-06-14 19:02 - 2016-07-16 07:42 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NmaDirect.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore6.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.CredDialogControlle r.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00244824 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00237568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Diagnostics.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSCard.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00236032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmWmiPl.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\tapi32.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockS creen.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_G18030.DLL
    2017-06-14 19:02 - 2016-07-16 07:42 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinesam.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ScDeviceEnum.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FSClient.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinRtTracing.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\certprop.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00187520 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudStorageWizard.exe
    2017-06-14 19:02 - 2016-07-16 07:42 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfksproxy.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00182272 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceDirectoryClient.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsensorgroup.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCCSEngineShared.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppnp.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00168800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
    2017-06-14 19:02 - 2016-07-16 07:42 - 00168424 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovslegacy.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00162850 _____ C:\WINDOWS\system32\C_932.NLS
    2017-06-14 19:02 - 2016-07-16 07:42 - 00141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMapi.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00136032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostUser.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00130048 _____ C:\WINDOWS\system32\chartv.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.SerialCommunic ation.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidsvc.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00119648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
    2017-06-14 19:02 - 2016-07-16 07:42 - 00116576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MapControls.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\dab.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReportingCSP.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\RjvMDMConfig.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthRadioMedia.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00090400 _____ (Microsoft Corporation) C:\WINDOWS\system32\devenum.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\powercfg.exe
    2017-06-14 19:02 - 2016-07-16 07:42 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmjpegdec.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CameraCaptureUI.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adsmsext.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManagerProxy.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\csrsrv.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\NfcRadioMedia.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00039424 _____ C:\WINDOWS\system32\efsext.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00038400 _____ C:\WINDOWS\SysWOW64\dtdump.exe
    2017-06-14 19:02 - 2016-07-16 07:42 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DdcWnsListener.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BthTelemetry.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
    2017-06-14 19:02 - 2016-07-16 07:42 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerSvc.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smphost.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slcext.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidcertstorecheck.exe
    2017-06-14 19:02 - 2016-07-16 07:42 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_IS2022.DLL
    2017-06-14 19:02 - 2016-07-16 07:42 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\c_GSM7.DLL
    2017-06-14 19:02 - 2016-07-16 07:42 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosTrace.dll
    2017-06-14 19:02 - 2016-07-16 07:42 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosHost.dll
    2017-06-14 19:02 - 2016-07-16 07:41 - 00336224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
    2017-06-14 19:02 - 2016-07-16 07:41 - 00279904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
    2017-06-14 19:02 - 2016-07-16 07:41 - 00187232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
    2017-06-14 19:02 - 2016-07-16 07:41 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
    2017-06-14 19:02 - 2016-07-16 07:41 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\capimg.sys
    2017-06-14 19:01 - 2016-07-16 07:44 - 13431808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
    2017-06-14 19:01 - 2016-07-16 07:44 - 09260032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmploc.DLL
    2017-06-14 19:01 - 2016-07-16 07:44 - 01509376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
    2017-06-14 19:01 - 2016-07-16 07:44 - 00270336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
    2017-06-14 19:01 - 2016-07-16 07:44 - 00259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.SyncEngine.dll
    2017-06-14 19:01 - 2016-07-16 07:44 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwmp.dll
    2017-06-14 19:01 - 2016-07-16 07:44 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdxm.ocx
    2017-06-14 19:01 - 2016-07-16 07:44 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxmasf.dll
    2017-06-14 19:01 - 2016-07-16 07:43 - 07623168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
    2017-06-14 19:01 - 2016-07-16 07:43 - 02611200 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll
    2017-06-14 19:01 - 2016-07-16 07:43 - 02049480 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
    2017-06-14 19:01 - 2016-07-16 07:43 - 01557296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
    2017-06-14 19:01 - 2016-07-16 07:43 - 01381728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystemController.dll
    2017-06-14 19:01 - 2016-07-16 07:43 - 01054048 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPolicy.dll
    2017-06-14 19:01 - 2016-07-16 07:43 - 00813408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntStreamingManager.dll
    2017-06-14 19:01 - 2016-07-16 07:43 - 00779616 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVReporting.dll
    2017-06-14 19:01 - 2016-07-16 07:43 - 00751968 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVOrchestration.dll
    2017-06-14 19:01 - 2016-07-16 07:43 - 00699232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntVirtualization.dll
    2017-06-14 19:01 - 2016-07-16 07:43 - 00696160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPublishing.dll
    2017-06-14 19:01 - 2016-07-16 07:43 - 00671232 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkCollectionAgent.dll
    2017-06-14 19:01 - 2016-07-16 07:43 - 00661504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
    2017-06-14 19:01 - 2016-07-16 07:43 - 00562528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVCatalog.dll
    2017-06-14 19:01 - 2016-07-16 07:43 - 00422400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll
    2017-06-14 19:01 - 2016-07-16 07:43 - 00405856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVScripting.dll
    2017-06-14 19:01 - 2016-07-16 07:43 - 00394240 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
    2017-06-14 19:01 - 2016-07-16 07:43 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
    2017-06-14 19:01 - 2016-07-16 07:43 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Picker.dll
    2017-06-14 19:01 - 2016-07-16 07:43 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\systemcpl.dll
    2017-06-14 19:01 - 2016-07-16 07:43 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll
    2017-06-14 19:01 - 2016-07-16 07:43 - 00241504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVShNotify.exe
    2017-06-14 19:01 - 2016-07-16 07:43 - 00167848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll
    2017-06-14 19:01 - 2016-07-16 07:43 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetCfgNotifyObjectHost.exe
    2017-06-14 19:01 - 2016-07-16 07:43 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
    2017-06-14 19:01 - 2016-07-16 07:42 - 13864960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 04708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 04557824 _____ (Microsoft) C:\WINDOWS\SysWOW64\dbgeng.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 03689984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 02422784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAJApi.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 01633792 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 01589248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 01570680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 01512448 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 01234944 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 01157008 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 01117024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 01063472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 00899584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 00823296 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 00765456 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 00746496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcprx.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 00641024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.InkControls.dl l
    2017-06-14 19:01 - 2016-07-16 07:42 - 00631808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 00512416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 00461312 _____ (Microsoft) C:\WINDOWS\SysWOW64\DbgModel.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Walle t.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 00386048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.WiFiDirect.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 00372440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 00260096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Phoneutil.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 00253440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 00219040 _____ (Microsoft Corporation) C:\WINDOWS\system32\IPHLPAPI.DLL
    2017-06-14 19:01 - 2016-07-16 07:42 - 00194048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFi.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ClipboardServer.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Energy.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSpkg.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 00114016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xolehlp.dll
    2017-06-14 19:01 - 2016-07-16 07:42 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\encapi.dll
    2017-06-14 19:01 - 2016-07-16 07:41 - 00082784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
    2017-06-14 19:01 - 2016-07-16 02:04 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
    2017-06-13 23:52 - 2016-07-16 07:43 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll

    ==================== Files in the root of some directories =======

    2017-06-14 19:30 - 2017-06-14 19:30 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

    ==================== Bamital & volsnap ======================

    (There is no automatic fix for files that do not pass verification.)

    C:\WINDOWS\system32\winlogon.exe => File is digitally signed
    C:\WINDOWS\system32\wininit.exe => File is digitally signed
    C:\WINDOWS\explorer.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
    C:\WINDOWS\system32\svchost.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
    C:\WINDOWS\system32\services.exe => File is digitally signed
    C:\WINDOWS\system32\User32.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
    C:\WINDOWS\system32\userinit.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
    C:\WINDOWS\system32\rpcss.dll => File is digitally signed
    C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
    C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

    LastRegBack: 2017-06-14 19:25

    ==================== End of FRST.txt ============================
    [HEADING=1]Addition:
    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-06-2017
    Ran by Nick (14-06-2017 21:27:53)
    Running from C:\Users\Nick\Desktop
    Windows 10 Pro Version 1607 (X64) (2017-06-14 23:52:43)
    Boot Mode: Normal[/HEADING]
    ==================== Accounts: =============================

    Administrator (S-1-5-21-3720547706-1333832102-3978629174-500 - Administrator - Disabled)
    DefaultAccount (S-1-5-21-3720547706-1333832102-3978629174-503 - Limited - Disabled)
    defaultuser0 (S-1-5-21-3720547706-1333832102-3978629174-1000 - Limited - Disabled) => C:\Users\defaultuser0
    Guest (S-1-5-21-3720547706-1333832102-3978629174-501 - Limited - Disabled)
    Nick (S-1-5-21-3720547706-1333832102-3978629174-1001 - Administrator - Enabled) => C:\Users\Nick

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with “Hidden” flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    AMD Settings (HKLM...\WUCCCApp) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.)
    Catalyst Control Center Next Localization BR (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization CHS (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization CHT (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization CS (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization DA (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization DE (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization EL (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization ES (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization FI (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization FR (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization HU (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization IT (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization JA (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization KO (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization NL (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization NO (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization PL (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization RU (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization SV (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization TH (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Next Localization TR (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32...{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32...{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32...{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32...{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Realtek High Definition Audio Driver (HKLM-x32...{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
    Synaptics Pointing Device Driver (HKLM...\SynTPDeinstKey) (Version: 19.0.14.1 - Synaptics Incorporated)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    ==================== Shortcuts & WMI ========================

    (The entries could be listed to be restored or removed.)

    ==================== Loaded Modules (Whitelisted) ==============

    2016-07-16 07:42 - 2016-07-16 07:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
    2016-07-16 07:42 - 2017-06-14 19:09 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
    2017-06-14 19:56 - 2017-06-14 19:56 - 00959168 _____ () C:\Users\Nick\AppData\Local\Microsoft\OneDrive\17. 3.6381.0405\amd64\ClientTelemetry.dll
    2016-07-16 07:42 - 2017-06-14 19:02 - 00130048 _____ () C:\WINDOWS\SYSTEM32\CHARTV.dll
    2016-07-16 07:42 - 2017-06-14 19:02 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.Share dUtilities.dll
    2016-07-16 07:43 - 2017-06-13 23:52 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
    2016-07-16 07:43 - 2017-06-14 19:08 - 09761280 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw 5n1h2txyewy\CortanaApi.dll
    2016-07-16 07:43 - 2017-06-14 19:08 - 01400320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw 5n1h2txyewy\Cortana.Core.dll
    2016-07-16 07:43 - 2017-06-14 19:08 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw 5n1h2txyewy\CSGSuggestLib.dll
    2016-07-16 07:43 - 2017-06-14 19:08 - 01033728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw 5n1h2txyewy\Cortana.Actions.dll
    2016-07-16 07:43 - 2017-06-14 19:08 - 02438144 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw 5n1h2txyewy\Cortana.BackgroundTask.dll
    2016-07-16 07:43 - 2017-06-14 19:08 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw 5n1h2txyewy\RemindersUI.dll
    2015-06-25 20:34 - 2015-06-25 20:34 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll
    2015-06-25 20:37 - 2015-06-25 20:37 - 00739840 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcont rolsplugin.dll
    2015-06-25 20:35 - 2015-06-25 20:35 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugi n.dll
    2015-06-25 20:38 - 2015-06-25 20:38 - 00071168 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayout splugin.dll
    2015-06-25 19:53 - 2015-06-25 19:53 - 00011776 _____ () C:\Program Files\AMD\CNext\CNext\libEGL.dll
    2015-06-25 19:51 - 2015-06-25 19:51 - 02013696 _____ () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
    2016-06-24 15:51 - 2016-06-24 15:51 - 00138752 _____ () C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe
    2017-06-14 19:56 - 2017-06-14 19:56 - 00679624 _____ () C:\Users\Nick\AppData\Local\Microsoft\OneDrive\17. 3.6381.0405\ClientTelemetry.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The “AlternateShell” will be restored.)

    ==================== Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)

    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)

    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2017-06-14 19:12 - 2017-06-14 19:10 - 00000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts

    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-3720547706-1333832102-3978629174-1001\Control Panel\Desktop\Wallpaper → C:\WINDOWS\web\wallpaper\Windows\img0.jpg
    DNS Servers: Media is not connected to internet.
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Pol icies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    ==================== Restore Points =========================

    ==================== Faulty Device Manager Devices =============

    ==================== Event log errors: =========================
    [HEADING=1]Application errors:[/HEADING]
    Error: (06/14/2017 09:07:21 PM) (Source: Windows Search Service) (EventID: 3104) (User: )
    Description: Enumerating user sessions to generate filter pools failed.

    Details:
    (HRESULT : 0x80040210) (0x80040210)

    Error: (06/14/2017 09:06:51 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
    Description: License Activation (slui.exe) failed with the following error code:
    hr=0x80072EE7
    Command-line arguments:
    RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=49cd895b-53b2-4dc4-a5f7-b18aa019ad37;NotificationInterval=1440;Trigger=Net workAvailable

    Error: (06/14/2017 09:06:51 PM) (Source: Software Protection Platform Service) (EventID: 1014) (User: )
    Description: Acquisition of End User License failed. hr=0x80072EE7
    Sku Id=49cd895b-53b2-4dc4-a5f7-b18aa019ad37

    Error: (06/14/2017 09:06:51 PM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
    Description: License acquisition failure details.
    hr=0x80072EE7

    Error: (06/14/2017 09:06:51 PM) (Source: Software Protection Platform Service) (EventID: 1014) (User: )
    Description: Acquisition of End User License failed. hr=0x80072EE7
    Sku Id=49cd895b-53b2-4dc4-a5f7-b18aa019ad37

    Error: (06/14/2017 09:06:51 PM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
    Description: License acquisition failure details.
    hr=0x80072EE7

    Error: (06/14/2017 08:10:02 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
    Description: License Activation (slui.exe) failed with the following error code:
    hr=0x80072EE7
    Command-line arguments:
    RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=49cd895b-53b2-4dc4-a5f7-b18aa019ad37;NotificationInterval=1440;Trigger=Net workAvailable

    Error: (06/14/2017 08:10:02 PM) (Source: Software Protection Platform Service) (EventID: 1014) (User: )
    Description: Acquisition of End User License failed. hr=0x80072EE7
    Sku Id=49cd895b-53b2-4dc4-a5f7-b18aa019ad37

    Error: (06/14/2017 08:10:02 PM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
    Description: License acquisition failure details.
    hr=0x80072EE7

    Error: (06/14/2017 08:10:01 PM) (Source: Software Protection Platform Service) (EventID: 1014) (User: )
    Description: Acquisition of End User License failed. hr=0x80072EE7
    Sku Id=49cd895b-53b2-4dc4-a5f7-b18aa019ad37
    [HEADING=1]System errors:[/HEADING]
    Error: (06/14/2017 08:39:09 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
    Description: 4

    Error: (06/14/2017 08:39:04 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {D63B10C5-BB46-4990-A94F-E40B9D520160}
    and APPID
    {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
    to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

    Error: (06/14/2017 07:20:48 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
    Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Time Broker service, but this action failed with the following error:
    An instance of the service is already running.

    Error: (06/14/2017 07:18:48 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The Security Center service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.

    Error: (06/14/2017 07:18:48 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The Time Broker service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.

    Error: (06/14/2017 07:18:48 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The TCP/IP NetBIOS Helper service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.

    Error: (06/14/2017 07:18:48 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The Windows Event Log service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.

    Error: (06/14/2017 07:18:48 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The DHCP Client service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.

    Error: (06/14/2017 09:57:50 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-SSRSVP2)
    Description: The server {9BA05972-F6A8-11CF-A442-00A0C90A8F39} did not register with DCOM within the required timeout.

    Error: (06/14/2017 08:34:06 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
    Description: 4

    ==================== Memory info ===========================

    Processor: Intel(R) Core™ i5-3570K CPU @ 3.40GHz
    Percentage of memory in use: 17%
    Total physical RAM: 8135.05 MB
    Available physical RAM: 6686.71 MB
    Total Virtual: 10055.05 MB
    Available Virtual: 8596.32 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:930.97 GB) (Free:905.54 GB) NTFS
    Drive e: (ESD-USB) (Removable) (Total:7.6 GB) (Free:7.59 GB) FAT32

    ==================== MBR & Partition Table ==================

    ================================================== ======
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 8B16E3A1)
    Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=450 MB) - (Type=27)

    ================================================== ======
    Disk: 1 (MBR Code: Windows 7 or 8) (Size: 7.6 GB) (Disk ID: 00000000)

    Partition: GPT.

    ==================== End of Addition.txt ============================

    aswMBR:
    [HEADING=1]aswMBR version 1.0.1.2290 Copyright(c) 2014 AVAST Software
    Run date: 2017-06-14 21:33:47[/HEADING]
    21:33:47.176 OS Version: Windows x64 6.2.9200
    21:33:47.176 Number of processors: 4 586 0x3A09
    21:33:47.176 ComputerName: DESKTOP-SSRSVP2 UserName: Nick
    21:33:48.270 Initialize success
    21:33:48.285 VM: initialized successfully
    21:33:48.285 VM: Intel CPU BiosDisabled
    21:34:13.964 Disk 0 (boot) \Device\Harddisk0\DR0 → \Device\0000002f
    21:34:13.964 Disk 0 Vendor: ST1000DM005_HD103SJ 1AJ100E5 Size: 953869MB BusType: 11
    21:34:14.105 Disk 0 MBR read successfully
    21:34:14.105 Disk 0 MBR scan
    21:34:14.121 Disk 0 Windows 7 default MBR code
    21:34:14.121 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
    21:34:14.136 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 953317 MB offset 206848
    21:34:14.167 Disk 0 Partition 3 00 27 Hidden NTFS WinRE NTFS 450 MB offset 1952600064
    21:34:14.167 Disk 0 scanning C:\WINDOWS\system32\drivers
    21:34:29.200 Service scanning
    21:34:41.060 Modules scanning
    21:34:41.060 Disk 0 trace - called modules:
    21:34:41.591 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys storahci.sys hal.dll
    21:34:41.591 1 nt!IofCallDriver → \Device\Harddisk0\DR0[0xffffd10fafd7d060]
    21:34:41.607 3 CLASSPNP.SYS[fffff80f03ff5eeb] → nt!IofCallDriver → [0xffffd10faf24a040]
    21:34:41.607 5 ACPI.sys[fffff80f030a4571] → nt!IofCallDriver → \Device\0000002f[0xffffd10faf20f400]
    21:34:41.623 Disk 0 statistics 15417/0/0 @ 0.53 MB/s
    21:34:41.623 Scan finished successfully
    21:35:21.312 Disk 0 MBR has been saved successfully to “C:\Users\Nick\Desktop\MBR.dat”
    21:35:21.328 The log file has been saved successfully to “C:\Users\Nick\Desktop\aswMBR.txt”
  • jmarket
    PCHF Owner
    • Jan 2015
    • 7634

    #2
    Hi Nick1234 and welcome to PCHF Let’s get underway.

    Zoek Scan

    Disable your antivirus prior to this scan.
    Download Zoek
    Save the file to your desktop.
    Right click Zoek.exe and run as administrator. (XP Users double click)
    Copy and paste the items in red below and paste them into Zoek.

    createsrpoint;
    emptyfolderscheck;delete
    emptyclsid;
    emptyalltemp;
    ipconfig /flushdns;b
    ResetHosts;
    autoclean;

    Now hit the run script button.
    The log will appear after a reboot, also you can find it on the C: drive.
    Post the log in your next reply.

    We need you to run ZHPCleaner to get a log, can you please go HERE to download and save it to your desktop. Once downloaded right click the desktop icon https://pchelpforum.net/attachments/zhp1-jpg.554/ and click “Run as administrator” from the menu. Accept the programs terms and conditions, then select “Scanner” from the main interface. It is safe to ignore any security warnings received when installing or running this software.



    ZHPCleaner may close your browser so do not be concerned. Scanning will begin and on completion may show a dialogue box as shown below, if so simply close it.



    The main interface will re-open and this time click “Repair”



    The main repair options dialogue box will open and any detected infections will be listed under the red tabs and be selected by default. Click “Repair” and ZHPCleaner will place the infections in Quarantine.



    If ZHPCleaner asks to reboot please allow it. Upon reboot if necessary, or even if not required there will be log file called ZHPCleaner.txt on your desktop.

    Please Copy and Paste the contents of this file in your next post

    ZHP Diag Scan

    Download ZHP Diag to your desktop.
    1. Right Click Run as Admin.
    2. Click the Options button.

    Click on Check All
    Then Click Validate
    Then click close.




    2. Click the Scanner button.



    When complete please push the report button.
    A notepad will open… copy and paste the report in your next reply.

    I will also tag @Malnutrition to assist you.

    Comment

    • nick1234
      PCHF Member
      • Jun 2017
      • 4

      #3
      ZOEK:

      Zoek.exe v5.0.0.1 Updated 27-09-2015
      Tool run by Nick on Wed 06/14/2017 at 22:12:52.30.
      Microsoft Windows 10 Pro 10.0.14393 x64
      Running in: Normal Mode No Internet Access Detected
      Launched: C:\Users\Nick\Desktop\zoek.exe [Scan all users] [Script inserted]

      ==== System Restore Info ======================

      6/14/2017 10:16:27 PM Zoek.exe System Restore Point Created Successfully.

      ==== Empty Folders Check ======================

      C:\PROGRA~3\Comms deleted successfully
      C:\PROGRA~3\SoftwareDistribution deleted successfully
      C:\Users\defaultuser0\AppData\LocalLow deleted successfully
      C:\Users\defaultuser0\AppData\Local\VirtualStore deleted successfully
      C:\Users\Nick\AppData\Local\PeerDistRepub deleted successfully
      C:\Users\Nick\AppData\Local\VirtualStore deleted successfully
      C:\WINDOWS\serviceprofiles\Localservice\AppData\Lo cal\NetworkTiles deleted successfully

      ==== Deleting CLSID Registry Keys ======================

      ==== Deleting CLSID Registry Values ======================

      ==== Deleting Services ======================

      ==== Batch Command(s) Run By Tool======================

      ==== Deleting Files \ Folders ======================

      C:\PROGRA~3\Package Cache deleted

      ==== Set IE to Default ======================

      Old Values:
      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
      “Start Page”=" MSN "
      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
      No DefaultScope Set For HKCU

      New Values:
      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
      “Start Page”=" MSN "
      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
      “DefaultScope”=“{012E1000-F331-11DB-8314-0800200C9A66}”

      ==== All HKCU SearchScopes ======================

      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
      {012E1000-F331-11DB-8314-0800200C9A66} Google Url=" Google {searchTerms}"
      {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url=" Search - Microsoft Bing {searchTerms}&src=IE-SearchBox&FORM=IE8SRC"

      ==== Empty IE Cache ======================

      C:\WINDOWS\system32\config\systemprofile\AppData\L ocal\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
      C:\Users\Nick\AppData\Local\Microsoft\Windows\INet Cache\Content.IE5 emptied successfully
      C:\WINDOWS\SysNative\config\systemprofile\AppData\ Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
      C:\Users\Nick\AppData\Local\Microsoft\Windows\INet Cache\IE emptied successfully
      C:\WINDOWS\SysNative\config\systemprofile\AppData\ Local\Microsoft\Windows\INetCache\IE emptied successfully

      ==== Empty FireFox Cache ======================

      No FireFox Profiles found

      ==== Empty Chrome Cache ======================

      No Chrome User Data found

      ==== Empty All Flash Cache ======================

      No Flash Cache Found

      ==== Empty All Java Cache ======================

      No Java Cache Found

      ==== C:\zoek_backup content ======================

      C:\zoek_backup (files=25 folders=29 28110730 bytes)

      ==== Empty Temp Folders ======================

      C:\WINDOWS\Temp will be emptied at reboot

      ==== After Reboot ======================

      ==== Reset Hosts File ======================

      Hosts File Reset Successfully

      ==== Empty Temp Folders ======================

      C:\WINDOWS\Temp successfully emptied
      C:\Users\Nick\AppData\Local\Temp successfully emptied

      ==== Empty Recycle Bin ======================

      C:$RECYCLE.BIN successfully emptied

      ==== EOF on Wed 06/14/2017 at 22:57:55.40 ======================

      ZHP DIAG:

      ~ ZHPDiag v2017.6.12.97 By Nicolas Coolman (2017/06/12)
      ~ Run by Nick (Administrator) (2017/06/14 23:04:10)
      ~ Web: https://www.nicolascoolman.com
      ~ Blog: https://nicolascoolman.eu/
      ~ Facebook: ZHP
      ~ State version: Version OK
      ~ Mode: Scan
      ~ Report: C:\Users\Nick\Desktop\ZHPDiag.txt
      ~ Report: C:\Users\Nick\AppData\Roaming\ZHP\ZHPDiag.txt
      ~ UAC: Activate
      ~ System startup: Normal (Normal boot)
      Windows 10 Pro, 64-bit (Build 14393) =>.Microsoft Corporation

      —\ Internet Browsers (2) - 0s
      ~ MSIE: Microsoft Edge v40
      ~ MSIE: Internet Explorer v11.0.14393.0

      —\ Windows Product Information (3) - 3s
      ~ Windows Server License Manager Script : OK
      ~ Licence Script File Génération : OK
      Windows Automatic Updates : OK

      —\ System protection software (1) - 1s
      Windows Defender (Activate) (Protection)

      —\ Information on the system (6) - 0s
      ~ Operating System: Intel64 Family 6 Model 58 Stepping 9, GenuineIntel
      ~ Operating System: 64-bit
      ~ Boot mode: Normal (Normal boot)
      Total RAM: 8330.292 MB (83% free) : OK =>.RAM Value
      System Restore: Activé (Enable)
      System drive C: has 927 GB (97%) free of 953 GB : OK =>.Disk Space

      —\ Connection to the system mode (3) - 0s
      ~ Computer Name: DESKTOP-SSRSVP2
      ~ User Name: Nick
      ~ Logged in as Administrator

      —\ Enumeration of the disk units (2) - 0s
      ~ Drive C: has 927 GB free of 953 GB (System)
      ~ Drive E: has 7 GB free of 7 GB

      —\ State of the Windows Security Center (7) - 0s
      [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Pol icies\Explorer] NoActiveDesktopChanges: Modified
      [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\system] EnableLUA: OK
      [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
      [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
      [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Associations] Application: OK
      [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
      [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

      —\ Search Generic System Files (24) - 1s
      [MD5.05181A5AC4197D6C5C02ACE6070AF234] - 14/06/2017 - (.Microsoft Corporation - Windows Explorer.) – C:\WINDOWS\Explorer.exe [4673304] =>.Microsoft Windows®
      [MD5.C7645D43451C6D94D87F4D07BDE59C89] - 16/07/2016 - (.Microsoft Corporation - Windows host process (Rundll32).) – C:\WINDOWS\System32\rundll32.exe [69632] =>.Microsoft Corporation
      [MD5.99A19C9A74E2F9820E501DCE77F84F70] - 16/07/2016 - (.Microsoft Corporation - Windows Start-Up Application.) – C:\WINDOWS\System32\Wininit.exe [304240] =>.Microsoft Windows Publisher®
      [MD5.6284717704B063B036BE00F2CB512A74] - 14/06/2017 - (.Microsoft Corporation - Internet Extensions for Win32.) – C:\WINDOWS\System32\wininet.dll [2630144] =>.Microsoft Corporation
      [MD5.770DB86BF679CA34FC927F25FBAA350C] - 14/06/2017 - (.Microsoft Corporation - Windows Logon Application.) – C:\WINDOWS\System32\Winlogon.exe [674304] =>.Microsoft Corporation
      [MD5.9600B7F2F89DE60A80D13DE42F672834] - 16/07/2016 - (.Microsoft Corporation - Software Licensing Library.) – C:\WINDOWS\System32\sppcomapi.dll [402432] =>.Microsoft Corporation
      [MD5.9BA2C83C355EAC4278F17BEF0852823A] - 14/06/2017 - (.Microsoft Corporation - DNS Client API DLL.) – C:\WINDOWS\System32\dnsapi.dll [646136] =>.Microsoft Windows®
      [MD5.6C1D303C703B27FE40D392899BC22E14] - 14/06/2017 - (.Microsoft Corporation - DNS Client API DLL.) – C:\WINDOWS\Syswow64\dnsapi.dll [496872] =>.Microsoft Windows®
      [MD5.983266DA83FFF73DBDDD3730A4712228] - 14/06/2017 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) – C:\WINDOWS\System32\drivers\AFD.sys [583520] =>.Microsoft Windows®
      [MD5.A10F989A812B57B9695F6C305907C9C6] - 16/07/2016 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) – C:\WINDOWS\System32\drivers\atapi.sys [28512] =>.Microsoft Windows®
      [MD5.F8FB51B9EF6372610E9B31A1D86B62FC] - 16/07/2016 - (.Microsoft Corporation - CD-ROM File System Driver.) – C:\WINDOWS\System32\drivers\Cdfs.sys [92160] =>.Microsoft Corporation
      [MD5.613D0137C269187FA298A157E3D14A18] - 16/07/2016 - (.Microsoft Corporation - SCSI CD-ROM Driver.) – C:\WINDOWS\System32\drivers\Cdrom.sys [173056] =>.Microsoft Corporation
      [MD5.7EAFDEF51136E8F2452CEBD8D084F108] - 14/06/2017 - (.Microsoft Corporation - DFS Namespace Client Driver.) – C:\WINDOWS\System32\drivers\DfsC.sys [144384] =>.Microsoft Corporation
      [MD5.10E3515FE5DBA6656FA62C29342EC4A1] - 16/07/2016 - (.Microsoft Corporation - High Definition Audio Bus Driver.) – C:\WINDOWS\System32\drivers\HDAudBus.sys [83456] =>.Microsoft Corporation
      [MD5.B54B30992620C97230013A74461C8517] - 16/07/2016 - (.Microsoft Corporation - i8042 Port Driver.) – C:\WINDOWS\System32\drivers\i8042prt.sys [114176] =>.Microsoft Corporation
      [MD5.F1DAECC3B3D6399875D4F10529D6A77C] - 16/07/2016 - (.Microsoft Corporation - IP Network Address Translator.) – C:\WINDOWS\System32\drivers\IpNat.sys [212480] =>.Microsoft Corporation
      [MD5.C9BB4E2FCAB693FEB00CF940060D94F4] - 14/06/2017 - (.Microsoft Corporation - Windows NT SMB Minirdr.) – C:\WINDOWS\System32\drivers\MRxSmb.sys [449376] =>.Microsoft Windows®
      [MD5.6FEBB0A847FFD5F057B9AC8889F1B9A7] - 16/07/2016 - (.Microsoft Corporation - MBT Transport driver.) – C:\WINDOWS\System32\drivers\netBT.sys [279040] =>.Microsoft Corporation
      [MD5.D1AF837A1555990602A51A3ED238EC80] - 14/06/2017 - (.Microsoft Corporation - NT File System Driver.) – C:\WINDOWS\System32\drivers\ntfs.sys [2257248] =>.Microsoft Windows®
      [MD5.6B81BF7853D161DB8AC62CD8B9C2DE6B] - 16/07/2016 - (.Microsoft Corporation - Parallel Port Driver.) – C:\WINDOWS\System32\drivers\Parport.sys [96768] =>.Microsoft Corporation
      [MD5.17E565710172ED71B8531D8822E1C5D1] - 16/07/2016 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) – C:\WINDOWS\System32\drivers\Rasl2tp.sys [104960] =>.Microsoft Corporation
      [MD5.7135785C21CA79D270D11037C43D3F19] - 16/07/2016 - (.Microsoft Corporation - Microsoft RDP Device redirector.) – C:\WINDOWS\System32\drivers\rdpdr.sys [177152] =>.Microsoft Corporation
      [MD5.9D2DD64A0B51C56285512DC9454340F6] - 14/06/2017 - (.Microsoft Corporation - TDI Translation Driver.) – C:\WINDOWS\System32\drivers\tdx.sys [118112] =>.Microsoft Windows®
      [MD5.BF2546583BB75F01DDA60A7921DFB230] - 16/07/2016 - (.Microsoft Corporation - Volume Shadow Copy driver.) – C:\WINDOWS\System32\drivers\volsnap.sys [391520] =>.Microsoft Windows®

      —\ Non Microsoft non disabled Windows Services (3) - 2s
      O23 - Service: AdaptiveSleepService (AdaptiveSleepService) . (…) - C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe =>.ATI
      O23 - Service: (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\WINDOWS\system32\atiesrxx.exe =>.AMD
      O23 - Service: DTSAudioSvc (DTSAudioSvc) . (.DTS, Inc - DTS Audio Service.) - C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe =>.DTS, Inc.®

      —\ Services not Microsoft (SR=Run, SS=Stop) (3) - 15s
      SR - Auto [24/06/2016] [ 138752] AdaptiveSleepService (AdaptiveSleepService) . (…) - C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe =>.ATI
      SR - Auto [13/09/2016] [ 287232] (AMD External Events Utility) . (.AMD.) - C:\WINDOWS\system32\atiesrxx.exe =>.Microsoft Windows Hardware Compatibility Publisher®
      SR - Auto [24/06/2015] [ 249328] DTSAudioSvc (DTSAudioSvc) . (.DTS, Inc.) - C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe =>.DTS, Inc.®

      —\ Auto loading programs from Registry and folders (9) - 0s
      O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (.not file.)
      O4 - HKLM..\Run: [WindowsDefender] . (.Microsoft Corporation - Windows Defender notification icon.) – C:\Program Files\Windows Defender\MSASCuiL.exe =>.Microsoft Corporation
      O4 - HKLM..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Realtek HD Audio Manager.) – C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe =>.Realtek Semiconductor Corp®
      O4 - HKLM..\Run: [RtHDVBg_DTS] . (.Realtek Semiconductor - HD Audio Background Process.) – C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe =>.Realtek Semiconductor Corp®
      O4 - HKLM..\Run: [StartCN] . (.Advanced Micro Devices, Inc. - Radeon Settings: Host Application.) – C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe =>.Advanced Micro Devices, Inc.®
      O4 - HKCU..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) – C:\Users\Nick\AppData\Local\Microsoft\OneDrive\One Drive.exe =>.Microsoft Corporation®
      O4 - HKUS\S-1-5-19..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) – C:\Windows\syswow64\OneDriveSetup.exe =>.Microsoft Corporation®
      O4 - HKUS\S-1-5-20..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) – C:\Windows\syswow64\OneDriveSetup.exe =>.Microsoft Corporation®
      O4 - HKUS\S-1-5-21-3720547706-1333832102-3978629174-1001..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) – C:\Users\Nick\AppData\Local\Microsoft\OneDrive\One Drive.exe =>.Microsoft Corporation®

      —\ Process running (8) - 1s
      [MD5.00000000000000000000000000000000] - (.AMD - AMD External Events Service Module.) – C:\WINDOWS\system32\atiesrxx.exe [0] [PID.1420] =>.AMD
      [MD5.00000000000000000000000000000000] - (.AMD - AMD External Events Client Module.) – C:\WINDOWS\system32\atieclxx.exe [0] [PID.1516] =>.AMD
      [MD5.1CFD1A335D08564184F5E406D7E1A2C0] - (.DTS, Inc - DTS Audio Service.) – C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [249328] [PID.2224] =>.DTS, Inc.®
      [MD5.059E8944776CD96C4D48ADECE806D140] - (…) – C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe [138752] [PID.3848] =>.ATI Technologies
      [MD5.22EBD5AE3B3220D713E544D1D3AB3FEE] - (.Realtek Semiconductor - Realtek HD Audio Manager.) – C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800] [PID.3284] =>.Realtek Semiconductor Corp®
      [MD5.31821EC63BDEDE18E64C11F7248B32AB] - (.Realtek Semiconductor - HD Audio Background Process.) – C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624] [PID.3252] =>.Realtek Semiconductor Corp®
      [MD5.6B34B34C61D69D9B7B7A46B364C9FC47] - (.Advanced Micro Devices, Inc. - Radeon Settings: Host Application.) – C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [6613896] [PID.4684] =>.Advanced Micro Devices, Inc.®
      [MD5.EA5DD793D0CDAA296F99EB72EA9539C3] - (.Nicolas Coolman - ZHPDiag.) – C:\Users\Nick\Desktop\ZHPDiag3.exe [2742784] [PID.5352] =>.Nicolas Coolman

      —\ Internet Explorer Extensions, Start, Search (17) - 0s
      R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
      R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
      R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
      R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
      R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
      R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
      R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
      R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
      R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
      R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
      R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
      R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
      R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
      R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
      R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphan =>.Microsoft Internet Explorer
      R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1
      R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1

      —\ Internet Explorer, Proxy Management (3) - 0s
      R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyEnable = 0
      R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings,MigrateProxy = 1
      R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Para meters\Internet\ManualProxies =>.Microsoft

      —\ Line Analysis, IniFiles, Auto loading programs (3) - 0s
      F2 - REG:system.ini: UserInit=
      F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
      F2 - REG:system.ini: VMApplet=

      —\ Hosts file redirection (1) - 0s
      ~ Le fichier hôte est sain (The hosts file is clean) (0)

      —\ Global shortcuts Startup (42) - 1s
      O4 - GS\Desktop [Administrator]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleane.) C:\Users\Nick\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman
      O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Nick\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
      O4 - GS\sendTo [Administrator]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
      O4 - GS\sendTo [Administrator]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
      O4 - GS\Programs [Administrator]: AMD Radeon Settings.lnk . (.Advanced Micro Devices, Inc. - .) C:\Program Files (x86)\AMD\CNext\CNext\RadeonSettings.exe =>.Advanced Micro Devices, Inc.
      O4 - GS\Programs [Administrator]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Nick\AppData\Local\Microsoft\OneDrive\One Drive.exe =>.Microsoft Corporation®
      O4 - GS\Desktop [defaultuser0]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleane.) C:\Users\Nick\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman
      O4 - GS\Desktop [defaultuser0]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Nick\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
      O4 - GS\sendTo [defaultuser0]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
      O4 - GS\sendTo [defaultuser0]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
      O4 - GS\Programs [defaultuser0]: AMD Radeon Settings.lnk . (.Advanced Micro Devices, Inc. - .) C:\Program Files (x86)\AMD\CNext\CNext\RadeonSettings.exe =>.Advanced Micro Devices, Inc.
      O4 - GS\Programs [defaultuser0]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Nick\AppData\Local\Microsoft\OneDrive\One Drive.exe =>.Microsoft Corporation®
      O4 - GS\Desktop [Guest]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleane.) C:\Users\Nick\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman
      O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Nick\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
      O4 - GS\sendTo [Guest]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
      O4 - GS\sendTo [Guest]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
      O4 - GS\Programs [Guest]: AMD Radeon Settings.lnk . (.Advanced Micro Devices, Inc. - .) C:\Program Files (x86)\AMD\CNext\CNext\RadeonSettings.exe =>.Advanced Micro Devices, Inc.
      O4 - GS\Programs [Guest]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Nick\AppData\Local\Microsoft\OneDrive\One Drive.exe =>.Microsoft Corporation®
      O4 - GS\Desktop [Nick]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleane.) C:\Users\Nick\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman
      O4 - GS\Desktop [Nick]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Nick\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
      O4 - GS\sendTo [Nick]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
      O4 - GS\sendTo [Nick]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
      O4 - GS\Programs [Nick]: AMD Radeon Settings.lnk . (.Advanced Micro Devices, Inc. - .) C:\Program Files (x86)\AMD\CNext\CNext\RadeonSettings.exe =>.Advanced Micro Devices, Inc.
      O4 - GS\Programs [Nick]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Nick\AppData\Local\Microsoft\OneDrive\One Drive.exe =>.Microsoft Corporation®
      O4 - GS\Programs [Public]: AMD Radeon Settings.lnk . (.Advanced Micro Devices, Inc. - .) C:\Program Files (x86)\AMD\CNext\CNext\RadeonSettings.exe =>.Advanced Micro Devices, Inc.
      O4 - GS\Programs [Public]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Nick\AppData\Local\Microsoft\OneDrive\One Drive.exe =>.Microsoft Corporation®
      O4 - GS\Accessories [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
      O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Notepad.) C:\WINDOWS\system32\notepad.exe =>.Microsoft Corporation
      O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation
      O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\WINDOWS\system32\mspaint.exe =>.Microsoft Corporation
      O4 - GS\Accessories [Public]: Quick Assist.lnk . (.Microsoft Corporation - Quick Assist.) C:\WINDOWS\system32\quickassist.exe =>.Microsoft Corporation
      O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Remote Desktop Connection.) C:\WINDOWS\system32\mstsc.exe =>.Microsoft Corporation
      O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\WINDOWS\system32\SnippingTool.exe =>.Microsoft Corporation
      O4 - GS\Accessories [Public]: Steps Recorder.lnk . (.Microsoft Corporation - Steps Recorder.) C:\WINDOWS\system32\psr.exe =>.Microsoft Corporation
      O4 - GS\Accessories [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe =>.Microsoft Corporation
      O4 - GS\Accessories [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
      O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Windows Wordpad Application.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
      O4 - GS\Accessories [Public]: XPS Viewer.lnk . (.Microsoft Corporation - XPS Viewer.) C:\WINDOWS\system32\xpsrchvw.exe =>.Microsoft Corporation
      O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Character Map.) C:\WINDOWS\system32\charmap.exe =>.Microsoft Corporation
      O4 - GS\ProgramsCommon [Public]: Immersive Control Panel.lnk . (.Microsoft Corporation - Windows Control Panel.) C:\WINDOWS\System32\Control.exe =>.Microsoft Corporation
      O4 - GS\ProgramsCommon [Public]: MiracastView.lnk . (.Microsoft Corporation - MiracastView.) C:\WINDOWS\MiracastView\MiracastView.exe =>.Microsoft Windows®
      O4 - GS\ProgramsCommon [Public]: PrintDialog.lnk . (.Microsoft Corporation - Print Dialog.) C:\WINDOWS\PrintDialog\PrintDialog.exe =>.Microsoft Windows®

      —\ Extra protocols (22) - 1s
      O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) – C:\Windows\syswow64\mshtml.dll =>.Microsoft Corporation
      O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\syswow64\urlmon.dll =>.Microsoft Corporation
      O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) – C:\Windows\syswow64\MSVidCtl.dll =>.Microsoft Corporation
      O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\syswow64\urlmon.dll =>.Microsoft Corporation
      O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\syswow64\urlmon.dll =>.Microsoft Corporation
      O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\syswow64\urlmon.dll =>.Microsoft Corporation
      O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\syswow64\urlmon.dll =>.Microsoft Corporation
      O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) – C:\Windows\syswow64\itss.dll =>.Microsoft Corporation
      O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) – C:\Windows\syswow64\mshtml.dll =>.Microsoft Corporation
      O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\syswow64\urlmon.dll =>.Microsoft Corporation
      O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) – C:\Windows\syswow64\mshtml.dll =>.Microsoft Corporation
      O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) – C:\Windows\syswow64\inetcomm.dll =>.Microsoft Corporation
      O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\syswow64\urlmon.dll =>.Microsoft Corporation
      O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) – C:\Windows\syswow64\itss.dll =>.Microsoft Corporation
      O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) – C:\Windows\syswow64\mshtml.dll =>.Microsoft Corporation
      O18 - Handler: tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) – C:\Windows\syswow64\tbauth.dll =>.Microsoft Corporation
      O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) – C:\Windows\syswow64\MSVidCtl.dll =>.Microsoft Corporation
      O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) – C:\Windows\syswow64\mshtml.dll =>.Microsoft Corporation
      O18 - Handler: windows.tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) – C:\Windows\syswow64\tbauth.dll =>.Microsoft Corporation
      O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) – C:\Windows\syswow64\mscoree.dll =>.Microsoft Corporation
      O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) – C:\Windows\syswow64\mscoree.dll =>.Microsoft Corporation
      O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) – C:\Windows\syswow64\mscoree.dll =>.Microsoft Corporation

      —\ Software installed (2) - 2s
      O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] – {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} =>.Realtek Semiconductor Corp®
      O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM][64Bits] – SynTPDeinstKey =>.Synaptics Incorporated

      —\ HKCU & HKLM Software Keys (19) - 2s
      HKLM\SOFTWARE\Wow6432Node\ATI =>.ATI
      HKLM\SOFTWARE\Wow6432Node\ATI Technologies =>.ATI Technologies
      HKLM\SOFTWARE\Wow6432Node\Chicony =>.Chicony
      HKLM\SOFTWARE\Wow6432Node\Intel =>.Intel
      HKLM\SOFTWARE\Wow6432Node\Khronos =>.Khronos
      HKLM\SOFTWARE\Wow6432Node\Macromedia =>.Macromedia
      HKLM\SOFTWARE\Wow6432Node\Nuance =>.Nuance
      HKLM\SOFTWARE\Wow6432Node\ODBC =>.DB Connectivity Solutions
      HKLM\SOFTWARE\Wow6432Node\SRS Labs =>.SRS Labs
      HKLM\SOFTWARE\Wow6432Node\WOW6432Node =>.Microsoft Corporation
      HKLM\SOFTWARE\Wow6432Node\RegisteredApplications =>.Microsoft Corporation
      HKCU\SOFTWARE\AMD =>.AMD
      HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation
      HKCU\SOFTWARE\ATI =>.ATI
      HKCU\SOFTWARE\Realtek =>.Realtek Semiconductor Corp.
      HKCU\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
      HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation
      HKCU\SOFTWARE\ZHP =>.Nicolas Coolman
      HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation

      —\ Contents of the Common Files folders (90) - 1s
      O43 - CFD: 14/06/2017 - D – C:\Program Files\AMD =>.Advanced Micro Devices, Inc.®
      O43 - CFD: 14/06/2017 - D – C:\Program Files\ATI Technologies =>.ATI Technologies
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Common Files =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Internet Explorer =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\MSBuild =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Realtek =>.Realtek
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Reference Assemblies =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Synaptics =>.Synaptics
      O43 - CFD: 14/06/2017 - [0] HD – C:\Program Files\Uninstall Information =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Windows Defender =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Windows Defender Advanced Threat Protection =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Windows Mail =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Windows Media Player =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Windows Multimedia Platform =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Windows NT =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Windows Portable Devices =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - SHD – C:\Program Files\Windows Sidebar =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - HD – C:\Program Files\WindowsApps =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\WindowsPowerShell =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\AMD =>.AMD
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Common Files =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\MSBuild =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Windows Defender =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Windows Multimedia Platform =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Windows NT =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - SHD – C:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\WindowsPowerShell =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - RD – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - RD – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - RD – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
      O43 - CFD: 14/06/2017 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Settings =>.Advanced Micro Devices Inc
      O43 - CFD: 14/06/2017 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - RD – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - RD – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\ProgramData\Application Data =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\ProgramData\Desktop =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\ProgramData\Documents =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - SD – C:\ProgramData\Microsoft =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\ProgramData\Microsoft OneDrive =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\ProgramData\regid.1991-06.com.microsoft =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\ProgramData\Start Menu =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\ProgramData\Templates =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\ProgramData\USOPrivate =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\ProgramData\USOShared =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Common Files\Microsoft Shared =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Common Files\System =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Roaming\Adobe =>.Adobe
      O43 - CFD: 14/06/2017 - SD – C:\Users\Nick\AppData\Roaming\Microsoft =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Roaming\ZHP =>.Nicolas Coolman
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Local\AMD =>.AMD
      O43 - CFD: 14/06/2017 - [0] SHD – C:\Users\Nick\AppData\Local\Application Data =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Local\Comms =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Local\ConnectedDevicesPlatfo rm =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Local\Diagnostics =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\Users\Nick\AppData\Local\History =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Local\Microsoft =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Local\MicrosoftEdge =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Local\Packages =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Local\Publishers =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Local\Temp =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\Users\Nick\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Local\TileDataLayer =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Local\ZHP =>.Nicolas Coolman
      O43 - CFD: 14/06/2017 - RD – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Accessibility =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - RD – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Accessories =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - RD – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Administrative Tools =>.Administrative Tools
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Maintenance =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - RD – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Startup =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - RD – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\System Tools =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - RD – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Windows PowerShell =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\Users\Default\AppData\Local\History =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] D – C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\Users\Default User\AppData\Local\History =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] D – C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\WINDOWS\System32\Config\systemprofile\AppData\L ocal\Microsoft =>.Microsoft Corporation

      —\ ShellIconOverlayIdentifiers (SIOI) (5) - 0s
      O106 - SIOI: ErrorOverlayHandler Class [ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) – C:\Users\Nick\AppData\Local\Microsoft\OneDrive\17. 3.6381.0405\FileSyncShell.dll =>.Microsoft Corporation®
      O106 - SIOI: SharedOverlayHandler Class [ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) – C:\Users\Nick\AppData\Local\Microsoft\OneDrive\17. 3.6381.0405\FileSyncShell.dll =>.Microsoft Corporation®
      O106 - SIOI: SharedSyncingOverlayHandler Class [ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) – C:\Users\Nick\AppData\Local\Microsoft\OneDrive\17. 3.6381.0405\FileSyncShell.dll =>.Microsoft Corporation®
      O106 - SIOI: UpToDateOverlayHandler Class [ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) – C:\Users\Nick\AppData\Local\Microsoft\OneDrive\17. 3.6381.0405\FileSyncShell.dll =>.Microsoft Corporation®
      O106 - SIOI: SyncingOverlayHandler Class [ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) – C:\Users\Nick\AppData\Local\Microsoft\OneDrive\17. 3.6381.0405\FileSyncShell.dll =>.Microsoft Corporation®

      —\ Image File Execution Options (17) - 1s
      O50 - IFEO:C:\Windows\System32\cscript.exe - (.Microsoft Corporation - Microsoft ® Console Based Script Host.) [DisableExceptionChainValidation\3] =>.Microsoft Corporation
      O50 - IFEO:C:\Windows\System32\dllhost.exe - (.Microsoft Corporation - COM Surrogate.) [DisableExceptionChainValidation\3] =>.Microsoft Windows®
      O50 - IFEO:C:\WINDOWS\System32\drvinst.exe - (.Microsoft Corporation - Driver Installation Module.) [DisableExceptionChainValidation\3] =>.Microsoft Corporation
      O50 - IFEO:C:\WINDOWS\System32\ie4uinit.exe - (.Microsoft Corporation - IE Per-User Initialization Utility.) [MitigationOptions\256] =>.Microsoft Corporation
      O50 - IFEO:C:\Windows\System32\ieUnatt.exe - (.Microsoft Corporation - IE 7.0 Unattended Install Utility.) [MitigationOptions\256] =>.Microsoft Corporation
      O50 - IFEO:C:\Windows\System32\mmc.exe - (.Microsoft Corporation - Microsoft Management Console.) [DisableExceptionChainValidation\3] =>.Microsoft Corporation
      O50 - IFEO:C:\Windows\System32\msfeedssync.exe - (.Microsoft Corporation - Microsoft Feeds Synchronization.) [MitigationOptions\256] =>.Microsoft Corporation
      O50 - IFEO:C:\Windows\System32\mshta.exe - (.Microsoft Corporation - Microsoft (R) HTML Application host.) [MitigationOptions\256] =>.Microsoft Corporation
      O50 - IFEO:C:\Windows\System32\PresentationHost.exe - (.Microsoft Corporation - Windows Presentation Foundation Host.) [MitigationOptions\1118481] =>.Microsoft Corporation
      O50 - IFEO:C:\WINDOWS\System32\PrintIsolationHost.exe - (.Microsoft Corporation - PrintIsolationHost.) [MitigationOptions\2097152] =>.Microsoft Corporation
      O50 - IFEO:C:\Windows\System32\rundll32.exe - (.Microsoft Corporation - Windows host process (Rundll32).) [DisableExceptionChainValidation\3] =>.Microsoft Corporation
      O50 - IFEO:C:\WINDOWS\System32\runtimebroker.exe - (.Microsoft Corporation - Runtime Broker.) [MitigationOptions\4294967296] =>.Microsoft Corporation
      O50 - IFEO:C:\Windows\System32\searchprotocolhost.exe - (.Microsoft Corporation - Microsoft Windows Search Protocol Host.) [DisableExceptionChainValidation\3] =>.Microsoft Corporation
      O50 - IFEO:C:\WINDOWS\System32\spoolsv.exe - (.Microsoft Corporation - Spooler SubSystem App.) [DisableExceptionChainValidation\3] =>.Microsoft Corporation
      O50 - IFEO:C:\WINDOWS\System32\spoolsv.exe - (.Microsoft Corporation - Spooler SubSystem App.) [MitigationOptions\2097152] =>.Microsoft Corporation
      O50 - IFEO:C:\Windows\System32\svchost.exe - (.Microsoft Corporation - Host Process for Windows Services.) [MinimumStackCommitInBytes\32768] =>.Microsoft Windows Publisher®
      O50 - IFEO:C:\Windows\System32\wscript.exe - (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) [DisableExceptionChainValidation\3] =>.Microsoft Corporation

      —\ System Drivers List (94) - 8s
      O58 - SDL:2016/07/16 07:41:53 A . (.LSI - LSI 3ware SCSI Storport Driver.) – C:\WINDOWS\System32\drivers\3ware.sys [107360] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) – C:\WINDOWS\System32\drivers\adp80xx.sys [1135456] =>.Microsoft Windows®
      O58 - SDL:2016/03/21 10:37:24 A . (.Advanced Micro Devices, Inc. - AMD Audio Bus Lower Filter.) – C:\WINDOWS\System32\drivers\amdkmafd.sys [23240] =>.Advanced Micro Devices, Inc.®
      O58 - SDL:2016/07/16 07:41:53 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) – C:\WINDOWS\System32\drivers\amdsata.sys [83296] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) – C:\WINDOWS\System32\drivers\amdsbs.sys [259424] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Advanced Micro Devices - Storage Filter Driver.) – C:\WINDOWS\System32\drivers\amdxata.sys [26976] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) – C:\WINDOWS\System32\drivers\arcsas.sys [131936] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:50 A . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) – C:\WINDOWS\System32\drivers\athw8x.sys [4233728] =>.Qualcomm Atheros Communications, Inc.
      O58 - SDL:2016/04/26 06:26:52 A . (.Advanced Micro Devices - AMD High Definition Audio Function Driver.) – C:\WINDOWS\System32\drivers\AtihdWT6.sys [110096] =>.Microsoft Windows Hardware Compatibility Publisher®
      O58 - SDL:2016/09/13 22:08:14 A . (.Advanced Micro Devices, Inc. - ATI Radeon Kernel Mode Driver.) – C:\WINDOWS\System32\drivers\atikmdag.sys [26706432] =>.Microsoft Windows Hardware Compatibility Publisher®
      O58 - SDL:2016/09/13 22:08:12 A . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) – C:\WINDOWS\System32\drivers\atikmpag.sys [518656] =>.Microsoft Windows Hardware Compatibility Publisher®
      O58 - SDL:2016/07/16 07:41:53 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) – C:\WINDOWS\System32\drivers\bcmfn.sys [9728] =>.Windows (R) Win 7 DDK provider
      O58 - SDL:2016/07/16 07:41:53 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) – C:\WINDOWS\System32\drivers\bcmfn2.sys [9728] =>.Windows (R) Win 7 DDK provider
      O58 - SDL:2016/07/16 07:41:52 A . (.QLogic Corporation - QLogic Gigabit Ethernet VBD.) – C:\WINDOWS\System32\drivers\bxvbda.sys [533856] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Chelsio Communications - Chelsio iSCSI Crash Dump Driver.) – C:\WINDOWS\System32\drivers\cht4dx64.sys [102752] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Chelsio Communications - Chelsio iSCSI VMiniport Driver.) – C:\WINDOWS\System32\drivers\cht4sx64.sys [346976] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Chelsio Communications - Virtual Bus Driver for Chelsio ® T4 Chipset.) – C:\WINDOWS\System32\drivers\cht4vx64.sys [2104160] =>.Microsoft Windows®
      O58 - SDL:2013/08/21 06:09:38 A . (.Intel Corporation - Intel(R) Gigabit Adapter NDIS 6.x driver.) – C:\WINDOWS\System32\drivers\e1c64x64.sys [468240] =>.Intel Corporation®
      O58 - SDL:2016/07/16 07:41:54 A . (.Intel Corporation - Intel(R) Gigabit Adapter NDIS 6.x driver.) – C:\WINDOWS\System32\drivers\e1i63x64.sys [524800] =>.Intel Corporation
      O58 - SDL:2016/07/16 07:41:52 A . (.QLogic Corporation - QLogic 10 GigE VBD.) – C:\WINDOWS\System32\drivers\evbda.sys [3418976] =>.Microsoft Windows®
      O58 - SDL:2012/07/17 18:12:08 A . (.Intel Corporation - Intel(R) Management Engine Interface.) – C:\WINDOWS\System32\drivers\HECIx64.sys [62784] =>.Intel Corporation®
      O58 - SDL:2016/07/16 07:41:53 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) – C:\WINDOWS\System32\drivers\HpSAMD.sys [64352] =>.Microsoft Windows®
      O58 - SDL:2009/08/15 00:58:04 A . (.Windows (R) Codename Longhorn DDK provider - Example Keyboard Filter Driver.) – C:\WINDOWS\System32\drivers\i8042HDR.sys [15920] =>.Chicony Electronics Co., Ltd.®
      O58 - SDL:2016/07/16 07:41:54 A . (.Intel(R) Corporation - Intel(R) Serial IO GPIO Controller Driver.) – C:\WINDOWS\System32\drivers\iagpio.sys [33280] =>.Intel(R) Corporation
      O58 - SDL:2016/07/16 07:41:54 A . (.Intel(R) Corporation - Intel(R) Serial IO I2C Driver.) – C:\WINDOWS\System32\drivers\iai2c.sys [81408] =>.Intel(R) Corporation
      O58 - SDL:2016/07/16 07:41:54 A . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) – C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [64512] =>.Intel Corporation
      O58 - SDL:2016/07/16 07:41:54 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) – C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [176384] =>.Intel Corporation - Embedded Subsystems and IP Blocks Group®
      O58 - SDL:2016/07/16 07:41:52 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) – C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [38128] =>.Intel Corporation - Client Components Group®
      O58 - SDL:2016/07/16 07:41:50 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) – C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [113152] =>.Intel Corporation
      O58 - SDL:2016/07/16 07:41:53 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) – C:\WINDOWS\System32\drivers\iaStorAV.sys [673120] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) – C:\WINDOWS\System32\drivers\iaStorV.sys [412000] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Mellanox - InfiniBand Fabric Bus Driver.) – C:\WINDOWS\System32\drivers\ibbus.sys [526176] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) – C:\WINDOWS\System32\drivers\lsi_sas.sys [108896] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) – C:\WINDOWS\System32\drivers\lsi_sas2i.sys [105824] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) – C:\WINDOWS\System32\drivers\lsi_sas3i.sys [101216] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) – C:\WINDOWS\System32\drivers\lsi_sss.sys [82776] =>.Microsoft Windows®
      O58 - SDL:2012/10/26 16:42:22 A . (.Logitech Inc. - Logitech USB Video Class Filter Driver.) – C:\WINDOWS\System32\drivers\lvbflt64.sys [26784] =>.Logitech, Inc.®
      O58 - SDL:2016/07/16 07:41:53 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) – C:\WINDOWS\System32\drivers\megasas.sys [59744] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) – C:\WINDOWS\System32\drivers\megasr.sys [575840] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Mellanox - MLX4 Bus Driver.) – C:\WINDOWS\System32\drivers\mlx4_bus.sys [842584] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) – C:\WINDOWS\System32\drivers\mvumis.sys [63840] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Mellanox - NetworkDirect Support Filter Driver.) – C:\WINDOWS\System32\drivers\ndfltr.sys [108896] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:42:03 A . (.Authors - .) – C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624] =>.Microsoft Corporation
      O58 - SDL:2016/07/16 07:41:53 A . (.NVIDIA Corporation - NVIDIA® nForce™ RAID Driver.) – C:\WINDOWS\System32\drivers\nvraid.sys [150368] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.NVIDIA Corporation - NVIDIA® nForce™ Sata Performance Driver.) – C:\WINDOWS\System32\drivers\nvstor.sys [166240] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) – C:\WINDOWS\System32\drivers\percsas2i.sys [58720] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) – C:\WINDOWS\System32\drivers\percsas3i.sys [61792] =>.Microsoft Windows®
      O58 - SDL:2015/06/24 22:57:00 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) – C:\WINDOWS\System32\drivers\RTKVHD64.sys [4504320] =>.Realtek Semiconductor Corp®
      O58 - SDL:2015/08/13 11:36:50 A . (.Razer Inc - Razer RzBTEndPt.) – C:\WINDOWS\System32\drivers\rzbtendpt.sys [51912] =>.Razer Inc.®
      O58 - SDL:2015/08/13 11:36:50 A . (.Razer Inc - Razer RzEndPt.) – C:\WINDOWS\System32\drivers\rzdaendpt.sys [43720] =>.Razer Inc.®
      O58 - SDL:2015/08/13 11:36:50 A . (.Razer Inc - Razer RzEndPt.) – C:\WINDOWS\System32\drivers\rzendpt.sys [50392] =>.Razer Inc.®
      O58 - SDL:2015/08/13 11:36:50 A . (.Razer Inc - Razer Inc. External Display Driver.) – C:\WINDOWS\System32\drivers\rzhnet.sys [29912] =>.Razer Inc.®
      O58 - SDL:2015/08/13 11:36:50 A . (.Razer Inc - Razer JoyStick Device.) – C:\WINDOWS\System32\drivers\rzjstk.sys [36568] =>.Razer Inc.®
      O58 - SDL:2015/08/13 11:36:50 A . (.Razer Inc - Razer RzEndPt.) – C:\WINDOWS\System32\drivers\rzkeypadendpt.sys [46280] =>.Razer Inc.®
      O58 - SDL:2015/08/13 11:36:50 A . (.Razer Inc - Razer RzMPos.) – C:\WINDOWS\System32\drivers\rzmpos.sys [48840] =>.Razer Inc.®
      O58 - SDL:2015/08/13 11:36:50 A . (.Razer Inc - Razer RzEndPt.) – C:\WINDOWS\System32\drivers\rzp1endpt.sys [52424] =>.Razer Inc.®
      O58 - SDL:2015/08/13 11:36:50 A . (.Razer Inc - Razer Rzudd Engine.) – C:\WINDOWS\System32\drivers\rzudd.sys [202952] =>.Razer Inc.®
      O58 - SDL:2015/08/13 11:36:50 A . (.Razer Inc - Razer Keyboard Device.) – C:\WINDOWS\System32\drivers\rzvkeyboard.sys [44232] =>.Razer Inc.®
      O58 - SDL:2015/08/13 11:36:50 A . (.Razer Inc - Razer Mouse Device.) – C:\WINDOWS\System32\drivers\rzvmouse.sys [42712] =>.Razer Inc.®
      O58 - SDL:2016/07/16 07:41:53 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) – C:\WINDOWS\System32\drivers\sisraid2.sys [44896] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) – C:\WINDOWS\System32\drivers\sisraid4.sys [81760] =>.Microsoft Windows®
      O58 - SDL:1999/12/31 20:00:00 A . (.Synaptics Incorporated - Synaptics SMBus Driver.) – C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [33960] =>.Synaptics Incorporated®
      O58 - SDL:2016/01/08 04:51:46 A . (.MCCI Corporation - SAMSUNG Android USB Composite Device Driver.) – C:\WINDOWS\System32\drivers\ssadbus.sys [169288] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:46 A . (.MCCI Corporation - Windows 2000/XP support functions.) – C:\WINDOWS\System32\drivers\ssadcm.sys [17224] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:46 A . (.MCCI Corporation - Windows 2000/XP support functions.) – C:\WINDOWS\System32\drivers\ssadcmnt.sys [17224] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:46 A . (.MCCI Corporation - SAMSUNG Android USB Diagnostic Serial Port.) – C:\WINDOWS\System32\drivers\ssadserd.sys [158024] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:46 A . (.MCCI Corporation - Windows 2000/XP support functions.) – C:\WINDOWS\System32\drivers\ssadwh.sys [17736] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:46 A . (.MCCI Corporation - Windows 2000/XP support functions.) – C:\WINDOWS\System32\drivers\ssadwhnt.sys [17736] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:52 A . (.MCCI Corporation - SAMSUNG USB Composite Device Driver.) – C:\WINDOWS\System32\drivers\sscdbus.sys [169288] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:52 A . (.MCCI Corporation - Windows 2000/XP support functions.) – C:\WINDOWS\System32\drivers\sscdcm.sys [17224] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:52 A . (.MCCI Corporation - Windows 2000/XP support functions.) – C:\WINDOWS\System32\drivers\sscdcmnt.sys [17224] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:52 A . (.MCCI Corporation - SAMSUNG Mobile Modem Diagnostic Serial Port.) – C:\WINDOWS\System32\drivers\sscdserd.sys [158024] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:52 A . (.MCCI Corporation - Windows 2000/XP support functions.) – C:\WINDOWS\System32\drivers\sscdwh.sys [17736] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:52 A . (.MCCI Corporation - Windows 2000/XP support functions.) – C:\WINDOWS\System32\drivers\sscdwhnt.sys [17736] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:54 A . (.MCCI Corporation - SAMSUNG USB Composite Device V2 Driver.) – C:\WINDOWS\System32\drivers\sscebus.sys [169288] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:54 A . (.MCCI Corporation - Windows 2000/XP support functions.) – C:\WINDOWS\System32\drivers\sscecm.sys [17224] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:54 A . (.MCCI Corporation - Windows 2000/XP support functions.) – C:\WINDOWS\System32\drivers\sscecmnt.sys [17224] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:54 A . (.MCCI Corporation - SAMSUNG Mobile Modem Diagnostic Serial Port.) – C:\WINDOWS\System32\drivers\ssceserd.sys [158024] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:54 A . (.MCCI Corporation - Windows 2000/XP support functions.) – C:\WINDOWS\System32\drivers\sscewh.sys [17736] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:54 A . (.MCCI Corporation - Windows 2000/XP support functions.) – C:\WINDOWS\System32\drivers\sscewhnt.sys [17736] =>.MCCI Corporation®
      O58 - SDL:2016/04/25 00:35:52 A . (.Samsung Electronics Co., Ltd. - SAMSUNG USB Composite Device Driver (MSS Ve.) – C:\WINDOWS\System32\drivers\ssudbus.sys [129152] =>.Samsung Electronics CO., LTD.®
      O58 - SDL:2016/01/08 04:51:54 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Mobile DevMgr Device Driver (MS.) – C:\WINDOWS\System32\drivers\ssuddmgr.sys [213088] =>.Samsung Electronics CO., LTD.®
      O58 - SDL:2016/01/08 04:51:54 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Mobile OBEX Device Driver (MSS.) – C:\WINDOWS\System32\drivers\ssudobex.sys [213088] =>.Samsung Electronics CO., LTD.®
      O58 - SDL:2016/04/25 00:36:00 A . (.QUALCOMM Incorporated - Filter Driver for the Qualcomm USB Driver S.) – C:\WINDOWS\System32\drivers\ssudqcfilter.sys [64640] =>.Samsung Electronics CO., LTD.®
      O58 - SDL:2016/01/08 04:51:54 A . (.DEVGURU Co., LTD. - USB Rmnet Device Driver.) – C:\WINDOWS\System32\drivers\ssudrmnet.sys [77408] =>.Samsung Electronics CO., LTD.®
      O58 - SDL:2016/01/08 04:51:54 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Mobile Logging Device Driver (M.) – C:\WINDOWS\System32\drivers\ssudserd.sys [213088] =>.Samsung Electronics CO., LTD.®
      O58 - SDL:2016/01/08 04:51:54 A . (.DEVGURU Co., LTD. - MSS CS Connectivity USB driver.) – C:\WINDOWS\System32\drivers\ss_conn_usb_driver.sys [33376] =>.Samsung Electronics CO., LTD.®
      O58 - SDL:2016/07/16 07:41:53 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) – C:\WINDOWS\System32\drivers\stexstor.sys [31072] =>.Microsoft Windows®
      O58 - SDL:2015/08/13 11:36:50 A . (.Synaptics Incorporated - Synaptics Touchpad Win64 Driver.) – C:\WINDOWS\System32\drivers\SynTP.sys [615632] =>.Synaptics Incorporated®
      O58 - SDL:2016/01/19 18:40:20 A . (.Oracle Corporation - VirtualBox USB Driver.) – C:\WINDOWS\System32\drivers\VBoxUSB.sys [125008] =>.Oracle Corporation®
      O58 - SDL:2016/07/16 07:41:53 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) – C:\WINDOWS\System32\drivers\vsmraid.sys [166752] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) – C:\WINDOWS\System32\drivers\VSTXRAID.SYS [305504] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Mellanox - Kernel WinMad.) – C:\WINDOWS\System32\drivers\winmad.sys [32096] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Mellanox - Kernel WinVerbs.) – C:\WINDOWS\System32\drivers\winverbs.sys [64864] =>.Microsoft Windows®

      —\ Last modified or created user files (1) - 1s
      O61 - LFC: 2017/06/14 22:09:58 A . (..) – C:\Users\Nick\Desktop\zoek.exe [1309184]

      —\ File Associations Shell Spawning (10) - 0s
      O67 - Shell Spawning: <.bat> [HKLM..\open\Command] (…) – “%1” %*
      O67 - Shell Spawning: <.cpl> [HKLM..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) – C:\Windows\System32\control.exe =>.Microsoft Corporation
      O67 - Shell Spawning: <.cmd> [HKLM..\open\Command] (…) – “%1” %*
      O67 - Shell Spawning: <.com> [HKLM..\open\Command] (…) – “%1” %*
      O67 - Shell Spawning: <.evt> [HKLM..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) – C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation
      O67 - Shell Spawning: <.exe> [HKLM..\open\Command] (…) – “%1” %*
      O67 - Shell Spawning: <.html> [HKLM..\open\Command] (.Microsoft Corporation - Internet Explorer.) – C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
      O67 - Shell Spawning: <.js> [HKLM..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) – C:\Windows\System32\wscript.exe =>.Microsoft Corporation
      O67 - Shell Spawning: <.reg> [HKLM..\open\Command] (.Microsoft Corporation - Registry Editor.) – C:\Windows\regedit.exe =>.Microsoft Corporation
      O67 - Shell Spawning: <.scr> [HKLM..\open\Command] (…) – “%1” /S

      —\ Start Menu Internet (4) - 0s
      O68 - StartMenuInternet: <IEXPLORE.EXE> [HKLM..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) – C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
      O68 - StartMenuInternet: <IEXPLORE.EXE> [HKLM..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) – C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
      O68 - StartMenuInternet: <IEXPLORE.EXE> [HKLM..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) – C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
      O68 - StartMenuInternet: <IEXPLORE.EXE> [HKLM..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) – C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation

      —\ Search Browser Infection (3) - 0s
      O69 - SBI: SearchScopes [HKCU] {012E1000-F331-11DB-8314-0800200C9A66} [DefaultScope] - (Google) - http://www.google.com/ =>.Google Inc.
      O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com/ =>.Bing.com
      O69 - SBI: SearchScopes [HKLM] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/ =>.Bing.com

      —\ Search Svchost Services (46) - 1s
      O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) – C:\WINDOWS\System32\certprop.dll [193536] =>.Microsoft Corporation
      O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) – C:\WINDOWS\System32\certprop.dll [193536] =>.Microsoft Corporation
      O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) – C:\WINDOWS\system32\srvsvc.dll [305152] =>.Microsoft Corporation
      O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) – C:\WINDOWS\System32\gpsvc.dll [1225728] =>.Microsoft Corporation
      O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) – C:\WINDOWS\System32\ikeext.dll [932352] =>.Microsoft Corporation
      O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Software installation Service.) – C:\Windows\System32\appmgmts.dll [197632] =>.Microsoft Corporation
      O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) – C:\WINDOWS\System32\iphlpsvc.dll [945664] =>.Microsoft Corporation
      O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) – C:\WINDOWS\system32\seclogon.dll [31232] =>.Microsoft Corporation
      O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) – C:\WINDOWS\System32\appinfo.dll [125952] =>.Microsoft Corporation
      O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) – C:\WINDOWS\system32\iscsiexe.dll [151552] =>.Microsoft Corporation
      O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) – C:\WINDOWS\System32\eapsvc.dll [112128] =>.Microsoft Corporation
      O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) – C:\WINDOWS\system32\schedsvc.dll [948224] =>.Microsoft Corporation
      O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) – C:\WINDOWS\system32\wbem\WMIsvc.dll [222720] =>.Microsoft Corporation
      O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - Computer Browser Service DLL.) – C:\WINDOWS\System32\browser.dll [134656] =>.Microsoft Corporation
      O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) – C:\WINDOWS\system32\profsvc.dll [358400] =>.Microsoft Corporation
      O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) – C:\Windows\System32\SessEnv.dll [386560] =>.Microsoft Corporation
      O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) – C:\WINDOWS\System32\wercplsupport.dll [94208] =>.Microsoft Corporation
      O83 - Search Svchost Services: shpamsvc (shpamsvc) . (.Microsoft Corporation - SharedPC.AccountManager.) – C:\WINDOWS\system32\Windows.SharedPC.AccountManage r.dll [161792] =>.Microsoft Corporation
      O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) – C:\WINDOWS\System32\XblGameSave.dll [1159680] =>.Microsoft Corporation
      O83 - Search Svchost Services: DcpSvc (DcpSvc) . (.Microsoft Corporation - dcpsvc Task.) – C:\WINDOWS\system32\dcpsvc.dll [183808] =>.Microsoft Corporation
      O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Microsoft® Account Service.) – C:\WINDOWS\system32\wlidsvc.dll [2104832] =>.Microsoft Corporation
      O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Microsoft Network Connectivity Assistant Se.) – C:\WINDOWS\System32\ncasvc.dll [167936] =>.Microsoft Corporation
      O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Network Setup Service.) – C:\WINDOWS\System32\NetSetupSvc.dll [265216] =>.Microsoft Corporation
      O83 - Search Svchost Services: WpnService (WpnService) . (.Microsoft Corporation - Windows Push Notification System Service.) – C:\WINDOWS\system32\WpnService.dll [234496] =>.Microsoft Corporation
      O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) – C:\WINDOWS\System32\bdesvc.dll [354304] =>.Microsoft Corporation
      O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) – C:\WINDOWS\system32\XboxNetApiSvc.dll [1025536] =>.Microsoft Corporation
      O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Update Session Orchestrator Core.) – C:\WINDOWS\system32\usocore.dll [539136] =>.Microsoft Corporation
      O83 - Search Svchost Services: wisvc (wisvc) . (.Microsoft Corporation - Flight Settings.) – C:\WINDOWS\system32\flightsettings.dll [614912] =>.Microsoft Corporation
      O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) – C:\WINDOWS\system32\dmwappushsvc.dll [57344] =>.Microsoft Corporation
      O83 - Search Svchost Services: Irmon (Irmon) . (.Microsoft Corporation - Infrared Monitor.) – C:\WINDOWS\System32\irmon.dll [25088] =>.Microsoft Corporation
      O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) – C:\WINDOWS\System32\rasauto.dll [105472] =>.Microsoft Corporation
      O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) – C:\WINDOWS\System32\rasmans.dll [647680] =>.Microsoft Corporation
      O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) – C:\Windows\System32\mprdim.dll [495104] =>.Microsoft Corporation
      O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) – C:\WINDOWS\System32\sens.dll [70656] =>.Microsoft Corporation
      O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) – C:\WINDOWS\System32\ipnathlp.dll [541696] =>.Microsoft Corporation
      O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows™ Telephony Server.) – C:\Windows\System32\tapisrv.dll [309248] =>.Microsoft Corporation
      O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) – C:\WINDOWS\system32\wuaueng.dll [2314752] =>.Microsoft Corporation
      O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) – C:\WINDOWS\System32\qmgr.dll [1052672] =>.Microsoft Corporation
      O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) – C:\Windows\System32\shsvcs.dll [617472] =>.Microsoft Corporation
      O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) – C:\WINDOWS\system32\themeservice.dll [70656] =>.Microsoft Corporation
      O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - Windows Managent Service DLL.) – C:\Windows\System32\Windows.Internal.Management.dl l [407552] =>.Microsoft Corporation
      O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Geolocation Service.) – C:\WINDOWS\System32\lfsvc.dll [37376] =>.Microsoft Corporation
      O83 - Search Svchost Services: RetailDemo (RetailDemo) . (.Microsoft Corporation - RDXService.) – C:\WINDOWS\system32\RDXService.dll [650752] =>.Microsoft Corporation
      O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) – C:\WINDOWS\System32\XblAuthManager.dll [1012224] =>.Microsoft Corporation
      O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) – C:\WINDOWS\System32\usermgr.dll [1020928] =>.Microsoft Corporation
      O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Device Setup Manager.) – C:\WINDOWS\System32\DeviceSetupManager.dll [197632] =>.Microsoft Corporation

      —\ Additional Scan (O88) (1) - 0s
      ~ No malicious or unnecessary items found.

      —\ Summary of the elements found (1) - 0s
      ~ No malicious or unnecessary items found.

      ~ Unselected Options:
      ~ End of the scan, 9841 items in 00mn56s (529)(0)

      ZHP CLEANER:

      ~ ZHPDiag v2017.6.12.97 By Nicolas Coolman (2017/06/12)
      ~ Run by Nick (Administrator) (2017/06/14 23:04:10)
      ~ Web: https://www.nicolascoolman.com
      ~ Blog: https://nicolascoolman.eu/
      ~ Facebook: ZHP
      ~ State version: Version OK
      ~ Mode: Scan
      ~ Report: C:\Users\Nick\Desktop\ZHPDiag.txt
      ~ Report: C:\Users\Nick\AppData\Roaming\ZHP\ZHPDiag.txt
      ~ UAC: Activate
      ~ System startup: Normal (Normal boot)
      Windows 10 Pro, 64-bit (Build 14393) =>.Microsoft Corporation

      —\ Internet Browsers (2) - 0s
      ~ MSIE: Microsoft Edge v40
      ~ MSIE: Internet Explorer v11.0.14393.0

      —\ Windows Product Information (3) - 3s
      ~ Windows Server License Manager Script : OK
      ~ Licence Script File Génération : OK
      Windows Automatic Updates : OK

      —\ System protection software (1) - 1s
      Windows Defender (Activate) (Protection)

      —\ Information on the system (6) - 0s
      ~ Operating System: Intel64 Family 6 Model 58 Stepping 9, GenuineIntel
      ~ Operating System: 64-bit
      ~ Boot mode: Normal (Normal boot)
      Total RAM: 8330.292 MB (83% free) : OK =>.RAM Value
      System Restore: Activé (Enable)
      System drive C: has 927 GB (97%) free of 953 GB : OK =>.Disk Space

      —\ Connection to the system mode (3) - 0s
      ~ Computer Name: DESKTOP-SSRSVP2
      ~ User Name: Nick
      ~ Logged in as Administrator

      —\ Enumeration of the disk units (2) - 0s
      ~ Drive C: has 927 GB free of 953 GB (System)
      ~ Drive E: has 7 GB free of 7 GB

      —\ State of the Windows Security Center (7) - 0s
      [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Pol icies\Explorer] NoActiveDesktopChanges: Modified
      [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\system] EnableLUA: OK
      [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
      [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
      [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Associations] Application: OK
      [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
      [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

      —\ Search Generic System Files (24) - 1s
      [MD5.05181A5AC4197D6C5C02ACE6070AF234] - 14/06/2017 - (.Microsoft Corporation - Windows Explorer.) – C:\WINDOWS\Explorer.exe [4673304] =>.Microsoft Windows®
      [MD5.C7645D43451C6D94D87F4D07BDE59C89] - 16/07/2016 - (.Microsoft Corporation - Windows host process (Rundll32).) – C:\WINDOWS\System32\rundll32.exe [69632] =>.Microsoft Corporation
      [MD5.99A19C9A74E2F9820E501DCE77F84F70] - 16/07/2016 - (.Microsoft Corporation - Windows Start-Up Application.) – C:\WINDOWS\System32\Wininit.exe [304240] =>.Microsoft Windows Publisher®
      [MD5.6284717704B063B036BE00F2CB512A74] - 14/06/2017 - (.Microsoft Corporation - Internet Extensions for Win32.) – C:\WINDOWS\System32\wininet.dll [2630144] =>.Microsoft Corporation
      [MD5.770DB86BF679CA34FC927F25FBAA350C] - 14/06/2017 - (.Microsoft Corporation - Windows Logon Application.) – C:\WINDOWS\System32\Winlogon.exe [674304] =>.Microsoft Corporation
      [MD5.9600B7F2F89DE60A80D13DE42F672834] - 16/07/2016 - (.Microsoft Corporation - Software Licensing Library.) – C:\WINDOWS\System32\sppcomapi.dll [402432] =>.Microsoft Corporation
      [MD5.9BA2C83C355EAC4278F17BEF0852823A] - 14/06/2017 - (.Microsoft Corporation - DNS Client API DLL.) – C:\WINDOWS\System32\dnsapi.dll [646136] =>.Microsoft Windows®
      [MD5.6C1D303C703B27FE40D392899BC22E14] - 14/06/2017 - (.Microsoft Corporation - DNS Client API DLL.) – C:\WINDOWS\Syswow64\dnsapi.dll [496872] =>.Microsoft Windows®
      [MD5.983266DA83FFF73DBDDD3730A4712228] - 14/06/2017 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) – C:\WINDOWS\System32\drivers\AFD.sys [583520] =>.Microsoft Windows®
      [MD5.A10F989A812B57B9695F6C305907C9C6] - 16/07/2016 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) – C:\WINDOWS\System32\drivers\atapi.sys [28512] =>.Microsoft Windows®
      [MD5.F8FB51B9EF6372610E9B31A1D86B62FC] - 16/07/2016 - (.Microsoft Corporation - CD-ROM File System Driver.) – C:\WINDOWS\System32\drivers\Cdfs.sys [92160] =>.Microsoft Corporation
      [MD5.613D0137C269187FA298A157E3D14A18] - 16/07/2016 - (.Microsoft Corporation - SCSI CD-ROM Driver.) – C:\WINDOWS\System32\drivers\Cdrom.sys [173056] =>.Microsoft Corporation
      [MD5.7EAFDEF51136E8F2452CEBD8D084F108] - 14/06/2017 - (.Microsoft Corporation - DFS Namespace Client Driver.) – C:\WINDOWS\System32\drivers\DfsC.sys [144384] =>.Microsoft Corporation
      [MD5.10E3515FE5DBA6656FA62C29342EC4A1] - 16/07/2016 - (.Microsoft Corporation - High Definition Audio Bus Driver.) – C:\WINDOWS\System32\drivers\HDAudBus.sys [83456] =>.Microsoft Corporation
      [MD5.B54B30992620C97230013A74461C8517] - 16/07/2016 - (.Microsoft Corporation - i8042 Port Driver.) – C:\WINDOWS\System32\drivers\i8042prt.sys [114176] =>.Microsoft Corporation
      [MD5.F1DAECC3B3D6399875D4F10529D6A77C] - 16/07/2016 - (.Microsoft Corporation - IP Network Address Translator.) – C:\WINDOWS\System32\drivers\IpNat.sys [212480] =>.Microsoft Corporation
      [MD5.C9BB4E2FCAB693FEB00CF940060D94F4] - 14/06/2017 - (.Microsoft Corporation - Windows NT SMB Minirdr.) – C:\WINDOWS\System32\drivers\MRxSmb.sys [449376] =>.Microsoft Windows®
      [MD5.6FEBB0A847FFD5F057B9AC8889F1B9A7] - 16/07/2016 - (.Microsoft Corporation - MBT Transport driver.) – C:\WINDOWS\System32\drivers\netBT.sys [279040] =>.Microsoft Corporation
      [MD5.D1AF837A1555990602A51A3ED238EC80] - 14/06/2017 - (.Microsoft Corporation - NT File System Driver.) – C:\WINDOWS\System32\drivers\ntfs.sys [2257248] =>.Microsoft Windows®
      [MD5.6B81BF7853D161DB8AC62CD8B9C2DE6B] - 16/07/2016 - (.Microsoft Corporation - Parallel Port Driver.) – C:\WINDOWS\System32\drivers\Parport.sys [96768] =>.Microsoft Corporation
      [MD5.17E565710172ED71B8531D8822E1C5D1] - 16/07/2016 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) – C:\WINDOWS\System32\drivers\Rasl2tp.sys [104960] =>.Microsoft Corporation
      [MD5.7135785C21CA79D270D11037C43D3F19] - 16/07/2016 - (.Microsoft Corporation - Microsoft RDP Device redirector.) – C:\WINDOWS\System32\drivers\rdpdr.sys [177152] =>.Microsoft Corporation
      [MD5.9D2DD64A0B51C56285512DC9454340F6] - 14/06/2017 - (.Microsoft Corporation - TDI Translation Driver.) – C:\WINDOWS\System32\drivers\tdx.sys [118112] =>.Microsoft Windows®
      [MD5.BF2546583BB75F01DDA60A7921DFB230] - 16/07/2016 - (.Microsoft Corporation - Volume Shadow Copy driver.) – C:\WINDOWS\System32\drivers\volsnap.sys [391520] =>.Microsoft Windows®

      —\ Non Microsoft non disabled Windows Services (3) - 2s
      O23 - Service: AdaptiveSleepService (AdaptiveSleepService) . (…) - C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe =>.ATI
      O23 - Service: (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\WINDOWS\system32\atiesrxx.exe =>.AMD
      O23 - Service: DTSAudioSvc (DTSAudioSvc) . (.DTS, Inc - DTS Audio Service.) - C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe =>.DTS, Inc.®

      —\ Services not Microsoft (SR=Run, SS=Stop) (3) - 15s
      SR - Auto [24/06/2016] [ 138752] AdaptiveSleepService (AdaptiveSleepService) . (…) - C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe =>.ATI
      SR - Auto [13/09/2016] [ 287232] (AMD External Events Utility) . (.AMD.) - C:\WINDOWS\system32\atiesrxx.exe =>.Microsoft Windows Hardware Compatibility Publisher®
      SR - Auto [24/06/2015] [ 249328] DTSAudioSvc (DTSAudioSvc) . (.DTS, Inc.) - C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe =>.DTS, Inc.®

      —\ Auto loading programs from Registry and folders (9) - 0s
      O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (.not file.)
      O4 - HKLM..\Run: [WindowsDefender] . (.Microsoft Corporation - Windows Defender notification icon.) – C:\Program Files\Windows Defender\MSASCuiL.exe =>.Microsoft Corporation
      O4 - HKLM..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Realtek HD Audio Manager.) – C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe =>.Realtek Semiconductor Corp®
      O4 - HKLM..\Run: [RtHDVBg_DTS] . (.Realtek Semiconductor - HD Audio Background Process.) – C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe =>.Realtek Semiconductor Corp®
      O4 - HKLM..\Run: [StartCN] . (.Advanced Micro Devices, Inc. - Radeon Settings: Host Application.) – C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe =>.Advanced Micro Devices, Inc.®
      O4 - HKCU..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) – C:\Users\Nick\AppData\Local\Microsoft\OneDrive\One Drive.exe =>.Microsoft Corporation®
      O4 - HKUS\S-1-5-19..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) – C:\Windows\syswow64\OneDriveSetup.exe =>.Microsoft Corporation®
      O4 - HKUS\S-1-5-20..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) – C:\Windows\syswow64\OneDriveSetup.exe =>.Microsoft Corporation®
      O4 - HKUS\S-1-5-21-3720547706-1333832102-3978629174-1001..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) – C:\Users\Nick\AppData\Local\Microsoft\OneDrive\One Drive.exe =>.Microsoft Corporation®

      —\ Process running (8) - 1s
      [MD5.00000000000000000000000000000000] - (.AMD - AMD External Events Service Module.) – C:\WINDOWS\system32\atiesrxx.exe [0] [PID.1420] =>.AMD
      [MD5.00000000000000000000000000000000] - (.AMD - AMD External Events Client Module.) – C:\WINDOWS\system32\atieclxx.exe [0] [PID.1516] =>.AMD
      [MD5.1CFD1A335D08564184F5E406D7E1A2C0] - (.DTS, Inc - DTS Audio Service.) – C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [249328] [PID.2224] =>.DTS, Inc.®
      [MD5.059E8944776CD96C4D48ADECE806D140] - (…) – C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe [138752] [PID.3848] =>.ATI Technologies
      [MD5.22EBD5AE3B3220D713E544D1D3AB3FEE] - (.Realtek Semiconductor - Realtek HD Audio Manager.) – C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800] [PID.3284] =>.Realtek Semiconductor Corp®
      [MD5.31821EC63BDEDE18E64C11F7248B32AB] - (.Realtek Semiconductor - HD Audio Background Process.) – C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624] [PID.3252] =>.Realtek Semiconductor Corp®
      [MD5.6B34B34C61D69D9B7B7A46B364C9FC47] - (.Advanced Micro Devices, Inc. - Radeon Settings: Host Application.) – C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [6613896] [PID.4684] =>.Advanced Micro Devices, Inc.®
      [MD5.EA5DD793D0CDAA296F99EB72EA9539C3] - (.Nicolas Coolman - ZHPDiag.) – C:\Users\Nick\Desktop\ZHPDiag3.exe [2742784] [PID.5352] =>.Nicolas Coolman

      —\ Internet Explorer Extensions, Start, Search (17) - 0s
      R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
      R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
      R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
      R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
      R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
      R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
      R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
      R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
      R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
      R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
      R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
      R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
      R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
      R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
      R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphan =>.Microsoft Internet Explorer
      R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1
      R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1

      —\ Internet Explorer, Proxy Management (3) - 0s
      R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyEnable = 0
      R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings,MigrateProxy = 1
      R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Para meters\Internet\ManualProxies =>.Microsoft

      —\ Line Analysis, IniFiles, Auto loading programs (3) - 0s
      F2 - REG:system.ini: UserInit=
      F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
      F2 - REG:system.ini: VMApplet=

      —\ Hosts file redirection (1) - 0s
      ~ Le fichier hôte est sain (The hosts file is clean) (0)

      —\ Global shortcuts Startup (42) - 1s
      O4 - GS\Desktop [Administrator]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleane.) C:\Users\Nick\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman
      O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Nick\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
      O4 - GS\sendTo [Administrator]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
      O4 - GS\sendTo [Administrator]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
      O4 - GS\Programs [Administrator]: AMD Radeon Settings.lnk . (.Advanced Micro Devices, Inc. - .) C:\Program Files (x86)\AMD\CNext\CNext\RadeonSettings.exe =>.Advanced Micro Devices, Inc.
      O4 - GS\Programs [Administrator]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Nick\AppData\Local\Microsoft\OneDrive\One Drive.exe =>.Microsoft Corporation®
      O4 - GS\Desktop [defaultuser0]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleane.) C:\Users\Nick\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman
      O4 - GS\Desktop [defaultuser0]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Nick\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
      O4 - GS\sendTo [defaultuser0]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
      O4 - GS\sendTo [defaultuser0]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
      O4 - GS\Programs [defaultuser0]: AMD Radeon Settings.lnk . (.Advanced Micro Devices, Inc. - .) C:\Program Files (x86)\AMD\CNext\CNext\RadeonSettings.exe =>.Advanced Micro Devices, Inc.
      O4 - GS\Programs [defaultuser0]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Nick\AppData\Local\Microsoft\OneDrive\One Drive.exe =>.Microsoft Corporation®
      O4 - GS\Desktop [Guest]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleane.) C:\Users\Nick\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman
      O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Nick\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
      O4 - GS\sendTo [Guest]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
      O4 - GS\sendTo [Guest]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
      O4 - GS\Programs [Guest]: AMD Radeon Settings.lnk . (.Advanced Micro Devices, Inc. - .) C:\Program Files (x86)\AMD\CNext\CNext\RadeonSettings.exe =>.Advanced Micro Devices, Inc.
      O4 - GS\Programs [Guest]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Nick\AppData\Local\Microsoft\OneDrive\One Drive.exe =>.Microsoft Corporation®
      O4 - GS\Desktop [Nick]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleane.) C:\Users\Nick\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman
      O4 - GS\Desktop [Nick]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Nick\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
      O4 - GS\sendTo [Nick]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
      O4 - GS\sendTo [Nick]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
      O4 - GS\Programs [Nick]: AMD Radeon Settings.lnk . (.Advanced Micro Devices, Inc. - .) C:\Program Files (x86)\AMD\CNext\CNext\RadeonSettings.exe =>.Advanced Micro Devices, Inc.
      O4 - GS\Programs [Nick]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Nick\AppData\Local\Microsoft\OneDrive\One Drive.exe =>.Microsoft Corporation®
      O4 - GS\Programs [Public]: AMD Radeon Settings.lnk . (.Advanced Micro Devices, Inc. - .) C:\Program Files (x86)\AMD\CNext\CNext\RadeonSettings.exe =>.Advanced Micro Devices, Inc.
      O4 - GS\Programs [Public]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Nick\AppData\Local\Microsoft\OneDrive\One Drive.exe =>.Microsoft Corporation®
      O4 - GS\Accessories [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
      O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Notepad.) C:\WINDOWS\system32\notepad.exe =>.Microsoft Corporation
      O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation
      O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\WINDOWS\system32\mspaint.exe =>.Microsoft Corporation
      O4 - GS\Accessories [Public]: Quick Assist.lnk . (.Microsoft Corporation - Quick Assist.) C:\WINDOWS\system32\quickassist.exe =>.Microsoft Corporation
      O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Remote Desktop Connection.) C:\WINDOWS\system32\mstsc.exe =>.Microsoft Corporation
      O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\WINDOWS\system32\SnippingTool.exe =>.Microsoft Corporation
      O4 - GS\Accessories [Public]: Steps Recorder.lnk . (.Microsoft Corporation - Steps Recorder.) C:\WINDOWS\system32\psr.exe =>.Microsoft Corporation
      O4 - GS\Accessories [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe =>.Microsoft Corporation
      O4 - GS\Accessories [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
      O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Windows Wordpad Application.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
      O4 - GS\Accessories [Public]: XPS Viewer.lnk . (.Microsoft Corporation - XPS Viewer.) C:\WINDOWS\system32\xpsrchvw.exe =>.Microsoft Corporation
      O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Character Map.) C:\WINDOWS\system32\charmap.exe =>.Microsoft Corporation
      O4 - GS\ProgramsCommon [Public]: Immersive Control Panel.lnk . (.Microsoft Corporation - Windows Control Panel.) C:\WINDOWS\System32\Control.exe =>.Microsoft Corporation
      O4 - GS\ProgramsCommon [Public]: MiracastView.lnk . (.Microsoft Corporation - MiracastView.) C:\WINDOWS\MiracastView\MiracastView.exe =>.Microsoft Windows®
      O4 - GS\ProgramsCommon [Public]: PrintDialog.lnk . (.Microsoft Corporation - Print Dialog.) C:\WINDOWS\PrintDialog\PrintDialog.exe =>.Microsoft Windows®

      —\ Extra protocols (22) - 1s
      O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) – C:\Windows\syswow64\mshtml.dll =>.Microsoft Corporation
      O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\syswow64\urlmon.dll =>.Microsoft Corporation
      O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) – C:\Windows\syswow64\MSVidCtl.dll =>.Microsoft Corporation
      O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\syswow64\urlmon.dll =>.Microsoft Corporation
      O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\syswow64\urlmon.dll =>.Microsoft Corporation
      O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\syswow64\urlmon.dll =>.Microsoft Corporation
      O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\syswow64\urlmon.dll =>.Microsoft Corporation
      O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) – C:\Windows\syswow64\itss.dll =>.Microsoft Corporation
      O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) – C:\Windows\syswow64\mshtml.dll =>.Microsoft Corporation
      O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\syswow64\urlmon.dll =>.Microsoft Corporation
      O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) – C:\Windows\syswow64\mshtml.dll =>.Microsoft Corporation
      O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) – C:\Windows\syswow64\inetcomm.dll =>.Microsoft Corporation
      O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\syswow64\urlmon.dll =>.Microsoft Corporation
      O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) – C:\Windows\syswow64\itss.dll =>.Microsoft Corporation
      O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) – C:\Windows\syswow64\mshtml.dll =>.Microsoft Corporation
      O18 - Handler: tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) – C:\Windows\syswow64\tbauth.dll =>.Microsoft Corporation
      O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) – C:\Windows\syswow64\MSVidCtl.dll =>.Microsoft Corporation
      O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) – C:\Windows\syswow64\mshtml.dll =>.Microsoft Corporation
      O18 - Handler: windows.tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) – C:\Windows\syswow64\tbauth.dll =>.Microsoft Corporation
      O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) – C:\Windows\syswow64\mscoree.dll =>.Microsoft Corporation
      O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) – C:\Windows\syswow64\mscoree.dll =>.Microsoft Corporation
      O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) – C:\Windows\syswow64\mscoree.dll =>.Microsoft Corporation

      —\ Software installed (2) - 2s
      O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] – {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} =>.Realtek Semiconductor Corp®
      O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM][64Bits] – SynTPDeinstKey =>.Synaptics Incorporated

      —\ HKCU & HKLM Software Keys (19) - 2s
      HKLM\SOFTWARE\Wow6432Node\ATI =>.ATI
      HKLM\SOFTWARE\Wow6432Node\ATI Technologies =>.ATI Technologies
      HKLM\SOFTWARE\Wow6432Node\Chicony =>.Chicony
      HKLM\SOFTWARE\Wow6432Node\Intel =>.Intel
      HKLM\SOFTWARE\Wow6432Node\Khronos =>.Khronos
      HKLM\SOFTWARE\Wow6432Node\Macromedia =>.Macromedia
      HKLM\SOFTWARE\Wow6432Node\Nuance =>.Nuance
      HKLM\SOFTWARE\Wow6432Node\ODBC =>.DB Connectivity Solutions
      HKLM\SOFTWARE\Wow6432Node\SRS Labs =>.SRS Labs
      HKLM\SOFTWARE\Wow6432Node\WOW6432Node =>.Microsoft Corporation
      HKLM\SOFTWARE\Wow6432Node\RegisteredApplications =>.Microsoft Corporation
      HKCU\SOFTWARE\AMD =>.AMD
      HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation
      HKCU\SOFTWARE\ATI =>.ATI
      HKCU\SOFTWARE\Realtek =>.Realtek Semiconductor Corp.
      HKCU\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
      HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation
      HKCU\SOFTWARE\ZHP =>.Nicolas Coolman
      HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation

      —\ Contents of the Common Files folders (90) - 1s
      O43 - CFD: 14/06/2017 - D – C:\Program Files\AMD =>.Advanced Micro Devices, Inc.®
      O43 - CFD: 14/06/2017 - D – C:\Program Files\ATI Technologies =>.ATI Technologies
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Common Files =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Internet Explorer =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\MSBuild =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Realtek =>.Realtek
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Reference Assemblies =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Synaptics =>.Synaptics
      O43 - CFD: 14/06/2017 - [0] HD – C:\Program Files\Uninstall Information =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Windows Defender =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Windows Defender Advanced Threat Protection =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Windows Mail =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Windows Media Player =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Windows Multimedia Platform =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Windows NT =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\Windows Portable Devices =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - SHD – C:\Program Files\Windows Sidebar =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - HD – C:\Program Files\WindowsApps =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files\WindowsPowerShell =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\AMD =>.AMD
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Common Files =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\MSBuild =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Windows Defender =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Windows Multimedia Platform =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Windows NT =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - SHD – C:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\WindowsPowerShell =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - RD – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - RD – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - RD – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
      O43 - CFD: 14/06/2017 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Settings =>.Advanced Micro Devices Inc
      O43 - CFD: 14/06/2017 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - RD – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - RD – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\ProgramData\Application Data =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\ProgramData\Desktop =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\ProgramData\Documents =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - SD – C:\ProgramData\Microsoft =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\ProgramData\Microsoft OneDrive =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\ProgramData\regid.1991-06.com.microsoft =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\ProgramData\Start Menu =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\ProgramData\Templates =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\ProgramData\USOPrivate =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\ProgramData\USOShared =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Common Files\Microsoft Shared =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Program Files (x86)\Common Files\System =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Roaming\Adobe =>.Adobe
      O43 - CFD: 14/06/2017 - SD – C:\Users\Nick\AppData\Roaming\Microsoft =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Roaming\ZHP =>.Nicolas Coolman
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Local\AMD =>.AMD
      O43 - CFD: 14/06/2017 - [0] SHD – C:\Users\Nick\AppData\Local\Application Data =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Local\Comms =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Local\ConnectedDevicesPlatfo rm =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Local\Diagnostics =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\Users\Nick\AppData\Local\History =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Local\Microsoft =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Local\MicrosoftEdge =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Local\Packages =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Local\Publishers =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Local\Temp =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\Users\Nick\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Local\TileDataLayer =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Local\ZHP =>.Nicolas Coolman
      O43 - CFD: 14/06/2017 - RD – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Accessibility =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - RD – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Accessories =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - RD – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Administrative Tools =>.Administrative Tools
      O43 - CFD: 14/06/2017 - D – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Maintenance =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - RD – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Startup =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - RD – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\System Tools =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - RD – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Windows PowerShell =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\Users\Default\AppData\Local\History =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] D – C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\Users\Default User\AppData\Local\History =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] D – C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - [0] SHD – C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
      O43 - CFD: 14/06/2017 - D – C:\WINDOWS\System32\Config\systemprofile\AppData\L ocal\Microsoft =>.Microsoft Corporation

      —\ ShellIconOverlayIdentifiers (SIOI) (5) - 0s
      O106 - SIOI: ErrorOverlayHandler Class [ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) – C:\Users\Nick\AppData\Local\Microsoft\OneDrive\17. 3.6381.0405\FileSyncShell.dll =>.Microsoft Corporation®
      O106 - SIOI: SharedOverlayHandler Class [ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) – C:\Users\Nick\AppData\Local\Microsoft\OneDrive\17. 3.6381.0405\FileSyncShell.dll =>.Microsoft Corporation®
      O106 - SIOI: SharedSyncingOverlayHandler Class [ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) – C:\Users\Nick\AppData\Local\Microsoft\OneDrive\17. 3.6381.0405\FileSyncShell.dll =>.Microsoft Corporation®
      O106 - SIOI: UpToDateOverlayHandler Class [ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) – C:\Users\Nick\AppData\Local\Microsoft\OneDrive\17. 3.6381.0405\FileSyncShell.dll =>.Microsoft Corporation®
      O106 - SIOI: SyncingOverlayHandler Class [ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) – C:\Users\Nick\AppData\Local\Microsoft\OneDrive\17. 3.6381.0405\FileSyncShell.dll =>.Microsoft Corporation®

      —\ Image File Execution Options (17) - 1s
      O50 - IFEO:C:\Windows\System32\cscript.exe - (.Microsoft Corporation - Microsoft ® Console Based Script Host.) [DisableExceptionChainValidation\3] =>.Microsoft Corporation
      O50 - IFEO:C:\Windows\System32\dllhost.exe - (.Microsoft Corporation - COM Surrogate.) [DisableExceptionChainValidation\3] =>.Microsoft Windows®
      O50 - IFEO:C:\WINDOWS\System32\drvinst.exe - (.Microsoft Corporation - Driver Installation Module.) [DisableExceptionChainValidation\3] =>.Microsoft Corporation
      O50 - IFEO:C:\WINDOWS\System32\ie4uinit.exe - (.Microsoft Corporation - IE Per-User Initialization Utility.) [MitigationOptions\256] =>.Microsoft Corporation
      O50 - IFEO:C:\Windows\System32\ieUnatt.exe - (.Microsoft Corporation - IE 7.0 Unattended Install Utility.) [MitigationOptions\256] =>.Microsoft Corporation
      O50 - IFEO:C:\Windows\System32\mmc.exe - (.Microsoft Corporation - Microsoft Management Console.) [DisableExceptionChainValidation\3] =>.Microsoft Corporation
      O50 - IFEO:C:\Windows\System32\msfeedssync.exe - (.Microsoft Corporation - Microsoft Feeds Synchronization.) [MitigationOptions\256] =>.Microsoft Corporation
      O50 - IFEO:C:\Windows\System32\mshta.exe - (.Microsoft Corporation - Microsoft (R) HTML Application host.) [MitigationOptions\256] =>.Microsoft Corporation
      O50 - IFEO:C:\Windows\System32\PresentationHost.exe - (.Microsoft Corporation - Windows Presentation Foundation Host.) [MitigationOptions\1118481] =>.Microsoft Corporation
      O50 - IFEO:C:\WINDOWS\System32\PrintIsolationHost.exe - (.Microsoft Corporation - PrintIsolationHost.) [MitigationOptions\2097152] =>.Microsoft Corporation
      O50 - IFEO:C:\Windows\System32\rundll32.exe - (.Microsoft Corporation - Windows host process (Rundll32).) [DisableExceptionChainValidation\3] =>.Microsoft Corporation
      O50 - IFEO:C:\WINDOWS\System32\runtimebroker.exe - (.Microsoft Corporation - Runtime Broker.) [MitigationOptions\4294967296] =>.Microsoft Corporation
      O50 - IFEO:C:\Windows\System32\searchprotocolhost.exe - (.Microsoft Corporation - Microsoft Windows Search Protocol Host.) [DisableExceptionChainValidation\3] =>.Microsoft Corporation
      O50 - IFEO:C:\WINDOWS\System32\spoolsv.exe - (.Microsoft Corporation - Spooler SubSystem App.) [DisableExceptionChainValidation\3] =>.Microsoft Corporation
      O50 - IFEO:C:\WINDOWS\System32\spoolsv.exe - (.Microsoft Corporation - Spooler SubSystem App.) [MitigationOptions\2097152] =>.Microsoft Corporation
      O50 - IFEO:C:\Windows\System32\svchost.exe - (.Microsoft Corporation - Host Process for Windows Services.) [MinimumStackCommitInBytes\32768] =>.Microsoft Windows Publisher®
      O50 - IFEO:C:\Windows\System32\wscript.exe - (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) [DisableExceptionChainValidation\3] =>.Microsoft Corporation

      —\ System Drivers List (94) - 8s
      O58 - SDL:2016/07/16 07:41:53 A . (.LSI - LSI 3ware SCSI Storport Driver.) – C:\WINDOWS\System32\drivers\3ware.sys [107360] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) – C:\WINDOWS\System32\drivers\adp80xx.sys [1135456] =>.Microsoft Windows®
      O58 - SDL:2016/03/21 10:37:24 A . (.Advanced Micro Devices, Inc. - AMD Audio Bus Lower Filter.) – C:\WINDOWS\System32\drivers\amdkmafd.sys [23240] =>.Advanced Micro Devices, Inc.®
      O58 - SDL:2016/07/16 07:41:53 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) – C:\WINDOWS\System32\drivers\amdsata.sys [83296] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) – C:\WINDOWS\System32\drivers\amdsbs.sys [259424] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Advanced Micro Devices - Storage Filter Driver.) – C:\WINDOWS\System32\drivers\amdxata.sys [26976] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) – C:\WINDOWS\System32\drivers\arcsas.sys [131936] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:50 A . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) – C:\WINDOWS\System32\drivers\athw8x.sys [4233728] =>.Qualcomm Atheros Communications, Inc.
      O58 - SDL:2016/04/26 06:26:52 A . (.Advanced Micro Devices - AMD High Definition Audio Function Driver.) – C:\WINDOWS\System32\drivers\AtihdWT6.sys [110096] =>.Microsoft Windows Hardware Compatibility Publisher®
      O58 - SDL:2016/09/13 22:08:14 A . (.Advanced Micro Devices, Inc. - ATI Radeon Kernel Mode Driver.) – C:\WINDOWS\System32\drivers\atikmdag.sys [26706432] =>.Microsoft Windows Hardware Compatibility Publisher®
      O58 - SDL:2016/09/13 22:08:12 A . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) – C:\WINDOWS\System32\drivers\atikmpag.sys [518656] =>.Microsoft Windows Hardware Compatibility Publisher®
      O58 - SDL:2016/07/16 07:41:53 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) – C:\WINDOWS\System32\drivers\bcmfn.sys [9728] =>.Windows (R) Win 7 DDK provider
      O58 - SDL:2016/07/16 07:41:53 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) – C:\WINDOWS\System32\drivers\bcmfn2.sys [9728] =>.Windows (R) Win 7 DDK provider
      O58 - SDL:2016/07/16 07:41:52 A . (.QLogic Corporation - QLogic Gigabit Ethernet VBD.) – C:\WINDOWS\System32\drivers\bxvbda.sys [533856] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Chelsio Communications - Chelsio iSCSI Crash Dump Driver.) – C:\WINDOWS\System32\drivers\cht4dx64.sys [102752] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Chelsio Communications - Chelsio iSCSI VMiniport Driver.) – C:\WINDOWS\System32\drivers\cht4sx64.sys [346976] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Chelsio Communications - Virtual Bus Driver for Chelsio ® T4 Chipset.) – C:\WINDOWS\System32\drivers\cht4vx64.sys [2104160] =>.Microsoft Windows®
      O58 - SDL:2013/08/21 06:09:38 A . (.Intel Corporation - Intel(R) Gigabit Adapter NDIS 6.x driver.) – C:\WINDOWS\System32\drivers\e1c64x64.sys [468240] =>.Intel Corporation®
      O58 - SDL:2016/07/16 07:41:54 A . (.Intel Corporation - Intel(R) Gigabit Adapter NDIS 6.x driver.) – C:\WINDOWS\System32\drivers\e1i63x64.sys [524800] =>.Intel Corporation
      O58 - SDL:2016/07/16 07:41:52 A . (.QLogic Corporation - QLogic 10 GigE VBD.) – C:\WINDOWS\System32\drivers\evbda.sys [3418976] =>.Microsoft Windows®
      O58 - SDL:2012/07/17 18:12:08 A . (.Intel Corporation - Intel(R) Management Engine Interface.) – C:\WINDOWS\System32\drivers\HECIx64.sys [62784] =>.Intel Corporation®
      O58 - SDL:2016/07/16 07:41:53 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) – C:\WINDOWS\System32\drivers\HpSAMD.sys [64352] =>.Microsoft Windows®
      O58 - SDL:2009/08/15 00:58:04 A . (.Windows (R) Codename Longhorn DDK provider - Example Keyboard Filter Driver.) – C:\WINDOWS\System32\drivers\i8042HDR.sys [15920] =>.Chicony Electronics Co., Ltd.®
      O58 - SDL:2016/07/16 07:41:54 A . (.Intel(R) Corporation - Intel(R) Serial IO GPIO Controller Driver.) – C:\WINDOWS\System32\drivers\iagpio.sys [33280] =>.Intel(R) Corporation
      O58 - SDL:2016/07/16 07:41:54 A . (.Intel(R) Corporation - Intel(R) Serial IO I2C Driver.) – C:\WINDOWS\System32\drivers\iai2c.sys [81408] =>.Intel(R) Corporation
      O58 - SDL:2016/07/16 07:41:54 A . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) – C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [64512] =>.Intel Corporation
      O58 - SDL:2016/07/16 07:41:54 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) – C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [176384] =>.Intel Corporation - Embedded Subsystems and IP Blocks Group®
      O58 - SDL:2016/07/16 07:41:52 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) – C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [38128] =>.Intel Corporation - Client Components Group®
      O58 - SDL:2016/07/16 07:41:50 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) – C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [113152] =>.Intel Corporation
      O58 - SDL:2016/07/16 07:41:53 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) – C:\WINDOWS\System32\drivers\iaStorAV.sys [673120] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) – C:\WINDOWS\System32\drivers\iaStorV.sys [412000] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Mellanox - InfiniBand Fabric Bus Driver.) – C:\WINDOWS\System32\drivers\ibbus.sys [526176] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) – C:\WINDOWS\System32\drivers\lsi_sas.sys [108896] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) – C:\WINDOWS\System32\drivers\lsi_sas2i.sys [105824] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) – C:\WINDOWS\System32\drivers\lsi_sas3i.sys [101216] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) – C:\WINDOWS\System32\drivers\lsi_sss.sys [82776] =>.Microsoft Windows®
      O58 - SDL:2012/10/26 16:42:22 A . (.Logitech Inc. - Logitech USB Video Class Filter Driver.) – C:\WINDOWS\System32\drivers\lvbflt64.sys [26784] =>.Logitech, Inc.®
      O58 - SDL:2016/07/16 07:41:53 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) – C:\WINDOWS\System32\drivers\megasas.sys [59744] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) – C:\WINDOWS\System32\drivers\megasr.sys [575840] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Mellanox - MLX4 Bus Driver.) – C:\WINDOWS\System32\drivers\mlx4_bus.sys [842584] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) – C:\WINDOWS\System32\drivers\mvumis.sys [63840] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Mellanox - NetworkDirect Support Filter Driver.) – C:\WINDOWS\System32\drivers\ndfltr.sys [108896] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:42:03 A . (.Authors - .) – C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624] =>.Microsoft Corporation
      O58 - SDL:2016/07/16 07:41:53 A . (.NVIDIA Corporation - NVIDIA® nForce™ RAID Driver.) – C:\WINDOWS\System32\drivers\nvraid.sys [150368] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.NVIDIA Corporation - NVIDIA® nForce™ Sata Performance Driver.) – C:\WINDOWS\System32\drivers\nvstor.sys [166240] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) – C:\WINDOWS\System32\drivers\percsas2i.sys [58720] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) – C:\WINDOWS\System32\drivers\percsas3i.sys [61792] =>.Microsoft Windows®
      O58 - SDL:2015/06/24 22:57:00 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) – C:\WINDOWS\System32\drivers\RTKVHD64.sys [4504320] =>.Realtek Semiconductor Corp®
      O58 - SDL:2015/08/13 11:36:50 A . (.Razer Inc - Razer RzBTEndPt.) – C:\WINDOWS\System32\drivers\rzbtendpt.sys [51912] =>.Razer Inc.®
      O58 - SDL:2015/08/13 11:36:50 A . (.Razer Inc - Razer RzEndPt.) – C:\WINDOWS\System32\drivers\rzdaendpt.sys [43720] =>.Razer Inc.®
      O58 - SDL:2015/08/13 11:36:50 A . (.Razer Inc - Razer RzEndPt.) – C:\WINDOWS\System32\drivers\rzendpt.sys [50392] =>.Razer Inc.®
      O58 - SDL:2015/08/13 11:36:50 A . (.Razer Inc - Razer Inc. External Display Driver.) – C:\WINDOWS\System32\drivers\rzhnet.sys [29912] =>.Razer Inc.®
      O58 - SDL:2015/08/13 11:36:50 A . (.Razer Inc - Razer JoyStick Device.) – C:\WINDOWS\System32\drivers\rzjstk.sys [36568] =>.Razer Inc.®
      O58 - SDL:2015/08/13 11:36:50 A . (.Razer Inc - Razer RzEndPt.) – C:\WINDOWS\System32\drivers\rzkeypadendpt.sys [46280] =>.Razer Inc.®
      O58 - SDL:2015/08/13 11:36:50 A . (.Razer Inc - Razer RzMPos.) – C:\WINDOWS\System32\drivers\rzmpos.sys [48840] =>.Razer Inc.®
      O58 - SDL:2015/08/13 11:36:50 A . (.Razer Inc - Razer RzEndPt.) – C:\WINDOWS\System32\drivers\rzp1endpt.sys [52424] =>.Razer Inc.®
      O58 - SDL:2015/08/13 11:36:50 A . (.Razer Inc - Razer Rzudd Engine.) – C:\WINDOWS\System32\drivers\rzudd.sys [202952] =>.Razer Inc.®
      O58 - SDL:2015/08/13 11:36:50 A . (.Razer Inc - Razer Keyboard Device.) – C:\WINDOWS\System32\drivers\rzvkeyboard.sys [44232] =>.Razer Inc.®
      O58 - SDL:2015/08/13 11:36:50 A . (.Razer Inc - Razer Mouse Device.) – C:\WINDOWS\System32\drivers\rzvmouse.sys [42712] =>.Razer Inc.®
      O58 - SDL:2016/07/16 07:41:53 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) – C:\WINDOWS\System32\drivers\sisraid2.sys [44896] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) – C:\WINDOWS\System32\drivers\sisraid4.sys [81760] =>.Microsoft Windows®
      O58 - SDL:1999/12/31 20:00:00 A . (.Synaptics Incorporated - Synaptics SMBus Driver.) – C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [33960] =>.Synaptics Incorporated®
      O58 - SDL:2016/01/08 04:51:46 A . (.MCCI Corporation - SAMSUNG Android USB Composite Device Driver.) – C:\WINDOWS\System32\drivers\ssadbus.sys [169288] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:46 A . (.MCCI Corporation - Windows 2000/XP support functions.) – C:\WINDOWS\System32\drivers\ssadcm.sys [17224] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:46 A . (.MCCI Corporation - Windows 2000/XP support functions.) – C:\WINDOWS\System32\drivers\ssadcmnt.sys [17224] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:46 A . (.MCCI Corporation - SAMSUNG Android USB Diagnostic Serial Port.) – C:\WINDOWS\System32\drivers\ssadserd.sys [158024] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:46 A . (.MCCI Corporation - Windows 2000/XP support functions.) – C:\WINDOWS\System32\drivers\ssadwh.sys [17736] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:46 A . (.MCCI Corporation - Windows 2000/XP support functions.) – C:\WINDOWS\System32\drivers\ssadwhnt.sys [17736] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:52 A . (.MCCI Corporation - SAMSUNG USB Composite Device Driver.) – C:\WINDOWS\System32\drivers\sscdbus.sys [169288] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:52 A . (.MCCI Corporation - Windows 2000/XP support functions.) – C:\WINDOWS\System32\drivers\sscdcm.sys [17224] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:52 A . (.MCCI Corporation - Windows 2000/XP support functions.) – C:\WINDOWS\System32\drivers\sscdcmnt.sys [17224] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:52 A . (.MCCI Corporation - SAMSUNG Mobile Modem Diagnostic Serial Port.) – C:\WINDOWS\System32\drivers\sscdserd.sys [158024] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:52 A . (.MCCI Corporation - Windows 2000/XP support functions.) – C:\WINDOWS\System32\drivers\sscdwh.sys [17736] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:52 A . (.MCCI Corporation - Windows 2000/XP support functions.) – C:\WINDOWS\System32\drivers\sscdwhnt.sys [17736] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:54 A . (.MCCI Corporation - SAMSUNG USB Composite Device V2 Driver.) – C:\WINDOWS\System32\drivers\sscebus.sys [169288] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:54 A . (.MCCI Corporation - Windows 2000/XP support functions.) – C:\WINDOWS\System32\drivers\sscecm.sys [17224] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:54 A . (.MCCI Corporation - Windows 2000/XP support functions.) – C:\WINDOWS\System32\drivers\sscecmnt.sys [17224] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:54 A . (.MCCI Corporation - SAMSUNG Mobile Modem Diagnostic Serial Port.) – C:\WINDOWS\System32\drivers\ssceserd.sys [158024] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:54 A . (.MCCI Corporation - Windows 2000/XP support functions.) – C:\WINDOWS\System32\drivers\sscewh.sys [17736] =>.MCCI Corporation®
      O58 - SDL:2016/01/08 04:51:54 A . (.MCCI Corporation - Windows 2000/XP support functions.) – C:\WINDOWS\System32\drivers\sscewhnt.sys [17736] =>.MCCI Corporation®
      O58 - SDL:2016/04/25 00:35:52 A . (.Samsung Electronics Co., Ltd. - SAMSUNG USB Composite Device Driver (MSS Ve.) – C:\WINDOWS\System32\drivers\ssudbus.sys [129152] =>.Samsung Electronics CO., LTD.®
      O58 - SDL:2016/01/08 04:51:54 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Mobile DevMgr Device Driver (MS.) – C:\WINDOWS\System32\drivers\ssuddmgr.sys [213088] =>.Samsung Electronics CO., LTD.®
      O58 - SDL:2016/01/08 04:51:54 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Mobile OBEX Device Driver (MSS.) – C:\WINDOWS\System32\drivers\ssudobex.sys [213088] =>.Samsung Electronics CO., LTD.®
      O58 - SDL:2016/04/25 00:36:00 A . (.QUALCOMM Incorporated - Filter Driver for the Qualcomm USB Driver S.) – C:\WINDOWS\System32\drivers\ssudqcfilter.sys [64640] =>.Samsung Electronics CO., LTD.®
      O58 - SDL:2016/01/08 04:51:54 A . (.DEVGURU Co., LTD. - USB Rmnet Device Driver.) – C:\WINDOWS\System32\drivers\ssudrmnet.sys [77408] =>.Samsung Electronics CO., LTD.®
      O58 - SDL:2016/01/08 04:51:54 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Mobile Logging Device Driver (M.) – C:\WINDOWS\System32\drivers\ssudserd.sys [213088] =>.Samsung Electronics CO., LTD.®
      O58 - SDL:2016/01/08 04:51:54 A . (.DEVGURU Co., LTD. - MSS CS Connectivity USB driver.) – C:\WINDOWS\System32\drivers\ss_conn_usb_driver.sys [33376] =>.Samsung Electronics CO., LTD.®
      O58 - SDL:2016/07/16 07:41:53 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) – C:\WINDOWS\System32\drivers\stexstor.sys [31072] =>.Microsoft Windows®
      O58 - SDL:2015/08/13 11:36:50 A . (.Synaptics Incorporated - Synaptics Touchpad Win64 Driver.) – C:\WINDOWS\System32\drivers\SynTP.sys [615632] =>.Synaptics Incorporated®
      O58 - SDL:2016/01/19 18:40:20 A . (.Oracle Corporation - VirtualBox USB Driver.) – C:\WINDOWS\System32\drivers\VBoxUSB.sys [125008] =>.Oracle Corporation®
      O58 - SDL:2016/07/16 07:41:53 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) – C:\WINDOWS\System32\drivers\vsmraid.sys [166752] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) – C:\WINDOWS\System32\drivers\VSTXRAID.SYS [305504] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Mellanox - Kernel WinMad.) – C:\WINDOWS\System32\drivers\winmad.sys [32096] =>.Microsoft Windows®
      O58 - SDL:2016/07/16 07:41:53 A . (.Mellanox - Kernel WinVerbs.) – C:\WINDOWS\System32\drivers\winverbs.sys [64864] =>.Microsoft Windows®

      —\ Last modified or created user files (1) - 1s
      O61 - LFC: 2017/06/14 22:09:58 A . (..) – C:\Users\Nick\Desktop\zoek.exe [1309184]

      —\ File Associations Shell Spawning (10) - 0s
      O67 - Shell Spawning: <.bat> [HKLM..\open\Command] (…) – “%1” %*
      O67 - Shell Spawning: <.cpl> [HKLM..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) – C:\Windows\System32\control.exe =>.Microsoft Corporation
      O67 - Shell Spawning: <.cmd> [HKLM..\open\Command] (…) – “%1” %*
      O67 - Shell Spawning: <.com> [HKLM..\open\Command] (…) – “%1” %*
      O67 - Shell Spawning: <.evt> [HKLM..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) – C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation
      O67 - Shell Spawning: <.exe> [HKLM..\open\Command] (…) – “%1” %*
      O67 - Shell Spawning: <.html> [HKLM..\open\Command] (.Microsoft Corporation - Internet Explorer.) – C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
      O67 - Shell Spawning: <.js> [HKLM..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) – C:\Windows\System32\wscript.exe =>.Microsoft Corporation
      O67 - Shell Spawning: <.reg> [HKLM..\open\Command] (.Microsoft Corporation - Registry Editor.) – C:\Windows\regedit.exe =>.Microsoft Corporation
      O67 - Shell Spawning: <.scr> [HKLM..\open\Command] (…) – “%1” /S

      —\ Start Menu Internet (4) - 0s
      O68 - StartMenuInternet: <IEXPLORE.EXE> [HKLM..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) – C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
      O68 - StartMenuInternet: <IEXPLORE.EXE> [HKLM..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) – C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
      O68 - StartMenuInternet: <IEXPLORE.EXE> [HKLM..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) – C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
      O68 - StartMenuInternet: <IEXPLORE.EXE> [HKLM..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) – C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation

      —\ Search Browser Infection (3) - 0s
      O69 - SBI: SearchScopes [HKCU] {012E1000-F331-11DB-8314-0800200C9A66} [DefaultScope] - (Google) - http://www.google.com/ =>.Google Inc.
      O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com/ =>.Bing.com
      O69 - SBI: SearchScopes [HKLM] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/ =>.Bing.com

      —\ Search Svchost Services (46) - 1s
      O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) – C:\WINDOWS\System32\certprop.dll [193536] =>.Microsoft Corporation
      O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) – C:\WINDOWS\System32\certprop.dll [193536] =>.Microsoft Corporation
      O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) – C:\WINDOWS\system32\srvsvc.dll [305152] =>.Microsoft Corporation
      O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) – C:\WINDOWS\System32\gpsvc.dll [1225728] =>.Microsoft Corporation
      O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) – C:\WINDOWS\System32\ikeext.dll [932352] =>.Microsoft Corporation
      O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Software installation Service.) – C:\Windows\System32\appmgmts.dll [197632] =>.Microsoft Corporation
      O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) – C:\WINDOWS\System32\iphlpsvc.dll [945664] =>.Microsoft Corporation
      O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) – C:\WINDOWS\system32\seclogon.dll [31232] =>.Microsoft Corporation
      O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) – C:\WINDOWS\System32\appinfo.dll [125952] =>.Microsoft Corporation
      O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) – C:\WINDOWS\system32\iscsiexe.dll [151552] =>.Microsoft Corporation
      O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) – C:\WINDOWS\System32\eapsvc.dll [112128] =>.Microsoft Corporation
      O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) – C:\WINDOWS\system32\schedsvc.dll [948224] =>.Microsoft Corporation
      O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) – C:\WINDOWS\system32\wbem\WMIsvc.dll [222720] =>.Microsoft Corporation
      O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - Computer Browser Service DLL.) – C:\WINDOWS\System32\browser.dll [134656] =>.Microsoft Corporation
      O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) – C:\WINDOWS\system32\profsvc.dll [358400] =>.Microsoft Corporation
      O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) – C:\Windows\System32\SessEnv.dll [386560] =>.Microsoft Corporation
      O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) – C:\WINDOWS\System32\wercplsupport.dll [94208] =>.Microsoft Corporation
      O83 - Search Svchost Services: shpamsvc (shpamsvc) . (.Microsoft Corporation - SharedPC.AccountManager.) – C:\WINDOWS\system32\Windows.SharedPC.AccountManage r.dll [161792] =>.Microsoft Corporation
      O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) – C:\WINDOWS\System32\XblGameSave.dll [1159680] =>.Microsoft Corporation
      O83 - Search Svchost Services: DcpSvc (DcpSvc) . (.Microsoft Corporation - dcpsvc Task.) – C:\WINDOWS\system32\dcpsvc.dll [183808] =>.Microsoft Corporation
      O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Microsoft® Account Service.) – C:\WINDOWS\system32\wlidsvc.dll [2104832] =>.Microsoft Corporation
      O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Microsoft Network Connectivity Assistant Se.) – C:\WINDOWS\System32\ncasvc.dll [167936] =>.Microsoft Corporation
      O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Network Setup Service.) – C:\WINDOWS\System32\NetSetupSvc.dll [265216] =>.Microsoft Corporation
      O83 - Search Svchost Services: WpnService (WpnService) . (.Microsoft Corporation - Windows Push Notification System Service.) – C:\WINDOWS\system32\WpnService.dll [234496] =>.Microsoft Corporation
      O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) – C:\WINDOWS\System32\bdesvc.dll [354304] =>.Microsoft Corporation
      O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) – C:\WINDOWS\system32\XboxNetApiSvc.dll [1025536] =>.Microsoft Corporation
      O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Update Session Orchestrator Core.) – C:\WINDOWS\system32\usocore.dll [539136] =>.Microsoft Corporation
      O83 - Search Svchost Services: wisvc (wisvc) . (.Microsoft Corporation - Flight Settings.) – C:\WINDOWS\system32\flightsettings.dll [614912] =>.Microsoft Corporation
      O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) – C:\WINDOWS\system32\dmwappushsvc.dll [57344] =>.Microsoft Corporation
      O83 - Search Svchost Services: Irmon (Irmon) . (.Microsoft Corporation - Infrared Monitor.) – C:\WINDOWS\System32\irmon.dll [25088] =>.Microsoft Corporation
      O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) – C:\WINDOWS\System32\rasauto.dll [105472] =>.Microsoft Corporation
      O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) – C:\WINDOWS\System32\rasmans.dll [647680] =>.Microsoft Corporation
      O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) – C:\Windows\System32\mprdim.dll [495104] =>.Microsoft Corporation
      O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) – C:\WINDOWS\System32\sens.dll [70656] =>.Microsoft Corporation
      O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) – C:\WINDOWS\System32\ipnathlp.dll [541696] =>.Microsoft Corporation
      O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows™ Telephony Server.) – C:\Windows\System32\tapisrv.dll [309248] =>.Microsoft Corporation
      O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) – C:\WINDOWS\system32\wuaueng.dll [2314752] =>.Microsoft Corporation
      O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) – C:\WINDOWS\System32\qmgr.dll [1052672] =>.Microsoft Corporation
      O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) – C:\Windows\System32\shsvcs.dll [617472] =>.Microsoft Corporation
      O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) – C:\WINDOWS\system32\themeservice.dll [70656] =>.Microsoft Corporation
      O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - Windows Managent Service DLL.) – C:\Windows\System32\Windows.Internal.Management.dl l [407552] =>.Microsoft Corporation
      O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Geolocation Service.) – C:\WINDOWS\System32\lfsvc.dll [37376] =>.Microsoft Corporation
      O83 - Search Svchost Services: RetailDemo (RetailDemo) . (.Microsoft Corporation - RDXService.) – C:\WINDOWS\system32\RDXService.dll [650752] =>.Microsoft Corporation
      O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) – C:\WINDOWS\System32\XblAuthManager.dll [1012224] =>.Microsoft Corporation
      O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) – C:\WINDOWS\System32\usermgr.dll [1020928] =>.Microsoft Corporation
      O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Device Setup Manager.) – C:\WINDOWS\System32\DeviceSetupManager.dll [197632] =>.Microsoft Corporation

      —\ Additional Scan (O88) (1) - 0s
      ~ No malicious or unnecessary items found.

      —\ Summary of the elements found (1) - 0s
      ~ No malicious or unnecessary items found.

      ~ Unselected Options:
      ~ End of the scan, 9841 items in 00mn56s (529)(0)

      Comment

      • Malnutrition
        PCHF Moderator
        • Jul 2016
        • 7045

        #4
        Eliminate restrictive settings with this tool.
        [ul]
        [li]Temporarily disable your antivirus — Your antivirus may flag this tool as malware, it is safe to run I assure you.[/li]
        [li]Download SupRestric.exe save to your desktop.[/li][li]Close all running programs.[/li][li]Double click the file to launch it.[/li][li]Windows: 7/8/10 Vista and run as administrator[/li][li]Click Yes at any prompt.[/li]
        [li]The analysis takes only a few moments.[/li][li]The report is on the desktop ( CTR.txt )[/li][li]Copy paste report in next reply.[/li][li]A reboot is needed to complete the repairs.[/li][/ul]

        HijackThis.

        1- Please Click HERE to download HijackThis. – Unzip to your desktop.
        2- Right click run as admin.
        3- Click on the Main Menu button if not already there.
        4- Select Do a system scan and save a logfile.
        5- Copy paste the log here.

        Rogue Killer Scan.

        Download RogueKiller – (Portable) – from one of the following links and save it to your Desktop:

        Link 1
        Link 2

        [ul]
        [li]Close all other the running programs[/li][li]Disable ALL Antivirus – Antimalware – Applications.[/li][li]Right Click Rogue Killer and Run as Administrator.[/li][li]Click the Start Scan button.[/li][li]Allow the scan to run – it can take ten minutes or more.[/li][li]Once the scan is complete check All items for removal.[/li][li]https://pchelpforum.net/attachments/...5-54-png.1658/ [/li]
        [li]After All items are checked then press Remove Selected.[/li]
        [li]Wait until the Status box shows Deleting Finished.[/li][li]Click on open report – then open txt[/li]
        [li]Copy the content of the report and paste it here in your next reply.[/li][/ul]

        JRT Scan.

        Please download Junkware Removal Tool and save it on your desktop.

        [ul]
        [li]Shut down your anti-virus, anti-spyware, and firewall software now to avoid potential conflicts.[/li][li]Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click it and select Run as administrator.[/li][li]The tool will open and start scanning your system.[/li][li]Please be patient as this can take a while to complete depending on your system’s specifications.[/li][li]On completion, a log is saved to your desktop and will automatically open.[/li][li]Please post the JRT log.[/li][/ul]

        Comment

        • Malnutrition
          PCHF Moderator
          • Jul 2016
          • 7045

          #5
          @nick1234 How about an update

          Comment

          • Malnutrition
            PCHF Moderator
            • Jul 2016
            • 7045

            #6
            Hello @nick1234

            How are you moving along with the instructions? Have you got an update for us?

            Please update this thread within 48 hours, or it will be closed. You can however have it re-opened at any time, by sending a private message to a staff member.

            Comment

            Working...