Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-04-2020
Ran by mhick (administrator) on DESKTOP-13E56T6 (Micro-Star International Co., Ltd MS-7C02) (20-04-2020 10:29:27)
Running from C:\Users\mhick\Downloads
Loaded Profiles: mhick (Available Profiles: test3 & mhick)
Platform: Windows 10 Home Version 1909 18363.778 (X64) Language: English (United Kingdom)
Default browser: FF
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSSrcExt.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0353065.inf_amd64_2af28622e162cc90\B353014\atieclxx.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0353065.inf_amd64_2af28622e162cc90\B353014\atiesrxx.exe
(Discord Inc. -> Discord Inc.) C:\Users\mhick\AppData\Local\Discord\app-0.0.306\Discord.exe <6>
(F.lux Software LLC -> f.lux Software LLC) C:\Users\mhick\AppData\Local\FluxSoftware\Flux\flux.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\mhick\AppData\Local\Microsoft\Teams\current\Teams.exe <6>
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12004.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.120.4062.0_x64__8wekyb3d8bbwe\GameBar.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.120.4062.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\NisSrv.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <9>
(Windscribe Limited -> Windscribe Limited) C:\Program Files (x86)\Windscribe\WindscribeService.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [Discord] => C:\ProgramData\SquirrelMachineInstalls\Discord.exe [61370712 2020-02-22] (Discord Inc. -> Discord Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [646160 2019-12-11] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [RazerCortex] => "C:\Program Files (x86)\Razer\Razer Cortex\CortexLauncher.exe" -autorun
HKU\S-1-5-21-1617416004-2811918536-4117151059-1008\...\Run: [Discord] => C:\Users\mhick\AppData\Local\Discord\app-0.0.306\Discord.exe [90950968 2020-02-24] (Discord Inc. -> Discord Inc.)
HKU\S-1-5-21-1617416004-2811918536-4117151059-1008\...\Run: [f.lux] => C:\Users\mhick\AppData\Local\FluxSoftware\Flux\flux.exe [1385480 2019-08-30] (F.lux Software LLC -> f.lux Software LLC)
HKU\S-1-5-21-1617416004-2811918536-4117151059-1008\...\Run: [com.squirrel.Teams.Teams] => C:\Users\mhick\AppData\Local\Microsoft\Teams\Update.exe [2339472 2020-04-20] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\80.0.3987.163\Installer\chrmstp.exe [2020-04-07] (Google LLC -> Google LLC)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {060B93C6-D6F7-40B2-B3E3-9B26C6CBE2DD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-03-11] (Google LLC -> Google LLC)
Task: {1229617A-5CD9-478A-8D74-4A36510A9E44} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {1B00DF57-3EF7-4F26-8424-777276D1A758} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [61624 2020-03-17] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {39BC6D43-497D-4FF0-BAAF-6C56D1379E43} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [69304 2020-03-17] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {39FA2510-506F-42FD-ABCF-1003ACB4D396} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-03-11] (Google LLC -> Google LLC)
Task: {49227488-63D4-4B10-8401-0E97A66136CA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4DA0A56D-75E2-4E10-911D-6504DD5777C7} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {5CAB4C93-0FFA-4D9C-A0C3-949DBBE85AF0} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\BIN64\InstallManagerApp.exe [1628160 2020-03-17] (Advanced Micro Devices, Inc.) [File not signed]
Task: {70F1D318-3134-42A8-B2E5-FB9ADC66646C} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1628160 2020-03-17] (Advanced Micro Devices, Inc.) [File not signed]
Task: {720C4904-D456-4A38-AE79-3D5A11C6A1B0} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1628160 2020-03-17] (Advanced Micro Devices, Inc.) [File not signed]
Task: {79296C8E-7681-4720-ABE5-C11A0A0A86BB} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {80CCFAFC-D3E1-4D9C-948E-F77A22AC8978} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [126152 2020-04-10] (Mozilla Corporation -> Mozilla Foundation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\..\Interfaces\{13c6a99f-9d95-4eec-a5df-4c2688d728fb}: [NameServer] 8.8.8.8,8.8.4.4
Internet Explorer:
==================
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_241\bin\ssv.dll [2020-03-01] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_241\bin\jp2ssv.dll [2020-03-01] (Oracle America, Inc. -> Oracle Corporation)
FireFox:
========
FF DefaultProfile: hdqllh35.default
FF ProfilePath: C:\Users\mhick\AppData\Roaming\Mozilla\Firefox\Profiles\hdqllh35.default [2020-04-15]
FF ProfilePath: C:\Users\mhick\AppData\Roaming\Mozilla\Firefox\Profiles\au3lx6ff.default-release [2020-04-20]
FF Session Restore: Mozilla\Firefox\Profiles\au3lx6ff.default-release -> is enabled.
FF Notifications: Mozilla\Firefox\Profiles\au3lx6ff.default-release -> hxxps://teams.microsoft.com
FF Extension: (Privacy Badger) - C:\Users\mhick\AppData\Roaming\Mozilla\Firefox\Profiles\au3lx6ff.default-release\Extensions\
jid1-MnnxcxisBPnSXQ@jetpack.xpi [2020-04-15]
FF Extension: (Malwarebytes Browser Guard) - C:\Users\mhick\AppData\Roaming\Mozilla\Firefox\Profiles\au3lx6ff.default-release\Extensions\{242af0bb-db11-4734-b7a0-61cb8a9b20fb}.xpi [2020-04-15]
FF Plugin-x32: @java.com/DTPlugin,version=11.241.2 -> C:\Program Files (x86)\Java\jre1.8.0_241\bin\dtplugin\npDeployJava1.dll [2020-03-01] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.241.2 -> C:\Program Files (x86)\Java\jre1.8.0_241\bin\plugin2\npjp2.dll [2020-03-01] (Oracle America, Inc. -> Oracle Corporation)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\mhick\AppData\Local\Google\Chrome\User Data\Default [2020-04-20]
CHR Extension: (Slides) - C:\Users\mhick\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-04-15]
CHR Extension: (Docs) - C:\Users\mhick\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-04-15]
CHR Extension: (Google Drive) - C:\Users\mhick\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-04-15]
CHR Extension: (YouTube) - C:\Users\mhick\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-04-15]
CHR Extension: (Sheets) - C:\Users\mhick\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-04-15]
CHR Extension: (Google Docs Offline) - C:\Users\mhick\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-04-15]
CHR Extension: (CJFallon) - C:\Users\mhick\AppData\Local\Google\Chrome\User Data\Default\Extensions\kailnainkajeebejeigmmbphdbibdcko [2020-04-15]
CHR Extension: (Chrome Web Store Payments) - C:\Users\mhick\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-04-15]
CHR Extension: (Gmail) - C:\Users\mhick\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-04-15]
CHR Extension: (Chrome Media Router) - C:\Users\mhick\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-15]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD External Events Utility; C:\Windows\System32\DriverStore\FileRepository\u0353065.inf_amd64_2af28622e162cc90\B353014\atiesrxx.exe [524712 2020-03-18] (Advanced Micro Devices, Inc. -> AMD)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8469592 2020-03-03] (BattlEye Innovations e.K. -> )
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [811120 2020-02-22] (EasyAntiCheat Oy -> Epic Games, Inc)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6933272 2020-03-15] (Malwarebytes Inc -> Malwarebytes)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\NisSrv.exe [3294680 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MsMpEng.exe [103168 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WindscribeService; C:\Program Files (x86)\Windscribe\WindscribeService.exe [493232 2019-01-19] (Windscribe Limited -> Windscribe Limited)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 amdgpio2; C:\Windows\System32\drivers\amdgpio2.sys [45832 2019-10-01] (Advanced Micro Devices INC. -> Advanced Micro Devices, Inc)
R3 amdgpio3; C:\Windows\System32\drivers\amdgpio3.sys [24424 2016-08-12] (AMD PMP-PE CB Code Signer v20160415 -> Advanced Micro Devices, Inc)
S3 amdkmcsp; C:\Windows\system32\DRIVERS\amdkmcsp.sys [101232 2017-06-12] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc. )
R3 amdkmdag; C:\Windows\System32\DriverStore\FileRepository\u0353065.inf_amd64_2af28622e162cc90\B353014\atikmdag.sys [65752488 2020-03-18] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\Windows\System32\DriverStore\FileRepository\u0353065.inf_amd64_2af28622e162cc90\B353014\atikmpag.sys [592296 2020-03-18] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [103456 2020-02-03] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R3 AMDPCIDev; C:\Windows\System32\drivers\AMDPCIDev.sys [31592 2018-04-26] (Advanced Micro Devices Inc. -> Advanced Micro Devices)
R0 amdpsp; C:\Windows\System32\DRIVERS\amdpsp.sys [243048 2017-06-12] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc. )
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [108152 2019-11-18] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [231936 2020-01-09] (Microsoft Corporation) [File not signed]
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [214496 2020-03-15] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [20936 2020-03-15] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [226448 2020-04-17] (Malwarebytes Inc -> Malwarebytes)
S3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [73584 2020-04-17] (Malwarebytes Corporation -> Malwarebytes)
S3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [248968 2020-04-17] (Malwarebytes Inc -> Malwarebytes)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [1160280 2020-02-18] (Realtek Semiconductor Corp. -> Realtek )
R3 SteamStreamingMicrophone; C:\Windows\system32\drivers\SteamStreamingMicrophone.sys [40736 2017-07-28] (Valve Corp. -> )
R3 SteamStreamingSpeakers; C:\Windows\system32\drivers\SteamStreamingSpeakers.sys [40736 2017-07-21] (Valve Corp. -> )
S3 tapprotonvpn; C:\Windows\System32\drivers\tapprotonvpn.sys [44976 2020-01-15] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
R3 tapwindscribe0901; C:\Windows\System32\drivers\tapwindscribe0901.sys [54896 2018-07-06] (Windscribe Limited -> The OpenVPN Project)
R1 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [131144 2017-01-16] (Oracle Corporation -> Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\system32\DRIVERS\VBoxNetLwf.sys [205440 2017-01-16] (Oracle Corporation -> Oracle Corporation)
S3 ViGEmBus; C:\Windows\System32\drivers\ViGEmBus.sys [69168 2020-01-10] (Microsoft Windows Hardware Compatibility Publisher -> Benjamin Höglinger-Stelzer)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [45960 2020-03-25] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [391392 2020-03-25] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [59104 2020-03-25] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-04-20 10:29 - 2020-04-20 10:29 - 000016260 _____ C:\Users\mhick\Downloads\FRST.txt
2020-04-20 10:28 - 2020-04-20 10:29 - 000000000 ____D C:\FRST
2020-04-20 10:28 - 2020-04-20 10:28 - 002281984 _____ (Farbar) C:\Users\mhick\Downloads\FRST64.exe
2020-04-20 10:15 - 2020-04-20 10:16 - 000000000 ____D C:\Users\mhick\AppData\Local\Steam
2020-04-20 08:46 - 2020-04-20 08:46 - 000002368 _____ C:\Users\mhick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk
2020-04-20 08:46 - 2020-04-20 08:46 - 000000000 ____D C:\Users\mhick\AppData\Roaming\Microsoft Teams
2020-04-19 09:53 - 2020-04-19 09:53 - 025444352 _____ (Microsoft Corporation) C:\Windows\system32\Hydrogen.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 022636544 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 019850240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 019812864 _____ (Microsoft Corporation) C:\Windows\system32\HologramWorld.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 018027520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 014818816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 008013824 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 007756800 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 007017472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 006523048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 005910016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 005040640 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 004611584 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 004538880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 004129624 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 003753472 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 003742544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OneCoreUAPCommonProxyStub.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 003512320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 002951832 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 002800640 _____ (Microsoft Corporation) C:\Windows\system32\WinSAT.exe
2020-04-19 09:53 - 2020-04-19 09:53 - 002800128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
2020-04-19 09:53 - 2020-04-19 09:53 - 002494744 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 002180408 _____ (Microsoft Corporation) C:\Windows\system32\workfolderssvc.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 001870408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 001835008 _____ (Microsoft Corporation) C:\Windows\system32\enterprisecsps.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 001729024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallService.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 001697792 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 001665216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 001664896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 001646048 _____ (Microsoft Corporation) C:\Windows\system32\gdi32full.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 001610240 _____ (Microsoft Corporation) C:\Windows\system32\HologramCompositor.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 001587712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aadtb.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 001545216 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2020-04-19 09:53 - 2020-04-19 09:53 - 001484384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 001477112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dcomp.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 001458688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 001413840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32full.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 001397576 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe
2020-04-19 09:53 - 2020-04-19 09:53 - 001368576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 001368576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Input.Inking.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 001310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 001264640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2020-04-19 09:53 - 2020-04-19 09:53 - 001245184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBroker.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 001151816 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 001081856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.Vpn.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 001077064 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe
2020-04-19 09:53 - 2020-04-19 09:53 - 001055376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 001013000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 001009152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpnapps.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 001008128 _____ (Microsoft Corporation) C:\Windows\system32\StorSvc.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000993280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000983040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmkvsrcsnk.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000980832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webservices.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000923136 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Management.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000912896 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000892416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApiPublic.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000868864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windowsperformancerecordercontrol.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000865280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000836608 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000835584 _____ (Microsoft Corporation) C:\Windows\system32\WorkfoldersControl.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000785920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000783480 _____ (Microsoft Corporation) C:\Windows\system32\tcblaunch.exe
2020-04-19 09:53 - 2020-04-19 09:53 - 000775696 _____ (Microsoft Corporation) C:\Windows\system32\securekernel.exe
2020-04-19 09:53 - 2020-04-19 09:53 - 000768528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000729600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FlightSettings.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Mirage.Internal.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BTAGService.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000673704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000673464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontdrvhost.exe
2020-04-19 09:53 - 2020-04-19 09:53 - 000668672 _____ (Microsoft Corporation) C:\Windows\system32\wsecedit.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netlogon.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000647680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Management.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000632832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WpcWebFilter.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000629760 _____ (Microsoft Corporation) C:\Windows\system32\ipnathlp.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000628616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000595968 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000555008 _____ (Microsoft Corporation) C:\Windows\system32\appwiz.cpl
2020-04-19 09:53 - 2020-04-19 09:53 - 000538160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000532480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000529408 _____ (Microsoft Corporation) C:\Windows\system32\nltest.exe
2020-04-19 09:53 - 2020-04-19 09:53 - 000525312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsecedit.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000507152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskschd.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000491008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppcext.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000487784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000456192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appwiz.cpl
2020-04-19 09:53 - 2020-04-19 09:53 - 000452096 _____ (Microsoft Corporation) C:\Windows\system32\rdpclip.exe
2020-04-19 09:53 - 2020-04-19 09:53 - 000444416 _____ (Microsoft Corporation) C:\Windows\system32\MSFlacDecoder.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000420152 _____ (Microsoft Corporation) C:\Windows\system32\MSAudDecMFT.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000415760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aepic.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000410112 _____ (Microsoft Corporation) C:\Windows\system32\rascustom.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000406480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Enumeration.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000380416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSFlacDecoder.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000336384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\es.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000330240 _____ (Microsoft Corporation) C:\Windows\system32\omadmclient.exe
2020-04-19 09:53 - 2020-04-19 09:53 - 000324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32k.sys
2020-04-19 09:53 - 2020-04-19 09:53 - 000321536 _____ (Microsoft Corporation) C:\Windows\system32\wbadmin.exe
2020-04-19 09:53 - 2020-04-19 09:53 - 000277864 _____ (Microsoft Corporation) C:\Windows\system32\LsaIso.exe
2020-04-19 09:53 - 2020-04-19 09:53 - 000277504 _____ (Microsoft Corporation) C:\Windows\system32\scecli.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000268008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Storage.ApplicationData.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msltus40.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000234496 _____ (Microsoft Corporation) C:\Windows\system32\iasrad.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000227840 _____ (Microsoft Corporation) C:\Windows\system32\IndexedDbLegacy.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000225792 _____ (Microsoft Corporation) C:\Windows\system32\WorkFoldersShell.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000214528 _____ (Microsoft Corporation) C:\Windows\system32\srumsvc.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scecli.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000211256 _____ (Microsoft Corporation) C:\Windows\system32\tcbloader.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000203264 _____ (Microsoft Corporation) C:\Windows\system32\LanguageComponentsInstaller.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000190048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logoncli.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iasrad.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000185952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\deviceaccess.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallServiceTasks.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000179712 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000179200 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.XamlHost.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000178176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srumsvc.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000175616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IndexedDbLegacy.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\updatepolicy.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000155136 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000139776 _____ (Microsoft Corporation) C:\Windows\system32\Chakrathunk.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000135168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.XamlHost.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000130560 _____ (Microsoft Corporation) C:\Windows\system32\StorageUsage.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000123952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KerbClientShared.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000118272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\slc.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakradiag.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000105472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakrathunk.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000105472 _____ (Microsoft Corporation) C:\Windows\system32\WorkFolders.exe
2020-04-19 09:53 - 2020-04-19 09:53 - 000101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppc.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000099328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000093712 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000090624 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000089336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32u.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000087552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dot3api.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dot3msm.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000087040 _____ (Microsoft Corporation) C:\Windows\system32\iasacct.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000084280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hvservice.sys
2020-04-19 09:53 - 2020-04-19 09:53 - 000071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Custom.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000066624 _____ (Microsoft Corporation) C:\Windows\system32\iumcrypt.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iasacct.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\srumapi.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srumapi.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000050544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudNotifications.exe
2020-04-19 09:53 - 2020-04-19 09:53 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\iaspolcy.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tbauth.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000046080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf3216.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iaspolcy.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000031744 _____ (Microsoft Corporation) C:\Windows\system32\ias.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cmintegrator.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000029184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBrokerCookies.exe
2020-04-19 09:53 - 2020-04-19 09:53 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ias.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000021520 _____ (Microsoft Corporation) C:\Windows\system32\kdhvcom.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000019968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\slcext.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\icsunattend.exe
2020-04-19 09:53 - 2020-04-19 09:53 - 000015872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Custom.ps.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000010752 _____ (Microsoft Corporation) C:\Windows\system32\DMAlertListener.ProxyStub.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DMAlertListener.ProxyStub.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimg32.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2020-04-19 09:53 - 2020-04-19 09:53 - 000000315 _____ C:\Windows\system32\DrtmAuth9.bin
2020-04-19 09:53 - 2020-04-19 09:53 - 000000315 _____ C:\Windows\system32\DrtmAuth8.bin
2020-04-19 09:53 - 2020-04-19 09:53 - 000000315 _____ C:\Windows\system32\DrtmAuth7.bin
2020-04-19 09:53 - 2020-04-19 09:53 - 000000315 _____ C:\Windows\system32\DrtmAuth6.bin
2020-04-19 09:53 - 2020-04-19 09:53 - 000000315 _____ C:\Windows\system32\DrtmAuth5.bin
2020-04-19 09:53 - 2020-04-19 09:53 - 000000315 _____ C:\Windows\system32\DrtmAuth4.bin
2020-04-19 09:53 - 2020-04-19 09:53 - 000000315 _____ C:\Windows\system32\DrtmAuth3.bin
2020-04-19 09:53 - 2020-04-19 09:53 - 000000315 _____ C:\Windows\system32\DrtmAuth2.bin
2020-04-19 09:53 - 2020-04-19 09:53 - 000000315 _____ C:\Windows\system32\DrtmAuth12.bin
2020-04-19 09:53 - 2020-04-19 09:53 - 000000315 _____ C:\Windows\system32\DrtmAuth11.bin
2020-04-19 09:53 - 2020-04-19 09:53 - 000000315 _____ C:\Windows\system32\DrtmAuth10.bin
2020-04-19 09:53 - 2020-04-19 09:53 - 000000315 _____ C:\Windows\system32\DrtmAuth1.bin
2020-04-19 09:52 - 2020-04-19 09:52 - 017790464 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 009930552 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2020-04-19 09:52 - 2020-04-19 09:52 - 007849216 _____ (Microsoft Corporation) C:\Windows\system32\OneCoreUAPCommonProxyStub.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 007604584 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 006168064 _____ (Microsoft Corporation) C:\Windows\system32\twinui.pcshell.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 004563200 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2020-04-19 09:52 - 2020-04-19 09:52 - 003802624 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 003729408 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2020-04-19 09:52 - 2020-04-19 09:52 - 003708928 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 003587384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2020-04-19 09:52 - 2020-04-19 09:52 - 003547648 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 003109376 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 002986808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2020-04-19 09:52 - 2020-04-19 09:52 - 002871608 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2020-04-19 09:52 - 2020-04-19 09:52 - 002767928 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 002717184 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2020-04-19 09:52 - 2020-04-19 09:52 - 002453504 _____ (Microsoft Corporation) C:\Windows\system32\InstallService.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 002131456 _____ (Microsoft Corporation) C:\Windows\system32\WpcDesktopMonSvc.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 002126144 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 002114560 _____ (Microsoft Corporation) C:\Windows\system32\Windows.CloudStore.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 002086656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001999960 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001960448 _____ (Microsoft Corporation) C:\Windows\system32\aadtb.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001945600 _____ (Microsoft Corporation) C:\Windows\system32\dcomp.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001942528 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001918976 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001783296 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Input.Inking.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001764336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001762816 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001757096 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2020-04-19 09:52 - 2020-04-19 09:52 - 001726264 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001719808 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001656904 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001612800 _____ (Microsoft Corporation) C:\Windows\system32\wpncore.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001603584 _____ (Microsoft Corporation) C:\Windows\system32\dosvc.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001512832 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2020-04-19 09:52 - 2020-04-19 09:52 - 001497600 _____ (Microsoft Corporation) C:\Windows\system32\TokenBroker.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001480192 _____ (Microsoft Corporation) C:\Windows\system32\usocoreworker.exe
2020-04-19 09:52 - 2020-04-19 09:52 - 001427456 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.Vpn.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001413704 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001378528 _____ (Microsoft Corporation) C:\Windows\system32\webservices.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001318912 _____ (Microsoft Corporation) C:\Windows\system32\wpnapps.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001300280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2020-04-19 09:52 - 2020-04-19 09:52 - 001263856 _____ (Microsoft Corporation) C:\Windows\system32\WpcMon.exe
2020-04-19 09:52 - 2020-04-19 09:52 - 001261808 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001257472 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001243648 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001180672 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.Web.Core.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001153024 _____ (Microsoft Corporation) C:\Windows\system32\windowsperformancerecordercontrol.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001136128 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApiPublic.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001127424 _____ (Microsoft Corporation) C:\Windows\system32\WpcRefreshTask.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001083904 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001071616 _____ (Microsoft Corporation) C:\Windows\system32\BTAGService.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 001011200 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 000982840 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 000974336 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 000924672 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 000915192 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 000893952 _____ (Microsoft Corporation) C:\Windows\system32\FlightSettings.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 000879616 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Management.Service.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 000874296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys
2020-04-19 09:52 - 2020-04-19 09:52 - 000865280 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll
2020-04-19 09:52 - 2020-04-19 09:52 - 000840704 _____ (Microsoft Corporation)