Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-10-2017
Ran by SYSTEM on MININT-8765UG2 (12-10-2017 15:53:08)
Running from f:\
Platform: Windows 10 Home Version 1703 170317-1834 (X64) Language: English (United States)
Internet Explorer Version 11
Boot Mode: Recovery
Default: ControlSet001
ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16475392 2016-05-12] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1429248 2016-05-12] (Realtek Semiconductor)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [35736 2010-11-15] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-11-15] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2013-05-01] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe [3576784 2012-12-18] (ASUS Cloud Corporation)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-01] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-10] (Oracle Corporation)
Startup: C:\Users\Charne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk [2014-01-30]
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
S2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe [72192 2012-12-18] ()
S2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3059440 2017-07-18] (Microsoft Corporation)
S2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.)
S2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [337888 2016-05-03] (Intel Corporation)
S2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
S2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [754280 2015-05-13] (McAfee, Inc.)
S3 McAWFwk; C:\Program Files\Common Files\mcafee\ActWiz\McAWFwk.exe [334760 2012-12-21] (McAfee, Inc.)
S2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\1.5.495.0\McCSPServiceHost.exe [207344 2015-06-04] (McAfee, Inc.)
S2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.)
S2 McNaiAnn; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [609592 2015-05-05] (McAfee, Inc.)
S4 McOobeSv2; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.)
S2 mcpltsvc; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.)
S2 McProxy; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.)
S3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [232656 2015-06-29] (McAfee, Inc.)
S2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [373704 2015-07-06] (McAfee, Inc.)
S2 mfevtp; C:\windows\system32\mfevtps.exe [254792 2015-06-29] (McAfee, Inc.)
S2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.)
S2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5491984 2015-05-20] (TeamViewer GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
S2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-07-10] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 ATP; C:\Windows\System32\drivers\AsusTP.sys [101368 2015-12-14] (ASUS Corporation)
S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [77536 2015-07-02] (McAfee, Inc.)
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [198448 2015-04-27] (McAfee, Inc.)
S3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-01] ( )
S2 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [412440 2015-07-02] (McAfee, Inc.)
S2 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [347800 2015-07-02] (McAfee, Inc.)
S0 mfedisk; C:\Windows\System32\DRIVERS\mfedisk.sys [101872 2015-04-08] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [80920 2015-07-02] (McAfee, Inc.)
S3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [496888 2015-07-02] (McAfee, Inc.)
S2 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [875928 2015-07-02] (McAfee, Inc.)
S3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [483240 2015-03-26] (McAfee, Inc.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [100720 2015-03-26] (McAfee, Inc.)
S2 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [344704 2015-07-02] (McAfee, Inc.)
S3 NETwNb64; C:\Windows\System32\drivers\Netwbw02.sys [3485696 2017-03-18] (Intel Corporation)
S3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [895256 2015-07-07] (Realtek )
S3 SDFRd; C:\Windows\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
S0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-10-12 15:53 - 2017-10-12 15:53 - 000000000 ____D C:\FRST
2017-10-09 14:06 - 2017-10-09 15:31 - 000000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2017-10-09 13:40 - 2017-10-09 13:40 - 000000000 ____D C:\Windows\LastGood.Tmp
2017-10-09 13:36 - 2017-10-09 13:41 - 000000000 ____D C:\AdwCleaner
2017-10-09 13:30 - 2017-10-09 13:30 - 009809688 _____ (Piriform Ltd) C:\Users\Charne\Downloads\ccsetup535.exe
2017-10-09 13:30 - 2017-10-09 13:30 - 008250832 _____ (Malwarebytes) C:\Users\Charne\Downloads\AdwCleaner.exe
2017-10-09 13:30 - 2017-10-09 13:30 - 001790024 _____ (Malwarebytes) C:\Users\Charne\Downloads\JRT.exe
2017-10-06 16:15 - 2017-10-06 16:15 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2017-10-04 17:05 - 2017-10-04 17:05 - 000000020 ___SH C:\Users\Charne\ntuser.ini
2017-09-24 16:28 - 2017-09-24 16:28 - 000000000 ____D C:\Windows.old
2017-09-24 16:24 - 2017-09-24 16:24 - 013844480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 006557520 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Media.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 005961728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 005821496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 005808640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 005721600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BingMaps.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 005225984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 004708504 _____ (Microsoft Corporation) C:\Windows\System32\mfcore.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 004671832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 004535296 _____ (Microsoft Corporation) C:\Windows\System32\MFMediaEngine.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 004056064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 003667456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 002859520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 002671616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 002604248 _____ (Microsoft Corporation) C:\Windows\System32\mfmp4srcsnk.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 002476712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 002424024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 002199552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Resources.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 002166808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 001627136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 001620880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 001291776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVPXENC.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 001248768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AzureSettingSyncProvider.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 001146176 _____ (Microsoft Corporation) C:\Windows\System32\mfds.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 001106904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 001060352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 001033544 _____ (Microsoft Corporation) C:\Windows\System32\DolbyDecMFT.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 001019904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aadtb.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 001013912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvproc.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000958664 _____ (Microsoft Corporation) C:\Windows\System32\msvproc.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000932352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GamePanel.exe
2017-09-24 16:24 - 2017-09-24 16:24 - 000918528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.Vpn.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000899584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.appcore.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000866808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DolbyDecMFT.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000761344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasapi32.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000750496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
2017-09-24 16:24 - 2017-09-24 16:24 - 000742912 _____ (Microsoft Corporation) C:\Windows\System32\nshwfp.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000715168 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\fvevol.sys
2017-09-24 16:24 - 2017-09-24 16:24 - 000636416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WpcWebFilter.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000586240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000569264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000551200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000446464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000430592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winspool.drv
2017-09-24 16:24 - 2017-09-24 16:24 - 000406544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\policymanager.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000394240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Management.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000387936 _____ (Microsoft Corporation) C:\Windows\System32\wmpps.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgentUserBroker.exe
2017-09-24 16:24 - 2017-09-24 16:24 - 000364032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msIso.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActivationManager.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000337920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgent.exe
2017-09-24 16:24 - 2017-09-24 16:24 - 000311296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000257024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Phoneutil.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000254176 _____ (Microsoft Corporation) C:\Windows\System32\mfps.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dinput8.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000173568 _____ (Microsoft Corporation) C:\Windows\System32\inetpp.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000147456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VCardParser.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000135680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qasf.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000134656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dinput.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000100352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasman.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000100232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcd.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000096648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dmcmnutils.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000085784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CredentialUIBroker.exe
2017-09-24 16:24 - 2017-09-24 16:24 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.exe
2017-09-24 16:24 - 2017-09-24 16:24 - 000029184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cmintegrator.dll
2017-09-24 16:24 - 2017-09-24 16:24 - 000022016 _____ (Microsoft Corporation) C:\Windows\System32\wpnpinst.exe
2017-09-24 16:24 - 2017-09-24 16:24 - 000018432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IpNatHlpClient.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 023684608 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 023679488 _____ (Microsoft Corporation) C:\Windows\System32\edgehtml.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 021352656 _____ (Microsoft Corporation) C:\Windows\System32\shell32.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 020509184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 020373408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 019336192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 017371136 _____ (Microsoft Corporation) C:\Windows\System32\Windows.UI.Xaml.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 012801536 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 011887104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 008333312 _____ (Microsoft Corporation) C:\Windows\System32\BingMaps.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 008319904 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 008213504 _____ (Microsoft Corporation) C:\Windows\System32\mstscax.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 008207872 _____ (Microsoft Corporation) C:\Windows\System32\Chakra.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 007931392 _____ (Microsoft Corporation) C:\Windows\System32\twinui.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 007907344 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Media.Protection.PlayReady.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 007598080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 007337472 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Data.Pdf.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 007326128 _____ (Microsoft Corporation) C:\Windows\System32\windows.storage.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 006761560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 006728704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 006265856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 005557760 _____ (Microsoft Corporation) C:\Windows\System32\dbgeng.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 005477096 _____ (Microsoft Corporation) C:\Windows\System32\OneCoreUAPCommonProxyStub.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 005302968 _____ (Microsoft Corporation) C:\Windows\System32\Windows.StateRepository.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 004848960 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 004730368 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 004707840 _____ (Microsoft Corporation) C:\Windows\System32\ExplorerFrame.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 004559360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbgeng.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 004471888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 004462120 _____ (Microsoft Corporation) C:\Windows\System32\setupapi.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 004445696 _____ (Microsoft Corporation) C:\Windows\System32\SettingsHandlers_nt.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 004417024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 004396032 _____ (Microsoft Corporation) C:\Windows\System32\D3DCompiler_47.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 004330920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupapi.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 004213656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepository.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 004175872 _____ (Microsoft Corporation) C:\Windows\System32\StartTileData.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 003995136 _____ (Microsoft Corporation) C:\Windows\System32\UIRibbon.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 003668992 _____ (Microsoft Corporation) C:\Windows\System32\win32kfull.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 003654656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 003464704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbon.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 003377664 _____ (Microsoft Corporation) C:\Windows\System32\tquery.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 003307008 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 003204608 _____ (Microsoft Corporation) C:\Windows\System32\Microsoft.Bluetooth.Profiles.Gatt.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 003116184 _____ (Microsoft Corporation) C:\Windows\System32\combase.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 003059200 _____ (Microsoft Corporation) C:\Windows\System32\NetworkMobileSettings.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 002972552 _____ (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 002969880 _____ (Microsoft Corporation) C:\Windows\System32\CoreUIComponents.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 002953216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 002939392 _____ (Microsoft Corporation) C:\Windows\System32\InputService.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 002805248 _____ (Microsoft Corporation) C:\Windows\System32\AppXDeploymentServer.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 002765824 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Shell.UnifiedTile.CuratedTileCollections.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 002680320 _____ (Microsoft Corporation) C:\Windows\System32\Windows.CloudStore.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 002675104 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 002647224 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 002516480 _____ (Microsoft Corporation) C:\Windows\System32\diagtrack.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 002503680 _____ (Microsoft Corporation) C:\Windows\System32\twinui.pcshell.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 002445824 _____ (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 002443168 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 002399728 _____ (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 002330520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 002327456 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 002259760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreUIComponents.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 002211840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputService.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 002199552 _____ (Microsoft Corporation) C:\Windows\System32\Windows.UI.Xaml.Resources.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 002177024 _____ (Microsoft Corporation) C:\Windows\System32\OpcServices.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 002153984 _____ (Microsoft Corporation) C:\Windows\System32\wlidsvc.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 002078720 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2017-09-24 16:23 - 2017-09-24 16:23 - 002055680 _____ (Microsoft Corporation) C:\Windows\System32\win32kbase.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 002009600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-09-24 16:23 - 2017-09-24 16:23 - 002006528 _____ (Microsoft Corporation) C:\Windows\System32\LocationFramework.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001930840 _____ (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001886208 _____ (Microsoft Corporation) C:\Windows\System32\AppXDeploymentExtensions.onecore.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001878016 _____ (Microsoft Corporation) C:\Windows\System32\AzureSettingSyncProvider.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001839872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001833984 _____ (Microsoft Corporation) C:\Windows\System32\workfolderssvc.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001802752 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001736704 _____ (Microsoft Corporation) C:\Windows\System32\wevtsvc.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001722880 _____ (Microsoft Corporation) C:\Windows\System32\dui70.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001706496 _____ (Microsoft Corporation) C:\Windows\System32\Windows.UI.Immersive.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001668344 _____ (Microsoft Corporation) C:\Windows\System32\propsys.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001657344 _____ (Microsoft Corporation) C:\Windows\System32\XpsPrint.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001639936 _____ (Microsoft Corporation) C:\Windows\System32\GdiPlus.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001619816 _____ (Microsoft Corporation) C:\Windows\System32\sppobjs.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001596592 _____ (Microsoft Corporation) C:\Windows\System32\gdi32full.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001583616 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001536512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001525760 _____ (Microsoft Corporation) C:\Windows\System32\RecoveryDrive.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 001468416 _____ (Microsoft Corporation) C:\Windows\System32\AppXDeploymentExtensions.desktop.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001463296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001460224 _____ (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001448960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001409048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32full.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001397760 _____ (Microsoft Corporation) C:\Windows\System32\wwansvc.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001357312 _____ (Microsoft Corporation) C:\Windows\System32\audiosrv.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001355264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OpcServices.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001346112 _____ (Microsoft Corporation) C:\Windows\System32\user32.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001337856 _____ (Microsoft Corporation) C:\Windows\System32\AudioEng.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001325968 _____ (Microsoft Corporation) C:\Windows\System32\ole32.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001320344 _____ (Microsoft Corporation) C:\Windows\System32\wpx.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001305088 _____ (Microsoft Corporation) C:\Windows\System32\dosvc.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001298432 _____ (Microsoft Corporation) C:\Windows\System32\lpasvc.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001293824 _____ (Microsoft Corporation) C:\Windows\System32\aadtb.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001292880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001275904 _____ (Microsoft Corporation) C:\Windows\System32\werconcpl.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001269760 _____ (Microsoft Corporation) C:\Windows\System32\enterprisecsps.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001260544 _____ (Microsoft Corporation) C:\Windows\System32\GamePanel.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 001242528 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ndis.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 001195760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001178624 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Networking.Vpn.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001147296 _____ (Microsoft Corporation) C:\Windows\System32\hvix64.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 001143296 _____ (Microsoft Corporation) C:\Windows\System32\localspl.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001114528 _____ (Microsoft Corporation) C:\Windows\System32\ReAgent.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001087488 _____ (Microsoft Corporation) C:\Windows\System32\reseteng.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001085440 _____ (Microsoft Corporation) C:\Windows\System32\rpcss.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001077248 _____ (Microsoft Corporation) C:\Windows\System32\twinui.appcore.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001068720 _____ (Microsoft Corporation) C:\Windows\System32\Windows.UI.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001057824 _____ (Microsoft Corporation) C:\Windows\System32\MrmCoreR.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001054280 _____ (Microsoft Corporation) C:\Windows\System32\AudioSes.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001052160 _____ (Microsoft Corporation) C:\Windows\System32\TokenBroker.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001051136 _____ (Microsoft Corporation) C:\Windows\System32\nettrace.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001046016 _____ (Microsoft Corporation) C:\Windows\System32\ngcsvc.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001046016 _____ (Microsoft Corporation) C:\Windows\System32\comdlg32.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001028608 _____ (Microsoft Corporation) C:\Windows\System32\modernexecserver.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 001024928 _____ (Microsoft Corporation) C:\Windows\System32\hvax64.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 001015296 _____ (Microsoft Corporation) C:\Windows\System32\XblAuthManager.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000996864 _____ (Microsoft Corporation) C:\Windows\System32\iphlpsvc.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000988168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000986624 _____ (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000972288 _____ (Microsoft Corporation) C:\Windows\System32\MPSSVC.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000971264 _____ (Microsoft Corporation) C:\Windows\System32\autochk.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000967584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgent.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000961952 _____ (Microsoft Corporation) C:\Windows\System32\efscore.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000954368 _____ (Microsoft Corporation) C:\Windows\System32\autoconv.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000952832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000946688 _____ (Microsoft Corporation) C:\Windows\System32\rasgcw.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000942592 _____ (Microsoft Corporation) C:\Windows\System32\wbiosrvc.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000926208 _____ (Microsoft Corporation) C:\Windows\System32\autofmt.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000925696 _____ (Microsoft Corporation) C:\Windows\System32\WpcWebFilter.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000923040 _____ (Microsoft Corporation) C:\Windows\System32\CoreMessaging.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000922112 _____ (Microsoft Corporation) C:\Windows\System32\kerberos.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000921600 _____ (Microsoft Corporation) C:\Windows\System32\rasdlg.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000892928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autochk.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000877056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autoconv.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000874496 _____ (Microsoft Corporation) C:\Windows\System32\rasmans.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000872472 _____ (Microsoft Corporation) C:\Windows\System32\ClipSVC.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000871448 _____ (Microsoft Corporation) C:\Windows\System32\winhttp.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000866816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswdat10.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000864256 _____ (Microsoft Corporation) C:\Windows\System32\NotificationController.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000864248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000853504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autofmt.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000852480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasgcw.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000847360 _____ (Microsoft Corporation) C:\Windows\System32\bisrv.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000844288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasdlg.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000832000 _____ (Microsoft Corporation) C:\Windows\System32\printfilterpipelinesvc.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000827904 _____ (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000821664 _____ (Microsoft Corporation) C:\Windows\System32\hvloader.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000820128 _____ (Microsoft Corporation) C:\Windows\System32\WWAHost.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000817664 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000810496 _____ (Microsoft Corporation) C:\Windows\System32\rasapi32.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000805888 _____ (Microsoft Corporation) C:\Windows\System32\ieproxy.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000805816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000803328 _____ (Microsoft Corporation) C:\Windows\System32\wcmsvc.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000798208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBroker.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000787456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000778240 _____ C:\Windows\System32\MBR2GPT.EXE
2017-09-24 16:23 - 2017-09-24 16:23 - 000778240 _____ (Microsoft Corporation) C:\Windows\System32\DolbyHrtfEnc.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000773120 _____ (Microsoft Corporation) C:\Windows\System32\PhoneService.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000772096 _____ (Microsoft Corporation) C:\Windows\System32\PCPKsp.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000772096 _____ (Microsoft Corporation) C:\Windows\System32\netlogon.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000757760 _____ (Microsoft Corporation) C:\Windows\System32\spoolsv.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000754176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000752640 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000750560 _____ (Microsoft Corporation) C:\Windows\System32\fontdrvhost.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000739840 _____ (Microsoft Corporation) C:\Windows\System32\PhoneProviders.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000724200 _____ (Microsoft Corporation) C:\Windows\System32\wer.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000723360 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\acpi.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000712600 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms2.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000706560 _____ (Microsoft Corporation) C:\Windows\System32\winlogon.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000703056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000699904 _____ (Microsoft Corporation) C:\Windows\System32\FlightSettings.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000692736 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000691712 _____ (Microsoft Corporation) C:\Windows\System32\tdh.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000687616 _____ (Microsoft Corporation) C:\Windows\System32\LogonController.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000685512 _____ (Microsoft Corporation) C:\Windows\System32\SHCore.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000664576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000660680 _____ (Microsoft Corporation) C:\Windows\System32\dxgi.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000657408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netlogon.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000654976 _____ (Microsoft Corporation) C:\Windows\System32\AppXDeploymentClient.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswstr10.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000640512 _____ (Microsoft Corporation) C:\Windows\System32\ngccredprov.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000627080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontdrvhost.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000625152 _____ (Microsoft Corporation) C:\Windows\System32\AudioEndpointBuilder.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000616448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrepl40.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000612864 _____ (Microsoft Corporation) C:\Windows\System32\shsvcs.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000611096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000610720 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\afd.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000600576 _____ (Microsoft Corporation) C:\Windows\System32\FrameServer.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000593408 _____ (Microsoft Corporation) C:\Windows\System32\BootMenuUX.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000590336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PCPKsp.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000586752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000586240 _____ (Microsoft Corporation) C:\Windows\System32\AppReadiness.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000584192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbonRes.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000584192 _____ (Microsoft Corporation) C:\Windows\System32\UIRibbonRes.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000583160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreMessaging.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000582656 _____ (Microsoft Corporation) C:\Windows\System32\SmsRouterSvc.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000579072 _____ (Microsoft Corporation) C:\Windows\System32\untfs.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000574464 _____ (Microsoft Corporation) C:\Windows\System32\configmanager2.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000566784 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Networking.UX.EapRequestHandler.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000564736 _____ (Microsoft Corporation) C:\Windows\System32\dsreg.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000564224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shsvcs.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000563200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000556032 _____ (Microsoft Corporation) C:\Windows\System32\TpmCoreProvisioning.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000554400 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\USBHUB3.SYS
2017-09-24 16:23 - 2017-09-24 16:23 - 000546816 _____ (Microsoft Corporation) C:\Windows\System32\winspool.drv
2017-09-24 16:23 - 2017-09-24 16:23 - 000546208 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\storport.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\untfs.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000536064 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Internal.Management.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000529992 _____ (Microsoft Corporation) C:\Windows\System32\TextInputFramework.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000527976 _____ (Microsoft Corporation) C:\Windows\System32\services.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000527872 _____ (Microsoft Corporation) C:\Windows\System32\daxexec.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000527360 _____ (Microsoft Corporation) C:\Windows\System32\aadcloudap.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000524800 _____ (Microsoft Corporation) C:\Windows\System32\TileDataRepository.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ngccredprov.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000519584 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\netio.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000518144 _____ C:\Windows\SysWOW64\msjetoledb40.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000500224 _____ (Microsoft Corporation) C:\Windows\System32\Windows.Shell.BlueLightReduction.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000499712 _____ (Microsoft Corporation) C:\Windows\System32\nltest.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000497152 _____ (Microsoft Corporation) C:\Windows\System32\rastls.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000491520 _____ (Microsoft Corporation) C:\Windows\System32\SettingsHandlers_Display.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000491520 _____ (Microsoft Corporation) C:\Windows\System32\NgcCtnrSvc.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000482816 _____ (Microsoft Corporation) C:\Windows\System32\dmenrollengine.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000477696 _____ (Microsoft Corporation) C:\Windows\System32\rasplap.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dsreg.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000475648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxbde40.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000473240 _____ (Microsoft Corporation) C:\Windows\System32\policymanager.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000471040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TpmCoreProvisioning.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000463360 _____ (Microsoft Corporation) C:\Windows\System32\werui.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000458752 _____ (Microsoft Corporation) C:\Windows\System32\NgcCtnr.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000457728 _____ (Microsoft Corporation) C:\Windows\System32\webplatstorageserver.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000455584 _____ (Microsoft Corporation) C:\Windows\System32\hal.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasplap.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000450048 _____ (Microsoft Corporation) C:\Windows\System32\bcdedit.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000447488 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000440320 _____ (Microsoft Corporation) C:\Windows\System32\windows.immersiveshell.serviceprovider.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000433664 _____ (Microsoft Corporation) C:\Windows\System32\msIso.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000431616 _____ (Microsoft Corporation) C:\Windows\System32\BthHFSrv.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000422400 _____ (Microsoft Corporation) C:\Windows\System32\WpAXHolder.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000420864 _____ (Microsoft Corporation) C:\Windows\System32\facecredentialprovider.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000417792 _____ (Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000414296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TextInputFramework.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000413184 _____ (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000412160 _____ (Microsoft Corporation) C:\Windows\System32\ActivationManager.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000411040 _____ (Microsoft Corporation) C:\Windows\System32\msv1_0.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000410168 _____ (Microsoft Corporation) C:\Windows\System32\Faultrep.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000408576 _____ (Microsoft Corporation) C:\Windows\System32\cryptngc.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000407040 _____ (Microsoft Corporation) C:\Windows\System32\wuuhext.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000404480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werui.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000397312 _____ (Microsoft Corporation) C:\Windows\System32\rascustom.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000388096 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000385536 _____ (Microsoft Corporation) C:\Windows\System32\tpmvsc.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000383488 _____ (Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000382368 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\clfs.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000381824 _____ (Microsoft Corporation) C:\Windows\System32\wevtapi.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000375808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mspbde40.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000370688 _____ (Microsoft Corporation) C:\Windows\System32\rastlsext.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000370176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\daxexec.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000365056 _____ (Microsoft Corporation) C:\Windows\System32\SettingsHandlers_Notifications.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000359560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Faultrep.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000358400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieproxy.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000353280 _____ (Microsoft Corporation) C:\Windows\System32\ntprint.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000349600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000343552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000339968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000339968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000334336 _____ (Microsoft Corporation) C:\Windows\System32\wc_storage.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000331264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastlsext.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000329728 _____ (Microsoft Corporation) C:\Windows\System32\RasMediaManager.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000327168 _____ (Microsoft Corporation) C:\Windows\System32\WinBioDataModel.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000323936 _____ (Microsoft Corporation) C:\Windows\System32\shlwapi.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000323584 _____ (Microsoft Corporation) C:\Windows\System32\DeviceEnroller.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000318232 _____ (Microsoft Corporation) C:\Windows\System32\wininit.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000316320 _____ (Microsoft Corporation) C:\Windows\System32\WerFault.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000315904 _____ (Microsoft Corporation) C:\Windows\System32\ncryptprov.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000312320 _____ (Microsoft Corporation) C:\Windows\System32\Phoneutil.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000310272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd2x40.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000307712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptngc.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000305152 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\netbt.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000303104 _____ (Microsoft Corporation) C:\Windows\System32\srvsvc.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32k.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000291904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wevtapi.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000290816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjtes40.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000290816 _____ (Microsoft Corporation) C:\Windows\System32\dmenterprisediagnostics.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000287648 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\sdbus.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000282112 _____ (Microsoft Corporation) C:\Windows\System32\dnsrslvr.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000280480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000279968 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\msiscsi.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000277432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shlwapi.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000274944 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000274432 _____ (Microsoft Corporation) C:\Windows\System32\authz.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000272896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstext40.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000268288 _____ (Microsoft Corporation) C:\Windows\System32\wisp.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000267264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncryptprov.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000266240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000259072 _____ (Microsoft Corporation) C:\Windows\System32\SettingsHandlers_Flights.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000257440 _____ (Microsoft Corporation) C:\Windows\System32\AppxAllUserStore.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000257024 _____ (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000255488 _____ (Microsoft Corporation) C:\Windows\System32\scksp.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000254976 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\srvnet.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000249344 _____ (Microsoft Corporation) C:\Windows\System32\coredpus.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000243712 _____ (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000240640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msltus40.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000231936 _____ (Microsoft Corporation) C:\Windows\System32\DolbyMATEnc.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000229888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scksp.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000229888 _____ (Microsoft Corporation) C:\Windows\System32\SIHClient.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000228256 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxsmb20.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000225792 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000223744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000221696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wisp.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000213504 _____ (Microsoft Corporation) C:\Windows\System32\dinput8.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000212384 _____ (Microsoft Corporation) C:\Windows\System32\browserbroker.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000209408 _____ (Microsoft Corporation) C:\Windows\System32\psmsrv.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000204192 _____ (Microsoft Corporation) C:\Windows\System32\basecsp.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000201728 _____ (Microsoft Corporation) C:\Windows\System32\RstrtMgr.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000197120 _____ (Microsoft Corporation) C:\Windows\System32\bcdboot.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000194048 _____ (Microsoft Corporation) C:\Windows\System32\mdmregistration.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000192264 _____ (Microsoft Corporation) C:\Windows\System32\mfsensorgroup.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000189440 _____ (Microsoft Corporation) C:\Windows\System32\BluetoothApis.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000189344 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\dumpsd.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000184832 _____ (Microsoft Corporation) C:\Windows\System32\VCardParser.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000184320 _____ (Microsoft Corporation) C:\Windows\System32\DWWIN.EXE
2017-09-24 16:23 - 2017-09-24 16:23 - 000182688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxAllUserStore.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000182688 _____ (Microsoft Corporation) C:\Windows\System32\wermgr.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000182272 _____ (Microsoft Corporation) C:\Windows\System32\ngcrecovery.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000181760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authz.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000176640 _____ (Microsoft Corporation) C:\Windows\System32\wersvc.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000176024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\basecsp.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000175616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RstrtMgr.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000173104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsensorgroup.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000169376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000165888 _____ (Microsoft Corporation) C:\Windows\System32\storewuauth.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000160768 _____ (Microsoft Corporation) C:\Windows\System32\dinput.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000159648 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\partmgr.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000156160 _____ (Microsoft Corporation) C:\Windows\System32\csplte.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000154624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWWIN.EXE
2017-09-24 16:23 - 2017-09-24 16:23 - 000153088 _____ (Microsoft Corporation) C:\Windows\System32\fdeploy.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000150528 _____ (Microsoft Corporation) C:\Windows\System32\qasf.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000144896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjint40.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000143872 _____ (Microsoft Corporation) C:\Windows\System32\profsvcext.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000143736 _____ (Microsoft Corporation) C:\Windows\System32\WerFaultSecure.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000142848 _____ (Microsoft Corporation) C:\Windows\System32\srpapi.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000142848 _____ (Microsoft Corporation) C:\Windows\System32\dwmredir.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000140800 _____ (Microsoft Corporation) C:\Windows\System32\dmcsps.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000140288 _____ (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000139776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BluetoothApis.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000138752 _____ (Microsoft Corporation) C:\Windows\System32\appinfo.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000136192 _____ (Microsoft Corporation) C:\Windows\System32\Windows.StateRepositoryUpgrade.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000136096 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000133904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFaultSecure.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000133632 _____ (Microsoft Corporation) C:\Windows\System32\CfgSPCellular.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000131584 _____ (Microsoft Corporation) C:\Windows\System32\EnterpriseAPNCsp.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000130560 _____ (Microsoft Corporation) C:\Windows\System32\policymanagerprecheck.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000128512 _____ (Microsoft Corporation) C:\Windows\System32\rasman.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000128000 _____ (Microsoft Corporation) C:\Windows\System32\mssprxy.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fdeploy.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000124928 _____ (Microsoft Corporation) C:\Windows\System32\httpprxm.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srpapi.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000119904 _____ (Microsoft Corporation) C:\Windows\System32\dmcmnutils.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000119712 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tdx.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000117760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepositoryUpgrade.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000116280 _____ (Microsoft Corporation) C:\Windows\System32\bcd.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000115792 _____ (Microsoft Corporation) C:\Windows\System32\win32u.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000115712 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\bridge.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000113152 _____ (Microsoft Corporation) C:\Windows\System32\wuuhosdeployment.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000112640 _____ (Microsoft Corporation) C:\Windows\System32\MDMAppInstaller.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000110592 _____ (Microsoft Corporation) C:\Windows\System32\Chakradiag.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000109056 _____ (Microsoft Corporation) C:\Windows\System32\dab.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000107008 _____ (Microsoft Corporation) C:\Windows\System32\ngcpopkeysrv.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000107008 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\hidbth.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000105472 _____ (Microsoft Corporation) C:\Windows\System32\RjvMDMConfig.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000104960 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\UcmCx.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000104432 _____ (Microsoft Corporation) C:\Windows\System32\msacm32.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000102912 _____ (Microsoft Corporation) C:\Windows\System32\officecsp.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000097792 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\bthhfenum.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000096256 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000095232 _____ (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000094624 _____ (Microsoft Corporation) C:\Windows\System32\rdpudd.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000093696 _____ (Microsoft Corporation) C:\Windows\System32\spbcd.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000093184 _____ (Microsoft Corporation) C:\Windows\System32\wercplsupport.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000090464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msacm32.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000090112 _____ (Microsoft Corporation) C:\Windows\System32\ofdeploy.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000090112 _____ (Microsoft Corporation) C:\Windows\System32\datamarketsvc.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000089088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\olepro32.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000089088 _____ (Microsoft Corporation) C:\Windows\System32\winsrvext.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000084992 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjter40.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000083968 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\vmbkmclr.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000082336 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\vmbkmcl.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000081176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32u.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakradiag.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000078848 _____ (Microsoft Corporation) C:\Windows\System32\setbcdlocale.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000078848 _____ (Microsoft Corporation) C:\Windows\System32\offreg.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000077824 _____ (Microsoft Corporation) C:\Windows\System32\wsqmcons.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spbcd.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000074240 _____ (Microsoft Corporation) C:\Windows\System32\EnterpriseDesktopAppMgmtCSP.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000071680 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbser.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000064680 _____ (Microsoft Corporation) C:\Windows\System32\appidapi.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000064512 _____ (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000064000 _____ (Microsoft Corporation) C:\Windows\System32\wups.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000064000 _____ (Microsoft Corporation) C:\Windows\System32\ntprint.exe
2017-09-24 16:23 - 2017-09-24 16:23 - 000061952 _____ (Microsoft Corporation) C:\Windows\System32\vss_ps.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000059392 _____ (Microsoft Corporation) C:\Windows\System32\DmApiSetExtImplDesktop.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000057856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\offreg.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000056832 _____ (Microsoft Corporation) C:\Windows\System32\cldapi.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000052768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000051712 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\UcmUcsi.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cldapi.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000049720 _____ (Microsoft Corporation) C:\Windows\System32\tbs.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000046592 _____ (Microsoft Corporation) C:\Windows\System32\sscore.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000044032 _____ (Microsoft Corporation) C:\Windows\System32\cmintegrator.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000043520 _____ (Microsoft Corporation) C:\Windows\System32\TpmTasks.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000043520 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\nsiproxy.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000042496 _____ (Microsoft Corporation) C:\Windows\System32\tokenbinding.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000042456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tbs.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000039424 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\buttonconverter.sys
2017-09-24 16:23 - 2017-09-24 16:23 - 000037376 _____ (Microsoft Corporation) C:\Windows\System32\SEMgrPS.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sscore.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tokenbinding.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000031932 _____ C:\Windows\System32\edgehtmlpluginpolicy.bin
2017-09-24 16:23 - 2017-09-24 16:23 - 000029696 _____ (Microsoft Corporation) C:\Windows\System32\odbcconf.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcconf.dll
2017-09-24 16:23 - 2017-09-24 16:23 - 000022528 _____ (Microsoft Corporation) C:\Windows\System32\IpNatHlpClient.dll
2017-09-24 16:10 - 2017-09-24 16:10 - 000008192 _____ C:\Windows\System32\config\userdiff
2017-09-24 16:10 - 2017-09-24 12:36 - 000000000 ____D C:\Windows\ServiceProfiles
2017-09-24 16:07 - 2017-09-24 16:07 - 000000000 ____D C:\Program Files\Reference Assemblies
2017-09-24 16:07 - 2017-09-24 16:07 - 000000000 ____D C:\Program Files\MSBuild
2017-09-24 16:07 - 2017-09-24 16:07 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2017-09-24 16:07 - 2017-09-24 16:07 - 000000000 ____D C:\Program Files (x86)\MSBuild
2017-09-24 16:06 - 2017-02-10 11:26 - 001166520 _____ (Microsoft Corporation) C:\Windows\System32\PresentationNative_v0300.dll
2017-09-24 16:06 - 2017-02-10 11:26 - 000124624 _____ (Microsoft Corporation) C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
2017-09-24 16:06 - 2017-02-10 11:26 - 000035480 _____ (Microsoft Corporation) C:\Windows\System32\TsWpfWrp.exe
2017-09-24 16:06 - 2017-02-10 11:21 - 000778936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationNative_v0300.dll
2017-09-24 16:06 - 2017-02-10 11:21 - 000103120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2017-09-24 16:06 - 2017-02-10 11:21 - 000035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2017-09-24 13:16 - 2017-09-24 13:19 - 000007623 _____ C:\Windows\diagwrn.xml
2017-09-24 13:16 - 2017-09-24 13:19 - 000007623 _____ C:\Windows\diagerr.xml
2017-09-24 13:08 - 2017-10-09 15:34 - 000945780 _____ C:\Windows\System32\PerfStringBackup.INI
2017-09-24 13:07 - 2017-10-12 11:48 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-09-24 13:07 - 2017-09-24 13:08 - 000003344 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-09-24 13:07 - 2017-09-24 13:08 - 000002860 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1241052491-2989075707-2494370071-1001
2017-09-24 13:07 - 2017-09-24 13:08 - 000002752 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1241052491-2989075707-2494370071-1001
2017-09-24 13:07 - 2017-09-24 13:08 - 000002386 _____ C:\Windows\System32\Tasks\McAfee Remediation (Prepare)
2017-09-24 13:07 - 2017-09-24 13:08 - 000002314 _____ C:\Windows\System32\Tasks\{27316D6C-1273-4606-B7EC-7559CE8CED58}
2017-09-24 13:07 - 2017-09-24 13:07 - 000003290 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{C12BC12E-5262-4B9E-B66C-421CE6825189}
2017-09-24 13:07 - 2017-09-24 13:07 - 000003272 _____ C:\Windows\System32\Tasks\G2MUploadTask-S-1-5-21-1241052491-2989075707-2494370071-1001
2017-09-24 13:07 - 2017-09-24 13:07 - 000003176 _____ C:\Windows\System32\Tasks\G2MUpdateTask-S-1-5-21-1241052491-2989075707-2494370071-1001
2017-09-24 13:07 - 2017-09-24 13:07 - 000003120 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-09-24 13:07 - 2017-09-24 13:07 - 000002826 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task
2017-09-24 13:07 - 2017-09-24 13:07 - 000002638 _____ C:\Windows\System32\Tasks\HPCustParticipation HP DeskJet 3630 series
2017-09-24 13:07 - 2017-09-24 13:07 - 000002308 _____ C:\Windows\System32\Tasks\McAfeeLogon
2017-09-24 13:07 - 2017-09-24 13:07 - 000002272 _____ C:\Windows\System32\Tasks\ASUS P4G
2017-09-24 13:07 - 2017-09-24 13:07 - 000002272 _____ C:\Windows\System32\Tasks\ASUS Live Update
2017-09-24 13:07 - 2017-09-24 13:07 - 000002198 _____ C:\Windows\System32\Tasks\AsusVibeSchedule
2017-09-24 13:07 - 2017-09-24 13:07 - 000002188 _____ C:\Windows\System32\Tasks\ASUS USB Charger Plus
2017-09-24 13:07 - 2017-09-24 13:07 - 000002070 _____ C:\Windows\System32\Tasks\ASUS Splendid ColorU
2017-09-24 13:07 - 2017-09-24 13:07 - 000002054 _____ C:\Windows\System32\Tasks\ASUS Splendid ACMON
2017-09-24 13:07 - 2017-09-24 13:07 - 000002008 _____ C:\Windows\System32\Tasks\ASUS InstantOn Config
2017-09-24 13:07 - 2017-09-24 13:07 - 000000000 ____D C:\Windows\System32\Tasks\WPD
2017-09-24 13:07 - 2017-09-24 13:07 - 000000000 ____D C:\Windows\System32\Tasks\McAfee
2017-09-24 13:07 - 2017-09-24 13:07 - 000000000 ____D C:\Windows\System32\Tasks\Apple
2017-09-24 12:48 - 2017-09-24 12:58 - 000000000 ____D C:\Windows\System32\config\bbimigrate
2017-09-24 12:47 - 2017-09-24 12:47 - 000000000 ____D C:\ProgramData\USOShared
2017-09-24 12:45 - 2017-10-09 15:25 - 000000000 ____D C:\users\Charne
2017-09-24 12:43 - 2017-10-09 13:40 - 000000000 ____D C:\Windows\SysWOW64\RTCOM
2017-09-24 12:43 - 2017-09-24 12:49 - 000000000 ____D C:\Program Files\Intel
2017-09-24 12:43 - 2017-09-24 12:43 - 000081908 _____ C:\Windows\System32\Drivers\RTWAVES30.dat
2017-09-24 12:43 - 2017-09-24 12:43 - 000001263 _____ C:\Users\Public\Desktop\Waves MAXXAudio.lnk
2017-09-24 12:43 - 2017-09-24 12:43 - 000000000 ____D C:\Program Files\Realtek
2017-09-24 12:43 - 2016-05-03 19:30 - 000081416 _____ (Khronos Group) C:\Windows\System32\OpenCL.DLL
2017-09-24 12:43 - 2016-05-03 19:30 - 000077832 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.DLL
2017-09-24 12:38 - 2017-09-24 12:58 - 000000000 ____D C:\ProgramData\SetupTPDriver
2017-09-24 12:38 - 2017-09-24 12:49 - 000000000 ____D C:\Program Files (x86)\ASUS
2017-09-24 12:38 - 2017-09-24 12:38 - 000000000 ____D C:\Windows\SysWOW64\sda
2017-09-24 12:38 - 2017-03-18 12:56 - 002233344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2017-09-24 12:36 - 2017-10-09 07:41 - 000000000 ____D C:\Windows\System32\SleepStudy
2017-09-24 12:36 - 2017-10-04 16:46 - 000396792 _____ C:\Windows\System32\FNTCACHE.DAT
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-10-12 11:49 - 2017-03-18 03:40 - 000524288 _____ C:\Windows\System32\config\BBI
2017-10-12 11:48 - 2017-03-18 03:40 - 000032768 _____ C:\Windows\System32\config\ELAM
2017-10-10 05:42 - 2014-10-21 14:55 - 000000000 ____D C:\Users\Charne\AppData\LocalLow\{CDCC6C14-DE92-4E47-83C5-2D5660DE3A57}
2017-10-09 14:26 - 2017-03-18 13:01 - 000000000 ____D C:\Windows\INF
2017-10-09 13:41 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\AppReadiness
2017-10-09 13:41 - 2017-03-18 13:03 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-10-09 13:38 - 2013-12-25 06:10 - 000000000 ____D C:\Users\Charne\AppData\Local\Packages
2017-10-09 13:37 - 2014-06-19 09:53 - 000000000 ____D C:\Program Files\Microsoft Office 15
2017-10-09 13:25 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\appcompat
2017-10-09 13:25 - 2013-12-25 06:11 - 000000062 _____ C:\Users\Charne\AppData\Roaming\sp_data.sys
2017-10-06 17:53 - 2016-10-09 15:11 - 000000000 ____D C:\Users\Charne\AppData\Local\ConnectedDevicesPlatform
2017-10-05 18:40 - 2015-12-05 14:28 - 000000000 __SHD C:\Users\Charne\IntelGraphicsProfiles
2017-10-05 18:23 - 2017-03-18 13:03 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2017-10-05 18:23 - 2013-12-14 01:08 - 000000000 __RHD C:\Users\Public\AccountPictures
2017-10-05 15:26 - 2017-03-18 13:03 - 000000000 ___HD C:\Program Files\WindowsApps
2017-10-05 15:26 - 2015-12-05 14:28 - 000000451 _____ C:\Windows\System32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2017-10-02 04:42 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\rescache
2017-10-02 04:31 - 2017-08-19 10:55 - 000000000 ___DC C:\Windows\Panther
2017-09-24 16:34 - 2017-03-18 13:03 - 000028672 _____ C:\Windows\System32\config\BCD-Template
2017-09-24 16:29 - 2017-03-18 13:06 - 000000000 ____D C:\Windows\Setup
2017-09-24 16:26 - 2017-03-18 13:03 - 000000000 ___SD C:\Windows\SysWOW64\F12
2017-09-24 16:26 - 2017-03-18 13:03 - 000000000 ___SD C:\Windows\System32\F12
2017-09-24 16:26 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2017-09-24 16:26 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\SysWOW64\setup
2017-09-24 16:26 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\System32\WinMetadata
2017-09-24 16:26 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\System32\setup
2017-09-24 16:26 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\ShellExperiences
2017-09-24 16:26 - 2017-03-18 13:03 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2017-09-24 16:26 - 2017-03-18 13:03 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-09-24 16:26 - 2017-03-18 12:51 - 000000000 ____D C:\Windows\CbsTemp
2017-09-24 13:20 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\System32\WinBioDatabase
2017-09-24 13:15 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\Registration
2017-09-24 13:15 - 2016-07-16 03:47 - 000000000 ____D C:\Windows\System32\Tasks_Migrated
2017-09-24 13:08 - 2017-03-18 18:31 - 000000000 ____D C:\Windows\HoloShell
2017-09-24 13:07 - 2015-04-13 18:09 - 000022840 _____ C:\Windows\System32\emptyregdb.dat
2017-09-24 13:06 - 2017-03-18 13:03 - 000000000 __RHD C:\Users\Public\Libraries
2017-09-24 12:59 - 2017-07-02 16:20 - 000000000 ____D C:\Windows\System32\UNP
2017-09-24 12:59 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\LiveKernelReports
2017-09-24 12:59 - 2015-10-30 01:07 - 000000000 ____D C:\Windows\ShellNew
2017-09-24 12:58 - 2013-05-01 01:37 - 000000000 ____D C:\Windows\fr
2017-09-24 12:58 - 2013-05-01 01:37 - 000000000 ____D C:\Windows\es
2017-09-24 12:58 - 2013-05-01 01:37 - 000000000 ____D C:\Windows\en
2017-09-24 12:54 - 2017-03-18 18:29 - 000000000 ____D C:\Windows\SysWOW64\sysprep
2017-09-24 12:54 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\SysWOW64\lv-LV
2017-09-24 12:54 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\SysWOW64\lt-LT
2017-09-24 12:54 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\SysWOW64\IME
2017-09-24 12:54 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\SysWOW64\et-EE
2017-09-24 12:54 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\SysWOW64\en-GB
2017-09-24 12:54 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\System32\WinBioPlugIns
2017-09-24 12:54 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\System32\spool
2017-09-24 12:54 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\System32\oobe
2017-09-24 12:54 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\System32\NDF
2017-09-24 12:54 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\System32\lv-LV
2017-09-24 12:54 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\System32\lt-LT
2017-09-24 12:54 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\System32\InputMethod
2017-09-24 12:54 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\System32\IME
2017-09-24 12:54 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\System32\et-EE
2017-09-24 12:54 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\System32\en-GB
2017-09-24 12:54 - 2013-08-22 07:36 - 000000000 ____D C:\Windows\System32\WindowsInternal.Inbox.Shared
2017-09-24 12:54 - 2013-08-22 07:36 - 000000000 ____D C:\Windows\System32\WindowsInternal.Inbox.Media.Shared
2017-09-24 12:49 - 2017-03-18 13:03 - 000000000 ____D C:\Windows\InputMethod
2017-09-24 12:49 - 2017-03-18 13:03 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2017-09-24 12:47 - 2017-03-18 13:03 - 000000000 ____D C:\ProgramData\USOPrivate
2017-09-24 12:44 - 2017-03-18 03:40 - 000000000 ____D C:\Windows\System32\Sysprep
2017-09-24 10:20 - 2017-07-10 22:54 - 000000000 ___HD C:\$WINDOWS.~BT
==================== Known DLLs (Whitelisted) =========================
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe
[2017-09-24 16:23] - [2017-09-24 16:23] - 000706560 _____ (Microsoft Corporation) 9CDA170849A4F66F4D68B3DBB3AC8394
C:\Windows\System32\wininit.exe
[2017-09-24 16:23] - [2017-09-24 16:23] - 000318232 _____ (Microsoft Corporation) 0242626678C83AE788C655C1990A3CC3
C:\Windows\explorer.exe
[2017-09-24 16:23] - [2017-09-24 16:23] - 004848960 _____ (Microsoft Corporation) 3AF6D6F752EDE013ED15DFD2D44F8EF9
C:\Windows\SysWOW64\explorer.exe
[2017-09-24 16:23] - [2017-09-24 16:23] - 004471888 _____ (Microsoft Corporation) 176EF3831ADD9AC33662B6D0CACBA74A
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2017-09-24 16:23] - [2017-09-24 16:23] - 000527976 _____ (Microsoft Corporation) C81F9707DEA008EED4071B5A39B7C76E
C:\Windows\System32\User32.dll
[2017-09-24 16:23] - [2017-09-24 16:23] - 001346112 _____ (Microsoft Corporation) 3570C1E0CD0CE833242FAFCCA1E75312
C:\Windows\SysWOW64\User32.dll
[2017-09-24 16:23] - [2017-09-24 16:23] - 001292880 _____ (Microsoft Corporation) 23D5AD415D0A8F845574EC9812898866
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll
[2017-09-24 16:23] - [2017-09-24 16:23] - 001085440 _____ (Microsoft Corporation) AA7F1C36F5BC779964CFA4F98D224D9F
C:\Windows\System32\dnsapi.dll => MD5 is legit
C:\Windows\SysWOW64\dnsapi.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys
[2017-03-18 12:57] - [2017-03-18 12:57] - 000397216 _____ (Microsoft Corporation) E3429DBBEA3965BB96E24B16EF4A2551
==================== Association (Whitelisted) =============
==================== Restore Points =========================
Restore point date: 2017-10-10 08:28
==================== Memory info ===========================
Percentage of memory in use: 9%
Total physical RAM: 12163.09 MB
Available physical RAM: 11018.51 MB
Total Virtual: 12163.09 MB
Available Virtual: 11054.35 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:278.56 GB) (Free:213.82 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (DATA) (Fixed) (Total:398.07 GB) (Free:397.93 GB) NTFS
Drive e: () (Fixed) (Total:0.89 GB) (Free:0.34 GB) NTFS
Drive f: (SYSRCD-5_1_) (Removable) (Total:3.72 GB) (Free:3.72 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.5 GB) (Free:0.5 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 698.6 GB) (Disk ID: 568814A2)
Partition: GPT.
========================================================
Disk: 1 (Size: 3.7 GB) (Disk ID: 1B8C73CB)
Partition 1: (Active) - (Size=3.7 GB) - (Type=0C)
LastRegBack: 2017-09-24 12:35
==================== End of FRST.txt ============================