Silverboots
Posts: 39 +0
C:\WINDOWS\system32\appidcertstorecheck.exe
2017-05-10 00:37 - 2017-04-28 01:01 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_ClosedCaptioning.dll
2017-05-10 00:37 - 2017-04-28 01:01 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netvsc.sys
2017-05-10 00:37 - 2017-04-28 01:01 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\virtdisk.dll
2017-05-10 00:37 - 2017-04-28 01:00 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Profile.RetailInfo.dll
2017-05-10 00:37 - 2017-04-28 01:00 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll
2017-05-10 00:37 - 2017-04-28 01:00 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2017-05-10 00:37 - 2017-04-28 00:59 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
2017-05-10 00:37 - 2017-04-28 00:59 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidsvc.dll
2017-05-10 00:37 - 2017-04-28 00:59 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2017-05-10 00:37 - 2017-04-28 00:58 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2017-05-10 00:37 - 2017-04-28 00:58 - 00150016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2017-05-10 00:37 - 2017-04-28 00:58 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsentUX.dll
2017-05-10 00:37 - 2017-04-28 00:57 - 00241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2017-05-10 00:37 - 2017-04-28 00:57 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthserv.dll
2017-05-10 00:37 - 2017-04-28 00:56 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2017-05-10 00:37 - 2017-04-28 00:56 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultcli.dll
2017-05-10 00:37 - 2017-04-28 00:56 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-05-10 00:37 - 2017-04-28 00:55 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthprops.cpl
2017-05-10 00:37 - 2017-04-28 00:54 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2017-05-10 00:37 - 2017-04-28 00:51 - 01913856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2017-05-10 00:37 - 2017-04-28 00:51 - 01584128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2017-05-10 00:37 - 2017-04-28 00:50 - 01476608 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2017-05-10 00:37 - 2017-04-28 00:50 - 00380416 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationApi.dll
2017-05-10 00:37 - 2017-04-28 00:50 - 00338944 _____ (Microsoft Corporation) C:\WINDOWS\system32\adsnt.dll
2017-05-10 00:37 - 2017-04-28 00:48 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2017-05-10 00:37 - 2017-04-28 00:47 - 00942080 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2017-05-10 00:37 - 2017-04-28 00:47 - 00649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\vds.exe
2017-05-10 00:37 - 2017-04-28 00:46 - 01547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe
2017-05-10 00:37 - 2017-04-28 00:46 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe
2017-05-10 00:37 - 2017-04-28 00:46 - 00501248 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi2.dll
2017-05-10 00:37 - 2017-04-28 00:46 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2017-05-10 00:37 - 2017-04-28 00:45 - 00946688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_sr.dll
2017-05-10 00:37 - 2017-04-28 00:45 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2017-05-10 00:37 - 2017-04-28 00:45 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceAgent.exe
2017-05-10 00:37 - 2017-04-28 00:43 - 00600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll
2017-05-10 00:37 - 2017-04-28 00:43 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2017-05-10 00:37 - 2017-04-28 00:42 - 01021440 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2017-05-10 00:37 - 2017-04-28 00:41 - 00890368 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2017-05-10 00:37 - 2017-04-28 00:41 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
2017-05-10 00:37 - 2017-04-28 00:40 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-05-10 00:37 - 2017-04-28 00:40 - 00886784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2017-05-10 00:37 - 2017-04-28 00:40 - 00770560 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2017-05-10 00:37 - 2017-04-28 00:39 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2017-05-10 00:37 - 2017-04-28 00:38 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2017-05-10 00:37 - 2017-04-28 00:37 - 02216960 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll
2017-05-10 00:37 - 2017-04-28 00:37 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2017-05-10 00:37 - 2017-04-28 00:34 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\spaceman.exe
2017-05-10 00:37 - 2017-04-28 00:33 - 01817088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2017-05-10 00:37 - 2016-12-21 08:09 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneBackupHandler.dll
2017-05-05 20:47 - 2017-05-05 20:47 - 01426918 _____ C:\Users\josle\Downloads\Headlines - 5th May 2017.pdf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-06-01 02:48 - 2016-11-22 16:22 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-05-31 18:03 - 2017-04-05 06:31 - 00004022 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1491370280
2017-05-31 18:03 - 2017-04-05 06:31 - 00001092 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2017-05-31 17:58 - 2017-03-06 23:24 - 00000000 __SHD C:\Users\silve\IntelGraphicsProfiles
2017-05-31 17:57 - 2017-04-01 17:06 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-05-31 17:56 - 2016-11-23 00:22 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-05-31 08:32 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-05-31 08:32 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-05-31 08:30 - 2016-11-23 00:32 - 01043726 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-05-31 08:23 - 2017-04-01 17:10 - 00000000 ____D C:\Users\silve
2017-05-31 08:22 - 2016-07-16 07:04 - 00786432 _____ C:\WINDOWS\system32\config\BBI
2017-05-31 08:19 - 2017-03-06 23:28 - 00000000 ___RD C:\Users\silve\OneDrive
2017-05-31 06:17 - 2015-07-10 12:04 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2017-05-31 05:12 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-05-31 05:10 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-05-30 21:57 - 2017-04-05 06:24 - 00004268 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update
2017-05-29 17:22 - 2017-04-01 17:09 - 00000000 ____D C:\Users\josle
2017-05-29 17:22 - 2017-03-07 18:18 - 00000000 ___RD C:\Users\josle\OneDrive
2017-05-29 16:57 - 2017-03-07 18:14 - 00000000 __SHD C:\Users\josle\IntelGraphicsProfiles
2017-05-28 14:01 - 2016-07-16 12:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-05-28 12:16 - 2016-03-08 22:51 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-05-24 00:17 - 2017-03-08 20:31 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-05-24 00:13 - 2017-03-08 20:31 - 132223576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-05-24 00:11 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-05-20 06:06 - 2015-08-31 11:51 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-05-20 05:51 - 2016-11-22 16:21 - 00394584 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-05-19 05:20 - 2017-03-06 23:24 - 00000000 ____D C:\Users\silve\AppData\Local\Packages
2017-05-19 04:11 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF
2017-05-18 19:16 - 2015-07-10 12:04 - 00000159 _____ C:\WINDOWS\win.ini
2017-05-16 17:33 - 2017-03-07 18:15 - 00000000 ____D C:\Users\josle\AppData\Local\Google
2017-05-16 15:57 - 2017-03-07 00:14 - 00002276 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-05-13 20:21 - 2016-11-23 00:36 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-05-13 16:07 - 2016-07-16 12:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-05-13 16:07 - 2016-07-16 12:47 - 00000000 ___SD C:\WINDOWS\system32\F12
2017-05-13 16:07 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\en-GB
2017-05-13 16:07 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2017-05-13 16:07 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\oobe
2017-05-13 16:07 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\en-GB
2017-05-13 16:07 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
2017-05-13 16:07 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\Provisioning
2017-05-13 16:07 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2017-05-13 16:07 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2017-05-13 16:06 - 2016-07-16 12:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-05-13 16:06 - 2016-07-16 12:47 - 00000000 ___RD C:\Program Files\Windows Defender
2017-05-13 16:06 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2017-05-13 16:06 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-05-13 16:06 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2017-05-13 04:36 - 2017-03-07 01:39 - 00026077 _____ C:\Users\silve\Documents\Wish List Stephanie.odt
2017-05-13 03:51 - 2017-04-05 06:24 - 00158880 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswstm.sys
2017-05-12 23:08 - 2017-03-07 18:14 - 00000000 ____D C:\Users\josle\AppData\Local\Packages
2017-05-10 15:50 - 2017-04-05 06:29 - 00032600 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2017-05-10 15:50 - 2017-04-05 06:24 - 01007160 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2017-05-10 15:50 - 2017-04-05 06:24 - 00569192 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2017-05-10 15:50 - 2017-04-05 06:24 - 00339696 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2017-05-10 15:50 - 2017-04-05 06:24 - 00334576 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbloga.sys
2017-05-10 15:50 - 2017-04-05 06:24 - 00311808 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys
2017-05-10 15:50 - 2017-04-05 06:24 - 00190256 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsha.sys
2017-05-10 15:50 - 2017-04-05 06:24 - 00128648 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2017-05-10 15:50 - 2017-04-05 06:24 - 00101152 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2017-05-10 15:50 - 2017-04-05 06:24 - 00075704 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2017-05-10 15:50 - 2017-04-05 06:24 - 00049016 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbuniva.sys
2017-05-10 15:50 - 2017-04-05 06:24 - 00038296 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2017-05-10 00:02 - 2016-07-16 12:42 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManMigrationPlugin.dll
==================== Files in the root of some directories =======
2017-04-01 17:06 - 2017-04-01 17:06 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2017-05-18 18:56 - 2017-05-18 19:16 - 0000824 _____ () C:\ProgramData\hpzinstall.log
Some files in TEMP:
====================
2017-05-13 15:57 - 2017-05-13 15:59 - 61416208 _____ (Serif (Europe) Ltd) C:\Users\silve\AppData\Local\Temp\CraftArtist-2-en-GB_2.1.0.037_64-Bit_Patch-Setup.exe
2017-05-31 05:15 - 2016-11-11 11:13 - 1886344 _____ (Microsoft Corporation) C:\Users\silve\AppData\Local\Temp\dllnt_dump.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-05-30 04:53
==================== End of FRST.txt ============================
2017-05-10 00:37 - 2017-04-28 01:01 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_ClosedCaptioning.dll
2017-05-10 00:37 - 2017-04-28 01:01 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netvsc.sys
2017-05-10 00:37 - 2017-04-28 01:01 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\virtdisk.dll
2017-05-10 00:37 - 2017-04-28 01:00 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Profile.RetailInfo.dll
2017-05-10 00:37 - 2017-04-28 01:00 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll
2017-05-10 00:37 - 2017-04-28 01:00 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2017-05-10 00:37 - 2017-04-28 00:59 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
2017-05-10 00:37 - 2017-04-28 00:59 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidsvc.dll
2017-05-10 00:37 - 2017-04-28 00:59 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2017-05-10 00:37 - 2017-04-28 00:58 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2017-05-10 00:37 - 2017-04-28 00:58 - 00150016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2017-05-10 00:37 - 2017-04-28 00:58 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsentUX.dll
2017-05-10 00:37 - 2017-04-28 00:57 - 00241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2017-05-10 00:37 - 2017-04-28 00:57 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthserv.dll
2017-05-10 00:37 - 2017-04-28 00:56 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2017-05-10 00:37 - 2017-04-28 00:56 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultcli.dll
2017-05-10 00:37 - 2017-04-28 00:56 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-05-10 00:37 - 2017-04-28 00:55 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthprops.cpl
2017-05-10 00:37 - 2017-04-28 00:54 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2017-05-10 00:37 - 2017-04-28 00:51 - 01913856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2017-05-10 00:37 - 2017-04-28 00:51 - 01584128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2017-05-10 00:37 - 2017-04-28 00:50 - 01476608 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2017-05-10 00:37 - 2017-04-28 00:50 - 00380416 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationApi.dll
2017-05-10 00:37 - 2017-04-28 00:50 - 00338944 _____ (Microsoft Corporation) C:\WINDOWS\system32\adsnt.dll
2017-05-10 00:37 - 2017-04-28 00:48 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2017-05-10 00:37 - 2017-04-28 00:47 - 00942080 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2017-05-10 00:37 - 2017-04-28 00:47 - 00649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\vds.exe
2017-05-10 00:37 - 2017-04-28 00:46 - 01547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe
2017-05-10 00:37 - 2017-04-28 00:46 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe
2017-05-10 00:37 - 2017-04-28 00:46 - 00501248 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi2.dll
2017-05-10 00:37 - 2017-04-28 00:46 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2017-05-10 00:37 - 2017-04-28 00:45 - 00946688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_sr.dll
2017-05-10 00:37 - 2017-04-28 00:45 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2017-05-10 00:37 - 2017-04-28 00:45 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceAgent.exe
2017-05-10 00:37 - 2017-04-28 00:43 - 00600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll
2017-05-10 00:37 - 2017-04-28 00:43 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2017-05-10 00:37 - 2017-04-28 00:42 - 01021440 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2017-05-10 00:37 - 2017-04-28 00:41 - 00890368 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2017-05-10 00:37 - 2017-04-28 00:41 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
2017-05-10 00:37 - 2017-04-28 00:40 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-05-10 00:37 - 2017-04-28 00:40 - 00886784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2017-05-10 00:37 - 2017-04-28 00:40 - 00770560 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2017-05-10 00:37 - 2017-04-28 00:39 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2017-05-10 00:37 - 2017-04-28 00:38 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2017-05-10 00:37 - 2017-04-28 00:37 - 02216960 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll
2017-05-10 00:37 - 2017-04-28 00:37 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2017-05-10 00:37 - 2017-04-28 00:34 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\spaceman.exe
2017-05-10 00:37 - 2017-04-28 00:33 - 01817088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2017-05-10 00:37 - 2016-12-21 08:09 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneBackupHandler.dll
2017-05-05 20:47 - 2017-05-05 20:47 - 01426918 _____ C:\Users\josle\Downloads\Headlines - 5th May 2017.pdf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-06-01 02:48 - 2016-11-22 16:22 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-05-31 18:03 - 2017-04-05 06:31 - 00004022 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1491370280
2017-05-31 18:03 - 2017-04-05 06:31 - 00001092 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2017-05-31 17:58 - 2017-03-06 23:24 - 00000000 __SHD C:\Users\silve\IntelGraphicsProfiles
2017-05-31 17:57 - 2017-04-01 17:06 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-05-31 17:56 - 2016-11-23 00:22 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-05-31 08:32 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-05-31 08:32 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-05-31 08:30 - 2016-11-23 00:32 - 01043726 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-05-31 08:23 - 2017-04-01 17:10 - 00000000 ____D C:\Users\silve
2017-05-31 08:22 - 2016-07-16 07:04 - 00786432 _____ C:\WINDOWS\system32\config\BBI
2017-05-31 08:19 - 2017-03-06 23:28 - 00000000 ___RD C:\Users\silve\OneDrive
2017-05-31 06:17 - 2015-07-10 12:04 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2017-05-31 05:12 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-05-31 05:10 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-05-30 21:57 - 2017-04-05 06:24 - 00004268 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update
2017-05-29 17:22 - 2017-04-01 17:09 - 00000000 ____D C:\Users\josle
2017-05-29 17:22 - 2017-03-07 18:18 - 00000000 ___RD C:\Users\josle\OneDrive
2017-05-29 16:57 - 2017-03-07 18:14 - 00000000 __SHD C:\Users\josle\IntelGraphicsProfiles
2017-05-28 14:01 - 2016-07-16 12:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-05-28 12:16 - 2016-03-08 22:51 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-05-24 00:17 - 2017-03-08 20:31 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-05-24 00:13 - 2017-03-08 20:31 - 132223576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-05-24 00:11 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-05-20 06:06 - 2015-08-31 11:51 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-05-20 05:51 - 2016-11-22 16:21 - 00394584 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-05-19 05:20 - 2017-03-06 23:24 - 00000000 ____D C:\Users\silve\AppData\Local\Packages
2017-05-19 04:11 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF
2017-05-18 19:16 - 2015-07-10 12:04 - 00000159 _____ C:\WINDOWS\win.ini
2017-05-16 17:33 - 2017-03-07 18:15 - 00000000 ____D C:\Users\josle\AppData\Local\Google
2017-05-16 15:57 - 2017-03-07 00:14 - 00002276 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-05-13 20:21 - 2016-11-23 00:36 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-05-13 16:07 - 2016-07-16 12:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-05-13 16:07 - 2016-07-16 12:47 - 00000000 ___SD C:\WINDOWS\system32\F12
2017-05-13 16:07 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\en-GB
2017-05-13 16:07 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2017-05-13 16:07 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\oobe
2017-05-13 16:07 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\en-GB
2017-05-13 16:07 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
2017-05-13 16:07 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\Provisioning
2017-05-13 16:07 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2017-05-13 16:07 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2017-05-13 16:06 - 2016-07-16 12:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-05-13 16:06 - 2016-07-16 12:47 - 00000000 ___RD C:\Program Files\Windows Defender
2017-05-13 16:06 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2017-05-13 16:06 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-05-13 16:06 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2017-05-13 04:36 - 2017-03-07 01:39 - 00026077 _____ C:\Users\silve\Documents\Wish List Stephanie.odt
2017-05-13 03:51 - 2017-04-05 06:24 - 00158880 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswstm.sys
2017-05-12 23:08 - 2017-03-07 18:14 - 00000000 ____D C:\Users\josle\AppData\Local\Packages
2017-05-10 15:50 - 2017-04-05 06:29 - 00032600 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2017-05-10 15:50 - 2017-04-05 06:24 - 01007160 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2017-05-10 15:50 - 2017-04-05 06:24 - 00569192 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2017-05-10 15:50 - 2017-04-05 06:24 - 00339696 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2017-05-10 15:50 - 2017-04-05 06:24 - 00334576 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbloga.sys
2017-05-10 15:50 - 2017-04-05 06:24 - 00311808 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys
2017-05-10 15:50 - 2017-04-05 06:24 - 00190256 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsha.sys
2017-05-10 15:50 - 2017-04-05 06:24 - 00128648 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2017-05-10 15:50 - 2017-04-05 06:24 - 00101152 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2017-05-10 15:50 - 2017-04-05 06:24 - 00075704 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2017-05-10 15:50 - 2017-04-05 06:24 - 00049016 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbuniva.sys
2017-05-10 15:50 - 2017-04-05 06:24 - 00038296 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2017-05-10 00:02 - 2016-07-16 12:42 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManMigrationPlugin.dll
==================== Files in the root of some directories =======
2017-04-01 17:06 - 2017-04-01 17:06 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2017-05-18 18:56 - 2017-05-18 19:16 - 0000824 _____ () C:\ProgramData\hpzinstall.log
Some files in TEMP:
====================
2017-05-13 15:57 - 2017-05-13 15:59 - 61416208 _____ (Serif (Europe) Ltd) C:\Users\silve\AppData\Local\Temp\CraftArtist-2-en-GB_2.1.0.037_64-Bit_Patch-Setup.exe
2017-05-31 05:15 - 2016-11-11 11:13 - 1886344 _____ (Microsoft Corporation) C:\Users\silve\AppData\Local\Temp\dllnt_dump.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-05-30 04:53
==================== End of FRST.txt ============================