TechSpot

Svchost.exe Issues

By Shakree
Dec 1, 2015
  1. Hello there! I'm new here. Well as the title said, Im having such problem since few days ago. Malwarebytes keep blocking its incoming and outgoing connections every now n then. The IP address changes everytime I restarts the PC. Another possible issue caused by it, is that my mouse is acting really weird lately. Sometimes it just wont move. However I still manage to click the left and right button. This happens even though I used different mouse to test. Sometimes the mouse clicks by itself....Here is the logs:
     
  2. Shakree

    Shakree TS Rookie Topic Starter Posts: 18

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:01-12-2015
    Ran by Shakree Elmi (administrator) on SHAKREECOMPUTER (01-12-2015 19:54:49)
    Running from C:\Users\Shakree Elmi\Desktop
    Loaded Profiles: Shakree Elmi (Available Profiles: Shakree Elmi)
    Platform: Windows 10 Pro Version 1511 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: Chrome)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (AMD) C:\Windows\System32\atiesrxx.exe
    (AMD) C:\Windows\System32\atieclxx.exe
    (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
    (MICRO-STAR INTERNATIONAL CO., LTD.) C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe
    (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
    (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
    (Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
    (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
    () C:\Program Files\WindowsApps\Microsoft.Messaging_1.11.19004.0_x86__8wekyb3d8bbwe\SkypeHost.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
    (Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
    (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
    (Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Live Update\Live Update.exe
    (Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
    (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    (DSD Consulting Services) D:\Program Files (x86)\DSDCS\InputMapper\InputMapper.exe
    (ESET) C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineScannerApp.exe
    () C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8484056 2015-06-12] (Realtek Semiconductor)
    HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-21] (Advanced Micro Devices, Inc.)
    HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
    HKLM-x32\...\Run: [] => [X]
    HKLM-x32\...\Run: [Live Update] => C:\Program Files (x86)\MSI\Live Update\Live Update.exe [11324368 2015-10-07] (Micro-Star INT'L CO., LTD.)
    HKU\S-1-5-21-1966762071-576509629-4117557406-1002\...\Run: [uTorrent] => C:\Users\Shakree Elmi\AppData\Roaming\uTorrent\uTorrent.exe [2026520 2015-11-28] (BitTorrent Inc.)
    HKU\S-1-5-21-1966762071-576509629-4117557406-1002\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3907152 2015-07-25] (Tonec Inc.)
    ShellIconOverlayIdentifiers: [! IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2015-07-24] (Tonec Inc.)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
    Tcpip\..\Interfaces\{8a1dcef8-4315-41f2-a54d-fd97fc3ce852}: [NameServer] 8.8.8.8,8.8.4.4
    Tcpip\..\Interfaces\{8a1dcef8-4315-41f2-a54d-fd97fc3ce852}: [DhcpNameServer] 192.168.0.1

    Internet Explorer:
    ==================
    BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2015-07-08] (Internet Download Manager, Tonec Inc.)
    BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2015-11-01] (Microsoft Corporation)
    BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2015-11-01] (Microsoft Corporation)
    BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2015-07-08] (Internet Download Manager, Tonec Inc.)
    BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2015-11-01] (Microsoft Corporation)
    BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2015-11-01] (Microsoft Corporation)
    Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2015-11-01] (Microsoft Corporation)
    Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2015-11-01] (Microsoft Corporation)
    Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2015-11-01] (Microsoft Corporation)
    Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2015-11-01] (Microsoft Corporation)

    FireFox:
    ========
    FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-11-01] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2015-11-01] (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-11-28] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-11-28] (Google Inc.)
    FF HKU\S-1-5-21-1966762071-576509629-4117557406-1002\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Shakree Elmi\AppData\Roaming\IDM\idmmzcc5
    FF Extension: IDM CC - C:\Users\Shakree Elmi\AppData\Roaming\IDM\idmmzcc5 [2015-12-01] [not signed]

    Chrome:
    =======
    CHR StartupUrls: Default -> "hxxp://www.google.com"
    CHR Profile: C:\Users\Shakree Elmi\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (AdBlock) - C:\Users\Shakree Elmi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-11-29]
    CHR Extension: (IDM Integration Module) - C:\Users\Shakree Elmi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2015-11-28]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\Shakree Elmi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-28]
    CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-07-24]
    CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-07-24]

    ==================== Services (Whitelisted) ========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2869432 2015-11-01] (Microsoft Corporation)
    R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
    R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
    R2 MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [1779664 2015-10-07] (Micro-Star INT'L CO., LTD.)
    R2 MSI_Trigger_Service; C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe [30240 2013-09-26] (MICRO-STAR INTERNATIONAL CO., LTD.)
    R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
    R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)

    ===================== Drivers (Whitelisted) ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [102912 2015-11-27] (Advanced Micro Devices)
    R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [245248 2015-10-30] (Microsoft Corporation)
    R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [47008 2015-11-28] ()
    R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
    R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2015-12-01] (Malwarebytes)
    R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
    R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [193336 2015-11-27] (Intel Corporation)
    S3 ptun0901; C:\Windows\System32\drivers\ptun0901.sys [27136 2014-08-08] (The OpenVPN Project)
    R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [886528 2015-05-29] (Realtek )
    R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [600832 2015-08-29] (Realtek Semiconductor Corporation)
    R3 RtlWlanu; C:\Windows\System32\drivers\rtwlanu.sys [4712800 2015-11-28] (Realtek Semiconductor Corporation )
    R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions)
    S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
    R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
    R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
    R3 XtuAcpiDriver; C:\Windows\System32\drivers\XtuAcpiDriver.sys [63840 2015-11-28] (Intel Corporation)

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
  3. Shakree

    Shakree TS Rookie Topic Starter Posts: 18

    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-12-01 19:54 - 2015-12-01 19:54 - 02350080 _____ (Farbar) C:\Users\Shakree Elmi\Desktop\FRST64.exe
    2015-12-01 19:54 - 2015-12-01 19:54 - 00011871 _____ C:\Users\Shakree Elmi\Desktop\FRST.txt
    2015-12-01 19:54 - 2015-12-01 19:54 - 00000000 ____D C:\FRST
    2015-12-01 16:00 - 2015-12-01 16:00 - 00000000 ____D C:\Program Files (x86)\ESET
    2015-12-01 15:57 - 2015-12-01 15:57 - 00004146 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{7DB598A6-A25C-4380-B226-D1FC91283E02}
    2015-12-01 15:52 - 2015-12-01 15:52 - 00001861 _____ C:\Users\Shakree Elmi\Desktop\aswMBR.txt
    2015-12-01 15:52 - 2015-12-01 15:52 - 00000512 _____ C:\Users\Shakree Elmi\Desktop\MBR.dat
    2015-12-01 15:30 - 2015-12-01 15:32 - 00250470 _____ C:\TDSSKiller.3.1.0.7_01.12.2015_15.30.59_log.txt
    2015-12-01 15:27 - 2015-12-01 15:28 - 00002930 _____ C:\Users\Shakree Elmi\Desktop\Rkill.txt
    2015-12-01 15:08 - 2015-12-01 19:53 - 00000000 ____D C:\Users\Shakree Elmi\AppData\LocalLow\uTorrent
    2015-12-01 14:37 - 2015-12-01 14:38 - 00174616 _____ C:\WINDOWS\ntbtlog.txt
    2015-12-01 14:37 - 2015-12-01 14:37 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
    2015-12-01 14:24 - 2015-12-01 14:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
    2015-12-01 14:24 - 2015-12-01 14:24 - 00000000 ____D C:\MSI
    2015-12-01 14:24 - 2014-04-30 16:23 - 00011248 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\acpimof.dll
    2015-12-01 13:42 - 2015-12-01 19:18 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
    2015-12-01 13:42 - 2015-12-01 13:42 - 00001171 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2015-12-01 13:42 - 2015-12-01 13:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2015-12-01 13:42 - 2015-12-01 13:42 - 00000000 ____D C:\ProgramData\Malwarebytes
    2015-12-01 13:42 - 2015-12-01 13:42 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
    2015-12-01 13:42 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
    2015-12-01 13:42 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
    2015-12-01 13:42 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
    2015-11-30 23:22 - 2015-11-30 23:22 - 00000000 ____D C:\Users\Shakree Elmi\Documents\Polyspace_Workspace
    2015-11-30 20:40 - 2015-11-30 20:40 - 00000897 _____ C:\Users\Public\Desktop\The Witcher 3 - Wild Hunt.lnk
    2015-11-30 20:40 - 2015-11-30 20:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Witcher 3 - Wild Hunt
    2015-11-30 14:59 - 2015-11-30 14:59 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\AMD
    2015-11-30 14:58 - 2015-11-30 22:30 - 00000000 ____D C:\Users\Shakree Elmi\Documents\MATLAB
    2015-11-30 14:58 - 2015-11-30 14:58 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\Subversion
    2015-11-30 14:58 - 2015-11-30 14:58 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\MathWorks
    2015-11-30 14:57 - 2015-11-30 14:57 - 00001671 _____ C:\Users\Shakree Elmi\Desktop\Matlab 2015a.lnk
    2015-11-30 14:57 - 2015-11-30 14:57 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\MathWorks
    2015-11-30 13:47 - 2015-11-30 13:47 - 00000000 ____D C:\Program Files\MATLAB
    2015-11-30 13:23 - 2015-11-30 13:23 - 00000000 ____D C:\WINDOWS\SysWOW64\directx
    2015-11-30 06:55 - 2015-11-30 06:55 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
    2015-11-30 01:01 - 2015-11-30 01:01 - 00003808 _____ C:\WINDOWS\System32\Tasks\HPCustParticipation HP Deskjet 2540 series
    2015-11-30 01:01 - 2015-11-30 01:01 - 00002289 _____ C:\Users\Public\Desktop\HP Deskjet 2540 series.lnk
    2015-11-30 01:01 - 2015-11-30 01:01 - 00000057 _____ C:\ProgramData\Ament.ini
    2015-11-30 01:01 - 2015-11-30 01:01 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\HpUpdate
    2015-11-30 01:01 - 2015-11-30 01:01 - 00000000 ____D C:\ProgramData\Visan
    2015-11-30 01:01 - 2015-11-30 01:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
    2015-11-30 01:01 - 2015-11-30 01:01 - 00000000 ____D C:\ProgramData\HP Photo Creations
    2015-11-30 01:01 - 2015-11-30 01:01 - 00000000 ____D C:\ProgramData\HP
    2015-11-30 01:01 - 2015-11-30 01:01 - 00000000 ____D C:\Program Files\HP
    2015-11-30 01:01 - 2015-11-30 01:01 - 00000000 ____D C:\Program Files (x86)\HP Photo Creations
    2015-11-30 01:01 - 2015-11-30 01:01 - 00000000 ____D C:\Program Files (x86)\HP
    2015-11-30 01:01 - 2015-11-30 01:01 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard
    2015-11-30 01:01 - 2014-03-06 12:51 - 00763912 ____N (Hewlett-Packard Co.) C:\WINDOWS\system32\HPDiscoPMC211.dll
    2015-11-30 00:59 - 2015-11-30 01:01 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\HP
    2015-11-30 00:29 - 2015-11-30 00:29 - 00000000 ____D C:\Users\Shakree Elmi\Documents\My Games
    2015-11-30 00:29 - 2015-11-30 00:29 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\Steam
    2015-11-30 00:29 - 2015-11-30 00:29 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\Fallout4
    2015-11-30 00:26 - 2015-11-30 00:26 - 00000689 _____ C:\Users\Public\Desktop\Far Cry 4.lnk
    2015-11-30 00:26 - 2015-11-30 00:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Far Cry 4
    2015-11-29 23:58 - 2015-11-30 00:14 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\Kodi
    2015-11-29 23:56 - 2015-11-29 23:56 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kodi
    2015-11-29 17:30 - 2015-11-29 17:30 - 00003476 _____ C:\WINDOWS\System32\Tasks\AutoPico Daily Restart
    2015-11-29 17:16 - 2015-11-29 17:16 - 00004608 _____ C:\WINDOWS\SECOH-QAD.exe
    2015-11-29 17:16 - 2015-11-29 17:16 - 00003584 _____ C:\WINDOWS\SECOH-QAD.dll
    2015-11-29 17:09 - 2015-11-29 17:09 - 00000000 ____D C:\ProgramData\KMSAuto
    2015-11-29 12:38 - 2015-11-29 11:58 - 00000000 ___DC C:\WINDOWS\Panther
    2015-11-29 12:37 - 2015-11-29 12:37 - 00000000 ____D C:\Windows.old
    2015-11-29 12:36 - 2015-11-29 12:36 - 24603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 22572632 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 22394880 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 21125408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 16984064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 13376512 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 13017088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 12120064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 07476576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 03670832 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
    2015-11-29 12:36 - 2015-11-29 12:36 - 02918808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
    2015-11-29 12:36 - 2015-11-29 12:36 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
    2015-11-29 12:36 - 2015-11-29 12:36 - 02587136 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 02544264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 02179584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 02064384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 02001408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 01998848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 01707008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
    2015-11-29 12:36 - 2015-11-29 12:36 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 01212416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 01063424 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00969728 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00914944 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00911648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00809312 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00803840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00791552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00704352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00698208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00675064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00674816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00586208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00586080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00578912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
    2015-11-29 12:36 - 2015-11-29 12:36 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00536768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00523616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
    2015-11-29 12:36 - 2015-11-29 12:36 - 00516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00511320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00454056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00408128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00405048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
    2015-11-29 12:36 - 2015-11-29 12:36 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00366224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00245848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00118624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
    2015-11-29 12:36 - 2015-11-29 12:36 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00116728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
    2015-11-29 12:36 - 2015-11-29 12:36 - 00110032 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00088392 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00073360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.proxy.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00035680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys
    2015-11-29 12:36 - 2015-11-29 12:36 - 00035656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00032040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringconfigsp.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.proxy.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\IcsEntitlementHost.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\readingviewresources.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
    2015-11-29 12:35 - 2015-10-30 03:43 - 05032960 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0816.dll
    2015-11-29 12:35 - 2015-10-30 03:42 - 05032960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0816.dll
    2015-11-29 12:35 - 2015-10-30 03:37 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0816.dll
    2015-11-29 12:35 - 2015-10-30 03:35 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0816.dll
    2015-11-29 12:33 - 2015-10-30 03:43 - 05091840 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0416.dll
    2015-11-29 12:33 - 2015-10-30 03:42 - 05091840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0416.dll
    2015-11-29 12:33 - 2015-10-30 03:38 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0416.dll
    2015-11-29 12:33 - 2015-10-30 03:36 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0416.dll
    2015-11-29 12:33 - 2015-10-30 03:28 - 04432384 _____ (Microsoft Corporation) C:\WINDOWS\system32\MLS6.dll
    2015-11-29 12:33 - 2015-10-30 03:26 - 04386304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MLS6.dll
    2015-11-29 12:32 - 2015-10-30 03:43 - 06238720 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons000c.dll
    2015-11-29 12:32 - 2015-10-30 03:41 - 06238720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons000c.dll
    2015-11-29 12:32 - 2015-10-30 03:30 - 02354176 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData000c.dll
    2015-11-29 12:32 - 2015-10-30 03:27 - 02268672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData000c.dll
    2015-11-29 12:30 - 2015-10-30 03:43 - 09893888 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons000a.dll
    2015-11-29 12:30 - 2015-10-30 03:42 - 09893888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons000a.dll
    2015-11-29 12:30 - 2015-10-30 03:26 - 09687552 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData000a.dll
    2015-11-29 12:30 - 2015-10-30 03:24 - 09566208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData000a.dll
    2015-11-29 12:28 - 2015-12-01 17:49 - 00777448 _____ C:\WINDOWS\system32\perfh007.dat
    2015-11-29 12:28 - 2015-12-01 17:49 - 00158898 _____ C:\WINDOWS\system32\perfc007.dat
    2015-11-29 12:28 - 2015-11-29 12:28 - 00305634 _____ C:\WINDOWS\system32\perfi007.dat
    2015-11-29 12:28 - 2015-11-29 12:28 - 00040390 _____ C:\WINDOWS\system32\perfd007.dat
    2015-11-29 12:28 - 2015-11-29 12:28 - 00000000 ____D C:\WINDOWS\SysWOW64\de
    2015-11-29 12:28 - 2015-11-29 12:28 - 00000000 ____D C:\WINDOWS\system32\de
    2015-11-29 12:28 - 2015-10-30 03:43 - 12039680 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0007.dll
    2015-11-29 12:28 - 2015-10-30 03:43 - 11602944 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0007.dll
    2015-11-29 12:28 - 2015-10-30 03:41 - 12039680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0007.dll
    2015-11-29 12:28 - 2015-10-30 03:28 - 02088960 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0007.dll
    2015-11-29 12:28 - 2015-10-30 03:26 - 01996800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0007.dll
    2015-11-29 12:26 - 2015-12-01 17:49 - 00812622 _____ C:\WINDOWS\system32\prfh0816.dat
    2015-11-29 12:26 - 2015-12-01 17:49 - 00161594 _____ C:\WINDOWS\system32\prfc0816.dat
    2015-11-29 12:26 - 2015-11-29 12:26 - 00341104 _____ C:\WINDOWS\system32\prfi0816.dat
    2015-11-29 12:26 - 2015-11-29 12:26 - 00042642 _____ C:\WINDOWS\system32\prfd0816.dat
    2015-11-29 12:26 - 2015-11-29 12:26 - 00000000 ____D C:\WINDOWS\SysWOW64\pt
    2015-11-29 12:26 - 2015-11-29 12:26 - 00000000 ____D C:\WINDOWS\system32\pt
    2015-11-29 12:24 - 2015-12-01 17:49 - 00798386 _____ C:\WINDOWS\system32\prfh0416.dat
    2015-11-29 12:24 - 2015-12-01 17:49 - 00158066 _____ C:\WINDOWS\system32\prfc0416.dat
    2015-11-29 12:24 - 2015-11-29 12:24 - 00328354 _____ C:\WINDOWS\system32\prfi0416.dat
    2015-11-29 12:24 - 2015-11-29 12:24 - 00040752 _____ C:\WINDOWS\system32\prfd0416.dat
    2015-11-29 12:23 - 2015-12-01 17:49 - 00826560 _____ C:\WINDOWS\system32\perfh00C.dat
    2015-11-29 12:23 - 2015-12-01 17:49 - 00159018 _____ C:\WINDOWS\system32\perfc00C.dat
    2015-11-29 12:23 - 2015-11-29 12:22 - 00350774 _____ C:\WINDOWS\system32\perfi00C.dat
    2015-11-29 12:23 - 2015-11-29 12:22 - 00040528 _____ C:\WINDOWS\system32\perfd00C.dat
    2015-11-29 12:22 - 2015-11-29 12:22 - 00000000 ____D C:\WINDOWS\SysWOW64\fr
    2015-11-29 12:22 - 2015-11-29 12:22 - 00000000 ____D C:\WINDOWS\system32\fr
    2015-11-29 12:21 - 2015-12-01 17:49 - 00822464 _____ C:\WINDOWS\system32\perfh00A.dat
    2015-11-29 12:21 - 2015-12-01 17:49 - 00164492 _____ C:\WINDOWS\system32\perfc00A.dat
    2015-11-29 12:21 - 2015-11-29 12:28 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
    2015-11-29 12:21 - 2015-11-29 12:21 - 00346516 _____ C:\WINDOWS\system32\perfi00A.dat
    2015-11-29 12:21 - 2015-11-29 12:21 - 00043804 _____ C:\WINDOWS\system32\perfd00A.dat
    2015-11-29 12:21 - 2015-11-29 12:21 - 00000000 ____D C:\WINDOWS\SysWOW64\es
    2015-11-29 12:21 - 2015-11-29 12:21 - 00000000 ____D C:\WINDOWS\system32\es
    2015-11-29 12:19 - 2015-11-29 12:19 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
    2015-11-29 12:18 - 2015-11-29 12:18 - 00000000 ____D C:\Program Files\Reference Assemblies
    2015-11-29 12:18 - 2015-11-29 12:18 - 00000000 ____D C:\Program Files\MSBuild
    2015-11-29 12:18 - 2015-11-29 12:18 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
    2015-11-29 12:18 - 2015-11-29 12:18 - 00000000 ____D C:\Program Files (x86)\MSBuild
    2015-11-29 12:18 - 2015-10-24 01:47 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
    2015-11-29 12:18 - 2015-10-24 01:47 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
    2015-11-29 12:18 - 2015-10-24 01:47 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
    2015-11-29 12:18 - 2015-10-24 01:46 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
    2015-11-29 12:18 - 2015-10-24 01:46 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
    2015-11-29 12:18 - 2015-10-24 01:45 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
    2015-11-29 12:12 - 2015-11-29 12:12 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\Comms
    2015-11-29 11:57 - 2015-11-29 11:57 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\ActiveSync
    2015-11-29 11:55 - 2015-11-29 11:55 - 00000020 ___SH C:\Users\Shakree Elmi\ntuser.ini
    2015-11-29 04:44 - 2015-12-01 17:44 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2015-11-29 04:44 - 2015-11-29 04:44 - 00022744 _____ C:\WINDOWS\system32\emptyregdb.dat
    2015-11-29 04:44 - 2015-11-29 04:44 - 00000000 _SHDL C:\Users\Default\My Documents
    2015-11-29 04:44 - 2015-11-29 04:44 - 00000000 _SHDL C:\Users\Default\Documents\My Videos
    2015-11-29 04:44 - 2015-11-29 04:44 - 00000000 _SHDL C:\Users\Default\Documents\My Pictures
    2015-11-29 04:44 - 2015-11-29 04:44 - 00000000 _SHDL C:\Users\Default\Documents\My Music
    2015-11-29 04:44 - 2015-11-29 04:44 - 00000000 _SHDL C:\Users\Default User\Documents\My Videos
    2015-11-29 04:44 - 2015-11-29 04:44 - 00000000 _SHDL C:\Users\Default User\Documents\My Pictures
    2015-11-29 04:44 - 2015-11-29 04:44 - 00000000 _SHDL C:\Users\Default User\Documents\My Music
    2015-11-29 04:42 - 2015-11-29 04:42 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
    2015-11-29 04:42 - 2015-11-29 04:42 - 00000000 ____D C:\Users\Default\AppData\Roaming\ATI
    2015-11-29 04:42 - 2015-11-29 04:42 - 00000000 ____D C:\Users\Default\AppData\Local\ATI
    2015-11-29 04:42 - 2015-11-29 04:42 - 00000000 ____D C:\Users\Default User\AppData\Roaming\ATI
    2015-11-29 04:42 - 2015-11-29 04:42 - 00000000 ____D C:\Users\Default User\AppData\Local\ATI
    2015-11-29 04:41 - 2015-11-30 16:51 - 00000000 ____D C:\Users\Shakree Elmi
    2015-11-29 04:41 - 2015-11-29 04:42 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
    2015-11-29 04:41 - 2015-11-29 04:41 - 00000000 _SHDL C:\Users\Shakree Elmi\My Documents
    2015-11-29 04:41 - 2015-11-29 04:41 - 00000000 _SHDL C:\Users\Shakree Elmi\Documents\My Videos
    2015-11-29 04:41 - 2015-11-29 04:41 - 00000000 _SHDL C:\Users\Shakree Elmi\Documents\My Pictures
    2015-11-29 04:41 - 2015-11-29 04:41 - 00000000 _SHDL C:\Users\Shakree Elmi\Documents\My Music
    2015-11-29 04:41 - 2015-10-30 07:17 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
    2015-11-29 04:40 - 2015-12-01 17:44 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin
    2015-11-29 04:40 - 2015-11-29 23:57 - 00000000 ____D C:\ProgramData\Package Cache
    2015-11-29 04:40 - 2015-11-29 04:41 - 00000000 ____D C:\Program Files\AMD
    2015-11-29 04:40 - 2015-11-29 04:40 - 00000000 ____H C:\ProgramData\DP45977C.lfl
    2015-11-29 04:40 - 2015-11-29 04:40 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
    2015-11-29 04:40 - 2015-11-29 04:40 - 00000000 ____D C:\WINDOWS\system32\DAX2
    2015-11-29 04:40 - 2015-11-29 04:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
    2015-11-29 04:40 - 2015-11-29 04:40 - 00000000 ____D C:\Program Files\Realtek
    2015-11-29 04:40 - 2015-11-29 04:40 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
    2015-11-29 04:40 - 2015-11-29 04:40 - 00000000 ____D C:\Program Files\ATI Technologies
    2015-11-29 04:40 - 2015-11-29 04:40 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
    2015-11-29 04:40 - 2015-11-29 04:40 - 00000000 _____ C:\WINDOWS\ativpsrm.bin
    2015-11-29 04:39 - 2015-11-30 13:44 - 00396752 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2015-11-29 04:39 - 2015-11-29 04:39 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
    2015-11-29 04:14 - 2015-11-29 04:44 - 00009528 _____ C:\WINDOWS\diagwrn.xml
    2015-11-29 04:14 - 2015-11-29 04:44 - 00009528 _____ C:\WINDOWS\diagerr.xml
    2015-11-29 04:13 - 2015-12-01 17:48 - 00000000 ____D C:\Users\Shakree Elmi\Desktop\Controller
    2015-11-28 19:08 - 2015-11-28 19:08 - 00001068 _____ C:\Users\Shakree Elmi\Desktop\Anno 2205.lnk
    2015-11-28 19:01 - 2015-12-01 19:31 - 00000000 ____D C:\Users\Shakree Elmi\Documents\wmd_symbol_cache
    2015-11-28 19:01 - 2015-11-28 19:03 - 00000000 ____D C:\Users\Shakree Elmi\Documents\Project CARS
    2015-11-28 19:01 - 2015-11-28 19:01 - 00000000 ____D C:\ProgramData\Steam
    2015-11-28 17:02 - 2015-11-28 17:02 - 01813392 _____ (Microsoft Corporation) C:\WINDOWS\system32\WdfCoInstaller01011.dll
    2015-11-28 17:02 - 2015-11-28 17:02 - 00063840 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\XtuAcpiDriver.sys
    2015-11-28 17:02 - 2015-08-29 06:58 - 00600832 _____ (Realtek Semiconductor Corporation) C:\WINDOWS\system32\Drivers\RtkBtfilter.sys
    2015-11-28 16:52 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_7.dll
    2015-11-28 16:52 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll
    2015-11-28 16:52 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_7.dll
    2015-11-28 16:52 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_7.dll
    2015-11-28 16:52 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll
    2015-11-28 16:52 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_5.dll
    2015-11-28 16:52 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll
    2015-11-28 16:52 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_43.dll
    2015-11-28 16:52 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_43.dll
    2015-11-28 16:52 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_43.dll
    2015-11-28 16:52 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_43.dll
    2015-11-28 16:52 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_43.dll
    2015-11-28 16:52 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_43.dll
    2015-11-28 16:52 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_43.dll
    2015-11-28 16:52 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll
    2015-11-28 16:52 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_43.dll
    2015-11-28 16:52 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_6.dll
    2015-11-28 16:52 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_6.dll
    2015-11-28 16:52 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_6.dll
    2015-11-28 16:52 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_6.dll
    2015-11-28 16:52 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_4.dll
    2015-11-28 16:52 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_4.dll
    2015-11-28 16:52 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_7.dll
    2015-11-28 16:52 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_7.dll
    2015-11-28 16:52 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_5.dll
    2015-11-28 16:52 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_5.dll
    2015-11-28 16:52 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_5.dll
    2015-11-28 16:52 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_5.dll
    2015-11-28 16:52 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_3.dll
    2015-11-28 16:52 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_3.dll
    2015-11-28 16:52 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_42.dll
    2015-11-28 16:52 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_42.dll
    2015-11-28 16:52 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_42.dll
    2015-11-28 16:52 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_42.dll
    2015-11-28 16:52 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_42.dll
    2015-11-28 16:52 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation)
     
  4. Shakree

    Shakree TS Rookie Topic Starter Posts: 18

    C:\WINDOWS\SysWOW64\D3DX9_42.dll
    2015-11-28 16:52 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll
    2015-11-28 16:52 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_42.dll
    2015-11-28 16:52 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_42.dll
    2015-11-28 16:52 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_42.dll
    2015-11-28 16:52 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_4.dll
    2015-11-28 16:52 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_4.dll
    2015-11-28 16:52 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_4.dll
    2015-11-28 16:52 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_4.dll
    2015-11-28 16:52 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_6.dll
    2015-11-28 16:52 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_6.dll
    2015-11-28 16:52 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_41.dll
    2015-11-28 16:52 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_41.dll
    2015-11-28 16:52 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_41.dll
    2015-11-28 16:52 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_41.dll
    2015-11-28 16:52 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_41.dll
    2015-11-28 16:52 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_41.dll
    2015-11-28 16:52 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_3.dll
    2015-11-28 16:52 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_3.dll
    2015-11-28 16:52 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_3.dll
    2015-11-28 16:52 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_3.dll
    2015-11-28 16:52 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_2.dll
    2015-11-28 16:52 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_2.dll
    2015-11-28 16:52 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_5.dll
    2015-11-28 16:52 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_5.dll
    2015-11-28 16:52 - 2008-10-10 04:52 - 05631312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_40.dll
    2015-11-28 16:52 - 2008-10-10 04:52 - 04379984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_40.dll
    2015-11-28 16:52 - 2008-10-10 04:52 - 02605920 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_40.dll
    2015-11-28 16:52 - 2008-10-10 04:52 - 02036576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_40.dll
    2015-11-28 16:52 - 2008-10-10 04:52 - 00519000 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_40.dll
    2015-11-28 16:52 - 2008-10-10 04:52 - 00452440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_40.dll
    2015-11-28 16:52 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_2.dll
    2015-11-28 16:52 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_2.dll
    2015-11-28 16:52 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_1.dll
    2015-11-28 16:52 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_1.dll
    2015-11-28 16:52 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_2.dll
    2015-11-28 16:52 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_2.dll
    2015-11-28 16:52 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll
    2015-11-28 16:52 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_39.dll
    2015-11-28 16:52 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll
    2015-11-28 16:52 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_39.dll
    2015-11-28 16:52 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll
    2015-11-28 16:52 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_39.dll
    2015-11-28 16:52 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_1.dll
    2015-11-28 16:52 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_1.dll
    2015-11-28 16:52 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_1.dll
    2015-11-28 16:52 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_1.dll
    2015-11-28 16:52 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_0.dll
    2015-11-28 16:52 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_0.dll
    2015-11-28 16:52 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_4.dll
    2015-11-28 16:52 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_4.dll
    2015-11-28 16:52 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_38.dll
    2015-11-28 16:52 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_38.dll
    2015-11-28 16:52 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_38.dll
    2015-11-28 16:52 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_38.dll
    2015-11-28 16:52 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_38.dll
    2015-11-28 16:52 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_38.dll
    2015-11-28 16:52 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_0.dll
    2015-11-28 16:52 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_0.dll
    2015-11-28 16:52 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_0.dll
    2015-11-28 16:52 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_0.dll
    2015-11-28 16:52 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_3.dll
    2015-11-28 16:52 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_3.dll
    2015-11-28 16:52 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_37.dll
    2015-11-28 16:52 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_37.dll
    2015-11-28 16:52 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_37.dll
    2015-11-28 16:52 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_37.dll
    2015-11-28 16:52 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_37.dll
    2015-11-28 16:52 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_37.dll
    2015-11-28 16:52 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_10.dll
    2015-11-28 16:52 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_10.dll
    2015-11-28 16:52 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_2.dll
    2015-11-28 16:52 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_2.dll
    2015-11-28 16:52 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_36.dll
    2015-11-28 16:52 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_36.dll
    2015-11-28 16:52 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_36.dll
    2015-11-28 16:52 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_36.dll
    2015-11-28 16:52 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_36.dll
    2015-11-28 16:52 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_36.dll
    2015-11-28 16:52 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_9.dll
    2015-11-28 16:52 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_9.dll
    2015-11-28 16:52 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_35.dll
    2015-11-28 16:52 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_35.dll
    2015-11-28 16:52 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_35.dll
    2015-11-28 16:52 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_35.dll
    2015-11-28 16:52 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_35.dll
    2015-11-28 16:52 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_35.dll
    2015-11-28 16:52 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_8.dll
    2015-11-28 16:52 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_8.dll
    2015-11-28 16:52 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_34.dll
    2015-11-28 16:52 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_34.dll
    2015-11-28 16:52 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_34.dll
    2015-11-28 16:52 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_34.dll
    2015-11-28 16:52 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_34.dll
    2015-11-28 16:52 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_34.dll
    2015-11-28 16:52 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_7.dll
    2015-11-28 16:52 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_7.dll
    2015-11-28 16:52 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_33.dll
    2015-11-28 16:52 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_33.dll
    2015-11-28 16:52 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_33.dll
    2015-11-28 16:52 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_33.dll
    2015-11-28 16:52 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_33.dll
    2015-11-28 16:52 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_33.dll
    2015-11-28 16:52 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_1.dll
    2015-11-28 16:52 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_1.dll
    2015-11-28 16:52 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_6.dll
    2015-11-28 16:52 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_6.dll
    2015-11-28 16:52 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_5.dll
    2015-11-28 16:52 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_5.dll
    2015-11-28 16:52 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_32.dll
    2015-11-28 16:52 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_32.dll
    2015-11-28 16:52 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10.dll
    2015-11-28 16:52 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10.dll
    2015-11-28 16:52 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_31.dll
    2015-11-28 16:52 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_31.dll
    2015-11-28 16:52 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_4.dll
    2015-11-28 16:52 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_4.dll
    2015-11-28 16:52 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_2.dll
    2015-11-28 16:52 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_3.dll
    2015-11-28 16:52 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_3.dll
    2015-11-28 16:52 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_2.dll
    2015-11-28 16:52 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_2.dll
    2015-11-28 16:52 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_2.dll
    2015-11-28 16:52 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_30.dll
    2015-11-28 16:52 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_30.dll
    2015-11-28 16:52 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_1.dll
    2015-11-28 16:52 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_1.dll
    2015-11-28 16:52 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_1.dll
    2015-11-28 16:52 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_1.dll
    2015-11-28 16:52 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_29.dll
    2015-11-28 16:52 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_29.dll
    2015-11-28 16:52 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_0.dll
    2015-11-28 16:52 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_0.dll
    2015-11-28 16:52 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_0.dll
    2015-11-28 16:52 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_0.dll
    2015-11-28 16:52 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_28.dll
    2015-11-28 16:52 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_28.dll
    2015-11-28 16:52 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_27.dll
    2015-11-28 16:52 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_27.dll
    2015-11-28 16:52 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_26.dll
    2015-11-28 16:52 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_26.dll
    2015-11-28 16:52 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_25.dll
    2015-11-28 16:52 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_25.dll
    2015-11-28 16:52 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_24.dll
    2015-11-28 16:52 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_24.dll
    2015-11-28 16:16 - 2015-11-29 04:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\by.xatab
    2015-11-28 16:16 - 2015-11-28 16:16 - 00000786 _____ C:\Users\Shakree Elmi\Desktop\x64-Project CARS.lnk
    2015-11-28 15:56 - 2015-11-28 15:56 - 00000000 ____D C:\ProgramData\DSDCS
    2015-11-28 15:55 - 2015-11-29 04:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InputMapper
    2015-11-28 15:55 - 2015-11-28 15:56 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\InputMapper
    2015-11-28 15:55 - 2015-11-28 15:55 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\DSDCS
    2015-11-28 15:55 - 2015-11-28 15:55 - 00000000 ____D C:\ProgramData\Caphyon
    2015-11-28 15:45 - 2015-12-01 19:37 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\DMCache
    2015-11-28 15:45 - 2015-12-01 14:23 - 00000000 ____D C:\Users\Shakree Elmi\Downloads\Compressed
    2015-11-28 15:45 - 2015-11-28 15:47 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\IDM
    2015-11-28 15:45 - 2015-11-28 15:45 - 00000000 ____D C:\Users\Shakree Elmi\Downloads\Video
    2015-11-28 15:45 - 2015-11-28 15:45 - 00000000 ____D C:\ProgramData\IDM
    2015-11-28 15:44 - 2015-11-29 04:42 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
    2015-11-28 15:44 - 2015-11-29 04:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
    2015-11-28 15:44 - 2015-11-28 15:45 - 00000000 ____D C:\Program Files (x86)\Internet Download Manager
    2015-11-28 15:17 - 2014-08-08 16:31 - 00027136 _____ (The OpenVPN Project) C:\WINDOWS\system32\Drivers\ptun0901.sys
    2015-11-28 15:17 - 2014-05-25 00:36 - 00015360 _____ C:\WINDOWS\system32\SppExtComObjHook.dll
    2015-11-28 15:17 - 2014-05-25 00:36 - 00004608 _____ C:\WINDOWS\system32\SppExtComObjPatcher.exe
    2015-11-28 15:13 - 2015-11-29 17:14 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\MSfree Inc
    2015-11-28 15:10 - 2015-11-28 15:10 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\PeerDistRepub
    2015-11-28 15:06 - 2015-11-29 04:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
    2015-11-28 15:06 - 2015-11-28 15:06 - 00002534 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
    2015-11-28 15:06 - 2015-11-28 15:06 - 00002498 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business 2016.lnk
    2015-11-28 15:06 - 2015-11-28 15:06 - 00002493 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
    2015-11-28 15:06 - 2015-11-28 15:06 - 00002492 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
    2015-11-28 15:06 - 2015-11-28 15:06 - 00002456 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk
    2015-11-28 15:06 - 2015-11-28 15:06 - 00002455 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
    2015-11-28 15:06 - 2015-11-28 15:06 - 00002449 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
    2015-11-28 15:06 - 2015-11-28 15:06 - 00002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
    2015-11-28 15:06 - 2015-11-28 15:06 - 00002435 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
    2015-11-28 15:04 - 2015-11-29 13:20 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
    2015-11-28 15:04 - 2015-11-28 15:04 - 00000000 ____D C:\Program Files\Microsoft Office 15
    2015-11-28 12:27 - 2015-11-28 12:27 - 633383604 _____ C:\WINDOWS\MEMORY.DMP
    2015-11-28 02:58 - 2015-11-28 02:58 - 00000000 ____D C:\Users\Shakree Elmi\Documents\Anno 2205
    2015-11-28 02:43 - 2015-11-28 02:43 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\WinRAR
    2015-11-28 02:18 - 2015-11-29 04:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics
    2015-11-28 02:18 - 2015-11-28 02:18 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\Anno 2205
    2015-11-28 02:18 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_3.dll
    2015-11-28 02:18 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_3.dll
    2015-11-28 01:42 - 2015-11-28 01:42 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\ATI
    2015-11-28 01:42 - 2015-11-28 01:42 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\ATI
     
  5. Shakree

    Shakree TS Rookie Topic Starter Posts: 18

    2015-11-28 01:42 - 2015-11-28 01:42 - 00000000 ____D C:\ProgramData\ATI
    2015-11-28 01:23 - 2015-11-28 01:23 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\Macromedia
    2015-11-28 01:19 - 2015-11-29 04:42 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
    2015-11-28 01:19 - 2015-11-29 04:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
    2015-11-28 01:19 - 2015-11-28 01:19 - 00000000 ____D C:\Program Files\WinRAR
    2015-11-28 01:14 - 2015-11-28 01:14 - 04712800 _____ (Realtek Semiconductor Corporation ) C:\WINDOWS\system32\Drivers\rtwlanu.sys
    2015-11-28 01:14 - 2015-11-28 01:14 - 00047008 _____ C:\WINDOWS\system32\Drivers\ISCTD64.sys
    2015-11-28 01:11 - 2015-11-29 04:40 - 00000000 ____D C:\AMD
    2015-11-28 01:11 - 2015-11-28 01:11 - 47794160 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\amdocl64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 39712768 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\amdocl.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 30776304 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atio6axx.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 27544560 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\amdocl12cl64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 25320432 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atioglxx.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 22327280 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\amdocl12cl.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 21648880 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Drivers\atikmdag.sys
    2015-11-28 01:11 - 2015-11-28 01:11 - 15725552 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\aticaldd64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 14310896 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\aticaldd.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 12088000 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atidxx64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 10211008 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atidxx32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 09355016 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdxc64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 08982440 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiumd6a.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 08864920 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiumd64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 08009360 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiumdva.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 07683096 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdxc32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 07482552 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiumdag.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 06686192 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmantle64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 05216240 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdmantle32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 03471376 _____ C:\WINDOWS\SysWOW64\atiumdva.cap
    2015-11-28 01:11 - 2015-11-28 01:11 - 03437632 _____ C:\WINDOWS\system32\atiumd6a.cap
    2015-11-28 01:11 - 2015-11-28 01:11 - 01479808 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\aticfx64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 01256432 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiadlxx.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 01223552 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\aticfx32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 01196032 _____ C:\WINDOWS\system32\amdocl_as64.exe
    2015-11-28 01:11 - 2015-11-28 01:11 - 01070592 _____ C:\WINDOWS\system32\amdocl_ld64.exe
    2015-11-28 01:11 - 2015-11-28 01:11 - 01004032 _____ C:\WINDOWS\SysWOW64\amdocl_as32.exe
    2015-11-28 01:11 - 2015-11-28 01:11 - 00935408 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxy.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00935408 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxx.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00874480 _____ (AMD) C:\WINDOWS\system32\coinst_15.20.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00833800 _____ C:\WINDOWS\system32\amdicdxx.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00807424 _____ C:\WINDOWS\SysWOW64\amdocl_ld32.exe
    2015-11-28 01:11 - 2015-11-28 01:11 - 00737410 _____ C:\WINDOWS\system32\atiicdxx.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00683504 _____ (AMD) C:\WINDOWS\system32\atieclxx.exe
    2015-11-28 01:11 - 2015-11-28 01:11 - 00674288 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Drivers\atikmpag.sys
    2015-11-28 01:11 - 2015-11-28 01:11 - 00662392 _____ C:\WINDOWS\SysWOW64\atiapfxx.blb
    2015-11-28 01:11 - 2015-11-28 01:11 - 00662392 _____ C:\WINDOWS\system32\atiapfxx.blb
    2015-11-28 01:11 - 2015-11-28 01:11 - 00631280 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdlvr64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00524272 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdlvr32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00471312 _____ C:\WINDOWS\system32\amdmiracast.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00451056 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atidemgy.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00375792 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiapfxx.exe
    2015-11-28 01:11 - 2015-11-28 01:11 - 00341488 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ATIODE.exe
    2015-11-28 01:11 - 2015-11-28 01:11 - 00322868 _____ C:\WINDOWS\system32\ativvaxy_vi.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00321200 _____ C:\WINDOWS\system32\ativvaxy_vi_nd.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00255808 _____ C:\WINDOWS\system32\ativvaxy_cz_nd.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00255472 _____ (AMD) C:\WINDOWS\system32\atiesrxx.exe
    2015-11-28 01:11 - 2015-11-28 01:11 - 00250884 _____ C:\WINDOWS\system32\ativvaxy_FJ.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00249088 _____ C:\WINDOWS\system32\ativvaxy_FJ_nd.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00243696 _____ C:\WINDOWS\system32\clinfo.exe
    2015-11-28 01:11 - 2015-11-28 01:11 - 00234420 _____ C:\WINDOWS\system32\ativvaxy_cik.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00232752 _____ C:\WINDOWS\system32\ativvaxy_cik_nd.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00213488 _____ C:\WINDOWS\system32\amdgfxinfo64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00204952 _____ C:\WINDOWS\SysWOW64\ativvsvl.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00204952 _____ C:\WINDOWS\system32\ativvsvl.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00199664 _____ (AMD) C:\WINDOWS\system32\atitmm64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00198640 _____ C:\WINDOWS\SysWOW64\amdgfxinfo32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00177344 _____ C:\WINDOWS\system32\ativce03.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00175648 _____ C:\WINDOWS\system32\amde31a.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00168944 _____ C:\WINDOWS\system32\atieah64.exe
    2015-11-28 01:11 - 2015-11-28 01:11 - 00165360 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6txx.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00162232 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiuxp64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00157144 _____ C:\WINDOWS\SysWOW64\ativvsva.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00157144 _____ C:\WINDOWS\system32\ativvsva.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00152560 _____ C:\WINDOWS\SysWOW64\atieah32.exe
    2015-11-28 01:11 - 2015-11-28 01:11 - 00151936 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdhcp64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00150512 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atigktxx.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00143344 _____ C:\WINDOWS\system32\amdhdl64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00143048 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiuxpag.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00140240 _____ C:\WINDOWS\system32\samu_krnl_ci.sbin
    2015-11-28 01:11 - 2015-11-28 01:11 - 00138832 _____ C:\WINDOWS\system32\samu_krnl_isv_ci.sbin
    2015-11-28 01:11 - 2015-11-28 01:11 - 00138376 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdhcp32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00136176 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantle64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00132080 _____ C:\WINDOWS\SysWOW64\amdhdl32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00130072 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiu9p64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00122352 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantle32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00117600 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdave64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00112360 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiu9pag.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00111600 _____ C:\WINDOWS\system32\hsa-thunk64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00111088 _____ C:\WINDOWS\SysWOW64\hsa-thunk.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00110312 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdave32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00103408 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantleaxl64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00100816 _____ C:\WINDOWS\system32\ativce02.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00097776 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atisamu64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00096752 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantleaxl32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00089584 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atisamu32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00088000 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdpcom64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00087992 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atimpc64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00083952 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6pxx.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00081168 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdpcom32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00081160 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atimpc32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00078320 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiglpxx.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00078320 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiglpxx.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00073712 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00071152 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\aticalrt64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00068080 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00064496 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\aticalcl64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00060912 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\aticalrt.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00059888 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ATIODCLI.exe
    2015-11-28 01:11 - 2015-11-28 01:11 - 00059376 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmmcl6.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00057840 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\aticalcl.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00052208 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Drivers\ati2erec.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00048112 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdmmcl.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00047664 _____ C:\WINDOWS\system32\kapp_ci.sbin
    2015-11-28 01:11 - 2015-11-28 01:11 - 00043536 _____ C:\WINDOWS\system32\kapp_si.sbin
    2015-11-28 01:11 - 2015-11-28 01:11 - 00038384 _____ (AMD) C:\WINDOWS\system32\atimuixx.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00012784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\detoured.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00012784 _____ (Microsoft Corporation) C:\WINDOWS\system32\detoured.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\NetworkTiles
    2015-11-28 01:03 - 2015-11-28 01:03 - 00002239 _____ C:\Users\Shakree Elmi\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
    2015-11-28 01:02 - 2015-12-01 19:53 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\uTorrent
    2015-11-28 01:02 - 2015-11-28 01:02 - 00001047 _____ C:\Users\Shakree Elmi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optional Features.lnk
    2015-11-27 13:00 - 2015-11-27 13:00 - 00193336 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\TeeDriverW8x64.sys
    2015-11-27 13:00 - 2015-11-27 13:00 - 00103424 _____ (Advanced Micro Devices) C:\WINDOWS\system32\DelayAPO.dll
    2015-11-27 13:00 - 2015-11-27 13:00 - 00102912 _____ (Advanced Micro Devices) C:\WINDOWS\system32\Drivers\AtihdWT6.sys
    2015-11-27 12:55 - 2015-11-30 23:37 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\ElevatedDiagnostics
    2015-11-27 12:53 - 2015-12-01 19:51 - 00000942 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
    2015-11-27 12:53 - 2015-12-01 17:45 - 00000938 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
    2015-11-27 12:53 - 2015-11-29 04:44 - 00003454 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
    2015-11-27 12:53 - 2015-11-29 04:44 - 00003230 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
    2015-11-27 12:53 - 2015-11-29 04:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
    2015-11-27 12:53 - 2015-11-27 12:53 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\Google
    2015-11-27 12:53 - 2015-11-27 12:53 - 00000000 ____D C:\Program Files (x86)\Google
    2015-11-27 12:52 - 2015-11-27 12:53 - 00000000 ___HD C:\Program Files (x86)\Temp
    2015-11-27 12:52 - 2015-06-15 13:41 - 02808859 _____ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT
    2015-11-27 12:52 - 2015-06-15 12:58 - 04493528 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys
    2015-11-27 12:52 - 2015-06-15 09:39 - 01748184 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll
    2015-11-27 12:52 - 2015-06-11 11:40 - 03157796 _____ C:\WINDOWS\system32\Drivers\rtkSSTsetting.dat
    2015-11-27 12:52 - 2015-06-10 05:20 - 03129672 _____ (Intel Corporation) C:\WINDOWS\system32\IntelSSTAPO.dll
    2015-11-27 12:52 - 2015-06-10 05:20 - 00728392 _____ (Intel Corporation) C:\WINDOWS\system32\IntelSstCApoPropPage.dll
    2015-11-27 12:52 - 2015-06-09 03:17 - 05708736 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICV2apo.dll
    2015-11-27 12:52 - 2015-06-05 05:45 - 02848472 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll
    2015-11-27 12:52 - 2015-06-05 05:45 - 02531544 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RltkAPO.dll
    2015-11-27 12:52 - 2015-06-02 11:25 - 01576976 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CX64APO.dll
    2015-11-27 12:52 - 2015-05-27 10:51 - 02461016 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv211.dll
    2015-11-27 12:52 - 2015-05-27 10:51 - 02393432 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv201.dll
    2015-11-27 12:52 - 2015-05-27 10:51 - 00944984 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOProp.dll
    2015-11-27 12:52 - 2015-05-27 10:51 - 00349528 _____ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2API.dll
    2015-11-27 12:52 - 2015-05-27 09:38 - 02825944 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\RtlExUpd.dll
    2015-11-27 12:52 - 2015-05-26 03:59 - 00166616 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll
    2015-11-27 12:52 - 2015-05-25 07:18 - 03195416 _____ (Fortemedia Corporation) C:\WINDOWS\system32\FMAPO64.dll
    2015-11-27 12:52 - 2015-05-20 08:14 - 03234520 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll
    2015-11-27 12:52 - 2015-05-18 06:47 - 02702040 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl
    2015-11-27 12:52 - 2015-05-15 11:27 - 02918104 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll
    2015-11-27 12:52 - 2015-05-15 08:32 - 01316056 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll
    2015-11-27 12:52 - 2015-05-11 10:53 - 12996528 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVoiceAPO3064.dll
    2015-11-27 12:52 - 2015-05-11 05:08 - 01374640 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO6064.dll
    2015-11-27 12:52 - 2015-05-11 05:08 - 01192368 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO5064.dll
    2015-11-27 12:52 - 2015-05-11 05:08 - 01145264 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO4064.dll
    2015-11-27 12:52 - 2015-05-11 05:08 - 00980400 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVoiceAPO2064.dll
    2015-11-27 12:52 - 2015-04-27 08:09 - 00328816 _____ (ICEpower a/s) C:\WINDOWS\system32\ICEsoundAPO64.dll
    2015-11-27 12:52 - 2015-04-23 21:42 - 00858256 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDRA64.dll
    2015-11-27 12:52 - 2015-04-23 21:42 - 00684176 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SECOMN64.dll
    2015-11-27 12:52 - 2015-04-23 21:42 - 00435856 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEAPO64.dll
    2015-11-27 12:52 - 2015-04-23 21:41 - 00555664 _____ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SECOMN32.DLL
    2015-11-27 12:52 - 2015-04-13 08:25 - 03262184 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE2.dll
    2015-11-27 12:52 - 2015-02-05 09:48 - 12834736 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVoiceAPO4064.dll
    2015-11-27 12:52 - 2015-02-05 09:48 - 02789808 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO7064.dll
    2015-11-27 12:52 - 2015-02-03 16:38 - 01413776 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRRPTR64.dll
    2015-11-27 12:52 - 2015-02-03 16:38 - 00454288 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRAPO64.dll
    2015-11-27 12:52 - 2015-02-03 16:38 - 00369296 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM64.dll
    2015-11-27 12:52 - 2015-02-03 16:38 - 00329360 _____ (Synopsys, Inc.) C:\WINDOWS\SysWOW64\SRCOM.dll
    2015-11-27 12:52 - 2015-02-03 16:38 - 00329360 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM.dll
    2015-11-27 12:52 - 2015-01-23 10:16 - 00213432 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tossaemaxapo64.dll
    2015-11-27 12:52 - 2015-01-19 10:10 - 72113152 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoRes64.dat
    2015-11-27 12:52 - 2014-12-11 00:10 - 01104040 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\slcnt64.dll
    2015-11-27 12:52 - 2014-12-11 00:10 - 00943784 _____ (DTS, Inc.) C:\WINDOWS\system32\sl3apo64.dll
    2015-11-27 12:52 - 2014-12-11 00:10 - 00734376 _____ (DTS, Inc.) C:\WINDOWS\system32\sltech64.dll
    2015-11-27 12:52 - 2014-12-11 00:10 - 00250536 _____ (TODO: <Company name>) C:\WINDOWS\system32\slprp64.dll
    2015-11-27 12:52 - 2014-11-11 05:44 - 00631000 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll
    2015-11-27 12:52 - 2014-11-04 05:42 - 06242576 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64AF3.dll
    2015-11-27 12:52 - 2014-11-04 05:42 - 01933584 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64AF3.dll
    2015-11-27 12:52 - 2014-11-04 05:42 - 00336144 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64AF3.dll
    2015-11-27 12:52 - 2014-11-04 05:42 - 00284944 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64F3.dll
    2015-11-27 12:52 - 2014-10-24 02:12 - 05234952 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICAPOlfx.dll
    2015-11-27 12:52 - 2014-10-24 02:12 - 00995120 _____ (Nahimic Inc) C:\WINDOWS\system32\NahimicAPONSControl.dll
    2015-11-27 12:52 - 2014-09-24 03:31 - 07087448 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64A.dll
    2015-11-27 12:52 - 2014-09-24 03:31 - 01939800 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64A.dll
    2015-11-27 12:52 - 2014-09-24 03:31 - 00315736 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64A.dll
    2015-11-27 12:52 - 2014-09-24 03:31 - 00261464 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64.dll
    2015-11-27 12:52 - 2014-08-14 11:16 - 05804772 _____ C:\WINDOWS\system32\Drivers\rtvienna.dat
    2015-11-27 12:52 - 2014-06-17 11:17 - 00856992 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo264.dll
    2015-11-27 12:52 - 2014-06-09 02:59 - 00560328 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAC64.dll
    2015-11-27 12:52 - 2014-05-22 08:24 - 00096568 _____ C:\WINDOWS\system32\audioLibVc.dll
    2015-11-27 12:52 - 2014-04-10 04:19 - 02101848 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\WavesGUILib64.dll
    2015-11-27 12:52 - 2014-04-10 04:19 - 02041432 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioEQ64.dll
    2015-11-27 12:52 - 2014-02-27 12:02 - 02162992 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE.dll
    2015-11-27 12:52 - 2014-01-31 09:27 - 01313904 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxSpeechAPO64.dll
    2015-11-27 12:52 - 2013-10-11 04:47 - 00113576 _____ (Real Sound Lab SIA) C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll
    2015-11-27 12:52 - 2013-10-11 03:31 - 00947760 _____ (Sony Corporation) C:\WINDOWS\system32\SFSS_APO.dll
    2015-11-27 12:52 - 2013-10-06 16:26 - 00501184 _____ (DTS) C:\WINDOWS\system32\DTSU2PLFX64.dll
    2015-11-27 12:52 - 2013-10-06 16:26 - 00487360 _____ (DTS) C:\WINDOWS\system32\DTSU2PGFX64.dll
    2015-11-27 12:52 - 2013-10-06 16:26 - 00415680 _____ (DTS) C:\WINDOWS\system32\DTSU2PREC64.dll
    2015-11-27 12:52 - 2013-08-14 07:36 - 00662784 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVolumeSDAPO.dll
    2015-11-27 12:52 - 2013-08-14 07:35 - 00663296 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO30.dll
    2015-11-27 12:52 - 2013-07-23 07:39 - 14048512 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioRealtek64.dll
    2015-11-27 12:52 - 2013-07-23 07:39 - 00922880 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPOShell64.dll
    2015-11-27 12:52 - 2013-06-25 04:47 - 00871856 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tossaeapo64.dll
    2015-11-27 12:52 - 2013-06-25 04:47 - 00162224 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\toseaeapo64.dll
    2015-11-27 12:52 - 2013-06-25 04:46 - 00582056 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tosasfapo64.dll
    2015-11-27 12:52 - 2013-06-21 03:01 - 00109848 _____ C:\WINDOWS\system32\AcpiServiceVnA64.dll
    2015-11-27 12:52 - 2013-04-03 06:13 - 00906800 _____ (Sony Corporation) C:\WINDOWS\system32\MISS_APO.dll
    2015-11-27 12:52 - 2012-08-31 11:18 - 07164176 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEP64A.dll
    2015-11-27 12:52 - 2012-08-31 11:17 - 00434960 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EED64A.dll
    2015-11-27 12:52 - 2012-08-31 11:17 - 00141584 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEL64A.dll
    2015-11-27 12:52 - 2012-08-31 11:17 - 00124176 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEA64A.dll
    2015-11-27 12:52 - 2012-08-31 11:17 - 00075024 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEG64A.dll
    2015-11-27 12:52 - 2012-03-08 03:47 - 00108640 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAR64.dll
    2015-11-27 12:52 - 2012-01-10 02:20 - 00065944 _____ (TOSHIBA CORPORATION.) C:\WINDOWS\system32\tepeqapo64.dll
    2015-11-27 12:52 - 2011-12-20 07:32 - 00331880 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll
    2015-11-27 12:52 - 2011-11-22 08:28 - 00014952 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll
    2015-11-27 12:52 - 2011-09-02 06:21 - 00221024 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFNHK64.dll
    2015-11-27 12:52 - 2011-09-02 06:21 - 00081248 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFCOM64.dll
    2015-11-27 12:52 - 2011-09-02 06:21 - 00078688 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFAPO64.dll
    2015-11-27 12:52 - 2011-08-23 09:00 - 00603984 _____ (Knowles Acoustics ) C:\WINDOWS\system32\KAAPORT64.dll
    2015-11-27 12:52 - 2011-05-31 01:42 - 01756264 _____ (DTS) C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll
    2015-11-27 12:52 - 2011-05-31 01:42 - 01568360 _____ (DTS) C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll
    2015-11-27 12:52 - 2011-05-31 01:42 - 01486952 _____ (DTS) C:\WINDOWS\system32\DTSBoostDLL64.dll
    2015-11-27 12:52 - 2011-05-31 01:42 - 00728680 _____ (DTS) C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll
    2015-11-27 12:52 - 2011-05-31 01:42 - 00712296 _____ (DTS) C:\WINDOWS\system32\DTSSymmetryDLL64.dll
    2015-11-27 12:52 - 2011-05-31 01:42 - 00693352 _____ (DTS) C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll
    2015-11-27 12:52 - 2011-05-31 01:42 - 00491112 _____ (DTS) C:\WINDOWS\system32\DTSNeoPCDLL64.dll
    2015-11-27 12:52 - 2011-05-31 01:42 - 00432744 _____ (DTS) C:\WINDOWS\system32\DTSLimiterDLL64.dll
    2015-11-27 12:52 - 2011-05-31 01:42 - 00428648 _____ (DTS) C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll
    2015-11-27 12:52 - 2011-05-31 01:42 - 00242792 _____ (DTS) C:\WINDOWS\system32\DTSLFXAPO64.dll
    2015-11-27 12:52 - 2011-05-31 01:42 - 00242792 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPO64.dll
    2015-11-27 12:52 - 2011-05-31 01:42 - 00241768 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPONS64.dll
    2015-11-27 12:52 - 2011-03-17 04:17 - 01361336 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tosade.dll
    2015-11-27 12:52 - 2011-03-07 09:11 - 00148416 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo.dll
    2015-11-27 12:52 - 2010-11-07 23:31 - 00375128 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEP64A.dll
    2015-11-27 12:52 - 2010-11-07 23:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DHT64.dll
    2015-11-27 12:52 - 2010-11-07 23:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DAA64.dll
    2015-11-27 12:52 - 2010-11-07 23:31 - 00204120 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEED64A.dll
    2015-11-27 12:52 - 2010-11-07 23:31 - 00101208 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEL64A.dll
    2015-11-27 12:52 - 2010-11-07 23:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEG64A.dll
    2015-11-27 12:52 - 2010-09-27 01:34 - 00318808 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO20.dll
    2015-11-27 12:52 - 2010-07-22 08:48 - 00074064 _____ (Virage Logic Corporation / Sonic Focus) C:\WINDOWS\SysWOW64\SFCOM.dll
    2015-11-27 12:52 - 2009-11-24 01:55 - 00518896 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSX64.dll
    2015-11-27 12:52 - 2009-11-24 01:55 - 00211184 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSH64.dll
    2015-11-27 12:52 - 2009-11-24 01:55 - 00198896 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSHP64.dll
    2015-11-27 12:52 - 2009-11-24 01:55 - 00155888 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSWOW64.dll
    2015-11-27 12:42 - 2015-12-01 14:24 - 00000000 ____D C:\Program Files (x86)\MSI
    2015-11-27 12:42 - 2015-11-27 12:52 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
    2015-11-27 12:42 - 2015-11-27 12:52 - 00000000 ____D C:\Program Files (x86)\Realtek
    2015-11-27 12:42 - 2015-11-27 12:42 - 00000000 ____D C:\Program Files\Intel
    2015-11-27 12:42 - 2015-05-29 02:14 - 00886528 _____ (Realtek ) C:\WINDOWS\system32\Drivers\rt640x64.sys
    2015-11-27 12:42 - 2015-05-29 02:14 - 00082544 _____ (Realtek Semiconductor Corporation) C:\WINDOWS\system32\RtNicProp64.dll
    2015-11-27 12:39 - 2015-11-27 12:39 - 00016148 _____ C:\WINDOWS\system32\DESKTOP-P1HFESU_Shakree Elmi_HistoryPrediction.bin
    2015-11-27 12:11 - 2015-11-28 01:12 - 00000000 ____D C:\Program Files (x86)\AMD
    2015-11-27 11:34 - 2015-11-29 11:56 - 00002355 _____ C:\Users\Shakree Elmi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
    2015-11-27 11:34 - 2015-11-29 11:56 - 00000000 ___RD C:\Users\Shakree Elmi\OneDrive
    2015-11-27 11:34 - 2015-11-27 11:34 - 00000000 ____D C:\WINDOWS\CSC
    2015-11-27 11:33 - 2015-11-29 12:12 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\Packages
    2015-11-27 11:33 - 2015-11-27 11:33 - 00016148 _____ C:\WINDOWS\system32\DESKTOP-P1HFESU_defaultuser0_HistoryPrediction.bin
    2015-11-27 11:33 - 2015-11-27 11:33 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\Adobe
    2015-11-27 11:33 - 2015-11-27 11:33 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\VirtualStore
    2015-11-27 11:33 - 2015-11-27 11:33 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\TileDataLayer
    2015-11-27 11:33 - 2015-11-27 11:33 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\Publishers

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-12-01 19:54 - 2015-10-30 06:28 - 00000000 ____D C:\Windows
    2015-12-01 17:49 - 2015-10-30 07:21 - 00000000 ____D C:\WINDOWS\INF
    2015-12-01 17:49 - 2015-09-21 12:21 - 05636772 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2015-12-01 17:44 - 2015-10-30 06:28 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
    2015-12-01 14:42 - 2015-10-30 07:24 - 00000000 ___HD C:\Program Files\WindowsApps
    2015-12-01 14:42 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\AppReadiness
    2015-11-30 23:51 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\system32\NDF
    2015-11-30 22:14 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports
    2015-11-30 03:47 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\appcompat
    2015-11-30 01:07 - 2015-10-30 07:11 - 00000000 ____D C:\WINDOWS\CbsTemp
    2015-11-29 13:20 - 2015-10-30 07:24 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2015-11-29 12:38 - 2015-10-30 07:24 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
    2015-11-29 12:37 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
    2015-11-29 12:37 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\system32\oobe
    2015-11-29 12:37 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
    2015-11-29 12:37 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\Provisioning
    2015-11-29 12:37 - 2015-10-30 06:28 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
    2015-11-29 12:37 - 2015-10-30 06:28 - 00000000 ____D C:\WINDOWS\system32\Dism
    2015-11-29 12:28 - 2015-10-30 09:07 - 00000000 ____D C:\Program Files\Windows Journal
    2015-11-29 12:28 - 2015-10-30 09:02 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm
    2015-11-29 12:28 - 2015-10-30 09:02 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
    2015-11-29 12:28 - 2015-10-30 09:02 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr
    2015-11-29 12:28 - 2015-10-30 09:02 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
    2015-11-29 12:28 - 2015-10-30 09:02 - 00000000 ____D C:\WINDOWS\system32\winrm
    2015-11-29 12:28 - 2015-10-30 09:02 - 00000000 ____D C:\WINDOWS\system32\WCN
    2015-11-29 12:28 - 2015-10-30 09:02 - 00000000 ____D C:\WINDOWS\system32\slmgr
    2015-11-29 12:28 - 2015-10-30 09:02 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ___SD C:\WINDOWS\system32\F12
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ___SD C:\WINDOWS\system32\dsc
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Com
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\system32\MUI
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\system32\migwiz
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\system32\Com
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\IME
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\Help
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files\Windows Photo Viewer
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files\Windows Defender
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files\Common Files\System
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files (x86)\Windows Defender
    2015-11-29 12:28 - 2015-10-30 06:28 - 00000000 ____D C:\WINDOWS\servicing
    2015-11-29 12:11 - 2015-10-30 07:24 - 00000000 ___RD C:\WINDOWS\DevicesFlow
    2015-11-29 11:55 - 2015-10-30 07:24 - 00000000 ___RD C:\WINDOWS\PrintDialog
    2015-11-29 11:55 - 2015-10-30 07:24 - 00000000 ___RD C:\WINDOWS\MiracastView
    2015-11-29 11:55 - 2015-10-30 07:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
    2015-11-29 11:55 - 2015-09-21 12:17 - 00000000 __RHD C:\Users\Public\AccountPictures
    2015-11-29 04:44 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
    2015-11-29 04:44 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\Registration
    2015-11-29 04:44 - 2015-10-30 06:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
    2015-11-29 04:43 - 2015-10-30 07:24 - 00000000 __RHD C:\Users\Public\Libraries
    2015-11-29 04:42 - 2015-07-10 09:05 - 00000000 ____D C:\Users\Default.migrated
    2015-11-29 04:41 - 2015-10-30 09:03 - 00000000 ____D C:\WINDOWS\OCR
    2015-11-29 04:41 - 2015-10-30 07:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
    2015-11-29 04:41 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\system32\spool
    2015-11-29 04:41 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
    2015-11-29 04:41 - 2015-10-30 07:24 - 00000000 ____D C:\ProgramData\USOPrivate
    2015-11-29 04:41 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
    2015-11-29 04:40 - 2015-10-30 06:28 - 00000000 ____D C:\WINDOWS\system32\Sysprep
    2015-11-29 04:39 - 2015-10-30 09:14 - 00000000 ____D C:\WINDOWS\ServiceProfiles
    2015-11-29 04:14 - 2015-10-30 09:42 - 00000000 ___HD C:\$WINDOWS.~BT
    2015-11-28 01:31 - 2015-09-21 12:31 - 00000000 ____D C:\WINDOWS\system32\MRT
    2015-11-03 00:12 - 2015-10-30 07:26 - 00810488 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
    2015-11-03 00:12 - 2015-10-30 07:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl

    ==================== Files in the root of some directories =======

    2015-11-30 01:01 - 2015-11-30 01:01 - 0000057 _____ () C:\ProgramData\Ament.ini
    2015-11-29 04:40 - 2015-11-29 04:40 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

    ==================== Bamital & volsnap =================

    (There is no automatic fix for files that do not pass verification.)

    C:\WINDOWS\system32\winlogon.exe => File is digitally signed
    C:\WINDOWS\system32\wininit.exe => File is digitally signed
    C:\WINDOWS\explorer.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
    C:\WINDOWS\system32\svchost.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
    C:\WINDOWS\system32\services.exe => File is digitally signed
    C:\WINDOWS\system32\User32.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
    C:\WINDOWS\system32\userinit.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
    C:\WINDOWS\system32\rpcss.dll => File is digitally signed
    C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
    C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2015-11-29 04:39

    ==================== End of FRST.txt ============================
     
  6. Shakree

    Shakree TS Rookie Topic Starter Posts: 18

    Additional scan result of Farbar Recovery Scan Tool (x64) Version:01-12-2015
    Ran by Shakree Elmi (2015-12-01 19:55:14)
    Running from C:\Users\Shakree Elmi\Desktop
    Windows 10 Pro (X64) (2015-11-29 04:45:00)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-1966762071-576509629-4117557406-500 - Administrator - Disabled)
    DefaultAccount (S-1-5-21-1966762071-576509629-4117557406-503 - Limited - Disabled)
    Guest (S-1-5-21-1966762071-576509629-4117557406-501 - Limited - Disabled)
    Shakree Elmi (S-1-5-21-1966762071-576509629-4117557406-1002 - Administrator - Enabled) => C:\Users\Shakree Elmi

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    µTorrent (HKU\S-1-5-21-1966762071-576509629-4117557406-1002\...\uTorrent) (Version: 3.4.5.41372 - BitTorrent Inc.)
    AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD)
    AMD Catalyst Install Manager (HKLM\...\{8F62BC70-DBB4-802D-1E1E-13630D9BA4D2}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
    Anno 2205 (HKLM-x32\...\Anno 2205_R.G. Mechanics_is1) (Version: - R.G. Mechanics, ProZorg_tm)
    ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - )
    Fallout 4 v.1.1.30 (HKLM-x32\...\Fallout 4_is1) (Version: - )
    Far Cry 4 (HKLM-x32\...\Far Cry 4_is1) (Version: - )
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 46.0.2490.86 - Google Inc.)
    Google Update Helper (x32 Version: 1.3.21.115 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
    HP Deskjet 2540 series Basic Device Software (HKLM\...\{6A79CD11-0C1C-4E24-A8C6-46A02F680346}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
    HP Deskjet 2540 series Help (HKLM-x32\...\{4539575D-C09D-4E71-B207-0F2D6BD74DA2}) (Version: 30.0.0 - Hewlett Packard)
    HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
    HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
    InputMapper (HKLM-x32\...\{1A44056A-C7D8-4561-BC43-A0AA7D7AAA64}) (Version: 1.5.31.0 - DSDCS)
    Intel(R) Chipset Device Software (x32 Version: 10.1.1.9 - Intel(R) Corporation) Hidden
    Internet Download Manager (HKLM-x32\...\Internet Download Manager) (Version: - Tonec Inc.)
    Kodi (HKU\S-1-5-21-1966762071-576509629-4117557406-1002\...\Kodi) (Version: - XBMC-Foundation)
    Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
    MATLAB Production Server R2015a (HKLM\...\MATLAB Production Server R2015a) (Version: 2.1 - MathWorks)
    Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 16.0.6001.1038 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
    MSI Live Update 6 (HKLM-x32\...\{4F46CF54-47D2-41F4-B230-B0954C544420}}_is1) (Version: 6.1.009 - MSI)
    Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.6001.1038 - Microsoft Corporation) Hidden
    Office 16 Click-to-Run Licensing Component (Version: 16.0.6001.1038 - Microsoft Corporation) Hidden
    Office 16 Click-to-Run Localization Component (x32 Version: 16.0.6001.1038 - Microsoft Corporation) Hidden
    Product Improvement Study for HP Deskjet 2540 series (HKLM\...\{DF34643B-A745-430C-B27B-A48F853C81E4}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
    Project CARS v.6.0 (HKLM-x32\...\Project CARS_is1) (Version: - )
    Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.1.505.2015 - Realtek)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7534 - Realtek Semiconductor Corp.)
    The Witcher 3: Wild Hunt (HKLM-x32\...\The Witcher 3: Wild Hunt_is1) (Version: - )
    VGA Boost (HKLM-x32\...\{809ACFAE-9A4D-4C60-9223-D8B615CD8CBA}}_is1) (Version: 1.0.0.8 - MSI)
    Windows 10 KMS Activator Ultimate 2015 v1.4 (HKLM\...\Windows 10 KMS Activator Ultimate 2015 v1.4_is1) (Version: v1.4 - )
    WinRAR 5.30 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.30.0 - win.rar GmbH)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-1966762071-576509629-4117557406-1002_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Shakree Elmi\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\FileCoAuth.exe (Microsoft Corporation)

    ==================== Restore Points =========================

    29-11-2015 12:23:42 Windows Update
    30-11-2015 13:30:46 Installed Microsoft Visual C++ 2005 Redistributable (x64)

    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2015-07-10 11:04 - 2015-07-10 11:02 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {1914852A-D9A1-4C69-AADA-53CD0C1AA4F6} - System32\Tasks\HPCustParticipation HP Deskjet 2540 series => C:\Program Files\HP\HP Deskjet 2540 series\Bin\HPCustPartic.exe [2014-03-06] (Hewlett-Packard Co.)
    Task: {19F0558C-99BB-4827-AABC-B89EB559EFB9} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-10-27] (Microsoft Corporation)
    Task: {40FB1BE7-703E-40E2-B465-98290C9C9196} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-28] (Google Inc.)
    Task: {4A3B4745-783E-48CB-A478-4D9C739AFC2D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2015-11-01] (Microsoft Corporation)
    Task: {5286C7D0-1061-469F-A4DF-A03B46DBFDE5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-28] (Google Inc.)
    Task: {D60E9870-8D1B-49A3-9765-11BD28187C9A} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2015-11-01] (Microsoft Corporation)
    Task: {DDB2B85B-AC2B-47BE-8B35-4508538F687D} - System32\Tasks\AutoPico Daily Restart => G:\KMSpico
    Task: {EE47F49F-AFAB-4B77-9F1B-B7180AC10084} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2015-11-01] (Microsoft Corporation)
    Task: {F4192480-BBB4-4A6D-9971-55BFDE927848} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2015-11-01] (Microsoft Corporation)

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    ==================== Shortcuts =============================

    (The entries could be listed to be restored or removed.)

    ==================== Loaded Modules (Whitelisted) ==============

    2015-10-30 07:18 - 2015-10-30 07:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
    2015-11-28 15:04 - 2015-11-01 02:11 - 00161448 _____ () C:\Program Files\Common Files\Microsoft Shared\ClickToRun\ApiClient.dll
    2015-10-30 07:17 - 2015-10-30 07:17 - 02652784 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
    2015-10-30 07:17 - 2015-10-30 07:17 - 02652784 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
    2015-11-29 13:18 - 2015-11-01 10:11 - 08901800 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
    2015-11-29 14:50 - 2015-11-29 14:51 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_1.11.19004.0_x86__8wekyb3d8bbwe\SkypeHost.exe
    2015-10-30 07:17 - 2015-10-30 07:17 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
    2015-10-30 07:17 - 2015-10-30 07:17 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
    2015-10-30 07:18 - 2015-10-30 09:07 - 08005632 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
    2015-10-30 07:18 - 2015-10-30 09:07 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
    2015-10-30 07:18 - 2015-10-30 09:07 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
    2015-10-30 07:18 - 2015-10-30 09:07 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
    2015-10-30 07:18 - 2015-10-30 09:07 - 00936448 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
    2015-12-01 16:00 - 2015-05-14 11:54 - 00422600 _____ () C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe
    2015-10-30 07:18 - 2015-10-30 09:07 - 03081568 _____ () C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\ContentDeliveryManager.Background.dll
    2015-10-30 07:18 - 2015-10-30 09:07 - 02394976 _____ () C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\ContentManagementSDK.dll
    2015-12-01 14:24 - 2005-07-18 13:43 - 00160256 _____ () C:\Program Files (x86)\MSI\Live Update\unrar.dll
    2015-11-29 13:17 - 2015-11-01 10:12 - 08901800 _____ () C:\Program Files (x86)\Microsoft Office\root\Office16\1033\GrooveIntlResource.dll
    2015-11-29 14:50 - 2015-11-29 14:51 - 00152064 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_1.11.19004.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
    2015-11-29 14:50 - 2015-11-29 14:51 - 18906624 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_1.11.19004.0_x86__8wekyb3d8bbwe\SkyWrap.dll
    2015-11-28 02:50 - 2015-11-07 04:36 - 01532744 _____ () C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\libglesv2.dll
    2015-11-28 02:50 - 2015-11-07 04:36 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\libegl.dll
    2015-11-28 02:50 - 2015-11-07 04:36 - 16496456 _____ () C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\PepperFlash\pepflashplayer.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


    ==================== EXE Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-1966762071-576509629-4117557406-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Shakree Elmi\pictures\brooklyn_bridge_manhattan_new_york-1920x1080.jpg
    DNS Servers: 8.8.8.8 - 8.8.4.4
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)


    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
    FirewallRules: [{E124B9E8-2D82-487E-A40F-FC391244BC7E}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    FirewallRules: [{51E2D813-4474-49F8-9711-B32BAB62F593}] => (Allow) C:\Users\Shakree Elmi\AppData\Roaming\uTorrent\uTorrent.exe
    FirewallRules: [{7D973C02-881A-42A4-841D-276E38B082C2}] => (Allow) C:\Users\Shakree Elmi\AppData\Roaming\uTorrent\uTorrent.exe
    FirewallRules: [{6E3582D3-88EB-430D-A767-1EED0F067E91}] => (Allow) C:\Users\Shakree Elmi\AppData\Roaming\uTorrent\uTorrent.exe
    FirewallRules: [{9ED4CE05-E53B-4457-9DC2-233B7C0F969F}] => (Allow) C:\Users\Shakree Elmi\AppData\Roaming\uTorrent\uTorrent.exe
    FirewallRules: [{C916FC7C-F6E6-4DE2-AB86-2738B279B9B5}] => (Allow) C:\Users\Shakree Elmi\AppData\Roaming\uTorrent\uTorrent.exe
    FirewallRules: [{A1B8FBC7-BFE3-4471-A5A7-41128AA1AD5C}] => (Allow) C:\Users\Shakree Elmi\AppData\Roaming\uTorrent\uTorrent.exe
    FirewallRules: [{A4516F8F-A072-4FD9-B1B2-21309FD632C3}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
    FirewallRules: [{235A0AFF-98BB-4BB9-BDDE-40823B9C1928}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
    FirewallRules: [{FAB8A033-607F-452A-B6CA-EE408AB50BC8}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
    FirewallRules: [{528DDFB0-8710-4358-84CF-131A8A29EE30}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
    FirewallRules: [{01BD95DB-CB51-4AAA-A85D-07A7CFEE8BD4}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
    FirewallRules: [TCP Query User{7987DA8D-3642-4568-89AE-71615ED50358}D:\program files (x86)\kodi\kodi.exe] => (Allow) D:\program files (x86)\kodi\kodi.exe
    FirewallRules: [UDP Query User{30C1CC94-F0CF-48A7-85D6-B7778C08DA7A}D:\program files (x86)\kodi\kodi.exe] => (Allow) D:\program files (x86)\kodi\kodi.exe
    FirewallRules: [TCP Query User{47633318-2712-41A5-B7A0-C87025311A3F}C:\users\shakree elmi\appdata\roaming\kodi\userdata\addon_data\plugin.video.pulsar\bin\windows_x86\pulsar.exe] => (Allow) C:\users\shakree elmi\appdata\roaming\kodi\userdata\addon_data\plugin.video.pulsar\bin\windows_x86\pulsar.exe
    FirewallRules: [UDP Query User{C51609DE-FDA7-4007-B46F-2A85E842A231}C:\users\shakree elmi\appdata\roaming\kodi\userdata\addon_data\plugin.video.pulsar\bin\windows_x86\pulsar.exe] => (Allow) C:\users\shakree elmi\appdata\roaming\kodi\userdata\addon_data\plugin.video.pulsar\bin\windows_x86\pulsar.exe
    FirewallRules: [{6DAC6E32-390A-4B55-8CA7-F5B9BE72322E}] => (Allow) C:\Program Files\HP\HP Deskjet 2540 series\Bin\DeviceSetup.exe
    FirewallRules: [{6B01B32B-865C-4B0E-AAEE-7CA0AD324901}] => (Allow) LPort=5357
    FirewallRules: [{4DE7EFD6-735A-4223-89E2-B9ABBB7AE31B}] => (Allow) C:\Program Files\HP\HP Deskjet 2540 series\Bin\HPNetworkCommunicatorCom.exe
    FirewallRules: [TCP Query User{F0F85900-57A5-4E26-A72E-DCC04887F969}C:\program files\matlab\matlab production server\r2015a\bin\win64\matlab.exe] => (Allow) C:\program files\matlab\matlab production server\r2015a\bin\win64\matlab.exe
    FirewallRules: [UDP Query User{B0C774E7-4490-45B1-94F6-5C03F5CCC2B0}C:\program files\matlab\matlab production server\r2015a\bin\win64\matlab.exe] => (Allow) C:\program files\matlab\matlab production server\r2015a\bin\win64\matlab.exe
    FirewallRules: [TCP Query User{2292BB42-AB96-45B6-B5AC-7AAADE568A2E}C:\program files\matlab\matlab production server\r2015a\bin\win64\matlab.exe] => (Allow) C:\program files\matlab\matlab production server\r2015a\bin\win64\matlab.exe
    FirewallRules: [UDP Query User{A33A66B7-129D-4F77-A3CB-DFA548C2772D}C:\program files\matlab\matlab production server\r2015a\bin\win64\matlab.exe] => (Allow) C:\program files\matlab\matlab production server\r2015a\bin\win64\matlab.exe

    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (12/01/2015 07:54:10 PM) (Source: SideBySide) (EventID: 78) (User: )
    Description: Activation context generation failed for "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" on line C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3.
    A component version required by the application conflicts with another component version already active.
    Conflicting components are:.
    Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest.
    Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest.

    Error: (12/01/2015 07:36:55 PM) (Source: SideBySide) (EventID: 78) (User: )
    Description: Activation context generation failed for "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" on line C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3.
    A component version required by the application conflicts with another component version already active.
    Conflicting components are:.
    Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest.
    Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest.

    Error: (12/01/2015 05:48:25 PM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program DS4Windows.exe version 1.4.3.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

    Process ID: 1ab4

    Start Time: 01d12c6011d65747

    Termination Time: 4294967295

    Application Path: C:\Users\Shakree Elmi\Desktop\Controller\DS4Windows.exe

    Report Id: b6202f3a-9853-11e5-9bd8-00e04c817b18

    Faulting package full name:

    Faulting package-relative application ID:

    Error: (12/01/2015 04:00:11 PM) (Source: SideBySide) (EventID: 78) (User: )
    Description: Activation context generation failed for "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" on line C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3.
    A component version required by the application conflicts with another component version already active.
    Conflicting components are:.
    Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest.
    Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest.

    Error: (12/01/2015 04:00:06 PM) (Source: SideBySide) (EventID: 78) (User: )
    Description: Activation context generation failed for "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" on line C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3.
    A component version required by the application conflicts with another component version already active.
    Conflicting components are:.
    Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest.
    Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest.

    Error: (12/01/2015 02:37:53 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: SHAKREECOMPUTER)
    Description: Activation of app Microsoft.Getstarted_2.5.6.0_x64__8wekyb3d8bbwe:App.AppX7mv0s3r0wanj0n66dy6vax24ps6avzvz.mca failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.

    Error: (12/01/2015 00:51:58 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: Fallout4.exe, version: 1.1.30.0, time stamp: 0x563b8ba7
    Faulting module name: Fallout4.exe, version: 1.1.30.0, time stamp: 0x563b8ba7
    Exception code: 0xc000041d
    Fault offset: 0x00000000016c723e
    Faulting process id: 0x348
    Faulting application start time: 0xFallout4.exe0
    Faulting application path: Fallout4.exe1
    Faulting module path: Fallout4.exe2
    Report Id: Fallout4.exe3
    Faulting package full name: Fallout4.exe4
    Faulting package-relative application ID: Fallout4.exe5

    Error: (11/30/2015 11:57:32 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: ShellExperienceHost.exe, version: 10.0.10586.0, time stamp: 0x5632d93d
    Faulting module name: NetworkUX.dll, version: 10.0.10586.0, time stamp: 0x5632d550
    Exception code: 0xc0000005
    Fault offset: 0x0000000000069d5e
    Faulting process id: 0xdf8
    Faulting application start time: 0xShellExperienceHost.exe0
    Faulting application path: ShellExperienceHost.exe1
    Faulting module path: ShellExperienceHost.exe2
    Report Id: ShellExperienceHost.exe3
    Faulting package full name: ShellExperienceHost.exe4
    Faulting package-relative application ID: ShellExperienceHost.exe5

    Error: (11/30/2015 11:57:32 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: NetworkUXBroker.exe, version: 10.0.10586.0, time stamp: 0x5632d7f4
    Faulting module name: ntdll.dll, version: 10.0.10586.0, time stamp: 0x5632d193
    Exception code: 0xc0000409
    Fault offset: 0x0000000000007f10
    Faulting process id: 0x4fc
    Faulting application start time: 0xNetworkUXBroker.exe0
    Faulting application path: NetworkUXBroker.exe1
    Faulting module path: NetworkUXBroker.exe2
    Report Id: NetworkUXBroker.exe3
    Faulting package full name: NetworkUXBroker.exe4
    Faulting package-relative application ID: NetworkUXBroker.exe5

    Error: (11/30/2015 11:40:07 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: NetworkUXBroker.exe, version: 10.0.10586.0, time stamp: 0x5632d7f4
    Faulting module name: NetworkUXBroker.exe, version: 10.0.10586.0, time stamp: 0x5632d7f4
    Exception code: 0xe0464645
    Fault offset: 0x000000000000a6d6
    Faulting process id: 0xf0c
    Faulting application start time: 0xNetworkUXBroker.exe0
    Faulting application path: NetworkUXBroker.exe1
    Faulting module path: NetworkUXBroker.exe2
    Report Id: NetworkUXBroker.exe3
    Faulting package full name: NetworkUXBroker.exe4
    Faulting package-relative application ID: NetworkUXBroker.exe5


    System errors:
    =============
    Error: (12/01/2015 07:44:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The eapihdrv service failed to start due to the following error:
    %%1275

    Error: (12/01/2015 07:44:41 PM) (Source: Application Popup) (EventID: 1060) (User: )
    Description: \??\C:\Users\SHAKRE~1\AppData\Local\Temp\ehdrv.sys

    Error: (12/01/2015 07:44:40 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The eapihdrv service failed to start due to the following error:
    %%1275

    Error: (12/01/2015 07:44:40 PM) (Source: Application Popup) (EventID: 1060) (User: )
    Description: \??\C:\Users\SHAKRE~1\AppData\Local\Temp\ehdrv.sys

    Error: (12/01/2015 07:44:40 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The eapihdrv service failed to start due to the following error:
    %%1275

    Error: (12/01/2015 07:44:40 PM) (Source: Application Popup) (EventID: 1060) (User: )
    Description: \??\C:\Users\SHAKRE~1\AppData\Local\Temp\ehdrv.sys

    Error: (12/01/2015 07:44:26 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The eapihdrv service failed to start due to the following error:
    %%1275

    Error: (12/01/2015 07:44:26 PM) (Source: Application Popup) (EventID: 1060) (User: )
    Description: \??\C:\Users\SHAKRE~1\AppData\Local\Temp\ehdrv.sys

    Error: (12/01/2015 07:44:26 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The eapihdrv service failed to start due to the following error:
    %%1275

    Error: (12/01/2015 07:44:26 PM) (Source: Application Popup) (EventID: 1060) (User: )
    Description: \??\C:\Users\SHAKRE~1\AppData\Local\Temp\ehdrv.sys


    CodeIntegrity:
    ===================================
    Date: 2015-12-01 17:36:15.788
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Windows.old\Windows\System32\WinBioPlugIns\winbiostorageadapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2015-12-01 17:36:15.772
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Windows.old\Windows\System32\WinBioPlugIns\winbiostorageadapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2015-12-01 17:36:15.754
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Windows.old\Windows\System32\WinBioPlugIns\winbiostorageadapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2015-12-01 17:36:15.738
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Windows.old\Windows\System32\WinBioPlugIns\winbiostorageadapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2015-12-01 17:36:15.719
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Windows.old\Windows\System32\WinBioPlugIns\winbiostorageadapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2015-12-01 17:36:15.698
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Windows.old\Windows\System32\WinBioPlugIns\winbiostorageadapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2015-12-01 17:36:15.670
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Windows.old\Windows\System32\WinBioPlugIns\winbiosensoradapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2015-12-01 17:36:15.653
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Windows.old\Windows\System32\WinBioPlugIns\winbiosensoradapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2015-12-01 17:36:15.637
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Windows.old\Windows\System32\WinBioPlugIns\winbiosensoradapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2015-12-01 17:36:15.620
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Windows.old\Windows\System32\WinBioPlugIns\winbiosensoradapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


    ==================== Memory info ===========================

    Processor: Intel(R) Core(TM) i5-4460 CPU @ 3.20GHz
    Percentage of memory in use: 41%
    Total physical RAM: 8134.53 MB
    Available physical RAM: 4730.09 MB
    Total Virtual: 10054.53 MB
    Available Virtual: 6194.41 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:223.02 GB) (Free:157.63 GB) NTFS
    Drive d: (HDD1) (Fixed) (Total:488.28 GB) (Free:232.4 GB) NTFS
    Drive e: (HDD2) (Fixed) (Total:443.1 GB) (Free:442.96 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 00000000)

    Partition: GPT.

    ========================================================
    Disk: 1 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: 00000000)

    Partition: GPT.

    ==================== End of Addition.txt ============================
     
  7. Broni

    Broni Malware Annihilator Posts: 52,915   +344

    Welcome aboard [​IMG]

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ============================

    [​IMG] Download RogueKiller from one of the following links and save it to your Desktop:

    Link 1
    Link 2
    • Close all the running programs
    • Windows Vista/7/8 users: right click on RogueKiller.exe, click Run as Administrator
    • Otherwise just double-click on RogueKiller.exe
    • Pre-scan will start. Let it finish.
    • Click on SCAN button.
    • Wait until the Status box shows Scan Finished
    • Click on Delete.
    • Wait until the Status box shows Deleting Finished.
    • Click on Report and copy/paste the content of the Notepad into your next reply.
    • RKreport.txt could also be found on your desktop.
    • If more than one log is produced post all logs.
    • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again
    [​IMG] Please download Malwarebytes Anti-Malware (MBAM) to your desktop.
    NOTE. If you already have MBAM 2.0 installed scroll down.
    • Double-click mbam-setup-2.0.0.1000.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to the following:
    • Launch Malwarebytes Anti-Malware
    • A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program.
    • Click Finish.
    • On the Dashboard, click the 'Update Now >>' link
    • After the update completes, click the 'Scan Now >>' button.
    • Or, on the Dashboard, click the Scan Now >> button.
    • If an update is available, click the Update Now button.
    • A Threat Scan will begin.
    • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
    • In most cases, a restart will be required.
    • Wait for the prompt to restart the computer to appear, then click on Yes.
    If you already have MBAM 2.0 installed:
    • On the Dashboard, click the 'Update Now >>' link
    • After the update completes, click the 'Scan Now >>' button.
    • Or, on the Dashboard, click the Scan Now >> button.
    • If an update is available, click the Update Now button.
    • A Threat Scan will begin.
    • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
    • In most cases, a restart will be required.
    • Wait for the prompt to restart the computer to appear, then click on Yes.
    How to get logs:
    (Export log to save as txt)
    • After the restart once you are back at your desktop, open MBAM once more.
    • Click on the History tab > Application Logs.
    • Double click on the Scan Log which shows the Date and time of the scan just performed.
    • Click 'Export'.
    • Click 'Text file (*.txt)'
    • In the Save File dialog box which appears, click on Desktop.
    • In the File name: box type a name for your scan log.
    • A message box named 'File Saved' should appear stating "Your file has been successfully exported".
    • Click Ok
    • Attach that saved log to your next reply.
    (Copy to clipboard for pasting into forum replies or tickets)
    • After the restart once you are back at your desktop, open MBAM once more.
    • Click on the History tab > Application Logs.
    • Double click on the Scan Log which shows the Date and time of the scan just performed.
    • Click 'Copy to Clipboard'
    • Paste the contents of the clipboard into your reply.
    [​IMG] Please download AdwCleaner by Xplode onto your desktop.
    • Close all open programs and internet browsers.
    • Double click on adwcleaner.exe to run the tool.
    • Click on Scan button.
    • When the scan has finished click on Clean button.
    • Your computer will be rebooted automatically. A text file will open after the restart.
    • Please post the contents of that logfile with your next reply.
    • You can find the logfile at C:\AdwCleaner[S1].txt as well.
    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
     
  8. Shakree

    Shakree TS Rookie Topic Starter Posts: 18

    RogueKiller V11.0.0.0 [Nov 27 2015] (Free) by Adlice Software
    mail : http://www.adlice.com/contact/
    Feedback : http://forum.adlice.com
    Website : http://www.adlice.com/software/roguekiller/
    Blog : http://www.adlice.com

    Operating System : Windows 10 (10.0.10586) 64 bits version
    Started in : Normal mode
    User : Shakree Elmi [Administrator]
    Started from : D:\Downloads\RogueKiller.exe
    Mode : Delete -- Date : 12/02/2015 03:16:15

    ¤¤¤ Processes : 0 ¤¤¤

    ¤¤¤ Registry : 1 ¤¤¤
    [PUP] (X64) HKEY_LOCAL_MACHINE\Software\Partner -> Deleted

    ¤¤¤ Tasks : 0 ¤¤¤

    ¤¤¤ Files : 0 ¤¤¤

    ¤¤¤ Hosts File : 0 ¤¤¤

    ¤¤¤ Antirootkit : 0 (Driver: Not loaded [0xc000036b]) ¤¤¤

    ¤¤¤ Web browsers : 0 ¤¤¤

    ¤¤¤ MBR Check : ¤¤¤
    +++++ PhysicalDrive0: TOSHIBA DT01ACA100 +++++
    --- User ---
    [MBR] 0086f36f0b7bc8b257f89fc226376c3d
    [BSP] 9e3b3c473b1db0daa516427cdae6e1cc : Windows Vista/7/8 MBR Code
    Partition table:
    0 - Microsoft reserved partition | Offset (sectors): 34 | Size: 128 MB
    1 - Basic data partition | Offset (sectors): 264192 | Size: 500000 MB
    2 - Basic data partition | Offset (sectors): 1024264192 | Size: 453739 MB
    User = LL1 ... OK
    User = LL2 ... OK

    +++++ PhysicalDrive1: KINGSTON SHFS37A240G +++++
    --- User ---
    [MBR] 0086f36f0b7bc8b257f89fc226376c3d
    [BSP] 9e3b3c473b1db0daa516427cdae6e1cc : Windows Vista/7/8 MBR Code
    Partition table:
    0 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2048 | Size: 450 MB
    1 - [MAN-MOUNT] EFI system partition | Offset (sectors): 923648 | Size: 99 MB
    2 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 1126400 | Size: 16 MB
    3 - Basic data partition | Offset (sectors): 1159168 | Size: 228370 MB
    User = LL1 ... OK
    User = LL2 ... OK

    +++++ PhysicalDrive2: TOSHIBA TransMemory USB Device +++++
    --- User ---
    [MBR] 0c32b3c8f36e867161826e931223e64a
    [BSP] e5b5096aa387558fe0746a8fa59377cb : Windows XP|VT.Unknown MBR Code
    Partition table:
    0 - [ACTIVE] FAT32 (0xb) [VISIBLE] Offset (sectors): 63 | Size: 7399 MB
    User = LL1 ... OK
    Error reading LL2 MBR! ([32] The request is not supported. )
     
  9. Shakree

    Shakree TS Rookie Topic Starter Posts: 18

    Malwarebytes Anti-Malware
    www.malwarebytes.org

    Scan Date: 02/12/2015
    Scan Time: 03:18
    Logfile: mbam.txt
    Administrator: Yes

    Version: 2.2.0.1024
    Malware Database: v2015.12.02.01
    Rootkit Database: v2015.11.26.01
    License: Trial
    Malware Protection: Enabled
    Malicious Website Protection: Enabled
    Self-protection: Disabled

    OS: Windows 10
    CPU: x64
    File System: NTFS
    User: Shakree Elmi

    Scan Type: Threat Scan
    Result: Completed
    Objects Scanned: 341019
    Time Elapsed: 3 min, 28 sec

    Memory: Enabled
    Startup: Enabled
    Filesystem: Enabled
    Archives: Enabled
    Rootkits: Disabled
    Heuristics: Enabled
    PUP: Enabled
    PUM: Enabled

    Processes: 0
    (No malicious items detected)

    Modules: 0
    (No malicious items detected)

    Registry Keys: 0
    (No malicious items detected)

    Registry Values: 0
    (No malicious items detected)

    Registry Data: 0
    (No malicious items detected)

    Folders: 0
    (No malicious items detected)

    Files: 0
    (No malicious items detected)

    Physical Sectors: 0
    (No malicious items detected)


    (end)
     
  10. Shakree

    Shakree TS Rookie Topic Starter Posts: 18

    # AdwCleaner v5.023 - Logfile created 02/12/2015 at 03:25:01
    # Updated 30/11/2015 by Xplode
    # Database : 2015-11-30.1 [Server]
    # Operating system : Windows 10 Pro (x64)
    # Username : Shakree Elmi - SHAKREECOMPUTER
    # Running from : D:\Downloads\adwcleaner_5.023.exe
    # Option : Cleaning
    # Support : http://toolslib.net/forum

    ***** [ Services ] *****


    ***** [ Folders ] *****

    [-] Folder Deleted : C:\Users\Shakree Elmi\Desktop\Controller

    ***** [ Files ] *****


    ***** [ DLLs ] *****


    ***** [ Shortcuts ] *****


    ***** [ Scheduled tasks ] *****


    ***** [ Registry ] *****


    ***** [ Web browsers ] *****

    [-] [C:\Users\Shakree Elmi\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : uk.ask.com

    *************************

    :: "Tracing" keys removed
    :: Winsock settings cleared

    ########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [848 bytes] ##########
     
  11. Shakree

    Shakree TS Rookie Topic Starter Posts: 18

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Malwarebytes
    Version: 8.0.1 (11.24.2015)
    Operating System: Windows 10 Pro x64
    Ran by Shakree Elmi (Administrator) on 02/12/2015 at 3:28:15.59
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




    File System: 0




    Registry: 0





    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on 02/12/2015 at 3:29:07.30
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     
  12. Broni

    Broni Malware Annihilator Posts: 52,915   +344

    Re-run Farbar Recovery Scan Tool (FRST/FRST64) you ran at the very beginning of this topic.

    • Double click to run it.
    • Make sure you checkmark Addition.txt box.
    • Press Scan button.
    • Scan will create two logs, FRST.txt and Addition.txt in the same directory the tool is run. Please copy and paste them to your reply.
     
  13. Shakree

    Shakree TS Rookie Topic Starter Posts: 18

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:01-12-2015
    Ran by Shakree Elmi (administrator) on SHAKREECOMPUTER (02-12-2015 13:10:10)
    Running from C:\Users\Shakree Elmi\Desktop
    Loaded Profiles: Shakree Elmi (Available Profiles: Shakree Elmi)
    Platform: Windows 10 Pro Version 1511 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: Chrome)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (AMD) C:\Windows\System32\atiesrxx.exe
    (AMD) C:\Windows\System32\atieclxx.exe
    (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
    (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
    (MICRO-STAR INTERNATIONAL CO., LTD.) C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe
    (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
    (Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
    (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
    () C:\Program Files\WindowsApps\Microsoft.Messaging_1.11.19004.0_x86__8wekyb3d8bbwe\SkypeHost.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
    (Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
    (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
    (Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Live Update\Live Update.exe
    (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    (Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
    (Microsoft Corporation) C:\Windows\System32\NetworkUXBroker.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.0_none_95e4f9a171a1ad95\TiWorker.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8484056 2015-06-12] (Realtek Semiconductor)
    HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-21] (Advanced Micro Devices, Inc.)
    HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
    HKLM-x32\...\Run: [] => [X]
    HKLM-x32\...\Run: [Live Update] => C:\Program Files (x86)\MSI\Live Update\Live Update.exe [11324368 2015-10-07] (Micro-Star INT'L CO., LTD.)
    HKU\S-1-5-21-1966762071-576509629-4117557406-1002\...\Run: [uTorrent] => C:\Users\Shakree Elmi\AppData\Roaming\uTorrent\uTorrent.exe [2026520 2015-11-28] (BitTorrent Inc.)
    HKU\S-1-5-21-1966762071-576509629-4117557406-1002\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3907152 2015-07-25] (Tonec Inc.)
    ShellIconOverlayIdentifiers: [! IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2015-07-24] (Tonec Inc.)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
    Tcpip\..\Interfaces\{db58a480-224d-4d75-bf94-77b244deef2d}: [DhcpNameServer] 192.168.0.1

    Internet Explorer:
    ==================
    BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2015-07-08] (Internet Download Manager, Tonec Inc.)
    BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2015-11-01] (Microsoft Corporation)
    BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2015-11-01] (Microsoft Corporation)
    BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2015-07-08] (Internet Download Manager, Tonec Inc.)
    BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2015-11-01] (Microsoft Corporation)
    BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2015-11-01] (Microsoft Corporation)
    Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2015-11-01] (Microsoft Corporation)
    Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2015-11-01] (Microsoft Corporation)
    Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2015-11-01] (Microsoft Corporation)
    Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2015-11-01] (Microsoft Corporation)

    FireFox:
    ========
    FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-11-01] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2015-11-01] (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-11-28] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-11-28] (Google Inc.)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
    FF HKU\S-1-5-21-1966762071-576509629-4117557406-1002\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Shakree Elmi\AppData\Roaming\IDM\idmmzcc5
    FF Extension: IDM CC - C:\Users\Shakree Elmi\AppData\Roaming\IDM\idmmzcc5 [2015-12-02] [not signed]

    Chrome:
    =======
    CHR StartupUrls: Default -> "hxxp://www.google.com"
    CHR Profile: C:\Users\Shakree Elmi\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (AdBlock) - C:\Users\Shakree Elmi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-11-29]
    CHR Extension: (IDM Integration Module) - C:\Users\Shakree Elmi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2015-11-28]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\Shakree Elmi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-28]
    CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-07-24]
    CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-07-24]

    ==================== Services (Whitelisted) ========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2869432 2015-11-01] (Microsoft Corporation)
    R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
    R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
    R2 MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [1779664 2015-10-07] (Micro-Star INT'L CO., LTD.)
    R2 MSI_Trigger_Service; C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe [30240 2013-09-26] (MICRO-STAR INTERNATIONAL CO., LTD.)
    R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
    R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)

    ===================== Drivers (Whitelisted) ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [102912 2015-11-27] (Advanced Micro Devices)
    R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [245248 2015-10-30] (Microsoft Corporation)
    R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [47008 2015-11-28] ()
    R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
    R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2015-12-02] (Malwarebytes)
    R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
    R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [193336 2015-11-27] (Intel Corporation)
    S3 ptun0901; C:\Windows\System32\drivers\ptun0901.sys [27136 2014-08-08] (The OpenVPN Project)
    R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [886528 2015-05-29] (Realtek )
    R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [593624 2015-11-28] (Realtek Semiconductor Corporation)
    R3 RtlWlanu; C:\Windows\System32\drivers\rtwlanu.sys [3764736 2015-10-30] (Realtek Semiconductor Corporation )
    R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions)
    U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [30848 2015-12-02] ()
    S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
    R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
    R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
    R3 XtuAcpiDriver; C:\Windows\System32\drivers\XtuAcpiDriver.sys [63840 2015-11-28] (Intel Corporation)

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-12-02 13:08 - 2015-12-02 13:09 - 00000000 ____D C:\Users\Shakree Elmi\AppData\LocalLow\uTorrent
    2015-12-02 13:06 - 2015-12-02 13:06 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
    2015-12-02 03:29 - 2015-12-02 03:29 - 00000553 _____ C:\Users\Shakree Elmi\Desktop\JRT.txt
    2015-12-02 03:23 - 2015-12-02 03:25 - 00000000 ____D C:\AdwCleaner
    2015-12-02 03:22 - 2015-12-02 03:22 - 00001043 _____ C:\Users\Shakree Elmi\Desktop\mbam.txt
    2015-12-02 03:17 - 2015-12-02 03:17 - 00004182 _____ C:\Users\Shakree Elmi\Desktop\RKreport.txt
    2015-12-02 03:08 - 2015-12-02 03:17 - 00000000 ____D C:\ProgramData\RogueKiller
    2015-12-02 03:08 - 2015-12-02 03:08 - 00030848 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
    2015-12-02 02:33 - 2015-12-02 02:33 - 00000804 _____ C:\Users\Shakree Elmi\Desktop\Fallout 4.lnk
    2015-12-01 22:08 - 2015-12-01 22:08 - 00000000 ____D C:\Users\Shakree Elmi\AppData\LocalLow\Adobe
    2015-12-01 22:08 - 2015-12-01 22:08 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\CEF
    2015-12-01 22:06 - 2015-12-02 03:07 - 00003972 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
    2015-12-01 22:06 - 2015-12-02 03:07 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
    2015-12-01 22:06 - 2015-12-01 22:08 - 00000000 ____D C:\ProgramData\Adobe
    2015-12-01 22:06 - 2015-12-01 22:06 - 00002124 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
    2015-12-01 22:06 - 2015-12-01 22:06 - 00000000 ____D C:\Program Files (x86)\Adobe
    2015-12-01 22:04 - 2015-12-01 22:08 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\Adobe
    2015-12-01 19:55 - 2015-12-01 19:55 - 00032514 _____ C:\Users\Shakree Elmi\Desktop\Addition.txt
    2015-12-01 19:54 - 2015-12-02 13:10 - 00011745 _____ C:\Users\Shakree Elmi\Desktop\FRST.txt
    2015-12-01 19:54 - 2015-12-02 13:10 - 00000000 ____D C:\FRST
    2015-12-01 19:54 - 2015-12-01 19:54 - 02350080 _____ (Farbar) C:\Users\Shakree Elmi\Desktop\FRST64.exe
    2015-12-01 15:57 - 2015-12-02 03:58 - 00004180 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{7DB598A6-A25C-4380-B226-D1FC91283E02}
    2015-12-01 15:52 - 2015-12-01 15:52 - 00001861 _____ C:\Users\Shakree Elmi\Desktop\aswMBR.txt
    2015-12-01 15:52 - 2015-12-01 15:52 - 00000512 _____ C:\Users\Shakree Elmi\Desktop\MBR.dat
    2015-12-01 15:30 - 2015-12-01 15:32 - 00250470 _____ C:\TDSSKiller.3.1.0.7_01.12.2015_15.30.59_log.txt
    2015-12-01 15:27 - 2015-12-01 15:28 - 00002930 _____ C:\Users\Shakree Elmi\Desktop\Rkill.txt
    2015-12-01 14:37 - 2015-12-01 14:38 - 00174616 _____ C:\WINDOWS\ntbtlog.txt
    2015-12-01 14:37 - 2015-12-01 14:37 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
    2015-12-01 14:24 - 2015-12-01 14:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
    2015-12-01 14:24 - 2015-12-01 14:24 - 00000000 ____D C:\MSI
    2015-12-01 14:24 - 2014-04-30 16:23 - 00011248 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\acpimof.dll
    2015-12-01 13:42 - 2015-12-02 13:08 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
    2015-12-01 13:42 - 2015-12-01 13:42 - 00001171 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2015-12-01 13:42 - 2015-12-01 13:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2015-12-01 13:42 - 2015-12-01 13:42 - 00000000 ____D C:\ProgramData\Malwarebytes
    2015-12-01 13:42 - 2015-12-01 13:42 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
    2015-12-01 13:42 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
    2015-12-01 13:42 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
    2015-12-01 13:42 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
    2015-11-30 23:22 - 2015-11-30 23:22 - 00000000 ____D C:\Users\Shakree Elmi\Documents\Polyspace_Workspace
    2015-11-30 20:40 - 2015-11-30 20:40 - 00000897 _____ C:\Users\Public\Desktop\The Witcher 3 - Wild Hunt.lnk
    2015-11-30 20:40 - 2015-11-30 20:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Witcher 3 - Wild Hunt
    2015-11-30 14:59 - 2015-11-30 14:59 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\AMD
    2015-11-30 14:58 - 2015-12-01 21:27 - 00000000 ____D C:\Users\Shakree Elmi\Documents\MATLAB
    2015-11-30 14:58 - 2015-11-30 14:58 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\Subversion
    2015-11-30 14:58 - 2015-11-30 14:58 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\MathWorks
    2015-11-30 14:57 - 2015-11-30 14:57 - 00001671 _____ C:\Users\Shakree Elmi\Desktop\Matlab 2015a.lnk
    2015-11-30 14:57 - 2015-11-30 14:57 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\MathWorks
    2015-11-30 13:47 - 2015-11-30 13:47 - 00000000 ____D C:\Program Files\MATLAB
    2015-11-30 13:23 - 2015-11-30 13:23 - 00000000 ____D C:\WINDOWS\SysWOW64\directx
    2015-11-30 06:55 - 2015-11-30 06:55 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
    2015-11-30 01:01 - 2015-11-30 01:01 - 00003808 _____ C:\WINDOWS\System32\Tasks\HPCustParticipation HP Deskjet 2540 series
    2015-11-30 01:01 - 2015-11-30 01:01 - 00002289 _____ C:\Users\Public\Desktop\HP Deskjet 2540 series.lnk
    2015-11-30 01:01 - 2015-11-30 01:01 - 00000057 _____ C:\ProgramData\Ament.ini
    2015-11-30 01:01 - 2015-11-30 01:01 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\HpUpdate
    2015-11-30 01:01 - 2015-11-30 01:01 - 00000000 ____D C:\ProgramData\Visan
    2015-11-30 01:01 - 2015-11-30 01:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
    2015-11-30 01:01 - 2015-11-30 01:01 - 00000000 ____D C:\ProgramData\HP Photo Creations
    2015-11-30 01:01 - 2015-11-30 01:01 - 00000000 ____D C:\ProgramData\HP
    2015-11-30 01:01 - 2015-11-30 01:01 - 00000000 ____D C:\Program Files\HP
    2015-11-30 01:01 - 2015-11-30 01:01 - 00000000 ____D C:\Program Files (x86)\HP Photo Creations
    2015-11-30 01:01 - 2015-11-30 01:01 - 00000000 ____D C:\Program Files (x86)\HP
    2015-11-30 01:01 - 2015-11-30 01:01 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard
    2015-11-30 01:01 - 2014-03-06 12:51 - 00763912 ____N (Hewlett-Packard Co.) C:\WINDOWS\system32\HPDiscoPMC211.dll
    2015-11-30 00:59 - 2015-11-30 01:01 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\HP
    2015-11-30 00:29 - 2015-11-30 00:29 - 00000000 ____D C:\Users\Shakree Elmi\Documents\My Games
    2015-11-30 00:29 - 2015-11-30 00:29 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\Steam
    2015-11-30 00:29 - 2015-11-30 00:29 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\Fallout4
    2015-11-30 00:26 - 2015-11-30 00:26 - 00000689 _____ C:\Users\Public\Desktop\Far Cry 4.lnk
    2015-11-30 00:26 - 2015-11-30 00:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Far Cry 4
    2015-11-29 23:58 - 2015-12-01 22:25 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\Kodi
    2015-11-29 23:56 - 2015-11-29 23:56 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kodi
    2015-11-29 17:30 - 2015-11-29 17:30 - 00003476 _____ C:\WINDOWS\System32\Tasks\AutoPico Daily Restart
    2015-11-29 17:16 - 2015-11-29 17:16 - 00004608 _____ C:\WINDOWS\SECOH-QAD.exe
    2015-11-29 17:16 - 2015-11-29 17:16 - 00003584 _____ C:\WINDOWS\SECOH-QAD.dll
    2015-11-29 17:09 - 2015-11-29 17:09 - 00000000 ____D C:\ProgramData\KMSAuto
    2015-11-29 12:38 - 2015-11-29 11:58 - 00000000 ___DC C:\WINDOWS\Panther
    2015-11-29 12:37 - 2015-11-29 12:37 - 00000000 ____D C:\Windows.old
    2015-11-29 12:36 - 2015-11-29 12:36 - 24603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 22572632 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 22394880 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 21125408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 16984064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 13376512 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 13017088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 12120064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 07476576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 03670832 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
    2015-11-29 12:36 - 2015-11-29 12:36 - 02918808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
    2015-11-29 12:36 - 2015-11-29 12:36 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
    2015-11-29 12:36 - 2015-11-29 12:36 - 02587136 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 02544264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 02179584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 02064384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 02001408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 01998848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 01707008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
    2015-11-29 12:36 - 2015-11-29 12:36 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 01212416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 01063424 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00969728 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00914944 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00911648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00809312 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00803840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00791552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00704352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00698208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00675064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00674816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00586208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00586080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00578912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
    2015-11-29 12:36 - 2015-11-29 12:36 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00536768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00523616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
    2015-11-29 12:36 - 2015-11-29 12:36 - 00516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00511320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00454056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00408128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00405048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
    2015-11-29 12:36 - 2015-11-29 12:36 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00366224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00245848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00118624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
    2015-11-29 12:36 - 2015-11-29 12:36 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00116728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
    2015-11-29 12:36 - 2015-11-29 12:36 - 00110032 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00088392 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00073360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.proxy.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00035680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys
    2015-11-29 12:36 - 2015-11-29 12:36 - 00035656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00032040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringconfigsp.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.proxy.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\IcsEntitlementHost.exe
    2015-11-29 12:36 - 2015-11-29 12:36 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\readingviewresources.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
    2015-11-29 12:36 - 2015-11-29 12:36 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
    2015-11-29 12:35 - 2015-10-30 03:43 - 05032960 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0816.dll
    2015-11-29 12:35 - 2015-10-30 03:42 - 05032960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0816.dll
    2015-11-29 12:35 - 2015-10-30 03:37 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0816.dll
    2015-11-29 12:35 - 2015-10-30 03:35 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0816.dll
    2015-11-29 12:33 - 2015-10-30 03:43 - 05091840 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0416.dll
    2015-11-29 12:33 - 2015-10-30 03:42 - 05091840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0416.dll
    2015-11-29 12:33 - 2015-10-30 03:38 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0416.dll
    2015-11-29 12:33 - 2015-10-30 03:36 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0416.dll
    2015-11-29 12:33 - 2015-10-30 03:28 - 04432384 _____ (Microsoft Corporation) C:\WINDOWS\system32\MLS6.dll
    2015-11-29 12:33 - 2015-10-30 03:26 - 04386304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MLS6.dll
    2015-11-29 12:32 - 2015-10-30 03:43 - 06238720 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons000c.dll
    2015-11-29 12:32 - 2015-10-30 03:41 - 06238720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons000c.dll
    2015-11-29 12:32 - 2015-10-30 03:30 - 02354176 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData000c.dll
    2015-11-29 12:32 - 2015-10-30 03:27 - 02268672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData000c.dll
    2015-11-29 12:30 - 2015-10-30 03:43 - 09893888 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons000a.dll
    2015-11-29 12:30 - 2015-10-30 03:42 - 09893888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons000a.dll
    2015-11-29 12:30 - 2015-10-30 03:26 - 09687552 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData000a.dll
    2015-11-29 12:30 - 2015-10-30 03:24 - 09566208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData000a.dll
    2015-11-29 12:28 - 2015-12-02 03:52 - 00777448 _____ C:\WINDOWS\system32\perfh007.dat
    2015-11-29 12:28 - 2015-12-02 03:52 - 00158898 _____ C:\WINDOWS\system32\perfc007.dat
    2015-11-29 12:28 - 2015-11-29 12:28 - 00305634 _____ C:\WINDOWS\system32\perfi007.dat
    2015-11-29 12:28 - 2015-11-29 12:28 - 00040390 _____ C:\WINDOWS\system32\perfd007.dat
    2015-11-29 12:28 - 2015-11-29 12:28 - 00000000 ____D C:\WINDOWS\SysWOW64\de
    2015-11-29 12:28 - 2015-11-29 12:28 - 00000000 ____D C:\WINDOWS\system32\de
    2015-11-29 12:28 - 2015-10-30 03:43 - 12039680 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0007.dll
    2015-11-29 12:28 - 2015-10-30 03:43 - 11602944 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0007.dll
    2015-11-29 12:28 - 2015-10-30 03:41 - 12039680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0007.dll
    2015-11-29 12:28 - 2015-10-30 03:28 - 02088960 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0007.dll
    2015-11-29 12:28 - 2015-10-30 03:26 - 01996800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0007.dll
    2015-11-29 12:26 - 2015-12-02 03:52 - 00812622 _____ C:\WINDOWS\system32\prfh0816.dat
    2015-11-29 12:26 - 2015-12-02 03:52 - 00161594 _____ C:\WINDOWS\system32\prfc0816.dat
    2015-11-29 12:26 - 2015-11-29 12:26 - 00341104 _____ C:\WINDOWS\system32\prfi0816.dat
    2015-11-29 12:26 - 2015-11-29 12:26 - 00042642 _____ C:\WINDOWS\system32\prfd0816.dat
    2015-11-29 12:26 - 2015-11-29 12:26 - 00000000 ____D C:\WINDOWS\SysWOW64\pt
    2015-11-29 12:26 - 2015-11-29 12:26 - 00000000 ____D C:\WINDOWS\system32\pt
    2015-11-29 12:24 - 2015-12-02 03:52 - 00798386 _____ C:\WINDOWS\system32\prfh0416.dat
    2015-11-29 12:24 - 2015-12-02 03:52 - 00158066 _____ C:\WINDOWS\system32\prfc0416.dat
    2015-11-29 12:24 - 2015-11-29 12:24 - 00328354 _____ C:\WINDOWS\system32\prfi0416.dat
    2015-11-29 12:24 - 2015-11-29 12:24 - 00040752 _____ C:\WINDOWS\system32\prfd0416.dat
    2015-11-29 12:23 - 2015-12-02 03:52 - 00826560 _____ C:\WINDOWS\system32\perfh00C.dat
    2015-11-29 12:23 - 2015-12-02 03:52 - 00159018 _____ C:\WINDOWS\system32\perfc00C.dat
    2015-11-29 12:23 - 2015-11-29 12:22 - 00350774 _____ C:\WINDOWS\system32\perfi00C.dat
    2015-11-29 12:23 - 2015-11-29 12:22 - 00040528 _____ C:\WINDOWS\system32\perfd00C.dat
    2015-11-29 12:22 - 2015-11-29 12:22 - 00000000 ____D C:\WINDOWS\SysWOW64\fr
    2015-11-29 12:22 - 2015-11-29 12:22 - 00000000 ____D C:\WINDOWS\system32\fr
    2015-11-29 12:21 - 2015-12-02 03:52 - 00822464 _____ C:\WINDOWS\system32\perfh00A.dat
    2015-11-29 12:21 - 2015-12-02 03:52 - 00164492 _____ C:\WINDOWS\system32\perfc00A.dat
    2015-11-29 12:21 - 2015-11-29 12:28 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
    2015-11-29 12:21 - 2015-11-29 12:21 - 00346516 _____ C:\WINDOWS\system32\perfi00A.dat
    2015-11-29 12:21 - 2015-11-29 12:21 - 00043804 _____ C:\WINDOWS\system32\perfd00A.dat
    2015-11-29 12:21 - 2015-11-29 12:21 - 00000000 ____D C:\WINDOWS\SysWOW64\es
    2015-11-29 12:21 - 2015-11-29 12:21 - 00000000 ____D C:\WINDOWS\system32\es
    2015-11-29 12:19 - 2015-11-29 12:19 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
    2015-11-29 12:18 - 2015-11-29 12:18 - 00000000 ____D C:\Program Files\Reference Assemblies
    2015-11-29 12:18 - 2015-11-29 12:18 - 00000000 ____D C:\Program Files\MSBuild
    2015-11-29 12:18 - 2015-11-29 12:18 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
    2015-11-29 12:18 - 2015-11-29 12:18 - 00000000 ____D C:\Program Files (x86)\MSBuild
    2015-11-29 12:18 - 2015-10-24 01:47 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
    2015-11-29 12:18 - 2015-10-24 01:47 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
    2015-11-29 12:18 - 2015-10-24 01:47 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
    2015-11-29 12:18 - 2015-10-24 01:46 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
    2015-11-29 12:18 - 2015-10-24 01:46 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
    2015-11-29 12:18 - 2015-10-24 01:45 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
    2015-11-29 12:12 - 2015-11-29 12:12 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\Comms
    2015-11-29 11:57 - 2015-11-29 11:57 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\ActiveSync
    2015-11-29 11:55 - 2015-11-29 11:55 - 00000020 ___SH C:\Users\Shakree Elmi\ntuser.ini
    2015-11-29 04:44 - 2015-12-02 13:07 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2015-11-29 04:44 - 2015-11-29 04:44 - 00022744 _____ C:\WINDOWS\system32\emptyregdb.dat
    2015-11-29 04:44 - 2015-11-29 04:44 - 00000000 _SHDL C:\Users\Default\My Documents
    2015-11-29 04:44 - 2015-11-29 04:44 - 00000000 _SHDL C:\Users\Default\Documents\My Videos
    2015-11-29 04:44 - 2015-11-29 04:44 - 00000000 _SHDL C:\Users\Default\Documents\My Pictures
    2015-11-29 04:44 - 2015-11-29 04:44 - 00000000 _SHDL C:\Users\Default\Documents\My Music
    2015-11-29 04:44 - 2015-11-29 04:44 - 00000000 _SHDL C:\Users\Default User\Documents\My Videos
    2015-11-29 04:44 - 2015-11-29 04:44 - 00000000 _SHDL C:\Users\Default User\Documents\My Pictures
    2015-11-29 04:44 - 2015-11-29 04:44 - 00000000 _SHDL C:\Users\Default User\Documents\My Music
    2015-11-29 04:42 - 2015-11-29 04:42 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
    2015-11-29 04:42 - 2015-11-29 04:42 - 00000000 ____D C:\Users\Default\AppData\Roaming\ATI
    2015-11-29 04:42 - 2015-11-29 04:42 - 00000000 ____D C:\Users\Default\AppData\Local\ATI
    2015-11-29 04:42 - 2015-11-29 04:42 - 00000000 ____D C:\Users\Default User\AppData\Roaming\ATI
    2015-11-29 04:42 - 2015-11-29 04:42 - 00000000 ____D C:\Users\Default User\AppData\Local\ATI
    2015-11-29 04:41 - 2015-12-02 12:55 - 00000000 ____D C:\Users\Shakree Elmi
    2015-11-29 04:41 - 2015-11-29 04:42 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
    2015-11-29 04:41 - 2015-11-29 04:41 - 00000000 _SHDL C:\Users\Shakree Elmi\My Documents
    2015-11-29 04:41 - 2015-11-29 04:41 - 00000000 _SHDL C:\Users\Shakree Elmi\Documents\My Videos
    2015-11-29 04:41 - 2015-11-29 04:41 - 00000000 _SHDL C:\Users\Shakree Elmi\Documents\My Pictures
    2015-11-29 04:41 - 2015-11-29 04:41 - 00000000 _SHDL C:\Users\Shakree Elmi\Documents\My Music
    2015-11-29 04:41 - 2015-10-30 07:17 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
    2015-11-29 04:40 - 2015-12-02 13:07 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin
    2015-11-29 04:40 - 2015-11-29 23:57 - 00000000 ____D C:\ProgramData\Package Cache
    2015-11-29 04:40 - 2015-11-29 04:41 - 00000000 ____D C:\Program Files\AMD
    2015-11-29 04:40 - 2015-11-29 04:40 - 00000000 ____H C:\ProgramData\DP45977C.lfl
    2015-11-29 04:40 - 2015-11-29 04:40 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
    2015-11-29 04:40 - 2015-11-29 04:40 - 00000000 ____D C:\WINDOWS\system32\DAX2
    2015-11-29 04:40 - 2015-11-29 04:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
    2015-11-29 04:40 - 2015-11-29 04:40 - 00000000 ____D C:\Program Files\Realtek
    2015-11-29 04:40 - 2015-11-29 04:40 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
    2015-11-29 04:40 - 2015-11-29 04:40 - 00000000 ____D C:\Program Files\ATI Technologies
    2015-11-29 04:40 - 2015-11-29 04:40 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
    2015-11-29 04:40 - 2015-11-29 04:40 - 00000000 _____ C:\WINDOWS\ativpsrm.bin
    2015-11-29 04:39 - 2015-11-30 13:44 - 00396752 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2015-11-29 04:39 - 2015-11-29 04:39 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
    2015-11-29 04:14 - 2015-11-29 04:44 - 00009528 _____ C:\WINDOWS\diagwrn.xml
    2015-11-29 04:14 - 2015-11-29 04:44 - 00009528 _____ C:\WINDOWS\diagerr.xml
    2015-11-28 19:08 - 2015-11-28 19:08 - 00001068 _____ C:\Users\Shakree Elmi\Desktop\Anno 2205.lnk
    2015-11-28 19:01 - 2015-12-01 19:31 - 00000000 ____D C:\Users\Shakree Elmi\Documents\wmd_symbol_cache
    2015-11-28 19:01 - 2015-11-28 19:03 - 00000000 ____D C:\Users\Shakree Elmi\Documents\Project CARS
    2015-11-28 19:01 - 2015-11-28 19:01 - 00000000 ____D C:\ProgramData\Steam
    2015-11-28 17:02 - 2015-11-28 17:02 - 01813392 _____ (Microsoft Corporation) C:\WINDOWS\system32\WdfCoInstaller01011.dll
    2015-11-28 17:02 - 2015-11-28 17:02 - 00593624 _____ (Realtek Semiconductor Corporation) C:\WINDOWS\system32\Drivers\SETD45E.tmp
    2015-11-28 17:02 - 2015-11-28 17:02 - 00063840 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\XtuAcpiDriver.sys
    2015-11-28 17:02 - 2015-11-28 17:02 - 00050928 _____ C:\WINDOWS\rtl8723b_mp_chip_bt40_fw_asic_rom_patch_new.dll
    2015-11-28 17:02 - 2015-11-28 17:02 - 00050876 _____ C:\WINDOWS\rtl8723b_mp_chip_bt40_fw_asic_rom_patch_new_s1.dll
    2015-11-28 17:02 - 2015-11-28 17:02 - 00049088 _____ C:\WINDOWS\rtl8761a_mp_chip_bt40_fw_asic_rom_patch_8812ae_new.dll
    2015-11-28 17:02 - 2015-11-28 17:02 - 00048276 _____ C:\WINDOWS\rtl8761a_mp_chip_bt40_fw_asic_rom_patch_8192ee_new.dll
    2015-11-28 17:02 - 2015-11-28 17:02 - 00048192 _____ C:\WINDOWS\rtl8761a_mp_chip_bt40_fw_asic_rom_patch_8192eu_new.dll
    2015-11-28 17:02 - 2015-11-28 17:02 - 00045868 _____ C:\WINDOWS\rtl8761a_mp_chip_bt40_fw_asic_rom_patch_new.dll
    2015-11-28 17:02 - 2015-11-28 17:02 - 00040516 _____ C:\WINDOWS\rlt8723a_chip_bt40_fw_asic_rom_patch.dll
    2015-11-28 17:02 - 2015-11-28 17:02 - 00033620 _____ C:\WINDOWS\rtl8821a_mp_chip_bt40_fw_asic_rom_patch_new.dll
    2015-11-28 17:02 - 2015-08-29 06:58 - 00600832 _____ (Realtek Semiconductor Corporation) C:\WINDOWS\system32\Drivers\RtkBtfilter.sys
    2015-11-28 16:52 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_7.dll
    2015-11-28 16:52 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll
    2015-11-28 16:52 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_7.dll
    2015-11-28 16:52 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_7.dll
    2015-11-28 16:52 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll
    2015-11-28 16:52 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_5.dll
    2015-11-28 16:52 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll
    2015-11-28 16:52 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_43.dll
    2015-11-28 16:52 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_43.dll
    2015-11-28 16:52 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_43.dll
    2015-11-28 16:52 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_43.dll
    2015-11-28 16:52 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_43.dll
    2015-11-28 16:52 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_43.dll
     
  14. Shakree

    Shakree TS Rookie Topic Starter Posts: 18

    2015-11-28 16:52 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_43.dll
    2015-11-28 16:52 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll
    2015-11-28 16:52 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_43.dll
    2015-11-28 16:52 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_6.dll
    2015-11-28 16:52 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_6.dll
    2015-11-28 16:52 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_6.dll
    2015-11-28 16:52 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_6.dll
    2015-11-28 16:52 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_4.dll
    2015-11-28 16:52 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_4.dll
    2015-11-28 16:52 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_7.dll
    2015-11-28 16:52 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_7.dll
    2015-11-28 16:52 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_5.dll
    2015-11-28 16:52 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_5.dll
    2015-11-28 16:52 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_5.dll
    2015-11-28 16:52 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_5.dll
    2015-11-28 16:52 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_3.dll
    2015-11-28 16:52 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_3.dll
    2015-11-28 16:52 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_42.dll
    2015-11-28 16:52 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_42.dll
    2015-11-28 16:52 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_42.dll
    2015-11-28 16:52 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_42.dll
    2015-11-28 16:52 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_42.dll
    2015-11-28 16:52 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_42.dll
    2015-11-28 16:52 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll
    2015-11-28 16:52 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_42.dll
    2015-11-28 16:52 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_42.dll
    2015-11-28 16:52 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_42.dll
    2015-11-28 16:52 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_4.dll
    2015-11-28 16:52 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_4.dll
    2015-11-28 16:52 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_4.dll
    2015-11-28 16:52 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_4.dll
    2015-11-28 16:52 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_6.dll
    2015-11-28 16:52 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_6.dll
    2015-11-28 16:52 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_41.dll
    2015-11-28 16:52 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_41.dll
    2015-11-28 16:52 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_41.dll
    2015-11-28 16:52 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_41.dll
    2015-11-28 16:52 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_41.dll
    2015-11-28 16:52 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_41.dll
    2015-11-28 16:52 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_3.dll
    2015-11-28 16:52 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_3.dll
    2015-11-28 16:52 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_3.dll
    2015-11-28 16:52 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_3.dll
    2015-11-28 16:52 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_2.dll
    2015-11-28 16:52 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_2.dll
    2015-11-28 16:52 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_5.dll
    2015-11-28 16:52 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_5.dll
    2015-11-28 16:52 - 2008-10-10 04:52 - 05631312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_40.dll
    2015-11-28 16:52 - 2008-10-10 04:52 - 04379984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_40.dll
    2015-11-28 16:52 - 2008-10-10 04:52 - 02605920 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_40.dll
    2015-11-28 16:52 - 2008-10-10 04:52 - 02036576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_40.dll
    2015-11-28 16:52 - 2008-10-10 04:52 - 00519000 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_40.dll
    2015-11-28 16:52 - 2008-10-10 04:52 - 00452440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_40.dll
    2015-11-28 16:52 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_2.dll
    2015-11-28 16:52 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_2.dll
    2015-11-28 16:52 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_1.dll
    2015-11-28 16:52 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_1.dll
    2015-11-28 16:52 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_2.dll
    2015-11-28 16:52 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_2.dll
    2015-11-28 16:52 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll
    2015-11-28 16:52 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_39.dll
    2015-11-28 16:52 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll
    2015-11-28 16:52 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_39.dll
    2015-11-28 16:52 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll
    2015-11-28 16:52 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_39.dll
    2015-11-28 16:52 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_1.dll
    2015-11-28 16:52 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_1.dll
    2015-11-28 16:52 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_1.dll
    2015-11-28 16:52 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_1.dll
    2015-11-28 16:52 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_0.dll
    2015-11-28 16:52 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_0.dll
    2015-11-28 16:52 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_4.dll
    2015-11-28 16:52 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_4.dll
    2015-11-28 16:52 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_38.dll
    2015-11-28 16:52 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_38.dll
    2015-11-28 16:52 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_38.dll
    2015-11-28 16:52 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_38.dll
    2015-11-28 16:52 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_38.dll
    2015-11-28 16:52 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_38.dll
    2015-11-28 16:52 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_0.dll
    2015-11-28 16:52 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_0.dll
    2015-11-28 16:52 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_0.dll
    2015-11-28 16:52 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_0.dll
    2015-11-28 16:52 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_3.dll
    2015-11-28 16:52 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_3.dll
    2015-11-28 16:52 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_37.dll
    2015-11-28 16:52 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_37.dll
    2015-11-28 16:52 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_37.dll
    2015-11-28 16:52 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_37.dll
    2015-11-28 16:52 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_37.dll
    2015-11-28 16:52 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_37.dll
    2015-11-28 16:52 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_10.dll
    2015-11-28 16:52 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_10.dll
    2015-11-28 16:52 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_2.dll
    2015-11-28 16:52 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_2.dll
    2015-11-28 16:52 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_36.dll
    2015-11-28 16:52 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_36.dll
    2015-11-28 16:52 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_36.dll
    2015-11-28 16:52 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_36.dll
    2015-11-28 16:52 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_36.dll
    2015-11-28 16:52 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_36.dll
    2015-11-28 16:52 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_9.dll
    2015-11-28 16:52 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_9.dll
    2015-11-28 16:52 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_35.dll
    2015-11-28 16:52 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_35.dll
    2015-11-28 16:52 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_35.dll
    2015-11-28 16:52 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_35.dll
    2015-11-28 16:52 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_35.dll
    2015-11-28 16:52 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_35.dll
    2015-11-28 16:52 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_8.dll
    2015-11-28 16:52 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_8.dll
    2015-11-28 16:52 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_34.dll
    2015-11-28 16:52 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_34.dll
    2015-11-28 16:52 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_34.dll
    2015-11-28 16:52 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_34.dll
    2015-11-28 16:52 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_34.dll
    2015-11-28 16:52 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_34.dll
    2015-11-28 16:52 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_7.dll
    2015-11-28 16:52 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_7.dll
    2015-11-28 16:52 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_33.dll
    2015-11-28 16:52 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_33.dll
    2015-11-28 16:52 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_33.dll
    2015-11-28 16:52 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_33.dll
    2015-11-28 16:52 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_33.dll
    2015-11-28 16:52 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_33.dll
    2015-11-28 16:52 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_1.dll
    2015-11-28 16:52 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_1.dll
    2015-11-28 16:52 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_6.dll
    2015-11-28 16:52 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_6.dll
    2015-11-28 16:52 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_5.dll
    2015-11-28 16:52 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_5.dll
    2015-11-28 16:52 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_32.dll
    2015-11-28 16:52 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_32.dll
    2015-11-28 16:52 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10.dll
    2015-11-28 16:52 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10.dll
    2015-11-28 16:52 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_31.dll
    2015-11-28 16:52 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_31.dll
    2015-11-28 16:52 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_4.dll
    2015-11-28 16:52 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_4.dll
    2015-11-28 16:52 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_2.dll
    2015-11-28 16:52 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_3.dll
    2015-11-28 16:52 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_3.dll
    2015-11-28 16:52 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_2.dll
    2015-11-28 16:52 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_2.dll
    2015-11-28 16:52 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_2.dll
    2015-11-28 16:52 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_30.dll
    2015-11-28 16:52 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_30.dll
    2015-11-28 16:52 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_1.dll
    2015-11-28 16:52 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_1.dll
    2015-11-28 16:52 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_1.dll
    2015-11-28 16:52 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_1.dll
    2015-11-28 16:52 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_29.dll
    2015-11-28 16:52 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_29.dll
    2015-11-28 16:52 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_0.dll
    2015-11-28 16:52 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_0.dll
    2015-11-28 16:52 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_0.dll
    2015-11-28 16:52 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_0.dll
    2015-11-28 16:52 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_28.dll
    2015-11-28 16:52 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_28.dll
    2015-11-28 16:52 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_27.dll
    2015-11-28 16:52 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_27.dll
    2015-11-28 16:52 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_26.dll
    2015-11-28 16:52 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_26.dll
    2015-11-28 16:52 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_25.dll
    2015-11-28 16:52 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_25.dll
    2015-11-28 16:52 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_24.dll
    2015-11-28 16:52 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_24.dll
    2015-11-28 16:16 - 2015-11-29 04:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\by.xatab
    2015-11-28 16:16 - 2015-11-28 16:16 - 00000786 _____ C:\Users\Shakree Elmi\Desktop\x64-Project CARS.lnk
    2015-11-28 15:56 - 2015-11-28 15:56 - 00000000 ____D C:\ProgramData\DSDCS
    2015-11-28 15:55 - 2015-12-02 02:32 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\InputMapper
    2015-11-28 15:55 - 2015-11-29 04:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InputMapper
    2015-11-28 15:55 - 2015-11-28 15:55 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\DSDCS
    2015-11-28 15:55 - 2015-11-28 15:55 - 00000000 ____D C:\ProgramData\Caphyon
    2015-11-28 15:45 - 2015-12-02 13:09 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\DMCache
    2015-11-28 15:45 - 2015-12-01 21:28 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\IDM
    2015-11-28 15:45 - 2015-12-01 14:23 - 00000000 ____D C:\Users\Shakree Elmi\Downloads\Compressed
    2015-11-28 15:45 - 2015-11-28 15:45 - 00000000 ____D C:\Users\Shakree Elmi\Downloads\Video
    2015-11-28 15:45 - 2015-11-28 15:45 - 00000000 ____D C:\ProgramData\IDM
    2015-11-28 15:44 - 2015-11-29 04:42 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
    2015-11-28 15:44 - 2015-11-29 04:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
    2015-11-28 15:44 - 2015-11-28 15:45 - 00000000 ____D C:\Program Files (x86)\Internet Download Manager
    2015-11-28 15:17 - 2014-08-08 16:31 - 00027136 _____ (The OpenVPN Project) C:\WINDOWS\system32\Drivers\ptun0901.sys
    2015-11-28 15:17 - 2014-05-25 00:36 - 00015360 _____ C:\WINDOWS\system32\SppExtComObjHook.dll
    2015-11-28 15:17 - 2014-05-25 00:36 - 00004608 _____ C:\WINDOWS\system32\SppExtComObjPatcher.exe
    2015-11-28 15:13 - 2015-11-29 17:14 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\MSfree Inc
    2015-11-28 15:10 - 2015-11-28 15:10 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\PeerDistRepub
    2015-11-28 15:06 - 2015-11-29 04:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
    2015-11-28 15:06 - 2015-11-28 15:06 - 00002534 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
    2015-11-28 15:06 - 2015-11-28 15:06 - 00002498 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business 2016.lnk
    2015-11-28 15:06 - 2015-11-28 15:06 - 00002493 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
    2015-11-28 15:06 - 2015-11-28 15:06 - 00002492 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
    2015-11-28 15:06 - 2015-11-28 15:06 - 00002456 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk
    2015-11-28 15:06 - 2015-11-28 15:06 - 00002455 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
    2015-11-28 15:06 - 2015-11-28 15:06 - 00002449 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
    2015-11-28 15:06 - 2015-11-28 15:06 - 00002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
    2015-11-28 15:06 - 2015-11-28 15:06 - 00002435 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
    2015-11-28 15:04 - 2015-11-29 13:20 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
    2015-11-28 15:04 - 2015-11-28 15:04 - 00000000 ____D C:\Program Files\Microsoft Office 15
    2015-11-28 12:27 - 2015-11-28 12:27 - 633383604 _____ C:\WINDOWS\MEMORY.DMP
    2015-11-28 02:58 - 2015-11-28 02:58 - 00000000 ____D C:\Users\Shakree Elmi\Documents\Anno 2205
    2015-11-28 02:43 - 2015-11-28 02:43 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\WinRAR
    2015-11-28 02:18 - 2015-11-29 04:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics
    2015-11-28 02:18 - 2015-11-28 02:18 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\Anno 2205
    2015-11-28 02:18 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_3.dll
    2015-11-28 02:18 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_3.dll
    2015-11-28 01:42 - 2015-11-28 01:42 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\ATI
    2015-11-28 01:42 - 2015-11-28 01:42 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\ATI
    2015-11-28 01:42 - 2015-11-28 01:42 - 00000000 ____D C:\ProgramData\ATI
    2015-11-28 01:23 - 2015-11-28 01:23 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\Macromedia
    2015-11-28 01:19 - 2015-11-29 04:42 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
    2015-11-28 01:19 - 2015-11-29 04:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
    2015-11-28 01:19 - 2015-11-28 01:19 - 00000000 ____D C:\Program Files\WinRAR
    2015-11-28 01:14 - 2015-11-28 01:14 - 00047008 _____ C:\WINDOWS\system32\Drivers\ISCTD64.sys
    2015-11-28 01:11 - 2015-11-29 04:40 - 00000000 ____D C:\AMD
    2015-11-28 01:11 - 2015-11-28 01:11 - 47794160 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\amdocl64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 39712768 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\amdocl.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 30776304 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atio6axx.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 27544560 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\amdocl12cl64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 25320432 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atioglxx.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 22327280 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\amdocl12cl.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 21648880 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Drivers\atikmdag.sys
    2015-11-28 01:11 - 2015-11-28 01:11 - 15725552 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\aticaldd64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 14310896 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\aticaldd.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 12088000 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atidxx64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 10211008 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atidxx32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 09355016 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdxc64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 08982440 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiumd6a.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 08864920 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiumd64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 08009360 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiumdva.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 07683096 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdxc32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 07482552 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiumdag.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 06686192 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmantle64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 05216240 _____ (Advanced Micro Devices, Inc. )
     
  15. Shakree

    Shakree TS Rookie Topic Starter Posts: 18

    C:\WINDOWS\SysWOW64\amdmantle32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 03471376 _____ C:\WINDOWS\SysWOW64\atiumdva.cap
    2015-11-28 01:11 - 2015-11-28 01:11 - 03437632 _____ C:\WINDOWS\system32\atiumd6a.cap
    2015-11-28 01:11 - 2015-11-28 01:11 - 01479808 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\aticfx64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 01256432 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiadlxx.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 01223552 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\aticfx32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 01196032 _____ C:\WINDOWS\system32\amdocl_as64.exe
    2015-11-28 01:11 - 2015-11-28 01:11 - 01070592 _____ C:\WINDOWS\system32\amdocl_ld64.exe
    2015-11-28 01:11 - 2015-11-28 01:11 - 01004032 _____ C:\WINDOWS\SysWOW64\amdocl_as32.exe
    2015-11-28 01:11 - 2015-11-28 01:11 - 00935408 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxy.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00935408 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxx.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00874480 _____ (AMD) C:\WINDOWS\system32\coinst_15.20.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00833800 _____ C:\WINDOWS\system32\amdicdxx.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00807424 _____ C:\WINDOWS\SysWOW64\amdocl_ld32.exe
    2015-11-28 01:11 - 2015-11-28 01:11 - 00737410 _____ C:\WINDOWS\system32\atiicdxx.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00683504 _____ (AMD) C:\WINDOWS\system32\atieclxx.exe
    2015-11-28 01:11 - 2015-11-28 01:11 - 00674288 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Drivers\atikmpag.sys
    2015-11-28 01:11 - 2015-11-28 01:11 - 00662392 _____ C:\WINDOWS\SysWOW64\atiapfxx.blb
    2015-11-28 01:11 - 2015-11-28 01:11 - 00662392 _____ C:\WINDOWS\system32\atiapfxx.blb
    2015-11-28 01:11 - 2015-11-28 01:11 - 00631280 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdlvr64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00524272 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdlvr32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00471312 _____ C:\WINDOWS\system32\amdmiracast.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00451056 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atidemgy.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00375792 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiapfxx.exe
    2015-11-28 01:11 - 2015-11-28 01:11 - 00341488 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ATIODE.exe
    2015-11-28 01:11 - 2015-11-28 01:11 - 00322868 _____ C:\WINDOWS\system32\ativvaxy_vi.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00321200 _____ C:\WINDOWS\system32\ativvaxy_vi_nd.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00255808 _____ C:\WINDOWS\system32\ativvaxy_cz_nd.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00255472 _____ (AMD) C:\WINDOWS\system32\atiesrxx.exe
    2015-11-28 01:11 - 2015-11-28 01:11 - 00250884 _____ C:\WINDOWS\system32\ativvaxy_FJ.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00249088 _____ C:\WINDOWS\system32\ativvaxy_FJ_nd.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00243696 _____ C:\WINDOWS\system32\clinfo.exe
    2015-11-28 01:11 - 2015-11-28 01:11 - 00234420 _____ C:\WINDOWS\system32\ativvaxy_cik.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00232752 _____ C:\WINDOWS\system32\ativvaxy_cik_nd.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00213488 _____ C:\WINDOWS\system32\amdgfxinfo64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00204952 _____ C:\WINDOWS\SysWOW64\ativvsvl.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00204952 _____ C:\WINDOWS\system32\ativvsvl.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00199664 _____ (AMD) C:\WINDOWS\system32\atitmm64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00198640 _____ C:\WINDOWS\SysWOW64\amdgfxinfo32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00177344 _____ C:\WINDOWS\system32\ativce03.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00175648 _____ C:\WINDOWS\system32\amde31a.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00168944 _____ C:\WINDOWS\system32\atieah64.exe
    2015-11-28 01:11 - 2015-11-28 01:11 - 00165360 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6txx.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00162232 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiuxp64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00157144 _____ C:\WINDOWS\SysWOW64\ativvsva.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00157144 _____ C:\WINDOWS\system32\ativvsva.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00152560 _____ C:\WINDOWS\SysWOW64\atieah32.exe
    2015-11-28 01:11 - 2015-11-28 01:11 - 00151936 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdhcp64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00150512 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atigktxx.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00143344 _____ C:\WINDOWS\system32\amdhdl64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00143048 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiuxpag.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00140240 _____ C:\WINDOWS\system32\samu_krnl_ci.sbin
    2015-11-28 01:11 - 2015-11-28 01:11 - 00138832 _____ C:\WINDOWS\system32\samu_krnl_isv_ci.sbin
    2015-11-28 01:11 - 2015-11-28 01:11 - 00138376 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdhcp32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00136176 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantle64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00132080 _____ C:\WINDOWS\SysWOW64\amdhdl32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00130072 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiu9p64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00122352 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantle32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00117600 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdave64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00112360 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiu9pag.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00111600 _____ C:\WINDOWS\system32\hsa-thunk64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00111088 _____ C:\WINDOWS\SysWOW64\hsa-thunk.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00110312 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdave32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00103408 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantleaxl64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00100816 _____ C:\WINDOWS\system32\ativce02.dat
    2015-11-28 01:11 - 2015-11-28 01:11 - 00097776 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atisamu64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00096752 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantleaxl32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00089584 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atisamu32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00088000 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdpcom64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00087992 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atimpc64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00083952 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6pxx.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00081168 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdpcom32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00081160 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atimpc32.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00078320 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiglpxx.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00078320 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiglpxx.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00073712 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00071152 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\aticalrt64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00068080 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00064496 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\aticalcl64.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00060912 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\aticalrt.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00059888 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ATIODCLI.exe
    2015-11-28 01:11 - 2015-11-28 01:11 - 00059376 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmmcl6.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00057840 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\aticalcl.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00052208 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Drivers\ati2erec.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00048112 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdmmcl.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00047664 _____ C:\WINDOWS\system32\kapp_ci.sbin
    2015-11-28 01:11 - 2015-11-28 01:11 - 00043536 _____ C:\WINDOWS\system32\kapp_si.sbin
    2015-11-28 01:11 - 2015-11-28 01:11 - 00038384 _____ (AMD) C:\WINDOWS\system32\atimuixx.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00012784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\detoured.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00012784 _____ (Microsoft Corporation) C:\WINDOWS\system32\detoured.dll
    2015-11-28 01:11 - 2015-11-28 01:11 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\NetworkTiles
    2015-11-28 01:03 - 2015-11-28 01:03 - 00002239 _____ C:\Users\Shakree Elmi\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
    2015-11-28 01:02 - 2015-12-02 13:10 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\uTorrent
    2015-11-28 01:02 - 2015-11-28 01:02 - 00001047 _____ C:\Users\Shakree Elmi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optional Features.lnk
    2015-11-27 13:00 - 2015-11-27 13:00 - 00193336 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\TeeDriverW8x64.sys
    2015-11-27 13:00 - 2015-11-27 13:00 - 00103424 _____ (Advanced Micro Devices) C:\WINDOWS\system32\DelayAPO.dll
    2015-11-27 13:00 - 2015-11-27 13:00 - 00102912 _____ (Advanced Micro Devices) C:\WINDOWS\system32\Drivers\AtihdWT6.sys
    2015-11-27 12:55 - 2015-11-30 23:37 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\ElevatedDiagnostics
    2015-11-27 12:53 - 2015-12-02 13:08 - 00000938 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
    2015-11-27 12:53 - 2015-12-02 12:52 - 00000942 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
    2015-11-27 12:53 - 2015-11-29 04:44 - 00003454 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
    2015-11-27 12:53 - 2015-11-29 04:44 - 00003230 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
    2015-11-27 12:53 - 2015-11-29 04:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
    2015-11-27 12:53 - 2015-11-27 12:53 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\Google
    2015-11-27 12:53 - 2015-11-27 12:53 - 00000000 ____D C:\Program Files (x86)\Google
    2015-11-27 12:52 - 2015-11-27 12:53 - 00000000 ___HD C:\Program Files (x86)\Temp
    2015-11-27 12:52 - 2015-06-15 13:41 - 02808859 _____ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT
    2015-11-27 12:52 - 2015-06-15 12:58 - 04493528 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys
    2015-11-27 12:52 - 2015-06-15 09:39 - 01748184 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll
    2015-11-27 12:52 - 2015-06-11 11:40 - 03157796 _____ C:\WINDOWS\system32\Drivers\rtkSSTsetting.dat
    2015-11-27 12:52 - 2015-06-10 05:20 - 03129672 _____ (Intel Corporation) C:\WINDOWS\system32\IntelSSTAPO.dll
    2015-11-27 12:52 - 2015-06-10 05:20 - 00728392 _____ (Intel Corporation) C:\WINDOWS\system32\IntelSstCApoPropPage.dll
    2015-11-27 12:52 - 2015-06-09 03:17 - 05708736 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICV2apo.dll
    2015-11-27 12:52 - 2015-06-05 05:45 - 02848472 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll
    2015-11-27 12:52 - 2015-06-05 05:45 - 02531544 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RltkAPO.dll
    2015-11-27 12:52 - 2015-06-02 11:25 - 01576976 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CX64APO.dll
    2015-11-27 12:52 - 2015-05-27 10:51 - 02461016 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv211.dll
    2015-11-27 12:52 - 2015-05-27 10:51 - 02393432 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv201.dll
    2015-11-27 12:52 - 2015-05-27 10:51 - 00944984 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOProp.dll
    2015-11-27 12:52 - 2015-05-27 10:51 - 00349528 _____ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2API.dll
    2015-11-27 12:52 - 2015-05-27 09:38 - 02825944 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\RtlExUpd.dll
    2015-11-27 12:52 - 2015-05-26 03:59 - 00166616 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll
    2015-11-27 12:52 - 2015-05-25 07:18 - 03195416 _____ (Fortemedia Corporation) C:\WINDOWS\system32\FMAPO64.dll
    2015-11-27 12:52 - 2015-05-20 08:14 - 03234520 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll
    2015-11-27 12:52 - 2015-05-18 06:47 - 02702040 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl
    2015-11-27 12:52 - 2015-05-15 11:27 - 02918104 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll
    2015-11-27 12:52 - 2015-05-15 08:32 - 01316056 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll
    2015-11-27 12:52 - 2015-05-11 10:53 - 12996528 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVoiceAPO3064.dll
    2015-11-27 12:52 - 2015-05-11 05:08 - 01374640 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO6064.dll
    2015-11-27 12:52 - 2015-05-11 05:08 - 01192368 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO5064.dll
    2015-11-27 12:52 - 2015-05-11 05:08 - 01145264 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO4064.dll
    2015-11-27 12:52 - 2015-05-11 05:08 - 00980400 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVoiceAPO2064.dll
    2015-11-27 12:52 - 2015-04-27 08:09 - 00328816 _____ (ICEpower a/s) C:\WINDOWS\system32\ICEsoundAPO64.dll
    2015-11-27 12:52 - 2015-04-23 21:42 - 00858256 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDRA64.dll
    2015-11-27 12:52 - 2015-04-23 21:42 - 00684176 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SECOMN64.dll
    2015-11-27 12:52 - 2015-04-23 21:42 - 00435856 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEAPO64.dll
    2015-11-27 12:52 - 2015-04-23 21:41 - 00555664 _____ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SECOMN32.DLL
    2015-11-27 12:52 - 2015-04-13 08:25 - 03262184 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE2.dll
    2015-11-27 12:52 - 2015-02-05 09:48 - 12834736 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVoiceAPO4064.dll
    2015-11-27 12:52 - 2015-02-05 09:48 - 02789808 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO7064.dll
    2015-11-27 12:52 - 2015-02-03 16:38 - 01413776 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRRPTR64.dll
    2015-11-27 12:52 - 2015-02-03 16:38 - 00454288 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRAPO64.dll
    2015-11-27 12:52 - 2015-02-03 16:38 - 00369296 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM64.dll
    2015-11-27 12:52 - 2015-02-03 16:38 - 00329360 _____ (Synopsys, Inc.) C:\WINDOWS\SysWOW64\SRCOM.dll
    2015-11-27 12:52 - 2015-02-03 16:38 - 00329360 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM.dll
    2015-11-27 12:52 - 2015-01-23 10:16 - 00213432 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tossaemaxapo64.dll
    2015-11-27 12:52 - 2015-01-19 10:10 - 72113152 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoRes64.dat
    2015-11-27 12:52 - 2014-12-11 00:10 - 01104040 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\slcnt64.dll
    2015-11-27 12:52 - 2014-12-11 00:10 - 00943784 _____ (DTS, Inc.) C:\WINDOWS\system32\sl3apo64.dll
    2015-11-27 12:52 - 2014-12-11 00:10 - 00734376 _____ (DTS, Inc.) C:\WINDOWS\system32\sltech64.dll
    2015-11-27 12:52 - 2014-12-11 00:10 - 00250536 _____ (TODO: <Company name>) C:\WINDOWS\system32\slprp64.dll
    2015-11-27 12:52 - 2014-11-11 05:44 - 00631000 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll
    2015-11-27 12:52 - 2014-11-04 05:42 - 06242576 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64AF3.dll
    2015-11-27 12:52 - 2014-11-04 05:42 - 01933584 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64AF3.dll
    2015-11-27 12:52 - 2014-11-04 05:42 - 00336144 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64AF3.dll
    2015-11-27 12:52 - 2014-11-04 05:42 - 00284944 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64F3.dll
    2015-11-27 12:52 - 2014-10-24 02:12 - 05234952 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICAPOlfx.dll
    2015-11-27 12:52 - 2014-10-24 02:12 - 00995120 _____ (Nahimic Inc) C:\WINDOWS\system32\NahimicAPONSControl.dll
    2015-11-27 12:52 - 2014-09-24 03:31 - 07087448 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64A.dll
    2015-11-27 12:52 - 2014-09-24 03:31 - 01939800 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64A.dll
    2015-11-27 12:52 - 2014-09-24 03:31 - 00315736 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64A.dll
    2015-11-27 12:52 - 2014-09-24 03:31 - 00261464 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64.dll
    2015-11-27 12:52 - 2014-08-14 11:16 - 05804772 _____ C:\WINDOWS\system32\Drivers\rtvienna.dat
    2015-11-27 12:52 - 2014-06-17 11:17 - 00856992 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo264.dll
    2015-11-27 12:52 - 2014-06-09 02:59 - 00560328 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAC64.dll
    2015-11-27 12:52 - 2014-05-22 08:24 - 00096568 _____ C:\WINDOWS\system32\audioLibVc.dll
    2015-11-27 12:52 - 2014-04-10 04:19 - 02101848 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\WavesGUILib64.dll
    2015-11-27 12:52 - 2014-04-10 04:19 - 02041432 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioEQ64.dll
    2015-11-27 12:52 - 2014-02-27 12:02 - 02162992 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE.dll
    2015-11-27 12:52 - 2014-01-31 09:27 - 01313904 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxSpeechAPO64.dll
    2015-11-27 12:52 - 2013-10-11 04:47 - 00113576 _____ (Real Sound Lab SIA) C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll
    2015-11-27 12:52 - 2013-10-11 03:31 - 00947760 _____ (Sony Corporation) C:\WINDOWS\system32\SFSS_APO.dll
    2015-11-27 12:52 - 2013-10-06 16:26 - 00501184 _____ (DTS) C:\WINDOWS\system32\DTSU2PLFX64.dll
    2015-11-27 12:52 - 2013-10-06 16:26 - 00487360 _____ (DTS) C:\WINDOWS\system32\DTSU2PGFX64.dll
    2015-11-27 12:52 - 2013-10-06 16:26 - 00415680 _____ (DTS) C:\WINDOWS\system32\DTSU2PREC64.dll
    2015-11-27 12:52 - 2013-08-14 07:36 - 00662784 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxVolumeSDAPO.dll
    2015-11-27 12:52 - 2013-08-14 07:35 - 00663296 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO30.dll
    2015-11-27 12:52 - 2013-07-23 07:39 - 14048512 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioRealtek64.dll
    2015-11-27 12:52 - 2013-07-23 07:39 - 00922880 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPOShell64.dll
    2015-11-27 12:52 - 2013-06-25 04:47 - 00871856 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tossaeapo64.dll
    2015-11-27 12:52 - 2013-06-25 04:47 - 00162224 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\toseaeapo64.dll
    2015-11-27 12:52 - 2013-06-25 04:46 - 00582056 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tosasfapo64.dll
    2015-11-27 12:52 - 2013-06-21 03:01 - 00109848 _____ C:\WINDOWS\system32\AcpiServiceVnA64.dll
    2015-11-27 12:52 - 2013-04-03 06:13 - 00906800 _____ (Sony Corporation) C:\WINDOWS\system32\MISS_APO.dll
    2015-11-27 12:52 - 2012-08-31 11:18 - 07164176 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEP64A.dll
    2015-11-27 12:52 - 2012-08-31 11:17 - 00434960 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EED64A.dll
    2015-11-27 12:52 - 2012-08-31 11:17 - 00141584 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEL64A.dll
    2015-11-27 12:52 - 2012-08-31 11:17 - 00124176 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEA64A.dll
    2015-11-27 12:52 - 2012-08-31 11:17 - 00075024 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEG64A.dll
    2015-11-27 12:52 - 2012-03-08 03:47 - 00108640 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAR64.dll
    2015-11-27 12:52 - 2012-01-10 02:20 - 00065944 _____ (TOSHIBA CORPORATION.) C:\WINDOWS\system32\tepeqapo64.dll
    2015-11-27 12:52 - 2011-12-20 07:32 - 00331880 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll
    2015-11-27 12:52 - 2011-11-22 08:28 - 00014952 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll
    2015-11-27 12:52 - 2011-09-02 06:21 - 00221024 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFNHK64.dll
    2015-11-27 12:52 - 2011-09-02 06:21 - 00081248 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFCOM64.dll
    2015-11-27 12:52 - 2011-09-02 06:21 - 00078688 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFAPO64.dll
    2015-11-27 12:52 - 2011-08-23 09:00 - 00603984 _____ (Knowles Acoustics ) C:\WINDOWS\system32\KAAPORT64.dll
    2015-11-27 12:52 - 2011-05-31 01:42 - 01756264 _____ (DTS) C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll
    2015-11-27 12:52 - 2011-05-31 01:42 - 01568360 _____ (DTS) C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll
    2015-11-27 12:52 - 2011-05-31 01:42 - 01486952 _____ (DTS) C:\WINDOWS\system32\DTSBoostDLL64.dll
    2015-11-27 12:52 - 2011-05-31 01:42 - 00728680 _____ (DTS) C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll
    2015-11-27 12:52 - 2011-05-31 01:42 - 00712296 _____ (DTS) C:\WINDOWS\system32\DTSSymmetryDLL64.dll
    2015-11-27 12:52 - 2011-05-31 01:42 - 00693352 _____ (DTS) C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll
    2015-11-27 12:52 - 2011-05-31 01:42 - 00491112 _____ (DTS) C:\WINDOWS\system32\DTSNeoPCDLL64.dll
    2015-11-27 12:52 - 2011-05-31 01:42 - 00432744 _____ (DTS) C:\WINDOWS\system32\DTSLimiterDLL64.dll
    2015-11-27 12:52 - 2011-05-31 01:42 - 00428648 _____ (DTS) C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll
    2015-11-27 12:52 - 2011-05-31 01:42 - 00242792 _____ (DTS) C:\WINDOWS\system32\DTSLFXAPO64.dll
    2015-11-27 12:52 - 2011-05-31 01:42 - 00242792 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPO64.dll
    2015-11-27 12:52 - 2011-05-31 01:42 - 00241768 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPONS64.dll
    2015-11-27 12:52 - 2011-03-17 04:17 - 01361336 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tosade.dll
    2015-11-27 12:52 - 2011-03-07 09:11 - 00148416 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo.dll
    2015-11-27 12:52 - 2010-11-07 23:31 - 00375128 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEP64A.dll
    2015-11-27 12:52 - 2010-11-07 23:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DHT64.dll
    2015-11-27 12:52 - 2010-11-07 23:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DAA64.dll
    2015-11-27 12:52 - 2010-11-07 23:31 - 00204120 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEED64A.dll
    2015-11-27 12:52 - 2010-11-07 23:31 - 00101208 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEL64A.dll
    2015-11-27 12:52 - 2010-11-07 23:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEG64A.dll
    2015-11-27 12:52 - 2010-09-27 01:34 - 00318808 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO20.dll
    2015-11-27 12:52 - 2010-07-22 08:48 - 00074064 _____ (Virage Logic Corporation / Sonic Focus) C:\WINDOWS\SysWOW64\SFCOM.dll
    2015-11-27 12:52 - 2009-11-24 01:55 - 00518896 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSX64.dll
    2015-11-27 12:52 - 2009-11-24 01:55 - 00211184 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSH64.dll
    2015-11-27 12:52 - 2009-11-24 01:55 - 00198896 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSHP64.dll
    2015-11-27 12:52 - 2009-11-24 01:55 - 00155888 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSWOW64.dll
    2015-11-27 12:42 - 2015-12-01 14:24 - 00000000 ____D C:\Program Files (x86)\MSI
    2015-11-27 12:42 - 2015-11-27 12:52 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
    2015-11-27 12:42 - 2015-11-27 12:52 - 00000000 ____D C:\Program Files (x86)\Realtek
    2015-11-27 12:42 - 2015-11-27 12:42 - 00000000 ____D C:\Program Files\Intel
    2015-11-27 12:42 - 2015-05-29 02:14 - 00886528 _____ (Realtek ) C:\WINDOWS\system32\Drivers\rt640x64.sys
    2015-11-27 12:42 - 2015-05-29 02:14 - 00082544 _____ (Realtek Semiconductor Corporation) C:\WINDOWS\system32\RtNicProp64.dll
    2015-11-27 12:39 - 2015-11-27 12:39 - 00016148 _____ C:\WINDOWS\system32\DESKTOP-P1HFESU_Shakree Elmi_HistoryPrediction.bin
    2015-11-27 12:11 - 2015-11-28 01:12 - 00000000 ____D C:\Program Files (x86)\AMD
    2015-11-27 11:34 - 2015-11-29 11:56 - 00002355 _____ C:\Users\Shakree Elmi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
    2015-11-27 11:34 - 2015-11-29 11:56 - 00000000 ___RD C:\Users\Shakree Elmi\OneDrive
    2015-11-27 11:34 - 2015-11-27 11:34 - 00000000 ____D C:\WINDOWS\CSC
    2015-11-27 11:33 - 2015-12-01 22:08 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Roaming\Adobe
    2015-11-27 11:33 - 2015-11-29 12:12 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\Packages
    2015-11-27 11:33 - 2015-11-27 11:33 - 00016148 _____ C:\WINDOWS\system32\DESKTOP-P1HFESU_defaultuser0_HistoryPrediction.bin
    2015-11-27 11:33 - 2015-11-27 11:33 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\VirtualStore
    2015-11-27 11:33 - 2015-11-27 11:33 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\TileDataLayer
    2015-11-27 11:33 - 2015-11-27 11:33 - 00000000 ____D C:\Users\Shakree Elmi\AppData\Local\Publishers

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-12-02 13:07 - 2015-10-30 06:28 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
    2015-12-02 13:07 - 2015-10-30 06:28 - 00000000 ____D C:\Windows
    2015-12-02 13:05 - 2015-10-30 07:21 - 00000000 ____D C:\WINDOWS\INF
    2015-12-02 12:59 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\system32\NDF
    2015-12-02 03:52 - 2015-09-21 12:21 - 05636772 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2015-12-01 14:42 - 2015-10-30 07:24 - 00000000 ___HD C:\Program Files\WindowsApps
    2015-12-01 14:42 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\AppReadiness
    2015-11-30 22:14 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports
    2015-11-30 03:47 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\appcompat
    2015-11-30 01:07 - 2015-10-30 07:11 - 00000000 ____D C:\WINDOWS\CbsTemp
    2015-11-29 13:20 - 2015-10-30 07:24 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2015-11-29 12:38 - 2015-10-30 07:24 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
    2015-11-29 12:37 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
    2015-11-29 12:37 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\system32\oobe
    2015-11-29 12:37 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
    2015-11-29 12:37 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\Provisioning
    2015-11-29 12:37 - 2015-10-30 06:28 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
    2015-11-29 12:37 - 2015-10-30 06:28 - 00000000 ____D C:\WINDOWS\system32\Dism
    2015-11-29 12:28 - 2015-10-30 09:07 - 00000000 ____D C:\Program Files\Windows Journal
    2015-11-29 12:28 - 2015-10-30 09:02 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm
    2015-11-29 12:28 - 2015-10-30 09:02 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
    2015-11-29 12:28 - 2015-10-30 09:02 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr
    2015-11-29 12:28 - 2015-10-30 09:02 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
    2015-11-29 12:28 - 2015-10-30 09:02 - 00000000 ____D C:\WINDOWS\system32\winrm
    2015-11-29 12:28 - 2015-10-30 09:02 - 00000000 ____D C:\WINDOWS\system32\WCN
    2015-11-29 12:28 - 2015-10-30 09:02 - 00000000 ____D C:\WINDOWS\system32\slmgr
    2015-11-29 12:28 - 2015-10-30 09:02 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ___SD C:\WINDOWS\system32\F12
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ___SD C:\WINDOWS\system32\dsc
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Com
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\system32\MUI
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\system32\migwiz
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\system32\Com
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\IME
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\Help
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files\Windows Photo Viewer
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files\Windows Defender
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files\Common Files\System
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
    2015-11-29 12:28 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files (x86)\Windows Defender
    2015-11-29 12:28 - 2015-10-30 06:28 - 00000000 ____D C:\WINDOWS\servicing
    2015-11-29 12:11 - 2015-10-30 07:24 - 00000000 ___RD C:\WINDOWS\DevicesFlow
    2015-11-29 11:55 - 2015-10-30 07:24 - 00000000 ___RD C:\WINDOWS\PrintDialog
    2015-11-29 11:55 - 2015-10-30 07:24 - 00000000 ___RD C:\WINDOWS\MiracastView
    2015-11-29 11:55 - 2015-10-30 07:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
    2015-11-29 11:55 - 2015-09-21 12:17 - 00000000 __RHD C:\Users\Public\AccountPictures
    2015-11-29 04:44 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
    2015-11-29 04:44 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\Registration
    2015-11-29 04:44 - 2015-10-30 06:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
    2015-11-29 04:43 - 2015-10-30 07:24 - 00000000 __RHD C:\Users\Public\Libraries
    2015-11-29 04:42 - 2015-07-10 09:05 - 00000000 ____D C:\Users\Default.migrated
    2015-11-29 04:41 - 2015-10-30 09:03 - 00000000 ____D C:\WINDOWS\OCR
    2015-11-29 04:41 - 2015-10-30 07:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
    2015-11-29 04:41 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\system32\spool
    2015-11-29 04:41 - 2015-10-30 07:24 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
    2015-11-29 04:41 - 2015-10-30 07:24 - 00000000 ____D C:\ProgramData\USOPrivate
    2015-11-29 04:41 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
    2015-11-29 04:40 - 2015-10-30 06:28 - 00000000 ____D C:\WINDOWS\system32\Sysprep
    2015-11-29 04:39 - 2015-10-30 09:14 - 00000000 ____D C:\WINDOWS\ServiceProfiles
    2015-11-29 04:14 - 2015-10-30 09:42 - 00000000 ___HD C:\$WINDOWS.~BT
    2015-11-28 01:31 - 2015-09-21 12:31 - 00000000 ____D C:\WINDOWS\system32\MRT
    2015-11-03 00:12 - 2015-10-30 07:26 - 00810488 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
    2015-11-03 00:12 - 2015-10-30 07:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl

    ==================== Files in the root of some directories =======

    2015-11-30 01:01 - 2015-11-30 01:01 - 0000057 _____ () C:\ProgramData\Ament.ini
    2015-11-29 04:40 - 2015-11-29 04:40 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

    Some files in TEMP:
    ====================
    C:\Users\Shakree Elmi\AppData\Local\Temp\dllnt_dump.dll
    C:\Users\Shakree Elmi\AppData\Local\Temp\sqlite3.dll


    ==================== Bamital & volsnap =================

    (There is no automatic fix for files that do not pass verification.)

    C:\WINDOWS\system32\winlogon.exe => File is digitally signed
    C:\WINDOWS\system32\wininit.exe => File is digitally signed
    C:\WINDOWS\explorer.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
    C:\WINDOWS\system32\svchost.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
    C:\WINDOWS\system32\services.exe => File is digitally signed
    C:\WINDOWS\system32\User32.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
    C:\WINDOWS\system32\userinit.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
    C:\WINDOWS\system32\rpcss.dll => File is digitally signed
    C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
    C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2015-11-29 04:39

    ==================== End of FRST.txt ============================
     
  16. Shakree

    Shakree TS Rookie Topic Starter Posts: 18

    Additional scan result of Farbar Recovery Scan Tool (x64) Version:01-12-2015
    Ran by Shakree Elmi (2015-12-02 13:10:33)
    Running from C:\Users\Shakree Elmi\Desktop
    Windows 10 Pro (X64) (2015-11-29 04:45:00)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-1966762071-576509629-4117557406-500 - Administrator - Disabled)
    DefaultAccount (S-1-5-21-1966762071-576509629-4117557406-503 - Limited - Disabled)
    Guest (S-1-5-21-1966762071-576509629-4117557406-501 - Limited - Disabled)
    Shakree Elmi (S-1-5-21-1966762071-576509629-4117557406-1002 - Administrator - Enabled) => C:\Users\Shakree Elmi

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    µTorrent (HKU\S-1-5-21-1966762071-576509629-4117557406-1002\...\uTorrent) (Version: 3.4.5.41372 - BitTorrent Inc.)
    Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.009.20079 - Adobe Systems Incorporated)
    AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD)
    AMD Catalyst Install Manager (HKLM\...\{8F62BC70-DBB4-802D-1E1E-13630D9BA4D2}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
    Anno 2205 (HKLM-x32\...\Anno 2205_R.G. Mechanics_is1) (Version: - R.G. Mechanics, ProZorg_tm)
    Fallout 4 v.1.1.30 (HKLM-x32\...\Fallout 4_is1) (Version: - )
    Far Cry 4 (HKLM-x32\...\Far Cry 4_is1) (Version: - )
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 46.0.2490.86 - Google Inc.)
    Google Update Helper (x32 Version: 1.3.21.115 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
    HP Deskjet 2540 series Basic Device Software (HKLM\...\{6A79CD11-0C1C-4E24-A8C6-46A02F680346}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
    HP Deskjet 2540 series Help (HKLM-x32\...\{4539575D-C09D-4E71-B207-0F2D6BD74DA2}) (Version: 30.0.0 - Hewlett Packard)
    HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
    HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
    InputMapper (HKLM-x32\...\{1A44056A-C7D8-4561-BC43-A0AA7D7AAA64}) (Version: 1.5.31.0 - DSDCS)
    Intel(R) Chipset Device Software (x32 Version: 10.1.1.9 - Intel(R) Corporation) Hidden
    Internet Download Manager (HKLM-x32\...\Internet Download Manager) (Version: - Tonec Inc.)
    Kodi (HKU\S-1-5-21-1966762071-576509629-4117557406-1002\...\Kodi) (Version: - XBMC-Foundation)
    Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
    MATLAB Production Server R2015a (HKLM\...\MATLAB Production Server R2015a) (Version: 2.1 - MathWorks)
    Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 16.0.6001.1038 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
    MSI Live Update 6 (HKLM-x32\...\{4F46CF54-47D2-41F4-B230-B0954C544420}}_is1) (Version: 6.1.009 - MSI)
    Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.6001.1038 - Microsoft Corporation) Hidden
    Office 16 Click-to-Run Licensing Component (Version: 16.0.6001.1038 - Microsoft Corporation) Hidden
    Office 16 Click-to-Run Localization Component (x32 Version: 16.0.6001.1038 - Microsoft Corporation) Hidden
    Product Improvement Study for HP Deskjet 2540 series (HKLM\...\{DF34643B-A745-430C-B27B-A48F853C81E4}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
    Project CARS v.6.0 (HKLM-x32\...\Project CARS_is1) (Version: - )
    Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.1.505.2015 - Realtek)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7534 - Realtek Semiconductor Corp.)
    The Witcher 3: Wild Hunt (HKLM-x32\...\The Witcher 3: Wild Hunt_is1) (Version: - )
    VGA Boost (HKLM-x32\...\{809ACFAE-9A4D-4C60-9223-D8B615CD8CBA}}_is1) (Version: 1.0.0.8 - MSI)
    Windows 10 KMS Activator Ultimate 2015 v1.4 (HKLM\...\Windows 10 KMS Activator Ultimate 2015 v1.4_is1) (Version: v1.4 - )
    WinRAR 5.30 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.30.0 - win.rar GmbH)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-1966762071-576509629-4117557406-1002_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Shakree Elmi\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\FileCoAuth.exe (Microsoft Corporation)

    ==================== Restore Points =========================

    29-11-2015 12:23:42 Windows Update
    30-11-2015 13:30:46 Installed Microsoft Visual C++ 2005 Redistributable (x64)
    02-12-2015 03:28:15 JRT Pre-Junkware Removal

    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2015-07-10 11:04 - 2015-07-10 11:02 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {1914852A-D9A1-4C69-AADA-53CD0C1AA4F6} - System32\Tasks\HPCustParticipation HP Deskjet 2540 series => C:\Program Files\HP\HP Deskjet 2540 series\Bin\HPCustPartic.exe [2014-03-06] (Hewlett-Packard Co.)
    Task: {1BC7D3A1-8054-4A8C-BA8E-77FAD6A620F6} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-10-27] (Microsoft Corporation)
    Task: {40FB1BE7-703E-40E2-B465-98290C9C9196} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-28] (Google Inc.)
    Task: {4A3B4745-783E-48CB-A478-4D9C739AFC2D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2015-11-01] (Microsoft Corporation)
    Task: {5286C7D0-1061-469F-A4DF-A03B46DBFDE5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-28] (Google Inc.)
    Task: {D60E9870-8D1B-49A3-9765-11BD28187C9A} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2015-11-01] (Microsoft Corporation)
    Task: {DDB2B85B-AC2B-47BE-8B35-4508538F687D} - System32\Tasks\AutoPico Daily Restart => G:\KMSpico
    Task: {EE47F49F-AFAB-4B77-9F1B-B7180AC10084} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2015-11-01] (Microsoft Corporation)
    Task: {F4192480-BBB4-4A6D-9971-55BFDE927848} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2015-11-01] (Microsoft Corporation)
    Task: {F73E4640-9A10-49C4-8C89-4FE581542E5C} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    ==================== Shortcuts =============================

    (The entries could be listed to be restored or removed.)

    ==================== Loaded Modules (Whitelisted) ==============

    2015-10-30 07:18 - 2015-10-30 07:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
    2015-11-28 15:04 - 2015-11-01 02:11 - 00161448 _____ () C:\Program Files\Common Files\Microsoft Shared\ClickToRun\ApiClient.dll
    2015-10-30 07:17 - 2015-10-30 07:17 - 02652784 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
    2015-10-30 07:17 - 2015-10-30 07:17 - 02652784 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
    2015-11-29 13:18 - 2015-11-01 10:11 - 08901800 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
    2015-11-29 14:50 - 2015-11-29 14:51 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_1.11.19004.0_x86__8wekyb3d8bbwe\SkypeHost.exe
    2015-10-30 07:17 - 2015-10-30 07:17 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
    2015-10-30 07:17 - 2015-10-30 07:17 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
    2015-10-30 07:18 - 2015-10-30 09:07 - 08005632 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
    2015-10-30 07:18 - 2015-10-30 09:07 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
    2015-10-30 07:18 - 2015-10-30 09:07 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
    2015-10-30 07:18 - 2015-10-30 09:07 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
    2015-10-30 07:18 - 2015-10-30 07:18 - 00218456 _____ () c:\windows\system32\WerEtw.dll
    2015-12-01 14:24 - 2005-07-18 13:43 - 00160256 _____ () C:\Program Files (x86)\MSI\Live Update\unrar.dll
    2015-11-29 13:17 - 2015-11-01 10:12 - 08901800 _____ () C:\Program Files (x86)\Microsoft Office\root\Office16\1033\GrooveIntlResource.dll
    2015-11-29 14:50 - 2015-11-29 14:51 - 00152064 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_1.11.19004.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
    2015-11-29 14:50 - 2015-11-29 14:51 - 18906624 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_1.11.19004.0_x86__8wekyb3d8bbwe\SkyWrap.dll
    2015-11-28 02:50 - 2015-11-07 04:36 - 01532744 _____ () C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\libglesv2.dll
    2015-11-28 02:50 - 2015-11-07 04:36 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\libegl.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


    ==================== EXE Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-1966762071-576509629-4117557406-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Shakree Elmi\pictures\brooklyn_bridge_manhattan_new_york-1920x1080.jpg
    DNS Servers: Media is not connected to internet.
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)


    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
    FirewallRules: [{E124B9E8-2D82-487E-A40F-FC391244BC7E}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    FirewallRules: [{51E2D813-4474-49F8-9711-B32BAB62F593}] => (Allow) C:\Users\Shakree Elmi\AppData\Roaming\uTorrent\uTorrent.exe
    FirewallRules: [{7D973C02-881A-42A4-841D-276E38B082C2}] => (Allow) C:\Users\Shakree Elmi\AppData\Roaming\uTorrent\uTorrent.exe
    FirewallRules: [{6E3582D3-88EB-430D-A767-1EED0F067E91}] => (Allow) C:\Users\Shakree Elmi\AppData\Roaming\uTorrent\uTorrent.exe
    FirewallRules: [{9ED4CE05-E53B-4457-9DC2-233B7C0F969F}] => (Allow) C:\Users\Shakree Elmi\AppData\Roaming\uTorrent\uTorrent.exe
    FirewallRules: [{C916FC7C-F6E6-4DE2-AB86-2738B279B9B5}] => (Allow) C:\Users\Shakree Elmi\AppData\Roaming\uTorrent\uTorrent.exe
    FirewallRules: [{A1B8FBC7-BFE3-4471-A5A7-41128AA1AD5C}] => (Allow) C:\Users\Shakree Elmi\AppData\Roaming\uTorrent\uTorrent.exe
    FirewallRules: [{A4516F8F-A072-4FD9-B1B2-21309FD632C3}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
    FirewallRules: [{235A0AFF-98BB-4BB9-BDDE-40823B9C1928}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
    FirewallRules: [{FAB8A033-607F-452A-B6CA-EE408AB50BC8}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
    FirewallRules: [{528DDFB0-8710-4358-84CF-131A8A29EE30}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
    FirewallRules: [{01BD95DB-CB51-4AAA-A85D-07A7CFEE8BD4}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
    FirewallRules: [TCP Query User{7987DA8D-3642-4568-89AE-71615ED50358}D:\program files (x86)\kodi\kodi.exe] => (Allow) D:\program files (x86)\kodi\kodi.exe
    FirewallRules: [UDP Query User{30C1CC94-F0CF-48A7-85D6-B7778C08DA7A}D:\program files (x86)\kodi\kodi.exe] => (Allow) D:\program files (x86)\kodi\kodi.exe
    FirewallRules: [TCP Query User{47633318-2712-41A5-B7A0-C87025311A3F}C:\users\shakree elmi\appdata\roaming\kodi\userdata\addon_data\plugin.video.pulsar\bin\windows_x86\pulsar.exe] => (Allow) C:\users\shakree elmi\appdata\roaming\kodi\userdata\addon_data\plugin.video.pulsar\bin\windows_x86\pulsar.exe
    FirewallRules: [UDP Query User{C51609DE-FDA7-4007-B46F-2A85E842A231}C:\users\shakree elmi\appdata\roaming\kodi\userdata\addon_data\plugin.video.pulsar\bin\windows_x86\pulsar.exe] => (Allow) C:\users\shakree elmi\appdata\roaming\kodi\userdata\addon_data\plugin.video.pulsar\bin\windows_x86\pulsar.exe
    FirewallRules: [{6DAC6E32-390A-4B55-8CA7-F5B9BE72322E}] => (Allow) C:\Program Files\HP\HP Deskjet 2540 series\Bin\DeviceSetup.exe
    FirewallRules: [{6B01B32B-865C-4B0E-AAEE-7CA0AD324901}] => (Allow) LPort=5357
    FirewallRules: [{4DE7EFD6-735A-4223-89E2-B9ABBB7AE31B}] => (Allow) C:\Program Files\HP\HP Deskjet 2540 series\Bin\HPNetworkCommunicatorCom.exe
    FirewallRules: [TCP Query User{F0F85900-57A5-4E26-A72E-DCC04887F969}C:\program files\matlab\matlab production server\r2015a\bin\win64\matlab.exe] => (Allow) C:\program files\matlab\matlab production server\r2015a\bin\win64\matlab.exe
    FirewallRules: [UDP Query User{B0C774E7-4490-45B1-94F6-5C03F5CCC2B0}C:\program files\matlab\matlab production server\r2015a\bin\win64\matlab.exe] => (Allow) C:\program files\matlab\matlab production server\r2015a\bin\win64\matlab.exe
    FirewallRules: [TCP Query User{2292BB42-AB96-45B6-B5AC-7AAADE568A2E}C:\program files\matlab\matlab production server\r2015a\bin\win64\matlab.exe] => (Allow) C:\program files\matlab\matlab production server\r2015a\bin\win64\matlab.exe
    FirewallRules: [UDP Query User{A33A66B7-129D-4F77-A3CB-DFA548C2772D}C:\program files\matlab\matlab production server\r2015a\bin\win64\matlab.exe] => (Allow) C:\program files\matlab\matlab production server\r2015a\bin\win64\matlab.exe
    FirewallRules: [TCP Query User{F8AE1977-0137-44E4-AD8C-03ABF1974A57}D:\program files (x86)\kodi\kodi.exe] => (Allow) D:\program files (x86)\kodi\kodi.exe
    FirewallRules: [UDP Query User{C3F12330-66B5-4FE1-8C78-1957DC2C318F}D:\program files (x86)\kodi\kodi.exe] => (Allow) D:\program files (x86)\kodi\kodi.exe
    FirewallRules: [TCP Query User{AE812336-F877-44D0-A559-51653F01D1F5}C:\users\shakree elmi\appdata\roaming\kodi\userdata\addon_data\plugin.video.pulsar\bin\windows_x86\pulsar.exe] => (Allow) C:\users\shakree elmi\appdata\roaming\kodi\userdata\addon_data\plugin.video.pulsar\bin\windows_x86\pulsar.exe
    FirewallRules: [UDP Query User{FF20AF07-E340-4250-9BF2-2739FFEE2CE0}C:\users\shakree elmi\appdata\roaming\kodi\userdata\addon_data\plugin.video.pulsar\bin\windows_x86\pulsar.exe] => (Allow) C:\users\shakree elmi\appdata\roaming\kodi\userdata\addon_data\plugin.video.pulsar\bin\windows_x86\pulsar.exe

    ==================== Faulty Device Manager Devices =============

    Name: Microsoft PS/2 Mouse
    Description: Microsoft PS/2 Mouse
    Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
    Manufacturer: Microsoft
    Service: i8042prt
    Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
    Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
    Devices stay in this state if they have been prepared for removal.
    After you remove the device, this error disappears.Remove the device, and this error should be resolved.

    Name: Standard PS/2 Keyboard
    Description: Standard PS/2 Keyboard
    Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
    Manufacturer: (Standard keyboards)
    Service: i8042prt
    Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
    Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
    Devices stay in this state if they have been prepared for removal.
    After you remove the device, this error disappears.Remove the device, and this error should be resolved.


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (12/02/2015 00:55:50 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: SHAKREECOMPUTER)
    Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.

    Error: (12/02/2015 03:28:17 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
    Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

    Details:
    AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

    System Error:
    Access is denied.
    .

    Error: (12/02/2015 03:08:41 AM) (Source: SideBySide) (EventID: 78) (User: )
    Description: Activation context generation failed for "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" on line C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3.
    A component version required by the application conflicts with another component version already active.
    Conflicting components are:.
    Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest.
    Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest.

    Error: (12/01/2015 07:54:10 PM) (Source: SideBySide) (EventID: 78) (User: )
    Description: Activation context generation failed for "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" on line C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3.
    A component version required by the application conflicts with another component version already active.
    Conflicting components are:.
    Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest.
    Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest.

    Error: (12/01/2015 07:36:55 PM) (Source: SideBySide) (EventID: 78) (User: )
    Description: Activation context generation failed for "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" on line C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3.
    A component version required by the application conflicts with another component version already active.
    Conflicting components are:.
    Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest.
    Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest.

    Error: (12/01/2015 05:48:25 PM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program DS4Windows.exe version 1.4.3.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

    Process ID: 1ab4

    Start Time: 01d12c6011d65747

    Termination Time: 4294967295

    Application Path: C:\Users\Shakree Elmi\Desktop\Controller\DS4Windows.exe

    Report Id: b6202f3a-9853-11e5-9bd8-00e04c817b18

    Faulting package full name:

    Faulting package-relative application ID:

    Error: (12/01/2015 04:00:11 PM) (Source: SideBySide) (EventID: 78) (User: )
    Description: Activation context generation failed for "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" on line C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3.
    A component version required by the application conflicts with another component version already active.
    Conflicting components are:.
    Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest.
    Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest.

    Error: (12/01/2015 04:00:06 PM) (Source: SideBySide) (EventID: 78) (User: )
    Description: Activation context generation failed for "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" on line C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3.
    A component version required by the application conflicts with another component version already active.
    Conflicting components are:.
    Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest.
    Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest.

    Error: (12/01/2015 02:37:53 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: SHAKREECOMPUTER)
    Description: Activation of app Microsoft.Getstarted_2.5.6.0_x64__8wekyb3d8bbwe:App.AppX7mv0s3r0wanj0n66dy6vax24ps6avzvz.mca failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.

    Error: (12/01/2015 00:51:58 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: Fallout4.exe, version: 1.1.30.0, time stamp: 0x563b8ba7
    Faulting module name: Fallout4.exe, version: 1.1.30.0, time stamp: 0x563b8ba7
    Exception code: 0xc000041d
    Fault offset: 0x00000000016c723e
    Faulting process id: 0x348
    Faulting application start time: 0xFallout4.exe0
    Faulting application path: Fallout4.exe1
    Faulting module path: Fallout4.exe2
    Report Id: Fallout4.exe3
    Faulting package full name: Fallout4.exe4
    Faulting package-relative application ID: Fallout4.exe5


    System errors:
    =============
    Error: (12/02/2015 01:10:23 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
    Description: WLAN Extensibility Module has failed to start.

    Module Path: C:\WINDOWS\system32\Rtlihvs.dll
    Error Code: 126

    Error: (12/02/2015 01:08:55 PM) (Source: DCOM) (EventID: 10016) (User: SHAKREECOMPUTER)
    Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}SHAKREECOMPUTERShakree ElmiS-1-5-21-1966762071-576509629-4117557406-1002LocalHost (Using LRPC)Microsoft.WindowsStore_2015.23.23.0_x64__8wekyb3d8bbweS-1-15-2-1609473798-1231923017-684268153-4268514328-882773646-2760585773-1760938157

    Error: (12/02/2015 01:07:06 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The Sync Host_42e59 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.

    Error: (12/02/2015 01:07:06 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable

    Error: (12/02/2015 01:00:20 PM) (Source: DCOM) (EventID: 10010) (User: SHAKREECOMPUTER)
    Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}

    Error: (12/02/2015 01:00:11 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The Sync Host_4027a service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.

    Error: (12/02/2015 01:00:11 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable

    Error: (12/02/2015 00:57:51 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
    Description: WLAN Extensibility Module has failed to start.

    Module Path: C:\WINDOWS\system32\Rtlihvs.dll
    Error Code: 126

    Error: (12/02/2015 00:55:50 PM) (Source: DCOM) (EventID: 10010) (User: SHAKREECOMPUTER)
    Description: CortanaUI.AppXn73w0hsq3g4wx1h9fhf7q02vw2wta6qc.mca

    Error: (12/02/2015 00:55:50 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The User Data Access_463a9 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.


    CodeIntegrity:
    ===================================
    Date: 2015-12-01 17:36:15.788
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Windows.old\Windows\System32\WinBioPlugIns\winbiostorageadapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2015-12-01 17:36:15.772
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Windows.old\Windows\System32\WinBioPlugIns\winbiostorageadapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2015-12-01 17:36:15.754
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Windows.old\Windows\System32\WinBioPlugIns\winbiostorageadapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2015-12-01 17:36:15.738
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Windows.old\Windows\System32\WinBioPlugIns\winbiostorageadapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2015-12-01 17:36:15.719
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Windows.old\Windows\System32\WinBioPlugIns\winbiostorageadapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2015-12-01 17:36:15.698
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Windows.old\Windows\System32\WinBioPlugIns\winbiostorageadapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2015-12-01 17:36:15.670
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Windows.old\Windows\System32\WinBioPlugIns\winbiosensoradapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2015-12-01 17:36:15.653
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Windows.old\Windows\System32\WinBioPlugIns\winbiosensoradapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2015-12-01 17:36:15.637
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Windows.old\Windows\System32\WinBioPlugIns\winbiosensoradapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2015-12-01 17:36:15.620
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Windows.old\Windows\System32\WinBioPlugIns\winbiosensoradapter.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


    ==================== Memory info ===========================

    Processor: Intel(R) Core(TM) i5-4460 CPU @ 3.20GHz
    Percentage of memory in use: 26%
    Total physical RAM: 8134.53 MB
    Available physical RAM: 5956.12 MB
    Total Virtual: 11078.53 MB
    Available Virtual: 8725.84 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:223.02 GB) (Free:156 GB) NTFS
    Drive d: (HDD1) (Fixed) (Total:488.28 GB) (Free:232.4 GB) NTFS
    Drive e: (HDD2) (Fixed) (Total:443.1 GB) (Free:442.96 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 00000000)

    Partition: GPT.

    ========================================================
    Disk: 1 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: 00000000)

    Partition: GPT.

    ==================== End of Addition.txt ============================
     
  17. Broni

    Broni Malware Annihilator Posts: 52,915   +344

    Download attached fixlist.txt file and save it to the Desktop.
    NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Run FRST(FRST64) and press the Fix button just once and wait.
    The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.
     

    Attached Files:

  18. Shakree

    Shakree TS Rookie Topic Starter Posts: 18

    Fix result of Farbar Recovery Scan Tool (x64) Version:01-12-2015
    Ran by Shakree Elmi (2015-12-03 02:18:45) Run:1
    Running from C:\Users\Shakree Elmi\Desktop
    Loaded Profiles: Shakree Elmi (Available Profiles: Shakree Elmi)
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    HKLM-x32\...\Run: [] => [X]
    2015-11-30 01:01 - 2015-11-30 01:01 - 0000057 _____ () C:\ProgramData\Ament.ini
    2015-11-29 04:40 - 2015-11-29 04:40 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
    C:\Users\Shakree Elmi\AppData\Local\Temp\dllnt_dump.dll
    C:\Users\Shakree Elmi\AppData\Local\Temp\sqlite3.dll

    *****************

    HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
    C:\ProgramData\Ament.ini => moved successfully
    C:\ProgramData\DP45977C.lfl => moved successfully
    C:\Users\Shakree Elmi\AppData\Local\Temp\dllnt_dump.dll => moved successfully
    C:\Users\Shakree Elmi\AppData\Local\Temp\sqlite3.dll => moved successfully

    ==== End of Fixlog 02:18:45 ====
     
  19. Broni

    Broni Malware Annihilator Posts: 52,915   +344

    Last scans...

    [​IMG] Download Security Check from here or here and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

    NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
    NOTE 2. SecurityCheck may produce some false warning(s), so leave the results reading to me.
    NOTE 3. If you receive UNSUPPORTED OPERATING SYSTEM! ABORTED! message restart computer and Security Check should run


    [​IMG] Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
    Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
    • Other Services

    Press "Scan".
    It will create a log (FSS.txt) in the same directory the tool is run.
    Please copy and paste the log to your reply.


    [​IMG] Download Temp File Cleaner (TFC)
    Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.


    [​IMG] Download Sophos Free Virus Removal Tool and save it to your desktop.
    • Double click the icon and select Run
    • Click Next
    • Select I accept the terms in this license agreement, then click Next twice
    • Click Install
    • Click Finish to launch the program
    • Once the virus database has been updated click Start Scanning
    • If any threats are found click Details, then View log file... (bottom left hand corner)
    • Copy and paste the results in your reply
    • Close the Notepad document, close the Threat Details screen, then click Start cleanup
    • Click Exit to close the program
     
  20. Shakree

    Shakree TS Rookie Topic Starter Posts: 18

    I cant boot up my pc after I did fixlist.txt...
     
  21. Shakree

    Shakree TS Rookie Topic Starter Posts: 18

    I did a system restore back to where I run the junkware removal tool bcs thats the latest system restore point...but even after that it stucks at the loading screen..but I can get into the safe mode though..
     
  22. Shakree

    Shakree TS Rookie Topic Starter Posts: 18

    Please close this thread as I already reformat my computer and decided to go for Windows 8.1 instead of 10. Thank you for your cooperation.
     
  23. Broni

    Broni Malware Annihilator Posts: 52,915   +344

    Thank you for letting me know :)
     

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...